Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
https://onset2.onsetcomp.com/files/software/hoboware/3.7.28/HOBOware_Free_Setup.exe

Overview

General Information

Sample URL:https://onset2.onsetcomp.com/files/software/hoboware/3.7.28/HOBOware_Free_Setup.exe
Analysis ID:1458958
Infos:

Detection

Score:48
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Creates autostart registry keys to launch java
Drops large PE files
Creates a process in suspended mode (likely to inject code)
Drops PE files
Found dropped PE file which has not been started or loaded
PE file contains executable resources (Code or Archives)
Queries keyboard layouts
Queries the volume information (name, serial number etc) of a device
Sample execution stops while process was sleeping (likely an evasion)
Searches for user specific document files
Sigma detected: Usage Of Web Request Commands And Cmdlets
Stores files to the Windows start menu directory
Very long cmdline option found, this is very uncommon (may be encrypted or packed)

Classification

  • System is w10x64
  • cmd.exe (PID: 5864 cmdline: C:\Windows\system32\cmd.exe /c wget -t 2 -v -T 60 -P "C:\Users\user\Desktop\download" --no-check-certificate --content-disposition --user-agent="Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; AS; rv:11.0) like Gecko" "https://onset2.onsetcomp.com/files/software/hoboware/3.7.28/HOBOware_Free_Setup.exe" > cmdline.out 2>&1 MD5: D0FCE3AFA6AA1D58CE9FA336CC2B675B)
    • conhost.exe (PID: 6000 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
    • wget.exe (PID: 4508 cmdline: wget -t 2 -v -T 60 -P "C:\Users\user\Desktop\download" --no-check-certificate --content-disposition --user-agent="Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; AS; rv:11.0) like Gecko" "https://onset2.onsetcomp.com/files/software/hoboware/3.7.28/HOBOware_Free_Setup.exe" MD5: 3DADB6E2ECE9C4B3E1E322E617658B60)
  • HOBOware_Free_Setup.exe (PID: 6392 cmdline: "C:\Users\user\Desktop\download\HOBOware_Free_Setup.exe" MD5: 09A67AE954237BFCC0FA90FE805449AD)
    • HOBOware_Free_Setup.tmp (PID: 5604 cmdline: "C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp" /SL5="$8004E,252732992,141824,C:\Users\user\Desktop\download\HOBOware_Free_Setup.exe" MD5: 461456B58784CAB0CA1D194B41A2D256)
      • _setup64.tmp (PID: 4156 cmdline: helper 105 0x4C4 MD5: E4211D6D009757C078A9FAC7FF4F03D4)
        • conhost.exe (PID: 1844 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
      • WINWORD.EXE (PID: 5992 cmdline: "C:\Program Files (x86)\Microsoft Office\Root\Office16\WINWORD.EXE" /n "C:\Program Files\Onset Computer Corporation\HOBOware\README.rtf" /o "" MD5: 1A0C2C2E7D9C4BC18E91604E9B0C7678)
  • cleanup
No configs have been found
No yara matches

System Summary

barindex
Source: Process startedAuthor: James Pemberton / @4A616D6573, Endgame, JHasenbusch, oscd.community, Austin Songer @austinsonger: Data: Command: C:\Windows\system32\cmd.exe /c wget -t 2 -v -T 60 -P "C:\Users\user\Desktop\download" --no-check-certificate --content-disposition --user-agent="Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; AS; rv:11.0) like Gecko" "https://onset2.onsetcomp.com/files/software/hoboware/3.7.28/HOBOware_Free_Setup.exe" > cmdline.out 2>&1, CommandLine: C:\Windows\system32\cmd.exe /c wget -t 2 -v -T 60 -P "C:\Users\user\Desktop\download" --no-check-certificate --content-disposition --user-agent="Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; AS; rv:11.0) like Gecko" "https://onset2.onsetcomp.com/files/software/hoboware/3.7.28/HOBOware_Free_Setup.exe" > cmdline.out 2>&1, CommandLine|base64offset|contains: , Image: C:\Windows\SysWOW64\cmd.exe, NewProcessName: C:\Windows\SysWOW64\cmd.exe, OriginalFileName: C:\Windows\SysWOW64\cmd.exe, ParentCommandLine: , ParentImage: , ParentProcessId: 5476, ProcessCommandLine: C:\Windows\system32\cmd.exe /c wget -t 2 -v -T 60 -P "C:\Users\user\Desktop\download" --no-check-certificate --content-disposition --user-agent="Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; AS; rv:11.0) like Gecko" "https://onset2.onsetcomp.com/files/software/hoboware/3.7.28/HOBOware_Free_Setup.exe" > cmdline.out 2>&1, ProcessId: 5864, ProcessName: cmd.exe
No Snort rule has matched

Click to jump to signature section

Show All Signature Results
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer CorporationJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOwareJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\PluginsJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\ProcessorsJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\unins000.datJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\is-CSK4J.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\is-OLD4F.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\is-38022.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\is-USKD6.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\is-BPEP4.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\is-6I1Q1.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\is-O4KOT.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\is-SPUMH.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\is-M9FQP.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\Microsoft.VC80.CRTJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\Microsoft.VC80.CRT\is-K8B1A.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\Microsoft.VC80.CRT\is-DHMOA.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\Microsoft.VC80.CRT\is-RABQE.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\Microsoft.VC80.CRT\is-AE1HA.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\is-5UK12.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\is-G4RJV.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\is-UR4RJ.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\is-G5Q8V.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\is-GIHG3.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\is-NJA8S.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\is-1Q5F1.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\is-5TI14.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\is-RFFRQ.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\is-FM82F.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\is-N2O9V.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\is-955ER.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\is-KBR3D.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\binJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\bin\is-KMING.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\bin\is-CG9U6.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\bin\is-PFBAT.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\bin\is-KLT2L.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\bin\is-7FJIO.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\bin\is-6E11D.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\bin\is-51T21.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\bin\is-LFCPA.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\bin\is-O1LIU.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\bin\is-AKCDD.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\bin\is-D8SKV.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\bin\is-CDCB3.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\bin\is-KHRAR.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\bin\is-17GVT.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\bin\is-PEQOG.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\bin\is-FH6VO.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\bin\is-Q6L16.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\bin\is-V6NQM.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\bin\is-P9SLC.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\bin\is-7AF32.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\bin\is-DHMGO.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\bin\is-LSS3F.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\bin\is-0E28A.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\bin\is-UHS4P.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\bin\is-7MD89.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\bin\is-B1P41.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\bin\is-CKC23.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\bin\is-7D8OJ.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\bin\is-DTMAF.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\bin\is-4SOA3.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\bin\is-G717E.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\bin\is-LCGMB.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\bin\is-H6KE5.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\bin\is-TNV7E.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\bin\is-22LH3.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\bin\is-JFEPN.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\bin\is-R45U1.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\bin\is-QKTHP.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\bin\is-SSFBR.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\bin\is-64R2F.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\bin\is-LNQOR.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\bin\is-8HR2T.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\bin\is-UTDOE.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\bin\is-GI8KC.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\bin\is-3PAHC.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\bin\is-BG5OH.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\bin\is-42EBJ.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\bin\is-SL3N6.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\bin\is-6RAEB.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\bin\is-JBVKE.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\bin\is-RHJE3.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\bin\is-DCFMK.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\bin\is-OT3AH.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\bin\serverJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\bin\server\is-HKCSB.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\bin\server\is-2K9SL.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demoJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\is-AS52E.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\appletsJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\ArcTestJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\ArcTest\is-6P7KL.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\ArcTest\is-JL1Q1.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\ArcTest\is-M6F81.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\ArcTest\is-VOFED.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\ArcTest\is-119FG.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\ArcTest\is-D0GR7.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\BarChartJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\BarChart\is-KANL1.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\BarChart\is-7BBI9.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\BarChart\is-0MGHQ.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\BarChart\is-5BOHM.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\BlinkJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\Blink\is-FJJSA.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\Blink\is-K259P.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\Blink\is-5FG69.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\Blink\is-5AHJ5.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\CardTestJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\CardTest\is-THNAM.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\CardTest\is-TKLKL.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\CardTest\is-QQTBO.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\CardTest\is-5SSPD.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\ClockJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\Clock\is-HMU0T.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\Clock\is-EL0MM.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\Clock\is-PF4KT.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\DitherTestJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\DitherTest\is-DTH25.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\DitherTest\is-UUIJM.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\DitherTest\is-GOJNK.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\DitherTest\is-2N08G.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\DitherTest\is-H19F6.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\DitherTest\is-0AKBQ.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\DitherTest\is-VA336.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\DitherTest\is-RBE1A.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\DrawTestJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\DrawTest\is-BNJ67.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\DrawTest\is-J5T60.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\DrawTest\is-FK894.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\DrawTest\is-JA5E2.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\DrawTest\is-VRRH0.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\FractalJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\Fractal\is-JR7J0.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\Fractal\is-6LVT7.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\Fractal\is-FPDHH.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\Fractal\is-T7TTB.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\Fractal\is-MHKNJ.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\Fractal\is-RF7N6.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\GraphicsTestJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\GraphicsTest\is-L8J2E.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\GraphicsTest\is-9NHST.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\GraphicsTest\is-TTICH.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\GraphicsTest\is-DMSIQ.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\GraphicsTest\is-MTUBI.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\GraphicsTest\is-4CP5H.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\GraphicsTest\is-ON0UH.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\GraphicsTest\is-09OFR.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\GraphicsTest\is-P19BK.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\GraphicsTest\is-75DGS.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\GraphicsTest\is-O4PEC.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\GraphicsTest\is-F2GI0.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\GraphicsTest\is-RJLLD.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\GraphicsTest\is-IHESP.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\GraphicsTest\is-OCJGP.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\GraphicsTest\is-VAJ11.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\GraphicsTest\is-B42FL.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\MoleculeViewerJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\MoleculeViewer\is-MQHAT.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\MoleculeViewer\is-SOBEG.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\MoleculeViewer\is-IK58N.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\MoleculeViewer\is-SH2L2.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\MoleculeViewer\is-MCB12.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\MoleculeViewer\is-9084A.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\MoleculeViewer\is-BD1OQ.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\NervousTextJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\NervousText\is-27IKF.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\NervousText\is-4E290.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\NervousText\is-9A12V.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\SimpleGraphJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\SimpleGraph\is-QQM51.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\SimpleGraph\is-FEEGI.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\SimpleGraph\is-BSRGE.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\SortDemoJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\SortDemo\is-2D4F6.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\SortDemo\is-NF154.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\SortDemo\is-7F803.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\SortDemo\is-HN795.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\SortDemo\is-BBT1O.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\SortDemo\is-46GKS.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\SortDemo\is-UBSDR.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\SortDemo\is-E9G8S.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\SortDemo\is-QHO7C.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\SortDemo\is-MUVK1.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\SortDemo\is-OHAOH.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\SpreadSheetJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\SpreadSheet\is-1B99C.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\SpreadSheet\is-N6C0Q.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\SpreadSheet\is-MNK6A.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\SpreadSheet\is-UN9IU.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\SpreadSheet\is-BTR8C.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\SpreadSheet\is-95T2R.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\SpreadSheet\is-G9TJF.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\SpreadSheet\is-3ST3P.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\WireFrameJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\WireFrame\is-3RJ7L.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\WireFrame\is-8E4M7.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\WireFrame\is-9BI79.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\WireFrame\is-2ID5R.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\WireFrame\is-S8GCU.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\WireFrame\is-LGMNL.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\WireFrame\is-19DHG.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\WireFrame\is-UVR7S.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jfcJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jfc\CodePointIMJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jfc\CodePointIM\is-6JI20.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jfc\CodePointIM\is-CQ7NU.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jfc\CodePointIM\is-NBE5Q.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jfc\CodePointIM\is-3OOCI.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jfc\CodePointIM\is-NP5KI.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jfc\FileChooserDemoJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jfc\FileChooserDemo\is-DUIRP.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jfc\FileChooserDemo\is-LHJS2.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jfc\FileChooserDemo\is-MCRAO.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jfc\Font2DTestJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jfc\Font2DTest\is-4MKMD.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jfc\Font2DTest\is-OPVRU.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jfc\Font2DTest\is-7PTFU.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jfc\Font2DTest\is-95MD4.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jfc\MetalworksJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jfc\Metalworks\is-HUIT8.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jfc\Metalworks\is-9N956.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jfc\Metalworks\is-EV716.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jfc\NotepadJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jfc\Notepad\is-O1DIE.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jfc\Notepad\is-PUC2S.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jfc\Notepad\is-6B1O9.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jfc\SampleTreeJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jfc\SampleTree\is-717JJ.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jfc\SampleTree\is-5QCDF.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jfc\SampleTree\is-L4I50.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jfc\SwingAppletJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jfc\SwingApplet\is-KJR9U.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jfc\SwingApplet\is-05FET.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jfc\SwingApplet\is-NBS4U.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jfc\SwingApplet\is-NOB5D.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jfc\TableExampleJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jfc\TableExample\is-TFC2U.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jfc\TableExample\is-I15UR.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jfc\TableExample\is-I3PJK.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jfc\TransparentRulerJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jfc\TransparentRuler\is-0HV9Q.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jfc\TransparentRuler\is-4KL00.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jfc\TransparentRuler\is-OS7J5.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jpdaJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jpda\is-BHB88.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jpda\is-S46S0.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jpda\comJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jpda\com\sunJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jpda\com\sun\toolsJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jpda\com\sun\tools\exampleJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jpda\com\sun\tools\example\is-737HS.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmtiJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\is-JT3VK.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\compiledMethodLoadJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\compiledMethodLoad\is-V0N5J.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\compiledMethodLoad\is-86O9M.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\compiledMethodLoad\libJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\compiledMethodLoad\lib\is-PNBTC.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\compiledMethodLoad\lib\is-4DRS0.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\compiledMethodLoad\lib\is-7JP2D.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\compiledMethodLoad\lib\is-AHM4L.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\gctestJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\gctest\is-9J6R5.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\gctest\is-L9V40.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\gctest\libJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\gctest\lib\is-37O9C.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\gctest\lib\is-MPT2K.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\gctest\lib\is-7CVO1.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\gctest\lib\is-Q5ANC.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\heapTrackerJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\heapTracker\is-CNTPB.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\heapTracker\is-6UHTC.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\heapTracker\is-FI6KO.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\heapTracker\libJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\heapTracker\lib\is-TS6PT.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\heapTracker\lib\is-2DA50.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\heapTracker\lib\is-HNFIK.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\heapTracker\lib\is-8FQ61.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\heapViewerJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\heapViewer\is-VS4JB.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\heapViewer\is-MBBJ3.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\heapViewer\libJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\heapViewer\lib\is-IKL45.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\heapViewer\lib\is-OFDKL.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\heapViewer\lib\is-7LSFD.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\heapViewer\lib\is-E9JUD.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\hprofJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\hprof\is-UUJNM.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\hprof\is-SPETB.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\hprof\libJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\hprof\lib\is-U8BTR.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\hprof\lib\is-0AELL.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\hprof\lib\is-B7SMV.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\hprof\lib\is-JCCGR.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\minstJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\minst\is-4KJIE.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\minst\is-1UMRK.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\minst\is-CVFFQ.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\minst\libJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\minst\lib\is-GORJU.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\minst\lib\is-7AL4T.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\minst\lib\is-76D71.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\minst\lib\is-BK7JS.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\mtraceJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\mtrace\is-3ITVC.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\mtrace\is-LVHH1.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\mtrace\is-MUE2L.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\mtrace\libJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\mtrace\lib\is-SPAP0.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\mtrace\lib\is-F87VS.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\mtrace\lib\is-ES6MI.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\mtrace\lib\is-2B7D7.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\versionCheckJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\versionCheck\is-ERMOR.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\versionCheck\is-FB6M7.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\versionCheck\libJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\versionCheck\lib\is-LLDP7.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\versionCheck\lib\is-KGEPG.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\versionCheck\lib\is-DOFH8.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\versionCheck\lib\is-T35N4.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\waitersJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\waiters\is-KSP0O.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\waiters\is-O5NE8.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\waiters\libJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\waiters\lib\is-L4D3S.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\waiters\lib\is-OHLBB.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\waiters\lib\is-HQHOU.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\waiters\lib\is-OO865.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\managementJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\management\is-BK9MH.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\management\FullThreadDumpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\management\FullThreadDump\is-USGFL.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\management\FullThreadDump\is-20MHH.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\management\FullThreadDump\is-C9HG2.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\management\JTopJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\management\JTop\is-AMFIV.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\management\JTop\is-VD2KQ.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\management\JTop\is-Q6OU8.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\management\MemoryMonitorJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\management\MemoryMonitor\is-RR3EL.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\management\MemoryMonitor\is-UD76T.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\management\MemoryMonitor\is-8KDVH.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\management\VerboseGCJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\management\VerboseGC\is-LURMR.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\management\VerboseGC\is-7N3OM.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\management\VerboseGC\is-GQ544.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbprojectJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\is-F4H8J.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\is-VJGN3.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\jfcJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\jfc\FileChooserDemoJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\jfc\FileChooserDemo\is-D63OU.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\jfc\FileChooserDemo\is-SAO0B.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\jfc\FileChooserDemo\nbprojectJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\jfc\FileChooserDemo\nbproject\is-NEDSN.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\jfc\FileChooserDemo\nbproject\is-7UMUO.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\jfc\FileChooserDemo\nbproject\is-R1ME4.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\jfc\FileChooserDemo\nbproject\is-8LMLB.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\jfc\Font2DTestJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\jfc\Font2DTest\is-KLDSL.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\jfc\Font2DTest\is-59OHH.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\jfc\Font2DTest\nbprojectJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\jfc\Font2DTest\nbproject\is-AK6B1.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\jfc\Font2DTest\nbproject\is-TPE0R.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\jfc\Font2DTest\nbproject\is-L79T6.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\jfc\Font2DTest\nbproject\is-P68N6.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\jfc\MetalworksJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\jfc\Metalworks\is-QLBMC.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\jfc\Metalworks\is-0BF4K.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\jfc\Metalworks\nbprojectJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\jfc\Metalworks\nbproject\is-V9F72.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\jfc\Metalworks\nbproject\is-4G1RG.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\jfc\Metalworks\nbproject\is-HK2AU.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\jfc\Metalworks\nbproject\is-J8T6D.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\jfc\NotepadJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\jfc\Notepad\is-6B5N0.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\jfc\Notepad\is-P83E7.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\jfc\Notepad\nbprojectJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\jfc\Notepad\nbproject\is-KSVNF.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\jfc\Notepad\nbproject\is-1NRFV.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\jfc\Notepad\nbproject\is-BCLTP.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\jfc\Notepad\nbproject\is-1OG31.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\jfc\SampleTreeJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\jfc\SampleTree\is-AE8UL.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\jfc\SampleTree\is-T9RF1.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\jfc\SampleTree\nbprojectJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\jfc\SampleTree\nbproject\is-1BF04.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\jfc\SampleTree\nbproject\is-SHBHP.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\jfc\SampleTree\nbproject\is-288NB.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\jfc\SampleTree\nbproject\is-3FALC.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\jfc\SwingAppletJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\jfc\SwingApplet\is-N3CMP.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\jfc\SwingApplet\is-KEOM5.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\jfc\SwingApplet\nbprojectJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\jfc\SwingApplet\nbproject\is-DB5C7.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\jfc\SwingApplet\nbproject\is-6C0ON.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\jfc\SwingApplet\nbproject\is-GKTEH.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\jfc\SwingApplet\nbproject\is-4NNFT.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\jfc\TableExampleJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\jfc\TableExample\is-FHMS1.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\jfc\TableExample\is-RSDIR.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\jfc\TableExample\nbprojectJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\jfc\TableExample\nbproject\is-10884.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\jfc\TableExample\nbproject\is-0632Q.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\jfc\TableExample\nbproject\is-1OSPI.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\jfc\TableExample\nbproject\is-US71F.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\jfc\TransparentRulerJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\jfc\TransparentRuler\is-U5IO9.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\jfc\TransparentRuler\is-R7FMK.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\jfc\TransparentRuler\nbprojectJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\jfc\TransparentRuler\nbproject\is-24KBH.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\jfc\TransparentRuler\nbproject\is-LTN6C.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\jfc\TransparentRuler\nbproject\is-GQ77P.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\jfc\TransparentRuler\nbproject\is-078N2.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\managementJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\management\FullThreadDumpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\management\FullThreadDump\is-NHECN.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\management\FullThreadDump\is-R2A79.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\management\FullThreadDump\nbprojectJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\management\FullThreadDump\nbproject\is-92QJB.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\management\FullThreadDump\nbproject\is-THEJS.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\management\FullThreadDump\nbproject\is-M35BR.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\management\FullThreadDump\nbproject\is-83SDV.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\management\JTopJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\management\JTop\is-A2IBN.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\management\JTop\is-4UL0R.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\management\JTop\nbprojectJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\management\JTop\nbproject\is-Q0JBM.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\management\JTop\nbproject\is-IV885.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\management\JTop\nbproject\is-5FALN.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\management\JTop\nbproject\is-RP0LN.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\management\MemoryMonitorJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\management\MemoryMonitor\is-MC830.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\management\MemoryMonitor\is-DFK7K.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\management\MemoryMonitor\nbprojectJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\management\MemoryMonitor\nbproject\is-8QSA0.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\management\MemoryMonitor\nbproject\is-3A5E7.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\management\MemoryMonitor\nbproject\is-T9USF.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\management\MemoryMonitor\nbproject\is-4B123.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\management\VerboseGCJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\management\VerboseGC\is-612LC.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\management\VerboseGC\is-924A3.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\management\VerboseGC\nbprojectJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\management\VerboseGC\nbproject\is-F1KMU.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\management\VerboseGC\nbproject\is-0FNHB.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\management\VerboseGC\nbproject\is-8B1OJ.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\management\VerboseGC\nbproject\is-M79D4.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\scriptingJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\scripting\jconsole-pluginJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\scripting\jconsole-plugin\is-5EU53.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\scripting\jconsole-plugin\is-MIMJ3.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\scripting\jconsole-plugin\nbprojectJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\scripting\jconsole-plugin\nbproject\is-FNC8C.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\scripting\jconsole-plugin\nbproject\is-TV9V2.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\scripting\jconsole-plugin\nbproject\is-PDTDM.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\scripting\jconsole-plugin\nbproject\is-NV194.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nioJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nio\zipfsJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nio\zipfs\is-JN9DG.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nio\zipfs\is-I12BK.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nio\zipfs\is-7KOBG.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nio\zipfs\is-0MCP5.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\scriptingJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\scripting\jconsole-pluginJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\scripting\jconsole-plugin\is-NGR4M.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\scripting\jconsole-plugin\is-CVK2I.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\scripting\jconsole-plugin\is-2AED8.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\scripting\jconsole-plugin\is-62ECU.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\includeJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\include\is-0M3UM.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\include\is-9U3NL.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\include\is-5AELN.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\include\is-H79I9.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\include\is-A1D09.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\include\is-8SN2K.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\include\win32Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\include\win32\is-A5DRK.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\include\win32\is-P6TQR.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\include\win32\bridgeJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\include\win32\bridge\is-K6C27.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\include\win32\bridge\is-7EIV8.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\include\win32\bridge\is-1ES9O.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\include\win32\bridge\is-O5KSF.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\jreJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\jre\is-T89H7.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\jre\is-T8PD9.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\jre\is-V7RUQ.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\jre\binJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\jre\bin\is-UVGGQ.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\jre\bin\is-H56E2.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\jre\bin\is-JQ7GE.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\jre\bin\is-FMMDJ.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\jre\bin\is-IUOLN.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\jre\bin\is-C62DF.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\jre\bin\is-OSJGF.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\jre\bin\is-HRISR.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\jre\bin\is-939CR.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpRegistry value created: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\HOBOware_3.7.28_is1Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\Users\user\AppData\Local\Temp\Setup Log 2024-06-18 #001.txtJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEFile created: C:\Program Files\Onset Computer Corporation\HOBOware\~$README.rtfJump to behavior
Source: Binary string: Z{app}\jre2\demo\jvmti\waiters\lib\waiters.pdb$Is64BitInstallMode source: HOBOware_Free_Setup.tmp, 0000000A.00000003.3873258864.0000000003380000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\minst\lib\minst.pdb source: HOBOware_Free_Setup.tmp, 0000000A.00000003.4865591021.0000000002334000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: c:\jenkins\worksp~1\j171-w~1\coinst\ftcserco\objfre_wnet_amd64\amd64\ftcserco.pdb source: HOBOware_Free_Setup.tmp, 0000000A.00000003.4848425848.0000000006830000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: T{app}\jre\demo\jvmti\gctest\lib\gctest.pdb$Is64BitInstallMode source: HOBOware_Free_Setup.tmp, 0000000A.00000003.3873258864.00000000031F0000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: C:\Users\IoT\Desktop\CDMDriverVS2015\x64\Release\FTDIBUS.pdb source: HOBOware_Free_Setup.tmp, 0000000A.00000003.4848425848.0000000006830000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: f:\binaries\Intermediate\vctools\crt_bld\SELF_64_amd64\crt\prebuild\build\amd64\dll_obj\eh\nativecpp\.compile.pdb source: is-8FQ61.tmp.10.dr
Source: Binary string: *{app}\jre\demo\jvmti\mtrace\lib\mtrace.pdb source: HOBOware_Free_Setup.tmp, 0000000A.00000003.4865591021.0000000002443000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: 3{app}\jre2\demo\jvmti\heapViewer\lib\heapViewer.pdb source: HOBOware_Free_Setup.tmp, 0000000A.00000003.4865591021.0000000002334000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: ){app}\jre2\demo\jvmti\minst\lib\minst.pdb source: HOBOware_Free_Setup.tmp, 0000000A.00000003.4865591021.0000000002443000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: l{app}\jre\demo\jvmti\versionCheck\lib\versionCheck.pdb$Is64BitInstallMode source: HOBOware_Free_Setup.tmp, 0000000A.00000003.3873258864.00000000031F0000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\heapViewer\lib\heapViewer.pdb source: HOBOware_Free_Setup.tmp, 0000000A.00000003.4865591021.00000000023CB000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: C:\Users\IoT\Desktop\CDMDriverVS2015\x64\Release\FTSER2K.pdb source: HOBOware_Free_Setup.tmp, 0000000A.00000003.4848425848.0000000006830000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: c:\jenkins\worksp~1\j171-w~1\pp\ftserui2\objfre_wnet_amd64\amd64\ftserui2.pdb source: HOBOware_Free_Setup.tmp, 0000000A.00000003.4848425848.0000000006830000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: 6{app}\jre\demo\jvmti\versionCheck\lib\versionCheck.pdb source: HOBOware_Free_Setup.tmp, 0000000A.00000003.4865591021.0000000002334000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: C:\Jenkins\workspace\J171-Windows-D2XX-VCP-VS2013\FTLang\Release\FTLang.pdb source: HOBOware_Free_Setup.tmp, 0000000A.00000003.4848425848.0000000006830000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: c:\jenkins\worksp~1\j171-w~1\pp\ftserui2\objfre_wnet_x86\i386\ftserui2.pdb source: HOBOware_Free_Setup.tmp, 0000000A.00000003.4848425848.0000000006830000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: c:\jenkins\workspace\j171-windows-d2xx-vcp-vs2013\d2xxlib\x64\release\vc120.pdbH source: HOBOware_Free_Setup.tmp, 0000000A.00000003.4848425848.0000000006830000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: R{app}\jre2\demo\jvmti\hprof\lib\hprof.pdb$Is64BitInstallMode source: HOBOware_Free_Setup.tmp, 0000000A.00000003.3873258864.0000000003380000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: XC:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\hprof\lib\hprof.pdbmp source: HOBOware_Free_Setup.tmp, 0000000A.00000003.4863238436.0000000003808000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: C:\Jenkins\workspace\J171-Windows-D2XX-VCP-VS2013\FTBUSUI\x64\Release\FTBUSUI.pdb~~ source: HOBOware_Free_Setup.tmp, 0000000A.00000003.4848425848.0000000006830000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: -{app}\jre2\demo\jvmti\waiters\lib\waiters.pdbAw> source: HOBOware_Free_Setup.tmp, 0000000A.00000003.4865591021.00000000023E5000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\gctest\lib\gctest.pdb source: HOBOware_Free_Setup.tmp, 0000000A.00000003.4865591021.0000000002334000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: P{app}\jre\demo\jvmti\minst\lib\minst.pdb$Is64BitInstallMode source: HOBOware_Free_Setup.tmp, 0000000A.00000003.3873258864.00000000031F0000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: ZC:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\gctest\lib\gctest.pdbpSQM; source: HOBOware_Free_Setup.tmp, 0000000A.00000003.4865591021.000000000237D000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\hprof\lib\hprof.pdb source: HOBOware_Free_Setup.tmp, 0000000A.00000003.4865591021.0000000002334000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: cwdC:\wsjdk\Corretto8Src\installers\windows\zip\corretto-build\buildRoot\jdk\makeexec:\progra~2\micros~3.0\vc\bin\amd64\link.exepdbc:\wsjdk\Corretto8Src\installers\windows\zip\corretto-build\buildRoot\build\windows-x86_64-normal-server-release\jdk\demo\jvmti\heapTracker\lib\heapTracker.pdb source: is-8FQ61.tmp.10.dr
Source: Binary string: C:\Program Files\Onset Computer Corporation\HOBOware\jre\demo\jvmti\waiters\lib\waiters.pdb source: HOBOware_Free_Setup.tmp, 0000000A.00000003.4863238436.00000000037A3000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: c:\wsjdk\Corretto8Src\installers\windows\zip\corretto-build\buildRoot\build\windows-x86_64-normal-server-release\jdk\demoobjs\jvmti\heapTracker\agent_util.pdb source: is-8FQ61.tmp.10.dr
Source: Binary string: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\compiledMethodLoad\lib\compiledMethodLoad.pdb source: HOBOware_Free_Setup.tmp, 0000000A.00000003.4864325209.0000000003453000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: c:\jenkins\worksp~1\j171-w~1\pp\ftserui2\objfre_wnet_amd64\amd64\ftserui2.pdbH source: HOBOware_Free_Setup.tmp, 0000000A.00000003.4848425848.0000000006830000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: f:\binaries\Intermediate\vctools\crt_bld\SELF_64_amd64\crt\prebuild\build\amd64\dll_obj\rtc\nativecpp\.compile.pdb source: is-8FQ61.tmp.10.dr
Source: Binary string: C:\Program Files\Onset Computer Corporation\HOBOware\jre\demo\jvmti\versionCheck\lib\versionCheck.pdb source: HOBOware_Free_Setup.tmp, 0000000A.00000003.4863238436.00000000037A3000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: 2{app}\jre\demo\jvmti\heapViewer\lib\heapViewer.pdbq source: HOBOware_Free_Setup.tmp, 0000000A.00000003.4865591021.0000000002334000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: dC:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\heapTracker\lib\heapTracker.pdbp source: HOBOware_Free_Setup.tmp, 0000000A.00000003.4865591021.0000000002334000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\waiters\lib\waiters.pdb source: HOBOware_Free_Setup.tmp, 0000000A.00000003.4865591021.0000000002334000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: C:\Jenkins\workspace\J171-Windows-D2XX-VCP-VS2013\FTLang\x64\Release\FTLang.pdb source: HOBOware_Free_Setup.tmp, 0000000A.00000003.4848425848.0000000006830000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: c:\jenkins\workspace\j171-windows-d2xx-vcp-vs2013\d2xxlib\x64\release\vc120.pdb@SH source: HOBOware_Free_Setup.tmp, 0000000A.00000003.4848425848.0000000006830000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: c:\jenkins\workspace\j171-windows-d2xx-vcp-vs2013\d2xxlib\x64\release\vc120.pdb" source: HOBOware_Free_Setup.tmp, 0000000A.00000003.4848425848.0000000006830000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: C:\Program Files\Onset Computer Corporation\HOBOware\jre\demo\jvmti\heapViewer\lib\heapViewer.pdb source: HOBOware_Free_Setup.tmp, 0000000A.00000003.4863238436.00000000037A3000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: C:\Jenkins\workspace\J171-Windows-D2XX-VCP-VS2013\FTBUSUI\Release\FTBUSUI.pdb source: HOBOware_Free_Setup.tmp, 0000000A.00000003.4848425848.0000000006830000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: n{app}\jre2\demo\jvmti\versionCheck\lib\versionCheck.pdb$Is64BitInstallMode source: HOBOware_Free_Setup.tmp, 0000000A.00000003.3873258864.0000000003380000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: d{app}\jre\demo\jvmti\heapViewer\lib\heapViewer.pdb$Is64BitInstallMode source: HOBOware_Free_Setup.tmp, 0000000A.00000003.3873258864.00000000031F0000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: c:\jenkins\workspace\j171-windows-d2xx-vcp-vs2013\d2xxlib\x64\release\vc120.pdb source: HOBOware_Free_Setup.tmp, 0000000A.00000003.4848425848.0000000006830000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: C:\Program Files\Onset Computer Corporation\HOBOware\jre\demo\jvmti\mtrace\lib\mtrace.pdb source: HOBOware_Free_Setup.tmp, 0000000A.00000003.4863238436.00000000037A3000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: X{app}\jre\demo\jvmti\waiters\lib\waiters.pdb$Is64BitInstallMode source: HOBOware_Free_Setup.tmp, 0000000A.00000003.3873258864.00000000031F0000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: fC:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\versionCheck\lib\versionCheck.pdb source: HOBOware_Free_Setup.tmp, 0000000A.00000003.4863238436.0000000003808000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: C:\Users\IoT\Desktop\CDMDriverVS2015\Release\FTSER2K.pdb source: HOBOware_Free_Setup.tmp, 0000000A.00000003.4848425848.0000000006830000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: f:\dd\vctools\crt\crtw32\misc\amd64\amdsecgs.asmf:\dd\vctools\crt\crtw32\startup\amd64\chkstk.asmc:\wsjdk\Corretto8Src\installers\windows\zip\corretto-build\buildRoot\build\windows-x86_64-normal-server-release\jdk\demo\jvmti\heapTracker\lib\heapTracker.pdb source: is-8FQ61.tmp.10.dr
Source: Binary string: P{app}\jre\demo\jvmti\hprof\lib\hprof.pdb$Is64BitInstallMode source: HOBOware_Free_Setup.tmp, 0000000A.00000003.3873258864.00000000031F0000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\mtrace\lib\mtrace.pdb source: HOBOware_Free_Setup.tmp, 0000000A.00000003.4865591021.0000000002334000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: c:\jenkins\workspace\j171-windows-d2xx-vcp-vs2013\d2xxlib\x64\release\vc120.pdb@comp.id source: HOBOware_Free_Setup.tmp, 0000000A.00000003.4848425848.0000000006830000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\versionCheck\lib\versionCheck.pdb source: HOBOware_Free_Setup.tmp, 0000000A.00000003.4865591021.00000000023CB000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: f:\binaries\Intermediate\vctools\crt_bld\SELF_64_amd64\crt\prebuild\build\amd64\dll_obj\nativec\.compile.pdb source: is-8FQ61.tmp.10.dr
Source: Binary string: XC:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\minst\lib\minst.pdbmp source: HOBOware_Free_Setup.tmp, 0000000A.00000003.4863238436.0000000003808000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: f:\binaries\Intermediate\vctools\crt_bld\SELF_64_amd64\crt\prebuild\build\amd64\dll_obj\others\nativec\.compile.pdb source: is-8FQ61.tmp.10.dr
Source: Binary string: C:\Program Files\Onset Computer Corporation\HOBOware\jre\demo\jvmti\heapTracker\lib\heapTracker.pdb source: HOBOware_Free_Setup.tmp, 0000000A.00000003.4863238436.00000000037A3000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: f{app}\jre2\demo\jvmti\heapViewer\lib\heapViewer.pdb$Is64BitInstallMode source: HOBOware_Free_Setup.tmp, 0000000A.00000003.3873258864.0000000003380000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: c:\jenkins\worksp~1\j171-w~1\coinst\ftcserco\objfre_wnet_x86\i386\ftcserco.pdb source: HOBOware_Free_Setup.tmp, 0000000A.00000003.4848425848.0000000006830000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: ({app}\jre\demo\jvmti\minst\lib\minst.pdbY source: HOBOware_Free_Setup.tmp, 0000000A.00000003.4865591021.0000000002443000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: rC:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\compiledMethodLoad\lib\compiledMethodLoad.pdbb source: HOBOware_Free_Setup.tmp, 0000000A.00000003.4865591021.00000000023CB000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: bC:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\heapViewer\lib\heapViewer.pdbb source: HOBOware_Free_Setup.tmp, 0000000A.00000003.4865591021.0000000002334000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: V{app}\jre2\demo\jvmti\mtrace\lib\mtrace.pdb$Is64BitInstallMode source: HOBOware_Free_Setup.tmp, 0000000A.00000003.3873258864.0000000003380000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: C:\Program Files\Onset Computer Corporation\HOBOware\jre\demo\jvmti\minst\lib\minst.pdb source: HOBOware_Free_Setup.tmp, 0000000A.00000003.4863238436.00000000037A3000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: h{app}\jre\demo\jvmti\heapTracker\lib\heapTracker.pdb$Is64BitInstallMode source: HOBOware_Free_Setup.tmp, 0000000A.00000003.3873258864.00000000031F0000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: ,{app}\jre\demo\jvmti\waiters\lib\waiters.pdb source: HOBOware_Free_Setup.tmp, 0000000A.00000003.4865591021.00000000023E5000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: C:\Jenkins\workspace\J171-Windows-D2XX-VCP-VS2013\d2xxdll\Release\FTD2XX.pdb source: HOBOware_Free_Setup.tmp, 0000000A.00000003.4848425848.0000000006830000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: *{app}\jre\demo\jvmti\gctest\lib\gctest.pdb source: HOBOware_Free_Setup.tmp, 0000000A.00000003.4865591021.0000000002443000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: C:\Program Files\Onset Computer Corporation\HOBOware\jre\demo\jvmti\hprof\lib\hprof.pdb source: HOBOware_Free_Setup.tmp, 0000000A.00000003.4863238436.00000000037A3000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: j{app}\jre2\demo\jvmti\heapTracker\lib\heapTracker.pdb$Is64BitInstallMode source: HOBOware_Free_Setup.tmp, 0000000A.00000003.3873258864.0000000003380000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: C:\Jenkins\workspace\J171-Windows-D2XX-VCP-VS2013\d2xxdll\x64\Release\FTD2XX64.pdb source: HOBOware_Free_Setup.tmp, 0000000A.00000003.4848425848.0000000006830000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: T{app}\jre\demo\jvmti\mtrace\lib\mtrace.pdb$Is64BitInstallMode source: HOBOware_Free_Setup.tmp, 0000000A.00000003.3873258864.00000000031F0000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: +{app}\jre2\demo\jvmti\gctest\lib\gctest.pdbI source: HOBOware_Free_Setup.tmp, 0000000A.00000003.4865591021.0000000002443000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: {app}\jre\demo\jvmti\compiledMethodLoad\lib\compiledMethodLoad.pdb$Is64BitInstallMode source: HOBOware_Free_Setup.tmp, 0000000A.00000003.3873258864.00000000031F0000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: R{app}\jre2\demo\jvmti\minst\lib\minst.pdb$Is64BitInstallMode source: HOBOware_Free_Setup.tmp, 0000000A.00000003.3873258864.0000000003380000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: C:\Jenkins\workspace\J171-Windows-D2XX-VCP-VS2013\FTBUSUI\x64\Release\FTBUSUI.pdb source: HOBOware_Free_Setup.tmp, 0000000A.00000003.4848425848.0000000006830000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: ){app}\jre2\demo\jvmti\hprof\lib\hprof.pdb! source: HOBOware_Free_Setup.tmp, 0000000A.00000003.4865591021.0000000002443000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: \C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\waiters\lib\waiters.pdbaB source: HOBOware_Free_Setup.tmp, 0000000A.00000003.4863238436.0000000003808000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: C:\Program Files\Onset Computer Corporation\HOBOware\jre\demo\jvmti\compiledMethodLoad\lib\compiledMethodLoad.pdb source: HOBOware_Free_Setup.tmp, 0000000A.00000003.4863238436.0000000003808000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: 4{app}\jre\demo\jvmti\heapTracker\lib\heapTracker.pdb source: HOBOware_Free_Setup.tmp, 0000000A.00000003.4865591021.0000000002334000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: c:\wsjdk\Corretto8Src\installers\windows\zip\corretto-build\buildRoot\build\windows-x86_64-normal-server-release\jdk\demoobjs\jvmti\heapTracker\heapTracker.pdb source: is-8FQ61.tmp.10.dr
Source: Binary string: C:\Users\IoT\Desktop\CDMDriverVS2015\Release\FTDIBUS.pdb source: HOBOware_Free_Setup.tmp, 0000000A.00000003.4848425848.0000000006830000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\heapTracker\lib\heapTracker.pdb source: HOBOware_Free_Setup.tmp, 0000000A.00000003.4865591021.00000000023CB000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: C{app}\jre2\demo\jvmti\compiledMethodLoad\lib\compiledMethodLoad.pdb source: HOBOware_Free_Setup.tmp, 0000000A.00000003.4865591021.0000000002334000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: ZC:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\mtrace\lib\mtrace.pdbp source: HOBOware_Free_Setup.tmp, 0000000A.00000003.4863238436.0000000003808000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: c:\jenkins\worksp~1\j171-w~1\coinst\ftcserco\objfre_wnet_amd64\amd64\ftcserco.pdbH source: HOBOware_Free_Setup.tmp, 0000000A.00000003.4848425848.0000000006830000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: +{app}\jre2\demo\jvmti\mtrace\lib\mtrace.pdba source: HOBOware_Free_Setup.tmp, 0000000A.00000003.4865591021.0000000002443000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: V{app}\jre2\demo\jvmti\gctest\lib\gctest.pdb$Is64BitInstallMode source: HOBOware_Free_Setup.tmp, 0000000A.00000003.3873258864.0000000003380000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: c:\wsjdk\Corretto8Src\installers\windows\zip\corretto-build\buildRoot\build\windows-x86_64-normal-server-release\jdk\demo\jvmti\heapTracker\lib\heapTracker.pdb source: is-8FQ61.tmp.10.dr
Source: Binary string: {app}\jre2\demo\jvmti\compiledMethodLoad\lib\compiledMethodLoad.pdb$Is64BitInstallMode source: HOBOware_Free_Setup.tmp, 0000000A.00000003.3873258864.0000000003380000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: B{app}\jre\demo\jvmti\compiledMethodLoad\lib\compiledMethodLoad.pdbqH4 source: HOBOware_Free_Setup.tmp, 0000000A.00000003.4865591021.0000000002334000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: c:\wsjdk\Corretto8Src\installers\windows\zip\corretto-build\buildRoot\build\windows-x86_64-normal-server-release\jdk\demoobjs\jvmti\heapTracker\java_crw_demo.pdb source: is-8FQ61.tmp.10.dr
Source: Binary string: c:\wsjdk\Corretto8Src\installers\windows\zip\corretto-build\buildRoot\build\windows-x86_64-normal-server-release\jdk\demo\jvmti\gctest\lib\gctest.pdb source: is-37O9C.tmp.10.dr
Source: Binary string: ({app}\jre\demo\jvmti\hprof\lib\hprof.pdb source: HOBOware_Free_Setup.tmp, 0000000A.00000003.4865591021.0000000002443000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: 5{app}\jre2\demo\jvmti\heapTracker\lib\heapTracker.pdb source: HOBOware_Free_Setup.tmp, 0000000A.00000003.4865591021.0000000002334000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: C:\Program Files\Onset Computer Corporation\HOBOware\jre\demo\jvmti\gctest\lib\gctest.pdb source: HOBOware_Free_Setup.tmp, 0000000A.00000003.4863238436.00000000037A3000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: 7{app}\jre2\demo\jvmti\versionCheck\lib\versionCheck.pdb source: HOBOware_Free_Setup.tmp, 0000000A.00000003.4865591021.0000000002334000.00000004.00001000.00020000.00000000.sdmp
Source: winword.exeMemory has grown: Private usage: 0MB later: 86MB
Source: is-37O9C.tmp.10.drString found in binary or memory: http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0E
Source: is-37O9C.tmp.10.drString found in binary or memory: http://cacerts.digicert.com/DigiCertHighAssuranceEVRootCA.crt0K
Source: is-37O9C.tmp.10.drString found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crt0
Source: is-37O9C.tmp.10.drString found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crt0
Source: is-37O9C.tmp.10.drString found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedRootG4.crt0C
Source: is-82F14.tmp.10.drString found in binary or memory: http://cps.chambersign.org/cps/chambersignroot.html0
Source: is-82F14.tmp.10.drString found in binary or memory: http://cps.chambersign.org/cps/chambersroot.html0
Source: is-82F14.tmp.10.drString found in binary or memory: http://crl.chambersign.org/chambersignroot.crl0
Source: is-82F14.tmp.10.drString found in binary or memory: http://crl.chambersign.org/chambersroot.crl0
Source: is-82F14.tmp.10.drString found in binary or memory: http://crl.comodoca.com/AAACertificateServices.crl06
Source: is-82F14.tmp.10.drString found in binary or memory: http://crl.comodoca.com/SecureCertificateServices.crl09
Source: is-82F14.tmp.10.drString found in binary or memory: http://crl.comodoca.com/TrustedCertificateServices.crl0:
Source: is-82F14.tmp.10.drString found in binary or memory: http://crl.netsolssl.com/NetworkSolutions_CA.crl07
Source: is-82F14.tmp.10.drString found in binary or memory: http://crl.oces.certifikat.dk/oces.crl0
Source: wget.exe, 00000002.00000003.3783604847.0000000001156000.00000004.00000020.00020000.00000000.sdmp, wget.exe, 00000002.00000003.3783604847.000000000115E000.00000004.00000020.00020000.00000000.sdmp, HOBOware_Free_Setup.exe, 00000009.00000003.3871173403.000000000263D000.00000004.00001000.00020000.00000000.sdmp, HOBOware_Free_Setup.exe, 00000009.00000003.3871359047.000000007F689000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://crl.sectigo.com/SectigoPublicCodeSigningCAR36.crl0y
Source: wget.exe, 00000002.00000003.3783604847.0000000001156000.00000004.00000020.00020000.00000000.sdmp, wget.exe, 00000002.00000003.3783604847.000000000115E000.00000004.00000020.00020000.00000000.sdmp, wget.exe, 00000002.00000003.3783604847.0000000001167000.00000004.00000020.00020000.00000000.sdmp, HOBOware_Free_Setup.exe, 00000009.00000003.3871173403.000000000263D000.00000004.00001000.00020000.00000000.sdmp, HOBOware_Free_Setup.exe, 00000009.00000003.3871359047.000000007F689000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://crl.sectigo.com/SectigoRSATimeStampingCA.crl0t
Source: wget.exe, 00000002.00000002.3834925180.0000000001167000.00000004.00000020.00020000.00000000.sdmp, wget.exe, 00000002.00000003.3834565014.0000000001167000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://crl.sectigo.com/n
Source: HOBOware_Free_Setup.tmp, 0000000A.00000003.4848425848.0000000006830000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://crl.thawte.com/ThawteTimestampingCA.crl0
Source: is-82F14.tmp.10.drString found in binary or memory: http://crl.xrampsecurity.com/XGCA.crl0
Source: is-82F14.tmp.10.drString found in binary or memory: http://crl2.netsolssl.com/NetworkSolutions_CA.crl0L
Source: is-37O9C.tmp.10.drString found in binary or memory: http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0
Source: is-37O9C.tmp.10.drString found in binary or memory: http://crl3.digicert.com/DigiCertHighAssuranceEVRootCA.crl0
Source: is-37O9C.tmp.10.drString found in binary or memory: http://crl3.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl0S
Source: is-37O9C.tmp.10.drString found in binary or memory: http://crl3.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crl0
Source: is-37O9C.tmp.10.drString found in binary or memory: http://crl3.digicert.com/DigiCertTrustedRootG4.crl0
Source: is-37O9C.tmp.10.drString found in binary or memory: http://crl4.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl0=
Source: wget.exe, 00000002.00000003.3783604847.0000000001156000.00000004.00000020.00020000.00000000.sdmp, wget.exe, 00000002.00000003.3783604847.000000000115E000.00000004.00000020.00020000.00000000.sdmp, HOBOware_Free_Setup.exe, 00000009.00000003.3871173403.000000000263D000.00000004.00001000.00020000.00000000.sdmp, HOBOware_Free_Setup.exe, 00000009.00000003.3871359047.000000007F689000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://crt.sectigo.com/SectigoPublicCodeSigningCAR36.crt0#
Source: wget.exe, 00000002.00000003.3783604847.0000000001156000.00000004.00000020.00020000.00000000.sdmp, wget.exe, 00000002.00000002.3834925180.0000000001167000.00000004.00000020.00020000.00000000.sdmp, wget.exe, 00000002.00000003.3834565014.0000000001167000.00000004.00000020.00020000.00000000.sdmp, wget.exe, 00000002.00000003.3783604847.000000000115E000.00000004.00000020.00020000.00000000.sdmp, wget.exe, 00000002.00000003.3783604847.0000000001167000.00000004.00000020.00020000.00000000.sdmp, HOBOware_Free_Setup.exe, 00000009.00000003.3871173403.000000000263D000.00000004.00001000.00020000.00000000.sdmp, HOBOware_Free_Setup.exe, 00000009.00000003.3871359047.000000007F689000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://crt.sectigo.com/SectigoRSATimeStampingCA.crt0#
Source: HOBOware_Free_Setup.tmp, 0000000A.00000003.4848425848.0000000006830000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://ftdichip.com/)
Source: is-37O9C.tmp.10.drString found in binary or memory: http://ocsp.digicert.com0
Source: is-37O9C.tmp.10.drString found in binary or memory: http://ocsp.digicert.com0A
Source: is-37O9C.tmp.10.drString found in binary or memory: http://ocsp.digicert.com0C
Source: is-37O9C.tmp.10.drString found in binary or memory: http://ocsp.digicert.com0I
Source: is-37O9C.tmp.10.drString found in binary or memory: http://ocsp.digicert.com0X
Source: is-82F14.tmp.10.drString found in binary or memory: http://ocsp.ips.es/0
Source: wget.exe, 00000002.00000003.3783604847.0000000001156000.00000004.00000020.00020000.00000000.sdmp, wget.exe, 00000002.00000002.3834925180.0000000001167000.00000004.00000020.00020000.00000000.sdmp, wget.exe, 00000002.00000003.3834565014.0000000001167000.00000004.00000020.00020000.00000000.sdmp, wget.exe, 00000002.00000003.3783604847.000000000115E000.00000004.00000020.00020000.00000000.sdmp, wget.exe, 00000002.00000003.3783604847.0000000001167000.00000004.00000020.00020000.00000000.sdmp, HOBOware_Free_Setup.exe, 00000009.00000003.3871173403.000000000263D000.00000004.00001000.00020000.00000000.sdmp, HOBOware_Free_Setup.exe, 00000009.00000003.3871359047.000000007F689000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://ocsp.sectigo.com0
Source: HOBOware_Free_Setup.tmp, 0000000A.00000003.4848425848.0000000006830000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://ocsp.thawte.com0
Source: is-82F14.tmp.10.drString found in binary or memory: http://repository.eid.belgium.be0
Source: HOBOware_Free_Setup.tmp, 0000000A.00000003.4848425848.0000000006830000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://s.symcb.com/pca3-g5.crl0
Source: HOBOware_Free_Setup.tmp, 0000000A.00000003.4848425848.0000000006830000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://s.symcd.com0_
Source: HOBOware_Free_Setup.tmp, 0000000A.00000003.4848425848.0000000006830000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://sw.symcb.com/sw.crl0f
Source: HOBOware_Free_Setup.tmp, 0000000A.00000003.4848425848.0000000006830000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://sw.symcd.com0
Source: HOBOware_Free_Setup.tmp, 0000000A.00000003.4848425848.0000000006830000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://sw1.symcb.com/sw.crt0
Source: HOBOware_Free_Setup.tmp, 0000000A.00000003.4848425848.0000000006830000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://ts-aia.ws.symantec.com/tss-ca-g2.cer0
Source: HOBOware_Free_Setup.tmp, 0000000A.00000003.4848425848.0000000006830000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://ts-crl.ws.symantec.com/tss-ca-g2.crl0(
Source: HOBOware_Free_Setup.tmp, 0000000A.00000003.4848425848.0000000006830000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://ts-ocsp.ws.symantec.com07
Source: is-82F14.tmp.10.drString found in binary or memory: http://www.a-cert.at/certificate-policy.html0
Source: is-82F14.tmp.10.drString found in binary or memory: http://www.a-cert.at/certificate-policy.html0;
Source: is-82F14.tmp.10.drString found in binary or memory: http://www.a-cert.at0E
Source: is-82F14.tmp.10.drString found in binary or memory: http://www.certifikat.dk/repository0
Source: is-82F14.tmp.10.drString found in binary or memory: http://www.chambersign.org1
Source: is-37O9C.tmp.10.drString found in binary or memory: http://www.digicert.com/CPS0
Source: is-82F14.tmp.10.drString found in binary or memory: http://www.entrust.net/CRL/Client1.crl0
Source: is-82F14.tmp.10.drString found in binary or memory: http://www.entrust.net/CRL/net1.crl0
Source: HOBOware_Free_Setup.tmp, 0000000A.00000003.4848425848.0000000006830000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://www.ftdichip.com/)
Source: HOBOware_Free_Setup.tmp, 0000000A.00000003.4848425848.0000000006830000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://www.ftdichip.com/Drivers/CDM/CDM%20v2.12.24%20WHQL%20Certified.zip
Source: HOBOware_Free_Setup.tmp, 0000000A.00000003.4848425848.0000000006830000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://www.ftdichip.com/FTDrivers.htm)
Source: HOBOware_Free_Setup.tmp, 0000000A.00000003.4848425848.0000000006830000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://www.ftdichip.com/FTProducts.htm)
Source: HOBOware_Free_Setup.tmp, 0000000A.00000003.4848425848.0000000006830000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://www.ftdichip.com/Support/Documents/AppNotes/AN_107_AdvancedDriverOptions_AN_000073.pdf)
Source: HOBOware_Free_Setup.tmp, 0000000A.00000003.4848425848.0000000006830000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://www.ftdichip.com/Support/Documents/AppNotes/AN_119_FTDI_Drivers_Installation_Guide_for_Window
Source: HOBOware_Free_Setup.tmp, 0000000A.00000003.4848425848.0000000006830000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://www.ftdichip.com/Support/Documents/AppNotes/AN_234_FTDI_Drivers_Installation_Guide_for_Window
Source: HOBOware_Free_Setup.tmp, 0000000A.00000003.4848425848.0000000006830000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://www.ftdichip.com/Support/Documents/InstallGuides/AN_396%20FTDI%20Drivers%20Installation%20Gui
Source: HOBOware_Free_Setup.tmp, 0000000A.00000003.4848425848.0000000006830000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://www.ftdichip.com/Support/Utilities.htm#CDMUninstaller)
Source: HOBOware_Free_Setup.tmp, 0000000A.00000003.4848425848.0000000006830000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://www.ftdichip.com/Support/Utilities.htm#Comport_Assignment)
Source: HOBOware_Free_Setup.tmp, 0000000A.00000003.4848425848.0000000006830000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://www.ftdichip.com/Support/Utilities.htm#MicrosoftUSBView)
Source: HOBOware_Free_Setup.tmp, 0000000A.00000003.4848425848.0000000006830000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://www.ftdichip.com/Support/Utilities.htm)
Source: HOBOware_Free_Setup.exe, 00000009.00000003.3871173403.0000000002520000.00000004.00001000.00020000.00000000.sdmp, HOBOware_Free_Setup.exe, 00000009.00000003.3871359047.000000007F570000.00000004.00001000.00020000.00000000.sdmp, HOBOware_Free_Setup.tmp, 0000000A.00000000.3871940847.0000000000401000.00000020.00000001.01000000.00000005.sdmpString found in binary or memory: http://www.innosetup.com/
Source: HOBOware_Free_Setup.exe, 00000009.00000000.3869477291.0000000000401000.00000020.00000001.01000000.00000004.sdmpString found in binary or memory: http://www.jrsoftware.org/ishelp/index.php?topic=setupcmdlineSetupU
Source: is-82F14.tmp.10.drString found in binary or memory: http://www.netsolssl.com/NetworkSolutions_CA.crt0
Source: is-82F14.tmp.10.drString found in binary or memory: http://www.networksolutions.com/legal/SSL-legal-repository-cps.jsp0z
Source: HOBOware_Free_Setup.exe, 00000009.00000003.4877042183.0000000002274000.00000004.00001000.00020000.00000000.sdmp, HOBOware_Free_Setup.tmp, 0000000A.00000003.4865591021.000000000242D000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://www.onsetcomp.com/hoboware
Source: HOBOware_Free_Setup.exe, 00000009.00000003.4877042183.0000000002274000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://www.onsetcomp.com/hobowareQN
Source: HOBOware_Free_Setup.tmp, 0000000A.00000003.4865591021.000000000242D000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://www.onsetcomp.com/hobowareQNC
Source: HOBOware_Free_Setup.tmp, 0000000A.00000003.4865591021.000000000242D000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://www.onsetcomp.com/hobowareYOC
Source: is-82F14.tmp.10.drString found in binary or memory: http://www.pkioverheid.nl/policies/root-policy0
Source: is-82F14.tmp.10.drString found in binary or memory: http://www.quovadis.bm0
Source: HOBOware_Free_Setup.exe, 00000009.00000003.3871173403.0000000002520000.00000004.00001000.00020000.00000000.sdmp, HOBOware_Free_Setup.exe, 00000009.00000003.3871359047.000000007F570000.00000004.00001000.00020000.00000000.sdmp, HOBOware_Free_Setup.tmp, 0000000A.00000000.3871940847.0000000000401000.00000020.00000001.01000000.00000005.sdmpString found in binary or memory: http://www.remobjects.com/ps
Source: is-82F14.tmp.10.drString found in binary or memory: http://www.rootca.or.kr/rca/cps.html0
Source: is-82F14.tmp.10.drString found in binary or memory: http://www.trustcenter.de/crl/v2/tc_class_2_ca_II.crl
Source: is-82F14.tmp.10.drString found in binary or memory: http://www.trustcenter.de/crl/v2/tc_class_3_ca_II.crl
Source: is-82F14.tmp.10.drString found in binary or memory: http://www.trustcenter.de/guidelines0
Source: is-82F14.tmp.10.drString found in binary or memory: http://www.valicert.com/1
Source: is-82F14.tmp.10.drString found in binary or memory: http://www.wellsfargo.com/certpolicy0
Source: HOBOware_Free_Setup.tmp, 0000000A.00000003.4848425848.0000000006830000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://d.symcb.com/cps0%
Source: HOBOware_Free_Setup.tmp, 0000000A.00000003.4848425848.0000000006830000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://d.symcb.com/rpa0
Source: HOBOware_Free_Setup.tmp, 0000000A.00000003.4848425848.0000000006830000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://d.symcb.com/rpa0)
Source: is-82F14.tmp.10.drString found in binary or memory: https://ocsp.quovadisoffshore.com0
Source: wget.exe, 00000002.00000002.3834816449.0000000000C28000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://onset2.onsetcomp.com/files/software/hoboware/3.7.28/HOBOware_Free_Setu
Source: wget.exe, 00000002.00000002.3834959667.00000000012A0000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://onset2.onsetcomp.com/files/software/hoboware/3.7.28/HOBOware_Free_Setup.exe
Source: wget.exe, 00000002.00000002.3834959667.00000000012A5000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://onset2.onsetcomp.com/files/software/hoboware/3.7.28/HOBOware_Free_Setup.exe(owqn
Source: wget.exe, 00000002.00000002.3834959667.00000000012A0000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://onset2.onsetcomp.com/files/software/hoboware/3.7.28/HOBOware_Free_Setup.exeData
Source: wget.exe, 00000002.00000002.3834959667.00000000012A0000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://onset2.onsetcomp.com/files/software/hoboware/3.7.28/HOBOware_Free_Setup.exeRO
Source: wget.exe, 00000002.00000003.3783604847.0000000001156000.00000004.00000020.00020000.00000000.sdmp, wget.exe, 00000002.00000002.3834925180.0000000001167000.00000004.00000020.00020000.00000000.sdmp, wget.exe, 00000002.00000003.3834565014.0000000001167000.00000004.00000020.00020000.00000000.sdmp, wget.exe, 00000002.00000003.3783604847.000000000115E000.00000004.00000020.00020000.00000000.sdmp, wget.exe, 00000002.00000003.3783604847.0000000001167000.00000004.00000020.00020000.00000000.sdmp, HOBOware_Free_Setup.exe, 00000009.00000003.3871173403.000000000263D000.00000004.00001000.00020000.00000000.sdmp, HOBOware_Free_Setup.exe, 00000009.00000003.3871359047.000000007F689000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://sectigo.com/CPS0
Source: is-82F14.tmp.10.drString found in binary or memory: https://secure.a-cert.at/cgi-bin/a-cert-advanced.cgi0
Source: is-82F14.tmp.10.drString found in binary or memory: https://www.apple.com/appleca/0
Source: is-82F14.tmp.10.drString found in binary or memory: https://www.apple.com/certificateauthority/casigners.html0
Source: is-82F14.tmp.10.drString found in binary or memory: https://www.apple.com/certificateauthority/root.crl0U
Source: is-82F14.tmp.10.drString found in binary or memory: https://www.apple.com/certificateauthority/terms.html0
Source: is-82F14.tmp.10.drString found in binary or memory: https://www.beTRUSTed.com/vault/terms01
Source: is-82F14.tmp.10.drString found in binary or memory: https://www.beTRUSTed.com/vault/terms04
Source: is-82F14.tmp.10.drString found in binary or memory: https://www.ips.es/0
Source: is-82F14.tmp.10.drString found in binary or memory: https://www.ips.es/ips2002/0
Source: is-82F14.tmp.10.drString found in binary or memory: https://www.ips.es/ips2002/08
Source: is-82F14.tmp.10.drString found in binary or memory: https://www.ips.es/ips2002/0;
Source: is-82F14.tmp.10.drString found in binary or memory: https://www.ips.es/ips2002/0A
Source: is-82F14.tmp.10.drString found in binary or memory: https://www.ips.es/ips2002/ips2002CAC.crl03
Source: is-82F14.tmp.10.drString found in binary or memory: https://www.ips.es/ips2002/ips2002CAC.crl0=
Source: is-82F14.tmp.10.drString found in binary or memory: https://www.ips.es/ips2002/ips2002CLASE1.crl0
Source: is-82F14.tmp.10.drString found in binary or memory: https://www.ips.es/ips2002/ips2002CLASE1.crl06
Source: is-82F14.tmp.10.drString found in binary or memory: https://www.ips.es/ips2002/ips2002CLASE3.crl0
Source: is-82F14.tmp.10.drString found in binary or memory: https://www.ips.es/ips2002/ips2002CLASE3.crl06
Source: is-82F14.tmp.10.drString found in binary or memory: https://www.ips.es/ips2002/ips2002CLASEA1.crl07
Source: is-82F14.tmp.10.drString found in binary or memory: https://www.ips.es/ips2002/ips2002CLASEA1.crl0A
Source: is-82F14.tmp.10.drString found in binary or memory: https://www.ips.es/ips2002/ips2002CLASEA3.crl07
Source: is-82F14.tmp.10.drString found in binary or memory: https://www.ips.es/ips2002/ips2002CLASEA3.crl0A
Source: is-82F14.tmp.10.drString found in binary or memory: https://www.ips.es/ips2002/ips2002Timestamping.crl0
Source: is-82F14.tmp.10.drString found in binary or memory: https://www.ips.es/ips2002/ips2002Timestamping.crl0F
Source: is-82F14.tmp.10.drString found in binary or memory: https://www.ips.es/ips2002/policyCAC.html0o
Source: is-82F14.tmp.10.drString found in binary or memory: https://www.ips.es/ips2002/policyCLASE1.html0u
Source: is-82F14.tmp.10.drString found in binary or memory: https://www.ips.es/ips2002/policyCLASE3.html0u
Source: is-82F14.tmp.10.drString found in binary or memory: https://www.ips.es/ips2002/policyCLASEA1.html0w
Source: is-82F14.tmp.10.drString found in binary or memory: https://www.ips.es/ips2002/policyCLASEA3.html0w
Source: is-82F14.tmp.10.drString found in binary or memory: https://www.ips.es/ips2002/policyTimestamping.html0
Source: is-82F14.tmp.10.drString found in binary or memory: https://www.ips.es/ips2002/renewalCAC.html?08
Source: is-82F14.tmp.10.drString found in binary or memory: https://www.ips.es/ips2002/renewalCLASE1.html?0;
Source: is-82F14.tmp.10.drString found in binary or memory: https://www.ips.es/ips2002/renewalCLASE3.html?0;
Source: is-82F14.tmp.10.drString found in binary or memory: https://www.ips.es/ips2002/renewalCLASEA1.html?0
Source: is-82F14.tmp.10.drString found in binary or memory: https://www.ips.es/ips2002/renewalCLASEA3.html?0
Source: is-82F14.tmp.10.drString found in binary or memory: https://www.ips.es/ips2002/renewalTimestamping.html?0A
Source: is-82F14.tmp.10.drString found in binary or memory: https://www.ips.es/ips2002/revocationCAC.html?0:
Source: is-82F14.tmp.10.drString found in binary or memory: https://www.ips.es/ips2002/revocationCLASE1.html?0=
Source: is-82F14.tmp.10.drString found in binary or memory: https://www.ips.es/ips2002/revocationCLASE3.html?0=
Source: is-82F14.tmp.10.drString found in binary or memory: https://www.ips.es/ips2002/revocationCLASEA1.html?0
Source: is-82F14.tmp.10.drString found in binary or memory: https://www.ips.es/ips2002/revocationCLASEA3.html?0
Source: is-82F14.tmp.10.drString found in binary or memory: https://www.ips.es/ips2002/revocationTimestamping.html?0C
Source: is-82F14.tmp.10.drString found in binary or memory: https://www.netlock.net/docs
Source: is-82F14.tmp.10.drString found in binary or memory: https://wwwback.ips.es/ips2002/ips2002CAC.crl0/
Source: is-82F14.tmp.10.drString found in binary or memory: https://wwwback.ips.es/ips2002/ips2002CLASE1.crl0/
Source: is-82F14.tmp.10.drString found in binary or memory: https://wwwback.ips.es/ips2002/ips2002CLASE3.crl0/
Source: is-82F14.tmp.10.drString found in binary or memory: https://wwwback.ips.es/ips2002/ips2002CLASEA1.crl0/
Source: is-82F14.tmp.10.drString found in binary or memory: https://wwwback.ips.es/ips2002/ips2002CLASEA3.crl0/
Source: is-82F14.tmp.10.drString found in binary or memory: https://wwwback.ips.es/ips2002/ips2002Timestamping.crl0/

System Summary

barindex
Source: C:\Windows\SysWOW64\wget.exeFile dump: HOBOware_Free_Setup.exe.2.dr 253469944Jump to dropped file
Source: HOBOware_Free_Setup.tmp.9.drStatic PE information: Resource name: RT_RCDATA type: PE32+ executable (console) x86-64, for MS Windows
Source: HOBOware_Free_Setup.tmp.9.drStatic PE information: Resource name: RT_RCDATA type: PE32 executable (DLL) (GUI) Intel 80386 (stripped to external PDB), for MS Windows
Source: classification engineClassification label: mal48.win@13/1588@0/8
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\Program Files\Onset Computer CorporationJump to behavior
Source: C:\Windows\SysWOW64\cmd.exeFile created: C:\Users\user\Desktop\cmdline.outJump to behavior
Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:1844:120:WilError_03
Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:6000:120:WilError_03
Source: C:\Users\user\Desktop\download\HOBOware_Free_Setup.exeFile created: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmpJump to behavior
Source: C:\Users\user\Desktop\download\HOBOware_Free_Setup.exeKey opened: HKEY_CURRENT_USER\Software\Borland\Delphi\LocalesJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpKey opened: HKEY_CURRENT_USER\Software\Borland\Delphi\LocalesJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpWMI Queries: IWbemServices::ExecQuery - root\CIMV2 : SELECT Name FROM Win32_Process Where Name="HOBOware.exe"
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile read: C:\Program Files\desktop.iniJump to behavior
Source: C:\Windows\SysWOW64\wget.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpKey value created or modified: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion RegisteredOrganizationJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-SE99M.tmp\_isetup\_setup64.tmpEvasive API call chain: GetCommandLine,DecisionNodes,ExitProcessgraph_12-67
Source: unknownProcess created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c wget -t 2 -v -T 60 -P "C:\Users\user\Desktop\download" --no-check-certificate --content-disposition --user-agent="Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; AS; rv:11.0) like Gecko" "https://onset2.onsetcomp.com/files/software/hoboware/3.7.28/HOBOware_Free_Setup.exe" > cmdline.out 2>&1
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\wget.exe wget -t 2 -v -T 60 -P "C:\Users\user\Desktop\download" --no-check-certificate --content-disposition --user-agent="Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; AS; rv:11.0) like Gecko" "https://onset2.onsetcomp.com/files/software/hoboware/3.7.28/HOBOware_Free_Setup.exe"
Source: unknownProcess created: C:\Users\user\Desktop\download\HOBOware_Free_Setup.exe "C:\Users\user\Desktop\download\HOBOware_Free_Setup.exe"
Source: C:\Users\user\Desktop\download\HOBOware_Free_Setup.exeProcess created: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp "C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp" /SL5="$8004E,252732992,141824,C:\Users\user\Desktop\download\HOBOware_Free_Setup.exe"
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpProcess created: C:\Users\user\AppData\Local\Temp\is-SE99M.tmp\_isetup\_setup64.tmp helper 105 0x4C4
Source: C:\Users\user\AppData\Local\Temp\is-SE99M.tmp\_isetup\_setup64.tmpProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpProcess created: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE "C:\Program Files (x86)\Microsoft Office\Root\Office16\WINWORD.EXE" /n "C:\Program Files\Onset Computer Corporation\HOBOware\README.rtf" /o ""
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\wget.exe wget -t 2 -v -T 60 -P "C:\Users\user\Desktop\download" --no-check-certificate --content-disposition --user-agent="Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; AS; rv:11.0) like Gecko" "https://onset2.onsetcomp.com/files/software/hoboware/3.7.28/HOBOware_Free_Setup.exe" Jump to behavior
Source: C:\Users\user\Desktop\download\HOBOware_Free_Setup.exeProcess created: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp "C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp" /SL5="$8004E,252732992,141824,C:\Users\user\Desktop\download\HOBOware_Free_Setup.exe" Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpProcess created: C:\Users\user\AppData\Local\Temp\is-SE99M.tmp\_isetup\_setup64.tmp helper 105 0x4C4Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpProcess created: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE "C:\Program Files (x86)\Microsoft Office\Root\Office16\WINWORD.EXE" /n "C:\Program Files\Onset Computer Corporation\HOBOware\README.rtf" /o ""Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess created: unknown unknownJump to behavior
Source: C:\Windows\SysWOW64\cmd.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Windows\SysWOW64\wget.exeSection loaded: cryptsp.dllJump to behavior
Source: C:\Windows\SysWOW64\wget.exeSection loaded: rsaenh.dllJump to behavior
Source: C:\Windows\SysWOW64\wget.exeSection loaded: cryptbase.dllJump to behavior
Source: C:\Windows\SysWOW64\wget.exeSection loaded: msasn1.dllJump to behavior
Source: C:\Windows\SysWOW64\wget.exeSection loaded: mswsock.dllJump to behavior
Source: C:\Windows\SysWOW64\wget.exeSection loaded: dnsapi.dllJump to behavior
Source: C:\Windows\SysWOW64\wget.exeSection loaded: iphlpapi.dllJump to behavior
Source: C:\Windows\SysWOW64\wget.exeSection loaded: rasadhlp.dllJump to behavior
Source: C:\Windows\SysWOW64\wget.exeSection loaded: fwpuclnt.dllJump to behavior
Source: C:\Windows\SysWOW64\wget.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Windows\SysWOW64\wget.exeSection loaded: uxtheme.dllJump to behavior
Source: C:\Windows\SysWOW64\wget.exeSection loaded: explorerframe.dllJump to behavior
Source: C:\Users\user\Desktop\download\HOBOware_Free_Setup.exeSection loaded: uxtheme.dllJump to behavior
Source: C:\Users\user\Desktop\download\HOBOware_Free_Setup.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpSection loaded: msimg32.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpSection loaded: version.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpSection loaded: mpr.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpSection loaded: uxtheme.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpSection loaded: textinputframework.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpSection loaded: coreuicomponents.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpSection loaded: coremessaging.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpSection loaded: ntmarta.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpSection loaded: wintypes.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpSection loaded: wintypes.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpSection loaded: wintypes.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpSection loaded: textshaping.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpSection loaded: dwmapi.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpSection loaded: windows.storage.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpSection loaded: wldp.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpSection loaded: profapi.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpSection loaded: shfolder.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpSection loaded: rstrtmgr.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpSection loaded: ncrypt.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpSection loaded: ntasn1.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpSection loaded: wbemcomn.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpSection loaded: sxs.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpSection loaded: amsi.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpSection loaded: userenv.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpSection loaded: msftedit.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpSection loaded: windows.globalization.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpSection loaded: bcp47langs.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpSection loaded: bcp47mrm.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpSection loaded: globinputhost.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpSection loaded: windows.ui.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpSection loaded: windowmanagementapi.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpSection loaded: inputhost.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpSection loaded: twinapi.appcore.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpSection loaded: twinapi.appcore.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpSection loaded: propsys.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpSection loaded: sspicli.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpSection loaded: apphelp.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpSection loaded: explorerframe.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpSection loaded: sfc.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpSection loaded: sfc_os.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpSection loaded: linkinfo.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpSection loaded: ntshrui.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpSection loaded: srvcli.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpSection loaded: cscapi.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpSection loaded: edputil.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpSection loaded: urlmon.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpSection loaded: iertutil.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpSection loaded: netutils.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpSection loaded: windows.staterepositoryps.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpSection loaded: policymanager.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpSection loaded: msvcp110_win.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpSection loaded: appresolver.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpSection loaded: slc.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpSection loaded: sppc.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpSection loaded: onecorecommonproxystub.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpSection loaded: onecoreuapcommonproxystub.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-SE99M.tmp\_isetup\_setup64.tmpSection loaded: ntmarta.dllJump to behavior
Source: C:\Windows\SysWOW64\wget.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{56FDF344-FD6D-11d0-958A-006097C9A090}\InProcServer32Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile opened: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\jre\lib\amd64\jvm.cfgJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpKey value created or modified: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion RegisteredOwnerJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpWindow found: window name: TSelectLanguageFormJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpAutomated click: OK
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpAutomated click: Next >
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpAutomated click: I accept the agreement
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpAutomated click: Next >
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpAutomated click: Next >
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpAutomated click: I accept the agreement
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpAutomated click: Next >
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpAutomated click: I accept the agreement
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpAutomated click: Next >
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpAutomated click: I accept the agreement
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpAutomated click: Install
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpAutomated click: I accept the agreement
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpAutomated click: Next >
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpAutomated click: I accept the agreement
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpAutomated click: Next >
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpAutomated click: I accept the agreement
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpAutomated click: Next >
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpAutomated click: I accept the agreement
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpAutomated click: Next >
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpAutomated click: I accept the agreement
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpAutomated click: Next >
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpAutomated click: I accept the agreement
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpAutomated click: Next >
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpAutomated click: I accept the agreement
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpAutomated click: Next >
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpAutomated click: I accept the agreement
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpAutomated click: Next >
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpAutomated click: I accept the agreement
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile opened: C:\Windows\SysWOW64\MSFTEDIT.DLLJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\CommonJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer CorporationJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOwareJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\PluginsJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\ProcessorsJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\unins000.datJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\is-CSK4J.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\is-OLD4F.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\is-38022.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\is-USKD6.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\is-BPEP4.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\is-6I1Q1.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\is-O4KOT.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\is-SPUMH.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\is-M9FQP.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\Microsoft.VC80.CRTJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\Microsoft.VC80.CRT\is-K8B1A.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\Microsoft.VC80.CRT\is-DHMOA.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\Microsoft.VC80.CRT\is-RABQE.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\Microsoft.VC80.CRT\is-AE1HA.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\is-5UK12.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\is-G4RJV.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\is-UR4RJ.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\is-G5Q8V.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\is-GIHG3.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\is-NJA8S.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\is-1Q5F1.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\is-5TI14.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\is-RFFRQ.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\is-FM82F.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\is-N2O9V.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\is-955ER.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\is-KBR3D.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\binJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\bin\is-KMING.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\bin\is-CG9U6.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\bin\is-PFBAT.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\bin\is-KLT2L.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\bin\is-7FJIO.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\bin\is-6E11D.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\bin\is-51T21.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\bin\is-LFCPA.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\bin\is-O1LIU.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\bin\is-AKCDD.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\bin\is-D8SKV.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\bin\is-CDCB3.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\bin\is-KHRAR.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\bin\is-17GVT.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\bin\is-PEQOG.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\bin\is-FH6VO.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\bin\is-Q6L16.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\bin\is-V6NQM.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\bin\is-P9SLC.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\bin\is-7AF32.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\bin\is-DHMGO.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\bin\is-LSS3F.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\bin\is-0E28A.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\bin\is-UHS4P.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\bin\is-7MD89.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\bin\is-B1P41.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\bin\is-CKC23.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\bin\is-7D8OJ.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\bin\is-DTMAF.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\bin\is-4SOA3.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\bin\is-G717E.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\bin\is-LCGMB.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\bin\is-H6KE5.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\bin\is-TNV7E.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\bin\is-22LH3.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\bin\is-JFEPN.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\bin\is-R45U1.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\bin\is-QKTHP.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\bin\is-SSFBR.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\bin\is-64R2F.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\bin\is-LNQOR.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\bin\is-8HR2T.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\bin\is-UTDOE.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\bin\is-GI8KC.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\bin\is-3PAHC.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\bin\is-BG5OH.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\bin\is-42EBJ.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\bin\is-SL3N6.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\bin\is-6RAEB.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\bin\is-JBVKE.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\bin\is-RHJE3.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\bin\is-DCFMK.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\bin\is-OT3AH.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\bin\serverJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\bin\server\is-HKCSB.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\bin\server\is-2K9SL.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demoJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\is-AS52E.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\appletsJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\ArcTestJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\ArcTest\is-6P7KL.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\ArcTest\is-JL1Q1.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\ArcTest\is-M6F81.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\ArcTest\is-VOFED.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\ArcTest\is-119FG.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\ArcTest\is-D0GR7.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\BarChartJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\BarChart\is-KANL1.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\BarChart\is-7BBI9.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\BarChart\is-0MGHQ.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\BarChart\is-5BOHM.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\BlinkJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\Blink\is-FJJSA.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\Blink\is-K259P.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\Blink\is-5FG69.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\Blink\is-5AHJ5.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\CardTestJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\CardTest\is-THNAM.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\CardTest\is-TKLKL.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\CardTest\is-QQTBO.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\CardTest\is-5SSPD.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\ClockJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\Clock\is-HMU0T.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\Clock\is-EL0MM.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\Clock\is-PF4KT.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\DitherTestJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\DitherTest\is-DTH25.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\DitherTest\is-UUIJM.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\DitherTest\is-GOJNK.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\DitherTest\is-2N08G.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\DitherTest\is-H19F6.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\DitherTest\is-0AKBQ.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\DitherTest\is-VA336.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\DitherTest\is-RBE1A.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\DrawTestJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\DrawTest\is-BNJ67.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\DrawTest\is-J5T60.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\DrawTest\is-FK894.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\DrawTest\is-JA5E2.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\DrawTest\is-VRRH0.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\FractalJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\Fractal\is-JR7J0.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\Fractal\is-6LVT7.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\Fractal\is-FPDHH.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\Fractal\is-T7TTB.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\Fractal\is-MHKNJ.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\Fractal\is-RF7N6.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\GraphicsTestJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\GraphicsTest\is-L8J2E.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\GraphicsTest\is-9NHST.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\GraphicsTest\is-TTICH.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\GraphicsTest\is-DMSIQ.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\GraphicsTest\is-MTUBI.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\GraphicsTest\is-4CP5H.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\GraphicsTest\is-ON0UH.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\GraphicsTest\is-09OFR.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\GraphicsTest\is-P19BK.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\GraphicsTest\is-75DGS.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\GraphicsTest\is-O4PEC.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\GraphicsTest\is-F2GI0.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\GraphicsTest\is-RJLLD.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\GraphicsTest\is-IHESP.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\GraphicsTest\is-OCJGP.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\GraphicsTest\is-VAJ11.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\GraphicsTest\is-B42FL.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\MoleculeViewerJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\MoleculeViewer\is-MQHAT.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\MoleculeViewer\is-SOBEG.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\MoleculeViewer\is-IK58N.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\MoleculeViewer\is-SH2L2.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\MoleculeViewer\is-MCB12.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\MoleculeViewer\is-9084A.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\MoleculeViewer\is-BD1OQ.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\NervousTextJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\NervousText\is-27IKF.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\NervousText\is-4E290.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\NervousText\is-9A12V.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\SimpleGraphJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\SimpleGraph\is-QQM51.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\SimpleGraph\is-FEEGI.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\SimpleGraph\is-BSRGE.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\SortDemoJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\SortDemo\is-2D4F6.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\SortDemo\is-NF154.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\SortDemo\is-7F803.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\SortDemo\is-HN795.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\SortDemo\is-BBT1O.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\SortDemo\is-46GKS.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\SortDemo\is-UBSDR.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\SortDemo\is-E9G8S.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\SortDemo\is-QHO7C.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\SortDemo\is-MUVK1.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\SortDemo\is-OHAOH.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\SpreadSheetJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\SpreadSheet\is-1B99C.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\SpreadSheet\is-N6C0Q.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\SpreadSheet\is-MNK6A.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\SpreadSheet\is-UN9IU.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\SpreadSheet\is-BTR8C.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\SpreadSheet\is-95T2R.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\SpreadSheet\is-G9TJF.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\SpreadSheet\is-3ST3P.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\WireFrameJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\WireFrame\is-3RJ7L.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\WireFrame\is-8E4M7.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\WireFrame\is-9BI79.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\WireFrame\is-2ID5R.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\WireFrame\is-S8GCU.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\WireFrame\is-LGMNL.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\WireFrame\is-19DHG.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\applets\WireFrame\is-UVR7S.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jfcJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jfc\CodePointIMJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jfc\CodePointIM\is-6JI20.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jfc\CodePointIM\is-CQ7NU.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jfc\CodePointIM\is-NBE5Q.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jfc\CodePointIM\is-3OOCI.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jfc\CodePointIM\is-NP5KI.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jfc\FileChooserDemoJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jfc\FileChooserDemo\is-DUIRP.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jfc\FileChooserDemo\is-LHJS2.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jfc\FileChooserDemo\is-MCRAO.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jfc\Font2DTestJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jfc\Font2DTest\is-4MKMD.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jfc\Font2DTest\is-OPVRU.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jfc\Font2DTest\is-7PTFU.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jfc\Font2DTest\is-95MD4.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jfc\MetalworksJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jfc\Metalworks\is-HUIT8.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jfc\Metalworks\is-9N956.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jfc\Metalworks\is-EV716.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jfc\NotepadJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jfc\Notepad\is-O1DIE.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jfc\Notepad\is-PUC2S.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jfc\Notepad\is-6B1O9.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jfc\SampleTreeJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jfc\SampleTree\is-717JJ.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jfc\SampleTree\is-5QCDF.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jfc\SampleTree\is-L4I50.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jfc\SwingAppletJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jfc\SwingApplet\is-KJR9U.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jfc\SwingApplet\is-05FET.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jfc\SwingApplet\is-NBS4U.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jfc\SwingApplet\is-NOB5D.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jfc\TableExampleJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jfc\TableExample\is-TFC2U.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jfc\TableExample\is-I15UR.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jfc\TableExample\is-I3PJK.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jfc\TransparentRulerJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jfc\TransparentRuler\is-0HV9Q.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jfc\TransparentRuler\is-4KL00.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jfc\TransparentRuler\is-OS7J5.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jpdaJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jpda\is-BHB88.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jpda\is-S46S0.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jpda\comJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jpda\com\sunJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jpda\com\sun\toolsJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jpda\com\sun\tools\exampleJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jpda\com\sun\tools\example\is-737HS.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmtiJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\is-JT3VK.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\compiledMethodLoadJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\compiledMethodLoad\is-V0N5J.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\compiledMethodLoad\is-86O9M.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\compiledMethodLoad\libJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\compiledMethodLoad\lib\is-PNBTC.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\compiledMethodLoad\lib\is-4DRS0.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\compiledMethodLoad\lib\is-7JP2D.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\compiledMethodLoad\lib\is-AHM4L.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\gctestJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\gctest\is-9J6R5.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\gctest\is-L9V40.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\gctest\libJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\gctest\lib\is-37O9C.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\gctest\lib\is-MPT2K.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\gctest\lib\is-7CVO1.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\gctest\lib\is-Q5ANC.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\heapTrackerJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\heapTracker\is-CNTPB.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\heapTracker\is-6UHTC.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\heapTracker\is-FI6KO.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\heapTracker\libJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\heapTracker\lib\is-TS6PT.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\heapTracker\lib\is-2DA50.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\heapTracker\lib\is-HNFIK.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\heapTracker\lib\is-8FQ61.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\heapViewerJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\heapViewer\is-VS4JB.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\heapViewer\is-MBBJ3.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\heapViewer\libJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\heapViewer\lib\is-IKL45.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\heapViewer\lib\is-OFDKL.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\heapViewer\lib\is-7LSFD.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\heapViewer\lib\is-E9JUD.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\hprofJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\hprof\is-UUJNM.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\hprof\is-SPETB.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\hprof\libJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\hprof\lib\is-U8BTR.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\hprof\lib\is-0AELL.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\hprof\lib\is-B7SMV.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\hprof\lib\is-JCCGR.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\minstJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\minst\is-4KJIE.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\minst\is-1UMRK.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\minst\is-CVFFQ.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\minst\libJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\minst\lib\is-GORJU.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\minst\lib\is-7AL4T.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\minst\lib\is-76D71.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\minst\lib\is-BK7JS.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\mtraceJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\mtrace\is-3ITVC.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\mtrace\is-LVHH1.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\mtrace\is-MUE2L.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\mtrace\libJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\mtrace\lib\is-SPAP0.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\mtrace\lib\is-F87VS.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\mtrace\lib\is-ES6MI.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\mtrace\lib\is-2B7D7.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\versionCheckJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\versionCheck\is-ERMOR.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\versionCheck\is-FB6M7.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\versionCheck\libJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\versionCheck\lib\is-LLDP7.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\versionCheck\lib\is-KGEPG.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\versionCheck\lib\is-DOFH8.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\versionCheck\lib\is-T35N4.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\waitersJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\waiters\is-KSP0O.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\waiters\is-O5NE8.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\waiters\libJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\waiters\lib\is-L4D3S.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\waiters\lib\is-OHLBB.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\waiters\lib\is-HQHOU.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\waiters\lib\is-OO865.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\managementJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\management\is-BK9MH.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\management\FullThreadDumpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\management\FullThreadDump\is-USGFL.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\management\FullThreadDump\is-20MHH.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\management\FullThreadDump\is-C9HG2.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\management\JTopJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\management\JTop\is-AMFIV.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\management\JTop\is-VD2KQ.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\management\JTop\is-Q6OU8.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\management\MemoryMonitorJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\management\MemoryMonitor\is-RR3EL.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\management\MemoryMonitor\is-UD76T.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\management\MemoryMonitor\is-8KDVH.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\management\VerboseGCJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\management\VerboseGC\is-LURMR.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\management\VerboseGC\is-7N3OM.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\management\VerboseGC\is-GQ544.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbprojectJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\is-F4H8J.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\is-VJGN3.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\jfcJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\jfc\FileChooserDemoJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\jfc\FileChooserDemo\is-D63OU.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\jfc\FileChooserDemo\is-SAO0B.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\jfc\FileChooserDemo\nbprojectJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\jfc\FileChooserDemo\nbproject\is-NEDSN.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\jfc\FileChooserDemo\nbproject\is-7UMUO.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\jfc\FileChooserDemo\nbproject\is-R1ME4.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\jfc\FileChooserDemo\nbproject\is-8LMLB.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\jfc\Font2DTestJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\jfc\Font2DTest\is-KLDSL.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\jfc\Font2DTest\is-59OHH.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\jfc\Font2DTest\nbprojectJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\jfc\Font2DTest\nbproject\is-AK6B1.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\jfc\Font2DTest\nbproject\is-TPE0R.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\jfc\Font2DTest\nbproject\is-L79T6.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\jfc\Font2DTest\nbproject\is-P68N6.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\jfc\MetalworksJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\jfc\Metalworks\is-QLBMC.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\jfc\Metalworks\is-0BF4K.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\jfc\Metalworks\nbprojectJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\jfc\Metalworks\nbproject\is-V9F72.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\jfc\Metalworks\nbproject\is-4G1RG.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\jfc\Metalworks\nbproject\is-HK2AU.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\jfc\Metalworks\nbproject\is-J8T6D.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\jfc\NotepadJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\jfc\Notepad\is-6B5N0.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\jfc\Notepad\is-P83E7.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\jfc\Notepad\nbprojectJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\jfc\Notepad\nbproject\is-KSVNF.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\jfc\Notepad\nbproject\is-1NRFV.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\jfc\Notepad\nbproject\is-BCLTP.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\jfc\Notepad\nbproject\is-1OG31.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\jfc\SampleTreeJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\jfc\SampleTree\is-AE8UL.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\jfc\SampleTree\is-T9RF1.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\jfc\SampleTree\nbprojectJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\jfc\SampleTree\nbproject\is-1BF04.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\jfc\SampleTree\nbproject\is-SHBHP.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\jfc\SampleTree\nbproject\is-288NB.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\jfc\SampleTree\nbproject\is-3FALC.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\jfc\SwingAppletJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\jfc\SwingApplet\is-N3CMP.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\jfc\SwingApplet\is-KEOM5.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\jfc\SwingApplet\nbprojectJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\jfc\SwingApplet\nbproject\is-DB5C7.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\jfc\SwingApplet\nbproject\is-6C0ON.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\jfc\SwingApplet\nbproject\is-GKTEH.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\jfc\SwingApplet\nbproject\is-4NNFT.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\jfc\TableExampleJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\jfc\TableExample\is-FHMS1.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\jfc\TableExample\is-RSDIR.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\jfc\TableExample\nbprojectJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\jfc\TableExample\nbproject\is-10884.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\jfc\TableExample\nbproject\is-0632Q.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\jfc\TableExample\nbproject\is-1OSPI.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\jfc\TableExample\nbproject\is-US71F.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\jfc\TransparentRulerJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\jfc\TransparentRuler\is-U5IO9.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\jfc\TransparentRuler\is-R7FMK.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\jfc\TransparentRuler\nbprojectJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\jfc\TransparentRuler\nbproject\is-24KBH.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\jfc\TransparentRuler\nbproject\is-LTN6C.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\jfc\TransparentRuler\nbproject\is-GQ77P.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\jfc\TransparentRuler\nbproject\is-078N2.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\managementJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\management\FullThreadDumpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\management\FullThreadDump\is-NHECN.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\management\FullThreadDump\is-R2A79.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\management\FullThreadDump\nbprojectJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\management\FullThreadDump\nbproject\is-92QJB.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\management\FullThreadDump\nbproject\is-THEJS.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\management\FullThreadDump\nbproject\is-M35BR.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\management\FullThreadDump\nbproject\is-83SDV.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\management\JTopJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\management\JTop\is-A2IBN.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\management\JTop\is-4UL0R.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\management\JTop\nbprojectJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\management\JTop\nbproject\is-Q0JBM.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\management\JTop\nbproject\is-IV885.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\management\JTop\nbproject\is-5FALN.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\management\JTop\nbproject\is-RP0LN.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\management\MemoryMonitorJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\management\MemoryMonitor\is-MC830.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\management\MemoryMonitor\is-DFK7K.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\management\MemoryMonitor\nbprojectJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\management\MemoryMonitor\nbproject\is-8QSA0.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\management\MemoryMonitor\nbproject\is-3A5E7.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\management\MemoryMonitor\nbproject\is-T9USF.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\management\MemoryMonitor\nbproject\is-4B123.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\management\VerboseGCJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\management\VerboseGC\is-612LC.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\management\VerboseGC\is-924A3.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\management\VerboseGC\nbprojectJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\management\VerboseGC\nbproject\is-F1KMU.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\management\VerboseGC\nbproject\is-0FNHB.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\management\VerboseGC\nbproject\is-8B1OJ.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\management\VerboseGC\nbproject\is-M79D4.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\scriptingJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\scripting\jconsole-pluginJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\scripting\jconsole-plugin\is-5EU53.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\scripting\jconsole-plugin\is-MIMJ3.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\scripting\jconsole-plugin\nbprojectJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\scripting\jconsole-plugin\nbproject\is-FNC8C.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\scripting\jconsole-plugin\nbproject\is-TV9V2.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\scripting\jconsole-plugin\nbproject\is-PDTDM.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nbproject\scripting\jconsole-plugin\nbproject\is-NV194.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nioJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nio\zipfsJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nio\zipfs\is-JN9DG.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nio\zipfs\is-I12BK.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nio\zipfs\is-7KOBG.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\nio\zipfs\is-0MCP5.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\scriptingJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\scripting\jconsole-pluginJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\scripting\jconsole-plugin\is-NGR4M.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\scripting\jconsole-plugin\is-CVK2I.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\scripting\jconsole-plugin\is-2AED8.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\scripting\jconsole-plugin\is-62ECU.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\includeJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\include\is-0M3UM.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\include\is-9U3NL.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\include\is-5AELN.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\include\is-H79I9.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\include\is-A1D09.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\include\is-8SN2K.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\include\win32Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\include\win32\is-A5DRK.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\include\win32\is-P6TQR.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\include\win32\bridgeJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\include\win32\bridge\is-K6C27.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\include\win32\bridge\is-7EIV8.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\include\win32\bridge\is-1ES9O.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\include\win32\bridge\is-O5KSF.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\jreJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\jre\is-T89H7.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\jre\is-T8PD9.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\jre\is-V7RUQ.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\jre\binJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\jre\bin\is-UVGGQ.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\jre\bin\is-H56E2.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\jre\bin\is-JQ7GE.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\jre\bin\is-FMMDJ.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\jre\bin\is-IUOLN.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\jre\bin\is-C62DF.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\jre\bin\is-OSJGF.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\jre\bin\is-HRISR.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDirectory created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\jre\bin\is-939CR.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpRegistry value created: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\HOBOware_3.7.28_is1Jump to behavior
Source: Binary string: Z{app}\jre2\demo\jvmti\waiters\lib\waiters.pdb$Is64BitInstallMode source: HOBOware_Free_Setup.tmp, 0000000A.00000003.3873258864.0000000003380000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\minst\lib\minst.pdb source: HOBOware_Free_Setup.tmp, 0000000A.00000003.4865591021.0000000002334000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: c:\jenkins\worksp~1\j171-w~1\coinst\ftcserco\objfre_wnet_amd64\amd64\ftcserco.pdb source: HOBOware_Free_Setup.tmp, 0000000A.00000003.4848425848.0000000006830000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: T{app}\jre\demo\jvmti\gctest\lib\gctest.pdb$Is64BitInstallMode source: HOBOware_Free_Setup.tmp, 0000000A.00000003.3873258864.00000000031F0000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: C:\Users\IoT\Desktop\CDMDriverVS2015\x64\Release\FTDIBUS.pdb source: HOBOware_Free_Setup.tmp, 0000000A.00000003.4848425848.0000000006830000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: f:\binaries\Intermediate\vctools\crt_bld\SELF_64_amd64\crt\prebuild\build\amd64\dll_obj\eh\nativecpp\.compile.pdb source: is-8FQ61.tmp.10.dr
Source: Binary string: *{app}\jre\demo\jvmti\mtrace\lib\mtrace.pdb source: HOBOware_Free_Setup.tmp, 0000000A.00000003.4865591021.0000000002443000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: 3{app}\jre2\demo\jvmti\heapViewer\lib\heapViewer.pdb source: HOBOware_Free_Setup.tmp, 0000000A.00000003.4865591021.0000000002334000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: ){app}\jre2\demo\jvmti\minst\lib\minst.pdb source: HOBOware_Free_Setup.tmp, 0000000A.00000003.4865591021.0000000002443000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: l{app}\jre\demo\jvmti\versionCheck\lib\versionCheck.pdb$Is64BitInstallMode source: HOBOware_Free_Setup.tmp, 0000000A.00000003.3873258864.00000000031F0000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\heapViewer\lib\heapViewer.pdb source: HOBOware_Free_Setup.tmp, 0000000A.00000003.4865591021.00000000023CB000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: C:\Users\IoT\Desktop\CDMDriverVS2015\x64\Release\FTSER2K.pdb source: HOBOware_Free_Setup.tmp, 0000000A.00000003.4848425848.0000000006830000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: c:\jenkins\worksp~1\j171-w~1\pp\ftserui2\objfre_wnet_amd64\amd64\ftserui2.pdb source: HOBOware_Free_Setup.tmp, 0000000A.00000003.4848425848.0000000006830000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: 6{app}\jre\demo\jvmti\versionCheck\lib\versionCheck.pdb source: HOBOware_Free_Setup.tmp, 0000000A.00000003.4865591021.0000000002334000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: C:\Jenkins\workspace\J171-Windows-D2XX-VCP-VS2013\FTLang\Release\FTLang.pdb source: HOBOware_Free_Setup.tmp, 0000000A.00000003.4848425848.0000000006830000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: c:\jenkins\worksp~1\j171-w~1\pp\ftserui2\objfre_wnet_x86\i386\ftserui2.pdb source: HOBOware_Free_Setup.tmp, 0000000A.00000003.4848425848.0000000006830000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: c:\jenkins\workspace\j171-windows-d2xx-vcp-vs2013\d2xxlib\x64\release\vc120.pdbH source: HOBOware_Free_Setup.tmp, 0000000A.00000003.4848425848.0000000006830000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: R{app}\jre2\demo\jvmti\hprof\lib\hprof.pdb$Is64BitInstallMode source: HOBOware_Free_Setup.tmp, 0000000A.00000003.3873258864.0000000003380000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: XC:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\hprof\lib\hprof.pdbmp source: HOBOware_Free_Setup.tmp, 0000000A.00000003.4863238436.0000000003808000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: C:\Jenkins\workspace\J171-Windows-D2XX-VCP-VS2013\FTBUSUI\x64\Release\FTBUSUI.pdb~~ source: HOBOware_Free_Setup.tmp, 0000000A.00000003.4848425848.0000000006830000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: -{app}\jre2\demo\jvmti\waiters\lib\waiters.pdbAw> source: HOBOware_Free_Setup.tmp, 0000000A.00000003.4865591021.00000000023E5000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\gctest\lib\gctest.pdb source: HOBOware_Free_Setup.tmp, 0000000A.00000003.4865591021.0000000002334000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: P{app}\jre\demo\jvmti\minst\lib\minst.pdb$Is64BitInstallMode source: HOBOware_Free_Setup.tmp, 0000000A.00000003.3873258864.00000000031F0000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: ZC:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\gctest\lib\gctest.pdbpSQM; source: HOBOware_Free_Setup.tmp, 0000000A.00000003.4865591021.000000000237D000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\hprof\lib\hprof.pdb source: HOBOware_Free_Setup.tmp, 0000000A.00000003.4865591021.0000000002334000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: cwdC:\wsjdk\Corretto8Src\installers\windows\zip\corretto-build\buildRoot\jdk\makeexec:\progra~2\micros~3.0\vc\bin\amd64\link.exepdbc:\wsjdk\Corretto8Src\installers\windows\zip\corretto-build\buildRoot\build\windows-x86_64-normal-server-release\jdk\demo\jvmti\heapTracker\lib\heapTracker.pdb source: is-8FQ61.tmp.10.dr
Source: Binary string: C:\Program Files\Onset Computer Corporation\HOBOware\jre\demo\jvmti\waiters\lib\waiters.pdb source: HOBOware_Free_Setup.tmp, 0000000A.00000003.4863238436.00000000037A3000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: c:\wsjdk\Corretto8Src\installers\windows\zip\corretto-build\buildRoot\build\windows-x86_64-normal-server-release\jdk\demoobjs\jvmti\heapTracker\agent_util.pdb source: is-8FQ61.tmp.10.dr
Source: Binary string: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\compiledMethodLoad\lib\compiledMethodLoad.pdb source: HOBOware_Free_Setup.tmp, 0000000A.00000003.4864325209.0000000003453000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: c:\jenkins\worksp~1\j171-w~1\pp\ftserui2\objfre_wnet_amd64\amd64\ftserui2.pdbH source: HOBOware_Free_Setup.tmp, 0000000A.00000003.4848425848.0000000006830000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: f:\binaries\Intermediate\vctools\crt_bld\SELF_64_amd64\crt\prebuild\build\amd64\dll_obj\rtc\nativecpp\.compile.pdb source: is-8FQ61.tmp.10.dr
Source: Binary string: C:\Program Files\Onset Computer Corporation\HOBOware\jre\demo\jvmti\versionCheck\lib\versionCheck.pdb source: HOBOware_Free_Setup.tmp, 0000000A.00000003.4863238436.00000000037A3000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: 2{app}\jre\demo\jvmti\heapViewer\lib\heapViewer.pdbq source: HOBOware_Free_Setup.tmp, 0000000A.00000003.4865591021.0000000002334000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: dC:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\heapTracker\lib\heapTracker.pdbp source: HOBOware_Free_Setup.tmp, 0000000A.00000003.4865591021.0000000002334000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\waiters\lib\waiters.pdb source: HOBOware_Free_Setup.tmp, 0000000A.00000003.4865591021.0000000002334000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: C:\Jenkins\workspace\J171-Windows-D2XX-VCP-VS2013\FTLang\x64\Release\FTLang.pdb source: HOBOware_Free_Setup.tmp, 0000000A.00000003.4848425848.0000000006830000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: c:\jenkins\workspace\j171-windows-d2xx-vcp-vs2013\d2xxlib\x64\release\vc120.pdb@SH source: HOBOware_Free_Setup.tmp, 0000000A.00000003.4848425848.0000000006830000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: c:\jenkins\workspace\j171-windows-d2xx-vcp-vs2013\d2xxlib\x64\release\vc120.pdb" source: HOBOware_Free_Setup.tmp, 0000000A.00000003.4848425848.0000000006830000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: C:\Program Files\Onset Computer Corporation\HOBOware\jre\demo\jvmti\heapViewer\lib\heapViewer.pdb source: HOBOware_Free_Setup.tmp, 0000000A.00000003.4863238436.00000000037A3000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: C:\Jenkins\workspace\J171-Windows-D2XX-VCP-VS2013\FTBUSUI\Release\FTBUSUI.pdb source: HOBOware_Free_Setup.tmp, 0000000A.00000003.4848425848.0000000006830000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: n{app}\jre2\demo\jvmti\versionCheck\lib\versionCheck.pdb$Is64BitInstallMode source: HOBOware_Free_Setup.tmp, 0000000A.00000003.3873258864.0000000003380000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: d{app}\jre\demo\jvmti\heapViewer\lib\heapViewer.pdb$Is64BitInstallMode source: HOBOware_Free_Setup.tmp, 0000000A.00000003.3873258864.00000000031F0000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: c:\jenkins\workspace\j171-windows-d2xx-vcp-vs2013\d2xxlib\x64\release\vc120.pdb source: HOBOware_Free_Setup.tmp, 0000000A.00000003.4848425848.0000000006830000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: C:\Program Files\Onset Computer Corporation\HOBOware\jre\demo\jvmti\mtrace\lib\mtrace.pdb source: HOBOware_Free_Setup.tmp, 0000000A.00000003.4863238436.00000000037A3000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: X{app}\jre\demo\jvmti\waiters\lib\waiters.pdb$Is64BitInstallMode source: HOBOware_Free_Setup.tmp, 0000000A.00000003.3873258864.00000000031F0000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: fC:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\versionCheck\lib\versionCheck.pdb source: HOBOware_Free_Setup.tmp, 0000000A.00000003.4863238436.0000000003808000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: C:\Users\IoT\Desktop\CDMDriverVS2015\Release\FTSER2K.pdb source: HOBOware_Free_Setup.tmp, 0000000A.00000003.4848425848.0000000006830000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: f:\dd\vctools\crt\crtw32\misc\amd64\amdsecgs.asmf:\dd\vctools\crt\crtw32\startup\amd64\chkstk.asmc:\wsjdk\Corretto8Src\installers\windows\zip\corretto-build\buildRoot\build\windows-x86_64-normal-server-release\jdk\demo\jvmti\heapTracker\lib\heapTracker.pdb source: is-8FQ61.tmp.10.dr
Source: Binary string: P{app}\jre\demo\jvmti\hprof\lib\hprof.pdb$Is64BitInstallMode source: HOBOware_Free_Setup.tmp, 0000000A.00000003.3873258864.00000000031F0000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\mtrace\lib\mtrace.pdb source: HOBOware_Free_Setup.tmp, 0000000A.00000003.4865591021.0000000002334000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: c:\jenkins\workspace\j171-windows-d2xx-vcp-vs2013\d2xxlib\x64\release\vc120.pdb@comp.id source: HOBOware_Free_Setup.tmp, 0000000A.00000003.4848425848.0000000006830000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\versionCheck\lib\versionCheck.pdb source: HOBOware_Free_Setup.tmp, 0000000A.00000003.4865591021.00000000023CB000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: f:\binaries\Intermediate\vctools\crt_bld\SELF_64_amd64\crt\prebuild\build\amd64\dll_obj\nativec\.compile.pdb source: is-8FQ61.tmp.10.dr
Source: Binary string: XC:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\minst\lib\minst.pdbmp source: HOBOware_Free_Setup.tmp, 0000000A.00000003.4863238436.0000000003808000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: f:\binaries\Intermediate\vctools\crt_bld\SELF_64_amd64\crt\prebuild\build\amd64\dll_obj\others\nativec\.compile.pdb source: is-8FQ61.tmp.10.dr
Source: Binary string: C:\Program Files\Onset Computer Corporation\HOBOware\jre\demo\jvmti\heapTracker\lib\heapTracker.pdb source: HOBOware_Free_Setup.tmp, 0000000A.00000003.4863238436.00000000037A3000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: f{app}\jre2\demo\jvmti\heapViewer\lib\heapViewer.pdb$Is64BitInstallMode source: HOBOware_Free_Setup.tmp, 0000000A.00000003.3873258864.0000000003380000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: c:\jenkins\worksp~1\j171-w~1\coinst\ftcserco\objfre_wnet_x86\i386\ftcserco.pdb source: HOBOware_Free_Setup.tmp, 0000000A.00000003.4848425848.0000000006830000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: ({app}\jre\demo\jvmti\minst\lib\minst.pdbY source: HOBOware_Free_Setup.tmp, 0000000A.00000003.4865591021.0000000002443000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: rC:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\compiledMethodLoad\lib\compiledMethodLoad.pdbb source: HOBOware_Free_Setup.tmp, 0000000A.00000003.4865591021.00000000023CB000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: bC:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\heapViewer\lib\heapViewer.pdbb source: HOBOware_Free_Setup.tmp, 0000000A.00000003.4865591021.0000000002334000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: V{app}\jre2\demo\jvmti\mtrace\lib\mtrace.pdb$Is64BitInstallMode source: HOBOware_Free_Setup.tmp, 0000000A.00000003.3873258864.0000000003380000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: C:\Program Files\Onset Computer Corporation\HOBOware\jre\demo\jvmti\minst\lib\minst.pdb source: HOBOware_Free_Setup.tmp, 0000000A.00000003.4863238436.00000000037A3000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: h{app}\jre\demo\jvmti\heapTracker\lib\heapTracker.pdb$Is64BitInstallMode source: HOBOware_Free_Setup.tmp, 0000000A.00000003.3873258864.00000000031F0000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: ,{app}\jre\demo\jvmti\waiters\lib\waiters.pdb source: HOBOware_Free_Setup.tmp, 0000000A.00000003.4865591021.00000000023E5000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: C:\Jenkins\workspace\J171-Windows-D2XX-VCP-VS2013\d2xxdll\Release\FTD2XX.pdb source: HOBOware_Free_Setup.tmp, 0000000A.00000003.4848425848.0000000006830000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: *{app}\jre\demo\jvmti\gctest\lib\gctest.pdb source: HOBOware_Free_Setup.tmp, 0000000A.00000003.4865591021.0000000002443000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: C:\Program Files\Onset Computer Corporation\HOBOware\jre\demo\jvmti\hprof\lib\hprof.pdb source: HOBOware_Free_Setup.tmp, 0000000A.00000003.4863238436.00000000037A3000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: j{app}\jre2\demo\jvmti\heapTracker\lib\heapTracker.pdb$Is64BitInstallMode source: HOBOware_Free_Setup.tmp, 0000000A.00000003.3873258864.0000000003380000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: C:\Jenkins\workspace\J171-Windows-D2XX-VCP-VS2013\d2xxdll\x64\Release\FTD2XX64.pdb source: HOBOware_Free_Setup.tmp, 0000000A.00000003.4848425848.0000000006830000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: T{app}\jre\demo\jvmti\mtrace\lib\mtrace.pdb$Is64BitInstallMode source: HOBOware_Free_Setup.tmp, 0000000A.00000003.3873258864.00000000031F0000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: +{app}\jre2\demo\jvmti\gctest\lib\gctest.pdbI source: HOBOware_Free_Setup.tmp, 0000000A.00000003.4865591021.0000000002443000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: {app}\jre\demo\jvmti\compiledMethodLoad\lib\compiledMethodLoad.pdb$Is64BitInstallMode source: HOBOware_Free_Setup.tmp, 0000000A.00000003.3873258864.00000000031F0000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: R{app}\jre2\demo\jvmti\minst\lib\minst.pdb$Is64BitInstallMode source: HOBOware_Free_Setup.tmp, 0000000A.00000003.3873258864.0000000003380000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: C:\Jenkins\workspace\J171-Windows-D2XX-VCP-VS2013\FTBUSUI\x64\Release\FTBUSUI.pdb source: HOBOware_Free_Setup.tmp, 0000000A.00000003.4848425848.0000000006830000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: ){app}\jre2\demo\jvmti\hprof\lib\hprof.pdb! source: HOBOware_Free_Setup.tmp, 0000000A.00000003.4865591021.0000000002443000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: \C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\waiters\lib\waiters.pdbaB source: HOBOware_Free_Setup.tmp, 0000000A.00000003.4863238436.0000000003808000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: C:\Program Files\Onset Computer Corporation\HOBOware\jre\demo\jvmti\compiledMethodLoad\lib\compiledMethodLoad.pdb source: HOBOware_Free_Setup.tmp, 0000000A.00000003.4863238436.0000000003808000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: 4{app}\jre\demo\jvmti\heapTracker\lib\heapTracker.pdb source: HOBOware_Free_Setup.tmp, 0000000A.00000003.4865591021.0000000002334000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: c:\wsjdk\Corretto8Src\installers\windows\zip\corretto-build\buildRoot\build\windows-x86_64-normal-server-release\jdk\demoobjs\jvmti\heapTracker\heapTracker.pdb source: is-8FQ61.tmp.10.dr
Source: Binary string: C:\Users\IoT\Desktop\CDMDriverVS2015\Release\FTDIBUS.pdb source: HOBOware_Free_Setup.tmp, 0000000A.00000003.4848425848.0000000006830000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\heapTracker\lib\heapTracker.pdb source: HOBOware_Free_Setup.tmp, 0000000A.00000003.4865591021.00000000023CB000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: C{app}\jre2\demo\jvmti\compiledMethodLoad\lib\compiledMethodLoad.pdb source: HOBOware_Free_Setup.tmp, 0000000A.00000003.4865591021.0000000002334000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: ZC:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\mtrace\lib\mtrace.pdbp source: HOBOware_Free_Setup.tmp, 0000000A.00000003.4863238436.0000000003808000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: c:\jenkins\worksp~1\j171-w~1\coinst\ftcserco\objfre_wnet_amd64\amd64\ftcserco.pdbH source: HOBOware_Free_Setup.tmp, 0000000A.00000003.4848425848.0000000006830000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: +{app}\jre2\demo\jvmti\mtrace\lib\mtrace.pdba source: HOBOware_Free_Setup.tmp, 0000000A.00000003.4865591021.0000000002443000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: V{app}\jre2\demo\jvmti\gctest\lib\gctest.pdb$Is64BitInstallMode source: HOBOware_Free_Setup.tmp, 0000000A.00000003.3873258864.0000000003380000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: c:\wsjdk\Corretto8Src\installers\windows\zip\corretto-build\buildRoot\build\windows-x86_64-normal-server-release\jdk\demo\jvmti\heapTracker\lib\heapTracker.pdb source: is-8FQ61.tmp.10.dr
Source: Binary string: {app}\jre2\demo\jvmti\compiledMethodLoad\lib\compiledMethodLoad.pdb$Is64BitInstallMode source: HOBOware_Free_Setup.tmp, 0000000A.00000003.3873258864.0000000003380000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: B{app}\jre\demo\jvmti\compiledMethodLoad\lib\compiledMethodLoad.pdbqH4 source: HOBOware_Free_Setup.tmp, 0000000A.00000003.4865591021.0000000002334000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: c:\wsjdk\Corretto8Src\installers\windows\zip\corretto-build\buildRoot\build\windows-x86_64-normal-server-release\jdk\demoobjs\jvmti\heapTracker\java_crw_demo.pdb source: is-8FQ61.tmp.10.dr
Source: Binary string: c:\wsjdk\Corretto8Src\installers\windows\zip\corretto-build\buildRoot\build\windows-x86_64-normal-server-release\jdk\demo\jvmti\gctest\lib\gctest.pdb source: is-37O9C.tmp.10.dr
Source: Binary string: ({app}\jre\demo\jvmti\hprof\lib\hprof.pdb source: HOBOware_Free_Setup.tmp, 0000000A.00000003.4865591021.0000000002443000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: 5{app}\jre2\demo\jvmti\heapTracker\lib\heapTracker.pdb source: HOBOware_Free_Setup.tmp, 0000000A.00000003.4865591021.0000000002334000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: C:\Program Files\Onset Computer Corporation\HOBOware\jre\demo\jvmti\gctest\lib\gctest.pdb source: HOBOware_Free_Setup.tmp, 0000000A.00000003.4863238436.00000000037A3000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: 7{app}\jre2\demo\jvmti\versionCheck\lib\versionCheck.pdb source: HOBOware_Free_Setup.tmp, 0000000A.00000003.4865591021.0000000002334000.00000004.00001000.00020000.00000000.sdmp
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\is-A2ADD.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\is-EEV09.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\mtrace\lib\is-SPAP0.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\Program Files\Onset Computer Corporation\HOBOware\jre\jre\bin\is-S4H4U.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\Program Files\Onset Computer Corporation\HOBOware\jre\jre\bin\is-PLTIL.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\Program Files\Onset Computer Corporation\HOBOware\jre\jre\bin\is-NVV99.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\Program Files\Onset Computer Corporation\HOBOware\jre\jre\bin\is-JF24I.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\Program Files\Onset Computer Corporation\HOBOware\jre\jre\bin\is-G7JA2.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\is-GRUKG.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\Program Files\Onset Computer Corporation\HOBOware\jre\jre\bin\is-V704D.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\Program Files\Onset Computer Corporation\HOBOware\jre\jre\bin\is-HP85J.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\jdeps.exe (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\jsadebugd.exe (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\javadoc.exe (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\appletviewer.exe (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\jstat.exe (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\Program Files\Onset Computer Corporation\HOBOware\jre\jre\bin\is-2LBJ9.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\Program Files\Onset Computer Corporation\HOBOware\jre\jre\bin\is-TIJ0O.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\Program Files\Onset Computer Corporation\HOBOware\jre\jre\bin\is-9RFGE.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\Program Files\Onset Computer Corporation\HOBOware\jre\jre\bin\is-R9ECQ.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\Program Files\Onset Computer Corporation\HOBOware\jre\jre\bin\is-4PL6E.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\Program Files\Onset Computer Corporation\HOBOware\jre\jre\bin\is-9D3ES.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\java.exe (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\Program Files\Onset Computer Corporation\HOBOware\jre\jre\bin\is-BBOH3.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\jinfo.exe (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\idlj.exe (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\Program Files\Onset Computer Corporation\HOBOware\jre\jre\bin\is-BCVNP.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\jconsole.exe (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\Program Files\Onset Computer Corporation\HOBOware\jre\jre\bin\is-OT4TQ.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\Program Files\Onset Computer Corporation\HOBOware\jre\jre\bin\is-M86V1.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\jabswitch.exe (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\jjs.exe (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\Program Files\Onset Computer Corporation\HOBOware\jre\jre\bin\is-7GHQB.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\Program Files\Onset Computer Corporation\HOBOware\jre\jre\bin\is-NIL39.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\Program Files\Onset Computer Corporation\HOBOware\jre\jre\bin\is-CLGV2.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\is-4I29T.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\is-RHBO1.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\Program Files\Onset Computer Corporation\HOBOware\jre\jre\bin\is-BSO9P.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\Program Files\Onset Computer Corporation\HOBOware\jre\jre\bin\is-O0KMU.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\Program Files\Onset Computer Corporation\HOBOware\jre\jre\bin\is-H45AQ.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\hprof\lib\is-U8BTR.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\Program Files\Onset Computer Corporation\HOBOware\jre\jre\bin\is-RNC4U.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\Program Files\Onset Computer Corporation\HOBOware\jre\jre\bin\is-70I4A.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\hsdb.exe (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\is-EMP87.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\is-7BV7A.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\Program Files\Onset Computer Corporation\HOBOware\jre\jre\bin\is-PEOBO.tmpJump to dropped file
Source: C:\Windows\SysWOW64\wget.exeFile created: C:\Users\user\Desktop\download\HOBOware_Free_Setup.exeJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\javah.exe (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\Program Files\Onset Computer Corporation\HOBOware\jre\jre\bin\is-E55HV.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\is-LJ3FO.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\jarsigner.exe (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\jcmd.exe (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\Program Files\Onset Computer Corporation\HOBOware\jre\jre\bin\is-LL20H.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\Program Files\Onset Computer Corporation\HOBOware\jre\jre\bin\is-CHQEV.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\is-TGBD8.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\is-BO8O1.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\is-PANRP.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\is-THC28.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\Program Files\Onset Computer Corporation\HOBOware\jre\jre\bin\is-R10L8.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\jstack.exe (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\is-NFS6P.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\clhsdb.exe (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\compiledMethodLoad\lib\is-PNBTC.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\Program Files\Onset Computer Corporation\HOBOware\jre\jre\bin\is-VEE83.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\is-RML27.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\jps.exe (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\Program Files\Onset Computer Corporation\HOBOware\jre\jre\bin\is-P9QHD.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\Program Files\Onset Computer Corporation\HOBOware\jre\jre\bin\is-1RJ9E.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\is-IIATI.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\is-IOH5C.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\compiledMethodLoad\lib\compiledMethodLoad.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\javafxpackager.exe (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\Program Files\Onset Computer Corporation\HOBOware\jre\jre\bin\is-CD8VL.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\is-PTUQN.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\gctest\lib\is-37O9C.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\minst\lib\minst.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\Program Files\Onset Computer Corporation\HOBOware\jre\jre\bin\is-COE29.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\Program Files\Onset Computer Corporation\HOBOware\jre\jre\bin\is-9KAEP.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\Program Files\Onset Computer Corporation\HOBOware\jre\jre\bin\is-5RR6V.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\Program Files\Onset Computer Corporation\HOBOware\jre\jre\bin\is-KMRET.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\Program Files\Onset Computer Corporation\HOBOware\jre\jre\bin\is-HSFOC.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\heapViewer\lib\heapViewer.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\Program Files\Onset Computer Corporation\HOBOware\jre\jre\bin\is-QB9S6.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\jfr.exe (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\Program Files\Onset Computer Corporation\HOBOware\jre\jre\bin\is-C30LE.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\Program Files\Onset Computer Corporation\HOBOware\jre\jre\bin\is-C6HO5.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\versionCheck\lib\is-LLDP7.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\Program Files\Onset Computer Corporation\HOBOware\jre\jre\bin\is-VOVOC.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\is-BJ05A.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\is-UGAPM.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\jar.exe (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\Program Files\Onset Computer Corporation\HOBOware\jre\jre\bin\is-D2KM5.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\Program Files\Onset Computer Corporation\HOBOware\jre\jre\bin\is-QQB3H.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\hprof\lib\hprof.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\Program Files\Onset Computer Corporation\HOBOware\jre\jre\bin\is-HMVH7.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\is-GP6ER.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\waiters\lib\waiters.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\extcheck.exe (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\Program Files\Onset Computer Corporation\HOBOware\jre\jre\bin\is-TQAMI.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\jmap.exe (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\Program Files\Onset Computer Corporation\HOBOware\jre\jre\bin\is-CDUKR.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\Program Files\Onset Computer Corporation\HOBOware\jre\jre\bin\is-DEMS9.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\java-rmi.exe (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\is-CS9LO.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\Program Files\Onset Computer Corporation\HOBOware\jre\jre\bin\is-V6MOG.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\is-8PMPD.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\is-B55AO.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\is-NR0FN.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\Program Files\Onset Computer Corporation\HOBOware\jre\jre\bin\is-I74II.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\Program Files\Onset Computer Corporation\HOBOware\jre\jre\bin\is-DAK19.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\jhat.exe (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\minst\lib\is-GORJU.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\versionCheck\lib\versionCheck.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\Program Files\Onset Computer Corporation\HOBOware\jre\jre\bin\is-E5VKU.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\javaw.exe (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\jrunscript.exe (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\Program Files\Onset Computer Corporation\HOBOware\jre\jre\bin\is-PDH0O.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\Program Files\Onset Computer Corporation\HOBOware\jre\jre\bin\is-HKNMP.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\Program Files\Onset Computer Corporation\HOBOware\jre\jre\bin\is-UMRUB.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\Program Files\Onset Computer Corporation\HOBOware\jre\demo\jvmti\waiters\lib\waiters.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\Program Files\Onset Computer Corporation\HOBOware\jre\jre\bin\is-2I5GK.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\Program Files\Onset Computer Corporation\HOBOware\jre\jre\bin\is-FAOLC.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\is-5OKK1.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\jli.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\gctest\lib\gctest.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\Program Files\Onset Computer Corporation\HOBOware\jre\jre\bin\is-KS9D4.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\javapackager.exe (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\Program Files\Onset Computer Corporation\HOBOware\jre\jre\bin\is-6DSAD.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\Program Files\Onset Computer Corporation\HOBOware\jre\jre\bin\is-GQ8ND.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\waiters\lib\is-L4D3S.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\Program Files\Onset Computer Corporation\HOBOware\jre\jre\bin\is-RGJ5T.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\Program Files\Onset Computer Corporation\HOBOware\jre\jre\bin\is-CIHJ2.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\heapViewer\lib\is-IKL45.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\Program Files\Onset Computer Corporation\HOBOware\jre\jre\bin\is-BKL1O.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\Program Files\Onset Computer Corporation\HOBOware\jre\jre\bin\is-HU7AF.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\heapTracker\lib\is-TS6PT.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\Program Files\Onset Computer Corporation\HOBOware\jre\jre\bin\is-79D08.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\is-J87GN.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\is-AP00G.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\Program Files\Onset Computer Corporation\HOBOware\jre\jre\bin\is-JGC1A.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\is-7N244.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\mtrace\lib\mtrace.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\Program Files\Onset Computer Corporation\HOBOware\jre\jre\bin\is-616LL.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\javap.exe (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\Program Files\Onset Computer Corporation\HOBOware\jre\jre\bin\is-I5DKL.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\jdb.exe (copy)Jump to dropped file
Source: C:\Users\user\Desktop\download\HOBOware_Free_Setup.exeFile created: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\is-J41FD.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\Program Files\Onset Computer Corporation\HOBOware\jre\jre\bin\is-BOQ76.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\Program Files\Onset Computer Corporation\HOBOware\jre\jre\bin\is-5BHRH.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\Program Files\Onset Computer Corporation\HOBOware\jre\jre\bin\is-HHC01.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\Program Files\Onset Computer Corporation\HOBOware\jre\jre\bin\is-DSJP5.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\Program Files\Onset Computer Corporation\HOBOware\jre\jre\bin\is-SQJHN.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\Program Files\Onset Computer Corporation\HOBOware\jre\jre\bin\is-K5E33.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\heapTracker\lib\heapTracker.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\Program Files\Onset Computer Corporation\HOBOware\jre\jre\bin\is-DA5UI.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\Program Files\Onset Computer Corporation\HOBOware\jre\jre\bin\is-1Q0UP.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\Program Files\Onset Computer Corporation\HOBOware\jre\jre\bin\is-NCN86.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\Program Files\Onset Computer Corporation\HOBOware\jre\demo\jvmti\waiters\lib\is-OLGAK.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\is-U4D40.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\Program Files\Onset Computer Corporation\HOBOware\jre\jre\bin\is-7FQOO.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\is-EQPTF.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\is-HJSIP.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\Program Files\Onset Computer Corporation\HOBOware\jre\jre\bin\is-Q7GT8.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\javac.exe (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\Users\user\AppData\Local\Temp\Setup Log 2024-06-18 #001.txtJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEFile created: C:\Program Files\Onset Computer Corporation\HOBOware\~$README.rtfJump to behavior

Boot Survival

barindex
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpRegistry value created or modified: HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000 RegFiles0000 C:\Program Files\Onset Computer Corporation\HOBOware\HOBOware.exeC:\Program Files\Onset Computer Corporation\HOBOware\jspWin.dllC:\Program Files\Onset Computer Corporation\HOBOware\ICE_JNIRegistry.dllC:\Program Files\Onset Computer Corporation\HOBOware\ousb.dllC:\Program Files\Onset Computer Corporation\HOBOware\ousbce.dllC:\Program Files\Onset Computer Corporation\HOBOware\WinFoldersJava_x64-1.1.dllC:\Program Files\Onset Computer Corporation\HOBOware\JavaDLL.dllC:\Program Files\Onset Computer Corporation\HOBOware\Microsoft.VC80.CRT\msvcm80.dllC:\Program Files\Onset Computer Corporation\HOBOware\Microsoft.VC80.CRT\msvcp80.dllC:\Program Files\Onset Computer Corporation\HOBOware\Microsoft.VC80.CRT\msvcr80.dllC:\Program Files\Onset Computer Corporation\HOBOware\jre2\bin\appletviewer.exeC:\Program Files\Onset Computer Corporation\HOBOware\jre2\bin\clhsdb.exeC:\Program Files\Onset Computer Corporation\HOBOware\jre2\bin\extcheck.exeC:\Program Files\Onset Computer Corporation\HOBOware\jre2\bin\hsdb.exeC:\Program Files\Onset Computer Corporation\HOBOware\jre2\bin\idlj.exeC:\Program Files\Onset Computer Corporation\HOBOware\jre2\bin\jabswitch.exeC:\Program Files\Onset Computer Corporation\HOBOware\jre2\bin\jar.exeC:\Program Files\Onset Computer Corporation\HOBOware\jre2\bin\jarsigner.exeC:\Program Files\Onset Computer Corporation\HOBOware\jre2\bin\java-rmi.exeC:\Program Files\Onset Computer Corporation\HOBOware\jre2\bin\java.exeC:\Program Files\Onset Computer Corporation\HOBOware\jre2\bin\javac.exeC:\Program Files\Onset Computer Corporation\HOBOware\jre2\bin\javadoc.exeC:\Program Files\Onset Computer Corporation\HOBOware\jre2\bin\javafxpackager.exeC:\Program Files\Onset Computer Corporation\HOBOware\jre2\bin\javah.exeC:\Program Files\Onset Computer Corporation\HOBOware\jre2\bin\javap.exeC:\Program Files\Onset Computer Corporation\HOBOware\jre2\bin\javapackager.exeC:\Program Files\Onset Computer Corporation\HOBOware\jre2\bin\javaw.exeC:\Program Files\Onset Computer Corporation\HOBOware\jre2\bin\jJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Onset Applications\HOBOware\HOBOware.lnkJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpFile created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Onset Applications\HOBOware\Uninstall HOBOware.lnkJump to behavior
Source: C:\Users\user\Desktop\download\HOBOware_Free_Setup.exeProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpProcess created: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpProcess created: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDropped PE file which has not been started: C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\is-A2ADD.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDropped PE file which has not been started: C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\is-EEV09.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDropped PE file which has not been started: C:\Program Files\Onset Computer Corporation\HOBOware\jre\jre\bin\is-S4H4U.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDropped PE file which has not been started: C:\Program Files\Onset Computer Corporation\HOBOware\jre\jre\bin\is-PLTIL.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDropped PE file which has not been started: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\mtrace\lib\is-SPAP0.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDropped PE file which has not been started: C:\Program Files\Onset Computer Corporation\HOBOware\jre\jre\bin\is-NVV99.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDropped PE file which has not been started: C:\Program Files\Onset Computer Corporation\HOBOware\jre\jre\bin\is-JF24I.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDropped PE file which has not been started: C:\Program Files\Onset Computer Corporation\HOBOware\jre\jre\bin\is-G7JA2.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDropped PE file which has not been started: C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\is-GRUKG.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDropped PE file which has not been started: C:\Program Files\Onset Computer Corporation\HOBOware\jre\jre\bin\is-HP85J.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDropped PE file which has not been started: C:\Program Files\Onset Computer Corporation\HOBOware\jre\jre\bin\is-V704D.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDropped PE file which has not been started: C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\jdeps.exe (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDropped PE file which has not been started: C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\jsadebugd.exe (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDropped PE file which has not been started: C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\javadoc.exe (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDropped PE file which has not been started: C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\appletviewer.exe (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDropped PE file which has not been started: C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\jstat.exe (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDropped PE file which has not been started: C:\Program Files\Onset Computer Corporation\HOBOware\jre\jre\bin\is-2LBJ9.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDropped PE file which has not been started: C:\Program Files\Onset Computer Corporation\HOBOware\jre\jre\bin\is-TIJ0O.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDropped PE file which has not been started: C:\Program Files\Onset Computer Corporation\HOBOware\jre\jre\bin\is-9RFGE.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDropped PE file which has not been started: C:\Program Files\Onset Computer Corporation\HOBOware\jre\jre\bin\is-R9ECQ.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDropped PE file which has not been started: C:\Program Files\Onset Computer Corporation\HOBOware\jre\jre\bin\is-4PL6E.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDropped PE file which has not been started: C:\Program Files\Onset Computer Corporation\HOBOware\jre\jre\bin\is-9D3ES.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDropped PE file which has not been started: C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\java.exe (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDropped PE file which has not been started: C:\Program Files\Onset Computer Corporation\HOBOware\jre\jre\bin\is-BBOH3.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDropped PE file which has not been started: C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\jinfo.exe (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDropped PE file which has not been started: C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\idlj.exe (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDropped PE file which has not been started: C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\jconsole.exe (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDropped PE file which has not been started: C:\Program Files\Onset Computer Corporation\HOBOware\jre\jre\bin\is-BCVNP.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDropped PE file which has not been started: C:\Program Files\Onset Computer Corporation\HOBOware\jre\jre\bin\is-OT4TQ.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDropped PE file which has not been started: C:\Program Files\Onset Computer Corporation\HOBOware\jre\jre\bin\is-M86V1.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDropped PE file which has not been started: C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\jjs.exe (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDropped PE file which has not been started: C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\jabswitch.exe (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDropped PE file which has not been started: C:\Program Files\Onset Computer Corporation\HOBOware\jre\jre\bin\is-7GHQB.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDropped PE file which has not been started: C:\Program Files\Onset Computer Corporation\HOBOware\jre\jre\bin\is-CLGV2.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDropped PE file which has not been started: C:\Program Files\Onset Computer Corporation\HOBOware\jre\jre\bin\is-NIL39.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDropped PE file which has not been started: C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\is-4I29T.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDropped PE file which has not been started: C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\is-RHBO1.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDropped PE file which has not been started: C:\Program Files\Onset Computer Corporation\HOBOware\jre\jre\bin\is-BSO9P.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDropped PE file which has not been started: C:\Program Files\Onset Computer Corporation\HOBOware\jre\jre\bin\is-O0KMU.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDropped PE file which has not been started: C:\Program Files\Onset Computer Corporation\HOBOware\jre\jre\bin\is-H45AQ.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDropped PE file which has not been started: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\hprof\lib\is-U8BTR.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDropped PE file which has not been started: C:\Program Files\Onset Computer Corporation\HOBOware\jre\jre\bin\is-RNC4U.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDropped PE file which has not been started: C:\Program Files\Onset Computer Corporation\HOBOware\jre\jre\bin\is-70I4A.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDropped PE file which has not been started: C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\hsdb.exe (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDropped PE file which has not been started: C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\is-EMP87.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDropped PE file which has not been started: C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\is-7BV7A.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDropped PE file which has not been started: C:\Program Files\Onset Computer Corporation\HOBOware\jre\jre\bin\is-PEOBO.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDropped PE file which has not been started: C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\javah.exe (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDropped PE file which has not been started: C:\Program Files\Onset Computer Corporation\HOBOware\jre\jre\bin\is-E55HV.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDropped PE file which has not been started: C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\is-LJ3FO.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDropped PE file which has not been started: C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\jarsigner.exe (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDropped PE file which has not been started: C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\jcmd.exe (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDropped PE file which has not been started: C:\Program Files\Onset Computer Corporation\HOBOware\jre\jre\bin\is-LL20H.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDropped PE file which has not been started: C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\is-PANRP.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDropped PE file which has not been started: C:\Program Files\Onset Computer Corporation\HOBOware\jre\jre\bin\is-CHQEV.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDropped PE file which has not been started: C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\is-BO8O1.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDropped PE file which has not been started: C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\is-TGBD8.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDropped PE file which has not been started: C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\is-THC28.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDropped PE file which has not been started: C:\Program Files\Onset Computer Corporation\HOBOware\jre\jre\bin\is-R10L8.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDropped PE file which has not been started: C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\jstack.exe (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDropped PE file which has not been started: C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\is-NFS6P.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDropped PE file which has not been started: C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\clhsdb.exe (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDropped PE file which has not been started: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\compiledMethodLoad\lib\is-PNBTC.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDropped PE file which has not been started: C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\jps.exe (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDropped PE file which has not been started: C:\Program Files\Onset Computer Corporation\HOBOware\jre\jre\bin\is-VEE83.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDropped PE file which has not been started: C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\is-RML27.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDropped PE file which has not been started: C:\Program Files\Onset Computer Corporation\HOBOware\jre\jre\bin\is-P9QHD.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDropped PE file which has not been started: C:\Program Files\Onset Computer Corporation\HOBOware\jre\jre\bin\is-1RJ9E.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDropped PE file which has not been started: C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\is-IIATI.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDropped PE file which has not been started: C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\is-IOH5C.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDropped PE file which has not been started: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\compiledMethodLoad\lib\compiledMethodLoad.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDropped PE file which has not been started: C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\javafxpackager.exe (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDropped PE file which has not been started: C:\Program Files\Onset Computer Corporation\HOBOware\jre\jre\bin\is-CD8VL.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDropped PE file which has not been started: C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\is-PTUQN.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDropped PE file which has not been started: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\gctest\lib\is-37O9C.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDropped PE file which has not been started: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\minst\lib\minst.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDropped PE file which has not been started: C:\Program Files\Onset Computer Corporation\HOBOware\jre\jre\bin\is-9KAEP.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDropped PE file which has not been started: C:\Program Files\Onset Computer Corporation\HOBOware\jre\jre\bin\is-COE29.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDropped PE file which has not been started: C:\Program Files\Onset Computer Corporation\HOBOware\jre\jre\bin\is-5RR6V.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDropped PE file which has not been started: C:\Program Files\Onset Computer Corporation\HOBOware\jre\jre\bin\is-HSFOC.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDropped PE file which has not been started: C:\Program Files\Onset Computer Corporation\HOBOware\jre\jre\bin\is-KMRET.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDropped PE file which has not been started: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\heapViewer\lib\heapViewer.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDropped PE file which has not been started: C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\jfr.exe (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDropped PE file which has not been started: C:\Program Files\Onset Computer Corporation\HOBOware\jre\jre\bin\is-QB9S6.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDropped PE file which has not been started: C:\Program Files\Onset Computer Corporation\HOBOware\jre\jre\bin\is-C6HO5.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDropped PE file which has not been started: C:\Program Files\Onset Computer Corporation\HOBOware\jre\jre\bin\is-C30LE.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDropped PE file which has not been started: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\versionCheck\lib\is-LLDP7.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDropped PE file which has not been started: C:\Program Files\Onset Computer Corporation\HOBOware\jre\jre\bin\is-VOVOC.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDropped PE file which has not been started: C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\is-BJ05A.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDropped PE file which has not been started: C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\is-UGAPM.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDropped PE file which has not been started: C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\jar.exe (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDropped PE file which has not been started: C:\Program Files\Onset Computer Corporation\HOBOware\jre\jre\bin\is-D2KM5.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDropped PE file which has not been started: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\hprof\lib\hprof.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDropped PE file which has not been started: C:\Program Files\Onset Computer Corporation\HOBOware\jre\jre\bin\is-QQB3H.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDropped PE file which has not been started: C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\is-GP6ER.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDropped PE file which has not been started: C:\Program Files\Onset Computer Corporation\HOBOware\jre\jre\bin\is-HMVH7.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDropped PE file which has not been started: C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\extcheck.exe (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDropped PE file which has not been started: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\waiters\lib\waiters.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDropped PE file which has not been started: C:\Program Files\Onset Computer Corporation\HOBOware\jre\jre\bin\is-TQAMI.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDropped PE file which has not been started: C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\jmap.exe (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDropped PE file which has not been started: C:\Program Files\Onset Computer Corporation\HOBOware\jre\jre\bin\is-CDUKR.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDropped PE file which has not been started: C:\Program Files\Onset Computer Corporation\HOBOware\jre\jre\bin\is-DEMS9.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDropped PE file which has not been started: C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\java-rmi.exe (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDropped PE file which has not been started: C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\is-CS9LO.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDropped PE file which has not been started: C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\is-8PMPD.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDropped PE file which has not been started: C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\is-B55AO.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDropped PE file which has not been started: C:\Program Files\Onset Computer Corporation\HOBOware\jre\jre\bin\is-V6MOG.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDropped PE file which has not been started: C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\is-NR0FN.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDropped PE file which has not been started: C:\Program Files\Onset Computer Corporation\HOBOware\jre\jre\bin\is-DAK19.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDropped PE file which has not been started: C:\Program Files\Onset Computer Corporation\HOBOware\jre\jre\bin\is-I74II.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDropped PE file which has not been started: C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\jhat.exe (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDropped PE file which has not been started: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\minst\lib\is-GORJU.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDropped PE file which has not been started: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\versionCheck\lib\versionCheck.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDropped PE file which has not been started: C:\Program Files\Onset Computer Corporation\HOBOware\jre\jre\bin\is-E5VKU.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDropped PE file which has not been started: C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\javaw.exe (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDropped PE file which has not been started: C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\jrunscript.exe (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDropped PE file which has not been started: C:\Program Files\Onset Computer Corporation\HOBOware\jre\jre\bin\is-PDH0O.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDropped PE file which has not been started: C:\Program Files\Onset Computer Corporation\HOBOware\jre\demo\jvmti\waiters\lib\waiters.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDropped PE file which has not been started: C:\Program Files\Onset Computer Corporation\HOBOware\jre\jre\bin\is-UMRUB.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDropped PE file which has not been started: C:\Program Files\Onset Computer Corporation\HOBOware\jre\jre\bin\is-HKNMP.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDropped PE file which has not been started: C:\Program Files\Onset Computer Corporation\HOBOware\jre\jre\bin\is-2I5GK.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDropped PE file which has not been started: C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\is-5OKK1.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDropped PE file which has not been started: C:\Program Files\Onset Computer Corporation\HOBOware\jre\jre\bin\is-FAOLC.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDropped PE file which has not been started: C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\jli.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDropped PE file which has not been started: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\gctest\lib\gctest.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDropped PE file which has not been started: C:\Program Files\Onset Computer Corporation\HOBOware\jre\jre\bin\is-KS9D4.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDropped PE file which has not been started: C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\javapackager.exe (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDropped PE file which has not been started: C:\Program Files\Onset Computer Corporation\HOBOware\jre\jre\bin\is-6DSAD.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDropped PE file which has not been started: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\waiters\lib\is-L4D3S.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDropped PE file which has not been started: C:\Program Files\Onset Computer Corporation\HOBOware\jre\jre\bin\is-GQ8ND.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDropped PE file which has not been started: C:\Program Files\Onset Computer Corporation\HOBOware\jre\jre\bin\is-RGJ5T.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDropped PE file which has not been started: C:\Program Files\Onset Computer Corporation\HOBOware\jre\jre\bin\is-CIHJ2.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDropped PE file which has not been started: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\heapViewer\lib\is-IKL45.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDropped PE file which has not been started: C:\Program Files\Onset Computer Corporation\HOBOware\jre\jre\bin\is-HU7AF.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDropped PE file which has not been started: C:\Program Files\Onset Computer Corporation\HOBOware\jre\jre\bin\is-BKL1O.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDropped PE file which has not been started: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\heapTracker\lib\is-TS6PT.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDropped PE file which has not been started: C:\Program Files\Onset Computer Corporation\HOBOware\jre\jre\bin\is-79D08.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDropped PE file which has not been started: C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\is-J87GN.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDropped PE file which has not been started: C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\is-AP00G.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDropped PE file which has not been started: C:\Program Files\Onset Computer Corporation\HOBOware\jre\jre\bin\is-JGC1A.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDropped PE file which has not been started: C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\is-7N244.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDropped PE file which has not been started: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\mtrace\lib\mtrace.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDropped PE file which has not been started: C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\javap.exe (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDropped PE file which has not been started: C:\Program Files\Onset Computer Corporation\HOBOware\jre\jre\bin\is-616LL.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDropped PE file which has not been started: C:\Program Files\Onset Computer Corporation\HOBOware\jre\jre\bin\is-I5DKL.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDropped PE file which has not been started: C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\jdb.exe (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDropped PE file which has not been started: C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\is-J41FD.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDropped PE file which has not been started: C:\Program Files\Onset Computer Corporation\HOBOware\jre\jre\bin\is-BOQ76.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDropped PE file which has not been started: C:\Program Files\Onset Computer Corporation\HOBOware\jre\jre\bin\is-HHC01.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDropped PE file which has not been started: C:\Program Files\Onset Computer Corporation\HOBOware\jre\jre\bin\is-5BHRH.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDropped PE file which has not been started: C:\Program Files\Onset Computer Corporation\HOBOware\jre\jre\bin\is-SQJHN.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDropped PE file which has not been started: C:\Program Files\Onset Computer Corporation\HOBOware\jre\jre\bin\is-DSJP5.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDropped PE file which has not been started: C:\Program Files\Onset Computer Corporation\HOBOware\jre\jre\bin\is-K5E33.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDropped PE file which has not been started: C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\heapTracker\lib\heapTracker.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDropped PE file which has not been started: C:\Program Files\Onset Computer Corporation\HOBOware\jre\jre\bin\is-DA5UI.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDropped PE file which has not been started: C:\Program Files\Onset Computer Corporation\HOBOware\jre\jre\bin\is-1Q0UP.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDropped PE file which has not been started: C:\Program Files\Onset Computer Corporation\HOBOware\jre\jre\bin\is-NCN86.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDropped PE file which has not been started: C:\Program Files\Onset Computer Corporation\HOBOware\jre\demo\jvmti\waiters\lib\is-OLGAK.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDropped PE file which has not been started: C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\is-U4D40.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDropped PE file which has not been started: C:\Program Files\Onset Computer Corporation\HOBOware\jre\jre\bin\is-7FQOO.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDropped PE file which has not been started: C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\is-EQPTF.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDropped PE file which has not been started: C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\is-HJSIP.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDropped PE file which has not been started: C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\javac.exe (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpDropped PE file which has not been started: C:\Program Files\Onset Computer Corporation\HOBOware\jre\jre\bin\is-Q7GT8.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpKey opened: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Keyboard Layouts\08070809Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpKey opened: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Keyboard Layouts\04070809Jump to behavior
Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
Source: is-AB5UO.tmp.10.drBinary or memory string: java/lang/VirtualMachineError.javaUT
Source: is-AB5UO.tmp.10.drBinary or memory string: com/sun/tools/jdi/VirtualMachineManagerImpl.javaUT
Source: is-AB5UO.tmp.10.drBinary or memory string: com/sun/tools/jdi/VirtualMachineImpl.javaUT
Source: is-AB5UO.tmp.10.drBinary or memory string: com/sun/jdi/VirtualMachine.javaUT
Source: is-AB5UO.tmp.10.drBinary or memory string: com/sun/jdi/VirtualMachineManager.javaUT
Source: is-AB5UO.tmp.10.drBinary or memory string: com/sun/tools/attach/VirtualMachineDescriptor.javaUT
Source: is-AB5UO.tmp.10.drBinary or memory string: com/sun/tools/jdi/VirtualMachineManagerService.javaUT
Source: is-AB5UO.tmp.10.drBinary or memory string: com/sun/jdi/PathSearchingVirtualMachine.javaUT
Source: is-AB5UO.tmp.10.drBinary or memory string: com/sun/tools/attach/VirtualMachine.javaUT
Source: wget.exe, 00000002.00000002.3834816449.0000000000C28000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dll
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpProcess information queried: ProcessInformationJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpProcess created: C:\Users\user\AppData\Local\Temp\is-SE99M.tmp\_isetup\_setup64.tmp helper 105 0x4C4Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpProcess created: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE "C:\Program Files (x86)\Microsoft Office\Root\Office16\WINWORD.EXE" /n "C:\Program Files\Onset Computer Corporation\HOBOware\README.rtf" /o ""Jump to behavior
Source: unknownProcess created: C:\Windows\SysWOW64\cmd.exe c:\windows\system32\cmd.exe /c wget -t 2 -v -t 60 -p "c:\users\user\desktop\download" --no-check-certificate --content-disposition --user-agent="mozilla/5.0 (windows nt 6.1; wow64; trident/7.0; as; rv:11.0) like gecko" "https://onset2.onsetcomp.com/files/software/hoboware/3.7.28/hoboware_free_setup.exe" > cmdline.out 2>&1
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\wget.exe wget -t 2 -v -t 60 -p "c:\users\user\desktop\download" --no-check-certificate --content-disposition --user-agent="mozilla/5.0 (windows nt 6.1; wow64; trident/7.0; as; rv:11.0) like gecko" "https://onset2.onsetcomp.com/files/software/hoboware/3.7.28/hoboware_free_setup.exe"
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\wget.exe wget -t 2 -v -t 60 -p "c:\users\user\desktop\download" --no-check-certificate --content-disposition --user-agent="mozilla/5.0 (windows nt 6.1; wow64; trident/7.0; as; rv:11.0) like gecko" "https://onset2.onsetcomp.com/files/software/hoboware/3.7.28/hoboware_free_setup.exe" Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-SE99M.tmp\_isetup\_setup64.tmpCode function: 12_2_0000000140001000 GetNamedSecurityInfoW,AllocateAndInitializeSid,SetEntriesInAclW,SetNamedSecurityInfoW,LocalFree,FreeSid,LocalFree,GetLastError,12_2_0000000140001000
Source: C:\Windows\SysWOW64\wget.exeQueries volume information: C:\Users\user\Desktop\download VolumeInformationJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpQueries volume information: C:\ VolumeInformationJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpQueries volume information: C:\ VolumeInformationJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmpQueries volume information: C:\ VolumeInformationJump to behavior
Source: C:\Windows\SysWOW64\wget.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuidJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-SE99M.tmp\_isetup\_setup64.tmpDirectory queried: C:\Users\Public\Documents\HOBOware Public Files\ConfigsJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-SE99M.tmp\_isetup\_setup64.tmpDirectory queried: C:\Users\Public\Documents\HOBOware Public Files\ConfigsJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-SE99M.tmp\_isetup\_setup64.tmpDirectory queried: C:\Users\Public\Documents\HOBOware Public Files\FWUpdatesJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-SE99M.tmp\_isetup\_setup64.tmpDirectory queried: C:\Users\Public\Documents\HOBOware Public Files\FWUpdatesJump to behavior
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid Accounts1
Windows Management Instrumentation
1
Windows Service
1
Windows Service
3
Masquerading
OS Credential Dumping1
Security Software Discovery
Remote Services1
Data from Local System
Data ObfuscationExfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault Accounts12
Command and Scripting Interpreter
11
Registry Run Keys / Startup Folder
11
Process Injection
11
Process Injection
LSASS Memory1
Process Discovery
Remote Desktop ProtocolData from Removable MediaJunk DataExfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain Accounts1
Native API
1
DLL Side-Loading
11
Registry Run Keys / Startup Folder
1
DLL Side-Loading
Security Account Manager2
System Owner/User Discovery
SMB/Windows Admin SharesData from Network Shared DriveSteganographyAutomated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin Hook1
DLL Side-Loading
1
Extra Window Memory Injection
NTDS11
File and Directory Discovery
Distributed Component Object ModelInput CaptureProtocol ImpersonationTraffic DuplicationData Destruction
Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon Script1
Extra Window Memory Injection
Software PackingLSA Secrets24
System Information Discovery
SSHKeyloggingFallback ChannelsScheduled TransferData Encrypted for Impact
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 process2 2 Behavior Graph ID: 1458958 URL: https://onset2.onsetcomp.co... Startdate: 18/06/2024 Architecture: WINDOWS Score: 48 7 HOBOware_Free_Setup.exe 2 2->7         started        10 cmd.exe 2 2->10         started        file3 28 C:\Users\user\...\HOBOware_Free_Setup.tmp, PE32 7->28 dropped 12 HOBOware_Free_Setup.tmp 90 1012 7->12         started        16 wget.exe 2 10->16         started        19 conhost.exe 10->19         started        process4 dnsIp5 30 C:\Users\Public\Documents\...\is-BE2CP.tmp, DOS 12->30 dropped 32 C:\Users\Public\Documents\...\is-3HC3I.tmp, DOS 12->32 dropped 34 C:\Program Files\...\is-VOVOC.tmp, PE32+ 12->34 dropped 38 165 other files (none is malicious) 12->38 dropped 48 Creates autostart registry keys to launch java 12->48 21 WINWORD.EXE 128 449 12->21         started        24 _setup64.tmp 1 12->24         started        40 54.225.184.108 AMAZON-AESUS United States 16->40 36 C:\Users\user\...\HOBOware_Free_Setup.exe, PE32 16->36 dropped 50 Drops large PE files 16->50 file6 signatures7 process8 dnsIp9 42 95.101.111.132 TELEFONICATELXIUSES European Union 21->42 44 40.79.167.8 MICROSOFT-CORP-MSN-AS-BLOCKUS United States 21->44 46 5 other IPs or domains 21->46 26 conhost.exe 24->26         started        process10

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
https://onset2.onsetcomp.com/files/software/hoboware/3.7.28/HOBOware_Free_Setup.exe0%Avira URL Cloudsafe
SourceDetectionScannerLabelLink
C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\compiledMethodLoad\lib\compiledMethodLoad.dll (copy)0%ReversingLabs
C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\compiledMethodLoad\lib\is-PNBTC.tmp0%ReversingLabs
C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\gctest\lib\gctest.dll (copy)0%ReversingLabs
C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\gctest\lib\is-37O9C.tmp0%ReversingLabs
C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\heapTracker\lib\heapTracker.dll (copy)0%ReversingLabs
C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\heapTracker\lib\is-TS6PT.tmp0%ReversingLabs
C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\heapViewer\lib\heapViewer.dll (copy)0%ReversingLabs
C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\heapViewer\lib\is-IKL45.tmp0%ReversingLabs
C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\hprof\lib\hprof.dll (copy)0%ReversingLabs
C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\hprof\lib\is-U8BTR.tmp0%ReversingLabs
C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\minst\lib\is-GORJU.tmp0%ReversingLabs
C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\minst\lib\minst.dll (copy)0%ReversingLabs
C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\mtrace\lib\is-SPAP0.tmp0%ReversingLabs
C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\mtrace\lib\mtrace.dll (copy)0%ReversingLabs
C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\versionCheck\lib\is-LLDP7.tmp0%ReversingLabs
C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\versionCheck\lib\versionCheck.dll (copy)0%ReversingLabs
C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\waiters\lib\is-L4D3S.tmp0%ReversingLabs
C:\Program Files\Onset Computer Corporation\HOBOware\jre2\demo\jvmti\waiters\lib\waiters.dll (copy)0%ReversingLabs
C:\Program Files\Onset Computer Corporation\HOBOware\jre2\sample\scripting\scriptpad\src\scripts\is-OJU99.tmp0%ReversingLabs
C:\Program Files\Onset Computer Corporation\HOBOware\jre2\sample\scripting\scriptpad\src\scripts\memory.sh (copy)0%ReversingLabs
C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\appletviewer.exe (copy)0%ReversingLabs
C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\clhsdb.exe (copy)0%ReversingLabs
C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\extcheck.exe (copy)0%ReversingLabs
C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\hsdb.exe (copy)0%ReversingLabs
C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\idlj.exe (copy)0%ReversingLabs
C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\is-4I29T.tmp0%ReversingLabs
C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\is-5OKK1.tmp0%ReversingLabs
C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\is-7BV7A.tmp0%ReversingLabs
C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\is-7N244.tmp0%ReversingLabs
C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\is-8PMPD.tmp0%ReversingLabs
C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\is-A2ADD.tmp0%ReversingLabs
C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\is-AP00G.tmp0%ReversingLabs
C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\is-B55AO.tmp0%ReversingLabs
C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\is-BJ05A.tmp0%ReversingLabs
C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\is-BO8O1.tmp0%ReversingLabs
C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\is-CS9LO.tmp0%ReversingLabs
C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\is-EEV09.tmp0%ReversingLabs
C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\is-EMP87.tmp0%ReversingLabs
C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\is-EQPTF.tmp0%ReversingLabs
C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\is-GP6ER.tmp0%ReversingLabs
C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\is-GRUKG.tmp0%ReversingLabs
C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\is-HJSIP.tmp0%ReversingLabs
C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\is-IIATI.tmp0%ReversingLabs
C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\is-IOH5C.tmp0%ReversingLabs
C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\is-J41FD.tmp0%ReversingLabs
C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\is-J87GN.tmp0%ReversingLabs
C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\is-LJ3FO.tmp0%ReversingLabs
C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\is-NFS6P.tmp0%ReversingLabs
C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\is-NR0FN.tmp0%ReversingLabs
C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\is-PANRP.tmp0%ReversingLabs
C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\is-PTUQN.tmp0%ReversingLabs
C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\is-RHBO1.tmp0%ReversingLabs
C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\is-RML27.tmp0%ReversingLabs
C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\is-TGBD8.tmp0%ReversingLabs
C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\is-THC28.tmp0%ReversingLabs
C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\is-U4D40.tmp0%ReversingLabs
C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\is-UGAPM.tmp0%ReversingLabs
C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\jabswitch.exe (copy)0%ReversingLabs
C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\jar.exe (copy)0%ReversingLabs
C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\jarsigner.exe (copy)0%ReversingLabs
C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\java-rmi.exe (copy)0%ReversingLabs
C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\java.exe (copy)0%ReversingLabs
C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\javac.exe (copy)0%ReversingLabs
C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\javadoc.exe (copy)0%ReversingLabs
C:\Program Files\Onset Computer Corporation\HOBOware\jre\bin\javafxpackager.exe (copy)0%ReversingLabs
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
http://ocsp.sectigo.com00%URL Reputationsafe
https://www.ips.es/ips2002/ips2002CAC.crl030%Avira URL Cloudsafe
http://crl.chambersign.org/chambersroot.crl00%Avira URL Cloudsafe
http://www.networksolutions.com/legal/SSL-legal-repository-cps.jsp0z0%Avira URL Cloudsafe
http://crl.thawte.com/ThawteTimestampingCA.crl00%URL Reputationsafe
https://www.ips.es/ips2002/00%Avira URL Cloudsafe
https://www.ips.es/ips2002/ips2002Timestamping.crl0F0%Avira URL Cloudsafe
http://www.certifikat.dk/repository00%Avira URL Cloudsafe
https://sectigo.com/CPS00%URL Reputationsafe
https://www.ips.es/ips2002/revocationTimestamping.html?0C0%Avira URL Cloudsafe
http://www.a-cert.at0E0%Avira URL Cloudsafe
http://www.ftdichip.com/FTProducts.htm)0%Avira URL Cloudsafe
http://ocsp.thawte.com00%URL Reputationsafe
http://crl.sectigo.com/SectigoRSATimeStampingCA.crl0t0%URL Reputationsafe
http://www.chambersign.org10%Avira URL Cloudsafe
http://crt.sectigo.com/SectigoRSATimeStampingCA.crt0#0%URL Reputationsafe
http://www.ftdichip.com/Support/Documents/AppNotes/AN_234_FTDI_Drivers_Installation_Guide_for_Window0%Avira URL Cloudsafe
http://repository.eid.belgium.be00%Avira URL Cloudsafe
http://www.pkioverheid.nl/policies/root-policy00%Avira URL Cloudsafe
https://wwwback.ips.es/ips2002/ips2002CLASEA1.crl0/0%Avira URL Cloudsafe
http://www.trustcenter.de/crl/v2/tc_class_3_ca_II.crl0%Avira URL Cloudsafe
http://www.ftdichip.com/FTDrivers.htm)0%Avira URL Cloudsafe
https://www.ips.es/ips2002/ips2002CAC.crl0=0%Avira URL Cloudsafe
http://www.ftdichip.com/Support/Documents/InstallGuides/AN_396%20FTDI%20Drivers%20Installation%20Gui0%Avira URL Cloudsafe
http://www.onsetcomp.com/hobowareYOC0%Avira URL Cloudsafe
https://www.ips.es/ips2002/ips2002CLASE1.crl060%Avira URL Cloudsafe
https://onset2.onsetcomp.com/files/software/hoboware/3.7.28/HOBOware_Free_Setup.exe(owqn0%Avira URL Cloudsafe
https://www.ips.es/ips2002/policyTimestamping.html00%Avira URL Cloudsafe
http://www.innosetup.com/0%Avira URL Cloudsafe
http://www.ftdichip.com/Support/Utilities.htm#Comport_Assignment)0%Avira URL Cloudsafe
https://wwwback.ips.es/ips2002/ips2002CLASEA3.crl0/0%Avira URL Cloudsafe
http://crl.netsolssl.com/NetworkSolutions_CA.crl070%Avira URL Cloudsafe
http://www.ftdichip.com/Support/Utilities.htm#MicrosoftUSBView)0%Avira URL Cloudsafe
https://www.ips.es/ips2002/revocationCLASE3.html?0=0%Avira URL Cloudsafe
http://crl.oces.certifikat.dk/oces.crl00%Avira URL Cloudsafe
https://www.ips.es/ips2002/policyCLASEA3.html0w0%Avira URL Cloudsafe
https://www.ips.es/ips2002/renewalCLASEA3.html?00%Avira URL Cloudsafe
http://www.onsetcomp.com/hobowareQN0%Avira URL Cloudsafe
https://www.beTRUSTed.com/vault/terms010%Avira URL Cloudsafe
https://www.ips.es/ips2002/renewalCLASE3.html?0;0%Avira URL Cloudsafe
http://crl2.netsolssl.com/NetworkSolutions_CA.crl0L0%Avira URL Cloudsafe
http://www.trustcenter.de/guidelines00%Avira URL Cloudsafe
http://www.rootca.or.kr/rca/cps.html00%Avira URL Cloudsafe
https://www.ips.es/ips2002/ips2002CLASE1.crl00%Avira URL Cloudsafe
http://www.entrust.net/CRL/Client1.crl00%Avira URL Cloudsafe
http://www.onsetcomp.com/hoboware0%Avira URL Cloudsafe
https://www.ips.es/ips2002/policyCAC.html0o0%Avira URL Cloudsafe
http://www.entrust.net/CRL/net1.crl00%Avira URL Cloudsafe
https://www.ips.es/ips2002/0;0%Avira URL Cloudsafe
https://www.ips.es/ips2002/080%Avira URL Cloudsafe
https://www.ips.es/ips2002/policyCLASE1.html0u0%Avira URL Cloudsafe
http://www.ftdichip.com/Support/Utilities.htm)0%Avira URL Cloudsafe
https://www.beTRUSTed.com/vault/terms040%Avira URL Cloudsafe
https://www.ips.es/ips2002/ips2002CLASEA3.crl070%Avira URL Cloudsafe
https://www.ips.es/ips2002/0A0%Avira URL Cloudsafe
https://www.ips.es/ips2002/ips2002CLASEA3.crl0A0%Avira URL Cloudsafe
http://crl.chambersign.org/chambersignroot.crl00%Avira URL Cloudsafe
http://crl.xrampsecurity.com/XGCA.crl00%Avira URL Cloudsafe
http://www.ftdichip.com/Drivers/CDM/CDM%20v2.12.24%20WHQL%20Certified.zip0%Avira URL Cloudsafe
http://www.quovadis.bm00%Avira URL Cloudsafe
https://wwwback.ips.es/ips2002/ips2002Timestamping.crl0/0%Avira URL Cloudsafe
https://www.netlock.net/docs0%Avira URL Cloudsafe
https://www.ips.es/ips2002/renewalCAC.html?080%Avira URL Cloudsafe
http://www.trustcenter.de/crl/v2/tc_class_2_ca_II.crl0%Avira URL Cloudsafe
http://www.ftdichip.com/)0%Avira URL Cloudsafe
https://www.ips.es/ips2002/revocationCLASEA1.html?00%Avira URL Cloudsafe
https://wwwback.ips.es/ips2002/ips2002CLASE1.crl0/0%Avira URL Cloudsafe
http://crl.sectigo.com/n0%Avira URL Cloudsafe
http://cps.chambersign.org/cps/chambersroot.html00%Avira URL Cloudsafe
http://www.ftdichip.com/Support/Documents/AppNotes/AN_107_AdvancedDriverOptions_AN_000073.pdf)0%Avira URL Cloudsafe
https://www.ips.es/ips2002/ips2002Timestamping.crl00%Avira URL Cloudsafe
http://www.jrsoftware.org/ishelp/index.php?topic=setupcmdlineSetupU0%Avira URL Cloudsafe
https://onset2.onsetcomp.com/files/software/hoboware/3.7.28/HOBOware_Free_Setup.exeRO0%Avira URL Cloudsafe
https://onset2.onsetcomp.com/files/software/hoboware/3.7.28/HOBOware_Free_Setup.exeData0%Avira URL Cloudsafe
http://www.valicert.com/10%Avira URL Cloudsafe
https://wwwback.ips.es/ips2002/ips2002CAC.crl0/0%Avira URL Cloudsafe
https://www.ips.es/ips2002/revocationCLASE1.html?0=0%Avira URL Cloudsafe
https://onset2.onsetcomp.com/files/software/hoboware/3.7.28/HOBOware_Free_Setu0%Avira URL Cloudsafe
https://ocsp.quovadisoffshore.com00%Avira URL Cloudsafe
https://www.ips.es/ips2002/revocationCAC.html?0:0%Avira URL Cloudsafe
https://www.ips.es/ips2002/renewalTimestamping.html?0A0%Avira URL Cloudsafe
http://www.netsolssl.com/NetworkSolutions_CA.crt00%Avira URL Cloudsafe
http://www.ftdichip.com/Support/Utilities.htm#CDMUninstaller)0%Avira URL Cloudsafe
https://www.ips.es/ips2002/ips2002CLASE3.crl00%Avira URL Cloudsafe
https://www.ips.es/ips2002/renewalCLASEA1.html?00%Avira URL Cloudsafe
http://www.ftdichip.com/Support/Documents/AppNotes/AN_119_FTDI_Drivers_Installation_Guide_for_Window0%Avira URL Cloudsafe
http://cps.chambersign.org/cps/chambersignroot.html00%Avira URL Cloudsafe
http://www.onsetcomp.com/hobowareQNC0%Avira URL Cloudsafe
https://wwwback.ips.es/ips2002/ips2002CLASE3.crl0/0%Avira URL Cloudsafe
http://www.a-cert.at/certificate-policy.html0;0%Avira URL Cloudsafe
http://crt.sectigo.com/SectigoPublicCodeSigningCAR36.crt0#0%Avira URL Cloudsafe
https://www.ips.es/ips2002/renewalCLASE1.html?0;0%Avira URL Cloudsafe
https://www.ips.es/ips2002/policyCLASEA1.html0w0%Avira URL Cloudsafe
https://www.ips.es/ips2002/ips2002CLASEA1.crl070%Avira URL Cloudsafe
https://www.ips.es/ips2002/ips2002CLASEA1.crl0A0%Avira URL Cloudsafe
https://www.ips.es/ips2002/policyCLASE3.html0u0%Avira URL Cloudsafe
http://www.a-cert.at/certificate-policy.html00%Avira URL Cloudsafe
http://crl.sectigo.com/SectigoPublicCodeSigningCAR36.crl0y0%Avira URL Cloudsafe
https://www.ips.es/00%Avira URL Cloudsafe
No contacted domains info
NameSourceMaliciousAntivirus DetectionReputation
http://www.networksolutions.com/legal/SSL-legal-repository-cps.jsp0zis-82F14.tmp.10.drfalse
  • Avira URL Cloud: safe
unknown
https://www.ips.es/ips2002/0is-82F14.tmp.10.drfalse
  • Avira URL Cloud: safe
unknown
http://www.a-cert.at0Eis-82F14.tmp.10.drfalse
  • Avira URL Cloud: safe
unknown
http://crl.chambersign.org/chambersroot.crl0is-82F14.tmp.10.drfalse
  • Avira URL Cloud: safe
unknown
https://www.ips.es/ips2002/ips2002Timestamping.crl0Fis-82F14.tmp.10.drfalse
  • Avira URL Cloud: safe
unknown
https://www.ips.es/ips2002/ips2002CAC.crl03is-82F14.tmp.10.drfalse
  • Avira URL Cloud: safe
unknown
http://www.ftdichip.com/FTProducts.htm)HOBOware_Free_Setup.tmp, 0000000A.00000003.4848425848.0000000006830000.00000004.00001000.00020000.00000000.sdmpfalse
  • Avira URL Cloud: safe
unknown
https://www.ips.es/ips2002/revocationTimestamping.html?0Cis-82F14.tmp.10.drfalse
  • Avira URL Cloud: safe
unknown
http://www.certifikat.dk/repository0is-82F14.tmp.10.drfalse
  • Avira URL Cloud: safe
unknown
http://www.chambersign.org1is-82F14.tmp.10.drfalse
  • Avira URL Cloud: safe
unknown
http://repository.eid.belgium.be0is-82F14.tmp.10.drfalse
  • Avira URL Cloud: safe
unknown
http://www.ftdichip.com/Support/Documents/AppNotes/AN_234_FTDI_Drivers_Installation_Guide_for_WindowHOBOware_Free_Setup.tmp, 0000000A.00000003.4848425848.0000000006830000.00000004.00001000.00020000.00000000.sdmpfalse
  • Avira URL Cloud: safe
unknown
http://www.pkioverheid.nl/policies/root-policy0is-82F14.tmp.10.drfalse
  • Avira URL Cloud: safe
unknown
https://wwwback.ips.es/ips2002/ips2002CLASEA1.crl0/is-82F14.tmp.10.drfalse
  • Avira URL Cloud: safe
unknown
http://www.ftdichip.com/FTDrivers.htm)HOBOware_Free_Setup.tmp, 0000000A.00000003.4848425848.0000000006830000.00000004.00001000.00020000.00000000.sdmpfalse
  • Avira URL Cloud: safe
unknown
http://www.ftdichip.com/Support/Documents/InstallGuides/AN_396%20FTDI%20Drivers%20Installation%20GuiHOBOware_Free_Setup.tmp, 0000000A.00000003.4848425848.0000000006830000.00000004.00001000.00020000.00000000.sdmpfalse
  • Avira URL Cloud: safe
unknown
http://www.trustcenter.de/crl/v2/tc_class_3_ca_II.crlis-82F14.tmp.10.drfalse
  • Avira URL Cloud: safe
unknown
https://www.ips.es/ips2002/ips2002CAC.crl0=is-82F14.tmp.10.drfalse
  • Avira URL Cloud: safe
unknown
http://www.onsetcomp.com/hobowareYOCHOBOware_Free_Setup.tmp, 0000000A.00000003.4865591021.000000000242D000.00000004.00001000.00020000.00000000.sdmpfalse
  • Avira URL Cloud: safe
unknown
https://www.ips.es/ips2002/ips2002CLASE1.crl06is-82F14.tmp.10.drfalse
  • Avira URL Cloud: safe
unknown
https://onset2.onsetcomp.com/files/software/hoboware/3.7.28/HOBOware_Free_Setup.exe(owqnwget.exe, 00000002.00000002.3834959667.00000000012A5000.00000004.00000020.00020000.00000000.sdmpfalse
  • Avira URL Cloud: safe
unknown
https://www.ips.es/ips2002/policyTimestamping.html0is-82F14.tmp.10.drfalse
  • Avira URL Cloud: safe
unknown
https://wwwback.ips.es/ips2002/ips2002CLASEA3.crl0/is-82F14.tmp.10.drfalse
  • Avira URL Cloud: safe
unknown
https://www.ips.es/ips2002/revocationCLASE3.html?0=is-82F14.tmp.10.drfalse
  • Avira URL Cloud: safe
unknown
http://www.innosetup.com/HOBOware_Free_Setup.exe, 00000009.00000003.3871173403.0000000002520000.00000004.00001000.00020000.00000000.sdmp, HOBOware_Free_Setup.exe, 00000009.00000003.3871359047.000000007F570000.00000004.00001000.00020000.00000000.sdmp, HOBOware_Free_Setup.tmp, 0000000A.00000000.3871940847.0000000000401000.00000020.00000001.01000000.00000005.sdmpfalse
  • Avira URL Cloud: safe
unknown
http://crl.netsolssl.com/NetworkSolutions_CA.crl07is-82F14.tmp.10.drfalse
  • Avira URL Cloud: safe
unknown
http://www.ftdichip.com/Support/Utilities.htm#Comport_Assignment)HOBOware_Free_Setup.tmp, 0000000A.00000003.4848425848.0000000006830000.00000004.00001000.00020000.00000000.sdmpfalse
  • Avira URL Cloud: safe
unknown
http://www.ftdichip.com/Support/Utilities.htm#MicrosoftUSBView)HOBOware_Free_Setup.tmp, 0000000A.00000003.4848425848.0000000006830000.00000004.00001000.00020000.00000000.sdmpfalse
  • Avira URL Cloud: safe
unknown
http://crl.oces.certifikat.dk/oces.crl0is-82F14.tmp.10.drfalse
  • Avira URL Cloud: safe
unknown
https://www.ips.es/ips2002/policyCLASEA3.html0wis-82F14.tmp.10.drfalse
  • Avira URL Cloud: safe
unknown
https://www.ips.es/ips2002/renewalCLASEA3.html?0is-82F14.tmp.10.drfalse
  • Avira URL Cloud: safe
unknown
http://www.onsetcomp.com/hobowareQNHOBOware_Free_Setup.exe, 00000009.00000003.4877042183.0000000002274000.00000004.00001000.00020000.00000000.sdmpfalse
  • Avira URL Cloud: safe
unknown
http://crl2.netsolssl.com/NetworkSolutions_CA.crl0Lis-82F14.tmp.10.drfalse
  • Avira URL Cloud: safe
unknown
https://www.ips.es/ips2002/ips2002CLASE1.crl0is-82F14.tmp.10.drfalse
  • Avira URL Cloud: safe
unknown
http://www.rootca.or.kr/rca/cps.html0is-82F14.tmp.10.drfalse
  • Avira URL Cloud: safe
unknown
http://www.trustcenter.de/guidelines0is-82F14.tmp.10.drfalse
  • Avira URL Cloud: safe
unknown
https://www.beTRUSTed.com/vault/terms01is-82F14.tmp.10.drfalse
  • Avira URL Cloud: safe
unknown
https://www.ips.es/ips2002/renewalCLASE3.html?0;is-82F14.tmp.10.drfalse
  • Avira URL Cloud: safe
unknown
http://www.entrust.net/CRL/Client1.crl0is-82F14.tmp.10.drfalse
  • Avira URL Cloud: safe
unknown
http://www.onsetcomp.com/hobowareHOBOware_Free_Setup.exe, 00000009.00000003.4877042183.0000000002274000.00000004.00001000.00020000.00000000.sdmp, HOBOware_Free_Setup.tmp, 0000000A.00000003.4865591021.000000000242D000.00000004.00001000.00020000.00000000.sdmpfalse
  • Avira URL Cloud: safe
unknown
https://www.ips.es/ips2002/policyCAC.html0ois-82F14.tmp.10.drfalse
  • Avira URL Cloud: safe
unknown
https://www.ips.es/ips2002/0;is-82F14.tmp.10.drfalse
  • Avira URL Cloud: safe
unknown
https://www.ips.es/ips2002/policyCLASE1.html0uis-82F14.tmp.10.drfalse
  • Avira URL Cloud: safe
unknown
http://www.entrust.net/CRL/net1.crl0is-82F14.tmp.10.drfalse
  • Avira URL Cloud: safe
unknown
https://www.ips.es/ips2002/08is-82F14.tmp.10.drfalse
  • Avira URL Cloud: safe
unknown
http://www.ftdichip.com/Support/Utilities.htm)HOBOware_Free_Setup.tmp, 0000000A.00000003.4848425848.0000000006830000.00000004.00001000.00020000.00000000.sdmpfalse
  • Avira URL Cloud: safe
unknown
https://www.beTRUSTed.com/vault/terms04is-82F14.tmp.10.drfalse
  • Avira URL Cloud: safe
unknown
https://www.ips.es/ips2002/ips2002CLASEA3.crl07is-82F14.tmp.10.drfalse
  • Avira URL Cloud: safe
unknown
https://www.ips.es/ips2002/ips2002CLASEA3.crl0Ais-82F14.tmp.10.drfalse
  • Avira URL Cloud: safe
unknown
https://www.ips.es/ips2002/0Ais-82F14.tmp.10.drfalse
  • Avira URL Cloud: safe
unknown
http://crl.chambersign.org/chambersignroot.crl0is-82F14.tmp.10.drfalse
  • Avira URL Cloud: safe
unknown
http://crl.xrampsecurity.com/XGCA.crl0is-82F14.tmp.10.drfalse
  • Avira URL Cloud: safe
unknown
http://www.ftdichip.com/Drivers/CDM/CDM%20v2.12.24%20WHQL%20Certified.zipHOBOware_Free_Setup.tmp, 0000000A.00000003.4848425848.0000000006830000.00000004.00001000.00020000.00000000.sdmpfalse
  • Avira URL Cloud: safe
unknown
http://www.quovadis.bm0is-82F14.tmp.10.drfalse
  • Avira URL Cloud: safe
unknown
https://wwwback.ips.es/ips2002/ips2002Timestamping.crl0/is-82F14.tmp.10.drfalse
  • Avira URL Cloud: safe
unknown
https://www.netlock.net/docsis-82F14.tmp.10.drfalse
  • Avira URL Cloud: safe
unknown
http://www.trustcenter.de/crl/v2/tc_class_2_ca_II.crlis-82F14.tmp.10.drfalse
  • Avira URL Cloud: safe
unknown
https://www.ips.es/ips2002/renewalCAC.html?08is-82F14.tmp.10.drfalse
  • Avira URL Cloud: safe
unknown
https://www.ips.es/ips2002/revocationCLASEA1.html?0is-82F14.tmp.10.drfalse
  • Avira URL Cloud: safe
unknown
http://www.ftdichip.com/)HOBOware_Free_Setup.tmp, 0000000A.00000003.4848425848.0000000006830000.00000004.00001000.00020000.00000000.sdmpfalse
  • Avira URL Cloud: safe
unknown
https://wwwback.ips.es/ips2002/ips2002CLASE1.crl0/is-82F14.tmp.10.drfalse
  • Avira URL Cloud: safe
unknown
http://crl.sectigo.com/nwget.exe, 00000002.00000002.3834925180.0000000001167000.00000004.00000020.00020000.00000000.sdmp, wget.exe, 00000002.00000003.3834565014.0000000001167000.00000004.00000020.00020000.00000000.sdmpfalse
  • Avira URL Cloud: safe
unknown
http://ocsp.sectigo.com0wget.exe, 00000002.00000003.3783604847.0000000001156000.00000004.00000020.00020000.00000000.sdmp, wget.exe, 00000002.00000002.3834925180.0000000001167000.00000004.00000020.00020000.00000000.sdmp, wget.exe, 00000002.00000003.3834565014.0000000001167000.00000004.00000020.00020000.00000000.sdmp, wget.exe, 00000002.00000003.3783604847.000000000115E000.00000004.00000020.00020000.00000000.sdmp, wget.exe, 00000002.00000003.3783604847.0000000001167000.00000004.00000020.00020000.00000000.sdmp, HOBOware_Free_Setup.exe, 00000009.00000003.3871173403.000000000263D000.00000004.00001000.00020000.00000000.sdmp, HOBOware_Free_Setup.exe, 00000009.00000003.3871359047.000000007F689000.00000004.00001000.00020000.00000000.sdmpfalse
  • URL Reputation: safe
unknown
https://onset2.onsetcomp.com/files/software/hoboware/3.7.28/HOBOware_Free_Setup.exewget.exe, 00000002.00000002.3834959667.00000000012A0000.00000004.00000020.00020000.00000000.sdmpfalse
    unknown
    http://www.jrsoftware.org/ishelp/index.php?topic=setupcmdlineSetupUHOBOware_Free_Setup.exe, 00000009.00000000.3869477291.0000000000401000.00000020.00000001.01000000.00000004.sdmpfalse
    • Avira URL Cloud: safe
    unknown
    http://cps.chambersign.org/cps/chambersroot.html0is-82F14.tmp.10.drfalse
    • Avira URL Cloud: safe
    unknown
    https://www.ips.es/ips2002/ips2002Timestamping.crl0is-82F14.tmp.10.drfalse
    • Avira URL Cloud: safe
    unknown
    http://www.ftdichip.com/Support/Documents/AppNotes/AN_107_AdvancedDriverOptions_AN_000073.pdf)HOBOware_Free_Setup.tmp, 0000000A.00000003.4848425848.0000000006830000.00000004.00001000.00020000.00000000.sdmpfalse
    • Avira URL Cloud: safe
    unknown
    https://onset2.onsetcomp.com/files/software/hoboware/3.7.28/HOBOware_Free_Setup.exeDatawget.exe, 00000002.00000002.3834959667.00000000012A0000.00000004.00000020.00020000.00000000.sdmpfalse
    • Avira URL Cloud: safe
    unknown
    https://onset2.onsetcomp.com/files/software/hoboware/3.7.28/HOBOware_Free_Setup.exeROwget.exe, 00000002.00000002.3834959667.00000000012A0000.00000004.00000020.00020000.00000000.sdmpfalse
    • Avira URL Cloud: safe
    unknown
    http://crl.thawte.com/ThawteTimestampingCA.crl0HOBOware_Free_Setup.tmp, 0000000A.00000003.4848425848.0000000006830000.00000004.00001000.00020000.00000000.sdmpfalse
    • URL Reputation: safe
    unknown
    https://wwwback.ips.es/ips2002/ips2002CAC.crl0/is-82F14.tmp.10.drfalse
    • Avira URL Cloud: safe
    unknown
    http://www.valicert.com/1is-82F14.tmp.10.drfalse
    • Avira URL Cloud: safe
    unknown
    https://www.ips.es/ips2002/revocationCLASE1.html?0=is-82F14.tmp.10.drfalse
    • Avira URL Cloud: safe
    unknown
    https://onset2.onsetcomp.com/files/software/hoboware/3.7.28/HOBOware_Free_Setuwget.exe, 00000002.00000002.3834816449.0000000000C28000.00000004.00000020.00020000.00000000.sdmpfalse
    • Avira URL Cloud: safe
    unknown
    https://ocsp.quovadisoffshore.com0is-82F14.tmp.10.drfalse
    • Avira URL Cloud: safe
    unknown
    https://www.ips.es/ips2002/renewalTimestamping.html?0Ais-82F14.tmp.10.drfalse
    • Avira URL Cloud: safe
    unknown
    https://www.ips.es/ips2002/revocationCAC.html?0:is-82F14.tmp.10.drfalse
    • Avira URL Cloud: safe
    unknown
    http://www.netsolssl.com/NetworkSolutions_CA.crt0is-82F14.tmp.10.drfalse
    • Avira URL Cloud: safe
    unknown
    https://www.ips.es/ips2002/ips2002CLASE3.crl0is-82F14.tmp.10.drfalse
    • Avira URL Cloud: safe
    unknown
    http://www.ftdichip.com/Support/Utilities.htm#CDMUninstaller)HOBOware_Free_Setup.tmp, 0000000A.00000003.4848425848.0000000006830000.00000004.00001000.00020000.00000000.sdmpfalse
    • Avira URL Cloud: safe
    unknown
    http://cps.chambersign.org/cps/chambersignroot.html0is-82F14.tmp.10.drfalse
    • Avira URL Cloud: safe
    unknown
    http://www.ftdichip.com/Support/Documents/AppNotes/AN_119_FTDI_Drivers_Installation_Guide_for_WindowHOBOware_Free_Setup.tmp, 0000000A.00000003.4848425848.0000000006830000.00000004.00001000.00020000.00000000.sdmpfalse
    • Avira URL Cloud: safe
    unknown
    https://www.ips.es/ips2002/renewalCLASEA1.html?0is-82F14.tmp.10.drfalse
    • Avira URL Cloud: safe
    unknown
    https://sectigo.com/CPS0wget.exe, 00000002.00000003.3783604847.0000000001156000.00000004.00000020.00020000.00000000.sdmp, wget.exe, 00000002.00000002.3834925180.0000000001167000.00000004.00000020.00020000.00000000.sdmp, wget.exe, 00000002.00000003.3834565014.0000000001167000.00000004.00000020.00020000.00000000.sdmp, wget.exe, 00000002.00000003.3783604847.000000000115E000.00000004.00000020.00020000.00000000.sdmp, wget.exe, 00000002.00000003.3783604847.0000000001167000.00000004.00000020.00020000.00000000.sdmp, HOBOware_Free_Setup.exe, 00000009.00000003.3871173403.000000000263D000.00000004.00001000.00020000.00000000.sdmp, HOBOware_Free_Setup.exe, 00000009.00000003.3871359047.000000007F689000.00000004.00001000.00020000.00000000.sdmpfalse
    • URL Reputation: safe
    unknown
    https://wwwback.ips.es/ips2002/ips2002CLASE3.crl0/is-82F14.tmp.10.drfalse
    • Avira URL Cloud: safe
    unknown
    http://www.onsetcomp.com/hobowareQNCHOBOware_Free_Setup.tmp, 0000000A.00000003.4865591021.000000000242D000.00000004.00001000.00020000.00000000.sdmpfalse
    • Avira URL Cloud: safe
    unknown
    http://ocsp.thawte.com0HOBOware_Free_Setup.tmp, 0000000A.00000003.4848425848.0000000006830000.00000004.00001000.00020000.00000000.sdmpfalse
    • URL Reputation: safe
    unknown
    http://crt.sectigo.com/SectigoPublicCodeSigningCAR36.crt0#wget.exe, 00000002.00000003.3783604847.0000000001156000.00000004.00000020.00020000.00000000.sdmp, wget.exe, 00000002.00000003.3783604847.000000000115E000.00000004.00000020.00020000.00000000.sdmp, HOBOware_Free_Setup.exe, 00000009.00000003.3871173403.000000000263D000.00000004.00001000.00020000.00000000.sdmp, HOBOware_Free_Setup.exe, 00000009.00000003.3871359047.000000007F689000.00000004.00001000.00020000.00000000.sdmpfalse
    • Avira URL Cloud: safe
    unknown
    http://www.a-cert.at/certificate-policy.html0;is-82F14.tmp.10.drfalse
    • Avira URL Cloud: safe
    unknown
    https://www.ips.es/ips2002/renewalCLASE1.html?0;is-82F14.tmp.10.drfalse
    • Avira URL Cloud: safe
    unknown
    https://www.ips.es/ips2002/ips2002CLASEA1.crl07is-82F14.tmp.10.drfalse
    • Avira URL Cloud: safe
    unknown
    https://www.ips.es/ips2002/policyCLASEA1.html0wis-82F14.tmp.10.drfalse
    • Avira URL Cloud: safe
    unknown
    https://www.ips.es/ips2002/ips2002CLASEA1.crl0Ais-82F14.tmp.10.drfalse
    • Avira URL Cloud: safe
    unknown
    http://crl.sectigo.com/SectigoRSATimeStampingCA.crl0twget.exe, 00000002.00000003.3783604847.0000000001156000.00000004.00000020.00020000.00000000.sdmp, wget.exe, 00000002.00000003.3783604847.000000000115E000.00000004.00000020.00020000.00000000.sdmp, wget.exe, 00000002.00000003.3783604847.0000000001167000.00000004.00000020.00020000.00000000.sdmp, HOBOware_Free_Setup.exe, 00000009.00000003.3871173403.000000000263D000.00000004.00001000.00020000.00000000.sdmp, HOBOware_Free_Setup.exe, 00000009.00000003.3871359047.000000007F689000.00000004.00001000.00020000.00000000.sdmpfalse
    • URL Reputation: safe
    unknown
    http://crl.sectigo.com/SectigoPublicCodeSigningCAR36.crl0ywget.exe, 00000002.00000003.3783604847.0000000001156000.00000004.00000020.00020000.00000000.sdmp, wget.exe, 00000002.00000003.3783604847.000000000115E000.00000004.00000020.00020000.00000000.sdmp, HOBOware_Free_Setup.exe, 00000009.00000003.3871173403.000000000263D000.00000004.00001000.00020000.00000000.sdmp, HOBOware_Free_Setup.exe, 00000009.00000003.3871359047.000000007F689000.00000004.00001000.00020000.00000000.sdmpfalse
    • Avira URL Cloud: safe
    unknown
    http://www.a-cert.at/certificate-policy.html0is-82F14.tmp.10.drfalse
    • Avira URL Cloud: safe
    unknown
    https://www.ips.es/0is-82F14.tmp.10.drfalse
    • Avira URL Cloud: safe
    unknown
    http://crt.sectigo.com/SectigoRSATimeStampingCA.crt0#wget.exe, 00000002.00000003.3783604847.0000000001156000.00000004.00000020.00020000.00000000.sdmp, wget.exe, 00000002.00000002.3834925180.0000000001167000.00000004.00000020.00020000.00000000.sdmp, wget.exe, 00000002.00000003.3834565014.0000000001167000.00000004.00000020.00020000.00000000.sdmp, wget.exe, 00000002.00000003.3783604847.000000000115E000.00000004.00000020.00020000.00000000.sdmp, wget.exe, 00000002.00000003.3783604847.0000000001167000.00000004.00000020.00020000.00000000.sdmp, HOBOware_Free_Setup.exe, 00000009.00000003.3871173403.000000000263D000.00000004.00001000.00020000.00000000.sdmp, HOBOware_Free_Setup.exe, 00000009.00000003.3871359047.000000007F689000.00000004.00001000.00020000.00000000.sdmpfalse
    • URL Reputation: safe
    unknown
    https://www.ips.es/ips2002/policyCLASE3.html0uis-82F14.tmp.10.drfalse
    • Avira URL Cloud: safe
    unknown
    • No. of IPs < 25%
    • 25% < No. of IPs < 50%
    • 50% < No. of IPs < 75%
    • 75% < No. of IPs
    IPDomainCountryFlagASNASN NameMalicious
    52.113.194.132
    unknownUnited States
    8068MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
    52.109.32.97
    unknownUnited States
    8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
    40.79.167.8
    unknownUnited States
    8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
    52.109.89.19
    unknownUnited States
    8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
    23.43.61.160
    unknownUnited States
    20940AKAMAI-ASN1EUfalse
    54.225.184.108
    unknownUnited States
    14618AMAZON-AESUSfalse
    95.101.111.132
    unknownEuropean Union
    12956TELEFONICATELXIUSESfalse
    2.16.164.34
    unknownEuropean Union
    20940AKAMAI-ASN1EUfalse
    Joe Sandbox version:40.0.0 Tourmaline
    Analysis ID:1458958
    Start date and time:2024-06-18 17:08:22 +02:00
    Joe Sandbox product:CloudBasic
    Overall analysis duration:0h 12m 27s
    Hypervisor based Inspection enabled:false
    Report type:full
    Cookbook file name:urldownload.jbs
    Sample URL:https://onset2.onsetcomp.com/files/software/hoboware/3.7.28/HOBOware_Free_Setup.exe
    Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
    Number of analysed new started processes analysed:26
    Number of new started drivers analysed:0
    Number of existing processes analysed:0
    Number of existing drivers analysed:0
    Number of injected processes analysed:0
    Technologies:
    • HCA enabled
    • EGA enabled
    • AMSI enabled
    Analysis Mode:default
    Analysis stop reason:Timeout
    Detection:MAL
    Classification:mal48.win@13/1588@0/8
    EGA Information:
    • Successful, ratio: 100%
    HCA Information:
    • Successful, ratio: 88%
    • Number of executed functions: 3
    • Number of non-executed functions: 0
    • Exclude process from analysis (whitelisted): dllhost.exe, RuntimeBroker.exe, WMIADAP.exe, SIHClient.exe, MoUsoCoreWorker.exe, backgroundTaskHost.exe, WmiPrvSE.exe, svchost.exe, UsoClient.exe
    • Not all processes where analyzed, report is missing behavior information
    • Report size exceeded maximum capacity and may have missing behavior information.
    • Report size getting too big, too many NtCreateFile calls found.
    • Report size getting too big, too many NtOpenFile calls found.
    • Report size getting too big, too many NtOpenKeyEx calls found.
    • Report size getting too big, too many NtProtectVirtualMemory calls found.
    • Report size getting too big, too many NtQueryAttributesFile calls found.
    • Report size getting too big, too many NtQueryValueKey calls found.
    • Report size getting too big, too many NtSetInformationFile calls found.
    • Report size getting too big, too many NtWriteFile calls found.
    • Skipping network analysis since amount of network traffic is too extensive
    • VT rate limit hit for: https://onset2.onsetcomp.com/files/software/hoboware/3.7.28/HOBOware_Free_Setup.exe
    No simulations
    No context
    No context
    No context
    No context
    No context
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PNG image data, 376 x 193, 8-bit/color RGBA, non-interlaced
    Category:dropped
    Size (bytes):13934
    Entropy (8bit):7.930609387391392
    Encrypted:false
    SSDEEP:384:YSY4E+eaw139kg3ytZaYKHY3HbMKiq0VkTixf2y0VmHj:YSY4E+Hwd9h3ytAHYAFkTm0S
    MD5:3D028B43AEA08DC0E3044DB4C3F46AF8
    SHA1:0724158E15CD8773F9AF7F9E48920E1793C74262
    SHA-256:EEAC1B4627078604E0905ADD7A8640AC7D34EA213C5FBDAB048407DB1C62A822
    SHA-512:6D70056F7E22814A843A73B59BC6D27ED875D24A55E340B2B70ABBAE2B1FEECA133D94673564587CCAB9541F77E0713B43263F09FCE96AF1730309EA60A2CAEE
    Malicious:false
    Reputation:low
    Preview:.PNG........IHDR...x........../......sRGB.........gAMA......a.....pHYs...t...t..f.x..6.IDATx^.{.UG...X)..EQ.(.*.m..).e.....F..L2...<........o.c...5.L.A.;~..`.....4k.c...@w......4........./.W..u.T..:..{...T..9u^U......Wu2W.^...Y.|.2.?.......Sp..18z.(.>|.Z[[Y:t..%*..........................Q. .'&&..s,utt...|.K...De@6@6@6....q#...#G..O>..OC..;......n..*s.e....._.T.e....IM.]....B1..r....y(w....L......,../...DaG.......ne..6T..Qm......^c|...k.6.{.........t....3./Z..ZZZ..W.\...iJ5X.SSS.w....UB..5].t.T..H.4>>..t..EP.....O.FTill,........QPa...m........G._.6<<..t.t..{..e!...%.1.?...[.n\...9W...j.u..,..M.l.o.mBg.b..~........./3>...|333...q.......8..;..\*.OJ.2e.RO.y..;?..P.B]<.\....<o.|..Q../.....l.g.x...v...=.......y[..|:.s..:..=. o.<.WA.d.X~..e.0.\._.<..,G.8..]..t...p.]w1...xe.^L..4.......F.....Q....F..6dlX&......2\M ../.\.y..y....U..u..,....^gC".y.R+y...ou6"..~....$r..5/...dp........[..,..D..e`[W.....m_....5d.u.. .^Vp2..\5.k.F.....fR..*.....$.
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:GIF image data, version 87a, 24 x 24
    Category:dropped
    Size (bytes):1107
    Entropy (8bit):4.798739063923186
    Encrypted:false
    SSDEEP:12:08uS0D2K6WJzuAZVfoLjsSCtLXlR1uUBH+9oGTaxu9sZ1YUoFxdE:mD2K6WJzuYtSG3LBe9kZ1YUoFvE
    MD5:81812FA24C349D631017E8D915D13B9D
    SHA1:0A0CD42A13969D0780A0C0EF805927BBBE8D7530
    SHA-256:E2E98975928D3EF666F9E85A01E30C75429FA29F86414944755D758E34B27A21
    SHA-512:C95B04D5D754E3AED62E7AE97615F01BBF4F16BA2421E04A82C29635DA96B68B73565E2932BAF29BB8077A2027AC5F9EC330527BDB29D8EED00E9C0BB9EC03D8
    Malicious:false
    Reputation:low
    Preview:GIF87a...................!!!)!.)!!)))111911999B99BBBJJJJJRRJ9RRRRZZZJ1ZZZZs.ccccs.cs.kcRkkkkkskssk{.k{.ssss..{{{{{.{...............{Z................c...........{J.............{J.....................................................Z.s..........c.k.{..........k.k.s.s.......{.....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................,...............H......&...a...a......#CnH..&E..H..A.D...0R@L...2eb"1.d..#V<.A....%L.8.... ~ ......Z8.a.DB.Mr..:...\....0C..8JXX...*"2 .@EH.....e.C....!..".....z...$....B.)B...B. ....B.?..D2..0I.@.P...a.,YR.J.0
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PNG image data, 649 x 483, 8-bit/color RGBA, non-interlaced
    Category:dropped
    Size (bytes):11353
    Entropy (8bit):7.565495071670627
    Encrypted:false
    SSDEEP:192:g4cMnxQ7zRw7x2VtgKF2S6YBvlK5vfQqGgrNJMBStHU:g4/nyRw7x2/gih6KOQqGYMwHU
    MD5:E61B436F16235C8F7825A3747C62471B
    SHA1:BF49F03A9B38EC5B3CE6141167A30BEB7168550B
    SHA-256:BCD3D0A74023B4E57CF283640662946CAF145B2756E374C87564F6CD5C3C0605
    SHA-512:CA80745DDD2C6905AA4EDDEB9AC6F43C1859B56750DA36A32D0DA7AD7BDC0D7C1B7E7AD451588E7BC75CF190F061ADF97A17C109DC70A286CDC1DFE7916CDE57
    Malicious:false
    Reputation:low
    Preview:.PNG........IHDR.............OP......sRGB.........gAMA......a.....pHYs...t...t..f.x..+.IDATx^...$.}../...i.5.@.....J......V....J.\..........%d.P.pVA.-.a].e..[.x....+$.B..W...<=.3O?.23g.......f......9.==g...V....D"...".......@.H...C$...v$.....oL..b.(._...........#.._.{._.......G.....7......._$..\.v....y|....D..G.W..s?........_.S../.V...o....:2....L......pp]P$~...V.<.d...._}...g..i.....9.'._.q....F"./..Z4l..\.....A{.....q$.@|..?.....<[.....n.._....o}.z....g..>...x.D..jG...b~.....}.z.....^.Y..G.....R..u.Z....Vo..F...~pa.x.X5.L...-.|..f.>}..n.rz...}.r.....pb..C'...;s.:../...z.f...X,{....#..x......r..t.Z<V.;...sN.m.Vm'[&......<...m.Q$>....S.P=.....o.U.../...o:U.......Z=..3;..:L....`._........e.y.8.E.<T..Y..r."^.yE...Y?V>.....5..s].o...s.<N.z.U.)..G...].!..`.6..o....;.>3..?.~...z........U......r.......0.,.:.%......U.U."H..hE\1o..Y<..t.....}..........r..y#c......<..`/l.._......q...Y....[n...o.S ...]...u .?.....J.(..:...Z......}).G#(..4^...x
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PNG image data, 919 x 523, 8-bit/color RGBA, non-interlaced
    Category:dropped
    Size (bytes):86275
    Entropy (8bit):7.964146070988722
    Encrypted:false
    SSDEEP:1536:b2ADkCm9zf7p7CjIdz1tO7a9WGXyQkUdjzXHVS0Vt8LH6wsOUKR:b2iUf7p71e7sWBQkG3FSMt8LHJh
    MD5:AE1FEE3365A6A57DFB60664933CDF712
    SHA1:52C95C761BBD866C26C616B357CE6C6706901945
    SHA-256:A54B0B37E9266A14A81DEA9E007390CC25F0BF1B111BF8A6913176C4F8F74E7C
    SHA-512:D93D013E29674377DC61F1D94115040F734B8972EFBA33BA79E5C990DAF35EB74C6774A7BE3D7FB09DB718AD8A10FDBF60193940025BFDE3F1463FD91373BDB1
    Malicious:false
    Reputation:low
    Preview:.PNG........IHDR.............|Fhi....sRGB.........gAMA......a.....pHYs...t...t..f.x....IDATx^..|T........!...$jXm$R.u.....Eqi..{A...6...A. ..VQ[.L+Z...Q\.Te..%X..a...2.y.;s..]gI&.~F2...9.s..7.Y|......t.9r.555.k.....`.L..0.&.....`.L..0..@.....*O.|>...........Z.._~:v..o..............9.kF;.q[.x.e.g4.x.c..m:V.._.....n.Y8.r.vc.K.(...S...UW..U>u..../../a.y..>..%...^H......{....~u[&.......u.^....:4K.M...cL.M.X...wJ..^.x.s.y....}..t......k.x..p..e..Y.q.e.....gy.i.8p...>...*l..k..s.=...K.I..M.4.._.~.}...>.&L@..-...?`.. ...B..&j..o._.9..d.7V1.....n..v.5^.o.cy.....n.1/.wjG...f.a.^Pn.].]s.........G}.m.1.....l.z.....n.x){}...Q..e....<3..y.=....}..#.W.b...=_.s...G...v.q.......sN...w...y.a.XX]7...F..........K.:2.C'.....aj.....3.M.r.....>+{c=Oy.p..t.E...........t.9..._..CQQQ!...{..N.s7..h...~...Dii)...Z|.....3N:.$)..}.Q).I`..L9|.0H.......?GUU....7..)R...M...U.....v.e...Y'.uum..m:..N.........o....g<o..*...Y.Vy.^oj.z<....$@..b.L....z
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PNG image data, 712 x 283, 8-bit/color RGB, non-interlaced
    Category:dropped
    Size (bytes):65865
    Entropy (8bit):7.9846399947572335
    Encrypted:false
    SSDEEP:1536:mcz5QMmTiHvgzx7O2sJwFyEKPxX+MFoAccJH2:D2MCvdi2FFDKPsMH2
    MD5:722E0F4978447302184BD1BADECC64F3
    SHA1:7E7C5D44844BF8C90C0589347ABA3AA3257833A7
    SHA-256:62DB266BE0EB044577249DAB8F9104CEF439E8E4DA0014194BC4978B4373027B
    SHA-512:1740DD76C330D2413AF978AFE6214B74D07C21D8962529E07E650D826C958F9D6C413E12053E7E5A9955BCC1CCDDE88082D7654EA45CE033AA875863C9FA69EB
    Malicious:false
    Reputation:low
    Preview:.PNG........IHDR.............H..=....sRGB.........gAMA......a.... cHRM..z&..............u0...`..:....p..Q<....IDATx^..x..u.=..w..9Ns...q.;...v.X.e.Yb.HQ.b.{.$.{.$H.....$z%z.....Xt....h..........ry..g.s.9...4........(.P(.P@..B..P.`......(.P(.P@..B..P@.H/J'....(.P(.P@..B..6.B.......(.P(.P@...(...KQR.G..B...c....c.R....B.y\S@.....).W(.P@..G.8x....w....L..%..I...D...EWT...../y....*..C..X|r.R....&2.....A@@....fp... ....0 8.......el1`.Lzem....,.'B..B.......vggg..l.......S.58.P.p ...... b.A(.....n..BT. .:t(KJ.G./....9...J...@..p.&...`1.n.......>..@P.k.k...B..&......-...]...}tbr..?.2...\.9....m.?.HHY...g.....`.q.+.b\.&e.....(.......v.:..E...20.*...r........A@..6...&.....r!V..9.5E..1.)...1~...).P(.P``...X.T...>..1.R.v...~....X..t.:b.D.D.a..C.q.`!...+.....J..M..X..;...P@..B.KP@h9..$T((1..1..............@D!M....X.c..X..c0.....4.3....I.c..)}X.....$5....(.P(.(.....Z......B6@.....ep`R8!.2.u/.2..Rd..~?....dhY.T.o...5.5?^...q....,..C..B..........q..,).&..N..u......B}
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PNG image data, 615 x 437, 8-bit/color RGB, non-interlaced
    Category:dropped
    Size (bytes):69916
    Entropy (8bit):7.988557970761225
    Encrypted:false
    SSDEEP:1536:M5yNyoHSAhMICVXXLTX6R68V7APi5omU8EMfx2d3UY7no:M5LoHBPCVnLje68V8P2UlM+no
    MD5:E018202D45E1151F71C4DDF7BF5D0070
    SHA1:F1778B68958AAE09B33E6BB65E67E3D51F6675C9
    SHA-256:C9381519D0F9422DD0E4C3508DF2543DD585890578066A63B99CBFA89B4F96D7
    SHA-512:984572F13159B280333BE9213A3EDC65F6BC71AC67D3399651CF93A0B97E754329AA9D58C1FC7F712C6095FB28BABBFF946A23C22D90DAEB884D4F18789EB013
    Malicious:false
    Reputation:low
    Preview:.PNG........IHDR...g.........3.......sRGB.........gAMA......a.... cHRM..z&..............u0...`..:....p..Q<....IDATx^..x\.y..9...7.o...'...J....%Y.%Y...%.b.w..$@..H.(...{...;..mQv.v.m...G...X,v.-s..,........M{N,..."@...P.(...E..k."@...P.(...E.0P..uC...P.(.....c..(P.(.....E.". ..5...:..P.(......5i..f.......9.4.......LLL. [[....cAzV!I.&.:#.P]...MD.t../.IYOO......j.).....$.....D..)Myyy.O.~[..qqq*.@..I..DYS%%..@t.5...>......K...._....~ddD.8...@ pss.e....C.s<.....(-.iii.q....K.,6.J..a.*_~~~/.....jii..g/...G....].0..5.84...h.x@.....8...b..Q..}.....8...E....F.n....@.........T..u.5QM_z.%.%4...^.8..0P)....:...0!.~........<....+.W...5!\ 8./..+.P..4.>..)_T...q.Q.....&..*\../..B.&.b...E....p.(..)u.$..Bh..{q8......].SW.!fY.%.rGQ.@...}&U.....%j&~..yF.D.A.....!..^B.7>!..;6....ZS...:.....&......29......J...O...E@....A.A.hS.7.5......1D..d..k.)..@...9H.YQE$#\.y._..d-..E..Yi1.Hf..9...9+h.....e9.*.j..$.I.c..AJ...n..d;L.Br...:p.*l...a.g.3.Jk...5....R..4E4HJ....3P
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PNG image data, 779 x 612, 8-bit/color RGBA, non-interlaced
    Category:dropped
    Size (bytes):44451
    Entropy (8bit):7.923386884583871
    Encrypted:false
    SSDEEP:768:j9Gzdk0ZC0bwGbcIKU4TOIHlAMKMLKRvPqEZ6Mhkodg7pegM1+jmNZrl5vYuLU:j9GzdZJkqcIP4hAQYvPqEYGNMegqdvde
    MD5:DDD55A3FC77AFF2022B3C66CA1575D67
    SHA1:C2548CC74FFD3CD1B2AEC606669C4926C5058EAD
    SHA-256:D86F23A4FD7F5EA541C428F848808E9887419EBBF607713209DF4E8F6CE06DC2
    SHA-512:7BCA970EE71350282BB210A4BAC6CF9B967ED6D2980926B9E242A13237C0A23C2FFCF6A15C0DF2F771051551333A99DE7DB23E9FD51CCF228CF883EE5DE9979E
    Malicious:false
    Reputation:low
    Preview:.PNG........IHDR.......d.....^s......sRGB.........gAMA......a.....pHYs...t...t..f.x...8IDATx^...|..?....5...) .....5,6...)$}.+."t.Jm..m....J.K)... ...%.*v.Q(_.j.&B.b.......?.G.O.G\......3g.=w23.O..7.......3g.L..9soJwOo/.......R..DDDDDD!.,......+..DDDDD..........|....}...G........)""""".J<.,..f.F......1RO......P..,.@.xN..sWx.]z..:.baf...i.v...:\e..u.^...s....a...k.n...[eW5.%DDDDD............s...?.....=./.x....:=.P.^....:3..[...U.u.f...a...d?t.*..?x#"""".'.`!55.w|v.....y...4=.(.{..zs.5?w+.T.]..c.q.?.....Q...d.j..?.V..;...m\..4..N.o....%@N5...C.....D..|R....!...[..^.l.....m?..$>. """".a?.....7C.Y.sYb..`#V....EgW..5ub..O..F.\.-xL..o.B...<k...X.ag...UO+d.1./0....F,\,.....(.Z.&.b.~b..s.E}..B.....Cy..W.`...lTe..T$..Lu....}x-w.r.y..9.f......c...Xmb.........""""......y..4..A.+......w...})j.V..e'_....ig.}&r...\..-:..3..j..bz...u`a..CC...a.ju..3(p*....+".0.}.V..b......g......{..'...S........y...r..1......%'....o"""""....W......'.*.].'....Q...{...F..;.
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PNG image data, 555 x 186, 8-bit/color RGBA, non-interlaced
    Category:dropped
    Size (bytes):13815
    Entropy (8bit):7.928995877743592
    Encrypted:false
    SSDEEP:192:6HYU/RtDGsoLrXrWB/TPB+mh1/9VLsTErsudRpyMNVJciTP8+esh86L4KGSQz:6j/RNmrITPLh5ees8iu7HgqVLFYz
    MD5:F601C38757732CF07975EC959A5287A3
    SHA1:B34447E7C4B170BFB522180D4DFEF7D78E4EAA40
    SHA-256:A1E1C19DDC1048E4AD2422C4A8967230EECC3189213241AF8A3A4AE87327922E
    SHA-512:56E667734C0B57CB856E06955E0DDEC3FD48372F805C9E3D8120BE65E689DF36D6715EEF2C6396F85A364F80A3103AB1DDCC17E5A8E45ADEFD0A447727CDFF27
    Malicious:false
    Reputation:low
    Preview:.PNG........IHDR...+.........o.......sRGB.........gAMA......a.... cHRM..z&..............u0...`..:....p..Q<....tIME......#P.....5bIDATx^.}ks..%.O./...?`.!..xc"lG8..k.Flh.;....Y.eO..a.H..=Z..$.....H......~7. .. .n.....w..XT..U.Y..*.ADF..ne.<y..S......S$.......@.... .Z...:.....p......p u..'UR.....#8......8..0. V..!T..p......Ts.b..M5AqW..*p............p......p ...X.ASMP.Q.......p.b.b.b......p..H5. V@.T..wT....N..&.....uu.F../p`l..w,.X. V...A^.;S.L.1.}.0Sa.:....>.}.G...,.=..Y.L.w...,.l.......(.X.`.xqS)V.v~:+.#.....~..._.....*<.H"q_...v:6q..e.I.GuM..0b.n..Q..C.k...+*.....?.5........4/...`...+:.}.. .~.k.....ir}.a.....#.v+Hyb.P..%...k..C......gq.k..Q..K?.Q.X...s$...7K.>f; ..6...A...:bE5.!;......_.........~..72..n.....w'....]...^...A..:X....}~.Sq...:2.jzm./U..*fL.C.#...j...T~.....5u..Z...X.PQ.....Y.<~.u...|w.:...@.7p..<.$....*i..x.........nS{?...^I..#.5t........k...L..c.;....'.T..'X....7.6.D.i<.x..[u.nnR.v..!V Vb.+*....U..N.....<^..%bL.5.N*<uD....?:I..kY2.*V.."?..
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:GIF image data, version 89a, 15 x 15
    Category:dropped
    Size (bytes):927
    Entropy (8bit):2.2155929209512633
    Encrypted:false
    SSDEEP:6:P/+FuTWs9OUYqk8Anek645TDJRdxRVFvywN2Nn5h1i:P2FiWsSYUF60hXx3swcV1i
    MD5:2108A6ABE2034706C311622210CDCBDB
    SHA1:6505A543AE5375A74550AF42BA38623773159B4B
    SHA-256:0AEE30761265F4CD624E8DEF9E2AF9E73B0B81B73AE89562617522547C38CAD1
    SHA-512:F1FBA020A2B4B5F0580CEC6A5788BE8FCF2800C44450B39EEF0AA5CE07FF5A421A37E0D861136D89995E1A6631E2C0F6AE459938B4AA0B835C92B6E931BC4DEF
    Malicious:false
    Reputation:low
    Preview:GIF89a.............!!!)))BBBJJJZZZccc{{{...................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................,...............H. .....L......J.. A..3^t...G...4....(S>p...K..\.d......l...&..?...*.......U.t.....J.JU.....f....._...uB..h.E;....o.....;
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PNG image data, 665 x 281, 8-bit/color RGB, non-interlaced
    Category:dropped
    Size (bytes):54532
    Entropy (8bit):7.985396497321957
    Encrypted:false
    SSDEEP:768:tHFywqprHgel8dyQSVj++ytsuCw25fJS6FF+LesxftLfM34VPKFIWV7zg6dqdTo:XMpzjrVj3sZ2ZpGPftLUkKFIk7zdqdE
    MD5:BCC6D9CC28DD992C939A3344C9175195
    SHA1:F0B3A48AC9CAF1928B8B6A314397C3A0A04F9D44
    SHA-256:1A1A64A715D1FFB0FA460BD2C63959E8E4DA34F24B9091F6585A99795B380B87
    SHA-512:441A6A90F1807365A3816BE05BD9AB0623DFBE1F2E6E75ADDE9C566060CD140E87CA427D8774D8EBADD5426DD5CB7A8A6A5FC1BE7CF347446C2E2B2C6AAF639D
    Malicious:false
    Reputation:low
    Preview:.PNG........IHDR.............S..@....sRGB.........gAMA......a.... cHRM..z&..............u0...`..:....p..Q<...IDATx^...T].....~..7.......{_.nw.......s..v...}.k_.7G..AB")...$D.Q....A.$.."..H".s...m.... @..3.8c...k.....5.k.?.h4..)..I`.....x^%y]J@J@J@J`}%.o..74....X.?R....F.1,.).).).)..%.I.fh\#...(&+(...hZ..!% % % %..$0...OH,.H.4.H,.S.).).)..(...K.1YkV..X.6......sdcMT7..&Y......X..H,.(....X.:.)o..+k,.h.G~ySQu....m..(4.)...M..R^b[YMJ@J@J@J`..$./..dU..Q.....=..w...GW..Es..8..c.f..8...k:.55.#..M.3.{.$.K.H.H.H..P...%@/C.*........9xP....s0 8.}XQ...r0;=..o.....v..3..=l.s..C~`F....}..R...Lh8O..wB3.s...u83.yN_r..% % %.H@b.2.LV.^/.P.T..:s....C....[.P...r....e.......e.}.m#..'...ykdb.........)9..]......lx....G.N..P....7.yT.@MK[........c,.)% %.K@b...eH`..{..N.=......G..?N.....?.W.:9....z...a...n.>......3<.w....&V.....+[.k............t._.........l.} 8*.?.n...MR..././% %..$ .|.H&...r,.5m.........._)..B.};.x.k...W.....#......?u.......u..y0..{VA5...6.5.....7..~....
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PNG image data, 554 x 374, 8-bit/color RGBA, non-interlaced
    Category:dropped
    Size (bytes):21637
    Entropy (8bit):7.905763519857631
    Encrypted:false
    SSDEEP:384:O8bq9oL8OkMvKWIe0czClddE7syGZ4pSLC3GUBi2zyleYtD+yJFYAOb27:TTBC9e0/dCy44C3G6teleO6yJMb4
    MD5:53CEBF08E50A172405AB506D808FE8FD
    SHA1:4B328C0822625FE622AF071383FBABCC9135D7E4
    SHA-256:853D613CF51F8314C024DB28F2EF1BE2827949FBD2F2C599F3A6A7DCDB528130
    SHA-512:155DFC45F5DBF1AC2A27EFF1341BA004114874612515BEE11EDECAADF9CA6618542E65581E7F64C7B634E4BB159D09D5B227C776610201119ABB76D0DE2DA6E4
    Malicious:false
    Reputation:low
    Preview:.PNG........IHDR...*...v.....@.......sRGB.........gAMA......a.... cHRM..z&..............u0...`..:....p..Q<....tIME......'N.i...S.IDATx^.[....G?...>,.......^../.........`..B.l...x-K......`....^..5..Vw.....d...,.Xd..d..,.Yl.u/.?..d'.#3"/'O.:....NfdD./...?#.....K.... ...@....$..~.O...@.h....4P)...).j........@.h....0*8gL*.@.h.....j...8++N....B.h......F.......@.h..... ...+).....@.h...Q....4..J.@..U.q..\.v...W4..}.C.J....\i...*..J......6....6.._.s*..Z...Yt;wJyjR....#..4I..K...<......=..+....pA...qA2..I.9.}y.J.s...)A)N#..\.4..z...N..<F%m..,...F...?O\..7.~...#.x]I..`..L.jC5...L...i.3.`e..i.w1uU.nY...w\.Y....Z.Q...i.Q...6fU....B..2.v.+)..$..F.7*I...}A....g"l.&:.....QI:.m.i.8(..k.w).[...G...._S=......J.I........v....h.q}n....V....V..I.V^t\.p.;.V.lc&NgY..4V\.I.....q16....l..1*...Q-....&.. .:0.LdI._.$.4.&...I+.<.p3....lf.o.&.....O.f3......}.:..7..<.<..7./.......p...^.Y....k.s....'..6..I....#.1]d...F.&F....5.I.6..&.4.=.D.:.....".....e..2..T.m..\....,i
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PNG image data, 306 x 215, 8-bit/color RGBA, non-interlaced
    Category:dropped
    Size (bytes):13370
    Entropy (8bit):7.965421685476815
    Encrypted:false
    SSDEEP:192:JeGTwGh59STxcHy6uNRso+rnGVM0cqNwMtKDzgTRXHhASNoUSTuKHEpQu9Xbjtih:Y+LBw2HyFRyTGSzgw7DGXJNfSfEugih
    MD5:11B97E46BDD55A60BD687E30B80890C6
    SHA1:BD5A3B6E1722C89D6C3CB0F2F7E7E257A2035864
    SHA-256:29AFE74D9FD843CDE0129D74B1A6F0B043553C3FE0AE64F96AA0F0B803430B17
    SHA-512:BF7115647818087BC0C9D8FBB8C15ED40677DE57D180F81D5639A0FD57F73E75B5D54428F275C6A8B1FB999B23AA53024E69921C3A191AD8008D7A760B9E0A9A
    Malicious:false
    Reputation:low
    Preview:.PNG........IHDR...2..........8.@....sRGB.........gAMA......a.....pHYs...t...t..f.x..3.IDATx^.].....I..%.!..tDe.Y....$...l..D.....Q.K\.T.@. .. "p..#*..y...EQ.!...Q.T\......S..]].......3......k....3.m.P*--%...#..."..#.:th...:3...#@)G6.1...#..............r..V..`....j........`....vd.P.l.#P...#+....3...@..~.1....'.|B?..S>..iC..5...O..n...F.!o....q.0Fftd.M.LG..............g..Z.p!.(..m..Z)".E........n.[.].N.......do..8...w/M........q..g.....Y....?t.1...C9.I.N.....<..lB^#.8..8...e*.B..vr`.r..@G....%.)8...%...d........hX..h...p..>&.l..*GVU....e...a...@.#C%?x.`.._V...-.V.n^..#.p._.4n.q....i..B..f...RA_].?..T^8.6.a"....y........,].u=.pHZ.f}.. ....09...uQ1..=..W_.k..4h.6........._J+....V..M.....a...K..........X9..]...a..H.:.O..u.....N..ih[.....[.......f..>...._.nW...-..4.k.x..W..}fW.;|.owu..D=f..DKW.....GNZ...8.aS1.]K/.....\M...[...2|..+.'..#...3<....MO.v.Z.>.I2...Y....\*.6.......M...t./...v?=...N.e.t5.8k.5}z..gMi.Y#h.SD.woG.K.....cn;....<v........
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PNG image data, 247 x 171, 8-bit/color RGBA, non-interlaced
    Category:dropped
    Size (bytes):13828
    Entropy (8bit):7.933037738585755
    Encrypted:false
    SSDEEP:192:BA61+fLDyvnrPHqrseK2t3OoZ9XgTLIZyOm7sGMp2/ftwdKFayFIg7:Bk2vnrPHqLz3OoZOTLSnlp2eWasD7
    MD5:0FD0A1165AB012B232C0F8389594AA14
    SHA1:FC6EFF139AFDC784F86EC00CD7B1148344C57972
    SHA-256:B39C251210E9E9622175DE75CBCCAFD921D6AED903ED73F37C375AFA8FE72EA4
    SHA-512:78B90F126DD3DA9232C2D68FF1B4EE2FFA25766E8C4BFEB0B8960B00558010DE0B8018B762E98E141C649432FB369D567F4A5AF5135E702A1EE21604B368944F
    Malicious:false
    Reputation:low
    Preview:.PNG........IHDR.....................sRGB.........gAMA......a.....pHYs...t...t..f.x..5.IDATx^.ytUU..S.....t.......{...*..g.RQ..U.r.B..K..*..R.| ..@P.D...Q....@.DT..$...........x.........}...'....]..i...g.~....d...T__O...1.?.***...7.|.^{.5.=z4..5.^z.%z.....^pry..@.........1ch.........i.ET.../_Ns..I.&y.....<.L'....t.:.....SO=...)S.x.....z_`....y.0.:.,z...../..c.u.}..W.]...t./...O....q....t.u?.S.N}...."..*....?.8......'S.e.<s...8...;v,...._O...r.J...P..;..W.XAI..>.|..R.>...2..Q.P>6}..G$Z.t)i}..dj.%$Z.xq..=..?..p...>...[.'...-}.>...O..Y/.[.)5M{.......v.Z=.M.X.Y.Y.X.=M...6..y..o....wS..u..;t.u.u..........VK...^>...,......^}[.z5...c....%...........MMM......BUh. ......o....]. i.5.B.......+.8G.x6..r.{R.........E..Q.{.=.`5.Z..O.X....}.....C..JG.{!j.:.....+:.......}0...v.v.Z.D..i...c.>...O.....b.K......?..g.......U.H..|>2.S...60..|.../i.......+..R.,v....;....m.k.s.z..../......w..B....ci........Xja.f..3..>.~.A.)c...h.zw..I.(..Y..>...
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PNG image data, 456 x 305, 8-bit/color RGB, non-interlaced
    Category:dropped
    Size (bytes):18062
    Entropy (8bit):7.909451662556986
    Encrypted:false
    SSDEEP:384:6vozcfoMFoVPpP2rmuG7C75LgGYgvQqpfL7PmTjYs1CIm+A3mShv5luFXB14e4V:goIfo3PpPBehgGQyPegmCIomShxluFA5
    MD5:D42EB25C7967D11CEBC463865A996547
    SHA1:B3DDB609920FCE31CEEAB07936050E17CFF39977
    SHA-256:59C3CC88465B9947404A3160839CA9FA3093311959D94FC9F1AF24EA0D54D455
    SHA-512:06F38B52E9C66C6EF4C753280BDF30BAC7FDBEEA72F0627D88CBBF3B6D47532148B00D3782860AD2786AB0C436B14BACB047F4AD93104A1E62B026D70F819D86
    Malicious:false
    Reputation:low
    Preview:.PNG........IHDR.......1.....w^.l....sRGB.........gAMA......a.... cHRM..z&..............u0...`..:....p..Q<..F.IDATx^.......Q ...OB.e....-1.....K.(.......q...h.%....h..[".....&.0.....20.=..30..O..9s..OUW.t.O_.5S]}..{.:....../.|...8`.@...1.=p@.........................:..A...Z:..Q...........z`pM.....O.=..6.P{ghP.j.....l..u...E.!.......:...D.}r.~U...3`d6l........o..c..w.s..?.o.?...a#^6.W.M........?%S.T.....].).&...Y.....<.@.A.t......Z.4$.z..*@..h...(*.z...`...^.5pV.:..T..P.TV...&....".......W.nJ....~.....)t..AT......).].c..*X...a....-..j.jC.....>..._9SL......W..Q.* ....^Z*( ...........4n..{...k.0.%t{c...4.k....!a.V........U.a....[C#...^...iA..V...B@.x.f@..._.q...F....Hu.~^=.vG.;*q.....<ts.a....b....k.a.F..m.]..a..U..!t..SW.?.....6A.([%^...{.C.z.[.d X..7......J..T@Q..4Y....X2...pu..jN..Xx..B#2.....o...+...8s..V."P........wT.n.0.cXx,xO..T.....2.....D.5.._,o/.z.....[....F.._^z.E.?.....a%...+..4.?.p..y?>*....o..T..\. =iA..Q...b..R5b.`.0UxZn..{.S.-
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PNG image data, 917 x 525, 8-bit/color RGBA, non-interlaced
    Category:dropped
    Size (bytes):74850
    Entropy (8bit):7.939483295423291
    Encrypted:false
    SSDEEP:1536:fWSmFFTwxQuE4yhhWNeGbpD/D3+ZtOfXWngqEUIxgU2WRwSuu2P:flEFBuE3hEbd/D3+ZtaKEU4hToZP
    MD5:7F1950C98421B35565C19651F37197B4
    SHA1:A4B2E593FB004CB4A78EE987D4B99F17116BFBE6
    SHA-256:F307211D28D1F4559A4EEFF9090095A97C5EA5461097D96F51EA9E7DE16022FA
    SHA-512:0FAC44F13BEC5F32ABB142F2A5BE6821F7B5792DCDBDBB55CD027B67D8DCB24C215E47E1DD8620998D940FCA7267909DF4269BFDB6E7E2BD0D1DDD6BBB81FDE2
    Malicious:false
    Reputation:low
    Preview:.PNG........IHDR...............[I....sRGB.........gAMA......a.....pHYs...t...t..f.x....IDATx^....]E................{.[.....0...*"C........DF.%9*jhP..@.@.a.!..`3$@r.B..9.@B.C..8....k.Z..jU.....<O..W.ZU_.5.....C...}.....................I.....D....`......`......`.........#sH.}..'&..y.{h.QH..0......0......0.....@....w.."..{.....{...M....w.6'M.D.=....w.......S#.e`K...#Ns...9s.L.g.&.....Rh.5k.....x.li...J...?.i...J..w.........^..=.........\...w.IH.!.<..0....U...s\w..(."x+:...}..7.}....CCCTf...Wm..C....Yh...eH.....Y.>...#.._.N.../..*....\.:.......{\..i?l.M.]...[....^k....._...........OT..,X@.i...dK.?.8.$...|.;..s....\.9#s.w..]B{.Z.>&.o....k...n.....2...F_..Wi...A...I_..W..../..|...%2./~.dJ...4n.8:..D....@..z.H..r.}....s...H...gE.;vl&.|...i.1.t.I'.-.x.$..'.@j:...I..|.3.3.=..R...4...c..O}.SI..'?Ij..'>A..sL..>.h.....8}.c...~..I.......G>BG.u.HG.yd.>......8...t..'...#5.z..;.U.!..Bj:...I..G.).t.AdK..x ...|....@E....OH.%.....W.!q$q..?.....]..E
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PNG image data, 247 x 202, 8-bit/color RGBA, non-interlaced
    Category:dropped
    Size (bytes):9452
    Entropy (8bit):7.946283228007435
    Encrypted:false
    SSDEEP:192:PqAzUNS+0Gbv10Q5wpxLzURXn1CaugW5qLJJHIma6AHRB/mJiyG:lWB3N0Z0RFCa7WkLJOuAHRB/rz
    MD5:517EF29369EDDAABE6D872ED2B29DAD7
    SHA1:B60F3EE9AF73AA9077FF82373E30F14F77738A92
    SHA-256:80C7BDDC8BE357898ED76F5636646E5E10858F8454230AB8404AED145531A1E4
    SHA-512:6C77A7086CD67D7ECB359AE040BE53A1E40C624AAFFFB34C3CD74BBFD87C3D8559313C3D056EEC2DB2BEB2F7B5FA81D024C8B8F7C3629FEB2BCB0B99D7447599
    Malicious:false
    Reputation:low
    Preview:.PNG........IHDR.............yh. ....sRGB.........gAMA......a.....pHYs...t...t..f.x..$.IDATx^..tU..Q(..+..:.".IK...R.0.....j^'.....u..V..K.*6v..6.O.....Q...HM@..lI..yU.6J...... 8..$...>.......&.....-.=..s..9...{..=....mM..=.w.q..}.]0.S.8....nR...)v...n...0L..f.m.V.7..M..G?....`c..........=z4e./..NS..0L....0%.;7.(..j.97.......#...}..q3f..|.S..-...d...L.zd,l.5...r.._...._.x1....2n..:.-[..p.;W.T[.p=.#...4~...Y~..A,Y..g.u.N.8..aT?TOT_&...YP=2.....|....'O.-.....'./.\....G&.....$[H..?..xD.-7.....S>6.1.)y...z...1......~...{.0..ec./....L|"5....b....Xq.8.e.6&........4....6......AG..7.8dA7.W=.&6b...Vlw..dQ.7R..N....)r.3...|....NY..)*..ys...e...3....6.$w..3W./.....-...a_...y.S&..rz......bS..8.v...'..&.}v-~.x.M..M...GX.*...fm..i../....y._..C.t......x...}Z.~M..s[....~.z..3.{...N....._......M.U.C..i..........F..C..n.....).....M.@..?{..X....'o.;.?..........X.g...<.?=y.^^}..y.+.}..........H5.|"....i.Y.,F..V....bow.l...>...1../..z.....^..G.}".<S..]
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:GIF image data, version 89a, 15 x 15
    Category:dropped
    Size (bytes):859
    Entropy (8bit):1.0161223903839385
    Encrypted:false
    SSDEEP:3:CcihvXPQEuxXzVFXwE8cw33q:PCHQEupV5wHXK
    MD5:CC5BB5A77F72E5D0601287A83042E8FB
    SHA1:74FAF0FBEA2FDEA8725E00F962402B0FF439C2AF
    SHA-256:05B7D42B20C31ED67BA8EF9C43DC8135B70A446F5A82DF491EADC44683B8B1C4
    SHA-512:0E451A83DA035D16101205B5D4D85C59E0BD23CB8AF722776B917FC12DED27B7FD071F97BDEEB156FEC600D646F062C6E1BFE01058C74EA6719349469A764BF6
    Malicious:false
    Reputation:low
    Preview:GIF89a.......................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................!.......,........@.8....H.......$.P.B..#&48.....f|....7"\..#..Q..X.cD....;
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PNG image data, 142 x 30, 8-bit/color RGBA, non-interlaced
    Category:dropped
    Size (bytes):1356
    Entropy (8bit):7.788940780926944
    Encrypted:false
    SSDEEP:24:4X1JHiHjmlzdrP/WWmXW/H/UcIhgQZAFDxrJQyLk5ugJD//cH4q65GnukXc:4lJCHArP/qyHShgQejrmuk04th5vl
    MD5:EE44B1C2DE8E57E274BFF0F5CF702E47
    SHA1:9B83345BB3665ABADA5C42905BF57D3F7A8C7F91
    SHA-256:DDAA42C22744FC2925B1968109251C8DA88E343A271BB684177205D5ED244FEF
    SHA-512:3A8F356773B43007010D951EFC75CD1E03A51485B9A2F33A27A058618C1555A23E6113D880C5E017890B58925E0D92B55413E93DA78EA4812ACE0BA4CFC3C122
    Malicious:false
    Reputation:low
    Preview:.PNG........IHDR...............&K....sRGB.........gAMA......a.....pHYs...t...t..f.x....IDATx^...@......%.v...5....2.....+c`-c`5.$..n.t..a.au9.*..0..?..........T.##..z..>.].}V..z.38.v.A.>5....|...y.!?0...|.d.G..p..P&w.3b....Cq..x..q..Y}p71..\u.}.=....j..0'...`{L...G.3`z....-&. .....$.4.c..*...?0ppP...`=.W.1|p.B.8...o.../..K.....=O....J....vjf....A$.N....."<#.f.7_.j..G.....|U..F..1d.PHxsX.f...p.n ..N.9k...*.Q8..xrq.)Pt....R.#_.9.)f.(D[@.G..$.".hC....46..b....3R.......W/....x.1qL.&....n.A..e.....r{.\`.......Y.6I....<.#<s9w@.....D..|..7...9..!..`.v.cr....)H.?.k......(4...).r..l(...].L....P...k.3.'b...@....T).....{....M9..Q.U...9E...7..&..2.......y4k...=....n...r....'.Oj..&T.%..Sx.f\.3'.]...^..J'e...R-.jG.....p.%.|8..N.r.Dy.\...d.4..M(}.bC.K.._.@.T..{........%.....g..G...J...'.......:........#M."..c`..%.Y.&y.]1H...Zb!......<......'.$..GS*.q..6.(...@.D.....-.../.?...pb`+m..C.G.IBl.../..!o.......0...[.c.c8..^9..0K^..C=....-Z.4.....pl.JrT..
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PNG image data, 955 x 471, 8-bit/color RGBA, non-interlaced
    Category:dropped
    Size (bytes):48219
    Entropy (8bit):7.929291166230815
    Encrypted:false
    SSDEEP:768:i+mzVtfL7fhBUO1jso8exvg6Ajji35LHVS3w9SZ/Jka35iwzi+eq:irv/fHX1jsDMgDjji35KwgZJki5iMilq
    MD5:8DE999A4E08C541EA14B90431DC8664F
    SHA1:3FE62AC94BF6C4B71AB15DC9458BA09A7AA86B87
    SHA-256:316FB0C93B8A2912B737CBE5F372D50E080730E34C15D4C9DC916A5860367714
    SHA-512:6F3D6B3C529C053873A8D6A023FABD2EDD423ECA3883B24EF61806F8532148AE8D4CC7B9C4D50E6A79EA2BD98E93DF6867EC43403AD824E614B0FB906E3A8FC8
    Malicious:false
    Reputation:low
    Preview:.PNG........IHDR.............}3M.....pHYs..........+......tIME.........47....tEXtAuthor....H....tEXtDescription...!#....tEXtCopyright....:....tEXtCreation time.5.......tEXtSoftware.]p.:....tEXtDisclaimer.........tEXtWarning........tEXtSource.........tEXtComment........tEXtTitle....'.. .IDATx....l[.}..'..k.....J.y..y...9....\X..l.B.E..u..,H. .....T$....+b.!..=....f.E.`.+Y.A........p....FU......v.i....sH....,E~=.B>.|.........|>.. ..........E.tZ............./lw."""""""..dWDDDDDDv.%.""""""..(........]G........:JvEDDDDDd.Q.+""""""...K.<{....C*......ow.bC.........v.!""""[.d..........z~v*=?;.s.=..GDDD..`...9|..v. """"...].......u........dWDDDDDDv.%.""""""..|~.._....6....i)c../.<.z.nr........H.|~.]...G..1.#2.....W.T..x.=..O..O./.....O...$...t.\...#...LDDDD..>g.n..;..3?..nT....j...'X.>)7..*...xv...t.t......p....0...b[.......=..'..,S......nr.w...*......o..}A.....a..........g.....7/X..g/|f.}....9.*m.G.,..W.+""""...>....e^}.0...<b$.-?.Ly.Q......."#<.3.(.C:..~5.?...H...^}
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PNG image data, 734 x 206, 8-bit/color RGB, non-interlaced
    Category:dropped
    Size (bytes):32795
    Entropy (8bit):7.969417959283188
    Encrypted:false
    SSDEEP:768:0EzU32FiOI/V5YJxN31qNbwEHvOgUQohqUoT2:Jo2FiT/YJUqEp+qHi
    MD5:CE1FF3954CA65A724C831F243442A691
    SHA1:B3C7C12EA3550CABE4EBE37367E2F66AA9357A9B
    SHA-256:28ADBD2398A8DD32EBDD698FB4B5FBB5311441AB48FE65B64B1FF867894E114F
    SHA-512:AF0B3CAC48EA7E40D2ED5EB5A64D793D1E5864B415A6F9A9208852B92B7A98C6DE7B0705860997DEA646C2F621CF52ABC248B4BCA38B9FA5B065F629E5E91607
    Malicious:false
    Reputation:low
    Preview:.PNG........IHDR.....................sRGB.........gAMA......a.... cHRM..z&..............u0...`..:....p..Q<....IDATx^..X.W....fw.%.n..t......)..D..1...R...K.{..T@A.AA.. .7+..(.|?8fv.../C...3..wn9../s.s.w.....<=..E@.P...E@.h .@M.P...E@.P...E.. p^..C.P...E@.P...E...((..."..(...".p.Pj.p.B%Q...E@.P....&.:t...x.'\]].....o...V...G.n..."..a.;y.d..j5Wif....R..w.zs5.XkP...E@.P..A..&P..3.c.E.......X41|..J..r...y..a..j.~f.NU.HA.8#'.Ey.*E@.P...E@....2jbC5.+?......Lb.....T...Ka2.gP'... ].&.F..&..F..']...Q3..#..|--.L....d.".K.t.)..."..(.......*.fP...[b..n!...DL,.-..(.]......EE.I.i....]..@>......./a..(._iQ.R.1..|H...........$.@.".."..(..."P[..Q..1.\.......&.O..,ahn..pa.K....$..*....1...AM.~.....jb4-.D*...F.v :e..*4Z.#dma..(..."..(..............@b.?P....C....(.U)....9.EL/"...s.@H.AM.&.s.^...j"F ...t.i.E@.P...E@..;..l.6~..T.&.m1TTJM..^)..4.`..98...]0..A....jNM.J1..g..W.I..3.Y.P...E@.p..2*`8h..AMl...q.._...IJ).8.z"UI.a9...f...#....e.fk.:..aW..S.u..88o4."..(..."PG..9t$
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PNG image data, 875 x 233, 8-bit/color RGB, non-interlaced
    Category:dropped
    Size (bytes):21960
    Entropy (8bit):7.9334181153784185
    Encrypted:false
    SSDEEP:384:cs5vRCCPsIV7jown9MEogfOg97GcqO7KgtSKVlfl8uuXE6geuOCayL2DFVCwnfY:covRTLVpn/o8X7IQBV0FrgeuiDHfY
    MD5:8AA178784D87ADE68512F4C8604BA1B5
    SHA1:5A67B544BA9CEA32FFEAD719499AA1488EA59704
    SHA-256:7DE29157FC6E506FA935E92C1F2DD5E624E105A7949AD4CE3073705CA71A58F4
    SHA-512:482FA90A9626251D308DDDC0E5CA6E103EF1CEBB0D55161D16152EB1F44C7BBE226A183A4592B8C9CAEC09BBCB580EE2562EFECCEE20B8FCCF6406D11A837E9E
    Malicious:false
    Reputation:low
    Preview:.PNG........IHDR...k.........5G8.....sRGB.........gAMA......a.....pHYs...t...t..f.x..U]IDATx^...T........%..(...fSHL4..$..Yb"b.......`.AG...A.....e...N\...L..lj"Y...q..].s...[..W].T7M..3o..s........*....7.......P..!..BH.&..*...A.}.g.Z...v#.!..BH...j.u.6mZ.j.L.1...{.nx..;v.o.../>....j.....h....)^..M.O.2..JZW...6a._.....4&u....)>..g.....1..x..c.9.p.....%v./.:..3_.......;w..._\..j.7y&.>.x..Z.h.7....v..AL.XD.>}.....b....?........O....555e.......R2q...].g.%H...BkR..s.._..h.....f......$........B.@...JI.~&.H?.e.._...dqJ.._..ld. .Y..AFP.'..../B.C.,.....:i.9...?.W.N.......... .@'....z_..6....UUU..]B<...xF.../...jFB.5:..ZZ.A..q..mO..&Q.!....5...]..._i...L^.m..ee..-........b.O.,7..^9.ws&.J..5.3c....&..xd.+f...M.<......>....].V.b.........|.s...3f..|..G.c...K"-Pm_...|).i5.....W..H.....^!d..e...o.P[. #h."....E..A...B[.....B... ...7P.]E.o}...f.....%S..h...OZ....(.......I..fnP./..i5.....g.GIR..U..?`.K.v!D.....-......A&@z!...~^..ef..<B?...d0
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PNG image data, 628 x 390, 8-bit/color RGB, non-interlaced
    Category:dropped
    Size (bytes):89329
    Entropy (8bit):7.992241457163792
    Encrypted:true
    SSDEEP:1536:nUVZHRI55nbI2sj/bhePzQB6HiCQl9Elt9ADrEoEuPbn2QFLmPNIXSx5ADuy38Nh:GZxI7bjsJekBcNO9EeEwn2LP6zuq8Nh
    MD5:CB9AB7C0B51B795406C3A453EFF3C2E1
    SHA1:AE368D2D1CDB21D0B92294AFB7AABB877BA61C0D
    SHA-256:12DDCD7779323786FBA67A2102F7A839CB525CB0F558BC3742A3520C2C1F5777
    SHA-512:B1054D7FACB383567AE8EFFD23C1797F9C9FE2B73DC931CAC1703CEE0ED8FBC48C19582CE82F686D4C481BF85A189FF09D5D393CE2542F3375537ABEFCACAE55
    Malicious:false
    Reputation:low
    Preview:.PNG........IHDR...t.........}.......sRGB.........gAMA......a.... cHRM..z&..............u0...`..:....p..Q<....IDATx^...|d.u.C.....~.Tx..6m..%.)Q.eS6%..$R....rs.....;..s.9a".A..r.9.s.s......vazz...F#.....{+.:un..T8...v..|...9 s@.....>...*_2.d....9 s@..9....d....9 s@...iJX.....2.d....9.[.........7.#zKK.o./.&s@.....2.|.U......^9...5_.AV......9...e....9 s@.o9.j...\.KP300P.2......d....9 s`.9.j........o..r=..Sb*...W..B.&...7&&f.(.(s@.....2.\9......n?w\.`..\.....2*...Xy]V.q..2.d...X]..Ep.#. .+.WW.U.K.kVV......2...0....9 s@...Z.W0.Y_......_. ".].{.ie....9 s@...r`-...T........W.U^.:.TX.....V.t..2.d....2s`.+x.v..\.N@.]K.9q@Ynx..."..E....9 s@...s`..UL...f=U`'j.x......V..b...%......L2.2.d....9 8...:_K..4.+7gd..9 s@.....+....+...,..2.d....9.C...:/3KZU.Bu....n\...i....."...[>..n..n.....BG..q..!.".G.....`..".O..>..~.d.4...m..F....b.....h|.ik'+.\.m.?........l...>..8n..)...............O......A..prx.8..v9.:..~..{.f.'..yB...x............p........
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PNG image data, 635 x 398, 8-bit/color RGB, non-interlaced
    Category:dropped
    Size (bytes):21167
    Entropy (8bit):7.836476900036338
    Encrypted:false
    SSDEEP:384:s45+8cEFEDjGbFJvS2AZBFs0BTvhJ6vIoV0LI5uzBeQyzQeSTZX//:d5+xKE27JABHRk0LMQXX//
    MD5:3E6871CA7F9CB47B4C7A852463C4B2CA
    SHA1:8FEF29DF3C29245973DADFB38C372DACEBFC2AE8
    SHA-256:F3177E52E6AEE2263E59001A206A4717CE2C4379911FF52902BC4D9630483933
    SHA-512:4693E605676A10B1134CF5DE7E06D4C270DCE48DD8DC1DA2EC0B807BDFC37887F372FB5CD192FE40C1B5603169B0934CC3F2D72F01738BDCB1B56130733AC707
    Malicious:false
    Reputation:low
    Preview:.PNG........IHDR...{.........`.R.....sRGB.........gAMA......a.... cHRM..z&..............u0...`..:....p..Q<..R-IDATx^.......Q.{....|.K...Y....c.......b\c.q..7.(..-.W....A.}..fqp...}_....{..p.pN........y....Y~U......PW.o..o\.6`.@Z..9.\=p@.........4........v..]=.A....F..R...^ ...y.........z.l...@..vh...0{.;:......A1..;..t....2Sg..................P.......(...u.].C........G{.{.w........F.`._.h.X.$..F@sh.#.@..vZa....C..3......d...D.D.....W9...g.....&....w.PV....D.....D.fI\.e.......H9.$8.X..2.'.v2..D+.l....(...wS2.l1N.a.5.k.z.qq.q....j).7.D..x[.......?v.....[...J..V......,'......F`..z.@...:JiC.9.3..L.w...on.8.i.um...oc.^.Lo..\.`...:._.tl.qe..h...J.3s....q/.d.vW.........i_.d~Jm.iB.....@..@..R.....R._;`|.]..d.....Lc......K..tq.........s.4.-.n.........NZn~L.t{_b.I.{.o.._..O......f..L.H ..@..;$........UJ1..ry..U..u..|.8..36.#6..%.R..i1.R..z.m...j.x..Y.\CS..5.5.f.@.Z...H .. .. .}.|....-}.zq..T.+..}..._Wy.....o<.l.o.~.V..S*...J.....=.h...g..u.O..sn...n.2.{
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PNG image data, 677 x 118, 8-bit/color RGBA, non-interlaced
    Category:dropped
    Size (bytes):4729
    Entropy (8bit):7.737248859174074
    Encrypted:false
    SSDEEP:96:+c76WgUazWCPJX1E0QedJGbvvy7KmwqQr1kAHbcxcO:+vKsRl/QVBrWAHQf
    MD5:483A1C5174FDA095592405EF36970335
    SHA1:080BDCBFF20552E5D7CF1C5BD463E10C8DF37F94
    SHA-256:1994B5E52B56AB6A0690463DE7613AC11645A4472FD72572155AA0892C014F78
    SHA-512:76AD7DEE10E78AE4EBADE2DAFC407C9D07639AA955DE727E5C1DC1994AAEF1F1A794F8F6A8AEF41136A101902C971FA5962FE7BEF21E5F189696A0F0973D8BB0
    Malicious:false
    Reputation:low
    Preview:.PNG........IHDR.......v............pHYs..........+......tIME.....1..%.....tEXtAuthor....H....tEXtDescription...!#....tEXtCopyright....:....tEXtCreation time.5.......tEXtSoftware.]p.:....tEXtDisclaimer.........tEXtWarning........tEXtSource.........tEXtComment........tEXtTitle....'...DIDATx...O.$G..._..}kr...q..1...q....u.....<H@.\.DA..E.!B6.E4./!'O.. .xJ..(".AO..........~...uuUW.....o....W.=5...Q"..............C)%..A.........5..\.....[J...Z.RJ..9.....q-............:.R...TGR.....HJ...P.I)....#)...@u$..................S).~.._...Rp.o~......e.fJ......n....{&)...s%....-............s...s.}.H..M<..RHr....|M..g..ua}.7.,.....Au....>q+.8.....`<.I.l6..~......^f;;.A.............6..L+..@?.>}..[.#......n}...-+...\..YN3.t=f.or.........._................f"}.a(Y.%.$....e.NJ..~...7.<8(.y=.Hxv................7.E>|..sTw..D.<......I..|....y..9.Zk..............Y.|.....WU...l2%"Zk-J)Nog.MP.........N.Y\.......D....0\.O.....C......:.R...TGR.....HJ...P.I)....#)...@u
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PNG image data, 251 x 238, 8-bit/color RGB, non-interlaced
    Category:dropped
    Size (bytes):21959
    Entropy (8bit):7.977738721043296
    Encrypted:false
    SSDEEP:384:Bgx9BYhn/O3qAM3+tHMk2L5wpokzt3DUhPY/+NWUipHQybnuilPuH0sF7KqHvQmo:Gx7Yh/3EU5wmSYPYOWTpxbnuNHJFfPXo
    MD5:49B2E5ADBBF5B4F5C0F4A0428008CAA4
    SHA1:F95AC457E40422DC66CE3945B4BD353D1A40FA36
    SHA-256:79E56A31789A204B6D87B56D8277B4DB54E1F590E17AF0B11A100A9EA67B9776
    SHA-512:78B0CFFC10CF127F71EE0B44C91D31236FC903B97FEA401E0D5FE95043B4365E03B4BD7B6B6310A4A70F3A5347682CCA2944A3179A14DA254A12B1F21CB9AE2C
    Malicious:false
    Reputation:low
    Preview:.PNG........IHDR.............p.......sRGB.........gAMA......a.... cHRM..z&..............u0...`..:....p..Q<..UEIDATx^..u.}Iq/..b.0.....d C...0L.2.@H.L.x.Q.n............;..{..U..s....=....o._.>.......]]}.g=.Y.k}V....H....8...........m.\X9pT.X%...{...W.82..:.....J....1`..#....*.G/.G.U.l............V.?..?....."pd.X%.....J....1`..#....*.G/.G.U.l............V.?..?....."pd.X%.....J.."....g.._.._Aa.......U....?..?.....g<....1...?..DvW...'..........._.._../../.Jd..2.V._FB~.W..._.....|...k....|..}.B..?..~.....~.A..A...}..k.v...T...V._F.......w........7~..}..=.....C..;..;;Q...9..............g..=..$.]....:../3|....x.{.........|.~*.............?.m..m....?.t...|....k..k..k~.7|...(|..|...n?.S?.7..7........|.....|..0x^.5^.......X.^.._....~.~.=..=...........~......O..2}.\TV._f<....a.{..7........[.5.../.....<.1..._.......[..[..#?.#....[.^.._....>.3>C.+..+?.......G.F.....R......I6./.r/w..~.W|EP...._.U^.......u....t.-.V....*..H<*?.C?Da....}.#.IX....
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PNG image data, 389 x 138, 8-bit/color RGB, non-interlaced
    Category:dropped
    Size (bytes):16727
    Entropy (8bit):7.938338632128563
    Encrypted:false
    SSDEEP:384:aPKX4MZyHKj1NcxrIwC0351oG5K1pr20ptX9nB61:7ocH1Nmg41oGI1pBg1
    MD5:6118E17692C1D9BCCE6A27FFB0D06DC2
    SHA1:1D66B7797B5C6A2C924120EBB43A0582832292F9
    SHA-256:DE17B44604B017B08AD77AD20BD57D7D6C3253EC03716D37124653D18F50C1CC
    SHA-512:4BDCC2209F29EDFD07C128C964714084CB701239091F2FF429E982B3A4B346AE4B5D0D017D2030AF13E059EF498BBF24E9A4179D306177816D0D6940A5ADC3D3
    Malicious:false
    Reputation:low
    Preview:.PNG........IHDR..............`.~....pHYs..........+......tIME.....+3..`.....tEXtAuthor....H....tEXtDescription...!#....tEXtCopyright....:....tEXtCreation time.5.......tEXtSoftware.]p.:....tEXtDisclaimer.........tEXtWarning........tEXtSource.........tEXtComment........tEXtTitle....'....IDATx..y\.....5-.J.f,i.B.D..-"T.K.t..p.?e........\.ts}U.K.Z.E....=55.......w>.|..L>....3.s..s>.N.....:4.X.((P.q............Q..........................}.w=.={..x..@(........>|..EEA.`"GYYY.o....F.......[[[..-X.......i.7o...500...JHH...".....={|||..V.f.....IDAT.1`...{.N.6.....~..w....LLL...MLL.R>..@....c.Y.)-&&........ ))......kmmU.G..n...#[[[...i.b.HuF.O..A`.d../..=......QYY9z.h..%''..?..1.....o.....++++))..dggkhh.uF.....\...Crr..c........R..R|U....)S.\.....2e..=.+W.....dr{{{]]]nn..........PPP0f...........IDAT.;c...&h...q...77..g......<x.g........r.-Z.SV.Xq..q..\\\...`....C.......$''......o.noo...,Y...#""n....jaa...N&Tb.%.7/>>..ZQQ1l...6LG.....s.......%...*H........#...
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PC bitmap, Windows 3.x format, 314 x 319 x 32, resolution 4724 x 4724 px/m, cbSize 400718, bits offset 54
    Category:dropped
    Size (bytes):400718
    Entropy (8bit):3.6893113184647643
    Encrypted:false
    SSDEEP:3072:3r84vAA4A4A4AAAA4A4CL3hegnAZwOMzMS58u:3KxegAZUV
    MD5:75D5859571E3BDA0D0888A74F9F2350F
    SHA1:C855516EF185EB6754FC39F45740626966550651
    SHA-256:38FA8C72372ED6E7E9EB1C360DB98125ACBECF17E3972067C27310B4B3BB7F48
    SHA-512:3DA3990AF454BB6DB57409A3B11E50E2503DF2111BF03A3BC57DCF9854317D14A5DCA48267366A515EDF039EA4B8C7667FBCEFEF53E7A6C66E79B2A314B4F17F
    Malicious:false
    Reputation:low
    Preview:BMN.......6...(...:...?..... .........t...t.............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PNG image data, 539 x 178, 8-bit/color RGB, non-interlaced
    Category:dropped
    Size (bytes):7572
    Entropy (8bit):7.880364202663105
    Encrypted:false
    SSDEEP:192:FW/KcgIRMSvf6Xe1aBHPwwx3BSt1gohAjkk05R2SEiTd818467B:4/Kcx6XeG9BSHgomjnmkSE1842
    MD5:7C7A6E140AE6319D3CC3576EC49F311F
    SHA1:1631D72C0CAA83DAFC19CFDB0480CF5B207CBA2B
    SHA-256:16725C6F971263B4A4885506A6E376CFA58FB98ECC41B5FFFDE57005BE2D6B76
    SHA-512:59E54418163C28056A727CEDA5682C885835FBADFC62EDA2CD1672F2D8BCC1F214536DAE32BD8D32A3B34BB047775C7F9A1F72B4DCDD1B73E41646AFDE262767
    Malicious:false
    Reputation:low
    Preview:.PNG........IHDR.............d......sRGB.........gAMA......a.... cHRM..z&..............u0...`..:....p..Q<....IDATx^.m.VE..M........J.EA.....)..f(E.[.%.[./...."2.5"..."(...Er..U1]..\..KsIK..L-...kp...9..k..\.{.........7.|..3g.....<H..H..H.t.P..$@.$@.$P:....... .. ...{..H..H..H...*...t...u.Xd.WJ,.C..../..$.....{......J..9QHf..4.^.(QQ^......N.....}.2.$...T.<D.e...P...&t5......6...>r.H..5k.^..(...9s&c@.y @E.C.YF.E..R. ..|.m...c...C........?..9.._...c.H ...(y.2.....woa].C....DA{......@..PQ..e.1........|.}..J(Eiii.4h.c@.y @E.C.Y..."..|...6..CE..^7.t.........*J...2....@...(IPf.$@.$...T.<D.e$.. .$.PQ...4H..H ...(y.2.H.$@.I...$A.i....@..PQ..e...H... @EI.2. .. .<....!.,#....$A....e.A.$@.y @E.C.YF. ..H...%..L..H...@....(..$@.$...*J...........%.Qf.I..H ..T.$(3.. .....*J...2....@...VQ..\(.-X...<H..H o....%.\(.....er$@.$....>*JZ.f.$@.$./.*.5.*..Z+......@T..7}..Q......$%....a...k[[..Q..d&o..D.....H.L..EQ....|.A.4..........c.YjT..AfT.2.*..$@.%............"0.....dFE)......
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PNG image data, 867 x 220, 8-bit/color RGBA, non-interlaced
    Category:dropped
    Size (bytes):13493
    Entropy (8bit):7.833190400343079
    Encrypted:false
    SSDEEP:384:K4gBYC5ufatVJsTfdpAd8LI5nWrsfow3XD1YI2:K4iYCczIaI5dooXDJ2
    MD5:8F09C4A44B758792A0EB5F5D2FACC6B1
    SHA1:6E7011632205134FFCA57D783DD9B0C372F37046
    SHA-256:B4E946E8F3306B11624426DA42A7CD502CD3FE3EF1FF00DCF2295359F5034F2A
    SHA-512:3C2444ABB66833DC8C306193E1609766E1690AADD2F32C69F2347A1ADDA72EF61E549255EC8B5EF4EACE3CF6C4490A7F253AE77F4A8C4EFEC881FCBF3C041A8A
    Malicious:false
    Reputation:low
    Preview:.PNG........IHDR...c..........Ey4....pHYs..........+......tIME..........5....tEXtAuthor....H....tEXtDescription...!#....tEXtCopyright....:....tEXtCreation time.5.......tEXtSoftware.]p.:....tEXtDisclaimer.........tEXtWarning........tEXtSource.........tEXtComment........tEXtTitle....'.. .IDATx...{.$u}....2.3.;;.m.6,.H...1."q...HDsy.xLN.$.......\...".&!.....s<1..x.K".....1.Q.da.vw...l.~..==.S[U].]....~.3;..]......W.F.........d-..02.h...4.aV_zxI3SE..I..I.k%.....j.....J..US......_.Wm.,./..G...c....h.1f........W.c.......1....H.........`.....R@0.....).]...+N....I.#O{=)..C...I....@V....'.s...n.k....uov.h. .C....4.N.l.c.=...x...9r..............r{.....F..#c5.......L.c..o..+..B...}-......w.34.X.G....../S..$MLL.....{U..{ZV.X..'.../.P...=-..........`.R.H..y.......=-...E}.+.../.p..r=#...<.92v.....gy....X..`.V..u].....zf.PO.;sv.\..V.=-..BG.~.\K.B......T0..X*.d..1.}\.1F.riU............w.R.1FG...8F.\o...8.e.3T..$.....J....1....O2....e.c...$...{..9.e.c0.... ]...$
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PNG image data, 623 x 870, 8-bit/color RGBA, non-interlaced
    Category:dropped
    Size (bytes):80425
    Entropy (8bit):7.968342575509573
    Encrypted:false
    SSDEEP:1536:ggyNmZMivEs/R51CTHwbXCQ15kULFCRbIdhPIapivWvvF:ggyNmyivEg51wQbyNo8hIfIasWF
    MD5:B4621E7DE4C3F1F04EAACBF09FC6DB0B
    SHA1:0F9EE2797B4A87BDB2842A76922D5B972A6E8B20
    SHA-256:B3268E940AA72F6591A09F45C22F147ABC3E72388E1C9B18B795910B85A6FE4D
    SHA-512:AEA07F2275AE5C813A0C5A9C5C34532D501D0836F0FB6894258C7447E4B3EDE5CEE6407AEB6C2577BE9D63E9C6A13C88BCBC85D558813464920790BC5FA065FB
    Malicious:false
    Reputation:low
    Preview:.PNG........IHDR...o...f......Nl.....sRGB.........gAMA......a.....pHYs...t...t..f.x....IDATx^..`.....,...B..[B".V..""X.M...........ZkY.V...)..eo...V.-...U.....`.l,.,.....!.........%7.M....9.937....3.QRR..@yy9.]....2\.z.....ir..<.....0..0Lh...@dd$....Q#4n..111..+W..H..@#.Fb.8s...=.7.|S...a..a..c.....t..x#......./...F.M.9.m.....{.I.........j......8.4._.*...../....?....N.....y...f..7.r...P..w}....1X]...[....[M]#......).y..z.-<...../..?.>..o..6.z.!9.k.......#.C..A.=.I.M.].t.E^7.nd.~.......?.-....6uBm.....M...../.:..o..*..U| y..._..i.........P.v.....8..wF....W<.fG..S.P.e&.UB..`..}8.k..;....Q..8..m......C.cu...2.j.U..N.|........+...c}....._m1.7.?......X.n.../GBI.R.'.|.?........k.%"I..2.:uJz.H..|..(...if...55..m`.q.jZ0F^C2.4.x;3.JS.O_..4..9l`....^p.....6....j=.Am.c\..z...'.m....:..e]f..k.W...N...8..J......../j.Vu.....JW.]..h..8...@....*c..MU...o...../u..;p....h.4..p.....6y.(L.."...H3.Y..u.]G..j.S..`.6...9......O....5.aU.....y..*
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PNG image data, 742 x 361, 8-bit/color RGBA, non-interlaced
    Category:dropped
    Size (bytes):56633
    Entropy (8bit):7.956864785647697
    Encrypted:false
    SSDEEP:768:u+bpqv8EV1avzCLWORrVXvsb4D7ayskbVvpBIQiLmbu6L/tdpNhzLlcZjHtWWV9U:NbSfXB/sseybxF/SIN0jtWm6XNv8rM
    MD5:B7A260F924C6CD6329E83C3C1B7A1E90
    SHA1:805AB5D8B0B2CC3709D3D2B27BE059E9CAE9D81B
    SHA-256:7119658BA635DC7B9FE4CB4BA8B5333AE9CBD881D4856A6B690D500AA1C5FCB2
    SHA-512:85389BA940854805DBF83EC3374A7DCC3190698E6EE952C32EC2963121EAB07E2EAFFBF3C94E85C2E6236F3E5288AA0D43685C40F4D9A4D8FCD79443E9B8CD56
    Malicious:false
    Reputation:low
    Preview:.PNG........IHDR.......i............sRGB.........gAMA......a.....pHYs...t...t..f.x....IDATx^...s_.u..o...u...N.4}..Tm..4t...6.L..06...B.LI..An.....c....F..4....X65.b...-.mY.$K.].-..^...9..}Y.r...#i=8...|..g..^...^{.5s.. ....[.....O9....Y.......|z.`....y....9..I........pM:&...S.q5=n...0..c....1z}......X.Q...`..........e.e..w.='.n....e.D...)..a'^..F......m.M..m.=d.....$.!l..C.d9...[^.J..........flm(...h;J...Dj..m.2M.....l......md~F.A....2j.._.|...d...I..$?..Cn..OZ.>%...>..#-....3u...f_..w....Wx?..-j?../.....1.1..s.W.'.....&.m..`...2.c`..[.F..^........s..\...).N,'.+ " ......N6v,.c.0...d..1...p.8Q.3v.`R...`b.)CA.$....6XcW.#...L.5..n.....f..r..P...P18/...Bwr..A.2.E._.s.q.s. =....\..#A...%@..,^...G........ .h.\.q;....aZ.#B..O..........O.}..C..E.).....,...,...r..|Qi_..V.y..+..@8/....{N'..5.".Z.H.s9r^..x...5.#.1.....)..5...0f.,Q.y.b.d.p..(....>...1X..`5..bE..5.74j.Ef.....x@.t...V....#...w..G.s9j.a..{|v,.7.D....y.c.o..<...F...I...5.gf....bk. .7.Qs....U.V3t.<..y
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PNG image data, 483 x 528, 8-bit/color RGBA, non-interlaced
    Category:dropped
    Size (bytes):31538
    Entropy (8bit):7.919203223420377
    Encrypted:false
    SSDEEP:768:VpaLcPRxvgmS0IxXQ0jlI/Bt5MwXF8cmRWdf59mILD8:VoLERanxXPJIpt51XmJBb
    MD5:3CB0FB392F51AABD35E8E07A0206768F
    SHA1:F83EF7DB4FFCA6EF5AD28AFBB1945A7346BCE81E
    SHA-256:86BEAD12621CC92ECF647558561816AB858355769AF773DF9729B1BBBB84E8F5
    SHA-512:C81BDC098747CE733F0CF4C649DEFDC1E2218E6D290A22170289C90F5541DFC0FDF3ABB18FE5B6224B797B6B1521797573049D9C72624B8E29213220D519B848
    Malicious:false
    Reputation:low
    Preview:.PNG........IHDR.....................sRGB.........gAMA......a.....pHYs...t...t..f.x..z.IDATx^...Gz.{.Z...p....@..w#...XK..v....1..n..~.s....q.u.0.bv<..H..M[#..Z..k..h...h~w74.f.Gn=Y'...........>.Tee~.....dVe...luu.......Ev...v..yv..iv..qv..Qv.....G..czz..4....`.......C?..c.U.+qv~~.].t.....A|........c......M.6......l.6...h....w9.gff..~..9.zw....1.ynn......./...../.....y.E...<`i..d....H;...<....as.5.r.U...G...{...$.mt.u3.Mm...T...f6:.uN^........hfk......5......m...-..\.........7..".._.....wx..W.....u....;.A...C..q..q.}..A..},//3.XZZb.......7.zP.@=._.....kL=.^...4W../3.....4.2../^dI....8.<.3.-....S.(.T.QFQ~.Fh..l...^>W...N.^....I{..e.u..Z}...Lw.t.|P8.tP.s=..>".......M.4I..~.m.E..d.>~..We~'..I..e.:..?.O.....o..}.x_-.'.........+.;W.v.?*.={.sE..S.o.,.V..G....._....N...O......&CsiP:.m -..0"...g..:...@...*`t@....d....:.T.M.m..m..e ..rT-m...X|.... KWg..S.M.L.vN..w..8...rn....K..i@..('9(I@Va,.....~.~s.......c..l..].-q...{...D..~......{.:
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PNG image data, 750 x 187, 8-bit/color RGB, non-interlaced
    Category:dropped
    Size (bytes):22952
    Entropy (8bit):7.955650332122989
    Encrypted:false
    SSDEEP:384:LC8bipwp9lLaEBCcCQ0W3trkzO+jBxMT1KaZBdg36E9WwVHYbV7iXkwqvAo8lwiW:/ipW9UtcH3tUjS/+Iw6R7iXkX8lcrvF9
    MD5:4ADEE46905AC8F57285134A38489DB41
    SHA1:3B0613F31EE20E54C92107A75246007B306A9283
    SHA-256:A02F58DE15B8694CC9FEA421D1AE365B2AB1A8EF7285ACF4B799DE7FB3604792
    SHA-512:5B5C2FDF98124D2B7AFC0E8F928FE797EC17F17384948B24DACE59533C0E2B2CD3DACF2E2B298E6470B450354F5A25265ACCE7CCA18D3DC31F7F8223451548AB
    Malicious:false
    Reputation:low
    Preview:.PNG........IHDR.....................gAMA......a...Y_IDATx^..XT...1^c...Mr../.$...5.kbOLbWTT.{o."..X0V,(. ....V,X.a....X.)..t..].5.{....q.....3...w...93?..9[.....x.J.*U.Fc.Q.T..@.*...b..FV......B..=....N}...?_........n..wc..[.3..F&..)....T.* .[.P.T...T....B..d..........f.i...b.N|n..]..W....&..0.W.F.O$...t.1..I..yg.......(..Z.7......@6$..1......*...../$..$N...;M.!. .....M... Tu|..........2.Lr...o7.z%X.y\iL...q.$..T........j..S..@..&..I|..%,..K...*...*Pi.K...U.:...,Cf..*.?{gLA..y..+..X...X.wP.|-N..iE..t./..M..Kc..@.h.G.U.hD...2.nY.|.:.M...B......kD.s.z..c...0....*.....(0*.2..i.F.....V....`.,..($.gB.8......Bxh.).....i~.....2..2p..e.<...i.h..M.R..+.^-..!.z.hLX..*P.@..`...*...+.....Zx...V^!.....].\ ....a..8..E&.^..f.......n.v.1.!7......0).x3".jh..`."}..3.T..@.P..@........N|....p'.iU.....J..;n.{.2]..,{Z.u.....*3..;i.]....'.<.....*CQ....`..KJ..@.......]...*..#@..`03..nH.V...?.Mg.Dk..<W..LM.._.1.....N...>....d5..w.I..%'.X'.}...1...VMK.7<..6..Z9..b..Q...~.
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:GIF image data, version 89a, 15 x 15
    Category:dropped
    Size (bytes):891
    Entropy (8bit):1.7350200267968847
    Encrypted:false
    SSDEEP:6:PvV+Z5heq4qRssDVu/3Qe9L3kICUp2lC+:PNA5kKsgWgeDCUp2l/
    MD5:FDACB0F5E8BC344EA4D521D0EAD5D1AD
    SHA1:BE3802F716CC1C5D6E9E54A2604BCC7FA7045189
    SHA-256:8EDCD243076C6B2893ECA050AAEEB36C6E31C2F38174C9957F5D4C6E204B6C80
    SHA-512:4A18B2558765790C80A95AE7AA34A3BFDE146FB4A14FF7D6B1D62C9DE4F335839C7ED662176E3A7CFACAA185855C10DF121484829625819098A438A384CAF6DE
    Malicious:false
    Reputation:low
    Preview:GIF89a.............)))BBBZZZkkk.............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................,..........`.........(4p......$(.. ......hp....8.. `.I....l..%....t 3..-k:P.`.H...4...#H...(.(.b..(.H....;
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:GIF image data, version 89a, 32 x 31
    Category:dropped
    Size (bytes):1493
    Entropy (8bit):7.802925479785536
    Encrypted:false
    SSDEEP:24:5SfUa1UmImvn5gPeOOBYWJhAGQMQ55vKfxbhzOPE2SM4DKUVAoCdnnl/UC:5sXanmKPeOOeQVQ15ChhzZsomoCdnl/J
    MD5:3E1AC5E2BD6B282BF8418ED5903CC37B
    SHA1:4802B0B635776C26144EC553A717F67F14E7F104
    SHA-256:2AE1E0FBF0AD822A9F4143BDEBDD9A9E8AB30BB0E4DF226C7E7791C17595DEBA
    SHA-512:BA294C6D6DAA2EAAF5334AE57085791A24EDC198B602A48FE9C89ADE810D5929FDBE5149D504F80F1611FE47E30FA891AF2A93F2645ACF739C3F3AEFEDD50ABB
    Malicious:false
    Reputation:low
    Preview:GIF89a ................................. """&&&00044466688889;:::<<<>>>AAACEFGGG@FNEFHFHJJJJHJLKLMNNNEJRNT^QQQUUUVVVVWZXY\]]]X_hY`jZakbbcbcdeeefffegkjlommmooobkxam~fnyjmrmpumpvnqwlqxms}qqqvvvpt{rw}vy}zzz|||~~~mu.iw.nz.rx.v|.r{.u|.v..|..|..}..~..x..~..u..z..|..}..}......................................................................................................................................................................................................................................................................................................................................................................................................................................................................................!.......,.... ..........HP`>Z....C....g.:.n.:B. jt./.^........l.:..:u..C....`.|U...M.vn....92?5.H..:}z...vh..:.5........1..S.2?..Q..9|X.....l...G..u....e..l.\1........a....9`+.1{..(B...c.9A_...3...-k
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PNG image data, 667 x 454, 8-bit/color RGBA, non-interlaced
    Category:dropped
    Size (bytes):45984
    Entropy (8bit):7.9192354532396285
    Encrypted:false
    SSDEEP:768:OC2ClCy/iMAkL6fqvn5NlsY7pFlpFfbOsF+YNeINAoPv9stwwTfZXi3so:OC2ClCzLszvn5HJ7pFFfqsF9Kmv9Xw9q
    MD5:205261AF717F56916D05AF6E06A2482D
    SHA1:690F8459BE6F0B546F658793F1AC548DF0AD7B89
    SHA-256:8134F7CED4B97EA668F469C837C5DEB3B6ADBBEA491C9052AAF26D62DB06B0F8
    SHA-512:C236517694DD404E0DE3E03FC2CCC88D8EB613829DC9EEB3FE856592F988804F9C96DE7DEBF612939589E21B31C4D1622927B097CF09C2DA506F876DDCE705FF
    Malicious:false
    Reputation:low
    Preview:.PNG........IHDR.............;j@.....sRGB.........gAMA......a.....pHYs...t...t..f.x...5IDATx^.....y.}g.g.I<.,.L.|c'....b..db...F.N..c'../.!..H.l..l...b. Y.....l..]@...B.M.eu.%O}.v...........}.z.9......w....zd......S+W.T?.....~..u..W....../.X}...U.^x........m..o}K......l..@...4..@...4.....0.%.\......t.Ru.-...+V..m....zH.z...+.L.r......C....h......h.....5..}N}.._M...^{m..#.<.H.<....7..^......H...K.W^._~Y!U......._T.H....n:t....<.:...8..........S.|:.y.h.:}.T<..y.7.......>D...l.N...........?|.....C...T_jSbGbHb./~....R#......$.|..^.....{.9.~.z.......|0..sz....%:..}..8.{.J.{.G5)..G?RU..w.8...m1..lKw.u...;.3.. ............oW.n...?}.D.lN..!..7.d.....o.QQ....D./(]...y...W..7..l.B.....(....%K...N.DOH......i...J&.."..../.]..t..+_Z.h......2%.=..I..,P1..<.....#.f.V..l.n|.Z..g..n.6u...~.........s..y......}.}..3.&.W.o.....7s.M..g..e.O..........A..>......5.>D.'._.=..gt.......H..t..{43.....d....6.|....}......Q..+.e..........N.$.j..N/.
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PNG image data, 851 x 499, 8-bit/color RGBA, non-interlaced
    Category:dropped
    Size (bytes):41371
    Entropy (8bit):7.811192843740686
    Encrypted:false
    SSDEEP:768:K7XlBoH2otcHPwbTlR1eBvdwIYHZI2sQBPeaWcdDgwVy:2BSY4PQ/B0TBPeafBk
    MD5:09176ED54A20F43782D3A5B931B4391A
    SHA1:74000E5B4579935297D7BBEDF44BE4D757F0C0E8
    SHA-256:9708FE248AE4F45A4D8ECEFEEC9874FE1A18A6E9A50A8791B63D58D115E0C04A
    SHA-512:118FFB2B68062407FA041577BE6E80DC5F79D681E1A6D41CA277741292BEC0ED2935C069B1E902713930D0A877BF640A11B824579151474F8308328459FC7617
    Malicious:false
    Reputation:low
    Preview:.PNG........IHDR...S..........;G[....sRGB.........gAMA......a.... cHRM..z&..............u0...`..:....p..Q<....pHYs...t...t..f.x....IDATx^...|$e.....>.8\=..mHB.d..tP.U.H...%.9....#.0..Aq..nV.....!Q......*A.. (.#..A.3`.d....r..:.3..y..U....Ku.;....&..<.<.........-.z....@....@....@.......5.#.... .... ......-..... A....@....@......X.~...#St...@....@....@.....2.H.... .... .....L...@....@....@..2....@#... .... .... @0E.@....@....@..... .*..$. .... .... ....}....@....@....(C.`..4. .... .... ....S....@....@....@.....2.H.... .... .....L...@....@....@..2....@#... .... .... @0E.@....@....@..... .*..$. .... .... ....}....@....@....(C.`..4. .... .... ...-.zh......C...o.....r...[/.MV.^-/{..d.....1........%.. .... .@....7..L. ...d..r.%...'.PB...>*_......K....J.XZ...ZZ.l.... .... P...T.r...'......s.1r...2rh.$k......g?.Y...C+.ci. .ki..5.. .... .@..N0.=S%.....r.q..H....S.h.b..K.tj....... .... .....0...O|.....>[B.x...}].he....mn/..S.5.yM..k..u...;m....c.f.|..r.i...j...Z.....U..W.
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:GIF image data, version 87a, 24 x 24
    Category:dropped
    Size (bytes):1148
    Entropy (8bit):4.677225304861723
    Encrypted:false
    SSDEEP:12:0HuJY35Cq338c9CZkIHuOzkI2NC61QfjaKftkOiCi6YHkZC7NFBymamQ:MLhMczefYQbFXbQkZC7XBymaJ
    MD5:CCE60E8BA951AACD5E6E2352465882DB
    SHA1:637CAA9D1E68969E13401F8B01BAC9C3CA3176EA
    SHA-256:12C1CE0B73E8638B1EA3A5DAB51D51D416CD0C9AB3E3687980BAFB49A205F8ED
    SHA-512:F6031EDF73E7EA32698ED509569F9EBD41840EFB2B197312D64A204D6FA29C56E2ADEE133B1C64E8FB2B7D6740F4F5557888C546C23D96EE2D6C19457D4CDAD5
    Malicious:false
    Reputation:low
    Preview:GIF87a...................!!!)))111999BBBB.BJJJRRRZZZZcZZ.Zcccckckkkkskk.ck.ck.ck.kssss{ss.ks.ss.s{{{{.{{..{.{{.{........{.....s.....{..............{.................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................,...............H....T`(\.!B.0.8.H.". ...pb..G.0..Q..a.(.S..2edI..P......../.i$G..98\0.....H.".r!...Fm.xa..#.B... ...~.Q......h}....).7...B.....0X`P...z.@..o....*...q..;X|..1.)...TA....PR.H......t4....@.1. 9....
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:GIF image data, version 89a, 15 x 11
    Category:dropped
    Size (bytes):941
    Entropy (8bit):4.341083623076991
    Encrypted:false
    SSDEEP:6:DG2ydJMufuOopSmxdzR+sxUnm2iaGsjyfGrGGk92CLwgyotJlp9u+uUowrJsVN+e:DG2i0p8mbzR+O+n5qtNLwutJXMqoEoge
    MD5:89A0D281832F6C9605E0408248D24384
    SHA1:A6131A16915AB4D0308BC5963A4666729BDB7F76
    SHA-256:B9423BE98181BB7CBCC8E28EF9712572BBDF2704CB7CD17820AED15B4500AA09
    SHA-512:99D346191117FD22959818DC5C2A3C1787EAA2B172F9C6285B6B5B6579739217D4A00FCE80B793DDB30DD684D3009163C07DCD53D22FEF0C66B17C819EDF4727
    Malicious:false
    Reputation:low
    Preview:GIF89a.............'''041>?>;@=BFCTWUVWWbfcdfdehfoooqqqwwwxzxw.|.....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................!.......,...............H.`..U.t.."......Hq...;.`9.....^.$....%E.<..e..)...P..'Vt.....CP.h!.I...(4@.A..!&N.......[nD...DT.3.P).%.. A..!.A.......`..x...;
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
    Category:dropped
    Size (bytes):1182
    Entropy (8bit):6.51483668366577
    Encrypted:false
    SSDEEP:24:N1h4SHWwjx82lY2T3UVr0H+0XyJ3V90+9UA0wGm/lmGI+byh:zKS2Nn2wl9dJ3vMAzhehh
    MD5:DB9744FF00E37CA8F37963D2104BDDF1
    SHA1:4B34F7EE95FB70B5162DDFD407CB122204434A6E
    SHA-256:77C29C1AB1B64E82E24066554A2A2DFE8C2CF2D6F3AF66C04312B07210CC1666
    SHA-512:F17ABB9A40F512C8D68C512930D6B15D2C279346123B2F7902609087C87ECEEC869B9AFFEF454B87E4296F69579435FC3A0B6D68B106EDC14B950684613F265C
    Malicious:false
    Reputation:low
    Preview:.PNG........IHDR................a....tEXtSoftware.Adobe ImageReadyq.e<...#iTXtXML:com.adobe.xmp.....<?xpacket begin="." id="W5M0MpCehiHzreSzNTczkc9d"?> <x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="Adobe XMP Core 5.5-c014 79.151481, 2013/03/13-12:09:15 "> <rdf:RDF xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"> <rdf:Description rdf:about="" xmlns:xmp="http://ns.adobe.com/xap/1.0/" xmlns:xmpMM="http://ns.adobe.com/xap/1.0/mm/" xmlns:stRef="http://ns.adobe.com/xap/1.0/sType/ResourceRef#" xmp:CreatorTool="Adobe Photoshop CC (Macintosh)" xmpMM:InstanceID="xmp.iid:6D2CCDC0ED8811E2930D892F06BCB8C6" xmpMM:DocumentID="xmp.did:EB82AA72ED8911E2930D892F06BCB8C6"> <xmpMM:DerivedFrom stRef:instanceID="xmp.iid:6D2CCDBEED8811E2930D892F06BCB8C6" stRef:documentID="xmp.did:6D2CCDBFED8811E2930D892F06BCB8C6"/> </rdf:Description> </rdf:RDF> </x:xmpmeta> <?xpacket end="r"?>........IDATx.b...?.%..b....%..g.<..h...... ...b....:...@.....d8.q<P......P.K3....}.{..X....3..f.X.D.x4....LH.'.L.:-.
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PNG image data, 329 x 167, 8-bit/color RGB, non-interlaced
    Category:dropped
    Size (bytes):15933
    Entropy (8bit):7.933261417229072
    Encrypted:false
    SSDEEP:384:71BJqd9Mj1AKspcdupsz7m+6agy+TgSZbHza56bN1Z:ZBK+W1rpgH6JvZbT8Q1Z
    MD5:AF39555EADA8B86A22F16C8E9509CF25
    SHA1:A6D926A48F3C1AB38843C03A68B49E17DB222741
    SHA-256:F75EA45F7F37AEBB0621BB30E176930C93E870753E9D78C7E986610282BE90DA
    SHA-512:F177CFB8B21D241B013CE0D363AE7F2E40849E05425B60D26185D0837D5853255BC813AB228B9E75383EAAA6653F5AB93C7A68C96E3B40C2179401BC59AD4279
    Malicious:false
    Reputation:low
    Preview:.PNG........IHDR...I...........9.....pHYs..........+......tIME.....1'<.Ny....tEXtAuthor....H....tEXtDescription...!#....tEXtCopyright....:....tEXtCreation time.5.......tEXtSoftware.]p.:....tEXtDisclaimer.........tEXtWarning........tEXtSource.........tEXtComment........tEXtTitle....'....IDATx..y\....OV..k@.. KY..(.*........J.}..u...jk.r[[.-..Q..K.E..R.......}.....s;wn23.......?.s.9.I....;..A.@CC.......(.~............5D,...............H.............F.a.....y...T.J ........n{.....V..m.%11......$''...P....j...~~~T.I....u...-,,`./Y.(Df.....IDATd......@PWW.d2.L..#.........y..=k-55...;p.@GGG/....?.....p.8....>r..;.bb.e.?.....555...D".E/......(..........\>.....D..Ckccc.....v....CoeV......>...c..~Oih.........%.......e..........--lqWWWCCC~~>....ijj..........g.....-...O.>...`...@hh...v......IDAT...SSS.......-[.KV.Z...'.Tyyy\\.={``..8............X.rell...I...[.w..'......844=.0....mll$.mll....7......R...f..[..ww..{{..g......haxx..._aaaSSSJJ.,,...aChh..{.
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:GIF image data, version 89a, 21 x 19
    Category:dropped
    Size (bytes):895
    Entropy (8bit):3.603831066478751
    Encrypted:false
    SSDEEP:24:TkEGY7peHU2k7N7DRhoZNtwNKzbEqNpmRJuNEKcE:wHU2k7N7YtG8EqNwcNH
    MD5:7125019A9552B98C3AB6420AB0CC6483
    SHA1:898209F8120D6BA7664F1AB00D369A20122ABF38
    SHA-256:940C1647E535727618F86EE38AAB0DD78AADCB90A0AF6D9B7E3457A5339D6BA5
    SHA-512:F246926FF9FDBB1CAB998BAE7AF11D473AEB3DE01C37191A32AA7F32533CB0C352EF081A861B4B6B409B14D43AF530C05EE8AE40B88C7E007364C30229505ABE
    Malicious:false
    Reputation:low
    Preview:GIF89a....................................................................................................................................3..f..........3..33.3f.3..3..3..f..f3.ff.f..f..f......3..f..............3..f.............3..f.........3..3.33.f3..3..3..33.33333f33.33.33.3f.3f33ff3f.3f.3f.3..3.33.f3..3..3..3..3.33.f3.3..3..3..3.33.f3..3..3..f..f.3f.ff..f..f..f3.f33f3ff3.f3.f3.ff.ff3fffff.ff.ff.f..f.3f.ff..f..f..f..f.3f.ff.f..f..f..f.3f.ff..f..f.......3..f.........3..33.3f.3..3.3..f..f3.ff.f..f.f......3..f.............3..f............3..f.............3..f..........3..33.3f.3..3..3..f..f3.ff.f..f..f....3.f...........3..f.............3..f..............3..f..........3..33.3f.3..3..3..f..f3.ff.f..f..f......3..f..............3..f.............3..f.........!.......,..........\....H......*\......U.b(._..............FQU.x$...&2.B..Q2.W.%E..e..Y.B..t*.Y.....P\..S....;
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:GIF image data, version 89a, 17 x 17
    Category:dropped
    Size (bytes):619
    Entropy (8bit):5.92844646927867
    Encrypted:false
    SSDEEP:12:ykpnhzjEU0dkbM9C1RPcp6MNUZSNCHEe5I:yshMqdjcZNjNC35I
    MD5:68D766AAB7BEA4BCFE04F201DE08FEF5
    SHA1:1E7B3F898D53D40E398C4BD7F2ED63C9DDAF9E37
    SHA-256:F77132D4F62095A9B6A1D3ACEC73233D8EE4C21BE1624146CE01B3F804F10656
    SHA-512:BDEA8768C443B97CF8CE4A80BE46AD49F6790CE10C0D43989602A13A51370BE77704818E6651E02FF355A9100C72F8EA2E25FA9AADA967F80BA20D4DC93395A2
    Malicious:false
    Reputation:low
    Preview:GIF89a.......\a]......................uyw..........................nuo............fff.............................{|{................................rts.........................x.|..........txx...................................................................................................................................................................................!.....E.,...........E......(...%...'.;..5..7..&.A6699+.#.=*6.B3.'.>"..4<#.).@...4....0.)...@1...8..:$. ..-...&.?!8./.../.8!?D...-.. .$:..8.C.1@...7.`|......(.<Ja`........D..B..P.C...+0`(Q"..........;&.x$.A...P.....@.;
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PNG image data, 464 x 547, 8-bit/color RGBA, non-interlaced
    Category:dropped
    Size (bytes):28116
    Entropy (8bit):7.883136326664214
    Encrypted:false
    SSDEEP:768:5KK6sxIxtEwD1papnhWcoYPCHmcsEkXmj6:TxSQoG31Ehj6
    MD5:FDEA1D30A4EDD4135A12C38C9C355BF9
    SHA1:E22E27820DEDDC4034585CDA0DD3B1B6F1DFD7C8
    SHA-256:3306EFA9BFA6DF046B89E9B2CCDD42922C8ACDB0B64DBCA765CD5777C8EFECE4
    SHA-512:F261D21226F2F7A55943174FDAE1AB0FE51788FA1AAEBEBEDAA928DE93CE198E320BE603B50D8C0C19BAA2A6673E24CE2D5B9A8FF326FA41ACD071800017250A
    Malicious:false
    Reputation:low
    Preview:.PNG........IHDR.......#.......J*....sRGB.........gAMA......a.....pHYs...t...t..f.x..miIDATx^.{.]..w.Y .=...A. .l.. .d.......x.....M2.de.z0.......^K.&....`.c.,Kn..z..$.gLQC."..H.).rS.$.b.l.......A...T..S.N.s...O.....:......U...~.....X..`....4~.......X..`.A@...`.,...@...........X..`.........X...X...0..`.,.....@@a..`.,...@...........X..`.........X...X...0..`.,.....@@a..`.,...@...........X..`.........X...X...0..`.,.....@@a..`.,...@..j..V..^........X..`...@#..z...\Jx...X..`.,0I.h,...a..]...Ey..7.w.W....]...:I...,.....P.....{..z}.~..w@_.8%...e...o.s.../..$....|F>.\.^.Vg....Nu*.....X.4./.S.[n.Q....../k{...r..........`.,Pi...t~.;.o.Ay..!9t..=qV~.w.'...G..g..c...4...B.....x.u\..r.g.YU...X.F..l..k./..@#[..O<.......@..*.|s...{hQ..9&.._......K_]'..........FQ.h.H.7...Y...X....\....-..LMb,.....,.$.j.v...x..;...;w^..<*..;..g...ly...v..:|.....v_~J....h>...S.f.....$.L.o.%.B.k....*S...*Y..3....(...*i-.z.g..^...o....gt]......,.....U..nn.........R{........n.9bC..
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PNG image data, 1057 x 394, 8-bit/color RGB, non-interlaced
    Category:dropped
    Size (bytes):26863
    Entropy (8bit):7.7709561824408055
    Encrypted:false
    SSDEEP:384:VFMqwgu51AOdbP1yU3ulo1Eu1C/bBz2jt++DpH0E5H9SR1WwV5d:4z51JdbPMU1EdDBajt/Dd0GS7Wwl
    MD5:164D7DF4C0F740016E7D0446CB007B8D
    SHA1:A8B439320D882A980C6CA7DB4ECCA97F7B6673E4
    SHA-256:20F810697CC309974B018021754E0149C887ED4182472E17C12160E19CE1112E
    SHA-512:B434746F865705587966FE34956BDD42E8F274FC13F2F2CDD07AD8BE894D452C38D5D5BFD7282E429CA23FB03549660CD48C10B660ADE050E2E7AC26E5FE1600
    Malicious:false
    Reputation:low
    Preview:.PNG........IHDR...!............#....sRGB.........gAMA......a.... cHRM..z&..............u0...`..:....p..Q<..hmIDATx^.....U.........?3..3...8.cp_. ..! .,.fTPDg..gD....#.(..............:...5....I....99.S...uo..u^...N..n...n.....z....L.0Q&....O.8a..j..&z/....'L.xp.Ao.w.....w..RF....@....S._. P....U.a. p.|...._B.W}''...}#.Q....#..^.O.F.6<......../..z{;{.t.K.%.C}M8.V.QW.t....8.....k....?<8u...?=..[.6.g~....6.....*....).....j=w.]. .X..DU...U..6?...IR.&../.x.V.M}...Q5O..#>.%../.L...t.1....J....7.n.9T3'.....@....@...2+ %.jj.......u....".n*2H.t.~i.'................z.yW..&yc.U;'^.OR......9(M=...D.@M<....2..IC....@........4...V.9#...^..M.....N.r....&\..h.......cS...T.T...<;...D..d..sZ....iM.u...a?c..........3]*oH.P...!..V..e.2>... .... ....dZ...].3.n..I.......~..6.$<.v.....Y..M........<.....+..3.w.".i..g.0.T....:i.]........F.d.......S........@...*S@"..F...\.....a.i....q........$.i.w.h...g...a.C.Ce.F.r.?E.w\..]..7);.U..!.... .... .@v....u.B
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PNG image data, 425 x 191, 8-bit/color RGBA, non-interlaced
    Category:dropped
    Size (bytes):11141
    Entropy (8bit):7.914100789862238
    Encrypted:false
    SSDEEP:192:6ko1UwldhHBrKghTtXYD0jbh3PBq/e3bCTYKlzgL6DloYK5sZSog8WgtMXtQ:6huwVHBD900jJY/ACTKL6DljK5s0q
    MD5:B92DD0D78583BA34AD09B727A2702251
    SHA1:A34BC085F1F26C9A08E280E26FF7D94602469960
    SHA-256:A0A9AF9E27FBECD612CCA6602F02CBE535F1EB842D6614AB07DC7477760158CF
    SHA-512:3A5E4166BFF295051C001234C4387C8224FEE330C01F8BC4E622699F4FAF1EF2C9BBFA6C2B42F0A4939CF70A0E6A7EEA1529E2080F2FBB6BD6A2C1426693689E
    Malicious:false
    Reputation:low
    Preview:.PNG........IHDR.............D.#i....sRGB.........gAMA......a.....pHYs...t...t..f.x..+.IDATx^..P.....|.......bD....-.'@....c.6.$..1.m.;s.9...m'L'.09Snn=7!.=1'.+5.0$1.!..hP.`.QS.D1.x.../..../../....].......~...wG\S.L$@.$@.$..."..&.D.$@.$@...E....H..H h.P..vhh.......E.s..H..H h.P..vhh.......E.s..H..H h.P..vhh.......E.s..H..H h.D.s3............ga. .. ..A.o.zd.F...~.VP..B.B$@.$0..LH.j..<.....ys.......qm.*r....i7..a. ........x#..M7-..o...e....x}.gXr......6.|.Z.]../..\'..Fy...moLRr.ak..q....Lc..e..r..r.]kM..8..A.K.@.$...&,R.>QQ.......HJL.UDag.G.y...?=-..J.E..E.T.~e2+x....6...G}}=...j0...e....$. .. .......!...8u.$'....{....9...N.....7...o...j..{H&..,.p.V.Pl....B..w...I..X8YM...%e6&.&.3o.y.i.........LX.""#......J.f 9).....w.kG.:...1#*B...../=.=..l..L....{].v.0...l.........p.!.e....qF.F.7.*<../.U...b.....H..%.n}..^.yN...:..8.!.v.G{9WJ..3..}......v.....3.G.y..-.'.T..6....L$@.$......9i......=W1s.L$$$`...!""...a.Wo....."}5.mvU(Xs?.......l.}....X....?.....N.L..
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:GIF image data, version 89a, 25 x 11
    Category:dropped
    Size (bytes):970
    Entropy (8bit):3.39944507331282
    Encrypted:false
    SSDEEP:6:0Wn3bAehmWxjKkjOIcqgXr8WBBLFQD5L3cveCeyfH2WSsTFwgsm4D0:00AehBrxchXr8W3LFQliSyfH2HsdsFD0
    MD5:99071E2DF379B422EA910DC7ECEB4C98
    SHA1:B368F96FB8646F3C258721AE5D7B24294681656A
    SHA-256:C16A2E6F0FE269B4984BD246138B43D57A4646912C1719E07E9A7246F0AAAB4F
    SHA-512:DB91AC884F9AB675E6169C442773586D4FA4B453E166EB150F0F7AD62899FD2F38B8A3A905ADBB727EDBB814D5157822C46BD631ADFD43936C046634C94FBE98
    Malicious:false
    Reputation:low
    Preview:GIF89a................!!!1.9999BB9BBBJJJZkcccckkkssss.s{{{{.{.s...........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................,.............X.@.....1`.....(N..H...#B..B..2@..Ir$..&\...../X.x.s&.2_z.Q.D..'...Jt...\8..Qb...R.P.B... ...ub..B8.p .../.....Y.a#..p@..."..i#......x..d.."E0.@...."K.Lyr...t...;
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PNG image data, 33 x 31, 8-bit/color RGBA, non-interlaced
    Category:dropped
    Size (bytes):1312
    Entropy (8bit):7.765550983451479
    Encrypted:false
    SSDEEP:24:nnztPWlXueI8hOwvrBLGMmGhxmdYttKGDvfV7utr++75GTB7Cp/Wocc7g8tIl4d:nreMwvrBQbytdwtrv7YB70c1S3d
    MD5:9B053037F410F92E801CFA476F2C4330
    SHA1:499612947CFCC55EE8DD5966A97C09ADEF24BD27
    SHA-256:985F22E094BEA336479CF52F04E0216FA9E77F18E943C2E12F15C3C2896A7042
    SHA-512:D0C3FBCB402CCF78BAFEDAE1771453FEF4FF004AF09C2D05A162AD1D239F12521C1FD3FB77FADE086B1C5D2C08A5E29FABCAEAF16D2EDA0C2D064BA5304D5693
    Malicious:false
    Reputation:low
    Preview:.PNG........IHDR...!.........i.......sRGB.........gAMA......a.....pHYs...t...t..f.x....IDATXG..KcW...O..a^}..)Z..U.Z.......:...R+...ft.T.I..8U.8..:.R.+^.>j4:***.b.I.D...&9.!........~Yg.}......_.GGG8<<.X......P..&..z..]]]...Cmm..jkk...,..boo...."..."./NOO=..f....C===..8A...cll.UUU ...)....F#b8...^3.s.............)...V.U\...\lmmaww.I;;;X__...[.Zz\....FNN...|\@..f.t:dff.............\-Q].3..B.t.;..C..~..x.....LNN..W....h..a\..q..IK.*.W|.u........k..u?.`<Y....Y...9h..`..............Ya*.~..n...^.Ea{..q-=......U+...~...J.;.BLL....122..B.///....;....=.Jx.`<I&8.. x..V..M]!........p..."**....Y.q..]....6....!Y...iTW.../G||<........J$&&bs*.{.....eZ...z. .O..N....B.`+.~.i.._F.C.{.......D|..&...,{.>..b....K..m.....>Y....\..0.......*M|6j....>P?...e..V..q-=..A0.$.<.{{{e!.FG.V=.u.o.h.PT.FEE.}..w....O1.[..F...k.W...d!.p.+..a.?.y..........@HH.|||..{....'.....^.!......e!X...)a..Dhh(.......0...........:1....r..'..';;;e!.... +...[.......q...3....lf....6......B...Y.#l.w
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PNG image data, 510 x 494, 8-bit/color RGB, non-interlaced
    Category:dropped
    Size (bytes):31038
    Entropy (8bit):7.931615592393801
    Encrypted:false
    SSDEEP:768:FtWlp9SEqxl0Ui/WdOU0fRmWxTfOwWqlhFry+R:FtWlPOxriMOhfRJo6hF+Q
    MD5:9431C9199AE98625CC7B8CF325134A6A
    SHA1:29F4C50B48FF963047F66251B8CAA376AF93CD71
    SHA-256:3EA17047601ACD0574DF08336DCF8A9B5B151E4E84BA40934CF39DFEAB3456ED
    SHA-512:99FE4FAE78E43CF164BF09BB65D32B1C47B2AE87CFAE8BDA1CD8AF39B56402D7BBFEB18F3D2EB1334268D798702E53A46F6CFE4A67B65DA0C77BAF8C9401E1A2
    Malicious:false
    Reputation:low
    Preview:.PNG........IHDR.....................sRGB.........gAMA......a.....pHYs...t...t..f.x..x.IDATx^.{...y.....&AS.(.(......`...E..".f.,..J.J...[.H..I...V.P,"....X...MI..%.t.....)...f.%./.M._D..-)u....3.9s....~.^Q.;s.3.s.s.y..../.?........g..;......k.....qx.t..T..P.*0-......;w..[P....g....x.........T`....W....o....2...wA.......7..--m.....?2A~.p.Q..4..q..R.VS.....s.?.u.z..^c..F.{.Q..zSn6._.n...zm<..?.....I...l-.u[j.....G.....dC..x....._..............x.OZ..w..... .!... ...p&'.....x...;u..ol......FRm99.7T.. .d...."7.@.=..EG..J...D7.IEX.,.v....p....\......N..s........~...h.8..>#..x.../].d...Ni......^..%..R7.bA..e......] /....^x....$JF.,...........!.Q...v...".....!.A..Y....e...p..@;.w.~/...?.h!+tn..G..>..k...m.m..j.8.T...$....:...=.`.+...r+.......G.@^P/......O<.O|B..,.u.pv...w....1....!x..<.........7....z.dm.m>5..Y.o[..?.-.[..Y[...........$m....b.g;s. y.........Y.........?.......e..y...........!....D.:.7...e.[wq.J....Ny...Z..*..ZIPp.m......#].../.;
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PNG image data, 267 x 296, 8-bit/color RGB, non-interlaced
    Category:dropped
    Size (bytes):11787
    Entropy (8bit):7.91186837035902
    Encrypted:false
    SSDEEP:192:LkCSF+BAnu9O1HABnnxHE6w8Ef8MHnqvv3CBn/ZPCu78UhjdnzHztZ2nSf+eAr+y:TSKYIO1gtxHENf8unSPClZJ78IhzhSS8
    MD5:95C8D00C339BC576F40791912CFDBF61
    SHA1:1F7947D83B40903C59BF8152232BD59058A8B5CA
    SHA-256:55F8A10AE5C938939A0029DD3EB7D04770E2763C26174A4EE27F5A9C40BFCB3C
    SHA-512:0BF6753AD6AECA4554068C8A39884F2F75FCC3038D74537D9AFF9260EDAC00D3A63343ED28BA1BC0239F1AF4D22D245BF554913D6AD315622616BBD317BDD915
    Malicious:false
    Reputation:low
    Preview:.PNG........IHDR.......(.......C.....pHYs..\F..\F...CA....tIME......(..p.....tEXtAuthor....H....tEXtDescription...!#....tEXtCopyright....:....tEXtCreation time.5.......tEXtSoftware.]p.:....tEXtDisclaimer.........tEXtWarning........tEXtSource.........tEXtComment........tEXtTitle....'....IDATx..y.T...U.t.l..8.......D.c\.........1F...}.yc..^.....h...{...[.QP.Y.Ad`...f........4MO...nf.}....ujyz.~..N.sJ...q.j!,...........Y.-(....E......L,".D.bu..9E8.mA.......!W........4..H.m8........`..l...n...^b!...@......H.....]....P.....@.W.1i/..c......IDAT^|.oo......`...MG.M............a.3..,.U.vI...@Q......$.....;A.A;v./.a......j..QE....+.T0.....!W.m..[..hm+v|n..&.H"......[H."`..(.E..-)J.........A.B.Ba.r...Pw..cdP..(D.I-.6."..K.r..qm"..B@CA.,.D..M=... ..........(.6B.ji.E..`K2.H%......@...e.5*..F.e.T...k.....IDAT>....0.....Dl.........."....!.h%....%.D....i....K .9b#......"@.....X.OA...d.v.1.m.B..5..i?.2.M.a.....+..9.N.,-7...+......V[D[)T.2.h+..&..6..i..L.....q............s
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PNG image data, 68 x 94, 8-bit/color RGB, non-interlaced
    Category:dropped
    Size (bytes):4800
    Entropy (8bit):7.872936852189291
    Encrypted:false
    SSDEEP:96:fxtCyzsswWnCStVrk0++JvUcrJzm7inu1aX4e+OKzVJFr6GHM1TB:fxtzkY++JvNrE7Ef0rdmB
    MD5:F63A8D4D04474CED193ECE441FD9929D
    SHA1:8C5DC1262147886B31DEBF3C8C31BB3703305A50
    SHA-256:4F887BAFF31B686F0D368ABEB6B7C767A571EBAE7E6AC217B6C16DC2D1928C72
    SHA-512:2A385FB063CFD82B95B4BD6CAE2FC90ABE0A20D562BEA28E49E1DA901082E998737368772F4623715FB91D12BFF0EE6F10E31F44FFA04BA96B22FE77B704504B
    Malicious:false
    Reputation:low
    Preview:.PNG........IHDR...D...^......<%.....pHYs..\F..\F...CA....tIME.....4.0.B.....tEXtAuthor....H....tEXtDescription...!#....tEXtCopyright....:....tEXtCreation time.5.......tEXtSoftware.]p.:....tEXtDisclaimer.........tEXtWarning........tEXtSource.........tEXtComment........tEXtTitle....'....IDATx..\{X.G.?..3.0....hD..T....Qc.~.1.5.oD|DEW%...{.F..|&.VQ.j..XM\...y....5.B.*...E.yOw....l.{..s...........N.9U5 ...2X.V.Z.R.0..c.a.@.........aY.eY....l6.J.R.Hq.1...@.R.!..l6..8//.c.,....".A.M3.C.%`.....?.4V.A...".*J.Bd.....A....).I..8.K$.!.ey.G...RO{.y....IDAT.p.Y(..Y.........N.&.P2d."...vA.T*.Q rzM_. ...q..1.y..8...w.D..:.W.@F..Z...f....z.@......2.Cy....[..#2TA.A........b....q..........<.f...L.m..QZZ...-..j-......J.4.......g...../.........q.....q.V..?.j.j.h..;<...Os.S'q.s..9.#..+HI9...}F.....w.........^....IDATS...R1bS$c....(.L&.N.....q4Z...1...._Rr.U+o1..-v......h.daa!...w........r.. w.p..TVV...O.9...3..0`.....mv.y..m......~...K.n....m.w.z.o=...u.2.f.......g....>}4...f
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:GIF image data, version 89a, 15 x 15
    Category:dropped
    Size (bytes):938
    Entropy (8bit):2.7725907011842175
    Encrypted:false
    SSDEEP:6:PCktqEqewqw2JaNKYfSFQEujXcpCPk/BosC1O663hIvU6W:PZZK8nfZuqTC1OJRy5W
    MD5:BBD3D85E9E11CE35D7EF31A556296E31
    SHA1:ED1D9CC022F49C37361F4D77A8616A5220884368
    SHA-256:626DF133B4301CECDFE5ACB01A89157AC6425D3BA489B2A188D397CD5177CB76
    SHA-512:E59B691A4733EDF2600CEA187043741D1B87B4F2E891FB422CCCFEA29A9F6B1087089904E2FB35051C96ADA6D3BA26E1439B17C59FD8E4DD6A9EFDC47F60B616
    Malicious:false
    Reputation:low
    Preview:GIF89a.............$$$///::::D:DOOOOOOZOZZZZdZooozzzz.zz................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................!.......,........@......H..?.(N.HX.....Hd P.....,...@ ......`..?..".L@.D....j.@..?.&B....C......J..@.$.t$.....%HD.@...(^.9S....,...`....H.u......... ....;
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PNG image data, 205 x 93, 8-bit/color RGB, non-interlaced
    Category:dropped
    Size (bytes):8057
    Entropy (8bit):7.913389686343832
    Encrypted:false
    SSDEEP:192:PFdvpk4Fan1h7KBL4Pw0MdiYhcjEqMr8J:bvnwn7KKnMdPGZMk
    MD5:BFB942A17681C7BC037A55D07983ABE9
    SHA1:B4326A35C48DFDF33CF8335DD506F45D7C83F338
    SHA-256:908F6B1D908083DC67E109FDB8E31D3266FFD57A592EBEDF80E00D8E598DA7C2
    SHA-512:2D2DD01C149BD28AE6BA43A624B28F51ACC44134AB60A9BA71C1BFAECBA06D58AA8B7EC421B6841FA06B4FB82284E0938A6B01E0D42D3A4B8069A61CCB816539
    Malicious:false
    Reputation:low
    Preview:.PNG........IHDR.......].......u}....pHYs..........+......tIME.....!........tEXtAuthor....H....tEXtDescription...!#....tEXtCopyright....:....tEXtCreation time.5.......tEXtSoftware.]p.:....tEXtDisclaimer.........tEXtWarning........tEXtSource.........tEXtComment........tEXtTitle....'....IDATx..{\S...?;;.L....u#B.qQ.$.@%...0..@%.Z.=..P...B4+....Tj....P..e.8... *q...c.....N..v....|.?.}...~.?...9..~3.Z-.f..s.NmmmHH.P'2.0...0..4....T0d........g...h4...uuu..f.rxz.)..d........w.....???......q..wtm.7n<z.(...d..$22.N....iiib...3.*.j.........@f<B3.....IDAT[bbbZZ....W.O.T.......p...5....'O..;umeee{....9r.R.T..4s.J..F...L..+...KKK.|>.@.V?x....+...=.QQQ<..c..xQQQ..v..\.N..VV................9r$....:88....;......8~.xhh..............snnn`` ..{.7...+2220I...gdd...#....b....a..?.0 ...a.%....FDDDnn...=0"....IDAT..|..U... ...b.)666...s..H$..}.]dd...ull.B.@.#...Z}..../999..7k...w.h.....;.....8..].P..3.m.......~..a.(.....$......_....Bg.F3f...|.RYUU..~..+W.`BK.R...R....D..
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PNG image data, 368 x 122, 8-bit/color RGBA, non-interlaced
    Category:dropped
    Size (bytes):9308
    Entropy (8bit):7.934610773361459
    Encrypted:false
    SSDEEP:192:ss4u5wm8mn88fjQ/9LQBqC0ucioLLaJsKWGb1:T4u5F8mHfjTMC0u9of+sxI1
    MD5:1C69F9415E15412A116C6E29CC5189C3
    SHA1:912BF577D0B4C86AF31A93FCE0789C5CE9D5F2F3
    SHA-256:402F17EFF1F2384285F153209B3C23A869361DE89924A6A9E940422657214E81
    SHA-512:E943480493DC192803B340444CBF2020C6CEEB0957B11CB9AE24F47220157A30091D4C5EF6CD69A17741904E2E6221438A5B56B5BF5E05C7826883BE2C80F9E6
    Malicious:false
    Reputation:low
    Preview:.PNG........IHDR...p...z.............sRGB.........gAMA......a.... cHRM..z&..............u0...`..:....p..Q<....tIME.....5#.....#.IDATx^.......0.3$..(.O#..KX\A.e..dDD.. .o1.i.....<..Hx....C.bLb|yIP..Qg...}eXF.:..[S.]..3}...3}.......N..........H.....i .5......!k.....[2uoTf.C...\[....2ki5[.b.l.ul..q).....P...N$....J...K.....is.6.Ak9...f.....ie...8...q?......e...;.1;..{..r.>..........`...a.S.Qk,..3K.{.]DZZF...]....q.o/u....:..Num.z.,....vK.R. kQ..=n=.!....1....F.w.EU...vk...{.g C..S.(.......u......tB6.^6...".N....GW.R^.>u.p.....s.8.%pM..FG.......'.f........K.. .oo..;.8.......X..O.....]l?...q...GB:..@..._:.v.6...,Y+....b?d/k..%..........|[d.....r].........v.y,.2.S..).Nw{...w..X....U..#.p....?..,....HH.d.d..a...l....e..1....^SaI>...A...g.(.\.I......=s..?"./...N~-.......@.3.<"..a.. .x.7..B..k.4.W{.....Y}!..f..3..}.O....@(.$...`..U...Z..1...W.C.8..1.,x#.QNz9.G6.0..u" n.p.bQ.,..|;z.bD..."NZ.H.........m@..Uo.C..^.&.m%.P..=P.......+g@p
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PNG image data, 729 x 322, 8-bit/color RGB, non-interlaced
    Category:dropped
    Size (bytes):57557
    Entropy (8bit):7.982089225891219
    Encrypted:false
    SSDEEP:1536:xPsZ5EXIANdjSkNSCLr6xhmyiJNp0+MQscRjEXUwiX:RJXIANpSdCShZiG+jWiX
    MD5:97D739736206D8847CE8B795FE74CCB0
    SHA1:E2822CBADFBF5947BF39A1CC4B49C9CA44CA50DE
    SHA-256:C7A74EC6B23719F0EA53ABCA5FBD36A4F53F0FCE949913A030846DA39649EAF1
    SHA-512:5B26F1A228D3A84F4C4D76C5A8081E9A8CC919D310306EE9B5674E5D8D78C31C91BAA38D13D8547136622E5C4E20C4D70C1FCC8F499295220C23AAB6276D0953
    Malicious:false
    Reputation:low
    Preview:.PNG........IHDR.......B......fV.....sRGB.........gAMA......a.... cHRM..z&..............u0...`..:....p..Q<...SIDATx^..|\Y~....d.2......d....l&..p.d..ff.m...n.....L.%.........%f..V..vuI*.*aI........w..;.C..j.6.......g...[.........e.........|..6..66.......o.2P^..l..1......Y..6....4.R.D..".q...o..........om.~{..wwj.o....]..l...6..n..D@"0..|g..;..=..l...z...Z.5..Z.....7.i..I.<..V..!.q$.c....k|....T.7.m^/.y....&.%.6K[u......6.t/.m..U".N..;u.V......".f...._s.c.]......_.vm....F.Wk~{.e.C.F....u..../..*G" ...e.[..`.R..s...=....Eu..t;'..6.xC...6o..Y...x..u......'?...5OB0r.5_&...P.....}.J.V...6.W.{..x.l.}.[.....[n........Ug..8...M..T...1....n.......'..?......i.b..h...E....L....i......pq.....0:":40.....M...2..6..jm.n....l^..].{.l^..y..w.7....m^....eM..|.*.j'._..e...Z..p_g....M.5...d......"....S.^.>..}.mp.C.'.....{m_.;{.}K._._..l.[.57|..9......=x.}.........M..*.....$Tr.....sm^.~./...w~.^...n.E.o........7.lC.~.q.w.6........o....mN=g....S..;.....v%
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PNG image data, 775 x 118, 8-bit/color RGBA, non-interlaced
    Category:dropped
    Size (bytes):11583
    Entropy (8bit):7.845280958819277
    Encrypted:false
    SSDEEP:192:NymmaUIiy96wXmyqiGRfVqAITeN83FZsi8SYQeJ6aAJDQfjxLAMivjflIt0Lo+IJ:N2aL1XdLGlU/k818xQXifmjRpo+wmC7T
    MD5:C4531F1E0C228B886069C524E1419877
    SHA1:970654481F053956DB319932B8D764C43F9429AC
    SHA-256:91D17311C4BA7069022B4BEBE1CEE0F8BCB67532F8523FC032251CE9BD95FB80
    SHA-512:474010EB786DD1CB5B9F746A5C06CC0691B49C4A0275BB45B445CCBE98056781EB230620E61E10CB930AD00EF27EAB23CE6E6ED440B01B70C68E13B00A3E6560
    Malicious:false
    Reputation:low
    Preview:.PNG........IHDR.......v............sRGB.........gAMA......a.....pHYs...t...t..f.x..,.IDATx^.[..W}.....J.zy....VHU..V-.....hK.-..XTi+.H)..h.."t.ui..i.8!1.i...q.'&qb.n'v.;.uw.^.w.!T.u.._f.?...a....s~..9....93#.g......0.......`....00.......`....0...........dN.9..`....0..................0.......`..@. }......`....0.....(.@..*.3.`....0.......`....D....0.......`.......................`....0..z...eEL.,--U.a........o.....`....0..*.......~..3=...zq.+...h.....8.l.p.....`....0..z......./Q..../...{....ct..-t...h..Yzn.v......4:..&v0H..{...tjW...MS......Q0..=.}...O`...........i...K{....t..............fff...^.X=B#..hk.N.n<..{.C..._.}....K. ........k..j..ab.m..`;......b..8`.`..{.}.i...Z<y....>..F/...[.W......S.j..ZU..........V..Cf.c..q...c.?C.j.&..dYM..e.~....#0.......-%z...tp.0......I.....'.....Z...nZ^^.}..x....D.L....2.L...,.0.d...8.g..&2....u. vr<;...o~Z.?.Z.{....N......).mt....i[.....Y.VOkVE..TW...Vf...-.{.l8....".c......>Q.Y.......S\...g[.....K5mo..........p]..
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PNG image data, 321 x 488, 8-bit/color RGB, non-interlaced
    Category:dropped
    Size (bytes):18634
    Entropy (8bit):7.9402143707625825
    Encrypted:false
    SSDEEP:384:ZaRGgfzgvto1Cas7vuRJuN4eVk9ROrzj9aoT2/iSDqpq0sxX:kZglgRsAYNJVkurMoy/iSWBsxX
    MD5:58D42F96A7CA138254E3280D3CA8583F
    SHA1:061539292BA6D08F8EA3744D15B5DFEFC675C366
    SHA-256:FB0EF4C137418DAFA1BAAFF9DF7267DF3F3132AEA1141F5ED4DB5302E532DF37
    SHA-512:5C75906C516DBC053B83AA365C6CCF5451C6769613B52B795F63890EBE1E1AB64EB2135B049C1D481B5EE524F5028D2CF236B77167BDC1EF720137B7FBD46123
    Malicious:false
    Reputation:low
    Preview:.PNG........IHDR...A.........X..@....sRGB.........gAMA......a.....pHYs...t...t..f.x..H_IDATx^...\.q........1..C.W..+[.DIT.kM(6...`.....o...C..EJ"1 A..A........ @`H......!H.x...$Z.fVf..W..........*++.*...z.........=..\Q...,..P.;........p..y.r...g\9}...S.O.....=}..S.>...3./..+.>..i....=...X.O^.2...................sOc9..3g.z..S.z.....N..;~t.....}....<...'..?y...r9..CG..:r..#..>y...........}.......P...Ce.......*.....{.?...=G.yl.=O=..G..{d..<S*.ay.....z...].?.e/....<..>..}.<~.g.....{.....=.w=vh..v.x....v..e.T...+T.[.=....]f...!l.....r..rrx..'w.....?.{.....e~..y......s.=..].T.iy,UT>w....}y..s......]P..-G.j...g.-`...V...r...'V.....Z...k.z......5.}`.{..:(.[s.u.'.[.f..0d..J(+W..CY.e.+.\.r|..+V...X5~.....^...+.o..?X...Wc.`U......*..X>.......~.|...W..|..V..w..u.WL,[.f...P.l.{....l.e.]Y.z...+..@.....>.9.....rA0,..0|.....q...W~`..._...........|......W.t...?.]....6.4..i....|h........e.._6..e+.l.u.@.\.0...*+..y[.....Q....s.A .P .......l.
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:GIF image data, version 89a, 15 x 15
    Category:dropped
    Size (bytes):933
    Entropy (8bit):2.4139050099863466
    Encrypted:false
    SSDEEP:6:P/+FuTW+COmaI50Aqm+Fu0z/JNH379zzMq8PcLZYUA51:P2FiW+NA0A1gDJxhzzMJPcLu
    MD5:3595CD2A28F3B1CAD7D80333D9DA01E0
    SHA1:B41E57FDDCFD92E14476806BC00040FC66B57CBC
    SHA-256:699B7F554CEF7CEC231FE71ED995EB606853C6F0563DB7437370601937B6C0B3
    SHA-512:7B00D279F313B617EEDB528DDFA5C512F7E6B6858CAB6E0580696AC3F547AA2EB01700EEA3A3BB7043CBEA9430C8A588AB160E2DFD3D684F31E8CEB5E14B5203
    Malicious:false
    Reputation:low
    Preview:GIF89a.............!!!)))BBBJJJZZZccc{{{..........RR.ZZ.cc.kk.ss.{{..........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................,.............0.Hp.A...4H.P!...(p01bE...$..q.G...@. ...%#H....K..b..)a.L.7'P00...@).-@...H)TXJ......>]j...X/......]1..Kv.Y....]...Z..4...@n\.u...;
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PNG image data, 384 x 336, 8-bit/color RGBA, non-interlaced
    Category:dropped
    Size (bytes):32265
    Entropy (8bit):7.955084888960379
    Encrypted:false
    SSDEEP:768:vmwkHv9a6kfRgv26zDJwAQTwOYGl6Zdk8Ug+YWuJ6vC6Xb:vPIv9deA26HqUOYe68pg+4JqRb
    MD5:F4ED71E1E7DBAF271BD33953A08AA16D
    SHA1:F346B8CC415B0B372B9C4D36EC618B69B4C6F53D
    SHA-256:BF9ABE883B69D475C99617B735C49E0F702B7C3CA4571A361981FED88A32B09D
    SHA-512:C464DB9EEB208862963AE5033A50D26D3ECA41124E036917683AA0F052E542E011B1D1A0B002C9B6229AD383B559EDB91F11F0BD52452D32008152F901E37747
    Malicious:false
    Reputation:low
    Preview:.PNG........IHDR.......P.............sRGB.........gAMA......a.....pHYs...t...t..f.x..}.IDATx^..`U..?~..a.;Z..fi..(..ZW.LD.J.~......~Ij.?+.o-..W$.V..Z...c...A6... RL.1...EdQ....s..ys.....}.:..{g9..9g...G....@kk.....@.@.!@....@R#....".......}.km'N.............D<!@....@8.}..n.A...!--.R233......~....o..f..#x](Q:...J"/.."}..h..7.W<...|..n.+...3........>V...I9r\].H.....8^X..s...p.w..'^Z.7I..y..x...a.}...O.C.=......}.r!.2|.p..>..S...~..\r.l..>..cn..a.|.!..,V....IC....h.J+.`.^....j".W..v...Q.EelH...b.T...J..^.Cg&..#..V1...Xc..;.N._.FWg.-....*.S.....).[~j^.].N0w.x*].{..7...E....L..L.x.T.*.t..Mh..2^..k.._..-.........+.X.v..k.T.Q..{.k...'..#.|.[M2.*..0._u*.-..o...../.....z......p.....+W.I'..g.}6._....~..A*2..>..?.....j...e.g.....!.....'./.w......I.;.......I+.1!.W..e!#../..2.'.....]^......P'..T......zx.'.%.>.1..:....r....*N:<......Zo5.9_5O7.tm".1..f*.n8.~.*..s.O.."Q.WZ9...-[O0.y.8..?...C.......A....X.c,..'.......M..0..ty.r.....A..>.S...g...z
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PNG image data, 148 x 25, 8-bit/color RGB, non-interlaced
    Category:dropped
    Size (bytes):1214
    Entropy (8bit):7.729296062955114
    Encrypted:false
    SSDEEP:24:uymJmoN6zvLCpuN8aKe69o96PBM3CfUmbCg4SPdGr91bXctirc3:EmlKe4o97obCg/dGbTctSc3
    MD5:EF460347A23A22E3DE24211525D0C66D
    SHA1:6EE4084DD22BCEAD6EEA011C4700C06E1140D32A
    SHA-256:2E6765F4846FC08370CD82237E8B4312F1827C833DE9DCF57FEBCEF9D9E9AC21
    SHA-512:A230A3E0A0ABB77F2EEB15522741BC106DFECDE018C5EDDD69A10819199A581D1A162069B98B0A1ABBBAD58D3D7A17F10FB7506199412A704CA09CAE175006B5
    Malicious:false
    Reputation:low
    Preview:.PNG........IHDR.............Xp......sRGB.........gAMA......a.... cHRM..z&..............u0...`..:....p..Q<...<IDAThC.XiO.a....W.> .@.c..)R.h)...bk).....[iE.B.[...Q.!.........(.h..#.#.#......oki..f>..>.3.tf..u.~.Ka.k..@.+k..)k4n6.?#..B.+....................'F...pX,.O.^...K^r.......Jqq.L&.....o..{...'o....h.-/....:;.L.N....c!.4.tm6.@P..hJ.+>....:.n.M}...9...q.w.2.=..eKOO?.Ct....8&.o.?!.._\x.v9....fM....h..<1.h......`.y3..N..0J....;..k....(.E.Dt....H.b>}}....C..I.......,.3...}m..&PB3#..gQ.J4y(1%....5.....b.y.KPQ......n........G..&P....F.".[.........w%.H.$.r$...TW.M#..)$.\.N....16t.UJE.........x.( .]iRu...F......F.l@...<.AJ..n!....FT.10zT.....(...J<.{.....]..A.i.l+.=.. .."w.=..`.F.I.#..-y.......I.C..S...y.8..2..;..Z...ta.i.>s...z........=z.q....@^.r.H.m..q./.H..6R...',.Xo.,w.At.c.Z.K...>\......1...t..0["..S..../.(3-Z.C..0J.KK...9C.I..1......_..7b.y.lq.A...g.._....]E.K...y!..".Y.....v..^X...Z...~..r.z.-..p.F...&n~^t.YL....r..MR..(|.p.>..i....D...p..
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PNG image data, 469 x 94, 8-bit/color RGB, non-interlaced
    Category:dropped
    Size (bytes):7617
    Entropy (8bit):7.938177707612789
    Encrypted:false
    SSDEEP:192:JWlLZIooT8ePjm9MTetqZChNYJlVijLXUK/eux:J0LZINT8smgZ2TjLX5eux
    MD5:54156AC76CDF6AAE981F073D1B22EC4F
    SHA1:76B102593A07827C8C06FCA09F5B8F92DD893FBD
    SHA-256:709F8CFED62237B44C86F84DDD3F95E97D9FFA5AA638B4AE5D5BD4DA06F0F936
    SHA-512:422D59D50958A5A2622C8AD3E3F636C94F2BF662CDFF93DC77DE0BD37417062CCD05D4EB4E62118B4D57FD37EE11DF256AC1AF1F557AA3E401F3E3F1C1A49FF2
    Malicious:false
    Reputation:low
    Preview:.PNG........IHDR.......^.............sRGB.........gAMA......a.... cHRM..z&..............u0...`..:....p..Q<...?IDATx^.].x...$..D.. W..RU@...K.^$...K.U.."..;B......PD$..&..@zH t....e....l.=.g.o..3.y...n_l.%I.......2n/......=)....[..L...<Oe.G....]~4.ed.=....F...i.L.SN......X....?.....}P.WPF.. %..Rj.,e.<.8?K.,~F.T..`...F@...T..................cH...G`di.S... 4.P....ex..${.F..`...c...../R.Y...+...,L"s..........,..#..0......2.~r%S..u.,X8.)..&.y.&...=.3.k....0..........HU.G..%`c.K.....\Y.6.g..-N..s.[...da...F..0..!..V......*h..lI.+..7Fba...F.!.t.!....[..{...wC..........#:......7.c... 17!.n%DG.>......=...9...0...c. ...^...:_].dK\|JB...;I..I)..).).:..IL..V\......!.x...`...B..|.5.T.T.7......z.z../>.e.O...z.d.......g.]......C...~.....^...@^y...F..`..D@..5.:j.r.5*V.|..5.V._.v...,Z....B.C.yK....n...V....#..0.R..%.....'..J...;s........B:...t..kw.2z.J.x.r...13...x.....6%.)5....t*.4...x.,IC[...aw..cS.Cya....<....E...14..e3F..`.. }....H...r....q...Xv....b
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PNG image data, 635 x 400, 8-bit/color RGB, non-interlaced
    Category:dropped
    Size (bytes):21163
    Entropy (8bit):7.829281439183165
    Encrypted:false
    SSDEEP:384:jzYPKRNkNlVvaCQeiKkMvE3Elx/BwbYTa4fC345etivJBGK:PXRWNlVTiKkMvQSx/OcBKI5etivCK
    MD5:D2FD2075773C2ACDB4EA8E1DCA8CF394
    SHA1:9052488134A1DAF8AC11D133C77AB02FA66DFF24
    SHA-256:A63E26714B1606E19903ED9F3FD93C2F44BB0C65A517E6BD6A3F15730D3B00BD
    SHA-512:7DAAAB3B52185C07FE45FED04D439E8F94228054018D42A366C0A36B42BE3500F5FA61C2855D9BE118CAA59C48C93F4D1AA95640841D9EE1F3AC32C2F2E2445A
    Malicious:false
    Reputation:low
    Preview:.PNG........IHDR...{.........Y=1.....sRGB.........gAMA......a.... cHRM..z&..............u0...`..:....p..Q<..R)IDATx^......[. q.....g..........c.A".`L4.N..`..6|.3.0...>cll..6A.HB.e...Z..v..9h..M..S..RUuuuOOo....z....o.....[..;.....^...g..tb...{z.......O...4......M.0<8...9..;..gh.-.../..M..~x.@`....... ....n..........v..o.9$.v..;...s........T..agoC....P.).K..P:...N...?..M..o....O}xx.Ox.M.~...3..H ...aj.#....wY../.ijQ~.w._..jr...D.I.d....8_/r...u..r;..F.....x..e.{...Hw?..h".fI<.c........:.$p,1..1.N.v2..N.oY....PJ.o...\..X..U\...........L...%R....L.u.i.......Sb../?....Cn.....D..............#@...2.cr.......;.....:.]..\..|+...v..m.K.nq..Og69.7...P...9..V&(...o..MW.;.72.%.e.U_..~J6.4...C.........$....k.w].m.Sr.U.\^..#.....+.tA..q3.s(.:g..&: ...z.C/..:~..1)...G....r...|....i.(L...,.<.v$..C...6......K..UJ)q=.....o.m.........O..L...-.,..z:......n..R\..,n83.u.P(|].su...Q2..B...@..@...O.G.,~eo....*n|.~_eY.C?l......=...j..f.wN...dJ..>.R._p...U..T..G.\....
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:GIF image data, version 89a, 32 x 19
    Category:dropped
    Size (bytes):1266
    Entropy (8bit):7.456889960083413
    Encrypted:false
    SSDEEP:24:xnXhp5I9j3tQk+ndOIpBUJiPUEABS/vS5CZe9WmDSIS5HiKg8mJ:xP297pGdpBgiPU2aH9/ZS5HiKHi
    MD5:E8DFB46589AB4757936BB45004C1D82C
    SHA1:1B74304FB18BB9ECB79E3FA7A163B970F1DC7663
    SHA-256:BB06BC22F71DFE08714F6FC12789F72E960001FE968440EFE53411325B315E0F
    SHA-512:7BF60DD8F25E7170F2A62D2DEC50145A46DA9F4DD291797414434058CB527F177554813E1B6DEC009AC228E933C3257354A469790534DE79D8F921738D78B5CC
    Malicious:false
    Reputation:low
    Preview:GIF89a .............! /207:7:::ADBIIIKMLEQHUXUYZZ^`^_b`eeeegeegfikilllfqhrrrssssvtzzz}}}|~}...s.wu.z}.~...{........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................!.......,.... ..........H.......B(nO..)P.....:.........?:l...=l.".y.d.B....!...!...k...8w....Wk..Z...... DX.r....j.u..n];w..A:!. :..L..V..7p.)k&..5n.I..n^=..d.....6R.^qU.+.h.ej.h.Q.|.:.._..?.....T(S.X..E..0Ao
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PNG image data, 554 x 236, 8-bit/color RGBA, non-interlaced
    Category:dropped
    Size (bytes):37783
    Entropy (8bit):7.950579884827317
    Encrypted:false
    SSDEEP:768:677+F0+KHJyPhaUUtLHO2Z4053zAMEV/AxD7D:677AKEPtUtLuwPU4d7D
    MD5:A6CC4429FF258B2729601494EC6CD9C0
    SHA1:10EE7EC437C1A415C64D4FCABBB510DAA06F8790
    SHA-256:E9ECEABD78B18EFA607F8176DCDDB908966FA4A98BB56A16482D9035DCCBE651
    SHA-512:D6E38391B1868BB8D6B917DE8A439D5ABF1D3DE68C4B81976716CF833970AE4DB333A0810D309EC9087803E1B2993B76B1B48BA720AD5AD72D1028D6E8D68200
    Malicious:false
    Reputation:low
    Preview:.PNG........IHDR...*.........Z..3....sRGB.........gAMA......a.... cHRM..z&..............u0...`..:....p..Q<....pHYs...t...t..f.x....IDATx^...]g}....iS^".%..^..dk... ..1.,...]....<a,Wt...x2..:0.&3.. l'.D.%....j..Q.......l...@0....C..&.....\........}.....s.s...s..}...9.j+.%..@"..$..@"...x...Sv).H...D .H.....$*. $..@"..$....E .....X"..$..@"..$Q.g .H...D .H..,.C#*?...={.........}..{.n{1m....xG...K.s<....7.../.H...D ....C#*.>.`......g......\l..{o...\T='uBN...../}......*.z...^.w{o}.[......C.n3.K.........$a.[...=..i.^.z.K.e..Q.f._,{.w....E..v...!04.2wCXZ5..#.)?....G?.../|......(......:}..o...F.n/z..W....gn..BA`||.&..;.{.6...G?.Q......i.^....A..L....b...0....x.X.D..?.A-.a.|r...}.k.!......NL.{...^...I}...7..:...}i.....w.[.n.........j...N..[........l...y.!>b......`.~.......u..}.sm.....p..?..91."._.......n.}.n.~..g....~.e...$|..V...X..>;m/...`w.~..X.jU}....+.B.....Z...T?6.c......zw{.G....u.W>.l....e......~:..j.c_........s.m....u9..........9/.o...
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PNG image data, 872 x 486, 8-bit/color RGBA, non-interlaced
    Category:dropped
    Size (bytes):35919
    Entropy (8bit):7.854230041587622
    Encrypted:false
    SSDEEP:768:XyI9x9kaadZNDIdivNTC30JhR3PyyXsKeTiQJSOHsfK2eYrGf:iI9xKaa7Kv3MhlPyyFpQgOHsfK2N6
    MD5:9E8E6CA64A0EAA73538AAEBE9466698E
    SHA1:140874A38443C8D16CDB802DC36CC64C6801BB83
    SHA-256:7A33D51A76F01057ADFE79DF108009E8209D1720581069072F1443FAAD0FBD35
    SHA-512:F0081B38B1F61CEC4CC15279E6A2C25480115B9E3DE14195F01F1D864C776F3BADC1E238422E17148DDBC445FECE26EFCA90FEEA8B35EC21D7B8A4115B99FB10
    Malicious:false
    Reputation:low
    Preview:.PNG........IHDR...h..........3......sRGB.........gAMA......a.....pHYs...t...t..f.x....IDATx^...\e..}z....k._.w...*..m...$.@..pl..B..!*.vB@!...f .2..!1L.I.e...2... !...E.$........g.z..z..v..5.s~..~.T.y.z.[..u......v........w............{.................P2.[.]._.x.;.........n@....B....w._................o..o.QSI..c{.[.,.W..Wn....v....{..>;d...`..#._..W.x.g..k..SO=..O>..'.....g.}...l.-..[.F.eK..=.X..7on`.M-.q..:...@g..e3b......H$.......5...7#V?..j.%V.(..G.k%[O../[...XM...a..+^}.U......x.a...k...\..../...N..d.l@..O..O.Yg..V.^....b......3.p.......w.S...l;...e.i-q.i.5..SOm`......c.].i.'vN.|u........>.)S.T9.S.N>..o}.[...f.I'.T...Ot'.p...7..p.......U......|.+._......../}.Kn...U.../..;.}.._p......>...I.&.c.=6.c.q........~.}.3.q.....>.....'...>:a....rG.yd.'?..O|..._.._.>..'|.c.K..G?..._.%.#..H.?...}.C.......>.....?.#.p..vX....>......z..C.q..tP.....8..7~.x..~..q..%..;...>.{..3fL..G.v.F.J.k...b.=....k..*z..r..z..=..=.........V..!..?......
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PNG image data, 290 x 154, 8-bit/color RGB, non-interlaced
    Category:dropped
    Size (bytes):4352
    Entropy (8bit):7.842873325787926
    Encrypted:false
    SSDEEP:96:ZcvKzAxTFoR2YEMmWWRCEC5zUuExFQVGxwxMSfgAY9J0nUV1TQX1YQu:ZaKzAxTFoR2YRGjC54H8VGxwxM4787OK
    MD5:4CA8115678A9D88F347FE22D3FEF9877
    SHA1:DC376A11C75D5AB8F7FE8ABCA47197203C1BC73B
    SHA-256:E0E5AB8930280B631B1AAE9D0FE726311C470351FFDF589E220262A95730918F
    SHA-512:CF9BE15E84B80F2061D8C8A3ACF795562846CF8597F811E52C299DD6145A399C780BE81BF2F9B36715FC640748B0914A7BA77ACFBA92D4C05BF85CB49F268368
    Malicious:false
    Reputation:low
    Preview:.PNG........IHDR..."..........2.M....pHYs..\F..\F...CA....tIME......:.......tEXtAuthor....H....tEXtDescription...!#....tEXtCopyright....:....tEXtCreation time.5.......tEXtSoftware.]p.:....tEXtDisclaimer.........tEXtWarning........tEXtSource.........tEXtComment........tEXtTitle....'....IDATx..M.%E..Ou......O...,......#$.4&..1Q....@.....u...a.A.b....6.0&.......HF.8....rQ}.s..~...;._^^...>U.o..T....[.... '.+............@f.dg....0.......G..Tl.d._.=..eW.t....'.Bf..x...g...kj.RU...VTk..R.$".t.i...|v.C.?............;D.H...Q].RT+]kAD........IDAT..uM;;....>t...d.@.k...Q..R..KDT+..U."MDTk.k""Q.Vo..0.........2..Z.^v.V.!.9..J.....ds...`...K......76.76g.wY.._.j...........5I-....IMR..D%.TBR.VF8...#8.x}cs.............^J.`..e.u.L.-ud.r.Q..,.....ZJ..P.D....TIE..H.......,x.6F...}.....*.....i.`._........IDAT..5...`.....X...!Jx.=..'N<..Qny..3G....S.......<o.K.C.TN.k-Nm..;k.-.'..m=D..T...(H=..I"z...O.<JD..O..$.....G..).....,...f.y..sg...."..?D.[........ ".1":....N.3B.\...
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:GIF image data, version 89a, 32 x 25
    Category:dropped
    Size (bytes):1272
    Entropy (8bit):7.208411497844456
    Encrypted:false
    SSDEEP:24:xdrzsJ8UeSQLdI+VBESM+Zjg6qFri/vAP5ydUAoOO/6KBEJf/iWolixiJ:xpa8Ue/zESM+Fwp31ALOyfJXiIxC
    MD5:55EBCAFAE9E0669575CF5FE6C8A61954
    SHA1:2E085BD660C8D4A6BBCFC4AE972E33458D32D5FF
    SHA-256:35865495C9F32FAE188B6E1A609C148C4C963FE9025E015DE6357AE66FC6649A
    SHA-512:F46DE15ADEFD6E43E4B3A114CB995567E804EA217E5C2D44E0DB10AC6E3B5C7E51BAECE9205080119A363D94EE75FD759AE2E0E7C9F4B7248248F4E57DB83226
    Malicious:false
    Reputation:low
    Preview:GIF89a ........................... .&&%&&&,,+---210321555998===A@?i_<BBBEEEHHFMMMPOMTTTWWUWWW\[[^][\\\mi\edceebdddkkkmljlllqqqssstttzzz.....~.......................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................!.......,.... ..........H............g.u0.Q.2j..q.. 5h.......(S.LIbN.....h....B...gO..,.H.. .Wo.@Q.d...<.J..u.)3.n..3..+9=....#..h.2`.i...!..4q...+..8a...../..>&..@....B.C.!G.#Kv.&....h...C.g!tQ.D....p.d..u.H#
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PNG image data, 641 x 183, 8-bit/color RGB, non-interlaced
    Category:dropped
    Size (bytes):42195
    Entropy (8bit):7.989028576705962
    Encrypted:false
    SSDEEP:768:PWCC+m6iFmErt5wbemroDAZkTdbjqi2s5ZpKHUnxdAwBjB/4E:P6+mzrt5wimroDeUgyfpKHUnPjf4E
    MD5:5B250F2B74F7DC6726FD88A114F7E845
    SHA1:55D11C4C296120A84ADD63EF304CEE5B601C7569
    SHA-256:817F971AC1A6E685F923D2895CED21FE54ACFDBB2840260A65973D21EF535AD4
    SHA-512:67D3BEFD77848DBD4F203C5E8A846E41825265B535CB1CB1726AF56615F237547E9A06957298F67CD6C69474CF53460C8E73FB9D4B715DBED4570A3D3BB63148
    Malicious:false
    Reputation:low
    Preview:.PNG........IHDR...............v....sRGB.........gAMA......a.... cHRM..z&..............u0...`..:....p..Q<...QIDATx^..ut]I........~o.yw.w....O.):..daV....J.t:.....$[.%Y.X.......[...o).+w..dI..k..G.X3..b..M..~Ky..^2..#.%%%...........o.o/Y..(.(.(....p..,$.m].....;...~.\..DB.u........l.?....V...j!......f...f&.H?7..M..........N.....>4.;..]3P..[..[..S..=.CLW.?q..>m..#P..]....34&....e.j.Q..wU-.._.M.O^I.......^...8*0.C]...".x.\...t...w7vj.U.3m...n....3...zMG.`........oId.U..TA.d..1.....t..,..........n...Z.k~....e..._`.z.....4....^..../4.........4>|....'..>t.g...;\..;.k..n.l..! u.5>..h.Q......To+.zjZz5.Cz....?..:".#2>S..g.WU5......SFCF.Z...j.6.._.:...._B..0!. I......+ .....U..'..I\.f.../:9....}.....A.)n..-...KW...3...... ..G......1Qr.C.%'|.G5..`c.n..w....j[....+...e..EJ..vQI5.0l..n...@O.j.W.2..X.Es.B.%+.).........3I.....z......^...i..bN......?>\.l...u....K.1.m.%.f.....}..CK.5.........j.z.......G.....g.........m.xH.E.m.%z.x..z.....,..Z..p.
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PNG image data, 449 x 69, 8-bit/color RGB, non-interlaced
    Category:dropped
    Size (bytes):11326
    Entropy (8bit):7.975883753922111
    Encrypted:false
    SSDEEP:192:Li/i/I62jeWEjun+w9yp7XN3EMRq40AgktKAfwjDVmPpKCCtIMqg:mq52iWEqn+wk7NtRqDMtKAfumPpKCrM1
    MD5:8C3572DAA1E0F730A36FC5EE518F08FB
    SHA1:B2D5F552813F5F7DA04E8F9BBE3E0E0CB35863C6
    SHA-256:12D9411C57F6F978A9BC70E279FFB19C65CA15366998B18B69348136C8B8E07C
    SHA-512:07E741B99C90F1CB597B9337564C661CA3DFD8903CA29C9EFD48B5AE70596F61FD0A0F63833CEF1C31C504F91EE1B8D4B8B2929D493388194BB76EC51B8E347E
    Malicious:false
    Reputation:low
    Preview:.PNG........IHDR.......E.............sRGB.........gAMA......a.... cHRM..z&..............u0...`..:....p..Q<..+.IDATx^.gt.W........|x3.o.8.5.3..0..c.....0.....D...L...E$....Y.,...j.,u+.r......j..6..^giUU.:g......9....FFF^.?2.O.....ww..+V...|.-......8T...<a.^..u....~...........^.\.....H..I.....4G@..i..S=.C.O...V...B..i.-s........9.`P.....c%KNs.d....z>.9.....i../....2.>m.......C...\......?V..4G@..i..S=.C.O...V...B..i.-s........9.`P.....c%KNs.d....z.....8T._.../.I2..x>......K.:k........" s.."(...............C..w.O.d.}>...Z%s....g..O.{.e.# s..1.k....C..y...9.y..a....d-.C@.P.p........R...# s......../..o{e.}..;].{..&|...yJT....N.ue=d..F@.P.......#G.L.6._.......|....A@......jrr....x...........C..?>.VL.*y77.g..YE.....9T..'.....u..L.{zz...r32..E@.P..)W.....tq..+d.d..Q.d.}F..L.....nB....}&......9T..'...5k......7.D...@n.....jhD..t#@.. .n.A.LF..E@..g.w...d..hT~...s.....2....D.`.H.CY!}.........C...\.....6..._.LF`z"...Q.._..,........K..B)U.g.....\....
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PNG image data, 289 x 225, 8-bit/color RGBA, non-interlaced
    Category:dropped
    Size (bytes):12550
    Entropy (8bit):7.961475862990064
    Encrypted:false
    SSDEEP:192:nLu9hk6+QenRvWryJRdzPbMO5526u+4yzTvlpDWHfOFycWtLc5zs9pvNvRi2Bpp5:nLu9N0RvBLdzQOD22rzToOaop6xM2tD9
    MD5:57EA996D5CBFF6942EC9C7C14D7CF126
    SHA1:923B9AD8B4890C67FCB0668BFD31D54205E37B43
    SHA-256:DE69CBA3FD264F52497E5CE1B5D94FE01995D42CDD382C9F445C33420C547F6C
    SHA-512:ADCA2AD9E0B4061F1FEE65D380F45840084F93BD59465DC28AA320CF25D388FD15BD55CC7999575E1A7F38266334AC20369842F7297493AB2C0489B2AB69D264
    Malicious:false
    Reputation:low
    Preview:.PNG........IHDR...!.................sRGB.........gAMA......a.....pHYs...t...t..f.x..0.IDATx^.}.....F...@.(....vLc...m.4L..m0C.l.Iv.d.....f.Y....Lo.B.#c:.,...........I;.lb..* .C.........].^U...._.>.>.{u..|..:.T.{...S.A@......!LB.....4*.........dpC .....@# $4.= ......!.A>..|A`.......(..S......T.h.B...Ygu.`}W.*."...(...,.........S...a..T..].`l...P..> .6.G...~.d.t.0...#..+V.zq..T}-.Q...ntwo...p.......T..<fEr43P....[.FB<.*....T......fl...#.!..l.j4.S>~...P.U.kQ..,[.M...:..9..0.tiFm.zd{....U..rS...<.Q.B..][7..f....IB....-..R[.I_..&.eK.......\...../.k=jL......A.jl.V.g.....N'...C^.....6....y&...vw/.}..TV^..j..H.-.p3.0..^..2t..m_....mi..V6...qG.Q~K@.gi-..1....g........W.ua.fR.>...[.+...g.v.f.F.."m...)...<.c-...j[.J{...-%..r-u..u-.w...j...+.{....\kM,]....|;.r...K:......~q.D....e... .A...k..CH.2...B.(.....L...Z..:..m.(Wx...%1...uhQ.kx.G...B..+..L.L..U....R..........ae.FD............2..C....8h>L?(c..K.i}..3"..z.n[j..z..j..V./..L.7...R.EB.&..D$a.~
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PNG image data, 522 x 540, 8-bit/color RGBA, non-interlaced
    Category:dropped
    Size (bytes):43150
    Entropy (8bit):7.925254022182907
    Encrypted:false
    SSDEEP:768:Wu0V0KRLwUnOyeweIH4KxEGGuOszp17MghNoUJ7MJ104SHlCS85:WYuJOueIVxEGzpH+UBMXU0S85
    MD5:284005E37C1F495C27925FF08AD54D77
    SHA1:FDF109544BF4D268B6F68A94BB08C12E05810BFB
    SHA-256:866819A373A3B3840E3BE46F14476976E37148FBAD495B0112E8E6393E68C616
    SHA-512:7B6A65D791340FAFE09B45CC4B37B28C981508D777B7A50B89EE7FEA768578E7251F771EE8682AB56C90B26FF9E15433B04F13938308AB372362149D61C23160
    Malicious:false
    Reputation:low
    Preview:.PNG........IHDR..............N......sRGB.........gAMA......a.....pHYs...t...t..f.x...#IDATx^...].u&|.C..tw........(....Mxi.......X6`....&..c;.B.....<.v.......c.,F#f!. 4..!..1z...:...NMg...{.......v}U...w....[<.......o.[.l....k..SSS.......w...{..w.-....r.Jq.w"A...0.......c..9.u......X.j.x..%. ..i.&.y..g..;..?..|....+n..v.b..q..7.k..F\u.U..+.../.W\q.X.l..d......0...0.H.ONN....Z\...R....?.<....<..<..b.....G.....o..../......{...../.>.lq.Yg..~...;..............0.........g.y....w.X.d.$~D.n..6..$Q .....zp..J20{.l1c..$.......`.....|......7....K/.d.;....&.?.~ ....-......s../...x..z ..^zIt3Q_6....e>..l.w......#.J....k....T..M...T.`.3e.......:.49...+bP.....>S.......}...../.>Q;...;....I...._.V....H\{...c..@.27.Ix..^'../.y........oQ%...kS".dJ...{L.S<G.D...~...[o.U..-..".C<.OIO?....J7.t..t.7...o.....GJ.]w]..0*Q..O..R.\W*Q\.J.......?..\~..B....L.D,W.K..D..t.R....x"...Y.x.q.K.\p.p...._Z.h.0%".`....Ly..x.T[T..<t.q..2o.;.-..2.u.....>..:..w.J.....
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PNG image data, 525 x 270, 8-bit/color RGB, non-interlaced
    Category:dropped
    Size (bytes):51810
    Entropy (8bit):7.99167575537392
    Encrypted:true
    SSDEEP:1536:FXPZDBHsh9CmGwMzY9UFSgtcO71oQr0Es:FxDBMymEzY9UFZ511m
    MD5:C4E895C503315AC148D8F09634FC38BF
    SHA1:C8C1F89AB202E705AD636B5217A5DFCE83502246
    SHA-256:AAACC283F6E0926136BAC7912E424F2350B3BA4688146269D7A0E9CB26284126
    SHA-512:AA7C26DCD0FE65BA8A3D000186F7B9619EDB5E6CBF1A94270C28FD980CB974F217A33EC74ECC0CBFE14194D963A802203235985351653555453E78725551955D
    Malicious:false
    Reputation:low
    Preview:.PNG........IHDR.....................sRGB.........gAMA......a.... cHRM..z&..............u0...`..:....p..Q<....IDATx^...t\Y....|.=....f.|_....yS=..]Y].P..Y.Y.ffffF.,K.-.bfffff.A.B......8..H.%.$.>.:q..}........t:.OL.).mw..=...!.O.......O.....~.W...?....g'N..&.~.....[.|||JJJ..9"..m..W...?..4.u...n.n..?....><..F.].O......Q...?.......o....?..?.mlll....cG~~.B...O......w........x..2...jnn.{7.........._....###.......,X@.K.q5.......p..........^}..O?....<x.w..........NNN..g.......===_{...fggCR.y..q.-**..~5...5.....{u.c.....6...7....*....?......6.m..-,c-.....h........t.W.._.._...W.......Q...<..3.JN8.(@..ST...{..].lS.....4..F......---..KKK..8..._.......A...V...o..=.)F...._q.v3....W3o..x..S.S._-..I......DC....o.)x.M...;w..o..I....7o....8..={lll..!777%%....s..T.........i..ki#.(,,LOO....1kk../..uuujj*~FWee.+W.n...K/.........O`A.w.....[.R...{.1......#dxdx..j<.%.]6ow...~a.EX~XV}.P^.R.Y...}.L.s..?....Y....nz..)..:T........./&Cf..7n.........*.....`.....
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PNG image data, 771 x 118, 8-bit/color RGBA, non-interlaced
    Category:dropped
    Size (bytes):11172
    Entropy (8bit):7.821093060807108
    Encrypted:false
    SSDEEP:192:PrjHNsN9vyAAMrec6ZXpW1kl1gdB9MqDb+7flapu/kkqPsWuhU/rzBLWZ17K5zAS:Pr5GvyAAKejRp1u1MqUx/sEvhU/BaW5f
    MD5:1B7FB6689F471479EBBF3C85F8057264
    SHA1:92DB743388AEF293C32AB326C12AE31CB0FBD96A
    SHA-256:81BC23231DE5CE1C5B216D5AB3AE584ACF6DAA9F7B4E32B983F6B0ECE3F42C78
    SHA-512:3237952D0C89906ABC3B601CDF7A1130264B0DE85DFAAE5047ACA3A1C8F8F8CF1B0C90391D90FF48E837FF0165058DE7C3351F134D617CE1AE410317529526F1
    Malicious:false
    Reputation:low
    Preview:.PNG........IHDR.......v......%O.....sRGB.........gAMA......a.....pHYs...t...t..f.x..+9IDATx^.[..E...C.a._d^x..7?.aL.vx0..G.s<'..0N.A.pP...L. w..h.......S+..*.+3kW...'b..../3.?se...u!........`....0......X...t..>..`....0..... . ..2..!0.......`.....2.10Q.c6...`....0...............`....0......(....u<f.0........`....0.1.1...0.......`.....2.....c..............`....0....@..x...h.!...............`....0.,....Tp.......9,..>"...............`....0....x.....8yV..?O.... ?..\...^......7V....b .wv@l^z]l;IP.?.....0W..l..u..0.F.k.Sm7.7...``q.h%..9}^.>wI..pY~.\.".\.&VW..w....:. ....^[.K...'.7l.c..9k..].....^o.c..9.^..>{g<V^..W.........6......?..b...w.../_.?\.&?+.n..7o..w............b.k..M.,y.1.1hw}..W).O.).....;....2..q]...kuQ7\c...>......8.d..J..........?...o.{...5...#q..+Q1pb{!.../...T......J.R.. ?[..ZQ QQ.M..hA.....K.~7......S]....2.....c....s=;....#.VI...U..FY.sd].&.Mm[.{.l.\.8.ze'd/.m...>...\..s.c.SO...s...}...m..Q......aq..,...g?+.-.)...K.~1.dJ].K.C.M.....,...X.2
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PNG image data, 647 x 434, 8-bit/color RGB, non-interlaced
    Category:dropped
    Size (bytes):87119
    Entropy (8bit):7.990612080660914
    Encrypted:true
    SSDEEP:1536:vXTYAXGgoqF9snqwDOERt2RNmwwjkVZYBYT2SB47s26odPyaaV2OiF:vXTjkqF9pwD1RsRNwgVZQ/dPyaE2xF
    MD5:4B931C877D89484FE876CEE0CDAAB3C9
    SHA1:EA08273B491346EFF69E30EF169555D0258C76E3
    SHA-256:39EC5748E0819C688CC745A902AB121BBC33E5E79EC558CDE36BB7FD82B261B1
    SHA-512:B2593E0F5E5063AA48E1BC8627339A64C27CD5322C13D0D4614F898B8D750F26EECF52D018BB1FE48410F904D738080C409436126C0CFA13D11ADEE2E9E7D8D2
    Malicious:false
    Reputation:low
    Preview:.PNG........IHDR..............).6....sRGB.........gAMA......a.... cHRM..z&..............u0...`..:....p..Q<....IDATx^..x..y...w.}>..9.>..|>..Y>.Nq..ZI..9gn.fr..9.s&@.$...9.3..8....7(....fz..AT?.....o.....[...f?yI.$.....D@"...`eyI.$.....D@"..... ..A" ...H.$.....DA" ...H.$.... Y.....{.nu..y..M.$5"....4.f...!..6.eqSB.]" ...L3.....xFF....=u.....A."".VL.B..~.ad.*..%......<R..D..%.................UZZ..@..,...... "..[.f0.&.O...98u..H.....L.+IDj.e.*..EP.U."..e%.:...u&...H.$.>E@......P.+.....X.".xoea.F.\...E...".....B...tE..'u!I.`..v......(X.X.P.H...,iuj..WE.+.'.e...P).di.....(by..d.....D...HV.b..ae.F..L&x.......Y.S+..fe.T.'5a:.z....JQ.#r.&..HM.=....q.C..WR.o..D?C.....%.....x.e.)...|..vvh.U+...H.$..A@..wp.H.....7..:...KX.j.l..b.*t%r._..8^.QA..d'...j...).@...)...U.W].!...P6..9..GBz.....5'...H.$.>B@.....|..@p..ge.ZX.b.v.....,.R..9c..B....D.Al...F.a..j..&+.x.i+.../,{..mJ+..."..Q....U&-..........5..)X.2.......~..S.....be.+#.b5..)^.F0..B.%..B.!.r..e.L..V.S.
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PNG image data, 372 x 140, 8-bit/color RGBA, non-interlaced
    Category:dropped
    Size (bytes):5075
    Entropy (8bit):7.871272990502757
    Encrypted:false
    SSDEEP:96:fbQHv6t/mOd9wYz9bJJJJJJb/G5yUebKuJb/HksxuzMLoLFzW9TeBSmTw6XIJJJM:DQA/mOv1JjjjiJebKubRgMLoLFzKeBvP
    MD5:DA134CC429D14F2114AF9249D0CDF6E1
    SHA1:2F568DCA0B0DEBBF50B5D9BA554236F28FB344DC
    SHA-256:CA238F97E41CCD36B7CCA64FEDFD538BAA6200CC59C02D6760EB3B6A84185DAB
    SHA-512:0BABB31B931473A31E5B30DA048A715AB39CB6DE37E8023DDE1DF252075549B23E3917D5A243EBAD1A9ADA018AEED2BBC51919731E06774D68399F4154994D26
    Malicious:false
    Reputation:low
    Preview:.PNG........IHDR...t.........l.R.....pHYs..........+......tIME..... .*0.....tEXtAuthor....H....tEXtDescription...!#....tEXtCopyright....:....tEXtCreation time.5.......tEXtSoftware.]p.:....tEXtDisclaimer.........tEXtWarning........tEXtSource.........tEXtComment........tEXtTitle....'....IDATx...Y...y........$....E...%6. .....$.a@v. ...ya..&c. ..A.....v .2"@P^..a....`.G....!.(Ra.....X........3=.}T........p.{....j....R..DD4...pz.1..h..E.......O.b... .v......'."-..-.....y<w.e.<.&.|...|n.~G....>.^...1...]o...6...j...-....3tO..DD5.FA.B.H....ok#......NDT..3..6X....NDT..3t_..DD...;..W.$./..t...\*""....DD...ND..c...?p...q.+..I.~M...v+~.A.....%..(........hCa.P.y.z.>...g.....Qg...e.{Vz..l..R.>i..|.e.k.q........Pux.K...........................m.Q..:......EuQ............4.`..Y.y..z.YtVe.>..B../.....(g.I>U..M*8T.....W.......V.........J....5..^v..u.E...,?.....Q.........wz;.`..|z]....l..r..a..r.5...G.FU/>. ..$.....o.*........n.....|.JGa;.:..?.....:...v|.i..
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PNG image data, 661 x 131, 8-bit/color RGB, non-interlaced
    Category:dropped
    Size (bytes):50528
    Entropy (8bit):7.986514593187892
    Encrypted:false
    SSDEEP:768:0ODW3VBpLZxxhbunRpwg6yHo5d1hAoBab6URFgZoS06mPqvMs83kmMJmPcc:+7FbwHwhRBqgURiiDSEJ3Pcc
    MD5:18D9E9FC3C8693C37AB75BA071091ECE
    SHA1:492846E3102E27A56273B6032B512FF0D8DDCCAB
    SHA-256:3CEB2F9B973151FBE7E6E762A6D8A5C27C13FF3CE3BC8B7E63EE8E3A7F6A0011
    SHA-512:0EF83B18C6002909E4386272C575255ACB6B5A1A1972C4CED6C33D841E6667B4C1BD7AB52E746C7C9826CE752062FDF7DE3A13A1C947D8A86491B9A37AD9C1CB
    Malicious:false
    Reputation:low
    Preview:.PNG........IHDR.............S#w_....sRGB.........gAMA......a.... cHRM..z&..............u0...`..:....p..Q<....IDATx^...UG..}...;wf2>w2.....x...b$..;.w.......k....v......i.......S..*.U.[k...WUU._._...........-.9ss..[.....x8Z.........._..R..+|O..<lv..0.....-`n....2.c.\...e.[..r......x.3.....-`n.s....)..).f.n....V.R....Ol......MGe.Q.m.....l.k..|.G~.>.............*.;K...K4h.......0.....-P....R..D3~?....O~.}=[......\R...K2h..#;..k9.Bs.Y.k.....y.....*{.9..[U..Q.#.......U..T6:.<FZ.#NE.......Z.:..........|!;[S...HV.........f.n... T\..S.j..+|..W..#............r6......IQ.....+..eu.`5.\k...t......^LN.-+-....'J...V+...x.xE'...R.N.....i%.....qE(3.J.k~n`.....=(.....}a.....o........<@F......u...[5~...1..h.:#...g..F.}...q...........; .|Yiq=.w=...e.v..O?Rg.......W/....I.@.G]=)P.......u.7s..E2c.Y.x4.1..H.......~....9.$....fI<tE.n..1+..//..!.....U.yQ..2~..7..TD.......kd.#SS.....]=.M...&...WA..3.....4c.|h..~~....z.;?;%%!..w.l..y.o....X....3HLeANZ
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PNG image data, 333 x 338, 8-bit/color RGBA, non-interlaced
    Category:dropped
    Size (bytes):24942
    Entropy (8bit):7.977220057187805
    Encrypted:false
    SSDEEP:768:K5IQ22y+YDNee2UBofd7+XmZUpVeos6DLQkB:K51ydYZLUpDDLQw
    MD5:66153CCA5B19F774F1DA57FA7ADA284D
    SHA1:427DCA8715DCFFB261B03D5589368EE8BD3F2C49
    SHA-256:276A6F0E5BACDAF7E26A786BB747B56FFCAB3F61A140B986154EF26D70D6D28C
    SHA-512:E659DFB47439903B65BADC9A72115E38FC3D6B3FE74FC0101E6A5930F7528FD5B516FC14E957B0B8B214C475CE253AF3AE7AD2C859A711FA45662C3F6943B696
    Malicious:false
    Reputation:low
    Preview:.PNG........IHDR...M...R.....vp......sRGB.........gAMA......a.....pHYs...t...t..f.x..a.IDATx^..|U.6.......U....".5h._..!..6.x.....RTn..{..b.\/..)j./...^[...!b.J...5.....X.VA.....;k.='s...<.$...o8.{..Y....|.Y.vm.G.}..?..r.|...}.Q...0..@.#PVV...?._..0t.P.r.!.|.......;v.@]].....*\v.e.^.....[...-...r...._Y.r2-.|.>}....G.g.u..F.R>.......~....\1u..~..n.*.(...<<.|..x...y.../p....._..E.}...;.o.;....,..S.m.6....@..8ha.ZY.$=.NQ.Ca.....S<&............C?2..M..8....G'>..7....V.T......{.U....u.:.3.J..;.n'..3.A.%....j.^....Y...55..o[q.....__..9a.......~c......]...T.OWj;.NY.....[...~.y..ud...n...........~.m.u.Qx..1W<#C.../....-.,......7|..Va...~..p..q'.9.J.^r....p.S..T.2a.c..$13..{...Z.*.$....B$...d.g...H..T.t"D]F%........x.K..>:.^...S....s.SY.Ma8.z....H..gL.....:........k.c.......-./.....Bn...n...'......~..HF..[.....x(>.W.`.#..Az...7].w..M.p.YgY........;.n........^..8....k"K.8..v".?~........$............$L.k.....,...E...nI:...........IG.Bz..'~..
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PNG image data, 398 x 357, 8-bit/color RGBA, non-interlaced
    Category:dropped
    Size (bytes):28450
    Entropy (8bit):7.948880686906759
    Encrypted:false
    SSDEEP:768:FJdeCEubRtbJDRJydZCOOO34MZiAzLNX1F7vQ:temRAd4OOOoMZnzLvFzQ
    MD5:CF64D18966456ED63F1CF3A0E0D95700
    SHA1:B6810C9E7C8642860B6C3383FCF9F96DF216B2AA
    SHA-256:B897FE5B4AD452658AAE5FFB5191418C8009DD71CA349EC9010DD198FF324FB4
    SHA-512:4ABFFC2339F22D9732F4D2B7CA86B38FD7C645DD2842D6619F4B3C19FA3579052BB69962687C0DCC5408C640D7F51247BADB087E737327D966649C63C9F124D0
    Malicious:false
    Reputation:low
    Preview:.PNG........IHDR.......e........=....sRGB.........gAMA......a.....pHYs...t...t..f.x..n.IDATx^.w.]..Y...f............rw.1.......d..C....1Q....Bd.@9g.J9.,UI*.P.J9."...k.....{.wnz.^...^....s....>.j...q.FZ.b..;.&M.D#G..A..Q.}.w...W/z.....w.w.y..~.m...............{O..~...a.h...4}.tZ.`.U577.U.h..4|.p...;S.N.D..D.D.D.:..<.....+.hGb.1..U.....a...[ZI.9.....}..'.......(...O.c..>.~.).J.......L.Hkk+.J.=K.]P.\......g.....]....m..}..Wt.u?....o./.O./.)8....O=...BF..AU.-.n...}....O.....Wko....Q.2..l.C....Y.r%.+........%xn.,]..LY.d..,^..LY.h...p.B2..(.....2o.<. ..2g....=;-.f."..3g...[.4ZL.6m..L.:.L.2e..L.<.LA..e..T__..:2e......q..Q.2v.X.8.......l.....7....u...zA=.b.#>.....s..c>3......u.........~A.{.G.Y.1......E.c.v.}..N.<I...Ut.q...E..G....RrD.H:..SJN+9.e8.B...).D}..I..<.....ZF.)%'..WrL.a-#..).W7.Z&......}.?~\...k..............7..cY.w.ECC..K`..;....s9.T.I..0.....H.P.@b...>.@.#....I>0..b.C.K..m|m..d.....I~3.k...f..J...=....k.@l...a......M
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PC bitmap, Windows 3.x format, 368 x 432 x 32, resolution 4724 x 4724 px/m, cbSize 635958, bits offset 54
    Category:dropped
    Size (bytes):635958
    Entropy (8bit):3.435879158564326
    Encrypted:false
    SSDEEP:768:HBVEhkqT305QK0/gCnwVaWlOQW9fm4QIVqQqHe2vuQZxjR5sXixixhCqrcl:HBVEhkqTk5QKEnwvKTIPd5Xij1r2
    MD5:F672AB3CAF467A727B1F8F3A9F11D6B0
    SHA1:38C6F5DA9687C10E741F9DD594915E3A83359406
    SHA-256:489FBB5FEC9A93D0D8F40E2A22804D6359A4F2782DC6C0EFA86026516A4712AC
    SHA-512:7FD37A4A3042A0CF65F5F15295D76CE6C8B0B9956874095BCE544D999D63A10154FB7150A871A5FE05104DEB8C67E62284EF20602A23E9E732EC4C7590EA654B
    Malicious:false
    Reputation:low
    Preview:BM6.......6...(...p......... .........t...t.............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PNG image data, 599 x 271, 8-bit/color RGBA, non-interlaced
    Category:dropped
    Size (bytes):11690
    Entropy (8bit):7.756442907026392
    Encrypted:false
    SSDEEP:192:GcAPS71nFDE8hycuuwv4fE3LCW9Yv1kV7X/h3csIqVuVuVuVzwvQcyR68U/2v8Aj:GEbQ8h7uuwAfMevveVF3csIqVuVuVuVJ
    MD5:97626133D03876DCE06F75F0E5C1FB67
    SHA1:0320AF837D60B09ADBA044B5C08C80B5FD522A1C
    SHA-256:D20A2E76B03C77BBC2CD895287AE62D4572F99EE34B3E0859C4B65625087B9E6
    SHA-512:D1087038F64311093371813CF6468A7014A12FDD1158436F564A33EE6CFCD4C078462EBF22A18D5EAFE8C6962E14C15C557C2AD33F32115518037275CF0D36AF
    Malicious:false
    Reputation:low
    Preview:.PNG........IHDR...W.........o......sRGB.........gAMA......a.... cHRM..z&..............u0...`..:....p..Q<....tIME......"......-.IDATx^.]..Iy.7. R$....Qr.)..b%7.".H,\$.\$(.."RnB.`..ED....*.....".|-h..j!..Y@,d...=...=....=..:vA.x...:............}....O=...f....."@.... .D.R...]............@O......H..9........... WH.b..0..0..0P...b0..0c.........@..+f+0..0..0....@.*..................b...0..0..0P...b0..0[.........@..+f+0..0..0....@.*................\....3./..0..........1P$W...{.>}.ln.j.;m......fgg.........+...q...u...0p.........8.:.UN....E.r....}M......v..P..c..#b\.ZV..V`..`..r...UJ..|.Ac....kQ.JU(&J......D.J......`..`..``....UN..\Y.:<..V..o.J+W.J.$h...1../..L...`..` .@.\.g..D..X...e..........J..u.72..>eH.B...r...........".r..;....Kbu...j+W.U..\..z.n-j...g....O.........(.+.[..P.+VV......U.......Li.....a..`..``....U.V...;w.4+W.(....5.....~........@.\..ce.+.Z.g.|.2...{.rb.......+.\V..z.v.9+.\..v..q.........4.(.+......bb..+...4.#...0..0..q....~.F..+.:.:......
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PNG image data, 186 x 211, 8-bit/color RGB, non-interlaced
    Category:dropped
    Size (bytes):23974
    Entropy (8bit):7.98980539299338
    Encrypted:false
    SSDEEP:384:3vmutSswGAPHg4bq4RvAC3Q6F2jZo7WyByTUQvKMU0albiWhpFYE1okcFuoqvED0:/mut4o4O433DYNjwQSMkuInd1HcFuoqV
    MD5:75DB8E0E5846B5C121A530E205E7F0A8
    SHA1:4D4233C7E01F12C34024EE03EC4BC3A9231DECAB
    SHA-256:663E0BD305B7D0E49FBE529C9D5EF07E298EDBD434BEA1D609CE781D86181C99
    SHA-512:8B5493146D929D178D23B5E8AD8DD799E448A7A3D39AD2173AE39F6E3F4513BB9BF6C0EB88FCCFB2686DBEB6DA07ACD1DFCD3A14532D2B7B19AFC6996115DF05
    Malicious:false
    Reputation:low
    Preview:.PNG........IHDR................4....sRGB.........gAMA......a.....pHYs...t...t..f.x..];IDATx^.].`T...lB..kP..<.5T}...R...J..4.".(U.......z.I.PBIHB.. ..l.......s.lB.)d.>..w..).93w...qm...Jqr....J...5`.%..[Z.X..40gH1\.z<.<....\h..-.........^.F\h`.0.b...(7v.../V...,..a.....}..j.....PV.K<..>o^....o.....b..d..%.^.~..X....d....;.={.e....,..gj.us..Te.Z.>..j.1.=Kn^..y.X]........E..|..W.u9....b.~d....Kl...0c...Jwy.X-......?}Y..2z...e..nU...s-...".....+.s.....B.o..........-.tV.G.Mg(q...%........:...W..y....h.~..V."L}G.w.=.B.y..+%.>.@..o..;civX,u...w_!..|...bI1.:%.......%.y}......~".4...:t?. ..G.<.../.DY{R...w<...,V....b.yr..Q.V.....+.}f\2}..`UR.,...N.:..[........Zw..L..SRS.R.^.F.<.I..[.%;o...$r....mK..|Qz..C.3...{M..bx........{.a/.G]:.Z2....o..R.<M.[._a.W.F..G.;.'.[.*..{..;.........u'.kK.....u.2.DN..5..`..b|.../.[.`.W.z;..gU*.....aV..b.q.b..Gu+.2$ci...0...M..c..i....Ic...9a.d..G<z4.W2==|.=.6...u^.z......+..../z.x*.q.c..u<}-yW.ZSr..2..v.C.V,C
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:GIF image data, version 89a, 25 x 11
    Category:dropped
    Size (bytes):1018
    Entropy (8bit):4.1515989285202926
    Encrypted:false
    SSDEEP:12:hvRk3OM2mKUwxxD8Tlvbl0jioxQjOjA9yv:hZcRxiYlvb+jioxQjOjAAv
    MD5:2B7D1F71A92261CC5FC2CB8CEAAA0B5D
    SHA1:9F2E798318CB2CB830EBACA3802239C633216ED8
    SHA-256:62E5952EF9198AC5940FB4BF90B580FBA3BA1D7253C282CA527AA95C9080574D
    SHA-512:9B2A00253D128F8E81A18F17A5076C4817581D6728D20B34039610B06BDD3E0D3B785DF07023BF5D6F6A1A9E62C5A46F86AF8A3E6CCE7DD62F31BC3D2E17E338
    Malicious:false
    Reputation:low
    Preview:GIF89a.........................)!!)))999BBBJJJRRRZZZccckZZkkkk..ss{{{{.cc.......ss.......kk.........................................................................................{{............ss......................{{...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................,............!l.@......r@..!....Tx..G..1.h..q#..;D...#..)Sv$...-_^AA#.....8.a....WZ.d.R..$.dP.#..!+...B.J.*.1..A.B.%<J.!bB*...^@.!..Mz. .d...%...A..(D`.!..D..H.+ny%B....$.1eF."'.&F.X#..-...`....5.X.+sc......P....
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PNG image data, 415 x 132, 8-bit/color RGB, non-interlaced
    Category:dropped
    Size (bytes):11435
    Entropy (8bit):7.91407264560111
    Encrypted:false
    SSDEEP:192:u8Mn+kqVYKVV90G9qsLQJ5r1Vff3UT2sTtN50VScEaEhas6BRlvVfVs5W:en3qtVV+iKZspaoaEUXBftyW
    MD5:90FEC936E7C51CA1CBADBA91574B67C7
    SHA1:B2CBC14A8EDAE5EEA33071E1A3B681398F257BD6
    SHA-256:12EF3FF9D5F5ECBF7465FD943776BD425561BFFFC9962447674226DF1316F5FF
    SHA-512:7D8F0737C2FFAF09A5D24AFEF485A84425CC0432B9418F309C0F3F2D6881F91FB9ACC259E8BE51681E24BBB0EB4E68F71F6DA37857F4981BAAC53C3ECA887226
    Malicious:false
    Reputation:low
    Preview:.PNG........IHDR.............../....pHYs..\F..\F...CA....tIME.....*!........tEXtAuthor....H....tEXtDescription...!#....tEXtCopyright....:....tEXtCreation time.5.......tEXtSoftware.]p.:....tEXtDisclaimer.........tEXtWarning........tEXtSource.........tEXtComment........tEXtTitle....'....IDATx..y|.E.....sdr....I.H.9.............z...J8\EA.w]WPQ_.B^............r.$..9....N.!.L&7....'....<U]U........vo3&. ...23.a.Cf..Pd.....2...C. ..2"t...@nm...........7Y..3.z..*`.....@.`U............@.F...Sv....g...tb.a.v.f..0.......3.@V.@.].8.................IDAT..en..}.9..CVN....V=......(+....{(-g..M,.....-....ae.L......@.QX.R...^.@ ..^..c...@{u..tp....s.YOU.....s...K.......v./Y.&)`..x.d..(.y.l..0....6...c.C...P....&.>..q..F2I.;.-3..4b.....Bd@.a1..Yd.D.X......R.tW..)..t......TQ^.U.C..s..E..H.$...........t`.....IDATu....8..,...._......k..C...'............T..t..1..3t2...!d........k.@w.v.`p.*..:$.i...&/.kU.W].U...'D.*.wpr.A....m}....8..d...K....P3.*)p..9..1*.*..U.$.3bd...........
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:JPEG image data, JFIF standard 1.01, resolution (DPI), density 300x300, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=12, height=883, bps=0, PhotometricIntepretation=RGB, orientation=upper-left, width=856], baseline, precision 8, 840x866, components 3
    Category:dropped
    Size (bytes):114872
    Entropy (8bit):7.795428115857149
    Encrypted:false
    SSDEEP:3072:CJASQEptdTA9W++bxsSohYyOFMaqIMwTySLYPjMsL:CectADBOFM5k2xAsL
    MD5:4C1169AC16284DB91B7C2767D569A78A
    SHA1:B70CA3A02B46450CF0CFEED522993232FEB17C7C
    SHA-256:12AAD01DF1DDFAC6AB77C7E83243EFD1D83D41A2CF2C2C73CE9C1434DC75E93C
    SHA-512:62E26AF0E787104B761800727E0D3A934C2A6D99ADBA0E6128C8B4847686586E2B32E8CF6232053DF6AF111556B18D0DC4A53DBFCFFAD6CFCB08D9AA30666CBE
    Malicious:false
    Reputation:low
    Preview:......JFIF.....,.,.....DExif..MM.*...............X...........s...........................................................................(...........1.....$.....2..........i.............$.......-....'..-....'.Adobe Photoshop CC 2015 (Macintosh).2015:08:27 15:29:22...........0221.......................H...........b...............................r...........z.(.........................................H.......H.........C................................... $.' ",#..(7),01444.'9=82<.342...C...........2!.!22222222222222222222222222222222222222222222222222......w.t..!............................................................}........!1A..Qa."q.2....#B...R..$3br........%&'()*456789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz..............................................................................................................................w.......!1..AQ.aq."2...B.....#3R..br...$4.%.....&'()*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz.................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PNG image data, 815 x 274, 8-bit/color RGB, non-interlaced
    Category:dropped
    Size (bytes):15854
    Entropy (8bit):7.7961968257281535
    Encrypted:false
    SSDEEP:384:C6LyymGib1aHY6j5goAh9VdgaiW1oTqLk1OFlm26:BGymR41g/+yoTWLU
    MD5:6088E531190EF69E0EF66CF4A62D26BF
    SHA1:4E37B5691F8BB5BDC7E11CDCA996666D32DC3D3E
    SHA-256:E39EDAB856231D2E2661F6D5DED452A73CB9C28A1C369DFE4DF3960515632B2A
    SHA-512:442CCFDBEA4D23B32B31394681C09500302CA9D5AA4DE718E01B93F950B763563EE5E6536E7D534C2158699A2A3710D35BA9A5F579E7873E62846AB52F842DFA
    Malicious:false
    Reputation:low
    Preview:.PNG........IHDR.../.........{4}=....pHYs..\F..\F...CA....tIME.........b....tEXtAuthor....H....tEXtDescription...!#....tEXtCopyright....:....tEXtCreation time.5.......tEXtSoftware.]p.:....tEXtDisclaimer.........tEXtWarning........tEXtSource.........tEXtComment........tEXtTitle....'....IDATx...}x......[...@.!@ ..y.V.(.... .(..K.W[....m..*.mm.J..Vo+X.(...." (...D.$..!..dw.....y.3;.;.....g..3.93;..3.].........'........h........l.....O........l.....O........l.....O.dcg.,.o.... 3%...q.....e.$......>..+............!...U.D\[.....YV2!...?......IDATJ...VP......t.ec.j#..].m..NeU.}.....$.$I..g...<.......z..h....W.J.....1.3.TWblDI+....R..`meU...1.R...:..:M...]_..S..Mf..........#.....&cc.SQ...&..FMnL..(...e.t.8=i.... 1....W..i..J%7+<I..x;..Is.......x.T...~.....n.7.....i#q+.....H..)...o........r...m..t....IDAT}c.......1....?!........1....?!........1....?!........1....?.}....hS..b...hRZ..4..B..H..D.$I..R0.!+.h.....d..y.p............hSs .xn.e.|Q..h.c.4.....)y..s.,S...z>.lz..\J
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PNG image data, 81 x 35, 8-bit/color RGBA, non-interlaced
    Category:dropped
    Size (bytes):1977
    Entropy (8bit):7.758975458182857
    Encrypted:false
    SSDEEP:48:W0DcGnipMUMlEjNyDhS2BEP/b0AeCmI1qzDUls:Wac5GQ8hShT0KzqPV
    MD5:17C344A30341E02FD0595764AB622DF1
    SHA1:F1594B5EDC082D5D84BD78E230C7F47FE53DD021
    SHA-256:C8D2467B6FFCB4E75F90FA3756DEA6E1492C9551665D704A3D25423C0BF1F92E
    SHA-512:DF7F19768273B3863E7BF699D4A22DB6E481891681018A768C67FE672837D9B00A3D98110FC9E8F274C8B325DFAF6449596246B93FCFB80A76AC5B5283263BF6
    Malicious:false
    Reputation:low
    Preview:.PNG........IHDR...Q...#......e......sRGB.........gAMA......a.....pHYs..\E..\E..-b,....tIME...../.........tEXtAuthor....H....tEXtDescription...!#....tEXtCopyright....:....tEXtCreation time.5.......tEXtSoftware.]p.:....tEXtDisclaimer.........tEXtWarning........tEXtSource.........tEXtComment........tEXtTitle....'...gIDAThC._LSw......-..........(:...1..1q....-[.f.|.e.2....m..63..d.n.A..w.. .f.*..a..R..h{.s.-.-L...8...r...O....9?.C.9.......^.s.g... ..Df6............r.3l.Xc.h.`.20I.`.z0*....x.........<CC..&%..Y.&6vZ.6H..y..;F...O.3.9..."...n...Bt:.lk......E...T"...'..<.......jE......Lp..G..$........1\......r.....si..).S....??"....! ...&5.I.ZO..V...`0x......D...iiPr\.|.g...`..A2.....\.0t..Px$....I..o^.}.....K._>...].-7.O.....p...,**BII.d2..}n..........gf.0O...MO.,.a...}.djgV.B......bA....i.].x1Epb...y..6.A.(.l.......y....?1..QQV...a.d..Q...2A...9..e........M)....p..HII.y...J...+.V......G..sx..L.LVP.6. Jjw..B.2....>.oCC.jN..V.TYJ...0d.."E.w..c'...|.FFF.
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PNG image data, 765 x 550, 8-bit/color RGBA, non-interlaced
    Category:dropped
    Size (bytes):51621
    Entropy (8bit):7.93748513782917
    Encrypted:false
    SSDEEP:1536:pz9oLtgMW2LkDzmyAa4ps3FSos2fqafhHK/dA/TJ4Eh:Nap6akDzmyz4ks+t8dAbeEh
    MD5:60853A8B217FD5902687CE6CB89FF07E
    SHA1:A86947E4E6699D4CC9B69CB8A35D2F4E034D7903
    SHA-256:B8C405E8227A577293DEFE4E439350DDED964B0333FCF46E48A78BB31C5F848D
    SHA-512:36EC87FB4EEBB67068A97A258D62868FDFEDEE7DF78CC8E8CECAD40AA142C251E38B5E153C8905B2BA4B4F0695A1B06E84BD9F084B82B223A069AD3EEEA5ECCE
    Malicious:false
    Reputation:low
    Preview:.PNG........IHDR.......&......?5.....sRGB.........gAMA......a.....pHYs...t...t..f.x...:IDATx^...`..?./[.wPQ....E.Xb."ZY...-j.V.{ .V....X_.O.Jm..Z....*.i..EPh..hYC.("K..$...~s..{.df.......3s.33w..9sfn./........N.>..'N...8u.JKKq....={........N.......5k...7G.-.U+.n..m.E.v.i.].vU...[A..C..t..A+.....W_..""""".D..o~..w...;.c.h.c.*..../.........1o.<.,a.....3...y%D.......F.m.^M..._.l;.^....h.C....~C..q.n4.og..u.w._M^.H.F.~..5.."=.w.0./..-;......K.Q;.....SOY#un..&\p....@..[.V.0..G.........~.G.}.:K.g.5.......S.?hz{5i.6..:.r{=....Vf.9.#..i.9...c..n....*s......|.2.h..8??.wNE4...l.T....F".K}..y.........:..i.).|....d.L.ahN....y.W.p..5.....q....o.^t.z].yg._..[._.......{d.i:OOM.<.:._.S,uM........<.8N}..-T3.)9..QU.....e...T:..4..p....".$UZK..eZ...).:*_.T..w..9.O..B...Y.y.9....../f...o........=._.....[...W_.m.Y.B.4..K.X.....#..h._}.2s;:9..z.$.Y..y.#...,.<..y....h.......^e..m..5.K.u..w.{.1....TsM.55...X.....GSG.e.n......m.
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PNG image data, 750 x 187, 8-bit/color RGB, non-interlaced
    Category:dropped
    Size (bytes):23056
    Entropy (8bit):7.952610377683983
    Encrypted:false
    SSDEEP:384:68I7SQtxFJ6oIKY9FfxBj28XtW/8X3uBkeiiC1DsgzCJ59D5ahNmUu7fZ2APyUAY:BSzL9kFfxBi89mpBkeqDPzO5VIheYUCY
    MD5:B54C9A944E0E808920C75FDA7698B4D8
    SHA1:CE593CB3C7FB36EE845FCDEFCE8E4B10604C2454
    SHA-256:31BBBF0588D58571B175E9D62B08A66A4A3EA87613955A3AC7A73A37C32B18D1
    SHA-512:8132974B61AEA5DC41EAC9E71CE741F5FD1BB760D453BCAA8312F24A247630C2F93632E2845448D28084C16D72799CCC0D3E1B48FAA63273A5A95F4DA9D34282
    Malicious:false
    Reputation:low
    Preview:.PNG........IHDR.....................gAMA......a...Y.IDATx^..XT...1^cr..&._.1...5.kb7......^...(v.],..D.....TD.a..... .;,.. j..08.O.EX.w.yxf......3.cf..*....Y..T.R..5.[......*P.....<4..~.Z...).*.#!.?...........L....\.wS...n...+..oe.on...`@....W........p....p..7./........0lA.Q..)/.~......B...2......g7.O5@.{#.c........J3uV.....o.....D.....*.....*....$#.."!.N.a..Hd.%.x.@./...^B0..7k.W."D.S&9f...u.~.f..W..`61......U....|Yu...H...D.!....I.b...@.P.A..Ly......E.q2...*6....:......h..<..%........f$..d..Q.t3..&@....f..5k..(S.P..-..O..)fc......`.H`...F....<...*...........aLF.1.b..lh..U2.,.J.0....1._..*..f=!<4........a..AD.SG.8.2.....4%4C..t.fr....'o...=l4&,...(U .l8.T..@....R..B-<Ry.+...`.......`.L....8...&.^..f.f...q..]F.e...{......7c..F.1..+r-.v......*P...64i....bm.>..yI...-.......?n.kJR..5Y..Z..dL.+........2..d/.2..Y..2._X...XR..L..@.Tf..<0FP....Y..`d.L....r.G.h...2.....|....*;.dB[{&4.R...MA.....i11.'y...P}....~..<....vf..)...6.I..'..=q\..Q.
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PNG image data, 657 x 172, 8-bit/color RGBA, non-interlaced
    Category:dropped
    Size (bytes):24296
    Entropy (8bit):7.93614619660457
    Encrypted:false
    SSDEEP:384:QMUYWwsqP2GrKl1pNiLjApTbzT8uJTyDS0FTh/CjB3lDjyG2MAtmZuszilYD3WAt:QxBwsDl1pQAMDx/CHDH2MAtmY/oW1M
    MD5:BEBF468C466BA1D0B6D09DBC62B8BD84
    SHA1:A7390A4BCC1A34B19C6EB1984697213241715CBB
    SHA-256:8A7A059FD3D666DB557F57AF3841B1824CE53CF5E4D7FB35902810AC46A2D604
    SHA-512:F0A6E311AAE10CF6D7705AA2427812A2DB6E2B957F23EB7D35054636973BFFD19BB2AEF3DB0E13F313EAB7917247EA60346F8FC4D71CEDA8A6286AB579453719
    Malicious:false
    Reputation:low
    Preview:.PNG........IHDR.............#P......sRGB.........gAMA......a.....pHYs...t...t..f.x..^}IDATx^.y.T...{....v....v.o.;...7.A.C..M..3..dh3..D....q.Q#*... 81O..2....&.T&!sw'Y.w..]....S..w.:..g..Y.j.......kj[.n]X.zux......#.<.&O.....p.m...G..n.!\w.u..k...F.J.9r..8..8.......n...0f.0n.p.........<,\.0$..j..h....w......O......|.q..q..ia.?..0t........i....C..B>..3...y.1bD8....?...._."..............+.C.....q.*...h....7.w.}...o_.w..nc.=Me.....]...J.Xu...X1..^3.._..].&V.u.u.Zs....b.y...XkH.Xk..o~.....?.o|..O..S...D}.W..pB..O~...$n8N.:5.=...a....mJ......$.w...V.\..|.....Ot.K.,1.:V...W..ty..Y..SO..V.w.U....P..=.p[..[..@...y.*.;..9s...<.Y.f%.6x..x..G+.m.....0s...3fT..C.%..8..t...|0A?...)S.T..lX<...u.4iR&......w.}...D....S..{j.......W.[e4w.uW.LN..I..w.Q.&9...o....5..zk.c..p.-...s....i.|..U.1N.. ....D.Q..Q..m.6C[.m.....c.X1d...ycX4v.X.....9n..K..i1.........s..C<o.....'./e..U.[....,...<../....@...k..?...Z..........X.'...x..s..l......N..X......
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PNG image data, 423 x 250, 8-bit/color RGB, non-interlaced
    Category:dropped
    Size (bytes):7766
    Entropy (8bit):7.8728053445552
    Encrypted:false
    SSDEEP:96:DIMKqFcPMlTaMJ2aa8RJyCGvB+TU/RlfvgCkGi+zDYHNhOQF/fPALeeeeeeeeeef:DPKqGMlTJoaaAyeEQCSIovDfPAfp
    MD5:EA9292188DD354745A6ABBD75F4FFE7E
    SHA1:FF755B3B4548F7FFB4BA4374BB612117B3FFA8F4
    SHA-256:C32752605B207AF6C89E2074C107B005FFBB1D69E66C29C97FA30AB62CC68F4F
    SHA-512:C3D58131C7B902C72D9A6FC18C25F9B29BED804CB40353CF8DC344E363DACE576F8090A343C551F6DA41CC46190EB82DC53FE8A9A73C57239F6A6A8B84371411
    Malicious:false
    Reputation:low
    Preview:.PNG........IHDR................R....sRGB.........gAMA......a.....pHYs...t...t..f.x....IDATx^.........x.!$$.a..%/..<....M.)...........J....XD.!.&;.q......6../..\|...3..[}...sz..:U.>.....].......WU=]..eC..@.....R...(...B=n..@....za]o.E.......=.mc....v=M..J...:..qpH.0P...b,I[_.U.Wj...p.......=..,.Y....]/jY...].5.<...@..%..&C.d*Gd.z...?.1.n.TW8I...]..0....P.#...^V..U.R=...ZTE.d..!...rM9.36+33.d..X.9..P.J.RI..v..u.6............/..r#.@Jq.m+.r..<|jl,...Yh.I.j7..N.,v..X.*xt..*.tE=.RI>%)/u..JE|....g-H...1M.....+0.+X..(..J.y].T...zM..L.XA.wUf..+..U.e.#.......V..]0Y....R..~*..^^....9_.Z.S....,...F..'_......(4..RY...!........* ..W.o..$.X.0...H...:.T.c..~..x....k..w..{....6./..H...Au..Y.....[RpvWr.m...f.F-.$.. 0........p.!......6x(.T..VRs...^d.x......S...+p&3.f.Q....z*..k...;<.+=......|./....\n}..4"Q../.........g..L.t.5......#?...[R.....V.Q:.'.x.......-%..Q.e.2*.(........0VR".......C...lL=...h.C;..U....I.(.....^... ....zr./'M...|.].Kf...rzJ}.....q.R.N...DQG.H.
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PNG image data, 496 x 168, 8-bit/color RGB, non-interlaced
    Category:dropped
    Size (bytes):17031
    Entropy (8bit):7.966033579794287
    Encrypted:false
    SSDEEP:384:lRYnzG6KdDsmz+z52/6F6+TvTSY2SoWn4yXPIQhhrjrA+ZC6j:atA1+N2i8+Tv+S4+P3hNkMC6j
    MD5:116C5A4FF6DA5CB53187C36A154EAB99
    SHA1:5A4307C517644BFCC84145D01C504852EE820C18
    SHA-256:3EA79061D938456683638BCF7EC1DFD0F317F8C14A72D2AAC4503AFA96DF3874
    SHA-512:F5D16BCDD4F84DABB6175BF4D336F17C374E0350BCC15BDB261952A5BFB043565DA47B52BA0DB9583139AE27E0F51951B49EEAB440454E13B009CCBEB716ACF3
    Malicious:false
    Reputation:low
    Preview:.PNG........IHDR..............d+.....gAMA......a...B>IDATx^..x.G....{...{g.....&'.d...l..M.9G.sF... ...L.9.......$$@B9......4..J....;5O?.VOwuu..ojjzz...j5.....l....X.@.-..`...,........-..`....p.[.-..`...,...t.8.<...[.-...................];.[M.0.*...l.....5...4.....Q.26.S...h:+./_.....%&.l..\.-`..P....4h.@y..t.9....`....V..PG....9......L.4f.@G.44...S4....W.e..\.-`^.`.W...L..0@.;.$g.....%..>|X..... ........".&T.....Ew..{Q.}...p....:.&..h..(F......^.HdP........:....5*..E.aOctF+1.!\..=b.......U.7.y}.Y[...[..^.h.2..P.......\.......U...[W........H.E...($x..TAy.u..j.C..."...!.FA.........)@\V...t.#....Ae..e....J....a.....t...4..=X.[..,.@..q.6@.PE^.8..a...~..@7.r!....e..E. .~`G.s....pEe..X.a..!...+.#.j.C..(d.=...+.J...L..R...C:....V......-[..-.@..PT...&.6..[.Dr...:.y..*.+A.@.^.%.%IO%..m....2.Q^...8Dm...].(T...0W~:#^D....Cc%...Z.)^......fd...a...}..3.....J.....N.{E.Sw.M8..%.0..+}g...._...2B.d:..B.*....t.!.\..O.@/@..}.YU..+Z..n..J....l...Q.B..g..`.A.S\[..K...
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PNG image data, 232 x 236, 8-bit/color RGB, non-interlaced
    Category:dropped
    Size (bytes):12142
    Entropy (8bit):7.926298956700684
    Encrypted:false
    SSDEEP:192:YSNto5DebCxMQdQntP7zhlN/WJtz5P0v9OcEIqqR8xw/ll1QdIjXaDhmmpmF:Yg25Dt6QmtTzh3WJtK9/dR8xwdsIjXgG
    MD5:795F15EF24424EB180082094EC14E9B6
    SHA1:F7810F9A66D669F5ABF0D8351CC79A4B68496F9D
    SHA-256:6E73012FE4908074090674CAB324A0A3666A4C72ED0CC5757E5C6AE1426B49D4
    SHA-512:7B8D4F3A366F636A940FB266A616AEDDC0E851A8486E3F15A8CE00FA9B65F5CF477FDFFF9036196977FB9A44C575431AE8D4FB4CDA1241A26026104BA4D2DCF9
    Malicious:false
    Reputation:low
    Preview:.PNG........IHDR..............Z}9....pHYs..\F..\F...CA....tIME.....43...V....tEXtAuthor....H....tEXtDescription...!#....tEXtCopyright....:....tEXtCreation time.5.......tEXtSoftware.]p.:....tEXtDisclaimer.........tEXtWarning........tEXtSource.........tEXtComment........tEXtTitle....'....IDATx..}{t....{...d...l...cc,[..1&..1...!..<f.......d&.f..!d.!....a.c..d...$.....,...N.3~ .._.%Y....~..Q......}...wtt.v.U.U.._}]..je...]]]..:..(.xAQ..q..B.,EQb..B.O.m..4..,.B.......<.....UUm.6.....S...m...TU.,].m..4.OI\......@t...4M....)..~.^.a ............IDATm..l.$t....o..."-.?na..'7.#...%.i..x.''..n=UUu].4._...i...."....O.q,.m..].v.;.g....i..q..*4M..B'..gU..UUU.f~.....y0..>.Zq..+......$. :...DT........JRa..@Q.,.Sa..I..2p........j..Ob.t..c,.-..k.F|..p.O..K.......%^*.A.....]6..q.. ..a.6..m.8.A.G.D.....IDAT..{?y\}l....=....8.m....!7.../X...M!B..$LZT..8.Q\(.;.!i....$...S)....gK....G.S7.x.;....O......h....H.@ws..P....D..X7Bn.}.8...[....D..)H.....8 .....Y%'.s......._5l..c
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PNG image data, 550 x 283, 8-bit/color RGB, non-interlaced
    Category:dropped
    Size (bytes):15446
    Entropy (8bit):7.873169515767567
    Encrypted:false
    SSDEEP:384:fJCCUG9D4HjRNShnQnvXCpTECnR2NQmUC8QQCT6qO0ZCCCCCCPMhJGH8:hCCV8jj7XCpNnR2kC8QQ+tCCCCCCED3
    MD5:5D21FD6A9DF1083CD2285FDC06517D88
    SHA1:882C3BC4984EC43D434DA068E0A6FCEF0B5C5A32
    SHA-256:370B1FA619277ECD358A31C4CEDAEDEE8AB499426019FB664DB89270D17108D3
    SHA-512:752021FEB74DD34459E785DC9288B65792C4F7C0990BA0E199BA8BF78073FA3369F7FBF4AE856CDD90704C293D9C600A063E2E17A0865F17C69E85560C0FD349
    Malicious:false
    Reputation:low
    Preview:.PNG........IHDR...&.........a.......pHYs..\F..\F...CA....tIME.....:.........tEXtAuthor....H....tEXtDescription...!#....tEXtCopyright....:....tEXtCreation time.5.......tEXtSoftware.]p.:....tEXtDisclaimer.........tEXtWarning........tEXtSource.........tEXtComment........tEXtTitle....'....IDATx..o......sXc.Y..yJ...[..us/..Q...........X.o.s........J..J$).{+h../..z..2$..-.......B....C..A`.....E......3g.3..O..=.OO..{f.;..g.}.$......Z....0Q.......X............X.....(D}.]....Q.~..l........^.._..........S...SX.U....&.r>s.g.,.3.....H.S......IDAT.j..W.D........]...S}.W..u.=...9)......:..0..Y.........|e...tE..>..`.H.9.-].....Sf..M.3.ons?6....X!.Y;....l.........@.)?I...p.Z.e..j.....7.c.n... ..[.{..s.].W..k..b.....Q5...C"...e.;>8..9..T=.q;4.o..7......FO.hh......g:...$.(...#.z9..fE.M......D..zI.....IDAT...@ma..... ..XO..............................................................................................................B..d.o1....U.c].:!...~..X...d..6u..]...6..,
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PNG image data, 872 x 234, 8-bit/color RGBA, non-interlaced
    Category:dropped
    Size (bytes):22603
    Entropy (8bit):7.922344963068278
    Encrypted:false
    SSDEEP:384:F+4bh7/8iXEwCIVtspXOTGgKqqfoizxLw7mOWXGLrZ3LeuK6VQzGykpblQmuc5d9:FbR04C6tweG21iz6M2LrplLVQqyU5juc
    MD5:C522F6F77C37CFAF6EC29D65DA733957
    SHA1:1DD06968489EAD09EE889ADA78BF75E5A5552DC0
    SHA-256:18FCE64F23FB96A00F4F0535AC65D127B41C0F58FC5222024B48B54BA1EA5F85
    SHA-512:ECD130B2CB88E863B91E4F6FDB46FC530E457A76071BA5FA3CFDE3DF1D90F9FA051C9FC35F5572C3349980B11309F64DC198EEECB0D34F07FD523EE812C7EE21
    Malicious:false
    Reputation:low
    Preview:.PNG........IHDR...h..........fs....sRGB.........gAMA......a.....pHYs...t...t..f.x..W.IDATx^.Y.\Wu.;...C..$.yD...<'.f[......F..F.d .B.lL....G,!.....L..Q...lY.*....d+6.*........Y......{.~.>.>...g...n.V.Z....g.?..?O..g....O.$....q..?...?..?.B.!..B..0t...<.>......L..6....^.._.5!..B.!..............i............]}..._.b:|...q...9x.`)v.?.*....>.../7Nt.OT.2...:(.m.s....|.._(......./..*..;..r..w.q......}.v.m...zk.[n.e"..wE......i..~D4VL..Y.".3....|......9..S...6g.y.'.;"l...7.y..%.V>..&.-.,...#..........| {._.._...o~.K.}T...o............8r.H..~...C..P:v.XV.....<.~.Y.... g...>..Of..=.Ioz....\.....>...7N....(s]6l.0..pm.......o.....3....q.{^..Y|..__O..._..n..v.....~...;............^....}.k3^..d.....W.......ty.+_Y...xE._.._......./.....^.../}.K.K^.....]^..........{...s.....~....q.9.d,,,tY.fM)g.u.H<.Y.ZQDu ..}....>...:.>.X`y.s....u.X........_..'..E/z.T...J$..*..W.... jSv...h.A.._.l........G0.@~A.s ..@..s...0.B~.|....(.U...!?C..sP.z..Q.H..J.s
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PNG image data, 555 x 263, 8-bit/color RGBA, non-interlaced
    Category:dropped
    Size (bytes):20775
    Entropy (8bit):7.924771584070644
    Encrypted:false
    SSDEEP:384:aB2rZvWihkSmJuROpiMmHQnQi1aT8J/Z3seyrcKr0w+MgnoRo05+r:I2N5kSmJuROpZhwQJhWcKr0VDVZr
    MD5:F31594FB15F166C3679D8145E1D0C3C3
    SHA1:F797CD2FB40E4E627BA6A2226AFC6233F29AD17F
    SHA-256:BEA10856DEF6E52DA832EC94C19F0C136F337E93E2BAF4E9A082F94F6CE1A24D
    SHA-512:30C52A28811C634BDA21F86161287F022548B87C025EBD8DEB5FFBDCC2EDAC2A8E4BB483FC20B883C6CCDC41D2BEBF2BC695409AC656A3C2798C258519B15CB8
    Malicious:false
    Reputation:low
    Preview:.PNG........IHDR...+.........o(......sRGB.........gAMA......a.....pHYs...t...t..f.x..P.IDATx^.}.......]......nq...,T.......(..bd.~Y..yW...a.h...&.DW.5UV@./[Z./[$o...0\..-%y.....93...j.=3..O?.y....i}z...t......0....u.@...A...0......0..0... ....0......0Pk.......(FU.U....0............0..........Zk.bD...0............0......0Pk.......(FT.Q....0............0..........Zk.bD...0........<{.....d^.........0....Ua.IV...W4...'Y.u.!#.yZ.jQk.|C.....h./......@g1.9....q'Y....%9..,0. ]+....?.!L.n.....iE.6,.,.....P(#..w....`.S...0.......d....c..S#a...):..k%.I..!.X.;vA>|IA;d%$ I......h....0..t...d.5..K.....>].QaJH..O.,..j)Z.E?L...T(...:.X.......Y=M.5.k$+s#Id%.{$.Fb..G.S./S...........0.....^d....'.+.....2&..EW.....=..L..r....C.^R..T.z..VH..h.'>.lE...Y..+.W.t.S........c.......z.8aa....6.....a.i..4P..... .gZ..MV.dH%+^........U.v...O`..........o_.d....*p(......i.G...Y........)...@.."5r.Nc.d....a...0...............hr.c.4....5+.......w...,..Y.w(....|}.S.N..`....z....J.....Hu....TT#j..
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PNG image data, 471 x 194, 8-bit/color RGBA, non-interlaced
    Category:dropped
    Size (bytes):14838
    Entropy (8bit):7.956464403549422
    Encrypted:false
    SSDEEP:384:sqUMaAyWAFwbI8Mvj/R9s+AWFGg+KUUOgWIc3YIHSFujiQ:35neFHr/bs+AG1+KUUEI2YpujiQ
    MD5:9D1526E01034C614BB952BE6FC63BCE1
    SHA1:6747AF5828DE501566124FFCA909A6E55D90DBC8
    SHA-256:43C5A21F2F7DF15AAD61DC74D451535391936E430B7BB1A51541D8E10B461CFC
    SHA-512:ACAD39242A3D1A0E3E9CCE7F5DBB1DC63EA434B8A522EFEE96D2707749B5BF08D9BE87E1B737CA8EFEFA82A0182682D607B5DE1C2A9E44E5A31837BD73E2ABA8
    Malicious:false
    Reputation:low
    Preview:.PNG........IHDR...............]....sRGB.........gAMA......a.... cHRM..z&..............u0...`..:....p..Q<....pHYs...t...t..f.x..9_IDATx^.}{t....J.!$.~..1.....m.NH.^.......x. ..83.r.d.GHf..9{...6..1.......o..`..d..D`../.(... ..IX..zlWKu).....!.{.kN.t.....~U].....N.:.h#...B.. .....(.L.)"...B.. ....."W....!@....@....F.(.#...B.. ..\......!@....#@..1.... ...B.. r.>@.....!@.D.@.....<U.J...3r.. ...s.L.^%r5.4..\[..b4U.h....A..}.....m-..>h....%`..T..\)-.... .r..6@.F....k..'L?...=a...Y..I..2..D.P^.....eA...."..!NV..Z.`;.....y;......=.v-A....%M......g.B.!xE..9......N.\.#_....#}..).......&r5.W$.#.b../>....... .Ts.T.}.......N....[..|}G.H.($r.FH..b. G.:....6..>]>..~.=..ND.....g..0..N..O.."@.f....!0-...<......".i...G.|.....~.k...F..E..cj.1.X`.7.d.\....n..^.W...'.*r...y...S....U..;q..9...5.K.Moh...$Z.xC.jp../.v.WmQ.e(.}-..._.........5.'...B.. ."B."...w5QD......?...az.p@.......l"W"..x'B.'...D.KNf'..KKA}0X..v.p.K.c.....D...N..N.-.[../9...,Y.......a..7.........4..pr=..H.....u+
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PNG image data, 599 x 140, 8-bit/color RGBA, non-interlaced
    Category:dropped
    Size (bytes):6635
    Entropy (8bit):7.811006420728725
    Encrypted:false
    SSDEEP:96:U5aFgBqB0SC5hCITqs/VWV0sedBdzLmgOh/qJ4pvHpNyyyRVCAgm3kUGHIdp7Zbs:UIFZjCPC2VYUPNO6UXBy+JqGUpVVzu
    MD5:8719EEC95D51D8602F2CEC5CAB0C992C
    SHA1:DAE6C0D5CB54F76F92B1E0E21590DC400554C0E5
    SHA-256:E690EFFBBC9277CF692388F0A0186A57541207F8E5D6AFF6ABD629DD26786195
    SHA-512:405A09DEF799689F12527E5F803B1FD70973C3ADF7235A960A4ACD5D59E14E606C233C90C38DA22745DA6DD9A60C71CA8D0F4D0DF9FA791ACEC1D8F24FE7CC18
    Malicious:false
    Reputation:low
    Preview:.PNG........IHDR...W.........Q].A....pHYs..........+......tIME.......'r......tEXtAuthor....H....tEXtDescription...!#....tEXtCopyright....:....tEXtCreation time.5.......tEXtSoftware.]p.:....tEXtDisclaimer.........tEXtWarning........tEXtSource.........tEXtComment........tEXtTitle....'....IDATx...}...y....y....Z.H0.%q..cT.c.8.....C..(.M.HiR........."J.5o.(r...%!....;.8..Sc'H)VR0.z..].N.X.2..3sf.wf.~?.z..s.s...gf}.I.....E.$.."....hU._.Z.A...t..+....H....<"...........#.+....z|U4...3..../.j......%W..._.....5.jc?.z].Z}.w.V..ow.../.....j;.}..#..*.nk.S}JR..:....\O.....1....K[n..%V.........v..F...<..;K.v..n..Y..):......~...*.j....\%%V..0.......us....$*..g..Y...u...o..%V..G..&\......eM....Z.i.>...m..N..Z.\.....t].I.f.'l......|...m..{.b......n..m...n3..../>...^g..T....\5..s.Y..]..Q.Us. .?"e:...`L..\.w.+O<Iqt*v.2Y.d....-......~.R..O+.6).<.CZ....R.K.....t.%w.x.n.,.H.H..r.\..c......h..H.~y.v.A.8r.2....mE.u.u...v.^H...M..N.;..">..5qo...f=We=V\....w.D.5.j.T5... .'
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PNG image data, 876 x 191, 8-bit/color RGBA, non-interlaced
    Category:dropped
    Size (bytes):7022
    Entropy (8bit):7.597215023404021
    Encrypted:false
    SSDEEP:192:W4+5uNTdzmt626B7c1pz4OYeHZjqz8pDeahIJ6EDHY:P+ImHYQTzM8pDe0EjY
    MD5:6DE6E88C9C46DBC2A99C59141008A9C1
    SHA1:B4187C113DECF737DE8D29332BCBA93197B6C5D5
    SHA-256:D949DEABFD9156DDB1937C22D1BCD41D3025CB0A7A041CB9222645469968DC91
    SHA-512:B447DE7B4EA39FA0CDA211BAFE7188FB0A27E2AA911136490BB8C4D22B14336739E4FE28EDB188432C97F8DC6F5EFDDD8E56F9CCA2187EEE0695EEED587795D5
    Malicious:false
    Reputation:low
    Preview:.PNG........IHDR...l..........._M....pHYs..........+......tIME......"C.ig....tEXtAuthor....H....tEXtDescription...!#....tEXtCopyright....:....tEXtCreation time.5.......tEXtSoftware.]p.:....tEXtDisclaimer.........tEXtWarning........tEXtSource.........tEXtComment........tEXtTitle....'...9IDATx...[..Wa.....,.dK.Z.)..[r,../$.....y....b.%..8...7.............!.5e..."..J..$.@6.RA..X.jw...s.0;.....=.3gz.?.xV=.O...3..e.$'....@p&$...].....@...{...........l.........gv.)......0...S..li.......I;8.)......(...............".....@..l.....(...............".....@..l.....(...............".....@..l.....(.[Ifv...=..H.f..5o.{.P.&.z!.2.'...`.&.*.....cO..z.....7.2.7*.\G.R.e.4...m.o...~!.).Q.?...B.[....=.....gg.,......{..`..;..=Xu.....9......TF.zi......u.K.....g.y..:.{...i..........7....,S..z-G..y...y....Viu.Vn..j..i.y.u...y..n.I.K;.6,....{.2...,.8....<...*.....Gg........zc....PT.:..,..u+.....#.:'M.S.^.%.g.2.*;)L...w........T.<|.}...*b{.G.e....|.5.......=.L........o......
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PNG image data, 526 x 183, 8-bit/color RGB, non-interlaced
    Category:dropped
    Size (bytes):7734
    Entropy (8bit):7.879695082053139
    Encrypted:false
    SSDEEP:192:mMoKrAsU3w6C+s7drIb60NArtMrZtjidM4N21Y9spThOMQAQC6Txsnnnnn/:mRKrAV3wx+8drIuIfj/1Y1MQAT6Txm
    MD5:EFC8FBB24E24B75741D7E2D17B4F4406
    SHA1:BCE8136DEDFD764BA6B30C7783229C5CCE6A7E04
    SHA-256:AE422795EE89E491DDD6C09928CCBB6DD8CC4A5C22E29BF50E920E7F78706BBC
    SHA-512:02D932B86EF0DF733F50028AEDF7A37201558FFED8CC8543F22733223A477725D90E7F50AAF73633B3CA85920A5A54CEB9E7C66A8B2E47B06034C2288A8FC4CA
    Malicious:false
    Reputation:low
    Preview:.PNG........IHDR...............A.....gAMA......a.....IDATx^.}..E..A%.c.J..@4~..?4...?.@@X...Uq..c.A..h..8..aT .z.....7.I....D....8. ...(.(H......R..>}.[}....t...y.._...SU......n<H..H..H...H... .. ..(B.........@q...F......@..............1@..!`..k.R&..;w.{.:.]D.>}^|..23gr....r.'9... ....0.)..?......L..-[....K..mH ..(..o#z..."R....A.}.A......^{.......?^P*.n.:e..\gF$.).JE..Yxu...!s.H}..K....5k...80...../.%...Y.fU.~,..*E.RQ)..7....*z.....!n......g..B.K$....".4&.@.....C....G...'.hoo.0`....7.......QC.$k.+V.PD.Z.."..5.u...,_....A..T.........A.R..E.A.$@.A..T.........A.R..E.A.$@.A..T.........A.R..E.A.$@.A..T.........A.R..E.A.$@.A..T.........A.R..E.A.$@.A..T.........A.R..E.A.$@.A..T.........A.R..E.A.$@.A..T.........A.R..E.A.$@.A..T.........A L..={....Y.g...$@.$.8...KC.~.G.R1..........@.........."..kG.$..P*D.`.Q*..!...5..I..'...t.n......5...}...[...t.JE.}IX_. ..........y.........9m.4S*..qf..~[H..j.@hR...aJ.y.!......T].3.T...'...M*..Ra...>\u.#F.0G...83$.
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PNG image data, 422 x 577, 8-bit/color RGBA, non-interlaced
    Category:dropped
    Size (bytes):35329
    Entropy (8bit):7.919109983017616
    Encrypted:false
    SSDEEP:768:4c+ajPsOGV9fvqI6fNFQt4iEkxWHPs3ZG7W8sSn4sLYwpQEA9scD:0OuqIki9SkjrMLEb5
    MD5:972F1F27F3947EA437B7BFB16CFE8BC1
    SHA1:ABDBA126D6D82860A5C21E174D5A10F140883B93
    SHA-256:5AF46C138B7344CE95A5ECFFE117CDDF833D8F0DC08CA81A0E3B83231F60D572
    SHA-512:C67544ACA67A92B123EB57180A825614F6DBEC5BC78B14E22D3D1C66716FB8B7BB96D6E28D3657EA5F4605372621E5D4B4F6D509E2E71130C73892EFA9B18689
    Malicious:false
    Reputation:low
    Preview:.PNG........IHDR.......A.............sRGB.........gAMA......a.....pHYs...t...t..f.x....IDATx^........r..@LD.V@@b..jP.D......=GE..`.,../.x..5.L..|"................5.%..,.H.E4....z.........Y...v.[....=.LU.N.l....O?..?..>....o......C.....t..Q....m....L)((...Bj.5.i..kG.:t...;......_.....k.{7=..~....@..o..o.G.:...[.n.K.*x.........?..O..........6g......U.V...4..)..d..#Uz.h.9..o.Q...zE...}..9/.....l....h..J.t.(..}{.......I..r...&..'V........-X.@..]|...wo-R.............t.]w.W..U-T<...w.....`a.1..N.<&U:c........ME...>......y.tW~.go.).......6.O.........-..W...}\...L..OP..o...O'l...R.e\..<BX^.}...J..=.{"U.N;.4..o.O~.C....j.............q.zY.Z..b....5...=..k.q...(.xr?..[...~K555.S'=Rz.'..[o.+..B.S!?[bQZ.h...1c........j<g..,J.\.m<.s.....$l........iA. ..|&...?......&..p......Oe.W.A>3....S49,[3,.%/.q..g...ai&..T...J...f..a&,...Op.M......aW~..iAp>......4!,.E.z.Q....[?|........^..C....T.v...wP..;....f...>~\...:p}.^\?...Y._.........p{..l.M.
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:GIF image data, version 89a, 15 x 15
    Category:dropped
    Size (bytes):947
    Entropy (8bit):4.3452573670291414
    Encrypted:false
    SSDEEP:12:P7fGqvP8TSrY/67yYdNSsRKLsoKtRbCadymjtE+TUXAE:jtvkTP/odIZQ9bbtELX7
    MD5:AED4BF38484DD3928BF37EB65D54D34D
    SHA1:F6699A8BDA91FF1FE3B647FEBA8049A644E6D4A0
    SHA-256:1E0B4A86ED970A162FF77A3BDDE1DC9877899954AB3DE24A7CAC9D28E2ADC2A1
    SHA-512:A076D60994EF5279CFCE26540DEEB9C3489D13D98E73702BD8FE18841CB4B452EEFCDD7A52BDC31ABDFFDB1DCEDBFA8EA20DA4F0002F60194E19C07DBD24920F
    Malicious:false
    Reputation:low
    Preview:GIF89a.............'''4//?==@99FAAWSSWUUf__fbbhddoooqqqwwwzvv.jj.||.\\.``.aa.ff.gg.ii.nn.pp.xx.~~..............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................!.......,...............H......jI...%,F.8.p`..!.tHACJ.&1D.......%.DAB...*[T......$<n.x2e..&\V.80.B..6..H..C......2....&....%...>$P..AG.,.....#.".8.. ..]...$..o..;
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PNG image data, 428 x 201, 8-bit/color RGBA, non-interlaced
    Category:dropped
    Size (bytes):10221
    Entropy (8bit):7.867409560642543
    Encrypted:false
    SSDEEP:192:h1lkLNlVPFV51ysHyqNW80a+egS2mzKqB1cfZfXwuHwx+xgAhfggggf:blkBnFVyHM//328KqB1Sfwb0Vhfggggf
    MD5:3346DEAD3984D52718703324061B7033
    SHA1:316BCC6C3A57C7D4E01BC91182AD4FA4548CF3AE
    SHA-256:31074E764648DF8CC70C60D8E7757CB464D371C2F3073B7ADFD28BCBABFFC46C
    SHA-512:3EC2B8D3D717902FD921384D27A7C409EABDA1DE2B6E4F45C04E032B420F9ADA9E6235E422E01F494513E9185D4F3A25D4C67E32E2FF5E664C774F88B095DC71
    Malicious:false
    Reputation:low
    Preview:.PNG........IHDR.....................sRGB.........gAMA......a.....pHYs...t...t..f.x..'.IDATx^.{l.........UU.*..T.P...S..Rz/....(.._...-PTqI..".uU.i..$8)!.E..p.<...$..0..y..3.....q...~w~ggfg........F..s.3...9.s..&.......P..D@.D..*B.(..... ..&..P..@.H(.`E..PI(.........(.........V$.....P..@......P..@.H(.`E..PI(.........(.........V$.....P..@......P..@.H(.`E..PI(.........(.........V$.....P..@......P..@.H(.`E..PI(.......X//YB~.........P W....K.(..A..P..@.(..rU..........Q..#t..).w?..W........@.(..X...:x...G{.qJv....#...]...4~a.>H&..V+-.=.f.G...v.i.<~=...(.?...k/n-.e...X.e...jq.^..*.C...%....@..(....'..x..;y.N..R..1...ZN..._..{i``P.Xf......,U...).x.*..T5(.m.JP...W....au.x7.:.G=..4>q..Uo..z.kh..%...V..=RIGNn.$......Y.Y...c.V.....>.P..@.E.|.....w.P..Y..<C....<.O..........w.../.....\?O..Z.>.gv..4.>%Hd.......i.h.<.k.E.o....X..;.4..i.-.1m....HE.r..u\.'.o...kX....Y.....N.Z.c...>.;...o.zmb........W.7....S..y:|4.Y].r.~5........~H.......X.L.".Kg..GftcL)*...eP.
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:GIF image data, version 87a, 17 x 17
    Category:dropped
    Size (bytes):882
    Entropy (8bit):1.5779511222694032
    Encrypted:false
    SSDEEP:3:MnBtK6kBDkt88Ru//TlPlhdsxdVgUyw9mKo/5ah2lY2dmWDmrAVlNidVt19ve:lcmXRxuRyw9Fo8glY6mWVa3G
    MD5:FD43C78217207FEA6F249854EE0F9134
    SHA1:4A50105C2D6C1043C217ACC368C4480ACD37C7E2
    SHA-256:C53A18DEFCB0FA71C0606941DCDF84941489921DAE9886F03E7B1F10DD071CD3
    SHA-512:2A9C9A1493EE3EBBBC657E2BB0FC01B5FDEC8884274C6F8A14EA9C0E812C5862F7442E502696EFF3A11833353062533D9B0F9385957196450D9E582FD46FECEB
    Malicious:false
    Reputation:low
    Preview:GIF87a......................+++333AAALLLXXXffffff............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................,..........W....H......6X.0.@...2.8...............).!..'S.Dx......8.Is&...p......@."$@.hQ.H.*M...;
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PNG image data, 363 x 354, 8-bit/color RGBA, non-interlaced
    Category:dropped
    Size (bytes):14035
    Entropy (8bit):7.897091177085313
    Encrypted:false
    SSDEEP:192:0IIk2KhZ2Y1BnjVI6xTYqZa71JpR5ezXQ1YWOHUr5XuQFb5LBtnTFB1avi/Z4t4D:lGCny6x0qA7rpXzhO8uQHjTOYZ4QD
    MD5:147483101E9386A7D042257A5B86499A
    SHA1:0CC527C5174ACD4D536091A687DC11BF373C927B
    SHA-256:33F7481874B729721A9D725F43E00F6126AE6EFD4436C7ED9A0FCCE416D44C49
    SHA-512:6108C61BF983AFD1CD8DA7CFF01C94881E64DA8B9B33B66F924C4F352A74EF9BE8D5C95C2D152B3C1295D05A8CEDBD1CD1610E03F05440AC6BFA81F0DC71B53B
    Malicious:false
    Reputation:low
    Preview:.PNG........IHDR...k...b.....0I......sRGB.........gAMA......a.....pHYs..........o.d..6hIDATx^....H....~.y...nZ....<A.+T=B..W.0B./.!q.DigS..Gi......?.85g(....j.FB....a..".';....O(E.......e{........h.....5p...v...?h..(..k.,..B.h.......DdEd.......DUh..T..`]...................4..+p.Q.Q..@........v....a.h`..j.TSl0...mA..b..(..www..y.W.....k...a.y/!.)}.?.....r.9/1f...i.hX+c..z.I.t{...g.....]s.?.........}.....u....U..G......c..[(...c.vyx86..........<....N.*._..w.\.. ..!.1....3..|m....w..f.O....v..T.......<kN..........>...F.}sw..O;x...p=..@..;....r.O.=...,r.........`.c.>.....I.........{...M....k..Aok3v.....<....@Y..-...[..._s.pn@..../Z3...e".....1`.s.].(.i..}.("l..|..hX.........p.on...f...U.L..l..3.V*5.:......{..\{.p~....6...X}j.........t..9.;d.DD...|..x.......<..5V'.3.u.I..m....,.....:..Z..5'.....j`s.V..wO+H..y.!./..t...kXu...R1OB...q.$~....h..+.....0.-...f.P..Z.. ".$.....i...C...6..........O..7.|...ow.S...`<....9m7M......tAd...?...T....T...`}7.'.
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PNG image data, 340 x 241, 8-bit/color RGB, non-interlaced
    Category:dropped
    Size (bytes):34990
    Entropy (8bit):7.979506031702677
    Encrypted:false
    SSDEEP:768:dVkCkrXVdTezsNtBxiJ0USdQxTWhoezj2m9fiPQpnqL2bBvdPE:dVFkrEOYshoezj2ifuL2bBFc
    MD5:B9E79F84163F94CBD5A78E557309DA98
    SHA1:A57E567C65521A48AD0AEDD87FB8144A1B1EE5BE
    SHA-256:C5413E2E6A71DDD6505E2BD69605F4E3D4E15A1D1F77708AAB7181003B81205D
    SHA-512:9DAF27F245FB4F77517548947E0B1CC361630B7FDBE0DEB755484AD6F9C9AD946D022C14B8EF10F44DD328F2073A1668E98BA6164DC7248DD23CB1AAB29BEFFC
    Malicious:false
    Reputation:low
    Preview:.PNG........IHDR...T..........V......sRGB.........gAMA......a.... cHRM..z&..............u0...`..:....p..Q<...,IDATx^..X\..Wvb.:=...|).I.........%.%...P.w..^@. @...H....v..{.m.|..#..Mt.x......3gv....;3..%I.B??...b..X/.*~.....z.Q.*..%..#.(.}DQS....^/E/.J....i.}.k.#)j....qA....V|.^.^.?.z.5.mL/EM..F#g..H..^..>..o._O?.....-..Z.......[ =.Xzl.._....-.~.Lz...r..K..-..\$=a......'.q./=>_zl......~:CRL..c%....))Fh/.Q..V..R..V..R.+U.+S...V.. ...c.?K1:W1"^1&M1!Sa..0.SL.SL)RL).B...B/.<..9..S.....k.....d+F...Fe...........%...w9.W.....h..].E...v9..n..x?P.qt...>.._.bd.bd.bt*..5)..q6Aa..0.U........3.c3..3.F..~......)....Cj....d9.IQ.IV.JV|.8x}f..m.z.tt..wv.....k...l1..8A.n.f.Q.>...y..ze.J.J..........'*F.....u..H.0O.L...t..t.4..4.P~?.....aP.B......^!I10I.?Q.u..g.tvM..m..+..L.\:!c...#...K.1(.....'.y=.....;w_.......T..k.........Q.b..@.b|v..Y....Y.1Z.?2C.?.'.|Yl.(..(.OV.MV.HQ..N....6...,.L..,d.61.E....E.\..?<.....@~.._....+7.5....wpm....3..K.7..N.-...RF....#..Yz<
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PNG image data, 591 x 323, 8-bit/color RGB, non-interlaced
    Category:dropped
    Size (bytes):62543
    Entropy (8bit):7.988356444921926
    Encrypted:false
    SSDEEP:1536:wnX80SsJC7g6rm5RtfSONFihMQDrLPRpNXGU1DWl/JX:cX8uJCdrqpSON8hdXPRpNXAN
    MD5:DDA73A188A60BC609F366ED3268B7104
    SHA1:253FF1F4E1C28A784A9559CEC6FCB174903ADD1E
    SHA-256:4EFF8CA0F21D8CA127DBEBFD19089CC95C3B12EEB0B5FEB1A99D286959C6C0CE
    SHA-512:2AFD910465307F0C11CD76145A6BB511188E0F23089BA5B7472B4A721670721F903DF121CCB023E028C39C9B0003A9932A7D9D9604BB5D52B5A754A83525D7DA
    Malicious:false
    Reputation:low
    Preview:.PNG........IHDR...O...C.......}.....gAMA......a.....IDATx^...xUIz..ow.vm....g...Y..zf.g<.OO.8....49g.".(.@.$!.P.9g..s..J.Q.*....[pQ.."t.4.<%=u.T..V..[.[u......^:.DTF..}......../...W.._.........._.bddd``............`......w....LLL.e..,$$......~..y..r?..........M.........S.q.w..wZ9.o~...|.MS.fgg333...~.....A.7..M``..o..;..; .n.:bj4...0PJOO......../.."55U.P.t.....?....G..G..J.*.........{{{SRR&''............./..].........}}}............?...........a.}uuu%%%Z...?..?....?<...,..?^.^....}.Z...GK...>H............?....nD.;..w~..~.].=3;...........w........ 9.....+..l7..3..:.L.....'MwW.Zenn~.....R..\......:;;...$$$ .L............iimq.p...j.kkUds#.....,{.R{.,.'?...5.k...(.}...S....Z[[+++.......9B.....'OZXX....b$q.x.qcxx..B.........g..i.c..;.....wtt0.......f....}}}.e.t..Q`.|...W..O.g..~...>....{G..s....9n.'.....%...........-...x.....'>.1.jjjhn..<..ie.d.^ ..{8......A:M.Z.?0...FG%a.m.6.3H.y3....Pd....s.N.....s........d.a..~.:.....v..w....v....O.T......LOMS
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PNG image data, 312 x 141, 8-bit/color RGBA, non-interlaced
    Category:dropped
    Size (bytes):6327
    Entropy (8bit):7.882261764146574
    Encrypted:false
    SSDEEP:96:rD0Zm+4jAoU/RjZ22iS4afAdZiUETNkeu2g5az2yK6SkX/VzDvn:N+oAoUb22EsArG3u2gQKKX/FDf
    MD5:CDA02DFD5493696AC572D257040C2665
    SHA1:4E2E316BE0AE4C489118E341F8EAE8B137029A08
    SHA-256:EBA764816173E3F7629D19FC0E71855145CC7A488BD00C1C771CDBCF6C80620B
    SHA-512:B151FA3DB4051D5154AF3671ACCD92A99BE9561B00A0F925ADBDC4455BFD27CA9C35CB2D954F3592826BC0F53F7CCFDA5980779BCE0BCC22AB70879E9D8D67AF
    Malicious:false
    Reputation:low
    Preview:.PNG........IHDR...8.........#.f.....sRGB.........gAMA......a.... cHRM..z&..............u0...`..:....p..Q<....tIME........`....."IDATx^.kl..u.......P..'..m.0..-j.i.....EQ.P..@?4v..h.....m%6F.#q.....J.....d.zPO.iQ.H.|.(./...KrI.....5..;......?...........3.3..n.:r..P..@.L*@.#W.v...C.4@. ..%..i...d......w....!...r.....\.\.........b..3..#..8h.-......3...Jl...*..8...C.d6..8.wf.;.*..ToE...p..b .1..!.3......j.....'...j.h'.}..WV...;...<r..~....$.R...P........6..i..... .</gl.l......."......v./-l....a..f.a.a.^.}2m.t9[.....M...b.D..TY....y.C.......J8...*D...*C.7am...~.Si".F._.........0.@6..x3...6m..M...X..I..O.p.)j..tAm2(....... ...B...~..?..2?L...#hGa;.:.....!.....6.|....j....+..Lb*+.D.8...``..4mC5 .I(..?Xl.M..aa..p*.M.e.........LT...X9.7..VO...............`.Vk..S......F.h~.U. .7.Po....t..S...b.DG..A>..P.....n..n....NB....'.K.r..N&b..,h/l....r.Up....h&{h.(.....,...:.L. ,.L....i...NA.'.......Mb...I-...t...@Y2..GW...N..n...lTU...#.C.'.._...N.t\tp..>.....6MAe3
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PNG image data, 299 x 206, 8-bit/color RGB, non-interlaced
    Category:dropped
    Size (bytes):6944
    Entropy (8bit):7.898466773364331
    Encrypted:false
    SSDEEP:192:D+YTo+DySUK4ds/XUiLVfeH33AGoHPpdqky6F:D+Yk+GSUKtf9mX3eHD
    MD5:51E7F57314129B005F6B7254A4E1909A
    SHA1:A39A06C9479363CD4733C11BFB97D9585B934D8C
    SHA-256:582FFED8B89065858FC5456F98D20654CDAC5060C3EAEE0594A774AA844054D4
    SHA-512:3FFC646429FC4F30D2F9E2FA5FF7B7D9C18DE441C89D8E095B41D2FE0E4378D498F2948AECAA0C9AFFE33A01002ECC16920DF43C5E979D660DDE0EF84F09E873
    Malicious:false
    Reputation:low
    Preview:.PNG........IHDR...+..........8.f....sRGB.........gAMA......a.... cHRM..z&..............u0...`..:....p..Q<....IDATx^..s....'l....]o\...}..[...m..p.z.*..N.....all. ..x.+....y.1/a..i. $..o...#! ...B.iF..q....g.L..Q.>.....s.{...?.....a..u.....(..S..~b.....)..Q..@H.@`H.Q......P .. 0....P...@(.R...R}T.(.'p....?P..@.....x..p..k.|.....;.q....._.b.'..b..)`\...l.....`.k.w.D.D..<A<L..L..&.........._...K...`..{...K..-......x..}...6iU.v%..t.D....hB.....8>..v.D o,U0>...5...W.Yl.5.3...2.l.....Y.!.....(.Iz-...@.%.H......D...YXt,u...v_....&.._z..[.....R.TT.%....3........YLtL.......k..m...-8.....z4....N.e!jJ.&..HK..8..o..p.......|%...%(.kKm...B.>..F....Q.}KT.7..8..:.g..Z....kN.y..:..;..D.. %.@....i.X\...rc...B..f.@UW.%.10;Y..D`.Fc4(...@ ...B*..C...D.G"+..A .......~....Q...@(.R...R..$r8.Y.....@H.@`H.#'NtL.. ..B.......&.....@...B*..C..9q.cj... ...T...T?5...DV...@..K.7...9..#......Z.?.......@....[..g.eO].=qn....@.hS...G...i.m...:..y.j.(%...H...P....~7.&..5q.F...q.
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:JPEG image data, JFIF standard 1.01, resolution (DPI), density 300x300, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=12, height=848, bps=0, PhotometricIntepretation=RGB, orientation=upper-left, width=865], baseline, precision 8, 840x823, components 3
    Category:dropped
    Size (bytes):86185
    Entropy (8bit):7.64659322399633
    Encrypted:false
    SSDEEP:1536:ZGn30QZ1+n//yt9YiZa5A+Mq6UPElWZngOK:u0sQW9YiA5lMVUMUZq
    MD5:EC4B877912DED02F1AD049594E333633
    SHA1:2E6CFB73A0BA0FE019CD6B8C06924B0AD7384515
    SHA-256:617BD15133DF1ABF5FC049548D29D324A1896CE009B3CAB9DAB60B7F6F876343
    SHA-512:3358C23C32DC186C76422C0DEFFA527CA0B7A574716D4F002F911F3C3FCC62786CEAFBB6B20871A7D742B1868D3B0745CB660C0C23AE8543623614173BE294EF
    Malicious:false
    Reputation:low
    Preview:......JFIF.....,.,......Exif..MM.*...............a...........P...........................................................................(...........1.....$.....2..........i.............$.......-....'..-....'.Adobe Photoshop CC 2015 (Macintosh).2015:08:27 15:29:00...........0221.......................H...........7...............................r...........z.(.........................................H.......H.........C................................... $.' ",#..(7),01444.'9=82<.342...C...........2!.!22222222222222222222222222222222222222222222222222......w.z..!............................................................}........!1A..Qa."q.2....#B...R..$3br........%&'()*456789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz..............................................................................................................................w.......!1..AQ.aq."2...B.....#3R..br...$4.%.....&'()*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz.................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PNG image data, 955 x 773, 8-bit/color RGBA, non-interlaced
    Category:dropped
    Size (bytes):102031
    Entropy (8bit):7.92418700836841
    Encrypted:false
    SSDEEP:1536:9WummtyeJ/qpYMUXrKafU6j+YEDXGs0Xf5IauIr492KapZ3meFCx0ptucHfNc:lJtyeRBtXfs/f0P5SIrpTrC6bucK
    MD5:036C197614E7FFB87C2588EF1EB05F49
    SHA1:519EB7F81A73DD36EDEE2EFAFC0C74F92C4CE63D
    SHA-256:3BB96E679DEC32B77B0A8EBDF5BAB41BC1D8E7B362C737D07E40EC717F095364
    SHA-512:F37621BDB2FA38FB826AAF3CD027284522BC96B0516AEE39343C1B6B5A8D2BF73D0EA0B87746E349675571F1FADFEC799001D547B796CB125AF503BFDCB3DD88
    Malicious:false
    Reputation:low
    Preview:.PNG........IHDR..............Z......sRGB.........gAMA......a.....pHYs...t...t..f.x....IDATx^..|........d.....*...*r.D...k[.......r.......5m."..R....Z.P...."...0 (K...DY# ......9.9sf=KrN.._#93..}..3s.s....;v4.=z.r?r..<x./.......................@2..?~<....G.t....;vD...VYY...~|..8v.....? ++.3f..]w....dnW.....)!m..\?...5..M...b.$@.Q...5...d..Qf4......?.V..+.<..l..aa..K....i...x\.j..X4.G{.h.|~...<.b.k...2.......(?''...z3.....2e....0...p..i......?...zL.8....&|..M[.jUSMM...:...{.?...!.......=..dg...M......S9V...7.7>....6..s..i...:dZ..Ve....<o.20>..e>.....vw.?...gs]c.....3'..^....h.[:.{.[~....{..M.....x..z.1.M....v.}...g./b........w..=.^r^...7.9.~....X.........9.T.m<WX...].......V.n..+qd~..........8w...k.....KyVmw...l..>.k..6.k..3.U...1`..L..N...Gq.=.......J....lB..+..._.'.s.y....f.V..tu.e:...!=.<..O...it...w.E..........j..{w.......C.{..-,,D..'5.;{.l..g?..#.LR.jU..BK........X}.....F.T.]..5......0....Tj...r.lW.r...l.j...N...2
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:GIF image data, version 87a, 20 x 22
    Category:dropped
    Size (bytes):1077
    Entropy (8bit):3.9047302648758917
    Encrypted:false
    SSDEEP:12:uZkCo+vNTGRSn1dGTakosD1bhdCecF4L5DXGEvQ1n:skCocClTgNecFivQx
    MD5:27185D305FDC21558356576B767CBA1C
    SHA1:901D72DD90BED9E1534308EF410987FC89D50229
    SHA-256:0EADDE405ACA2E01E7C39194BD9A7C8A7506FCB90D673F41F447B3918A72A735
    SHA-512:39CEDF299BBDF1C7500A96528686D7522FF0987C7A0EAED2B1B2FF73D101783D75C0A42CE68EB2F277744C3977E034286212A95DD3E9A778FCF6C565F33973CE
    Malicious:false
    Reputation:low
    Preview:GIF87a...................!!!!)))))))1111999BBBJ..JJJJZkR..RRRZZZccck..kkks..s..sss{..{{{....................................................................1..9...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................,............s..A......z.!....CxP......3b<.a...*4..Ir....rd.....%5..!...+:...s...rX....H...`!....@H.Ju....rD..b..`....!.../H.].v...r<.....x... ...2L..Lx....r(`...c.2.(.@....3k.<CA.....XA....6.8.a.....c.m.A..
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PNG image data, 31 x 29, 8-bit/color RGB, non-interlaced
    Category:dropped
    Size (bytes):1503
    Entropy (8bit):7.575914242534896
    Encrypted:false
    SSDEEP:24:BwDBzu+QOZ1RH8ykew1ao+fVQP/cFeQW6YcgxKDJifCx17tckf:KDllCp1T+fVymY7xKD0Cx1hhf
    MD5:9C5D92CE6FD7E75834B96417F0953A73
    SHA1:E7F968AC4B3635FC6ED11F6FB69278BCBCC0EDFA
    SHA-256:298869A1AF8317E6AE8B40C2D1B128784316C104D305BC48E48C0DDF6390F5B0
    SHA-512:349B4BC3BF03E7D51773C23BD7BF6BCB7D6B47E035F05A59C80B0F6B6BA3D6499B6BEDBC7FB8D6DAA0C87CDFD81045A7DE491970F522077558258D0DED73CA50
    Malicious:false
    Reputation:low
    Preview:.PNG........IHDR............... e....pHYs..\F..\F...CA....tIME.....,!........tEXtAuthor....H....tEXtDescription...!#....tEXtCopyright....:....tEXtCreation time.5.......tEXtSoftware.]p.:....tEXtDisclaimer.........tEXtWarning........tEXtSource.........tEXtComment........tEXtTitle....'....IDATx..V]lTE....{..mYj..J(%1.Q. H..b.............`b.O. . Qx.$1F.1.`b.B.......'...[..l.lwg...t..e.X.......7...........!"..D.)..&..=p.9.BH/HI..c...a........9...l..l...\..... ..8....m..?3.....U.]7.~...;....9..uO.!..g.Y]......l^{+.1...o...z...1...#...p.......IDATe.b...Xk......]..l. ....Z!..K.d...DT*....R....q......J.@D..E...\...S..R.8.b.X.2..1...n{`.R.......6$...[ ..P..p.bX..L\....{..=..2...?{j<....""$@.q5*.LQ.`.!.../.]V.r.......z..O..'Dzs.."X.(.1.....Q. ....'r...'...._......C&..@..f.^.".k-%N.>=<<|.h......IDAT.........v!......+.F;.E...h+....;44...6l..d..L.U...m.`..5...6...tq\......\......R>{~....W)..m,"...[..........&.~....w...M...fU...#....Z.7.......P.sc..
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PNG image data, 317 x 255, 8-bit/color RGBA, non-interlaced
    Category:dropped
    Size (bytes):27387
    Entropy (8bit):7.966308521454677
    Encrypted:false
    SSDEEP:768:iJTzW9uou8S07K8v0Jv1HWJ5d0JFRynJRHPbY:WTzGuouU7K8vGv1HWJ5dSkRHjY
    MD5:35902A9077FEE99253CE3EEEA226B509
    SHA1:F7EFC0D36C2CF1A9C721B770DEAC9CE3DC5B8A2D
    SHA-256:D54E743D485B3F9989CE8C9DCD5E8A8244A795D2C1469C027E0A4AAB2D832D46
    SHA-512:81D2746202E138FD7C24BBFF36701BF15B803AF599C974500168F63D8017F7F2E7C7E2C18868799ED88F0A69752B60E3FAD2A393067ABE0DAD756C3E8E9FAB88
    Malicious:false
    Reputation:low
    Preview:.PNG........IHDR...=.................sRGB.........gAMA......a.....pHYs..........o.d..j.IDATx^..|.......^}.[..[..^..X....A.Cp.@p.^...$!.....]...$..=.{.....L.. ..f_...3;;;.;.>3+.z.........?.].....c.}.s'.o..[.b.-022........C."o..LLL`ii.'''.sz.........1e....;V..............077...j.......r..9.g7v.m...]....%,.5S..k.b.a.5k.N.<.+W.@/$$.fff.2d...;...J$%%!&&.....'.<..q...DGG.7QQQ.DFF6#""B....&...$BCC...!'88.... ...@....&.............i...[...K....xxxH...7......k.........?..GG.&._..A=.9W.^./....--...e...#.|;.w.V9|...}C....G.....~.c....':nt..x..cM.....*3...r%/sje.-..r.....S.Q.v.eNv..l.rF..-j.......mgkh..p......{[./..o`.;Y......5.*F..-..e.RG[._.Ea.?.l...4..[TT..+V@___r...l. ui)....I\\\........m..../rar.R$Z+P-I.."T.QM.J..K.m..R....J+. .....A..F....8r..w.o...yj(.%...>9.m..S.P.?....#.\|r....!.......G(._K....r...k..a".A...J.e..(w..*..+.P.c.3.......D.J...g.1n1j.7....Q.(c....Q.......A.X._...N.=.s...3g0}.t..s.p1$$$H$&&J..GA[.8.....-.nI.-IR^..{.-RT.Q.F....N.H.F...
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PNG image data, 165 x 238, 8-bit/color RGB, non-interlaced
    Category:dropped
    Size (bytes):5168
    Entropy (8bit):7.848937146702235
    Encrypted:false
    SSDEEP:96:fj/6E/sJQY8aaoel9IoQcgC+d+s+QDtN1Wx:fpHaaoFHdl+QDtmx
    MD5:E973C5E4E111168A951110910C5ED610
    SHA1:882E95398235A96B00C8543EB813506B49F8348C
    SHA-256:C5BA531CEBB1C4CDA0809E74B91E57B45ED8DA7AB5B288BF984DEAB22A8506AF
    SHA-512:321250175EC632606A19DD344CA785251DF83D8FB859AEACB18B073EAFFC364E995F696894AD7153C7FAC027710F165FBA520D6C1DC495FDDB21CC38366FAF66
    Malicious:false
    Reputation:low
    Preview:.PNG........IHDR...............P"....pHYs..\F..\F...CA....tIME.........S`....tEXtAuthor....H....tEXtDescription...!#....tEXtCopyright....:....tEXtCreation time.5.......tEXtSoftware.]p.:....tEXtDisclaimer.........tEXtWarning........tEXtSource.........tEXtComment........tEXtTitle....'....IDATx......u.......$./(.....1-xU....v....9..?.Z..J..Q..E...Y....X.q-KV.lD~....u.N...MA.d6...]/....{O...x...y..{.|.Z..9..;.;..yg...[....<.z...CO...z;.$.%..4.V.m.......0wV...I.....&...%Q.......V.6vh.<Q...w...gT....X.=..6..o..(.\.n.%\.h.8f&(.........IDATJ..(.T........~..P.`O..m..,O..7.v...Q?."6..D.....QWHo. ...6...,Ho.Hx.F..D....R..X............../.9S#.g...)G8...h...b..K.....Az71......w.@M...G'.......x.7.r...x......8...()..*]8~z...G0.../....?[.u9...../..PRB..kz../!.Q.lG"k..3.....'..._..~.e8.|....IDAT.O_..{...B...f;R..Z......g..w..k%.O...........O>.d.-.D)t..X<v......=.....w.}..fq..HfV.#.R...<......?...]].I.....?.p.-.D)..[....|...O.<.v..3g.B...x.....B).5....|.*
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PNG image data, 874 x 148, 8-bit/color RGB, non-interlaced
    Category:dropped
    Size (bytes):9486
    Entropy (8bit):7.825576528008506
    Encrypted:false
    SSDEEP:192:LepEQC5CO9fED6eF5FmEQHSnLOkBDXC5T4V6fKXmByizAA5oS1od:LepEQC5C6ohQKh47KraAu1od
    MD5:6239AA96DADFE8529BC987F2E7F51EDF
    SHA1:F07C0234CC32ECCF308FBB32317574175ED69C5C
    SHA-256:A895EB413D5B2B24D863C8E4152CA091AD955921B76DE37FC0DAB6793EEDF572
    SHA-512:50CBC634F36A621AC97A0D82C926CAFE393FF37B266B41337EC7CD905F121308FCB2DD3C4134333217861FA45B915CAA4029C2B118C49154234F2A856C4D0EB2
    Malicious:false
    Reputation:low
    Preview:.PNG........IHDR...j.........m9M.....gAMA......a...$.IDATx^.[l..y.....)...S^..%@...Q.m..4.."yp..@....R u..h...."..+.4Q.$.+'.`.%..-K.D."E..L..x3)Q.E.-/.K...<...........rx......?gvv...@...... ...."0;3D... ...@....@$.{"3... ...@...... .X.c..K*C...... ........]..}...@...... ....RD>..O.@...... .._..G_R.|....... ...@ .|D>B...... .... .|......@...... ...#....... ...@ ...c.X\m@...... ... ....... ...@..1. .c..j...... ...@...|... ...@....A.....W..... ...@...GU>.ol,|d4..d.';..G*{.... E..d...K..i...he...G.....\me;....G...gw...?..f$h.....a ...G.Y3]3.m....#+...Ru....OS.:M..>6..hb.. ...).G}y...s..+.H.J_..N|b...*4......_...+*|*G....KK..|l.v...n.....@...4P>.."(..}.:..P3.S.nw5]....mS.s..p'...~}..N..u.`..[w....N0.y$o..p........q....\y.qV..l.>...K$4.....9..A...sq0.e.....z ..."9...3..B..-N..F.l...F?...'...r.g5..3.g>%...RN.9KQZF....Q..t..c..S...'6w..FVz.m).JHQ.q}.1tD.1Tlv.0=gV,..I.....P(....U.ma...5(...R.%..[..x6.<.@ G.R.....dJ...i.......q....J...bI..P....P7.-..2.G..4.
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PNG image data, 613 x 86, 8-bit/color RGBA, non-interlaced
    Category:dropped
    Size (bytes):2611
    Entropy (8bit):7.666961473647625
    Encrypted:false
    SSDEEP:48:3DpxcJxnzlmRjZTjF9ckCO1LFma+DBcix2Y4Dk08HgAOIXHYNamKiG4:zq9w5JjJZ+V+YcoPH8amC4
    MD5:9A4EFC60F1A7AC72E79BBC858587D238
    SHA1:D8FD6061E7D2A4F35C03B18B11C830B86B55F38D
    SHA-256:83FE78E81C7E0081A8A886B12548EB852C868869CCC50C9CFDEDC8C57FCA6DBA
    SHA-512:565C9EFC726B63C8B94AD1E6BB18E64F494F69C712EE7F36A7338FB0B4648865540F326DF19B8C10E96C98DD4BF54D3DB1E922B98F73E9E9D0B56140E38190AB
    Malicious:false
    Reputation:low
    Preview:.PNG........IHDR...e...V.............pHYs..........+......tIME......9".n&....tEXtAuthor....H....tEXtDescription...!#....tEXtCopyright....:....tEXtCreation time.5.......tEXtSoftware.]p.:....tEXtDisclaimer.........tEXtWarning........tEXtSource.........tEXtComment........tEXtTitle....'....IDATx...1.......=....$$. 0..,....7.,l......e>............p..16.a..O......./...........~p.y..3{.....*.....,.Z.!...e..K9=.B.t'...B..@..2....e........ ....@(..(.P..P.kK..........'[.......e!....]...:....j..u..x..:\..hg.:=...tpzR.....B...@..CYc(..u|...Im........0&...1E.)..d..../.[%.?;__zlb.....0..g..Y..b.l......:.......v;...6...;......CY...~.N...o....NU]].l.BM,h._O.@C.-..:....."B.j.ri..../n=...~..S...w.lj...G..m.g.p<..e..X#..j..o...9.R....o.o......Ry7..-_.j....<..L...u.~..Cx..k.@...,.......t.L.'ko..9..8|.....!....@..1...}..eC..Su.|X g...a+`.......en ..8.......JU.......szR-.|..@.{........ ....@(..(.P..P......B..@..2....e........ ....@(..(.P..P.kKw..|....].....w....=..+......<x..cP....
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PNG image data, 367 x 152, 8-bit/color RGB, non-interlaced
    Category:dropped
    Size (bytes):16511
    Entropy (8bit):7.930529414839677
    Encrypted:false
    SSDEEP:384:DWoQd7vR78BXa+hc/1sD3RI/Vxs9Efof5hY5bomp4EOesUyWw:DhGvR7yX7cshungE5meFc
    MD5:487FBA2DDD5D344D8A5AC92171979440
    SHA1:D30C331C69C38DAF65C39E0DEF5F806046AF77F5
    SHA-256:AFE8DA255EB4C1813CBBD1C9BBF6A58477DC6E17237FC91A7427E62F094845DF
    SHA-512:CFDC2029EDA8447B0BD6D7C3231FE1BCFFF83F151AAA90C13F04755B871BA2AFF2BAC1DADA11821BABB6165CD6D1AE8E59C9B4F152E2C72736CE0B0A38316820
    Malicious:false
    Reputation:low
    Preview:.PNG........IHDR...o............V....pHYs..........+......tIME.....$%..A....tEXtAuthor....H....tEXtDescription...!#....tEXtCopyright....:....tEXtCreation time.5.......tEXtSoftware.]p.:....tEXtDisclaimer.........tEXtWarning........tEXtSource.........tEXtComment........tEXtTitle....'....IDATx..y\S...'..... ..$.,.....**. V@*.....U......u..}....(^El+RA..V.#.5."F... ...........|?..d.sf.I..93...$.....@...@;.@ >.P4A .}.{.&...O.>moo....Bv...._...%..{.*.....q....o.d2...lmm..5,....V..,.iSRR....r....^^^...f.w........L..........{..Y/+.....l6....i....IDAT...+133.s.y......'N.........srr. ....{.[[[..FhJ....%.N...Ah.dYaa.C....sss...\]]../==}................J.qww.q..<.u.............>...x@.C ...I...GCCC.PCC......>..V......dqGGGcc#........#F..JKK'O....1...7o.@KOO.s..M.6./.......sG.qZZ.......%K`..+..;.#.=....IDAT.`.===.....\.`0...`."^.x<...--....y..%''....:t..755...........<<<Z[[.......UVVfoo.....HOO.....---R."....hb``......200 .#>.............~...Llmm.....z..A.......))...))
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PNG image data, 875 x 235, 8-bit/color RGB, non-interlaced
    Category:dropped
    Size (bytes):27111
    Entropy (8bit):7.952021015019732
    Encrypted:false
    SSDEEP:768:IPNGtqCA/Q0CxO2eXjHC+40pmA9J9KrDzrCtKZ:I3C6Q6ziW99J9KrDiKZ
    MD5:D725CCC167AFD5AB4CAFB10B524D6559
    SHA1:B4F231299F290102A2D3A801D46CB288BA2333BC
    SHA-256:AB2B27FE1244C528564C834DBFC215FA75BCCCCE83B1528DF0AE8A280913BCC2
    SHA-512:CD2FC9A068DC164221FA6B7B06ABD3ED9B177AB974D0E73FD5EA21972AC266A7723128479166E3B67AE583FCD555F91D01F0F93397290DFA42927B78F5542344
    Malicious:false
    Reputation:low
    Preview:.PNG........IHDR...k.........x.......sRGB.........gAMA......a.....pHYs...t...t..f.x..i|IDATx^...U..}...._...._c$u.(6...).....5}c.&.R**..[.4FiD.^z...i..TPc.....D.W#.....&c..k..{...........c3.\s...5......O..O....x.!.|...>....<....8.C.....~B.!...}.'.....:.o}.[......._D.y.b..J..w.....B.!....W.......I..........W~..D..}.k........^-y.-a.T..DI..$......,.J.f..g.#.7r.b[..-.l..M...!...%.~....T... *..+V.Km.}9,Nda....E.X.*.b.."..o[\.....;.Yc,.....1..|...}.._....g.}...3.................!..B}....;.s...&L..o.{.-....[Kb..A#.nN1....sS1.J..0.[...i..;....\.:.....]..q.....qm.5.\.O...W]u.1W\q.e.K/.....%.\.;../......_..W...W.......t.w.y.{./~.;.9..={.<..t..8........'.....?r..........}.{.u..8..S{8N>..N:...O<...;.;.c.=....w....k.#.G.qD...;wrt.....;1QW....a....M......?9*..E.</...|..U.........s....`.._..r..KW..0qy...J.....F......93.#<.h..)... ..F....H..2.;.c...@.A.a.a$bTBx..S.V.[.^.b...A..%....B.@.C.D@D|............ .2.".".3.[l......X w...W.....L...~....8~.%..
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PNG image data, 781 x 350, 8-bit/color RGBA, non-interlaced
    Category:dropped
    Size (bytes):35671
    Entropy (8bit):7.9098048989524115
    Encrypted:false
    SSDEEP:768:BXnQWDf9EU9mOBkF+qxIFb4fNzCESvrLfc4xg6KL:BXFDlnmOeFN44NW/vc0KL
    MD5:30ED165235283284D73C10F49452B66C
    SHA1:8B56F889A9337C375FB20D70ECEC9C7573A0EF93
    SHA-256:8AB767A2ED0D95954FEF648CCA3F6308D8777CD372740787DE877F85E2A62C81
    SHA-512:F4B5A5437C9AC8618338D5D2EECB23BD5A64E317DCB177E67274734FF9729B83683E1C11F32F080AC092589B2EB1D4F5AA34B5E28BE1E655A32CA787F7C3695B
    Malicious:false
    Reputation:low
    Preview:.PNG........IHDR.......^......d.....sRGB.........gAMA......a.....pHYs...t...t..f.x....IDATx^.y.].u.[.._.z.[+.V..=..t^:.V^..6V^.NO..v.....d...!..$^.6nb.8..d..d....h....TX..%4P.Jc..T.J.*M%...Hx.....{...}.;..~.Z.Uu.........snU.s.hff...?N...4<<L....;v.;.C.7o...~.6n.Xd............c...}}}.w.^.........G..C.>.'?..]{...........?..m...l...C..?u...V......3.....:z....w..8fggM........9..hC....k...r....5?.p...T..j..zq.."i.q.....Z.W.....XuV...,....|]......V. .....q.........G?.....Y...`M.b....a.....$.8p...+..........bzz.).8q...*..c.~*s......crr.....>|.a.!+...U..+.+.O....]..:7+....c.5...-...i..qF.=#k.........3........F.9A...5g.y...Q....#...E.;>::....H"...OR.Nct].F...F.~Y..._.....3...F.=.4.X....2.|....i.q..t.R..}<.]../...a.O.C.I.x..(bq...?..`-..........o...S...*./,.h.6..r....l=x.k...=.....z...H...X...................qX....=.....G6..)....na..F.%..o....=g.9.X....K.$..w......@c.........^.._.G.1._.I.Z..#F...?..i..........1...E..W..JE.#e._..&.S|.~.}..Q+..'.h.
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PNG image data, 456 x 406, 8-bit/color RGB, non-interlaced
    Category:dropped
    Size (bytes):23567
    Entropy (8bit):7.927363032931655
    Encrypted:false
    SSDEEP:384:asjSV2oakH7mjHsCQ8fOGqO5m9q/wVQSGv5d3YHy7gM5haDtYa7ZCn/bsRN7Qi+D:9M7mj3F6bC5xI8gqaxNNiD5i+S/bCt
    MD5:FE64653A46F483A6A5B5F25C72F9ADAD
    SHA1:5E03354988448628B4492735E82715FFF291D7AF
    SHA-256:A7AD358D35A894F7C701BF0C8884A18C7B1AB870592C881D89CC36E9452942E3
    SHA-512:FA93B2B7B9A0ADF6A8C44B720B04F0B1CA88F37D9579453B26BDDF6C829F895BC8619E1BFEDF9385DE7F50F650A0637D509DA2DEA4D483AEDE021C717EA7DF69
    Malicious:false
    Reputation:low
    Preview:.PNG........IHDR.............sG.:....sRGB.........gAMA......a.... cHRM..z&..............u0...`..:....p..Q<..[.IDATx^...]E..o..8>3.hf...P.Qq..n.....D6.2(.#.QA.uF....C..P.YdH..%+.W.....!Kw.....;.....j;u.=..so...'9......._....L8v.XB..pe...i..$o...._.<..41q....0.;a..c...CG.'..8!.8z...}._L...%..........<..#.......D.....P.......8.Do_b.K..$.D.<q$...@....|.).+..pe.....=..S~v...3.;.........;.1/]../}....2 .A..a.W.T ...>h.E;.....tj.0..Dx.D.<..C.O.IL..q..T=.k.D....1.GG)+g.....Dx}..c.8....P..@.8+@.c.9...Y..p....?.p.'.IJ......JW.=...X.....2q....5QJ|..%...;{&.5H.M........._..m..'..(..,'....L...=.....`4c.bi...n..xG...:&...zg._F....>..5..W.......4y..P.rU......X.(H...ts]......W.<....-...m.......P ...k.DJ.6M.....)%....Z/M..MDL.......&L+M\Ni....D.D.O.H...W..&.^wp41....u4..vg...-}.!X.9.7R..hH|...@.A..F.z..U.....9..I.7n......$...Q.pJ..g....g..+.X....J.`.........^.1.<f.G..P...J..{.h.}....o..n.....k..-u?.^;cZ..U......|../.T...(U^../]...i.-..;...h..=.....\y =gi..
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PNG image data, 469 x 202, 8-bit/color RGBA, non-interlaced
    Category:dropped
    Size (bytes):12008
    Entropy (8bit):7.883283719018848
    Encrypted:false
    SSDEEP:192:02dPR7agEfc2LqItomAZjqsqF11MeNCxfX1mnPZfCHfCUdOAHgLuHbIYjdeut+P8:0IR7agEf5LjopusAIxfXaP46Udd8uHbj
    MD5:16C25E01F72FA812C2317C5C81A669B1
    SHA1:54ACAF291F76DC5539AAD5F1A686E49E57DAA035
    SHA-256:1F3BAD7FD211F1D929D4A4FB62E498277BBAE6355F354363EF78ABC04DEAB073
    SHA-512:3E40F135746449B7C97868F5F7681DD181CB1E13CB6D2CE92F70E7C46EF411F0BC5701531B5114D551293D951A45C6A21EA4434FF0E0AF5EA03A218DA404E144
    Malicious:false
    Reputation:low
    Preview:.PNG........IHDR..............N......sRGB.........gAMA......a.....pHYs...t...t..f.x...}IDATx^.{l.W~..O...E.hQ.(. AR.Xt..a.n..4.......$..,*..B..d....-.....+.........E.%Q2-K.W.$.z....(>..DJ.".D.._.w.33g...{.._....9.=.9....3.6.?(.......P ...29.........P......@.(......H.@5#!q.(........*<.......P #.....a.....P.........P..@....T3.....P..@.(....P..@.(..2R .T._O..2.+........P ..$...w...a..P..@.(..ZA.TP}g.........8u..^.H..........V.....@.(..X..P=~......y.:=".+Wo..?..o.G...hph(.P..B+W...+...i.CkW..?.yZ..U.8..=...m.J.2-.y..:.....I3.:......*...zU+P5T.N_...G.....M\...s......w_.!....4=}9...[V....-..].e..q..{../*.cS@5.>.v..B........;`Z...sH:./.X..e~.y`m......G.....3./..I....[....>....fZX.K......y...Mf./...^...h..ka........q.U...O.:....-.CV.@j.r....8MN_...W...4tf.....!}..}./.{.hl|byP...d.-...Sr.......E...........+.u..'G.+...J..~.....Iv...\...>j..FF.k....yRh...P.q.S{.}g...}..2.6....."S.lw.....e...X.4Z.=...}........v.!....[...z......3..E7..>Af..g~.H...34
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:GIF image data, version 87a, 24 x 24
    Category:dropped
    Size (bytes):1193
    Entropy (8bit):5.107627428609815
    Encrypted:false
    SSDEEP:24:Sycf9PgDefYOOuxltV3QfJVWXFs87S/1ofuEa3:Sy45gDuxlEOV7SNo43
    MD5:8F0CA61EB113FBBBE1FE4D5E28858FA5
    SHA1:D917CBA5B5140A34ABF03A8DCCF1C5199B0F1F8C
    SHA-256:58F24169FC0633FBDA7E5F18949B912947F013854EDB6769B752B264ADCC51AD
    SHA-512:A4A11DB44E8B634D315C9778B19B222FD4025DC0BB91BBF070B0B4FA4EB4EE33579943E1364540FF98B026AB155B663ECC3EC043FE55096718C348742D1B2C43
    Malicious:false
    Reputation:low
    Preview:GIF87a...................!!!))!)))11)111999BBBJJJRRRZZZccckkksss{{{....{J.......sJ.{J.{R.{c..Z..c..s..{.......kR.sR.{Z..k.......cZ.J9....!..!..1!.........................!..)!.1!.91.B).B1.J9.cB....cJ.kR.sR.{Z.R.c.R.k.c.{.{.....s....{..........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................,..............,A......*.@....#. .a..(X2j........T..e..(S...@...4.I.fM.C.P. 0..,....*....X$D..!..'P.J.....-. .|.a.._.0...F.'[ <...A..p.h.!...-.fy.@`..`...rD......!......4.S.r..?...b....b.0.......E..!D...@.@.....
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:JPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, baseline, precision 8, 343x343, components 3
    Category:dropped
    Size (bytes):12485
    Entropy (8bit):7.8277799177202025
    Encrypted:false
    SSDEEP:384:di3X0Jn9Gza86KC1nPOnNV5As5Yf7dvBkTPODju:di3Xm9UHLV5jYDdBkTPOu
    MD5:08A2BD4BA485F3FB3DBA494B657ACA50
    SHA1:80BA24DF28F1A659A3247A96996C745AB1699CFF
    SHA-256:37DB7A752A2D532A268BD2D5FEAFE262D0493D7872D1EB214B2B48A0B649057F
    SHA-512:8BD6F20EBFA8DC9840E537EF5A1EFB4A239CE84D5CDD8E558CDDC247ED2691509AC6BC293C11BD07A43906D26DAFF5B14944DC18338F323848B9AD9EF035067C
    Malicious:false
    Reputation:low
    Preview:......JFIF.....`.`.....C................................... $.' ",#..(7),01444.'9=82<.342...C...........2!.!22222222222222222222222222222222222222222222222222......W.W.."............................................................}........!1A..Qa."q.2....#B...R..$3br........%&'()*456789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz..............................................................................................................................w.......!1..AQ.aq."2...B.....#3R..br...$4.%.....&'()*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz....................................................................................?...(...(...(...(...(...+.-.1........wP...F....<....?..}........+..c....O5.....4..']Q..{...?.M.z5../._S....W_....k..O.b.sw...omp`.)X.....Z....(...(...(...(...(...(...(...(...(...(...(...(...(...(...(...(...(...(........xcO...F..ap.|.BG8.#..?..u.7.>!?K!...W..@.w....J..........U...2h.... }....^.E.x.....s.C..}l......^...5.....n5'.14e..W.2..(...(...(...(..(|v..m{....l..
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
    Category:dropped
    Size (bytes):1068
    Entropy (8bit):6.239604882999454
    Encrypted:false
    SSDEEP:24:N1h4SHWwjx82lY2T3UVq90Hy0XyJ3Vw0+U0wGBx36:zKS2Nn2wkhdJ3Oez88
    MD5:40EF77F5D40FA1231141853DCF5986BE
    SHA1:E042C8B3A9C15D11B6B0F28C98C3441AE4A83E60
    SHA-256:4A5B4BAC4CAC02D34B670030743335E5AF523D66BF4DE790F5ED47520A6877E7
    SHA-512:19469C2745913F506A41CE8858D951DCFCB5E6E0D2E26988AAF110651172FBF7D4D6249892C691BE1D5E7B472ADD7FEFD6F3F8F554AC5EF6DD4DBC00A886223C
    Malicious:false
    Reputation:low
    Preview:.PNG........IHDR................a....tEXtSoftware.Adobe ImageReadyq.e<...#iTXtXML:com.adobe.xmp.....<?xpacket begin="." id="W5M0MpCehiHzreSzNTczkc9d"?> <x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="Adobe XMP Core 5.5-c014 79.151481, 2013/03/13-12:09:15 "> <rdf:RDF xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"> <rdf:Description rdf:about="" xmlns:xmp="http://ns.adobe.com/xap/1.0/" xmlns:xmpMM="http://ns.adobe.com/xap/1.0/mm/" xmlns:stRef="http://ns.adobe.com/xap/1.0/sType/ResourceRef#" xmp:CreatorTool="Adobe Photoshop CC (Macintosh)" xmpMM:InstanceID="xmp.iid:EB82AA75ED8911E2930D892F06BCB8C6" xmpMM:DocumentID="xmp.did:EB82AA76ED8911E2930D892F06BCB8C6"> <xmpMM:DerivedFrom stRef:instanceID="xmp.iid:EB82AA73ED8911E2930D892F06BCB8C6" stRef:documentID="xmp.did:EB82AA74ED8911E2930D892F06BCB8C6"/> </rdf:Description> </rdf:RDF> </x:xmpmeta> <?xpacket end="r"?>/.......IDATx.b...?.%..p[..>...E.....$.]....d..8P..$.`..t.....@..0b....>0..u..$......j.0....."m.@.@...W@i N@.D...x.t
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PNG image data, 736 x 445, 8-bit/color RGBA, non-interlaced
    Category:dropped
    Size (bytes):58633
    Entropy (8bit):7.917206927252893
    Encrypted:false
    SSDEEP:1536:SvUKvdo42+K8vwbetxhxT8TWoZ54/OYmCq:CUudo425mcejT8ix/NmCq
    MD5:30E5FE65325AD6DF9CFFF9900DD2847D
    SHA1:BF12E402A57B6FE211588611A82B0361820291BE
    SHA-256:4062EE93DF3184634C58A0252FBC071F0E3C12BDABE837306C941D4CC97E6AA0
    SHA-512:D46C2AFEAD3FA16B7970CC67957CDAF4186F032B4236143286530872B73295A14B86D7DE806F903B0E854904B9DFDF8DE6DC28283AC1A8D5E35DBA70B7BF37E8
    Malicious:false
    Reputation:low
    Preview:.PNG........IHDR.............T&.....sRGB.........gAMA......a.....pHYs...t...t..f.x...IDATx^..|.G..............z.k....`...X'...lc@k........E..........(..s@9.. 2.._.3-..tOwO.F.+>.A..~.....<..GZZ....PRR....TVV...~..........EEETH...4.h....1@c.......:..g.2..kjjP__...f....#%%.YYY...GAA...NN.222......d$$$.%>>..i@c.......4.h....1@c.......$.tff..............D.M.....8.:t.C...G.}.O>....6.TH...4.h....1@c............;.....<.][[....X......m.0x.`|.......K.p..e.r...8.\.z...k..7.{..}..S.....Z}.k.......{.=....[.\..g...V.^i;..*.#...}lO..}\..z.L....Fl.|<*.....}Eu...W.g..S.....\..m.9.=.t.8U..7n`......dn...../.=**......[.n..$<..#....GLL.6n....",,.MMM...k...P.X............g.T.;...?..=.H.+~W....s.k.8w..j..Z...3..q.....=k.Juu5..V..q>.......r(.>..V.70....*.'..v....v.sc.....5..q...J.G..m./.q.......R.wJ}(.?..sE..~R.#._..I....'..I.>...g.k..O.^.5.t..^.Z.P..U.6...^W..+}..e8=}.w.y_....7...#..,...~.m.A.-[...*.7.z..9k...;....^z.;v.{...{...;.p...o..a\o...siG*..-....O.
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PNG image data, 406 x 493, 8-bit/color RGBA, non-interlaced
    Category:dropped
    Size (bytes):35278
    Entropy (8bit):7.945447594401715
    Encrypted:false
    SSDEEP:768:r3QgsMdV6glAQo17Wk4VgHfLe0YRAXre2GwgdZzsi45xH+U+:rAgTVRmQuQVgHfTYg+ZIiuwU+
    MD5:A11DAB4751C760978F51CF361293F1F5
    SHA1:72B052DE6D1DCE2F8FF939CC825DE78A0228D355
    SHA-256:93B729B6210383E5391D516777592767DE32636BFDCD3D2DC86A475167E38C0C
    SHA-512:73B27C75615DEA56168A468BB98432456C84E42A451E2CB6E9EAC8FB6B10AE8CE0AB130BD216D38FDB1FEC8C3CD3CCFD0074E8A37C2CA2E70D8A5228BE299807
    Malicious:false
    Reputation:low
    Preview:.PNG........IHDR.............:.X.....sRGB.........gAMA......a.....pHYs...t...t..f.x...cIDATx^.i..G..[|z..X....{..zW...^....{....=...AF.=\...tCO4..,. .T.Cc.X..I..*.x.eI.mY%.,k,.$.,.TRY.Mc...bG..3N.tN......9....sg.r....o.>.........[G...t...K...o......7.@?...G?.....?.@.....l..m.Y.L..O.J..-..+W./..K..{h....`y...{.n...c..4a...t......`..6.w..w..o..:".V..p..m......~..[....~Z.p!.={..?..r..9j....3g.P^y...)....Q..>}....S.%....GN.<Iy$....t.v..\..kR..,.H..$.M.'Zy...~../>....;.{.vr{..1'...o|.......t..7S.c.=f.......>Z.x1...k...e.=..3^.m........).<...%.....'.$W.x....H...<...G.!...~8&.6m...7.]..z.._O.>.`$..dy........t.}...6D..nb.."...;m.e..t..wXY.f...W[.X......~..V.....n...[n......{."+V. ...........m[..r..|>......]ww.n....n>...e......X.l.1z...>.k$.....k.......?........~e..I.s......m.....m.m..]l...}....{O.w....[.=.....'....Bzu.):.v..8......KF^.r..7..FF...r...y..P..u+..3..W|e.>..9me..22j...b.v:f.h(G......o}......s...s..!p...
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PNG image data, 571 x 684, 8-bit/color RGBA, non-interlaced
    Category:dropped
    Size (bytes):43823
    Entropy (8bit):7.872920312999266
    Encrypted:false
    SSDEEP:768:gPzh8DenKNx3a/0Wnxm638HSZ3qRoLkHjKQe+JNN4H47ojjaz/Ap70:gPznnKb3o863iSZ6RoLkHjKQeoNNe0u6
    MD5:C6855C59FCA77F88CEB497B299CD00FD
    SHA1:367011139608FC4E44D725EB62E549CE4CCD925E
    SHA-256:1FB0BD90AA0391F4115B1449BA34FEF9D5CCD7EFE80A1406EB976B958AA1B5CE
    SHA-512:65317B8BE029DAF5017E2C558BB8E5C5212AF82D26D711CE73D8833AAEB335F780494C9D3E005DC22BF50ED98CEBEA7B7ED16C069B40051192F50D2A2F713386
    Malicious:false
    Reputation:low
    Preview:.PNG........IHDR...;...........|.....sRGB.........gAMA......a.....pHYs...t...t..f.x....IDATx^..........|.......6..8..0...........d.... $..!. $..r. !...s.*k..VZi.rz.~j.f.k:MO.LO.o>..hg.....t.w.z..d...b...3g.M.4.>..S.2d.....w.N].t.......u..>...$h......`....@..@......i.q4p.@.4.7.K.......`.....l.6P.6P.l.2.;v..........R...544....#....).......).TWWG^.c..).=z.....Z..9B~.[.^.........s....>.+...P..C.H&....d..W}...uU.:.{...^..m.......I..3._2{.l.0`...o|...W/:p..UUU...i.EyK\...n....*-X....{..y.HOs..%.x.P&..N.f.JI3g..3f.....I.i..LS.N%NS.L.i...TYY)..Q....'....O........H.}...4z.h1..i.Q"}..'4r.H.F..!....L.}..H...i.a.4t.P.......i.A..F.o.....p.e.;./..e;.]o...l+.c.d..w.<....#.kun|~j..?q.._"...d..$j..7...L={.$..?bd.aj=u...R.]I&.|.<... ......s.s.{.<w.F.OU_+..Y.z..7......i..].....q.r..]+.u....:..._.n...~:.W...._j..w..~/.0aB...m....4..%K.....e..Ov......YA..>v...~....|.~db......@&.=.|..C.$.0.0..A..>. t...A....'AB}.7g.....t$.I...A.[{U.QAGm...0..M[..
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PNG image data, 624 x 167, 8-bit/color RGB, non-interlaced
    Category:dropped
    Size (bytes):10690
    Entropy (8bit):7.889446449308767
    Encrypted:false
    SSDEEP:192:wlb1X2ZFsuXsV6OgCQsw065pLXR1XK/bAPccdWvy4F8NLueYuJ:wlkZFVX2TQD5prK/w2vy4OLGq
    MD5:CB31C4CC7F7E930C6FF0F6340C3DDD20
    SHA1:1D5E504E7951EB5C7DB488C733D2A01D101D0AE0
    SHA-256:90784ABE865BB8240C0A3A22AD9754C573117710D2040541726A47031F66F2C5
    SHA-512:E731C1F00A100D0E90BFA970738C436C90D523A1637C1B79FDD7412E36A82A9B436A35494A1F93EBC8AAD95EF3BD535D3A4A5F976C966659BC6C4305D31C29E8
    Malicious:false
    Reputation:low
    Preview:.PNG........IHDR...p............J....gAMA......a.....tIME.....!.MY....)fIDATx^.ko\...).j...`..~......3.03..o2..`..l..X..#{7F.8....$..I.$.E.E..H..(.M..&.7......U.I.n...9}.O.....=O...M...~@..@..@..B!P.A..........M....n.. .. .. ..D....9........@....D..@..@..@...A..........@PC..s........@P!. .. .. ....j..q..........*...@..@..B ...@' .. .. ....... .. .. ........$.h.. .. ....T.*........@.....t..0....... . ..T...........5..AN4h.. .. ....T.*........@.#..M2.' .,l.hc.2J.).....W@.R."b....X.jA........y.!.......xr.c...g...z....Z.[K...>.....i....!N?,..........R.....(.{.8!..,/.Qh(@.U.{.7.z.......#r.......'.X....y:..s..@.&-....L..EQ..{IkN[vvi.._....|...JB.|..c......*!.....W.1......r...Uw....7d..{.P..K..=a".z..0..".&"`W...Y...._y.a"BJ..e..F]d.2....uJ.Q.Y;.....|TRN.5.2.>.\s[^..9..e@]3?..t."5..W......(....~.l........a.U]..W....-.z.r.~..N.\.14.!&pS...Q.Ti,t.........2O..OY...zPp.pu..Z]..^...LM...r[....+.O.(.. .*.MoN5....C...BS..wf..;.C.n.1..N.tk^.S.5.*T..6k.|
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
    Category:dropped
    Size (bytes):1066
    Entropy (8bit):6.215222583179275
    Encrypted:false
    SSDEEP:24:N1h4SHWwjx82lY2T3UV20HN90XyJ3Vph80+I0wGhTF99:zKS2Nn2wYE9dJ3x8azMFT
    MD5:64B794E4E3CFF519503A136128C94A87
    SHA1:8C3029B9CA6916565CC38F9E569A1B5AAA0C46ED
    SHA-256:0234FF80D2DD2DF9733B32823C8E0B9571DC638CDE5DD2819E30624B4062B377
    SHA-512:5FB249D1A58307337770C60FFCF5AA37F516FF43F06D647EEE9685707CFFAD5CF1C0B830E4A35BB7F22FBAE1DCB77E97A743F7A3E79DCA23DCC43762F53E23FF
    Malicious:false
    Reputation:low
    Preview:.PNG........IHDR................a....tEXtSoftware.Adobe ImageReadyq.e<...#iTXtXML:com.adobe.xmp.....<?xpacket begin="." id="W5M0MpCehiHzreSzNTczkc9d"?> <x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="Adobe XMP Core 5.5-c014 79.151481, 2013/03/13-12:09:15 "> <rdf:RDF xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"> <rdf:Description rdf:about="" xmlns:xmp="http://ns.adobe.com/xap/1.0/" xmlns:xmpMM="http://ns.adobe.com/xap/1.0/mm/" xmlns:stRef="http://ns.adobe.com/xap/1.0/sType/ResourceRef#" xmp:CreatorTool="Adobe Photoshop CC (Macintosh)" xmpMM:InstanceID="xmp.iid:EB82AA79ED8911E2930D892F06BCB8C6" xmpMM:DocumentID="xmp.did:EB82AA7AED8911E2930D892F06BCB8C6"> <xmpMM:DerivedFrom stRef:instanceID="xmp.iid:EB82AA77ED8911E2930D892F06BCB8C6" stRef:documentID="xmp.did:EB82AA78ED8911E2930D892F06BCB8C6"/> </rdf:Description> </rdf:RDF> </x:xmpmeta> <?xpacket end="r"?>a.7.....IDATx.b...?.%...B@...F.....}.........$....$...B N....<..$......*.@...)..P.L....a.... ......@...*....$. .2..h.
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PNG image data, 22 x 24, 8-bit/color RGB, non-interlaced
    Category:dropped
    Size (bytes):544
    Entropy (8bit):7.199069019405828
    Encrypted:false
    SSDEEP:12:6v/7pb/U4K5QYuDt4zvSRmzXGWVBTl+1SSJ1G05T7Ya1tz:84X5QbWz6RsGWVBTYoE19T7v1tz
    MD5:236B7F2F8A95A455603A0DA19E879349
    SHA1:D2C7AAD6E5710C990F009C08C0D59B033B8358F5
    SHA-256:E259D919D024DF24EFD8EF451D03925B198877D024CD78C75A36EA29395CD55D
    SHA-512:D97B47B1D15C36FA89300525D6F7829D11C9E529006E2947FA6C32E95FE4993342449C4612157AECE82CBC3869DEDAB4D30003DD347AACB58D61853E52C1B021
    Malicious:false
    Reputation:low
    Preview:.PNG........IHDR.............q......sRGB.........gAMA......a.... cHRM..z&..............u0...`..:....p..Q<....IDAT8Oc...?...h..%.&N.@..3g&..@...p...{.n......F.....wo.~........<......0..ruq...g.V.h...FF...(F.9.>......vn.....3\?..@..I..\j.p..+.J.. ..b.P......[.nl...[[...@)4......4>.8.........r.Z.0..4.(.P_...k.....r...g.P.......Gg+:.p.'`DfF...K^.^........HL..zk........4"<<......m...#......wv=.....L#.....=...a .L#,--..;.... .L#.........}}}2.PSS....'.....4..P...3O.>...'...6))..W.....o.P'..... EF.5...Pj...@)..8"l.j3i....IEND.B`.
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PNG image data, 265 x 231, 8-bit/color RGB, non-interlaced
    Category:dropped
    Size (bytes):17628
    Entropy (8bit):7.975445347197741
    Encrypted:false
    SSDEEP:384:G2l3i+kukSpr54RUXeFkqB3SFBNBlPkWlZ2qLOFe2xK54LbwaRBIF:/l3ihdSp94RU+kqBylZ2de2xY4LbwaLk
    MD5:FB78964EDCD5B1E924713FD47B8152B1
    SHA1:541B5B93406036587F603DA81E8EB02103B4F6D6
    SHA-256:EB0F8530FDB9C17DE599D2497293F9B56F60D036FF96C3F2D40B1BAAE9B37CD2
    SHA-512:C0D04804AD306A13ED1148E95FCFDB4FAF2DA783076E30A2B71B4BF851773E9616BE7FC7E6F36FA3FE49449CD2FC25DD19C9942FBB9CFEE3471A0508438E8A20
    Malicious:false
    Reputation:low
    Preview:.PNG........IHDR..............34u....sRGB.........gAMA......a.... cHRM..z&..............u0...`..:....p..Q<..DZIDATx^..x........w..w{..-.n.."......R..P....,.....I.....'..9...{B."....y.....}efv.o:....!9 9`...!.....C...d...@.....!9.2...//.{...k.H''..@d*..0.|.6~.U...z.}..%J..U...\+,./.._...s..Ug1Lp...].vq..('...&.rD..w..w.~...q..e..4....e.tr ml g...S..Z.u...!).ts*bD...&........4.7h.7.\x.d.~..E..=M../.2}.8..6.;._...R.`.d.\"4.).#\.u..W.F....B,$I..~...-M..v....P...r..C..JiJ.".R..*-.G.9j'J]..xJ.5Z.N.ZR......KP.."a...W.+Z..V..LCX.D...6..."..}*z.,.Gy*DA..:..h...3r.`.Kd......0..dI..(..va...Ji.?.. D...Q$V...JC.P.F.+C...nR.%.X.,... n*..H..J..0J.4.S"......x.....P.....!U..y.g.....}%.Qn..Ri.Z(......B.Eb!........4A...B..4.f..u.n....P"JS.F..tbC1S....JI@...y......)..Bmk..5..7.6..._q......*.hT..B.o*.PHU.h.2..v..`;E.+7...P.....%.S.....Hl..*D.4...1..... 5=..<.M.o..`CP.&6D-.C.N.d..).W&.!Xa.g...!..F.f.B.Q.....(gy.4.!..:.T{G.ZJ....S.f........J.Ai.A3....W.4......]5A'7..R.....
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PNG image data, 724 x 139, 8-bit/color RGB, non-interlaced
    Category:dropped
    Size (bytes):29671
    Entropy (8bit):7.981103508366686
    Encrypted:false
    SSDEEP:768:SK+CSQNkCQjTHUXs5/7AzDjCBJuiHnozxx8wk9zY+tSEd4OK:SFCsjYM/O8JXn8Weg4OK
    MD5:214B6BFE2FE83096EA9E8323C5983BE1
    SHA1:0660EA1CF8CE015493883798F24D7AE600BD452D
    SHA-256:66A9312DBB4C2A179622B616097EF4D078A064795CB11CE9F94DE2154BFA4DA2
    SHA-512:159799884D297B347468F43A4990ED3B914215D96B6B97E44D9C92C71608C7C14C61F5A32A2F10C366476C413B3AB459D3432915F8F7B6328DCE235EE932A19F
    Malicious:false
    Reputation:low
    Preview:.PNG........IHDR.....................sRGB.........gAMA......a.... cHRM..z&..............u0...`..:....p..Q<..seIDATx^.gT\.......s...|x......n...v..nwn..Z9G..@."(.PB..A..".D.H.."..s*r.z.....F..*TH...]k.....9......R*.?..#C......q`@..#.1r8....D@"0:............C~...........yH.$.....D.mB@.ljj(.....j<..-.y..9..H.$......@g[...H..c$.=].=m..<yH.$.....D.mB`.....D..c$.u.M.......:....(....F;0.My.z....d...Q....Czx.`.K.HH{".1....k..QI...&.z$.'$..V....j`.:6.........nCMyL.7Z%.G.J}...z..<6-.AZ.$..H>.eU.Oz..Y..\4....M....y[..7.&..-E.mMym.F6.....j.v..ow...nc.jD.AV....U.:.........".pJ}...}o.."....h-.....GbvE....^}]..GYizSciC]..m....*...iKSi}m.0/...b...........v5=v...G......%......B..^..t....5G4HQ...G....5.....|........F..\/.PmMNyYfKS.............C...~.|..u.W.BI....5.IL[k..W......fEIkKY].P...V...._.^[.....$. ?.....&G.>W./.2......'...(M.T..8^85M?.oi.mi.y~...$]....vF.P...(3#F.T.h...PcR.(.2G......y..s...iM......+.TmK..5.v.W.<e:.UX..x..=..!.....,.h..."...O...p.1...
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PNG image data, 447 x 428, 8-bit/color RGB, non-interlaced
    Category:dropped
    Size (bytes):18461
    Entropy (8bit):7.8893505926794205
    Encrypted:false
    SSDEEP:384:50lp4nRrempOhmYadC/CT6EmOfkgm34du2zC:50lQFeWOhD/CpmOfBm2zC
    MD5:9DB578F8F7237EA99C9107FA42027FE2
    SHA1:7D476B6D0ED8593429AA8F429F1D3E5A39639F74
    SHA-256:4785618FEC8256CE4C289B0FFFA1ADE9E2572040E307A91EC96C97106818865E
    SHA-512:A21317508D004A5B53DE6AB4AD24D8254F6FEA8481C83192878F2C9D3815FB9F65F4AEEF1C0470B14D1CCC8602E83BAB186F133236D417A50E50E1A771D44912
    Malicious:false
    Reputation:low
    Preview:.PNG........IHDR..............3>.....sRGB.........gAMA......a.....pHYs...t...t..f.x..G.IDATx^.{...u...ow+..M.+..lm*.ynb$#'...#166..<.J..I6I9...).....8+..x.1`...a.Y;........1.....%].....c...93.;..y...........;=..9..g&'N.8r.....w....O>..#_....x...~......{.U....@.(0B.....G.}.'. Z.--M..>./N...[.....P....?.......|....SOM..;v....)..k.m...R[.|...|.t.N9.I{"..h:^0='.<T;/.Q.C5..`%.s....}....NdT.....K/.t....W..C.zRm....H.$N^w.udz?.....~..y...w..u5....|l..h3."0*=kI.jh.)...@6Q.G.g......kio6..iw6}+..92&..S$-..C.....\#.'U..Om..QsY...&].~%.*...eV.k..?.R..\y....]..u....S..%.\J1.M).}O..... s....k......XI..t"b#U.8I.d.N....)._....._.|.+..rJn.g.^..|..[..d...'.L.3.....e..)$@U+.@Y.@P..Iy.1...(...yV..'..pR.fz..k..t.7J-IO>.q.hI.8..s...5k...V".5z...^;.,.....'}V....<=....h......T..F..@.@....P.i...V..L<i..~......6c._..a~.ON..l........s.-...&....~{C..-r.\kGU2w..1k3BC..<=.>...|.{Rz...e.]Y..7..5.Ts..F...Rj....J|.o.......([.^..^.]....HO.%1..9!........t.#.C.^...(..k.
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PNG image data, 704 x 431, 8-bit/color RGB, non-interlaced
    Category:dropped
    Size (bytes):90802
    Entropy (8bit):7.9843629544816785
    Encrypted:false
    SSDEEP:1536:kb8wxwxW/mqEJLTk+kTEnzZr4WQWYNa9YdM9vMJyG1uSWLJ3EpQhUc3p7RvxMRe2:zwxiW/mqEJLfkTEnzOhwUJyRRUc57bMX
    MD5:04981BC4ECAAFE46E3F2236AE404E574
    SHA1:3FB7940D2729FC1ACC98163605B497C0BB2BB732
    SHA-256:7869B8A3359B341D6C074697FBEEFDBF0F15277C2B049EC6AFC9F09EA1E5E895
    SHA-512:476D53C5A8B5AE10D045FB5DF01C6C1B480948E9CE9FAAE6C65EC41F5D214CDFCAC4FC3004D1923B08A43CA31CF0030059960EEC1551A7446E10147EFE63E2B9
    Malicious:false
    Reputation:low
    Preview:.PNG........IHDR.....................sRGB.........gAMA......a.... cHRM..z&..............u0...`..:....p..Q<....IDATx^.}.x\....m...R.7...M.B..Mr..vb;ff.m.A.%.e.d.b[.......v.....j...V.].g...9..3g.w..'.j5.^....E."@...P.&.....(.....E."@...L...|S.....E."@...P.4......E."@...P.(..E...."F.S.(.....E."@-...L...._..{..8.kkk...'J....P.(.......@.2.f....3..C'.'........,0M."@...P....J ........z...=...(.....\D....Xj3&.X.........d".!..inn.W........b.X.d.....e.&L...P.(..!@..A.-.@........6@H.C 0....W..{.!.... ......T.o..E."0'...bN..L.=.@.+0..H.........#-1Q.'...s...6S...R.(.......P..?V.z.9..+.......I...x..1f.n.2A./h...P.(.s..J .h.....B.....x.........<....Pt...(M."@......%..". .$...6....c....B.@..0%.1.....Q.i..E."0W...b....=.@`..l......=HA.\@r.x 7."...k4f$w4Q..E."@....J ....e..l....1...bK 3".$J....=f<...$...t.9.aNj{.Z.....E."0....b6....$.,..@..l..........P..*p.=......s.@@...P.(...a.(...."@...P.(...I#@..!..(.....E."@........E."@...P.&..%.......P.(.....E...Z.(.....E."@..4..@L.2.
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PNG image data, 204 x 47, 8-bit/color RGB, non-interlaced
    Category:dropped
    Size (bytes):4550
    Entropy (8bit):7.9400251493956535
    Encrypted:false
    SSDEEP:96:iTr7BYFrWF37PyO1KnnZuWGAQEfKAUISxHBKcT96ok:iT2FrW5bXH1EyBXxH0cpe
    MD5:6BFBC2409BCB2F40C5564F2DE3797897
    SHA1:72FCBAEA0DE7F93A29102A94C55195EFDEDF8563
    SHA-256:01E1A5A734AFD91D913AF5430053F4BDE95C8B7F41989B093D53AF152E8D6E67
    SHA-512:F633E733FBC386B14B7AFDAE89FB5F1C3D15518ACF6238D518B5634F2C829BDCE7DFD6601ED79781879451C3749C1473F977BC7B445559A35DC3AD035FEB2C1B
    Malicious:false
    Reputation:low
    Preview:.PNG........IHDR......./..... .......sRGB.........gAMA......a.....pHYs...t...t..f.x...[IDATx^.}P..}.w.......@@..."......S,aY..q<.Q.n._&...t.I...m..v..L:..i.."..;....8.Lj9N............n....=.= ..}Y.e_....}........5..v.V..PC..d.m...5..''..!..R........"...4.Ix........:.uv...|........HY.....{?..+K.QVP...=-......J".r........g.Y...=..h.p8.@m...d......_...z{>..?.lf.4A.@..(........E)..ON.x..c.L...>...E.M5..T+d..\../~....#.......`'.J.'.R....!.7..Dy.F.{o\.H+52..@ ..6..T.d_..o..~..O?tb...".....|!....y...c.......h..r....M~.o..OC..v^C;E.@.<...s_..k'N....$...#.e.AejC..u..t.T..f......8...x.k_.......6tbC;C.@v....._>...C..(....D...........V...I....98[.|M.e.S.....o\8t......=.K.4.a.z...g.=...U<p....&.$....F;.4.d.E@..1.....a....Q0<$YVdI.e.gy.x..k7.....z.K..p8....WFK.+...~v.{..K...=+.}|.Twi{UfM.|.A....v..###..J......(...ZZB.....(...)=i'(..9^.d.v....$.i.$...&k{."J..p..L$.\:[.....8C.....:.....1#J...........J{V..=.S...-....c.@.5...e.v..2]...i...}......H...z!.
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PNG image data, 310 x 199, 8-bit/color RGB, non-interlaced
    Category:dropped
    Size (bytes):8162
    Entropy (8bit):7.9569015545090895
    Encrypted:false
    SSDEEP:192:1HRFoFlad8Rfso1y7vPgVlOH4mKnCGoPZCSVJQVFR4c:1HR+FlaifBWvPgl3nQPZ6Vj
    MD5:FF63919E98773A2F3C3F9E9FAFB67751
    SHA1:3ECCB78D5ED4B9E28841B0B2A58C047ED8919DEC
    SHA-256:02D70770C50EF827895962EA9B04ED48F9AD4BC58FA2CF14A7825BAC42246FA8
    SHA-512:D77964BB9066C64122599B545548EDC1B553D60A9A0C01D40047BD910F0C612D0E7B44167EEC5198DF7F35105A15234C7DDFBC7BEC3F5B2D67649EA2B3C2C1AF
    Malicious:false
    Reputation:low
    Preview:.PNG........IHDR...6..........g......sRGB.........gAMA......a.....pHYs...t...t..f.x...wIDATx^.....}.g.. ..AELbc.9Z.k)..h.?m9, ..b.lJ..Hq..J....)[yS...^]H..j.eKN.%X....!WU%'r..L.+h....l.....yo.7.3ogg.....y....}.....gJ'N~......k..fe.Z.n..#W_}M....@q.(}w......~.K....Y+.WZO=um..k..\.....@1.(M......G.}d.. .&..Y..>......]...X...(.....;.......8....v...'O.......Y.....P.tmu.u..X.~.Y.'.}}}...{o....._.....@...._..z....p.Ygg~..>ku.....?|......Q.b(P....w.......f....~..W.....m{....3.X....4X.....[....F1..V..Y+.jY.5k...dA2..i.hY}k..&(...G<..*.Q.T@G..5..V..q.G7.yf......M...i....-._x..v..:e........>.`|T....A3.^.5........./..3.E...+...._.B.7..+..|.......^.........a+P.3......[k;.XT4.....+.......^........o.15)_....7...t.).....;..q>&..Db...@... ...8o.zd......>..8.OwY.{.t.+.._..........lo.s.E..v..G....q..+....G.P...}....O.....pu..~..O?...nY.'a.....Z?....a......V.s......._......^.. .b.><.o8"N...*.....$.,........f..'...o.d......%.2...^.@....../T...R.fQb.f....^,.%...
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PNG image data, 386 x 702, 8-bit/color RGBA, non-interlaced
    Category:dropped
    Size (bytes):46876
    Entropy (8bit):7.919861294066282
    Encrypted:false
    SSDEEP:768:J3oodyEMf8YcmNz+gbDNh/24V/BoQuunrv+SMWw0JZTOkuyp4f:J3odCezlZh/2eCQFYSJZqkuypy
    MD5:024ACFE3A058DD64779D4C51E2520419
    SHA1:BFF86EBA3D37500C5AAEF3A1141F353CCA4EEC32
    SHA-256:2F62E720DB2A08BB17A8DB33887BE902F07EB72D00ED103851F68BB556171F26
    SHA-512:AD5238A787AF04B0650DF2E7CD699E24F82AFECD01FB9BDEA01D3C10B9E5C951B5B9D7DA1A8B2ACDBBE4BD3B0A076307030136A593D1BF12C78CAA9159E094D7
    Malicious:false
    Reputation:low
    Preview:.PNG........IHDR.....................sRGB.........gAMA......a.....pHYs...t...t..f.x....IDATx^.}t...{..yk%.V...Z.O.......\..%.....'...?....x2W....9.s..2....c...[B....2.6...`..,... .>..$.....!.w..>.u.....>g...tNwWW....wUw..].....066...........p..qhmm..>....=j.#G.......H.$....8...s...p..Yf.GFF`rr.RSSS0::....o.>(++.D2 . . .(0.x.W..c....p..9.x."...}}}.k....K.,...f..O(...n..IM....E....).q..L._.?..y..y:..t.\...\V...n9...~....*...2:...$.....c}.,h.....u+..<y..?.)..!p.}.....T..W..*].r.(.....!..C.a.K....^.......0.~........O.F....T.{.v..`LN......\..n..cw....../.......r@...P~(g.....7Y.Tz!.?....f.x....m.E.P..l..J...&...'.a.M033......h...s.`.(...2B.A$H....!.....0..)........N....V..;U.@ .i7@.:...V@.0.A........n@`50...*=.A..Y........:.... @.*.....G..S....z..{...... ...W......\B W..:..G}n........./....n..4.*O...h.x..s.}e.@...A....9......^.....({.^a.:...\.D..m.2.0.u..........)+.././.7n.P.'.`......p..*/@..p..x.... ....r'....d 8....[.@>O...^....."B.
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PNG image data, 312 x 295, 8-bit/color RGBA, non-interlaced
    Category:dropped
    Size (bytes):40981
    Entropy (8bit):7.934449586749865
    Encrypted:false
    SSDEEP:768:3mf2KpDhuasYUBv0ZKqI8x707+kasdppXWxnWJ1EBsq1Vyl+5SkgX:WeKhIB8Zn/kTpNWNY4sykF
    MD5:EFCD74DBA904AA90815090785FF9C81B
    SHA1:486EE5E9BCAB877746B9B78D613EC6309F876DB7
    SHA-256:C5E3303EA4A9A801DCABB7C6D445C69C8B141CA24F4F942082CC48B7B2153B28
    SHA-512:E8027F33CD5031AB6E05F830E109992ABE180E15083474C3CA2644891947630C6D5C7D9778C5683ED659D54083FB7BF20A5432B19B4DDB287F2F4274B4ACDDA7
    Malicious:false
    Reputation:low
    Preview:.PNG........IHDR...8...'.....=._$....sRGB.........gAMA......a.....pHYs..........o.d....IDATx^.....WQ.p....%RD.@B(.!!..<...FH.... p.Az..(.....bo.PTT....+v..{.|.m&l7..s.}..{.y{...o.]g.{f...|.......`y.(..2..w...N.....at...d..A.6.....4hci..A.6.....4hci..A.6.....4hci..A.6.....4hci..A.6.....4hci..A.6.....4hci..A.6.....4hci..A.6.....4hci..A.6.....4hci..A.6.....4hci..A.6.....4hci..A.6.....4hci..A.6.....4hci..m.AY....'m....ZD..e..y..................O....1......O..O..p....}..?............)m.._...[..[.......s.y..7h.......N....0..o.....O/|.../../.~.'.r........n.>t.f....>}.W.ui..|.............?.../../.~.w~.f.A..i..Y.....;..;.G<...].z..nw.[y=..s.9g...../../n.>t......8=..O....GM..M.4......_.....\0mmmM?..?}3..A.4.n.,......>u..}.S^?.>iz.+_9=.q...?..../.~....... ..c?.c..W_]....B.._......r.WA.Ee.....A............^......../../.8.......?..'?........q.....b.........u..o.......K....5........P.7.O..O.........;o.......+u......~.W.u......x..=.S.=.....J_..~.....
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:GIF image data, version 87a, 16 x 16
    Category:dropped
    Size (bytes):864
    Entropy (8bit):1.1104691609476027
    Encrypted:false
    SSDEEP:3:MUaxZXllLlv8PLnmI8GhgO3lIybfzWle:dG8jvhHI2Oe
    MD5:DB26AE69F040FE12907BC8CAD48BB1FD
    SHA1:7E116442BA09361C5C77C4F98E611674323D735F
    SHA-256:C4A9BAD8FC6525D96BCCF6AABBF06627F319827E191FA127BA3AE46BA3B4FB39
    SHA-512:68FDEDAD644D478FEF60F050C9EC55A69D4564C6C4249D8284194FB668CD0197E3164304A14F2F09487FDE48137073E56D27B6695D0C66DF4FF4E35E5E00A200
    Malicious:false
    Reputation:low
    Preview:GIF87a.......L...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................,..........E.....@......<..!A...BD.qb...-V.Q.D...J.0.C..-...r..+Q......"m.....;
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PNG image data, 148 x 29, 8-bit/color RGB, non-interlaced
    Category:dropped
    Size (bytes):1352
    Entropy (8bit):7.727985602301419
    Encrypted:false
    SSDEEP:24:u/gC+56hpTLS3Byee35rjSlOBR50mJsNGd2/WFSN+dElG8J431D9k34lbzYeF:ZC+5wpXUByeE5bINA9UYYJ6RkodkeF
    MD5:461BB3762D7F1B8D5A757455A72E015C
    SHA1:18825654EBCA8BE759D398F3346CD1B44923FB1F
    SHA-256:F496506550EF92A2EE6FA127EF8D5DA47CA18BF2036061FA8F6A8CAC20B07994
    SHA-512:3E542A43C2899E33B298A84F68371B9891B9D80949F8A5A331E168052574F04459B50E8A4A4EF91447E6139981B6D45D750934886BC68E58B2F6521B7AF96133
    Malicious:false
    Reputation:low
    Preview:.PNG........IHDR....................sRGB.........gAMA......a.... cHRM..z&..............u0...`..:....p..Q<....IDAThCc...?.(..!...Q4DC.a..{.......!\..F.h.V.....9o s....>...%.......~.XMMM___cc......._.=Z>....H.....3...333C....y.....&...x.i)..9.yt.....O10\.u.v....k{.....9w......V.....3...31...xqb.1.7.yt..g.6......V=.ek..~~`...+..8.2.....9.iG....ne$..sT...G...o.)#..W...[V|....=....z.6?......@..5.'..R;...{..=HL@!..2...C..@I...#^%1......I....U{.l..w....I.T...\?k.....;Or.bn...;.W.X...B....y.i....%...([qv..++gO(;.....=.v.6N..?....Nu...2...'V7......Y...d.Z.D...x. &.-+.2.M#.Q..............S.n#>...s..]2....m...<..p.#l...QvvPA..^P.?...........S!.....R.....Fdo.....xWa.2..NL@g..N.;g....+[....O/.Tr@4_\4..c...@Y .*.*&.L,....I.<x.E....h..-.cz.Z...N...QL|.K....:.sW..&...IS..3.........P.P..D...&.yX.Y\S+..#h,..O|..t..i...B....A..v9.c..@..Os..6.2.b2#.^.c-s.-..).R.....%.L#U.._.*.......%..+k.......F.*A........l....7c.,.5,k...!.L.}..$./4..*4Y.....~..XJj..9V0.....V..`.....
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PNG image data, 663 x 127, 8-bit/color RGB, non-interlaced
    Category:dropped
    Size (bytes):46431
    Entropy (8bit):7.9896908550908
    Encrypted:false
    SSDEEP:768:14s09zwwqKfPXb6d7qajPlKCoBg0B9r8s8W7m+Nax5MMSgDEg6+8NaLt6kk9+yq7:WRHqKed7boBg0B9oNX+Nax57SgsCt6Jg
    MD5:BF17D01430F240F4077232C37B79D22C
    SHA1:D87A00FD8A8A9F79003AB08FA261766BAF1BA53A
    SHA-256:2A2E35FDF7129AE7D26E2E82D7C92D2BCB8C3B509D1540FFBEB223B7E3FFE0BF
    SHA-512:98B2D644F00590892D225653D223C7B4B5CBC8985786F75A185AA2871809CE1B0A784604393BC06FB07E2310A020337D80ACE007D24584C664D4F564E29786FE
    Malicious:false
    Reputation:low
    Preview:.PNG........IHDR.............5.~.....sRGB.........gAMA......a.... cHRM..z&..............u0...`..:....p..Q<....IDATx^....G..;...w......A.xf<&.d.(.c.l.A.eK.d.bff.f.5...Q.jfff.>.W'[...VK.-..S_}.S............P(~............_..[oo.4cM.F...h$...t......??..5.t.@__...!...F...h$....%...tCp....f.....H.k$...F...h$p#.t.WjP|:..@_.B...Q..5..H@#...4......M....(^T......w9..^.k$...F...h$0.....hP|:......].~.~d....o>..5..H@#...4..)......tDq/g.}:66..A.Y~.]#...4..H@#....I-...Dq....S.......]#...4..H@#...P..hP|.......Yy.-%.mqfK.`.p.16..ii(n./j....~x..t.~...l..6.......Z.....ck.....[.K.rb..+:.jncl....[....b...<--.O..*..o.+..k..\....quue]m......>.........fN..'....:/7'...e......Q....d...{(.H.h)....x..G..7...Pik*MI......l.....2cP.)o7-p.l.[.CfFDYEa.OkSm.H.....o.w.sM.#%@o......v5..'S..2l.........-...^...o.g3i.0.jc{.S.ipUW.......{#.1.t.`Ct...k....M-..........P.1.](.K*R.5.9...3...^.~0..lmT&.G..k.......P..0..;F...a.[.c.....j=.l...qog......$\......r...m.e.[.UvfTyEa_w.H.....K.R..8...
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PNG image data, 271 x 314, 8-bit/color RGB, non-interlaced
    Category:dropped
    Size (bytes):11438
    Entropy (8bit):7.94053551695892
    Encrypted:false
    SSDEEP:192:hbUt9tDH9V33MKGJPIoToWRdzW5rd4cNKaPWs3UfMxMn2VFp+ZalP6bBw:BiDtnGfhlW5rd4QleTiM2rp+iKBw
    MD5:DDE0A70AE08DCAE42EEEED0B933423EC
    SHA1:12BD0C2A44631DF5AF4AB5298FEB7119589123E1
    SHA-256:47FE07E6F2D6773CEB6D5417E1469D9644203ACC99625D6E1A6A5BABCC6F628E
    SHA-512:5A4E213674B26ECA5E692DE16D787D1815E2CF780BB1198130621E19935B2BDFBAB3735F4253678EE95F80256893FFEA25438CBE7C9896B9AD72271BFD4E0B56
    Malicious:false
    Reputation:low
    Preview:.PNG........IHDR.......:.......@w....sRGB.........gAMA......a.....pHYs...t...t..f.x..,CIDATx^...]....0.;bbb:...4....c"&...A...4.6.e.1....,.v.mv...I.I........#.va$..,f...F4.1.o..<...{..{....D..r.d...}.U......h.%.4>...(....E.]<g......gZB..Q/.?....6.......7.b.........?..U.h........|...o^....7=............h.2....?.>.....l....S..[v....?V.e.K.....}.....S...{..e..C.......E...;...:..;..._>;.....{...}.....-.^.o....g.{.O>5.s...\6.Qb..?......K.~.l..w..3*..UdY....?n..4..V.s\.v.X...f........e.#`zN.v.85..=......3.C.,..sB.c3.......<....oyf.....{.i.s....uf...m.z..._....Udym.p.+.z..yk.....k..^..&.7..........:[. .....{.C...gJ=..d....]8]].......5$......}..e....#.>..U...8c1*.Rg.....8i.....N..*..9.......=./h4...@...r...k......2.[....4qJ...6..R..<.}L..v...O....J...Pt....P....(N-.W....vl....g5.\.J\~|.}..N..........%. ..jA..U6....q.....$....V8Z7$wk5O.H.=....,O.m...W.&./.......3^.L'fM.R.C..K...J.....h.OiC...7..;tL.`...R~..".W..o......KNk.......,..;.^B....y3..t.c
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PNG image data, 464 x 320, 8-bit/color RGB, non-interlaced
    Category:dropped
    Size (bytes):34908
    Entropy (8bit):7.977040402205251
    Encrypted:false
    SSDEEP:768:h6U5ekLlsEvYttmnBfWpqv0TUBzylz/iD+4y29AwS:NLSE0tw8pNRziDxi
    MD5:5F697E2664CEC5D1C55F60D3BF8EFF1C
    SHA1:B98FE2ADF08FFD1E66DD1423A3F228924FE38576
    SHA-256:0CC135E25063A852E10633FE6FC013BBBE14D6A33ADC85826B29540AE22113EC
    SHA-512:ADBAF9D674141DD60F821F291AEC387B3EB49DBA93C642837ED289E64BEC2DED2027A838B3ED6ACB0B88CA44C57EA2038336C53D6A7CB717BA53928EB59C2BC7
    Malicious:false
    Reputation:low
    Preview:.PNG........IHDR.......@......Y......sRGB.........gAMA......a.... cHRM..z&..............u0...`..:....p..Q<....IDATx^....U...........v]w...(AQ.#. *.(Q$H... ".$.s.9.....4..9.....^k.{zzfzR.O1T.:7.[..S....L&S9.i.h.h.h...............@.. ...........5.5.5.5P4.(..=r.....g......q....&!!...'..ls)`......Z.-.5.5....'pCBB.,Y.e.7.x....P....{..g.K...^.l......./.b..I.......B.Er1..UH^.)5".j.cG9.k".....R..h.h.8..<.7&&f...O=.T.v..Y....q....M{....e..'..I.6A%uU.(vn..W(o,.mH.*H.)..q..gl.<e.p.u.d.ZLk@k.J.y....g.j.&N......*}}}.5k...@.q3.5'.......b....m.61!a.rA@41..$v....]C.a..4....Qd(.%A.K*....V..*Y. .B"@.I..6.....+.X*%.s .%..*k..*...~A.b.()9........5......[..<u&{._.1~....q../..:...!...B......J.q.....e.5.U.b...V8....qV.P4.U..&..#:.R.1>x.W=.T......1..U..W4 ......q..(Z..Q.........h.1x...E4.+p........KT.=1.T..-\...........K.*.'.3Z.......L%..X.*..*S..Vy`H........G........E...1.\%[..c]f..R.....4..s.5V.....*..p...=...L0nr..\Esy...$....+.I..B.m.....(.....`e ..........
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PNG image data, 456 x 538, 8-bit/color RGB, non-interlaced
    Category:dropped
    Size (bytes):25200
    Entropy (8bit):7.908916013980272
    Encrypted:false
    SSDEEP:768:H7WcUnSRVe5KeCQ45WedpE0sTxBpeBRLRfF:bWcGWVOkh5We7HSBpIRLb
    MD5:4A5224EF32CDDF02DA71C110B1111BCE
    SHA1:483222C8CB6DDDA50AF36C9160EB2FB58E741096
    SHA-256:E3B3C2B45A9A12A8423CEA40C4E4AD8970D94AA1C619D91C64E7E07A581CC9EB
    SHA-512:A29FDCDD8EE47BD9EBAD5D13EACE8829AC3316BA0259922B19F2F83E6BB05A4EC5A3F6B26D7B395FAA1CE9E43B893484CF4507A6AD0FE9B432A50CBE61B89A6F
    Malicious:false
    Reputation:low
    Preview:.PNG........IHDR.............+.J.....sRGB.........gAMA......a.....pHYs...t...t..f.x..b.IDATx^.{..W~...,.D2. A. .......u......d.......q.kL....c..Y.fg..`.=..cF..c.........CRC._....j...W.Iv.I6.dSM....w.~.Q.{.v..-4.U.....9.|.W........ .. P)..J.........=.+......TL..Z1P.......+......TL..Z1P.......+......TL..Z1P.......+......TL..Z1P.......+......TL UX.j..R?...s .. .X.Y..i.$....8....TL GX.z...._.y...?:z..]{.~w../...n.9...&......?.?....;|.~>....+o..../_....X.....Bm+...c...h,^B...+S]8.-..1..S.|U.ua...`eM....4...:v...#'>>v..3.~.+/...[.......*Q.(.....].8..;..V.........J.......VR.....?yz....+W.zf3......'...U.h5.KftU....^.......Tpe.5..J...TA _Xi......S.\.|e..3....=.....9:77wr.T..z.jo.Y"k.+.[6...;+.N..I..+.SR.b..@%u...{y....c~rau.-.....^5.lv.....D<V.m.fp....(....*.$l.@............|$r.[.n.m....\..;w..q...3E.ULg).R.xJ...J9.b..."..n:l*..XKG....z........P......RX.w..*..(.W9...~.........6..#.y'.#.........^..c__s...7v......IO.......}....U.$.<-.*..U,B0]I.)......F
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PNG image data, 980 x 692, 8-bit/color RGB, non-interlaced
    Category:dropped
    Size (bytes):82258
    Entropy (8bit):7.932199160854409
    Encrypted:false
    SSDEEP:1536:sNoLEwwl5QTEyNv7eJgk+LoB9m+047OjV1BgCdbyklLFi:q5KAwjej+i9mwqV8rwLY
    MD5:DD6EE63574D377901B5849E43A205173
    SHA1:F68D254EC3C93E66EB17DF16FF32DC009507DD18
    SHA-256:6DEAB29FBE17FC2485BD96B395ABBDEB8B84C85D38E8207567708BF2EA864E09
    SHA-512:2B24EC4932B18E6F20721AD99C153A461139DF4E823E89281904C729DC9B153DE76F2FBA8C9FA3AC69BBD7BE7E365D9BF014C325A9250DEBB2E07313F2500986
    Malicious:false
    Reputation:low
    Preview:.PNG........IHDR.............m5.=....gAMA......a.....IDATx^..|..........^+ ...W.].!bC.Az.........D...{.E.."....BI..C $!....v..p2[2.lvg..~.'...3g.sv.'.....H..H..H..H..H...F.................@..H......'.. .. .. .. ...YV.SRSS3;?)6.J..D.....$@.$@.$@.$@.$...,(...:.c...s...&.. .. .. .. ...XP.m.1lF..:..L.$@.$@.$@.$`M.V.oE.s..u;.D.KY..hc.H..H..H..H ....|;R.U.#.%5C\.1.<>|y.$@.$@.$@.$.\.,-...i4S...o.&L...k...$@.$@.$@.$@.V.oXuJJ.k.v..5e.vm;..J.......%.x.2e.......7o.jIII<.$@.$@.$@.$@.$`}......J...T[RR.3.F..Y.....R.n....>v._.[....n.1g..q......>*Y.B.....:p.@bb.>. .;..z..N.o..Yk..V.w.......&.................@...vl?N..;r.m.s..w....+..n......8{....W.c.../]..t)..W.\...s.....O..u...x........a.Tqd........p..K...V]&..+3m!...a.J.=.C..pP...|.g..x>... ...........8...|;D1)..m......:.D..5..8g...'..8{4,....{...7l........G.......'....8u....K...y.....5r\LL..8.4M.].krp..0..gr.R....J...='z..!...|..6...L&.7..~g............(...o.&/^:...No....:k.......y...;.m.~........
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PNG image data, 456 x 406, 8-bit/color RGB, non-interlaced
    Category:dropped
    Size (bytes):23744
    Entropy (8bit):7.925091958400853
    Encrypted:false
    SSDEEP:384:i2onw02FkL3c7MgtbHfkbmszV5VAV18AHynbizXGg+7S6scSzRRGlwiqr5pxTp40:Yq2Q7LtDcPp5VAV19H5fkzscw0wiqr5X
    MD5:CAA1A6481652BE62589B7AC0CB554E0B
    SHA1:72A7FDBD028F9257E9D431ACBF5C00EA7552271E
    SHA-256:7AC5E647F6E88C42332A2746EB2D40B9DA1985B889D07C2EEF31286453C59B72
    SHA-512:9E2EC5C611FA9761CDA39F9E2DBF803673D5C0749911245CC1C5CF5BA4B369969652437CE13A50148E00626F4EF83E7DFCD7DA59A26ACFFE48406ADA15C4742C
    Malicious:false
    Reputation:low
    Preview:.PNG........IHDR.............sG.:....sRGB.........gAMA......a.... cHRM..z&..............u0...`..:....p..Q<..\>IDATx^....E...B......*..z.."...+.!." .Y.rQ.. F......U..@X... .Dv....C.}.L2!.Lf...I.OOMj...O.s....>I.>OU=..o=].{.C.......3.v......;f...{...&...H..c.=4x(.<.8.......$...b..w(.}...g..x.qM...=..U..':XG'........D..#.}......x.a..!.#....}u....]E.X....(....q?.<.....^:.>....:t....|.Kg?.....R....&|.I.......]..a...@.&...N.GJD...L|.0q.Z.......'...q?;H...'>p.......$.,K.NlC.(....q.%.$.f|dA$..O.S...M..')..k.R.[.....Q=.&..1qEE..cnm...~3K..wv....P.....?=D.m.|'.`;...A.x.%....L.1?:.....`4c.bi..#n..{{..[......=..C...N.....`..M.......D{(]S.8.G..b...nI.G.H..6..z.Y.+K.d....|...6....@.(.w...i,.[....@g...Q..V..&V.'"&KW.{.2Jc&.'...;q.;^....6%>.....Wx_.X..;..a....:....=........,...)...'........qSJC.=.......n.....M.;..-..7{T%.R..C`....t...V.D ..0.z{(...!qc..h.3........R..,.e.i!.....//n|...ss.O&.L.P}..U..W...T.t...o.E....y...M.x..?Tp.......R.r.....S..
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PNG image data, 998 x 399, 8-bit/color RGBA, non-interlaced
    Category:dropped
    Size (bytes):89086
    Entropy (8bit):7.9736854054733035
    Encrypted:false
    SSDEEP:1536:HppeB29YPAWgLQuKjR9uWIQW7x1akmccZjgO0NLGC5cfBxBk4L2J:HppZYo2uKjR8WIQW7bSZjh0NL6fq3
    MD5:D3A6F5763A8C4485C337A8158EAB0DEE
    SHA1:D10F8329E382C7EFE838E9F657907307A343ABB5
    SHA-256:DC7CA5B9C399BE9FE869B69F36B0D114223B0B1A3678AEC347DA604E592CB555
    SHA-512:4D30D65C8D71541D4303C720984A25FCE47D55C695DA18372C32E35F690ABAAFB9611863C5C22847BBA458BC3ACF279D989A720372E9C55CF22DC181C35D2385
    Malicious:false
    Reputation:low
    Preview:.PNG........IHDR....................sRGB.........gAMA......a.....pHYs...t...t..f.x....IDATx^..`T....HH.+@... .@...[.D...<.V{...E[h....oo..B....U..j.y.\@(o..*B ....#..$$!!..sf..3s.d&..n's.~.....u..k.....V..C..a...U[[+>....W^y..F....%...H.$.....D@" ...H.$.....9.^...1c..........6m.......\..).r.*.k.1..%...H.$.....D@" ...H.$.......3.y...D@" ...H.$.....D@" ...H.$....)..{..p..%.....D@" ...H.$.....D@"....5.+...<,,...%...H.$.....D@" ...H.$....@.!`..s.7.Tw..%.....D@" ...H.$.....D@"...Pum=N.\.?..3.<..m.....o.(I.%.....D@" ...H.$.....D@".g..^.*\....'jV=.......8|.0._oG....b>h..~&MV'...H.$.....D@" ...H.$.....7...O1_....b%%%...A.6m....@..1.b`...2..<..2..>B..K(..n<...P.`.1.hU.=.iv5V..?.kc...U..1....T.9..Vs..\.1......D@" ...H.$.....D@" .h...Z......-,.........o...9.Vt$c....D@" ...H.$.....D@".+...|..p/\.......&.........l%.....C...X.7....BA.B.Gw.%1.G(.p.%^..`|....L<......#.XF.q\;....H.O.<^/,.O>.v.....m.|.....\.~.l^.O" ...H.$.....D@" ...H.$.!.@UU.P.+**L...8?.3{5i..
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PNG image data, 206 x 90, 8-bit/color RGB, non-interlaced
    Category:dropped
    Size (bytes):3752
    Entropy (8bit):7.855093346354451
    Encrypted:false
    SSDEEP:96:h/iBB6OwPJ9K26scoO0qgR5VX8W6fzNo47sut:JiBB6bO26scHMyW6fhoasQ
    MD5:623A19AB274A4FE45BD281650DA6A07B
    SHA1:5DF3ED76CAE87D292DDC9622B8CD75FDF9EFC0E4
    SHA-256:2046D0014AD7FF8EB5CBFE68FEE499FD95393357C878BEFC31EC2C53A385C67D
    SHA-512:5E08DB0D11EDE013D3A85333C263C565D92CDDB456D2431644CF2A8E64E462AA05BBE8DD2C1DB69D05AB4BAB91CCB8A6A7C1BC461E79AD67A230EF9C67E2AB58
    Malicious:false
    Reputation:low
    Preview:.PNG........IHDR.......Z.............pHYs..\F..\F...CA....tIME.....)...KY....tEXtAuthor....H....tEXtDescription...!#....tEXtCopyright....:....tEXtCreation time.5.......tEXtSoftware.]p.:....tEXtDisclaimer.........tEXtWarning........tEXtSource.........tEXtComment........tEXtTitle....'....IDATx..}..e...3.../..w....-...bk#.. .5.....hT.....I@QKmI..CH.&...M.UJ0.....U.P.....B........<?.......gfw....'....m.....g..m...E..3......."&...1......=..[g...Y.....e.{?.x.R.B.}{...j.U..."&...1.....%5EL(.)bBIM..zs.../..een..=.].s....|_...n.%..n..r.........IDAT3..9?..L.'.}{.8?...f.q}JS.z/[...o..&o..&.t..U.'d......gqS._.'.....8.._...41T...G8.3......V'.+Rrz.1s<.......--l....ok.Z. $.].S.U...1]...iUj......./m|2..c...{..c.0{Jz...N..d.%.....a.2.c..X............U.dc.;.*..|...y..u.y......'..\.bJ..J.y2.....IDATj..PRS..."&...1.....%5EL(.)bBIM..Jj..PRS.D;.F.e.............v..X.V#..0..$.m...k.^"..{..NL.Mc7.E....x.4.E&......h.5..q4..j....@...........PZ@.d I.H..i..|`K....
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PNG image data, 444 x 133, 8-bit/color RGB, non-interlaced
    Category:dropped
    Size (bytes):4309
    Entropy (8bit):7.819688180943613
    Encrypted:false
    SSDEEP:96:AIN0+L5WfHxyaw4zFiy5zx4Ymc8N+mWRpxRAYfcZlIfZlE:xbCRyGEUVmc8cjfcbkbE
    MD5:5F5F208383185938F324524CBE42449B
    SHA1:883BB8D11B74882C0E19EF74242F77E6F59C364F
    SHA-256:54825AFF387D865C2E1DC3D8EDF2E60B42F70EEE3C44B7855FAF3F104DBCE7E4
    SHA-512:3F00AEEC0F4F1B41EA143DB6279AA03316FF81B52B0A8B0EAAEA72BC9FFDC71E27C829E86038C4BF874D21519B8F42DA50A30F9A2B5B1A32A265647714FB0EC3
    Malicious:false
    Reputation:low
    Preview:.PNG........IHDR................Y....sRGB.........gAMA......a.... cHRM..z&..............u0...`..:....p..Q<...SIDATx^.k..E...A|C.........9.h...X[..%A..".C....r.5!@cR....#H....VR9..[...3...{r......k.;.o....a.*.P..P...)...P..P....\@k0...@..@.N....F..@......bq.E..@...4Q..P`..@s.X.cQ..P.h.M.@....... ..X.@........{....P..P.......<...Vln.p{B..Q.&$.....,F...|..W..|r..q...0.O2..S..7..B..@.....'.n..].7..........\o0...1...P...,.....-....zs\.Ah*...76.$.p...@......P..P.P......+nv.G..r..,.&......T.[........Q....vh........}..O....k..4n(.k.`..Y./.....~.. ....u.|t.3........h&<..B...W..4.....'wn....R|....7....qP..l..t.D...P...N3.@.....%...AS.....P.M..N3..C.iN.<Wt6.....yP..ZV ;4.......P`N....V{;...\P..J)0Oh.R.qQ..f....O...........f..e.(..A..&.D..@......b.OA.....^...4Q..P`..@s.X.?.2A.@...@.h............. .P..f.....(..(0@.;4.....R.XO.........@U.8...._......8..Z.bZS......*.4[.F.....fYj.<z.p..R..E....8....IO..Z72.P..4.Z........".2"..0.M....p..5,>~....76..b.R$....i..)!
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PNG image data, 652 x 686, 8-bit/color RGBA, non-interlaced
    Category:dropped
    Size (bytes):56144
    Entropy (8bit):7.883282881083759
    Encrypted:false
    SSDEEP:1536:lDhayiSy31ByWwbLWQSz6HXXvJd9PlHnJrDz0O:lDcyFy31By1WQSzkB1qO
    MD5:2D6BED8E73BF86AAFD568B3EB5ED5F37
    SHA1:5B26E506658AEDD8940165286A7ABE27C1F87A32
    SHA-256:E86EF166CE1B074C3ABD16C5DC17CC1379EF9B794C85083515A79D090101C4BE
    SHA-512:FBDA96A8A97294368C4B18D041E60E3525E4AD4DADBA74C2D7C80DC5AA5A606897D52CEAF0843E3C03050BDA31739C484021071467A9BDBE96DDAF196D20D026
    Malicious:false
    Reputation:low
    Preview:.PNG........IHDR.............+WM.....sRGB.........gAMA......a.....pHYs...t...t..f.x....IDATx^......y....Jbg..$'...~.7...D..Hr,...N.E.I....v.MH..h...Cj1)R.(..Dq.1......I...A`.b..0..e.0....s....[......}...}...!.vuu.S.....TU.~...O~..z.....4==M?......t..I:~.8.;v...9.....&...4..@...4..@....w.{.}........_..^}.U...EN|..!.o.MNN.].h..4>>..6....h......h..4011A.w.{..........455%...833C.z].`PdH.m.m..^~.ez.h.U.......@...4..@...4.%.`.[.f.d>f?f@.......G...E.EvC.8p@......z.f...6....h......h..4p..Jh\.v-...+.}.v.Hd.b.....H.;?...R..g..{N.m..=......,.C|..{.m..E(.8s..%..-u$.3..m...Y.'....<....Y.fWu^.o;...K..^W.Yt.....*.+.YkG...\.<.i..[.y.Md./{5-....../.~....G;....Y..'........x.]w.............<O.a../...K`...c.U;.NE..N."...Y.`.N:xn.~.W.<..k;.I...........Cy.....B..sYm..sP.={.<xj.:l..7u=...e.2.zp=U..6jR..e..m...A....|I6W...y...m.....g<....U..m....$.N.......p..-...o.oJ...,.y2./..{.....:[.h...o..u..eq.....i....>......oqcj....v>...2.h."...J..l...5q.I
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PNG image data, 297 x 228, 8-bit/color RGBA, non-interlaced
    Category:dropped
    Size (bytes):7871
    Entropy (8bit):7.885349537648428
    Encrypted:false
    SSDEEP:192:Cn6BOd0O2nR6Lx8U0mWXHPKWf6PomU9sNO9cO2fXY9f:bByoAnAPtkysN8cOSI9f
    MD5:8B1999DCB2AF81EE4962C2AB7D6CD590
    SHA1:BC9A4DA33AF476FEE640F0D61BA597194C77C316
    SHA-256:2296CE782D51FD0646EF6F336BCC1B499F42BA446D514BE8E6686BC64576DA40
    SHA-512:12604142A00C25CD8B3EB64D6DB6903E92A44BAD2B5B867A4CEA30391FE12833890B3D119F21018B6FDA9C16645E4BAE84AEFF414051E60F48139EAB2B982B07
    Malicious:false
    Reputation:low
    Preview:.PNG........IHDR...)...........\....sRGB.........gAMA......a.... cHRM..z&..............u0...`..:....p..Q<....tIME........?.....*IDATx^....u.. @..92.$....Hv....+.d..A.l......J.d.8..1.!r.Y.,..M...(R$E...%.!.(rH.!...p8..}zXT..zt.....48.oWW..~.U.~..-[L...".. ..F..z..b..@..i......hb...... .....4P...)..h..M.M.R.. .....@..-Z.pRpR.. .HA.Ek...@..(.... .H.R.@.... PU...Q..%.e.M..:.6........AH...5`....xj~R..hR..D.......4n|...kz..z.?5}..%C*....o.8/....A....1.R..c..s$M.wuN7.\=...._2.......,5.:W..|...g."..1..s?!.h...%..Z.x.S %A.IY4...'..7.UL:.}BZh..P.|.nJ~R.}...m.....j#..Y~..R..K.$..C..(v4...Wf.`B...uE..rI...(.;$$-.Y.J:_....E.44M..6...{_.....SJY9l..!.....B*..1.0%...BP..N..!....)..3..S..T...L.Uh..u.P......4....P..v..|R............B*..N$.;..b;.$._.B..D..j!.......Zn.(.H......+._+S(...kG+on~>H..#&.....}L...O.y..j2..*...)B..p(.&.j.o..1.../.}L.}..Uh..}....Km.Ii.hl.C1..NB}5V'm....l...-vt.,t.8...u..Q......Ow..D.5...2.....-cL[.h'...F.........WZ\B.j.@1..B........5.......lR.X.
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PNG image data, 725 x 443, 8-bit/color RGBA, non-interlaced
    Category:dropped
    Size (bytes):55749
    Entropy (8bit):7.928157851308836
    Encrypted:false
    SSDEEP:1536:8i8N8AONM4hyUaHj34AYrkuPt5yrrrrrr4BrbjTu+v:8JNXONMOCoQEfNnv
    MD5:4AA1678091552577C5DC2E25F2F7CE98
    SHA1:CF1748F3C41C51670060788BF9D9F86F06D4A57E
    SHA-256:0E092342BC5087FBF7A8255B1A129FFD9670D52667DC4DE89667AEE44E3B9A8C
    SHA-512:E2C7CA76D78D226DCF7CAD82445FDE8C04B43B86D74C191036747D6AEC00B66694CF26BF0C867F488586EB03BEAC10F81B99109B8DC4BD166C069769E8ABA18F
    Malicious:false
    Reputation:low
    Preview:.PNG........IHDR...............i.....sRGB.........gAMA......a.....pHYs...t...t..f.x...ZIDATx^..x........[.M.M.$R.q.u.......I.X.r..Gnq..jK.dY.....%.."%."%vR..w.............$A..y....r...o..{._aa!rrr......c..........|.r,^.......s1g..|...5k..k.}...........p..>0(.../q.....t.R.^..[.l..={p..A.9r.~..cbb.w.^.Y.F..q..a.............p..>.}.....{.x...'.h...7j`.......,$%%i....._~..v..W`.%hoo..':....4..=.o..:.}.....A.......w.....DKK....fX...&x.....4....Q__.}.....dUk..y.y8[...I..J+o..~FV.i.s..=/g..1................;.|..e=......xol.........x...:N:^.\......?....=.k..]..w..QDFFjil.........Gmm-...................x...n.\-.f.S..jDGGC.....?....Av.}DEEA...R.:t..SDDDt..e.............EhhhG...@..d...CFPP......2".n.d...2....s'(v....dU.}...mC@@.C.O3..y36m...t.)c....I.....:y(.W..t..X.r%..b...A7.j,[...t...JFA'.>..Y...-..X.p!.B]..-.Im..Q;..t<t..I..t.......V..u.Gg...W~6.>#..U.V....%?'.."Md...<...gd...m..$..........s..w^/<..j..d9.m2.6.k....N...:..z.^..^....U....j.....
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PNG image data, 516 x 252, 8-bit/color RGBA, non-interlaced
    Category:dropped
    Size (bytes):25284
    Entropy (8bit):7.944621550040602
    Encrypted:false
    SSDEEP:768:kTBPCnyA+ztudJHxDve9rg8RhIgQ4jZesiO/YL0wpa+:kTBPCnyA+zMFvX67i3LrpH
    MD5:DA091579936DC66B6117B495AAB5471D
    SHA1:12496724224E1EB9F0A2539B744B285ACB5F4660
    SHA-256:93FE5CB28066CB99C0FA48DDECBABCF65C539FD10703A2882C283F52EF6B480A
    SHA-512:0490ECA4C78F43D761C5EE1004441F7169F3AE35A2AE001165483B37D737629C40D4C2A10BCD5FB871A442D5B28FF528FAA5F249729AA8E28AB50A00220E4BD5
    Malicious:false
    Reputation:low
    Preview:.PNG........IHDR..............\......sRGB.........gAMA......a.....pHYs...t...t..f.x..bYIDATx^..`.....I.A..\......FM].."(Zjq..F...V.....F..7..J..."K.*..ACU.. .....uc.w......y..Br~z.{.9w.;..3.%...?....o..w....wd....m..o..;w.......A..a.#--....h...o...;.s......M{..w...k._...k.b..^qA..A.Z.g.y&z..=...=z..n........../.a..<...N.0v.X..t"...T....NK.;Ev...L.a}....4..I.....8....G.g.c....l....../U.....S'\z.0..ks<M..3O.....?..?..Ox..'..s...g.'8H.2eJ...<.........Y%.G.............R_..t].:...HT.a.)o....6}..>.^..].=Oi.....GK..u......#...7".....6....4.n..YG..T....EC.7Uce..nS...4.;....N.*..|$...ou......FPZ.3~7.6_..~v../L9....._..............{w...%5.i..4.j...&.....|H..:..<mw(...+....J....7.z+J..g...k.........n....... .&..';...!C.f...}..v....Z..o......[?KFFFL.u....2........7...V./.:....D..x.z[....1.,.>.X.i]......ca....6..,.v]h..N.zN7T..D....,.....W....mi.k....a..y....,.9.:N.[..0....w.l...l6..z.A>...5{......C.1...uJvn....mE.....o.
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PNG image data, 644 x 447, 8-bit/color RGBA, non-interlaced
    Category:dropped
    Size (bytes):34238
    Entropy (8bit):7.893201879020466
    Encrypted:false
    SSDEEP:768:f55555ZtOA02oGywZY7hpK43l3zLI4qZFZbE7Jt4LN:f55555zyGykghpp3EaQN
    MD5:46AFE543DAA01754D54C3D0FC715AB86
    SHA1:C97D335C81FAF0B985E884D5B2D0AB8CC1E73E04
    SHA-256:0C91BF053AEC9051717A9E9DE08335726B50F2295FF5EA9D4D51CA6B95AE7ED2
    SHA-512:6CA1E805FD8D49E7751FD2780914FABFD3E664D49F59BEAD919655214D20B85B90CBDC1F34D22AE28333285474004779D841AB3CDA6E959522C52440DAA5B0B4
    Malicious:false
    Reputation:low
    Preview:.PNG........IHDR....................sRGB.........gAMA......a.....pHYs...t...t..f.x...SIDATx^..|TE..Oz..@B.W.H.".`.,...."..E.......E.D.T.& ..T.H.C ..d.7w.....M6...s.=...7......a(...H..H..H..H.m.x.m.Yq. .. .. .. .M......H..H..H.......w.V..H..H..H..(...H..H..H..H...P..y.`.I..H..H..H...}..H..H..H.......w.V..H..H..H..(...H..H..H..H...P..y.`.I..H..H..H...}..H..H..H.......w.V..H..H..H..(...H..H..H..H...P..y.`.I..H..H..H...}..H..H..H.......w.V..H..H..H..(...H..H..H..H...P..y.`.I..H..H..H...}..H..H..H.......w.V..H..H..H..(...H..H..H..H...P..y.`.I..H..H..H...}..H..H..H.......w.V..H..H..H..(...H..H..H..H...P..y.`.I..H..H..H...}..H..H..H.......w.V..H..H..H..(...H..H..H..H...x.....O.$@.$@.yB ))................q..`N....h,2........HII..o............k3...\.r....x.......|...Q...h^..H..H...$&&b.ix......^.w..p.>}:..N....P..[T.!t,O.F.$@.$@...x.Dl.........Err...0..FA.?.y.. .. .7$ .P......G..I.P.:i.X$@.$@.$.h.2....b........m..M.6.K.n......a.3..I..H..H.@..8q.#F...s.......S....
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:GIF image data, version 89a, 15 x 15
    Category:dropped
    Size (bytes):885
    Entropy (8bit):1.656279852382666
    Encrypted:false
    SSDEEP:6:PvV+Z5MPja9qWqh/lVuQXNTko9WTztXeg3Wn:PNA5j9FIhBko9WTztn3Wn
    MD5:F02E1D274CCDD7C1B34D2B8ED8E0EBB2
    SHA1:A8A641E097726AA4C983B8C646C0F2BC9C0658EB
    SHA-256:6B37731B8C7344CA1E8DA3B3C70D15A554F635BA9CE71A8617B89852237C9993
    SHA-512:9FF83A4094301704A4ED1A976C2133DDAD48DC50E96591A528AFC3CBE91EEFC6F9C7122B61E89046E72D2B467C5E434F7AA14CFA789535FD890A349C5B93B1C2
    Malicious:false
    Reputation:low
    Preview:GIF89a.............)))BBBZZZkkk.......RR.ss..................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................,..........Z..........(4p.a...".px.....(..........X .d..(..X..eA....|.....P2H.R....Lr.h."F..%.4..i@..;
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PNG image data, 239 x 127, 8-bit/color RGBA, non-interlaced
    Category:dropped
    Size (bytes):5682
    Entropy (8bit):7.916273307517291
    Encrypted:false
    SSDEEP:96:z4nuQAWXwaEwKG/eAf+XpNlV6RSX8smXoUHtz+AWspUpkIEuecSUO17wASL/uFN8:knuqjEw9df+X7wXhtHpUJnecSU+sAE
    MD5:BCEAB682F5AD0D3B28476B9E3FE3B91E
    SHA1:9E73BF1D29E696D7E6E5AD89D788A25A5819CD37
    SHA-256:96D11BEAC7B568FA2BF30EB6B161663F5110B887D3951AE2EB8EE484E15CDE54
    SHA-512:E56C8D3B3B71CE14CEF63933496BDB2FD928943CC8497A6A0DAF459145371548ED31C1A513787DE241796D51B61AB7B2DCFA397E1CD3837C403F755A61C2128B
    Malicious:false
    Reputation:low
    Preview:.PNG........IHDR.....................pHYs..........+......tIME.....*..l$.....tEXtAuthor....H....tEXtDescription...!#....tEXtCopyright....:....tEXtCreation time.5.......tEXtSoftware.]p.:....tEXtDisclaimer.........tEXtWarning........tEXtSource.........tEXtComment........tEXtTitle....'....IDATx..kl.U......v..'.8...l2.......b.....-.ha5..j..jv....VZ>..X.Y.........CvV.Bf".,.L..../Bl...vW?..~0.........]..I..u.....[...` ."p..pq.l.. ....6.._m'..p../A.....UAN.@Q.`,....l....".......8..).....:A../Y....N...99.........w>....y|...!.......LQ...: ..i7..6...x.7...B.?..8....o/S>...../to...{.1.y.SI...H.v.b...w>..{..|c+.c......?..>.tb.. YV...}......c..r...q%.S..@..+.c..wo......J..\...b.....1.(..j0..!.."...,.g#...e..Q......T...T%.%...Cu@.m7...P...1.L..:.^..`.b..+7..(...8..~...{.fU....?.O>..R.....'G.y.&..hg..h...EQ.J-..8D.....\..L&.t:....R...P......u.F..$.Yp+jk.H.._.v.....nD......@.J.W......099eyp6lhF]].7.*...4>....5aliiC}}._M^...<.P.....^.L&.K./`..q.Ek..v..q...5h`.n...R
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:GIF image data, version 87a, 13 x 20
    Category:dropped
    Size (bytes):969
    Entropy (8bit):2.7311193052817644
    Encrypted:false
    SSDEEP:12:7pQvqcfL1vps3loLDU3uztBmWcm8A3cQE:7WycjMSvU3amWcmzcQE
    MD5:878A348A754F3F72F2CDEF77C2A4EE30
    SHA1:0E3D289243DAE3EA6022B37377A4A40B0B08EBC2
    SHA-256:762C2F780ED810499298B47B3D37EACE98817EC2D4E217D5A2214C773744C7CF
    SHA-512:A544D4BCFC74324A98A96A99B39775FBF8DF00501F8EE31785B7FC620D767CB09C9566D1B751556DF3C3F3871C9522CCF78D4BDBE7E8B81C73B8566305D8CD8E
    Malicious:false
    Reputation:low
    Preview:GIF87a...................!!!111999BBBJJJRRRZZZccckkksss{{{...................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................,............;H.H.`...$P.`....."..p..E.. t.......t.........|.A$.....<x.........`B.....<.......U...O....L......2<H..A...00@0...........Y.....P......v .........+`e..s..D.xh......p....;...;
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PNG image data, 669 x 329, 8-bit/color RGBA, non-interlaced
    Category:dropped
    Size (bytes):73179
    Entropy (8bit):7.971727094323448
    Encrypted:false
    SSDEEP:1536:3Mx83sCoYhN1d2v/Ljy6rPqSRGsRDbwKI53RUpPMju:0l9YhNWv/3y6riODbI5B/ju
    MD5:E53B64872FCBF134C2C8AD4D4B3E5DCA
    SHA1:C90863BEF6F98F6BF6F6FF112E48576662DE686D
    SHA-256:0A7F6337B5A94FE25E89CB18AE2B100FAC2E581E038A7374300A54A780D126B6
    SHA-512:24298732FD72EAB5A2E1E6E7EBC8FD78222FDFDF36C6733A24CED6B581326EF08A047B12D7159A082770A27AD4688174E07542E409FB8C2EFD9E9156D5A8E054
    Malicious:false
    Reputation:low
    Preview:.PNG........IHDR.......I............sRGB.........gAMA......a.....pHYs..........o.d....IDATx^...w.G...........=..yog.....}o.;..Q..b;.Z..7-G.S...$......{......B..U(..T..Y.. ...%.v|d.defdF../###....o......A..d.A..d.A..........y....H$..D".H.......tJ$..D".H..R:%..D".H$O.)...D".H$....N.D".H$..Sg.t......NFF..{........>.....NBB..dx....hhhp]y..D"...f.t.....Kyy..{...0._.LII..e(....www.\...a...s.....$..D"......t~q.N..\.?.../.tJ$...o.)._1H... ...!.S".H$.KH...AJ...)._.)...D".[...P^..?......."....7C()L...'.M.......l.JJwO.......}..~..Q.J\.JR8.._...n.....@...nE?3.F.Q...,...i.0R:%..D..w'...B:....]...K.......=.>..v.)L../..nl..i.R..3?.O.......U.......<...3.<9.3..u.4vp..~.k..qH.#.../..e..5.6l.t.71......!.S".H$.K<3.Y^.......1.[.Y....~........Jb.%.......<.!.ye$x..GJI.~...../.)..F:...|v+..."......\.YF..O.......p.+...@>..A....<w.%......B:.........Z>..iJ..c............~o_#.g..C.l.9..`..!.O.)...D".[.;.._.._s.....p.........KrJgl.......).....G.S...t....y.."..D/...=2.Z.7
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:GIF image data, version 87a, 24 x 24
    Category:dropped
    Size (bytes):1258
    Entropy (8bit):5.537567907924503
    Encrypted:false
    SSDEEP:24:Syc3wQ7OwGaiYGNPuWeQe1ZqJd9UtyLm8z7leGk/zfDkf:SyDa8RuNQe3qJdqki8cv/zYf
    MD5:AA47A4D5076ED72497ED6C75D1D73F3B
    SHA1:88830F24C31B17C27BAFF603DC7BC83ECFA27D68
    SHA-256:0A6800717FC8B07827D9DE5CE70B6AA4D4AF9BA076F924D6256A9D8996E741AC
    SHA-512:AD375EC42014D60F43338309229B4692E4758173E627202730EAB302D752E4E9983050797ED463ED716B8B5677946A187E5C67C5E379593D204F5C3069716546
    Malicious:false
    Reputation:low
    Preview:GIF87a...................!!!))!)))11)111999BBBJJJRRRZZZccckkksss{{{....{B.{J..R.......{J.{R..Z..c..c..k..s..{.......kJ.sR.{c..k..k..{..k..s..{................J1.9).91.ZJ....!..)..)!......................!..)!.1!.9).B).91.J9.RB.cB....cJ.sR.{Z.{c.c.R.c.k..s......{......s......{........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................,..............|A......*....#.p.ba.1l2j.......\..&.,&Q.Li2J.6 ...`....\n.....'m,H..A..... U.ti..<....A ..G+(..+W.C....A...n.T..V...j..x.......<.SFC..A|d...J./e.<p ...9f4.1#.....%+.......2h@'.4in(1....4?D.IC....
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PNG image data, 698 x 330, 8-bit/color RGB, non-interlaced
    Category:dropped
    Size (bytes):81192
    Entropy (8bit):7.990145480194172
    Encrypted:true
    SSDEEP:1536:FJXgRG9ht61xxza7rV8SQbSS5Sc2uyRLX8tIvmLhDCKfZKhm1UZ7mFkZVhLg:FJXNQxNaF8S8ScAuEShDCKfQ4c7w0hLg
    MD5:F9A451CA796EE843BDCFB57214C36144
    SHA1:F78FCCFEB76B14777524B32EA4B6A2B4597FF01A
    SHA-256:01FF2B038DDCED670C4AF08DAA34A2CC891376705ECD9736AF048D068B186F62
    SHA-512:E51251288A57392095E778B5D45BF1EF7BFE7ADC801E8859BA1C702C8E688348D65FAB943436EA6FB4E506E5111038FB5DD44E54D1BE67334A4757AE2830FCC6
    Malicious:false
    Reputation:low
    Preview:.PNG........IHDR.......J.....}.k.....sRGB.........gAMA......a.... cHRM..z&..............u0...`..:....p..Q<....IDATx^..x[.y&L;.&q..l.c'Y'Yo...n..xc;...W....{.]b...{...I....H..D#:@....#..E.D..5........{.9s.b..<....................._~..W...+_..8k..._u.R....W%.W^...v>;..3...|.....u...^.2...v.2m../].%_.+#....a......W....{x.X......8...........?....l.c.....;......u..........6E.E.i..<.)...<...J..^....<>U..n.U..9...W.O....._\T.....'J.O..pt.....%..rD.*....Od...~.....5_?.....o.T}..w.Lz....u.k..D...x4.B...g._.$....w................3...9.....1..F...,....G.Q..E..a..^.......I`.....c..4>H7.M5.L2....L...=...,M.1..|2M....i....+q.K....._.p.+._U.:..>..4..0..7..K.{u.....3<....-].~.ta.@-..7q.k.@nq.L...i$.2.tJ.4...|gO....o.x|.poJ<>..xK.....;.._J..#.......s...x.....|.9.@.ys........(.."....u...?..uo2..z+.t0.....w..^?o....7Os?......+.\.1}z...u./..~tF.OG...4~......LS....S..O~ ;....I?....0.a...q_...%jAJ.....t.S.;..H.........]..O?.......c.\........\.2.
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PNG image data, 373 x 211, 8-bit/color RGBA, non-interlaced
    Category:dropped
    Size (bytes):14222
    Entropy (8bit):7.931235696174882
    Encrypted:false
    SSDEEP:192:SSfxZTBK9CBJakR10xUdL3f8iYYXv+1vcf1btaM6MI3WmBWHzQ9mceRs2QYf:Z9K9w7Ru83thwc9UMmnBZ90GE
    MD5:C10D52C629B9507FABD1376D590758C9
    SHA1:8B214D9E55C8B4BA7FC773CE2B402841A2170F94
    SHA-256:9A6EEF97280F212F03751FE5C08C81CCDD4D151189F267D38F6C1F29F3B96F01
    SHA-512:F59CC4D367D6C9C50A511729361150E1242A1C1AAAAF458DA09D6FB6D76F037676D50741E1EDBC66DCC6D8477A37CC4DAD945C38EFE4EE0B3BF0AB2DB4C2A712
    Malicious:false
    Reputation:low
    Preview:.PNG........IHDR...u.........~......sRGB.........gAMA......a.....pHYs..........o.d..7#IDATx^........?.z<;.m<.#6...1.....u...i....;..Ak.B.M..i..F.,Y@7HH.x.... .A.FjDc.$....!..`....nV..........U...<u2+.t..].y.&].z..?O'N.......h.}4>>N.....'tccc...3\W..u....@..%..ff......C..'..3g..@.|.2.={V:..i.&...C.@. ......K/.D..>..W...?..k.L.c...ke...e.....>...`up..=.t.o..rw..!.w..mj..u.VM\|....4.......*3....42...../.,.....GV...h..2..hf53...^......Tb.....%.g.I.m.B.....7nP=......:.v.k..j.C#.+W(...].t.Lw..E.......q.Q..s.~..+.....D)...>}...S.N.....[.U...\7\o\.\.=.vn....I..8.`.....>.'.....o...>I...^o.u.y}...e........3B....{.nI|.:..:..v\........a3;.+.F.\.+..........$.. ..Nm.;.3.i..Y...n.s..==3.z...vS6L9P.g....%B].G..nk.$....7.......6l..|.;RCO..W=.4....%.....j.7..*.P.i...4`O......c..n.......w........&.6....9.'i...n.]S...8+..=...x...>*I....H........\.....c.h07.....z..1..h....Gk......<..mP...W.'...2.4S.}.0.7.8.+.0.{].L./zf...Y...
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PNG image data, 647 x 389, 8-bit/color RGB, non-interlaced
    Category:dropped
    Size (bytes):22039
    Entropy (8bit):7.865971299191113
    Encrypted:false
    SSDEEP:384:eqwiMTuGRF+FGm+n0l/Oq8j6QIz2B86JVgPWHrG23wVdPqbZ4FrVp86GMSb:yz+Wn0dOqwkqyWLp3wXPiaxVTS
    MD5:3891FC7ED75DDAD485A0D5FEFA14A98E
    SHA1:47577F2EA01FD5256D9D7F4A7C1B5194954D04DF
    SHA-256:E927E553110B47C000348CE5C4521C8077709F6BA0D6CED553E67EAC5C1EA25B
    SHA-512:4915CCA92822CF22A75BCDB3C1A873419C5E2DE9A0150ED0498B39A7092A8066D0E8F31D476AB1079F6F79E09503017297F1F0807499119D531FD479FEBAD0E2
    Malicious:false
    Reputation:low
    Preview:.PNG........IHDR..............V.#....sRGB.........gAMA......a.... cHRM..z&..............u0...`..:....p..Q<..U.IDATx^......G......;.}.|`.1.g...c...&....6.M2pN|.3...p.cc.A.&J .H....A....9.V...{jU[...3S....LM....i....J..1.7..3."...9.c...y.x.....C.&....1c....%..&.9$qH"1x..........s(........);2..#0$NG.|. 0{.+:..O..8<i.}.$.?.K.wB....s.M&>4.?..[7..s..EVf.1..(.~S.;........................&=.o..3... ....0.[ `H .q..@.U|....2K..q....J.T{...'.Q....wq.+.......q....))..3.(..?..H I. F.9........J.$A.X..s&W.}e..".l....,.q..PH|.3qj..c..7.'..H\.k.....75.@..{k.......?..{.......H..E.~. m.YJ......8.1?.D.....H.B....X.3m.!7..{s.....\...#...:..p.-.......w.6$......pYe....b...lJ|.t$\]..a=34.......y.......>...........~.4..u.c.k......M|...S....K.pQ..1S...S.8w....).....y-.M..W8o../.5....b.n..@.GG...[jz...`.G.......G.....;..t....a.W..x}uS?.l...3..;cSb.FG..b...|.........eeve[...L.........N.....-..@..@..@`t..^..f/....n|.v_yq..?...wL..6.....V....t...?.B.._t._(.rb.....K
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PNG image data, 403 x 106, 8-bit/color RGBA, non-interlaced
    Category:dropped
    Size (bytes):7443
    Entropy (8bit):7.939765113796375
    Encrypted:false
    SSDEEP:192:iImCPcWi5aYkxea/A+u6Y9UzBgd06JKU4Ra+eT8m4KfRZOd:VmWi5adFA+4uzunJRJT8ERZ4
    MD5:6FEFDA6AEC07AFF20B11083C4FBBBE71
    SHA1:9B76348EABD9891D6C8D5CE7C8673F933E862DD4
    SHA-256:94B7358389033281422E14762A3B872AED6F267C6B8C1C6CA603F4700C28CCE2
    SHA-512:7401F7A63140F1FB93AD3208F0534AA1169AEF356E10411ADE4EEDA242867ADFE02590AB849111B750CC2AAD3017B2BB81F3EAC0AA964D8EB4FCB640959DFFBE
    Malicious:false
    Reputation:low
    Preview:.PNG........IHDR.......j.....y.......pHYs..........+......tIME........a......tEXtAuthor....H....tEXtDescription...!#....tEXtCopyright....:....tEXtCreation time.5.......tEXtSoftware.]p.:....tEXtDisclaimer.........tEXtWarning........tEXtSource.........tEXtComment........tEXtTitle....'....IDATx...y|.....[..e..._.m....pls.V......&...smB.@ ,l...l.2.pz6...92.s.....p.L..O06>e.,..........R...|?..z.}...G......!..Y......J.@[.s.....nC)....;%M........1!l..D.&.....0.....F....b02......J..........x...**...._..-4.S....@..L7=.F.y...#..=..>H..T...^...K.....'PD.k.5.#.`.........._..#.....|....}..B.!.N..S..e......@.y..A..P^<^.A.1.3.ch.Z.W..c^d:._)..Ji...B.q0.~.qd.@h7.*.-.%<..1..m.1.aB.s*..Y4..S.9..........&q.*..K.#.."_..PX.4B0.9..p.P.\.e.h.9b......*.......I.!Do.?T..I&;.AY!J.@..i.P1g.5...@[6J+...l..r.\.,....O...sc...3.h ..+.D,I&B.^...#.:.I.@.Aw.V..?.e....?d(.R....@9g....we.(...,./..f..|..iNE.G"a9..B..Q..mtd.......=.P..R.0:.I...>.....5~.zwu..\.%..%rd.WN2.^0|.]...M
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PNG image data, 777 x 121, 8-bit/color RGBA, non-interlaced
    Category:dropped
    Size (bytes):14169
    Entropy (8bit):7.90177939074778
    Encrypted:false
    SSDEEP:384:9LMmuRzGad5Jpw6LjZKC+DzXtRY3xBIbl7KsgdE:9LfuBGQRjAQ3xBIRdgdE
    MD5:A4938B9006E4A4FFE68A32F578B065A4
    SHA1:326D7D2F63E46B37308B30F002EA11237FAB7752
    SHA-256:C7758F12A0BE4C2725FDCD329A92829C7B03B35CDC7558D0988C01C04830B52A
    SHA-512:4BF614C38DA236A09F7D86E2026B84DCB29249D053F56B5AEE6E698D3C3C05E44F84C7E49D5772AB6D7B0D7927B551717F3EF61249AA5D1F1244A297612DD559
    Malicious:false
    Reputation:low
    Preview:.PNG........IHDR.......y.....rQm.....sRGB.........gAMA......a.....pHYs...t...t..f.x..6.IDATx^........@@..L....1!R/.b..2C..,.n..^..+Iv.P/..,..[.....U...*.2RD...Yw...I.".! .3...P~.......9.}..O...wn.{.]u.....<.......u...]#. .. .. .. .. .. ...C.._.....;.#g6..^>.gW..@..@..@.....@.!2.T$.1..>..@.....5.............5`d..=..pf.&&.`..........(.........HD...D.....NH5.t3.C......A&. a.....%..X"P.? @.} ......@.. H(.[......(T.S @..[AR........ HH.)Z..#....w.....$......(-...@}..G.....@Q.Q..*.......M.@*.......%.J..z.DRo...$$B.JUB...l....= ......@....$<..%..C................$....9;.00.-`.l..R......d.@.k.n.6...>u3M.....3...3.tKS#.......eC.LJ.M...m'.p..3)l..2.....I....(.._r......:tL................61k0b.0..8..4......9.p?m.....z.NZ.v....<.g9d..4....:?."&.rWv...--.xf...3...4.....@m.H=Hp.......$..A#8@.:............G>U....6..D..+E^.....(T..#@..C.........H5H..RG.x....=.%f.88...$..a.<.....A...]DK~L.......n.'.Db.a!...a6.@.....Z'.........n;[.s....[....w.(.....G....
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PNG image data, 363 x 354, 8-bit/color RGBA, non-interlaced
    Category:dropped
    Size (bytes):12326
    Entropy (8bit):7.886600697641364
    Encrypted:false
    SSDEEP:192:ql6cu7SfCTwzG32AYdYLnaqvgyHJaWtyEGr6u3mGGHkE01IKpZ3baccc4C5Ymh1E:6/a320naqvgmaWg3WRHyphbGCmmI7
    MD5:6BD9B290E6D444F05558C0157EEE2F7D
    SHA1:CE1FA4781C2D00630DAB050CFD2E245ED92A99FA
    SHA-256:E70FFBBDDAAF324E2CBC071D46727AF8EF3C92008007104DCFE4EED17CA7E0CF
    SHA-512:3992AB11EE56293149B14C848A460392C980287435055FDECE5E0DAF1DE67C0E6909526055F33FFD53B4D4B9BBF4BAD7C81241C026F538CBBA3FD5998986A006
    Malicious:false
    Reputation:low
    Preview:.PNG........IHDR...k...b.....0I......sRGB.........gAMA......a.....pHYs..........o.d../.IDATx^..,Gu...!.d...I.<'.....DJ.(......=6..x.p...b.$.D..G......!&.X.......F.......Z..==3.z..F.....W_..Z..y.f.....0......... ......0................8.e....`....QU`..(..d..I.*T.....5d....`@.. k.NBU.......!kT.....0.Y+p...U....d.Y.....P...Z..PU.*0.. k..U......@.....BU..0.YC.*0...`..V.$T......]d}....mu5...].\...........%..jU....w..z*..:k...k...s.v .0P,Y7.}!i.M"s.W.c.m...,..*.z.9....'......c!.C.j.e.......w..v...M......"..k.r..Y$..........kl,M..}m..32.....j{z}a.C...Y0...k.l...`..V.l-....D{ ....4.$..C......6;........#.x]....o...xM.!.6i.9......_j.%..^L.Y&).yY.y.?.....].k...1$...RX%T.*n.p.r.q...HD............Iw.R.[.K,.SV...B=F.J.3...0.0..+.@.)...21..m]..2I....+=RK...}H..[..I.smt.H.?..&..&.T..u:....&.......d...!..wM<.Q...)..C*k[wG|Rh!....p........_.>...c...H....;.^..z..t r...dc`Yd.<@.......oo........D.V......%...../._.3..7....~.}.p6|......4...[{A....u.S.^.oe.5.......0.`......
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PNG image data, 498 x 419, 8-bit/color RGBA, non-interlaced
    Category:dropped
    Size (bytes):32021
    Entropy (8bit):7.927400834510535
    Encrypted:false
    SSDEEP:768:V2a1IoNiEqqXDn/hiPAhhaVx6GnZUbni2r/78KNRJ:V2rVgDgBV3+f/AKNf
    MD5:5FB3D32B730A2B45C2BE823B2AC921B4
    SHA1:0A00AF7C32D9FACE8FAE4240CDC384BB1A7D89D6
    SHA-256:460C204B4F81F8CA30CDC9ECFBF10980FC8E7A061F97AB0A29854F3EA0642124
    SHA-512:3F93B952C10EBC102016196DD55F4190416E6AE813CA9D2B99F5C47AD4212DA1E1CFDBE293BAF283F2429E0FCBAFF05B5BB96555182409E5A2FB115CCDEEA67D
    Malicious:false
    Reputation:low
    Preview:.PNG........IHDR..............C......sRGB.........gAMA......a.....pHYs...t...t..f.x..|.IDATx^.{.d.u....@... A. ...v...($.......8..!mST$/..HL~.."-0|H..q9.#..I....MR".....r...)...]..;;....i..t~.....{o.......P..u.u...9...../R.V...Y.....G.....i...s.Nz..h.."m...2..@......@.u...}.v.e.3szbb.......?s...8qB.].v.o.I..-B........t.:.#.x....w..A..>.:t.*.3.GGG.._..v.w.......H.ep....._.L...K.&q.FO..\......dJ.|...H..g.e.ea+.4....1.>k]D.]...]..TW\f.....jO8?.M....z....^.m..E.q....9.g.{=.....e[`.3....>.......*.N.......[h...!a.<w.1-,,P.R....>??O.477GQ.;[j:{.,..GV.t..i2.S.N.L'O.$=.^p...nI2r#.s'PO....499I...:I.CI2...I.&.{..1.....y.,\&.+..."..r..qV.r..&..oR..:.r..I.,.5.._....m.K...|.Y_z]..2.Z...t.{...8..vt..4..sdY.Q.<....M..T....}.~.jg...>..o.e.....\f.4.Z....i.&Ax>.^......N.5J.Rr.E5H6PI..(x..b.z...........88.T.K8.0.p`9e.y.NTTg*..e.E.....Z.Qr..r.}..w.T.K.....L6.m......kt..Q...C'..s.<...$...;.8..c<$.fn.Px...W.\I...g.pL.`.._.,.. W.H5j....*&oP...Gn.
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PNG image data, 750 x 187, 8-bit/color RGB, non-interlaced
    Category:dropped
    Size (bytes):23015
    Entropy (8bit):7.952432336464197
    Encrypted:false
    SSDEEP:384:ecSU8YWPDDUJ0/7el7Ra2YAE8aau4o1vaYcNHDtotR15Nxpz/svfYBG:52Ym+1He8avLGjyXNxpz/svfYBG
    MD5:AC0C43C9E2B742E8E964A60D8651F97B
    SHA1:E363AFD8E6DC4331886BCAB2760244D424576776
    SHA-256:6E03C23EF6920C1CE0237A8399D8A288DCEC2D7934A916841DF5011FD0043023
    SHA-512:A0A77EA17292D3C82503C638ED3E8F1E76E9394A4D7422CF922CA264F11D83468C86B04488526EA03DEF1D37668D7B6DAD1D0B4FDD8BC68D34B798D4F0348F48
    Malicious:false
    Reputation:low
    Preview:.PNG........IHDR.....................gAMA......a...Y.IDATx^..XT...1^c...Mr../......5............. ....."...".V,X.a....X.)..t..].5.{.<.O..X.w.yxf.3.....1g..j....E..T.V..5.[......*P.....<4..~.//...B.....RPs..O....J*......w...[.......S.Ww.@.0...."...UM...@.X....8J.../........0mA.Y.../-~.o.....!.dW...*.H...... .Qi.1.MW...:.M3........-o.....D.....*.....*....$#.."!.N.i.....J..... .....&....GE.2.Lr...o.,.$Y.zZmR...)Y$..T...n....b....@..N$.....kX.!..P.T...U.....P.Z..$.'...MH.f..IE..T...6Ve1&.bx...y.4el...#3..p.:..&....ap......b.e.....c1...0:.b|......(....Q.mt.......@.P.T...G....!..6....@...ja.B.kyi.F!aP"..$@.f.k...c..1T..pL.....B.1w....(3.ii LSB34...L.....8DA.....c@.J.H.....@.P.a..TX.P..T....d.X!.......".).4...L..+c.,C.`.s..-..#.2........*..o.[.N..LW./.v......*P...1\>yG.<.X..rA^2.._.[F.!%k-..j.L..*...5.kt...cZ\.&..-..B....V&{...1Weh...A0..%M..@z%.#UY.z..#...../......--V.j.g.X...*.....b...U]..:.B..*..^...mA....i=%...<.KN.........H...0'm..T...[K..q..&t..
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:JPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, baseline, precision 8, 321x321, components 3
    Category:dropped
    Size (bytes):10135
    Entropy (8bit):7.749834139232858
    Encrypted:false
    SSDEEP:192:WerKMWSP5zSq74r6ngpekQLGVBlk+9VrCVcuXiRlz24YSXibaK:hr/d742+ekQOJrycuyTznXibaK
    MD5:FC87B508004E85E401FB16DE9244E3C1
    SHA1:F28394D87EF31BCEF1A71D5C985F2C27AABCCD13
    SHA-256:692E5F1650668B6B0E7E140D884F4D299B5BB5BC18166DF7EAAC4011FCE6DCA5
    SHA-512:B228EFC91644DFE7877AAB4F1174B801DBD9B265CEA6042FAA08283924BE64353B1261697D829AECCD59AC6ED719B7C20E81A11909D984347BC5D41AE92DDFD4
    Malicious:false
    Reputation:low
    Preview:......JFIF.....`.`.....C................................... $.' ",#..(7),01444.'9=82<.342...C...........2!.!22222222222222222222222222222222222222222222222222......A.A.."............................................................}........!1A..Qa."q.2....#B...R..$3br........%&'()*456789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz..............................................................................................................................w.......!1..AQ.aq."2...B.....#3R..br...$4.%.....&'()*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz....................................................................................?...(...(...(...(...(...(...(...(...(...(...(...(...(...(...(...(...(...(...(...(...(...(...(...(...(.....^../.i...7F.4..P..#._..F...u.....-.d..o..:...r.Q.....x.k.n....}/?..>.1P..3.7?.....cL..n6...}#..._W..]..U.......ed.....e....,dB.......?..}...\..o..=o..U...x.S..u8. ..+..eG.d...~.z.5_.k.......&?.j..>..^.....j7w...D.5..d6z..z}yO..wm.Z.f......j0~.y......(.
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PNG image data, 498 x 39, 8-bit/color RGBA, non-interlaced
    Category:dropped
    Size (bytes):2460
    Entropy (8bit):7.771511832304445
    Encrypted:false
    SSDEEP:48:VDOrY29vfs5VFMaRM8Gs/C5noHtXIRjiIwHMaGzULQfGL5ySz:BsaTRM8Gs/NXsjiIwsaCnfIz
    MD5:84C3C62F314191357F50A85C3FCF5F6B
    SHA1:B20127B6F68E451F1C235B81B8D1A3C98A6BDCD1
    SHA-256:4AB99A16083CA61AC2A7BEDDFAD294AF7B4CB818BD3CEC114B9365C88B0B7614
    SHA-512:6F3D21B88A16A90186F307888E8CCD3940C4875FB16DCC3B6A281F9C824C05133A11FDB406BD65F2E7E88CCCED91144E9A25E4A1D9B031B475345ABB62C1D62C
    Malicious:false
    Reputation:low
    Preview:.PNG........IHDR.......'.............pHYs..........+......tIME.......O.......tEXtAuthor....H....tEXtDescription...!#....tEXtCopyright....:....tEXtCreation time.5.......tEXtSoftware.]p.:....tEXtDisclaimer.........tEXtWarning........tEXtSource.........tEXtComment........tEXtTitle....'...gIDATx...M..f.....dwv'.M.]@...."!5R.."R......C".r......*$N....i.H.Z..R9qC P.,-RY.,.........x.......s............=... "".V.....w........]w.DDD...9..Q.........9..Q.........9..Q.........9..Q.......X.....|...|.A..W>...KH.9u..o.`Y.l....i8.31=./....i.G.UQ..I..G.m..x.].~.....u.4...p..E....!..$l.}9.}}.d......N4...n..O..`.....^.|....?.u.?......i..[.K.3a..`...=.k........./..s. "..p..3O.k_...z..g..3..q.=.C.D...lm.q..OBDA....ND..g7....,..&..d..`...}(.._.q.x....].y..eY...W...(.w<.;..x.q../...O..C.{.........!....B......X6d......^^/.9dt~c....0e.&Y.}~c..r.PT.J......b...a....(..y..?..We...=[...........ta... q......64.x....M..U...6h@...n.wl..0.sY.'.<".%>.2i&@...3.....U......{.V...
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PNG image data, 323 x 316, 8-bit/color RGBA, non-interlaced
    Category:dropped
    Size (bytes):12365
    Entropy (8bit):7.924979218559118
    Encrypted:false
    SSDEEP:192:V3+MT8R88w7foxoSqueaj5dJVsF8WBzZwELm3ZHPCgPIsPkCsGFmTWZis6ZpE:VfDeVJeGPJGuEL2ZHqgpiWOE
    MD5:86BBE1308F0AAF197B62A751764031CA
    SHA1:DD7B2B4530671397B5CBB5672C993A8D01ACE73C
    SHA-256:B9FCBDBC25912DE2E65B5D43360AC73AD123D2932FD9561387DB5707F4B32012
    SHA-512:597437380A1443F9A9F7683166A0C2A48CEA37739857CB38207C448B28ADC5849B0CB90FAB4406FFDA10C5BBB350C0767787ADF74981FE5DEDAE1C64AB9D72B9
    Malicious:false
    Reputation:low
    Preview:.PNG........IHDR...C...<.....ZG......sRGB.........gAMA......a.....pHYs..........(J.../.IDATx^...P..'.g@. ,..8..s..D...B..NJ.U.h..+.......w.U..6...nm..r...8A..9.M..u.S....rU...vLle.....8..b....@s.WO.....3.C......f..?......?..J<..;).~...{./..YV....(j(.....!...T....!.O...sT=............:I.......z.......=B...3p.1D....l.._.<_./...>.S.v......m..{...q..v..m}~.#[.._'..9...t[S..9..2.D.N..w...;'..o..;V..B....|.4}u.z .6..8+.r...vSu.N.O.*.K.'...w...g.o..g....-..p.w..{.vi..z.W.....j...0......wt..m.>g.p.....x.Z~....lk......Ph;......<.N`.`1[..6....Q.Iz.......rf...7..gh...D./.Qb...;Q..g;u.....A.O.....'v..;N?.?.W..5.....Q....}.9.<......y.....n.....y......5.]xEW.hJ...9..<<.........j6..o......h..|...z.....kKS.P.Q.............u.z.a..lN5..~\....AY.6..@.....4..F. j.....#....i........,.1..l.|...6...E..t..A...uZ..8...2Gl.)..P..-.S6.I|..dyM.ky=. .!..(....m~..dt..H..o.........N.......!.....?<PM.=0".......k>}..P.L.q".7.. m<!...c....q.o.v.M..kC..|x......"'....=
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PNG image data, 528 x 107, 8-bit/color RGB, non-interlaced
    Category:dropped
    Size (bytes):5582
    Entropy (8bit):7.794454314079811
    Encrypted:false
    SSDEEP:96:TYd1TgoiYtqG+joNRLCBa7XGR5fYd6W2itPOIS2hXj+0SVgMl5VumNxfYZ8:TYTgo9t7+joL97XNn2isIS2hXjKVtb
    MD5:16C8446FE344D924AFE9A46EBB064FBF
    SHA1:89BE67F2F7E2689BE0979736850D1A1357AB4200
    SHA-256:227C0CA2F877D03F05834E57555312FF5CBCEB96CFBA9FCB66D80721565BD220
    SHA-512:E8A9BBEF83CED9887547AE13F36F7B315A5A7A7708DCAEAAD98AD37DEE977103DA0A1CC9794AB3FFD5BCE66E198E55D79B363F9AC1AC88C9AE43CAB00C4AFA0C
    Malicious:false
    Reputation:low
    Preview:.PNG........IHDR.......k.......,.....pHYs..\F..\F...CA....tIME.....5)..M.....tEXtAuthor....H....tEXtDescription...!#....tEXtCopyright....:....tEXtCreation time.5.......tEXtSoftware.]p.:....tEXtDisclaimer.........tEXtWarning........tEXtSource.........tEXtComment........tEXtTitle....'....IDATx..Oh.I.._..@.2 ....!.YH/1X..".>L.....f..{..=e7..#..O...B.CX...K..mX..a@......L.s.$7..:4.;.T.W.Qu.%u[...G...~.U.>]U.]s..8#...`..3m............0....Z.0...h.............0....Z.0...haD-h............x.....).-..7u....4...../..97m...P`"..i............n#.^s.....IDAT....B..._..^.~]),.U.K*.....3.g..@..2.]....8....6;..`s$.r.Z.j..`6.b..M...m.c.'.?(WnyP .+..cV...0"./.u....2....^5O..=z]8D......0.0.R...Q..K.L..L...VF....dN.}.2.o..;....(..6&b..n+B....d......k..Dn.H......01.Z.......x.<...S9jG...Fa......t......h.`..y....IDAT............0....Z.0...h.............0....Z.0...h.............0....Z.0...h.............0....Z.0...h1.)Z..0.4..O...9+sB...>0.p..O.pYA..0.0[..".C>3..'X.Z.....:`*....
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PNG image data, 322 x 112, 8-bit/color RGB, non-interlaced
    Category:dropped
    Size (bytes):5961
    Entropy (8bit):7.945621518332899
    Encrypted:false
    SSDEEP:96:AXkU8DreMNF9C38jKKiaIa/s7l9QoT1NKjboEEGD75BFCI0Nxzmum3lhz9:5jDdNK3AKKPn/fymjtALKumlT
    MD5:65627672958CB4BFB0BE36AA5BE0A657
    SHA1:9A38A637ECAFD3945209D7A2D45EDE11F1E7A9C8
    SHA-256:A6EB4AC33614F39D1BDE970661BC6B5BB14414B0EEB3E0E7AB73F3655CB4A69D
    SHA-512:3950CDFEF8CD5D91460A43A25F2A09C3FCEFB2C63431CF8D1B4C9BED2F62C0946A6D42BB3944E7028E8AFECB7F738C9C4D24372E752A46DF478874583693B04B
    Malicious:false
    Reputation:low
    Preview:.PNG........IHDR...B...p.............gAMA......a.....IDATx^.].SWG....z3..k~p..L.I.&.%..c.h....8...*A.& .........E..%..#....E.1.T..i......w...{..-...{...O..9....Iz..h.....c_.w].Q.....W."...A~3;..*3.WK.+c5.}T...}e.../h.s......g..XRy.:...+........^..=..x.]D.m..,..6...uxO[.O.U<.^e:....1b..a,..<...i.....D.o.W1S.-.n...54..)..E..r..........*.2{"..0.x/1..[..0.1...fv....|%.....C9..g..X..n..7...z2.K(......I...l:Z.3..+=...yO..7..W...c..3...Bx...E."..e...A..g.WCd.ud.l.XS........M...,.."aD?4S..l!.I9.....b.X.4f(`Os'.\.1......N......._..<[v&.!p.0..OB4.....|U.3Z...5C.. `..|......a.."...q.?.e.5.#..*.....Z&....O#0.2...LBf....{.#.%....i......z.b..gG.u.i.2....q..I.G1....:.4_..l...Y.w..F...L......?.>22.f...7...?z...'.}...O..Q#.....b..x......];v.q._.$.&m.........o;._...].............7o.=w..i_.@sm...[...>Z..ryf.....N..F@#.9..h....o..:.c..M...}\ul.e_....e-........Lo<...."..1Ck...3...?|.p.}.'..e/._......{....9^{.!w......'...5..d.8.aT......&.L......q.y...
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PNG image data, 918 x 497, 8-bit/color RGBA, non-interlaced
    Category:dropped
    Size (bytes):73733
    Entropy (8bit):7.933092876911331
    Encrypted:false
    SSDEEP:1536:pxVWOM58IVjwGjpuXMk2JoUq/jvYQNTDgVXYpWgIOE/mjSLeSAJxrhb:zVWfygjvpu8shJWXYs//muLeS+xrhb
    MD5:D320D5596F40D38324BD6C798E4D9E3F
    SHA1:18FD10EE8CE4D05267438B4340777E6301146AA5
    SHA-256:495E7D569CCF5BBDE538F134CD2422CAAFBC358BF279A6289D896525F6B5278E
    SHA-512:9A245C6719C4A4167B84AE8FA6DBF59D8DB2F0897AD82DA706334D42BA3F354D63AE052AD33FAFD7CBE110B2ADB3A1580ACBA9EA00FF96BC95397D9CE2385283
    Malicious:false
    Reputation:low
    Preview:.PNG........IHDR..............e#.....sRGB.........gAMA......a.....pHYs...t...t..f.x....IDATx^....oUu'..)x."..i.~C(.b .HJ.(.....tBGTP.(Q....li.[.h...iL.C#.Q..6..Z..!.V..h.....A.b..d$.V.A...|.[.........u.w.N.{....:.|.Zk......e.....!`.....!`.....!`..@`e.v.!`.....!`.....!`.....!...4#0...C..0...C..0...C.......Q....!`.....!`.....!`...F,....C..0...C..0...C..0.F!`.r.|v.!`.....!`.....!`......K..C..0...C..0...C..0...Q.......l.....!`.....!`.....!`..l..0...C..0...C..0...C`..F,G.g7....!`.....!`.....!`...4.0...C..0...C..0...C.......Q....!`.....!`.....!`...F,....C..0...|.{..:.5....i.....eK....{..'W.<.....'.0..N.z.5........b.g.3.........~.uG.ydw..w.~...>..~.g..~..:=...V..!`.....!....K%`M.!`...-#..|.;....@..1.............i..5.yM....~..g>.......5r...s..Bv..v......?..T...n.......\....z.........0...C..0.t.0b...I5...C.i..?..._....$...aD0v..a...SO]#...?...x.$....wg#.....)=..,S..0...C..X...X.A%....!`.,......g*.SV}=1...b....D.o}..W...M.}........\w.....~.[.Z...a
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PNG image data, 589 x 348, 8-bit/color RGBA, non-interlaced
    Category:dropped
    Size (bytes):31749
    Entropy (8bit):7.914022767510723
    Encrypted:false
    SSDEEP:768:rhUFrorDLEGPtiX30s1CKDAXi2WgZ2Mun6L/3NMiiJpNpUDVs53nI4:dVrDNQ30PaA8Muns3+iiJzuDAD
    MD5:714355A7D04E768DD9B4DC91DC1E29E8
    SHA1:7A330716D8073E42ED405B7715218F3128E52BC0
    SHA-256:55EF6E6D324EE2C5FE125AF6BA5CE29438EF0B0FC9F29E74ADE9A423A00BE11C
    SHA-512:8E4EA74E232A57E51659945E86F06BF8268F58C2251C551CB76C0C1C6CF96EA94E324CAD6008717F79AB0B6E9D48A88BB465957E6F4268F39D6C0848C5DA0096
    Malicious:false
    Reputation:low
    Preview:.PNG........IHDR...M...\............sRGB.........gAMA......a.....pHYs...t...t..f.x..{.IDATx^.....u..y.{/./..u.....r.%.......Q....f.A..)B`[6...,..d@B`,...YBB.... .MHB:.u4OH:..&...z{U...{.]....|...9..U.....^k.....i..4o.<.5k.M.<..y...9r$=..C4d.....{i...t.=.....{.|..@...4..@.M..f.f......Fc..'.|..N.J/....?.2.M...*M.6.....Q.>}.K..0.......h....ZN.?..O.[n..G.=.X.Ns...e..8.t.]w....G?JC....G.....+j'N. X..*....c..e..r.....#G.P-....T+;t..U...<HiZGG.U...8@6.i.y.6....r.}........i...c.z7.....w..8\....K.=.K....7..y..........~.._......?~<=..3.y.W.....>.!.>|8..../_.....J..C7...-X...8.......>....qy...>........_~..^z.%...._.0cZ.m.9...G...y..={6.=..s$.)]..3g...3Hl......L1.u.=..$...m.)...O?M.qjYl.Id...z.l6q.Dr.....8.k..O<A>......1...l...n.^....&.x.0.#.b<&.l.1....Il.Q......1b...c....M.+....i.>. ....<@6.?#..cs....v>.>?>_......~d.../\......?.7..}.V.Z.c.[...w.c..........y?.>M}.m....._....:.k..Q.....q..../x..1.....x\..J.........e.4.N}.5.a._.....4l>4.....g.....
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PNG image data, 710 x 581, 8-bit/color RGBA, non-interlaced
    Category:dropped
    Size (bytes):56081
    Entropy (8bit):7.914654020027739
    Encrypted:false
    SSDEEP:1536:KUiwA1u/mmLTENtqhc+rG5lXU3shhEtAhFC:KUifu/bLTMeGf5itAK
    MD5:9EA86E91EDE00BCC6AAE706700C37215
    SHA1:1D758F627B89B925AE489FD38176A26615B14490
    SHA-256:5AE304DBDF3ACAF323F315F067300E1F673EA1AF57EE216557C033A010D7FC5F
    SHA-512:77A205E1DF6E93E1AD4AC36F1050E8B78ADAC914555AE6FDF4E97C790EAC1153B53004FF4DC2BEEF4BA99E5EE067382EDFDA442073028A7BBFFD1A633355BA68
    Malicious:false
    Reputation:low
    Preview:.PNG........IHDR.......E......L1.....sRGB.........gAMA......a.....pHYs...t...t..f.x...IDATx^.....u.{..K'......._;yI<@;..g0v....vba.N;pec........]0..;.BB.u..f..Q ..$4#a......x...W..V.U..Tu.Su..~...=..v...W....wu6m..{.1u.}..[o.U]s.5.K.QK.,Q.s...w...<.Lu..g.o....[.....7....@...4..@...4...F....~z..{......UW].n....|..;.7nT+V.P7.x...b.=..c.9s.`.h......h.........g?.Y..~5v._~..1..y...#.._.C..o|#.....Fu..g.._|Q.....6x.T?..q.4;;..={...{.nU%..KQ.c.......rN.S..`...?V.s.NUw.c..f..G.....^c.a...(.?.....h./..i.}jX.._Vzz..W....?V.....'.'....X...._.b.E....u.].:..sO.J&(~....-Z..}.Y.......[.u.]Y..u&.L~.,u.....0WGS..O].F#.t..w([".>..o.=K..v.....P..[...?...t..7+.n..&E...p.....^Q"..t..*J.....D.8....j.izzZ-[.,.....+..RQ..+.D#8....2u.f.B~8..9.......8...|.w.S.K.O..d*..^......2.T.W.G...v..]......\...l.2.W.QW......{.....@.i......d"'.L../V2.w.yJOt..D.W.D.%=.5$.u.Y.(...Me.2R...T?./....8.)..Ij....Oy....k...+O.F....m2_S.....e..._&.^".....{.S...Q..E..=.>.^..?
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PNG image data, 238 x 125, 8-bit/color RGBA, non-interlaced
    Category:dropped
    Size (bytes):5559
    Entropy (8bit):7.923386687622863
    Encrypted:false
    SSDEEP:96:7H2QPf3aXr7WI4WDCgZfLhh43laiuRhemIVwDc6O+DaU3zwjXN:7H7iR4oCAPx06c6faUE5
    MD5:496CDB36D42D5FAC59C77652E9D80AE1
    SHA1:7A56F4F61C91AD180A559CAAACB50011DE8F5E18
    SHA-256:C059FB1CD173EAD0D326127BC7AF6B940421B7A891CDADCE9623DB4835B2870F
    SHA-512:C07197971869C4982C667C9BB2E55111135F08B5F624E6F640FCB4DB0D819A9D5060EA033DC51C6570DD697E4B874E37CD29FA1DA8953CE36F3D895CB1099DE6
    Malicious:false
    Reputation:low
    Preview:.PNG........IHDR.......}......._.....pHYs..........+......tIME.....,1..\.....tEXtAuthor....H....tEXtDescription...!#....tEXtCopyright....:....tEXtCreation time.5.......tEXtSoftware.]p.:....tEXtDisclaimer.........tEXtWarning........tEXtSource.........tEXtComment........tEXtTitle....'....IDATx..y..W}.?}..^..v%.d.....d..0&*A.|..............HR.'..D..l.\.E......-..6.X...Y.V...%..........vO....~....~.{...~.;...K... .....7.:.A.<.h.z..B...1..V.d,N.J..?F.D|.Cp.....5MC.4t. P.....<~..jr1.o.(....X.].y.....1...k..%LWk=wl.....C... \..!..v....[...........s;.^.0.^..>q..>.3.....]..{......P..s....c|......R..g..N>w.6.....F.`eI...k.1..R...s.5W...R g.*.R....f`p....N...I.......f....i.i,.D.L$H&b..~.C.@.......F.M.PJa.S.S).y.../..F. ..2(..T..*V. up...s.U.P.*.SL..o........0)......#.mt..K_z.%K..\N.,a..J..t:M$2..i...a.&.d.x<N4.erj.H$B .......0......g.....B$R.9.R.].xi7...hll.p...J.u%655q....;f.....T.......?Q..bEg7..-.{.,...hjn"..&.O2z.,'.O..od...hii.0..1.l.f.Z_nu....P(.R.q.....7.
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:ASCII text, with very long lines (2158), with no line terminators
    Category:dropped
    Size (bytes):2158
    Entropy (8bit):3.9502479829143406
    Encrypted:false
    SSDEEP:24:VJBbPDE2hlQdkOCsXI8QpTOsJmfiN3FqYJcUfR62fb/he+/LJIiIUUIdwvGiTWvY:VJ1DRlQ7fzadvxBp/LeJIiHWXw
    MD5:26605E1EE8A64C027406B3416D5C790C
    SHA1:90566B33D3347564540AB293DC58D6210273FC65
    SHA-256:9F65B8614CC62B4EBBAF6BC244F39778709AF54A68574C6C8D0C928693093D2D
    SHA-512:4FC76CC74BC3DECD19600A76FADC1B268704DC2E97E10F70B06EF52C0426853A8B3FCEB885B621932341F7B00ACC84DEA77DC0344EE956E41B3DC2F58E19B607
    Malicious:false
    Reputation:low
    Preview:define({numchunks:1,prefix:'Master_Chunk',chunkstart:['/Content/HOBOware/Alarm \u0026 Readout Tool/art-intro.htm'],tree:{n:[{i:0,c:0},{i:1,c:0,n:[{i:2,c:0},{i:3,c:0},{i:4,c:0}]},{i:5,c:0,n:[{i:6,c:0},{i:7,c:0,n:[{i:8,c:0},{i:9,c:0},{i:10,c:0},{i:11,c:0},{i:12,c:0},{i:13,c:0},{i:14,c:0},{i:15,c:0},{i:16,c:0},{i:17,c:0},{i:18,c:0},{i:19,c:0}]},{i:20,c:0,n:[{i:21,c:0},{i:22,c:0},{i:23,c:0},{i:24,c:0},{i:25,c:0},{i:26,c:0},{i:27,c:0},{i:28,c:0},{i:29,c:0},{i:30,c:0}]},{i:31,c:0,n:[{i:32,c:0}]},{i:33,c:0}]},{i:34,c:0,n:[{i:35,c:0},{i:36,c:0,n:[{i:37,c:0},{i:38,c:0},{i:39,c:0},{i:40,c:0},{i:41,c:0},{i:42,c:0},{i:43,c:0},{i:44,c:0},{i:45,c:0},{i:46,c:0}]},{i:47,c:0,n:[{i:48,c:0,n:[{i:49,c:0},{i:50,c:0},{i:51,c:0},{i:52,c:0},{i:53,c:0}]},{i:54,c:0},{i:55,c:0},{i:56,c:0},{i:57,c:0},{i:58,c:0},{i:59,c:0},{i:60,c:0},{i:61,c:0},{i:62,c:0},{i:63,c:0},{i:64,c:0}]},{i:65,c:0,n:[{i:66,c:0},{i:67,c:0},{i:68,c:0},{i:69,c:0},{i:70,c:0},{i:71,c:0},{i:72,c:0},{i:73,c:0}]},{i:74,c:0,n:[{i:75,c:0},{i:76,c:0}
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:ASCII text, with very long lines (17408), with no line terminators
    Category:dropped
    Size (bytes):17408
    Entropy (8bit):5.26065640178504
    Encrypted:false
    SSDEEP:384:bhIPqWZdtTgjaGz9y4g8eULGn+jQz35+EB9w:ba3ZdtULy4g8eULG+jQz35+EU
    MD5:C4A683CC38AC964A866C8A09717EADA3
    SHA1:94F6A49FAA2AD389B7B5D5741DA9821A73704721
    SHA-256:107D82B93FB9170D37C24F8CF0FA64EC5C5BCE42D2D96CFA59AC99A765C5E5D2
    SHA-512:72EDAB9444D96D9E4D67646DA11E976304C18065724C458A0E6A1690E940DED04BD1CF488E767079F6D39766E74FBAC2CA1E686401D2A3DEBB19BF4001B29EE7
    Malicious:false
    Reputation:low
    Preview:define({'/Content/HOBOware/Alarm \u0026 Readout Tool/art-intro.htm':{i:[169],t:['Alarm \u0026 Readout Tool'],b:['']},'/Content/HOBOware/CSH/csh-CO2.htm':{i:[30],t:['Carbon Dioxide Sensor Settings'],b:['']},'/Content/HOBOware/CSH/csh-add-nw-map.htm':{i:[133],t:['Adding a Device to the Network Map'],b:['']},'/Content/HOBOware/CSH/csh-add-sens-alrm.htm':{i:[124],t:['Adding a Sensor Alarm'],b:['']},'/Content/HOBOware/CSH/csh-advanced-calibration.htm':{i:[25],t:['Advanced Sensor Properties: Calibration'],b:['']},'/Content/HOBOware/CSH/csh-advanced-occupancy.htm':{i:[26],t:['Advanced Sensor Properties: Occupancy'],b:['']},'/Content/HOBOware/CSH/csh-alarms.htm':{i:[23],t:['Configure Alarms'],b:['']},'/Content/HOBOware/CSH/csh-burst.htm':{i:[29],t:['Burst Logging'],b:['']},'/Content/HOBOware/CSH/csh-convert-units.htm':{i:[62],t:['Converting Units'],b:['']},'/Content/HOBOware/CSH/csh-crop.htm':{i:[58],t:['Cropping a Series'],b:['']},'/Content/HOBOware/CSH/csh-dif-filters-stats.htm':{i:[28],t:['
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text, with very long lines (28534), with CRLF line terminators
    Category:dropped
    Size (bytes):28627
    Entropy (8bit):4.00570345719037
    Encrypted:false
    SSDEEP:768:ifW5r1GNjsO13vdExCTbxhUXs+7Gfs7otdp5zblf5P6Gna4rypB0/uYcxQBG4n+T:86/Bom+aGZE0fK6Zfdpy
    MD5:96FDAD959300B4F33991DB583A967B28
    SHA1:8F447807CD7C9F601BA5C8FAA2FE3C3E61F94889
    SHA-256:7BFFDB59BF23678832B061A47BB676285772ECA8959CD819AADF9A0838E51682
    SHA-512:6BE132D9AB65DCED17B763FA240FDFE8AA7E36FC6961F7198D86903026CF1B271DE31D7A41D8E574D7726781FC9971E8C19981EB3D3B355BC698C08BAF052C8C
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="utf-8"?><index> saved from url=(0016)http://localhost -->..<stem n="crop"><phr n="cropping"><ent r="4" t="1" w="173" /><ent r="4" t="6" w="244" /><ent r="5" t="48" w="64" /><ent r="268435456" t="59" w="1" /><ent r="16777218" t="59" w="5" /><ent r="4" t="59" w="153" /></phr><phr n="crop"><ent r="4" t="46" w="494" /><ent r="3" t="59" w="11" /><ent r="3" t="59" w="36" /><ent r="4" t="59" w="55" /><ent r="4" t="59" w="58" /><ent r="4" t="59" w="74" /><ent r="4" t="59" w="84" /><ent r="4" t="59" w="95" /><ent r="4" t="59" w="157" /></phr><phr n="cropped"><ent r="4" t="59" w="163" /><ent r="4" t="59" w="178" /></phr></stem><stem n="21"><phr n="21"><ent r="4" t="1" w="177" /><ent r="268435456" t="5" w="5" /><ent r="16777218" t="5" w="15" /><ent r="4" t="5" w="33" /><ent r="8" t="38" w="50" /><ent r="8" t="38" w="65" /><ent r="3" t="151" w="1534" /></phr></stem><stem n="cfr"><phr n="cfr"><ent r="4" t="1" w="178" /><ent r="268435456" t="5" w="6" /><ent r="16777
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:exported SGML document, ASCII text, with very long lines (32119), with CRLF line terminators
    Category:dropped
    Size (bytes):32363
    Entropy (8bit):4.360507675297074
    Encrypted:false
    SSDEEP:768:+iyyGGvvYYQQJJmmI9JWggmmAAEEvvSS1133uuDDpp11PBV6azsUVGssooIHmo2r:QAO5HsOY8I44gX
    MD5:86922719866938C1ED2D7B1A245700FD
    SHA1:91826C9CE3079628A9CECC83D526BA2B821DDA44
    SHA-256:2ACADCE57EF63C17E84249257D153F5D6A31974177E2CD541AFDA0F7764D7BC5
    SHA-512:58F5177F4EA432B44C1D37D1301E8B062E662ADC6A2FBEC651B0EC4C9008F639B6D66336B3E38931A4860AA31D96365F7BCC6BCF817BE4433E57A16C307B67A8
    Malicious:false
    Reputation:low
    Preview:var xmlSearch_Chunk86Data = "";..xmlSearch_Chunk86Data += '<?xml version=\"1.0\" encoding=\"utf-8\"?><index> saved from url=(0016)http://localhost -->';..xmlSearch_Chunk86Data += '<stem n=\"end-point\"><phr n=\"end-point\"><ent r=\"3\" t=\"103\" w=\"26\" /><ent r=\"3\" t=\"103\" w=\"26\" /><ent r=\"3\" t=\"138\" w=\"64\" /><ent r=\"3\" t=\"138\" w=\"64\" /><ent r=\"3\" t=\"139\" w=\"49\" /><ent r=\"3\" t=\"139\" w=\"49\" /><ent r=\"3\" t=\"139\" w=\"62\" /><ent r=\"3\" t=\"139\" w=\"62\" /><ent r=\"4\" t=\"143\" w=\"243\" /><ent r=\"4\" t=\"143\" w=\"243\" /><ent r=\"4\" t=\"143\" w=\"272\" /><ent r=\"4\" t=\"143\" w=\"272\" /><ent r=\"5\" t=\"143\" w=\"544\" /><ent r=\"5\" t=\"143\" w=\"544\" /><ent r=\"4\" t=\"144\" w=\"307\" /><ent r=\"4\" t=\"144\" w=\"307\" /><ent r=\"4\" t=\"144\" w=\"327\" /><ent r=\"4\" t=\"144\" w=\"327\" /></phr><phr n=\"End-Point\"><ent r=\"65\" t=\"125\" w=\"479\" /><ent r=\"65\" t=\"125\" w=\"479\" /><ent r=\"65\" t=\"125\" w=\"495\" /><ent r=\"65\" t=
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:exported SGML document, ASCII text, with very long lines (32021), with CRLF line terminators
    Category:dropped
    Size (bytes):32265
    Entropy (8bit):4.001334067411446
    Encrypted:false
    SSDEEP:768:uq0xlVrNJTM7nuM0MDoijYIseatNq/ZsqFAIzyDFSGcew7KHUyFiFY3Ws72qeAHN:vcJbLqx+GXl9QTtEmKsD
    MD5:B4011E09F468859BBF31BE5502E966A0
    SHA1:AB6DAB3726BE08FB91FB0E5E03B2EB3C1D798B0A
    SHA-256:6666576E291D244FD330FBCEA413E3766A3C49BACB48E63B64A9188B463C1416
    SHA-512:3EAA0494E24724E4AE612D6E9CCF12F7BE61FDE5BDC0214FAAF7A7BE9DEBAAB8F08219A9A9F0A4BB2B81B8456CF6837760ADA55E9895C9798B54582E386E2FC0
    Malicious:false
    Reputation:low
    Preview:var xmlSearch_Chunk12Data = "";..xmlSearch_Chunk12Data += '<?xml version=\"1.0\" encoding=\"utf-8\"?><index> saved from url=(0016)http://localhost -->';..xmlSearch_Chunk12Data += '<stem n=\"linear\"><phr n=\"linear\"><ent r=\"3\" t=\"1\" w=\"53\" /><ent r=\"4\" t=\"3\" w=\"1138\" /><ent r=\"5\" t=\"3\" w=\"1399\" /><ent r=\"3\" t=\"3\" w=\"1542\" /><ent r=\"4\" t=\"16\" w=\"658\" /><ent r=\"4\" t=\"17\" w=\"635\" /><ent r=\"4\" t=\"22\" w=\"400\" /><ent r=\"4\" t=\"23\" w=\"269\" /><ent r=\"4\" t=\"66\" w=\"107\" /><ent r=\"7\" t=\"66\" w=\"192\" /><ent r=\"4\" t=\"66\" w=\"198\" /><ent r=\"4\" t=\"66\" w=\"231\" /><ent r=\"268435456\" t=\"67\" w=\"1\" /><ent r=\"16777218\" t=\"67\" w=\"5\" /><ent r=\"3\" t=\"67\" w=\"10\" /><ent r=\"3\" t=\"67\" w=\"43\" /><ent r=\"3\" t=\"67\" w=\"132\" /><ent r=\"4\" t=\"67\" w=\"192\" /><ent r=\"4\" t=\"67\" w=\"222\" /><ent r=\"1048578\" t=\"67\" w=\"234\" /><ent r=\"3\" t=\"67\" w=\"294\" /><ent r=\"3\" t=\"67\" w=\"298\" /><ent r=\"4\" t=\"6
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:exported SGML document, ASCII text, with very long lines (31962), with CRLF line terminators
    Category:dropped
    Size (bytes):32206
    Entropy (8bit):4.039022032370306
    Encrypted:false
    SSDEEP:768:IIhoF0iVqZf9L8C+vlQ/u+Wt+N3GXHuq4c5jxoFu9FvIRn0dcAf7eHJlxWzMEfaA:5mSv2aWXpoW
    MD5:19709B08E671B45EE5CF1167802B6812
    SHA1:3D1689B35F5470C65FE8F3407132F7560B5CF111
    SHA-256:16BA1D59E42C30B8631C530029E994A06D42F0EB0631C66E8BBB2D9ADF478250
    SHA-512:F0E515E284AFD8F1AC39E2FCA3768B0E0218FB9DF67472A6B0E87079865A7AE62715EA7C4E587F16A3A82F386B7CA41FF6585FEC73FF10D2398BC2B543A9A05C
    Malicious:false
    Reputation:low
    Preview:var xmlSearch_Chunk41Data = "";..xmlSearch_Chunk41Data += '<?xml version=\"1.0\" encoding=\"utf-8\"?><index> saved from url=(0016)http://localhost -->';..xmlSearch_Chunk41Data += '<stem n=\"scroll\"><phr n=\"scroll\"><ent r=\"3\" t=\"4\" w=\"199\" /><ent r=\"3\" t=\"42\" w=\"154\" /><ent r=\"4\" t=\"80\" w=\"609\" /><ent r=\"4\" t=\"104\" w=\"520\" /><ent r=\"4\" t=\"139\" w=\"176\" /><ent r=\"4\" t=\"154\" w=\"739\" /><ent r=\"4\" t=\"154\" w=\"761\" /><ent r=\"3\" t=\"168\" w=\"337\" /></phr><phr n=\"scrolling\"><ent r=\"3\" t=\"42\" w=\"163\" /><ent r=\"4\" t=\"49\" w=\"178\" /></phr></stem><stem n=\"move\"><phr n=\"move\"><ent r=\"3\" t=\"4\" w=\"202\" /><ent r=\"4\" t=\"26\" w=\"428\" /><ent r=\"4\" t=\"40\" w=\"116\" /><ent r=\"4\" t=\"42\" w=\"68\" /><ent r=\"4\" t=\"42\" w=\"340\" /><ent r=\"3\" t=\"43\" w=\"504\" /><ent r=\"3\" t=\"43\" w=\"562\" /><ent r=\"3\" t=\"55\" w=\"430\" /><ent r=\"3\" t=\"55\" w=\"443\" /><ent r=\"3\" t=\"56\" w=\"179\" /><ent r=\"3\" t=\"56\" w=
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:exported SGML document, ASCII text, with very long lines (34292), with CRLF line terminators
    Category:dropped
    Size (bytes):34536
    Entropy (8bit):3.957409756016627
    Encrypted:false
    SSDEEP:768:vkVkLSODxRgoL5MrJhVLiNSf4A2Nv3FBZLC5QtxcoKspIV54UPFIxVdY3ywbiPNq:m3O4QhzfwMNzXU70Z4/
    MD5:87907C872E3F0C57ED6ADB4A38432DC7
    SHA1:2C95EC5DD4FF1C158ABD251B162AAC97196D00F4
    SHA-256:98BF39EF56843572930BFE72F95A8E0273D8C9CF026B32E3E0477E65402405CC
    SHA-512:61CDA9DB4E667DB2A7ED673A09AF828EB066A262D42720230E80E6F1969416295D56B021A80E7E2F4883FB0D49F28448A0294E0D3828C2F2852FB2C76F73BABB
    Malicious:false
    Reputation:low
    Preview:var xmlSearch_Chunk31Data = "";..xmlSearch_Chunk31Data += '<?xml version=\"1.0\" encoding=\"utf-8\"?><index> saved from url=(0016)http://localhost -->';..xmlSearch_Chunk31Data += '<stem n=\"burst\"><phr n=\"burst\"><ent r=\"4\" t=\"3\" w=\"78\" /><ent r=\"5\" t=\"3\" w=\"269\" /><ent r=\"5\" t=\"3\" w=\"343\" /><ent r=\"5\" t=\"3\" w=\"492\" /><ent r=\"4\" t=\"11\" w=\"523\" /><ent r=\"5\" t=\"11\" w=\"529\" /><ent r=\"4\" t=\"11\" w=\"621\" /><ent r=\"4\" t=\"11\" w=\"668\" /><ent r=\"6\" t=\"11\" w=\"1023\" /><ent r=\"4\" t=\"12\" w=\"672\" /><ent r=\"5\" t=\"12\" w=\"678\" /><ent r=\"4\" t=\"12\" w=\"770\" /><ent r=\"4\" t=\"15\" w=\"594\" /><ent r=\"5\" t=\"15\" w=\"615\" /><ent r=\"4\" t=\"15\" w=\"725\" /><ent r=\"5\" t=\"21\" w=\"86\" /><ent r=\"4\" t=\"24\" w=\"132\" /><ent r=\"5\" t=\"24\" w=\"148\" /><ent r=\"5\" t=\"28\" w=\"292\" /><ent r=\"268435456\" t=\"30\" w=\"1\" /><ent r=\"16777218\" t=\"30\" w=\"4\" /><ent r=\"3\" t=\"30\" w=\"7\" /><ent r=\"3\" t=\"30\" w=\"53\
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text, with very long lines (27407), with CRLF line terminators
    Category:dropped
    Size (bytes):27500
    Entropy (8bit):4.373124605628063
    Encrypted:false
    SSDEEP:768:bUIIQQbbKKee99AAaZJQiiYYuuuuHH88ppTTIIbbNNdd//80nx5I6622qTNoMaNZ:DOvaX
    MD5:C98F815DDC4489E3F25A64926352AEEC
    SHA1:40530AF577487DBB00346273D4D858C81B0D0E94
    SHA-256:E65293A804F523A5831193D9DEE29A431157A3CF4CD548F389488DAFBB5DC6E2
    SHA-512:35765F0A7DBB062F2094DA8D4DAAE94E979A8EAE4B34B3896F8D2FBFE5230A358C931A7E86F63F7BFF9910E691021E2768743B8AE5FC668408FC29B6B4139BEB
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="utf-8"?><index> saved from url=(0016)http://localhost -->..<stem n="end-point"><phr n="end-point"><ent r="3" t="103" w="26" /><ent r="3" t="103" w="26" /><ent r="3" t="138" w="64" /><ent r="3" t="138" w="64" /><ent r="3" t="139" w="49" /><ent r="3" t="139" w="49" /><ent r="3" t="139" w="62" /><ent r="3" t="139" w="62" /><ent r="4" t="143" w="243" /><ent r="4" t="143" w="243" /><ent r="4" t="143" w="272" /><ent r="4" t="143" w="272" /><ent r="5" t="143" w="544" /><ent r="5" t="143" w="544" /><ent r="4" t="144" w="307" /><ent r="4" t="144" w="307" /><ent r="4" t="144" w="327" /><ent r="4" t="144" w="327" /></phr><phr n="End-Point"><ent r="65" t="125" w="479" /><ent r="65" t="125" w="479" /><ent r="65" t="125" w="495" /><ent r="65" t="125" w="495" /><ent r="65" t="135" w="45" /><ent r="65" t="135" w="45" /><ent r="65" t="135" w="58" /><ent r="65" t="135" w="58" /><ent r="1000" t="138" w="8" /><ent r="1000" t="138" w="8" /><ent r="102" t="138" w="25" /><en
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text, with very long lines (26830), with CRLF line terminators
    Category:dropped
    Size (bytes):26923
    Entropy (8bit):4.190889803600203
    Encrypted:false
    SSDEEP:768:/Py++ZD8K0GhXBOX3RfxtsBw22ii332f5chddhhgZZttjjppvveeooRRrrrr++2y:B9uyhrgGPaF27ipdnLlD
    MD5:3ACC8B6ACD804B16308ADEC81BFD5D07
    SHA1:7DCB022E8D3713305A201F0D41E2384875F5F983
    SHA-256:9F53204EF4DFF239174E55BF78B8E0581CE09C49BA9C324A7829DC909BA1E686
    SHA-512:58E6CD70E196F2826A898D62E2E1E38CED438E64F92C3BBFF5B2372DBDCA6AC658A124D3C7E9AD9F9E871B3AE25DEBAC1C9A13A822AA00124BBFCE28A8062345
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="utf-8"?><index> saved from url=(0016)http://localhost -->..<stem n="manipul"><phr n="manipulate"><ent r="3" t="25" w="494" /><ent r="3" t="25" w="494" /></phr></stem><stem n="lux"><phr n="lux"><ent r="3" t="25" w="542" /><ent r="3" t="25" w="542" /><ent r="3" t="25" w="560" /><ent r="3" t="25" w="560" /><ent r="6" t="80" w="688" /></phr></stem><stem n="residenti"><phr n="residential"><ent r="3" t="25" w="551" /><ent r="3" t="25" w="551" /></phr></stem><stem n="500"><phr n="500"><ent r="3" t="25" w="559" /><ent r="3" t="25" w="559" /></phr></stem><stem n="retail"><phr n="retail"><ent r="3" t="25" w="569" /><ent r="3" t="25" w="569" /></phr></stem><stem n="mg"><phr n="mG"><ent r="3" t="25" w="580" /><ent r="3" t="25" w="580" /><ent r="3" t="25" w="595" /><ent r="3" t="25" w="595" /></phr><phr n="mg"><ent r="5" t="69" w="1082" /><ent r="5" t="69" w="1177" /><ent r="4" t="69" w="1538" /><ent r="7" t="69" w="1745" /><ent r="3" t="97" w="155" /><ent r="3" t=
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:exported SGML document, ASCII text, with very long lines (32560), with CRLF line terminators
    Category:dropped
    Size (bytes):32804
    Entropy (8bit):4.0528620937117115
    Encrypted:false
    SSDEEP:768:MYLWKKK4v0aR79jmaR+uFdBJrsFqWIyeywxyE+N1jw/o6otFx09jSQVENoagoQw5:MQU4UZzs
    MD5:49AF59C269D0080AE44B7D21602517AE
    SHA1:7CFE3FB0FF877906C754594A113D62E23D0B8DA0
    SHA-256:E45BDC39A746B8A3F17310484D82058C5BE8D1699F2C4E4FDC83A786AE6FCD59
    SHA-512:C696B01B831AE0DF87138512EE1AA1F1A59ACFE060204E7A66C477450FA65D982B2ACBF913188486A0F99C6904FF10F3E2409C143F233097989A79B8BAFFE29E
    Malicious:false
    Reputation:low
    Preview:var xmlSearch_Chunk47Data = "";..xmlSearch_Chunk47Data += '<?xml version=\"1.0\" encoding=\"utf-8\"?><index> saved from url=(0016)http://localhost -->';..xmlSearch_Chunk47Data += '<stem n=\"here\"><phr n=\"here\"><ent r=\"3\" t=\"9\" w=\"84\" /><ent r=\"4\" t=\"10\" w=\"118\" /><ent r=\"4\" t=\"11\" w=\"145\" /><ent r=\"4\" t=\"12\" w=\"129\" /><ent r=\"4\" t=\"13\" w=\"133\" /><ent r=\"4\" t=\"16\" w=\"129\" /><ent r=\"4\" t=\"33\" w=\"306\" /><ent r=\"3\" t=\"62\" w=\"307\" /><ent r=\"5\" t=\"71\" w=\"1381\" /><ent r=\"5\" t=\"71\" w=\"1445\" /><ent r=\"4\" t=\"74\" w=\"257\" /><ent r=\"5\" t=\"104\" w=\"88\" /><ent r=\"4\" t=\"125\" w=\"198\" /><ent r=\"4\" t=\"125\" w=\"268\" /><ent r=\"3\" t=\"160\" w=\"33\" /><ent r=\"4\" t=\"169\" w=\"223\" /><ent r=\"4\" t=\"174\" w=\"247\" /><ent r=\"4\" t=\"197\" w=\"47\" /><ent r=\"3\" t=\"198\" w=\"38\" /></phr></stem><stem n=\"desir\"><phr n=\"desired\"><ent r=\"4\" t=\"9\" w=\"211\" /><ent r=\"4\" t=\"10\" w=\"245\" /><ent r=\"3\" t=\
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text, with very long lines (26493), with CRLF line terminators
    Category:dropped
    Size (bytes):26586
    Entropy (8bit):3.9917065532583513
    Encrypted:false
    SSDEEP:768:WfNpBfh1fCDP8e6+DeMWeqwctdoXZOkpiez07NkYaA2bYbWMt4BWbYaXEgMWGARz:88wzyXbQ7otvn3wr53Ga
    MD5:89236E9C2D7ED4AE9708AC100E7154AD
    SHA1:955E2BFE4851E891997228CBBB70A9647436C2B1
    SHA-256:7DA0980A65A51ADC5BCC286D427DB921B6B9267BEE2D082CDF58BE8A5EA27473
    SHA-512:E10D00647FA57E10596FF445AB4AFFACBAF5023DEC1CCBFD89276D202C9A492D7AAD53D46CEC7831004D4D6D89F7227ABA13D7826971CFCF27CFBFB7670BF3B9
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="utf-8"?><index> saved from url=(0016)http://localhost -->..<stem n="linear"><phr n="linear"><ent r="3" t="1" w="53" /><ent r="4" t="3" w="1138" /><ent r="5" t="3" w="1399" /><ent r="3" t="3" w="1542" /><ent r="4" t="16" w="658" /><ent r="4" t="17" w="635" /><ent r="4" t="22" w="400" /><ent r="4" t="23" w="269" /><ent r="4" t="66" w="107" /><ent r="7" t="66" w="192" /><ent r="4" t="66" w="198" /><ent r="4" t="66" w="231" /><ent r="268435456" t="67" w="1" /><ent r="16777218" t="67" w="5" /><ent r="3" t="67" w="10" /><ent r="3" t="67" w="43" /><ent r="3" t="67" w="132" /><ent r="4" t="67" w="192" /><ent r="4" t="67" w="222" /><ent r="1048578" t="67" w="234" /><ent r="3" t="67" w="294" /><ent r="3" t="67" w="298" /><ent r="4" t="67" w="309" /><ent r="4" t="67" w="402" /><ent r="3" t="68" w="43" /><ent r="4" t="68" w="194" /><ent r="5" t="68" w="222" /><ent r="5" t="70" w="211" /><ent r="10" t="70" w="224" /><ent r="10" t="70" w="232" /><ent r="5" t="70" w=
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text, with very long lines (27167), with CRLF line terminators
    Category:dropped
    Size (bytes):27260
    Entropy (8bit):4.266428425245951
    Encrypted:false
    SSDEEP:768:QDKPdEkjjBBMMGGZZwt8IP+nw7kUqttto2gaUddqquuAAvv11IHHUUyy2ArA2csa:YzlNqjmllbA6YbrWWJ2xooRZM+ZkM
    MD5:AB1AE4F61C3CEDFF5F9DD90FA2921E62
    SHA1:128C72C2711310281209492C0C72EAEE4C20323F
    SHA-256:06796CE2CACAB4EA9A501A879581F3B6E6E9B158C219CDFDDD1BC32FB8DB484C
    SHA-512:4C29D95BCE3914188BF30821CA534ACF66A8F14AC657A7B74C0F843A6266FE06D3C76162823E9BB289B38CD4D938340BCA1CF5D2DFDE506136DD49CBB3AFCBCD
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="utf-8"?><index> saved from url=(0016)http://localhost -->..<stem n="cw"><phr n="CW"><ent r="7" t="110" w="302" /><ent r="7" t="110" w="302" /><ent r="7" t="110" w="316" /><ent r="7" t="110" w="316" /></phr></stem><stem n="doc"><phr n="docs"><ent r="64" t="110" w="339" /></phr></stem><stem n="0-20ma"><phr n="0-20mA"><ent r="92" t="110" w="347" /><ent r="92" t="110" w="347" /></phr></stem><stem n="0-100ma"><phr n="0-100mA"><ent r="92" t="110" w="350" /><ent r="92" t="110" w="350" /></phr></stem><stem n="100ma"><phr n="100mA"><ent r="92" t="110" w="351" /></phr></stem><stem n="0-200ma"><phr n="0-200mA"><ent r="92" t="110" w="353" /><ent r="92" t="110" w="353" /></phr></stem><stem n="200ma"><phr n="200mA"><ent r="92" t="110" w="354" /></phr></stem><stem n="wc"><phr n="WC"><ent r="3" t="111" w="37" /><ent r="92" t="111" w="121" /><ent r="92" t="111" w="121" /><ent r="92" t="111" w="127" /><ent r="92" t="111" w="127" /><ent r="92" t="111" w="133" /><ent r="9
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text, with very long lines (27073), with CRLF line terminators
    Category:dropped
    Size (bytes):27166
    Entropy (8bit):4.104504010419777
    Encrypted:false
    SSDEEP:768:qmUUYYffkk77WkkTTllhhOO1122llKKIIOOSS44MMTm/EEggEExx22cc5557pjnP:yEpb2p383
    MD5:4BB08CB5A3A522446051E39FF3F3E171
    SHA1:FEC7B36667577F3A545D2D359BE4DF329DD8D648
    SHA-256:8EFBE0DC637DEB613789E116A3C04D18789C253136460D44518F01547D49C568
    SHA-512:1BA87B4006F1E57780100EAE03D49966CF5C96CE4853D514CACC139E9EF3E1198C051AEFAAA581A4F8F500DC028FFF4A129289DA11A2E41CE99FB707AD4D2A77
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="utf-8"?><index> saved from url=(0016)http://localhost -->..<stem n="determin"><phr n="determine"><ent r="4" t="14" w="617" /><ent r="4" t="14" w="617" /><ent r="4" t="16" w="532" /><ent r="4" t="16" w="532" /><ent r="4" t="16" w="914" /><ent r="4" t="16" w="914" /><ent r="4" t="31" w="1014" /><ent r="4" t="31" w="1014" /><ent r="4" t="41" w="129" /><ent r="4" t="41" w="129" /><ent r="4" t="59" w="336" /><ent r="4" t="59" w="336" /><ent r="3" t="83" w="263" /><ent r="4" t="83" w="585" /><ent r="4" t="83" w="585" /><ent r="3" t="88" w="199" /><ent r="3" t="88" w="199" /><ent r="3" t="110" w="234" /><ent r="3" t="110" w="234" /><ent r="4" t="120" w="214" /><ent r="4" t="120" w="214" /><ent r="3" t="120" w="454" /><ent r="3" t="120" w="454" /><ent r="3" t="125" w="36" /><ent r="3" t="125" w="36" /><ent r="3" t="127" w="40" /><ent r="3" t="127" w="40" /><ent r="3" t="173" w="129" /><ent r="3" t="173" w="129" /><ent r="3" t="173" w="227" /><ent r="3" t="173"
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:exported SGML document, ASCII text, with very long lines (33166), with CRLF line terminators
    Category:dropped
    Size (bytes):33410
    Entropy (8bit):4.0071477455754065
    Encrypted:false
    SSDEEP:768:dSorxlc0xjwaB5Y49mrNode8fOLJ8rAt/WU3YoxdHZt0oE1bYh+YIWlyKJc9NfAe:ZM3QARAA/2Y2s++huuYIje9xzGdYui
    MD5:371910E2CFB2C363EFF81A9D55214B68
    SHA1:B8C5E5053FBA3B174A611F055B81711037EBACDE
    SHA-256:F7973579564DD9BBCEACEECBBA30D1F867546FF5000BF24B9DED178AC40A01C4
    SHA-512:B37ECCE48871CF11D8B8900580E8DEE1BA5CEEC926D90DEAC915A0A65159ADFEDA3B7DA708EE9F2ECD218C508144A0F4CC55EC95F0C306AE62E55B956582F0F2
    Malicious:false
    Reputation:low
    Preview:var xmlSearch_Chunk29Data = "";..xmlSearch_Chunk29Data += '<?xml version=\"1.0\" encoding=\"utf-8\"?><index> saved from url=(0016)http://localhost -->';..xmlSearch_Chunk29Data += '<stem n=\"commun\"><phr n=\"communication\"><ent r=\"3\" t=\"2\" w=\"706\" /><ent r=\"4\" t=\"100\" w=\"794\" /><ent r=\"3\" t=\"102\" w=\"63\" /><ent r=\"3\" t=\"102\" w=\"109\" /><ent r=\"4\" t=\"103\" w=\"178\" /><ent r=\"4\" t=\"103\" w=\"206\" /><ent r=\"3\" t=\"103\" w=\"238\" /><ent r=\"3\" t=\"103\" w=\"256\" /><ent r=\"3\" t=\"103\" w=\"269\" /><ent r=\"3\" t=\"103\" w=\"275\" /><ent r=\"5\" t=\"116\" w=\"237\" /><ent r=\"4\" t=\"116\" w=\"244\" /><ent r=\"5\" t=\"116\" w=\"267\" /><ent r=\"4\" t=\"116\" w=\"281\" /><ent r=\"4\" t=\"116\" w=\"300\" /><ent r=\"4\" t=\"123\" w=\"811\" /><ent r=\"4\" t=\"123\" w=\"823\" /><ent r=\"4\" t=\"123\" w=\"840\" /><ent r=\"3\" t=\"124\" w=\"143\" /><ent r=\"3\" t=\"124\" w=\"160\" /><ent r=\"4\" t=\"134\" w=\"204\" /><ent r=\"3\" t=\"143\" w=\"93\" /><ent r
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text, with very long lines (28052), with CRLF line terminators
    Category:dropped
    Size (bytes):28145
    Entropy (8bit):3.9548719761777678
    Encrypted:false
    SSDEEP:768:EyW8ej5oO5D8RHCIdHHhI4Tp3SWTD8d3HLhhIusd+s/5d2KRaQWV2QeKM0DXQcgU:HHAP5qzrdoo0ZVnceWS0A28owj
    MD5:B864437A273FF7CC522F183E451B45CE
    SHA1:6FFC9D02DA3C312FBE543B40E29421433B42B983
    SHA-256:DE18376B0DD23867478C93D0CBE716D312EF43D74AC5F0A27CB5561F3BE6DE31
    SHA-512:4AF9CEB86754C20F49776BFE5BAFE75355B27819C0E0ECC7EC08F3B9DEAB41C4BADEC35FAA006CD32C817406F557E3527CCBE3476CF65638BED0685542164979
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="utf-8"?><index> saved from url=(0016)http://localhost -->..<stem n="statu"><phr n="status"><ent r="3" t="1" w="36" /><ent r="4" t="3" w="1054" /><ent r="3" t="4" w="40" /><ent r="4" t="5" w="398" /><ent r="5" t="6" w="62" /><ent r="4" t="6" w="75" /><ent r="3" t="7" w="103" /><ent r="3" t="7" w="676" /><ent r="3" t="7" w="704" /><ent r="3" t="9" w="127" /><ent r="3" t="9" w="136" /><ent r="5" t="10" w="164" /><ent r="4" t="10" w="168" /><ent r="5" t="11" w="191" /><ent r="4" t="11" w="195" /><ent r="5" t="12" w="175" /><ent r="4" t="12" w="179" /><ent r="5" t="13" w="179" /><ent r="4" t="13" w="183" /><ent r="5" t="14" w="181" /><ent r="4" t="14" w="185" /><ent r="4" t="14" w="200" /><ent r="4" t="14" w="652" /><ent r="5" t="15" w="300" /><ent r="4" t="15" w="304" /><ent r="5" t="16" w="191" /><ent r="4" t="16" w="195" /><ent r="4" t="16" w="641" /><ent r="5" t="17" w="215" /><ent r="4" t="17" w="219" /><ent r="4" t="17" w="608" /><ent r="3" t="20" w="
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text, with very long lines (28626), with CRLF line terminators
    Category:dropped
    Size (bytes):28719
    Entropy (8bit):4.020198373929365
    Encrypted:false
    SSDEEP:768:vffAAFpp77WN1S1SppngNEddppaaDD++QQvv1rV4w8rosZRRLLffUUzz44ttoyFB:emxXI8jjT0YS16A0D11Iyu+OAZhT
    MD5:F4BBB685E2C6528467BA3CAFF8329EA5
    SHA1:38CC7D3FF7E0DBF43A6CC595C072945637521BA5
    SHA-256:80E2C63AAE2999C790398670781E4EDC6DF3D5345D07FE63DBE7629A8A110C6A
    SHA-512:0444E41E2D9B465E2A61DA88D3527729C677DE809C526FCF067CED47EC9F8AC1CF96AFF207FDA4F97ABAE90A9E7EBD4D14E02E270E78BB0B556EEDDA033A0337
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="utf-8"?><index> saved from url=(0016)http://localhost -->..<stem n="durat"><phr n="duration"><ent r="3" t="9" w="395" /><ent r="4" t="11" w="596" /><ent r="4" t="11" w="596" /><ent r="4" t="12" w="745" /><ent r="4" t="12" w="745" /><ent r="4" t="18" w="164" /><ent r="4" t="18" w="186" /><ent r="4" t="18" w="186" /><ent r="4" t="18" w="193" /><ent r="4" t="18" w="193" /><ent r="3" t="24" w="73" /><ent r="3" t="24" w="128" /><ent r="4" t="24" w="236" /><ent r="4" t="24" w="236" /><ent r="4" t="27" w="535" /><ent r="4" t="27" w="535" /><ent r="4" t="29" w="719" /><ent r="3" t="54" w="438" /><ent r="4" t="54" w="506" /><ent r="4" t="54" w="523" /><ent r="3" t="54" w="543" /><ent r="3" t="54" w="543" /><ent r="3" t="87" w="521" /><ent r="3" t="87" w="521" /><ent r="5" t="154" w="664" /><ent r="5" t="154" w="664" /><ent r="4" t="154" w="679" /><ent r="4" t="154" w="679" /><ent r="3" t="173" w="407" /><ent r="3" t="173" w="407" /><ent r="3" t="174" w="529" />
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:exported SGML document, ASCII text, with very long lines (33458), with CRLF line terminators
    Category:dropped
    Size (bytes):33702
    Entropy (8bit):4.310290122910874
    Encrypted:false
    SSDEEP:768:BoykgAbS5c9L3zn2P9ElmdzGc2zU8zrb0pfSM1aKUohV5uvgL0T+hxjfx57ZERU5:TONZMBwE
    MD5:130DAB6CE7EB17DA096DF04C3AE8747D
    SHA1:157C4BD3C75CA97F7DE33812AB12028E67461D13
    SHA-256:8DFB890470D107AF285900DC92C831B4BCAEA64A90D5A2342FBCC8E6FA353D06
    SHA-512:0805A9CCCCE69AA9CA55997E81E4752FB3D57732D890C9625414762027B30A73C99F2A9A44DECC1C23B4897A9FDB4F9D296B955D0574355DF362C8675C2AAB93
    Malicious:false
    Reputation:low
    Preview:var xmlSearch_Chunk54Data = "";..xmlSearch_Chunk54Data += '<?xml version=\"1.0\" encoding=\"utf-8\"?><index> saved from url=(0016)http://localhost -->';..xmlSearch_Chunk54Data += '<stem n=\"tile\"><phr n=\"tile\"><ent r=\"4\" t=\"37\" w=\"508\" /><ent r=\"4\" t=\"37\" w=\"511\" /><ent r=\"5\" t=\"166\" w=\"72\" /><ent r=\"4\" t=\"166\" w=\"110\" /><ent r=\"5\" t=\"166\" w=\"120\" /><ent r=\"4\" t=\"166\" w=\"158\" /><ent r=\"3\" t=\"166\" w=\"188\" /></phr><phr n=\"tiled\"><ent r=\"4\" t=\"166\" w=\"95\" /><ent r=\"4\" t=\"166\" w=\"143\" /></phr></stem><stem n=\"horizont\"><phr n=\"horizontally\"><ent r=\"4\" t=\"37\" w=\"509\" /><ent r=\"4\" t=\"43\" w=\"281\" /><ent r=\"3\" t=\"43\" w=\"515\" /><ent r=\"4\" t=\"61\" w=\"418\" /><ent r=\"5\" t=\"166\" w=\"73\" /><ent r=\"4\" t=\"166\" w=\"84\" /></phr><phr n=\"horizontal\"><ent r=\"4\" t=\"40\" w=\"306\" /><ent r=\"4\" t=\"43\" w=\"243\" /><ent r=\"3\" t=\"43\" w=\"475\" /><ent r=\"4\" t=\"49\" w=\"222\" /><ent r=\"3\" t=\"73\" w
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:exported SGML document, ASCII text, with very long lines (45774), with CRLF line terminators
    Category:dropped
    Size (bytes):46014
    Entropy (8bit):3.928677761805769
    Encrypted:false
    SSDEEP:768:zeOtko70EJpMGkU0RQz3dJreIrnsXJi+psLT0OfoGbW6hNMvHw+/xY0tUHBzoPck:vsAMuduQm4XQbo0NoaROk44pD
    MD5:269E7E494ABBE24EC8FD215D80EDAD70
    SHA1:088EF5D34A66485DE95347845D2FEDCAE494A29E
    SHA-256:8FC7F7187B400FC4F6269D48E82B5C5DD035EBDFF0E43DD3DC4C09F559AB5A5D
    SHA-512:4FE0F3655A6438FE65F8462F64FA751DB768A7560F7A352D9C401806641A578AA9C840124EA6C4050669B82250DA44911321B6BDA2C9DB462B033B8C7A53417A
    Malicious:false
    Reputation:low
    Preview:var xmlSearch_Chunk2Data = "";..xmlSearch_Chunk2Data += '<?xml version=\"1.0\" encoding=\"utf-8\"?><index> saved from url=(0016)http://localhost -->';..xmlSearch_Chunk2Data += '<stem n=\"hobo\"><phr n=\"hobo\"><ent r=\"5\" t=\"0\" w=\"29\" /><ent r=\"4\" t=\"0\" w=\"166\" /><ent r=\"3\" t=\"1\" w=\"23\" /><ent r=\"4\" t=\"1\" w=\"90\" /><ent r=\"4\" t=\"1\" w=\"103\" /><ent r=\"5\" t=\"1\" w=\"296\" /><ent r=\"3\" t=\"2\" w=\"698\" /><ent r=\"5\" t=\"3\" w=\"61\" /><ent r=\"5\" t=\"3\" w=\"218\" /><ent r=\"4\" t=\"3\" w=\"254\" /><ent r=\"4\" t=\"3\" w=\"328\" /><ent r=\"4\" t=\"3\" w=\"398\" /><ent r=\"4\" t=\"3\" w=\"455\" /><ent r=\"5\" t=\"3\" w=\"478\" /><ent r=\"4\" t=\"3\" w=\"839\" /><ent r=\"4\" t=\"3\" w=\"905\" /><ent r=\"4\" t=\"3\" w=\"988\" /><ent r=\"4\" t=\"3\" w=\"1076\" /><ent r=\"4\" t=\"3\" w=\"1093\" /><ent r=\"4\" t=\"3\" w=\"1303\" /><ent r=\"5\" t=\"3\" w=\"1423\" /><ent r=\"4\" t=\"3\" w=\"1473\" /><ent r=\"4\" t=\"3\" w=\"1497\" /><ent r=\"8\" t=\"5\" w=\"
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text, with very long lines (27490), with CRLF line terminators
    Category:dropped
    Size (bytes):27583
    Entropy (8bit):3.9967562700417703
    Encrypted:false
    SSDEEP:768:lIWbhhdl7S05xOufNf4fTwotuJfE+jgf1G7OFvUCXuy5lbN8aG1vWV7E9e6QBk4I:5VCobO+zXWU/u3klPZ+X5Cxn
    MD5:0B2F96DF3221A2F39BEB61B06B47AA8B
    SHA1:C0E947D0A3EEE1F97F5BD920A022AE553C9699E8
    SHA-256:BCCE18A34EC6AD464B2C5914CF78D823F2BCE03286EA2E6D9EE6AB529E1FCF52
    SHA-512:5FA859312A96DDF49A219481B3096CF3567CF21AAFDF366B44777901289111CBCF44D1733D3FCAB5205B327DB21E6935735BD5A1EC2B3274C10411A0EDDA87BB
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="utf-8"?><index> saved from url=(0016)http://localhost -->..<stem n="commun"><phr n="communication"><ent r="3" t="2" w="706" /><ent r="4" t="100" w="794" /><ent r="3" t="102" w="63" /><ent r="3" t="102" w="109" /><ent r="4" t="103" w="178" /><ent r="4" t="103" w="206" /><ent r="3" t="103" w="238" /><ent r="3" t="103" w="256" /><ent r="3" t="103" w="269" /><ent r="3" t="103" w="275" /><ent r="5" t="116" w="237" /><ent r="4" t="116" w="244" /><ent r="5" t="116" w="267" /><ent r="4" t="116" w="281" /><ent r="4" t="116" w="300" /><ent r="4" t="123" w="811" /><ent r="4" t="123" w="823" /><ent r="4" t="123" w="840" /><ent r="3" t="124" w="143" /><ent r="3" t="124" w="160" /><ent r="4" t="134" w="204" /><ent r="3" t="143" w="93" /><ent r="3" t="143" w="110" /><ent r="4" t="146" w="344" /><ent r="4" t="146" w="367" /><ent r="4" t="146" w="384" /><ent r="4" t="146" w="405" /><ent r="4" t="147" w="544" /><ent r="4" t="147" w="558" /><ent r="4" t="147" w="575" /><
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:exported SGML document, ASCII text, with very long lines (34442), with CRLF line terminators
    Category:dropped
    Size (bytes):34686
    Entropy (8bit):4.011341677486081
    Encrypted:false
    SSDEEP:768:hL8VD9olnSktTXNKVgr3RNSbeMDUrC/iNJxFjDhX1HI0rYqv4FVW/oem5WR0WDgR:CGuwDqjX
    MD5:2B4809108B3FC9C748DCF433799197E9
    SHA1:E96DB631D771F3938058C646E38D4103B6435E08
    SHA-256:385E635DEE13DB5EA03CA5994470340D9E255C78A39C5FD1D5D2D6215E3FDB9F
    SHA-512:BE88A41D1B4C21CB85850AE21DBAE931AC82B68702417E96C82F4C1D99244FCA0B0A9B4885242B0B4E933C482047C6AC1E6FF9D1EE8CC3C51194A48C8C20EDF8
    Malicious:false
    Reputation:low
    Preview:var xmlSearch_Chunk17Data = "";..xmlSearch_Chunk17Data += '<?xml version=\"1.0\" encoding=\"utf-8\"?><index> saved from url=(0016)http://localhost -->';..xmlSearch_Chunk17Data += '<stem n=\"crop\"><phr n=\"cropping\"><ent r=\"4\" t=\"1\" w=\"173\" /><ent r=\"4\" t=\"6\" w=\"244\" /><ent r=\"5\" t=\"48\" w=\"64\" /><ent r=\"268435456\" t=\"59\" w=\"1\" /><ent r=\"16777218\" t=\"59\" w=\"5\" /><ent r=\"4\" t=\"59\" w=\"153\" /></phr><phr n=\"crop\"><ent r=\"4\" t=\"46\" w=\"494\" /><ent r=\"3\" t=\"59\" w=\"11\" /><ent r=\"3\" t=\"59\" w=\"36\" /><ent r=\"4\" t=\"59\" w=\"55\" /><ent r=\"4\" t=\"59\" w=\"58\" /><ent r=\"4\" t=\"59\" w=\"74\" /><ent r=\"4\" t=\"59\" w=\"84\" /><ent r=\"4\" t=\"59\" w=\"95\" /><ent r=\"4\" t=\"59\" w=\"157\" /></phr><phr n=\"cropped\"><ent r=\"4\" t=\"59\" w=\"163\" /><ent r=\"4\" t=\"59\" w=\"178\" /></phr></stem><stem n=\"21\"><phr n=\"21\"><ent r=\"4\" t=\"1\" w=\"177\" /><ent r=\"268435456\" t=\"5\" w=\"5\" /><ent r=\"16777218\" t=\"5\" w=\"15\" />
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:exported SGML document, ASCII text, with very long lines (32189), with CRLF line terminators
    Category:dropped
    Size (bytes):32433
    Entropy (8bit):4.153095560523318
    Encrypted:false
    SSDEEP:768:4Ysu9R6SpmHQTSoc/ePakBu4Fjb7Wy6NX14iFc0F9skFkLbOEw3/WtsetFz1bJHP:J+j3d705d
    MD5:DD0E81AE63745EE252EECAB0A015B6BC
    SHA1:E09E285DB813B6575A430EFD877C20F3BBFD5436
    SHA-256:9D82A04DDD672C6A8B2C56881C094C2EBC386761B6FACF3E3E65175D2AA370E5
    SHA-512:14D4A4F706E52D52734CE72AA440C7B268A671C6E3C8AF3904302A74F92BBB137D4E3D0A20734C4A8677D92175B948C6A23054D990911FFD9D178726B0D97594
    Malicious:false
    Reputation:low
    Preview:var xmlSearch_Chunk38Data = "";..xmlSearch_Chunk38Data += '<?xml version=\"1.0\" encoding=\"utf-8\"?><index> saved from url=(0016)http://localhost -->';..xmlSearch_Chunk38Data += '<stem n=\"ux90-004x\"><phr n=\"ux90-004x\"><ent r=\"4\" t=\"3\" w=\"1028\" /></phr></stem><stem n=\"004x\"><phr n=\"004x\"><ent r=\"4\" t=\"3\" w=\"1029\" /></phr></stem><stem n=\"util\"><phr n=\"utility\"><ent r=\"4\" t=\"3\" w=\"1061\" /><ent r=\"4\" t=\"124\" w=\"109\" /><ent r=\"5\" t=\"138\" w=\"82\" /><ent r=\"268435456\" t=\"144\" w=\"5\" /><ent r=\"16777218\" t=\"144\" w=\"11\" /><ent r=\"3\" t=\"144\" w=\"33\" /><ent r=\"3\" t=\"144\" w=\"41\" /><ent r=\"3\" t=\"144\" w=\"70\" /><ent r=\"3\" t=\"144\" w=\"101\" /><ent r=\"3\" t=\"144\" w=\"137\" /><ent r=\"3\" t=\"144\" w=\"161\" /><ent r=\"3\" t=\"144\" w=\"188\" /><ent r=\"3\" t=\"144\" w=\"226\" /></phr><phr n=\"utilities\"><ent r=\"4\" t=\"9\" w=\"234\" /><ent r=\"268435456\" t=\"21\" w=\"3\" /><ent r=\"16777218\" t=\"21\" w=\"7\" /><ent r=\"
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:exported SGML document, ASCII text, with very long lines (36630), with CRLF line terminators
    Category:dropped
    Size (bytes):36874
    Entropy (8bit):3.9922743539017174
    Encrypted:false
    SSDEEP:768:7VT3DGakk0lVuPHYOuKIQSn8dOB6UyROlKWoCF7jjHf1jiGSQEa9kUraFwplcKsZ:FN6s12V8WhX2
    MD5:651F2D5801433CEB9D32DC1C0D6D91E6
    SHA1:83FF54D9F832B576CA880D0B29F41956877FDD15
    SHA-256:674F8D0404225BF08F2353D8CB945223505D679F958C510D6CAFDB50EB142913
    SHA-512:5FCA809DA6664C30A596B0109BC257896EF23FCB32FC10FF711622B3A8DFEB18758116BB1E5701601518F8FB58EDE9BA517332D40AD088FC6A7B677EB7CC40CD
    Malicious:false
    Reputation:low
    Preview:var xmlSearch_Chunk24Data = "";..xmlSearch_Chunk24Data += '<?xml version=\"1.0\" encoding=\"utf-8\"?><index> saved from url=(0016)http://localhost -->';..xmlSearch_Chunk24Data += '<stem n=\"applic\"><phr n=\"applications\"><ent r=\"4\" t=\"2\" w=\"275\" /><ent r=\"4\" t=\"2\" w=\"336\" /><ent r=\"4\" t=\"3\" w=\"1318\" /><ent r=\"4\" t=\"66\" w=\"486\" /><ent r=\"4\" t=\"71\" w=\"1263\" /><ent r=\"3\" t=\"73\" w=\"44\" /><ent r=\"3\" t=\"76\" w=\"36\" /><ent r=\"3\" t=\"78\" w=\"32\" /><ent r=\"3\" t=\"126\" w=\"138\" /><ent r=\"3\" t=\"168\" w=\"253\" /><ent r=\"4\" t=\"174\" w=\"288\" /><ent r=\"3\" t=\"183\" w=\"613\" /></phr><phr n=\"applicable\"><ent r=\"4\" t=\"3\" w=\"1414\" /><ent r=\"4\" t=\"12\" w=\"300\" /><ent r=\"4\" t=\"14\" w=\"562\" /><ent r=\"4\" t=\"16\" w=\"318\" /><ent r=\"3\" t=\"24\" w=\"1003\" /><ent r=\"3\" t=\"28\" w=\"673\" /><ent r=\"6\" t=\"29\" w=\"262\" /><ent r=\"4\" t=\"31\" w=\"337\" /><ent r=\"5\" t=\"33\" w=\"277\" /><ent r=\"5\" t=\"33\" w=\"334\
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text, with very long lines (27582), with CRLF line terminators
    Category:dropped
    Size (bytes):27675
    Entropy (8bit):4.43066513425702
    Encrypted:false
    SSDEEP:768:szm8vUJJeekkOOJJccR273pPeeCCXbxWENNHHNN4+1ddnnSS4AsOtigiTTUlbiNt:wZUceNb
    MD5:AEB6D2C63D3BA09382338B0741D30880
    SHA1:0947F2BC96D985CEF322EA6AC3AB5D83727C8882
    SHA-256:FB9720B064737D3719096075F0975DBF7C1F0C1E9D3238EB9706C35BC195FC4A
    SHA-512:9FD23759A24A554AF7877A5019C5A35DC0C06987E018D2F110A78883423DDC68274DB65012A364FB17493015009F75223EE3E0D4EA588BA2485278AA862C2AAF
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="utf-8"?><index> saved from url=(0016)http://localhost -->..<stem n="bin"><phr n="bin"><ent r="64" t="132" w="140" /></phr></stem><stem n="py"><phr n="py"><ent r="64" t="132" w="142" /></phr></stem><stem n="hl"><phr n="hl"><ent r="64" t="132" w="143" /></phr></stem><stem n="en"><phr n="en"><ent r="64" t="132" w="144" /></phr></stem><stem n="13287"><phr n="13287"><ent r="64" t="132" w="146" /><ent r="64" t="132" w="146" /></phr></stem><stem n="hotmail"><phr n="Hotmail"><ent r="4" t="132" w="148" /><ent r="4" t="132" w="148" /></phr></stem><stem n="liveunplug"><phr n="liveunplugged"><ent r="64" t="132" w="151" /></phr></stem><stem n="blog"><phr n="blog"><ent r="64" t="132" w="155" /></phr></stem><stem n="cn"><phr n="cns"><ent r="64" t="132" w="156" /></phr></stem><stem n="f92775fc46a390ca"><phr n="F92775FC46A390CA"><ent r="64" t="132" w="157" /></phr></stem><stem n="422"><phr n="422"><ent r="64" t="132" w="158" /></phr></stem><stem n="alltel"><phr n="Allt
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text, with very long lines (27383), with CRLF line terminators
    Category:dropped
    Size (bytes):27476
    Entropy (8bit):4.273170288211834
    Encrypted:false
    SSDEEP:768:D/ZHo0zuSK8o6fs/1e33rMGN5q/WPAmYhXeWI0GhRkYnxzNAXHrPCCv7uL7vqo1A:6T+AYCxgvZohn9SRUawalRmgW
    MD5:4EB1BF8027DF397EF24ACC91E034BD66
    SHA1:F1C3BAAF6E5771DF10ECCEC323DC7C6D2A51FD36
    SHA-256:E899C89B680AE943A35360C019538E073767F2D8A3643878571D15D8859895EC
    SHA-512:D46B46FC17BA83106456A93B95A1797331869391123C766AC4B0CB7F5361E45E59055973B759955730EE93701638BA1CE137D6CA359D19442794FEE6068EB454
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="utf-8"?><index> saved from url=(0016)http://localhost -->..<stem n="compar"><phr n="compares"><ent r="3" t="29" w="120" /><ent r="3" t="182" w="53" /></phr><phr n="compare"><ent r="3" t="46" w="72" /></phr><phr n="comparing"><ent r="5" t="51" w="529" /><ent r="4" t="122" w="232" /></phr></stem><stem n="best"><phr n="best"><ent r="3" t="29" w="132" /><ent r="3" t="31" w="98" /><ent r="4" t="31" w="119" /><ent r="4" t="31" w="591" /><ent r="4" t="31" w="846" /><ent r="5" t="69" w="298" /><ent r="4" t="71" w="683" /><ent r="3" t="113" w="236" /><ent r="4" t="137" w="187" /><ent r="4" t="137" w="280" /><ent r="4" t="146" w="130" /><ent r="4" t="147" w="194" /><ent r="3" t="176" w="228" /><ent r="3" t="177" w="483" /></phr></stem><stem n="solut"><phr n="solution"><ent r="3" t="29" w="133" /><ent r="3" t="70" w="426" /><ent r="3" t="100" w="218" /><ent r="4" t="100" w="1015" /><ent r="3" t="100" w="1353" /></phr><phr n="solutions"><ent r="5" t="70" w="240" /
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:exported SGML document, ASCII text, with very long lines (39226), with CRLF line terminators
    Category:dropped
    Size (bytes):39466
    Entropy (8bit):3.975507753755767
    Encrypted:false
    SSDEEP:768:rQAkHdynjUXWAKfahTvIvZ9ok0h9A+yfp7zJ1uiCj3G9ZlJ0BNTv/YA922nY+u+V:PVf2HsC
    MD5:23D228FDE99BE1981DCDDEDCDADEE4E7
    SHA1:A6F3378D943C7AA5173CB46BBB08921A2240482B
    SHA-256:7FE54248C3DB58BB9726A59D7829BE6EA1F763784566533392D42C3768BA3064
    SHA-512:31718879AC9DEDB009607C2D22EFC6CEB4C43D30F3159C2DFC4F623A9C29033419A72704C61BA99863BC49DC38A69D21E3E2BF45762B98F47FCBACD9E52AB361
    Malicious:false
    Reputation:low
    Preview:var xmlSearch_Chunk6Data = "";..xmlSearch_Chunk6Data += '<?xml version=\"1.0\" encoding=\"utf-8\"?><index> saved from url=(0016)http://localhost -->';..xmlSearch_Chunk6Data += '<stem n=\"bulk\"><phr n=\"bulk\"><ent r=\"5\" t=\"0\" w=\"47\" /><ent r=\"4\" t=\"1\" w=\"136\" /><ent r=\"5\" t=\"75\" w=\"73\" /><ent r=\"268435456\" t=\"80\" w=\"2\" /><ent r=\"16777218\" t=\"80\" w=\"7\" /><ent r=\"3\" t=\"80\" w=\"12\" /><ent r=\"3\" t=\"80\" w=\"55\" /><ent r=\"3\" t=\"80\" w=\"106\" /><ent r=\"1048578\" t=\"80\" w=\"150\" /><ent r=\"3\" t=\"80\" w=\"159\" /><ent r=\"4\" t=\"80\" w=\"168\" /><ent r=\"3\" t=\"80\" w=\"400\" /><ent r=\"3\" t=\"80\" w=\"477\" /><ent r=\"4\" t=\"80\" w=\"613\" /><ent r=\"5\" t=\"150\" w=\"217\" /><ent r=\"4\" t=\"150\" w=\"224\" /><ent r=\"4\" t=\"152\" w=\"905\" /><ent r=\"3\" t=\"165\" w=\"16\" /><ent r=\"4\" t=\"165\" w=\"33\" /></phr></stem><stem n=\"export\"><phr n=\"export\"><ent r=\"5\" t=\"0\" w=\"48\" /><ent r=\"3\" t=\"1\" w=\"39\" /><ent r=\"4\"
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text, with very long lines (27258), with CRLF line terminators
    Category:dropped
    Size (bytes):27351
    Entropy (8bit):4.065236566026653
    Encrypted:false
    SSDEEP:768:iIUWcZiKznyHaS+5eROyW6xQCGPG/GNgQefjwlwcFqY5fQSLBC5Fbxclp7BHXpgm:Mue7VtbJTSl1iqpTm9lxKw+XMn+35k
    MD5:B4A9B93A3595BEDAB9050FB289798B03
    SHA1:6443065347025EA4C1094F4D214DB56E4A185989
    SHA-256:A7318D06F50E542AC792C25BA541A140B1A6EB4BC76C8D25C6E89E9EFBB32BC0
    SHA-512:C5AA2BABCFB1940C7A9A91827D4F42EC65B06441E508BF588B5581513CF4068D23E0688C9E55538B9CCC88FDE82AF9E04542CFEA17404A7CA1B9D9267ACB78A7
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="utf-8"?><index> saved from url=(0016)http://localhost -->..<stem n="drop-down"><phr n="drop-down"><ent r="4" t="10" w="234" /><ent r="4" t="10" w="277" /><ent r="3" t="11" w="242" /><ent r="4" t="13" w="254" /><ent r="3" t="13" w="297" /><ent r="4" t="13" w="325" /><ent r="4" t="19" w="81" /><ent r="4" t="28" w="421" /><ent r="4" t="30" w="542" /><ent r="5" t="46" w="245" /><ent r="4" t="55" w="137" /><ent r="4" t="62" w="198" /><ent r="3" t="63" w="122" /><ent r="3" t="63" w="140" /><ent r="4" t="63" w="189" /><ent r="3" t="66" w="711" /><ent r="4" t="67" w="325" /><ent r="4" t="68" w="323" /><ent r="4" t="69" w="235" /><ent r="5" t="71" w="1045" /><ent r="5" t="71" w="1311" /><ent r="5" t="71" w="1359" /><ent r="4" t="72" w="115" /><ent r="4" t="72" w="134" /><ent r="4" t="73" w="274" /><ent r="4" t="74" w="217" /><ent r="4" t="74" w="239" /><ent r="4" t="74" w="291" /><ent r="4" t="91" w="391" /><ent r="4" t="98" w="101" /><ent r="4" t="105" w="120"
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:exported SGML document, ASCII text, with very long lines (31907), with CRLF line terminators
    Category:dropped
    Size (bytes):32151
    Entropy (8bit):4.078119557066821
    Encrypted:false
    SSDEEP:768:q2ZKt0nzHI+nFE580+7f3CalLaHLX9terdl82CQ70PkecwVbc06WNX9lJL2vdbjx:fjyWA1H7KTju+Iqdhuneo39LrDGE6llb
    MD5:E53215D391BAB3A0080C31A6ECF83BE3
    SHA1:2C04450E595E5FC8277ED51F611C372F768E994F
    SHA-256:8D91F0867FF6D41246B43D3485F109ACA97681CB4E21D8C12AB62DEB785F19A9
    SHA-512:2A6225F655810CC0A69D83870D46E8EF163F5EB1A47B641AA82B75A42FEDB7D995FC20820E24CBDFB169AABD125B408A8E96E4D56308CE597BCFF9A6DD4EA10B
    Malicious:false
    Reputation:low
    Preview:var xmlSearch_Chunk37Data = "";..xmlSearch_Chunk37Data += '<?xml version=\"1.0\" encoding=\"utf-8\"?><index> saved from url=(0016)http://localhost -->';..xmlSearch_Chunk37Data += '<stem n=\"accuraci\"><phr n=\"accuracy\"><ent r=\"4\" t=\"3\" w=\"822\" /><ent r=\"3\" t=\"31\" w=\"99\" /><ent r=\"4\" t=\"31\" w=\"596\" /><ent r=\"4\" t=\"31\" w=\"847\" /><ent r=\"5\" t=\"69\" w=\"299\" /><ent r=\"4\" t=\"71\" w=\"409\" /><ent r=\"4\" t=\"71\" w=\"684\" /><ent r=\"4\" t=\"86\" w=\"497\" /><ent r=\"4\" t=\"113\" w=\"126\" /></phr></stem><stem n=\"u26\"><phr n=\"u26\"><ent r=\"4\" t=\"3\" w=\"840\" /><ent r=\"5\" t=\"16\" w=\"980\" /><ent r=\"4\" t=\"16\" w=\"995\" /><ent r=\"5\" t=\"16\" w=\"1029\" /><ent r=\"5\" t=\"33\" w=\"398\" /><ent r=\"4\" t=\"33\" w=\"406\" /><ent r=\"5\" t=\"33\" w=\"438\" /><ent r=\"4\" t=\"66\" w=\"388\" /><ent r=\"4\" t=\"71\" w=\"35\" /><ent r=\"4\" t=\"71\" w=\"44\" /><ent r=\"5\" t=\"84\" w=\"56\" /><ent r=\"5\" t=\"84\" w=\"71\" /><ent r=\"268435456\" t
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:exported SGML document, ASCII text, with very long lines (32554), with CRLF line terminators
    Category:dropped
    Size (bytes):32798
    Entropy (8bit):3.9633681790416193
    Encrypted:false
    SSDEEP:768:syxKpXbhGoTe10FuxtDVt2fPWA0nSdBHtsYHdVZeDk9bffzl34QaoObfg3w5LrmE:Zc0x
    MD5:CCCB56DB90DEF6084C23F5D6B6D0B539
    SHA1:8A0B333B3912A460E8ABA5EB3B6D4AC0F6B200E1
    SHA-256:A7C98C3C88E569B4C45F3CD3ADF4D77B45EC10D5DFC7D87129463D4C6ADB486F
    SHA-512:C317187C94AABBF0BCD21B6123AD233663B142BE208F40BE27FC84475F23D7608A96FDAEA400CD2833C592AD1E0D43FCACA2111E2BDD811603E716CC24A56ED2
    Malicious:false
    Reputation:low
    Preview:var xmlSearch_Chunk21Data = "";..xmlSearch_Chunk21Data += '<?xml version=\"1.0\" encoding=\"utf-8\"?><index> saved from url=(0016)http://localhost -->';..xmlSearch_Chunk21Data += '<stem n=\"double-click\"><phr n=\"double-click\"><ent r=\"4\" t=\"2\" w=\"170\" /><ent r=\"4\" t=\"2\" w=\"263\" /><ent r=\"4\" t=\"2\" w=\"295\" /><ent r=\"4\" t=\"2\" w=\"304\" /><ent r=\"3\" t=\"4\" w=\"728\" /><ent r=\"3\" t=\"22\" w=\"209\" /><ent r=\"3\" t=\"23\" w=\"143\" /><ent r=\"4\" t=\"38\" w=\"89\" /><ent r=\"4\" t=\"40\" w=\"329\" /><ent r=\"3\" t=\"41\" w=\"93\" /><ent r=\"4\" t=\"43\" w=\"347\" /><ent r=\"3\" t=\"43\" w=\"631\" /><ent r=\"4\" t=\"50\" w=\"51\" /><ent r=\"4\" t=\"51\" w=\"53\" /><ent r=\"4\" t=\"52\" w=\"24\" /><ent r=\"4\" t=\"53\" w=\"24\" /><ent r=\"4\" t=\"55\" w=\"80\" /><ent r=\"3\" t=\"56\" w=\"213\" /><ent r=\"4\" t=\"61\" w=\"205\" /><ent r=\"4\" t=\"61\" w=\"267\" /><ent r=\"4\" t=\"61\" w=\"354\" /><ent r=\"3\" t=\"66\" w=\"164\" /><ent r=\"4\" t=\"89\" w=\"256\"
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text, with very long lines (28424), with CRLF line terminators
    Category:dropped
    Size (bytes):28517
    Entropy (8bit):4.3224692445564905
    Encrypted:false
    SSDEEP:768:pCQSiujsdKFrzHnQjBadkJD4CoDqarz+VjAuhkMP99x8uAudObIBZf7hVf1Od+MS:eJ6pV1AAP8iOPfI
    MD5:D1AADB7C8D9FFE66DF3F1482E24323BF
    SHA1:C4F9AC991BC712609FD3B3F6696E71C0564FA72C
    SHA-256:D7C6CA8252B5A103CBF1D8EA82E80D55D3244A7018DCCE2E4C5A2E5795A41AE9
    SHA-512:5A73686C2B3409E2F141D09F951EE53862B7034C6B8E047AE17150EADFEBCD063F816158A974ABAA800CD5608BBE776140A3F8E7B08B5AA2D891F9BA57BA72CF
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="utf-8"?><index> saved from url=(0016)http://localhost -->..<stem n="tile"><phr n="tile"><ent r="4" t="37" w="508" /><ent r="4" t="37" w="511" /><ent r="5" t="166" w="72" /><ent r="4" t="166" w="110" /><ent r="5" t="166" w="120" /><ent r="4" t="166" w="158" /><ent r="3" t="166" w="188" /></phr><phr n="tiled"><ent r="4" t="166" w="95" /><ent r="4" t="166" w="143" /></phr></stem><stem n="horizont"><phr n="horizontally"><ent r="4" t="37" w="509" /><ent r="4" t="43" w="281" /><ent r="3" t="43" w="515" /><ent r="4" t="61" w="418" /><ent r="5" t="166" w="73" /><ent r="4" t="166" w="84" /></phr><phr n="horizontal"><ent r="4" t="40" w="306" /><ent r="4" t="43" w="243" /><ent r="3" t="43" w="475" /><ent r="4" t="49" w="222" /><ent r="3" t="73" w="81" /><ent r="6" t="73" w="365" /><ent r="6" t="73" w="470" /><ent r="6" t="73" w="570" /><ent r="6" t="116" w="630" /><ent r="5" t="154" w="773" /><ent r="4" t="154" w="781" /><ent r="5" t="164" w="168" /><ent r="4" t=
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:exported SGML document, ASCII text, with very long lines (35194), with CRLF line terminators
    Category:dropped
    Size (bytes):35438
    Entropy (8bit):4.018632929634
    Encrypted:false
    SSDEEP:768:7bSKyWcahaGCOOUUVVnvX22X9FcwSfggppSSEEoZS66++77wwSSooTTss//vvLLj:PsfeTH
    MD5:EFF7C899DDCE0884D5140BCB2EEF3CD6
    SHA1:6F2302DC09BE86353D62262B3FF57840D991EB7B
    SHA-256:5CA560529EE93784107FA8F3E162213FE3BCFA6C184C65A223600F61A15EEB29
    SHA-512:7DC2D385486FD8A3DF5FBF2BCFD69C2EC49C800FA3625BB812F6024B85A1FEA2A000985E233463CE685C6A979AD5C4CA8721C87C855BC56949D4CA028DAC35CD
    Malicious:false
    Reputation:low
    Preview:var xmlSearch_Chunk68Data = "";..xmlSearch_Chunk68Data += '<?xml version=\"1.0\" encoding=\"utf-8\"?><index> saved from url=(0016)http://localhost -->';..xmlSearch_Chunk68Data += '<stem n=\"answer\"><phr n=\"Answer\"><ent r=\"4\" t=\"8\" w=\"110\" /><ent r=\"4\" t=\"8\" w=\"110\" /></phr><phr n=\"answer\"><ent r=\"64\" t=\"130\" w=\"141\" /><ent r=\"64\" t=\"130\" w=\"145\" /></phr></stem><stem n=\"accordingli\"><phr n=\"accordingly\"><ent r=\"4\" t=\"8\" w=\"115\" /><ent r=\"4\" t=\"60\" w=\"117\" /><ent r=\"4\" t=\"60\" w=\"258\" /><ent r=\"3\" t=\"108\" w=\"74\" /><ent r=\"3\" t=\"173\" w=\"108\" /></phr></stem><stem n=\"finish\"><phr n=\"finished\"><ent r=\"4\" t=\"8\" w=\"157\" /><ent r=\"4\" t=\"8\" w=\"157\" /><ent r=\"3\" t=\"11\" w=\"1516\" /><ent r=\"3\" t=\"12\" w=\"1550\" /><ent r=\"3\" t=\"14\" w=\"1578\" /><ent r=\"4\" t=\"21\" w=\"295\" /><ent r=\"4\" t=\"22\" w=\"173\" /><ent r=\"4\" t=\"22\" w=\"173\" /><ent r=\"4\" t=\"69\" w=\"1489\" /><ent r=\"4\" t=\"69\" w=\"1
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text, with very long lines (18948), with CRLF line terminators
    Category:dropped
    Size (bytes):19041
    Entropy (8bit):4.521575725000465
    Encrypted:false
    SSDEEP:384:9EZPFhMEaW37hLTJT3OAGhVhCvoI90NN2hT4NQRV+4JOyDrVqqeBBJx0Sv+8prLr:9EZPFhMEaW37hLTJT3OAGhVhCvoI90Nb
    MD5:635BD69CDE5D99965787F47A7A5DDF3A
    SHA1:F0AAC0D60C0DAFAA1DBA55893B52931BB6D50159
    SHA-256:3C6063D9B8C0F19B75BFB0297A216E6D5767AD742D8FAE07EE9995033A608F73
    SHA-512:0E821F3CD2CC75F86C64DB5BF5C6FFC07BD09C46A2214E226B3CBCC0AA7D2909924D1FCFAB5366A13976579C70496E1CC0EB60F3D4577BE09A90E2B7C4F0C6DE
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="utf-8"?><index> saved from url=(0016)http://localhost -->..<stem n="protocol"><phr n="protocol"><ent r="3" t="151" w="1615" /><ent r="4" t="184" w="247" /></phr></stem><stem n="fraction"><phr n="fractional"><ent r="5" t="152" w="304" /><ent r="4" t="152" w="312" /></phr></stem><stem n="facilit"><phr n="facilitate"><ent r="4" t="152" w="358" /><ent r="4" t="194" w="426" /></phr></stem><stem n="split"><phr n="split"><ent r="4" t="152" w="367" /><ent r="4" t="192" w="154" /><ent r="3" t="194" w="202" /></phr><phr n="splits"><ent r="4" t="194" w="435" /></phr></stem><stem n="quot"><phr n="quotes"><ent r="5" t="152" w="377" /><ent r="4" t="152" w="546" /><ent r="4" t="189" w="35" /></phr></stem><stem n="quotat"><phr n="quotations"><ent r="4" t="152" w="394" /></phr><phr n="quotation"><ent r="4" t="152" w="420" /><ent r="4" t="192" w="37" /><ent r="4" t="192" w="86" /></phr></stem><stem n="slash"><phr n="slash"><ent r="4" t="152" w="606" /><ent r="4" t="156"
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text, with very long lines (26953), with CRLF line terminators
    Category:dropped
    Size (bytes):27046
    Entropy (8bit):4.042317027443486
    Encrypted:false
    SSDEEP:768:qTsDoHjEunuS4RvGFLSzFQO7u5z93lo3kFqhs7MFazy2BBzu6uSb2VRbDNu3Ep8X:DPnVvVjP6qtGmsZGjzzm
    MD5:48B58AA2B22A32E1676607CE92CEB18D
    SHA1:0B46EDD6A0627C1F8CBCE546CC70866D29C33C51
    SHA-256:80B83A661452AF900FCD2E873A97D58B7D6B75D16FC174E50D004852AF867227
    SHA-512:FB85D7D39177E923513FBAAF8AEBC077FCE1F104F24120CF3676AA9957C0E6A54B40607DE90DBD611552339EE2A7FB00A87416C670E457E9679E47D362D8FBB4
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="utf-8"?><index> saved from url=(0016)http://localhost -->..<stem n="overwrit"><phr n="overwrite"><ent r="4" t="3" w="1289" /><ent r="6" t="10" w="1170" /><ent r="6" t="11" w="986" /><ent r="6" t="12" w="1091" /><ent r="6" t="13" w="1062" /><ent r="6" t="14" w="1116" /><ent r="6" t="15" w="1065" /><ent r="4" t="17" w="1374" /><ent r="3" t="123" w="651" /><ent r="3" t="123" w="704" /><ent r="6" t="194" w="91" /></phr><phr n="overwriting"><ent r="3" t="80" w="82" /><ent r="3" t="187" w="138" /></phr></stem><stem n="exist"><phr n="existing"><ent r="4" t="3" w="1290" /><ent r="4" t="37" w="42" /><ent r="4" t="55" w="78" /><ent r="4" t="58" w="14" /><ent r="4" t="58" w="45" /><ent r="3" t="65" w="85" /><ent r="3" t="66" w="568" /><ent r="3" t="80" w="85" /><ent r="4" t="99" w="126" /><ent r="4" t="101" w="159" /><ent r="3" t="119" w="112" /><ent r="3" t="123" w="653" /><ent r="3" t="126" w="363" /><ent r="4" t="150" w="211" /><ent r="4" t="163" w="51" /><ent
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:exported SGML document, ASCII text, with very long lines (32046), with CRLF line terminators
    Category:dropped
    Size (bytes):32290
    Entropy (8bit):4.412772663837532
    Encrypted:false
    SSDEEP:768:oZmYSNmkyw7DrUaoPS0Ia47onSu5kZOL4goIldPlgsRhblwipsnTgGkpOJmFduSA:vJ5jAdHhOX/rIdhYVqIJ4KlUar
    MD5:2FBC37F0BE22086224ABD4DCD9772EF1
    SHA1:8916FB450377FC88C34893E3D42C9161C9B9312A
    SHA-256:B9A26D4BCB07D5767CE52FD2A6AC4702C34C727E5A60806A1B22618A579491C1
    SHA-512:6C767478711B1487937DB3F7BB82DAEF1F25BDA5F2217B8CCAA0D523E9EAAA3499515E508744068A06B94925AAE1BE9DE57BF5F2816F98B3EC5C5E5A976B89A4
    Malicious:false
    Reputation:low
    Preview:var xmlSearch_Chunk58Data = "";..xmlSearch_Chunk58Data += '<?xml version=\"1.0\" encoding=\"utf-8\"?><index> saved from url=(0016)http://localhost -->';..xmlSearch_Chunk58Data += '<stem n=\"share\"><phr n=\"shared\"><ent r=\"6\" t=\"101\" w=\"103\" /><ent r=\"3\" t=\"123\" w=\"346\" /><ent r=\"3\" t=\"123\" w=\"756\" /><ent r=\"6\" t=\"146\" w=\"323\" /><ent r=\"6\" t=\"147\" w=\"160\" /></phr><phr n=\"sharing\"><ent r=\"1048578\" t=\"116\" w=\"739\" /><ent r=\"3\" t=\"116\" w=\"745\" /><ent r=\"4\" t=\"121\" w=\"382\" /><ent r=\"4\" t=\"121\" w=\"771\" /><ent r=\"3\" t=\"123\" w=\"383\" /><ent r=\"3\" t=\"123\" w=\"519\" /><ent r=\"4\" t=\"150\" w=\"157\" /></phr><phr n=\"share\"><ent r=\"3\" t=\"118\" w=\"164\" /><ent r=\"4\" t=\"121\" w=\"103\" /><ent r=\"3\" t=\"121\" w=\"217\" /><ent r=\"3\" t=\"121\" w=\"620\" /><ent r=\"4\" t=\"123\" w=\"70\" /><ent r=\"4\" t=\"123\" w=\"192\" /><ent r=\"3\" t=\"123\" w=\"460\" /><ent r=\"3\" t=\"123\" w=\"497\" /><ent r=\"3\" t=\"123\" w=\"
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text, with very long lines (27646), with CRLF line terminators
    Category:dropped
    Size (bytes):27739
    Entropy (8bit):3.960641440537542
    Encrypted:false
    SSDEEP:768:dy3hERVyAHbEYDAzE52MJgaQ5XVZIn+y1Qwrocv4BGAOMHNkbU9oqTROblW5o9j5:9AiKAH+xlop8rcsk0WBnu5jTluaPHt5W
    MD5:3B66EFA61A20E940F16E33FD48558878
    SHA1:2C43731A3EDF8B992EF5E4D3CAB8088D9DAEF880
    SHA-256:29DB47C3113B6641A947485E6330D262A63C183040BAE41C5CACEBE4DFB2C692
    SHA-512:E90392C07AC51EDB7D0AA9E52F4EEC664EF5FF8FEA431D57E260F0381E0F3E3FE9C968C60AB90E54B36C0B8DA14F204DD873A0E5EED6E58EB3EB2D8D685F975C
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="utf-8"?><index> saved from url=(0016)http://localhost -->..<stem n="font"><phr n="font"><ent r="8" t="1" w="150" /><ent r="4" t="49" w="233" /><ent r="4" t="53" w="84" /><ent r="5" t="55" w="324" /><ent r="5" t="55" w="327" /><ent r="5" t="55" w="333" /><ent r="5" t="55" w="337" /><ent r="3" t="116" w="462" /><ent r="3" t="154" w="152" /><ent r="3" t="154" w="179" /><ent r="3" t="154" w="188" /></phr><phr n="fonts"><ent r="4" t="150" w="88" /><ent r="3" t="154" w="13" /><ent r="1048578" t="154" w="143" /><ent r="3" t="154" w="147" /></phr></stem><stem n="type"><phr n="type"><ent r="4" t="1" w="151" /><ent r="3" t="2" w="369" /><ent r="4" t="2" w="655" /><ent r="4" t="3" w="646" /><ent r="3" t="4" w="172" /><ent r="3" t="5" w="105" /><ent r="3" t="5" w="564" /><ent r="3" t="9" w="69" /><ent r="4" t="9" w="206" /><ent r="3" t="9" w="505" /><ent r="3" t="9" w="572" /><ent r="4" t="10" w="238" /><ent r="4" t="10" w="267" /><ent r="4" t="10" w="299" /><ent
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, Unicode text, UTF-8 text, with very long lines (27361), with CRLF line terminators
    Category:dropped
    Size (bytes):27457
    Entropy (8bit):4.385287918841305
    Encrypted:false
    SSDEEP:768:5AaaccE4t++RRSJvCC5o5oYYccMFF44cM2mxFOZOLLkkuuwwSS22VcjJ+p886ZZs:zaButHDNXCnr
    MD5:C37BFCB12A1C3E645A591DF014E8F232
    SHA1:57D003E6116536409431A995219DCC35371BDE70
    SHA-256:73218EB7737CB90CD049147C7FF6D849B2BFABAA80BFAA18AE9AF87156397D89
    SHA-512:E2747666C13CE7DDFD0895AE3FE3A9A4345EF6AC4446A016A7439E5C2CA556F22DCC5C77CCA4A31841450DA162B183737A18DD8154AE4BF4A449F494258AC48E
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="utf-8"?><index> saved from url=(0016)http://localhost -->..<stem n="redon"><phr n="redone"><ent r="3" t="62" w="160" /></phr></stem><stem n="unlimit"><phr n="unlimited"><ent r="3" t="62" w="204" /><ent r="3" t="62" w="204" /><ent r="3" t="62" w="220" /><ent r="3" t="62" w="220" /><ent r="3" t="151" w="1358" /><ent r="3" t="151" w="1358" /><ent r="3" t="151" w="1383" /><ent r="3" t="151" w="1383" /></phr></stem><stem n="altogeth"><phr n="altogether"><ent r="3" t="62" w="215" /></phr></stem><stem n="slower"><phr n="slower"><ent r="3" t="62" w="229" /><ent r="3" t="62" w="229" /><ent r="4" t="150" w="311" /><ent r="4" t="150" w="311" /><ent r="4" t="150" w="354" /><ent r="4" t="150" w="354" /><ent r="3" t="151" w="1392" /><ent r="3" t="151" w="1392" /></phr></stem><stem n="transduc"><phr n="transducer"><ent r="3" t="64" w="41" /><ent r="3" t="64" w="41" /><ent r="4" t="64" w="515" /><ent r="4" t="64" w="515" /><ent r="4" t="72" w="262" /><ent r="4" t="72"
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text, with very long lines (28289), with CRLF line terminators
    Category:dropped
    Size (bytes):28382
    Entropy (8bit):4.024656325928842
    Encrypted:false
    SSDEEP:768:UrLLhhDDzzZZpTz+Hw4lxfhbYMqQQX5YeeNN2SC5555kkPPvvNNddJJpvtKddQGr:xP6rGlwf833yToYFyqQgv/6aHRBSDDkm
    MD5:3921489DEA64E571056EF4267C01001E
    SHA1:38DD526EEC4877410F6A0BFE0B313DAC7C411122
    SHA-256:30D9C244C8F58DCC814C262296EC4B6E182D0C1DA41A666FDCD985CE15BABD98
    SHA-512:826E124D86F1C2818BA462FF4FD467E3A394AA6D29423128302DC0EC73AC66332A87CA14CE1CCB5490346343BE2180A6C38231F294535271F64CB8533A2C914C
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="utf-8"?><index> saved from url=(0016)http://localhost -->..<stem n="small"><phr n="small"><ent r="4" t="7" w="274" /><ent r="4" t="7" w="274" /><ent r="4" t="31" w="198" /><ent r="4" t="31" w="198" /><ent r="3" t="40" w="243" /><ent r="3" t="40" w="243" /><ent r="3" t="40" w="421" /><ent r="3" t="40" w="421" /><ent r="4" t="97" w="640" /><ent r="4" t="97" w="640" /><ent r="5" t="154" w="711" /><ent r="5" t="154" w="711" /><ent r="3" t="163" w="232" /><ent r="3" t="163" w="232" /></phr></stem><stem n="9-pin"><phr n="9-pin"><ent r="4" t="7" w="333" /><ent r="4" t="7" w="333" /></phr></stem><stem n="9"><phr n="9"><ent r="4" t="7" w="333" /><ent r="6" t="10" w="978" /><ent r="6" t="11" w="806" /><ent r="6" t="12" w="927" /><ent r="6" t="13" w="885" /><ent r="6" t="14" w="940" /><ent r="5" t="15" w="1114" /><ent r="6" t="16" w="1158" /><ent r="4" t="29" w="388" /><ent r="4" t="29" w="401" /><ent r="4" t="29" w="408" /><ent r="4" t="29" w="440" /><ent r="4"
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text, with very long lines (27314), with CRLF line terminators
    Category:dropped
    Size (bytes):27407
    Entropy (8bit):4.317920392436308
    Encrypted:false
    SSDEEP:768:KR2p8aa2kFJLf2y6YV2O5MfjD5rrTTWpcooppZS/8h00vplHH7JcAnfdpzzNwYY9:sG6
    MD5:E58AFBC6AFF994BDC8577953920E684F
    SHA1:3A1E269EB73ADE988963EF579EA142C1A584D54C
    SHA-256:C861B5D5DC8A63563E7F0923B6F9ACE0D391F925CB47C04AA7541BF9CCCD6CCD
    SHA-512:FE6F07CFD5FA1B326F06FE2A16ED5419B9FC315D246226D9277F5B0992BA9D0F11A6B935B67BCB14599C399114377BE309E480A4E70CAC01EDF272ED3704A36A
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="utf-8"?><index> saved from url=(0016)http://localhost -->..<stem n="portabl"><phr n="portable"><ent r="3" t="68" w="646" /><ent r="3" t="68" w="646" /></phr></stem><stem n="launchtim"><phr n="launchtime"><ent r="3" t="68" w="653" /></phr></stem><stem n="notebook"><phr n="notebook"><ent r="3" t="68" w="701" /><ent r="3" t="68" w="701" /><ent r="4" t="68" w="738" /><ent r="4" t="68" w="738" /></phr></stem><stem n="whenev"><phr n="Whenever"><ent r="4" t="68" w="811" /><ent r="4" t="68" w="811" /></phr><phr n="whenever"><ent r="3" t="86" w="68" /><ent r="3" t="86" w="68" /><ent r="4" t="151" w="1155" /><ent r="4" t="151" w="1155" /></phr></stem><stem n="clean"><phr n="clean"><ent r="4" t="68" w="819" /><ent r="4" t="68" w="819" /><ent r="3" t="97" w="276" /><ent r="3" t="97" w="276" /></phr><phr n="cleaning"><ent r="3" t="97" w="1375" /><ent r="3" t="97" w="1375" /></phr></stem><stem n="cotton"><phr n="cotton"><ent r="4" t="68" w="825" /><ent r="4" t="68"
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:exported SGML document, Unicode text, UTF-8 text, with very long lines (32315), with CRLF line terminators
    Category:dropped
    Size (bytes):32562
    Entropy (8bit):4.355540371670447
    Encrypted:false
    SSDEEP:768:m2AAiiuWRUUlloRHUU8866mm2VVCCqGgAVKOjjiiMM22ccUUtujy1CCkVVXooY+8:Usj
    MD5:B376B4A0CCED7795348DB3390C87D023
    SHA1:0A6E76B125578CF131654022790C0234850967DD
    SHA-256:664CEA18C8F94A058E65F6EBC7524404F425A1CE862361DC67A0B201A7E035D5
    SHA-512:9801272043B0DBE2F44E83382BE285BCF02EEEA3CCBB68CA459210358FDAEA771372F9C76926161B815DB583440C4DA6DAC684BA9908F5F85E633A7458245E4D
    Malicious:false
    Reputation:low
    Preview:var xmlSearch_Chunk82Data = "";..xmlSearch_Chunk82Data += '<?xml version=\"1.0\" encoding=\"utf-8\"?><index> saved from url=(0016)http://localhost -->';..xmlSearch_Chunk82Data += '<stem n=\"redon\"><phr n=\"redone\"><ent r=\"3\" t=\"62\" w=\"160\" /></phr></stem><stem n=\"unlimit\"><phr n=\"unlimited\"><ent r=\"3\" t=\"62\" w=\"204\" /><ent r=\"3\" t=\"62\" w=\"204\" /><ent r=\"3\" t=\"62\" w=\"220\" /><ent r=\"3\" t=\"62\" w=\"220\" /><ent r=\"3\" t=\"151\" w=\"1358\" /><ent r=\"3\" t=\"151\" w=\"1358\" /><ent r=\"3\" t=\"151\" w=\"1383\" /><ent r=\"3\" t=\"151\" w=\"1383\" /></phr></stem><stem n=\"altogeth\"><phr n=\"altogether\"><ent r=\"3\" t=\"62\" w=\"215\" /></phr></stem><stem n=\"slower\"><phr n=\"slower\"><ent r=\"3\" t=\"62\" w=\"229\" /><ent r=\"3\" t=\"62\" w=\"229\" /><ent r=\"4\" t=\"150\" w=\"311\" /><ent r=\"4\" t=\"150\" w=\"311\" /><ent r=\"4\" t=\"150\" w=\"354\" /><ent r=\"4\" t=\"150\" w=\"354\" /><ent r=\"3\" t=\"151\" w=\"1392\" /><ent r=\"3\" t=\"151\" w=\"1
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:exported SGML document, ASCII text, with very long lines (33307), with CRLF line terminators
    Category:dropped
    Size (bytes):33551
    Entropy (8bit):4.025209353327898
    Encrypted:false
    SSDEEP:768:Y5ysENskAKYmjgaVJbqxlocjki0sSyQFrQ8m7yFMkE6wxYO6crP4SnHEEasGP9ez:GkcQv+
    MD5:62DD02A79250E80B957D83935AAF59E0
    SHA1:353FFB3E0374EA7E012FC24B4CA68E69939D94C4
    SHA-256:C5ED79001BAAEFEF8826EA9C38ADA480CECACE83CCA38D47E4E9E18DA2646A4F
    SHA-512:931A613BC13BCDBEA268E29EA9602EB0D3617162264149B7BCE230A38EAE8AAF6DED1AE83684B2B6325623713E6F6E516A5630B6278889F62EA8B910413088E7
    Malicious:false
    Reputation:low
    Preview:var xmlSearch_Chunk40Data = "";..xmlSearch_Chunk40Data += '<?xml version=\"1.0\" encoding=\"utf-8\"?><index> saved from url=(0016)http://localhost -->';..xmlSearch_Chunk40Data += '<stem n=\"u24-002\"><phr n=\"u24-002\"><ent r=\"4\" t=\"3\" w=\"1500\" /><ent r=\"5\" t=\"70\" w=\"163\" /></phr></stem><stem n=\"002\"><phr n=\"002\"><ent r=\"4\" t=\"3\" w=\"1501\" /><ent r=\"4\" t=\"39\" w=\"67\" /><ent r=\"4\" t=\"39\" w=\"135\" /><ent r=\"4\" t=\"39\" w=\"162\" /><ent r=\"4\" t=\"39\" w=\"170\" /><ent r=\"5\" t=\"70\" w=\"164\" /></phr></stem><stem n=\"disabl\"><phr n=\"disable\"><ent r=\"4\" t=\"3\" w=\"1506\" /><ent r=\"3\" t=\"4\" w=\"314\" /><ent r=\"3\" t=\"4\" w=\"578\" /><ent r=\"4\" t=\"12\" w=\"518\" /><ent r=\"4\" t=\"13\" w=\"643\" /><ent r=\"4\" t=\"14\" w=\"750\" /><ent r=\"4\" t=\"16\" w=\"814\" /><ent r=\"4\" t=\"17\" w=\"984\" /><ent r=\"4\" t=\"49\" w=\"244\" /><ent r=\"3\" t=\"56\" w=\"457\" /><ent r=\"3\" t=\"64\" w=\"212\" /><ent r=\"3\" t=\"80\" w=\"421\" /><ent
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text, with very long lines (27379), with CRLF line terminators
    Category:dropped
    Size (bytes):27472
    Entropy (8bit):4.154635630593215
    Encrypted:false
    SSDEEP:768:ss/o5sXLbL8QctdCPNoMwqO8PFQuCSdOcJjL1nJNHQD0wqTh0iZwc5w33Uwo8Zij:Pt0Qr77bUr8JQtCakO5mw8JWtw3Rpr4K
    MD5:196D4416B24607B16C94A8B7CA71A8BD
    SHA1:9C88203CEBEE22CBC641FD3BE1A53CDD01330F18
    SHA-256:74EA74CFC8D117336B55DEC698CDF0238AB783B4E1567FDEF090653FA4A43536
    SHA-512:1535FD1A9DFBA0F299BD1C8FFC9AFD18950E5687E2D8ED5FC97D416731BACC49872DC43A6BE56C6AD1E0FEB0B0C8755F56BFE75884F82A79C18E1DB547BD2101
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="utf-8"?><index> saved from url=(0016)http://localhost -->..<stem n="flash"><phr n="flash"><ent r="5" t="16" w="1201" /><ent r="6" t="17" w="1211" /><ent r="4" t="19" w="242" /><ent r="4" t="31" w="793" /><ent r="4" t="96" w="324" /><ent r="3" t="146" w="677" /></phr><phr n="flashing"><ent r="3" t="140" w="70" /><ent r="4" t="141" w="99" /><ent r="4" t="142" w="112" /></phr></stem><stem n="2000"><phr n="2000"><ent r="4" t="17" w="188" /><ent r="7" t="110" w="298" /><ent r="4" t="192" w="214" /></phr></stem><stem n="built"><phr n="built"><ent r="3" t="17" w="242" /><ent r="3" t="26" w="217" /><ent r="3" t="26" w="239" /><ent r="3" t="169" w="19" /></phr></stem><stem n="ascend"><phr n="ascending"><ent r="4" t="17" w="253" /><ent r="4" t="76" w="335" /><ent r="4" t="86" w="543" /><ent r="4" t="89" w="80" /><ent r="6" t="156" w="482" /><ent r="6" t="156" w="504" /></phr></stem><stem n="posit"><phr n="position"><ent r="4" t="17" w="262" /><ent r="4" t="26" w
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:exported SGML document, ASCII text, with very long lines (32276), with CRLF line terminators
    Category:dropped
    Size (bytes):32520
    Entropy (8bit):4.008236665573068
    Encrypted:false
    SSDEEP:768:EwJJLLeeEE33txfjjNN55UUGG1Dx77ZZMM6633VV/9eiiQQaazz++cbmZZAA33Sy:g
    MD5:78B9C4C56D54805D1FFA927A4F318C64
    SHA1:D362F2EF859CD3A133E1CC332D74D4F7D51EC954
    SHA-256:3ABCBEF2EA5D07A295CBF77FE4F695CF31855C440E68F1731ED8EB42CEA6CBD6
    SHA-512:5447148DA96EC5A9CE3B257B00A5D112FFE3639220FAC85836C2E23B5C777E6B2C34B5152F9FCBE5763C84E5BAC62423712B6E28605ABA76B884B43B8F462B4E
    Malicious:false
    Reputation:low
    Preview:var xmlSearch_Chunk71Data = "";..xmlSearch_Chunk71Data += '<?xml version=\"1.0\" encoding=\"utf-8\"?><index> saved from url=(0016)http://localhost -->';..xmlSearch_Chunk71Data += '<stem n=\"unless\"><phr n=\"Unless\"><ent r=\"4\" t=\"10\" w=\"679\" /><ent r=\"4\" t=\"10\" w=\"679\" /><ent r=\"4\" t=\"11\" w=\"392\" /><ent r=\"4\" t=\"11\" w=\"392\" /><ent r=\"4\" t=\"12\" w=\"502\" /><ent r=\"4\" t=\"12\" w=\"502\" /><ent r=\"4\" t=\"13\" w=\"627\" /><ent r=\"4\" t=\"13\" w=\"627\" /><ent r=\"4\" t=\"14\" w=\"734\" /><ent r=\"4\" t=\"14\" w=\"734\" /><ent r=\"4\" t=\"15\" w=\"798\" /><ent r=\"4\" t=\"15\" w=\"798\" /><ent r=\"4\" t=\"16\" w=\"485\" /><ent r=\"4\" t=\"16\" w=\"485\" /></phr><phr n=\"unless\"><ent r=\"3\" t=\"30\" w=\"53\" /><ent r=\"3\" t=\"30\" w=\"53\" /><ent r=\"3\" t=\"32\" w=\"20\" /><ent r=\"3\" t=\"32\" w=\"20\" /><ent r=\"3\" t=\"34\" w=\"51\" /><ent r=\"3\" t=\"34\" w=\"51\" /><ent r=\"4\" t=\"36\" w=\"168\" /><ent r=\"4\" t=\"36\" w=\"168\" /><ent r=\"3\"
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:exported SGML document, ASCII text, with very long lines (40019), with CRLF line terminators
    Category:dropped
    Size (bytes):40263
    Entropy (8bit):3.9782618834623964
    Encrypted:false
    SSDEEP:768:1YkUPoJGOasRo4XdqsWgZm0vhuCNczut0LAI/V2h/ioCTG2BoRVWCIYfCFSwP7Wc:Vr+dSnpdxX5p50
    MD5:56B8C4DE64D66C5AC66D6EAE5697E9CE
    SHA1:8C6BBB8C68B3AC8BFBDAAC21C6972C568EC0EA52
    SHA-256:4E73022E3A1CD34500000073D4976E6A53C23980D55F902C5513355F08226FDE
    SHA-512:0097742402F5B36468FC7FC67211C5370A7BF3EC3D121F3ECB5489E83DF263C0F1C92952F9A084154361F851D71FCA72694D298786975AFC0B523D4FA5820BB4
    Malicious:false
    Reputation:low
    Preview:var xmlSearch_Chunk30Data = "";..xmlSearch_Chunk30Data += '<?xml version=\"1.0\" encoding=\"utf-8\"?><index> saved from url=(0016)http://localhost -->';..xmlSearch_Chunk30Data += '<stem n=\"via\"><phr n=\"via\"><ent r=\"4\" t=\"3\" w=\"33\" /><ent r=\"4\" t=\"3\" w=\"1292\" /><ent r=\"3\" t=\"7\" w=\"612\" /><ent r=\"3\" t=\"15\" w=\"172\" /><ent r=\"3\" t=\"17\" w=\"36\" /><ent r=\"3\" t=\"26\" w=\"215\" /><ent r=\"4\" t=\"67\" w=\"92\" /><ent r=\"3\" t=\"76\" w=\"50\" /><ent r=\"3\" t=\"85\" w=\"89\" /><ent r=\"3\" t=\"116\" w=\"749\" /><ent r=\"4\" t=\"117\" w=\"86\" /><ent r=\"3\" t=\"118\" w=\"167\" /><ent r=\"4\" t=\"123\" w=\"81\" /><ent r=\"4\" t=\"123\" w=\"246\" /><ent r=\"3\" t=\"123\" w=\"500\" /><ent r=\"3\" t=\"123\" w=\"644\" /><ent r=\"3\" t=\"125\" w=\"107\" /><ent r=\"4\" t=\"128\" w=\"235\" /><ent r=\"4\" t=\"129\" w=\"218\" /><ent r=\"4\" t=\"130\" w=\"367\" /><ent r=\"4\" t=\"131\" w=\"38\" /><ent r=\"4\" t=\"131\" w=\"41\" /><ent r=\"4\" t=\"152\" w=\"903\" />
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text, with very long lines (27218), with CRLF line terminators
    Category:dropped
    Size (bytes):27311
    Entropy (8bit):4.043613393954228
    Encrypted:false
    SSDEEP:768:aPXaXaEEbbHHssJJOOPPuu88xx11EEneWeU7txxYYCCiiKKjjHH22hhZ++cc11s+:gglQlGaoEVZ9ZR6kEceGGswD2STY
    MD5:C9964C9D8F01B2BFF4CE607000F52CE8
    SHA1:3CF29C7252914FAA79C182AF9981485D0BBEC5FC
    SHA-256:0E7AD69F36FFF851CCA55226CF2BFF426D17860E8A71EB369B8B53516948E0B6
    SHA-512:73B9591401B047407521E372230D3F26E73700038C602D3B0C68B79F7D3F9409B6B756E5E9EDC77D86F2D8DD4300602FA7D9319B96F8E510A17376185F4266F6
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="utf-8"?><index> saved from url=(0016)http://localhost -->..<stem n="what"><phr n="what"><ent r="4" t="10" w="258" /><ent r="4" t="10" w="258" /><ent r="4" t="44" w="210" /><ent r="4" t="44" w="210" /><ent r="3" t="88" w="200" /><ent r="3" t="88" w="200" /><ent r="3" t="97" w="436" /><ent r="3" t="97" w="436" /><ent r="5" t="101" w="225" /><ent r="5" t="101" w="225" /><ent r="5" t="101" w="314" /><ent r="5" t="101" w="314" /><ent r="3" t="120" w="455" /><ent r="3" t="120" w="455" /><ent r="4" t="122" w="204" /><ent r="4" t="122" w="204" /><ent r="4" t="126" w="188" /><ent r="4" t="126" w="188" /><ent r="4" t="148" w="378" /><ent r="4" t="148" w="378" /><ent r="4" t="148" w="578" /><ent r="4" t="148" w="578" /><ent r="3" t="153" w="192" /><ent r="3" t="153" w="192" /><ent r="4" t="153" w="304" /><ent r="4" t="153" w="304" /><ent r="4" t="166" w="578" /><ent r="4" t="166" w="578" /><ent r="5" t="172" w="256" /><ent r="5" t="172" w="256" /></phr><phr n="Wh
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:exported SGML document, ASCII text, with very long lines (32679), with CRLF line terminators
    Category:dropped
    Size (bytes):32923
    Entropy (8bit):4.065225850133276
    Encrypted:false
    SSDEEP:768:9ssjjIIVVaSHmmkk//QQKK88JjI3KCjsw375hhuuT0XTTDDMChhnyf88ToaaHEFU:m0jxb
    MD5:A3225EC579E4452C7A1ADEF93CE1FCE3
    SHA1:53E1E4FECA24642A3C9871AA67D299C442E27B7A
    SHA-256:11543C1CAF693B6D26B1E4E4918A697B04FB12A923E8D725025AC24E4E3ADCA8
    SHA-512:E57BBBDF4893DDF8B49FE3E3F1E7A1345008BD087599F33E89542572BB3016A1126747B6DA1487CB955EC48231CA04DC56550E31A6A34F1CA50B88F46393CA05
    Malicious:false
    Reputation:low
    Preview:var xmlSearch_Chunk67Data = "";..xmlSearch_Chunk67Data += '<?xml version=\"1.0\" encoding=\"utf-8\"?><index> saved from url=(0016)http://localhost -->';..xmlSearch_Chunk67Data += '<stem n=\"proce\"><phr n=\"proceed\"><ent r=\"3\" t=\"7\" w=\"703\" /><ent r=\"4\" t=\"97\" w=\"917\" /><ent r=\"4\" t=\"97\" w=\"917\" /><ent r=\"4\" t=\"97\" w=\"1216\" /><ent r=\"4\" t=\"97\" w=\"1216\" /><ent r=\"4\" t=\"125\" w=\"135\" /><ent r=\"4\" t=\"125\" w=\"135\" /><ent r=\"4\" t=\"126\" w=\"133\" /><ent r=\"4\" t=\"126\" w=\"133\" /><ent r=\"4\" t=\"127\" w=\"175\" /><ent r=\"4\" t=\"127\" w=\"175\" /></phr></stem><stem n=\"blink\"><phr n=\"Blink\"><ent r=\"3\" t=\"7\" w=\"743\" /><ent r=\"3\" t=\"7\" w=\"743\" /></phr><phr n=\"blink\"><ent r=\"6\" t=\"10\" w=\"1185\" /><ent r=\"6\" t=\"13\" w=\"940\" /><ent r=\"6\" t=\"13\" w=\"940\" /><ent r=\"6\" t=\"13\" w=\"977\" /><ent r=\"6\" t=\"13\" w=\"977\" /><ent r=\"6\" t=\"14\" w=\"995\" /><ent r=\"6\" t=\"14\" w=\"995\" /><ent r=\"3\" t=\"23\"
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:exported SGML document, ASCII text, with very long lines (33948), with CRLF line terminators
    Category:dropped
    Size (bytes):34192
    Entropy (8bit):4.025354722390734
    Encrypted:false
    SSDEEP:768:NGiIbA3xb/1EVMsMgoC0sZiy83aGCetVbl2R6gFW0V+kJG4Dq0H5qk3q+S16fCYd:ea2eP6Mc1TD
    MD5:BC779607B72CE45FF029A9ABCD4B8F79
    SHA1:61DF6B01AA74A0CD7F1198767B59810A1D12BD70
    SHA-256:139A25400BE249C1B70C766A623AB81E2999CAEB10C8AC95B0B3AC19F4D886BF
    SHA-512:2EF9FE1B870850534AD3318C5FCD3650200FCC87420C3E51389D0CB9105F50B130959BF355E3E879A5A7EF4570DFFDCD7A5B85F591B4A10A4948CAAA153A612C
    Malicious:false
    Reputation:low
    Preview:var xmlSearch_Chunk36Data = "";..xmlSearch_Chunk36Data += '<?xml version=\"1.0\" encoding=\"utf-8\"?><index> saved from url=(0016)http://localhost -->';..xmlSearch_Chunk36Data += '<stem n=\"datafil\"><phr n=\"datafiles\"><ent r=\"5\" t=\"3\" w=\"658\" /><ent r=\"3\" t=\"5\" w=\"49\" /><ent r=\"3\" t=\"36\" w=\"76\" /><ent r=\"4\" t=\"36\" w=\"248\" /><ent r=\"3\" t=\"39\" w=\"25\" /><ent r=\"4\" t=\"46\" w=\"432\" /><ent r=\"3\" t=\"62\" w=\"14\" /><ent r=\"4\" t=\"62\" w=\"60\" /><ent r=\"4\" t=\"62\" w=\"80\" /><ent r=\"4\" t=\"76\" w=\"92\" /><ent r=\"4\" t=\"78\" w=\"63\" /><ent r=\"3\" t=\"86\" w=\"381\" /><ent r=\"3\" t=\"95\" w=\"15\" /><ent r=\"4\" t=\"95\" w=\"52\" /><ent r=\"3\" t=\"96\" w=\"416\" /><ent r=\"3\" t=\"98\" w=\"384\" /><ent r=\"3\" t=\"151\" w=\"1525\" /><ent r=\"4\" t=\"156\" w=\"538\" /><ent r=\"4\" t=\"158\" w=\"117\" /><ent r=\"3\" t=\"161\" w=\"18\" /><ent r=\"5\" t=\"161\" w=\"77\" /><ent r=\"3\" t=\"165\" w=\"26\" /><ent r=\"3\" t=\"177\" w=\"49\" /><
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text, with very long lines (27241), with CRLF line terminators
    Category:dropped
    Size (bytes):27334
    Entropy (8bit):4.360463776795224
    Encrypted:false
    SSDEEP:768:4vIIRoWbbTTtS3xcqjr2YE23ECkydgtFxvvzzfSRjPPys1rcGtnfKoZrd45pp++q:PLApgsMqUOdufG6
    MD5:234E07F2D879C9A3B4DC19E782DBAD25
    SHA1:1DA63642EDEDCF7AE3B6FB5DC3E950F6F0785FFF
    SHA-256:20FDC7CD0ECF908613FB743A4F72BB6E65BC1FE33DC04EF1F2EE2157C1E2EAF8
    SHA-512:0A3365DB484772375B0CFB9CC73F634AF9E15B9A3E2D5123FF0F23E22D4F9AE6345AC5A5C39423784DF1752E71926FBAA90C738B8316C8938EFDEA9A6387627D
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="utf-8"?><index> saved from url=(0016)http://localhost -->..<stem n="resourc"><phr n="resources"><ent r="4" t="79" w="181" /></phr></stem><stem n="incom"><phr n="incoming"><ent r="4" t="79" w="279" /><ent r="4" t="79" w="279" /><ent r="4" t="100" w="185" /><ent r="4" t="100" w="185" /><ent r="3" t="145" w="452" /><ent r="3" t="145" w="452" /></phr></stem><stem n="year"><phr n="year"><ent r="4" t="79" w="283" /><ent r="4" t="79" w="283" /><ent r="4" t="149" w="619" /><ent r="4" t="149" w="619" /><ent r="3" t="153" w="231" /><ent r="3" t="153" w="231" /><ent r="4" t="153" w="313" /><ent r="4" t="153" w="327" /><ent r="4" t="153" w="327" /></phr><phr n="years"><ent r="4" t="96" w="240" /><ent r="4" t="96" w="240" /></phr><phr n="Year"><ent r="4" t="149" w="594" /><ent r="4" t="149" w="597" /><ent r="4" t="149" w="599" /><ent r="4" t="153" w="290" /><ent r="4" t="153" w="293" /><ent r="4" t="153" w="295" /><ent r="5" t="153" w="320" /><ent r="5" t="153" w="
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Unicode text, UTF-8 text, with very long lines (29757), with no line terminators
    Category:dropped
    Size (bytes):29808
    Entropy (8bit):5.087127158946169
    Encrypted:false
    SSDEEP:384:WVbLTrznBEky+cDyK0t7iWIIA6v6OD6bDiZEsJl2pkRRRZ6chA/zCd3PoaJo+UBM:WVbLTrznplZHJTEMvZ2Zucu2ccHxvLdC
    MD5:2518EFCF262FCC793E54884B43913A5D
    SHA1:0903FB478ADCE550B9C9F6275C1EED6BED0E7166
    SHA-256:3088B7C95118629ED18AA4632DC4F843477DC0CCF9FC2A37710926970ECD6A9D
    SHA-512:A6E98A0E245115D8589C3BB1337FF890BA9392CF8A3536CD2B339743C69D36EA1AC75F7585912D839037980F434AB2FBE3406D6303344F8332C696228E154D2A
    Malicious:false
    Reputation:low
    Preview:define({"69":{y:0,u:"../Content/HOBOware/Data Assistants/da-cond.htm",l:-1,t:"Conductivity Assistant",i:0.00360678445995186,a:"The Conductivity Assistant converts raw conductivity data from a U24 logger to Specific Conductance and/or Salinity. You can also use it to enter field calibration measurements recorded at the beginning and end of a deployment for calibration and to compensate for drift and sensor fouling effects. ..."},"70":{y:0,u:"../Content/HOBOware/Data Assistants/da-do.htm",l:-1,t:"Dissolved Oxygen Assistant",i:0.00297466171724492,a:"The Dissolved Oxygen Assistant corrects for measurement drift from fouling and provides salinity-adjusted DO concentration as well as percent saturation data. Read out a U26 series logger or open a datafile from a U26 logger. From the Plot Setup window, select the Dissolved Oxygen Assistant and ..."},"71":{y:0,u:"../Content/HOBOware/Data Assistants/da-gpp.htm",l:-1,t:"Grains Per Pound Assistant",i:0.00292614815270489,a:"The Grains Per Pound A
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text, with very long lines (37825), with CRLF line terminators
    Category:dropped
    Size (bytes):37918
    Entropy (8bit):3.9144535995717242
    Encrypted:false
    SSDEEP:768:IQ8hOGvmiBdCcyC2F+bb1hrgSP3CPpwkduvPaQa4DYIhJW3HisbJZF2bV/yT+afL:A2c2vbGF5A49cQrsCi
    MD5:69DD6A318204B96B2F2A877E5E69F9D7
    SHA1:88EFB616F625A9A61BE8C6F11618134C73B0ED7B
    SHA-256:42C56496B17A3E7580556624872D223BFCF0DAEB5E05151AE494DABD0DC55073
    SHA-512:4A72B6AC159E1C79F468CEB299129FC17FD60B5129EE6977D93C3561C934A547FDEACF7295396F020DD0749DEBEDEB0592F336C3BFAD070876E6AC8EB1027C0F
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="utf-8"?><index> saved from url=(0016)http://localhost -->..<stem n="hobo"><phr n="hobo"><ent r="5" t="0" w="29" /><ent r="4" t="0" w="166" /><ent r="3" t="1" w="23" /><ent r="4" t="1" w="90" /><ent r="4" t="1" w="103" /><ent r="5" t="1" w="296" /><ent r="3" t="2" w="698" /><ent r="5" t="3" w="61" /><ent r="5" t="3" w="218" /><ent r="4" t="3" w="254" /><ent r="4" t="3" w="328" /><ent r="4" t="3" w="398" /><ent r="4" t="3" w="455" /><ent r="5" t="3" w="478" /><ent r="4" t="3" w="839" /><ent r="4" t="3" w="905" /><ent r="4" t="3" w="988" /><ent r="4" t="3" w="1076" /><ent r="4" t="3" w="1093" /><ent r="4" t="3" w="1303" /><ent r="5" t="3" w="1423" /><ent r="4" t="3" w="1473" /><ent r="4" t="3" w="1497" /><ent r="8" t="5" w="646" /><ent r="4" t="5" w="749" /><ent r="268435456" t="6" w="3" /><ent r="16777218" t="6" w="9" /><ent r="3" t="6" w="15" /><ent r="3" t="7" w="8" /><ent r="3" t="7" w="22" /><ent r="3" t="7" w="25" /><ent r="3" t="7" w="29" /><ent r=
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:exported SGML document, ASCII text, with very long lines (65378), with CRLF line terminators
    Category:dropped
    Size (bytes):70013
    Entropy (8bit):3.92608741722553
    Encrypted:false
    SSDEEP:768:QM6IBMU1NekyGvNeaGUTAUoV52jBd3FDlqHfweEeCOP4LnaG7lvsh0xcJVd+1oV1:vSvI8e0
    MD5:CDCE01F783A87BA536B729198F00B11D
    SHA1:89552FA89A393AB659896B0541643FF923C67DA3
    SHA-256:E86CFA1FC6E2DB13DC36CFC6F1AF1FD3DFBA43FF67B47D413035C76D83EFBD0A
    SHA-512:B1EE043DDE20B6BADDD05A04EBD29036088E140B82DC25D377DC7C54B47D5716EEF87938ED8DCC827CE5E0603916346E565EB72C8E96FC29C004A34ABEB42AFA
    Malicious:false
    Reputation:low
    Preview:var xmlSearch_Chunk23Data = "";..xmlSearch_Chunk23Data += '<?xml version=\"1.0\" encoding=\"utf-8\"?><index> saved from url=(0016)http://localhost -->';..xmlSearch_Chunk23Data += '<stem n=\"now\"><phr n=\"now\"><ent r=\"3\" t=\"2\" w=\"216\" /><ent r=\"4\" t=\"3\" w=\"116\" /><ent r=\"4\" t=\"3\" w=\"459\" /><ent r=\"4\" t=\"3\" w=\"1199\" /><ent r=\"6\" t=\"10\" w=\"944\" /><ent r=\"6\" t=\"11\" w=\"777\" /><ent r=\"6\" t=\"12\" w=\"903\" /><ent r=\"6\" t=\"13\" w=\"859\" /><ent r=\"6\" t=\"14\" w=\"913\" /><ent r=\"6\" t=\"15\" w=\"861\" /><ent r=\"5\" t=\"16\" w=\"1086\" /><ent r=\"6\" t=\"17\" w=\"1112\" /><ent r=\"4\" t=\"30\" w=\"424\" /><ent r=\"4\" t=\"76\" w=\"449\" /><ent r=\"4\" t=\"88\" w=\"291\" /><ent r=\"3\" t=\"118\" w=\"369\" /><ent r=\"131076\" t=\"133\" w=\"253\" /><ent r=\"131076\" t=\"133\" w=\"275\" /><ent r=\"4\" t=\"151\" w=\"422\" /><ent r=\"4\" t=\"151\" w=\"432\" /><ent r=\"4\" t=\"151\" w=\"462\" /><ent r=\"4\" t=\"151\" w=\"528\" /><ent r=\"3\" t=\"173\
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:exported SGML document, Unicode text, UTF-8 text, with very long lines (32129), with CRLF line terminators
    Category:dropped
    Size (bytes):32375
    Entropy (8bit):4.390871894156112
    Encrypted:false
    SSDEEP:768:pnQPs3cL6Agk4/XTygMMLIdR0ihEgvVvyOI+LGcNoVzo4ZUdAmNw/bBq2nTh6UPi:6lFiVm8cJb
    MD5:9A3A51DCEC466AFB3BB5E0474E8504A8
    SHA1:A38EAA393E5467DEC95F11ACFFA72C3425C4398A
    SHA-256:A27B91ECCC317A723CD25D09F47720F471A7C568676F9F00B45427E36E4AB6D7
    SHA-512:E1415060247FA4FB6DC1715545B724A717A9B3DB2ABEBF549FCD792ED66BAE7585FBBB39A50E825A7C3586C2062ABCED5FEDF3D68D5CA8A3FEED0D43F9B24F31
    Malicious:false
    Reputation:low
    Preview:var xmlSearch_Chunk56Data = "";..xmlSearch_Chunk56Data += '<?xml version=\"1.0\" encoding=\"utf-8\"?><index> saved from url=(0016)http://localhost -->';..xmlSearch_Chunk56Data += '<stem n=\"s-ucb\"><phr n=\"s-ucb\"><ent r=\"4\" t=\"68\" w=\"122\" /><ent r=\"3\" t=\"74\" w=\"74\" /></phr></stem><stem n=\"s-ucb-xxxx\"><phr n=\"s-ucb-xxxx\"><ent r=\"4\" t=\"68\" w=\"122\" /><ent r=\"3\" t=\"74\" w=\"74\" /></phr></stem><stem n=\"ucb\"><phr n=\"ucb\"><ent r=\"4\" t=\"68\" w=\"123\" /><ent r=\"3\" t=\"74\" w=\"75\" /></phr></stem><stem n=\"ucb-xxxx\"><phr n=\"ucb-xxxx\"><ent r=\"4\" t=\"68\" w=\"123\" /><ent r=\"3\" t=\"74\" w=\"75\" /></phr></stem><stem n=\"s-ucd\"><phr n=\"s-ucd\"><ent r=\"4\" t=\"68\" w=\"126\" /><ent r=\"3\" t=\"74\" w=\"78\" /></phr></stem><stem n=\"s-ucd-xxxx\"><phr n=\"s-ucd-xxxx\"><ent r=\"4\" t=\"68\" w=\"126\" /><ent r=\"3\" t=\"74\" w=\"78\" /></phr></stem><stem n=\"ucd\"><phr n=\"ucd\"><ent r=\"4\" t=\"68\" w=\"127\" /><ent r=\"3\" t=\"74\" w=\"79\" /></phr>
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text, with very long lines (27170), with CRLF line terminators
    Category:dropped
    Size (bytes):27263
    Entropy (8bit):4.06856237360604
    Encrypted:false
    SSDEEP:768:HxKboE3bF9wLsN64m8lMpNj2z5iyz1xZjqRgTlhZ/MPmGLhKpTpNA8mC7vpTyxf+:aNY07Bdq14wustjE2D1NwX
    MD5:847F5FF8DC88D0179F965A8DC7F05948
    SHA1:6C688162B5A91CB919569D1FE7C3DBF65214B282
    SHA-256:09423A541E2C08C5736829DFB30E673D96DB1F9578149529AB95B1B60F1F0406
    SHA-512:B56979C3C950E55C438491BDE90741218AA70E628395965A81F2D97FBF7C5DFA9A2A7282C4A8BBC503108DEAF2C9191D028C8E114814B9176F2B9C047A8751B2
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="utf-8"?><index> saved from url=(0016)http://localhost -->..<stem n="cabl"><phr n="cable"><ent r="3" t="7" w="20" /><ent r="3" t="7" w="39" /><ent r="3" t="7" w="249" /><ent r="4" t="7" w="262" /><ent r="4" t="7" w="279" /><ent r="3" t="7" w="325" /><ent r="4" t="7" w="339" /><ent r="4" t="7" w="359" /><ent r="4" t="7" w="522" /><ent r="3" t="7" w="597" /><ent r="3" t="11" w="1514" /><ent r="4" t="12" w="244" /><ent r="3" t="12" w="1544" /><ent r="3" t="14" w="1569" /><ent r="3" t="15" w="174" /><ent r="3" t="15" w="1315" /><ent r="4" t="16" w="338" /><ent r="3" t="17" w="38" /><ent r="3" t="17" w="42" /><ent r="4" t="36" w="371" /><ent r="4" t="67" w="63" /><ent r="4" t="67" w="69" /><ent r="4" t="67" w="71" /><ent r="4" t="67" w="76" /><ent r="4" t="67" w="78" /><ent r="4" t="85" w="134" /><ent r="4" t="85" w="228" /><ent r="4" t="85" w="317" /><ent r="4" t="85" w="409" /><ent r="4" t="85" w="452" /><ent r="4" t="85" w="618" /><ent r="4" t="87" w="67"
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text, with very long lines (27567), with CRLF line terminators
    Category:dropped
    Size (bytes):27660
    Entropy (8bit):4.42549110626363
    Encrypted:false
    SSDEEP:768:UR0unnRRHHiy3jjJJggawUMrC8QNNudp8HFbXpjzZJgwtyeIZZEEA+fZk/mounuP:21u1xZmqeWmKpU9hKrBy3Dp9AkuiWK6H
    MD5:559A6FE1A36F3D91EA1B67DC5594DFEB
    SHA1:C04013551F92282E43866CB86DD7C1786FAC0CC8
    SHA-256:9A9662271EE7B0E26144B08985075B09FAF61F6AE2C6DE7492269124645445FC
    SHA-512:CCFBF9967EB6209C9E004CA3285CD2E8813E0BF7C0C4D332E19B304D5B58C79E91F95707439555596AF3813717F4131F87B1EA8709DC52C75BF0C8700EC2E2CE
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="utf-8"?><index> saved from url=(0016)http://localhost -->..<stem n="boost"><phr n="Boost"><ent r="82" t="130" w="237" /><ent r="82" t="130" w="237" /></phr></stem><stem n="mobil"><phr n="Mobile"><ent r="82" t="130" w="238" /><ent r="82" t="130" w="238" /><ent r="82" t="130" w="294" /><ent r="82" t="130" w="323" /><ent r="82" t="130" w="323" /><ent r="92" t="175" w="338" /><ent r="92" t="175" w="338" /><ent r="3" t="175" w="345" /><ent r="3" t="175" w="345" /><ent r="3" t="175" w="377" /><ent r="3" t="175" w="377" /></phr><phr n="mobile"><ent r="3" t="175" w="66" /><ent r="3" t="175" w="66" /><ent r="3" t="175" w="356" /><ent r="3" t="175" w="356" /><ent r="3" t="175" w="435" /><ent r="3" t="175" w="435" /><ent r="4" t="181" w="131" /><ent r="4" t="181" w="131" /><ent r="4" t="193" w="165" /><ent r="4" t="193" w="165" /></phr></stem><stem n="myboostmobil"><phr n="myboostmobile"><ent r="3" t="130" w="244" /><ent r="3" t="130" w="249" /></phr></stem><stem
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text, with very long lines (27434), with CRLF line terminators
    Category:dropped
    Size (bytes):27527
    Entropy (8bit):4.404798258536513
    Encrypted:false
    SSDEEP:768:Rqld4gi0JaLLhkNu8Hu5sOnPCvBDR+unLP+unLPFlQxJ4X80ZoyFX/neZj5TkmKU:N497O7dGDSaqdwjQEUoX+N66CX+EG
    MD5:384D776407CD03B4D2CBEBBCA58243E6
    SHA1:C90AE26728A3B78B72874B3E4C7780C69A20C567
    SHA-256:91570862C6E3447F5921FDBF0CB097B1070DD77CECDD831519024C3E96BBAFA7
    SHA-512:B48671EDA426AA341CDE3FF6B54791600C18003B843392B95AFD05CFA378C02DEB400C2C0677A4D94791032E70E0719791C68D4927F78C6653BAF3247AF20F45
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="utf-8"?><index> saved from url=(0016)http://localhost -->..<stem n="represent"><phr n="representation"><ent r="3" t="46" w="36" /><ent r="4" t="154" w="417" /></phr></stem><stem n="piec"><phr n="piece"><ent r="4" t="46" w="213" /></phr></stem><stem n="wedg"><phr n="wedge"><ent r="4" t="46" w="222" /></phr></stem><stem n="yellow"><phr n="yellow"><ent r="4" t="46" w="227" /></phr></stem><stem n="timefram"><phr n="timeframe"><ent r="5" t="46" w="259" /><ent r="4" t="118" w="134" /><ent r="3" t="128" w="31" /><ent r="3" t="204" w="28" /></phr></stem><stem n="overlap"><phr n="overlaps"><ent r="4" t="46" w="442" /></phr><phr n="overlap"><ent r="3" t="62" w="35" /><ent r="4" t="100" w="685" /></phr><phr n="overlapping"><ent r="5" t="69" w="462" /></phr></stem><stem n="have"><phr n="having"><ent r="4" t="46" w="449" /><ent r="4" t="71" w="1226" /><ent r="3" t="85" w="95" /><ent r="3" t="107" w="114" /><ent r="3" t="142" w="86" /><ent r="3" t="148" w="13" /><en
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text, with very long lines (27877), with CRLF line terminators
    Category:dropped
    Size (bytes):27970
    Entropy (8bit):4.139976294637279
    Encrypted:false
    SSDEEP:768:nLWWKk3ddvvnn22GGddMHYDRfZQlXXooFFJJhpeIllJJlhlhSSIIRR//kkKKNNIp:ErhzU31iAwWlXJMKLKK4tBsBCZMl8uq6
    MD5:5E5F21BBCA209E77431AF08C44250EA9
    SHA1:CF5F5E3E1D778A42CC6966AD55C369386D1BFBCA
    SHA-256:73269B1F79AC4C4F6E69B5BF6516F5A827D15BE3A787875E099018A8EE01ECDF
    SHA-512:6971DC9C41526796E78D7ADEEC4A10AE071E1BC8EEABD43252BAEA2B3E75A14E0D1A475EF3726087EBB0CBD3CF28F3F6E7AAF3D2BF5579B7B7192AA14D1B1741
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="utf-8"?><index> saved from url=(0016)http://localhost -->..<stem n="carri"><phr n="carried"><ent r="6" t="11" w="1270" /><ent r="6" t="11" w="1270" /><ent r="6" t="12" w="1351" /><ent r="6" t="12" w="1351" /><ent r="6" t="14" w="1379" /><ent r="6" t="14" w="1379" /></phr></stem><stem n="regardless"><phr n="regardless"><ent r="6" t="11" w="1339" /><ent r="6" t="11" w="1339" /><ent r="4" t="16" w="258" /><ent r="4" t="16" w="258" /><ent r="4" t="35" w="279" /><ent r="4" t="35" w="279" /><ent r="4" t="83" w="548" /><ent r="4" t="83" w="548" /><ent r="4" t="86" w="85" /><ent r="4" t="86" w="85" /><ent r="4" t="94" w="110" /><ent r="4" t="94" w="110" /><ent r="4" t="148" w="498" /><ent r="4" t="148" w="498" /><ent r="4" t="153" w="808" /><ent r="4" t="153" w="808" /></phr></stem><stem n="err"><phr n="Err"><ent r="3" t="11" w="1517" /><ent r="3" t="11" w="1528" /><ent r="3" t="12" w="1551" /><ent r="3" t="12" w="1562" /><ent r="3" t="14" w="1579" /><ent r="3
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:exported SGML document, ASCII text, with very long lines (34520), with CRLF line terminators
    Category:dropped
    Size (bytes):34764
    Entropy (8bit):4.024187744156323
    Encrypted:false
    SSDEEP:768:fbbaa1hhff85WWRRfJ0leddFF00PPcceezztXJyaS6ORhhvvHHmmrree11mUhKoz:dvvOOccMoRx
    MD5:C404A48679E034EF0C4B168D4071CBF4
    SHA1:214178AA95FE125BB3DE57C93E8D50B63E0F684C
    SHA-256:BAAC107A0B6960B3A95483124FCD8104EF46E8D9C016BCFA1306FDEAB7DB8BE1
    SHA-512:684CF23164B9D6637BCF2D1122F15905AA1B8F96788DE7717806585063A60D41786BDD1C5369C1DA6CDB19059C80A767067E91DB76952E60190C676095A9B556
    Malicious:false
    Reputation:low
    Preview:var xmlSearch_Chunk69Data = "";..xmlSearch_Chunk69Data += '<?xml version=\"1.0\" encoding=\"utf-8\"?><index> saved from url=(0016)http://localhost -->';..xmlSearch_Chunk69Data += '<stem n=\"durat\"><phr n=\"duration\"><ent r=\"3\" t=\"9\" w=\"395\" /><ent r=\"4\" t=\"11\" w=\"596\" /><ent r=\"4\" t=\"11\" w=\"596\" /><ent r=\"4\" t=\"12\" w=\"745\" /><ent r=\"4\" t=\"12\" w=\"745\" /><ent r=\"4\" t=\"18\" w=\"164\" /><ent r=\"4\" t=\"18\" w=\"186\" /><ent r=\"4\" t=\"18\" w=\"186\" /><ent r=\"4\" t=\"18\" w=\"193\" /><ent r=\"4\" t=\"18\" w=\"193\" /><ent r=\"3\" t=\"24\" w=\"73\" /><ent r=\"3\" t=\"24\" w=\"128\" /><ent r=\"4\" t=\"24\" w=\"236\" /><ent r=\"4\" t=\"24\" w=\"236\" /><ent r=\"4\" t=\"27\" w=\"535\" /><ent r=\"4\" t=\"27\" w=\"535\" /><ent r=\"4\" t=\"29\" w=\"719\" /><ent r=\"3\" t=\"54\" w=\"438\" /><ent r=\"4\" t=\"54\" w=\"506\" /><ent r=\"4\" t=\"54\" w=\"523\" /><ent r=\"3\" t=\"54\" w=\"543\" /><ent r=\"3\" t=\"54\" w=\"543\" /><ent r=\"3\" t=\"87\" w=\"521\"
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text, with very long lines (27005), with CRLF line terminators
    Category:dropped
    Size (bytes):27098
    Entropy (8bit):4.2671070830004245
    Encrypted:false
    SSDEEP:768:OdbJnRAkn1eu1wlBmCYfltqWj3rv2PoeCqBSfl3/EjShI3MJ9etjRhvsM/ogeX/F:Ob27QqKdChCHqJSEPlj5ygvfe
    MD5:67F56BD7C619CC2BBCE808E89DBE9DFB
    SHA1:313C0322833C1AB847C718BF0A875AC02BE5CA3F
    SHA-256:CBE3EECA02EC20C6D53386181821D7F90FFD2C6DF5089CC679940025A51A41E9
    SHA-512:5D803BD7F508F525F845CC368F5A15185BAF9724075F82B02D83AE11D3FBB0FF3AD3D57A6F63A25C4009BE8FAFB19D5BD9B27192DD6A9C8AA70029599D7D717E
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="utf-8"?><index> saved from url=(0016)http://localhost -->..<stem n="blue"><phr n="blue"><ent r="4" t="24" w="282" /><ent r="3" t="24" w="980" /><ent r="4" t="30" w="650" /><ent r="4" t="51" w="440" /><ent r="6" t="116" w="686" /><ent r="5" t="183" w="437" /><ent r="3" t="184" w="513" /></phr></stem><stem n="actual"><phr n="actual"><ent r="3" t="24" w="304" /><ent r="3" t="24" w="1055" /><ent r="3" t="28" w="159" /><ent r="4" t="30" w="228" /><ent r="4" t="42" w="304" /><ent r="4" t="42" w="345" /><ent r="4" t="70" w="293" /><ent r="3" t="70" w="686" /><ent r="4" t="70" w="742" /><ent r="6" t="73" w="531" /><ent r="6" t="73" w="566" /><ent r="6" t="73" w="616" /><ent r="5" t="73" w="656" /><ent r="4" t="96" w="636" /></phr></stem><stem n="limit"><phr n="limits"><ent r="3" t="24" w="312" /><ent r="4" t="24" w="640" /><ent r="4" t="24" w="663" /><ent r="3" t="24" w="907" /><ent r="4" t="30" w="234" /><ent r="3" t="30" w="662" /><ent r="3" t="30" w="824" /
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:exported SGML document, ASCII text, with very long lines (32092), with CRLF line terminators
    Category:dropped
    Size (bytes):32336
    Entropy (8bit):4.2394641426947075
    Encrypted:false
    SSDEEP:768:90hXheHbukJVVCHdHH11Pf5OhAsxxORe1p0GbnnJJBB3RO4uuIFhG1hDd99ppaaJ:eg
    MD5:08E32317BCDD393ED95D1B27D864C983
    SHA1:DE1F163C01D456D903AE5D5FFD1FD63076743582
    SHA-256:C11E7465E0D7B85D33E46CE6AB533DA20F1EFFD1DCE1DC7C7B762F92919008E7
    SHA-512:830D2D06A084416049B82DE598365E7730CF46FC92CF18051BB8251A2A853D0B8FCBAA6C0052588B1A02CF6B13C93AB9ABF017813F2E37834B757463E004D526
    Malicious:false
    Reputation:low
    Preview:var xmlSearch_Chunk85Data = "";..xmlSearch_Chunk85Data += '<?xml version=\"1.0\" encoding=\"utf-8\"?><index> saved from url=(0016)http://localhost -->';..xmlSearch_Chunk85Data += '<stem n=\"sync\"><phr n=\"Sync\"><ent r=\"4\" t=\"93\" w=\"351\" /><ent r=\"4\" t=\"93\" w=\"351\" /><ent r=\"4\" t=\"93\" w=\"404\" /><ent r=\"4\" t=\"93\" w=\"404\" /></phr></stem><stem n=\"desc\"><phr n=\"Desc\"><ent r=\"5\" t=\"93\" w=\"605\" /></phr></stem><stem n=\"repair\"><phr n=\"repairs\"><ent r=\"3\" t=\"93\" w=\"769\" /><ent r=\"3\" t=\"93\" w=\"769\" /></phr></stem><stem n=\"94\"><phr n=\"94\"><ent r=\"3\" t=\"94\" w=\"210\" /><ent r=\"3\" t=\"94\" w=\"210\" /></phr></stem><stem n=\"mb\"><phr n=\"MB\"><ent r=\"3\" t=\"94\" w=\"211\" /><ent r=\"3\" t=\"94\" w=\"211\" /><ent r=\"3\" t=\"141\" w=\"209\" /><ent r=\"3\" t=\"141\" w=\"217\" /><ent r=\"3\" t=\"141\" w=\"217\" /></phr></stem><stem n=\"64\"><phr n=\"64\"><ent r=\"3\" t=\"94\" w=\"222\" /><ent r=\"3\" t=\"94\" w=\"222\" /><ent r=\"5\"
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:exported SGML document, ASCII text, with very long lines (32326), with CRLF line terminators
    Category:dropped
    Size (bytes):32566
    Entropy (8bit):3.971122807616695
    Encrypted:false
    SSDEEP:768:XzZNAuwwf6VkG8iUdN9wNzF9/0jPgbAbthRniOaxtpNq0U5JKD1EblNgmzjMmx/z:UlzoPKLDA8lvLVLhsv
    MD5:FAA5389831FC713B820A5915FEAB19E0
    SHA1:EB161A12006DC94882666F44813E662089AAAD4E
    SHA-256:2623BBD48FC64580916499794DAECB608B787C9820D691CC33B09458A5AD8833
    SHA-512:9CE828F60F44679BC8F538F38CCDF7AFB240ABA606CFF8571BC7D7AE8636591785A3EA99480F06EDE7886651318CAF1480112FF0550833E50ADF184E130F4D02
    Malicious:false
    Reputation:low
    Preview:var xmlSearch_Chunk9Data = "";..xmlSearch_Chunk9Data += '<?xml version=\"1.0\" encoding=\"utf-8\"?><index> saved from url=(0016)http://localhost -->';..xmlSearch_Chunk9Data += '<stem n=\"properti\"><phr n=\"property\"><ent r=\"4\" t=\"0\" w=\"212\" /></phr><phr n=\"properties\"><ent r=\"3\" t=\"4\" w=\"741\" /><ent r=\"4\" t=\"6\" w=\"266\" /><ent r=\"5\" t=\"21\" w=\"55\" /><ent r=\"5\" t=\"21\" w=\"64\" /><ent r=\"5\" t=\"21\" w=\"69\" /><ent r=\"268435456\" t=\"25\" w=\"3\" /><ent r=\"16777218\" t=\"25\" w=\"12\" /><ent r=\"3\" t=\"25\" w=\"23\" /><ent r=\"4\" t=\"25\" w=\"504\" /><ent r=\"4\" t=\"25\" w=\"509\" /><ent r=\"268435456\" t=\"26\" w=\"3\" /><ent r=\"16777218\" t=\"26\" w=\"8\" /><ent r=\"3\" t=\"26\" w=\"15\" /><ent r=\"4\" t=\"26\" w=\"607\" /><ent r=\"4\" t=\"26\" w=\"612\" /><ent r=\"268435456\" t=\"27\" w=\"3\" /><ent r=\"16777218\" t=\"27\" w=\"8\" /><ent r=\"3\" t=\"27\" w=\"15\" /><ent r=\"4\" t=\"27\" w=\"144\" /><ent r=\"4\" t=\"27\" w=\"149\" /><ent r=\"26
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:exported SGML document, ASCII text, with very long lines (32784), with CRLF line terminators
    Category:dropped
    Size (bytes):33028
    Entropy (8bit):4.066396871288085
    Encrypted:false
    SSDEEP:768:7mGsCJEYLHIfYgEBUl4Y40FWQWSEuKcTnuNiuJ0WhfiIPZ0hxzPNiRBbVnDRuWZF:kQ23y
    MD5:FD11D1DC08AA8CA05A115F441E287899
    SHA1:159C405C0EA2BB11A2C1B85E5F5E3CC44A21882F
    SHA-256:88DA16B3A76E8646F2705F0A7AB21992E434AC892983579048E3EA1024D99BA2
    SHA-512:B5FDD98425FEC0D993B919A052950C983A5991C8467D33FB2A65C8329400AD5FACFD42BD654F8AF9D68210A444EA3E5662CE43C4569A84D6C5CEEC864BE32407
    Malicious:false
    Reputation:low
    Preview:var xmlSearch_Chunk48Data = "";..xmlSearch_Chunk48Data += '<?xml version=\"1.0\" encoding=\"utf-8\"?><index> saved from url=(0016)http://localhost -->';..xmlSearch_Chunk48Data += '<stem n=\"drop-down\"><phr n=\"drop-down\"><ent r=\"4\" t=\"10\" w=\"234\" /><ent r=\"4\" t=\"10\" w=\"277\" /><ent r=\"3\" t=\"11\" w=\"242\" /><ent r=\"4\" t=\"13\" w=\"254\" /><ent r=\"3\" t=\"13\" w=\"297\" /><ent r=\"4\" t=\"13\" w=\"325\" /><ent r=\"4\" t=\"19\" w=\"81\" /><ent r=\"4\" t=\"28\" w=\"421\" /><ent r=\"4\" t=\"30\" w=\"542\" /><ent r=\"5\" t=\"46\" w=\"245\" /><ent r=\"4\" t=\"55\" w=\"137\" /><ent r=\"4\" t=\"62\" w=\"198\" /><ent r=\"3\" t=\"63\" w=\"122\" /><ent r=\"3\" t=\"63\" w=\"140\" /><ent r=\"4\" t=\"63\" w=\"189\" /><ent r=\"3\" t=\"66\" w=\"711\" /><ent r=\"4\" t=\"67\" w=\"325\" /><ent r=\"4\" t=\"68\" w=\"323\" /><ent r=\"4\" t=\"69\" w=\"235\" /><ent r=\"5\" t=\"71\" w=\"1045\" /><ent r=\"5\" t=\"71\" w=\"1311\" /><ent r=\"5\" t=\"71\" w=\"1359\" /><ent r=\"4\" t=\"72\" w
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text, with very long lines (35675), with CRLF line terminators
    Category:dropped
    Size (bytes):35768
    Entropy (8bit):3.9243401745103745
    Encrypted:false
    SSDEEP:768:GfOy8bg/gKpcT2O/iO8LyqK4oovq7JHAsQgU/UAzWgQG9n7K7sHBRr2xZwE9U1Vx:fqrp9EqqzDe3YJMMJUtvbpOg
    MD5:1CC61037BBC4225F700D0B1289C91CE9
    SHA1:C1CF4275733BBCA8A528CEC476DFE939CA13715D
    SHA-256:62882959AC627D7850E21F178B4724D38F4F965D205B872C73A80F2819E35479
    SHA-512:E5ABFCBF254F1F0DA731C7B7BD05F4BB3DAD0EB66D2411C43823165D5BD70648F9418F7DC92A40761C776B1FC06459B2136E2629DB690E6A05976FB88601C684
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="utf-8"?><index> saved from url=(0016)http://localhost -->..<stem n="pie"><phr n="pie"><ent r="4" t="1" w="140" /><ent r="5" t="3" w="518" /><ent r="4" t="37" w="609" /><ent r="4" t="37" w="634" /><ent r="5" t="37" w="640" /><ent r="5" t="40" w="470" /><ent r="4" t="40" w="476" /><ent r="268435456" t="46" w="3" /><ent r="16777218" t="46" w="8" /><ent r="3" t="46" w="11" /><ent r="3" t="46" w="115" /><ent r="4" t="46" w="144" /><ent r="4" t="46" w="149" /><ent r="4" t="46" w="168" /><ent r="4" t="46" w="173" /><ent r="4" t="46" w="181" /><ent r="4" t="46" w="199" /><ent r="4" t="46" w="216" /><ent r="4" t="46" w="221" /><ent r="5" t="46" w="238" /><ent r="5" t="46" w="264" /><ent r="5" t="46" w="286" /><ent r="5" t="46" w="314" /><ent r="5" t="46" w="330" /><ent r="4" t="46" w="343" /><ent r="4" t="46" w="354" /><ent r="4" t="46" w="379" /><ent r="4" t="46" w="422" /><ent r="4" t="46" w="433" /><ent r="4" t="46" w="453" /><ent r="4" t="46" w="470" /><ent
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text, with very long lines (26632), with CRLF line terminators
    Category:dropped
    Size (bytes):26725
    Entropy (8bit):4.078069163939941
    Encrypted:false
    SSDEEP:768:VdYdFefdYYddFFeeYMSVAs7zOAMvAK/rfGDCyFF+uohevlFF++uuoohheevvgsbD:hpW7B7PQuvuCNCEEGGtOii/PK4WzfahH
    MD5:C256B6EDE01297EE6672FED85C3BFF20
    SHA1:2E05DBF855120D33D54FC83FF9CAD9FE500F5EB1
    SHA-256:C3F224A2E31239EA8B1C458CAA941CCE41FB13AD7D79334E9FE63931F94FEB42
    SHA-512:7D2801878BAA13E22E918E13ABE69E407DC4A82618E0478DE386A058B9D003934225F76291B22D0837483B62A8D8752AF780F12785F56ABC4C2439062C6F2377
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="utf-8"?><index> saved from url=(0016)http://localhost -->..<stem n="ua"><phr n="UA"><ent r="3" t="23" w="32" /><ent r="4" t="23" w="452" /><ent r="4" t="23" w="525" /><ent r="4" t="23" w="571" /><ent r="4" t="23" w="607" /><ent r="3" t="23" w="953" /><ent r="3" t="23" w="1068" /></phr></stem><stem n="ua-001"><phr n="UA-001"><ent r="3" t="23" w="32" /><ent r="4" t="23" w="452" /><ent r="4" t="23" w="525" /><ent r="4" t="23" w="525" /><ent r="4" t="23" w="571" /><ent r="4" t="23" w="571" /><ent r="4" t="23" w="607" /><ent r="4" t="23" w="607" /><ent r="3" t="23" w="953" /><ent r="3" t="23" w="953" /><ent r="3" t="23" w="1068" /><ent r="3" t="23" w="1068" /></phr></stem><stem n="001"><phr n="001"><ent r="3" t="23" w="33" /><ent r="4" t="23" w="453" /><ent r="4" t="23" w="526" /><ent r="4" t="23" w="572" /><ent r="4" t="23" w="608" /><ent r="3" t="23" w="954" /><ent r="3" t="23" w="1069" /><ent r="4" t="37" w="63" /><ent r="4" t="37" w="126" /><ent r="4" t
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:exported SGML document, ASCII text, with very long lines (39676), with CRLF line terminators
    Category:dropped
    Size (bytes):39916
    Entropy (8bit):3.9370754352199167
    Encrypted:false
    SSDEEP:768:0PUa9o3QwD00of92Sw2dGrE3oD0vsr2624cNVUbX3UUapLp3VH6V6uzqFgqLJEZC:DFLKBzBsalGSbGKkS8kYNXRy
    MD5:64907FC54FBCEEA49095BBF3A1740A09
    SHA1:24D3BA2F82C809ADF56FA1CE3697B24F25F1B0E4
    SHA-256:62A3DB8360820D9215359202EA2524B2AC4596399DD97B928BFF9FBAAF9A60AB
    SHA-512:9D7A4BCF1CBCB9B66B42559F03FB24AD89E2CF05CE1F4609106A54990F61783E96CB9470971B868BC75D6EAF55B2D46470A90E79C54999BA29707C0947679B9A
    Malicious:false
    Reputation:low
    Preview:var xmlSearch_Chunk4Data = "";..xmlSearch_Chunk4Data += '<?xml version=\"1.0\" encoding=\"utf-8\"?><index> saved from url=(0016)http://localhost -->';..xmlSearch_Chunk4Data += '<stem n=\"read\"><phr n=\"reading\"><ent r=\"5\" t=\"0\" w=\"33\" /><ent r=\"3\" t=\"1\" w=\"17\" /><ent r=\"5\" t=\"1\" w=\"300\" /><ent r=\"4\" t=\"3\" w=\"639\" /><ent r=\"4\" t=\"4\" w=\"764\" /><ent r=\"3\" t=\"5\" w=\"622\" /><ent r=\"5\" t=\"5\" w=\"630\" /><ent r=\"5\" t=\"5\" w=\"663\" /><ent r=\"5\" t=\"5\" w=\"703\" /><ent r=\"5\" t=\"5\" w=\"738\" /><ent r=\"5\" t=\"5\" w=\"775\" /><ent r=\"4\" t=\"6\" w=\"176\" /><ent r=\"4\" t=\"10\" w=\"599\" /><ent r=\"3\" t=\"23\" w=\"74\" /><ent r=\"3\" t=\"24\" w=\"17\" /><ent r=\"4\" t=\"24\" w=\"209\" /><ent r=\"4\" t=\"24\" w=\"218\" /><ent r=\"4\" t=\"24\" w=\"262\" /><ent r=\"4\" t=\"24\" w=\"272\" /><ent r=\"3\" t=\"24\" w=\"359\" /><ent r=\"3\" t=\"24\" w=\"402\" /><ent r=\"4\" t=\"24\" w=\"528\" /><ent r=\"4\" t=\"24\" w=\"638\" /><ent r=\"4\" t=\"
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text, with very long lines (29873), with CRLF line terminators
    Category:dropped
    Size (bytes):29966
    Entropy (8bit):3.9583260919963386
    Encrypted:false
    SSDEEP:768:gvPFpr/DAaCd+PhFwiLpzuNmJP2R0mvN9H6TikAQwcP/lxmQRoKiaRnQ/XjGrnNN:gFps8k1eojby9QLSaNLhuN
    MD5:F2E732535147A761CE7170F3A8D679FF
    SHA1:F52BC1C4FF16F078EFC34FCF27C6FBA033911F0A
    SHA-256:15526105D8EE58E5E02EA6421301D09ACAD886CA048A5D648CB9B3E94DA0D095
    SHA-512:066F12BCBE7D6201F7449073A16813D14D5EC4148C6EB0E29CC75E77CBC09E0F7F12190D13F2F1638884CA511A1C312F2E0E8B19EEA698D90B9466A4CC85BC6E
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="utf-8"?><index> saved from url=(0016)http://localhost -->..<stem n="si"><phr n="si"><ent r="4" t="2" w="512" /><ent r="3" t="63" w="13" /><ent r="3" t="63" w="33" /><ent r="4" t="73" w="745" /><ent r="4" t="73" w="844" /><ent r="4" t="91" w="358" /><ent r="4" t="91" w="426" /><ent r="3" t="156" w="91" /><ent r="3" t="168" w="133" /><ent r="3" t="176" w="442" /><ent r="3" t="187" w="110" /></phr></stem><stem n="show"><phr n="show"><ent r="4" t="2" w="526" /><ent r="4" t="3" w="149" /><ent r="6" t="4" w="316" /><ent r="3" t="4" w="508" /><ent r="3" t="4" w="513" /><ent r="3" t="4" w="518" /><ent r="6" t="4" w="580" /><ent r="3" t="4" w="717" /><ent r="5" t="10" w="400" /><ent r="5" t="10" w="424" /><ent r="4" t="22" w="276" /><ent r="4" t="32" w="115" /><ent r="3" t="33" w="709" /><ent r="4" t="37" w="482" /><ent r="4" t="40" w="345" /><ent r="4" t="40" w="373" /><ent r="10" t="46" w="304" /><ent r="4" t="49" w="121" /><ent r="4" t="49" w="130" /><ent r=
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text, with very long lines (28151), with CRLF line terminators
    Category:dropped
    Size (bytes):28244
    Entropy (8bit):4.054341327282423
    Encrypted:false
    SSDEEP:768:t7RRcPP44EEkeeVVzzLss55JJwwLLyydssRRhs88aoAWJJl9VRRQQMMxxuuHHYY0:7fxyebS+CDZtEz733iEmgUPdlH2
    MD5:3678B5541DC43A55F7A19592844CB0F9
    SHA1:827A20A0C22316C94BD63068D78DA345916E5F6F
    SHA-256:7754AA681F409A12EEA326B11457F57465CDD74566148FD26F2B51BABA96E858
    SHA-512:1FD656F5F89E422E5C1B59EFA4ABB2321820D8A82DEB9CBDC990092340A2DC63F6DFE373CBA39A4A1825C534F6C8FCE135ED5BC4F8C542A5914D11FB3577E265
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="utf-8"?><index> saved from url=(0016)http://localhost -->..<stem n="begin"><phr n="begins"><ent r="3" t="5" w="57" /><ent r="3" t="5" w="57" /><ent r="3" t="8" w="203" /><ent r="3" t="8" w="203" /><ent r="4" t="10" w="570" /><ent r="4" t="10" w="580" /><ent r="4" t="10" w="580" /><ent r="6" t="10" w="950" /><ent r="6" t="10" w="950" /><ent r="6" t="11" w="780" /><ent r="6" t="11" w="780" /><ent r="4" t="12" w="389" /><ent r="4" t="12" w="417" /><ent r="4" t="12" w="417" /><ent r="6" t="12" w="906" /><ent r="6" t="12" w="906" /><ent r="6" t="12" w="1136" /><ent r="6" t="12" w="1136" /><ent r="4" t="13" w="532" /><ent r="4" t="13" w="542" /><ent r="4" t="13" w="542" /><ent r="6" t="13" w="864" /><ent r="6" t="13" w="864" /><ent r="6" t="13" w="983" /><ent r="6" t="13" w="983" /><ent r="6" t="13" w="1109" /><ent r="6" t="13" w="1109" /><ent r="6" t="14" w="919" /><ent r="6" t="14" w="919" /><ent r="6" t="14" w="1164" /><ent r="6" t="14" w="1164" /><ent r=
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text, with very long lines (27619), with CRLF line terminators
    Category:dropped
    Size (bytes):27712
    Entropy (8bit):4.019481983228679
    Encrypted:false
    SSDEEP:768:jZQdoixeOq82QH+Up4ovIu4V2eX6A6eQ8mt3ai4ToFqKW4yugCAwOfPKAv7Ebu0u:gO6/2cxUzfP+yEL/ST3HhvaVM/W+/n
    MD5:41285613ABE1BB07469E43374EED8B99
    SHA1:9152B0528B5174EEC4605B166ACCB4B9FD8066F1
    SHA-256:8DF54C175A3030AB32736AD02564AE8BD27282C57FF42609889C7368BE75824E
    SHA-512:2CF74168D02A0BE378B5D21B3CAC127389BA945ACC0471F4E20438EBF05D3C723A1176DEA9D159AE825C41EFFD1750B0EB7DDA224C1D6B8ECE24A7F674D1CF39
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="utf-8"?><index> saved from url=(0016)http://localhost -->..<stem n="u24-002"><phr n="u24-002"><ent r="4" t="3" w="1500" /><ent r="5" t="70" w="163" /></phr></stem><stem n="002"><phr n="002"><ent r="4" t="3" w="1501" /><ent r="4" t="39" w="67" /><ent r="4" t="39" w="135" /><ent r="4" t="39" w="162" /><ent r="4" t="39" w="170" /><ent r="5" t="70" w="164" /></phr></stem><stem n="disabl"><phr n="disable"><ent r="4" t="3" w="1506" /><ent r="3" t="4" w="314" /><ent r="3" t="4" w="578" /><ent r="4" t="12" w="518" /><ent r="4" t="13" w="643" /><ent r="4" t="14" w="750" /><ent r="4" t="16" w="814" /><ent r="4" t="17" w="984" /><ent r="4" t="49" w="244" /><ent r="3" t="56" w="457" /><ent r="3" t="64" w="212" /><ent r="3" t="80" w="421" /><ent r="3" t="121" w="725" /><ent r="3" t="123" w="935" /><ent r="4" t="125" w="255" /><ent r="3" t="139" w="54" /><ent r="4" t="153" w="275" /><ent r="4" t="153" w="333" /><ent r="4" t="154" w="922" /><ent r="4" t="154" w="986"
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text, with very long lines (12957), with CRLF line terminators
    Category:dropped
    Size (bytes):13050
    Entropy (8bit):4.466051793491933
    Encrypted:false
    SSDEEP:384:k/ttXkHdTLLToTshQ3cc00zrzA6YYkcU6AA/TOPe88++OOTJSJBAsiS52vv/GApz:k/ttXkHdTLLToTshQ3cc00Ps6YYkcU6N
    MD5:E932E7FE4D30F480466E9EF5611C65DF
    SHA1:505213334B7B1B8567A3046863FC1D1FFA9A94C8
    SHA-256:B1ECA9322B7F2CD70EA56A84D1A9E88EC1F8C0DCCD738791103A0D943517E8D1
    SHA-512:A9A68AC9529F66C05672BE6F4A234B876DEF772B3FBE92CF762068BE63F04D94CB581077267CEF1FE2D497A812590D8AF8070722B9C01365E7FA555EBF86F264
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="utf-8"?><index> saved from url=(0016)http://localhost -->..<stem n="wrap-en"><phr n="wrap-enabled"><ent r="4" t="170" w="512" /><ent r="4" t="170" w="512" /><ent r="3" t="172" w="124" /><ent r="3" t="172" w="124" /><ent r="5" t="176" w="313" /><ent r="5" t="176" w="313" /></phr></stem><stem n="discontinu"><phr n="discontinued"><ent r="4" t="170" w="545" /><ent r="3" t="172" w="157" /><ent r="5" t="176" w="346" /></phr></stem><stem n="scheme"><phr n="scheme"><ent r="4" t="170" w="725" /><ent r="4" t="170" w="725" /><ent r="92" t="186" w="125" /><ent r="92" t="186" w="125" /><ent r="3" t="186" w="135" /><ent r="3" t="186" w="135" /></phr></stem><stem n="definit"><phr n="definitions"><ent r="3" t="171" w="45" /><ent r="3" t="171" w="45" /></phr></stem><stem n="construct"><phr n="construct"><ent r="4" t="172" w="281" /><ent r="4" t="172" w="281" /><ent r="4" t="178" w="8" /><ent r="4" t="178" w="8" /></phr></stem><stem n="halrm"><phr n="halrm"><ent r="4" t
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:exported SGML document, ASCII text, with very long lines (32696), with CRLF line terminators
    Category:dropped
    Size (bytes):32940
    Entropy (8bit):4.067738397360823
    Encrypted:false
    SSDEEP:768:V9ES+/TNJeHmxA+Ul0A0it9rU3lcwDpRJDUd+rFpJDCTEMjJQ9vZ1u6kEnDBnkRs:IsxcTCS7
    MD5:A62F1EE010E5AC1C528A62E1559D287E
    SHA1:DA937E86C51E44A589AF8D2BF4BF067E1829F47E
    SHA-256:DC1AC2D5704D8028B7A690C121A189854009F15AFE29284E1DD5FF522CF98BF3
    SHA-512:24CDDA737AB9128E5F5C88C779BB48E2FB6FEB431E76229DD5CDACBB6E7CAFB60CF84B3D0253266DB7DFBF8071C24E283072B805B9FCD0E88DA941E28615E15C
    Malicious:false
    Reputation:low
    Preview:var xmlSearch_Chunk45Data = "";..xmlSearch_Chunk45Data += '<?xml version=\"1.0\" encoding=\"utf-8\"?><index> saved from url=(0016)http://localhost -->';..xmlSearch_Chunk45Data += '<stem n=\"cabl\"><phr n=\"cable\"><ent r=\"3\" t=\"7\" w=\"20\" /><ent r=\"3\" t=\"7\" w=\"39\" /><ent r=\"3\" t=\"7\" w=\"249\" /><ent r=\"4\" t=\"7\" w=\"262\" /><ent r=\"4\" t=\"7\" w=\"279\" /><ent r=\"3\" t=\"7\" w=\"325\" /><ent r=\"4\" t=\"7\" w=\"339\" /><ent r=\"4\" t=\"7\" w=\"359\" /><ent r=\"4\" t=\"7\" w=\"522\" /><ent r=\"3\" t=\"7\" w=\"597\" /><ent r=\"3\" t=\"11\" w=\"1514\" /><ent r=\"4\" t=\"12\" w=\"244\" /><ent r=\"3\" t=\"12\" w=\"1544\" /><ent r=\"3\" t=\"14\" w=\"1569\" /><ent r=\"3\" t=\"15\" w=\"174\" /><ent r=\"3\" t=\"15\" w=\"1315\" /><ent r=\"4\" t=\"16\" w=\"338\" /><ent r=\"3\" t=\"17\" w=\"38\" /><ent r=\"3\" t=\"17\" w=\"42\" /><ent r=\"4\" t=\"36\" w=\"371\" /><ent r=\"4\" t=\"67\" w=\"63\" /><ent r=\"4\" t=\"67\" w=\"69\" /><ent r=\"4\" t=\"67\" w=\"71\" /><ent r=\"4\"
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:exported SGML document, ASCII text, with very long lines (13320), with CRLF line terminators
    Category:dropped
    Size (bytes):13564
    Entropy (8bit):4.4850924786286095
    Encrypted:false
    SSDEEP:384:NzaEEppyyF44czG0qYz+j+erQcXXYYa14ohe1AA5DBll2G1wE9I3lyj70iv11inc:NzaEEppyyF44czG0qYz+j+erQcXXYYaA
    MD5:8BE86A99319BA7E4113BB9D550E19319
    SHA1:E17E161DA2AAAC63BA04AEA7A36ABF35E2D1C425
    SHA-256:08B082654D235209D3DD1C6C681F6AD3433E9D23FF3D696F222E8B38EBCADDEA
    SHA-512:805C3FB07C9AB6571539399E221335C87B3B8F7678C8410381A4A90B0C589B87ABCDEC33F84BB8B4F29DA2E8137A2E3AF7D143589A8121129A54594C2E06C315
    Malicious:false
    Reputation:low
    Preview:var xmlSearch_Chunk89Data = "";..xmlSearch_Chunk89Data += '<?xml version=\"1.0\" encoding=\"utf-8\"?><index> saved from url=(0016)http://localhost -->';..xmlSearch_Chunk89Data += '<stem n=\"tri\"><phr n=\"tries\"><ent r=\"5\" t=\"172\" w=\"198\" /><ent r=\"5\" t=\"172\" w=\"198\" /></phr></stem><stem n=\"poll\"><phr n=\"polling\"><ent r=\"3\" t=\"173\" w=\"175\" /><ent r=\"3\" t=\"173\" w=\"175\" /><ent r=\"3\" t=\"173\" w=\"199\" /><ent r=\"3\" t=\"173\" w=\"199\" /><ent r=\"3\" t=\"179\" w=\"145\" /><ent r=\"3\" t=\"179\" w=\"145\" /><ent r=\"3\" t=\"180\" w=\"49\" /><ent r=\"3\" t=\"180\" w=\"49\" /><ent r=\"4\" t=\"181\" w=\"424\" /><ent r=\"4\" t=\"181\" w=\"424\" /></phr><phr n=\"polls\"><ent r=\"3\" t=\"179\" w=\"41\" /><ent r=\"3\" t=\"179\" w=\"41\" /></phr><phr n=\"poll\"><ent r=\"3\" t=\"179\" w=\"122\" /><ent r=\"3\" t=\"179\" w=\"122\" /><ent r=\"3\" t=\"180\" w=\"26\" /><ent r=\"3\" t=\"180\" w=\"26\" /></phr></stem><stem n=\"unpredict\"><phr n=\"unpredictable\"><ent
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:exported SGML document, ASCII text, with very long lines (26935), with CRLF line terminators
    Category:dropped
    Size (bytes):53846
    Entropy (8bit):5.345451892448637
    Encrypted:false
    SSDEEP:768:QmE9UanJNZSVOEa4IZUon/IDO0MS9Qm37kbKsAEhrmAim722rFsncWhrdrbqU/pt:bi/7cVOEOZ1096rYQS2SnFxdqU/p2+t
    MD5:5ACA5CB112520ADBB029B7D9AAE5BDAF
    SHA1:AECC5EC9880A12406F9808B57A288AA5F27AB12E
    SHA-256:A2449F30AB360012B70BEE3B7898E8023970F078947B9445CA39804572E5793C
    SHA-512:C66232ABCBA2C1502A8BEA43806CB0912ECEA8EF4D08D3D37183EC8F04667296B8C8BB684A3E60A7F39771BE13BF0BAD94BAA33A97D45A9639B8F2918AF2E55E
    Malicious:false
    Reputation:low
    Preview:var xmlSkinData = "";..xmlSkinData += '<?xml version=\"1.0\" encoding=\"utf-8\"?>';..xmlSkinData += '<CatapultSkin Version=\"1\" Title=\"HOBOware Help\" AutoSyncTOC=\"True\" Tabs=\"TOC,Index,Search,Favorites\" Top=\"118px\" Left=\"164px\" Width=\"800px\" Height=\"600px\" DefaultTab=\"TOC\" Bottom=\"482px\" Right=\"956px\" Anchors=\"Width,Height\" UseBrowserDefaultSize=\"True\" UseDefaultBrowserSetup=\"True\" NavigationLinkTop=\"true\" ToolbarInTopic=\"true\">';..xmlSkinData += ' saved from url=(0016)http://localhost -->';..xmlSkinData += ' saved from url=(0014)about:internet -->';..xmlSkinData += ' <HtmlHelpOptions ShowMenuBar=\"False\" TopmostWindowStyle=\"False\" AutoShowNavigationPane=\"False\" EnableButtonCaptions=\"True\" NavigationPaneWidth=\"0\" Buttons=\"Print,Next,Previous\" HideNavigationOnStartup=\"False\" />';..xmlSkinData += ' <Toc LinesBetweenItems=\"true\" LinesFromRoot=\"true\" SingleClick=\"false\" PlusMinusSquares=\"true\" AlwaysShowSelection=\"t
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text, with very long lines (27564), with CRLF line terminators
    Category:dropped
    Size (bytes):27657
    Entropy (8bit):4.085382890746136
    Encrypted:false
    SSDEEP:768:h44k9szzTTR1goVV/RbrpaXLLIITTpkLnXgPEEvvHHcckk88nnwwQr700yyuu11Z:zXwNjJMfWP/zaI9Tr2e5/d6NNgQZltIi
    MD5:1B0D7F7C438FB32EA07A6EDF636E62CC
    SHA1:DA4D530F80CBC79AD1EE2AAF44F0CA92B2333728
    SHA-256:5A6D025CAC2D178508E8E05801F4FB8772C18985CD5A154159D2BBA7CE9F33DC
    SHA-512:ADFCBEDF566C176C379C3B20783BFE5BD6DBE2B6272D17D59520668E8C42FA67AF1BA2EB92F0A59465176CE1897B105C1C10E6AD0A545F2730FF0C85A3AA184D
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="utf-8"?><index> saved from url=(0016)http://localhost -->..<stem n="humid"><phr n="humidity"><ent r="4" t="5" w="387" /><ent r="4" t="15" w="478" /><ent r="4" t="15" w="478" /><ent r="4" t="64" w="430" /><ent r="3" t="70" w="28" /><ent r="4" t="70" w="68" /><ent r="4" t="153" w="579" /><ent r="4" t="153" w="579" /><ent r="4" t="154" w="561" /><ent r="4" t="154" w="561" /><ent r="4" t="154" w="578" /><ent r="4" t="154" w="578" /></phr><phr n="Humidity"><ent r="4" t="15" w="492" /><ent r="4" t="15" w="492" /><ent r="4" t="70" w="110" /><ent r="6" t="80" w="738" /><ent r="6" t="80" w="738" /><ent r="5" t="154" w="553" /></phr></stem><stem n="retain"><phr n="retain"><ent r="4" t="5" w="393" /><ent r="4" t="5" w="393" /><ent r="4" t="81" w="98" /><ent r="4" t="81" w="98" /></phr><phr n="retained"><ent r="3" t="67" w="620" /><ent r="4" t="155" w="242" /></phr><phr n="retaining"><ent r="4" t="151" w="748" /><ent r="4" t="151" w="748" /></phr></stem><stem n="c
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:exported SGML document, ASCII text, with very long lines (43177), with CRLF line terminators
    Category:dropped
    Size (bytes):43421
    Entropy (8bit):3.937548181780402
    Encrypted:false
    SSDEEP:768:XvHooCX6veAZKv0wjcoyC0EEY2fH0/JXKSKWivWevcmiYxbzsXmDhtr09Vmq9u95:qDRyOkPw0
    MD5:77234FD184C4DF0A314B04C4D576BB80
    SHA1:6C85075456FCBCA0A24E9753BF6B54B0CF0B2C72
    SHA-256:7682B4FC089B4BD20EE4819058628068F334B4A7B950249684A6D292AF473234
    SHA-512:3E323AD03184B62B8B9CECF15FF2E15B6EBC72D16C098B3BDDF6A0ACE50AAED5460F5979E4F94DFD29362A71ACE4DC5EB1E4AC5BBA7BD8964401CAEBA069A70D
    Malicious:false
    Reputation:low
    Preview:var xmlSearch_Chunk15Data = "";..xmlSearch_Chunk15Data += '<?xml version=\"1.0\" encoding=\"utf-8\"?><index> saved from url=(0016)http://localhost -->';..xmlSearch_Chunk15Data += '<stem n=\"pie\"><phr n=\"pie\"><ent r=\"4\" t=\"1\" w=\"140\" /><ent r=\"5\" t=\"3\" w=\"518\" /><ent r=\"4\" t=\"37\" w=\"609\" /><ent r=\"4\" t=\"37\" w=\"634\" /><ent r=\"5\" t=\"37\" w=\"640\" /><ent r=\"5\" t=\"40\" w=\"470\" /><ent r=\"4\" t=\"40\" w=\"476\" /><ent r=\"268435456\" t=\"46\" w=\"3\" /><ent r=\"16777218\" t=\"46\" w=\"8\" /><ent r=\"3\" t=\"46\" w=\"11\" /><ent r=\"3\" t=\"46\" w=\"115\" /><ent r=\"4\" t=\"46\" w=\"144\" /><ent r=\"4\" t=\"46\" w=\"149\" /><ent r=\"4\" t=\"46\" w=\"168\" /><ent r=\"4\" t=\"46\" w=\"173\" /><ent r=\"4\" t=\"46\" w=\"181\" /><ent r=\"4\" t=\"46\" w=\"199\" /><ent r=\"4\" t=\"46\" w=\"216\" /><ent r=\"4\" t=\"46\" w=\"221\" /><ent r=\"5\" t=\"46\" w=\"238\" /><ent r=\"5\" t=\"46\" w=\"264\" /><ent r=\"5\" t=\"46\" w=\"286\" /><ent r=\"5\" t=\"46\" w=\"314
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text, with very long lines (26737), with CRLF line terminators
    Category:dropped
    Size (bytes):26830
    Entropy (8bit):3.9552981278001087
    Encrypted:false
    SSDEEP:768:T3N1e8+qrEt2geQ6ZVJaZbNx+P3mnSTxZNHYwsRV5d8CKVJYvFaLxp6sbfeMtfm8:wiS5dmiYTQqHb3
    MD5:FF34B33023C992FACEC27032A7FA253F
    SHA1:2714D65214A51844E5F0E975D20CF81E9C177BB1
    SHA-256:C8E711F6812F557FC1C940089844C642D885EAAA1BAECB3DBFA3791C80C4062F
    SHA-512:65089941A684055D6227AC03528C33373BE4274D1B63B1016D1564BD7174D03AD9B2001EAE2E643971CBEC858EA354C9890D351302E69C831F518763785A355A
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="utf-8"?><index> saved from url=(0016)http://localhost -->..<stem n="properti"><phr n="property"><ent r="4" t="0" w="212" /></phr><phr n="properties"><ent r="3" t="4" w="741" /><ent r="4" t="6" w="266" /><ent r="5" t="21" w="55" /><ent r="5" t="21" w="64" /><ent r="5" t="21" w="69" /><ent r="268435456" t="25" w="3" /><ent r="16777218" t="25" w="12" /><ent r="3" t="25" w="23" /><ent r="4" t="25" w="504" /><ent r="4" t="25" w="509" /><ent r="268435456" t="26" w="3" /><ent r="16777218" t="26" w="8" /><ent r="3" t="26" w="15" /><ent r="4" t="26" w="607" /><ent r="4" t="26" w="612" /><ent r="268435456" t="27" w="3" /><ent r="16777218" t="27" w="8" /><ent r="3" t="27" w="15" /><ent r="4" t="27" w="144" /><ent r="4" t="27" w="149" /><ent r="268435456" t="31" w="3" /><ent r="4" t="40" w="53" /><ent r="4" t="40" w="277" /><ent r="4" t="40" w="282" /><ent r="5" t="40" w="338" /><ent r="4" t="40" w="389" /><ent r="5" t="40" w="504" /><ent r="3" t="40" w="552" /><e
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text, with very long lines (26607), with CRLF line terminators
    Category:dropped
    Size (bytes):26700
    Entropy (8bit):4.067181016614088
    Encrypted:false
    SSDEEP:768:w5AA99uu8811qqllPPQQLLffJHYbbggppddqqHHXXAA2OND/sLjj00OSoqq7HZuu:uuJo6PmotusOODFqnC9Pn
    MD5:C737E71EF4F41132BEDEDC4E9D465DF1
    SHA1:6ED18E79C89538B3679202D10ECC528DF9020795
    SHA-256:8919D3A0A64DF2F6A8309B99D6DE921FB421DF318EE49703F1B51EC1A1899CCA
    SHA-512:362037E4F7C523DD90914D9BF1CF672CD044C63BE5B4410ED726B2792E932BECB26D4137C3A746FE161CED679830BCB05D8929C36E62BC2776E7CBC401BEF384
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="utf-8"?><index> saved from url=(0016)http://localhost -->..<stem n="six"><phr n="six"><ent r="6" t="10" w="1077" /><ent r="6" t="10" w="1077" /><ent r="6" t="11" w="850" /><ent r="6" t="11" w="850" /><ent r="6" t="12" w="995" /><ent r="6" t="12" w="995" /><ent r="6" t="13" w="968" /><ent r="6" t="13" w="968" /><ent r="6" t="14" w="1023" /><ent r="6" t="14" w="1023" /><ent r="5" t="15" w="1226" /><ent r="5" t="15" w="1226" /><ent r="6" t="16" w="1247" /><ent r="6" t="16" w="1247" /><ent r="3" t="95" w="436" /><ent r="3" t="95" w="436" /><ent r="3" t="96" w="39" /><ent r="3" t="96" w="39" /><ent r="4" t="143" w="96" /><ent r="4" t="143" w="96" /><ent r="4" t="163" w="86" /><ent r="4" t="163" w="86" /><ent r="4" t="163" w="134" /><ent r="4" t="163" w="134" /><ent r="3" t="174" w="562" /><ent r="3" t="174" w="562" /></phr></stem><stem n="month"><phr n="months"><ent r="6" t="10" w="1078" /><ent r="6" t="10" w="1078" /><ent r="6" t="11" w="851" /><ent r="6"
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text, with very long lines (28233), with CRLF line terminators
    Category:dropped
    Size (bytes):28326
    Entropy (8bit):3.9573474963011943
    Encrypted:false
    SSDEEP:768:WTiQ6WLOxH8HVSG1cwAyUMzGcDD/7SdY8rZA2Bo47sAusZTFI6HoYA06WuG82xVO:nH5KMi8P6yD+O/QKskvtvoBP
    MD5:6CCF213CA7E1E25943CA996A1F8EE4E6
    SHA1:CFF8ED58D9B7FEFF44EB76395988B66BAD6F5C9B
    SHA-256:7D43A8CD3F0AA8761B8C61F8AC2CCFBB16BEDC2DFC5948E856589C90399C2396
    SHA-512:6DAB1CCFC6795AF2D4A2C144EBC29E6CC242906AB0C89703740D7F915237B01508ED7FEE11B42725DB66649F11554671CDA185125176318F73C111B479AF4D2F
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="utf-8"?><index> saved from url=(0016)http://localhost -->..<stem n="port"><phr n="ports"><ent r="3" t="2" w="440" /><ent r="4" t="7" w="483" /><ent r="3" t="7" w="645" /><ent r="4" t="7" w="842" /><ent r="4" t="7" w="866" /><ent r="3" t="17" w="358" /><ent r="5" t="84" w="34" /><ent r="5" t="86" w="439" /><ent r="268435456" t="89" w="6" /><ent r="16777218" t="89" w="13" /><ent r="6" t="89" w="48" /><ent r="6" t="89" w="67" /><ent r="4" t="89" w="74" /><ent r="4" t="89" w="145" /><ent r="4" t="89" w="163" /><ent r="3" t="90" w="22" /><ent r="5" t="90" w="357" /><ent r="4" t="91" w="58" /><ent r="4" t="92" w="86" /><ent r="3" t="108" w="43" /><ent r="3" t="108" w="177" /><ent r="4" t="121" w="469" /><ent r="4" t="121" w="477" /><ent r="4" t="150" w="76" /><ent r="1048578" t="153" w="180" /><ent r="3" t="153" w="187" /><ent r="3" t="153" w="204" /><ent r="3" t="153" w="213" /><ent r="3" t="153" w="239" /><ent r="5" t="158" w="170" /><ent r="4" t="158" w="
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
    Category:dropped
    Size (bytes):34122
    Entropy (8bit):4.972148069411361
    Encrypted:false
    SSDEEP:192:GQ05mIYYWXN/wgKCLFWPKjJ700bx2Y9L5ZrCvgePLAgkckJf7NpfJLA1opKAn:GrmpdIgKCRHj+4gYx3rCvXGt7NxJ9pKA
    MD5:2D6B44DB36B84D7951CC4B078729B6A8
    SHA1:D9C98C4FA226ED11135361E24036CFEF5F54EC6C
    SHA-256:957424E9245DC4B1E786C5EA1C647C0D948E66CA526E21F081921EEE40BC5EE8
    SHA-512:379492BBCD4F09D57148DC443D391466A2A8BCCEB961273D434BA8D7FA430D819D0E8E2CD7A54978DED66F82F8BCC13F9974E0A788AB67B339810A6E85FE0280
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="utf-8"?>..<CatapultToc Version="1" DescendantCount="199">.. saved from url=(0016)http://localhost -->.. <TocEntry Title="Welcome" Link="/Content/welcome.htm" ComputedResetPageLayout="true" ComputedFirstTopic="true" DescendantCount="0" />.. <TocEntry Title="An Overview of HOBOware" Link="/Content/HOBOware/General/hw_overview.htm" ComputedFirstTopic="false" DescendantCount="4">.. <TocEntry Title="Installing HOBOware" Link="/Content/HOBOware/General/installation.htm" ComputedFirstTopic="false" DescendantCount="0" />.. <TocEntry Title="New HOBOware Features" Link="/Content/HOBOware/General/new-features.htm" ComputedFirstTopic="false" DescendantCount="0" />.. <TocEntry Title="A Tour of the HOBOware Interface" Link="/Content/HOBOware/General/gui-ov.htm" ComputedFirstTopic="false" DescendantCount="0" />.. <TocEntry Title="Working in Secure Mode: 21 CFR Part 11 Compliance" Link="/Content/HOBOware/Data Files/secure_mode.htm
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text, with very long lines (27388), with CRLF line terminators
    Category:dropped
    Size (bytes):27481
    Entropy (8bit):4.024286570278367
    Encrypted:false
    SSDEEP:768:XObbccccJJ22JJYYbbnnII//9A9ADDToToIInnYdxxsnn00Obb11yyBBssssCCZz:YqqaFXgsvImgqp3JCJNEhu9M70llvsFV
    MD5:9ACEA3A2124BCBD452B793D6EA3F458F
    SHA1:7064BFDEA81FEDD772DB768BA0BDA846A9694E84
    SHA-256:F7DFBEAA79C3B59AEE58760CFD8E97C03723FD9DF2E7A9AEB0D2319B74CD78B2
    SHA-512:1097B1F2411BF2C38F994BDF7834DBE5E491A64D9C488B8B1499774178C40D2BE479DC7247F36E725D97CC236A7FC022FD98D0BB7A564C41FC55F7A5ACDB26A2
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="utf-8"?><index> saved from url=(0016)http://localhost -->..<stem n="certain"><phr n="certain"><ent r="4" t="6" w="210" /><ent r="4" t="6" w="210" /><ent r="5" t="15" w="1149" /><ent r="5" t="15" w="1149" /><ent r="3" t="23" w="27" /><ent r="3" t="23" w="27" /><ent r="3" t="32" w="54" /><ent r="3" t="32" w="54" /><ent r="4" t="38" w="427" /><ent r="4" t="38" w="427" /><ent r="3" t="52" w="14" /><ent r="3" t="52" w="14" /><ent r="3" t="72" w="125" /><ent r="3" t="72" w="125" /><ent r="3" t="79" w="19" /><ent r="3" t="79" w="19" /><ent r="3" t="80" w="21" /><ent r="3" t="80" w="21" /><ent r="4" t="115" w="111" /><ent r="4" t="115" w="111" /><ent r="4" t="151" w="77" /><ent r="4" t="151" w="77" /><ent r="4" t="158" w="217" /><ent r="4" t="158" w="217" /><ent r="3" t="164" w="23" /><ent r="3" t="164" w="23" /><ent r="4" t="164" w="119" /><ent r="4" t="164" w="119" /><ent r="4" t="166" w="343" /><ent r="4" t="166" w="343" /><ent r="4" t="176" w="16" /><ent r
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text, with very long lines (26472), with CRLF line terminators
    Category:dropped
    Size (bytes):26565
    Entropy (8bit):3.9544446311536645
    Encrypted:false
    SSDEEP:768:kEE2cJccv7/BhoXb9Qspvb4q7YaGBj/r/Sbqrz3F/l8svreteaQwB3Ip33qHf5Cm:ailXFDvnzVh2cW3AFcij
    MD5:0A69E28CEE7533689DB25EDA86DA6FB7
    SHA1:10380EBF28A25ADA4B89991C8355A4EF66A5533E
    SHA-256:B7F592D97B76783EC68BAD4342D1E80777AD6D9D253B05677DA2013BA844BB59
    SHA-512:95E9FF58D6BC0FE286CE16CFCEAD40CDF2D7B54E69FBC82C9F09F2294AE1381FA584AFA2383AED04727AF55095A3EA9ED2C984A86E8FA6690430231F114D727D
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="utf-8"?><index> saved from url=(0016)http://localhost -->..<stem n="project"><phr n="project"><ent r="3" t="1" w="46" /><ent r="4" t="5" w="174" /><ent r="4" t="6" w="256" /><ent r="3" t="38" w="18" /><ent r="3" t="38" w="209" /><ent r="4" t="38" w="218" /><ent r="4" t="38" w="222" /><ent r="3" t="39" w="55" /><ent r="3" t="45" w="88" /><ent r="3" t="45" w="97" /><ent r="3" t="45" w="161" /><ent r="5" t="48" w="98" /><ent r="3" t="60" w="262" /><ent r="4" t="62" w="279" /><ent r="268435456" t="65" w="2" /><ent r="16777218" t="65" w="6" /><ent r="3" t="65" w="10" /><ent r="3" t="65" w="32" /><ent r="3" t="65" w="44" /><ent r="3" t="65" w="77" /><ent r="3" t="65" w="86" /><ent r="3" t="65" w="90" /><ent r="3" t="70" w="625" /><ent r="4" t="71" w="1595" /><ent r="4" t="76" w="71" /><ent r="4" t="81" w="512" /><ent r="4" t="157" w="235" /><ent r="5" t="157" w="239" /><ent r="4" t="157" w="261" /><ent r="4" t="157" w="290" /><ent r="4" t="158" w="121" /><en
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:exported SGML document, ASCII text, with very long lines (15097), with CRLF line terminators
    Category:dropped
    Size (bytes):15341
    Entropy (8bit):4.468818395568653
    Encrypted:false
    SSDEEP:384:HDJJjaP9LvvKuNSnmiqqj/eE++2KyQCC4oMu8PQGGggAA/BUZxOSQMVE3XH8iFFH:HDJJjaP9LvvKuNSnmiqqjGE++2KyQCCR
    MD5:AF6419F5D412173BBED6D8D30E6C2116
    SHA1:7D42E5D535836F9A8261ACFCB4AAD503E4CEE216
    SHA-256:FE258F331429313976D1E434825D1FD7939D4742F9D914E159981ACB14F4B431
    SHA-512:BAC14D00A09C6A64C3C023AE1D6E5C34D957AD4B676FE81357C95EF1E9550A52537AE99C51C1B2D2FB0EDC886CACE2AA683334A843A2FBE0C78E0E4BB8C927CC
    Malicious:false
    Reputation:low
    Preview:var xmlSearch_Chunk91Data = "";..xmlSearch_Chunk91Data += '<?xml version=\"1.0\" encoding=\"utf-8\"?><index> saved from url=(0016)http://localhost -->';..xmlSearch_Chunk91Data += '<stem n=\"wrap-en\"><phr n=\"wrap-enabled\"><ent r=\"4\" t=\"170\" w=\"512\" /><ent r=\"4\" t=\"170\" w=\"512\" /><ent r=\"3\" t=\"172\" w=\"124\" /><ent r=\"3\" t=\"172\" w=\"124\" /><ent r=\"5\" t=\"176\" w=\"313\" /><ent r=\"5\" t=\"176\" w=\"313\" /></phr></stem><stem n=\"discontinu\"><phr n=\"discontinued\"><ent r=\"4\" t=\"170\" w=\"545\" /><ent r=\"3\" t=\"172\" w=\"157\" /><ent r=\"5\" t=\"176\" w=\"346\" /></phr></stem><stem n=\"scheme\"><phr n=\"scheme\"><ent r=\"4\" t=\"170\" w=\"725\" /><ent r=\"4\" t=\"170\" w=\"725\" /><ent r=\"92\" t=\"186\" w=\"125\" /><ent r=\"92\" t=\"186\" w=\"125\" /><ent r=\"3\" t=\"186\" w=\"135\" /><ent r=\"3\" t=\"186\" w=\"135\" /></phr></stem><stem n=\"definit\"><phr n=\"definitions\"><ent r=\"3\" t=\"171\" w=\"45\" /><ent r=\"3\" t=\"171\" w=\"45\" /></phr></ste
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text, with very long lines (27040), with CRLF line terminators
    Category:dropped
    Size (bytes):27133
    Entropy (8bit):4.0504725079524135
    Encrypted:false
    SSDEEP:768:GarEswgKTOGrFjRvYly9rdBhJ3Sh88KIkIqtw6gV5LKCIidRxdo9DIulmN+kzu6/:uS10RzWmw9x0Zj9HAvuep
    MD5:638A9F0E794230C2D0DE4230DB635C29
    SHA1:27C2F7E6A9405DBECF3B92CAD7C0B86D143B6591
    SHA-256:B817D21AE56F7847CC9ACB2BED7793BA42400764D03DF48FDEFFAE594B3C0B2A
    SHA-512:E6578DEFDAC9C2C797194FB4A23D9397D7051664D3216640811167F30A87F6DA53A27337FD0CC341D1EE7113CA42FD3BD5AFB437332F3D968AA862BFC65225D1
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="utf-8"?><index> saved from url=(0016)http://localhost -->..<stem n="here"><phr n="here"><ent r="3" t="9" w="84" /><ent r="4" t="10" w="118" /><ent r="4" t="11" w="145" /><ent r="4" t="12" w="129" /><ent r="4" t="13" w="133" /><ent r="4" t="16" w="129" /><ent r="4" t="33" w="306" /><ent r="3" t="62" w="307" /><ent r="5" t="71" w="1381" /><ent r="5" t="71" w="1445" /><ent r="4" t="74" w="257" /><ent r="5" t="104" w="88" /><ent r="4" t="125" w="198" /><ent r="4" t="125" w="268" /><ent r="3" t="160" w="33" /><ent r="4" t="169" w="223" /><ent r="4" t="174" w="247" /><ent r="4" t="197" w="47" /><ent r="3" t="198" w="38" /></phr></stem><stem n="desir"><phr n="desired"><ent r="4" t="9" w="211" /><ent r="4" t="10" w="245" /><ent r="3" t="11" w="252" /><ent r="4" t="12" w="269" /><ent r="4" t="13" w="462" /><ent r="4" t="14" w="412" /><ent r="3" t="15" w="341" /><ent r="4" t="16" w="351" /><ent r="4" t="16" w="712" /><ent r="4" t="17" w="681" /><ent r="4" t="22"
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:exported SGML document, ASCII text, with very long lines (33944), with CRLF line terminators
    Category:dropped
    Size (bytes):34188
    Entropy (8bit):3.9684555665432013
    Encrypted:false
    SSDEEP:768:WcUu4zp+wRHCZHwKpfPdiwNj0QPj+hfXbBtGYCR8yPhdos5AmAtouAICeTP2ETEg:ywkOUp3mF96iweL4Nt
    MD5:C6082CE704CD715E7031DC167A3FDF2B
    SHA1:66E010967E7F26384BB5787E48C7E4C5EC55115D
    SHA-256:4217051FF4EE028ACB5D6326D3B8B9247574CABCE9A1640747D79146C9B65AF6
    SHA-512:6B5344D7AE75A449F3B7A1F2B231AE6E77C3B06737ED21A5C5064AF224240C3D541B91046CB260E0EE5FB5E877FCE914AA8AACD6064DD0CF93D8188493A97924
    Malicious:false
    Reputation:low
    Preview:var xmlSearch_Chunk10Data = "";..xmlSearch_Chunk10Data += '<?xml version=\"1.0\" encoding=\"utf-8\"?><index> saved from url=(0016)http://localhost -->';..xmlSearch_Chunk10Data += '<stem n=\"statu\"><phr n=\"status\"><ent r=\"3\" t=\"1\" w=\"36\" /><ent r=\"4\" t=\"3\" w=\"1054\" /><ent r=\"3\" t=\"4\" w=\"40\" /><ent r=\"4\" t=\"5\" w=\"398\" /><ent r=\"5\" t=\"6\" w=\"62\" /><ent r=\"4\" t=\"6\" w=\"75\" /><ent r=\"3\" t=\"7\" w=\"103\" /><ent r=\"3\" t=\"7\" w=\"676\" /><ent r=\"3\" t=\"7\" w=\"704\" /><ent r=\"3\" t=\"9\" w=\"127\" /><ent r=\"3\" t=\"9\" w=\"136\" /><ent r=\"5\" t=\"10\" w=\"164\" /><ent r=\"4\" t=\"10\" w=\"168\" /><ent r=\"5\" t=\"11\" w=\"191\" /><ent r=\"4\" t=\"11\" w=\"195\" /><ent r=\"5\" t=\"12\" w=\"175\" /><ent r=\"4\" t=\"12\" w=\"179\" /><ent r=\"5\" t=\"13\" w=\"179\" /><ent r=\"4\" t=\"13\" w=\"183\" /><ent r=\"5\" t=\"14\" w=\"181\" /><ent r=\"4\" t=\"14\" w=\"185\" /><ent r=\"4\" t=\"14\" w=\"200\" /><ent r=\"4\" t=\"14\" w=\"652\" /><ent r=\"5\"
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:ASCII text, with very long lines (9503), with no line terminators
    Category:dropped
    Size (bytes):9503
    Entropy (8bit):4.960727159126462
    Encrypted:false
    SSDEEP:96:Z5GfV6oMPceruRBOgSeh4L74QL7y39LWy2JS0RR:XGNQcerABO0e74Qq39LVRG
    MD5:DDC8BEC4552F790A8D2C63300DA85C66
    SHA1:9C721F31BB9E0F8E25BC70EB430EF95875277599
    SHA-256:5CEB0A4E9FB996181A2EA3C4CBB905FF59347332347D10EB90306ABD4A81F43F
    SHA-512:5EBC8697DD6735139054986BBB71B03D973E2E753CF3FD6931471B5478485B3DA7A3ABBA71211879DA2B17D022100772022F7D2629419B357527F37AE8124F33
    Malicious:false
    Reputation:low
    Preview:define({"../Content/HOBOware/Alarm \u0026 Readout Tool/art-intro.htm":169,"../Content/HOBOware/CSH/csh-CO2.htm":30,"../Content/HOBOware/CSH/csh-add-nw-map.htm":133,"../Content/HOBOware/CSH/csh-add-sens-alrm.htm":124,"../Content/HOBOware/CSH/csh-advanced-calibration.htm":25,"../Content/HOBOware/CSH/csh-advanced-occupancy.htm":26,"../Content/HOBOware/CSH/csh-alarms.htm":23,"../Content/HOBOware/CSH/csh-burst.htm":29,"../Content/HOBOware/CSH/csh-convert-units.htm":62,"../Content/HOBOware/CSH/csh-crop.htm":58,"../Content/HOBOware/CSH/csh-dif-filters-stats.htm":28,"../Content/HOBOware/CSH/csh-filter-at-launch.htm":21,"../Content/HOBOware/CSH/csh-filter-series.htm":57,"../Content/HOBOware/CSH/csh-firmware.htm":99,"../Content/HOBOware/CSH/csh-heartbeat-alrm.htm":172,"../Content/HOBOware/CSH/csh-hnm-db-backup.htm":122,"../Content/HOBOware/CSH/csh-hnm-firmware.htm":145,"../Content/HOBOware/CSH/csh-hnm-main.htm":102,"../Content/HOBOware/CSH/csh-hnm-map-config.htm":134,"../Content/HOBOware/CSH/csh
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:exported SGML document, ASCII text, with very long lines (32364), with CRLF line terminators
    Category:dropped
    Size (bytes):32608
    Entropy (8bit):4.24102215956261
    Encrypted:false
    SSDEEP:768:1H11GGti0ff4400aaSUEE++33bbqqXXeeyyFF++00EEkk0077WW669HWKJTxEc+z:S
    MD5:5D05AE39596A3D1FBB24999758E7BC8D
    SHA1:9FBD154542BAB8F8AFD2D3758C01FF5D4CB6F7E2
    SHA-256:4E4075572032BB6D1BA332C0501D18D3CFB5CA7EF0FCC95E6413F3702E0BECFE
    SHA-512:B23563EA0E81DFF5659493E12654B619776E128F22216DB5ED41AACDCC26F1296F213EEA0AE6AD710E4445276368EA75E1137491122033160A128054CA697234
    Malicious:false
    Reputation:low
    Preview:var xmlSearch_Chunk81Data = "";..xmlSearch_Chunk81Data += '<?xml version=\"1.0\" encoding=\"utf-8\"?><index> saved from url=(0016)http://localhost -->';..xmlSearch_Chunk81Data += '<stem n=\"unsav\"><phr n=\"unsaved\"><ent r=\"3\" t=\"43\" w=\"185\" /><ent r=\"3\" t=\"43\" w=\"185\" /><ent r=\"5\" t=\"154\" w=\"210\" /><ent r=\"5\" t=\"154\" w=\"210\" /><ent r=\"4\" t=\"163\" w=\"50\" /><ent r=\"4\" t=\"163\" w=\"50\" /><ent r=\"5\" t=\"195\" w=\"42\" /><ent r=\"5\" t=\"195\" w=\"42\" /></phr></stem><stem n=\"provid\"><phr n=\"provides\"><ent r=\"3\" t=\"44\" w=\"31\" /><ent r=\"3\" t=\"44\" w=\"31\" /><ent r=\"3\" t=\"69\" w=\"20\" /><ent r=\"3\" t=\"69\" w=\"20\" /><ent r=\"4\" t=\"69\" w=\"406\" /><ent r=\"4\" t=\"69\" w=\"406\" /><ent r=\"4\" t=\"93\" w=\"207\" /><ent r=\"4\" t=\"93\" w=\"207\" /><ent r=\"3\" t=\"101\" w=\"15\" /><ent r=\"3\" t=\"101\" w=\"15\" /><ent r=\"3\" t=\"113\" w=\"744\" /><ent r=\"3\" t=\"113\" w=\"744\" /></phr><phr n=\"provide\"><ent r=\"4\" t=\"64\"
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:exported SGML document, ASCII text, with very long lines (32106), with CRLF line terminators
    Category:dropped
    Size (bytes):32350
    Entropy (8bit):4.105190084015802
    Encrypted:false
    SSDEEP:768:Yli0E0ZZooWWII+qPgVV8RnXXPZTtDDQQaapp//XXzzSSJJ22LLLLHHrrm66N205:Ys+S
    MD5:75EF27C565B6E759AFE67455A2EB962C
    SHA1:F08FC0A5E7856FA71CEB6AD3CE3D0858F21C0855
    SHA-256:7F1D92AF56D33F5E38A632FAFD12C1A24401A8075D7C93243237ABBFD3312DEF
    SHA-512:6F9D8404270E44F033090BD8675683179FFC696DD726CF383D7F4AD18ABD995093AC70A696B45504B0C80D23C6A21C81F0679315AD5B9AF366E025BF5B46D5FE
    Malicious:false
    Reputation:low
    Preview:var xmlSearch_Chunk75Data = "";..xmlSearch_Chunk75Data += '<?xml version=\"1.0\" encoding=\"utf-8\"?><index> saved from url=(0016)http://localhost -->';..xmlSearch_Chunk75Data += '<stem n=\"h21\"><phr n=\"H21\"><ent r=\"4\" t=\"16\" w=\"655\" /><ent r=\"4\" t=\"16\" w=\"655\" /></phr></stem><stem n=\"h22\"><phr n=\"H22\"><ent r=\"4\" t=\"16\" w=\"664\" /><ent r=\"4\" t=\"16\" w=\"664\" /></phr></stem><stem n=\"trm\"><phr n=\"TRMS\"><ent r=\"4\" t=\"16\" w=\"838\" /><ent r=\"4\" t=\"16\" w=\"838\" /><ent r=\"4\" t=\"65\" w=\"111\" /><ent r=\"4\" t=\"65\" w=\"111\" /><ent r=\"3\" t=\"89\" w=\"54\" /><ent r=\"3\" t=\"89\" w=\"54\" /><ent r=\"3\" t=\"89\" w=\"63\" /><ent r=\"3\" t=\"89\" w=\"63\" /><ent r=\"5\" t=\"154\" w=\"714\" /><ent r=\"5\" t=\"154\" w=\"714\" /><ent r=\"4\" t=\"154\" w=\"735\" /><ent r=\"4\" t=\"154\" w=\"735\" /></phr></stem><stem n=\"erron\"><phr n=\"erroneous\"><ent r=\"4\" t=\"16\" w=\"856\" /><ent r=\"4\" t=\"16\" w=\"856\" /></phr></stem><stem n=\"togeth\">
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:exported SGML document, ASCII text, with very long lines (32273), with CRLF line terminators
    Category:dropped
    Size (bytes):32517
    Entropy (8bit):4.159626274611325
    Encrypted:false
    SSDEEP:768:gTppHHeeGt8frrko86cEEKKrreexoxoBB11wwHHuuvJgPPppAAmmyyTThhooccsf:8kb
    MD5:CF58D463EF733E7F86807D80884FAA31
    SHA1:81FC94A36FC81BD8D3A60C3328CBB71A859EA9BF
    SHA-256:BBE1EA9EDA6C3A1E85885E06B28576A55E6EC17698247B441C51C6198B3C8ED0
    SHA-512:004E061464E54382FE3B8B7477F4A72554E467CD6FA07B92AB580C1A225A1F19E0269A99633F4979602DC7F84BFF89874E67654840A7C69935EEC3075B138966
    Malicious:false
    Reputation:low
    Preview:var xmlSearch_Chunk80Data = "";..xmlSearch_Chunk80Data += '<?xml version=\"1.0\" encoding=\"utf-8\"?><index> saved from url=(0016)http://localhost -->';..xmlSearch_Chunk80Data += '<stem n=\"zoom\"><phr n=\"zoomed\"><ent r=\"4\" t=\"38\" w=\"146\" /><ent r=\"4\" t=\"38\" w=\"146\" /><ent r=\"3\" t=\"40\" w=\"135\" /><ent r=\"3\" t=\"40\" w=\"135\" /><ent r=\"3\" t=\"41\" w=\"406\" /><ent r=\"3\" t=\"41\" w=\"406\" /><ent r=\"3\" t=\"41\" w=\"591\" /><ent r=\"3\" t=\"41\" w=\"591\" /><ent r=\"3\" t=\"41\" w=\"678\" /><ent r=\"4\" t=\"151\" w=\"719\" /><ent r=\"4\" t=\"151\" w=\"719\" /></phr><phr n=\"zooming\"><ent r=\"4\" t=\"38\" w=\"160\" /><ent r=\"4\" t=\"38\" w=\"160\" /><ent r=\"4\" t=\"38\" w=\"164\" /><ent r=\"4\" t=\"38\" w=\"164\" /><ent r=\"3\" t=\"41\" w=\"25\" /><ent r=\"3\" t=\"41\" w=\"108\" /><ent r=\"4\" t=\"41\" w=\"134\" /><ent r=\"4\" t=\"41\" w=\"200\" /><ent r=\"4\" t=\"41\" w=\"246\" /><ent r=\"4\" t=\"41\" w=\"277\" /><ent r=\"4\" t=\"41\" w=\"277\" /><ent r=
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text, with very long lines (29158), with CRLF line terminators
    Category:dropped
    Size (bytes):29251
    Entropy (8bit):4.0153400697825505
    Encrypted:false
    SSDEEP:768:aPYAYIGANoUwcceeRRDLXccLxN+SsPee55MM66yRQ88QQnn22QQWWPP22zzLL1Jl:uXFaBwyXc+Z/W7d6q
    MD5:628E23B4E89010D6F676B5DE03B8E74F
    SHA1:0D9D833171C74A6F686D8FC2007CDD8CF8E9C336
    SHA-256:63733FA106035F42695C955D8AF68631ACF126C7DEE92C865E823D3192849D6E
    SHA-512:A10D83CB71981D71FD7F36C2C475ACB43E44854DF29E2495C91C051EC5C09D0D17AA9A2D6CDF1EACD730492D4875427875243B5BC45BD2D367729B35F80CAADB
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="utf-8"?><index> saved from url=(0016)http://localhost -->..<stem n="answer"><phr n="Answer"><ent r="4" t="8" w="110" /><ent r="4" t="8" w="110" /></phr><phr n="answer"><ent r="64" t="130" w="141" /><ent r="64" t="130" w="145" /></phr></stem><stem n="accordingli"><phr n="accordingly"><ent r="4" t="8" w="115" /><ent r="4" t="60" w="117" /><ent r="4" t="60" w="258" /><ent r="3" t="108" w="74" /><ent r="3" t="173" w="108" /></phr></stem><stem n="finish"><phr n="finished"><ent r="4" t="8" w="157" /><ent r="4" t="8" w="157" /><ent r="3" t="11" w="1516" /><ent r="3" t="12" w="1550" /><ent r="3" t="14" w="1578" /><ent r="4" t="21" w="295" /><ent r="4" t="22" w="173" /><ent r="4" t="22" w="173" /><ent r="4" t="69" w="1489" /><ent r="4" t="69" w="1489" /><ent r="4" t="85" w="328" /><ent r="4" t="85" w="328" /><ent r="4" t="144" w="782" /><ent r="3" t="183" w="64" /></phr><phr n="finish"><ent r="3" t="91" w="243" /><ent r="3" t="91" w="243" /><ent r="4" t="93" w=
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:exported SGML document, ASCII text, with very long lines (32446), with CRLF line terminators
    Category:dropped
    Size (bytes):32690
    Entropy (8bit):4.089020528166503
    Encrypted:false
    SSDEEP:768:O9QH9EgEGQMeo7Waz+o5APmciu2ONt8LJ+9SL2MlDwoRr+1sB2Arjfn8ftzb4oje:2V9YZ3zpjR
    MD5:2B271F702407366C0C7B746374EA9D75
    SHA1:BCAAF931DE44A60D0E8FA80FE3EE50DD156EF6C6
    SHA-256:9563D052FF86B1301E54B55739924FF48BD1D72E79D4EEEB3EA2042FF392CC0D
    SHA-512:116641ECF50E89C424CC46AF8829158627E340D39B9219ECB40C0915C26B56DB4711E479E475A2B8FFB9F0CCBED7642AC8C897571B4CF8FBDC0CFC1920393F5E
    Malicious:false
    Reputation:low
    Preview:var xmlSearch_Chunk44Data = "";..xmlSearch_Chunk44Data += '<?xml version=\"1.0\" encoding=\"utf-8\"?><index> saved from url=(0016)http://localhost -->';..xmlSearch_Chunk44Data += '<stem n=\"messag\"><phr n=\"message\"><ent r=\"3\" t=\"5\" w=\"488\" /><ent r=\"4\" t=\"33\" w=\"451\" /><ent r=\"3\" t=\"33\" w=\"815\" /><ent r=\"4\" t=\"80\" w=\"239\" /><ent r=\"3\" t=\"80\" w=\"359\" /><ent r=\"3\" t=\"86\" w=\"205\" /><ent r=\"3\" t=\"86\" w=\"232\" /><ent r=\"4\" t=\"96\" w=\"462\" /><ent r=\"4\" t=\"96\" w=\"475\" /><ent r=\"4\" t=\"96\" w=\"495\" /><ent r=\"4\" t=\"96\" w=\"523\" /><ent r=\"4\" t=\"100\" w=\"786\" /><ent r=\"4\" t=\"101\" w=\"207\" /><ent r=\"4\" t=\"101\" w=\"247\" /><ent r=\"3\" t=\"101\" w=\"270\" /><ent r=\"3\" t=\"101\" w=\"309\" /><ent r=\"3\" t=\"101\" w=\"321\" /><ent r=\"4\" t=\"101\" w=\"451\" /><ent r=\"4\" t=\"101\" w=\"546\" /><ent r=\"4\" t=\"101\" w=\"563\" /><ent r=\"4\" t=\"101\" w=\"698\" /><ent r=\"3\" t=\"102\" w=\"92\" /><ent r=\"3\" t=\"102\
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text, with very long lines (31902), with CRLF line terminators
    Category:dropped
    Size (bytes):31995
    Entropy (8bit):3.969145216267512
    Encrypted:false
    SSDEEP:768:MiNbvD6uuSPES5POUo81GytXAASB3NtmMGfaowHUTPdYACdTDYjCWWA7HJjLkGgr:H+HAnONULXtaigC806v
    MD5:0EB03E944486037B902103095164214A
    SHA1:71225933DCD8A6B1262897BB36A738F34657C44E
    SHA-256:489EE5B07E258299E3DE899D07DF1DAA7B6E14653D9AF3EFBE9E59F835B3FA30
    SHA-512:DEB679D35191DB4503452A17038E235A59CBD22D9E9A2A9F2E47DFA738F0EDF46EE1DE2B1DEE3F728B8E98B56C8BE0A18C0CA6C678A9D0252603C74DDD6714CD
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="utf-8"?><index> saved from url=(0016)http://localhost -->..<stem n="6"><phr n="6"><ent r="3" t="3" w="248" /><ent r="4" t="3" w="732" /><ent r="3" t="15" w="94" /><ent r="4" t="15" w="534" /><ent r="3" t="26" w="252" /><ent r="4" t="71" w="97" /><ent r="4" t="71" w="971" /><ent r="3" t="123" w="490" /><ent r="8" t="124" w="217" /><ent r="8" t="143" w="158" /></phr></stem><stem n="4"><phr n="4"><ent r="4" t="3" w="255" /><ent r="4" t="3" w="329" /><ent r="3" t="3" w="446" /><ent r="3" t="3" w="471" /><ent r="3" t="3" w="762" /><ent r="5" t="3" w="1424" /><ent r="4" t="3" w="1474" /><ent r="5" t="9" w="610" /><ent r="5" t="9" w="622" /><ent r="5" t="9" w="634" /><ent r="4" t="10" w="367" /><ent r="5" t="10" w="1391" /><ent r="5" t="10" w="1403" /><ent r="5" t="10" w="1415" /><ent r="268435456" t="11" w="11" /><ent r="16777218" t="11" w="28" /><ent r="3" t="11" w="50" /><ent r="5" t="11" w="1578" /><ent r="5" t="11" w="1590" /><ent r="268435456" t="12" w=
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:exported SGML document, ASCII text, with very long lines (34119), with CRLF line terminators
    Category:dropped
    Size (bytes):34363
    Entropy (8bit):4.027821942938091
    Encrypted:false
    SSDEEP:768:/FoW7//99XXjjNNd/3ALmuZx39PeqcKKX5OQQBVs0AVVzhzhOOK0K0jjllll99lY:lts3A9nPW
    MD5:0ECC84354F4DE22783BDB35CEF81D6A3
    SHA1:778CF53A61003DDC779C0A2AF0E58F60C38DF150
    SHA-256:BFA4D5DFA5D2A22DDE75EC526048D35AF60E9B6BC98EEA29E7F8E580083E1AC5
    SHA-512:35E3CEAF27D184E7FB121608DAC8955104EC1565E9B666C3ECEF24301B4ECF9EBA3AA7640F868AB1A4FE42FAF79514D9CED547DA32E8BC7BBF3F021A1B0F8666
    Malicious:false
    Reputation:low
    Preview:var xmlSearch_Chunk66Data = "";..xmlSearch_Chunk66Data += '<?xml version=\"1.0\" encoding=\"utf-8\"?><index> saved from url=(0016)http://localhost -->';..xmlSearch_Chunk66Data += '<stem n=\"small\"><phr n=\"small\"><ent r=\"4\" t=\"7\" w=\"274\" /><ent r=\"4\" t=\"7\" w=\"274\" /><ent r=\"4\" t=\"31\" w=\"198\" /><ent r=\"4\" t=\"31\" w=\"198\" /><ent r=\"3\" t=\"40\" w=\"243\" /><ent r=\"3\" t=\"40\" w=\"243\" /><ent r=\"3\" t=\"40\" w=\"421\" /><ent r=\"3\" t=\"40\" w=\"421\" /><ent r=\"4\" t=\"97\" w=\"640\" /><ent r=\"4\" t=\"97\" w=\"640\" /><ent r=\"5\" t=\"154\" w=\"711\" /><ent r=\"5\" t=\"154\" w=\"711\" /><ent r=\"3\" t=\"163\" w=\"232\" /><ent r=\"3\" t=\"163\" w=\"232\" /></phr></stem><stem n=\"9-pin\"><phr n=\"9-pin\"><ent r=\"4\" t=\"7\" w=\"333\" /><ent r=\"4\" t=\"7\" w=\"333\" /></phr></stem><stem n=\"9\"><phr n=\"9\"><ent r=\"4\" t=\"7\" w=\"333\" /><ent r=\"6\" t=\"10\" w=\"978\" /><ent r=\"6\" t=\"11\" w=\"806\" /><ent r=\"6\" t=\"12\" w=\"927\" /><ent r=\"6\" t
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:exported SGML document, ASCII text, with very long lines (33052), with CRLF line terminators
    Category:dropped
    Size (bytes):33296
    Entropy (8bit):4.027599238999001
    Encrypted:false
    SSDEEP:768:HwHHKK66xxUUJJqqLLjjyyLLMM77CC++jj+h99Crr66Q//BBAAFFaammooBB4046:RwLQ
    MD5:FDB7112DBFBEACFB8BB08E314CD888DB
    SHA1:A6900CB268D7BB02BF1CFA86A97C55DC862294A1
    SHA-256:F1C28519BD18152217AD80956D4931B6CD2CE2D390176F005A935CFCF8B7764B
    SHA-512:4987AA1CADD3C61BD94AD486C597A80183F5BEE4B43F7B7F3C5693B9ED61905C8EAE98FCBDD70E1721816D501DAAAA30A1909A348A873C2BDF118B8F0EBB0D05
    Malicious:false
    Reputation:low
    Preview:var xmlSearch_Chunk65Data = "";..xmlSearch_Chunk65Data += '<?xml version=\"1.0\" encoding=\"utf-8\"?><index> saved from url=(0016)http://localhost -->';..xmlSearch_Chunk65Data += '<stem n=\"certain\"><phr n=\"certain\"><ent r=\"4\" t=\"6\" w=\"210\" /><ent r=\"4\" t=\"6\" w=\"210\" /><ent r=\"5\" t=\"15\" w=\"1149\" /><ent r=\"5\" t=\"15\" w=\"1149\" /><ent r=\"3\" t=\"23\" w=\"27\" /><ent r=\"3\" t=\"23\" w=\"27\" /><ent r=\"3\" t=\"32\" w=\"54\" /><ent r=\"3\" t=\"32\" w=\"54\" /><ent r=\"4\" t=\"38\" w=\"427\" /><ent r=\"4\" t=\"38\" w=\"427\" /><ent r=\"3\" t=\"52\" w=\"14\" /><ent r=\"3\" t=\"52\" w=\"14\" /><ent r=\"3\" t=\"72\" w=\"125\" /><ent r=\"3\" t=\"72\" w=\"125\" /><ent r=\"3\" t=\"79\" w=\"19\" /><ent r=\"3\" t=\"79\" w=\"19\" /><ent r=\"3\" t=\"80\" w=\"21\" /><ent r=\"3\" t=\"80\" w=\"21\" /><ent r=\"4\" t=\"115\" w=\"111\" /><ent r=\"4\" t=\"115\" w=\"111\" /><ent r=\"4\" t=\"151\" w=\"77\" /><ent r=\"4\" t=\"151\" w=\"77\" /><ent r=\"4\" t=\"158\" w=\"217\" /><e
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Unicode text, UTF-8 text, with very long lines (29665), with no line terminators
    Category:dropped
    Size (bytes):29701
    Entropy (8bit):5.028168026514675
    Encrypted:false
    SSDEEP:768:dVgRPy0MjC1DLaz5rGVTYThovkAqHvXWFHsrdQsj2s8kQkGNfFrnVzTOR7y:4HV7gvXWFo2s8/kGNfFZSy
    MD5:DE4EBE095ED0E1620326A688A5A155BA
    SHA1:CA478239C2D91F70EA9385F835EB0F269166D7E5
    SHA-256:9D02F8EF41A01A03937D66A9CAAC177C52AF093A6CE344B464362C7CA9C868CC
    SHA-512:069A25F5737F839E4F910A933C64068839C9EC34C5214308F2BC3629750C16392CBDB2698909B5A2764DC8BB6D4BC8434B7F6748C432BDCD8513054FD9053776
    Malicious:false
    Reputation:low
    Preview:define({"0":{y:0,u:"../Content/HOBOware/welcome.htm",l:-1,t:"Welcome",i:0.00172092340204347,a:".HOBOware Help . . Quick Links New Features An Overview of HOBOware A Tour of the HOBOware Interface Working with HOBO.Data Loggers Reading Out, Plotting, and Analyzing Data Using Data Assistants HOBOnode Manager Bulk Export Tool Hardware Reference . PDFs available from www.onsetcomp.com: HOBOware ..."},"1":{y:0,u:"../Content/HOBOware/General/hw_overview.htm",l:-1,t:"An Overview of.HOBOware",i:0.00193196961795664,a:"An Overview of HOBOware HOBOware software is used for launching, reading out, and plotting data from HOBO. data loggers. With HOBOware, you can also check logger status, filter and export data, save changes to graphs in project files, and scale data with the Linear Scaling and Pulse Scaling data ..."},"2":{y:0,u:"../Content/HOBOware/General/new-features.htm",l:-1,t:"New HOBOware Features",i:0.00188345605341661,a:"The following features are available in HOBOware 3.7.18: Upda
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:exported SGML document, ASCII text, with very long lines (33458), with CRLF line terminators
    Category:dropped
    Size (bytes):33702
    Entropy (8bit):4.019427677519843
    Encrypted:false
    SSDEEP:768:HoG5IAphbr24aCCSbjiGoxIfLjvdPTVwp+KowhK0CoE4uqZHCo6I0EHCo6foTpBX:arN4TDI
    MD5:911342250A9F2B28B750E641A2C44FB5
    SHA1:51D4A8CF68824BD7D1D0FD66D6940B833488F678
    SHA-256:F6069F38008DCD63DA0B7D31F190051C27C5B0B3F01124A1D6D7A696D36DF1D1
    SHA-512:6B293D36860806CF9340A3C072933B54AAB7549E498A6A165B591D48759D4BF41AF7FF894E5C48017ECFEF8A3A27F40D54A4BFDE3BF54B2AA1B6F3F991E28FA4
    Malicious:false
    Reputation:low
    Preview:var xmlSearch_Chunk42Data = "";..xmlSearch_Chunk42Data += '<?xml version=\"1.0\" encoding=\"utf-8\"?><index> saved from url=(0016)http://localhost -->';..xmlSearch_Chunk42Data += '<stem n=\"entir\"><phr n=\"entire\"><ent r=\"3\" t=\"4\" w=\"447\" /><ent r=\"4\" t=\"14\" w=\"606\" /><ent r=\"4\" t=\"28\" w=\"385\" /><ent r=\"3\" t=\"56\" w=\"346\" /><ent r=\"3\" t=\"63\" w=\"43\" /><ent r=\"3\" t=\"90\" w=\"158\" /><ent r=\"3\" t=\"90\" w=\"518\" /><ent r=\"4\" t=\"100\" w=\"1019\" /><ent r=\"3\" t=\"124\" w=\"233\" /><ent r=\"3\" t=\"144\" w=\"89\" /><ent r=\"4\" t=\"146\" w=\"189\" /><ent r=\"4\" t=\"163\" w=\"359\" /><ent r=\"3\" t=\"168\" w=\"342\" /><ent r=\"3\" t=\"168\" w=\"365\" /></phr><phr n=\"entirely\"><ent r=\"4\" t=\"169\" w=\"663\" /></phr></stem><stem n=\"tree\"><phr n=\"tree\"><ent r=\"3\" t=\"4\" w=\"449\" /><ent r=\"3\" t=\"4\" w=\"458\" /></phr></stem><stem n=\"hidden\"><phr n=\"hidden\"><ent r=\"3\" t=\"4\" w=\"491\" /><ent r=\"3\" t=\"4\" w=\"515\" /><ent r=\"3
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
    Category:dropped
    Size (bytes):181
    Entropy (8bit):5.0683177153058185
    Encrypted:false
    SSDEEP:3:vFWWMNHU8LdgCfd5XRJiCPIDqF/Hv1KxTMCSKGEJ7dGFmhJbGFkTOFKMv+S5c:TMVBdvRJhzF/P1KxACSdEJ7UmhVSkTqg
    MD5:D8FEA23D9AB4A7423DB45959901487DD
    SHA1:B3E41263AF4F71D279DC1C605137266E561F0245
    SHA-256:C00FA318A83192500207F55F2707932D7927ECDE59D56658FB000368AE51E821
    SHA-512:EB81444D1E63E17DF9B44A99033B7060719FB454AF9C9078007040B1B9E33B77847764F4C23C2320DD5881E01FDDBD6906746E3BFC0BFB1DD88D93AA9689874C
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="utf-8"?>..<MadCapSynonyms xml:lang="en-us">.. saved from url=(0016)http://localhost -->.. <Groups />.. <Directional />..</MadCapSynonyms>
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:exported SGML document, ASCII text, with very long lines (33182), with CRLF line terminators
    Category:dropped
    Size (bytes):33426
    Entropy (8bit):4.09806633769329
    Encrypted:false
    SSDEEP:768:RM9z4k0uNGvtpST2+u10EaWPJEc3awBA9fvk2Sqd1gfzzzGUqlD/90greLIegUGG:EgKQ7
    MD5:3FEC6F8784952FB74728E3F405CDCA2A
    SHA1:F22EBFCF3B29D438DB0663611B5A907C19002AD1
    SHA-256:E6B2360102E6CE83EC06BB4FC267972CCF1188578DD177CFA22BA5A52563AB6A
    SHA-512:8FB5D103511FDB1A843F15467E381E0261D0A1CD7B5DCA6DABE4C04D5061787DE1E6BAC0946EFBFB42456C65415766DE0DD67E23628315355F6E9D8CAB30D00F
    Malicious:false
    Reputation:low
    Preview:var xmlSearch_Chunk46Data = "";..xmlSearch_Chunk46Data += '<?xml version=\"1.0\" encoding=\"utf-8\"?><index> saved from url=(0016)http://localhost -->';..xmlSearch_Chunk46Data += '<stem n=\"unplug\"><phr n=\"unplug\"><ent r=\"3\" t=\"7\" w=\"592\" /><ent r=\"3\" t=\"7\" w=\"599\" /><ent r=\"4\" t=\"8\" w=\"190\" /><ent r=\"4\" t=\"86\" w=\"502\" /><ent r=\"8\" t=\"146\" w=\"772\" /><ent r=\"8\" t=\"147\" w=\"944\" /><ent r=\"4\" t=\"169\" w=\"536\" /></phr><phr n=\"unplugging\"><ent r=\"3\" t=\"148\" w=\"98\" /><ent r=\"4\" t=\"169\" w=\"467\" /></phr></stem><stem n=\"remov\"><phr n=\"remove\"><ent r=\"3\" t=\"7\" w=\"617\" /><ent r=\"3\" t=\"17\" w=\"271\" /><ent r=\"4\" t=\"17\" w=\"1047\" /><ent r=\"3\" t=\"18\" w=\"190\" /><ent r=\"3\" t=\"42\" w=\"454\" /><ent r=\"3\" t=\"42\" w=\"466\" /><ent r=\"3\" t=\"42\" w=\"470\" /><ent r=\"3\" t=\"55\" w=\"462\" /><ent r=\"3\" t=\"55\" w=\"475\" /><ent r=\"4\" t=\"56\" w=\"389\" /><ent r=\"3\" t=\"56\" w=\"633\" /><ent r=\"4\" t=\"56\"
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, Unicode text, UTF-8 text, with very long lines (27455), with CRLF line terminators
    Category:dropped
    Size (bytes):27550
    Entropy (8bit):4.407538524876717
    Encrypted:false
    SSDEEP:768:3L6neXSnYKmmujPfImaS7iV80ZwCft3Y82cHkaNKlXO+FzatOUBWLzNkcjvV4mO9:PyUdTa5JndF
    MD5:8E3A76C1B7936137117A70FF60672458
    SHA1:54EB2FB237DF8A013014C710EA8589E9242818E6
    SHA-256:5EC7FF700973CCB044A3EADBC47D3CA674A8FBA8D43594D835CD92E7246FBD63
    SHA-512:051113CFE69FC599A3EF3C0D47410B96F8D5332C1B764B0466D58CA7644D253E438A218C8EC5479C6CB964ABA3BCC014B4568E0A295C6CC1B89BA7661BB57BD8
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="utf-8"?><index> saved from url=(0016)http://localhost -->..<stem n="s-ucb"><phr n="s-ucb"><ent r="4" t="68" w="122" /><ent r="3" t="74" w="74" /></phr></stem><stem n="s-ucb-xxxx"><phr n="s-ucb-xxxx"><ent r="4" t="68" w="122" /><ent r="3" t="74" w="74" /></phr></stem><stem n="ucb"><phr n="ucb"><ent r="4" t="68" w="123" /><ent r="3" t="74" w="75" /></phr></stem><stem n="ucb-xxxx"><phr n="ucb-xxxx"><ent r="4" t="68" w="123" /><ent r="3" t="74" w="75" /></phr></stem><stem n="s-ucd"><phr n="s-ucd"><ent r="4" t="68" w="126" /><ent r="3" t="74" w="78" /></phr></stem><stem n="s-ucd-xxxx"><phr n="s-ucd-xxxx"><ent r="4" t="68" w="126" /><ent r="3" t="74" w="78" /></phr></stem><stem n="ucd"><phr n="ucd"><ent r="4" t="68" w="127" /><ent r="3" t="74" w="79" /></phr></stem><stem n="ucd-xxxx"><phr n="ucd-xxxx"><ent r="4" t="68" w="127" /><ent r="3" t="74" w="79" /></phr></stem><stem n="closur"><phr n="closure"><ent r="4" t="68" w="130" /><ent r="3" t="74" w="82" /></
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Unicode text, UTF-8 text, with very long lines (16296), with no line terminators
    Category:dropped
    Size (bytes):16316
    Entropy (8bit):5.034952184060327
    Encrypted:false
    SSDEEP:384:WoQpXFQ+dYDdLzSIqeuJynqwRV00XweC1VPuX2LMQWP6PTr:dQpXFBdkdhOyqmaeIVWmLMIrr
    MD5:2F7231809D3F4E796EC73CFF74294274
    SHA1:F9E10E19C6F045E39E2378B38F9AD968FD112103
    SHA-256:4DC2236C47B66D63EC5070DDB9050D22528CE02845AC14513B52B5601B047874
    SHA-512:7CCBEA251C393C86CD1B2003DE7DB9F8D1C3FE177C5AD2864C8AA97267B6886682C406D1EBB9F739204238D7B03B693B0A0295B775BC0AEEE7A8E20160B3B331
    Malicious:false
    Reputation:low
    Preview:define({"137":{y:0,u:"../Content/HOBOware/HOBOnode Manager/hnm-change-sensor-type.htm",l:-1,t:"Changing External Sensor Type",i:0.001896113022339,a:"Many types of HOBO data nodes can be configured with external sensors. One of the benefits of using external sensors is that you can swap them out when necessary for different ones if you want to modify your wireless network. Or, you can disable the external sensor channel if you don\u0027t need it for ..."},"138":{y:0,u:"../Content/HOBOware/HOBOnode Manager/hnm-move-node.htm",l:-1,t:"Moving or Removing a Data Node",i:0.001896113022339,a:"If you will not be using a data node for an extended period of time, you may want to deactivate it to stop measurements and save batteries. To deactivate a data node, use a paper clip to press the Activate button as shown in the photo below for 5 seconds until the red LED starts flashing. To later ..."},"139":{y:0,u:"../Content/HOBOware/HOBOnode Manager/hnm-switch-to-batt.htm",l:-1,t:"Converting a Rout
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:exported SGML document, ASCII text, with very long lines (32169), with CRLF line terminators
    Category:dropped
    Size (bytes):32413
    Entropy (8bit):4.409848810544316
    Encrypted:false
    SSDEEP:768:Ng0h0I774040zzMkjDDZZKKc+yW7sOiFFgtFyvp7djTR5S2BI4yNNuui0BOQoQTk:j+
    MD5:576A493204AE6483380080A9B80ADEAA
    SHA1:3B0CA41C49C7CF90FB2100D8FA0BB716965E3B73
    SHA-256:F54BFE5051B993F3C4D1815CB7747008EAFF6C5957A80693C0A518B5847A5D38
    SHA-512:752C90A9D88BFDB341A792BDA9FAA277CADD64A550FFE83735A689CC0780FBDEEC31638187D3A2B613FE874318C5DFF03632834129E472521E256C1D36EE97FA
    Malicious:false
    Reputation:low
    Preview:var xmlSearch_Chunk88Data = "";..xmlSearch_Chunk88Data += '<?xml version=\"1.0\" encoding=\"utf-8\"?><index> saved from url=(0016)http://localhost -->';..xmlSearch_Chunk88Data += '<stem n=\"boost\"><phr n=\"Boost\"><ent r=\"82\" t=\"130\" w=\"237\" /><ent r=\"82\" t=\"130\" w=\"237\" /></phr></stem><stem n=\"mobil\"><phr n=\"Mobile\"><ent r=\"82\" t=\"130\" w=\"238\" /><ent r=\"82\" t=\"130\" w=\"238\" /><ent r=\"82\" t=\"130\" w=\"294\" /><ent r=\"82\" t=\"130\" w=\"323\" /><ent r=\"82\" t=\"130\" w=\"323\" /><ent r=\"92\" t=\"175\" w=\"338\" /><ent r=\"92\" t=\"175\" w=\"338\" /><ent r=\"3\" t=\"175\" w=\"345\" /><ent r=\"3\" t=\"175\" w=\"345\" /><ent r=\"3\" t=\"175\" w=\"377\" /><ent r=\"3\" t=\"175\" w=\"377\" /></phr><phr n=\"mobile\"><ent r=\"3\" t=\"175\" w=\"66\" /><ent r=\"3\" t=\"175\" w=\"66\" /><ent r=\"3\" t=\"175\" w=\"356\" /><ent r=\"3\" t=\"175\" w=\"356\" /><ent r=\"3\" t=\"175\" w=\"435\" /><ent r=\"3\" t=\"175\" w=\"435\" /><ent r=\"4\" t=\"181\" w=\"131\" /><
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:exported SGML document, ASCII text, with very long lines (32691), with CRLF line terminators
    Category:dropped
    Size (bytes):32935
    Entropy (8bit):3.955054568494726
    Encrypted:false
    SSDEEP:768:hAXdTIDngmztLDM/gcu2sKzLtJre3Nf8Mq/40NfnaHI4o3kgCS5o4YAchWZ+oUaW:Dajpna
    MD5:D6E284910744FD856AB1EAA4A03F4B41
    SHA1:218C017A30142E143C3A05557A388562479FD1F2
    SHA-256:835C8D776228B597B4CDD6FB608A242F2177ED49FF6160035F31BFF36AEEC774
    SHA-512:236A989E1541548D353599379FC83CFCAE4804A79FFB2EBAC7F11903A4EBE7AB44596185FCEB5C4D41E26373341E312B38941D5C5E1962F30DF31D0C6621227C
    Malicious:false
    Reputation:low
    Preview:var xmlSearch_Chunk20Data = "";..xmlSearch_Chunk20Data += '<?xml version=\"1.0\" encoding=\"utf-8\"?><index> saved from url=(0016)http://localhost -->';..xmlSearch_Chunk20Data += '<stem n=\"if\"><phr n=\"if\"><ent r=\"4\" t=\"2\" w=\"154\" /><ent r=\"3\" t=\"2\" w=\"190\" /><ent r=\"3\" t=\"2\" w=\"210\" /><ent r=\"4\" t=\"2\" w=\"493\" /><ent r=\"3\" t=\"2\" w=\"584\" /><ent r=\"3\" t=\"2\" w=\"594\" /><ent r=\"3\" t=\"2\" w=\"690\" /><ent r=\"3\" t=\"3\" w=\"772\" /><ent r=\"3\" t=\"4\" w=\"71\" /><ent r=\"3\" t=\"4\" w=\"235\" /><ent r=\"3\" t=\"4\" w=\"289\" /><ent r=\"3\" t=\"4\" w=\"553\" /><ent r=\"3\" t=\"4\" w=\"667\" /><ent r=\"4\" t=\"5\" w=\"113\" /><ent r=\"4\" t=\"5\" w=\"125\" /><ent r=\"4\" t=\"5\" w=\"131\" /><ent r=\"4\" t=\"5\" w=\"183\" /><ent r=\"3\" t=\"5\" w=\"463\" /><ent r=\"4\" t=\"7\" w=\"158\" /><ent r=\"4\" t=\"7\" w=\"378\" /><ent r=\"3\" t=\"7\" w=\"421\" /><ent r=\"4\" t=\"7\" w=\"558\" /><ent r=\"3\" t=\"7\" w=\"637\" /><ent r=\"3\" t=\"7\" w=\"772\
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text, with very long lines (27234), with CRLF line terminators
    Category:dropped
    Size (bytes):27327
    Entropy (8bit):4.204549632330146
    Encrypted:false
    SSDEEP:768:GIDFPjGJ8ydGIAPs6yMKu8MriXzG7VB7b+W3cacXBi4ZqRRYpuQoeQVJRUFw3T3L:ccLKtspQlZfHoeDSKuUcWHeFSjsG64eZ
    MD5:D534537F3501A68D6BB8E7BBDD064610
    SHA1:87625E9466C33F180D18057D6C6BE6196CAF1712
    SHA-256:3D2EDA4D9BF23DCB05CE2E07C894B686AB357A7712E4DEAFC7250AEC34242497
    SHA-512:D6E7FA1E399E4D7660DFC463A2203E68166BA0FA0763B7138484CE22524643B2A52BF2BA7D352D0D7503D55401E8364C225072A2629D0C48568E48D68E09A179
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="utf-8"?><index> saved from url=(0016)http://localhost -->..<stem n="although"><phr n="although"><ent r="4" t="12" w="339" /><ent r="4" t="12" w="550" /><ent r="4" t="13" w="482" /><ent r="4" t="16" w="373" /><ent r="3" t="22" w="87" /><ent r="4" t="23" w="344" /><ent r="3" t="39" w="13" /><ent r="3" t="86" w="164" /><ent r="4" t="89" w="396" /><ent r="4" t="147" w="412" /></phr></stem><stem n="physic"><phr n="physically"><ent r="4" t="12" w="360" /><ent r="4" t="13" w="503" /></phr><phr n="physical"><ent r="4" t="17" w="261" /><ent r="4" t="86" w="551" /><ent r="4" t="89" w="88" /></phr></stem><stem n="jack"><phr n="jack"><ent r="4" t="12" w="400" /></phr></stem><stem n="possibl"><phr n="possible"><ent r="4" t="12" w="553" /><ent r="4" t="13" w="810" /><ent r="4" t="16" w="973" /><ent r="4" t="17" w="1042" /><ent r="4" t="23" w="347" /><ent r="3" t="25" w="89" /><ent r="3" t="25" w="122" /><ent r="4" t="31" w="597" /><ent r="4" t="37" w="560" /><ent r=
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:exported SGML document, ASCII text, with very long lines (33454), with CRLF line terminators
    Category:dropped
    Size (bytes):33698
    Entropy (8bit):3.973329836698748
    Encrypted:false
    SSDEEP:768:XUXFCZ1YaXvajWo+xMyhS8exD80JGTQwVExyGaf6Z0SsOT12P2pyorxsTRL0BGg2:mJEsaI8Rh
    MD5:D03FEBC4596DBF09D894A56765F1D021
    SHA1:E3479222CBB50F03F35BE7CB402C3AAB4C936BE3
    SHA-256:BAB33233273663EECE509762E941906DA89B39484165DA8629A925DCD120E683
    SHA-512:AB0A51B78D15336DA487AB01887E6055239A06F73868B987D136EBEF5574D647D0B1B54B7B8CD0022F04A947EF45A5023990CD3585BB9FDC0F28FD539A09C0B7
    Malicious:false
    Reputation:low
    Preview:var xmlSearch_Chunk16Data = "";..xmlSearch_Chunk16Data += '<?xml version=\"1.0\" encoding=\"utf-8\"?><index> saved from url=(0016)http://localhost -->';..xmlSearch_Chunk16Data += '<stem n=\"font\"><phr n=\"font\"><ent r=\"8\" t=\"1\" w=\"150\" /><ent r=\"4\" t=\"49\" w=\"233\" /><ent r=\"4\" t=\"53\" w=\"84\" /><ent r=\"5\" t=\"55\" w=\"324\" /><ent r=\"5\" t=\"55\" w=\"327\" /><ent r=\"5\" t=\"55\" w=\"333\" /><ent r=\"5\" t=\"55\" w=\"337\" /><ent r=\"3\" t=\"116\" w=\"462\" /><ent r=\"3\" t=\"154\" w=\"152\" /><ent r=\"3\" t=\"154\" w=\"179\" /><ent r=\"3\" t=\"154\" w=\"188\" /></phr><phr n=\"fonts\"><ent r=\"4\" t=\"150\" w=\"88\" /><ent r=\"3\" t=\"154\" w=\"13\" /><ent r=\"1048578\" t=\"154\" w=\"143\" /><ent r=\"3\" t=\"154\" w=\"147\" /></phr></stem><stem n=\"type\"><phr n=\"type\"><ent r=\"4\" t=\"1\" w=\"151\" /><ent r=\"3\" t=\"2\" w=\"369\" /><ent r=\"4\" t=\"2\" w=\"655\" /><ent r=\"4\" t=\"3\" w=\"646\" /><ent r=\"3\" t=\"4\" w=\"172\" /><ent r=\"3\" t=\"5\" w=\"105\
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:ASCII text, with very long lines (17502), with no line terminators
    Category:dropped
    Size (bytes):17502
    Entropy (8bit):5.261685888138302
    Encrypted:false
    SSDEEP:384:GSNP5WZdtTgvZa88+y2MHO5DGrHmsGEypjkvw:GAoZdtMny2MHO5DGDmsGEypjP
    MD5:41BE27A32A211468E284216BC833C69D
    SHA1:917B8E9918A5EBB65410DCC81CFF0F9A5EB289F4
    SHA-256:45BE6FC91A1CCBAA805863D0F5C9DEBAA8F185E40006F8C04C8CE2BB743CB030
    SHA-512:754AEA04C535931BCABC0C762E82458C768A8DE2A733AD98A369C94E60CA98FC852966081CAFC171699FD1F582B1DF804D1B838F30875D21D95C2E264953E522
    Malicious:false
    Reputation:low
    Preview:define({'/Content/HOBOware/Alarm \u0026 Readout Tool/art-intro.htm':{i:[170],t:['Alarm \u0026 Readout Tool'],b:['']},'/Content/HOBOware/CSH/csh-CO2.htm':{i:[30],t:['Carbon Dioxide Sensor Settings'],b:['']},'/Content/HOBOware/CSH/csh-add-nw-map.htm':{i:[134],t:['Adding a Device to the Network Map'],b:['']},'/Content/HOBOware/CSH/csh-add-sens-alrm.htm':{i:[125],t:['Adding a Sensor Alarm'],b:['']},'/Content/HOBOware/CSH/csh-advanced-calibration.htm':{i:[25],t:['Advanced Sensor Properties: Calibration'],b:['']},'/Content/HOBOware/CSH/csh-advanced-occupancy.htm':{i:[26],t:['Advanced Sensor Properties: Occupancy'],b:['']},'/Content/HOBOware/CSH/csh-alarms.htm':{i:[23],t:['Configure Alarms'],b:['']},'/Content/HOBOware/CSH/csh-burst.htm':{i:[29],t:['Burst Logging'],b:['']},'/Content/HOBOware/CSH/csh-convert-units.htm':{i:[62],t:['Converting Units'],b:['']},'/Content/HOBOware/CSH/csh-crop.htm':{i:[58],t:['Cropping a Series'],b:['']},'/Content/HOBOware/CSH/csh-dif-filters-stats.htm':{i:[28],t:['
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:ASCII text, with very long lines (2167), with no line terminators
    Category:dropped
    Size (bytes):2167
    Entropy (8bit):3.938615261022936
    Encrypted:false
    SSDEEP:24:VJjPDE2hlQdkOCsXI8QpTOsJmfiN3FqYJcUfR62fb/Vfd8ieTbD0UIdrYvGinL3z:VJzDRlQ7fzadvxB9W/VIG7urg
    MD5:C4C04038F05C7352BFBB4E9B9D2BA656
    SHA1:74C067D1D383B3B2B69ECF2A135EAA41DF4A5877
    SHA-256:D011AFBF0722D2697AC62C81C52838FCC741099F642C5390B0B654BE9ED19776
    SHA-512:0180B6AC9FF7388A8197DE045C3C35F67940E0B7CB683FDDFC80F2DA96C09584444EC779DF3CE82074188972F8E76F80EA6B9CDCBA2B8DD578C89CF7FECF7B2A
    Malicious:false
    Reputation:low
    Preview:define({numchunks:1,prefix:'Toc_Chunk',chunkstart:['/Content/HOBOware/Alarm \u0026 Readout Tool/art-intro.htm'],tree:{n:[{i:0,c:0},{i:1,c:0,n:[{i:2,c:0},{i:3,c:0},{i:4,c:0}]},{i:5,c:0,n:[{i:6,c:0},{i:7,c:0,n:[{i:8,c:0},{i:9,c:0},{i:10,c:0},{i:11,c:0},{i:12,c:0},{i:13,c:0},{i:14,c:0},{i:15,c:0},{i:16,c:0},{i:17,c:0},{i:18,c:0},{i:19,c:0}]},{i:20,c:0,n:[{i:21,c:0},{i:22,c:0},{i:23,c:0},{i:24,c:0},{i:25,c:0},{i:26,c:0},{i:27,c:0},{i:28,c:0},{i:29,c:0},{i:30,c:0}]},{i:31,c:0,n:[{i:32,c:0}]},{i:33,c:0}]},{i:34,c:0,n:[{i:35,c:0},{i:36,c:0,n:[{i:37,c:0},{i:38,c:0},{i:39,c:0},{i:40,c:0},{i:41,c:0},{i:42,c:0},{i:43,c:0},{i:44,c:0},{i:45,c:0},{i:46,c:0}]},{i:47,c:0,n:[{i:48,c:0,n:[{i:49,c:0},{i:50,c:0},{i:51,c:0},{i:52,c:0},{i:53,c:0}]},{i:54,c:0},{i:55,c:0},{i:56,c:0},{i:57,c:0},{i:58,c:0},{i:59,c:0},{i:60,c:0},{i:61,c:0},{i:62,c:0},{i:63,c:0},{i:64,c:0}]},{i:65,c:0,n:[{i:66,c:0},{i:67,c:0},{i:68,c:0},{i:69,c:0},{i:70,c:0},{i:71,c:0},{i:72,c:0},{i:73,c:0}]},{i:74,c:0,n:[{i:75,c:0},{i:76,c:0},{i
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text, with very long lines (27366), with CRLF line terminators
    Category:dropped
    Size (bytes):27459
    Entropy (8bit):4.086665693261268
    Encrypted:false
    SSDEEP:768:2qmmIflGCgWtMgUMqqUsG/3A2uJ2Qtad4r+FwJ7BTpE2SsDjO8QWG+HMLPmLnd7O:FXS0vr6v+/OUqYggDzOvB1dif
    MD5:90494043C1D61FA8475EC00CB3B084FF
    SHA1:C5BB4B2CD0E9518DE029D017728C8100F9706C17
    SHA-256:791DFD3FDE0B15F15761FA5AE6ABF963E7BAFF671C1740A4B4C0B5C9B9949090
    SHA-512:0368D6460C7F615EF678E4B63F90ED7D39A2CE07E433FB47D89331B08DCC5842656C3BA2C302B67654FFF7E4719EFC372C30E7F3037FB21E891142EEA4F834A7
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="utf-8"?><index> saved from url=(0016)http://localhost -->..<stem n="guid"><phr n="guide"><ent r="5" t="0" w="64" /><ent r="5" t="0" w="68" /><ent r="4" t="7" w="138" /><ent r="3" t="7" w="308" /><ent r="4" t="15" w="72" /><ent r="4" t="81" w="353" /><ent r="3" t="94" w="93" /><ent r="4" t="98" w="327" /><ent r="4" t="103" w="54" /><ent r="4" t="103" w="81" /><ent r="3" t="113" w="259" /></phr><phr n="guides"><ent r="4" t="3" w="108" /><ent r="4" t="3" w="812" /><ent r="4" t="3" w="973" /></phr></stem><stem n="user'"><phr n="user's"><ent r="5" t="0" w="67" /><ent r="4" t="15" w="71" /></phr></stem><stem n="version"><phr n="version"><ent r="4" t="0" w="72" /><ent r="3" t="2" w="196" /><ent r="3" t="3" w="760" /><ent r="3" t="3" w="779" /><ent r="4" t="5" w="136" /><ent r="3" t="5" w="568" /><ent r="3" t="5" w="577" /><ent r="5" t="5" w="638" /><ent r="5" t="5" w="659" /><ent r="5" t="5" w="710" /><ent r="4" t="40" w="263" /><ent r="4" t="81" w="35" /><en
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text, with very long lines (31432), with CRLF line terminators
    Category:dropped
    Size (bytes):31525
    Entropy (8bit):3.980133887314395
    Encrypted:false
    SSDEEP:768:lBLI9LdF2fhgGzNPKkH9ralwY+dcjUHrShqi1ZOtCOIfSa20WzVTnfMSL7H20fUl:Y58EStm8wEL39T8YNwTtk8
    MD5:D5804EBB1AA1AAF97D77E2602BCF9B89
    SHA1:BAFC04B9F982F8EB897C6DBB0C6C5AE2BF8D9526
    SHA-256:A32327BDB0D1310613E25354A4D3BFD6580CF19F6AC03162B5F092A7CACC502C
    SHA-512:48F668474E23600806CD076AF92D4D3E2E8BB5AC8CFD3C2630F7A5E51B9741B8896F17817B21B367C34F2CC03139B8F7C529B808DFA3E3A10FDC4C82E7CE5F05
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="utf-8"?><index> saved from url=(0016)http://localhost -->..<stem n="period"><phr n="periodically"><ent r="3" t="2" w="592" /><ent r="3" t="66" w="661" /><ent r="3" t="124" w="55" /><ent r="3" t="125" w="79" /><ent r="3" t="126" w="91" /><ent r="3" t="143" w="16" /><ent r="3" t="171" w="600" /></phr><phr n="period"><ent r="4" t="14" w="608" /><ent r="4" t="24" w="590" /><ent r="4" t="25" w="271" /><ent r="3" t="27" w="35" /><ent r="3" t="28" w="209" /><ent r="4" t="31" w="335" /><ent r="4" t="31" w="364" /><ent r="3" t="31" w="418" /><ent r="4" t="31" w="651" /><ent r="4" t="58" w="38" /><ent r="4" t="61" w="338" /><ent r="4" t="61" w="372" /><ent r="4" t="61" w="386" /><ent r="3" t="68" w="542" /><ent r="5" t="69" w="464" /><ent r="3" t="73" w="73" /><ent r="3" t="74" w="563" /><ent r="3" t="90" w="399" /><ent r="3" t="99" w="48" /><ent r="3" t="128" w="34" /><ent r="4" t="128" w="210" /><ent r="3" t="140" w="27" /><ent r="3" t="187" w="214" /><ent r="
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text, with very long lines (29295), with CRLF line terminators
    Category:dropped
    Size (bytes):29388
    Entropy (8bit):3.9753145651106867
    Encrypted:false
    SSDEEP:768:JCAKAqjoSnfRwkkYa/zZ9uUjXvprfLHITiWckCu6/z+wBjIurxKc9yBTMLTb5SdZ:0gB9ch9WLBMitEsu7vT
    MD5:CC41674E8B82B16C93A30B01417CB251
    SHA1:181F53023A6C12A192F68BBC187CB5D6151EF707
    SHA-256:D0373CD26D51D418FAB2FA52D367D1D3210442B852FE1BB884C46A0310AAA488
    SHA-512:BC5AF389441E19818A852F222973FC4EA8AD556EBDA2448A43D750F4A4464C31AFECDE33FCF98061608D62C94642132F06B536A831CB6695569626B3E83709AF
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="utf-8"?><index> saved from url=(0016)http://localhost -->..<stem n="set"><phr n="setting"><ent r="4" t="1" w="233" /><ent r="4" t="3" w="620" /><ent r="4" t="3" w="1438" /><ent r="4" t="10" w="543" /><ent r="4" t="10" w="549" /><ent r="4" t="10" w="910" /><ent r="4" t="11" w="743" /><ent r="6" t="11" w="1077" /><ent r="4" t="12" w="350" /><ent r="4" t="12" w="869" /><ent r="6" t="12" w="1154" /><ent r="4" t="13" w="493" /><ent r="4" t="13" w="825" /><ent r="4" t="14" w="879" /><ent r="6" t="14" w="1179" /><ent r="4" t="15" w="827" /><ent r="4" t="16" w="383" /><ent r="4" t="16" w="1048" /><ent r="3" t="17" w="379" /><ent r="4" t="17" w="1078" /><ent r="268435456" t="20" w="1" /><ent r="16777218" t="20" w="11" /><ent r="3" t="20" w="40" /><ent r="4" t="20" w="185" /><ent r="3" t="21" w="20" /><ent r="3" t="21" w="28" /><ent r="4" t="23" w="290" /><ent r="4" t="24" w="42" /><ent r="4" t="24" w="813" /><ent r="3" t="25" w="60" /><ent r="4" t="29" w="729"
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:exported SGML document, ASCII text, with very long lines (34163), with CRLF line terminators
    Category:dropped
    Size (bytes):34407
    Entropy (8bit):3.9700174950728973
    Encrypted:false
    SSDEEP:768:b3MeIEzuvBvCDRYctOmuU6C7Mjif/3bgF6q7ZGEQufWSMOlzl+kEHz26yswM0ewW:u1MTrzzRNDRVEPcRu2GaX
    MD5:59B637AE730A38905650ACB61D81D189
    SHA1:5D9BAA12C22CDACA0A47F7171B2523C261CAD4A9
    SHA-256:553B0F0EA8F4F80483E47E7E01B5C76330AF6DA66AE5604EC184512C4C3A59C3
    SHA-512:C0B50136985F8F3C7C14E3468F6647578CF7DF02B80DA03DFF788957D7554DCB9B219B943CE90B4031638C67268ABFBCE604E5CC36EEA4518D283E06183BFA17
    Malicious:false
    Reputation:low
    Preview:var xmlSearch_Chunk26Data = "";..xmlSearch_Chunk26Data += '<?xml version=\"1.0\" encoding=\"utf-8\"?><index> saved from url=(0016)http://localhost -->';..xmlSearch_Chunk26Data += '<stem n=\"port\"><phr n=\"ports\"><ent r=\"3\" t=\"2\" w=\"440\" /><ent r=\"4\" t=\"7\" w=\"483\" /><ent r=\"3\" t=\"7\" w=\"645\" /><ent r=\"4\" t=\"7\" w=\"842\" /><ent r=\"4\" t=\"7\" w=\"866\" /><ent r=\"3\" t=\"17\" w=\"358\" /><ent r=\"5\" t=\"84\" w=\"34\" /><ent r=\"5\" t=\"86\" w=\"439\" /><ent r=\"268435456\" t=\"89\" w=\"6\" /><ent r=\"16777218\" t=\"89\" w=\"13\" /><ent r=\"6\" t=\"89\" w=\"48\" /><ent r=\"6\" t=\"89\" w=\"67\" /><ent r=\"4\" t=\"89\" w=\"74\" /><ent r=\"4\" t=\"89\" w=\"145\" /><ent r=\"4\" t=\"89\" w=\"163\" /><ent r=\"3\" t=\"90\" w=\"22\" /><ent r=\"5\" t=\"90\" w=\"357\" /><ent r=\"4\" t=\"91\" w=\"58\" /><ent r=\"4\" t=\"92\" w=\"86\" /><ent r=\"3\" t=\"108\" w=\"43\" /><ent r=\"3\" t=\"108\" w=\"177\" /><ent r=\"4\" t=\"121\" w=\"469\" /><ent r=\"4\" t=\"121\" w=\"477\"
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:exported SGML document, ASCII text, with very long lines (32159), with CRLF line terminators
    Category:dropped
    Size (bytes):32403
    Entropy (8bit):4.2546898300490295
    Encrypted:false
    SSDEEP:768:2/sXVeCDDRRaa88BB+NmeL30Tr6bm28NNxq42sK11MMQQuurrhhinnxoxo888iZA:Vb/I
    MD5:D61C444621B4B129DFC997101CE61884
    SHA1:2924A35DD8277417B976BE921609D7084DD7040A
    SHA-256:0DBDCB7C4756BA93BEC7E7D738ED6EA62D05EF47510EFD2F8770C7CD3CE724C6
    SHA-512:9300C99B88D3612ADAE78039B4AB257258EFFDAC71FA400C12CFA19F4319ED84E093D8B86292956B5A509F32CA9D0F065123631521BB7289363E77C96E13778B
    Malicious:false
    Reputation:low
    Preview:var xmlSearch_Chunk87Data = "";..xmlSearch_Chunk87Data += '<?xml version=\"1.0\" encoding=\"utf-8\"?><index> saved from url=(0016)http://localhost -->';..xmlSearch_Chunk87Data += '<stem n=\"cw\"><phr n=\"CW\"><ent r=\"7\" t=\"110\" w=\"302\" /><ent r=\"7\" t=\"110\" w=\"302\" /><ent r=\"7\" t=\"110\" w=\"316\" /><ent r=\"7\" t=\"110\" w=\"316\" /></phr></stem><stem n=\"doc\"><phr n=\"docs\"><ent r=\"64\" t=\"110\" w=\"339\" /></phr></stem><stem n=\"0-20ma\"><phr n=\"0-20mA\"><ent r=\"92\" t=\"110\" w=\"347\" /><ent r=\"92\" t=\"110\" w=\"347\" /></phr></stem><stem n=\"0-100ma\"><phr n=\"0-100mA\"><ent r=\"92\" t=\"110\" w=\"350\" /><ent r=\"92\" t=\"110\" w=\"350\" /></phr></stem><stem n=\"100ma\"><phr n=\"100mA\"><ent r=\"92\" t=\"110\" w=\"351\" /></phr></stem><stem n=\"0-200ma\"><phr n=\"0-200mA\"><ent r=\"92\" t=\"110\" w=\"353\" /><ent r=\"92\" t=\"110\" w=\"353\" /></phr></stem><stem n=\"200ma\"><phr n=\"200mA\"><ent r=\"92\" t=\"110\" w=\"354\" /></phr></stem><stem n=\"wc\">
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text, with very long lines (27207), with CRLF line terminators
    Category:dropped
    Size (bytes):27300
    Entropy (8bit):4.150441860607726
    Encrypted:false
    SSDEEP:768:Gdpp2Q9q7JJJJyyyyQQvSrCHTHH2ZM1M33TTMMPquH8A3D1Y0gbOhZ/2nSb2CCe7:SIBJSaY//EIUeAuZUulltpzD
    MD5:312C74DCDA6643E0FD6F17DFAE48B269
    SHA1:DD59456B3CFCBD01BAA5670DCC01E9E7FCDAE07A
    SHA-256:3C554E66C8C8D03164090BC9F671C7F10817B5FCD688AABB23C922CB40F855F9
    SHA-512:3D0FBB1CED39BA113C55D5225E8CEDCBF011055F80CBEE25E20C93FEEE93D138E7A0A7ECAEA24F32F66B6572E54106291C9DC5309E928411B7889AACD5AB3376
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="utf-8"?><index> saved from url=(0016)http://localhost -->..<stem n="chan"><phr n="Chan"><ent r="3" t="23" w="1166" /><ent r="3" t="23" w="1166" /><ent r="3" t="23" w="1171" /><ent r="3" t="23" w="1171" /><ent r="3" t="23" w="1185" /><ent r="3" t="23" w="1185" /></phr></stem><stem n="furthest"><phr n="furthest"><ent r="3" t="23" w="1195" /><ent r="3" t="23" w="1195" /></phr></stem><stem n="prevent"><phr n="prevents"><ent r="3" t="24" w="48" /><ent r="3" t="24" w="48" /></phr><phr n="prevent"><ent r="3" t="25" w="259" /><ent r="3" t="25" w="259" /><ent r="4" t="25" w="436" /><ent r="4" t="25" w="436" /><ent r="3" t="40" w="162" /><ent r="3" t="40" w="162" /><ent r="3" t="58" w="119" /><ent r="3" t="58" w="119" /><ent r="3" t="64" w="608" /><ent r="3" t="64" w="608" /><ent r="3" t="78" w="81" /><ent r="3" t="78" w="81" /><ent r="3" t="154" w="38" /><ent r="3" t="154" w="38" /></phr><phr n="preventing"><ent r="5" t="101" w="455" /><ent r="5" t="101" w="455
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:exported SGML document, ASCII text, with very long lines (32195), with CRLF line terminators
    Category:dropped
    Size (bytes):32435
    Entropy (8bit):3.9815268791975216
    Encrypted:false
    SSDEEP:768:K9s1mM3wF+AvNSaQjHy+fjufD+qoJjPjpi5j2CthAoL/ANHpf3p3B5vrVUlvnRvB:P76+7e0E3t82vEOOoPqhtRRmnt
    MD5:1D3A0FC5C25E1D973C06865776ACAA4C
    SHA1:A5D2B3F820484E409B56D8D9616FBC3D50257380
    SHA-256:7158B2B1C4E8556A28271E40E7C538AE2BB546F565C91AEFEA13D68DE5616A95
    SHA-512:2F5706089484CAA42B3F5E933CC900E0051FB24006F44E9DBB50656980A8673537E812CA0ED87C1B833921812B2281998D19473634B298EF63F05C01363F8A73
    Malicious:false
    Reputation:low
    Preview:var xmlSearch_Chunk1Data = "";..xmlSearch_Chunk1Data += '<?xml version=\"1.0\" encoding=\"utf-8\"?><index> saved from url=(0016)http://localhost -->';..xmlSearch_Chunk1Data += '<stem n=\"welcom\"><phr n=\"welcome\"><ent r=\"268435456\" t=\"0\" w=\"1\" /></phr></stem><stem n=\"hobowar\"><phr n=\"hoboware\"><ent r=\"3\" t=\"0\" w=\"3\" /><ent r=\"5\" t=\"0\" w=\"18\" /><ent r=\"5\" t=\"0\" w=\"24\" /><ent r=\"5\" t=\"0\" w=\"61\" /><ent r=\"5\" t=\"0\" w=\"66\" /><ent r=\"4\" t=\"0\" w=\"168\" /><ent r=\"268435456\" t=\"1\" w=\"4\" /><ent r=\"16777218\" t=\"1\" w=\"9\" /><ent r=\"3\" t=\"1\" w=\"11\" /><ent r=\"3\" t=\"1\" w=\"30\" /><ent r=\"3\" t=\"1\" w=\"65\" /><ent r=\"3\" t=\"1\" w=\"66\" /><ent r=\"3\" t=\"1\" w=\"68\" /><ent r=\"3\" t=\"1\" w=\"70\" /><ent r=\"3\" t=\"1\" w=\"186\" /><ent r=\"3\" t=\"1\" w=\"188\" /><ent r=\"3\" t=\"1\" w=\"204\" /><ent r=\"3\" t=\"1\" w=\"217\" /><ent r=\"3\" t=\"1\" w=\"241\" /><ent r=\"3\" t=\"1\" w=\"252\" /><ent r=\"3\" t=\"1\" w=\"280\"
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:exported SGML document, ASCII text, with very long lines (50667), with CRLF line terminators
    Category:dropped
    Size (bytes):50907
    Entropy (8bit):3.9136091682260967
    Encrypted:false
    SSDEEP:768:S3ZYyNBCojtEtgwoICkOBhrt54iOsGvF/dpT/VKPD7HYodDE0OoAXL+7G1rx2oi1:Uju2XSsgGVpf
    MD5:D07C8DCE2F6BEA2500EF6B643395F968
    SHA1:DBE0B82B6E26ADCAB891382629315F7FE36DFFE4
    SHA-256:7B2CEA62B78BD059DBED8BAD28AFE189E52E76934D64C64E88C54F3AF34C7BF4
    SHA-512:8707A694AF73C277C6476BD7BC79A82BA576430561004854E981DC64C2BFE37EA72F4F72D85FE1B90916104B080BFDDAD8BA50F0BB0120F030F1E4715CB6D201
    Malicious:false
    Reputation:low
    Preview:var xmlSearch_Chunk3Data = "";..xmlSearch_Chunk3Data += '<?xml version=\"1.0\" encoding=\"utf-8\"?><index> saved from url=(0016)http://localhost -->';..xmlSearch_Chunk3Data += '<stem n=\"logger\"><phr n=\"loggers\"><ent r=\"5\" t=\"0\" w=\"31\" /><ent r=\"3\" t=\"0\" w=\"111\" /><ent r=\"3\" t=\"1\" w=\"28\" /><ent r=\"4\" t=\"1\" w=\"86\" /><ent r=\"4\" t=\"1\" w=\"145\" /><ent r=\"3\" t=\"1\" w=\"255\" /><ent r=\"3\" t=\"1\" w=\"264\" /><ent r=\"5\" t=\"1\" w=\"298\" /><ent r=\"4\" t=\"3\" w=\"394\" /><ent r=\"5\" t=\"3\" w=\"482\" /><ent r=\"4\" t=\"3\" w=\"522\" /><ent r=\"4\" t=\"3\" w=\"556\" /><ent r=\"4\" t=\"3\" w=\"580\" /><ent r=\"4\" t=\"3\" w=\"642\" /><ent r=\"4\" t=\"3\" w=\"992\" /><ent r=\"4\" t=\"3\" w=\"1168\" /><ent r=\"4\" t=\"3\" w=\"1515\" /><ent r=\"3\" t=\"3\" w=\"1527\" /><ent r=\"3\" t=\"5\" w=\"100\" /><ent r=\"3\" t=\"5\" w=\"106\" /><ent r=\"4\" t=\"5\" w=\"717\" /><ent r=\"4\" t=\"5\" w=\"731\" /><ent r=\"4\" t=\"5\" w=\"755\" /><ent r=\"4\" t=\"5\" w
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text, with very long lines (7245), with CRLF line terminators
    Category:dropped
    Size (bytes):7338
    Entropy (8bit):4.5573029257784965
    Encrypted:false
    SSDEEP:192:Eh6WlLELBLwm3UcUk1KveE9H1UHTUOLSIyGVeX+XxCkj70Jtsw1DpHwwYuTnZmPH:Eh6W6LBLwm3fB1K3XmhVeX+XxCkjIJtA
    MD5:93EF9536193E362FA61E92556F486A35
    SHA1:8EF28C4082CBDB918809893732E3D4672F062275
    SHA-256:44A9BF33F6266ED06C7F7FCE8FB0CCEA277F50736BCABFEABB757E8341DFA51E
    SHA-512:7CBF7E95ABEB91E67DF3E94A88AE10B77A444F30277426F0DFCD718AC09AEAD674E11F514CF14C134D57BF6DEF0E4794EC0F26B6EB085712D7C2CE63D900C7F0
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="utf-8"?><index> saved from url=(0016)http://localhost -->..<stem n="creation"><phr n="creation"><ent r="4" t="177" w="780" /><ent r="4" t="177" w="1037" /><ent r="4" t="177" w="1225" /></phr></stem><stem n="subj"><phr n="subj"><ent r="4" t="177" w="924" /><ent r="4" t="178" w="245" /><ent r="3" t="178" w="421" /></phr></stem><stem n="someth"><phr n="something"><ent r="3" t="177" w="1365" /></phr></stem><stem n="wrong"><phr n="wrong"><ent r="3" t="177" w="1367" /></phr></stem><stem n="environment"><phr n="environmental"><ent r="3" t="178" w="88" /></phr></stem><stem n="flare"><phr n="flares"><ent r="3" t="178" w="93" /></phr></stem><stem n="manner"><phr n="manner"><ent r="3" t="178" w="106" /></phr></stem><stem n="odd"><phr n="odds"><ent r="3" t="178" w="132" /></phr></stem><stem n="john"><phr n="john"><ent r="3" t="178" w="155" /></phr></stem><stem n="mari"><phr n="mary"><ent r="3" t="178" w="158" /></phr></stem><stem n="sm"><phr n="sms"><ent r="3" t="
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text, with very long lines (26565), with CRLF line terminators
    Category:dropped
    Size (bytes):26658
    Entropy (8bit):4.075860988446219
    Encrypted:false
    SSDEEP:768:hcVYpCnLqwooLlCBR4HPHIU1fk/XDxBo3xluQYOzirzOQq29r++go97RpFjk7F7j:+MvznyafvCOpQTzu6
    MD5:7D33F0E431AEB0225CD7612F126C48DF
    SHA1:A429ADAAD31C1E73F2E951936A1439F90EFF84C9
    SHA-256:D0EA9A55EAEF9CF82955D75B754C17F857DA0B80E95A7284C83946E2CAA90424
    SHA-512:35C503EC06D264E32F5408E661E67EFF7A286A3EED1B1C9F0892A5618347A387F2BEF3B83D5E6968BC740D0D3ABD7A566A2D771B5DEC7B4F9FCB20F7CE3C61A6
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="utf-8"?><index> saved from url=(0016)http://localhost -->..<stem n="accuraci"><phr n="accuracy"><ent r="4" t="3" w="822" /><ent r="3" t="31" w="99" /><ent r="4" t="31" w="596" /><ent r="4" t="31" w="847" /><ent r="5" t="69" w="299" /><ent r="4" t="71" w="409" /><ent r="4" t="71" w="684" /><ent r="4" t="86" w="497" /><ent r="4" t="113" w="126" /></phr></stem><stem n="u26"><phr n="u26"><ent r="4" t="3" w="840" /><ent r="5" t="16" w="980" /><ent r="4" t="16" w="995" /><ent r="5" t="16" w="1029" /><ent r="5" t="33" w="398" /><ent r="4" t="33" w="406" /><ent r="5" t="33" w="438" /><ent r="4" t="66" w="388" /><ent r="4" t="71" w="35" /><ent r="4" t="71" w="44" /><ent r="5" t="84" w="56" /><ent r="5" t="84" w="71" /><ent r="268435456" t="99" w="6" /><ent r="16777218" t="99" w="18" /><ent r="3" t="99" w="27" /><ent r="268435456" t="100" w="9" /><ent r="16777218" t="100" w="22" /><ent r="3" t="100" w="35" /><ent r="4" t="157" w="650" /><ent r="4" t="157" w="692
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:exported SGML document, ASCII text, with very long lines (34186), with CRLF line terminators
    Category:dropped
    Size (bytes):34430
    Entropy (8bit):4.093551794579148
    Encrypted:false
    SSDEEP:768:27IRw0jIp0Y2wt9QJu+07n6Oov14XerFIPN+r3sEDiMwLmTXkyBuVfeLQxP6K1WY:3XvvPNpTxuNlTyyWS+G
    MD5:D1ECED8A48FCEC11A160F5E0B0AC8E7A
    SHA1:CA1A15AB8EFABA581EDDD306C074701C75F0108E
    SHA-256:CD35D02C23596CC396C8F3CCCA8C123905A6160153199A8C2B3CCA2027F540D1
    SHA-512:DE2DD537AAEABD02F2AEA9A433F9A6D93DF5F4A1C3679B0DB3C8DFA6D9E93593D14E6BDFF912B2F4AD11D1709C8D7DD0D7BAE6835C015990585956F3EE1AC52E
    Malicious:false
    Reputation:low
    Preview:var xmlSearch_Chunk43Data = "";..xmlSearch_Chunk43Data += '<?xml version=\"1.0\" encoding=\"utf-8\"?><index> saved from url=(0016)http://localhost -->';..xmlSearch_Chunk43Data += '<stem n=\"enabl\"><phr n=\"enabled\"><ent r=\"3\" t=\"5\" w=\"54\" /><ent r=\"4\" t=\"5\" w=\"232\" /><ent r=\"3\" t=\"5\" w=\"456\" /><ent r=\"4\" t=\"11\" w=\"569\" /><ent r=\"4\" t=\"12\" w=\"718\" /><ent r=\"4\" t=\"13\" w=\"306\" /><ent r=\"4\" t=\"14\" w=\"409\" /><ent r=\"4\" t=\"14\" w=\"428\" /><ent r=\"3\" t=\"15\" w=\"138\" /><ent r=\"4\" t=\"15\" w=\"573\" /><ent r=\"4\" t=\"15\" w=\"607\" /><ent r=\"4\" t=\"15\" w=\"649\" /><ent r=\"4\" t=\"15\" w=\"701\" /><ent r=\"4\" t=\"16\" w=\"247\" /><ent r=\"4\" t=\"24\" w=\"102\" /><ent r=\"4\" t=\"24\" w=\"815\" /><ent r=\"5\" t=\"25\" w=\"375\" /><ent r=\"3\" t=\"28\" w=\"38\" /><ent r=\"3\" t=\"28\" w=\"122\" /><ent r=\"3\" t=\"28\" w=\"148\" /><ent r=\"4\" t=\"28\" w=\"478\" /><ent r=\"6\" t=\"29\" w=\"248\" /><ent r=\"6\" t=\"29\" w=\"343\" /><e
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text, with very long lines (11442), with CRLF line terminators
    Category:dropped
    Size (bytes):11535
    Entropy (8bit):4.477222196789357
    Encrypted:false
    SSDEEP:192:rrKoo66VVIIx2ymr4mMevALIALyyjjqqs3tgg7O6t2d1iiRLZ99gYdqi4LKO3BQb:/ro66VVIIx2ymr4mMevALIALyyjjqqss
    MD5:ACD7A20A563A9AC6339AB5827A158D86
    SHA1:E738947C20FE03FACED5DA72F3DF4C597B20B3F1
    SHA-256:7EE3B49FB089EBE621C6A85E5B444C50824A86633F491C371045C1D010B25CDE
    SHA-512:2C32C55B930CC1AA57B350389AA0AE8901B95CE2D2385FC922D55CCE0CFC6F61BF62EF43562486606A03B5E74E6306B86CBDD4E776F2FC4541DD46F3653D54D4
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="utf-8"?><index> saved from url=(0016)http://localhost -->..<stem n="tri"><phr n="tries"><ent r="5" t="172" w="198" /><ent r="5" t="172" w="198" /></phr></stem><stem n="poll"><phr n="polling"><ent r="3" t="173" w="175" /><ent r="3" t="173" w="175" /><ent r="3" t="173" w="199" /><ent r="3" t="173" w="199" /><ent r="3" t="179" w="145" /><ent r="3" t="179" w="145" /><ent r="3" t="180" w="49" /><ent r="3" t="180" w="49" /><ent r="4" t="181" w="424" /><ent r="4" t="181" w="424" /></phr><phr n="polls"><ent r="3" t="179" w="41" /><ent r="3" t="179" w="41" /></phr><phr n="poll"><ent r="3" t="179" w="122" /><ent r="3" t="179" w="122" /><ent r="3" t="180" w="26" /><ent r="3" t="180" w="26" /></phr></stem><stem n="unpredict"><phr n="unpredictable"><ent r="3" t="173" w="209" /><ent r="3" t="173" w="209" /><ent r="3" t="174" w="464" /><ent r="3" t="174" w="464" /></phr></stem><stem n="put"><phr n="put"><ent r="3" t="173" w="246" /><ent r="3" t="173" w="246" /><ent r
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:exported SGML document, ASCII text, with very long lines (35383), with CRLF line terminators
    Category:dropped
    Size (bytes):35627
    Entropy (8bit):3.986426780266724
    Encrypted:false
    SSDEEP:768:JI90Mq4z2APv9CyOy8f/5Vs23zrh77ze7E0OiYkQXj0qNL2QXZQeh0FzrzyPLbNK:KPFkuTKv6ct/y34UE6
    MD5:0FD2BA1763023322E1F207DCD47F25D9
    SHA1:ACC8DC49D2639D8A531FF125226A62A562B41CA9
    SHA-256:3504DC6005C6CA89D4C6FCDB022F86BB2BA11AAEF058B431347D15208CC14474
    SHA-512:9F9E925C2D9DC3A79B12046D4C66A22972A2ED1F0CD86F0A60DD01BA6B0B3BBCF0A1B497B195538E53CBCB4A187C27D4F591204AB5CBA76CA08169DA02F9E78B
    Malicious:false
    Reputation:low
    Preview:var xmlSearch_Chunk18Data = "";..xmlSearch_Chunk18Data += '<?xml version=\"1.0\" encoding=\"utf-8\"?><index> saved from url=(0016)http://localhost -->';..xmlSearch_Chunk18Data += '<stem n=\"set\"><phr n=\"setting\"><ent r=\"4\" t=\"1\" w=\"233\" /><ent r=\"4\" t=\"3\" w=\"620\" /><ent r=\"4\" t=\"3\" w=\"1438\" /><ent r=\"4\" t=\"10\" w=\"543\" /><ent r=\"4\" t=\"10\" w=\"549\" /><ent r=\"4\" t=\"10\" w=\"910\" /><ent r=\"4\" t=\"11\" w=\"743\" /><ent r=\"6\" t=\"11\" w=\"1077\" /><ent r=\"4\" t=\"12\" w=\"350\" /><ent r=\"4\" t=\"12\" w=\"869\" /><ent r=\"6\" t=\"12\" w=\"1154\" /><ent r=\"4\" t=\"13\" w=\"493\" /><ent r=\"4\" t=\"13\" w=\"825\" /><ent r=\"4\" t=\"14\" w=\"879\" /><ent r=\"6\" t=\"14\" w=\"1179\" /><ent r=\"4\" t=\"15\" w=\"827\" /><ent r=\"4\" t=\"16\" w=\"383\" /><ent r=\"4\" t=\"16\" w=\"1048\" /><ent r=\"3\" t=\"17\" w=\"379\" /><ent r=\"4\" t=\"17\" w=\"1078\" /><ent r=\"268435456\" t=\"20\" w=\"1\" /><ent r=\"16777218\" t=\"20\" w=\"11\" /><ent r=\"3\" t=\"2
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:exported SGML document, ASCII text, with very long lines (32031), with CRLF line terminators
    Category:dropped
    Size (bytes):32275
    Entropy (8bit):4.253118769021213
    Encrypted:false
    SSDEEP:768:afd/FCKvftosZ2VxYwinBZI03XTH4DKE0QpwjVbvyDE5e3ex0tLp9DimS90Yf32I:O+6nyAJ+lr8oYlSMmc+aX
    MD5:D2090375F2FEB6F5DA75DA55C1B42B84
    SHA1:549AB198B80C6D7FA8CFAF28C29A85C8D97FB295
    SHA-256:EDB41425D03B6204E8F8BF2C434EA4F2331E0A9659C4A57D6705BC287B014257
    SHA-512:111473077F9A8C5D04C9D204EE6D8C812AC86061149A22FD849C65E2B194EEE033EF4D3BD17B2D73A0C854FB1E07C8F5873909085A577AA5FF87EEB6AA8E6A83
    Malicious:false
    Reputation:low
    Preview:var xmlSearch_Chunk52Data = "";..xmlSearch_Chunk52Data += '<?xml version=\"1.0\" encoding=\"utf-8\"?><index> saved from url=(0016)http://localhost -->';..xmlSearch_Chunk52Data += '<stem n=\"blue\"><phr n=\"blue\"><ent r=\"4\" t=\"24\" w=\"282\" /><ent r=\"3\" t=\"24\" w=\"980\" /><ent r=\"4\" t=\"30\" w=\"650\" /><ent r=\"4\" t=\"51\" w=\"440\" /><ent r=\"6\" t=\"116\" w=\"686\" /><ent r=\"5\" t=\"183\" w=\"437\" /><ent r=\"3\" t=\"184\" w=\"513\" /></phr></stem><stem n=\"actual\"><phr n=\"actual\"><ent r=\"3\" t=\"24\" w=\"304\" /><ent r=\"3\" t=\"24\" w=\"1055\" /><ent r=\"3\" t=\"28\" w=\"159\" /><ent r=\"4\" t=\"30\" w=\"228\" /><ent r=\"4\" t=\"42\" w=\"304\" /><ent r=\"4\" t=\"42\" w=\"345\" /><ent r=\"4\" t=\"70\" w=\"293\" /><ent r=\"3\" t=\"70\" w=\"686\" /><ent r=\"4\" t=\"70\" w=\"742\" /><ent r=\"6\" t=\"73\" w=\"531\" /><ent r=\"6\" t=\"73\" w=\"566\" /><ent r=\"6\" t=\"73\" w=\"616\" /><ent r=\"5\" t=\"73\" w=\"656\" /><ent r=\"4\" t=\"96\" w=\"636\" /></phr></stem><s
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text, with very long lines (29388), with CRLF line terminators
    Category:dropped
    Size (bytes):29481
    Entropy (8bit):3.911969545530266
    Encrypted:false
    SSDEEP:768:r/iJTB17FuVU5R5rneekU0j+tWjZMELTe6fv1KmB0EyqVPY9dKNodb0eyxif3oGv:cGL1RaQaH7YoXCoEyA9uG5EsO30w
    MD5:174E500B6367520E113E608D8B8D8641
    SHA1:07EE5409A161D5114D0E5DFCA571980DB1F06818
    SHA-256:89336C9166CC99121D9A4370A164CA35D651C79986C2607DE9846D412FB8E046
    SHA-512:A14AFB0B39C649975A755BFC0E3613643C66F685D8A99233B34F806472B4C83B5B27E5F584A5A72A8910B6262E77F27A5C616E5C2C5C77552001F63D59811455
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="utf-8"?><index> saved from url=(0016)http://localhost -->..<stem n="setup"><phr n="setup"><ent r="3" t="2" w="206" /><ent r="1048578" t="2" w="414" /><ent r="3" t="2" w="419" /><ent r="3" t="2" w="450" /><ent r="3" t="2" w="474" /><ent r="3" t="2" w="546" /><ent r="3" t="2" w="568" /><ent r="4" t="3" w="1057" /><ent r="4" t="3" w="1345" /><ent r="3" t="4" w="624" /><ent r="3" t="4" w="643" /><ent r="4" t="6" w="34" /><ent r="4" t="10" w="630" /><ent r="5" t="17" w="630" /><ent r="3" t="22" w="16" /><ent r="4" t="22" w="334" /><ent r="3" t="23" w="240" /><ent r="5" t="30" w="487" /><ent r="3" t="37" w="28" /><ent r="4" t="37" w="526" /><ent r="4" t="37" w="553" /><ent r="4" t="37" w="579" /><ent r="4" t="37" w="585" /><ent r="4" t="37" w="616" /><ent r="4" t="37" w="705" /><ent r="4" t="38" w="163" /><ent r="4" t="46" w="156" /><ent r="5" t="46" w="405" /><ent r="4" t="47" w="48" /><ent r="4" t="53" w="63" /><ent r="3" t="66" w="76" /><ent r="4" t="66"
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:exported SGML document, ASCII text, with very long lines (36109), with CRLF line terminators
    Category:dropped
    Size (bytes):36353
    Entropy (8bit):3.9711496040262264
    Encrypted:false
    SSDEEP:768:6PlRL77OI4NcrBvxe0flnYR4RLYVCYTtlrQTM+eSSybfRpwywkIjoB/+LXvwDjeC:s2CtYlNVhJuPXALpg7JS89AZg
    MD5:9EC7B4EB1DF94D63E1C995757259821E
    SHA1:1C108E90E169DD87CEB61479B0A2A0E23DCB80AE
    SHA-256:0E29B2274003860D7BF562EFCFD0481510EF59EF57A758C27930F4D4BDC7F9AC
    SHA-512:DB6BF6E90D6844B91EEAAF926120DB6EF8BFC8F18B603EC74596F369EE89F59D5E48680DA919146E6B0218AB2D49881B307992615CBA50E9621FCF9C219C5779
    Malicious:false
    Reputation:low
    Preview:var xmlSearch_Chunk27Data = "";..xmlSearch_Chunk27Data += '<?xml version=\"1.0\" encoding=\"utf-8\"?><index> saved from url=(0016)http://localhost -->';..xmlSearch_Chunk27Data += '<stem n=\"si\"><phr n=\"si\"><ent r=\"4\" t=\"2\" w=\"512\" /><ent r=\"3\" t=\"63\" w=\"13\" /><ent r=\"3\" t=\"63\" w=\"33\" /><ent r=\"4\" t=\"73\" w=\"745\" /><ent r=\"4\" t=\"73\" w=\"844\" /><ent r=\"4\" t=\"91\" w=\"358\" /><ent r=\"4\" t=\"91\" w=\"426\" /><ent r=\"3\" t=\"156\" w=\"91\" /><ent r=\"3\" t=\"168\" w=\"133\" /><ent r=\"3\" t=\"176\" w=\"442\" /><ent r=\"3\" t=\"187\" w=\"110\" /></phr></stem><stem n=\"show\"><phr n=\"show\"><ent r=\"4\" t=\"2\" w=\"526\" /><ent r=\"4\" t=\"3\" w=\"149\" /><ent r=\"6\" t=\"4\" w=\"316\" /><ent r=\"3\" t=\"4\" w=\"508\" /><ent r=\"3\" t=\"4\" w=\"513\" /><ent r=\"3\" t=\"4\" w=\"518\" /><ent r=\"6\" t=\"4\" w=\"580\" /><ent r=\"3\" t=\"4\" w=\"717\" /><ent r=\"5\" t=\"10\" w=\"400\" /><ent r=\"5\" t=\"10\" w=\"424\" /><ent r=\"4\" t=\"22\" w=\"276\" /><
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text, with very long lines (27730), with CRLF line terminators
    Category:dropped
    Size (bytes):27823
    Entropy (8bit):4.013648370870043
    Encrypted:false
    SSDEEP:768:9UN2ClVDh50SA4AIvT01NSvXn3pnHtmxMGhkm5K+kQxDt0emKDt0zW3xdlnkRh9W:OaXL2o//z0GrvPoDrrRZrErXIzF5HI
    MD5:96A30D530C84C22E094F6A683FC96692
    SHA1:B2756CFD41211E362D04FD407E835A30FAC06B43
    SHA-256:3ED97153ED5394257204E36730AECCCF30075C898FA712B7989293494EADB755
    SHA-512:1B894FC92512275E4FD5DAB2A41EDDF7CEDE4CFF370BE415AF270DE20D228BD7DAF730DD83AF7536A3D306964B1A9F30BE06FB8480AEB708F6859D7769DBF7FD
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="utf-8"?><index> saved from url=(0016)http://localhost -->..<stem n="entir"><phr n="entire"><ent r="3" t="4" w="447" /><ent r="4" t="14" w="606" /><ent r="4" t="28" w="385" /><ent r="3" t="56" w="346" /><ent r="3" t="63" w="43" /><ent r="3" t="90" w="158" /><ent r="3" t="90" w="518" /><ent r="4" t="100" w="1019" /><ent r="3" t="124" w="233" /><ent r="3" t="144" w="89" /><ent r="4" t="146" w="189" /><ent r="4" t="163" w="359" /><ent r="3" t="168" w="342" /><ent r="3" t="168" w="365" /></phr><phr n="entirely"><ent r="4" t="169" w="663" /></phr></stem><stem n="tree"><phr n="tree"><ent r="3" t="4" w="449" /><ent r="3" t="4" w="458" /></phr></stem><stem n="hidden"><phr n="hidden"><ent r="3" t="4" w="491" /><ent r="3" t="4" w="515" /><ent r="3" t="4" w="524" /><ent r="3" t="41" w="63" /><ent r="5" t="50" w="329" /><ent r="3" t="57" w="49" /><ent r="3" t="60" w="129" /><ent r="3" t="60" w="197" /><ent r="3" t="60" w="221" /><ent r="3" t="66" w="627" /><ent r="
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text, with very long lines (27097), with CRLF line terminators
    Category:dropped
    Size (bytes):27190
    Entropy (8bit):4.110670743497856
    Encrypted:false
    SSDEEP:768:wea95foOfsu9tZhOqrUy1Af3ZVlYHTW846DsbyQRP/eE9PmD2BWv1morCSk0Bd7R:BZGXzldrms
    MD5:52D5817D1D50A27DF69114E6EFA8663A
    SHA1:4E55A1F38B6F0D25D8035F747142D9DC69325544
    SHA-256:AAE336258DEFB0AC64040F253F5FFFE83CCD5A384AB7F16D8C9BD20177DC0842
    SHA-512:CAB2D62AA99318FC830C61B55DDFDE1DEA80694D571B7ECB69E38F18E718854A9273FC29B68C14E48E46645928802E0E897FE5ADCAD4E7E5458B4F4FA857E6C5
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="utf-8"?><index> saved from url=(0016)http://localhost -->..<stem n="15"><phr n="15"><ent r="4" t="10" w="784" /><ent r="4" t="11" w="490" /><ent r="12" t="11" w="1186" /><ent r="4" t="12" w="625" /><ent r="12" t="12" w="1263" /><ent r="4" t="13" w="723" /><ent r="12" t="14" w="1288" /><ent r="4" t="15" w="506" /><ent r="6" t="15" w="864" /><ent r="6" t="15" w="960" /><ent r="4" t="17" w="416" /><ent r="4" t="17" w="426" /><ent r="4" t="17" w="435" /><ent r="4" t="17" w="813" /><ent r="4" t="24" w="550" /><ent r="4" t="24" w="559" /><ent r="4" t="30" w="466" /><ent r="3" t="30" w="781" /><ent r="3" t="30" w="793" /><ent r="3" t="30" w="812" /><ent r="3" t="73" w="106" /><ent r="4" t="100" w="729" /><ent r="7" t="110" w="162" /><ent r="3" t="176" w="463" /><ent r="3" t="176" w="472" /><ent r="3" t="176" w="506" /><ent r="3" t="178" w="416" /><ent r="5" t="189" w="126" /></phr></stem><stem n="shorter"><phr n="shorter"><ent r="4" t="10" w="787" /><ent r="4
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text, with very long lines (41832), with CRLF line terminators
    Category:dropped
    Size (bytes):41925
    Entropy (8bit):3.9002482028423313
    Encrypted:false
    SSDEEP:768:2rR+EhJQmXxKBKei+ciMxRjtluwAOwLhn9J33xMTDHjeKx/2e8uG3fEn4J3R5IXN:gqw8tFPOMBy9m963fPmdTQ
    MD5:79C73F5F4A6E06D13E2C3E88902C5CAA
    SHA1:A0BF903607CB96605CBC6D0D22039CABD7792BFA
    SHA-256:00CDB97C9667A345D3E9D82B4C617B8F320905BA75836B0DE27594D1DA93CE1F
    SHA-512:D7857F8EF3D24792BBD5FBF44330C8E4CE33704776B2860DA473D8B3C6F1082C5D1A94BC8A53B2C3AE9825013EBA144D97355A48DE7479DD50D7A56D43E213E5
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="utf-8"?><index> saved from url=(0016)http://localhost -->..<stem n="logger"><phr n="loggers"><ent r="5" t="0" w="31" /><ent r="3" t="0" w="111" /><ent r="3" t="1" w="28" /><ent r="4" t="1" w="86" /><ent r="4" t="1" w="145" /><ent r="3" t="1" w="255" /><ent r="3" t="1" w="264" /><ent r="5" t="1" w="298" /><ent r="4" t="3" w="394" /><ent r="5" t="3" w="482" /><ent r="4" t="3" w="522" /><ent r="4" t="3" w="556" /><ent r="4" t="3" w="580" /><ent r="4" t="3" w="642" /><ent r="4" t="3" w="992" /><ent r="4" t="3" w="1168" /><ent r="4" t="3" w="1515" /><ent r="3" t="3" w="1527" /><ent r="3" t="5" w="100" /><ent r="3" t="5" w="106" /><ent r="4" t="5" w="717" /><ent r="4" t="5" w="731" /><ent r="4" t="5" w="755" /><ent r="4" t="5" w="771" /><ent r="268435456" t="6" w="5" /><ent r="16777218" t="6" w="11" /><ent r="3" t="6" w="17" /><ent r="3" t="7" w="10" /><ent r="3" t="7" w="52" /><ent r="3" t="9" w="115" /><ent r="3" t="9" w="158" /><ent r="4" t="9" w="300" />
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:exported SGML document, ASCII text, with very long lines (32452), with CRLF line terminators
    Category:dropped
    Size (bytes):32696
    Entropy (8bit):4.194287994678196
    Encrypted:false
    SSDEEP:768:YODRXPoEI+cdzcmurig4KQgiEcorwnrAn5p3vMEvaqLC/mCdABh+50KS0i1RReVy:NG2S2KGV+uKx2r
    MD5:6E5E74A27C563E73904030BE1CBBD592
    SHA1:28E0501DBC51421EF7965BB50AB18C4DA606E6C0
    SHA-256:4B064C74E9CCC4848B1655649732C2526F36DD195AA66E5930CFA1FF5C9045C4
    SHA-512:0455A86031D1317044F25BBA774CBD6F35F13BB4243D3BDA024480CD9B2022C0A2B91F39983792F632AEAFB8C0F7E3B284B69208CF0C61B74F3CB7AC1EC641E9
    Malicious:false
    Reputation:low
    Preview:var xmlSearch_Chunk50Data = "";..xmlSearch_Chunk50Data += '<?xml version=\"1.0\" encoding=\"utf-8\"?><index> saved from url=(0016)http://localhost -->';..xmlSearch_Chunk50Data += '<stem n=\"although\"><phr n=\"although\"><ent r=\"4\" t=\"12\" w=\"339\" /><ent r=\"4\" t=\"12\" w=\"550\" /><ent r=\"4\" t=\"13\" w=\"482\" /><ent r=\"4\" t=\"16\" w=\"373\" /><ent r=\"3\" t=\"22\" w=\"87\" /><ent r=\"4\" t=\"23\" w=\"344\" /><ent r=\"3\" t=\"39\" w=\"13\" /><ent r=\"3\" t=\"86\" w=\"164\" /><ent r=\"4\" t=\"89\" w=\"396\" /><ent r=\"4\" t=\"147\" w=\"412\" /></phr></stem><stem n=\"physic\"><phr n=\"physically\"><ent r=\"4\" t=\"12\" w=\"360\" /><ent r=\"4\" t=\"13\" w=\"503\" /></phr><phr n=\"physical\"><ent r=\"4\" t=\"17\" w=\"261\" /><ent r=\"4\" t=\"86\" w=\"551\" /><ent r=\"4\" t=\"89\" w=\"88\" /></phr></stem><stem n=\"jack\"><phr n=\"jack\"><ent r=\"4\" t=\"12\" w=\"400\" /></phr></stem><stem n=\"possibl\"><phr n=\"possible\"><ent r=\"4\" t=\"12\" w=\"553\" /><ent r=\"4\" t=\"13\
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text, with very long lines (29369), with CRLF line terminators
    Category:dropped
    Size (bytes):29462
    Entropy (8bit):3.9876877617248563
    Encrypted:false
    SSDEEP:768:rPpHiAYd4y2mwqb1rHj+9rEk19eYLOhZ7Ute9lea0DEi0aVXfQrUr11M9l8MqCsW:wAjnLqgxExnU4n6Hfs
    MD5:3F19AADF3F4CFA79FBE7862580E802BE
    SHA1:397AF407556923FF354226B52FDBEB4140CADCEE
    SHA-256:8277A88A38B32627C05CFA9564BA2410C33F44966FBFBF08AD1AE8D5DABD3E26
    SHA-512:858D94D0A5D81127DA473766CE7E387EB205FF7BA63901B7D64F4C087C8FD2D33AA67D7CBAAD621B5A82B584DEBC9994F4D6B7A4B910B9823578FF791DB99A99
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="utf-8"?><index> saved from url=(0016)http://localhost -->..<stem n="time-sav"><phr n="time-saving"><ent r="4" t="1" w="110" /><ent r="4" t="7" w="933" /><ent r="3" t="9" w="549" /><ent r="4" t="10" w="926" /><ent r="3" t="10" w="1363" /><ent r="4" t="11" w="759" /><ent r="3" t="11" w="1461" /><ent r="4" t="12" w="885" /><ent r="3" t="12" w="1491" /><ent r="4" t="13" w="841" /><ent r="3" t="13" w="1252" /><ent r="4" t="14" w="895" /><ent r="3" t="14" w="1516" /><ent r="4" t="15" w="843" /><ent r="3" t="15" w="1262" /><ent r="4" t="16" w="1064" /><ent r="3" t="16" w="1289" /><ent r="4" t="17" w="1094" /><ent r="3" t="17" w="1439" /><ent r="4" t="20" w="173" /><ent r="3" t="20" w="304" /><ent r="4" t="36" w="423" /><ent r="4" t="37" w="603" /><ent r="4" t="150" w="52" /><ent r="1048578" t="151" w="82" /><ent r="1048578" t="151" w="677" /><ent r="3" t="151" w="920" /><ent r="1048578" t="151" w="1060" /><ent r="5" t="169" w="353" /><ent r="4" t="169" w="377
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:exported SGML document, ASCII text, with very long lines (38556), with CRLF line terminators
    Category:dropped
    Size (bytes):38800
    Entropy (8bit):3.9774599873867986
    Encrypted:false
    SSDEEP:768:5E1vPvIX2yvopzoOi+5gk53mOwBvFhUic3A+yzivO0BiWwlnPSPUosmvDNXf+w6p:7fHpjVy7E
    MD5:2F4F8F23CABE3E12DE29A6955C634768
    SHA1:E11ED66C9B4CF19E3B39F59FB02FA7A92C384640
    SHA-256:E5854983213E225846175A6114E3D49B258BA94B72EE63DC23B0ADDB11F8FC02
    SHA-512:51436609841FBC408AA5BF4646212CB7442187B7CD8B326F7B7394D2961B1238D3D7E5522D54C9AD983FDD574C3A0BC8B342E1210F177629AA7A34438AB420AA
    Malicious:false
    Reputation:low
    Preview:var xmlSearch_Chunk33Data = "";..xmlSearch_Chunk33Data += '<?xml version=\"1.0\" encoding=\"utf-8\"?><index> saved from url=(0016)http://localhost -->';..xmlSearch_Chunk33Data += '<stem n=\"6\"><phr n=\"6\"><ent r=\"3\" t=\"3\" w=\"248\" /><ent r=\"4\" t=\"3\" w=\"732\" /><ent r=\"3\" t=\"15\" w=\"94\" /><ent r=\"4\" t=\"15\" w=\"534\" /><ent r=\"3\" t=\"26\" w=\"252\" /><ent r=\"4\" t=\"71\" w=\"97\" /><ent r=\"4\" t=\"71\" w=\"971\" /><ent r=\"3\" t=\"123\" w=\"490\" /><ent r=\"8\" t=\"124\" w=\"217\" /><ent r=\"8\" t=\"143\" w=\"158\" /></phr></stem><stem n=\"4\"><phr n=\"4\"><ent r=\"4\" t=\"3\" w=\"255\" /><ent r=\"4\" t=\"3\" w=\"329\" /><ent r=\"3\" t=\"3\" w=\"446\" /><ent r=\"3\" t=\"3\" w=\"471\" /><ent r=\"3\" t=\"3\" w=\"762\" /><ent r=\"5\" t=\"3\" w=\"1424\" /><ent r=\"4\" t=\"3\" w=\"1474\" /><ent r=\"5\" t=\"9\" w=\"610\" /><ent r=\"5\" t=\"9\" w=\"622\" /><ent r=\"5\" t=\"9\" w=\"634\" /><ent r=\"4\" t=\"10\" w=\"367\" /><ent r=\"5\" t=\"10\" w=\"1391\" /><ent r=\"
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text, with very long lines (27015), with CRLF line terminators
    Category:dropped
    Size (bytes):27108
    Entropy (8bit):4.16869921423869
    Encrypted:false
    SSDEEP:768:HruouoTT00MJ+fTTOKycOSSssnnIIssllppKK77ssnVaLLNNOOMMQQLLppGGOOOR:KhpcEDT30EzQkhN5NwxE
    MD5:037D19592D4CF9F9CC22EB1FD7ABCF67
    SHA1:13917B2ADEE5D3F6BC7338EE240E08EAE47FDEAE
    SHA-256:B7200111CEB053B51FA93D051C1B9C6C0C0A92171CC06343149AB70F4C801FFC
    SHA-512:193765C91964D8E7ECCB1E419DB580DC96A61B055B5BFC38EAC6FB902FB898240E8E704217F84B920D679EA516F936DF352B1723EB2D9605CC910B03AD1F1BE9
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="utf-8"?><index> saved from url=(0016)http://localhost -->..<stem n="zoom"><phr n="zoomed"><ent r="4" t="38" w="146" /><ent r="4" t="38" w="146" /><ent r="3" t="40" w="135" /><ent r="3" t="40" w="135" /><ent r="3" t="41" w="406" /><ent r="3" t="41" w="406" /><ent r="3" t="41" w="591" /><ent r="3" t="41" w="591" /><ent r="3" t="41" w="678" /><ent r="4" t="151" w="719" /><ent r="4" t="151" w="719" /></phr><phr n="zooming"><ent r="4" t="38" w="160" /><ent r="4" t="38" w="160" /><ent r="4" t="38" w="164" /><ent r="4" t="38" w="164" /><ent r="3" t="41" w="25" /><ent r="3" t="41" w="108" /><ent r="4" t="41" w="134" /><ent r="4" t="41" w="200" /><ent r="4" t="41" w="246" /><ent r="4" t="41" w="277" /><ent r="4" t="41" w="277" /><ent r="4" t="41" w="288" /><ent r="4" t="41" w="288" /><ent r="3" t="41" w="420" /><ent r="3" t="41" w="420" /><ent r="3" t="41" w="605" /><ent r="3" t="41" w="605" /><ent r="3" t="41" w="609" /><ent r="3" t="41" w="609" /><ent r="4" t
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text, with very long lines (28338), with CRLF line terminators
    Category:dropped
    Size (bytes):28431
    Entropy (8bit):3.941220347386749
    Encrypted:false
    SSDEEP:768:i+2oaD0MrJFGQdSzZ5V3Elob2KUBbzFpBjAtCd530mte11Se3FSd9V6/U63EnJC/:U1hDsqUWho5oRZbbDk
    MD5:C4BA5B1A743125595DCD2626CD4CF1FD
    SHA1:012CA27E2EE07655704F423C70CBBB98ED118B5C
    SHA-256:F8F11C5F5FB33E79084A17F3D6D531E7ACC3B852DB7BF6605B9D6B79507EA11D
    SHA-512:2A4E6991EFD2DF3C64EC4B4CE25656162DD751A4D51A177C0E298D0465C3EAF6EE56CC0006A6B8A2E873B77436DD54E8D467C100F9ABEF7F0690CAB671390318
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="utf-8"?><index> saved from url=(0016)http://localhost -->..<stem n="burst"><phr n="burst"><ent r="4" t="3" w="78" /><ent r="5" t="3" w="269" /><ent r="5" t="3" w="343" /><ent r="5" t="3" w="492" /><ent r="4" t="11" w="523" /><ent r="5" t="11" w="529" /><ent r="4" t="11" w="621" /><ent r="4" t="11" w="668" /><ent r="6" t="11" w="1023" /><ent r="4" t="12" w="672" /><ent r="5" t="12" w="678" /><ent r="4" t="12" w="770" /><ent r="4" t="15" w="594" /><ent r="5" t="15" w="615" /><ent r="4" t="15" w="725" /><ent r="5" t="21" w="86" /><ent r="4" t="24" w="132" /><ent r="5" t="24" w="148" /><ent r="5" t="28" w="292" /><ent r="268435456" t="30" w="1" /><ent r="16777218" t="30" w="4" /><ent r="3" t="30" w="7" /><ent r="3" t="30" w="53" /><ent r="3" t="30" w="162" /><ent r="4" t="30" w="196" /><ent r="4" t="30" w="222" /><ent r="4" t="30" w="232" /><ent r="4" t="30" w="270" /><ent r="4" t="30" w="296" /><ent r="4" t="30" w="320" /><ent r="4" t="30" w="360" /><ent
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:exported SGML document, ASCII text, with very long lines (33625), with CRLF line terminators
    Category:dropped
    Size (bytes):33869
    Entropy (8bit):4.0597653293512765
    Encrypted:false
    SSDEEP:768:+ovI+XdaajjaicGjdwjPjcLdAjXbfZhcTlJeZ1KWyEAEDykr5H1nrNFpHTZfXyF3:jVw7ymK77SdAP7tcE
    MD5:907F47A5EF1DFCD6E20D06AE349761D6
    SHA1:E5AC0A2BCF5C8AFA12C39D7E9CEC69FF3D1B8CD9
    SHA-256:0F751C013C7E89087C53F93E995192BFFE96E62D5B4103E66AA0233FE9DEBD66
    SHA-512:0288311D8A387A747142694CB51D64398D6279267FDDCFAA0AE2ED133198BF3D7F1072FD1367D954EBAB0930F5F03AE08A06A1CF1C68EECA1F11A292334DFBD6
    Malicious:false
    Reputation:low
    Preview:var xmlSearch_Chunk19Data = "";..xmlSearch_Chunk19Data += '<?xml version=\"1.0\" encoding=\"utf-8\"?><index> saved from url=(0016)http://localhost -->';..xmlSearch_Chunk19Data += '<stem n=\"topic\"><phr n=\"topics\"><ent r=\"3\" t=\"1\" w=\"285\" /><ent r=\"3\" t=\"9\" w=\"590\" /><ent r=\"3\" t=\"75\" w=\"40\" /><ent r=\"3\" t=\"84\" w=\"11\" /><ent r=\"3\" t=\"128\" w=\"501\" /><ent r=\"3\" t=\"130\" w=\"449\" /><ent r=\"4\" t=\"131\" w=\"321\" /><ent r=\"3\" t=\"138\" w=\"20\" /><ent r=\"1048578\" t=\"171\" w=\"677\" /></phr><phr n=\"topic\"><ent r=\"3\" t=\"104\" w=\"14\" /><ent r=\"5\" t=\"104\" w=\"580\" /><ent r=\"3\" t=\"127\" w=\"99\" /><ent r=\"3\" t=\"129\" w=\"257\" /></phr></stem><stem n=\"instal\"><phr n=\"installing\"><ent r=\"268435456\" t=\"2\" w=\"1\" /><ent r=\"16777218\" t=\"2\" w=\"4\" /><ent r=\"1048578\" t=\"2\" w=\"89\" /><ent r=\"3\" t=\"2\" w=\"118\" /><ent r=\"1048578\" t=\"2\" w=\"128\" /><ent r=\"1048578\" t=\"66\" w=\"745\" /><ent r=\"3\" t=\"99\" w=\"
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text, with very long lines (26535), with CRLF line terminators
    Category:dropped
    Size (bytes):26628
    Entropy (8bit):4.024962044204365
    Encrypted:false
    SSDEEP:768:mOU4aW+ele5e9eCebeSeslYBLkSS9r/UaGxiAHVvgcPdnhB7VpLB827haY3WnyKR:FY0ADqTwktf23W2tfoWF3iXDc
    MD5:AD8850FCAEFFF1B4FD9E906597FFAA42
    SHA1:7234C370F0AE6D3F4D17BFD4DA0DBAE224CE429C
    SHA-256:71CADBDE25D75356508252A652AB0C643A024BE1218A1068C0CCB2AC3440C052
    SHA-512:A1284D76A50252145BBE6C813B463F2A05F8309585CF7B9271D1C9971A45A582A1E8F1EF6D182E991AF37D3181CE4D94563ABB0C9530BF430C4ED569C52FBFEE
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="utf-8"?><index> saved from url=(0016)http://localhost -->..<stem n="tabl"><phr n="table"><ent r="4" t="3" w="314" /><ent r="5" t="3" w="409" /><ent r="3" t="4" w="95" /><ent r="1048578" t="4" w="105" /><ent r="3" t="4" w="109" /><ent r="3" t="4" w="127" /><ent r="3" t="4" w="149" /><ent r="3" t="4" w="211" /><ent r="3" t="4" w="233" /><ent r="3" t="4" w="246" /><ent r="3" t="4" w="272" /><ent r="3" t="4" w="280" /><ent r="3" t="4" w="283" /><ent r="3" t="4" w="296" /><ent r="3" t="4" w="319" /><ent r="3" t="4" w="473" /><ent r="3" t="4" w="489" /><ent r="3" t="4" w="560" /><ent r="3" t="4" w="583" /><ent r="3" t="24" w="1052" /><ent r="3" t="29" w="119" /><ent r="4" t="37" w="451" /><ent r="3" t="42" w="131" /><ent r="3" t="42" w="144" /><ent r="3" t="42" w="178" /><ent r="3" t="42" w="187" /><ent r="3" t="42" w="213" /><ent r="3" t="42" w="443" /><ent r="3" t="44" w="23" /><ent r="4" t="44" w="40" /><ent r="4" t="49" w="126" /><ent r="4" t="49" w="146
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text, with very long lines (26630), with CRLF line terminators
    Category:dropped
    Size (bytes):26723
    Entropy (8bit):3.9685433124249165
    Encrypted:false
    SSDEEP:768:oha9cGzeR42/dkQG7r4ovDAvDEEaN3JQVMAFBmm0oTO5P9XDpPltHD9mBTT5bLGU:jFgfjBVQrwY1XtTUV
    MD5:E4BD6F4C5A25EF89DAB46A95B4EDA8AD
    SHA1:1AFCEDD156CCE3424ACCA668AEDA673CBD92F201
    SHA-256:F2C3CD7418CCDE23986E25DB6FCD2C1602E4AF28136AD59FF413B2D8361D14DB
    SHA-512:EB77EFE2E8B6161EAD426A679A70C045EA5076B97A3BEB4A63693C62473B602F12EA4ADDABFEED67873719765BBA07E8AC9B0B18EFD828CF215579DDCC905D34
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="utf-8"?><index> saved from url=(0016)http://localhost -->..<stem n="welcom"><phr n="welcome"><ent r="268435456" t="0" w="1" /></phr></stem><stem n="hobowar"><phr n="hoboware"><ent r="3" t="0" w="3" /><ent r="5" t="0" w="18" /><ent r="5" t="0" w="24" /><ent r="5" t="0" w="61" /><ent r="5" t="0" w="66" /><ent r="4" t="0" w="168" /><ent r="268435456" t="1" w="4" /><ent r="16777218" t="1" w="9" /><ent r="3" t="1" w="11" /><ent r="3" t="1" w="30" /><ent r="3" t="1" w="65" /><ent r="3" t="1" w="66" /><ent r="3" t="1" w="68" /><ent r="3" t="1" w="70" /><ent r="3" t="1" w="186" /><ent r="3" t="1" w="188" /><ent r="3" t="1" w="204" /><ent r="3" t="1" w="217" /><ent r="3" t="1" w="241" /><ent r="3" t="1" w="252" /><ent r="3" t="1" w="280" /><ent r="5" t="1" w="291" /><ent r="268435456" t="2" w="2" /><ent r="16777218" t="2" w="5" /><ent r="3" t="2" w="12" /><ent r="3" t="2" w="17" /><ent r="3" t="2" w="62" /><ent r="3" t="2" w="64" /><ent r="3" t="2" w="87" /><en
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, Unicode text, UTF-8 (with BOM) text, with very long lines (26917), with CRLF line terminators
    Category:dropped
    Size (bytes):51636
    Entropy (8bit):5.269035798165582
    Encrypted:false
    SSDEEP:768:ImE9UanJNZSVOEa4IZUon/IDO0MS9Qm3zbbKsAEhrmAim722rFsncWhrdrk:Ti/7cVOEOZ1097rYQS2SnFxS
    MD5:EA5A74B6C6970059E6F7839F2DEA2522
    SHA1:7DBBF7F7D0B8C1B550E2C2A728E0EC4553772D94
    SHA-256:4EE60C8B9B6520ABA6690BF92974A91C18EE6DAA082FE6516A43F2F1196D63D7
    SHA-512:D5F02B26749F4E797884CDDD4F53CA466F0A76FE6C8CB1E9D56695D0592C05873A85C0106756BD0F6BE5D66A0CD462380023D1C9CAFC88053F014AB37BA81CF0
    Malicious:false
    Reputation:low
    Preview:.<?xml version="1.0" encoding="utf-8"?>..<CatapultSkin Version="1" Title="HOBOware Help" AutoSyncTOC="True" Tabs="TOC,Index,Search,Favorites" Top="118px" Left="164px" Width="800px" Height="600px" DefaultTab="TOC" Bottom="482px" Right="956px" Anchors="Width,Height" UseBrowserDefaultSize="True" UseDefaultBrowserSetup="True" NavigationLinkTop="true" ToolbarInTopic="true">.. saved from url=(0016)http://localhost -->.. saved from url=(0014)about:internet -->.. <HtmlHelpOptions ShowMenuBar="False" TopmostWindowStyle="False" AutoShowNavigationPane="False" EnableButtonCaptions="True" NavigationPaneWidth="0" Buttons="Print,Next,Previous" HideNavigationOnStartup="False" />.. <Toc LinesBetweenItems="true" LinesFromRoot="true" SingleClick="false" PlusMinusSquares="true" AlwaysShowSelection="true" UseFolderIcons="false" ImageListWidth="16" BinaryStorage="false" />.. <Index BinaryStorage="True" />.. <WebHelpOptions NavigationPaneWidth="300" HideNavigationOnStartup="fals
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:exported SGML document, ASCII text, with very long lines (32028), with CRLF line terminators
    Category:dropped
    Size (bytes):32272
    Entropy (8bit):4.179766155034548
    Encrypted:false
    SSDEEP:768:JnossdXuEKYp3M0AT3Nnl1KxKkkccLLUvxaB99VVS55hhffRRTTIIiiVVbbffMMX:+g8
    MD5:2A916FBAB9DA89B3E47563D8D4C341E4
    SHA1:B439E6C81BF5C2D039D67D1D371A29B421E5B401
    SHA-256:8B33F9BF2E2131B03BDA2E6620D3C445A98E7141005975F8DB43FA06DD19258C
    SHA-512:AFAA1B993B8BECEA32EC046DA7C266D016E295D07FCE196216D7B53A0FED08A9F3233319F40EE2351726C9AE2F68694518281A8587D0E25F3601354462CE47E1
    Malicious:false
    Reputation:low
    Preview:var xmlSearch_Chunk78Data = "";..xmlSearch_Chunk78Data += '<?xml version=\"1.0\" encoding=\"utf-8\"?><index> saved from url=(0016)http://localhost -->';..xmlSearch_Chunk78Data += '<stem n=\"manipul\"><phr n=\"manipulate\"><ent r=\"3\" t=\"25\" w=\"494\" /><ent r=\"3\" t=\"25\" w=\"494\" /></phr></stem><stem n=\"lux\"><phr n=\"lux\"><ent r=\"3\" t=\"25\" w=\"542\" /><ent r=\"3\" t=\"25\" w=\"542\" /><ent r=\"3\" t=\"25\" w=\"560\" /><ent r=\"3\" t=\"25\" w=\"560\" /><ent r=\"6\" t=\"80\" w=\"688\" /></phr></stem><stem n=\"residenti\"><phr n=\"residential\"><ent r=\"3\" t=\"25\" w=\"551\" /><ent r=\"3\" t=\"25\" w=\"551\" /></phr></stem><stem n=\"500\"><phr n=\"500\"><ent r=\"3\" t=\"25\" w=\"559\" /><ent r=\"3\" t=\"25\" w=\"559\" /></phr></stem><stem n=\"retail\"><phr n=\"retail\"><ent r=\"3\" t=\"25\" w=\"569\" /><ent r=\"3\" t=\"25\" w=\"569\" /></phr></stem><stem n=\"mg\"><phr n=\"mG\"><ent r=\"3\" t=\"25\" w=\"580\" /><ent r=\"3\" t=\"25\" w=\"580\" /><ent r=\"3\" t=\"25\" w=\"
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:exported SGML document, ASCII text, with CRLF line terminators
    Category:dropped
    Size (bytes):428
    Entropy (8bit):5.158722506679957
    Encrypted:false
    SSDEEP:12:RzoECv7MM8CdYREl9C/1xCn7yWC/+hVEWC/GqKQWCBVx4+DnjcLk:REECvuC2R4C/16C/eaWC/B1WCBVx4cnv
    MD5:31FD7DFACA29002A34E4E94B97F97293
    SHA1:923D743D20F2ABFA5C7043F0DA38987313C0049A
    SHA-256:73675F436B022538A06D12351A9DC679273F91CCE4E29A9C5ECD2B11381649F0
    SHA-512:C2C2D8DF22C9D9AF012C5784CC014C2ACD4BFD6F2F4E093C53685B44976C9D1435658620FD0D1E950AA98AAE0690C68197CCA9ACED8AE0191B2BF7A736493088
    Malicious:false
    Reputation:low
    Preview:var xmlSynonymsData = "";..xmlSynonymsData += '<?xml version=\"1.0\" encoding=\"utf-8\"?>';..xmlSynonymsData += '<MadCapSynonyms xml:lang=\"en-us\">';..xmlSynonymsData += ' saved from url=(0016)http://localhost -->';..xmlSynonymsData += ' <Groups />';..xmlSynonymsData += ' <Directional />';..xmlSynonymsData += '</MadCapSynonyms>';..MadCap.Utilities.Xhr._FilePathToXmlStringMap.Add('Synonyms', xmlSynonymsData);..
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:exported SGML document, ASCII text, with very long lines (32304), with CRLF line terminators
    Category:dropped
    Size (bytes):32548
    Entropy (8bit):4.29833956046867
    Encrypted:false
    SSDEEP:768:QBss0sbwvEvkONNzXEAYWR4wR+Lvzdbbnng5ammJJlYjOp2yLp9zzr5K+PvVRLLQ:hMGzjkUcv
    MD5:423BD9B9889C7D5E5D2856153BE46FBB
    SHA1:14BF5F41F27D09D1E64FA7970605D95283E41209
    SHA-256:5796E39D344B1C163140109BD07C86B59E7B54444F616B5BFAB56F6988F32B44
    SHA-512:B5F16C7FAE29D3D85C9558D30E91927D0CCE2DBD28E3D88C905717DF74D7938E4A0C3CEDA160A46F0CE9886773F0164D87C73FB34FF986F92F57F0F93AAB3909
    Malicious:false
    Reputation:low
    Preview:var xmlSearch_Chunk83Data = "";..xmlSearch_Chunk83Data += '<?xml version=\"1.0\" encoding=\"utf-8\"?><index> saved from url=(0016)http://localhost -->';..xmlSearch_Chunk83Data += '<stem n=\"portabl\"><phr n=\"portable\"><ent r=\"3\" t=\"68\" w=\"646\" /><ent r=\"3\" t=\"68\" w=\"646\" /></phr></stem><stem n=\"launchtim\"><phr n=\"launchtime\"><ent r=\"3\" t=\"68\" w=\"653\" /></phr></stem><stem n=\"notebook\"><phr n=\"notebook\"><ent r=\"3\" t=\"68\" w=\"701\" /><ent r=\"3\" t=\"68\" w=\"701\" /><ent r=\"4\" t=\"68\" w=\"738\" /><ent r=\"4\" t=\"68\" w=\"738\" /></phr></stem><stem n=\"whenev\"><phr n=\"Whenever\"><ent r=\"4\" t=\"68\" w=\"811\" /><ent r=\"4\" t=\"68\" w=\"811\" /></phr><phr n=\"whenever\"><ent r=\"3\" t=\"86\" w=\"68\" /><ent r=\"3\" t=\"86\" w=\"68\" /><ent r=\"4\" t=\"151\" w=\"1155\" /><ent r=\"4\" t=\"151\" w=\"1155\" /></phr></stem><stem n=\"clean\"><phr n=\"clean\"><ent r=\"4\" t=\"68\" w=\"819\" /><ent r=\"4\" t=\"68\" w=\"819\" /><ent r=\"3\" t=\"97\" w=\"2
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:exported SGML document, ASCII text, with very long lines (32178), with CRLF line terminators
    Category:dropped
    Size (bytes):32422
    Entropy (8bit):4.414647454745471
    Encrypted:false
    SSDEEP:768:KDMOJ/hiFF88eeAAJJ++VYrP9jwwYYTzA0r0+55e0e0BByg5NNXXccSGiotUa07d:c/Q
    MD5:09D707BB50E657DF0FB808B51298D2ED
    SHA1:1985CA0D94F701B8C3ED6FDA30A2B78166D78AE3
    SHA-256:835AA26EC012636E9300114EEDA030462920C6DDAEFB9266B49E1DB1F8579102
    SHA-512:0713667047AD5B1E2C4B719AC6523BC9EACA6E4B9FDF4419A9A794C2E49EAD03EE15D38B16485751454120D75A034AA319521D205F219902A2BC3D91E822D584
    Malicious:false
    Reputation:low
    Preview:var xmlSearch_Chunk90Data = "";..xmlSearch_Chunk90Data += '<?xml version=\"1.0\" encoding=\"utf-8\"?><index> saved from url=(0016)http://localhost -->';..xmlSearch_Chunk90Data += '<stem n=\"bin\"><phr n=\"bin\"><ent r=\"64\" t=\"132\" w=\"140\" /></phr></stem><stem n=\"py\"><phr n=\"py\"><ent r=\"64\" t=\"132\" w=\"142\" /></phr></stem><stem n=\"hl\"><phr n=\"hl\"><ent r=\"64\" t=\"132\" w=\"143\" /></phr></stem><stem n=\"en\"><phr n=\"en\"><ent r=\"64\" t=\"132\" w=\"144\" /></phr></stem><stem n=\"13287\"><phr n=\"13287\"><ent r=\"64\" t=\"132\" w=\"146\" /><ent r=\"64\" t=\"132\" w=\"146\" /></phr></stem><stem n=\"hotmail\"><phr n=\"Hotmail\"><ent r=\"4\" t=\"132\" w=\"148\" /><ent r=\"4\" t=\"132\" w=\"148\" /></phr></stem><stem n=\"liveunplug\"><phr n=\"liveunplugged\"><ent r=\"64\" t=\"132\" w=\"151\" /></phr></stem><stem n=\"blog\"><phr n=\"blog\"><ent r=\"64\" t=\"132\" w=\"155\" /></phr></stem><stem n=\"cn\"><phr n=\"cns\"><ent r=\"64\" t=\"132\" w=\"156\" /></phr></stem><s
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text, with very long lines (32455), with CRLF line terminators
    Category:dropped
    Size (bytes):32548
    Entropy (8bit):3.967145847154524
    Encrypted:false
    SSDEEP:768:MeaqrpkjKvAiAPsh73i7ZJCRhJiIYPFP/JtUUgT7ct5p5OJ5zjDiq5k4vGEAU2aT:Fh79F5x/gYiCVFyebwf2
    MD5:8CC394208E2E0016C3222A4FE4E37952
    SHA1:28E745F582B18B056AB0AE07D7013D35E621608F
    SHA-256:5E50A8F0A7D93AC456BF2C08A1E64C538A406FA379D6EB2A92BC036CD74A6ADA
    SHA-512:88F775EC473DFEFB72700B1AEC35C246F67D03D381E9397528C04C7420552D02611D0591AE3EC2E41E347E3E7D806B9937B35FC2F9D2BD55F89EA005DA83F41E
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="utf-8"?><index> saved from url=(0016)http://localhost -->..<stem n="bulk"><phr n="bulk"><ent r="5" t="0" w="47" /><ent r="4" t="1" w="136" /><ent r="5" t="75" w="73" /><ent r="268435456" t="80" w="2" /><ent r="16777218" t="80" w="7" /><ent r="3" t="80" w="12" /><ent r="3" t="80" w="55" /><ent r="3" t="80" w="106" /><ent r="1048578" t="80" w="150" /><ent r="3" t="80" w="159" /><ent r="4" t="80" w="168" /><ent r="3" t="80" w="400" /><ent r="3" t="80" w="477" /><ent r="4" t="80" w="613" /><ent r="5" t="150" w="217" /><ent r="4" t="150" w="224" /><ent r="4" t="152" w="905" /><ent r="3" t="165" w="16" /><ent r="4" t="165" w="33" /></phr></stem><stem n="export"><phr n="export"><ent r="5" t="0" w="48" /><ent r="3" t="1" w="39" /><ent r="4" t="1" w="137" /><ent r="5" t="3" w="408" /><ent r="5" t="3" w="427" /><ent r="4" t="3" w="438" /><ent r="4" t="5" w="177" /><ent r="5" t="35" w="50" /><ent r="7" t="71" w="457" /><ent r="6" t="71" w="467" /><ent r="6" t="71
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text, with very long lines (27558), with CRLF line terminators
    Category:dropped
    Size (bytes):27651
    Entropy (8bit):4.419503139391955
    Encrypted:false
    SSDEEP:768:iuouheuo24uzuqfHWIfufnuVuLujzoa6DcwNqVMDSima+mFpzZC+51rxyoJan7qa:tc+busCsNs3ARqc
    MD5:6FDA6BD0FF67B44EB2F8494034C12FB2
    SHA1:16366EAD0CB9CBF6669D185E190B55181D45152E
    SHA-256:E28201C78B56878A7F8662CC871C93F13A6509932493154E2942EFE9D8419F38
    SHA-512:1C6CB2CB40981DEDD9295F2FBF241BCF1CEC7CC710438450EF74EFFD9231D5E7DCFC4DED37E2512ABDE20E47A684B428E13B887CBB6F71DC55B61A2B3BDCFAC7
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="utf-8"?><index> saved from url=(0016)http://localhost -->..<stem n="share"><phr n="shared"><ent r="6" t="101" w="103" /><ent r="3" t="123" w="346" /><ent r="3" t="123" w="756" /><ent r="6" t="146" w="323" /><ent r="6" t="147" w="160" /></phr><phr n="sharing"><ent r="1048578" t="116" w="739" /><ent r="3" t="116" w="745" /><ent r="4" t="121" w="382" /><ent r="4" t="121" w="771" /><ent r="3" t="123" w="383" /><ent r="3" t="123" w="519" /><ent r="4" t="150" w="157" /></phr><phr n="share"><ent r="3" t="118" w="164" /><ent r="4" t="121" w="103" /><ent r="3" t="121" w="217" /><ent r="3" t="121" w="620" /><ent r="4" t="123" w="70" /><ent r="4" t="123" w="192" /><ent r="3" t="123" w="460" /><ent r="3" t="123" w="497" /><ent r="3" t="123" w="1022" /></phr></stem><stem n="newer"><phr n="newer"><ent r="4" t="101" w="234" /><ent r="3" t="101" w="262" /></phr></stem><stem n="hex"><phr n="hex"><ent r="6" t="101" w="291" /><ent r="8" t="146" w="286" /><ent r="10" t="1
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text, with very long lines (28005), with CRLF line terminators
    Category:dropped
    Size (bytes):28098
    Entropy (8bit):4.015772352752248
    Encrypted:false
    SSDEEP:768:DeXr3KSl1KF1aBmhzDo9pB+0kh8Jv6ifjC3K1/wsZ9Dhrz2NKDLBehTepuaBbnrN:MIBkU/a+YKIPpoduSg65APh
    MD5:08CE89527A6BC65FE934788BEEC43C57
    SHA1:BD574274A68142285E7A87074E727C1154BD14A9
    SHA-256:9FAF5BD600FDD3BAA5613E46DCC61FED18B2383180C8191718E77FAFD7E5923A
    SHA-512:17859B702B644CA8791BE487DFD18FCBF4E80E3A92CB6E0F20EB46F5AD5F53F2C242DC4F956FFCB68BF1C26587D84E14C6897F013CF4F87BFCE79B0350E5B881
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="utf-8"?><index> saved from url=(0016)http://localhost -->..<stem n="higher"><phr n="higher"><ent r="4" t="3" w="121" /><ent r="4" t="25" w="305" /><ent r="3" t="26" w="519" /><ent r="3" t="32" w="196" /><ent r="3" t="33" w="764" /><ent r="3" t="47" w="159" /><ent r="4" t="81" w="39" /><ent r="3" t="94" w="85" /></phr></stem><stem n="both"><phr n="both"><ent r="4" t="3" w="127" /><ent r="3" t="15" w="61" /><ent r="4" t="16" w="512" /><ent r="4" t="25" w="289" /><ent r="4" t="26" w="123" /><ent r="3" t="28" w="114" /><ent r="4" t="28" w="495" /><ent r="4" t="28" w="520" /><ent r="3" t="29" w="22" /><ent r="3" t="29" w="42" /><ent r="3" t="30" w="657" /><ent r="3" t="31" w="51" /><ent r="4" t="31" w="624" /><ent r="4" t="31" w="655" /><ent r="4" t="33" w="972" /><ent r="4" t="37" w="739" /><ent r="4" t="37" w="768" /><ent r="4" t="56" w="510" /><ent r="4" t="59" w="172" /><ent r="3" t="62" w="309" /><ent r="3" t="62" w="346" /><ent r="3" t="66" w="186" />
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text, with very long lines (27447), with CRLF line terminators
    Category:dropped
    Size (bytes):27540
    Entropy (8bit):4.259035855316948
    Encrypted:false
    SSDEEP:768:9t/z6E/Joobb33vvffwwTT1J1J77eeggbbqqREB+pbmmYYESYVtt5gjXwcnnkkFn:X/DDNuGUrkYI/00Dk5+
    MD5:E1F06A98F7DD6A3541A02C5FD8F71245
    SHA1:56C293459B8EFB331666E458A60423CBB95DB1AA
    SHA-256:514917BE4AF782F794AF6A3CBF5F850FA9B8FADE6C57058E378794FE24AD16E4
    SHA-512:59FE9E5C736C5CA1AAC5486AE0C7A7527772104716A1026EFAAAD1A50F647F002435B28C6E8A3454B80EA6BE86614D55FF63F6328A5205CD39BEE9CB681B3F0E
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="utf-8"?><index> saved from url=(0016)http://localhost -->..<stem n="z-axi"><phr n="Z-axis"><ent r="4" t="31" w="1087" /><ent r="4" t="31" w="1087" /></phr></stem><stem n="z"><phr n="Z"><ent r="4" t="31" w="1087" /><ent r="3" t="41" w="48" /></phr><phr n="z"><ent r="6" t="80" w="589" /><ent r="6" t="80" w="589" /><ent r="6" t="80" w="807" /><ent r="6" t="80" w="807" /></phr></stem><stem n="graphic"><phr n="graphically"><ent r="4" t="31" w="1090" /><ent r="4" t="31" w="1090" /></phr><phr n="graphical"><ent r="3" t="44" w="35" /><ent r="3" t="44" w="35" /></phr><phr n="graphic"><ent r="4" t="148" w="1423" /></phr></stem><stem n="vertic"><phr n="vertical"><ent r="4" t="31" w="1093" /><ent r="4" t="38" w="103" /><ent r="4" t="38" w="103" /><ent r="4" t="38" w="308" /><ent r="4" t="38" w="308" /><ent r="4" t="41" w="245" /><ent r="4" t="41" w="245" /><ent r="3" t="41" w="477" /><ent r="3" t="41" w="477" /><ent r="4" t="47" w="225" /><ent r="4" t="47" w="225"
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text, with very long lines (27188), with CRLF line terminators
    Category:dropped
    Size (bytes):27281
    Entropy (8bit):4.052324515610098
    Encrypted:false
    SSDEEP:768:NW6JcTSefOuD1rHpXa5qs0HnN5KM3vGNJA95SD5faUKDHJlztwarWAU0EKIzfQQZ:wYbIBpRumRUlItk4RW+F4NukSnGaGBN5
    MD5:0B304100E6EFE0B4AFFA90BCF8181A53
    SHA1:5C3686C517786C1395AA03707D3B258A3BD8B666
    SHA-256:3DFF846CD24752C4427634802948F9A3B68608E6EB0F6415347D8A36EA87A875
    SHA-512:44A3D1E5E23313A63ED9A00415BA86042767CBF65B2A68EF7002DAFBFB063C8895216AA65C89BF85C3ED27EA44992821A70366C45F432D7BD2382FEA017F7C62
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="utf-8"?><index> saved from url=(0016)http://localhost -->..<stem n="png"><phr n="png"><ent r="8" t="3" w="534" /><ent r="10" t="46" w="319" /></phr></stem><stem n="analysi"><phr n="analysis"><ent r="4" t="3" w="538" /><ent r="4" t="3" w="1491" /><ent r="3" t="66" w="28" /><ent r="3" t="83" w="33" /><ent r="3" t="86" w="392" /><ent r="3" t="118" w="77" /><ent r="4" t="123" w="56" /><ent r="3" t="123" w="787" /><ent r="4" t="163" w="48" /><ent r="3" t="168" w="558" /></phr></stem><stem n="beyond"><phr n="beyond"><ent r="4" t="3" w="539" /><ent r="3" t="156" w="191" /><ent r="4" t="157" w="690" /></phr></stem><stem n="line"><phr n="line"><ent r="4" t="3" w="540" /><ent r="6" t="4" w="662" /><ent r="4" t="40" w="104" /><ent r="3" t="46" w="50" /><ent r="3" t="51" w="37" /><ent r="5" t="51" w="244" /><ent r="5" t="51" w="253" /><ent r="5" t="51" w="270" /><ent r="5" t="51" w="308" /><ent r="4" t="51" w="419" /><ent r="4" t="51" w="442" /><ent r="4" t="73" w
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:exported SGML document, ASCII text, with very long lines (33770), with CRLF line terminators
    Category:dropped
    Size (bytes):34014
    Entropy (8bit):4.014456752492057
    Encrypted:false
    SSDEEP:768:7RnvMYFAAUUlcdLGGI0I0Bh88RR70nnv/Cbb1JHFiiM0M0EEvvSS44vv99llbbJO:RdDotSG99W
    MD5:149652B64A6927661F836F1652B53747
    SHA1:5B7DC33BDC9223E5F41D65C6B7D8811D797250D2
    SHA-256:AD67985AEB215F9DC60C7600EC5784CCD7C142C59783C1B7154C14A1B353C75E
    SHA-512:A24EAB660BA6D07E8001AB37534D069AE83DEED39B1891B5E99BCC552DC4D11DD1E709C6E9100EB106CBDB4DDE46015DC451D978EECDBA803C1E0C56E2089ECE
    Malicious:false
    Reputation:low
    Preview:var xmlSearch_Chunk64Data = "";..xmlSearch_Chunk64Data += '<?xml version=\"1.0\" encoding=\"utf-8\"?><index> saved from url=(0016)http://localhost -->';..xmlSearch_Chunk64Data += '<stem n=\"involv\"><phr n=\"involves\"><ent r=\"3\" t=\"6\" w=\"18\" /><ent r=\"3\" t=\"6\" w=\"18\" /><ent r=\"4\" t=\"9\" w=\"342\" /><ent r=\"4\" t=\"9\" w=\"342\" /></phr><phr n=\"involve\"><ent r=\"3\" t=\"28\" w=\"28\" /><ent r=\"3\" t=\"28\" w=\"28\" /></phr></stem><stem n=\"basic\"><phr n=\"basic\"><ent r=\"3\" t=\"6\" w=\"21\" /><ent r=\"3\" t=\"6\" w=\"21\" /></phr></stem><stem n=\"initi\"><phr n=\"initial\"><ent r=\"4\" t=\"6\" w=\"33\" /><ent r=\"4\" t=\"6\" w=\"33\" /><ent r=\"3\" t=\"142\" w=\"23\" /><ent r=\"3\" t=\"142\" w=\"23\" /><ent r=\"3\" t=\"142\" w=\"429\" /><ent r=\"3\" t=\"142\" w=\"429\" /><ent r=\"4\" t=\"174\" w=\"200\" /><ent r=\"4\" t=\"174\" w=\"200\" /></phr><phr n=\"initialization\"><ent r=\"4\" t=\"31\" w=\"416\" /><ent r=\"4\" t=\"31\" w=\"416\" /></phr><phr n=\"initial
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text, with very long lines (27610), with CRLF line terminators
    Category:dropped
    Size (bytes):27703
    Entropy (8bit):4.416200329432823
    Encrypted:false
    SSDEEP:768:9NqV+0Bmkn8DhYSFOf01K2TLNhbA2RIgNpZVnEL4H7hKPLH0OatGNyDtS5knp4Id:ND1bE76d+jidvcztzXEZ6nFBKChWJHXn
    MD5:3CCF18CA3E1F8ACF4F65BBC229BD006C
    SHA1:08675F67A33071BA1BFDCB5FD1EB46B584B3B5E9
    SHA-256:9DA4E1D12FDDC216BEBE5519DE15CC6C5C7C274127ECEE6EC42A0887DD02B455
    SHA-512:CD2A663C63C53AFF0F6FCB26279213990883638009C9B5F5C6784373A3997B1BFDB0D7D87EA8E112997AB7C0A48939AAA88522C606E3197D53EE72B9BB284E3F
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="utf-8"?><index> saved from url=(0016)http://localhost -->..<stem n="multi-turn"><phr n="multi-turn"><ent r="3" t="113" w="171" /></phr></stem><stem n="amperag"><phr n="amperage"><ent r="3" t="113" w="193" /><ent r="3" t="113" w="202" /><ent r="3" t="113" w="218" /><ent r="3" t="113" w="237" /><ent r="3" t="113" w="249" /></phr></stem><stem n="smallest"><phr n="smallest"><ent r="3" t="113" w="201" /></phr></stem><stem n="fulli"><phr n="fully"><ent r="3" t="113" w="214" /><ent r="3" t="113" w="230" /><ent r="4" t="121" w="541" /><ent r="4" t="198" w="116" /></phr></stem><stem n="counterclockwis"><phr n="counterclockwise"><ent r="3" t="113" w="215" /></phr></stem><stem n="greatest"><phr n="greatest"><ent r="3" t="113" w="217" /></phr></stem><stem n="clockwis"><phr n="clockwise"><ent r="3" t="113" w="231" /></phr></stem><stem n="optimum"><phr n="optimum"><ent r="3" t="113" w="266" /></phr></stem><stem n="clamp"><phr n="clamp"><ent r="3" t="113" w="280" /><
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text, with very long lines (26927), with CRLF line terminators
    Category:dropped
    Size (bytes):27020
    Entropy (8bit):4.159738317618283
    Encrypted:false
    SSDEEP:768:8yOYR1gkxgPG7jYiSHYP46dwyhnvr/cUIRXhH2MhampVC+t+nXE2eTr0dK747x7v:TPW3oROT1iPHPSJiQuwa
    MD5:CB405C1B5B637BBD2AB58909B30CD16F
    SHA1:AEB9D7597DD63A2871C0EB9D8C83AC108BCCF3C6
    SHA-256:8B537C8294DFC2BB87EF556AD980930AADF4964DFE4121BA8F57F83CBC8CAFB9
    SHA-512:1A97882724FBAC05AA4922A5B49B770D2522C9A6A715747988B0B0B0D64E6193B67DCF1F609F922629542159844A6C925194B4C2E7AF36051B6FAF4AC4CE83B7
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="utf-8"?><index> saved from url=(0016)http://localhost -->..<stem n="ux90-004x"><phr n="ux90-004x"><ent r="4" t="3" w="1028" /></phr></stem><stem n="004x"><phr n="004x"><ent r="4" t="3" w="1029" /></phr></stem><stem n="util"><phr n="utility"><ent r="4" t="3" w="1061" /><ent r="4" t="124" w="109" /><ent r="5" t="138" w="82" /><ent r="268435456" t="144" w="5" /><ent r="16777218" t="144" w="11" /><ent r="3" t="144" w="33" /><ent r="3" t="144" w="41" /><ent r="3" t="144" w="70" /><ent r="3" t="144" w="101" /><ent r="3" t="144" w="137" /><ent r="3" t="144" w="161" /><ent r="3" t="144" w="188" /><ent r="3" t="144" w="226" /></phr><phr n="utilities"><ent r="4" t="9" w="234" /><ent r="268435456" t="21" w="3" /><ent r="16777218" t="21" w="7" /><ent r="3" t="21" w="12" /><ent r="3" t="21" w="33" /><ent r="4" t="74" w="114" /><ent r="3" t="101" w="641" /><ent r="5" t="162" w="377" /><ent r="4" t="162" w="381" /></phr></stem><stem n="databas"><phr n="database"><ent
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:exported SGML document, ASCII text, with very long lines (21810), with CRLF line terminators
    Category:dropped
    Size (bytes):22054
    Entropy (8bit):4.523161419904809
    Encrypted:false
    SSDEEP:384:wIrFdd0sr/J/3Rr3I6g/JFku2OxZQ5jWpmxt46dYAjzVgc0VJl920rg2hvHRD/lz:wIrFdd0sr/J/3Rr3I6g/JFku2OxZQ5j4
    MD5:3E2690F6E291E4ECED520BF27CEFCAD5
    SHA1:92111AEA6FBE2879D395B22F7AFD7704841E4851
    SHA-256:FDA8DF0CDDCD8E1AF5A871DA664A7858CA6F2C5CC5F14BA161FEFD125AC88A7E
    SHA-512:CD8BF7E7C8D1BBC9D02ED1ADD587BB86B37CB350AAD8D0F6C85ACED53F9F91B13EED513B7BC071AA96B4161519349FFD06A327E3C23A4F3CBDD853461FF15D69
    Malicious:false
    Reputation:low
    Preview:var xmlSearch_Chunk60Data = "";..xmlSearch_Chunk60Data += '<?xml version=\"1.0\" encoding=\"utf-8\"?><index> saved from url=(0016)http://localhost -->';..xmlSearch_Chunk60Data += '<stem n=\"protocol\"><phr n=\"protocol\"><ent r=\"3\" t=\"151\" w=\"1615\" /><ent r=\"4\" t=\"184\" w=\"247\" /></phr></stem><stem n=\"fraction\"><phr n=\"fractional\"><ent r=\"5\" t=\"152\" w=\"304\" /><ent r=\"4\" t=\"152\" w=\"312\" /></phr></stem><stem n=\"facilit\"><phr n=\"facilitate\"><ent r=\"4\" t=\"152\" w=\"358\" /><ent r=\"4\" t=\"194\" w=\"426\" /></phr></stem><stem n=\"split\"><phr n=\"split\"><ent r=\"4\" t=\"152\" w=\"367\" /><ent r=\"4\" t=\"192\" w=\"154\" /><ent r=\"3\" t=\"194\" w=\"202\" /></phr><phr n=\"splits\"><ent r=\"4\" t=\"194\" w=\"435\" /></phr></stem><stem n=\"quot\"><phr n=\"quotes\"><ent r=\"5\" t=\"152\" w=\"377\" /><ent r=\"4\" t=\"152\" w=\"546\" /><ent r=\"4\" t=\"189\" w=\"35\" /></phr></stem><stem n=\"quotat\"><phr n=\"quotations\"><ent r=\"4\" t=\"152\" w=\"394\" />
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text, with very long lines (27141), with CRLF line terminators
    Category:dropped
    Size (bytes):27234
    Entropy (8bit):4.066158801082028
    Encrypted:false
    SSDEEP:768:3OOjjtotoFFokzooKKHHCCYYGGRL2n0cLqyvXtBBMMfOv33DDusppPczyy6ccfKS:tcTEf1lAfHPashXeZxxyT8MhiJGB7Gom
    MD5:7FDBC945D9F91D0A1BD7C21BAD281AC1
    SHA1:FAA57F25F416F873CD33B35E4E6AC3067926CE80
    SHA-256:1950E49033C8F18208079B3A6E9B2ADDCEDF94A7C01638A4BD72EF0B92C8137E
    SHA-512:165660216E7552BCACE123D27D4F6A965D1E3E5126E4E8E33DC0FDAD70B4E0FEB881A37A3E2479FCA10061656C5F4E4DD67744A5A39F58635255782CA3D300D0
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="utf-8"?><index> saved from url=(0016)http://localhost -->..<stem n="proce"><phr n="proceed"><ent r="3" t="7" w="703" /><ent r="4" t="97" w="917" /><ent r="4" t="97" w="917" /><ent r="4" t="97" w="1216" /><ent r="4" t="97" w="1216" /><ent r="4" t="125" w="135" /><ent r="4" t="125" w="135" /><ent r="4" t="126" w="133" /><ent r="4" t="126" w="133" /><ent r="4" t="127" w="175" /><ent r="4" t="127" w="175" /></phr></stem><stem n="blink"><phr n="Blink"><ent r="3" t="7" w="743" /><ent r="3" t="7" w="743" /></phr><phr n="blink"><ent r="6" t="10" w="1185" /><ent r="6" t="13" w="940" /><ent r="6" t="13" w="940" /><ent r="6" t="13" w="977" /><ent r="6" t="13" w="977" /><ent r="6" t="14" w="995" /><ent r="6" t="14" w="995" /><ent r="3" t="23" w="962" /><ent r="3" t="23" w="962" /><ent r="7" t="110" w="291" /><ent r="7" t="110" w="291" /><ent r="7" t="110" w="305" /><ent r="7" t="110" w="305" /><ent r="7" t="110" w="313" /><ent r="7" t="110" w="313" /></phr><phr n=
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:exported SGML document, ASCII text, with very long lines (32519), with CRLF line terminators
    Category:dropped
    Size (bytes):32763
    Entropy (8bit):4.100008715160425
    Encrypted:false
    SSDEEP:768:isyyWWnnSS338KKLLdd55EEdd0055YYKKjojoX0X0SSuuvsLmmB0B0ii11kk++9j:3TQyC512lONmmTh8RXKl66bI6svZ8XID
    MD5:EBC2BF21B2CE087BA2C1DC8951F16723
    SHA1:8303C6D74388AF47CC764D2E3C230A47A5351DCC
    SHA-256:05987D87357FD3D318C6309A0CAAECBE48D878A5D89178EFBE43BF7290FDC02B
    SHA-512:C494479E5505BD77A2CE8B7A66E65EE24A40BFA66A4DE304C9C736F9C4A2289824BA99E6EA113B11E45392D18A53749A983DEE1A6E9F8DF232EBB3E0A01187B0
    Malicious:false
    Reputation:low
    Preview:var xmlSearch_Chunk74Data = "";..xmlSearch_Chunk74Data += '<?xml version=\"1.0\" encoding=\"utf-8\"?><index> saved from url=(0016)http://localhost -->';..xmlSearch_Chunk74Data += '<stem n=\"determin\"><phr n=\"determine\"><ent r=\"4\" t=\"14\" w=\"617\" /><ent r=\"4\" t=\"14\" w=\"617\" /><ent r=\"4\" t=\"16\" w=\"532\" /><ent r=\"4\" t=\"16\" w=\"532\" /><ent r=\"4\" t=\"16\" w=\"914\" /><ent r=\"4\" t=\"16\" w=\"914\" /><ent r=\"4\" t=\"31\" w=\"1014\" /><ent r=\"4\" t=\"31\" w=\"1014\" /><ent r=\"4\" t=\"41\" w=\"129\" /><ent r=\"4\" t=\"41\" w=\"129\" /><ent r=\"4\" t=\"59\" w=\"336\" /><ent r=\"4\" t=\"59\" w=\"336\" /><ent r=\"3\" t=\"83\" w=\"263\" /><ent r=\"4\" t=\"83\" w=\"585\" /><ent r=\"4\" t=\"83\" w=\"585\" /><ent r=\"3\" t=\"88\" w=\"199\" /><ent r=\"3\" t=\"88\" w=\"199\" /><ent r=\"3\" t=\"110\" w=\"234\" /><ent r=\"3\" t=\"110\" w=\"234\" /><ent r=\"4\" t=\"120\" w=\"214\" /><ent r=\"4\" t=\"120\" w=\"214\" /><ent r=\"3\" t=\"120\" w=\"454\" /><ent r=\"3\" t=\"12
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:exported SGML document, ASCII text, with very long lines (32788), with CRLF line terminators
    Category:dropped
    Size (bytes):33032
    Entropy (8bit):4.046401725143146
    Encrypted:false
    SSDEEP:768:m700qq33bbWW99ccTTYYmmJJllGGbIM0WT55522ggAAIIzz33EE991II22llaaPv:Zegcr/iWh
    MD5:B47D855800F9DF71A15CDFBDB3921A30
    SHA1:E1749F0B61807C27E92EA630276067D087CD7AFC
    SHA-256:7014872AF1B2E7D924E2E0C1A5AEF542FD4D3D030E7779DB6FBCBA1858A35123
    SHA-512:0D18627179F75D3E2349B57ACED4A4B032E43CF842B8FFAED89D88813CA4F3A118E64CA08F00D36EC05700F4830F355FD647C67D51984B57C47569EEC4F23D43
    Malicious:false
    Reputation:low
    Preview:var xmlSearch_Chunk70Data = "";..xmlSearch_Chunk70Data += '<?xml version=\"1.0\" encoding=\"utf-8\"?><index> saved from url=(0016)http://localhost -->';..xmlSearch_Chunk70Data += '<stem n=\"what\"><phr n=\"what\"><ent r=\"4\" t=\"10\" w=\"258\" /><ent r=\"4\" t=\"10\" w=\"258\" /><ent r=\"4\" t=\"44\" w=\"210\" /><ent r=\"4\" t=\"44\" w=\"210\" /><ent r=\"3\" t=\"88\" w=\"200\" /><ent r=\"3\" t=\"88\" w=\"200\" /><ent r=\"3\" t=\"97\" w=\"436\" /><ent r=\"3\" t=\"97\" w=\"436\" /><ent r=\"5\" t=\"101\" w=\"225\" /><ent r=\"5\" t=\"101\" w=\"225\" /><ent r=\"5\" t=\"101\" w=\"314\" /><ent r=\"5\" t=\"101\" w=\"314\" /><ent r=\"3\" t=\"120\" w=\"455\" /><ent r=\"3\" t=\"120\" w=\"455\" /><ent r=\"4\" t=\"122\" w=\"204\" /><ent r=\"4\" t=\"122\" w=\"204\" /><ent r=\"4\" t=\"126\" w=\"188\" /><ent r=\"4\" t=\"126\" w=\"188\" /><ent r=\"4\" t=\"148\" w=\"378\" /><ent r=\"4\" t=\"148\" w=\"378\" /><ent r=\"4\" t=\"148\" w=\"578\" /><ent r=\"4\" t=\"148\" w=\"578\" /><ent r=\"3\" t=\"153\
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text, with very long lines (39733), with CRLF line terminators
    Category:dropped
    Size (bytes):39826
    Entropy (8bit):4.002286930449639
    Encrypted:false
    SSDEEP:768:ymNGKU4xN1NSdkzLEuznmrkwhnczuLmylmR7HSdfXfifnPpAQRuPPx52Oc2M4DY4:F9pOxWmsMKW8KtKJIgBxfWcL5axBx
    MD5:F6524C6DE8D4D7FA8B418AFA608CE231
    SHA1:E253946337A554047329AD7C1BE99BD604D0655E
    SHA-256:9569848DDE23181B8879127230CBB5E64943ABF039B8CDE3C8DA71F7200205EE
    SHA-512:912A8BF2E5BBC79A664C264C92CFC46A99281487B3E39EB685D8AF8933B4A4F88C83766DC91FE2D9A5E692A41EC069993E910D88EAF84A9D16A1D9FF30B09491
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="utf-8"?><index> saved from url=(0016)http://localhost -->..<stem n="8am"><phr n="8am"><ent r="3" t="0" w="137" /><ent r="3" t="0" w="149" /></phr></stem><stem n="8pm"><phr n="8pm"><ent r="3" t="0" w="139" /></phr></stem><stem n="et"><phr n="et"><ent r="3" t="0" w="140" /><ent r="3" t="0" w="152" /></phr></stem><stem n="mondai"><phr n="monday"><ent r="3" t="0" w="141" /><ent r="3" t="0" w="153" /></phr></stem><stem n="fridai"><phr n="friday"><ent r="3" t="0" w="143" /><ent r="3" t="0" w="155" /></phr></stem><stem n="custom"><phr n="customer"><ent r="4" t="0" w="145" /><ent r="3" t="1" w="199" /><ent r="3" t="2" w="75" /><ent r="3" t="66" w="873" /></phr><phr n="custom"><ent r="4" t="3" w="1372" /><ent r="4" t="10" w="762" /><ent r="6" t="10" w="1253" /><ent r="4" t="11" w="468" /><ent r="6" t="11" w="1303" /><ent r="4" t="12" w="603" /><ent r="6" t="12" w="1380" /><ent r="4" t="13" w="701" /><ent r="6" t="13" w="1144" /><ent r="6" t="14" w="1405" /><ent
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text, with very long lines (57621), with CRLF line terminators
    Category:dropped
    Size (bytes):57714
    Entropy (8bit):3.92378935412236
    Encrypted:false
    SSDEEP:1536:fwWkYXmmp6SzXiXWSrh2dIaN94StILo2A6RveRtE:fxkYjyX/h2Z94S6ko9eRtE
    MD5:17A1E66B5A7A601AD1D5797857A5F596
    SHA1:2C5B533A61E60796A5EB09AF5EF603D353A8D1C3
    SHA-256:DDF1416558CC64FE7996E3EF714A8DA91280C3F7696E1E60BF3F0884BB098A0C
    SHA-512:1EF25B18911347BD0F19FC40AD61BCC43490AD7F8B15BD10F1A58A502D63C2D77BBDC787B55BB8DF60B8DAD65ECB78F69489D75A14C7C3D9EAECB0087198C551
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="utf-8"?><index> saved from url=(0016)http://localhost -->..<stem n="now"><phr n="now"><ent r="3" t="2" w="216" /><ent r="4" t="3" w="116" /><ent r="4" t="3" w="459" /><ent r="4" t="3" w="1199" /><ent r="6" t="10" w="944" /><ent r="6" t="11" w="777" /><ent r="6" t="12" w="903" /><ent r="6" t="13" w="859" /><ent r="6" t="14" w="913" /><ent r="6" t="15" w="861" /><ent r="5" t="16" w="1086" /><ent r="6" t="17" w="1112" /><ent r="4" t="30" w="424" /><ent r="4" t="76" w="449" /><ent r="4" t="88" w="291" /><ent r="3" t="118" w="369" /><ent r="131076" t="133" w="253" /><ent r="131076" t="133" w="275" /><ent r="4" t="151" w="422" /><ent r="4" t="151" w="432" /><ent r="4" t="151" w="462" /><ent r="4" t="151" w="528" /><ent r="3" t="173" w="79" /><ent r="4" t="173" w="311" /><ent r="4" t="180" w="159" /></phr></stem><stem n="log"><phr n="logged"><ent r="3" t="2" w="220" /><ent r="3" t="4" w="119" /><ent r="4" t="14" w="692" /><ent r="4" t="17" w="857" /><ent r="4
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:exported SGML document, ASCII text, with very long lines (34454), with CRLF line terminators
    Category:dropped
    Size (bytes):34694
    Entropy (8bit):3.9779792169011836
    Encrypted:false
    SSDEEP:768:NIyDtAh7RUZTPfZ8JFoN+4MbceOkmSVc1R7AZMUXp9Gj9dgoUrPleja8XjnF952a:rVWR4prmK4SFdOwSC
    MD5:C316D9B8209271C4BA1E966437064C18
    SHA1:6119AA5EDC76CFAFED51975276CE2DB7111F6ABF
    SHA-256:8169A038ED18396F1588C1DA2ECCCF683F7CF65DD3D3479806A915083ECF00E5
    SHA-512:6A5E5FEFDAAF95E9B794F183770888AE1BEDFCF5A0730A9FFEB5C91058961C4E8458FB397B92B94F6FE8FF90E4309CB07C1D7D6E72A936B88FCA2DE5AF03EDBF
    Malicious:false
    Reputation:low
    Preview:var xmlSearch_Chunk5Data = "";..xmlSearch_Chunk5Data += '<?xml version=\"1.0\" encoding=\"utf-8\"?><index> saved from url=(0016)http://localhost -->';..xmlSearch_Chunk5Data += '<stem n=\"analyz\"><phr n=\"analyzing\"><ent r=\"5\" t=\"0\" w=\"37\" /><ent r=\"5\" t=\"1\" w=\"304\" /><ent r=\"4\" t=\"4\" w=\"768\" /><ent r=\"268435456\" t=\"35\" w=\"5\" /><ent r=\"16777218\" t=\"35\" w=\"12\" /><ent r=\"3\" t=\"75\" w=\"13\" /></phr><phr n=\"analyze\"><ent r=\"4\" t=\"6\" w=\"215\" /><ent r=\"3\" t=\"117\" w=\"19\" /><ent r=\"4\" t=\"194\" w=\"478\" /></phr></stem><stem n=\"us\"><phr n=\"using\"><ent r=\"5\" t=\"0\" w=\"40\" /><ent r=\"3\" t=\"1\" w=\"251\" /><ent r=\"3\" t=\"2\" w=\"693\" /><ent r=\"4\" t=\"3\" w=\"166\" /><ent r=\"4\" t=\"3\" w=\"1295\" /><ent r=\"4\" t=\"7\" w=\"124\" /><ent r=\"3\" t=\"7\" w=\"246\" /><ent r=\"3\" t=\"7\" w=\"293\" /><ent r=\"3\" t=\"7\" w=\"322\" /><ent r=\"3\" t=\"7\" w=\"424\" /><ent r=\"4\" t=\"7\" w=\"913\" /><ent r=\"4\" t=\"9\" w=\"204\" />
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:exported SGML document, ASCII text, with very long lines (32549), with CRLF line terminators
    Category:dropped
    Size (bytes):32793
    Entropy (8bit):4.246587246965237
    Encrypted:false
    SSDEEP:768:q1DjUu3RiizzrrnnrruuDDffXXggOOHHggBiBUFPYYyyKAatN5dufbSCPPuupp3j:DNNsj
    MD5:A58B0657CF26ED4719750EF626EC3CAC
    SHA1:BA284498EE332B77FDC8F4F48D78EA6866D15D14
    SHA-256:C8A458F8F2C357C16056D62D0303FBD35D43C7005F60D04E05E29D2176BA9900
    SHA-512:436CA75E59BE797A634B009FD85B8FDABDA965D52AA7467ECDF23865638639DC84A8DD05A97C0D91660821FA5A3F3DFA6B6C36024E71EE044B3DB888BBB8B3DD
    Malicious:false
    Reputation:low
    Preview:var xmlSearch_Chunk79Data = "";..xmlSearch_Chunk79Data += '<?xml version=\"1.0\" encoding=\"utf-8\"?><index> saved from url=(0016)http://localhost -->';..xmlSearch_Chunk79Data += '<stem n=\"z-axi\"><phr n=\"Z-axis\"><ent r=\"4\" t=\"31\" w=\"1087\" /><ent r=\"4\" t=\"31\" w=\"1087\" /></phr></stem><stem n=\"z\"><phr n=\"Z\"><ent r=\"4\" t=\"31\" w=\"1087\" /><ent r=\"3\" t=\"41\" w=\"48\" /></phr><phr n=\"z\"><ent r=\"6\" t=\"80\" w=\"589\" /><ent r=\"6\" t=\"80\" w=\"589\" /><ent r=\"6\" t=\"80\" w=\"807\" /><ent r=\"6\" t=\"80\" w=\"807\" /></phr></stem><stem n=\"graphic\"><phr n=\"graphically\"><ent r=\"4\" t=\"31\" w=\"1090\" /><ent r=\"4\" t=\"31\" w=\"1090\" /></phr><phr n=\"graphical\"><ent r=\"3\" t=\"44\" w=\"35\" /><ent r=\"3\" t=\"44\" w=\"35\" /></phr><phr n=\"graphic\"><ent r=\"4\" t=\"148\" w=\"1423\" /></phr></stem><stem n=\"vertic\"><phr n=\"vertical\"><ent r=\"4\" t=\"31\" w=\"1093\" /><ent r=\"4\" t=\"38\" w=\"103\" /><ent r=\"4\" t=\"38\" w=\"103\" /><ent r=\"4\"
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:exported SGML document, ASCII text, with very long lines (32757), with CRLF line terminators
    Category:dropped
    Size (bytes):33001
    Entropy (8bit):4.146940255891291
    Encrypted:false
    SSDEEP:768:NC/uROnj7PeK+pzFcbYOu8gSzr9eIMI1cyNzndH/jj63uOcnV68pyiJl0L/OytsL:NYXa3vic9RY7r
    MD5:8DD50F65CE0B233DE89DB13C9C42469E
    SHA1:50589787A2886C48DEA074A2A604D141B541821E
    SHA-256:D82C87FBE1128655A728A9DD426FC863BFEFCC81F77E863A108BB96020B06775
    SHA-512:629BE8D30D6D7D4E3E86784D15DC16C75771F0263E2C9025774DDD518FE6391D30E4A14474756258CE813B7E9CD167856F3118C629EF4ADDDFB46FD349D1F319
    Malicious:false
    Reputation:low
    Preview:var xmlSearch_Chunk51Data = "";..xmlSearch_Chunk51Data += '<?xml version=\"1.0\" encoding=\"utf-8\"?><index> saved from url=(0016)http://localhost -->';..xmlSearch_Chunk51Data += '<stem n=\"flash\"><phr n=\"flash\"><ent r=\"5\" t=\"16\" w=\"1201\" /><ent r=\"6\" t=\"17\" w=\"1211\" /><ent r=\"4\" t=\"19\" w=\"242\" /><ent r=\"4\" t=\"31\" w=\"793\" /><ent r=\"4\" t=\"96\" w=\"324\" /><ent r=\"3\" t=\"146\" w=\"677\" /></phr><phr n=\"flashing\"><ent r=\"3\" t=\"140\" w=\"70\" /><ent r=\"4\" t=\"141\" w=\"99\" /><ent r=\"4\" t=\"142\" w=\"112\" /></phr></stem><stem n=\"2000\"><phr n=\"2000\"><ent r=\"4\" t=\"17\" w=\"188\" /><ent r=\"7\" t=\"110\" w=\"298\" /><ent r=\"4\" t=\"192\" w=\"214\" /></phr></stem><stem n=\"built\"><phr n=\"built\"><ent r=\"3\" t=\"17\" w=\"242\" /><ent r=\"3\" t=\"26\" w=\"217\" /><ent r=\"3\" t=\"26\" w=\"239\" /><ent r=\"3\" t=\"169\" w=\"19\" /></phr></stem><stem n=\"ascend\"><phr n=\"ascending\"><ent r=\"4\" t=\"17\" w=\"253\" /><ent r=\"4\" t=\"76\" w=
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:exported SGML document, ASCII text, with very long lines (35590), with CRLF line terminators
    Category:dropped
    Size (bytes):35834
    Entropy (8bit):3.9324630505590665
    Encrypted:false
    SSDEEP:768:SjDwFHx9rhgV2FhlD7csGyircNwTp+23HwEDHxAMJaOgQhXaZ1oVetTC48xM3vOo:M52jATwSxI
    MD5:A550E1C4FDF4B6BCAE82D35C35048B67
    SHA1:877913285D2F857AE125DAEB3AF582095FDC8F44
    SHA-256:AD73A4CD898D918AFDBBC599D04CA8DC9C0B15FBAF2ADF1E3292E3B9EDC8C5C6
    SHA-512:FB8F65087568FA6BA3E35AF1A234E756D886B507AE05B8955F9A73BDE3586B0E1BDC8DC496135AB982585676C65782BE862E80C8AC24C0F75FACE2D8A0769DCC
    Malicious:false
    Reputation:low
    Preview:var xmlSearch_Chunk22Data = "";..xmlSearch_Chunk22Data += '<?xml version=\"1.0\" encoding=\"utf-8\"?><index> saved from url=(0016)http://localhost -->';..xmlSearch_Chunk22Data += '<stem n=\"setup\"><phr n=\"setup\"><ent r=\"3\" t=\"2\" w=\"206\" /><ent r=\"1048578\" t=\"2\" w=\"414\" /><ent r=\"3\" t=\"2\" w=\"419\" /><ent r=\"3\" t=\"2\" w=\"450\" /><ent r=\"3\" t=\"2\" w=\"474\" /><ent r=\"3\" t=\"2\" w=\"546\" /><ent r=\"3\" t=\"2\" w=\"568\" /><ent r=\"4\" t=\"3\" w=\"1057\" /><ent r=\"4\" t=\"3\" w=\"1345\" /><ent r=\"3\" t=\"4\" w=\"624\" /><ent r=\"3\" t=\"4\" w=\"643\" /><ent r=\"4\" t=\"6\" w=\"34\" /><ent r=\"4\" t=\"10\" w=\"630\" /><ent r=\"5\" t=\"17\" w=\"630\" /><ent r=\"3\" t=\"22\" w=\"16\" /><ent r=\"4\" t=\"22\" w=\"334\" /><ent r=\"3\" t=\"23\" w=\"240\" /><ent r=\"5\" t=\"30\" w=\"487\" /><ent r=\"3\" t=\"37\" w=\"28\" /><ent r=\"4\" t=\"37\" w=\"526\" /><ent r=\"4\" t=\"37\" w=\"553\" /><ent r=\"4\" t=\"37\" w=\"579\" /><ent r=\"4\" t=\"37\" w=\"585\" /><ent r
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:exported SGML document, ASCII text, with very long lines (32734), with CRLF line terminators
    Category:dropped
    Size (bytes):32978
    Entropy (8bit):4.054649236780045
    Encrypted:false
    SSDEEP:768:M805uDEJkIARLfRHoN0SWnzBZwEn3/s1gRN0Fz06wfTJJfdSYj7Yxa+cuXfeuKwz:OsBZVjYTCq
    MD5:0F23AF8C83228001264C39CE32DFE258
    SHA1:4FB57101FB0538203D9B8AC07BDCDF617C6B31DF
    SHA-256:48BEE6E2AD1CA5035B90D8C0EF5F9EC9EDAB7F5E2CBD4B41E1393E568FD5D4E9
    SHA-512:18C0FC3D9AD28C6CB6CCDEA3A6C366C883BC7E80AD6FAC7AC5FDECD4655FA088D192F0AD518C1E1460EB0783700B39C459E0F03E1A5AE3CF77C8C62C9C026C8A
    Malicious:false
    Reputation:low
    Preview:var xmlSearch_Chunk35Data = "";..xmlSearch_Chunk35Data += '<?xml version=\"1.0\" encoding=\"utf-8\"?><index> saved from url=(0016)http://localhost -->';..xmlSearch_Chunk35Data += '<stem n=\"png\"><phr n=\"png\"><ent r=\"8\" t=\"3\" w=\"534\" /><ent r=\"10\" t=\"46\" w=\"319\" /></phr></stem><stem n=\"analysi\"><phr n=\"analysis\"><ent r=\"4\" t=\"3\" w=\"538\" /><ent r=\"4\" t=\"3\" w=\"1491\" /><ent r=\"3\" t=\"66\" w=\"28\" /><ent r=\"3\" t=\"83\" w=\"33\" /><ent r=\"3\" t=\"86\" w=\"392\" /><ent r=\"3\" t=\"118\" w=\"77\" /><ent r=\"4\" t=\"123\" w=\"56\" /><ent r=\"3\" t=\"123\" w=\"787\" /><ent r=\"4\" t=\"163\" w=\"48\" /><ent r=\"3\" t=\"168\" w=\"558\" /></phr></stem><stem n=\"beyond\"><phr n=\"beyond\"><ent r=\"4\" t=\"3\" w=\"539\" /><ent r=\"3\" t=\"156\" w=\"191\" /><ent r=\"4\" t=\"157\" w=\"690\" /></phr></stem><stem n=\"line\"><phr n=\"line\"><ent r=\"4\" t=\"3\" w=\"540\" /><ent r=\"6\" t=\"4\" w=\"662\" /><ent r=\"4\" t=\"40\" w=\"104\" /><ent r=\"3\" t=\"46\" w=\"
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:exported SGML document, ASCII text, with very long lines (31973), with CRLF line terminators
    Category:dropped
    Size (bytes):32217
    Entropy (8bit):4.0695029430436405
    Encrypted:false
    SSDEEP:768:aBKKddssSShhQQZZLLCC//fftfSDDaallhrhrYYTTHH66g8dbX+zLLyy8oyoo7vJ:jet1yAy
    MD5:446F04FC7F955097630C05063ED68141
    SHA1:058F0473B2C27AE3511D68F96D0FF2698FFC4622
    SHA-256:A8E731791F2ACD9F99CEF87E0E795D4E4EB2AB3DC2A768C27A7A16D0624590A5
    SHA-512:DDF25C24B105ECC452864C4F8F77C5C46E8965F9FFF3598AF441B728CD971CF0E927233106B3739D83AD9ADAA0686C99A3BE9E55A2909CC2E9E0386E8AB231E3
    Malicious:false
    Reputation:low
    Preview:var xmlSearch_Chunk72Data = "";..xmlSearch_Chunk72Data += '<?xml version=\"1.0\" encoding=\"utf-8\"?><index> saved from url=(0016)http://localhost -->';..xmlSearch_Chunk72Data += '<stem n=\"six\"><phr n=\"six\"><ent r=\"6\" t=\"10\" w=\"1077\" /><ent r=\"6\" t=\"10\" w=\"1077\" /><ent r=\"6\" t=\"11\" w=\"850\" /><ent r=\"6\" t=\"11\" w=\"850\" /><ent r=\"6\" t=\"12\" w=\"995\" /><ent r=\"6\" t=\"12\" w=\"995\" /><ent r=\"6\" t=\"13\" w=\"968\" /><ent r=\"6\" t=\"13\" w=\"968\" /><ent r=\"6\" t=\"14\" w=\"1023\" /><ent r=\"6\" t=\"14\" w=\"1023\" /><ent r=\"5\" t=\"15\" w=\"1226\" /><ent r=\"5\" t=\"15\" w=\"1226\" /><ent r=\"6\" t=\"16\" w=\"1247\" /><ent r=\"6\" t=\"16\" w=\"1247\" /><ent r=\"3\" t=\"95\" w=\"436\" /><ent r=\"3\" t=\"95\" w=\"436\" /><ent r=\"3\" t=\"96\" w=\"39\" /><ent r=\"3\" t=\"96\" w=\"39\" /><ent r=\"4\" t=\"143\" w=\"96\" /><ent r=\"4\" t=\"143\" w=\"96\" /><ent r=\"4\" t=\"163\" w=\"86\" /><ent r=\"4\" t=\"163\" w=\"86\" /><ent r=\"4\" t=\"163\" w=\"134\
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:exported SGML document, ASCII text, with very long lines (8305), with CRLF line terminators
    Category:dropped
    Size (bytes):8549
    Entropy (8bit):4.602499569395209
    Encrypted:false
    SSDEEP:192:CtAAkfhrQL4FF3BVczfcWCZtoforHRr0r2Xyy0TRRvt20z/xQ/DFDc34gvNLI:CtAAkfhr+4FF3BVczfc9tofozRIiXyy/
    MD5:DBD13993E52F7B4DD44987DB8A0642B6
    SHA1:35E823F3D7E3C8B3F44EB574EE3BAA000092B1A4
    SHA-256:6047B3C612E6BA6D793478C9A8457D01359B6AEF3617604D47A6E623BCBCF17A
    SHA-512:5D08F3A8130D96878BA22A07216B5C52C72DE88E0E2503BD3328C05CF867D355A47B560DE32D58295A5455EAB5803784624F48A7834F82F916EE5A22F45FCF99
    Malicious:false
    Reputation:low
    Preview:var xmlSearch_Chunk61Data = "";..xmlSearch_Chunk61Data += '<?xml version=\"1.0\" encoding=\"utf-8\"?><index> saved from url=(0016)http://localhost -->';..xmlSearch_Chunk61Data += '<stem n=\"creation\"><phr n=\"creation\"><ent r=\"4\" t=\"177\" w=\"780\" /><ent r=\"4\" t=\"177\" w=\"1037\" /><ent r=\"4\" t=\"177\" w=\"1225\" /></phr></stem><stem n=\"subj\"><phr n=\"subj\"><ent r=\"4\" t=\"177\" w=\"924\" /><ent r=\"4\" t=\"178\" w=\"245\" /><ent r=\"3\" t=\"178\" w=\"421\" /></phr></stem><stem n=\"someth\"><phr n=\"something\"><ent r=\"3\" t=\"177\" w=\"1365\" /></phr></stem><stem n=\"wrong\"><phr n=\"wrong\"><ent r=\"3\" t=\"177\" w=\"1367\" /></phr></stem><stem n=\"environment\"><phr n=\"environmental\"><ent r=\"3\" t=\"178\" w=\"88\" /></phr></stem><stem n=\"flare\"><phr n=\"flares\"><ent r=\"3\" t=\"178\" w=\"93\" /></phr></stem><stem n=\"manner\"><phr n=\"manner\"><ent r=\"3\" t=\"178\" w=\"106\" /></phr></stem><stem n=\"odd\"><phr n=\"odds\"><ent r=\"3\" t=\"178\" w=\"132\" />
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:exported SGML document, ASCII text, with very long lines (32126), with CRLF line terminators
    Category:dropped
    Size (bytes):32370
    Entropy (8bit):4.407677707931546
    Encrypted:false
    SSDEEP:768:CZUtUelsi3ARz8Ahjnj9jqjP0jRjwO1et8LtpGwGWlRx9mKfHZwL7T6MUVgl70jx:IRz8ABjVUaxIUme//6XRa
    MD5:6A875A4472ECAA2C8ACB3C205EC4EDE9
    SHA1:CF523B07D422AEF2F367CBD1492A293EEB5C432A
    SHA-256:3E07826EE2702D4CCEE70A0632D6C343F8BB239E4CF12263125AC0C10625FB7E
    SHA-512:7E63DAF5B58B8A5A4EBF077973F023D602E28BE8D6CDC5D44AA478E4557F212CCB691CC6552BF66B4EC932D1F972311397FF1EAE96AE959A7C4B6234F1725E00
    Malicious:false
    Reputation:low
    Preview:var xmlSearch_Chunk59Data = "";..xmlSearch_Chunk59Data += '<?xml version=\"1.0\" encoding=\"utf-8\"?><index> saved from url=(0016)http://localhost -->';..xmlSearch_Chunk59Data += '<stem n=\"multi-turn\"><phr n=\"multi-turn\"><ent r=\"3\" t=\"113\" w=\"171\" /></phr></stem><stem n=\"amperag\"><phr n=\"amperage\"><ent r=\"3\" t=\"113\" w=\"193\" /><ent r=\"3\" t=\"113\" w=\"202\" /><ent r=\"3\" t=\"113\" w=\"218\" /><ent r=\"3\" t=\"113\" w=\"237\" /><ent r=\"3\" t=\"113\" w=\"249\" /></phr></stem><stem n=\"smallest\"><phr n=\"smallest\"><ent r=\"3\" t=\"113\" w=\"201\" /></phr></stem><stem n=\"fulli\"><phr n=\"fully\"><ent r=\"3\" t=\"113\" w=\"214\" /><ent r=\"3\" t=\"113\" w=\"230\" /><ent r=\"4\" t=\"121\" w=\"541\" /><ent r=\"4\" t=\"198\" w=\"116\" /></phr></stem><stem n=\"counterclockwis\"><phr n=\"counterclockwise\"><ent r=\"3\" t=\"113\" w=\"215\" /></phr></stem><stem n=\"greatest\"><phr n=\"greatest\"><ent r=\"3\" t=\"113\" w=\"217\" /></phr></stem><stem n=\"clockwis\"><phr
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text, with very long lines (28156), with CRLF line terminators
    Category:dropped
    Size (bytes):28249
    Entropy (8bit):4.020290519648517
    Encrypted:false
    SSDEEP:768:dkEWfOLNPnpGCmeOWzuZEEGnQEY0F5z5odcS9bpIaVYKXzPB8230IoBYH8ei6ytA:DKmHbKv9yICFpM3PSD1BNvDI/lUC
    MD5:618485910308634AC056B03CA2B1D039
    SHA1:E338C808ABED6B40C68C091E521329E1DDD10342
    SHA-256:F096A959491B351D2F6B1925A42DC98C21AE7F806219FC0B04F55DF9C9E2CBA8
    SHA-512:83EE59903436CA310B8C34034ECB4AAC673616D257E74C291E56FA857EDF5FCA69A2133B6918B7821C0D1017E281CCC6AD36F05282503DD3D0A5CD96F815CDD0
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="utf-8"?><index> saved from url=(0016)http://localhost -->..<stem n="datafil"><phr n="datafiles"><ent r="5" t="3" w="658" /><ent r="3" t="5" w="49" /><ent r="3" t="36" w="76" /><ent r="4" t="36" w="248" /><ent r="3" t="39" w="25" /><ent r="4" t="46" w="432" /><ent r="3" t="62" w="14" /><ent r="4" t="62" w="60" /><ent r="4" t="62" w="80" /><ent r="4" t="76" w="92" /><ent r="4" t="78" w="63" /><ent r="3" t="86" w="381" /><ent r="3" t="95" w="15" /><ent r="4" t="95" w="52" /><ent r="3" t="96" w="416" /><ent r="3" t="98" w="384" /><ent r="3" t="151" w="1525" /><ent r="4" t="156" w="538" /><ent r="4" t="158" w="117" /><ent r="3" t="161" w="18" /><ent r="5" t="161" w="77" /><ent r="3" t="165" w="26" /><ent r="3" t="177" w="49" /><ent r="4" t="177" w="784" /><ent r="4" t="177" w="1041" /><ent r="4" t="177" w="1229" /><ent r="4" t="183" w="573" /><ent r="3" t="187" w="57" /><ent r="3" t="187" w="70" /></phr><phr n="datafile"><ent r="3" t="4" w="92" /><ent r="3"
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text, with very long lines (26490), with CRLF line terminators
    Category:dropped
    Size (bytes):26583
    Entropy (8bit):4.0367824964340056
    Encrypted:false
    SSDEEP:768:kmcx2k1U/171PWsorlSTs00NHoB70XfAE6KBX5WtolF/ejf+piifzUflx1cnm2zp:54aQxlmgU0jmFkubFiUzwXXvc+y9y1N9
    MD5:461808D94EAAA1DA89A8457F5CFA2AD8
    SHA1:ED13AFE172FBE44B1497AA08E5964CFCEE73CFF9
    SHA-256:0C98708833917D049519CE46016A7609A2C7B2DFC1A2272BE60A5DA02DA439BB
    SHA-512:C1DC5589BCFBCD70B7CF7385A488D24173BC7060605184E6FC1B50B37494DB2509430670FA31761286B834259C20D60B58D9BEBEE3F3471412B1C5159BC7F862
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="utf-8"?><index> saved from url=(0016)http://localhost -->..<stem n="scroll"><phr n="scroll"><ent r="3" t="4" w="199" /><ent r="3" t="42" w="154" /><ent r="4" t="80" w="609" /><ent r="4" t="104" w="520" /><ent r="4" t="139" w="176" /><ent r="4" t="154" w="739" /><ent r="4" t="154" w="761" /><ent r="3" t="168" w="337" /></phr><phr n="scrolling"><ent r="3" t="42" w="163" /><ent r="4" t="49" w="178" /></phr></stem><stem n="move"><phr n="move"><ent r="3" t="4" w="202" /><ent r="4" t="26" w="428" /><ent r="4" t="40" w="116" /><ent r="4" t="42" w="68" /><ent r="4" t="42" w="340" /><ent r="3" t="43" w="504" /><ent r="3" t="43" w="562" /><ent r="3" t="55" w="430" /><ent r="3" t="55" w="443" /><ent r="3" t="56" w="179" /><ent r="3" t="56" w="312" /><ent r="3" t="56" w="326" /><ent r="3" t="56" w="344" /><ent r="4" t="57" w="89" /><ent r="3" t="100" w="480" /><ent r="3" t="118" w="343" /><ent r="3" t="118" w="407" /><ent r="4" t="135" w="45" /><ent r="4" t="135"
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:exported SGML document, ASCII text, with very long lines (31999), with CRLF line terminators
    Category:dropped
    Size (bytes):32243
    Entropy (8bit):4.0307609519595795
    Encrypted:false
    SSDEEP:768:6EejaEoAE8MxSVvZ2RLOcM5TTOoo1dDp7WCTJ75ZL1hHpSYrFwuX8bokgj7sgokm:oA5jHyAQfPdZmXuau8uputumurzW5im4
    MD5:449A0D0E431250B94CDBB91971E396EA
    SHA1:8139438E1743FE556C2C9C41CAA0ACC584E8ACD5
    SHA-256:6296D225039222CE243C519024485058FA8D45CD0C231736AC507FE71FACEC3C
    SHA-512:3DFFAE6550F8926B32C3A83F2306313271BE33D51DD5976AE978875DFCF46AA15326F5038010AA4E286A9467A5788104614F25D6F1EC261AB7D5704EBEF28B47
    Malicious:false
    Reputation:low
    Preview:var xmlSearch_Chunk34Data = "";..xmlSearch_Chunk34Data += '<?xml version=\"1.0\" encoding=\"utf-8\"?><index> saved from url=(0016)http://localhost -->';..xmlSearch_Chunk34Data += '<stem n=\"tabl\"><phr n=\"table\"><ent r=\"4\" t=\"3\" w=\"314\" /><ent r=\"5\" t=\"3\" w=\"409\" /><ent r=\"3\" t=\"4\" w=\"95\" /><ent r=\"1048578\" t=\"4\" w=\"105\" /><ent r=\"3\" t=\"4\" w=\"109\" /><ent r=\"3\" t=\"4\" w=\"127\" /><ent r=\"3\" t=\"4\" w=\"149\" /><ent r=\"3\" t=\"4\" w=\"211\" /><ent r=\"3\" t=\"4\" w=\"233\" /><ent r=\"3\" t=\"4\" w=\"246\" /><ent r=\"3\" t=\"4\" w=\"272\" /><ent r=\"3\" t=\"4\" w=\"280\" /><ent r=\"3\" t=\"4\" w=\"283\" /><ent r=\"3\" t=\"4\" w=\"296\" /><ent r=\"3\" t=\"4\" w=\"319\" /><ent r=\"3\" t=\"4\" w=\"473\" /><ent r=\"3\" t=\"4\" w=\"489\" /><ent r=\"3\" t=\"4\" w=\"560\" /><ent r=\"3\" t=\"4\" w=\"583\" /><ent r=\"3\" t=\"24\" w=\"1052\" /><ent r=\"3\" t=\"29\" w=\"119\" /><ent r=\"4\" t=\"37\" w=\"451\" /><ent r=\"3\" t=\"42\" w=\"131\" /><ent r=\"3\"
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text, with very long lines (30328), with CRLF line terminators
    Category:dropped
    Size (bytes):30421
    Entropy (8bit):3.984726968899729
    Encrypted:false
    SSDEEP:768:CNDDnwcO9ZlzM/HqgcfoyOIfW5AhU2M5ctA8WY5PjvH/JLkMY6+UR4fK3Qtelxyf:vxOX8x7WlNORa1UHjUECqLE
    MD5:39F3A33202BF062F30489837F5BCCD0E
    SHA1:9735FFEF02C62CBA96F529C5CA5A6A5C3EF7AB36
    SHA-256:79A4DDDD2104737B5D920B005288B8AEDDF8ED7D437919D61CB6E7619DE3647C
    SHA-512:4E0B23995872EB63014239F0407A2445A56D0B3036EFBAE3D431EA9D6B7F37E4997FC1B71D8F4C0F32C2843026A3A85DA9D6DB87BD6FD15E90849C921AC17D01
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="utf-8"?><index> saved from url=(0016)http://localhost -->..<stem n="applic"><phr n="applications"><ent r="4" t="2" w="275" /><ent r="4" t="2" w="336" /><ent r="4" t="3" w="1318" /><ent r="4" t="66" w="486" /><ent r="4" t="71" w="1263" /><ent r="3" t="73" w="44" /><ent r="3" t="76" w="36" /><ent r="3" t="78" w="32" /><ent r="3" t="126" w="138" /><ent r="3" t="168" w="253" /><ent r="4" t="174" w="288" /><ent r="3" t="183" w="613" /></phr><phr n="applicable"><ent r="4" t="3" w="1414" /><ent r="4" t="12" w="300" /><ent r="4" t="14" w="562" /><ent r="4" t="16" w="318" /><ent r="3" t="24" w="1003" /><ent r="3" t="28" w="673" /><ent r="6" t="29" w="262" /><ent r="4" t="31" w="337" /><ent r="5" t="33" w="277" /><ent r="5" t="33" w="334" /><ent r="5" t="33" w="375" /><ent r="5" t="33" w="660" /><ent r="4" t="33" w="936" /><ent r="4" t="37" w="311" /><ent r="4" t="46" w="136" /><ent r="4" t="47" w="123" /><ent r="4" t="62" w="229" /><ent r="4" t="72" w="215" /><
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:exported SGML document, ASCII text, with very long lines (32865), with CRLF line terminators
    Category:dropped
    Size (bytes):33105
    Entropy (8bit):4.086135442711296
    Encrypted:false
    SSDEEP:768:Kkz04eHZQE2Q9EWiew8uiL0vHG0gxEyh8tCTMlyFrRvdqUk2zT426wU4YoCbjmVO:rAeKT+wG3
    MD5:220746BCF6A137F462CD778F8A03222F
    SHA1:F4761484205B33576BA7CFAA7495B19F64601D20
    SHA-256:210E205A1F8DF883D876D5056B8FC89A9FD8C7AE8510CBF4B39568B9204D34F5
    SHA-512:041D34521D53C10B4F5A53E71625CB8AAC1B4220A7804F42762866BDB72707529D519CB4A3907E12FF9C9B22DABDFC73C440FB8DEEA6361950ACBC64F5C2AA31
    Malicious:false
    Reputation:low
    Preview:var xmlSearch_Chunk7Data = "";..xmlSearch_Chunk7Data += '<?xml version=\"1.0\" encoding=\"utf-8\"?><index> saved from url=(0016)http://localhost -->';..xmlSearch_Chunk7Data += '<stem n=\"guid\"><phr n=\"guide\"><ent r=\"5\" t=\"0\" w=\"64\" /><ent r=\"5\" t=\"0\" w=\"68\" /><ent r=\"4\" t=\"7\" w=\"138\" /><ent r=\"3\" t=\"7\" w=\"308\" /><ent r=\"4\" t=\"15\" w=\"72\" /><ent r=\"4\" t=\"81\" w=\"353\" /><ent r=\"3\" t=\"94\" w=\"93\" /><ent r=\"4\" t=\"98\" w=\"327\" /><ent r=\"4\" t=\"103\" w=\"54\" /><ent r=\"4\" t=\"103\" w=\"81\" /><ent r=\"3\" t=\"113\" w=\"259\" /></phr><phr n=\"guides\"><ent r=\"4\" t=\"3\" w=\"108\" /><ent r=\"4\" t=\"3\" w=\"812\" /><ent r=\"4\" t=\"3\" w=\"973\" /></phr></stem><stem n=\"user\'\"><phr n=\"user\'s\"><ent r=\"5\" t=\"0\" w=\"67\" /><ent r=\"4\" t=\"15\" w=\"71\" /></phr></stem><stem n=\"version\"><phr n=\"version\"><ent r=\"4\" t=\"0\" w=\"72\" /><ent r=\"3\" t=\"2\" w=\"196\" /><ent r=\"3\" t=\"3\" w=\"760\" /><ent r=\"3\" t=\"3\" w=\"779\
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text, with very long lines (28482), with CRLF line terminators
    Category:dropped
    Size (bytes):28575
    Entropy (8bit):4.0962576047549275
    Encrypted:false
    SSDEEP:768:QLChCKLOQKUW9Fip4P3jgsVo/J6ro/9GnVc/vK2LkyOu4MlVlxGYZUJv8zuF3Agf:eInS5TtfLTkUaKOY0qmFsFAi
    MD5:FB489CC3F6969675313285AD671DD571
    SHA1:CD87C5692A83E57EE042E8C6510C2BC7ED6CCB10
    SHA-256:1D67266D1A4769DA427D4FEB3D2136F7367DA5A3B2901EDABA89BC5507B9DAF6
    SHA-512:82B74FCE8FAFE2A03B8823663FC7F527B757F816C4581FAA0B8FB18F6C2D9BE9186F7F4D791FAE5DCA3EDE305D7137B57FD9AD6C9884E600F185C84F633D453F
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="utf-8"?><index> saved from url=(0016)http://localhost -->..<stem n="enabl"><phr n="enabled"><ent r="3" t="5" w="54" /><ent r="4" t="5" w="232" /><ent r="3" t="5" w="456" /><ent r="4" t="11" w="569" /><ent r="4" t="12" w="718" /><ent r="4" t="13" w="306" /><ent r="4" t="14" w="409" /><ent r="4" t="14" w="428" /><ent r="3" t="15" w="138" /><ent r="4" t="15" w="573" /><ent r="4" t="15" w="607" /><ent r="4" t="15" w="649" /><ent r="4" t="15" w="701" /><ent r="4" t="16" w="247" /><ent r="4" t="24" w="102" /><ent r="4" t="24" w="815" /><ent r="5" t="25" w="375" /><ent r="3" t="28" w="38" /><ent r="3" t="28" w="122" /><ent r="3" t="28" w="148" /><ent r="4" t="28" w="478" /><ent r="6" t="29" w="248" /><ent r="6" t="29" w="343" /><ent r="4" t="30" w="205" /><ent r="4" t="46" w="363" /><ent r="4" t="46" w="384" /><ent r="4" t="51" w="471" /><ent r="4" t="56" w="374" /><ent r="4" t="76" w="474" /><ent r="3" t="80" w="531" /><ent r="3" t="98" w="421" /><ent r="3"
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:exported SGML document, ASCII text, with very long lines (35429), with CRLF line terminators
    Category:dropped
    Size (bytes):35673
    Entropy (8bit):3.997785516693443
    Encrypted:false
    SSDEEP:768:PvZ8owWqtac08ic7l/fPQJzWajpjV8jKLgVhTOJcVl4r0CzeYWMJfry3C7FRSdBv:3ZkqPsSiOMFd+YHyMzUm5
    MD5:C055099A1109D2C0D0D08991D81030DB
    SHA1:60B187706EE0BE083A7237CFE9A0722D6C724753
    SHA-256:820B15F3B2DD6D27BC8E8A4B44376AAAE0E04781225B2F0BD22B6A4870387A28
    SHA-512:C34D1CB572CB02DA916E429F622DA9D5FD60AF292EAA0A7605476AEA473C0FA0113CBEA8C54261D18FCEA0E6BB09D8C170FD53B617D2BE294413BB45FAD0CF17
    Malicious:false
    Reputation:low
    Preview:var xmlSearch_Chunk14Data = "";..xmlSearch_Chunk14Data += '<?xml version=\"1.0\" encoding=\"utf-8\"?><index> saved from url=(0016)http://localhost -->';..xmlSearch_Chunk14Data += '<stem n=\"time-sav\"><phr n=\"time-saving\"><ent r=\"4\" t=\"1\" w=\"110\" /><ent r=\"4\" t=\"7\" w=\"933\" /><ent r=\"3\" t=\"9\" w=\"549\" /><ent r=\"4\" t=\"10\" w=\"926\" /><ent r=\"3\" t=\"10\" w=\"1363\" /><ent r=\"4\" t=\"11\" w=\"759\" /><ent r=\"3\" t=\"11\" w=\"1461\" /><ent r=\"4\" t=\"12\" w=\"885\" /><ent r=\"3\" t=\"12\" w=\"1491\" /><ent r=\"4\" t=\"13\" w=\"841\" /><ent r=\"3\" t=\"13\" w=\"1252\" /><ent r=\"4\" t=\"14\" w=\"895\" /><ent r=\"3\" t=\"14\" w=\"1516\" /><ent r=\"4\" t=\"15\" w=\"843\" /><ent r=\"3\" t=\"15\" w=\"1262\" /><ent r=\"4\" t=\"16\" w=\"1064\" /><ent r=\"3\" t=\"16\" w=\"1289\" /><ent r=\"4\" t=\"17\" w=\"1094\" /><ent r=\"3\" t=\"17\" w=\"1439\" /><ent r=\"4\" t=\"20\" w=\"173\" /><ent r=\"3\" t=\"20\" w=\"304\" /><ent r=\"4\" t=\"36\" w=\"423\" /><ent r=\"4\" t=\"
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text, with very long lines (27935), with CRLF line terminators
    Category:dropped
    Size (bytes):28028
    Entropy (8bit):4.059707073660739
    Encrypted:false
    SSDEEP:768:mjyQfZg4LcAOrkRK3ezFC/fLTh45BENhwQkeKuzw63BrB7TlFdHv5HXkJSzh+rl9:HgVjrwKe6oxqWTpRLO/pk7SsMH
    MD5:213A76AC513B6FC43EACE9CC5F58D63C
    SHA1:98C272DBF3FE9D88753BF41C97375C07FE8594F0
    SHA-256:A3D571E45C2E67635D8275FB88C3882AC0887807B465EEFB20A3E85A02E811D7
    SHA-512:FDA42BAB5B297FA440B7FDEA8D09660E1AB491D448B437F1107CA10E4F315588CB46711F25B3D30C7617A6ED1C173AB40BFC3C460E4B3E093A5B53C420D5F202
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="utf-8"?><index> saved from url=(0016)http://localhost -->..<stem n="topic"><phr n="topics"><ent r="3" t="1" w="285" /><ent r="3" t="9" w="590" /><ent r="3" t="75" w="40" /><ent r="3" t="84" w="11" /><ent r="3" t="128" w="501" /><ent r="3" t="130" w="449" /><ent r="4" t="131" w="321" /><ent r="3" t="138" w="20" /><ent r="1048578" t="171" w="677" /></phr><phr n="topic"><ent r="3" t="104" w="14" /><ent r="5" t="104" w="580" /><ent r="3" t="127" w="99" /><ent r="3" t="129" w="257" /></phr></stem><stem n="instal"><phr n="installing"><ent r="268435456" t="2" w="1" /><ent r="16777218" t="2" w="4" /><ent r="1048578" t="2" w="89" /><ent r="3" t="2" w="118" /><ent r="1048578" t="2" w="128" /><ent r="1048578" t="66" w="745" /><ent r="3" t="99" w="247" /><ent r="4" t="169" w="101" /></phr><phr n="install"><ent r="3" t="2" w="11" /><ent r="3" t="2" w="86" /><ent r="3" t="2" w="214" /><ent r="3" t="2" w="229" /><ent r="4" t="2" w="257" /><ent r="4" t="3" w="1228" />
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:exported SGML document, ASCII text, with very long lines (32569), with CRLF line terminators
    Category:dropped
    Size (bytes):32813
    Entropy (8bit):4.142145911207376
    Encrypted:false
    SSDEEP:768:/N99g+dDkTpp99AA44qqm0mRfgb3Tj8w8zzjjaaTBfG2zfxa2eYBN/oz4ncYYsX1:VZravSvrUc
    MD5:ED4D2DAE0368D381CE35ABE53D83539C
    SHA1:C797B0090939703017603BED723E9F7AFBDB94FA
    SHA-256:0E5EDB4B3286A01E2AB38870A89669BDF6A618E393B614AECC0609C3A23232F4
    SHA-512:66CEB9D969F7325175E402ADE03B08F3F1B35E4E0110FBC38F7F48EE37F132DF3D6A3C6E785A39DE2FA4947616C85BCC5A87C95A4DFA07EB1F04B71CE5D1BDF2
    Malicious:false
    Reputation:low
    Preview:var xmlSearch_Chunk77Data = "";..xmlSearch_Chunk77Data += '<?xml version=\"1.0\" encoding=\"utf-8\"?><index> saved from url=(0016)http://localhost -->';..xmlSearch_Chunk77Data += '<stem n=\"chan\"><phr n=\"Chan\"><ent r=\"3\" t=\"23\" w=\"1166\" /><ent r=\"3\" t=\"23\" w=\"1166\" /><ent r=\"3\" t=\"23\" w=\"1171\" /><ent r=\"3\" t=\"23\" w=\"1171\" /><ent r=\"3\" t=\"23\" w=\"1185\" /><ent r=\"3\" t=\"23\" w=\"1185\" /></phr></stem><stem n=\"furthest\"><phr n=\"furthest\"><ent r=\"3\" t=\"23\" w=\"1195\" /><ent r=\"3\" t=\"23\" w=\"1195\" /></phr></stem><stem n=\"prevent\"><phr n=\"prevents\"><ent r=\"3\" t=\"24\" w=\"48\" /><ent r=\"3\" t=\"24\" w=\"48\" /></phr><phr n=\"prevent\"><ent r=\"3\" t=\"25\" w=\"259\" /><ent r=\"3\" t=\"25\" w=\"259\" /><ent r=\"4\" t=\"25\" w=\"436\" /><ent r=\"4\" t=\"25\" w=\"436\" /><ent r=\"3\" t=\"40\" w=\"162\" /><ent r=\"3\" t=\"40\" w=\"162\" /><ent r=\"3\" t=\"58\" w=\"119\" /><ent r=\"3\" t=\"58\" w=\"119\" /><ent r=\"3\" t=\"64\" w=\"608\" /
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:exported SGML document, ASCII text, with very long lines (32014), with CRLF line terminators
    Category:dropped
    Size (bytes):32258
    Entropy (8bit):3.9714239824177127
    Encrypted:false
    SSDEEP:768:XOW8OlOm7bjBovb5Ke1nPyczakMFTPHMbgz/DJTlmqjg5IkyelLmhvjQzLtMd1fG:3LVQEsF7jS9E5Oa
    MD5:D4629A45AB40C166C57E524FAADDCFBE
    SHA1:C7FC8FB2C05157206EAED9B9136148A985E18363
    SHA-256:B14496F886EC50790CA8651E983EFD848946B8C38ED3D35128E61CFBFD017CBA
    SHA-512:F7F3EF1725FBC48751804D1E0A4CE8A4BB1BD978A6FC7DC4A91E6364228032F0BDC3996D595DFCED5BACCA50C87E0FD07C62001896536E2AB2B665B1C17DF090
    Malicious:false
    Reputation:low
    Preview:var xmlSearch_Chunk11Data = "";..xmlSearch_Chunk11Data += '<?xml version=\"1.0\" encoding=\"utf-8\"?><index> saved from url=(0016)http://localhost -->';..xmlSearch_Chunk11Data += '<stem n=\"project\"><phr n=\"project\"><ent r=\"3\" t=\"1\" w=\"46\" /><ent r=\"4\" t=\"5\" w=\"174\" /><ent r=\"4\" t=\"6\" w=\"256\" /><ent r=\"3\" t=\"38\" w=\"18\" /><ent r=\"3\" t=\"38\" w=\"209\" /><ent r=\"4\" t=\"38\" w=\"218\" /><ent r=\"4\" t=\"38\" w=\"222\" /><ent r=\"3\" t=\"39\" w=\"55\" /><ent r=\"3\" t=\"45\" w=\"88\" /><ent r=\"3\" t=\"45\" w=\"97\" /><ent r=\"3\" t=\"45\" w=\"161\" /><ent r=\"5\" t=\"48\" w=\"98\" /><ent r=\"3\" t=\"60\" w=\"262\" /><ent r=\"4\" t=\"62\" w=\"279\" /><ent r=\"268435456\" t=\"65\" w=\"2\" /><ent r=\"16777218\" t=\"65\" w=\"6\" /><ent r=\"3\" t=\"65\" w=\"10\" /><ent r=\"3\" t=\"65\" w=\"32\" /><ent r=\"3\" t=\"65\" w=\"44\" /><ent r=\"3\" t=\"65\" w=\"77\" /><ent r=\"3\" t=\"65\" w=\"86\" /><ent r=\"3\" t=\"65\" w=\"90\" /><ent r=\"3\" t=\"70\" w=\"625\" /
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text, with very long lines (32767), with CRLF line terminators
    Category:dropped
    Size (bytes):32860
    Entropy (8bit):3.922241875285846
    Encrypted:false
    SSDEEP:768:dzOYQXOqnp+f58E1g1i1Uo1CT2yGnyjgwkKOpZi/7bCuAZzlLJ34tAsXANuM/p4y:J02UcWnKypQ4WCK1EWSY2q2GXRwntyz
    MD5:D186FE9825BC5F87FD9DE8E1652C2322
    SHA1:BF5E962A26B5C8A17E3A4606A278176EEF6A3CE1
    SHA-256:BEA1F93CC2425C478CBA1A0AD700AA1EA58D3E30EC723C54773ECC2F5D05EEE5
    SHA-512:9CF9A58773E2A84B27FC77577A821DB768A908F3F8DEE2717668B407B51AD6547B82BA05E25B949D5E89B02FDC874182332592F4112FE23521D828DB86DB4E6F
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="utf-8"?><index> saved from url=(0016)http://localhost -->..<stem n="read"><phr n="reading"><ent r="5" t="0" w="33" /><ent r="3" t="1" w="17" /><ent r="5" t="1" w="300" /><ent r="4" t="3" w="639" /><ent r="4" t="4" w="764" /><ent r="3" t="5" w="622" /><ent r="5" t="5" w="630" /><ent r="5" t="5" w="663" /><ent r="5" t="5" w="703" /><ent r="5" t="5" w="738" /><ent r="5" t="5" w="775" /><ent r="4" t="6" w="176" /><ent r="4" t="10" w="599" /><ent r="3" t="23" w="74" /><ent r="3" t="24" w="17" /><ent r="4" t="24" w="209" /><ent r="4" t="24" w="218" /><ent r="4" t="24" w="262" /><ent r="4" t="24" w="272" /><ent r="3" t="24" w="359" /><ent r="3" t="24" w="402" /><ent r="4" t="24" w="528" /><ent r="4" t="24" w="638" /><ent r="4" t="24" w="651" /><ent r="3" t="28" w="217" /><ent r="4" t="28" w="552" /><ent r="3" t="29" w="184" /><ent r="4" t="30" w="280" /><ent r="4" t="30" w="327" /><ent r="4" t="30" w="417" /><ent r="4" t="30" w="596" /><ent r="4" t="30" w="63
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:exported SGML document, ASCII text, with very long lines (37944), with CRLF line terminators
    Category:dropped
    Size (bytes):38188
    Entropy (8bit):3.988384597676978
    Encrypted:false
    SSDEEP:768:29PKJ7pdwX9+wnBa0X0WbRDEdmWkt+vOfrU54cdNEpYke3AwQ1oUzpL7vGgvn3MR:dpvw+WADn
    MD5:0B7E4C598252C11BD6ED59331984A305
    SHA1:6E32BA903F78360A55F51AE715219961B077ACCF
    SHA-256:24F447980CFAC4753FA036E7D170466AB70DAF97864289216EA926F8DA975F78
    SHA-512:5D51C42D5094C61A9A0D60853D211EBD344C88B02927EDA78D00D7C9EA5C7E1288ED69B624D958F07737194E51F7766FB47EE5061D41F4DA3782C25A2739DB6F
    Malicious:false
    Reputation:low
    Preview:var xmlSearch_Chunk28Data = "";..xmlSearch_Chunk28Data += '<?xml version=\"1.0\" encoding=\"utf-8\"?><index> saved from url=(0016)http://localhost -->';..xmlSearch_Chunk28Data += '<stem n=\"period\"><phr n=\"periodically\"><ent r=\"3\" t=\"2\" w=\"592\" /><ent r=\"3\" t=\"66\" w=\"661\" /><ent r=\"3\" t=\"124\" w=\"55\" /><ent r=\"3\" t=\"125\" w=\"79\" /><ent r=\"3\" t=\"126\" w=\"91\" /><ent r=\"3\" t=\"143\" w=\"16\" /><ent r=\"3\" t=\"171\" w=\"600\" /></phr><phr n=\"period\"><ent r=\"4\" t=\"14\" w=\"608\" /><ent r=\"4\" t=\"24\" w=\"590\" /><ent r=\"4\" t=\"25\" w=\"271\" /><ent r=\"3\" t=\"27\" w=\"35\" /><ent r=\"3\" t=\"28\" w=\"209\" /><ent r=\"4\" t=\"31\" w=\"335\" /><ent r=\"4\" t=\"31\" w=\"364\" /><ent r=\"3\" t=\"31\" w=\"418\" /><ent r=\"4\" t=\"31\" w=\"651\" /><ent r=\"4\" t=\"58\" w=\"38\" /><ent r=\"4\" t=\"61\" w=\"338\" /><ent r=\"4\" t=\"61\" w=\"372\" /><ent r=\"4\" t=\"61\" w=\"386\" /><ent r=\"3\" t=\"68\" w=\"542\" /><ent r=\"5\" t=\"69\" w=\"464\" /><en
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:exported SGML document, ASCII text, with very long lines (32455), with CRLF line terminators
    Category:dropped
    Size (bytes):32699
    Entropy (8bit):4.25859945217908
    Encrypted:false
    SSDEEP:768:0H9PeyD0zo0uiMPa/1EXPTI0xxcP4vuweRX0o+O4FlCyP+oTZqPv/ooUborvsEo6:E8/8w2YpC/u2nGuFdxiIyLz
    MD5:9A1FE72CCE3811EE1F3EC7F8EFAF6F0F
    SHA1:EF99B1438DE1A05935CAC2EC884DA3D214EE9159
    SHA-256:F57887B60103D07A0B05B59D569415AAE7C5E3DD609FF50FCAE4B9E19656C7C9
    SHA-512:0D8445D5AE9C3779CF39DBDDB0C7FF26A9D1E8E2CCDD6AE927BE364C6CC628C8141EAC9DC3F6ECB1B075B205B27309062881F6ABD61D32C1E9B563A2061B935A
    Malicious:false
    Reputation:low
    Preview:var xmlSearch_Chunk53Data = "";..xmlSearch_Chunk53Data += '<?xml version=\"1.0\" encoding=\"utf-8\"?><index> saved from url=(0016)http://localhost -->';..xmlSearch_Chunk53Data += '<stem n=\"compar\"><phr n=\"compares\"><ent r=\"3\" t=\"29\" w=\"120\" /><ent r=\"3\" t=\"182\" w=\"53\" /></phr><phr n=\"compare\"><ent r=\"3\" t=\"46\" w=\"72\" /></phr><phr n=\"comparing\"><ent r=\"5\" t=\"51\" w=\"529\" /><ent r=\"4\" t=\"122\" w=\"232\" /></phr></stem><stem n=\"best\"><phr n=\"best\"><ent r=\"3\" t=\"29\" w=\"132\" /><ent r=\"3\" t=\"31\" w=\"98\" /><ent r=\"4\" t=\"31\" w=\"119\" /><ent r=\"4\" t=\"31\" w=\"591\" /><ent r=\"4\" t=\"31\" w=\"846\" /><ent r=\"5\" t=\"69\" w=\"298\" /><ent r=\"4\" t=\"71\" w=\"683\" /><ent r=\"3\" t=\"113\" w=\"236\" /><ent r=\"4\" t=\"137\" w=\"187\" /><ent r=\"4\" t=\"137\" w=\"280\" /><ent r=\"4\" t=\"146\" w=\"130\" /><ent r=\"4\" t=\"147\" w=\"194\" /><ent r=\"3\" t=\"176\" w=\"228\" /><ent r=\"3\" t=\"177\" w=\"483\" /></phr></stem><stem n=\"solu
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text, with very long lines (26878), with CRLF line terminators
    Category:dropped
    Size (bytes):26971
    Entropy (8bit):3.949570308443081
    Encrypted:false
    SSDEEP:768:CUJ8Zr/VVL4t6JoZ1XpREL3wyizoZZ3RW2nNp1MnaR3PH3B3ehed4Sg/3e/y9nDH:vs26GrzMXzjJTewNEp
    MD5:5517B9BF1F5F0451A356DB76A41975B7
    SHA1:A65FF9BFFDE007F3BD509C2E2EFD8B22748D8D66
    SHA-256:B2D302B379B53EA2E66C8B48062D83B42B7409281F7DECA0D8683D891B5DFCCB
    SHA-512:2531F5690C72F53D970138186BF96CBC89CBE67EA7C5BF77F3DF58C52D2CC68249A1A394C478D00DDF0A458B66CFA63C9765BE65E63F147382A6EEF639388B9B
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="utf-8"?><index> saved from url=(0016)http://localhost -->..<stem n="double-click"><phr n="double-click"><ent r="4" t="2" w="170" /><ent r="4" t="2" w="263" /><ent r="4" t="2" w="295" /><ent r="4" t="2" w="304" /><ent r="3" t="4" w="728" /><ent r="3" t="22" w="209" /><ent r="3" t="23" w="143" /><ent r="4" t="38" w="89" /><ent r="4" t="40" w="329" /><ent r="3" t="41" w="93" /><ent r="4" t="43" w="347" /><ent r="3" t="43" w="631" /><ent r="4" t="50" w="51" /><ent r="4" t="51" w="53" /><ent r="4" t="52" w="24" /><ent r="4" t="53" w="24" /><ent r="4" t="55" w="80" /><ent r="3" t="56" w="213" /><ent r="4" t="61" w="205" /><ent r="4" t="61" w="267" /><ent r="4" t="61" w="354" /><ent r="3" t="66" w="164" /><ent r="4" t="89" w="256" /><ent r="5" t="104" w="83" /><ent r="3" t="106" w="133" /><ent r="4" t="107" w="276" /><ent r="4" t="108" w="229" /><ent r="4" t="109" w="36" /><ent r="4" t="139" w="83" /><ent r="4" t="139" w="160" /><ent r="3" t="140" w="107" /><
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text, with very long lines (42337), with CRLF line terminators
    Category:dropped
    Size (bytes):42430
    Entropy (8bit):3.938663139996884
    Encrypted:false
    SSDEEP:768:aBVo39BRg8MyXJtyfULPBHRa8/6ABNLf7ltUUk9EBKM4Dbi1BjqoZfDBGBnBb3yM:aw3G4J2BjCrW1N0bP6EqkPKAFryKbNOn
    MD5:F6E2D3D844C48DC16572EC5A04A6CD62
    SHA1:DA1C800D8482BBF87C90958240B62F993178C8F1
    SHA-256:064A5931193C1D8A0DDA83FF29A353D30BC25668BD34D27921F1B761D5A13CD5
    SHA-512:1F30DE3612B2EF7E028E186DDF364C5229E93A6BD9B221D007D026102154D1D4F0AA7C6DC0436C8B67FBC6C825EB0EE03E4249F36A46DB51A0A81D8D22DE2535
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="utf-8"?><index> saved from url=(0016)http://localhost -->..<stem n="u-shuttl"><phr n="u-shuttle"><ent r="4" t="1" w="91" /><ent r="3" t="94" w="28" /><ent r="3" t="94" w="184" /><ent r="65538" t="94" w="246" /><ent r="3" t="94" w="260" /><ent r="4" t="94" w="285" /><ent r="5" t="95" w="77" /><ent r="3" t="96" w="21" /><ent r="4" t="96" w="43" /><ent r="10" t="96" w="167" /><ent r="4" t="96" w="180" /><ent r="10" t="96" w="193" /><ent r="4" t="96" w="212" /><ent r="4" t="96" w="491" /><ent r="3" t="97" w="151" /><ent r="3" t="97" w="205" /><ent r="3" t="97" w="218" /><ent r="4" t="167" w="130" /><ent r="5" t="167" w="163" /></phr></stem><stem n="shuttl"><phr n="shuttle"><ent r="4" t="1" w="92" /><ent r="4" t="1" w="95" /><ent r="4" t="6" w="155" /><ent r="4" t="7" w="128" /><ent r="1048578" t="7" w="236" /><ent r="3" t="7" w="243" /><ent r="3" t="7" w="297" /><ent r="3" t="7" w="305" /><ent r="4" t="19" w="116" /><ent r="4" t="19" w="141" /><ent r="3" t
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text, with very long lines (26506), with CRLF line terminators
    Category:dropped
    Size (bytes):26599
    Entropy (8bit):3.9724060617390458
    Encrypted:false
    SSDEEP:768:Wm9oBCKjSJNTByB+51yHyqo4YMnSKyrfjY561UuyU3y17ubT3H9NAi4xbJZADU5b:mWGrdGHQQo8GOMQyesqltDloT7
    MD5:1DAB7791BAD4907C6BF6ECA37DCB1D2B
    SHA1:7F42738B0D35FB25AFB41A75F27E7170B7C36AD7
    SHA-256:099E27D5728C517927A3074E6739978C7020850E01B8E26099BEECFF6EDDAE81
    SHA-512:86E66362D22F28A81B888CCC4FC5C125A3FCC68A3775FA610F2B85428D9610555A1BC4E1452E7D4C12B11612E86DFB6EF02993131B1C35F9D2CD10F8A17337CA
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="utf-8"?><index> saved from url=(0016)http://localhost -->..<stem n="ok"><phr n="ok"><ent r="3" t="2" w="380" /><ent r="4" t="2" w="665" /><ent r="4" t="5" w="227" /><ent r="4" t="7" w="419" /><ent r="4" t="7" w="496" /><ent r="3" t="7" w="696" /><ent r="4" t="20" w="191" /><ent r="4" t="24" w="844" /><ent r="4" t="28" w="616" /><ent r="4" t="30" w="728" /><ent r="4" t="47" w="61" /><ent r="4" t="47" w="126" /><ent r="5" t="58" w="145" /><ent r="6" t="71" w="472" /><ent r="4" t="76" w="173" /><ent r="4" t="77" w="96" /><ent r="3" t="78" w="149" /><ent r="4" t="79" w="149" /><ent r="4" t="80" w="247" /><ent r="4" t="81" w="362" /><ent r="4" t="81" w="479" /><ent r="4" t="88" w="283" /><ent r="4" t="90" w="549" /><ent r="4" t="91" w="452" /><ent r="4" t="107" w="304" /><ent r="4" t="108" w="260" /><ent r="4" t="109" w="318" /><ent r="5" t="120" w="139" /><ent r="4" t="121" w="508" /><ent r="4" t="121" w="791" /><ent r="4" t="123" w="736" /><ent r="3" t="1
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text, with very long lines (27007), with CRLF line terminators
    Category:dropped
    Size (bytes):27100
    Entropy (8bit):3.9366443885101243
    Encrypted:false
    SSDEEP:768:YqzFz6X7eebeYRTbmf6aUMCgHnF13gXd76SQf+y9PTkLOeOruCEgYGyOa9ENdukO:Iq/YjwPIORvU0BD05iVX/YRGMB/
    MD5:F107C0D2CDC7B4F9D15A9B66D6DE43B3
    SHA1:F9DBE53BF634E18577A0E51506B18C58C0F60138
    SHA-256:56702F6A352A0852FB014A42BCCCA0615C7F2B59A8A7440E5A91F72371406768
    SHA-512:53A5E760459CC7743598E05583141FF87F85518D3326E17282F0BB4358A05F171D8F0D3ED29FB7864DDAB7C06DF05059E0F929918A21F1F0592EB034BFFC4BFD
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="utf-8"?><index> saved from url=(0016)http://localhost -->..<stem n="if"><phr n="if"><ent r="4" t="2" w="154" /><ent r="3" t="2" w="190" /><ent r="3" t="2" w="210" /><ent r="4" t="2" w="493" /><ent r="3" t="2" w="584" /><ent r="3" t="2" w="594" /><ent r="3" t="2" w="690" /><ent r="3" t="3" w="772" /><ent r="3" t="4" w="71" /><ent r="3" t="4" w="235" /><ent r="3" t="4" w="289" /><ent r="3" t="4" w="553" /><ent r="3" t="4" w="667" /><ent r="4" t="5" w="113" /><ent r="4" t="5" w="125" /><ent r="4" t="5" w="131" /><ent r="4" t="5" w="183" /><ent r="3" t="5" w="463" /><ent r="4" t="7" w="158" /><ent r="4" t="7" w="378" /><ent r="3" t="7" w="421" /><ent r="4" t="7" w="558" /><ent r="3" t="7" w="637" /><ent r="3" t="7" w="772" /><ent r="3" t="7" w="781" /><ent r="4" t="7" w="823" /><ent r="4" t="7" w="902" /><ent r="3" t="8" w="42" /><ent r="6" t="8" w="62" /><ent r="4" t="8" w="118" /><ent r="6" t="8" w="213" /><ent r="3" t="9" w="489" /><ent r="4" t="10" w="
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:exported SGML document, ASCII text, with very long lines (33397), with CRLF line terminators
    Category:dropped
    Size (bytes):33641
    Entropy (8bit):4.131438810291378
    Encrypted:false
    SSDEEP:768:ofAAU2DJJDDLLzgzg88VV9o915oTlf5yJTTyyJJddJtoaNNhhHHMMCCZZXX++wwM:M6dZmBJIA
    MD5:0D779089D0677F7F6356174EDE55F97A
    SHA1:7BB2B3C0413A14DB4BA3BF92FC6FB5951EC97FFC
    SHA-256:FA82BE057D0CF99E0082ABED7C9684F0A2F725EA022BAA0DAFCE9811EB7E83BC
    SHA-512:48C016F021587EAC0DDD2A99DFC6E700D4899C9580B7BD9DF2EBC773FABB549D3C7C52558B3AB22BA1CE924737DBC77C6833D393D878DE8FA87DDA681A1246B3
    Malicious:false
    Reputation:low
    Preview:var xmlSearch_Chunk73Data = "";..xmlSearch_Chunk73Data += '<?xml version=\"1.0\" encoding=\"utf-8\"?><index> saved from url=(0016)http://localhost -->';..xmlSearch_Chunk73Data += '<stem n=\"carri\"><phr n=\"carried\"><ent r=\"6\" t=\"11\" w=\"1270\" /><ent r=\"6\" t=\"11\" w=\"1270\" /><ent r=\"6\" t=\"12\" w=\"1351\" /><ent r=\"6\" t=\"12\" w=\"1351\" /><ent r=\"6\" t=\"14\" w=\"1379\" /><ent r=\"6\" t=\"14\" w=\"1379\" /></phr></stem><stem n=\"regardless\"><phr n=\"regardless\"><ent r=\"6\" t=\"11\" w=\"1339\" /><ent r=\"6\" t=\"11\" w=\"1339\" /><ent r=\"4\" t=\"16\" w=\"258\" /><ent r=\"4\" t=\"16\" w=\"258\" /><ent r=\"4\" t=\"35\" w=\"279\" /><ent r=\"4\" t=\"35\" w=\"279\" /><ent r=\"4\" t=\"83\" w=\"548\" /><ent r=\"4\" t=\"83\" w=\"548\" /><ent r=\"4\" t=\"86\" w=\"85\" /><ent r=\"4\" t=\"86\" w=\"85\" /><ent r=\"4\" t=\"94\" w=\"110\" /><ent r=\"4\" t=\"94\" w=\"110\" /><ent r=\"4\" t=\"148\" w=\"498\" /><ent r=\"4\" t=\"148\" w=\"498\" /><ent r=\"4\" t=\"153\" w=\"808\"
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text, with very long lines (33137), with CRLF line terminators
    Category:dropped
    Size (bytes):33230
    Entropy (8bit):3.9698593706090897
    Encrypted:false
    SSDEEP:768:/e2W3+dI4M+MfKf7uMuJCEls57LZYIlarMoj2SDlg1rpwX8cVqlFwkKCrYVoG3vD:AOSRsnBgxFW6lco7RW0eCkjqkM3TOFHm
    MD5:8275F6B0522996F91538C8354187A695
    SHA1:90C3C9F235EF9FBA4CDDF453A432D0E0F5FB7E3F
    SHA-256:33B62C2785CEDA9FED34C17F792D3DF5626EF875CEFEEBB2E32F040A244645C9
    SHA-512:AA9C01DD07282651D79265DB758BA37708F8A2DD7BE875C4E4C662E77D1F5CA98A777C8F466AC9342DC22C2EF6D47D36DC8F60274961164EC24CA847C2A5578E
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="utf-8"?><index> saved from url=(0016)http://localhost -->..<stem n="via"><phr n="via"><ent r="4" t="3" w="33" /><ent r="4" t="3" w="1292" /><ent r="3" t="7" w="612" /><ent r="3" t="15" w="172" /><ent r="3" t="17" w="36" /><ent r="3" t="26" w="215" /><ent r="4" t="67" w="92" /><ent r="3" t="76" w="50" /><ent r="3" t="85" w="89" /><ent r="3" t="116" w="749" /><ent r="4" t="117" w="86" /><ent r="3" t="118" w="167" /><ent r="4" t="123" w="81" /><ent r="4" t="123" w="246" /><ent r="3" t="123" w="500" /><ent r="3" t="123" w="644" /><ent r="3" t="125" w="107" /><ent r="4" t="128" w="235" /><ent r="4" t="129" w="218" /><ent r="4" t="130" w="367" /><ent r="4" t="131" w="38" /><ent r="4" t="131" w="41" /><ent r="4" t="152" w="903" /><ent r="4" t="153" w="295" /><ent r="3" t="171" w="353" /><ent r="3" t="177" w="679" /><ent r="4" t="201" w="211" /></phr></stem><stem n="10"><phr n="10"><ent r="4" t="3" w="43" /><ent r="4" t="3" w="731" /><ent r="4" t="3" w="734" /
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text, with very long lines (27952), with CRLF line terminators
    Category:dropped
    Size (bytes):28045
    Entropy (8bit):4.010373043439651
    Encrypted:false
    SSDEEP:768:MB7nOO1uu66lTlUJfYYRRZt++ll6TTfn4PPdlXZMM99qqDDccSSDDRRRR77RRJJA:GZK4i6KuyqGD6Ox5EdHMU
    MD5:FB0E4A5D783D07F7825E87630344DF29
    SHA1:CF52893243436AA64BE6D725DDAE1CF7A34D420E
    SHA-256:80D409FDE83071C5E97DAF5D89F5A9BF6E991A30D2E8EFD6C4F41F980EEED8DB
    SHA-512:CFCF7EB6768B7464ABA405EFA17B16BA991EC05E21D9595C10AE91B50A5DA43808A42D972444A558E26DDB53D5B365CD3443D95059D50344835FE61FDEC63636
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="utf-8"?><index> saved from url=(0016)http://localhost -->..<stem n="involv"><phr n="involves"><ent r="3" t="6" w="18" /><ent r="3" t="6" w="18" /><ent r="4" t="9" w="342" /><ent r="4" t="9" w="342" /></phr><phr n="involve"><ent r="3" t="28" w="28" /><ent r="3" t="28" w="28" /></phr></stem><stem n="basic"><phr n="basic"><ent r="3" t="6" w="21" /><ent r="3" t="6" w="21" /></phr></stem><stem n="initi"><phr n="initial"><ent r="4" t="6" w="33" /><ent r="4" t="6" w="33" /><ent r="3" t="142" w="23" /><ent r="3" t="142" w="23" /><ent r="3" t="142" w="429" /><ent r="3" t="142" w="429" /><ent r="4" t="174" w="200" /><ent r="4" t="174" w="200" /></phr><phr n="initialization"><ent r="4" t="31" w="416" /><ent r="4" t="31" w="416" /></phr><phr n="initially"><ent r="3" t="77" w="27" /><ent r="3" t="77" w="27" /><ent r="3" t="103" w="48" /><ent r="3" t="103" w="48" /><ent r="3" t="138" w="38" /><ent r="3" t="138" w="38" /><ent r="3" t="139" w="37" /><ent r="3" t="139"
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:exported SGML document, ASCII text, with very long lines (32111), with CRLF line terminators
    Category:dropped
    Size (bytes):32355
    Entropy (8bit):4.3386207931571485
    Encrypted:false
    SSDEEP:768:vbGGdqwjjjj5E3NWUzEumIJZqEiUhWV5BjjTT3shrPP4GZDOYtMu1P5OtppoowuW:4Wt5laeb2DTmnIIUwE
    MD5:E0DE333C1FF18C76D54639AD4BCEE309
    SHA1:D5D3A23BAB8CADC282EB8397FEFEBB9A6A652404
    SHA-256:A44036898F3AFC671D6F42BF6890105E8F264FB0491BA03EBC66155D13A480E6
    SHA-512:27A729F8FF26769D6F2DAC9A7FF7946DFC54750D55A701907A86B0EB23A05CF0FC710280913A5881134A1B4BD5F19DC93AC520EBB948A395C936A9983B4CD3F5
    Malicious:false
    Reputation:low
    Preview:var xmlSearch_Chunk84Data = "";..xmlSearch_Chunk84Data += '<?xml version=\"1.0\" encoding=\"utf-8\"?><index> saved from url=(0016)http://localhost -->';..xmlSearch_Chunk84Data += '<stem n=\"resourc\"><phr n=\"resources\"><ent r=\"4\" t=\"79\" w=\"181\" /></phr></stem><stem n=\"incom\"><phr n=\"incoming\"><ent r=\"4\" t=\"79\" w=\"279\" /><ent r=\"4\" t=\"79\" w=\"279\" /><ent r=\"4\" t=\"100\" w=\"185\" /><ent r=\"4\" t=\"100\" w=\"185\" /><ent r=\"3\" t=\"145\" w=\"452\" /><ent r=\"3\" t=\"145\" w=\"452\" /></phr></stem><stem n=\"year\"><phr n=\"year\"><ent r=\"4\" t=\"79\" w=\"283\" /><ent r=\"4\" t=\"79\" w=\"283\" /><ent r=\"4\" t=\"149\" w=\"619\" /><ent r=\"4\" t=\"149\" w=\"619\" /><ent r=\"3\" t=\"153\" w=\"231\" /><ent r=\"3\" t=\"153\" w=\"231\" /><ent r=\"4\" t=\"153\" w=\"313\" /><ent r=\"4\" t=\"153\" w=\"327\" /><ent r=\"4\" t=\"153\" w=\"327\" /></phr><phr n=\"years\"><ent r=\"4\" t=\"96\" w=\"240\" /><ent r=\"4\" t=\"96\" w=\"240\" /></phr><phr n=\"Year\"><ent r=\"4
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:exported SGML document, ASCII text, with very long lines (32028), with CRLF line terminators
    Category:dropped
    Size (bytes):32272
    Entropy (8bit):3.9860157746432043
    Encrypted:false
    SSDEEP:768:Ys5SZgkH8x9nlENEp9ADkYCOW6Hs4Y7OF41+YgmbkpfIjXLr5t+kOpXhZOH69jtT:R3Qh14KYHA0UGehB9
    MD5:B28157B25BB22B3CA4BA559A30C1FC69
    SHA1:BB5690235678BC2542703F5DC2DC153CC46A079F
    SHA-256:561589ED8EBBCFE2687C8003D6C3AF9864DBB69090190302C7AD666CF8753F94
    SHA-512:13ED5C84E67C2A99BC5A2427AB49D2E9245D01783D2AE43388BEA38F3BFB6AD71403BA909DEBAAC9BD9582522D5A7AEE45D1EA9BC66C8B1BBB7F309105B6D278
    Malicious:false
    Reputation:low
    Preview:var xmlSearch_Chunk25Data = "";..xmlSearch_Chunk25Data += '<?xml version=\"1.0\" encoding=\"utf-8\"?><index> saved from url=(0016)http://localhost -->';..xmlSearch_Chunk25Data += '<stem n=\"ok\"><phr n=\"ok\"><ent r=\"3\" t=\"2\" w=\"380\" /><ent r=\"4\" t=\"2\" w=\"665\" /><ent r=\"4\" t=\"5\" w=\"227\" /><ent r=\"4\" t=\"7\" w=\"419\" /><ent r=\"4\" t=\"7\" w=\"496\" /><ent r=\"3\" t=\"7\" w=\"696\" /><ent r=\"4\" t=\"20\" w=\"191\" /><ent r=\"4\" t=\"24\" w=\"844\" /><ent r=\"4\" t=\"28\" w=\"616\" /><ent r=\"4\" t=\"30\" w=\"728\" /><ent r=\"4\" t=\"47\" w=\"61\" /><ent r=\"4\" t=\"47\" w=\"126\" /><ent r=\"5\" t=\"58\" w=\"145\" /><ent r=\"6\" t=\"71\" w=\"472\" /><ent r=\"4\" t=\"76\" w=\"173\" /><ent r=\"4\" t=\"77\" w=\"96\" /><ent r=\"3\" t=\"78\" w=\"149\" /><ent r=\"4\" t=\"79\" w=\"149\" /><ent r=\"4\" t=\"80\" w=\"247\" /><ent r=\"4\" t=\"81\" w=\"362\" /><ent r=\"4\" t=\"81\" w=\"479\" /><ent r=\"4\" t=\"88\" w=\"283\" /><ent r=\"4\" t=\"90\" w=\"549\" /><ent r=\"4\"
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:exported SGML document, ASCII text, with very long lines (32449), with CRLF line terminators
    Category:dropped
    Size (bytes):32693
    Entropy (8bit):4.047407303271832
    Encrypted:false
    SSDEEP:768:1LCjiPru4XqBffkdfg3tKILuTxfVSD69AhuHmcLckZFHhnbwZlPvFkPN0NOjXMEp:OyR
    MD5:8A3FF2EB0AB723EBC0F7E9935C3242DF
    SHA1:CE2C6FAC885889958A027CF23A9BD830A782702A
    SHA-256:325EB169832897B44499A2EE804B0207720F6C57991283770DFA0F71B75588F9
    SHA-512:7A9D1E22536B20AB9142867E07E62D8FFC78D829D6834634079783B8CE3311F135D491FA4D13F989FAAC89AEE778AE60B93143376813231E58CDACEAA6A4BAE6
    Malicious:false
    Reputation:low
    Preview:var xmlSearch_Chunk39Data = "";..xmlSearch_Chunk39Data += '<?xml version=\"1.0\" encoding=\"utf-8\"?><index> saved from url=(0016)http://localhost -->';..xmlSearch_Chunk39Data += '<stem n=\"overwrit\"><phr n=\"overwrite\"><ent r=\"4\" t=\"3\" w=\"1289\" /><ent r=\"6\" t=\"10\" w=\"1170\" /><ent r=\"6\" t=\"11\" w=\"986\" /><ent r=\"6\" t=\"12\" w=\"1091\" /><ent r=\"6\" t=\"13\" w=\"1062\" /><ent r=\"6\" t=\"14\" w=\"1116\" /><ent r=\"6\" t=\"15\" w=\"1065\" /><ent r=\"4\" t=\"17\" w=\"1374\" /><ent r=\"3\" t=\"123\" w=\"651\" /><ent r=\"3\" t=\"123\" w=\"704\" /><ent r=\"6\" t=\"194\" w=\"91\" /></phr><phr n=\"overwriting\"><ent r=\"3\" t=\"80\" w=\"82\" /><ent r=\"3\" t=\"187\" w=\"138\" /></phr></stem><stem n=\"exist\"><phr n=\"existing\"><ent r=\"4\" t=\"3\" w=\"1290\" /><ent r=\"4\" t=\"37\" w=\"42\" /><ent r=\"4\" t=\"55\" w=\"78\" /><ent r=\"4\" t=\"58\" w=\"14\" /><ent r=\"4\" t=\"58\" w=\"45\" /><ent r=\"3\" t=\"65\" w=\"85\" /><ent r=\"3\" t=\"66\" w=\"568\" /><ent r=\"3\
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text, with very long lines (26982), with CRLF line terminators
    Category:dropped
    Size (bytes):27075
    Entropy (8bit):4.0928848661955675
    Encrypted:false
    SSDEEP:768:FZq/V1Hu+4e/YMfkG5yj0uA04U9uMfWvNI9QbUq9r62FTslW50mrPzDKvZ3jLUFf:wgdy9JQZ2l19ski/+2VcJ8q
    MD5:96103EA81DA4A3B7B9FA45809531C26E
    SHA1:D395AEC0A7D1F9167652981C47FAFCF66907EDFA
    SHA-256:B6F736504247C434D43B912EEAA80333837E3A61F3AC811E16BEA38B34CA1507
    SHA-512:91ED721E9854330C9F036075450D11269295431E7838CD09345CD1E34D88C12ADC42143380F29746B54B07CF25CC50F0ABA53162E3AE915C819C30C4878E9120
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="utf-8"?><index> saved from url=(0016)http://localhost -->..<stem n="messag"><phr n="message"><ent r="3" t="5" w="488" /><ent r="4" t="33" w="451" /><ent r="3" t="33" w="815" /><ent r="4" t="80" w="239" /><ent r="3" t="80" w="359" /><ent r="3" t="86" w="205" /><ent r="3" t="86" w="232" /><ent r="4" t="96" w="462" /><ent r="4" t="96" w="475" /><ent r="4" t="96" w="495" /><ent r="4" t="96" w="523" /><ent r="4" t="100" w="786" /><ent r="4" t="101" w="207" /><ent r="4" t="101" w="247" /><ent r="3" t="101" w="270" /><ent r="3" t="101" w="309" /><ent r="3" t="101" w="321" /><ent r="4" t="101" w="451" /><ent r="4" t="101" w="546" /><ent r="4" t="101" w="563" /><ent r="4" t="101" w="698" /><ent r="3" t="102" w="92" /><ent r="3" t="102" w="203" /><ent r="4" t="103" w="339" /><ent r="4" t="103" w="380" /><ent r="4" t="116" w="368" /><ent r="3" t="121" w="641" /><ent r="3" t="123" w="409" /><ent r="4" t="123" w="887" /><ent r="3" t="126" w="39" /><ent r="4" t="131
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:exported SGML document, ASCII text, with very long lines (32038), with CRLF line terminators
    Category:dropped
    Size (bytes):32282
    Entropy (8bit):4.076908300281989
    Encrypted:false
    SSDEEP:768:FNWNpYvNWWNNppYY6uUJKqTzoaCnWI8or3ojsQxpIwelgrNxpIIwweellggrryO9:6GE
    MD5:32C0A55F111D61690E7E6733185CE99C
    SHA1:F8A082DDAF6FF5F8C985B0F771838485BDB62334
    SHA-256:A44B5DF6CDC75B0D63FC82E90E65A3110271345E2968A3D706E73C0846A6100D
    SHA-512:849BDBBC9FA07179BB38E2DDD9832C8814FB40C2811387EF94E3788040884031A031563979B5576552A0664E4103EC78216CDCEF66305359787293B9E8E2E62E
    Malicious:false
    Reputation:low
    Preview:var xmlSearch_Chunk76Data = "";..xmlSearch_Chunk76Data += '<?xml version=\"1.0\" encoding=\"utf-8\"?><index> saved from url=(0016)http://localhost -->';..xmlSearch_Chunk76Data += '<stem n=\"ua\"><phr n=\"UA\"><ent r=\"3\" t=\"23\" w=\"32\" /><ent r=\"4\" t=\"23\" w=\"452\" /><ent r=\"4\" t=\"23\" w=\"525\" /><ent r=\"4\" t=\"23\" w=\"571\" /><ent r=\"4\" t=\"23\" w=\"607\" /><ent r=\"3\" t=\"23\" w=\"953\" /><ent r=\"3\" t=\"23\" w=\"1068\" /></phr></stem><stem n=\"ua-001\"><phr n=\"UA-001\"><ent r=\"3\" t=\"23\" w=\"32\" /><ent r=\"4\" t=\"23\" w=\"452\" /><ent r=\"4\" t=\"23\" w=\"525\" /><ent r=\"4\" t=\"23\" w=\"525\" /><ent r=\"4\" t=\"23\" w=\"571\" /><ent r=\"4\" t=\"23\" w=\"571\" /><ent r=\"4\" t=\"23\" w=\"607\" /><ent r=\"4\" t=\"23\" w=\"607\" /><ent r=\"3\" t=\"23\" w=\"953\" /><ent r=\"3\" t=\"23\" w=\"953\" /><ent r=\"3\" t=\"23\" w=\"1068\" /><ent r=\"3\" t=\"23\" w=\"1068\" /></phr></stem><stem n=\"001\"><phr n=\"001\"><ent r=\"3\" t=\"23\" w=\"33\" /><ent r=\"4\"
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text, with very long lines (27628), with CRLF line terminators
    Category:dropped
    Size (bytes):27721
    Entropy (8bit):4.102059659012513
    Encrypted:false
    SSDEEP:768:EmNOiG29B4L5B8rkYUBSOkATNqqbYWxitDjS44IdBCvnDTM28hjSUflSt+36aQi8:0Mk+PZ5L04egdqmBb1Gr6ZxMmwT3CER
    MD5:5DAACA7977CF13E8894E452176BCBF7B
    SHA1:6B0F67E837E3B5E4152D40EF5BBB27B6672083D8
    SHA-256:42973B6C9D8BAA48CDEA6F276082C36C1E149E65FE7D57D6354BCA6437BFF481
    SHA-512:CB5A006F57343B1147039113F58EDD3610039745B318DF348C30910C05448BB431D089CDB33725D20726D798991B73041466EA3C1B06D2906C53D8086084857B
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="utf-8"?><index> saved from url=(0016)http://localhost -->..<stem n="unplug"><phr n="unplug"><ent r="3" t="7" w="592" /><ent r="3" t="7" w="599" /><ent r="4" t="8" w="190" /><ent r="4" t="86" w="502" /><ent r="8" t="146" w="772" /><ent r="8" t="147" w="944" /><ent r="4" t="169" w="536" /></phr><phr n="unplugging"><ent r="3" t="148" w="98" /><ent r="4" t="169" w="467" /></phr></stem><stem n="remov"><phr n="remove"><ent r="3" t="7" w="617" /><ent r="3" t="17" w="271" /><ent r="4" t="17" w="1047" /><ent r="3" t="18" w="190" /><ent r="3" t="42" w="454" /><ent r="3" t="42" w="466" /><ent r="3" t="42" w="470" /><ent r="3" t="55" w="462" /><ent r="3" t="55" w="475" /><ent r="4" t="56" w="389" /><ent r="3" t="56" w="633" /><ent r="4" t="56" w="646" /><ent r="4" t="56" w="655" /><ent r="3" t="60" w="228" /><ent r="3" t="60" w="246" /><ent r="3" t="60" w="269" /><ent r="4" t="60" w="288" /><ent r="4" t="60" w="296" /><ent r="4" t="60" w="313" /><ent r="4" t="60"
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:exported SGML document, ASCII text, with very long lines (33915), with CRLF line terminators
    Category:dropped
    Size (bytes):34159
    Entropy (8bit):4.054253978032468
    Encrypted:false
    SSDEEP:768:cXBB6vvqqaam00RRXLXLf++VVFFCC77AA9qqZZtOiiw6iEBBJttttSSqqBBMMHHa:H/QUojchNA
    MD5:4AC1122C24810CB4C8D89DA53E4174DA
    SHA1:03ACF286C5BB9427C31AEACCE63F4F9B37600EF8
    SHA-256:0CC5396CDB9B3F5FFA96F34D1EE7D7BFBC445B1FA48CB5F8389FF4964B98CA79
    SHA-512:07CD27345A32C22F65E2D83CD830B76B16B1AE5BEDD19CF8449CD0B21A24134A7ECD3539D089E3AFCA0CE3EAFA44BA894144593BBB416B999BA83D2ECF65279E
    Malicious:false
    Reputation:low
    Preview:var xmlSearch_Chunk62Data = "";..xmlSearch_Chunk62Data += '<?xml version=\"1.0\" encoding=\"utf-8\"?><index> saved from url=(0016)http://localhost -->';..xmlSearch_Chunk62Data += '<stem n=\"begin\"><phr n=\"begins\"><ent r=\"3\" t=\"5\" w=\"57\" /><ent r=\"3\" t=\"5\" w=\"57\" /><ent r=\"3\" t=\"8\" w=\"203\" /><ent r=\"3\" t=\"8\" w=\"203\" /><ent r=\"4\" t=\"10\" w=\"570\" /><ent r=\"4\" t=\"10\" w=\"580\" /><ent r=\"4\" t=\"10\" w=\"580\" /><ent r=\"6\" t=\"10\" w=\"950\" /><ent r=\"6\" t=\"10\" w=\"950\" /><ent r=\"6\" t=\"11\" w=\"780\" /><ent r=\"6\" t=\"11\" w=\"780\" /><ent r=\"4\" t=\"12\" w=\"389\" /><ent r=\"4\" t=\"12\" w=\"417\" /><ent r=\"4\" t=\"12\" w=\"417\" /><ent r=\"6\" t=\"12\" w=\"906\" /><ent r=\"6\" t=\"12\" w=\"906\" /><ent r=\"6\" t=\"12\" w=\"1136\" /><ent r=\"6\" t=\"12\" w=\"1136\" /><ent r=\"4\" t=\"13\" w=\"532\" /><ent r=\"4\" t=\"13\" w=\"542\" /><ent r=\"4\" t=\"13\" w=\"542\" /><ent r=\"6\" t=\"13\" w=\"864\" /><ent r=\"6\" t=\"13\" w=\"864\" /><e
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:exported SGML document, ASCII text, with very long lines (47952), with CRLF line terminators
    Category:dropped
    Size (bytes):48192
    Entropy (8bit):4.000892284777609
    Encrypted:false
    SSDEEP:768:BoJU8q6ZtFNUNiDbq43zY2ypzKHgDo8VwlXTQ1DInXhymxQ3j5FMEC86u7+SGpv6:w1qVBbeXApRwsVeSdbFghVhzGfmq54RO
    MD5:158E5FA88DF1BD66DF30FD6156DC46A4
    SHA1:BE32B7BE5DCC286F97443BED1F235FA12DFF2FB1
    SHA-256:DA976AE607359840126B3D92A8638CA15316FEC0FEDF2350BFCAEE7DBCD9A9DD
    SHA-512:3143458871F7F509201FB410FE8C2ED98F36E6DF95A9EAC9C389BF6F06B5C6853541CA1EF6640D9EB0BB7F019931FF96B53D359AF26D3C205C2C0CDA88DD17F0
    Malicious:false
    Reputation:low
    Preview:var xmlSearch_Chunk8Data = "";..xmlSearch_Chunk8Data += '<?xml version=\"1.0\" encoding=\"utf-8\"?><index> saved from url=(0016)http://localhost -->';..xmlSearch_Chunk8Data += '<stem n=\"8am\"><phr n=\"8am\"><ent r=\"3\" t=\"0\" w=\"137\" /><ent r=\"3\" t=\"0\" w=\"149\" /></phr></stem><stem n=\"8pm\"><phr n=\"8pm\"><ent r=\"3\" t=\"0\" w=\"139\" /></phr></stem><stem n=\"et\"><phr n=\"et\"><ent r=\"3\" t=\"0\" w=\"140\" /><ent r=\"3\" t=\"0\" w=\"152\" /></phr></stem><stem n=\"mondai\"><phr n=\"monday\"><ent r=\"3\" t=\"0\" w=\"141\" /><ent r=\"3\" t=\"0\" w=\"153\" /></phr></stem><stem n=\"fridai\"><phr n=\"friday\"><ent r=\"3\" t=\"0\" w=\"143\" /><ent r=\"3\" t=\"0\" w=\"155\" /></phr></stem><stem n=\"custom\"><phr n=\"customer\"><ent r=\"4\" t=\"0\" w=\"145\" /><ent r=\"3\" t=\"1\" w=\"199\" /><ent r=\"3\" t=\"2\" w=\"75\" /><ent r=\"3\" t=\"66\" w=\"873\" /></phr><phr n=\"custom\"><ent r=\"4\" t=\"3\" w=\"1372\" /><ent r=\"4\" t=\"10\" w=\"762\" /><ent r=\"6\" t=\"10\" w=\"125
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:exported SGML document, ASCII text, with very long lines (32158), with CRLF line terminators
    Category:dropped
    Size (bytes):32402
    Entropy (8bit):4.385567397086285
    Encrypted:false
    SSDEEP:768:k8Zh1I6JI7f1mNQa/QFEz8zj0blDRn0Qjnz70QjnzhlaBJ+nWCYMV/bbQFDB/Gw9:ZkD3O5hM
    MD5:6F80B0F457D783C2C9391F27265210F5
    SHA1:03F92D3097D4CD7209E76A0AE147E2234EFF57CA
    SHA-256:F704679FA2892FAD965A2E8EC661137F573CD02343355CA70EAF73CB9B4348EF
    SHA-512:9E1D91460226980E1ED89F4A22A8CA4419C61DDE01385179A5CEEBDA31F2A833AE8719A3AADE0DB7E03B3D6F3AA798161536810319AA8CF8F54E3EF6DD8606ED
    Malicious:false
    Reputation:low
    Preview:var xmlSearch_Chunk55Data = "";..xmlSearch_Chunk55Data += '<?xml version=\"1.0\" encoding=\"utf-8\"?><index> saved from url=(0016)http://localhost -->';..xmlSearch_Chunk55Data += '<stem n=\"represent\"><phr n=\"representation\"><ent r=\"3\" t=\"46\" w=\"36\" /><ent r=\"4\" t=\"154\" w=\"417\" /></phr></stem><stem n=\"piec\"><phr n=\"piece\"><ent r=\"4\" t=\"46\" w=\"213\" /></phr></stem><stem n=\"wedg\"><phr n=\"wedge\"><ent r=\"4\" t=\"46\" w=\"222\" /></phr></stem><stem n=\"yellow\"><phr n=\"yellow\"><ent r=\"4\" t=\"46\" w=\"227\" /></phr></stem><stem n=\"timefram\"><phr n=\"timeframe\"><ent r=\"5\" t=\"46\" w=\"259\" /><ent r=\"4\" t=\"118\" w=\"134\" /><ent r=\"3\" t=\"128\" w=\"31\" /><ent r=\"3\" t=\"204\" w=\"28\" /></phr></stem><stem n=\"overlap\"><phr n=\"overlaps\"><ent r=\"4\" t=\"46\" w=\"442\" /></phr><phr n=\"overlap\"><ent r=\"3\" t=\"62\" w=\"35\" /><ent r=\"4\" t=\"100\" w=\"685\" /></phr><phr n=\"overlapping\"><ent r=\"5\" t=\"69\" w=\"462\" /></phr></stem><stem
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text, with very long lines (27537), with CRLF line terminators
    Category:dropped
    Size (bytes):27630
    Entropy (8bit):4.398853309166129
    Encrypted:false
    SSDEEP:768:HFUzXxexW5yupwW5Rnkq9brEvfBt8e9oz8e9ottJSWb+tJha/ffGgsebIlgOQVEB:QCUe6X3mphb+qgfZ98sv
    MD5:6F1CFF73B61BC8458838689990B94DCA
    SHA1:FCD0F64AB0B18700D4BA4EC9F53BC87F24EC4144
    SHA-256:A7C22783F383738411A8777A93E1FE062E57CD3CD937EFB54E787A8E6C2666E7
    SHA-512:EA220F3303500F14B3DEEC40FA49B8B3BE972F172EA3BF857319960FCF24CAA0FB032A74517A755ABADBB5972A5DAB075971444E2121C87EC8E8A2CE6CAB2576
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="utf-8"?><index> saved from url=(0016)http://localhost -->..<stem n="sss"><phr n="sss"><ent r="6" t="82" w="355" /><ent r="5" t="189" w="169" /></phr></stem><stem n="23"><phr n="23"><ent r="4" t="82" w="401" /><ent r="4" t="82" w="405" /><ent r="3" t="113" w="176" /><ent r="3" t="176" w="70" /><ent r="3" t="177" w="369" /></phr></stem><stem n="59"><phr n="59"><ent r="4" t="82" w="402" /><ent r="8" t="82" w="403" /><ent r="4" t="82" w="406" /><ent r="4" t="82" w="407" /><ent r="3" t="90" w="240" /><ent r="3" t="90" w="469" /><ent r="4" t="96" w="387" /><ent r="3" t="176" w="72" /><ent r="3" t="176" w="75" /><ent r="3" t="177" w="372" /></phr></stem><stem n="blank"><phr n="blank"><ent r="4" t="82" w="442" /></phr></stem><stem n="parenthesi"><phr n="parenthesis"><ent r="3" t="82" w="485" /><ent r="5" t="152" w="384" /><ent r="4" t="152" w="417" /><ent r="4" t="152" w="553" /></phr></stem><stem n="38"><phr n="38"><ent r="4" t="82" w="493" /><ent r="4" t="82
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:exported SGML document, ASCII text, with very long lines (32257), with CRLF line terminators
    Category:dropped
    Size (bytes):32501
    Entropy (8bit):4.38233050760032
    Encrypted:false
    SSDEEP:768:stqrDNEt0JMIN+EZ7mcdzji7v/+joMH+joMlJhwULk9RlADbTU2juQbaCoyoaRJY:1ivAPQ2uXbPQ2uX0T7ru6p5KZuj28lcF
    MD5:D7BCB293CE866C063E83BC7976CE3858
    SHA1:FB6597183C3AD1C1EBD09F4AFFB3F16A8F275D30
    SHA-256:0BE7AED4CD92F0B13CEF15BFFD218EC399F510A1866C867174A2261B8E4F609F
    SHA-512:C7B97602EC6B9947E6D4C01AA8EB0FF6ACD14BAD3ABD00DE9CF49D7D6A964469FE6138F68DAE598BD8FC785C8EAE459590FED30EE4D032215544FECD6FA8760C
    Malicious:false
    Reputation:low
    Preview:var xmlSearch_Chunk57Data = "";..xmlSearch_Chunk57Data += '<?xml version=\"1.0\" encoding=\"utf-8\"?><index> saved from url=(0016)http://localhost -->';..xmlSearch_Chunk57Data += '<stem n=\"sss\"><phr n=\"sss\"><ent r=\"6\" t=\"82\" w=\"355\" /><ent r=\"5\" t=\"189\" w=\"169\" /></phr></stem><stem n=\"23\"><phr n=\"23\"><ent r=\"4\" t=\"82\" w=\"401\" /><ent r=\"4\" t=\"82\" w=\"405\" /><ent r=\"3\" t=\"113\" w=\"176\" /><ent r=\"3\" t=\"176\" w=\"70\" /><ent r=\"3\" t=\"177\" w=\"369\" /></phr></stem><stem n=\"59\"><phr n=\"59\"><ent r=\"4\" t=\"82\" w=\"402\" /><ent r=\"8\" t=\"82\" w=\"403\" /><ent r=\"4\" t=\"82\" w=\"406\" /><ent r=\"4\" t=\"82\" w=\"407\" /><ent r=\"3\" t=\"90\" w=\"240\" /><ent r=\"3\" t=\"90\" w=\"469\" /><ent r=\"4\" t=\"96\" w=\"387\" /><ent r=\"3\" t=\"176\" w=\"72\" /><ent r=\"3\" t=\"176\" w=\"75\" /><ent r=\"3\" t=\"177\" w=\"372\" /></phr></stem><stem n=\"blank\"><phr n=\"blank\"><ent r=\"4\" t=\"82\" w=\"442\" /></phr></stem><stem n=\"parenthesi\"><
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text, with very long lines (27236), with CRLF line terminators
    Category:dropped
    Size (bytes):27329
    Entropy (8bit):4.257024133207435
    Encrypted:false
    SSDEEP:768:3zuauaMMNcmbbqq6644EuWWssvvffooPPggkk55ggSSqqKKmm33AAwwpv00VroGw:S/lo1y/D2rLWeCSg/WTgsc
    MD5:DC23D7553B1DF5118FC432284E4F5CC5
    SHA1:1A30F1AAC8032D76070CDC6BAF9239742D8BD9EF
    SHA-256:B66A560ACC1EE5A989E19F2DB89D1E1FEBDBA8817F66CF56856FCFFAB3A682D6
    SHA-512:EEB20EB882606FA9C931A55948C55DB054E15ED429ADAF25DEB39B4F4154C68D42617B542CB32DBB3F90D694793ABD1596659C5B1BFA435DA3A3ABE27EC17BA7
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="utf-8"?><index> saved from url=(0016)http://localhost -->..<stem n="unsav"><phr n="unsaved"><ent r="3" t="43" w="185" /><ent r="3" t="43" w="185" /><ent r="5" t="154" w="210" /><ent r="5" t="154" w="210" /><ent r="4" t="163" w="50" /><ent r="4" t="163" w="50" /><ent r="5" t="195" w="42" /><ent r="5" t="195" w="42" /></phr></stem><stem n="provid"><phr n="provides"><ent r="3" t="44" w="31" /><ent r="3" t="44" w="31" /><ent r="3" t="69" w="20" /><ent r="3" t="69" w="20" /><ent r="4" t="69" w="406" /><ent r="4" t="69" w="406" /><ent r="4" t="93" w="207" /><ent r="4" t="93" w="207" /><ent r="3" t="101" w="15" /><ent r="3" t="101" w="15" /><ent r="3" t="113" w="744" /><ent r="3" t="113" w="744" /></phr><phr n="provide"><ent r="4" t="64" w="337" /><ent r="5" t="67" w="432" /><ent r="5" t="67" w="432" /><ent r="4" t="68" w="315" /><ent r="4" t="68" w="315" /><ent r="3" t="87" w="77" /><ent r="3" t="87" w="77" /><ent r="3" t="87" w="264" /><ent r="3" t="87" w="
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:exported SGML document, ASCII text, with very long lines (32449), with CRLF line terminators
    Category:dropped
    Size (bytes):32693
    Entropy (8bit):4.109729955398627
    Encrypted:false
    SSDEEP:768:skotZXiYjyEFZlBwUj6Qt+rLpBliTPgOqgLOnA6pPvIGJ/IW0U5MftEOTAsCy55t:h8gwb1Vyhe2o4o
    MD5:1446CF162BFAF27E0E99E42D1EFA6EB9
    SHA1:EDC9136A51108BD2803B4CF772CACD765FF122CB
    SHA-256:D95FA69FBAAD61FCE6C42A0EC396106E143695AE271B3D646F35B452F563A194
    SHA-512:1E3A0B76663535B7D1E4A120D2E10028B39FA4C3D5558CE831203C6156047738C196A0E177F1C0CBD426F7BCD2B7F304495297D19E7F7E29907C34614DB7447D
    Malicious:false
    Reputation:low
    Preview:var xmlSearch_Chunk49Data = "";..xmlSearch_Chunk49Data += '<?xml version=\"1.0\" encoding=\"utf-8\"?><index> saved from url=(0016)http://localhost -->';..xmlSearch_Chunk49Data += '<stem n=\"15\"><phr n=\"15\"><ent r=\"4\" t=\"10\" w=\"784\" /><ent r=\"4\" t=\"11\" w=\"490\" /><ent r=\"12\" t=\"11\" w=\"1186\" /><ent r=\"4\" t=\"12\" w=\"625\" /><ent r=\"12\" t=\"12\" w=\"1263\" /><ent r=\"4\" t=\"13\" w=\"723\" /><ent r=\"12\" t=\"14\" w=\"1288\" /><ent r=\"4\" t=\"15\" w=\"506\" /><ent r=\"6\" t=\"15\" w=\"864\" /><ent r=\"6\" t=\"15\" w=\"960\" /><ent r=\"4\" t=\"17\" w=\"416\" /><ent r=\"4\" t=\"17\" w=\"426\" /><ent r=\"4\" t=\"17\" w=\"435\" /><ent r=\"4\" t=\"17\" w=\"813\" /><ent r=\"4\" t=\"24\" w=\"550\" /><ent r=\"4\" t=\"24\" w=\"559\" /><ent r=\"4\" t=\"30\" w=\"466\" /><ent r=\"3\" t=\"30\" w=\"781\" /><ent r=\"3\" t=\"30\" w=\"793\" /><ent r=\"3\" t=\"30\" w=\"812\" /><ent r=\"3\" t=\"73\" w=\"106\" /><ent r=\"4\" t=\"100\" w=\"729\" /><ent r=\"7\" t=\"110\" w=\"162\"
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:exported SGML document, ASCII text, with very long lines (33150), with CRLF line terminators
    Category:dropped
    Size (bytes):33394
    Entropy (8bit):4.081588109338711
    Encrypted:false
    SSDEEP:768:Lee+Ni33bb9FmmU0U0D5f/9AfTTmmXXxufmrqqDDHHWW22uuPPKKOH3WW8844xxL:33J
    MD5:4B16A305EA78FEF782541782D225084D
    SHA1:6FE2147D16B16B4E7ECDD60995753DEA0406C54E
    SHA-256:B7A0F84EF0775340344A9107B8EAB35147C3D123795ACEF2E14F69F168E390D9
    SHA-512:CE5D3949CDFDCBE2BE074943BA114A83A343AF30243B517C74E5F04585FC0896BA1822A59880A881EB2569C2EA91CE883A14747CDBDDA28FB64A41182C125F62
    Malicious:false
    Reputation:low
    Preview:var xmlSearch_Chunk63Data = "";..xmlSearch_Chunk63Data += '<?xml version=\"1.0\" encoding=\"utf-8\"?><index> saved from url=(0016)http://localhost -->';..xmlSearch_Chunk63Data += '<stem n=\"humid\"><phr n=\"humidity\"><ent r=\"4\" t=\"5\" w=\"387\" /><ent r=\"4\" t=\"15\" w=\"478\" /><ent r=\"4\" t=\"15\" w=\"478\" /><ent r=\"4\" t=\"64\" w=\"430\" /><ent r=\"3\" t=\"70\" w=\"28\" /><ent r=\"4\" t=\"70\" w=\"68\" /><ent r=\"4\" t=\"153\" w=\"579\" /><ent r=\"4\" t=\"153\" w=\"579\" /><ent r=\"4\" t=\"154\" w=\"561\" /><ent r=\"4\" t=\"154\" w=\"561\" /><ent r=\"4\" t=\"154\" w=\"578\" /><ent r=\"4\" t=\"154\" w=\"578\" /></phr><phr n=\"Humidity\"><ent r=\"4\" t=\"15\" w=\"492\" /><ent r=\"4\" t=\"15\" w=\"492\" /><ent r=\"4\" t=\"70\" w=\"110\" /><ent r=\"6\" t=\"80\" w=\"738\" /><ent r=\"6\" t=\"80\" w=\"738\" /><ent r=\"5\" t=\"154\" w=\"553\" /></phr></stem><stem n=\"retain\"><phr n=\"retain\"><ent r=\"4\" t=\"5\" w=\"393\" /><ent r=\"4\" t=\"5\" w=\"393\" /><ent r=\"4\" t=\"81\
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text, with very long lines (26998), with CRLF line terminators
    Category:dropped
    Size (bytes):27091
    Entropy (8bit):4.255378689408267
    Encrypted:false
    SSDEEP:768:LmRnaaBulBlrwsrBrVVY0G5nnxxvbt4NWqJJkRsJ0kjzzxxllT1gKooq1twB9/ZB:dauPdF3Hoo4H9nMcst+iaRnOCa
    MD5:CAFE5E8B292915F10860B475DF73F1CD
    SHA1:72F1E2C5E2776033AA907773EF7A812067408688
    SHA-256:A6E725899A6330D890D4A87C3A7FD48C13F1EE5FD99287354E70CD58FE08902E
    SHA-512:43A0411BD2EB5075A4807436C77A61DDB720E1CB751E58C3FBC2B3A2DC07E8902A32A7222022C335AA4BD209E5477AF12AD19532E432EFB8EF6269F29AF36250
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="utf-8"?><index> saved from url=(0016)http://localhost -->..<stem n="sync"><phr n="Sync"><ent r="4" t="93" w="351" /><ent r="4" t="93" w="351" /><ent r="4" t="93" w="404" /><ent r="4" t="93" w="404" /></phr></stem><stem n="desc"><phr n="Desc"><ent r="5" t="93" w="605" /></phr></stem><stem n="repair"><phr n="repairs"><ent r="3" t="93" w="769" /><ent r="3" t="93" w="769" /></phr></stem><stem n="94"><phr n="94"><ent r="3" t="94" w="210" /><ent r="3" t="94" w="210" /></phr></stem><stem n="mb"><phr n="MB"><ent r="3" t="94" w="211" /><ent r="3" t="94" w="211" /><ent r="3" t="141" w="209" /><ent r="3" t="141" w="217" /><ent r="3" t="141" w="217" /></phr></stem><stem n="64"><phr n="64"><ent r="3" t="94" w="222" /><ent r="3" t="94" w="222" /><ent r="5" t="143" w="553" /><ent r="5" t="143" w="553" /><ent r="4" t="144" w="336" /><ent r="4" t="144" w="336" /></phr></stem><stem n="kb"><phr n="KB"><ent r="3" t="94" w="223" /></phr></stem><stem n="varh"><phr n="VARh">
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text, with very long lines (26742), with CRLF line terminators
    Category:dropped
    Size (bytes):26835
    Entropy (8bit):3.999021600515749
    Encrypted:false
    SSDEEP:768:7SVVDDkkmmrrdNbDDJJxxeewwh/p//hhCCkkHHJJ/hs00GGUUvvccOLoddiinnAK:Uh2IcHSrZqKprhJv01
    MD5:396CBFB59ACDD9AF11364176AC6AB420
    SHA1:BD56DF8CDA1B2C985F05129D90D973DCDDF6CE86
    SHA-256:D8D531D1D522031131F8FEECE5B9B887D6BA94560E33D6484757672C906AED58
    SHA-512:3472DEEFBD9F57214AC3DDF8ED16B968E2362AD015DF5B30B802A66405F2506E5AE4ECE1B7BF640B9F7B4A6A52E960890369DD16C03A0E264B904A7786E83A77
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="utf-8"?><index> saved from url=(0016)http://localhost -->..<stem n="unless"><phr n="Unless"><ent r="4" t="10" w="679" /><ent r="4" t="10" w="679" /><ent r="4" t="11" w="392" /><ent r="4" t="11" w="392" /><ent r="4" t="12" w="502" /><ent r="4" t="12" w="502" /><ent r="4" t="13" w="627" /><ent r="4" t="13" w="627" /><ent r="4" t="14" w="734" /><ent r="4" t="14" w="734" /><ent r="4" t="15" w="798" /><ent r="4" t="15" w="798" /><ent r="4" t="16" w="485" /><ent r="4" t="16" w="485" /></phr><phr n="unless"><ent r="3" t="30" w="53" /><ent r="3" t="30" w="53" /><ent r="3" t="32" w="20" /><ent r="3" t="32" w="20" /><ent r="3" t="34" w="51" /><ent r="3" t="34" w="51" /><ent r="4" t="36" w="168" /><ent r="4" t="36" w="168" /><ent r="3" t="64" w="561" /><ent r="3" t="64" w="561" /><ent r="3" t="118" w="703" /><ent r="3" t="118" w="703" /><ent r="4" t="120" w="809" /><ent r="4" t="120" w="809" /></phr></stem><stem n="suspect"><phr n="suspect"><ent r="4" t="10" w="6
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text, with very long lines (28537), with CRLF line terminators
    Category:dropped
    Size (bytes):28630
    Entropy (8bit):3.963550210200452
    Encrypted:false
    SSDEEP:768:5iEnNOxjlu97bnFipFiZwSm7KQgWkItORNvCxBoi/15knZNKiWn/hc4+rfZRtonI:+tQPJqeyh4ph5RtTr
    MD5:28202657DF6E783B26EF5684468DD8A8
    SHA1:4A49223F56BBFAA05EFDFAD54C7CFCA2B784B603
    SHA-256:AFAE07F6FEB89FBFD6980AEC0958E8CC0442255077E289DEB6887EDC62B6CAC4
    SHA-512:CF38540F0FD47D6C0D944740D3FBE0E49B92B8BFB4302190AC1E9FECFA40FC976B6D57FEA0A7858572DA868A00C248BE28B2172270C3FCC4485F05988DC3FF2F
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="utf-8"?><index> saved from url=(0016)http://localhost -->..<stem n="analyz"><phr n="analyzing"><ent r="5" t="0" w="37" /><ent r="5" t="1" w="304" /><ent r="4" t="4" w="768" /><ent r="268435456" t="35" w="5" /><ent r="16777218" t="35" w="12" /><ent r="3" t="75" w="13" /></phr><phr n="analyze"><ent r="4" t="6" w="215" /><ent r="3" t="117" w="19" /><ent r="4" t="194" w="478" /></phr></stem><stem n="us"><phr n="using"><ent r="5" t="0" w="40" /><ent r="3" t="1" w="251" /><ent r="3" t="2" w="693" /><ent r="4" t="3" w="166" /><ent r="4" t="3" w="1295" /><ent r="4" t="7" w="124" /><ent r="3" t="7" w="246" /><ent r="3" t="7" w="293" /><ent r="3" t="7" w="322" /><ent r="3" t="7" w="424" /><ent r="4" t="7" w="913" /><ent r="4" t="9" w="204" /><ent r="3" t="9" w="493" /><ent r="3" t="9" w="577" /><ent r="4" t="13" w="232" /><ent r="10" t="16" w="1141" /><ent r="4" t="17" w="486" /><ent r="268435456" t="21" w="1" /><ent r="16777218" t="21" w="5" /><ent r="3" t="21"
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:exported SGML document, ASCII text, with very long lines (33779), with CRLF line terminators
    Category:dropped
    Size (bytes):34023
    Entropy (8bit):4.0216316183551
    Encrypted:false
    SSDEEP:768:zsH3Uocgd54hZ8h8V/f6F9lceKdSVzIgPPAPMFreaZNHtTrkJYjf5clH0AE9fnYa:yLEmjxKTH9E
    MD5:6A65DF59D5D62B1AAEC5F378154C7E16
    SHA1:D0C194969868B7C2C76BAD8134DC741C4869803C
    SHA-256:7550BED0CD90A13AE74AB36C2E12D7E482DD9C66B45A8C28B7F1E88F0E66986C
    SHA-512:A54EFA7498EEDD8F2484B9DDC6C3E2F1CD4C82B29F2A8972F4E5F3ACDA5AC7B0CB7AE1E305387A83855FB8A434AD28F2D356E656F1A9CA42D5557F9BA47A601A
    Malicious:false
    Reputation:low
    Preview:var xmlSearch_Chunk32Data = "";..xmlSearch_Chunk32Data += '<?xml version=\"1.0\" encoding=\"utf-8\"?><index> saved from url=(0016)http://localhost -->';..xmlSearch_Chunk32Data += '<stem n=\"higher\"><phr n=\"higher\"><ent r=\"4\" t=\"3\" w=\"121\" /><ent r=\"4\" t=\"25\" w=\"305\" /><ent r=\"3\" t=\"26\" w=\"519\" /><ent r=\"3\" t=\"32\" w=\"196\" /><ent r=\"3\" t=\"33\" w=\"764\" /><ent r=\"3\" t=\"47\" w=\"159\" /><ent r=\"4\" t=\"81\" w=\"39\" /><ent r=\"3\" t=\"94\" w=\"85\" /></phr></stem><stem n=\"both\"><phr n=\"both\"><ent r=\"4\" t=\"3\" w=\"127\" /><ent r=\"3\" t=\"15\" w=\"61\" /><ent r=\"4\" t=\"16\" w=\"512\" /><ent r=\"4\" t=\"25\" w=\"289\" /><ent r=\"4\" t=\"26\" w=\"123\" /><ent r=\"3\" t=\"28\" w=\"114\" /><ent r=\"4\" t=\"28\" w=\"495\" /><ent r=\"4\" t=\"28\" w=\"520\" /><ent r=\"3\" t=\"29\" w=\"22\" /><ent r=\"3\" t=\"29\" w=\"42\" /><ent r=\"3\" t=\"30\" w=\"657\" /><ent r=\"3\" t=\"31\" w=\"51\" /><ent r=\"4\" t=\"31\" w=\"624\" /><ent r=\"4\" t=\"31\" w=\"6
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:exported SGML document, ASCII text, with very long lines (51163), with CRLF line terminators
    Category:dropped
    Size (bytes):51407
    Entropy (8bit):3.947053925525171
    Encrypted:false
    SSDEEP:768:RXqpDyoy0DOotwzqH31/NoejjQS1VPXnJRyCGRWeCW/7QR97ISVzjaV5gKCoBxi6:YhQS9FWmqvhJ
    MD5:BE0478867EADD6945BD2695B3B0B17B3
    SHA1:2EC3EF7F873D9FA792AF17C97C01405BCE10982D
    SHA-256:AF912C03B2204CD999028005CA708CB72257C8E4124C09B5F38B1200999815E8
    SHA-512:1B53EE1BF17F8A59286881D75D54ABF5CFF0F326A022581F33F2FC376DFEC00591F0BDBA9F7F669DDF9B8C1F2BC7FCF01E04828CB060B4C839EBF26A8FF40B32
    Malicious:false
    Reputation:low
    Preview:var xmlSearch_Chunk13Data = "";..xmlSearch_Chunk13Data += '<?xml version=\"1.0\" encoding=\"utf-8\"?><index> saved from url=(0016)http://localhost -->';..xmlSearch_Chunk13Data += '<stem n=\"u-shuttl\"><phr n=\"u-shuttle\"><ent r=\"4\" t=\"1\" w=\"91\" /><ent r=\"3\" t=\"94\" w=\"28\" /><ent r=\"3\" t=\"94\" w=\"184\" /><ent r=\"65538\" t=\"94\" w=\"246\" /><ent r=\"3\" t=\"94\" w=\"260\" /><ent r=\"4\" t=\"94\" w=\"285\" /><ent r=\"5\" t=\"95\" w=\"77\" /><ent r=\"3\" t=\"96\" w=\"21\" /><ent r=\"4\" t=\"96\" w=\"43\" /><ent r=\"10\" t=\"96\" w=\"167\" /><ent r=\"4\" t=\"96\" w=\"180\" /><ent r=\"10\" t=\"96\" w=\"193\" /><ent r=\"4\" t=\"96\" w=\"212\" /><ent r=\"4\" t=\"96\" w=\"491\" /><ent r=\"3\" t=\"97\" w=\"151\" /><ent r=\"3\" t=\"97\" w=\"205\" /><ent r=\"3\" t=\"97\" w=\"218\" /><ent r=\"4\" t=\"167\" w=\"130\" /><ent r=\"5\" t=\"167\" w=\"163\" /></phr></stem><stem n=\"shuttl\"><phr n=\"shuttle\"><ent r=\"4\" t=\"1\" w=\"92\" /><ent r=\"4\" t=\"1\" w=\"95\" /><ent r=\"4\
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text, with very long lines (26750), with CRLF line terminators
    Category:dropped
    Size (bytes):26843
    Entropy (8bit):4.109207933287718
    Encrypted:false
    SSDEEP:768:vdrdBBWWggyywszmddy1b//79DtrreeYYxxbbTTbb8855AA//33vvffIkk571kKB:OLbrEM/3EE1
    MD5:EEF8BFD78CD2AA45B01BB1D80219CBF0
    SHA1:0957F2015541A5972BB0DCA359236F9F3C4B4D58
    SHA-256:91E7DE899606B872246011C1D1D395D7791E956096718469C81371E581D6BC20
    SHA-512:5958716C5A63A763749A3E26830BB69CD46EE98D7B9F04C661CC5DAB396E564FFCD5EFD55ED1B766CBEF3ECDF84EDE1A7A2876B008C7AF08680867A560FDEF39
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="utf-8"?><index> saved from url=(0016)http://localhost -->..<stem n="h21"><phr n="H21"><ent r="4" t="16" w="655" /><ent r="4" t="16" w="655" /></phr></stem><stem n="h22"><phr n="H22"><ent r="4" t="16" w="664" /><ent r="4" t="16" w="664" /></phr></stem><stem n="trm"><phr n="TRMS"><ent r="4" t="16" w="838" /><ent r="4" t="16" w="838" /><ent r="4" t="65" w="111" /><ent r="4" t="65" w="111" /><ent r="3" t="89" w="54" /><ent r="3" t="89" w="54" /><ent r="3" t="89" w="63" /><ent r="3" t="89" w="63" /><ent r="5" t="154" w="714" /><ent r="5" t="154" w="714" /><ent r="4" t="154" w="735" /><ent r="4" t="154" w="735" /></phr></stem><stem n="erron"><phr n="erroneous"><ent r="4" t="16" w="856" /><ent r="4" t="16" w="856" /></phr></stem><stem n="togeth"><phr n="together"><ent r="4" t="16" w="884" /><ent r="4" t="16" w="884" /><ent r="3" t="40" w="89" /><ent r="3" t="40" w="89" /><ent r="3" t="58" w="49" /><ent r="3" t="59" w="184" /></phr></stem><stem n="valid"><phr
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:HTML document, ASCII text, with very long lines (9108), with CRLF line terminators
    Category:dropped
    Size (bytes):9292
    Entropy (8bit):5.316142642493652
    Encrypted:false
    SSDEEP:192:eSlbnE+xxJ5gaSJJJkSeIUHVrLDDhWwpy8b7H:hlbjxJ5gakrwHVvHh1pH
    MD5:3EBB4643783188B17078B8615F089DB7
    SHA1:DF1B4BFF3D99455348493ED7417BCDFC37499257
    SHA-256:E2E9C2A8CAF63E6916FFEE45F802B86532D1C13B5A480267DBC99C000D6D63B7
    SHA-512:53504CBB85927FFDC138ACA77DEB7CB9ED3CA5AD8410615F34484DD270F223E806CD652342C80EC780B2243470D49048A2516206AE7774DC4177EB106B6C5CD3
    Malicious:false
    Reputation:low
    Preview:/* Modernizr 2.6.2 (Custom Build) | MIT & BSD.. * Build: http://modernizr.com/download/#-inlinesvg-svg-svgclippaths-touch-shiv-mq-cssclasses-teststyles-prefixes-ie8compat-load.. */..;window.Modernizr=function(a,b,c){function y(a){j.cssText=a}function z(a,b){return y(m.join(a+";")+(b||""))}function A(a,b){return typeof a===b}function B(a,b){return!!~(""+a).indexOf(b)}function C(a,b,d){for(var e in a){var f=b[a[e]];if(f!==c)return d===!1?a[e]:A(f,"function")?f.bind(d||b):f}return!1}var d="2.6.2",e={},f=!0,g=b.documentElement,h="modernizr",i=b.createElement(h),j=i.style,k,l={}.toString,m=" -webkit- -moz- -o- -ms- ".split(" "),n={svg:"http://www.w3.org/2000/svg"},o={},p={},q={},r=[],s=r.slice,t,u=function(a,c,d,e){var f,i,j,k,l=b.createElement("div"),m=b.body,n=m||b.createElement("body");if(parseInt(d,10))while(d--)j=b.createElement("div"),j.id=e?e[d]:h+(d+1),l.appendChild(j);return f=["&#173;",'<style id="s',h,'">',a,"</style>"].join(""),l.id=h,(m?l:n).innerHTML+=f,n.appendChild(l),m||(n.
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:ASCII text, with very long lines (26006)
    Category:dropped
    Size (bytes):256500
    Entropy (8bit):5.46131903159356
    Encrypted:false
    SSDEEP:6144:obAgMM0L56gFpWad+96Qz64jhel742qkyA:I0QgFpWadV0e42IA
    MD5:05014E0147F42C8340EA09BF4D92ABB7
    SHA1:EEEC1C0C7FCDC2E37A9F34143A1504A1D585465E
    SHA-256:73278083C1FEC8605ABD8507A929BD6DFDC23365A170218D5A547B75BF8AD174
    SHA-512:1B7F105C6A39149596D3410B35EACC27EBC82221539FD9C0A6194B0D0485EACF2A8048DC0ADB077499712B6A72349BE3C8EE6F6A9D141B92394F05B0459EA297
    Malicious:false
    Reputation:low
    Preview:/*.* Copyright MadCap Software.* http://www.madcapsoftware.com/. * Unlicensed use is strictly prohibited.*. * v15.0.7081.30245.*/.window.MadCap={};MadCap.CreateNamespace=function(c){var d=c.split(".");var e=MadCap;for(var a=0,b=d.length;a<b;a++){var c=d[a];if(c=="MadCap"){continue}if(typeof(e[c])!="undefined"){e=e[c];continue}e[c]={};e=e[c]}return e};if(!Object.create){Object.create=function(b){if(arguments.length>1){throw new Error("Object.create implementation only accepts the first parameter.")}function a(){}a.prototype=b;return new a()}}if(typeof String.prototype.trim!=="function"){String.prototype.trim=function(){return this.replace(/^\s+|\s+$/g,"")}}if(!Array.prototype.indexOf){Array.prototype.indexOf=function(a){var c=this.length>>>0;var b=Number(arguments[1])||0;b=(b<0)?Math.ceil(b):Math.floor(b);if(b<0){b+=c}for(;b<c;b++){if(b in this&&this[b]===a){return b}}return -1}}MadCap.Extend=function(a,b){b.prototype=Object.create(a.prototype);b.prototype.constructor=b;b.prototype.base
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:ASCII text, with CRLF, LF line terminators
    Category:dropped
    Size (bytes):2903
    Entropy (8bit):5.197724022688476
    Encrypted:false
    SSDEEP:48:chJw6PvjR8QHvs6IE33rxF7LIGyvmfXIxGPylNSgPcBcCL+yBxL:sPbKQHdrzIZul2g1HL
    MD5:F5511D5F62DC60F87759FDA56B1A170E
    SHA1:923E275729FD6D1D4624A9A6983C7D2D4A76E741
    SHA-256:83904CC9493D1BF70AFB36D88D1FDAEEB6C1C4DAB69D617D158C2982AE9E358D
    SHA-512:EE9D9A3386BF3A183A041D67CAED51D74E8EFFBF975315CD3BE96FD1AE8EF72CBA6C2AE2FD2763B13A5958D5BD3081E1DAE4F8FCB6FE5E45E9D888F70E594531
    Malicious:false
    Reputation:low
    Preview:/*..Copyright (c) 2011 ZURB, http://www.zurb.com/....Permission is hereby granted, free of charge, to any person obtaining..a copy of this software and associated documentation files (the.."Software"), to deal in the Software without restriction, including..without limitation the rights to use, copy, modify, merge, publish,..distribute, sublicense, and/or sell copies of the Software, and to..permit persons to whom the Software is furnished to do so, subject to..the following conditions:....The above copyright notice and this permission notice shall be..included in all copies or substantial portions of the Software.....THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND,..EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF..MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND..NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE..LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION..OF CONTRACT, TORT OR OTHERWISE, ARISING FR
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:ASCII text, with very long lines (15466), with CRLF line terminators
    Category:dropped
    Size (bytes):15658
    Entropy (8bit):5.032978106701097
    Encrypted:false
    SSDEEP:384:rsRbAgnKQT/X/+JvBIuJcOvH86xmAUZjCIrZ9D:wRbAq/XW8Of85trZ9D
    MD5:0306BF23D93EFECF4422B22FCD27DE27
    SHA1:B4E791985690F8F9D3A20F2399A2409E57636CDF
    SHA-256:BFEA62BA9211CA7F91BA83C8A92CE8A60EB255EF6C3C1DD69426DA8DB917367C
    SHA-512:C80F4A504AE5049A7858237360864B9A5F567B378AC46068C53465425A49B9912944F96CB96076ECDA0F575E394A8CC102F6FCEC16516B69BB0F69DBE203D83D
    Malicious:false
    Reputation:low
    Preview:/*.. * Foundation Responsive Library.. * http://foundation.zurb.com.. * Copyright 2013, ZURB.. * Free to use under the MIT license... * http://www.opensource.org/licenses/mit-license.php..*/..(function (e, t, n, r) { "use strict"; function i(e) { "use strict"; var t, n = this; this.trackingClick = false; this.trackingClickStart = 0; this.targetElement = null; this.touchStartX = 0; this.touchStartY = 0; this.lastTouchIdentifier = 0; this.touchBoundary = 10; this.layer = e; if (!e || !e.nodeType) { throw new TypeError("Layer must be a document node") } this.onClick = function () { return i.prototype.onClick.apply(n, arguments) }; this.onMouse = function () { return i.prototype.onMouse.apply(n, arguments) }; this.onTouchStart = function () { return i.prototype.onTouchStart.apply(n, arguments) }; this.onTouchMove = function () { return i.prototype.onTouchMove.apply(n, arguments) }; this.onTouchEnd = function () { return i.prototype.onTouchEnd.apply(n, arguments) }; this.onTouchCancel = fun
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:ASCII text, with very long lines (65430), with CRLF line terminators
    Category:dropped
    Size (bytes):104836
    Entropy (8bit):4.982346252587675
    Encrypted:false
    SSDEEP:3072:AiW6e9xmwHU3dZtnMrwis3ZlPrB9SxRGebDU0:AiI9xE3dZtnMrwN3rPERTbDU0
    MD5:A24F29B74EF67CD254D531FDA2324BB5
    SHA1:FB9C0A10BB7DE33179C643FF40054F2BD740DB13
    SHA-256:C1CD2D68BF3D0F424987EE9B2B8D59568404C40383E6858B4717379B372E6120
    SHA-512:4D1925B0B7E2DC8A45C6462F18778EF843B1DB747360A99A233AAEEB85A14DADE41EE1957FA2DF92F4E31E2FC5E8D96E1C59C739CF99F74E5FF90EFF2F527918
    Malicious:false
    Reputation:low
    Preview:/* jQuery begin */../*! jQuery v3.3.1 | (c) JS Foundation and other contributors | jquery.org/license */..!function (e, t) { "use strict"; "object" == typeof module && "object" == typeof module.exports ? module.exports = e.document ? t(e, !0) : function (e) { if (!e.document) throw new Error("jQuery requires a window with a document"); return t(e) } : t(e) }("undefined" != typeof window ? window : this, function (e, t) { "use strict"; var n = [], r = e.document, i = Object.getPrototypeOf, o = n.slice, a = n.concat, s = n.push, u = n.indexOf, l = {}, c = l.toString, f = l.hasOwnProperty, p = f.toString, d = p.call(Object), h = {}, g = function e(t) { return "function" == typeof t && "number" != typeof t.nodeType }, y = function e(t) { return null != t && t === t.window }, v = { type: !0, src: !0, noModule: !0 }; function m(e, t, n) { var i, o = (t = t || r).createElement("script"); if (o.text = e, n) for (i in v) n[i] && (o[i] = n[i]); t.head.appendChild(o).parentNode.removeChild(o) } f
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java archive data (JAR)
    Category:dropped
    Size (bytes):8481860
    Entropy (8bit):7.999656150996925
    Encrypted:true
    SSDEEP:196608:3IY4Su7OjkZCrpJt2zfhTjpDnsWLiLzvYIq1sgg5yC0vP:3IPROjgIT8DkN8IqugJ/vP
    MD5:1182345CB2CFD5676B5960F9967F4D46
    SHA1:8BC0F8CDEF7CE4EF948DFC2BCB645F607AFD3A66
    SHA-256:74BBFED59768B6262C1FD3539BEF920F9DE324663D14EFB4ECBB3137BBE467E2
    SHA-512:9E3BA9FC4639684CA3441EA8DDB3AE5F6B69BF602AA3D1A747204A81687C8148F449ED62C744ED7D8767C0778BEB1DEE43A1A76503B4BC7F1A568DC2A8B11E62
    Malicious:false
    Reputation:low
    Preview:PK........0wpK................META-INF/....PK......../wpK.r..\...h.......META-INF/MANIFEST.MF.M..LK-...K-*...R0.3..r.C.q,HL.HU...%-.Lx...R.KRSt.*A.-......u....4....sR......K..h.r.r..PK........-wpK................css/PK........-wpK................images/PK........-wpK................scripts/PK........-wpK................scripts/OpenLayers-2.9.1/PK........-wpK................scripts/OpenLayers-2.9.1/art/PK........-wpK................scripts/OpenLayers-2.9.1/img/PK........-wpK................scripts/OpenLayers-2.9.1/theme/PK........-wpK............'...scripts/OpenLayers-2.9.1/theme/default/PK........-wpK............+...scripts/OpenLayers-2.9.1/theme/default/img/PK........-wpK.eF._...a.......META-INF/context.xml.....Q(K-*...U2.3PRH.K.O..K.U..q.P....q..+I.(QH.+..r...O..+))*MUR(H,.U...w...OI..L-O-R..j..PK........-wpK........21......css/basic.css.ZYo..~N....E...xI.....)0].i..P...C..E...../IQ.)Q^.{:E5.&!..;....p.^..."..f...l..@.!..+.B..K.?...........q<.#)..f...n/.x....F.L..<../....
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java KeyStore
    Category:dropped
    Size (bytes):122936
    Entropy (8bit):7.357284845286926
    Encrypted:false
    SSDEEP:1536:itPeatPM756akto7bwtQDj2T5aQngvi5wyiH3MnD17a9Da/5ykMUxeSwnUDzTF42:OkFVbXknSW/yUcb7NvSp
    MD5:ECC7E7A950CC146CD6155F1D4ACB6AAE
    SHA1:5AC2B4D8AF377B831CC498AAF0077468BA948E18
    SHA-256:ED237DA76EE1F63414905397C4069CCEC6BAE26A3F74F5DCEDEF1E88BA93810D
    SHA-512:42E27F8F47F422D0E07CDB82A0BB5D1ED938B5E5B6D26A4BB21307C926F5C27B78CF744E637A850CDBADFC27C33FF671F8E45AF70C92FCB6182583B7D13C1CB2
    Malicious:false
    Reputation:low
    Preview:...........p......keychainrootca-34...../...X.509....0...0..[........0...*.H........0...1.0...U....ES1.0...U....Barcelona1.0...U....Barcelona1.0,..U...%IPS Internet publishing Services s.l.1+0)..U..."ips@mail.ips.es C.I.F. B-609294521.0,..U...%IPS CA CLASE1 Certification Authority1.0,..U...%IPS CA CLASE1 Certification Authority1.0...*.H........ips@mail.ips.es0...011231111103Z..251229111103Z0...1.0...U....ES1.0...U....Barcelona1.0...U....Barcelona1.0,..U...%IPS Internet publishing Services s.l.1+0)..U..."ips@mail.ips.es C.I.F. B-609294521.0,..U...%IPS CA CLASE1 Certification Authority1.0,..U...%IPS CA CLASE1 Certification Authority1.0...*.H........ips@mail.ips.es0..0...*.H............0............t.....nG._?.....3......to....W/.v..n.......@..j..j..-..-.....G].S.]T.'tc.~..1...O.u/..,YL..V(..b.....V..-%u.;"j.........R0..N0...U......m[...a7..x......A..y0..D..U.#...;0..7..m[...a7..x......A..y........0...1.0...U....ES1.0...U....Barcelona1.0...U....Barcelona1.0,..U...%IPS Interne
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:JPEG image data, JFIF standard 1.02, resolution (DPI), density 72x72, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop CS4 Macintosh, datetime=2009:09:02 08:17:23], baseline, precision 8, 4096x4096, components 1
    Category:dropped
    Size (bytes):1727431
    Entropy (8bit):7.058287286120259
    Encrypted:false
    SSDEEP:24576:xNrruNiPUJD2mbV66YlaoDPz9tw1/XGFt3M718Y+C++/susDi/6SEm7QOUqI5jA9:G+CDvqED0BUI8OzDT3cFckz
    MD5:1F31A2D6DA883A47C2B38A8BAD653D7B
    SHA1:104CAC2E9CD8D236F25FEAC17BE417D37ECB055E
    SHA-256:5191ED16508ABDF9387E3A12016693ED5CF8760A4CBD27B1035130DFE7AC9285
    SHA-512:6B51F8D1C982900CC355BEACE168506C4F589402A35E3FC86F20AF2814546BACA4F65F8070A8A404890E541F265CEB0883EB5DFE0F4A82941451D9BEA9F65428
    Malicious:false
    Reputation:low
    Preview:......JFIF.....H.H.....xExif..MM.*.............................b...........j.(...........1.........r.2...........i....................'.......'.Adobe Photoshop CS4 Macintosh.2009:09:02 08:17:23..................................................................................&.(.................................B.......H.......H..........JFIF.....H.H......Adobe_CM......Adobe.d......................................................................................................................................................"................?..........................................................................3......!.1.AQa."q.2.....B#$.R.b34r..C.%.S...cs5....&D.TdE.t6..U.e...u..F'...............Vfv........7GWgw........................5.....!1..AQaq"..2.....B#.R..3$b.r..CS.cs4.%......&5..D.T..dEU6te....u..F...............Vfv........'7GWgw.................?...zi....UM.........k}.kZ..x.....<..IJ G...J..D....J...IJh..J..;...s...'^..%(..w..(...c....(>?.%(..D.n:v.. ..."Pd....
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):44276
    Entropy (8bit):3.97500740258782
    Encrypted:false
    SSDEEP:384:TBzT0d1bUNR7EUCT0d1bgeU6cQT0d1b3QZjwT0d1b3q:dvIU9m
    MD5:123D9AA3E11EF98A8761A640F1952E54
    SHA1:3D032CE920FC64FB10E6BB66E56FD92AFBF64816
    SHA-256:02A6905B5B7937CCEA8554958E3CF6AE2E706152DB9A40132A662BE35759FF4A
    SHA-512:CEDBAFF647A7A0DA568DBFA6BF512DFC81E5D5095E836B92E4E41F89054CDD72AF17C78947AFC2B58574E3FCC7D69ACACFEC5B775F44D2573DAE1C6A73E89C5A
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?> .<java version="1.5.0_04" class="java.beans.XMLDecoder"> . <object class="java.util.ArrayList"> . <void method="add"> . <object class="OLServices.FlexModuleDef"> . <void property="currentUnits"> . <string>mA</string> . </void> . <void property="gainCurHighValues"> . <object class="java.util.ArrayList"> . <void method="add"> . <float>1.4E-45</float> . </void> . <void method="add"> . <float>1.4E-45</float> . </void> . <void method="add"> . <float>1.4E-45</float> . </void> . <void method="add"> . <float>20.0</float> . </void> . </object> . </void> . <void property="gainCurLowValues"> . <object class="java.util.ArrayList"> . <void method="add"> . <float>1.4E-45</float> . </void> . <void method="add"> . <float>1.4E-45</float> . </void> . <void method="add"> . <float>1.4E-45</float> . </void> . <void meth
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:C++ source, ASCII text
    Category:dropped
    Size (bytes):7640
    Entropy (8bit):4.497733668710008
    Encrypted:false
    SSDEEP:192:l6rsdrsQXJ3r37e6E3H8QKHUHpI3Nx21wo98muW0g2:ArsdrsU5D7u3HnKHUJy721wo98jv1
    MD5:DE902252F62A4C6541F412F916145057
    SHA1:8730178ECAB4489E65B2AA4BF8B922ADB2C46A94
    SHA-256:09C6C4E7C4F5E343BF238EC6C0DEEA61B35E74E0034A5F3E7D49BA119C75D8B4
    SHA-512:25EA473FA3EE0E74FB3B1929DF21F4C87B980BDCC5F4E9ECA931127CAABF853E767710D570E112BADD9E7A7B375FA0D4736892AF6C262A110BE26212E94DA703
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 1995, 2011, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABI
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java source, ASCII text
    Category:dropped
    Size (bytes):16493
    Entropy (8bit):4.240656223447306
    Encrypted:false
    SSDEEP:384:SrsdrsU5D7u3lWru/65uITiadBrFzoe166THt3:SAPD7UlWru/FIT/VF15
    MD5:BC9F9EC334FCFE3353EFF414ED84B9A1
    SHA1:59968CA1570D2358823023F7DC37C5981C3FC1BF
    SHA-256:0630E720BD485B6FFDDA069D5C013A47F4AFE8FA237A1656322C84C2272394D3
    SHA-512:BF81EF7B59B4330842AB7243613A669CE3FFCD6601888FA966E746450B466B43D26CE073C04EDF40A57E74F1E76C0D836CC55BBB60461EFEFC62B5FEBC34E58B
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 1995, 2013, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABI
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java archive data (JAR)
    Category:dropped
    Size (bytes):38569
    Entropy (8bit):7.956651983631013
    Encrypted:false
    SSDEEP:768:MiKQj8zxT5YuwmOSkvQHozMlCIEBne8bpMTqAqJk1erunSYaAHLps:/KQId+uwGMfoAIEBe81Oqq1O5WG
    MD5:AF2E14AC9DF3D9B2BB9BEF85762B72EB
    SHA1:5D21D532098800D60591EAAD8A7DAB2AFCE266A3
    SHA-256:E0E9DB378B29A5FDEF07583AF7EA2A125CAF2DBE465125ACDEEB317A5357D465
    SHA-512:59BC4ADC10A857046EB243A160200E1CC77D6BD075CC06405F3F579E78FE41D5A93BDAE0FBE3A99A58207C89B8A0238AD1E16C49BAEA7ADC2B9B2F1335683912
    Malicious:false
    Reputation:low
    Preview:PK..........V................META-INF/......PK..............PK..........V................META-INF/MANIFEST.MFm...A...~`.!....(..t.XA..[.c..f2Kv...}..69..L.mIuL.$...A;miU..'../.de...&x@X.9ZO0..W.....ik..w.ZVdli.C.6H.3A... U...[..;.e...y...7..@.\.#m...Y.....)pj...M.......j....a]g....H+..PK... .....M...PK..........V................example1.htmlm.AO.0....W.......AZ.18...$..m.&S.L..i....Hh..X_......V.....T.....a...%../CM.....fZ..L.^_...y.....GK.M$.f.M.X....mNT~..7...2.M+.\.V..tZRY-n..#..be.D.v.2./.h.....Yd..J.}...f...0..8..6.h........u.....;............=.=C.=.....,...0!~.O4....y..\.........A.k_f?....Y...B.m..X.c>S,1.1.oPK....Ai .......PK..........V................example2.htmlmQ.n.0.=...z`..2q.m.Il.M.4..6..J.. .~I;........Wj.m=.(5.JE:...T.6..........\..K".WF.xu.Q..]^l..|+.x.$.Ft..L..[.!.r.../....S~@..Q...r..L.%...<b.....O.pB;P...P(.0."..!.x..Re.~`h..1.N..A...&.[Y.n..o.y'k....LpO.<8g\7..........L.....G..h..d/`:..:....b....D..U....O..8.D.".....b.c.?PK..g.b."
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java source, ASCII text
    Category:dropped
    Size (bytes):16493
    Entropy (8bit):4.240656223447306
    Encrypted:false
    SSDEEP:384:SrsdrsU5D7u3lWru/65uITiadBrFzoe166THt3:SAPD7UlWru/FIT/VF15
    MD5:BC9F9EC334FCFE3353EFF414ED84B9A1
    SHA1:59968CA1570D2358823023F7DC37C5981C3FC1BF
    SHA-256:0630E720BD485B6FFDDA069D5C013A47F4AFE8FA237A1656322C84C2272394D3
    SHA-512:BF81EF7B59B4330842AB7243613A669CE3FFCD6601888FA966E746450B466B43D26CE073C04EDF40A57E74F1E76C0D836CC55BBB60461EFEFC62B5FEBC34E58B
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 1995, 2013, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABI
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Zip archive data, at least v2.0 to extract, compression method=deflate
    Category:dropped
    Size (bytes):37882
    Entropy (8bit):7.965443906062041
    Encrypted:false
    SSDEEP:768:agAJsBuwmOSkvQHozUlCIEBne8bpMTqAeJk1erunSYpopv2U9djn2:fAOuwGMfQAIEBe81Oeq1O5dpD9dq
    MD5:CC2CFA0A5961A351AFFC19FF5A379EDA
    SHA1:0A1D7DE604D666044288C08000F6668AE574934B
    SHA-256:DCD2ED9EFC8BCD12D8F76F074DE736F5338A30E32F79F849E2FF6660837AD8AF
    SHA-512:61BCE6CB337A7692160C02355C8D54D06CFE20E609AA815E64C9EE9C73DBCA246D7EA68FA4119AA6E127E6FB1977AE6E2983512BCB0317CECC64C0B3D4274E41
    Malicious:false
    Reputation:low
    Preview:PK...........V..Ai ...........example1.htmlUT...%..d%..dux.............m.AO.0....W.......AZ.18...$..m.&S.L..i....Hh..X_......V.....T.....a...%../CM.....fZ..L.^_...y.....GK.M$.f.M.X....mNT~..7...2.M+.\.V..tZRY-n..#..be.D.v.2./.h.....Yd..J.}...f...0..8..6.h........u.....;............=.=C.=.....,...0!~.O4....y..\.........A.k_f?....Y...B.m..X.c>S,1.1.oPK...........Vg.b."...........example2.htmlUT...%..d%..dux.............mQ.n.0.=...z`..2q.m.Il.M.4..6..J.. .~I;........Wj.m=.(5.JE:...T.6..........\..K".WF.xu.Q..]^l..|+.x.$.Ft..L..[.!.r.../....S~@..Q...r..L.%...<b.....O.pB;P...P(.0."..!.x..Re.~`h..1.N..A...&.[Y.n..o.y'k....LpO.<8g\7..........L.....G..h..d/`:..:....b....D..U....O..8.D.".....b.c.?PK...........V9.}.&...........example3.htmlUT...%..d%..dux.............mQ.j.0.=._...]F.QvY....;l.Ca.4.D.]...JK.~N....,..g.Wh.l9.(4a3..)..r....}......l..../*..D.p....w....[..#Vm4....b..\ks .i.^.;Jw.p4.h..s.dZ-CY.n.=F...S. ...=.d..L...~...W.$2..J.|.P.?.b.]C..].@4....y.~...[Y.
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:C++ source, ASCII text
    Category:dropped
    Size (bytes):7640
    Entropy (8bit):4.497733668710008
    Encrypted:false
    SSDEEP:192:l6rsdrsQXJ3r37e6E3H8QKHUHpI3Nx21wo98muW0g2:ArsdrsU5D7u3HnKHUJy721wo98jv1
    MD5:DE902252F62A4C6541F412F916145057
    SHA1:8730178ECAB4489E65B2AA4BF8B922ADB2C46A94
    SHA-256:09C6C4E7C4F5E343BF238EC6C0DEEA61B35E74E0034A5F3E7D49BA119C75D8B4
    SHA-512:25EA473FA3EE0E74FB3B1929DF21F4C87B980BDCC5F4E9ECA931127CAABF853E767710D570E112BADD9E7A7B375FA0D4736892AF6C262A110BE26212E94DA703
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 1995, 2011, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABI
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java archive data (JAR)
    Category:dropped
    Size (bytes):38569
    Entropy (8bit):7.956651983631013
    Encrypted:false
    SSDEEP:768:MiKQj8zxT5YuwmOSkvQHozMlCIEBne8bpMTqAqJk1erunSYaAHLps:/KQId+uwGMfoAIEBe81Oqq1O5WG
    MD5:AF2E14AC9DF3D9B2BB9BEF85762B72EB
    SHA1:5D21D532098800D60591EAAD8A7DAB2AFCE266A3
    SHA-256:E0E9DB378B29A5FDEF07583AF7EA2A125CAF2DBE465125ACDEEB317A5357D465
    SHA-512:59BC4ADC10A857046EB243A160200E1CC77D6BD075CC06405F3F579E78FE41D5A93BDAE0FBE3A99A58207C89B8A0238AD1E16C49BAEA7ADC2B9B2F1335683912
    Malicious:false
    Reputation:low
    Preview:PK..........V................META-INF/......PK..............PK..........V................META-INF/MANIFEST.MFm...A...~`.!....(..t.XA..[.c..f2Kv...}..69..L.mIuL.$...A;miU..'../.de...&x@X.9ZO0..W.....ik..w.ZVdli.C.6H.3A... U...[..;.e...y...7..@.\.#m...Y.....)pj...M.......j....a]g....H+..PK... .....M...PK..........V................example1.htmlm.AO.0....W.......AZ.18...$..m.&S.L..i....Hh..X_......V.....T.....a...%../CM.....fZ..L.^_...y.....GK.M$.f.M.X....mNT~..7...2.M+.\.V..tZRY-n..#..be.D.v.2./.h.....Yd..J.}...f...0..8..6.h........u.....;............=.=C.=.....,...0!~.O4....y..\.........A.k_f?....Y...B.m..X.c>S,1.1.oPK....Ai .......PK..........V................example2.htmlmQ.n.0.=...z`..2q.m.Il.M.4..6..J.. .~I;........Wj.m=.(5.JE:...T.6..........\..K".WF.xu.Q..]^l..|+.x.$.Ft..L..[.!.r.../....S~@..Q...r..L.%...<b.....O.pB;P...P(.0."..!.x..Re.~`h..1.N..A...&.[Y.n..o.y'k....LpO.<8g\7..........L.....G..h..d/`:..:....b....D..U....O..8.D.".....b.c.?PK..g.b."
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Zip archive data, at least v2.0 to extract, compression method=deflate
    Category:dropped
    Size (bytes):37882
    Entropy (8bit):7.965443906062041
    Encrypted:false
    SSDEEP:768:agAJsBuwmOSkvQHozUlCIEBne8bpMTqAeJk1erunSYpopv2U9djn2:fAOuwGMfQAIEBe81Oeq1O5dpD9dq
    MD5:CC2CFA0A5961A351AFFC19FF5A379EDA
    SHA1:0A1D7DE604D666044288C08000F6668AE574934B
    SHA-256:DCD2ED9EFC8BCD12D8F76F074DE736F5338A30E32F79F849E2FF6660837AD8AF
    SHA-512:61BCE6CB337A7692160C02355C8D54D06CFE20E609AA815E64C9EE9C73DBCA246D7EA68FA4119AA6E127E6FB1977AE6E2983512BCB0317CECC64C0B3D4274E41
    Malicious:false
    Reputation:low
    Preview:PK...........V..Ai ...........example1.htmlUT...%..d%..dux.............m.AO.0....W.......AZ.18...$..m.&S.L..i....Hh..X_......V.....T.....a...%../CM.....fZ..L.^_...y.....GK.M$.f.M.X....mNT~..7...2.M+.\.V..tZRY-n..#..be.D.v.2./.h.....Yd..J.}...f...0..8..6.h........u.....;............=.=C.=.....,...0!~.O4....y..\.........A.k_f?....Y...B.m..X.c>S,1.1.oPK...........Vg.b."...........example2.htmlUT...%..d%..dux.............mQ.n.0.=...z`..2q.m.Il.M.4..6..J.. .~I;........Wj.m=.(5.JE:...T.6..........\..K".WF.xu.Q..]^l..|+.x.$.Ft..L..[.!.r.../....S~@..Q...r..L.%...<b.....O.pB;P...P(.0."..!.x..Re.~`h..1.N..A...&.[Y.n..o.y'k....LpO.<8g\7..........L.....G..h..d/`:..:....b....D..U....O..8.D.".....b.c.?PK...........V9.}.&...........example3.htmlUT...%..d%..dux.............mQ.j.0.=._...]F.QvY....;l.Ca.4.D.]...JK.~N....,..g.Wh.l9.(4a3..)..r....}......l..../*..D.p....w....[..#Vm4....b..\ks .i.^.;Jw.p4.h..s.dZ-CY.n.=F...S. ...=.d..L...~...W.$2..J.|.P.?.b.]C..].@4....y.~...[Y.
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java archive data (JAR)
    Category:dropped
    Size (bytes):12663
    Entropy (8bit):7.817681750861166
    Encrypted:false
    SSDEEP:384:U/bTBh+pXo26UaS12wTPj6SO8tXqktj6r:U/bTBh+pXokXbQkt2
    MD5:9AB7F7C481B2A30281D4F24AB8744BE4
    SHA1:4C0DCBB69241FB1BECE6D0ACD64299DF816972D6
    SHA-256:48DC8DADADB2DBF6A383C6ED21D65C092DC0302541F4E176A052BF47B7425047
    SHA-512:2D4491F1D1E8911E2462D271B6C9A856AD038B1C394633C06174DED71897BE3356A237E99EE59E6B56EF82C859E47D15F15AECD6A6926E2E60A2FE4150734E7E
    Malicious:false
    Reputation:low
    Preview:PK..........V................META-INF/......PK..............PK..........V................META-INF/MANIFEST.MFm.1k.@..........u..o.....iJ. .2..$s..._.%i.d..x.S...M){.8.J..yaM.FO.$a:..WN.*x....]......U.....l....f?....^c....'.5....k.r.....6].....?.k.H....g.U.....*.....|q._.+..Y...4UG..:eIMk.5_PK....a/....R...PK..........V................CodePointIM.classm.]S.@...m.n...bQQ.-)h.."....f.i....WiX;.m.I7...k.../...(.....Ev..{..d.........:&Q.`A..\.q..Y\..nF...e.p...m...9V9L.....eH..C...$..+....V]..z.2Z.....r.|v...5........r.OU....A..a..W2........~....La.a6..X.)..hG....5.s.1p.e...=.g._..#K...c..#l2,.-.J6...tH.......m%}..cl.x.m....Pg...~,\5H...:Q.zC....6...Y../.......;..T>..G8...0L..z.}.(...A...WI.: .".pZv.o.P.._.M..a.....I....Y.(.....8.t..._:......I.ESA....ie...~.......q.I.a.L."I..K...A.|Gj=..w....8.B.H.a.4f.Q J"..i.lR....Y..<vH....X..V..s..H...........PK..q.d.........PK..........V............D...com/sun/inputmethods/internal/codepointim/CodePointInpu
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:HTML document, ASCII text
    Category:dropped
    Size (bytes):3230
    Entropy (8bit):4.811225881707454
    Encrypted:false
    SSDEEP:48:7tUq66QEkPNF1Or1Xg7LMokcSke+mXJlYU14VuIdid27pi:73uEINF1Or1w5Tj3mXnKhdid27E
    MD5:1B280A86EE86CFC279300120D3861014
    SHA1:65A9B9AE6BBFB21A0CC33C11D63EE032F7B1B125
    SHA-256:A21FB253F5AD6F06CB3BE7540439D16B3D0D19B322DD7475D1C7B6E37CDA044D
    SHA-512:6AA67A1FA20CEF9E0A0FF055870F5EE0EDC9CB4D441FF7E5B577F59B1CEE5BEF4B760692F41EA3F38CE1C7DC547764D941A14F6A40CF32BFE32ED65640F82A82
    Malicious:false
    Reputation:low
    Preview:<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">.<html>.<head>. <title>README - CodePointIM</title>. <meta http-equiv="content-type" content="text/html; charset=ISO-8859-1">.</head>.<body>.<h1>Code Point Input Method</h1>.<p>.The Code Point Input Method is a simple input method that allows Unicode.characters to be entered using their code point or code unit values..<p>.The input method accepts three different notations, all using hexadecimal.digits from the set [0-9a-fA-F]:.<br>.<ul>. <li>"\uxxxx": The standard Unicode escape notation of the Java programming.language. This notation allows input of code points up to U+FFFE; the illegal.code point U+FFFF is not allowed.</li>. <li>"\Uxxxxxx": An extended Unicode escape notation specific to this input.method. This notation allows direct input of any Unicode code Point except the.illegal code point U+FFFF. The uppercase "U" indicates that six hexadecimal.digits follow. "xxxxxx" must be between 000000 and 10FFFF.</li>. <l
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:HTML document, Unicode text, UTF-8 text, with very long lines (480)
    Category:dropped
    Size (bytes):4499
    Entropy (8bit):5.481551762672928
    Encrypted:false
    SSDEEP:96:DLwJSjKDNiRlUs2tJn+0GY5IZnH4EGRGlaCFl3J1idO8b:DLRjws2tJzUb3eQ8b
    MD5:13025FBA899D8838C5C930168BA715C3
    SHA1:340C776BA99E000E47B7A8AA64AEFA6BCFB25AAF
    SHA-256:3970F66C098F3B6758B4788A17A73A0FD6615BF11A5D5EDAE52E05EBD902600A
    SHA-512:8071119AFD42FC4799E520EB274D8468A02FA1D0FB40C94A591F8D15F61CB9463A24B74209F012588845CA060DC708303A7FD38BE15E0C36102F41DB529AB86D
    Malicious:false
    Reputation:low
    Preview:<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">.<html>.<head>. <meta content="text/html; charset=UTF-8" http-equiv="content-type">. <title>README - CodePointIM</title>.</head>.<body>.<h1>Code Point Input Method</h1>.<p>.Code Point Input Method.....................Unicode.........................<p>....................0.9.a.f.A.F......................<br>.<ul>. <li>"\uxxxx".Java............Unicode..................U+0000..U+FFFE...............................U+FFFF.........</li>. <li>"\Uxxxxxx".................Unicode.........................Unicode......
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:HTML document, Unicode text, UTF-8 (with BOM) text
    Category:dropped
    Size (bytes):3041
    Entropy (8bit):6.371616946844483
    Encrypted:false
    SSDEEP:48:uLz69ncz4GVz0j4kOTaSuuOpZebhE/u8WRYwwjp4HEHR787:uLkncz4G6jJbSuBvWhmXWRYnjR787
    MD5:5656477DE19CED3165443DD73DED0130
    SHA1:17CD4ED80CDA5CA10B06ABD19CA680024FD57056
    SHA-256:24D3CE1C116D3CA1964586E8975584B6E2017A0031321003FE595CBE337F3770
    SHA-512:10BFBD6A1F924D0E60D8A4E32547311B3D192DDC24AA2A37D12BA925BA02B1FD2037B3D9152487E6BF4ACCE51ADA17F8996A3169EAA2115DF84CD7CF7DF8AB57
    Malicious:false
    Reputation:low
    Preview:.<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">.<html>.<head>. <title>............</title>. <meta http-equiv="content-type" content="text/html; charset=UTF-8">.</head>.<body>.<h1>......</h1>.<p>....................... Unicode ............... Unicode ....</p>.<p>............................ [0-9a-fA-F] ........ <br>.</p>.<ul>. <li>"\uxxxx".Java ....... Unicode ................. U+FFFE................ U+FFFF.</li>. <li>"\Uxxxxxx".......... Unicode .................. Unicode........... U+FFFF ..... "U" ............."xxxxxx" ... 000000 . 10FFFF....</li>. <li>"\uxxxx\uyyyy"..
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:HTML document, Unicode text, UTF-8 (with BOM) text
    Category:dropped
    Size (bytes):3041
    Entropy (8bit):6.371616946844483
    Encrypted:false
    SSDEEP:48:uLz69ncz4GVz0j4kOTaSuuOpZebhE/u8WRYwwjp4HEHR787:uLkncz4G6jJbSuBvWhmXWRYnjR787
    MD5:5656477DE19CED3165443DD73DED0130
    SHA1:17CD4ED80CDA5CA10B06ABD19CA680024FD57056
    SHA-256:24D3CE1C116D3CA1964586E8975584B6E2017A0031321003FE595CBE337F3770
    SHA-512:10BFBD6A1F924D0E60D8A4E32547311B3D192DDC24AA2A37D12BA925BA02B1FD2037B3D9152487E6BF4ACCE51ADA17F8996A3169EAA2115DF84CD7CF7DF8AB57
    Malicious:false
    Reputation:low
    Preview:.<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">.<html>.<head>. <title>............</title>. <meta http-equiv="content-type" content="text/html; charset=UTF-8">.</head>.<body>.<h1>......</h1>.<p>....................... Unicode ............... Unicode ....</p>.<p>............................ [0-9a-fA-F] ........ <br>.</p>.<ul>. <li>"\uxxxx".Java ....... Unicode ................. U+FFFE................ U+FFFF.</li>. <li>"\Uxxxxxx".......... Unicode .................. Unicode........... U+FFFF ..... "U" ............."xxxxxx" ... 000000 . 10FFFF....</li>. <li>"\uxxxx\uyyyy"..
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java archive data (JAR)
    Category:dropped
    Size (bytes):12663
    Entropy (8bit):7.817681750861166
    Encrypted:false
    SSDEEP:384:U/bTBh+pXo26UaS12wTPj6SO8tXqktj6r:U/bTBh+pXokXbQkt2
    MD5:9AB7F7C481B2A30281D4F24AB8744BE4
    SHA1:4C0DCBB69241FB1BECE6D0ACD64299DF816972D6
    SHA-256:48DC8DADADB2DBF6A383C6ED21D65C092DC0302541F4E176A052BF47B7425047
    SHA-512:2D4491F1D1E8911E2462D271B6C9A856AD038B1C394633C06174DED71897BE3356A237E99EE59E6B56EF82C859E47D15F15AECD6A6926E2E60A2FE4150734E7E
    Malicious:false
    Reputation:low
    Preview:PK..........V................META-INF/......PK..............PK..........V................META-INF/MANIFEST.MFm.1k.@..........u..o.....iJ. .2..$s..._.%i.d..x.S...M){.8.J..yaM.FO.$a:..WN.*x....]......U.....l....f?....^c....'.5....k.r.....6].....?.k.H....g.U.....*.....|q._.+..Y...4UG..:eIMk.5_PK....a/....R...PK..........V................CodePointIM.classm.]S.@...m.n...bQQ.-)h.."....f.i....WiX;.m.I7...k.../...(.....Ev..{..d.........:&Q.`A..\.q..Y\..nF...e.p...m...9V9L.....eH..C...$..+....V]..z.2Z.....r.|v...5........r.OU....A..a..W2........~....La.a6..X.)..hG....5.s.1p.e...=.g._..#K...c..#l2,.-.J6...tH.......m%}..cl.x.m....Pg...~,\5H...:Q.zC....6...Y../.......;..T>..G8...0L..z.}.(...A...WI.: .".pZv.o.P.._.M..a.....I....Y.(.....8.t..._:......I.ESA....ie...~.......q.I.a.L."I..K...A.|Gj=..w....8.B.H.a.4f.Q J"..i.lR....Y..<vH....X..V..s..H...........PK..q.d.........PK..........V............D...com/sun/inputmethods/internal/codepointim/CodePointInpu
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:HTML document, ASCII text
    Category:dropped
    Size (bytes):3230
    Entropy (8bit):4.811225881707454
    Encrypted:false
    SSDEEP:48:7tUq66QEkPNF1Or1Xg7LMokcSke+mXJlYU14VuIdid27pi:73uEINF1Or1w5Tj3mXnKhdid27E
    MD5:1B280A86EE86CFC279300120D3861014
    SHA1:65A9B9AE6BBFB21A0CC33C11D63EE032F7B1B125
    SHA-256:A21FB253F5AD6F06CB3BE7540439D16B3D0D19B322DD7475D1C7B6E37CDA044D
    SHA-512:6AA67A1FA20CEF9E0A0FF055870F5EE0EDC9CB4D441FF7E5B577F59B1CEE5BEF4B760692F41EA3F38CE1C7DC547764D941A14F6A40CF32BFE32ED65640F82A82
    Malicious:false
    Reputation:low
    Preview:<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">.<html>.<head>. <title>README - CodePointIM</title>. <meta http-equiv="content-type" content="text/html; charset=ISO-8859-1">.</head>.<body>.<h1>Code Point Input Method</h1>.<p>.The Code Point Input Method is a simple input method that allows Unicode.characters to be entered using their code point or code unit values..<p>.The input method accepts three different notations, all using hexadecimal.digits from the set [0-9a-fA-F]:.<br>.<ul>. <li>"\uxxxx": The standard Unicode escape notation of the Java programming.language. This notation allows input of code points up to U+FFFE; the illegal.code point U+FFFF is not allowed.</li>. <li>"\Uxxxxxx": An extended Unicode escape notation specific to this input.method. This notation allows direct input of any Unicode code Point except the.illegal code point U+FFFF. The uppercase "U" indicates that six hexadecimal.digits follow. "xxxxxx" must be between 000000 and 10FFFF.</li>. <l
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:HTML document, Unicode text, UTF-8 text, with very long lines (480)
    Category:dropped
    Size (bytes):4499
    Entropy (8bit):5.481551762672928
    Encrypted:false
    SSDEEP:96:DLwJSjKDNiRlUs2tJn+0GY5IZnH4EGRGlaCFl3J1idO8b:DLRjws2tJzUb3eQ8b
    MD5:13025FBA899D8838C5C930168BA715C3
    SHA1:340C776BA99E000E47B7A8AA64AEFA6BCFB25AAF
    SHA-256:3970F66C098F3B6758B4788A17A73A0FD6615BF11A5D5EDAE52E05EBD902600A
    SHA-512:8071119AFD42FC4799E520EB274D8468A02FA1D0FB40C94A591F8D15F61CB9463A24B74209F012588845CA060DC708303A7FD38BE15E0C36102F41DB529AB86D
    Malicious:false
    Reputation:low
    Preview:<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">.<html>.<head>. <meta content="text/html; charset=UTF-8" http-equiv="content-type">. <title>README - CodePointIM</title>.</head>.<body>.<h1>Code Point Input Method</h1>.<p>.Code Point Input Method.....................Unicode.........................<p>....................0.9.a.f.A.F......................<br>.<ul>. <li>"\uxxxx".Java............Unicode..................U+0000..U+FFFE...............................U+FFFF.........</li>. <li>"\Uxxxxxx".................Unicode.........................Unicode......
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Zip archive data, at least v2.0 to extract, compression method=deflate
    Category:dropped
    Size (bytes):15270
    Entropy (8bit):7.800623409841461
    Encrypted:false
    SSDEEP:384:SbqvQ5fRQOwQHSczwT0j6SM+tXqktsMsZ:SuqRivAQkts
    MD5:7B06BF9E4BA977AD29B71C35EA8D8835
    SHA1:19820A4B27728BE57392376E7F9ADB83A264D223
    SHA-256:90A415D120DF2C139D57E8918DB6F1326E1130C76E8EDF70D5C5CB450390D3DD
    SHA-512:1587662CF059123B86DB693894E9041063E13AB2902F25EA7B240AFADCD2770AFA2FA512A72EBDAC0CE9889048AAE014EDE19B11249F4AE9D6C35D0489CA9759
    Malicious:false
    Reputation:low
    Preview:PK...........V.\......f.......CodePointIM.javaUT...%..d%..dux..............V.r.F....]>.--.M.....T.D$a.+..,.0.!.3#{].......;Nr..[h._.{........=>...;......?....c@.).ZQ.TW.!.,...u.PX...,.e.yP..x...J[g.}.t.0.uV.n..)=$..0O.m...........c.C[......0.....s...i.t.../..(..u.....mSiv...~..~:.F..Uz...W.V...%W _F....>:...5...`.-..d..........}Pf./. .4C6 \u...J.z..T..A5...........7...s.|.....9.Xi..6MqP..........l....p....D....,ZRM...[.y.Z.....X!At....y/.m.....ed........3.]M.g....2.,..o.T...ir#gbF.;.....]*...r&..x..q...&O.."..Jf..,..H|^.".(II..K.<.H.8.".H..r3..< `P..+..,O.>/.'%..i...p*.2..!.e.s.k..i....6.0e..&]'. .7.Y...J.&.$....s...r..or.....,9.;..6..E..tg2.Q..."..,..ek.I<0..,.*L.......e.;..,\.s....<.R.I.s.&.f..2...I2.g"....>.2.r.L.......P..,`>.d.k(.\..f..$.D.o..2..=.b'..........z.r.t..8JY^.Z.rdP/.....b.gd.'...8.l.0...%.'..Q9.m........G.;q...W..5..........<.../Z...{q5.]....[..T....U]..b..._...;?....6.U...><.T.o.........R..W.R?..c....Ca....&...O...v. :F(.&..
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Zip archive data, at least v2.0 to extract, compression method=deflate
    Category:dropped
    Size (bytes):15270
    Entropy (8bit):7.800623409841461
    Encrypted:false
    SSDEEP:384:SbqvQ5fRQOwQHSczwT0j6SM+tXqktsMsZ:SuqRivAQkts
    MD5:7B06BF9E4BA977AD29B71C35EA8D8835
    SHA1:19820A4B27728BE57392376E7F9ADB83A264D223
    SHA-256:90A415D120DF2C139D57E8918DB6F1326E1130C76E8EDF70D5C5CB450390D3DD
    SHA-512:1587662CF059123B86DB693894E9041063E13AB2902F25EA7B240AFADCD2770AFA2FA512A72EBDAC0CE9889048AAE014EDE19B11249F4AE9D6C35D0489CA9759
    Malicious:false
    Reputation:low
    Preview:PK...........V.\......f.......CodePointIM.javaUT...%..d%..dux..............V.r.F....]>.--.M.....T.D$a.+..,.0.!.3#{].......;Nr..[h._.{........=>...;......?....c@.).ZQ.TW.!.,...u.PX...,.e.yP..x...J[g.}.t.0.uV.n..)=$..0O.m...........c.C[......0.....s...i.t.../..(..u.....mSiv...~..~:.F..Uz...W.V...%W _F....>:...5...`.-..d..........}Pf./. .4C6 \u...J.z..T..A5...........7...s.|.....9.Xi..6MqP..........l....p....D....,ZRM...[.y.Z.....X!At....y/.m.....ed........3.]M.g....2.,..o.T...ir#gbF.;.....]*...r&..x..q...&O.."..Jf..,..H|^.".(II..K.<.H.8.".H..r3..< `P..+..,O.>/.'%..i...p*.2..!.e.s.k..i....6.0e..&]'. .7.Y...J.&.$....s...r..or.....,9.;..6..E..tg2.Q..."..,..ek.I<0..,.*L.......e.;..,\.s....<.R.I.s.&.f..2...I2.g"....>.2.r.L.......P..,`>.d.k(.\..f..$.D.o..2..=.b'..........z.r.t..8JY^.Z.rdP/.....b.gd.'...8.l.0...%.'..Q9.m........G.;q...W..5..........<.../Z...{q5.]....[..T....U]..b..._...;?....6.U...><.T.o.........R..W.R?..c....Ca....&...O...v. :F(.&..
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java archive data (JAR)
    Category:dropped
    Size (bytes):20453
    Entropy (8bit):7.902736091567514
    Encrypted:false
    SSDEEP:384:fvtbN6Zov6X8NF/vJi5gCjmCx9MxD/uSIeX2jhcw7LM8+HLar/:fuzXAvEiFjxDZzmjhc4LXQw
    MD5:DE8A451F571291B18B81367948FA0922
    SHA1:0D0BB9F03603733CAB70AD41A3A8F8922AA0AD42
    SHA-256:D0F58A4438CDE8C9A03D6E13CBF6724DF5AE28260D45F2C14F4A580D153E5189
    SHA-512:E2E122DC8B0A4B341F23BEF4B50BB5ED652AFAC26E02CD2ACA9726E8358D3EEBE0B66D0A82FA55AE2FCB7AB1E9807662B49ECEB9F3530A07CB82B49D8692B7C8
    Malicious:false
    Reputation:low
    Preview:PK..........V................META-INF/......PK..............PK..........V................META-INF/MANIFEST.MFm..J.A......C.z..eou....E.W..,.f.%3...[.mm.&....P..\.g..*...#.4DJ$..aXm.Dj`.;..7)...cS.D..$lR.^n'c....s...Uk..0D.VmP.Z.....WK0]w..]...x..a.mu..[.n.W..*u.......?.[.A.V.R..sn`...W.L6...y..PK..,.......V...PK..........V................ExampleFileSystemView.classmS]O.A.=.n..... `....X?@."..D...U.......4..-?.....B....o2.;[.,.d...9..............#........4c..#.U....t...]...I.Ra.4..<V..!<g.7...S........y..k..m.3.K.St...5^]....0...}.iX.X.J<.....Q.....Y.C.X.u.V..........[!<...S[..8...\...,.R2...2..i}m.....X.^V.4]U..N.K.C.r.,WJ...s...)...C..v=(.)......hx.Y......L...,..=..%.x..^.\..g..K~o.m.%..L.\.4.@V. .4.a........@...R=.TS3.*%m..a...w.f`Ws...Me.YE9..F..t| !zkX[..R.{.e.E._.\....Z.5@...+...L....[....E...0.t7.....#... ...t...}.`.a.9C..z.'..}..i5.....u.V'N.v..3.7cJ.._.h.r.P}..Q.~.~..jU..`..x.$r.....I;..0.......R.=.6..>@.. ...)...&..di$...t......fN.q..D......+u
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:ASCII text
    Category:dropped
    Size (bytes):586
    Entropy (8bit):4.512171391742326
    Encrypted:false
    SSDEEP:12:8SA0PMFI4N5X6KURTSASEyT8XjhyR7DVs/N8w3w9Rx21FexsXvV61Wtv:8z0IF+RH368t0DVs/NA9b21FIsXvYWv
    MD5:23386942A8ACA3DA4F792E3CF773E5B8
    SHA1:7228933C945403FAC62B1A9425E5FBF44DF73EE4
    SHA-256:224CBCC0D59B50973C37E8884F1F340D71918C17494632B093157EA7CF846CBE
    SHA-512:6A5FD4B8279BE523C86C06CD7988307C6F77AB390970432FCB4EF630EDB7B3EA3876ED83DCCC3B940EEBE8E533E1BC2765F46FCFD1E1DEA9133EA9CBD8CC05A3
    Malicious:false
    Reputation:low
    Preview:FileChooserDemo demonstrates some of the capabilities of the .JFileChooser object. It brings up a window displaying several.configuration controls that allow you to play with the.JFileChooser options dynamically.. .To run the FileChooserDemo demo:.. java -jar FileChooserDemo.jar..These instructions assume that this installation's version of the java.command is in your path. If it isn't, then you should either.specify the complete path to the java command or update your.PATH environment variable as described in the installation.instructions for the Java(TM) SE Development Kit..
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java archive data (JAR)
    Category:dropped
    Size (bytes):20453
    Entropy (8bit):7.902736091567514
    Encrypted:false
    SSDEEP:384:fvtbN6Zov6X8NF/vJi5gCjmCx9MxD/uSIeX2jhcw7LM8+HLar/:fuzXAvEiFjxDZzmjhc4LXQw
    MD5:DE8A451F571291B18B81367948FA0922
    SHA1:0D0BB9F03603733CAB70AD41A3A8F8922AA0AD42
    SHA-256:D0F58A4438CDE8C9A03D6E13CBF6724DF5AE28260D45F2C14F4A580D153E5189
    SHA-512:E2E122DC8B0A4B341F23BEF4B50BB5ED652AFAC26E02CD2ACA9726E8358D3EEBE0B66D0A82FA55AE2FCB7AB1E9807662B49ECEB9F3530A07CB82B49D8692B7C8
    Malicious:false
    Reputation:low
    Preview:PK..........V................META-INF/......PK..............PK..........V................META-INF/MANIFEST.MFm..J.A......C.z..eou....E.W..,.f.%3...[.mm.&....P..\.g..*...#.4DJ$..aXm.Dj`.;..7)...cS.D..$lR.^n'c....s...Uk..0D.VmP.Z.....WK0]w..]...x..a.mu..[.n.W..*u.......?.[.A.V.R..sn`...W.L6...y..PK..,.......V...PK..........V................ExampleFileSystemView.classmS]O.A.=.n..... `....X?@."..D...U.......4..-?.....B....o2.;[.,.d...9..............#........4c..#.U....t...]...I.Ra.4..<V..!<g.7...S........y..k..m.3.K.St...5^]....0...}.iX.X.J<.....Q.....Y.C.X.u.V..........[!<...S[..8...\...,.R2...2..i}m.....X.^V.4]U..N.K.C.r.,WJ...s...)...C..v=(.)......hx.Y......L...,..=..%.x..^.\..g..K~o.m.%..L.\.4.@V. .4.a........@...R=.TS3.*%m..a...w.f`Ws...Me.YE9..F..t| !zkX[..R.{.e.E._.\....Z.5@...+...L....[....E...0.t7.....#... ...t...}.`.a.9C..z.'..}..i5.....u.V'N.v..3.7cJ.._.h.r.P}..Q.~.~..jU..`..x.$r.....I;..0.......R.=.6..>@.. ...)...&..di$...t......fN.q..D......+u
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:ASCII text
    Category:dropped
    Size (bytes):586
    Entropy (8bit):4.512171391742326
    Encrypted:false
    SSDEEP:12:8SA0PMFI4N5X6KURTSASEyT8XjhyR7DVs/N8w3w9Rx21FexsXvV61Wtv:8z0IF+RH368t0DVs/NA9b21FIsXvYWv
    MD5:23386942A8ACA3DA4F792E3CF773E5B8
    SHA1:7228933C945403FAC62B1A9425E5FBF44DF73EE4
    SHA-256:224CBCC0D59B50973C37E8884F1F340D71918C17494632B093157EA7CF846CBE
    SHA-512:6A5FD4B8279BE523C86C06CD7988307C6F77AB390970432FCB4EF630EDB7B3EA3876ED83DCCC3B940EEBE8E533E1BC2765F46FCFD1E1DEA9133EA9CBD8CC05A3
    Malicious:false
    Reputation:low
    Preview:FileChooserDemo demonstrates some of the capabilities of the .JFileChooser object. It brings up a window displaying several.configuration controls that allow you to play with the.JFileChooser options dynamically.. .To run the FileChooserDemo demo:.. java -jar FileChooserDemo.jar..These instructions assume that this installation's version of the java.command is in your path. If it isn't, then you should either.specify the complete path to the java command or update your.PATH environment variable as described in the installation.instructions for the Java(TM) SE Development Kit..
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Zip archive data, at least v2.0 to extract, compression method=deflate
    Category:dropped
    Size (bytes):15301
    Entropy (8bit):7.933044817249284
    Encrypted:false
    SSDEEP:384:VFZ6RQQGxOBKATLJb0MAh6ytKp1YWt77Lh8nHLaFK:rjQGMBKATLY6iKzL6rD
    MD5:2AB3631E0F4765E2A9042AF26A4B10D2
    SHA1:4FD16069FB644137A33F79F2546DE295C355EAB1
    SHA-256:004D64171F86982E8F675B88270CD4BD2FA687C44FC058FE1A78D1FD19EA027C
    SHA-512:0C6A3680F7AB3E3F9845CC2C2BCEDABF17085C050A2F0051CA87E941A01567AAD1B9A4BB86DE91C75AE60B28A3B76DE6B1582A6B9B8BAE214EAA4E54F12D87BB
    Malicious:false
    Reputation:low
    Preview:PK...........Vi.cyN...........ExampleFileSystemView.javaUT...%..d%..dux..............W.S.F.~._..K .5...d+u...U..'..*..A..5....J..~_.HX..l^.Ea......_......B.;...i.<..?.........Q.DS.kC..$.kU+.J;.....Y2.J....x...J....U.a..$..).$=.F......)=.vC...k.e.+.V.`.).#i'.V...hg.^Uxh7../....O.y.R7.b%.(....O.kD..gI...J]A..-Bj..ed..|...Q...RN!.,..d..m..k.`....J3..o`uD.....:x..r.|..T..n+.V......0.E....=.....CL.r.,..d...j.....l...{8m,...Ar.!.M...Vr....n%y.P...D5.0k.{R.^.O\.}....k.....pu5...EQ\.9..eq.d..y....<...=.#...}._].t...Q.S...6)..bU.xq.....'.,H.).u.EyNiF..r..... ).(.R....<N....J...M\@.H......^.M....3...qq.L^.E...a/.e..q.Z..#-W.2.#...q....&...N.0E.QRP~.,.o.M.(C.n....mp...=.;..(,8..S....bJ.2.c<0P.k....~...6......i...W..... K.*.n.wp....".VEDWi:w..Qv..Q...i.[...F.`.G..0..._...q.'E.e.e.....~...i..#;M\. +...H.K..#.eL.c-`:r...c1....(X.I..E|.%a..)...yt.....Q..]..+.;'.....U.P.S.]./)...../....~.}.u.>...dr....q...p@.....3....;+.....>mh-E..7|x..r.O....a....d..$....j...X9.
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Zip archive data, at least v2.0 to extract, compression method=deflate
    Category:dropped
    Size (bytes):15301
    Entropy (8bit):7.933044817249284
    Encrypted:false
    SSDEEP:384:VFZ6RQQGxOBKATLJb0MAh6ytKp1YWt77Lh8nHLaFK:rjQGMBKATLY6iKzL6rD
    MD5:2AB3631E0F4765E2A9042AF26A4B10D2
    SHA1:4FD16069FB644137A33F79F2546DE295C355EAB1
    SHA-256:004D64171F86982E8F675B88270CD4BD2FA687C44FC058FE1A78D1FD19EA027C
    SHA-512:0C6A3680F7AB3E3F9845CC2C2BCEDABF17085C050A2F0051CA87E941A01567AAD1B9A4BB86DE91C75AE60B28A3B76DE6B1582A6B9B8BAE214EAA4E54F12D87BB
    Malicious:false
    Reputation:low
    Preview:PK...........Vi.cyN...........ExampleFileSystemView.javaUT...%..d%..dux..............W.S.F.~._..K .5...d+u...U..'..*..A..5....J..~_.HX..l^.Ea......_......B.;...i.<..?.........Q.DS.kC..$.kU+.J;.....Y2.J....x...J....U.a..$..).$=.F......)=.vC...k.e.+.V.`.).#i'.V...hg.^Uxh7../....O.y.R7.b%.(....O.kD..gI...J]A..-Bj..ed..|...Q...RN!.,..d..m..k.`....J3..o`uD.....:x..r.|..T..n+.V......0.E....=.....CL.r.,..d...j.....l...{8m,...Ar.!.M...Vr....n%y.P...D5.0k.{R.^.O\.}....k.....pu5...EQ\.9..eq.d..y....<...=.#...}._].t...Q.S...6)..bU.xq.....'.,H.).u.EyNiF..r..... ).(.R....<N....J...M\@.H......^.M....3...qq.L^.E...a/.e..q.Z..#-W.2.#...q....&...N.0E.QRP~.,.o.M.(C.n....mp...=.;..(,8..S....bJ.2.c<0P.k....~...6......i...W..... K.*.n.wp....".VEDWi:w..Qv..Q...i.[...F.`.G..0..._...q.'E.e.e.....~...i..#;M\. +...H.K..#.eL.c-`:r...c1....(X.I..E|.%a..)...yt.....Q..]..+.;'.....U.P.S.]./)...../....~.}.u.>...dr....q...p@.....3....;+.....>mh-E..7|x..r.O....a....d..$....j...X9.
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:HTML document, ASCII text
    Category:dropped
    Size (bytes):1132
    Entropy (8bit):5.198706384322876
    Encrypted:false
    SSDEEP:24:J8nRpx71d6LZECKKSmrKRU7I6wxKCKIVlTkJVsiAfD:+dGTKkrKRUvGnZ
    MD5:6AF51FE8562F3651535B6EB08422B306
    SHA1:132B0521E0D2CD29D7940356F328A8440C90A82F
    SHA-256:E1F7B8A36A97F663C6FA3B16CDB7253249C3F68BB3EA259EB75BDC0A2CDA3A61
    SHA-512:9AFE5671B8AC61F12FB0167C27D1F1C8E0F35C5A6AE0A43749A33D9C2E4BFD587741419E9FD0F54A1D5A63A4BAEF205A489C7C5F3FB8FF364FECD1CE6CDCBF1E
    Malicious:false
    Reputation:low
    Preview:<html>. Changed by: Shinsuke Fukuda, 4-Aug-2000 -->.<head>.<title>.Font2DTest Demo.</title>.</head>..<BODY BGCOLOR="#FFFFFF">.<font size=-1>.<hr>.</font>..<h1>.Font2DTest.</h1>..An encompassing font/glyph demo application..Source code is in <BR>.<a href=src/Font2DTest.java>Font2DTest.java</a>,<BR>.<a href=src/Font2DTestApplet.java>Font2DTestApplet.java</a>,<BR>.<a href=src/RangeMenu.java>RangeMenu.java</a> and<BR>.<a href=src/FontPanel.java>FontPanel.java</a>.<BR>.You can run this program either as an applet or as an application.<BR>.Detailed information about the program can be found in.<a href=README.txt>README.txt</a><BR>..<p>To run it as an application,.execute the <code>Font2DTest</code> class..For example:..<blockquote>.<pre>.% <b>java -jar Font2DTest.jar</b>.</pre>.</blockquote>..<p>.Note: If AWTPermission's showWindowWithoutWarningBanner permission is not given,<BR>.the zoom feature will not look as good, as characters may be hidden by the warning banner.<BR>..<APPLET code
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java archive data (JAR)
    Category:dropped
    Size (bytes):49473
    Entropy (8bit):7.944877016765783
    Encrypted:false
    SSDEEP:1536:+rCD7lru79AsMKblvdNHKQlOkQu1bO2pPPw:AQvsMiHPhjZw
    MD5:953ED06ABF86D36848B2BCDEBFFF0647
    SHA1:3BD9D9007C0EA322F796F25ADABE0C94214B7A80
    SHA-256:B6A8891AD8ECCE10069ED032C30B6B8897611815C3AC7E1F7F20874C1B2EE24E
    SHA-512:CE673EDDDA8959AC47E1443F8DA3747FFBC5F38E69A0D3C683D93118528D7734C4D03535F045DF6A640A72988BD937CCC5CB0A0F07504871BC348EB0A4B4946D
    Malicious:false
    Reputation:low
    Preview:PK..........V................META-INF/......PK..............PK..........V................META-INF/MANIFEST.MFm.Mk.@.......X..6.*.iT. .U..a....L...z....^g..y.. ...).V8..t.U..G.8b...FG9...u.h=..O6..@..)l...'.L.mC.....>H..3.q...F..O>...Z..YU..6...hU..H.d~.+}d.6.x.N.x(.......Zm.rR8l..V.1[......PK..!.......Q...PK..........V................Font2DTest$1.classmR.J.@.=....h..n......o. UA..X.|K...t........G..Q....3;s..I>>...l..C.Fld1jc.c6.1aa..4CV.B.....A,..^.+.E.m!..a.W~'...2.8.....O.7M.jx."..!..S.b%.%C.R...<..h..q.....o...}..[>?....jx...w.c..8.0.`.s.,.:..`...J..Q.&.%..t=...j...W.3.....[.[$.Kf.S\.o.....I.ra.+.h...........'i..U4.K..N...'LUC.pj..>......y).9. ...n"vu......A.3K.,....?.%...W}.{E.....6)v..]#.|.X..d3.k.c*.0.../PK...6..}...D...PK..........V................Font2DTest$2.classmR.J.1.=ik.[[.j.....*.)...J......6R.....$x..?...'.P.....9393.._...6.K...6...1.q....0ea.!..B..Ne?.z.\.Jo..-..;......)C......!.q...7..E..dGH?.....!..\ym..:..m..{.......O.V....IOu.Y3y
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:ASCII text
    Category:dropped
    Size (bytes):6777
    Entropy (8bit):4.6624612271949255
    Encrypted:false
    SSDEEP:192:+NJVGBtSV0+EsPG74qqR63IrK3Ml9VjnG9FvWTOSyGp:+NJ6QVNVqqRa2I49VQuTP3p
    MD5:9F923E7DD2F847EA8EF900E99915B3B7
    SHA1:B3B407D339E57F3ADEC79E8CF7CF73F91E57F768
    SHA-256:97436FB1638165B4C816B8C84A8B424C19DF593E352204E4C14551C7F06E2F4E
    SHA-512:0E792FC94ACFAE319A8B1F1F60977741CFBCA0B2F6DF656E98F5DBC89DD2952622287A644D94213D614456B03519C508A5E9D337FED7BB790F9EF73A31E28BED
    Malicious:false
    Reputation:low
    Preview:Font2DTest.-----------..To run Font2DTest:..% java -jar Font2DTest.jar. or .% appletviewer Font2DTest.html..These instructions assume that the 1.7 versions of the java.and appletviewer commands are in your path. If they aren't,.then you should either specify the complete path to the commands.or update your PATH environment variable as described in the.installation instructions for the Java(TM) SE Development Kit...To view Font2DTest within a web browser with Java Plugin,.load Font2DTest.html...If you wish to modify any of the source code, you may want to extract.the contents of the Font2DTest.jar file by executing this command:..% jar -xvf Font2DTest.jar..NOTE:..When Font2DTest is ran as an applet, the browser plugin/viewer needs.following permissions given in order to run properly:..AWTPermission "showWindowWithoutWarningBanner".RuntimePermission "queuePrintJob"..The program will run without these properties set,.but some of its features will be limited..To enable all features
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:HTML document, ASCII text
    Category:dropped
    Size (bytes):1132
    Entropy (8bit):5.198706384322876
    Encrypted:false
    SSDEEP:24:J8nRpx71d6LZECKKSmrKRU7I6wxKCKIVlTkJVsiAfD:+dGTKkrKRUvGnZ
    MD5:6AF51FE8562F3651535B6EB08422B306
    SHA1:132B0521E0D2CD29D7940356F328A8440C90A82F
    SHA-256:E1F7B8A36A97F663C6FA3B16CDB7253249C3F68BB3EA259EB75BDC0A2CDA3A61
    SHA-512:9AFE5671B8AC61F12FB0167C27D1F1C8E0F35C5A6AE0A43749A33D9C2E4BFD587741419E9FD0F54A1D5A63A4BAEF205A489C7C5F3FB8FF364FECD1CE6CDCBF1E
    Malicious:false
    Reputation:low
    Preview:<html>. Changed by: Shinsuke Fukuda, 4-Aug-2000 -->.<head>.<title>.Font2DTest Demo.</title>.</head>..<BODY BGCOLOR="#FFFFFF">.<font size=-1>.<hr>.</font>..<h1>.Font2DTest.</h1>..An encompassing font/glyph demo application..Source code is in <BR>.<a href=src/Font2DTest.java>Font2DTest.java</a>,<BR>.<a href=src/Font2DTestApplet.java>Font2DTestApplet.java</a>,<BR>.<a href=src/RangeMenu.java>RangeMenu.java</a> and<BR>.<a href=src/FontPanel.java>FontPanel.java</a>.<BR>.You can run this program either as an applet or as an application.<BR>.Detailed information about the program can be found in.<a href=README.txt>README.txt</a><BR>..<p>To run it as an application,.execute the <code>Font2DTest</code> class..For example:..<blockquote>.<pre>.% <b>java -jar Font2DTest.jar</b>.</pre>.</blockquote>..<p>.Note: If AWTPermission's showWindowWithoutWarningBanner permission is not given,<BR>.the zoom feature will not look as good, as characters may be hidden by the warning banner.<BR>..<APPLET code
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:ASCII text
    Category:dropped
    Size (bytes):6777
    Entropy (8bit):4.6624612271949255
    Encrypted:false
    SSDEEP:192:+NJVGBtSV0+EsPG74qqR63IrK3Ml9VjnG9FvWTOSyGp:+NJ6QVNVqqRa2I49VQuTP3p
    MD5:9F923E7DD2F847EA8EF900E99915B3B7
    SHA1:B3B407D339E57F3ADEC79E8CF7CF73F91E57F768
    SHA-256:97436FB1638165B4C816B8C84A8B424C19DF593E352204E4C14551C7F06E2F4E
    SHA-512:0E792FC94ACFAE319A8B1F1F60977741CFBCA0B2F6DF656E98F5DBC89DD2952622287A644D94213D614456B03519C508A5E9D337FED7BB790F9EF73A31E28BED
    Malicious:false
    Reputation:low
    Preview:Font2DTest.-----------..To run Font2DTest:..% java -jar Font2DTest.jar. or .% appletviewer Font2DTest.html..These instructions assume that the 1.7 versions of the java.and appletviewer commands are in your path. If they aren't,.then you should either specify the complete path to the commands.or update your PATH environment variable as described in the.installation instructions for the Java(TM) SE Development Kit...To view Font2DTest within a web browser with Java Plugin,.load Font2DTest.html...If you wish to modify any of the source code, you may want to extract.the contents of the Font2DTest.jar file by executing this command:..% jar -xvf Font2DTest.jar..NOTE:..When Font2DTest is ran as an applet, the browser plugin/viewer needs.following permissions given in order to run properly:..AWTPermission "showWindowWithoutWarningBanner".RuntimePermission "queuePrintJob"..The program will run without these properties set,.but some of its features will be limited..To enable all features
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Zip archive data, at least v2.0 to extract, compression method=deflate
    Category:dropped
    Size (bytes):32843
    Entropy (8bit):7.985523358671337
    Encrypted:false
    SSDEEP:768:EoChYlGhEptXiPSn8bkU4+zV8SjFqzUKwgKb+z7o9h:EoChYlG6pUK8bnfjFqzUKjwT
    MD5:AA087BDF671CF92142BCB72E6BBDABB7
    SHA1:0436C593F71732F51CC452CCC99C575B7EA991F6
    SHA-256:C8A252A65F840E10688320D805D57999F4FCE54A34E73E46607C163BC3E0FCE0
    SHA-512:050588948019A0747443A72335DB3A22A18669709293DD44A6725818F030283476400C2DBC67B2364E6FEBA67C974F4F6245BA0F1DA6EFE7F8818CD7A4CBBAA3
    Malicious:false
    Reputation:low
    Preview:PK...........V.3.hO...l.......Font2DTest.htmlUT...%..d%..dux.............}T.n.0.}.W.e..B..6m.B$(.4.].E..x.\b......~..MW..C..{.>>N&l..Q.!I.\....b{..B......U8...L\...F#H.F........V.t....Z.e..,..F..fv....7W7.q..2.b.X1.z.L........%N..=./D...J.v..R....v.*...F.h.V..V;S...".=H..t.....j.2.+.......Y...?......`.}.......!.N=.PU...QQ...O=j. ..A...S`..3.6..I+......"..p..@3#...TH...o...,..+.W*...)_....b2......C.d ..._......".P.,.......Y...l8.C....`..9c.......g.3...Y.{. y@.o..di.S..y|..=F.xx.?W0.[...c....z......v....DNQ)6.{...S.B-.I..7..u.+B....l.P.h..v.ZW.?(..,-..Z.z...*b.....*.Av.b.d>..X....\..b@S......s7......Q..d-.8.6.......4.7.....O@....PK...........V.R..).........Font2DTest.javaUT...%..d%..dux..............<k..8...+8..'O<.G..n.I..nuG)...<.I.d..5.%......._..%..dwvo...".. .. .......0><$.v..k.%....K.\._\..$.W!%~.>...d).7. ....}b.!a.R..&wt..|.rF.A.%.2.8B.$O)."..y.b(.2...l.d...}.......y.X..:..+.q.Pr..>.2.&.$....%......'... .U...."....4B~..KI..t..5@.i.,e>..
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java archive data (JAR)
    Category:dropped
    Size (bytes):49473
    Entropy (8bit):7.944877016765783
    Encrypted:false
    SSDEEP:1536:+rCD7lru79AsMKblvdNHKQlOkQu1bO2pPPw:AQvsMiHPhjZw
    MD5:953ED06ABF86D36848B2BCDEBFFF0647
    SHA1:3BD9D9007C0EA322F796F25ADABE0C94214B7A80
    SHA-256:B6A8891AD8ECCE10069ED032C30B6B8897611815C3AC7E1F7F20874C1B2EE24E
    SHA-512:CE673EDDDA8959AC47E1443F8DA3747FFBC5F38E69A0D3C683D93118528D7734C4D03535F045DF6A640A72988BD937CCC5CB0A0F07504871BC348EB0A4B4946D
    Malicious:false
    Reputation:low
    Preview:PK..........V................META-INF/......PK..............PK..........V................META-INF/MANIFEST.MFm.Mk.@.......X..6.*.iT. .U..a....L...z....^g..y.. ...).V8..t.U..G.8b...FG9...u.h=..O6..@..)l...'.L.mC.....>H..3.q...F..O>...Z..YU..6...hU..H.d~.+}d.6.x.N.x(.......Zm.rR8l..V.1[......PK..!.......Q...PK..........V................Font2DTest$1.classmR.J.@.=....h..n......o. UA..X.|K...t........G..Q....3;s..I>>...l..C.Fld1jc.c6.1aa..4CV.B.....A,..^.+.E.m!..a.W~'...2.8.....O.7M.jx."..!..S.b%.%C.R...<..h..q.....o...}..[>?....jx...w.c..8.0.`.s.,.:..`...J..Q.&.%..t=...j...W.3.....[.[$.Kf.S\.o.....I.ra.+.h...........'i..U4.K..N...'LUC.pj..>......y).9. ...n"vu......A.3K.,....?.%...W}.{E.....6)v..]#.|.X..d3.k.c*.0.../PK...6..}...D...PK..........V................Font2DTest$2.classmR.J.1.=ik.[[.j.....*.)...J......6R.....$x..?...'.P.....9393.._...6.K...6...1.q....0ea.!..B..Ne?.z.\.Jo..-..;......)C......!.q...7..E..dGH?.....!..\ym..:..m..{.......O.V....IOu.Y3y
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Zip archive data, at least v2.0 to extract, compression method=deflate
    Category:dropped
    Size (bytes):32843
    Entropy (8bit):7.985523358671337
    Encrypted:false
    SSDEEP:768:EoChYlGhEptXiPSn8bkU4+zV8SjFqzUKwgKb+z7o9h:EoChYlG6pUK8bnfjFqzUKjwT
    MD5:AA087BDF671CF92142BCB72E6BBDABB7
    SHA1:0436C593F71732F51CC452CCC99C575B7EA991F6
    SHA-256:C8A252A65F840E10688320D805D57999F4FCE54A34E73E46607C163BC3E0FCE0
    SHA-512:050588948019A0747443A72335DB3A22A18669709293DD44A6725818F030283476400C2DBC67B2364E6FEBA67C974F4F6245BA0F1DA6EFE7F8818CD7A4CBBAA3
    Malicious:false
    Reputation:low
    Preview:PK...........V.3.hO...l.......Font2DTest.htmlUT...%..d%..dux.............}T.n.0.}.W.e..B..6m.B$(.4.].E..x.\b......~..MW..C..{.>>N&l..Q.!I.\....b{..B......U8...L\...F#H.F........V.t....Z.e..,..F..fv....7W7.q..2.b.X1.z.L........%N..=./D...J.v..R....v.*...F.h.V..V;S...".=H..t.....j.2.+.......Y...?......`.}.......!.N=.PU...QQ...O=j. ..A...S`..3.6..I+......"..p..@3#...TH...o...,..+.W*...)_....b2......C.d ..._......".P.,.......Y...l8.C....`..9c.......g.3...Y.{. y@.o..di.S..y|..=F.xx.?W0.[...c....z......v....DNQ)6.{...S.B-.I..7..u.+B....l.P.h..v.ZW.?(..,-..Z.z...*b.....*.Av.b.d>..X....\..b@S......s7......Q..d-.8.6.......4.7.....O@....PK...........V.R..).........Font2DTest.javaUT...%..d%..dux..............<k..8...+8..'O<.G..n.I..nuG)...<.I.d..5.%......._..%..dwvo...".. .. .......0><$.v..k.%....K.\._\..$.W!%~.>...d).7. ....}b.!a.R..&wt..|.rF.A.%.2.8B.$O)."..y.b(.2...l.d...}.......y.X..:..+.q.Pr..>.2.&.$....%......'... .U...."....4B~..KI..t..5@.i.,e>..
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java archive data (JAR)
    Category:dropped
    Size (bytes):43867
    Entropy (8bit):7.855491878879143
    Encrypted:false
    SSDEEP:768:rMbNRhRRXIv4HFyarIQ7PO7VT65CUUs7MfA3u9N1a2D4kxAa64yaaaxGd:QDRR4vRitqRThs7MfF7IQ4N67a
    MD5:A01539D3DC3249F2CB015BFB497AB9B5
    SHA1:1777B83003FD80054EBC1C046AAF6B42FF65B660
    SHA-256:5E78AFADD3AE7226AAF061AEAF66BC70625D6715E56FB1C1C42A8CB31A63FC2B
    SHA-512:629391DC70BA6C83817755C12E2227D50A2390EABFC985844733EF8A8534A10F548FE51BFDA0AFA50F4B6BCDA0AEFEDB6D39706B0858410651BEF33A16E8D23E
    Malicious:false
    Reputation:low
    Preview:PK..........V................META-INF/......PK..............PK..........V................META-INF/MANIFEST.MFm.Mk.A...............t....k.c..g.%3*......^..7oZd.Q..+i.....5M..E..cXl}.T.......>.,..U..=...Y9z..&...|..U.N.......h/......7.s'.a.i..{..m`M...v...S.i..y.p.$B.....w.;hM...:`J...1.D...k..PK....H.....Q...PK..........V................AquaMetalTheme.class...N.Q.....~....A.T....za...`R..X .. ..d.[.-.;_.+^....&.k_.w .9lh.$M&3s..f..9.......XH!.i.3)..(..f....q....&...v.x<.....q.Ox.>..........v.8.;.'..........C.T.a.V.}.0..D...`..T1.DX..e...]Nb.0 M..&...F..4d.....m.j(.#..+.;|S...:..x&gg0.1..0..=. .t...F.f..w....w'3.....[{M4y...Q.T...;...I....2...#*.`r[.Y:...X...U~#..mZ.Nv../h.d..d..G.S..d.f..........5&...X......E...g.M7K...qLD.l.....eB....:..... .......^.PK..[].b........PK..........V................BigContrastMetalTheme.class.V{S.F...0..q.`.$.i.`....(.h..jl....l..@..$c`.....~..k...d.L?@?T.{.lc.ik.....w{.{.....?.......H.c...W....BJ.E!..,.....)H..'
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:ASCII text
    Category:dropped
    Size (bytes):2083
    Entropy (8bit):4.6143550675645395
    Encrypted:false
    SSDEEP:48:D2Ea0N25/ZMctIAQbWFICgWApwE6Lck7x4tEnLX3sMVJ:DiI/oRLxx4tEnLHswJ
    MD5:CB0342F829E27B283A1FA4A029D428EC
    SHA1:52E4D8DCF3CA84B5FF2C8E48D6E23D637726D515
    SHA-256:CA373951D7FB60E3D1F370349157C8ABAAA8D5DE8A54FD907A76F6266B38B404
    SHA-512:9C10715306F7B805CED0D5FC601D2D7B4AEBF67E9DC5A2BDB0582861F2CE3062E76B9CD39149FA7838F503A498CCCF728BBC6F73CF088ADC20517B15FEDF3E69
    Malicious:false
    Reputation:low
    Preview:About Metalworks.================.Metalworks is a simple Swing-based simulated e-mail.application. It shows off several features of Swing, including.JInternalFrame, JTabbedPane, JFileChooser, JEditorPane, and.JRadioButtonMenuItem. Metalworks is optimized to work with the.Java look and feel (codenamed "Metal") and shows use of several.features, such as themes, that are specific to the Java look and.feel....Running Metalworks.==================..To run the Metalworks demo:.. java -jar Metalworks.jar..These instructions assume that this installation's version of the java.command is in your path. If it isn't, then you should either.specify the complete path to the java command or update your.PATH environment variable as described in the installation.instructions for the Java(TM) SE Development Kit....Metalworks Features.===================.The functionality of the Metalworks demo is minimal, and many.controls are non-functional. They are intended only to show how.to construct the UI f
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:ASCII text
    Category:dropped
    Size (bytes):2083
    Entropy (8bit):4.6143550675645395
    Encrypted:false
    SSDEEP:48:D2Ea0N25/ZMctIAQbWFICgWApwE6Lck7x4tEnLX3sMVJ:DiI/oRLxx4tEnLHswJ
    MD5:CB0342F829E27B283A1FA4A029D428EC
    SHA1:52E4D8DCF3CA84B5FF2C8E48D6E23D637726D515
    SHA-256:CA373951D7FB60E3D1F370349157C8ABAAA8D5DE8A54FD907A76F6266B38B404
    SHA-512:9C10715306F7B805CED0D5FC601D2D7B4AEBF67E9DC5A2BDB0582861F2CE3062E76B9CD39149FA7838F503A498CCCF728BBC6F73CF088ADC20517B15FEDF3E69
    Malicious:false
    Reputation:low
    Preview:About Metalworks.================.Metalworks is a simple Swing-based simulated e-mail.application. It shows off several features of Swing, including.JInternalFrame, JTabbedPane, JFileChooser, JEditorPane, and.JRadioButtonMenuItem. Metalworks is optimized to work with the.Java look and feel (codenamed "Metal") and shows use of several.features, such as themes, that are specific to the Java look and.feel....Running Metalworks.==================..To run the Metalworks demo:.. java -jar Metalworks.jar..These instructions assume that this installation's version of the java.command is in your path. If it isn't, then you should either.specify the complete path to the java command or update your.PATH environment variable as described in the installation.instructions for the Java(TM) SE Development Kit....Metalworks Features.===================.The functionality of the Metalworks demo is minimal, and many.controls are non-functional. They are intended only to show how.to construct the UI f
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Zip archive data, at least v2.0 to extract, compression method=deflate
    Category:dropped
    Size (bytes):43428
    Entropy (8bit):7.930085874536078
    Encrypted:false
    SSDEEP:768:ik++tH4ybLcDDyTTC0hzBknVvWCHtTaUm1XVoh275JwCzuaUD4kx4a64yaRkbVy+:ijybzZMV+2y1XVo8tZzVG4J6+bY+
    MD5:5EE61D8516C2C434258C35D2C3924D73
    SHA1:FC000F0E6826D5B7ACB772D1AC0B54E41D2AF9AD
    SHA-256:5549B4739D7BA126ABCDD0C843861859ADBB65311AD3FEF137DEE5A08F0F0708
    SHA-512:41FCD16A8FC614F85EAD8596BDD4466880C4BF7E0F107FFA48B6BD09AF288CCD04A7CF7CB759D381E3582B4223F02D94A9AB05E0F137EAAF6912A769AA6D9A9E
    Malicious:false
    Reputation:low
    Preview:PK...........V..='............AquaMetalTheme.javaUT...%..d%..dux..............V.S.6.~._...t|..s3.Lg.q.h...v.x..B.:vN...s.{......)..V.~..j..........5....#...}.....(......dZGj.0.Q.vC....9GV;m7....!S]..Zs.....:.........M..3-..r.=.vI.....e.US..).c......+....m6..K.T-..8U.<........r...V..nK...+z...W...\..Z......ome.Q..5..`b.U.d...>.?...Rf...+l.uO....\v`.?..>..T...J..........o...K.|..y?...cm.Y...J3.mq......l...{..:.}.{.u.(..u.U.%......K.r,A...Y`...5....b[e.....Y..g....."...e.E~....>K..9....aSP...Ryy..U2..4.0.`5.S9.......dv......Y*......l*...i..Rd..8..'2.....'9M..a.'A.K|.$%.t-...?.......y..../.Y..2.O..f.t.d.8...i(..dH ..$nD.Sv.N...Mnc."..K.......S..C....(.^.".......$^.H|..*L.......q.;..$../..._.,E.T\3wh...Y..y..2I&^.L.72..9M..+7.D.'y.l.........Lz.e..4..r..GH.-.....'^.$.1C.$...#..>...^.l.,.W-d92....fp.1.`.'..Sy).H.A.@.2.G...KFe.!<.}.4p._...]=.>.$/(..H.GAdr[?^..j.>.......z.f.9..B..h...wN=.........Vmg}..n..em>v..X*.k..RW.^3H.L.....F..e..TE..k.=......
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java archive data (JAR)
    Category:dropped
    Size (bytes):43867
    Entropy (8bit):7.855491878879143
    Encrypted:false
    SSDEEP:768:rMbNRhRRXIv4HFyarIQ7PO7VT65CUUs7MfA3u9N1a2D4kxAa64yaaaxGd:QDRR4vRitqRThs7MfF7IQ4N67a
    MD5:A01539D3DC3249F2CB015BFB497AB9B5
    SHA1:1777B83003FD80054EBC1C046AAF6B42FF65B660
    SHA-256:5E78AFADD3AE7226AAF061AEAF66BC70625D6715E56FB1C1C42A8CB31A63FC2B
    SHA-512:629391DC70BA6C83817755C12E2227D50A2390EABFC985844733EF8A8534A10F548FE51BFDA0AFA50F4B6BCDA0AEFEDB6D39706B0858410651BEF33A16E8D23E
    Malicious:false
    Reputation:low
    Preview:PK..........V................META-INF/......PK..............PK..........V................META-INF/MANIFEST.MFm.Mk.A...............t....k.c..g.%3*......^..7oZd.Q..+i.....5M..E..cXl}.T.......>.,..U..=...Y9z..&...|..U.N.......h/......7.s'.a.i..{..m`M...v...S.i..y.p.$B.....w.;hM...:`J...1.D...k..PK....H.....Q...PK..........V................AquaMetalTheme.class...N.Q.....~....A.T....za...`R..X .. ..d.[.-.;_.+^....&.k_.w .9lh.$M&3s..f..9.......XH!.i.3)..(..f....q....&...v.x<.....q.Ox.>..........v.8.;.'..........C.T.a.V.}.0..D...`..T1.DX..e...]Nb.0 M..&...F..4d.....m.j(.#..+.;|S...:..x&gg0.1..0..=. .t...F.f..w....w'3.....[{M4y...Q.T...;...I....2...#*.`r[.Y:...X...U~#..mZ.Nv../h.d..d..G.S..d.f..........5&...X......E...g.M7K...qLD.l.....eB....:..... .......^.PK..[].b........PK..........V................BigContrastMetalTheme.class.V{S.F...0..q.`.$.i.`....(.h..jl....l..@..$c`.....~..k...d.L?@?T.{.lc.ik.....w{.{.....?.......H.c...W....BJ.E!..,.....)H..'
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Zip archive data, at least v2.0 to extract, compression method=deflate
    Category:dropped
    Size (bytes):43428
    Entropy (8bit):7.930085874536078
    Encrypted:false
    SSDEEP:768:ik++tH4ybLcDDyTTC0hzBknVvWCHtTaUm1XVoh275JwCzuaUD4kx4a64yaRkbVy+:ijybzZMV+2y1XVo8tZzVG4J6+bY+
    MD5:5EE61D8516C2C434258C35D2C3924D73
    SHA1:FC000F0E6826D5B7ACB772D1AC0B54E41D2AF9AD
    SHA-256:5549B4739D7BA126ABCDD0C843861859ADBB65311AD3FEF137DEE5A08F0F0708
    SHA-512:41FCD16A8FC614F85EAD8596BDD4466880C4BF7E0F107FFA48B6BD09AF288CCD04A7CF7CB759D381E3582B4223F02D94A9AB05E0F137EAAF6912A769AA6D9A9E
    Malicious:false
    Reputation:low
    Preview:PK...........V..='............AquaMetalTheme.javaUT...%..d%..dux..............V.S.6.~._...t|..s3.Lg.q.h...v.x..B.:vN...s.{......)..V.~..j..........5....#...}.....(......dZGj.0.Q.vC....9GV;m7....!S]..Zs.....:.........M..3-..r.=.vI.....e.US..).c......+....m6..K.T-..8U.<........r...V..nK...+z...W...\..Z......ome.Q..5..`b.U.d...>.?...Rf...+l.uO....\v`.?..>..T...J..........o...K.|..y?...cm.Y...J3.mq......l...{..:.}.{.u.(..u.U.%......K.r,A...Y`...5....b[e.....Y..g....."...e.E~....>K..9....aSP...Ryy..U2..4.0.`5.S9.......dv......Y*......l*...i..Rd..8..'2.....'9M..a.'A.K|.$%.t-...?.......y..../.Y..2.O..f.t.d.8...i(..dH ..$nD.Sv.N...Mnc."..K.......S..C....(.^.".......$^.H|..*L.......q.;..$../..._.,E.T\3wh...Y..y..2I&^.L.72..9M..+7.D.'y.l.........Lz.e..4..r..GH.-.....'^.$.1C.$...#..>...^.l.,.W-d92....fp.1.`.'..Sy).H.A.@.2.G...KFe.!<.}.4p._...]=.>.$/(..H.GAdr[?^..j.>.......z.f.9..B..h...wN=.........Vmg}..n..em>v..X*.k..RW.^3H.L.....F..e..TE..k.=......
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java archive data (JAR)
    Category:dropped
    Size (bytes):36553
    Entropy (8bit):7.848249467992872
    Encrypted:false
    SSDEEP:768:1nn9CV/9PLPi9/CfhnS75+HWtDX4Y0mqlX6Q:9n9CV/9ri1OW+9lKQ
    MD5:5C8B0435E975FA395C58B4F173B63D71
    SHA1:780DC3CC74F11F239BC365CDA6DA7E96F32F0E04
    SHA-256:3EEBD2350198739203F480F77155FC68D6B377AFB7CE2F3623AB3B839BF270D7
    SHA-512:DE86B5E17D72B0537BDF276C01810670342C6F4C0375BF7ECCAE3A6371C5E72C2CF86823DBC2E30E814D413A2101B3F914B8DBFEE8BBAB24543A52CC6984CE35
    Malicious:false
    Reputation:low
    Preview:PK..........V................META-INF/......PK..............PK..........V................META-INF/MANIFEST.MFm....@......C.zhq9(.i.P......)..$e:...n.{M>...!...l)4V8.n...#O.1^...FG.L..s..`...........?.i.......RB.......j...|..t.+..F..>.o...Vy .T&.......pj.C.&m......j5C.I.i2.K..K..:.PK...d.%....N...PK..........V................ElementTreePanel$1.class.U]S.U.~N..Mr..EHm%......wh.4...j...E.$.X..M...Zu..u../.....Vg.Ag:z....@..3u..Y.&(....~>.{.s.........@..."..8....$C.c$..8.1... 8N*},.SH....1..y.{A....T...JOj.V@3J.U.i./....d4d..9.......e...b...MY....HyZ..9B..e....FwzE_....%.ZJ.dN(.]$_..CS.D...a.j)/+Y=o.%\..UYq.t.*.vV.....0uB...;...&s.;...B.......L.e..[L...'.8.s,0.3v.R...*.Y..Q.K.[..v.vZ..v..U.^.&p..+.u..{VJ.&j`TU@G^.....(2t.w|.j.EYa`..rQ`........09J..l....qQ.*...........U..U.K.+...a]e.A. ...u...K..UW:.(._.A.0...,YI...H..c.Z.T$C{..0.l..N..$...Ru.31nUK....m...M...b....9I..mQ.w.zb{.A.o.....$-I..K..ja..6.i-....I..FhU.c'..^R...}.C.m.3mWd......s.!
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:ASCII text
    Category:dropped
    Size (bytes):356
    Entropy (8bit):4.467510487260601
    Encrypted:false
    SSDEEP:6:hRlkSEy88AAMYgwLkKRLxIQoRtRPLV4mQ/N8qt3wdNFan5qx2AWd3exNLiRgKRLl:hRuSEynlXjhyR7DVs/N8w3w9Rx21Fexi
    MD5:F6FB9D6964DEC2DC0C52CB56F2A27302
    SHA1:83EFEC2BBC630B2AA800F5C98E4E2AA7C285BEC2
    SHA-256:939E0B5A172948C642990DEA4B670BFED9ABC632C9939870086C6628BD633DB4
    SHA-512:6A1CC2477F6F4DC817BC2BFB43A6DF74B819C1271B58B4127E649ECF0D21B1AF2152E15B7BDDCC32A739475BD2355B1EA94DAF466464A724936AAF67EFA243A4
    Malicious:false
    Reputation:low
    Preview:.To run the Notepad demo:.. java -jar Notepad.jar..These instructions assume that this installation's version of the java.command is in your path. If it isn't, then you should either.specify the complete path to the java command or update your.PATH environment variable as described in the installation.instructions for the Java(TM) SE Development Kit...
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Zip archive data, at least v2.0 to extract, compression method=deflate
    Category:dropped
    Size (bytes):20703
    Entropy (8bit):7.888087556425236
    Encrypted:false
    SSDEEP:384:RDjaFpXekVxgufSslQUibAba3o3ytcfRyyVBc5kmI1TMwo2hNbyco1bDb5:RfaFpOkVxguatb0baI0N8lXwn9
    MD5:75A12694F0E3776DDC0EF4E1BF23E3D3
    SHA1:4C579D0A4C5DCC0087DAE6CFA53C778A38E177CB
    SHA-256:F3924E740C11BF8F05B40A452A20B4BB858B19A5A5A8EC36BC10144DD57F7C7A
    SHA-512:DFB3712E6A460B0242F933BE92815363FE1781E08F2B201F5172FCA8EBBB364D73B841588FF8FC5D7295BE7FC9CA1EEC1D429147EED043D7480D425CDABE9CD1
    Malicious:false
    Reputation:low
    Preview:PK...........VH..D.....W......ElementTreePanel.javaUT...%..d%..dux..............<.r.8........D.....q.jYV.M.W..I.......E.I.v+.>... .Jv.gg...$pp.7.:}v$..~..e.....x....+...W]1.."VB&.i....\..8.....cA.r..\e.*......0.,.o.(M....JD...m. .b.%2.e...x....U..t[ .u.F.h!.FW.L....QQ.Pl..>..K......N...Qr'.i.F8)G(8o...i.xQC/....HC.... .../B...._i61.!......C.\....k..U.`.E,...=....k.6@p....E.......v..B.....0 .k.~..8/e@.C..!...*..8&.k..i.J..1I...`..3.4.a..+.#.".*..B..<.i.....1..A...%.g...x@..Z&.Z....../C.JX...b.~8.......d ...d.ax9......@..7.&.w.g..xt9.LE....^.&.........j8=.w..Ob....`:...^........g...+........]W..q=....j8.a.q...xf..[q5.......h8.DK...q...^O..&.a.v. .....x:.H..p....W..@.....|.\...}o4..;.x=....K\z/..m.b4......d.!].>p...u..f.....4.....M>u.7.v:..[....e......f.H..;.\!......t6......x|I|..&.....L..S...t.Ef.......`...........`2......' ..!..../...k...5.|.....A.....j..%....S.^....%..3.X.s=x7...\..8`..>........{.Pq.=X..hG..n.uH.h..K....w.a........b_...>.....)...V
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java archive data (JAR)
    Category:dropped
    Size (bytes):36553
    Entropy (8bit):7.848249467992872
    Encrypted:false
    SSDEEP:768:1nn9CV/9PLPi9/CfhnS75+HWtDX4Y0mqlX6Q:9n9CV/9ri1OW+9lKQ
    MD5:5C8B0435E975FA395C58B4F173B63D71
    SHA1:780DC3CC74F11F239BC365CDA6DA7E96F32F0E04
    SHA-256:3EEBD2350198739203F480F77155FC68D6B377AFB7CE2F3623AB3B839BF270D7
    SHA-512:DE86B5E17D72B0537BDF276C01810670342C6F4C0375BF7ECCAE3A6371C5E72C2CF86823DBC2E30E814D413A2101B3F914B8DBFEE8BBAB24543A52CC6984CE35
    Malicious:false
    Reputation:low
    Preview:PK..........V................META-INF/......PK..............PK..........V................META-INF/MANIFEST.MFm....@......C.zhq9(.i.P......)..$e:...n.{M>...!...l)4V8.n...#O.1^...FG.L..s..`...........?.i.......RB.......j...|..t.+..F..>.o...Vy .T&.......pj.C.&m......j5C.I.i2.K..K..:.PK...d.%....N...PK..........V................ElementTreePanel$1.class.U]S.U.~N..Mr..EHm%......wh.4...j...E.$.X..M...Zu..u../.....Vg.Ag:z....@..3u..Y.&(....~>.{.s.........@..."..8....$C.c$..8.1... 8N*},.SH....1..y.{A....T...JOj.V@3J.U.i./....d4d..9.......e...b...MY....HyZ..9B..e....FwzE_....%.ZJ.dN(.]$_..CS.D...a.j)/+Y=o.%\..UYq.t.*.vV.....0uB...;...&s.;...B.......L.e..[L...'.8.s,0.3v.R...*.Y..Q.K.[..v.vZ..v..U.^.&p..+.u..{VJ.&j`TU@G^.....(2t.w|.j.EYa`..rQ`........09J..l....qQ.*...........U..U.K.+...a]e.A. ...u...K..UW:.(._.A.0...,YI...H..c.Z.T$C{..0.l..N..$...Ru.31nUK....m...M...b....9I..mQ.w.zb{.A.o.....$-I..K..ja..6.i-....I..FhU.c'..^R...}.C.m.3mWd......s.!
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:ASCII text
    Category:dropped
    Size (bytes):356
    Entropy (8bit):4.467510487260601
    Encrypted:false
    SSDEEP:6:hRlkSEy88AAMYgwLkKRLxIQoRtRPLV4mQ/N8qt3wdNFan5qx2AWd3exNLiRgKRLl:hRuSEynlXjhyR7DVs/N8w3w9Rx21Fexi
    MD5:F6FB9D6964DEC2DC0C52CB56F2A27302
    SHA1:83EFEC2BBC630B2AA800F5C98E4E2AA7C285BEC2
    SHA-256:939E0B5A172948C642990DEA4B670BFED9ABC632C9939870086C6628BD633DB4
    SHA-512:6A1CC2477F6F4DC817BC2BFB43A6DF74B819C1271B58B4127E649ECF0D21B1AF2152E15B7BDDCC32A739475BD2355B1EA94DAF466464A724936AAF67EFA243A4
    Malicious:false
    Reputation:low
    Preview:.To run the Notepad demo:.. java -jar Notepad.jar..These instructions assume that this installation's version of the java.command is in your path. If it isn't, then you should either.specify the complete path to the java command or update your.PATH environment variable as described in the installation.instructions for the Java(TM) SE Development Kit...
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Zip archive data, at least v2.0 to extract, compression method=deflate
    Category:dropped
    Size (bytes):20703
    Entropy (8bit):7.888087556425236
    Encrypted:false
    SSDEEP:384:RDjaFpXekVxgufSslQUibAba3o3ytcfRyyVBc5kmI1TMwo2hNbyco1bDb5:RfaFpOkVxguatb0baI0N8lXwn9
    MD5:75A12694F0E3776DDC0EF4E1BF23E3D3
    SHA1:4C579D0A4C5DCC0087DAE6CFA53C778A38E177CB
    SHA-256:F3924E740C11BF8F05B40A452A20B4BB858B19A5A5A8EC36BC10144DD57F7C7A
    SHA-512:DFB3712E6A460B0242F933BE92815363FE1781E08F2B201F5172FCA8EBBB364D73B841588FF8FC5D7295BE7FC9CA1EEC1D429147EED043D7480D425CDABE9CD1
    Malicious:false
    Reputation:low
    Preview:PK...........VH..D.....W......ElementTreePanel.javaUT...%..d%..dux..............<.r.8........D.....q.jYV.M.W..I.......E.I.v+.>... .Jv.gg...$pp.7.:}v$..~..e.....x....+...W]1.."VB&.i....\..8.....cA.r..\e.*......0.,.o.(M....JD...m. .b.%2.e...x....U..t[ .u.F.h!.FW.L....QQ.Pl..>..K......N...Qr'.i.F8)G(8o...i.xQC/....HC.... .../B...._i61.!......C.\....k..U.`.E,...=....k.6@p....E.......v..B.....0 .k.~..8/e@.C..!...*..8&.k..i.J..1I...`..3.4.a..+.#.".*..B..<.i.....1..A...%.g...x@..Z&.Z....../C.JX...b.~8.......d ...d.ax9......@..7.&.w.g..xt9.LE....^.&.........j8=.w..Ob....`:...^........g...+........]W..q=....j8.a.q...xf..[q5.......h8.DK...q...^O..&.a.v. .....x:.H..p....W..@.....|.\...}o4..;.x=....K\z/..m.b4......d.!].>p...u..f.....4.....M>u.7.v:..[....e......f.H..;.\!......t6......x|I|..&.....L..S...t.Ef.......`...........`2......' ..!..../...k...5.|.....A.....j..%....S.^....%..3.X.s=x7...\..8`..>........{.Pq.=X..hG..n.uH.h..K....w.a........b_...>.....)...V
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:ASCII text
    Category:dropped
    Size (bytes):952
    Entropy (8bit):4.597969349837422
    Encrypted:false
    SSDEEP:24:dx6bJoKMP94jQ4GYnl8URBIoNt0DVs/NA9b21FIsXvYW3:dMWeSYndj3NtIAQbWFICgW3
    MD5:3FFDE29DE0B31E0DC01B69DB3EAEAC9A
    SHA1:D0C561C313190B8008F155335ED471E9CDAD65E2
    SHA-256:6D2F3A4F541E90F22F0ED1B5AAF790E7728301FB8551991EC6BA0FF259B30F29
    SHA-512:AD6DF17228083BEEAC753BAD016C1AF5800B68099F3358185D600C14DC71428AE621A3CD21821AF1ED33B949E97AE10169D2CD619EC5FEA452065A265BA33BF8
    Malicious:false
    Reputation:low
    Preview:SampleTree demonstrates JTree features. Each node of SampleTree has 7.children, with each one drawn in a random font and color. Each node is.named after its font. While the data isn't interesting, the example.illustrates a number of features:..- Dynamically loading children (see DynamicTreeNode.java).- Adding/removing/inserting/reloading (see the following inner. classes in SampleTree.java: AddAction, RemoveAction, InsertAction,. and ReloadAction).- Creating a custom cell renderer (see SampleTreeCellRenderer.java).- Subclassing JTreeModel for editing (see SampleTreeModel.java)...To run the SampleTree demo:.. java -jar SampleTree.jar..These instructions assume that this installation's version of the java.command is in your path. If it isn't, then you should either.specify the complete path to the java command or update your.PATH environment variable as described in the installation.instructions for the Java(TM) SE Development Kit...
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java archive data (JAR)
    Category:dropped
    Size (bytes):19625
    Entropy (8bit):7.804623186630404
    Encrypted:false
    SSDEEP:384:g9oLVjEH7BbSfWnit5RFGI9TOo4OHgXxe+FTBWLGgXx:g9wZEb0e83q9rXxPsLbx
    MD5:499776AFB67451F2569ED2011DBE99F7
    SHA1:48F8CF50F6E8C99CDA58ACA12F124580980D2A5D
    SHA-256:A6B4DE16EEA2BB8DF03644C14E6808C87789C52FFEBE386732855A786B1E8079
    SHA-512:E58DF97FA39E7385D55971627699E1C7A481BB39F2B9D1FC2DCFEFA471A6E417E20615FBA95DAB48AB7A234817679C379BC096D1ED8F7914915EA20C5D861984
    Malicious:false
    Reputation:low
    Preview:PK..........V................META-INF/......PK..............PK..........V................META-INF/MANIFEST.MFm....@.E....Y...B.N...bQq+aLa`&S.Q..*..&..,.mEML.$...A?.iU..'....dc....xDX.8ZO0..-......n8.h........ .,..#..An.o..v.0VA<L..>.....V..F.'..Si4....9pj...M........j....a.d..6.."....PK..."*.....Q...PK..........V................DynamicTreeNode.class}U[S.U......2..$..:.....b....] ...,.l.&gw..0;.....D.%...U.,....XV@.J%./y....|...UZ.>..L../=.t...u..g~.......A...x....I..vX......|u..4...h...O..$..C.Q.:..?...#.,.9...1...&$...K..`H.K0%X.....`Kp$.....$LK..P.q._vR.0.....i.....,......z......)..$..).b0s.%..9.N.1.t.....M.-=."....j...l+...2...'.xwO.Hb.hl__">.=x4..dp....P..L.e.;...j..l.9....9.....M...P.x.....Z.mo....Y9M...nj..|F..Y. MPw.....kl.@5....\%m.r.).e'..P9$.t..f..i..$......#kx.<nZ..SV..j=:?.>^....a[......Y.^t.hG.....!N.W..x.{d<..d..^...U...-.E....|....e"^..2^._..._....e..7e..[......j.W.(..j~).$.'...R.&..a+.>....."G56Q.n.!+...N>r.66..usR7../.=...T.~j.G..
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java archive data (JAR)
    Category:dropped
    Size (bytes):19625
    Entropy (8bit):7.804623186630404
    Encrypted:false
    SSDEEP:384:g9oLVjEH7BbSfWnit5RFGI9TOo4OHgXxe+FTBWLGgXx:g9wZEb0e83q9rXxPsLbx
    MD5:499776AFB67451F2569ED2011DBE99F7
    SHA1:48F8CF50F6E8C99CDA58ACA12F124580980D2A5D
    SHA-256:A6B4DE16EEA2BB8DF03644C14E6808C87789C52FFEBE386732855A786B1E8079
    SHA-512:E58DF97FA39E7385D55971627699E1C7A481BB39F2B9D1FC2DCFEFA471A6E417E20615FBA95DAB48AB7A234817679C379BC096D1ED8F7914915EA20C5D861984
    Malicious:false
    Reputation:low
    Preview:PK..........V................META-INF/......PK..............PK..........V................META-INF/MANIFEST.MFm....@.E....Y...B.N...bQq+aLa`&S.Q..*..&..,.mEML.$...A?.iU..'....dc....xDX.8ZO0..-......n8.h........ .,..#..An.o..v.0VA<L..>.....V..F.'..Si4....9pj...M........j....a.d..6.."....PK..."*.....Q...PK..........V................DynamicTreeNode.class}U[S.U......2..$..:.....b....] ...,.l.&gw..0;.....D.%...U.,....XV@.J%./y....|...UZ.>..L../=.t...u..g~.......A...x....I..vX......|u..4...h...O..$..C.Q.:..?...#.,.9...1...&$...K..`H.K0%X.....`Kp$.....$LK..P.q._vR.0.....i.....,......z......)..$..).b0s.%..9.N.1.t.....M.-=."....j...l+...2...'.xwO.Hb.hl__">.=x4..dp....P..L.e.;...j..l.9....9.....M...P.x.....Z.mo....Y9M...nj..|F..Y. MPw.....kl.@5....\%m.r.).e'..P9$.t..f..i..$......#kx.<nZ..SV..j=:?.>^....a[......Y.^t.hG.....!N.W..x.{d<..d..^...U...-.E....|....e"^..2^._..._....e..7e..[......j.W.(..j~).$.'...R.&..a+.>....."G56Q.n.!+...N>r.66..usR7../.=...T.~j.G..
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:ASCII text
    Category:dropped
    Size (bytes):952
    Entropy (8bit):4.597969349837422
    Encrypted:false
    SSDEEP:24:dx6bJoKMP94jQ4GYnl8URBIoNt0DVs/NA9b21FIsXvYW3:dMWeSYndj3NtIAQbWFICgW3
    MD5:3FFDE29DE0B31E0DC01B69DB3EAEAC9A
    SHA1:D0C561C313190B8008F155335ED471E9CDAD65E2
    SHA-256:6D2F3A4F541E90F22F0ED1B5AAF790E7728301FB8551991EC6BA0FF259B30F29
    SHA-512:AD6DF17228083BEEAC753BAD016C1AF5800B68099F3358185D600C14DC71428AE621A3CD21821AF1ED33B949E97AE10169D2CD619EC5FEA452065A265BA33BF8
    Malicious:false
    Reputation:low
    Preview:SampleTree demonstrates JTree features. Each node of SampleTree has 7.children, with each one drawn in a random font and color. Each node is.named after its font. While the data isn't interesting, the example.illustrates a number of features:..- Dynamically loading children (see DynamicTreeNode.java).- Adding/removing/inserting/reloading (see the following inner. classes in SampleTree.java: AddAction, RemoveAction, InsertAction,. and ReloadAction).- Creating a custom cell renderer (see SampleTreeCellRenderer.java).- Subclassing JTreeModel for editing (see SampleTreeModel.java)...To run the SampleTree demo:.. java -jar SampleTree.jar..These instructions assume that this installation's version of the java.command is in your path. If it isn't, then you should either.specify the complete path to the java command or update your.PATH environment variable as described in the installation.instructions for the Java(TM) SE Development Kit...
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Zip archive data, at least v2.0 to extract, compression method=deflate
    Category:dropped
    Size (bytes):16510
    Entropy (8bit):7.9195151528778025
    Encrypted:false
    SSDEEP:384:wiGyY3nUWTjv6hEvP8Yy7luCOHR1LmwDvX:wDUW3v6qcf7kzDy8X
    MD5:CE046035D83DBAF4ADF5D45D692D4A25
    SHA1:A034BD74ADB3F8CFDE26D69BD7712BD774EB98C2
    SHA-256:3C0875066FDA4D5DF3C7403DB38A3DEB7D009CAE113D30C37F396A0EA6F4CB4C
    SHA-512:EA8AA8FE012384A742C196374799BF2A479C8AF147BEB3EF08E27593375ADA1F0226A2899A61DB49E93616407822DE51B7F2ECFE9E09D9F4161BECF546759661
    Malicious:false
    Reputation:low
    Preview:PK...........V,.B....t.......DynamicTreeNode.javaUT...%..d%..dux..............Yms....._q..s.Vu(_...b+../....a.f-.c...h.8....sv%Y~i..)...}..s..Wg..j...eA..Ko.........[.&..RI"./TNI.I,.I..B...iJ.\j.?..<..d.."O.e.........*..@.<.D....W.MR,.R._U...Rq.H"....\.Z.(dL.\=&1..KQ./..4U.${.Heq.4..,..T#zs..&....T...`R!./#..z..M..(SE.I.[.M)..g'.....F.HV2.=....\Sk........"kk....\..u.8..6.B..D.z...;Fn..6q,.s..db%Y.*.2.{l".4.....N..r.4..G.B..b<..2.c..I.EH...".k...S.Z..N.*.H.e.9...'_...<.e....).\O...#|..&...7...X..?.{..7.S....^..;...x..W...............r.xaH...........x.{.C..?....C...dJC..O.m:q.^..4.....o.......y.O.,...\.s.......f..$....a...#o.#(.....S.o.........`...W..u.....s.~...l..[.^..C..;.....y.x....;......g.u..#..Fv^v.....u.O..U8....G7....=.w~../i8...f..@..u*....a.._.B....O. ..M......C....q.dll..&.{.2.....[.K...x.ew..^.....p.e,.......o.0..z]D.~7....]H...9h..~.M&.....M.....W...._.q_...>.....-.[[;.MZ.ZM..$..8L..Z<....:.h!EQ.|..d..?J.%.B..).i2..
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Zip archive data, at least v2.0 to extract, compression method=deflate
    Category:dropped
    Size (bytes):16510
    Entropy (8bit):7.9195151528778025
    Encrypted:false
    SSDEEP:384:wiGyY3nUWTjv6hEvP8Yy7luCOHR1LmwDvX:wDUW3v6qcf7kzDy8X
    MD5:CE046035D83DBAF4ADF5D45D692D4A25
    SHA1:A034BD74ADB3F8CFDE26D69BD7712BD774EB98C2
    SHA-256:3C0875066FDA4D5DF3C7403DB38A3DEB7D009CAE113D30C37F396A0EA6F4CB4C
    SHA-512:EA8AA8FE012384A742C196374799BF2A479C8AF147BEB3EF08E27593375ADA1F0226A2899A61DB49E93616407822DE51B7F2ECFE9E09D9F4161BECF546759661
    Malicious:false
    Reputation:low
    Preview:PK...........V,.B....t.......DynamicTreeNode.javaUT...%..d%..dux..............Yms....._q..s.Vu(_...b+../....a.f-.c...h.8....sv%Y~i..)...}..s..Wg..j...eA..Ko.........[.&..RI"./TNI.I,.I..B...iJ.\j.?..<..d.."O.e.........*..@.<.D....W.MR,.R._U...Rq.H"....\.Z.(dL.\=&1..KQ./..4U.${.Heq.4..,..T#zs..&....T...`R!./#..z..M..(SE.I.[.M)..g'.....F.HV2.=....\Sk........"kk....\..u.8..6.B..D.z...;Fn..6q,.s..db%Y.*.2.{l".4.....N..r.4..G.B..b<..2.c..I.EH...".k...S.Z..N.*.H.e.9...'_...<.e....).\O...#|..&...7...X..?.{..7.S....^..;...x..W...............r.xaH...........x.{.C..?....C...dJC..O.m:q.^..4.....o.......y.O.,...\.s.......f..$....a...#o.#(.....S.o.........`...W..u.....s.~...l..[.^..C..;.....y.x....;......g.u..#..Fv^v.....u.O..U8....G7....=.w~../i8...f..@..u*....a.._.B....O. ..M......C....q.dll..&.{.2.....[.K...x.ew..^.....p.e,.......o.0..z]D.~7....]H...9h..~.M&.....M.....W...._.q_...>.....-.[[;.MZ.ZM..$..8L..Z<....:.h!EQ.|..d..?J.%.B..).i2..
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:ASCII text
    Category:dropped
    Size (bytes):651
    Entropy (8bit):4.493184863082543
    Encrypted:false
    SSDEEP:12:IGOvEi76EZCqQpHjEonLqyCdI5lfjhyENDVs/N8w3w9LDoFexsXvV61Wt3:Ix776fhpDxLPwI5DVVs/NA9AFIsXvYW3
    MD5:5F681EE55CC340F3F83DE618759E4145
    SHA1:4042DDCB8C6B47DB5E8AA3CA9492C6B6B1EF825A
    SHA-256:46196E8AA6CACFB2383952DE20C5CBA36D438FF270C200C8FAD60F8C30477775
    SHA-512:658B4B334ADBF95B5B274607EAB908EFDD4FF71B95B4A01D9B331E58E8CBA24DEEE56F4D4BF6A6C2C074F7ABCABBC3C2DEE695AC9D385BA41F5F2D4AD8AB339C
    Malicious:false
    Reputation:low
    Preview:SwingApplet illustrates how it's possible to run a Swing-based.applet, as long as the Swing classes are in the browser's class.path. In the Java 2 platform, Standard Edition, the Swing classes.are core, and thus are always in the class path. For example,.you can run SwingApplet with this command:.. appletviewer SwingApplet.html..These instructions assume that this installation's version of appletviewer.command is in your path. If it isn't, then you should either.specify the complete path to the appletviewer command or update.your PATH environment variable as described in the installation.instructions for the Java(TM) SE Development Kit...
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:HTML document, ASCII text
    Category:dropped
    Size (bytes):199
    Entropy (8bit):5.135020177715082
    Encrypted:false
    SSDEEP:3:PIyPhxn087vyLzLUROSSMH23vXbvxh+VJ8d2Y2RV7GVV2+oMnLVyESVtf8BFc4Nu:pn08ryLzLIqhfXLxY823GuCLV3mtd4QL
    MD5:BDFDB7A517641E5E8BB0CAF553B99447
    SHA1:E4A7E49A2CADA707C28F53EA624411A40D87C95B
    SHA-256:A2123E43B3FD3DE06337A44820BDDA67F9E844729CA374D0696923529B1B0B12
    SHA-512:7CD284E7318D6CCF4395D2991C8558360EFA9E3318210A23100B9EB5567320703FBA81F3743C78E9F58F7960ECAAA69410E2D4C7ECED839F0745E376BE207389
    Malicious:false
    Reputation:low
    Preview:<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML//EN">.<html>.<head><title>Swing Applet</title></head>.<body> <applet code=SwingApplet archive=SwingApplet.jar width=500 height=300>.</applet>.</body>.</html>.
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java archive data (JAR)
    Category:dropped
    Size (bytes):2821
    Entropy (8bit):7.4662119637895
    Encrypted:false
    SSDEEP:48:9Ut7AoOl9ZAfC7iTxjzOilmT/laSvTWH6Nsp3h1zFy0OiMAnTYgx5dkAuMp:GGcpTl8f7BNs3kAnMgxgJy
    MD5:10CB4B71DF56559EBA5A6E937DFE282A
    SHA1:CABC47D1214E3559D8A52DE4F11B55DD3944BCB4
    SHA-256:81A765D75310887B191978D17240125342825CD1DCBA468DE9B6E8185990E528
    SHA-512:F8718344D7C2833F423859529B37020F42098A140040AEE3A7D681FABF3D94C68D13FA0F25DBC89844EFF83F9EF1F95BC8DE4DC4FB48A22B2F867BFB780BE603
    Malicious:false
    Reputation:low
    Preview:PK..........V................META-INF/......PK..............PK..........V................META-INF/MANIFEST.MFm.=k.@.........&I..o......C. .r..........-...Uz..*.n...B.^2X.K.J.Yr$..XL..-e.....,.......|C3..l......VMG.[6.BN>d...X.......][.....?.<.f.U..#....U.i.....x.....;~-'.V..$...ygy.qp|.V_PK..........R...PK..........V................README.txteRMk.0...W.[w!.C....e.RXp.....Y2............}..5...i...1....C^..N0e.p...(s...#..$.....H.s.._.x..>..qQa..c.p1....t../..J...S$=.2..)%O.....9......f"y..M..Jg....R{...I.Y.s..Sj..2....s........^..\......s.......:63".h...._E)ZF..........}.M.l..........B.....=.|.L..y..kT.6_.X.o.\...y...\...x..NK(9.....@.1.=K_.....\..[....8..D...p.S.}..w..PK...v..d.......PK..........V................SwingApplet$1.classUQ.J.@.=.i...z.".Z.V.M..(..b+.....Mi...AQ|...(.l.Z.vf....3._.......G.K&.X6Q..U...6...V...V..S..........3.../../.i.})PjyJ^..=9.sz>..$V.U.dv.x..KO........B.~..n.h...lZ....9.y}.Ie3..#..J)9i.N.....;jP......P
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Zip archive data, at least v2.0 to extract, compression method=deflate
    Category:dropped
    Size (bytes):2528
    Entropy (8bit):7.727894642504275
    Encrypted:false
    SSDEEP:48:9xdPZAfC7ij2Ey0OiMEP0eHarmBT6UzBOgwADj0W0TXpFWLMByYo:xxcpj2gkEP0MaIBDbZ0bbVBlo
    MD5:CF09940B64B3ACDF952AE62B705A0666
    SHA1:0E3214BCD1CEC0D07B1309E8A5A57954C11EB7FD
    SHA-256:63B97393683EB307DDCD7D78356554A299E884F2C550C284E1D7F67066E65A97
    SHA-512:95FFF584007CD7825F5109BB5D2F9746B6A97831FBA554A3C563FEFB0FF68A70806C9469A2B389127BF1C643E613AA9DA697400CB8E06029657D5C1CC1F75F0F
    Malicious:false
    Reputation:low
    Preview:PK...........V.v..d...........README.txtUT...%..d%..dux.............eRMk.0...W.[w!.C....e.RXp.....Y2............}..5...i...1....C^..N0e.p...(s...#..$.....H.s.._.x..>..qQa..c.p1....t../..J...S$=.2..)%O.....9......f"y..M..Jg....R{...I.Y.s..Sj..2....s........^..\......s.......:63".h...._E)ZF..........}.M.l..........B.....=.|.L..y..kT.6_.X.o.\...y...\...x..NK(9.....@.1.=K_.....\..[....8..D...p.S.}..w..PK...........VK..............SwingApplet.htmlUT...%..d%..dux.............U.A..@......{.Bt..J..+...qu.w.RdI..........Ze.T<..N.\Bu?.E.......1.._..K.#2..-.....4.M...~.:..CG..^}9..+4.....rl...u...a..d...m[.-c...g..x....PK...........V.,q.............SwingApplet.javaUT...%..d%..dux..............W.r.6...+6.T.(t.K'.d&.....JRv|.HHFC.....t..}.)K....<84.x.....9y..4.7.Z..,..!...........#...KI.*NjM....*......%.}..4Roe...A&.P.j.h..+.@...*2u.s.I.U..@.Z...#dq..u(.PK...1".%m.^+keA.]oU..{',~H..e}....uU(..8..o-./.5.w.....;^y] .1.%Y...Y,.[.djQ...\......t8...cb..B......
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:ASCII text
    Category:dropped
    Size (bytes):651
    Entropy (8bit):4.493184863082543
    Encrypted:false
    SSDEEP:12:IGOvEi76EZCqQpHjEonLqyCdI5lfjhyENDVs/N8w3w9LDoFexsXvV61Wt3:Ix776fhpDxLPwI5DVVs/NA9AFIsXvYW3
    MD5:5F681EE55CC340F3F83DE618759E4145
    SHA1:4042DDCB8C6B47DB5E8AA3CA9492C6B6B1EF825A
    SHA-256:46196E8AA6CACFB2383952DE20C5CBA36D438FF270C200C8FAD60F8C30477775
    SHA-512:658B4B334ADBF95B5B274607EAB908EFDD4FF71B95B4A01D9B331E58E8CBA24DEEE56F4D4BF6A6C2C074F7ABCABBC3C2DEE695AC9D385BA41F5F2D4AD8AB339C
    Malicious:false
    Reputation:low
    Preview:SwingApplet illustrates how it's possible to run a Swing-based.applet, as long as the Swing classes are in the browser's class.path. In the Java 2 platform, Standard Edition, the Swing classes.are core, and thus are always in the class path. For example,.you can run SwingApplet with this command:.. appletviewer SwingApplet.html..These instructions assume that this installation's version of appletviewer.command is in your path. If it isn't, then you should either.specify the complete path to the appletviewer command or update.your PATH environment variable as described in the installation.instructions for the Java(TM) SE Development Kit...
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:HTML document, ASCII text
    Category:dropped
    Size (bytes):199
    Entropy (8bit):5.135020177715082
    Encrypted:false
    SSDEEP:3:PIyPhxn087vyLzLUROSSMH23vXbvxh+VJ8d2Y2RV7GVV2+oMnLVyESVtf8BFc4Nu:pn08ryLzLIqhfXLxY823GuCLV3mtd4QL
    MD5:BDFDB7A517641E5E8BB0CAF553B99447
    SHA1:E4A7E49A2CADA707C28F53EA624411A40D87C95B
    SHA-256:A2123E43B3FD3DE06337A44820BDDA67F9E844729CA374D0696923529B1B0B12
    SHA-512:7CD284E7318D6CCF4395D2991C8558360EFA9E3318210A23100B9EB5567320703FBA81F3743C78E9F58F7960ECAAA69410E2D4C7ECED839F0745E376BE207389
    Malicious:false
    Reputation:low
    Preview:<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML//EN">.<html>.<head><title>Swing Applet</title></head>.<body> <applet code=SwingApplet archive=SwingApplet.jar width=500 height=300>.</applet>.</body>.</html>.
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java archive data (JAR)
    Category:dropped
    Size (bytes):2821
    Entropy (8bit):7.4662119637895
    Encrypted:false
    SSDEEP:48:9Ut7AoOl9ZAfC7iTxjzOilmT/laSvTWH6Nsp3h1zFy0OiMAnTYgx5dkAuMp:GGcpTl8f7BNs3kAnMgxgJy
    MD5:10CB4B71DF56559EBA5A6E937DFE282A
    SHA1:CABC47D1214E3559D8A52DE4F11B55DD3944BCB4
    SHA-256:81A765D75310887B191978D17240125342825CD1DCBA468DE9B6E8185990E528
    SHA-512:F8718344D7C2833F423859529B37020F42098A140040AEE3A7D681FABF3D94C68D13FA0F25DBC89844EFF83F9EF1F95BC8DE4DC4FB48A22B2F867BFB780BE603
    Malicious:false
    Reputation:low
    Preview:PK..........V................META-INF/......PK..............PK..........V................META-INF/MANIFEST.MFm.=k.@.........&I..o......C. .r..........-...Uz..*.n...B.^2X.K.J.Yr$..XL..-e.....,.......|C3..l......VMG.[6.BN>d...X.......][.....?.<.f.U..#....U.i.....x.....;~-'.V..$...ygy.qp|.V_PK..........R...PK..........V................README.txteRMk.0...W.[w!.C....e.RXp.....Y2............}..5...i...1....C^..N0e.p...(s...#..$.....H.s.._.x..>..qQa..c.p1....t../..J...S$=.2..)%O.....9......f"y..M..Jg....R{...I.Y.s..Sj..2....s........^..\......s.......:63".h...._E)ZF..........}.M.l..........B.....=.|.L..y..kT.6_.X.o.\...y...\...x..NK(9.....@.1.=K_.....\..[....8..D...p.S.}..w..PK...v..d.......PK..........V................SwingApplet$1.classUQ.J.@.=.i...z.".Z.V.M..(..b+.....Mi...AQ|...(.l.Z.vf....3._.......G.K&.X6Q..U...6...V...V..S..........3.../../.i.})PjyJ^..=9.sz>..$V.U.dv.x..KO........B.~..n.h...lZ....9.y}.Ie3..#..J)9i.N.....;jP......P
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Zip archive data, at least v2.0 to extract, compression method=deflate
    Category:dropped
    Size (bytes):2528
    Entropy (8bit):7.727894642504275
    Encrypted:false
    SSDEEP:48:9xdPZAfC7ij2Ey0OiMEP0eHarmBT6UzBOgwADj0W0TXpFWLMByYo:xxcpj2gkEP0MaIBDbZ0bbVBlo
    MD5:CF09940B64B3ACDF952AE62B705A0666
    SHA1:0E3214BCD1CEC0D07B1309E8A5A57954C11EB7FD
    SHA-256:63B97393683EB307DDCD7D78356554A299E884F2C550C284E1D7F67066E65A97
    SHA-512:95FFF584007CD7825F5109BB5D2F9746B6A97831FBA554A3C563FEFB0FF68A70806C9469A2B389127BF1C643E613AA9DA697400CB8E06029657D5C1CC1F75F0F
    Malicious:false
    Reputation:low
    Preview:PK...........V.v..d...........README.txtUT...%..d%..dux.............eRMk.0...W.[w!.C....e.RXp.....Y2............}..5...i...1....C^..N0e.p...(s...#..$.....H.s.._.x..>..qQa..c.p1....t../..J...S$=.2..)%O.....9......f"y..M..Jg....R{...I.Y.s..Sj..2....s........^..\......s.......:63".h...._E)ZF..........}.M.l..........B.....=.|.L..y..kT.6_.X.o.\...y...\...x..NK(9.....@.1.=K_.....\..[....8..D...p.S.}..w..PK...........VK..............SwingApplet.htmlUT...%..d%..dux.............U.A..@......{.Bt..J..+...qu.w.RdI..........Ze.T<..N.\Bu?.E.......1.._..K.#2..-.....4.M...~.:..CG..^}9..+4.....rl...u...a..d...m[.-c...g..x....PK...........V.,q.............SwingApplet.javaUT...%..d%..dux..............W.r.6...+6.T.(t.K'.d&.....JRv|.HHFC.....t..}.)K....<84.x.....9y..4.7.Z..,..!...........#...KI.*NjM....*......%.}..4Roe...A&.P.j.h..+.@...*2u.s.I.U..@.Z...#dq..u(.PK...1".%m.^+keA.]oU..{',~H..e}....uU(..8..o-./.5.w.....;^y] .1.%Y...Y,.[.djQ...\......t8...cb..B......
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:ASCII text
    Category:dropped
    Size (bytes):1718
    Entropy (8bit):4.609390999541685
    Encrypted:false
    SSDEEP:48:Z3YdWdRYP8coosNEVFcH9p5MPbdenIAQbWFICgW3:Z3YURYj7VFcHv5UdeS/y
    MD5:982528D629649F350252F7E0D43DCAAC
    SHA1:B969D2D09E93486F201BD1F2A9AD37E9AF269A98
    SHA-256:52EFAF14455455D048B307C346C1F5B3D26A4CD8F2174B679C253F490C26E469
    SHA-512:524D010848FC1BE33C859040E7CB70767AA100C3703B31326BDD7D390B9CD1CAEF0EEBAE6D53FDED20F64E2911EDA7C4C4EC79935951BEBD918CEE07A502A3D5
    Malicious:false
    Reputation:low
    Preview:The four examples in this directory show how to use some of the.features of the JTable component...TableExample:. This application includes a GUI for configuring the. database connection and specifying the query..TableExample2:. The query and database connection are specified at the command. line. The results are displayed in a JTable..TableExample3:. Is a minimal example showing how to plug a generic sorter into the. JTable..TableExample4:. Uses specialized renderers and editors...TableExample3 and TableExample4 do not depend on database connectivity.and can be compiled and run in the normal way...The most interesting example is probably TableExample, which has a.TextArea that can be used as an editor for an SQL expression. Pressing.the Fetch button sends the expression to the database. The results are.displayed in the JTable underneath the text area...To run TableExample and TableExample2, you need to find a driver for.your database and set the environment variable J
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java archive data (JAR)
    Category:dropped
    Size (bytes):26011
    Entropy (8bit):7.889486129325493
    Encrypted:false
    SSDEEP:768:+DrIUcuX22uVYJ0Fs1FT0gIsjFalLn+i6:+DlUYEs1FoguV+T
    MD5:B349BA0A5D5021873BF9920228A2D738
    SHA1:A7CD56DF3EF1AE5004DE13E478A1C7FC43282563
    SHA-256:4AAD4FA19020341FCE15458F9149AC0A43E1BF6AE8F80F9DC82794D5192D40BA
    SHA-512:6600F83C08121430D12BF864ECA1F20F8282459DA506253F6AFFD39C9DA3ABF298A4EF46EBFD27904B00DA5915BAA26BC770818FFD497C31FD769A2953A049F5
    Malicious:false
    Reputation:low
    Preview:PK..........V................META-INF/......PK..............PK..........V................META-INF/MANIFEST.MFm.=..0...@..:..1(.8T.........R.(..*j..w...s.d]P..-.J;N.....li.....a...P.s<!....%..I{.5..7..qo7...X..t......,=*C.:_:.X.....`(..0.3..~.?.R..0.!.^.J..t&...c.,d...?..-P..j.R.U.....fg..RHq.PK...Pl.....S...PK..........V................JDBCAdapter.class.W.x.U..g_3.L.t..I.R.$.6....i1M[.$.#..Pd.;M.lv....wU...w......[lS.. ...(.<DA@@Q| ...}.....{.....s....8.G.h..*.(B..Tq...\...~|..+..q../..E\...eY.V....]......!<.T.-....b....r]1..w..b|.7...B..'.Fy......2.Y.-B...rL...h..5.H6.*:.b...U...*2*v..".'..b........0..n...q:..p....Ov..p..u...jx@..d.....p.a..e.s...pH...._.....8...a+..+(o[gl0.R.c.-y.|.E)..^3n).\...Q.%i..1....2G%Kq8.K..;.^3...|.+f.{().....Ll.b........h.>.3..7.t.T0o.r..s[...u.c.B.).zM.XlX...q.l......G...........}-...........n3.et.H.@g./j7....+.O"R.nn2.i.\.6....q4.[E.(..c....k.0..Ma.ObH.jk.q#..B....j.Cd.....<_K.HQ..6.|S.!7...%.T...-.D-.Romkk.y
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Zip archive data, at least v2.0 to extract, compression method=deflate
    Category:dropped
    Size (bytes):25048
    Entropy (8bit):7.968455209662083
    Encrypted:false
    SSDEEP:768:ToaQ14QAWaeLRBxAp4SbIg9+WQEL9HalU7d0e:ToX14MLRfAp49gsWtL96lUee
    MD5:C92B77A4C8E564C37B429529CE99D166
    SHA1:F6C7A41CA9CA3E88D09D547E5DC95DD0C7F11037
    SHA-256:CB9250C7915F573F43F92F03595B2534498703DF76E25292CD3914FEFBA35627
    SHA-512:48ACD1A51D41F3297FB4796B165DB0B0A66CA3B9D9693632FBE6D65277DECA24691C83FA133543C70A71D9861481711FC8ABF207F9B3609F708682B39A98D778
    Malicious:false
    Reputation:low
    Preview:PK...........V.xI.x....#......JDBCAdapter.javaUT...%..d%..dux..............YKs.F...W...*f {/[.+.HH..E..hE..aH.E. @.!E.....3...zky.(.L.......G.=...C..n2.....?.cD......X..D....YJb...@d25..CR.RJd*.;....$...i...<...P.J."J.<Y)...".<.:N...lC....<c*.....J0...D.N&. .O.$..|..6"...0...Vq..|(e*|n+..hD?..K)^.r.b...4.J...LY,.;^*...Eq....[..B.d:.o.cS0p]."...xD.p.......9$...DZ.....2Q... ....~..0.|.|...U..@..=..J....(..+O .J) .&.').>.Rr.A..d.....8..M.p.! ..$..6J...{..".(........|.GW..,MkZx..K...6.......'.No.h.x~u.....]...q.M.t.9......t.....9.!.+.r].;d_^Mm....y.......=;..h.l....=l..#-..s..gti9...k..S.Q,.lo.....+....bj:L.j.\.].X....}iM...`L.Gk.{aN.-}..3...K...Z..<.Z....5.X....V.....W....&d.bA+...m@.>,...41/.s(9|.<..x.X.,;l..N]....E...D......r..t.*.-\k.&.9*...X.;..t......gq....1.~..AR..'......;7......#.....y..L6....6..1...Lgf.O.sk6.x..].u....2.k...Jwv.d.?m..e<..w.>#s..f........G.o|QX......D'...A..8 W.0..%....y*n....E.F.."...>..r.../....."..a
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java archive data (JAR)
    Category:dropped
    Size (bytes):26011
    Entropy (8bit):7.889486129325493
    Encrypted:false
    SSDEEP:768:+DrIUcuX22uVYJ0Fs1FT0gIsjFalLn+i6:+DlUYEs1FoguV+T
    MD5:B349BA0A5D5021873BF9920228A2D738
    SHA1:A7CD56DF3EF1AE5004DE13E478A1C7FC43282563
    SHA-256:4AAD4FA19020341FCE15458F9149AC0A43E1BF6AE8F80F9DC82794D5192D40BA
    SHA-512:6600F83C08121430D12BF864ECA1F20F8282459DA506253F6AFFD39C9DA3ABF298A4EF46EBFD27904B00DA5915BAA26BC770818FFD497C31FD769A2953A049F5
    Malicious:false
    Reputation:low
    Preview:PK..........V................META-INF/......PK..............PK..........V................META-INF/MANIFEST.MFm.=..0...@..:..1(.8T.........R.(..*j..w...s.d]P..-.J;N.....li.....a...P.s<!....%..I{.5..7..qo7...X..t......,=*C.:_:.X.....`(..0.3..~.?.R..0.!.^.J..t&...c.,d...?..-P..j.R.U.....fg..RHq.PK...Pl.....S...PK..........V................JDBCAdapter.class.W.x.U..g_3.L.t..I.R.$.6....i1M[.$.#..Pd.;M.lv....wU...w......[lS.. ...(.<DA@@Q| ...}.....{.....s....8.G.h..*.(B..Tq...\...~|..+..q../..E\...eY.V....]......!<.T.-....b....r]1..w..b|.7...B..'.Fy......2.Y.-B...rL...h..5.H6.*:.b...U...*2*v..".'..b........0..n...q:..p....Ov..p..u...jx@..d.....p.a..e.s...pH...._.....8...a+..+(o[gl0.R.c.-y.|.E)..^3n).\...Q.%i..1....2G%Kq8.K..;.^3...|.+f.{().....Ll.b........h.>.3..7.t.T0o.r..s[...u.c.B.).zM.XlX...q.l......G...........}-...........n3.et.H.@g./j7....+.O"R.nn2.i.\.6....q4.[E.(..c....k.0..Ma.ObH.jk.q#..B....j.Cd.....<_K.HQ..6.|S.!7...%.T...-.D-.Romkk.y
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:ASCII text
    Category:dropped
    Size (bytes):1718
    Entropy (8bit):4.609390999541685
    Encrypted:false
    SSDEEP:48:Z3YdWdRYP8coosNEVFcH9p5MPbdenIAQbWFICgW3:Z3YURYj7VFcHv5UdeS/y
    MD5:982528D629649F350252F7E0D43DCAAC
    SHA1:B969D2D09E93486F201BD1F2A9AD37E9AF269A98
    SHA-256:52EFAF14455455D048B307C346C1F5B3D26A4CD8F2174B679C253F490C26E469
    SHA-512:524D010848FC1BE33C859040E7CB70767AA100C3703B31326BDD7D390B9CD1CAEF0EEBAE6D53FDED20F64E2911EDA7C4C4EC79935951BEBD918CEE07A502A3D5
    Malicious:false
    Reputation:low
    Preview:The four examples in this directory show how to use some of the.features of the JTable component...TableExample:. This application includes a GUI for configuring the. database connection and specifying the query..TableExample2:. The query and database connection are specified at the command. line. The results are displayed in a JTable..TableExample3:. Is a minimal example showing how to plug a generic sorter into the. JTable..TableExample4:. Uses specialized renderers and editors...TableExample3 and TableExample4 do not depend on database connectivity.and can be compiled and run in the normal way...The most interesting example is probably TableExample, which has a.TextArea that can be used as an editor for an SQL expression. Pressing.the Fetch button sends the expression to the database. The results are.displayed in the JTable underneath the text area...To run TableExample and TableExample2, you need to find a driver for.your database and set the environment variable J
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Zip archive data, at least v2.0 to extract, compression method=deflate
    Category:dropped
    Size (bytes):25048
    Entropy (8bit):7.968455209662083
    Encrypted:false
    SSDEEP:768:ToaQ14QAWaeLRBxAp4SbIg9+WQEL9HalU7d0e:ToX14MLRfAp49gsWtL96lUee
    MD5:C92B77A4C8E564C37B429529CE99D166
    SHA1:F6C7A41CA9CA3E88D09D547E5DC95DD0C7F11037
    SHA-256:CB9250C7915F573F43F92F03595B2534498703DF76E25292CD3914FEFBA35627
    SHA-512:48ACD1A51D41F3297FB4796B165DB0B0A66CA3B9D9693632FBE6D65277DECA24691C83FA133543C70A71D9861481711FC8ABF207F9B3609F708682B39A98D778
    Malicious:false
    Reputation:low
    Preview:PK...........V.xI.x....#......JDBCAdapter.javaUT...%..d%..dux..............YKs.F...W...*f {/[.+.HH..E..hE..aH.E. @.!E.....3...zky.(.L.......G.=...C..n2.....?.cD......X..D....YJb...@d25..CR.RJd*.;....$...i...<...P.J."J.<Y)...".<.:N...lC....<c*.....J0...D.N&. .O.$..|..6"...0...Vq..|(e*|n+..hD?..K)^.r.b...4.J...LY,.;^*...Eq....[..B.d:.o.cS0p]."...xD.p.......9$...DZ.....2Q... ....~..0.|.|...U..@..=..J....(..+O .J) .&.').>.Rr.A..d.....8..M.p.! ..$..6J...{..".(........|.GW..,MkZx..K...6.......'.No.h.x~u.....]...q.M.t.9......t.....9.!.+.r].;d_^Mm....y.......=;..h.l....=l..#-..s..gti9...k..S.Q,.lo.....+....bj:L.j.\.].X....}iM...`L.Gk.{aN.-}..3...K...Z..<.Z....5.X....V.....W....&d.bA+...m@.>,...41/.s(9|.<..x.X.,;l..N]....E...D......r..t.*.-\k.&.9*...X.;..t......gq....1.~..AR..'......;7......#.....y..L6....6..1...Lgf.O.sk6.x..].u....2.k...Jwv.d.?m..e<..w.>#s..f........G.o|QX......D'...A..8 W.0..%....y*n....E.F.."...>..r.../....."..a
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:ASCII text
    Category:dropped
    Size (bytes):362
    Entropy (8bit):4.470758355734411
    Encrypted:false
    SSDEEP:6:hRzYzEy8oTLAMYgwLkKRLxIQoRtRPLV4mQ/N8qt3wdNFan5qx2AWd3exNLiRgKRx:hRzYzEyJT0XjhyR7DVs/N8w3w9Rx21F9
    MD5:051D449816EB774B6640D4892DB39F6E
    SHA1:966F1F20003E169190DD32990ABB8A1D996E18C0
    SHA-256:D346B216485B1F6A1C56C30DD81056A733657A8DF6ABAFAC077457A07C6E6D4A
    SHA-512:A4B91445B4B8B436ECE06BCD9C47A249325669EF7BADC483816B96FD6A625304759C2B98B479830916ED0739A7FDBC43BA6BD0FBFBE2F0DE0ABD4694D73C6C48
    Malicious:false
    Reputation:low
    Preview:.To run the Ruler demo:.. java -jar TransparentRuler.jar..These instructions assume that this installation's version of the java.command is in your path. If it isn't, then you should either.specify the complete path to the java command or update your.PATH environment variable as described in the installation.instructions for the Java(TM) SE Development Kit..
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java archive data (JAR)
    Category:dropped
    Size (bytes):7929
    Entropy (8bit):7.7550997281671386
    Encrypted:false
    SSDEEP:192:yJ4Sqrx0KkDaWv1zpA11cTS/zO1lSLjDNsy9nKv6:yGKaWtzmLAS/Eo3DNT7
    MD5:1BAC33654FAFF2653F8B0FC130643DF5
    SHA1:85D32DAD746C0F4D13456A2988CCC868A46CBC77
    SHA-256:BCE4B8E6F56C4B054CF85CFC134D96FAF0253E13B9B2F52F0DF9ADAB9D8C6DD8
    SHA-512:995C4D8723B4C930D7D78FFF055B9BE0F37F5451130691659B541AAC40F8B9C4DA77BFA5F970F0E2980795B0085B728348C2EAB29FD86773FB6D8D554309EA22
    Malicious:false
    Reputation:low
    Preview:PK..........V................META-INF/......PK..............PK..........V................META-INF/MANIFEST.MFm.Mk.0........CL..VrK..)....:........._./.v..:H.^=j.]O)._$.E...L.j..).g.f.u.S.K.!lF...|..I.3.......m>..s .zg.........2D......k.....Z7..{..hU.a..X....g0..."...4l..?.\-.@.Zt\..S*!.r.PN[2z..9W..:.PK...gx.....]...PK..........V................README.txtU..J.1.D.........MPP.A.....&K&............*.......ee.k`..[::.\i'<^I0.E.$.K..6tn\Y.>j.:....T....b..R...bgQ.!-=.%.)m....[..Le......<..C.w....f...8.<...qF....(.7.?.IP.Lfi9..i|...K....N.....?.$..s[...vq.j/.m.w..?....g.9..'_...PK...q......j...PK..........V................transparentruler/Ruler$1.classuR]K#1.=...Z.u].j.i.[a.V.).B..+>......3.$..?.g..*>......M....r.{.797....7.o..C.s><.....E.K..x..P2=..M......2y?.y...w..I%.>.r...v.Pl..`.lK%~.o."?..<.(..RE).B.;.3T.......5.1.H...9..+8.1<.>....I.y$..3..;...y..$.R]...Kc.+.F1...j.5...@%.&.$.}..]..X).......k.]. ..9..........(....l:....}....H.tX{k..Q.G.0..L...v.uzT....V$.F
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:ASCII text
    Category:dropped
    Size (bytes):362
    Entropy (8bit):4.470758355734411
    Encrypted:false
    SSDEEP:6:hRzYzEy8oTLAMYgwLkKRLxIQoRtRPLV4mQ/N8qt3wdNFan5qx2AWd3exNLiRgKRx:hRzYzEyJT0XjhyR7DVs/N8w3w9Rx21F9
    MD5:051D449816EB774B6640D4892DB39F6E
    SHA1:966F1F20003E169190DD32990ABB8A1D996E18C0
    SHA-256:D346B216485B1F6A1C56C30DD81056A733657A8DF6ABAFAC077457A07C6E6D4A
    SHA-512:A4B91445B4B8B436ECE06BCD9C47A249325669EF7BADC483816B96FD6A625304759C2B98B479830916ED0739A7FDBC43BA6BD0FBFBE2F0DE0ABD4694D73C6C48
    Malicious:false
    Reputation:low
    Preview:.To run the Ruler demo:.. java -jar TransparentRuler.jar..These instructions assume that this installation's version of the java.command is in your path. If it isn't, then you should either.specify the complete path to the java command or update your.PATH environment variable as described in the installation.instructions for the Java(TM) SE Development Kit..
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Zip archive data, at least v2.0 to extract, compression method=deflate
    Category:dropped
    Size (bytes):4039
    Entropy (8bit):7.845322422408321
    Encrypted:false
    SSDEEP:96:2k1QDLpEa4IswOYpyuI+J/HwmzceSxACWIqBBtp2:XSbswOYIy/DT4T1
    MD5:5B1A458AAAEBA9BC1F16303F2F3FCE6A
    SHA1:A51898E37591F022684ED45CD7C5C93D692E2F0D
    SHA-256:D1DF82E39DACF483F352832FD3824CADEAA28192D7EBE5210A9CFA6B4F0B9102
    SHA-512:204375A664699FA779AE44183652DB8C0534B5A128E9631E5871F76465F3038B8F3045BF79513C52DE1EF63F8243F05DD5F52D3EC4A968487863F3B131F2A2B1
    Malicious:false
    Reputation:low
    Preview:PK...........V.q......j.......README.txtUT...%..d%..dux.............U..J.1.D.........MPP.A.....&K&............*.......ee.k`..[::.\i'<^I0.E.$.K..6tn\Y.>j.:....T....b..R...bgQ.!-=.%.)m....[..Le......<..C.w....f...8.<...qF....(.7.?.IP.Lfi9..i|...K....N.....?.$..s[...vq.j/.m.w..?....g.9..'_...PK...........V................transparentruler/UT...%..d%..dux.............PK...........V_L%......%......transparentruler/Ruler.javaUT...%..d%..dux..............Zyo.....b.@....G.6.klh....*IE....4....-...{3.DJ...n...9..(.'G.u..:..y.4............yQp.'Ld)...D(...:3.I..%<..#.t.#.6.D.%b.g"....S.D..8O|I.ME.%k..'...V".3p..q...E....{D....%O.".x..I.(.<ds/...:a..D4c~....R.Bx..}(Dc..x)..J..8.t.fP). /Q...#..fRT...L.................'.<...\+.)...A...O.1.kI*..|...+.G... a.x?.^.n} }G...TU.p!q.&....+.+....'.f...]....|.l.)..E.x..-.....8.L....@@DcI....(i...( .(c...c...|.EW..,M+Z.w...;1l..yd.?[].....d...m...n...A.o..m]..!^......cyf..2...6...mf.G=....6..e:mf.:.q....h...e=.o..s.m%...7.o
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java archive data (JAR)
    Category:dropped
    Size (bytes):7929
    Entropy (8bit):7.7550997281671386
    Encrypted:false
    SSDEEP:192:yJ4Sqrx0KkDaWv1zpA11cTS/zO1lSLjDNsy9nKv6:yGKaWtzmLAS/Eo3DNT7
    MD5:1BAC33654FAFF2653F8B0FC130643DF5
    SHA1:85D32DAD746C0F4D13456A2988CCC868A46CBC77
    SHA-256:BCE4B8E6F56C4B054CF85CFC134D96FAF0253E13B9B2F52F0DF9ADAB9D8C6DD8
    SHA-512:995C4D8723B4C930D7D78FFF055B9BE0F37F5451130691659B541AAC40F8B9C4DA77BFA5F970F0E2980795B0085B728348C2EAB29FD86773FB6D8D554309EA22
    Malicious:false
    Reputation:low
    Preview:PK..........V................META-INF/......PK..............PK..........V................META-INF/MANIFEST.MFm.Mk.0........CL..VrK..)....:........._./.v..:H.^=j.]O)._$.E...L.j..).g.f.u.S.K.!lF...|..I.3.......m>..s .zg.........2D......k.....Z7..{..hU.a..X....g0..."...4l..?.\-.@.Zt\..S*!.r.PN[2z..9W..:.PK...gx.....]...PK..........V................README.txtU..J.1.D.........MPP.A.....&K&............*.......ee.k`..[::.\i'<^I0.E.$.K..6tn\Y.>j.:....T....b..R...bgQ.!-=.%.)m....[..Le......<..C.w....f...8.<...qF....(.7.?.IP.Lfi9..i|...K....N.....?.$..s[...vq.j/.m.w..?....g.9..'_...PK...q......j...PK..........V................transparentruler/Ruler$1.classuR]K#1.=...Z.u].j.i.[a.V.).B..+>......3.$..?.g..*>......M....r.{.797....7.o..C.s><.....E.K..x..P2=..M......2y?.y...w..I%.>.r...v.Pl..`.lK%~.o."?..<.(..RE).B.;.3T.......5.1.H...9..+8.1<.>....I.y$..3..;...y..$.R]...Kc.+.F1...j.5...@%.&.$.}..]..X).......k.]. ..9..........(....l:....}....H.tX{k..Q.G.0..L...v.uzT....V$.F
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Zip archive data, at least v2.0 to extract, compression method=deflate
    Category:dropped
    Size (bytes):4039
    Entropy (8bit):7.845322422408321
    Encrypted:false
    SSDEEP:96:2k1QDLpEa4IswOYpyuI+J/HwmzceSxACWIqBBtp2:XSbswOYIy/DT4T1
    MD5:5B1A458AAAEBA9BC1F16303F2F3FCE6A
    SHA1:A51898E37591F022684ED45CD7C5C93D692E2F0D
    SHA-256:D1DF82E39DACF483F352832FD3824CADEAA28192D7EBE5210A9CFA6B4F0B9102
    SHA-512:204375A664699FA779AE44183652DB8C0534B5A128E9631E5871F76465F3038B8F3045BF79513C52DE1EF63F8243F05DD5F52D3EC4A968487863F3B131F2A2B1
    Malicious:false
    Reputation:low
    Preview:PK...........V.q......j.......README.txtUT...%..d%..dux.............U..J.1.D.........MPP.A.....&K&............*.......ee.k`..[::.\i'<^I0.E.$.K..6tn\Y.>j.:....T....b..R...bgQ.!-=.%.)m....[..Le......<..C.w....f...8.<...qF....(.7.?.IP.Lfi9..i|...K....N.....?.$..s[...vq.j/.m.w..?....g.9..'_...PK...........V................transparentruler/UT...%..d%..dux.............PK...........V_L%......%......transparentruler/Ruler.javaUT...%..d%..dux..............Zyo.....b.@....G.6.klh....*IE....4....-...{3.DJ...n...9..(.'G.u..:..y.4............yQp.'Ld)...D(...:3.I..%<..#.t.#.6.D.%b.g"....S.D..8O|I.ME.%k..'...V".3p..q...E....{D....%O.".x..I.(.<ds/...:a..D4c~....R.Bx..}(Dc..x)..J..8.t.fP). /Q...#..fRT...L.................'.<...\+.)...A...O.1.kI*..|...+.G... a.x?.^.n} }G...TU.p!q.&....+.+....'.f...]....|.l.)..E.x..-.....8.L....@@DcI....(i...( .(c...c...|.EW..,M+Z.w...;1l..yd.?[].....d...m...n...A.o..m]..!^......cyf..2...6...mf.G=....6..e:mf.:.q....h...e=.o..s.m%...7.o
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:ASCII text
    Category:dropped
    Size (bytes):55
    Entropy (8bit):4.233442842437981
    Encrypted:false
    SSDEEP:3:c3AXFsZE7uRBQMr+M4n:c9ZMucM4
    MD5:FC724CDAA63BEFC4B5F744F91383D1AF
    SHA1:7BB94D667728AB6AD79C2CEAD180CAFF741292A3
    SHA-256:15CC6A7A6E4D00AB9060A6D5B1AEA2A5B44570073560242D075DA15972168BD8
    SHA-512:EB561CDA0D88AC1E42299AC7C5C219ADF334B7C25C59A20EF811404BF5E0CE28C43706D3AB6A0734FC2CC5B7B12B13514428AF05AD315BE7044001B3086C0275
    Malicious:false
    Reputation:low
    Preview:Please refer to the documentation in:...doc/index.html.
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:ASCII text
    Category:dropped
    Size (bytes):55
    Entropy (8bit):4.233442842437981
    Encrypted:false
    SSDEEP:3:c3AXFsZE7uRBQMr+M4n:c9ZMucM4
    MD5:FC724CDAA63BEFC4B5F744F91383D1AF
    SHA1:7BB94D667728AB6AD79C2CEAD180CAFF741292A3
    SHA-256:15CC6A7A6E4D00AB9060A6D5B1AEA2A5B44570073560242D075DA15972168BD8
    SHA-512:EB561CDA0D88AC1E42299AC7C5C219ADF334B7C25C59A20EF811404BF5E0CE28C43706D3AB6A0734FC2CC5B7B12B13514428AF05AD315BE7044001B3086C0275
    Malicious:false
    Reputation:low
    Preview:Please refer to the documentation in:...doc/index.html.
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java archive data (JAR)
    Category:dropped
    Size (bytes):321403
    Entropy (8bit):7.955717236300726
    Encrypted:false
    SSDEEP:6144:LPo8YPIYJ5rsomTWEoYVlW+Bdka4BitYfNxX96GNC3bcZK:L1YPIs5rsomTDDVlW+BdOBitYffX04ZK
    MD5:3365B2E8A17A3256CC7E356B6100FA63
    SHA1:023ABE3C57E3D698BAF7773503527C16D24F7B57
    SHA-256:B421DF2195111B6FD29E27B96E166956FCF29D3B1A1294EAE9F60F8E85850A5E
    SHA-512:41C281B669C2AA9B2919C6568B70ED1044C1C3FF5E7B0202520062C031FEBA8C021337D994A56D7668E3CAB9CEF40527F6D715589E38FC990B79E82034F98A99
    Malicious:false
    Reputation:low
    Preview:PK..........V................META-INF/......PK..............PK..........V................META-INF/MANIFEST.MFm.=..0...=..p..-...nZ.*.........R.X._..~..=..^....B.%.i.9..D...,q.p.F......au.-..{.._.....d7.R).-).h...w>..Ge...[.o.o.~.6...-L..>.o.....'...f.g.I.....X9.%.x..{./(E....`.. ..gPK........G...PK...........V................com/sun/tools/example/README..IM,NU(JMK-R(.W(.HUH.O..M.+I,...S........g.V.e...p..PK..U...8...7...PK...........V............9...com/sun/tools/example/debug/bdi/AccessWatchpointSpec.java.VQo.9.~.W.....n w=).*.6%.......h.Y..bom/....o...G.n_.3..o..8?...\.j.....=.^^^..b0..a.,..Q....D..R..>..,!.....J......%...(.Y...n....g.l..v...G..ny;^..x2..Q.q.1.c,..AZ.@..C.o....`ok..PR.}pzU...-.U:.....F..P .t..6..>M....t..y.*....h<.......XS.. <.T...T..G...8p..K.D.{...).zmX*.....u)...$.._.....l.}u]..+..W..$V..q..[.P1.Q8..&........ -...J.M.C..Iq.........T.ij......e.(.>.....%c.....fY:]>\Qp(,....(..J.@*9a..p7.o)>.0....`.......@.Ha.f..I...>...#.v....c.c...
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java archive data (JAR)
    Category:dropped
    Size (bytes):321403
    Entropy (8bit):7.955717236300726
    Encrypted:false
    SSDEEP:6144:LPo8YPIYJ5rsomTWEoYVlW+Bdka4BitYfNxX96GNC3bcZK:L1YPIs5rsomTDDVlW+BdOBitYffX04ZK
    MD5:3365B2E8A17A3256CC7E356B6100FA63
    SHA1:023ABE3C57E3D698BAF7773503527C16D24F7B57
    SHA-256:B421DF2195111B6FD29E27B96E166956FCF29D3B1A1294EAE9F60F8E85850A5E
    SHA-512:41C281B669C2AA9B2919C6568B70ED1044C1C3FF5E7B0202520062C031FEBA8C021337D994A56D7668E3CAB9CEF40527F6D715589E38FC990B79E82034F98A99
    Malicious:false
    Reputation:low
    Preview:PK..........V................META-INF/......PK..............PK..........V................META-INF/MANIFEST.MFm.=..0...=..p..-...nZ.*.........R.X._..~..=..^....B.%.i.9..D...,q.p.F......au.-..{.._.....d7.R).-).h...w>..Ge...[.o.o.~.6...-L..>.o.....'...f.g.I.....X9.%.x..{./(E....`.. ..gPK........G...PK...........V................com/sun/tools/example/README..IM,NU(JMK-R(.W(.HUH.O..M.+I,...S........g.V.e...p..PK..U...8...7...PK...........V............9...com/sun/tools/example/debug/bdi/AccessWatchpointSpec.java.VQo.9.~.W.....n w=).*.6%.......h.Y..bom/....o...G.n_.3..o..8?...\.j.....=.^^^..b0..a.,..Q....D..R..>..,!.....J......%...(.Y...n....g.l..v...G..ny;^..x2..Q.q.1.c,..AZ.@..C.o....`ok..PR.}pzU...-.U:.....F..P .t..6..>M....t..y.*....h<.......XS.. <.T...T..G...8p..K.D.{...).zmX*.....u)...$.._.....l.}u]..+..W..$V..q..[.P1.Q8..&........ -...J.M.C..Iq.........T.ij......e.(.>.....%c.....fY:]>\Qp(,....(..J.@*9a..p7.o)>.0....`.......@.Ha.f..I...>...#.v....c.c...
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Zip archive data, at least v1.0 to extract, compression method=store
    Category:dropped
    Size (bytes):327091
    Entropy (8bit):7.9537146463166
    Encrypted:false
    SSDEEP:6144:jQz0QumUU5rQrvYWKtYVqq+4ZYLpVZ854Yf+R1P2KEC31byceG:jzQumZ5rQrvYNKVqq+4ZEne4Yf01eKBL
    MD5:463001EA67AFB8FF953AF42F9D63BC91
    SHA1:E8599D2748704E7DFEB6C5E9E533A9CA58F01F46
    SHA-256:FC125FB59F1EA6E13F8D034E056C28D4C187AE56FCDFC04416F404560A5E1ECC
    SHA-512:0543B63DE9E9E20D3D255B8DD332D3BFBF60628F57A7D8184C7AF229FA4E864AAF017059E5E768FE862B1B760D1913063F9317F094314F7862014F8BFDFEBFEE
    Malicious:false
    Reputation:low
    Preview:PK...........V................com/sun/tools/example/UT... ..d ..dux.............PK...........V................com/sun/tools/example/debug/UT... ..d ..dux.............PK...........V............ ...com/sun/tools/example/debug/bdi/UT... ..d ..dux.............PK...........V...v........9...com/sun/tools/example/debug/bdi/AccessWatchpointSpec.javaUT... ..d ..dux..............VQo.9.~.W.....n w=).*.6%.......h.Y..bom/....o...G.n_.3..o..8?...\.j.....=.^^^..b0..a.,..Q....D..R..>..,!.....J......%...(.Y...n....g.l..v...G..ny;^..x2..Q.q.1.c,..AZ.@..C.o....`ok..PR.}pzU...-.U:.....F..P .t..6..>M....t..y.*....h<.......XS.. <.T...T..G...8p..K.D.{...).zmX*.....u)...$.._.....l.}u]..+..W..$V..q..[.P1.Q8..&........ -...J.M.C..Iq.........T.ij......e.(.>.....%c.....fY:]>\Qp(,....(..J.@*9a..p7.o)>.0....`.......@.Ha.f..I...>...#.v....c.c......B......\.6.....H.P'U.2>..=.[*(....5.....o.1....uT......t..>.&..\.3...ild.wC.....t.F..|SZ.....@.p...b8....:..."mK..(...&.2g.6...Z..{......
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Zip archive data, at least v1.0 to extract, compression method=store
    Category:dropped
    Size (bytes):327091
    Entropy (8bit):7.9537146463166
    Encrypted:false
    SSDEEP:6144:jQz0QumUU5rQrvYWKtYVqq+4ZYLpVZ854Yf+R1P2KEC31byceG:jzQumZ5rQrvYNKVqq+4ZEne4Yf01eKBL
    MD5:463001EA67AFB8FF953AF42F9D63BC91
    SHA1:E8599D2748704E7DFEB6C5E9E533A9CA58F01F46
    SHA-256:FC125FB59F1EA6E13F8D034E056C28D4C187AE56FCDFC04416F404560A5E1ECC
    SHA-512:0543B63DE9E9E20D3D255B8DD332D3BFBF60628F57A7D8184C7AF229FA4E864AAF017059E5E768FE862B1B760D1913063F9317F094314F7862014F8BFDFEBFEE
    Malicious:false
    Reputation:low
    Preview:PK...........V................com/sun/tools/example/UT... ..d ..dux.............PK...........V................com/sun/tools/example/debug/UT... ..d ..dux.............PK...........V............ ...com/sun/tools/example/debug/bdi/UT... ..d ..dux.............PK...........V...v........9...com/sun/tools/example/debug/bdi/AccessWatchpointSpec.javaUT... ..d ..dux..............VQo.9.~.W.....n w=).*.6%.......h.Y..bom/....o...G.n_.3..o..8?...\.j.....=.^^^..b0..a.,..Q....D..R..>..,!.....J......%...(.Y...n....g.l..v...G..ny;^..x2..Q.q.1.c,..AZ.@..C.o....`ok..PR.}pzU...-.U:.....F..P .t..6..>M....t..y.*....h<.......XS.. <.T...T..G...8p..K.D.{...).zmX*.....u)...$.._.....l.}u]..+..W..$V..q..[.P1.Q8..&........ -...J.M.C..Iq.........T.ij......e.(.>.....%c.....fY:]>\Qp(,....(..J.@*9a..p7.o)>.0....`.......@.Ha.f..I...>...#.v....c.c......B......\.6.....H.P'U.2>..=.[*(....5.....o.1....uT......t..>.&..\.3...ild.wC.....t.F..|SZ.....@.p...b8....:..."mK..(...&.2g.6...Z..{......
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:ASCII text
    Category:dropped
    Size (bytes):1859
    Entropy (8bit):5.169809880681725
    Encrypted:false
    SSDEEP:48:VFyOlrYJErYJFHvv432sDt32sWEtPu3tOHxC:VFPlrYJErYJFPQ3vt3S34RC
    MD5:DCFE5E04E222305AD6EA5F19AC886723
    SHA1:D65CF75E956F497F7B6901ED3F5D770C8BD4F01E
    SHA-256:B61BABB18886D0C1FB13CFEA762D92B5A7E47F61E7177A2906B1F171C040D04D
    SHA-512:ECBF0B369E1EF71C595C2C18CA141896F0F5E5FFB6A4D741A2FF2E59C835F38C943405FAA4D8A6322BF3BA0CADA1919675401805EB1E5034D1234C7B0D9962D5
    Malicious:false
    Reputation:low
    Preview:#.# Copyright (c) 2010, Oracle and/or its affiliates. All rights reserved..#.# Redistribution and use in source and binary forms, with or without.# modification, are permitted provided that the following conditions.# are met:.#.# - Redistributions of source code must retain the above copyright.# notice, this list of conditions and the following disclaimer..#.# - Redistributions in binary form must reproduce the above copyright.# notice, this list of conditions and the following disclaimer in the.# documentation and/or other materials provided with the distribution..#.# - Neither the name of Oracle nor the names of its.# contributors may be used to endorse or promote products derived.# from this software without specific prior written permission..#.# THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS.# IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,.# THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PART
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Zip archive data, at least v2.0 to extract, compression method=deflate
    Category:dropped
    Size (bytes):11217
    Entropy (8bit):7.9475942625930776
    Encrypted:false
    SSDEEP:192:tqGQQSW1tFdvMAxJiWG91Yo12jbpf9sNJosX31osw5fcL1nI/IGcGCCRCFX:EGJV1NxJnG9nydBUpGRqX
    MD5:82C6EDDAEE8971A519320887058FA84E
    SHA1:AA2364121E931E6A9A743BE776B550EF3CCF3033
    SHA-256:49DA45DF97332491D6A8E113352FAE3A69F82B4D20FE83E0AD76956BB6A4CD77
    SHA-512:E35FC870DE2EB0CF4CCE1BF533B1ABDB7E8AF38A97A2FB2017A52330B2BEFD1F1287E828AA02F5F497D2BD8EF03122055863E8AD01ED24C43497C6A355CF7283
    Malicious:false
    Reputation:low
    Preview:PK...........V"..'....-'......compiledMethodLoad.cUT...%..d%..dux..............Z[s.H.~..8.V\.....$.2...XI...d.1..I...3....t..$;.J...w.V.m...0..../S.=..........;......a.<M.Y,...%..>.}..,a.y.G.&.x...n..0 .X'.x.I..]..w<p.GX..*Q...K@*...SBY.._p.!....A...OS.A.....t...C....xp.n.x.6%.B.V,=.X.8j..@...rC.W...EJ....pCS..$.@...e......H8%m!c.1...._....n.jE597(..F..G...5..Bw.bA...#..qA.+.~..?)m lG.UA."N..{iM..1.9W......f9.......>..#?B)B`....\..X.).."tG..Do.a.8/......".2H"..^N...w....".}.[`....jj...q...!.....czk.W6\...fZ.N.8:.M.|f.8.Q-....S'...255....}<...Lub..>..fC}r..b..a..u..."..Zv.q.c..\.O.\.... y..."w..T.....f#.$......$.P..#U.k.c@&.0h.....J.....7..D.D...{.!...H..P.nj...*..P...H.k..t.B@./.J......a-.?3\..0T..%..}Y=h......;...[.n.l...c(.ni.>.3........$b.J&....p..?.Y..>.5.Mm....7.!.T..C.lc"dFe..-....C.C..+..LR..J.P{....I.2..3..G..6.h.. ....zh=...$T"~."...........a]./@.^........3....\e..x{p.V....2..Jr.X.I,..!B}.8.".8p.q...9.:....s.....Ub.$....c>.
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:ASCII text
    Category:dropped
    Size (bytes):1859
    Entropy (8bit):5.169809880681725
    Encrypted:false
    SSDEEP:48:VFyOlrYJErYJFHvv432sDt32sWEtPu3tOHxC:VFPlrYJErYJFPQ3vt3S34RC
    MD5:DCFE5E04E222305AD6EA5F19AC886723
    SHA1:D65CF75E956F497F7B6901ED3F5D770C8BD4F01E
    SHA-256:B61BABB18886D0C1FB13CFEA762D92B5A7E47F61E7177A2906B1F171C040D04D
    SHA-512:ECBF0B369E1EF71C595C2C18CA141896F0F5E5FFB6A4D741A2FF2E59C835F38C943405FAA4D8A6322BF3BA0CADA1919675401805EB1E5034D1234C7B0D9962D5
    Malicious:false
    Reputation:low
    Preview:#.# Copyright (c) 2010, Oracle and/or its affiliates. All rights reserved..#.# Redistribution and use in source and binary forms, with or without.# modification, are permitted provided that the following conditions.# are met:.#.# - Redistributions of source code must retain the above copyright.# notice, this list of conditions and the following disclaimer..#.# - Redistributions in binary form must reproduce the above copyright.# notice, this list of conditions and the following disclaimer in the.# documentation and/or other materials provided with the distribution..#.# - Neither the name of Oracle nor the names of its.# contributors may be used to endorse or promote products derived.# from this software without specific prior written permission..#.# THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS.# IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,.# THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PART
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
    Category:dropped
    Size (bytes):23560
    Entropy (8bit):6.709114063357369
    Encrypted:false
    SSDEEP:384:NcnkfqNNOLMLEk2T9hcWqsCi7jiZSf+VIYinvyONdPxh8E9VF0NyGISS:pQoLS2Hdq07d/YinrXPxWEwj
    MD5:938A2829B92A11911F6255D98516BC57
    SHA1:A5E942F9518F7DE9B40AD536F2CC830C73AB7A79
    SHA-256:CF91D0C4EDACC75E62461A506D333DE2B2B800410D05F5B3E4AB76859E15CA70
    SHA-512:7DE4E061A3D634359EF3D945A6C17A27F277202916DA446B6786A9CCDB23D78A6E135A32E0F4EA81EAC64370F43A2B609F678E4FB613D636BC0AC33ACDFB4088
    Malicious:false
    Antivirus:
    • Antivirus: ReversingLabs, Detection: 0%
    Reputation:low
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......v...2o.2o.2o..,.0o.2o..o.t>:.1o.t>8.3o.t>..9o.t>..0o....0o..;.3o.?=<.3o..9.3o.Rich2o.........................PE..d...`..d.........." ................t................................................r....`..........................................7..o... 8..<....`.......P..P....,...0...p......P1..8............................4..p............0...............................text............................... ..`.rdata.......0......................@..@.data........@......."..............@....pdata..P....P.......$..............@..@.rsrc........`.......&..............@..@.reloc.......p.......*..............@..B................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Intel amd64 COFF object file, not stripped, 2 sections, symbol offset=0x2c9, 10 symbols, created Fri Jul 14 19:39:12 2023, 1st section name ".edata"
    Category:dropped
    Size (bytes):925
    Entropy (8bit):4.590674153801106
    Encrypted:false
    SSDEEP:24:gd5a1T4Na2wIeKPb0d7qymxHxu3g419l9V:594BwIeKj0d7qtHxuQ419lv
    MD5:8DB9CEDB12C0F53E197D17470BAB45FF
    SHA1:6331ECD9660EFA3378AFA02B2689C0EF1A597DD4
    SHA-256:FCDAD6EBB3F21A59235C1DDEE2AA0BDC1FA68D600D66C0B2C6EDCA8653982B98
    SHA-512:1D79C690AF2E0453E32F9EC6906DB1BA4310777D8AD1AE544F03AEBE0B9A7DF028A32D0E157B418853D4F8BFE0239B61BC3276B4D6297C8E79B73944E4FD31D1
    Malicious:false
    Reputation:low
    Preview:d...`..d.............edata..........o...d...............@..@.debug$S............$...............@..B....`..d....................................................compiledMethodLoad.dll.Agent_OnLoad.Agent_OnUnload...................... .........$.........(.........0.........,.........4.............................c:/wsjdk/Corretto8Src/installers/windows/zip/corretto-build/buildRoot/build/windows-x86_64-normal-server-release/jdk/demoobjs/jvmti/compiledMethodLoad/compiledMethodLoad.exp.+.<.......................Microsoft (R) LINK...=..cwd.C:\wsjdk\Corretto8Src\installers\windows\zip\corretto-build\buildRoot\jdk\make.exe.c:\progra~2\micros~3.0\vc\bin\amd64\link.exe....8.....Agent_OnLoad...8.....Agent_OnUnload.@comp.id...........edata............szName..<.........rgpv....(.........rgszName0.........rgwOrd..8.........$N00001.S.........$N00002.`............................................. ...Agent_OnLoad.Agent_OnUnload.
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:current ar archive
    Category:dropped
    Size (bytes):2144
    Entropy (8bit):4.670686323035202
    Encrypted:false
    SSDEEP:24:Uy12vAXmwh72199vOPgPcLKlHsryAOm12vRC+kK//yL2tvKPjv7RvN:UXv2KvNPcLK6yAOrvRvkK7tvKLvBN
    MD5:C0725D1955F438C829D0F78A2DFB852D
    SHA1:B32356EA49AFF2BA5F962F0015DD97F4AB9DA22A
    SHA-256:9CEA147EB0F48E38B173FB152F076EC2CF352FEFF981DE1DE503EA82E387BF16
    SHA-512:2FB111C9CF0338F4C22F476C53AA717DA22E9B225DFAD6536855F2A68DA043892F20757FEBD42C6185007061C3AD9508C45EC728462CBE317DE20B13044C7B86
    Malicious:false
    Reputation:low
    Preview:!<arch>./ 1689363552 0 200 `........n...........v...v........__IMPORT_DESCRIPTOR_compiledMethodLoad.__NULL_IMPORT_DESCRIPTOR..compiledMethodLoad_NULL_THUNK_DATA.Agent_OnLoad.__imp_Agent_OnLoad.Agent_OnUnload.__imp_Agent_OnUnload./ 1689363552 0 210 `.....n...........v.........................Agent_OnLoad.Agent_OnUnload.__IMPORT_DESCRIPTOR_compiledMethodLoad.__NULL_IMPORT_DESCRIPTOR.__imp_Agent_OnLoad.__imp_Agent_OnUnload..compiledMethodLoad_NULL_THUNK_DATA.// 1689363552 0 23 `.compiledMethodLoad.dll../0 1689363552 0 538 `.d...`..d"............debug$S........L...................@..B.idata$2............................@.0..idata$6............................@. ..............compiledMethodLoad.dll'......................Microsoft (R) LINK..................................................compiledMethodLoad.dll..@comp.id....................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:MSVC program database ver 7.00, 4096*81 bytes
    Category:dropped
    Size (bytes):331776
    Entropy (8bit):4.568356369019405
    Encrypted:false
    SSDEEP:6144:ZG4s3EO9I2eUP3dReW5jfgj0XmSmuCDjyAd3JOg/CD:ZEHljgM
    MD5:4B9A0A002A45B1046F5073DDBE1FC30F
    SHA1:54BD1E66F77C68CE2D3BD7A92F156F2BB37A0829
    SHA-256:04A4A5AF462AF06839DC44D2BC9EE208247E45EA7479DEDE07EE9AD6FBB048FC
    SHA-512:4F3A2A7B0FFAC1946FF7B4DF4E86A7B98C1FC9F60E3565E2DACE92F7E94C0A508E2C1B4C9985E38FEE36E29B32D7202FD307128111C10E567F3E25F80C691D0F
    Malicious:false
    Reputation:low
    Preview:Microsoft C/C++ MSF 7.00...DS...........Q...........P...................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Intel amd64 COFF object file, not stripped, 2 sections, symbol offset=0x2c9, 10 symbols, created Fri Jul 14 19:39:12 2023, 1st section name ".edata"
    Category:dropped
    Size (bytes):925
    Entropy (8bit):4.590674153801106
    Encrypted:false
    SSDEEP:24:gd5a1T4Na2wIeKPb0d7qymxHxu3g419l9V:594BwIeKj0d7qtHxuQ419lv
    MD5:8DB9CEDB12C0F53E197D17470BAB45FF
    SHA1:6331ECD9660EFA3378AFA02B2689C0EF1A597DD4
    SHA-256:FCDAD6EBB3F21A59235C1DDEE2AA0BDC1FA68D600D66C0B2C6EDCA8653982B98
    SHA-512:1D79C690AF2E0453E32F9EC6906DB1BA4310777D8AD1AE544F03AEBE0B9A7DF028A32D0E157B418853D4F8BFE0239B61BC3276B4D6297C8E79B73944E4FD31D1
    Malicious:false
    Reputation:low
    Preview:d...`..d.............edata..........o...d...............@..@.debug$S............$...............@..B....`..d....................................................compiledMethodLoad.dll.Agent_OnLoad.Agent_OnUnload...................... .........$.........(.........0.........,.........4.............................c:/wsjdk/Corretto8Src/installers/windows/zip/corretto-build/buildRoot/build/windows-x86_64-normal-server-release/jdk/demoobjs/jvmti/compiledMethodLoad/compiledMethodLoad.exp.+.<.......................Microsoft (R) LINK...=..cwd.C:\wsjdk\Corretto8Src\installers\windows\zip\corretto-build\buildRoot\jdk\make.exe.c:\progra~2\micros~3.0\vc\bin\amd64\link.exe....8.....Agent_OnLoad...8.....Agent_OnUnload.@comp.id...........edata............szName..<.........rgpv....(.........rgszName0.........rgwOrd..8.........$N00001.S.........$N00002.`............................................. ...Agent_OnLoad.Agent_OnUnload.
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:current ar archive
    Category:dropped
    Size (bytes):2144
    Entropy (8bit):4.670686323035202
    Encrypted:false
    SSDEEP:24:Uy12vAXmwh72199vOPgPcLKlHsryAOm12vRC+kK//yL2tvKPjv7RvN:UXv2KvNPcLK6yAOrvRvkK7tvKLvBN
    MD5:C0725D1955F438C829D0F78A2DFB852D
    SHA1:B32356EA49AFF2BA5F962F0015DD97F4AB9DA22A
    SHA-256:9CEA147EB0F48E38B173FB152F076EC2CF352FEFF981DE1DE503EA82E387BF16
    SHA-512:2FB111C9CF0338F4C22F476C53AA717DA22E9B225DFAD6536855F2A68DA043892F20757FEBD42C6185007061C3AD9508C45EC728462CBE317DE20B13044C7B86
    Malicious:false
    Reputation:low
    Preview:!<arch>./ 1689363552 0 200 `........n...........v...v........__IMPORT_DESCRIPTOR_compiledMethodLoad.__NULL_IMPORT_DESCRIPTOR..compiledMethodLoad_NULL_THUNK_DATA.Agent_OnLoad.__imp_Agent_OnLoad.Agent_OnUnload.__imp_Agent_OnUnload./ 1689363552 0 210 `.....n...........v.........................Agent_OnLoad.Agent_OnUnload.__IMPORT_DESCRIPTOR_compiledMethodLoad.__NULL_IMPORT_DESCRIPTOR.__imp_Agent_OnLoad.__imp_Agent_OnUnload..compiledMethodLoad_NULL_THUNK_DATA.// 1689363552 0 23 `.compiledMethodLoad.dll../0 1689363552 0 538 `.d...`..d"............debug$S........L...................@..B.idata$2............................@.0..idata$6............................@. ..............compiledMethodLoad.dll'......................Microsoft (R) LINK..................................................compiledMethodLoad.dll..@comp.id....................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:MSVC program database ver 7.00, 4096*81 bytes
    Category:dropped
    Size (bytes):331776
    Entropy (8bit):4.568356369019405
    Encrypted:false
    SSDEEP:6144:ZG4s3EO9I2eUP3dReW5jfgj0XmSmuCDjyAd3JOg/CD:ZEHljgM
    MD5:4B9A0A002A45B1046F5073DDBE1FC30F
    SHA1:54BD1E66F77C68CE2D3BD7A92F156F2BB37A0829
    SHA-256:04A4A5AF462AF06839DC44D2BC9EE208247E45EA7479DEDE07EE9AD6FBB048FC
    SHA-512:4F3A2A7B0FFAC1946FF7B4DF4E86A7B98C1FC9F60E3565E2DACE92F7E94C0A508E2C1B4C9985E38FEE36E29B32D7202FD307128111C10E567F3E25F80C691D0F
    Malicious:false
    Reputation:low
    Preview:Microsoft C/C++ MSF 7.00...DS...........Q...........P...................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
    Category:dropped
    Size (bytes):23560
    Entropy (8bit):6.709114063357369
    Encrypted:false
    SSDEEP:384:NcnkfqNNOLMLEk2T9hcWqsCi7jiZSf+VIYinvyONdPxh8E9VF0NyGISS:pQoLS2Hdq07d/YinrXPxWEwj
    MD5:938A2829B92A11911F6255D98516BC57
    SHA1:A5E942F9518F7DE9B40AD536F2CC830C73AB7A79
    SHA-256:CF91D0C4EDACC75E62461A506D333DE2B2B800410D05F5B3E4AB76859E15CA70
    SHA-512:7DE4E061A3D634359EF3D945A6C17A27F277202916DA446B6786A9CCDB23D78A6E135A32E0F4EA81EAC64370F43A2B609F678E4FB613D636BC0AC33ACDFB4088
    Malicious:false
    Antivirus:
    • Antivirus: ReversingLabs, Detection: 0%
    Reputation:low
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......v...2o.2o.2o..,.0o.2o..o.t>:.1o.t>8.3o.t>..9o.t>..0o....0o..;.3o.?=<.3o..9.3o.Rich2o.........................PE..d...`..d.........." ................t................................................r....`..........................................7..o... 8..<....`.......P..P....,...0...p......P1..8............................4..p............0...............................text............................... ..`.rdata.......0......................@..@.data........@......."..............@....pdata..P....P.......$..............@..@.rsrc........`.......&..............@..@.reloc.......p.......*..............@..B................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Zip archive data, at least v2.0 to extract, compression method=deflate
    Category:dropped
    Size (bytes):11217
    Entropy (8bit):7.9475942625930776
    Encrypted:false
    SSDEEP:192:tqGQQSW1tFdvMAxJiWG91Yo12jbpf9sNJosX31osw5fcL1nI/IGcGCCRCFX:EGJV1NxJnG9nydBUpGRqX
    MD5:82C6EDDAEE8971A519320887058FA84E
    SHA1:AA2364121E931E6A9A743BE776B550EF3CCF3033
    SHA-256:49DA45DF97332491D6A8E113352FAE3A69F82B4D20FE83E0AD76956BB6A4CD77
    SHA-512:E35FC870DE2EB0CF4CCE1BF533B1ABDB7E8AF38A97A2FB2017A52330B2BEFD1F1287E828AA02F5F497D2BD8EF03122055863E8AD01ED24C43497C6A355CF7283
    Malicious:false
    Reputation:low
    Preview:PK...........V"..'....-'......compiledMethodLoad.cUT...%..d%..dux..............Z[s.H.~..8.V\.....$.2...XI...d.1..I...3....t..$;.J...w.V.m...0..../S.=..........;......a.<M.Y,...%..>.}..,a.y.G.&.x...n..0 .X'.x.I..]..w<p.GX..*Q...K@*...SBY.._p.!....A...OS.A.....t...C....xp.n.x.6%.B.V,=.X.8j..@...rC.W...EJ....pCS..$.@...e......H8%m!c.1...._....n.jE597(..F..G...5..Bw.bA...#..qA.+.~..?)m lG.UA."N..{iM..1.9W......f9.......>..#?B)B`....\..X.).."tG..Do.a.8/......".2H"..^N...w....".}.[`....jj...q...!.....czk.W6\...fZ.N.8:.M.|f.8.Q-....S'...255....}<...Lub..>..fC}r..b..a..u..."..Zv.q.c..\.O.\.... y..."w..T.....f#.$......$.P..#U.k.c@&.0h.....J.....7..D.D...{.!...H..P.nj...*..P...H.k..t.B@./.J......a-.?3\..0T..%..}Y=h......;...[.n.l...c(.ni.>.3........$b.J&....p..?.Y..>.5.Mm....7.!.T..C.lc"dFe..-....C.C..+..LR..J.P{....I.2..3..G..6.h.. ....zh=...$T"~."...........a]./@.^........3....\e..x{p.V....2..Jr.X.I,..!B}.8.".8p.q...9.:....s.....Ub.$....c>.
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:ASCII text
    Category:dropped
    Size (bytes):2407
    Entropy (8bit):5.195593565746548
    Encrypted:false
    SSDEEP:48:RyOlrYJErYJFHvv432sDt32sWEtPu3tOHsOGfwoNATIBOAaJi:RPlrYJErYJFPQ3vt3S34edNAcw9i
    MD5:CE11C05D0C4A8472F095A6FC6A6128CC
    SHA1:E58984E951E53FE028CAB7CEDDFC05CBF7485B9D
    SHA-256:489C7D6DBCB32AB492A826651D9192B58C9F6546CDA8CFD5C5408AC6D051B5E1
    SHA-512:62C678D289F36AA4ACE33E1750305A4243CC38A0CB877641D82DE9831F07E231E03281F7FDE0C4EABDD4B2F3A1AA0E3F13F15D77E5C7926714F6E2564F2854FD
    Malicious:false
    Reputation:low
    Preview:#.# Copyright (c) 2004, 2007, Oracle and/or its affiliates. All rights reserved..#.# Redistribution and use in source and binary forms, with or without.# modification, are permitted provided that the following conditions.# are met:.#.# - Redistributions of source code must retain the above copyright.# notice, this list of conditions and the following disclaimer..#.# - Redistributions in binary form must reproduce the above copyright.# notice, this list of conditions and the following disclaimer in the.# documentation and/or other materials provided with the distribution..#.# - Neither the name of Oracle nor the names of its.# contributors may be used to endorse or promote products derived.# from this software without specific prior written permission..#.# THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS.# IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,.# THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:ASCII text
    Category:dropped
    Size (bytes):2407
    Entropy (8bit):5.195593565746548
    Encrypted:false
    SSDEEP:48:RyOlrYJErYJFHvv432sDt32sWEtPu3tOHsOGfwoNATIBOAaJi:RPlrYJErYJFPQ3vt3S34edNAcw9i
    MD5:CE11C05D0C4A8472F095A6FC6A6128CC
    SHA1:E58984E951E53FE028CAB7CEDDFC05CBF7485B9D
    SHA-256:489C7D6DBCB32AB492A826651D9192B58C9F6546CDA8CFD5C5408AC6D051B5E1
    SHA-512:62C678D289F36AA4ACE33E1750305A4243CC38A0CB877641D82DE9831F07E231E03281F7FDE0C4EABDD4B2F3A1AA0E3F13F15D77E5C7926714F6E2564F2854FD
    Malicious:false
    Reputation:low
    Preview:#.# Copyright (c) 2004, 2007, Oracle and/or its affiliates. All rights reserved..#.# Redistribution and use in source and binary forms, with or without.# modification, are permitted provided that the following conditions.# are met:.#.# - Redistributions of source code must retain the above copyright.# notice, this list of conditions and the following disclaimer..#.# - Redistributions in binary form must reproduce the above copyright.# notice, this list of conditions and the following disclaimer in the.# documentation and/or other materials provided with the distribution..#.# - Neither the name of Oracle nor the names of its.# contributors may be used to endorse or promote products derived.# from this software without specific prior written permission..#.# THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS.# IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,.# THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Zip archive data, at least v2.0 to extract, compression method=deflate
    Category:dropped
    Size (bytes):10897
    Entropy (8bit):7.947329804088253
    Encrypted:false
    SSDEEP:192:jWw1AMrMBHU66l1wB1Qfe+MsuvYCt1LxZzlgqNy31osw5fcL1nI/IGcGCCV:jf5rctesQfjMsuvYK1LPz6qjBUpGV
    MD5:CF012133B059F57FD831D65E5612176D
    SHA1:784EDC1E7087879D5E9C541B6CE5E211F4B3B779
    SHA-256:5E7C957C2776A9BE281BB16D20F2635E1C5D97E7AFB73CCF6B99E3BAB56FE25B
    SHA-512:55F80F7A92031EC67C37ED3F1D1E34D285348FBF12FE2276151B3354DBC0AA01B1F3C888A712AF7A7902A57367C098AEBB4267099BD4419FE01C8CE9A9CE115A
    Malicious:false
    Reputation:low
    Preview:PK...........V1..g...........gctest.cUT...%..d%..dux..............X]o...}.....K.I.....D.L%R....( P..Z.".......=.KJ.b.q..T....9sv...GtL.l...EI.C.y.....}.. 7..DP..YN.,(..e".R.]2...\A.(D..q..X.'bY....K..... .R...H...L....Y.,.z..`....%kYf...(d........,EL.<.....",..$..dzGQ......rKQ.VA#:9.WP6.qEY...Ke...9.e..T....Y)#a`.,(.B...|....Q....A...jj4p8^.....i_kUq..."-...8.2l.i...e...3Pg...4]t.T..'....U..f.eu......kuY^..#......H.1V...p,.R...... ..V3.wMJ......*.X..c..../..Ju..E.....w/.....c...V..n...;....U@W.oy>.N..N......B..Y...7.%...|.\...xhC..x...o.........r......-p...zB..K.Y^....=..[e....6w.{&.M/.{........E._..{C..Y......um9..W.px.{.X.<P............n...^.~.z`.(...c.g..Y.-xez..s...................z...1vp.O....&.E...+.}..{..FC.W.M|...4*....a.._L|[qh;..y.q`.N..~....t_..:.g..z.....u...\Y..1..5....^/hn.I..4.e=.5.....Y..eE7.oupz6..X+..1ay.|.C.6.h.H...P.K.%..k..W....]...wU..yqztt..C....Fq@..$A..Q8T....N....).EX.sU|...h...k.%.a...X$r&XI.H.\..$.Z....paBE
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
    Category:dropped
    Size (bytes):23008
    Entropy (8bit):6.610230395712639
    Encrypted:false
    SSDEEP:384:g3BtXrGx3zsnUITqsvvVBZSf+VIYinvynzPxh8E9VF0NyBInno:oL77q8vVQ/YinCzPxWETz
    MD5:EC68FAAA95FAF1E19FE6C457E762135D
    SHA1:19E563ED49845515CCF84873CE093E90B20F8ADE
    SHA-256:54246AD3AC88CD6B697CE02CC6DEAE588710EB6F43419D07A3D63E617D3563F5
    SHA-512:5FAEE29FBBCA0F6DC135FB8A80098CDDD350D4C2F43169B46B3BB1F0670E76C2E716923AF5F21FD4A7CC107E210369A7A5A96CD1C20B77D3A7DD325571A49B49
    Malicious:false
    Antivirus:
    • Antivirus: ReversingLabs, Detection: 0%
    Reputation:low
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......v...2og.2og.2og...0og.2of..og.t>..1og.t>..3og.t>..9og.t>..0og...0og...3og.?=..3og...3og.Rich2og.........................PE..d...`..d.........." ................t........................................p.......}....`..........................................&..c....&..<....P.......@..P....*.../...`......@!..8............................$..p............ ...............................text............................... ..`.rdata..p.... ......................@..@.data........0....... ..............@....pdata..P....@......."..............@..@.rsrc........P.......$..............@..@.reloc.......`.......(..............@..B................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Intel amd64 COFF object file, not stripped, 2 sections, symbol offset=0x2a5, 10 symbols, created Fri Jul 14 19:39:12 2023, 1st section name ".edata"
    Category:dropped
    Size (bytes):889
    Entropy (8bit):4.546791057358621
    Encrypted:false
    SSDEEP:24:gZ5aFT4Na2cmeKPb0d7qymxHxu3g41Jx9V:xFT4BcmeKj0d7qtHxuQ41Jxv
    MD5:7B699A9B823B0134F3FABF1C4CA6F9C9
    SHA1:81602793BBCC64EF2A914E3CFB13B5219C23729B
    SHA-256:40A03AD5A1EA666F3C8ED780D308B6C65945A6A0822FDFC3CFE3DC5B663F51BE
    SHA-512:71A2FECA85DBE7178A12DFB83FF905BC479998ABB95FD0862AA7CC3E09C6A85E7DA31C4BB6E30D3D10EC700B6E32B62B2314604AD79DCDDDF577E4AA2790C3A3
    Malicious:false
    Reputation:low
    Preview:d...`..d.............edata..........c...d...............@..@.debug$S............................@..B....`..d....................................................gctest.dll.Agent_OnLoad.Agent_OnUnload...................... .........$.........(.........0.........,.........4.............................c:/wsjdk/Corretto8Src/installers/windows/zip/corretto-build/buildRoot/build/windows-x86_64-normal-server-release/jdk/demoobjs/jvmti/gctest/gctest.exp.+.<.......................Microsoft (R) LINK...=..cwd.C:\wsjdk\Corretto8Src\installers\windows\zip\corretto-build\buildRoot\jdk\make.exe.c:\progra~2\micros~3.0\vc\bin\amd64\link.exe....8.....Agent_OnLoad...8.....Agent_OnUnload.@comp.id...........edata............szName..<.........rgpv....(.........rgszName0.........rgwOrd..8.........$N00001.G.........$N00002.T............................................. ...Agent_OnLoad.Agent_OnUnload.
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:current ar archive
    Category:dropped
    Size (bytes):1904
    Entropy (8bit):4.651558482679126
    Encrypted:false
    SSDEEP:24:swmUJlX0WO72J96/cLcPsnvKZsryAOGJ3/cEm0K//yk/cxBzKPY/cEs/cWt:swmzWO7UnvKuyAO0K0KL2BzKAkpt
    MD5:46FCEA359C347CAE147628CF6F2383B4
    SHA1:467AC06C406FE06BF9E448516F8801442C14D711
    SHA-256:3B8958BAB59FC70A2BE8BB31833CA27A37D30241CE5F105D9DFFB615DCA6B954
    SHA-512:F20F95B375846F2A39266802A30FD25E9F2029CFACF0097A8DC015220DA59AC91F2BD39873EEAAACF6D2E1BBE01BEB30F7967DD2F757A42DDBEA333D427B093A
    Malicious:false
    Reputation:low
    Preview:!<arch>./ 1689363552 0 176 `................F................__IMPORT_DESCRIPTOR_gctest.__NULL_IMPORT_DESCRIPTOR..gctest_NULL_THUNK_DATA.Agent_OnLoad.__imp_Agent_OnLoad.Agent_OnUnload.__imp_Agent_OnUnload./ 1689363552 0 186 `.............F.............................Agent_OnLoad.Agent_OnUnload.__IMPORT_DESCRIPTOR_gctest.__NULL_IMPORT_DESCRIPTOR.__imp_Agent_OnLoad.__imp_Agent_OnUnload..gctest_NULL_THUNK_DATA.gctest.dll/ 1689363552 0 490 `.d...`..d.............debug$S........@...................@..B.idata$2............................@.0..idata$6............................@. ..............gctest.dll'......................Microsoft (R) LINK..................................................gctest.dll..@comp.id.............................idata$2@.......h..idata$6...........idata$4@.......h..idata$5@.......h.......................8.............P...__IMPORT_DESCRIPTOR_gctest.__NULL_IM
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:MSVC program database ver 7.00, 4096*81 bytes
    Category:dropped
    Size (bytes):331776
    Entropy (8bit):4.519053688505432
    Encrypted:false
    SSDEEP:6144:K6k4qWNW2s2sg8EBpn2OsmJmdCZOGEBlCDEf:azmwSEf
    MD5:405392F99DDCF95425CD43242D06F1A5
    SHA1:A3E7C1E4C0C43D8013929D569678D4CD20F09FA1
    SHA-256:1842DCDCE8A4B89FBE8288B57596B2A5A2933F947C9656D9CFFAF1ECE5FE86CA
    SHA-512:3F19EC9358AB835A9F777C5591F02197467207EB817C2757F670D38B446CD18B41E9BFB525FD0C2D9E45708FE996C3A1ABC2DA6B592D20E48BD2C1A8965850B6
    Malicious:false
    Reputation:low
    Preview:Microsoft C/C++ MSF 7.00...DS...........Q...........P...................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
    Category:dropped
    Size (bytes):23008
    Entropy (8bit):6.610230395712639
    Encrypted:false
    SSDEEP:384:g3BtXrGx3zsnUITqsvvVBZSf+VIYinvynzPxh8E9VF0NyBInno:oL77q8vVQ/YinCzPxWETz
    MD5:EC68FAAA95FAF1E19FE6C457E762135D
    SHA1:19E563ED49845515CCF84873CE093E90B20F8ADE
    SHA-256:54246AD3AC88CD6B697CE02CC6DEAE588710EB6F43419D07A3D63E617D3563F5
    SHA-512:5FAEE29FBBCA0F6DC135FB8A80098CDDD350D4C2F43169B46B3BB1F0670E76C2E716923AF5F21FD4A7CC107E210369A7A5A96CD1C20B77D3A7DD325571A49B49
    Malicious:false
    Antivirus:
    • Antivirus: ReversingLabs, Detection: 0%
    Reputation:low
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......v...2og.2og.2og...0og.2of..og.t>..1og.t>..3og.t>..9og.t>..0og...0og...3og.?=..3og...3og.Rich2og.........................PE..d...`..d.........." ................t........................................p.......}....`..........................................&..c....&..<....P.......@..P....*.../...`......@!..8............................$..p............ ...............................text............................... ..`.rdata..p.... ......................@..@.data........0....... ..............@....pdata..P....@......."..............@..@.rsrc........P.......$..............@..@.reloc.......`.......(..............@..B................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:current ar archive
    Category:dropped
    Size (bytes):1904
    Entropy (8bit):4.651558482679126
    Encrypted:false
    SSDEEP:24:swmUJlX0WO72J96/cLcPsnvKZsryAOGJ3/cEm0K//yk/cxBzKPY/cEs/cWt:swmzWO7UnvKuyAO0K0KL2BzKAkpt
    MD5:46FCEA359C347CAE147628CF6F2383B4
    SHA1:467AC06C406FE06BF9E448516F8801442C14D711
    SHA-256:3B8958BAB59FC70A2BE8BB31833CA27A37D30241CE5F105D9DFFB615DCA6B954
    SHA-512:F20F95B375846F2A39266802A30FD25E9F2029CFACF0097A8DC015220DA59AC91F2BD39873EEAAACF6D2E1BBE01BEB30F7967DD2F757A42DDBEA333D427B093A
    Malicious:false
    Reputation:low
    Preview:!<arch>./ 1689363552 0 176 `................F................__IMPORT_DESCRIPTOR_gctest.__NULL_IMPORT_DESCRIPTOR..gctest_NULL_THUNK_DATA.Agent_OnLoad.__imp_Agent_OnLoad.Agent_OnUnload.__imp_Agent_OnUnload./ 1689363552 0 186 `.............F.............................Agent_OnLoad.Agent_OnUnload.__IMPORT_DESCRIPTOR_gctest.__NULL_IMPORT_DESCRIPTOR.__imp_Agent_OnLoad.__imp_Agent_OnUnload..gctest_NULL_THUNK_DATA.gctest.dll/ 1689363552 0 490 `.d...`..d.............debug$S........@...................@..B.idata$2............................@.0..idata$6............................@. ..............gctest.dll'......................Microsoft (R) LINK..................................................gctest.dll..@comp.id.............................idata$2@.......h..idata$6...........idata$4@.......h..idata$5@.......h.......................8.............P...__IMPORT_DESCRIPTOR_gctest.__NULL_IM
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Intel amd64 COFF object file, not stripped, 2 sections, symbol offset=0x2a5, 10 symbols, created Fri Jul 14 19:39:12 2023, 1st section name ".edata"
    Category:dropped
    Size (bytes):889
    Entropy (8bit):4.546791057358621
    Encrypted:false
    SSDEEP:24:gZ5aFT4Na2cmeKPb0d7qymxHxu3g41Jx9V:xFT4BcmeKj0d7qtHxuQ41Jxv
    MD5:7B699A9B823B0134F3FABF1C4CA6F9C9
    SHA1:81602793BBCC64EF2A914E3CFB13B5219C23729B
    SHA-256:40A03AD5A1EA666F3C8ED780D308B6C65945A6A0822FDFC3CFE3DC5B663F51BE
    SHA-512:71A2FECA85DBE7178A12DFB83FF905BC479998ABB95FD0862AA7CC3E09C6A85E7DA31C4BB6E30D3D10EC700B6E32B62B2314604AD79DCDDDF577E4AA2790C3A3
    Malicious:false
    Reputation:low
    Preview:d...`..d.............edata..........c...d...............@..@.debug$S............................@..B....`..d....................................................gctest.dll.Agent_OnLoad.Agent_OnUnload...................... .........$.........(.........0.........,.........4.............................c:/wsjdk/Corretto8Src/installers/windows/zip/corretto-build/buildRoot/build/windows-x86_64-normal-server-release/jdk/demoobjs/jvmti/gctest/gctest.exp.+.<.......................Microsoft (R) LINK...=..cwd.C:\wsjdk\Corretto8Src\installers\windows\zip\corretto-build\buildRoot\jdk\make.exe.c:\progra~2\micros~3.0\vc\bin\amd64\link.exe....8.....Agent_OnLoad...8.....Agent_OnUnload.@comp.id...........edata............szName..<.........rgpv....(.........rgszName0.........rgwOrd..8.........$N00001.G.........$N00002.T............................................. ...Agent_OnLoad.Agent_OnUnload.
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:MSVC program database ver 7.00, 4096*81 bytes
    Category:dropped
    Size (bytes):331776
    Entropy (8bit):4.519053688505432
    Encrypted:false
    SSDEEP:6144:K6k4qWNW2s2sg8EBpn2OsmJmdCZOGEBlCDEf:azmwSEf
    MD5:405392F99DDCF95425CD43242D06F1A5
    SHA1:A3E7C1E4C0C43D8013929D569678D4CD20F09FA1
    SHA-256:1842DCDCE8A4B89FBE8288B57596B2A5A2933F947C9656D9CFFAF1ECE5FE86CA
    SHA-512:3F19EC9358AB835A9F777C5591F02197467207EB817C2757F670D38B446CD18B41E9BFB525FD0C2D9E45708FE996C3A1ABC2DA6B592D20E48BD2C1A8965850B6
    Malicious:false
    Reputation:low
    Preview:Microsoft C/C++ MSF 7.00...DS...........Q...........P...................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Zip archive data, at least v2.0 to extract, compression method=deflate
    Category:dropped
    Size (bytes):10897
    Entropy (8bit):7.947329804088253
    Encrypted:false
    SSDEEP:192:jWw1AMrMBHU66l1wB1Qfe+MsuvYCt1LxZzlgqNy31osw5fcL1nI/IGcGCCV:jf5rctesQfjMsuvYK1LPz6qjBUpGV
    MD5:CF012133B059F57FD831D65E5612176D
    SHA1:784EDC1E7087879D5E9C541B6CE5E211F4B3B779
    SHA-256:5E7C957C2776A9BE281BB16D20F2635E1C5D97E7AFB73CCF6B99E3BAB56FE25B
    SHA-512:55F80F7A92031EC67C37ED3F1D1E34D285348FBF12FE2276151B3354DBC0AA01B1F3C888A712AF7A7902A57367C098AEBB4267099BD4419FE01C8CE9A9CE115A
    Malicious:false
    Reputation:low
    Preview:PK...........V1..g...........gctest.cUT...%..d%..dux..............X]o...}.....K.I.....D.L%R....( P..Z.".......=.KJ.b.q..T....9sv...GtL.l...EI.C.y.....}.. 7..DP..YN.,(..e".R.]2...\A.(D..q..X.'bY....K..... .R...H...L....Y.,.z..`....%kYf...(d........,EL.<.....",..$..dzGQ......rKQ.VA#:9.WP6.qEY...Ke...9.e..T....Y)#a`.,(.B...|....Q....A...jj4p8^.....i_kUq..."-...8.2l.i...e...3Pg...4]t.T..'....U..f.eu......kuY^..#......H.1V...p,.R...... ..V3.wMJ......*.X..c..../..Ju..E.....w/.....c...V..n...;....U@W.oy>.N..N......B..Y...7.%...|.\...xhC..x...o.........r......-p...zB..K.Y^....=..[e....6w.{&.M/.{........E._..{C..Y......um9..W.px.{.X.<P............n...^.~.z`.(...c.g..Y.-xez..s...................z...1vp.O....&.E...+.}..{..FC.W.M|...4*....a.._L|[qh;..y.q`.N..~....t_..:.g..z.....u...\Y..1..5....^/hn.I..4.e=.5.....Y..eE7.oupz6..X+..1ay.|.C.6.h.H...P.K.%..k..W....]...wU..yqztt..C....Fq@..$A..Q8T....N....).EX.sU|...h...k.%.a...X$r&XI.H.\..$.Z....paBE
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:ASCII text
    Category:dropped
    Size (bytes):1997
    Entropy (8bit):5.185413177957239
    Encrypted:false
    SSDEEP:48:RyOlrYJErYJFHvv432sDt32sWEtPu3tOHIVdMFf6GfwVGNC:RPlrYJErYJFPQ3vt3S34wMFfbikC
    MD5:5D0B04C594D8F41FD605F8F33A2FEC20
    SHA1:A82F60E4CB3A601BE38EF22D74AE5EBEA44174C0
    SHA-256:65411FD6D1CDE0D3D985D9A1AAA81C5AA053D33A24A7E57083D288B9FA8496E2
    SHA-512:29B0CD11320D960CABE39422D539208EE4449E002CB8537A1707EF728DAD8F12C92BD1C98ADE0F5BB3D7DB0DBA22D2D37DDC21EE1C7417652CF444D6326FF3A3
    Malicious:false
    Reputation:low
    Preview:#.# Copyright (c) 2004, 2007, Oracle and/or its affiliates. All rights reserved..#.# Redistribution and use in source and binary forms, with or without.# modification, are permitted provided that the following conditions.# are met:.#.# - Redistributions of source code must retain the above copyright.# notice, this list of conditions and the following disclaimer..#.# - Redistributions in binary form must reproduce the above copyright.# notice, this list of conditions and the following disclaimer in the.# documentation and/or other materials provided with the distribution..#.# - Neither the name of Oracle nor the names of its.# contributors may be used to endorse or promote products derived.# from this software without specific prior written permission..#.# THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS.# IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,.# THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java archive data (JAR)
    Category:dropped
    Size (bytes):15126
    Entropy (8bit):7.940645249018299
    Encrypted:false
    SSDEEP:384:yQME7X5s3vsI+pF0dWcxv6u3kiGCPtRn5l8ewcAV:yQMuXID+pCFv6uUPCFRTU
    MD5:543518A993112054331442EA4B5E753E
    SHA1:6336256E6BA1F22F261256DB20587B10073D1A67
    SHA-256:0B33B9DDE5861C0FBD06B00B2073D88193C5E9DF685A3E8DB124BF19ED6DBDDA
    SHA-512:EFB5411F4EC7CFF40FB951A70D14A760A8935BDE95EA2EC9FF46512C8B709CBB11FA5DC2C64849F44FE3381058712BD0A2A904CBADC0FB683F27138F00E3BA80
    Malicious:false
    Reputation:low
    Preview:PK..........V................META-INF/......PK..............PK..........V................META-INF/MANIFEST.MFm.=..0...=..p..-...nZ.*.........R.X._..~..=..^....B.%.i.9..D...,q.p.F......au.-..{.._.....d7.R).-).h...w>..Ge...[.o.o.~.6...-L..>.o.....'...f.g.I.....X9.%.x..{./(E....`.. ..gPK........G...PK...........V................heapTracker.c.=ks.8...+.m%..Y...s{q.9Y.m..W..Ie]*J.l...!);.....@.$(...^..q.2..4..F...^..]......}...&^.z.C.....~.L.p..e..?..3..s.I..!..z.....<......s.8...*.....U..?.q....RL.....,..q]....V...*A(...g..A.u.D.Xz..O....(..].#.q....8.yx...b.....b....^.F.&.^..X.3..4t..*N.K..."dg...'I&."D.&..C.?.s..p....&b..t.../j...Z.H.....+..wBHp_.(7...^.8j...B(....~.;.8...;..wD.b.........I....5......pgpa.C..b.!.A/B......e..E.x.I...........3Q.p..#CH....".A]../B.....X...3.....Cs.......s.>.G..c[........8.w...h...mo4..]....."..B.......=...@t./........Q.=..N..<..N..`.^.$........u.m.).'.=h....Q...}.&O:..6w..5.Es0.....B...\.m..;..[.f.}....4,......5..\...z..
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:ASCII text
    Category:dropped
    Size (bytes):1997
    Entropy (8bit):5.185413177957239
    Encrypted:false
    SSDEEP:48:RyOlrYJErYJFHvv432sDt32sWEtPu3tOHIVdMFf6GfwVGNC:RPlrYJErYJFPQ3vt3S34wMFfbikC
    MD5:5D0B04C594D8F41FD605F8F33A2FEC20
    SHA1:A82F60E4CB3A601BE38EF22D74AE5EBEA44174C0
    SHA-256:65411FD6D1CDE0D3D985D9A1AAA81C5AA053D33A24A7E57083D288B9FA8496E2
    SHA-512:29B0CD11320D960CABE39422D539208EE4449E002CB8537A1707EF728DAD8F12C92BD1C98ADE0F5BB3D7DB0DBA22D2D37DDC21EE1C7417652CF444D6326FF3A3
    Malicious:false
    Reputation:low
    Preview:#.# Copyright (c) 2004, 2007, Oracle and/or its affiliates. All rights reserved..#.# Redistribution and use in source and binary forms, with or without.# modification, are permitted provided that the following conditions.# are met:.#.# - Redistributions of source code must retain the above copyright.# notice, this list of conditions and the following disclaimer..#.# - Redistributions in binary form must reproduce the above copyright.# notice, this list of conditions and the following disclaimer in the.# documentation and/or other materials provided with the distribution..#.# - Neither the name of Oracle nor the names of its.# contributors may be used to endorse or promote products derived.# from this software without specific prior written permission..#.# THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS.# IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,.# THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java archive data (JAR)
    Category:dropped
    Size (bytes):15126
    Entropy (8bit):7.940645249018299
    Encrypted:false
    SSDEEP:384:yQME7X5s3vsI+pF0dWcxv6u3kiGCPtRn5l8ewcAV:yQMuXID+pCFv6uUPCFRTU
    MD5:543518A993112054331442EA4B5E753E
    SHA1:6336256E6BA1F22F261256DB20587B10073D1A67
    SHA-256:0B33B9DDE5861C0FBD06B00B2073D88193C5E9DF685A3E8DB124BF19ED6DBDDA
    SHA-512:EFB5411F4EC7CFF40FB951A70D14A760A8935BDE95EA2EC9FF46512C8B709CBB11FA5DC2C64849F44FE3381058712BD0A2A904CBADC0FB683F27138F00E3BA80
    Malicious:false
    Reputation:low
    Preview:PK..........V................META-INF/......PK..............PK..........V................META-INF/MANIFEST.MFm.=..0...=..p..-...nZ.*.........R.X._..~..=..^....B.%.i.9..D...,q.p.F......au.-..{.._.....d7.R).-).h...w>..Ge...[.o.o.~.6...-L..>.o.....'...f.g.I.....X9.%.x..{./(E....`.. ..gPK........G...PK...........V................heapTracker.c.=ks.8...+.m%..Y...s{q.9Y.m..W..Ie]*J.l...!);.....@.$(...^..q.2..4..F...^..]......}...&^.z.C.....~.L.p..e..?..3..s.I..!..z.....<......s.8...*.....U..?.q....RL.....,..q]....V...*A(...g..A.u.D.Xz..O....(..].#.q....8.yx...b.....b....^.F.&.^..X.3..4t..*N.K..."dg...'I&."D.&..C.?.s..p....&b..t.../j...Z.H.....+..wBHp_.(7...^.8j...B(....~.;.8...;..wD.b.........I....5......pgpa.C..b.!.A/B......e..E.x.I...........3Q.p..#CH....".A]../B.....X...3.....Cs.......s.>.G..c[........8.w...h...mo4..]....."..B.......=...@t./........Q.=..N..<..N..`.^.$........u.m.).'.=h....Q...}.&O:..6w..5.Es0.....B...\.m..;..[.f.}....4,......5..\...z..
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Zip archive data, at least v2.0 to extract, compression method=deflate
    Category:dropped
    Size (bytes):38886
    Entropy (8bit):7.984556538916662
    Encrypted:false
    SSDEEP:768:rkDRYfn9Bm1FR5TlBUpGPyLXoIOdRUBCLll3ZYdQ3ul+yPw0:r/kdTlOpGPMXojRhEjw0
    MD5:EB48CF01B1F6753B624054FE6E0BBDDF
    SHA1:A8C5376E30835D753FCB58972B09897ED75BFA8E
    SHA-256:D552911526BB43ACE7608E887D6AD9F0DC92E46BA9CC52E07ED745A3685AD860
    SHA-512:34EE2DDB9CC35368A0474F079735F0AB40B822A322027E3466B1CE8F0B7D066874F50A16821A17C056EDA2248B581E83FC0100293F3528032F499E103CACB847
    Malicious:false
    Reputation:low
    Preview:PK...........V...]J$..........heapTracker.cUT...%..d%..dux..............<kW.H.......m.A...;.Bv.-@=.fl.tN..#K2V.%.$C.}..{.UR.a.......`.....~..%vE'Z>...<.M.%...........x....Q,.4..l....z.h...q.....<w..!...I...U.G!.....~(.h.;.RL....,...!..t.....V)BYD.?...a..=.....+.qt..!..)...N.D.~x#.(t}.. ......4!.J.%".)....$..R..E..4..WRL.E.0J}.3......"..7.X$..:../.x..5.U.....vW@.D.`^.(7rV./Lm5....t...f?.. ....!..,.=..b..^xH.T.0.i&@...@;.....>...z.\D..]h.Pe..E.z.E...........P.h..BH-...sP.`.....v..gI.q1>.Fb48..l.M../...V..O......uv>..^...D....xh.\....h...5j.v..0.........uq... ...c.....wzW]..f..!....Y........e...Sqa.;..}b...'Byj.......e{8.:W...!]^./.#S .]k...../..@,..f.,F..^....c.....Kt~OL..}.3.....fg.|.: E..g......2.1.......#..W...n..}.L6....R.jh^ . ....hl...8...$..9.`u....F$...i..q.\......'W#.dh...pxu9....L.G..P..]...O<....O..!.<h:....WC./I......:c....a.5f.N.<.Ygf.cb....h.......!TD......w.4..?Z..J...]a..v........#K....s...v.zk.5...V.A}.9...A.N,..A..J..r..
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
    Category:dropped
    Size (bytes):44728
    Entropy (8bit):6.698236404876538
    Encrypted:false
    SSDEEP:768:eKsS55V2LglfqjJoBn4DYw/Xri5SwDRh5T5kQASUUnNKr5Rr/YinKaPxWETzI:L20yVs9th5T5kQASxNir/7FPxlI
    MD5:9FF5841F05175774EE7E9E60B5DA83B2
    SHA1:C5DB961651C2213CF625FB79D42C328BC01D4D8D
    SHA-256:226F4CB60D03F320C5B412005CAB200DD36187965F46A295DDA2E2980AB96535
    SHA-512:5FD7BDC3F8543C063C0A9DE742FBC096FC9CF726E35FA19C30BD27EF52C361610447881878A3C9DFE11905F60E84CD1891349EF8736EB442D27EA4F6DFFBE2FD
    Malicious:false
    Antivirus:
    • Antivirus: ReversingLabs, Detection: 0%
    Reputation:low
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.....................2|....@mp............j......h......W......V....kSW....kSk.....l....kSi....Rich...................PE..d...`..d.........." .....T...........\.......................................P............`.................................................T...<....0....... .......~...0...@..4....q..8............................}..p............p...............................text...;S.......T.................. ..`.rdata..F....p.......X..............@..@.data................r..............@....pdata....... .......t..............@..@.rsrc........0.......x..............@..@.reloc..4....@.......|..............@..B................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Intel amd64 COFF object file, not stripped, 2 sections, symbol offset=0x34b, 14 symbols, created Fri Jul 14 19:39:12 2023, 1st section name ".edata"
    Category:dropped
    Size (bytes):1165
    Entropy (8bit):4.528541986767785
    Encrypted:false
    SSDEEP:24:gVlZmqgVe+uMv4Na2feKPb0d7qydaBErxxrxu3oI1uenTUZ1gI:i4oMv4BfeKj0d7qyayrxuYI1uoTUZL
    MD5:104E3B1A2FE77FCEC373AF4472384EA5
    SHA1:7146F12EA6A8C0810B3F4B38567181957A863CFE
    SHA-256:C3FE3C5D342314549CD702255FC90068B089EE674D9C1DEFFF3EC5AACFAF2A77
    SHA-512:DB19FBE32202623F41130BC27138264878EB0A5BED13B13B8FC148892E0C236405B1E663E828B46ED160405104B4302A9B0C3A5CAE9AD5724D3BD07C6906A605
    Malicious:false
    Reputation:low
    Preview:d...`..dK............edata..............d...............@..@.debug$S............~...............@..B....`..d........................................................................heapTracker.dll.Agent_OnLoad.Agent_OnUnload.java_crw_demo.java_crw_demo_classname..................... .........$.........(.........8.........,.........<.........0.........@.........4.........D.............................c:/wsjdk/Corretto8Src/installers/windows/zip/corretto-build/buildRoot/build/windows-x86_64-normal-server-release/jdk/demoobjs/jvmti/heapTracker/heapTracker.exp.+.<.......................Microsoft (R) LINK...=..cwd.C:\wsjdk\Corretto8Src\installers\windows\zip\corretto-build\buildRoot\jdk\make.exe.c:\progra~2\micros~3.0\vc\bin\amd64\link.exe....8.....Agent_OnLoad...8.....Agent_OnUnload...8.....java_crw_demo...8.....java_crw_demo_classname.@comp.id...........edata............szName..P.........rgpv....(.........rgszName8.........rgwOrd..H.........$N00001.`.........$N00002.m.........$N00003.|....
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:current ar archive
    Category:dropped
    Size (bytes):2408
    Entropy (8bit):4.907378506687872
    Encrypted:false
    SSDEEP:48:PDemHGeD/PQKpUyAOGGxeQKzGncYFQKBGlGWGtcGp:MpKrRKCn6KoM1tTp
    MD5:60DD60CEA876145E73BFC0FA41A91013
    SHA1:F28A7A0F28DD07F00D06E8E34230F1310A333EFE
    SHA-256:12E135AA197129A880109D614E4D7898E3DEBF5C2BF7BD7EA95B41075B5E0E35
    SHA-512:200A0B9EDB20182D85F46DBC7E9CBCF9098D8430B288D1231D17B7FB06AE1ADDA6B862689B3795D55E65EE60F6CB484BEB645BB21C67D6BA94F337B598CAC97D
    Malicious:false
    Reputation:low
    Preview:!<arch>./ 1689363552 0 290 `................B................................__IMPORT_DESCRIPTOR_heapTracker.__NULL_IMPORT_DESCRIPTOR..heapTracker_NULL_THUNK_DATA.Agent_OnLoad.__imp_Agent_OnLoad.Agent_OnUnload.__imp_Agent_OnUnload.__imp_java_crw_demo.java_crw_demo.__imp_java_crw_demo_classname.java_crw_demo_classname./ 1689363552 0 300 `.............B.............................................Agent_OnLoad.Agent_OnUnload.__IMPORT_DESCRIPTOR_heapTracker.__NULL_IMPORT_DESCRIPTOR.__imp_Agent_OnLoad.__imp_Agent_OnUnload.__imp_java_crw_demo.__imp_java_crw_demo_classname.java_crw_demo.java_crw_demo_classname..heapTracker_NULL_THUNK_DATA.heapTracker.dll/1689363552 0 509 `.d...`..d.............debug$S........E...................@..B.idata$2............................@.0..idata$6............................@. ..............heapTracker.dll'......................Microsoft (R) LINK.............
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:MSVC program database ver 7.00, 4096*95 bytes
    Category:dropped
    Size (bytes):389120
    Entropy (8bit):4.716461005373976
    Encrypted:false
    SSDEEP:6144:wUjsO3m1T0wBczAMe+Zsb2gyjhQsyA6H8uKvmjmlCA9TcsNC9qJ:ldyAT4q
    MD5:42858ED8A62353F3CD8DCB9F4D86F479
    SHA1:0C6555425839D4254D893CF1EEA24FAF25621173
    SHA-256:E97162128EE5D4DE9F2D26D8ACCE904B1F171799C8CCEA87BDBBBA474C838B6F
    SHA-512:6B1026224CAD9310C54E165ADEECFC44211472C642E806FDFB0EFFA7466E2F150A3A3DC714B3364A68E5F91406DB6FD2BB2F7F7D47BBCBDB65D27199D9BEBC63
    Malicious:false
    Reputation:low
    Preview:Microsoft C/C++ MSF 7.00...DS..........._...........^...................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Intel amd64 COFF object file, not stripped, 2 sections, symbol offset=0x34b, 14 symbols, created Fri Jul 14 19:39:12 2023, 1st section name ".edata"
    Category:dropped
    Size (bytes):1165
    Entropy (8bit):4.528541986767785
    Encrypted:false
    SSDEEP:24:gVlZmqgVe+uMv4Na2feKPb0d7qydaBErxxrxu3oI1uenTUZ1gI:i4oMv4BfeKj0d7qyayrxuYI1uoTUZL
    MD5:104E3B1A2FE77FCEC373AF4472384EA5
    SHA1:7146F12EA6A8C0810B3F4B38567181957A863CFE
    SHA-256:C3FE3C5D342314549CD702255FC90068B089EE674D9C1DEFFF3EC5AACFAF2A77
    SHA-512:DB19FBE32202623F41130BC27138264878EB0A5BED13B13B8FC148892E0C236405B1E663E828B46ED160405104B4302A9B0C3A5CAE9AD5724D3BD07C6906A605
    Malicious:false
    Reputation:low
    Preview:d...`..dK............edata..............d...............@..@.debug$S............~...............@..B....`..d........................................................................heapTracker.dll.Agent_OnLoad.Agent_OnUnload.java_crw_demo.java_crw_demo_classname..................... .........$.........(.........8.........,.........<.........0.........@.........4.........D.............................c:/wsjdk/Corretto8Src/installers/windows/zip/corretto-build/buildRoot/build/windows-x86_64-normal-server-release/jdk/demoobjs/jvmti/heapTracker/heapTracker.exp.+.<.......................Microsoft (R) LINK...=..cwd.C:\wsjdk\Corretto8Src\installers\windows\zip\corretto-build\buildRoot\jdk\make.exe.c:\progra~2\micros~3.0\vc\bin\amd64\link.exe....8.....Agent_OnLoad...8.....Agent_OnUnload...8.....java_crw_demo...8.....java_crw_demo_classname.@comp.id...........edata............szName..P.........rgpv....(.........rgszName8.........rgwOrd..H.........$N00001.`.........$N00002.m.........$N00003.|....
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:MSVC program database ver 7.00, 4096*95 bytes
    Category:dropped
    Size (bytes):389120
    Entropy (8bit):4.716461005373976
    Encrypted:false
    SSDEEP:6144:wUjsO3m1T0wBczAMe+Zsb2gyjhQsyA6H8uKvmjmlCA9TcsNC9qJ:ldyAT4q
    MD5:42858ED8A62353F3CD8DCB9F4D86F479
    SHA1:0C6555425839D4254D893CF1EEA24FAF25621173
    SHA-256:E97162128EE5D4DE9F2D26D8ACCE904B1F171799C8CCEA87BDBBBA474C838B6F
    SHA-512:6B1026224CAD9310C54E165ADEECFC44211472C642E806FDFB0EFFA7466E2F150A3A3DC714B3364A68E5F91406DB6FD2BB2F7F7D47BBCBDB65D27199D9BEBC63
    Malicious:false
    Reputation:low
    Preview:Microsoft C/C++ MSF 7.00...DS..........._...........^...................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:current ar archive
    Category:dropped
    Size (bytes):2408
    Entropy (8bit):4.907378506687872
    Encrypted:false
    SSDEEP:48:PDemHGeD/PQKpUyAOGGxeQKzGncYFQKBGlGWGtcGp:MpKrRKCn6KoM1tTp
    MD5:60DD60CEA876145E73BFC0FA41A91013
    SHA1:F28A7A0F28DD07F00D06E8E34230F1310A333EFE
    SHA-256:12E135AA197129A880109D614E4D7898E3DEBF5C2BF7BD7EA95B41075B5E0E35
    SHA-512:200A0B9EDB20182D85F46DBC7E9CBCF9098D8430B288D1231D17B7FB06AE1ADDA6B862689B3795D55E65EE60F6CB484BEB645BB21C67D6BA94F337B598CAC97D
    Malicious:false
    Reputation:low
    Preview:!<arch>./ 1689363552 0 290 `................B................................__IMPORT_DESCRIPTOR_heapTracker.__NULL_IMPORT_DESCRIPTOR..heapTracker_NULL_THUNK_DATA.Agent_OnLoad.__imp_Agent_OnLoad.Agent_OnUnload.__imp_Agent_OnUnload.__imp_java_crw_demo.java_crw_demo.__imp_java_crw_demo_classname.java_crw_demo_classname./ 1689363552 0 300 `.............B.............................................Agent_OnLoad.Agent_OnUnload.__IMPORT_DESCRIPTOR_heapTracker.__NULL_IMPORT_DESCRIPTOR.__imp_Agent_OnLoad.__imp_Agent_OnUnload.__imp_java_crw_demo.__imp_java_crw_demo_classname.java_crw_demo.java_crw_demo_classname..heapTracker_NULL_THUNK_DATA.heapTracker.dll/1689363552 0 509 `.d...`..d.............debug$S........E...................@..B.idata$2............................@.0..idata$6............................@. ..............heapTracker.dll'......................Microsoft (R) LINK.............
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
    Category:dropped
    Size (bytes):44728
    Entropy (8bit):6.698236404876538
    Encrypted:false
    SSDEEP:768:eKsS55V2LglfqjJoBn4DYw/Xri5SwDRh5T5kQASUUnNKr5Rr/YinKaPxWETzI:L20yVs9th5T5kQASxNir/7FPxlI
    MD5:9FF5841F05175774EE7E9E60B5DA83B2
    SHA1:C5DB961651C2213CF625FB79D42C328BC01D4D8D
    SHA-256:226F4CB60D03F320C5B412005CAB200DD36187965F46A295DDA2E2980AB96535
    SHA-512:5FD7BDC3F8543C063C0A9DE742FBC096FC9CF726E35FA19C30BD27EF52C361610447881878A3C9DFE11905F60E84CD1891349EF8736EB442D27EA4F6DFFBE2FD
    Malicious:false
    Antivirus:
    • Antivirus: ReversingLabs, Detection: 0%
    Reputation:low
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.....................2|....@mp............j......h......W......V....kSW....kSk.....l....kSi....Rich...................PE..d...`..d.........." .....T...........\.......................................P............`.................................................T...<....0....... .......~...0...@..4....q..8............................}..p............p...............................text...;S.......T.................. ..`.rdata..F....p.......X..............@..@.data................r..............@....pdata....... .......t..............@..@.rsrc........0.......x..............@..@.reloc..4....@.......|..............@..B................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Zip archive data, at least v2.0 to extract, compression method=deflate
    Category:dropped
    Size (bytes):38886
    Entropy (8bit):7.984556538916662
    Encrypted:false
    SSDEEP:768:rkDRYfn9Bm1FR5TlBUpGPyLXoIOdRUBCLll3ZYdQ3ul+yPw0:r/kdTlOpGPMXojRhEjw0
    MD5:EB48CF01B1F6753B624054FE6E0BBDDF
    SHA1:A8C5376E30835D753FCB58972B09897ED75BFA8E
    SHA-256:D552911526BB43ACE7608E887D6AD9F0DC92E46BA9CC52E07ED745A3685AD860
    SHA-512:34EE2DDB9CC35368A0474F079735F0AB40B822A322027E3466B1CE8F0B7D066874F50A16821A17C056EDA2248B581E83FC0100293F3528032F499E103CACB847
    Malicious:false
    Reputation:low
    Preview:PK...........V...]J$..........heapTracker.cUT...%..d%..dux..............<kW.H.......m.A...;.Bv.-@=.fl.tN..#K2V.%.$C.}..{.UR.a.......`.....~..%vE'Z>...<.M.%...........x....Q,.4..l....z.h...q.....<w..!...I...U.G!.....~(.h.;.RL....,...!..t.....V)BYD.?...a..=.....+.qt..!..)...N.D.~x#.(t}.. ......4!.J.%".)....$..R..E..4..WRL.E.0J}.3......"..7.X$..:../.x..5.U.....vW@.D.`^.(7rV./Lm5....t...f?.. ....!..,.=..b..^xH.T.0.i&@...@;.....>...z.\D..]h.Pe..E.z.E...........P.h..BH-...sP.`.....v..gI.q1>.Fb48..l.M../...V..O......uv>..^...D....xh.\....h...5j.v..0.........uq... ...c.....wzW]..f..!....Y........e...Sqa.;..}b...'Byj.......e{8.:W...!]^./.#S .]k...../..@,..f.,F..^....c.....Kt~OL..}.3.....fg.|.: E..g......2.1.......#..W...n..}.L6....R.jh^ . ....hl...8...$..9.`u....F$...i..q.\......'W#.dh...pxu9....L.G..P..]...O<....O..!.<h:....WC./I......:c....a.5f.N.<.Ygf.cb....h.......!TD......w.4..?Z..J...]a..v........#K....s...v.zk.5...V.A}.9...A.N,..A..J..r..
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:ASCII text
    Category:dropped
    Size (bytes):2380
    Entropy (8bit):5.1709818838433295
    Encrypted:false
    SSDEEP:48:RyOlrYJErYJFHvv432sDt32sWEtPu3tOH3/W2agLKVD6GfwVuzC:RPlrYJErYJFPQ3vt3S34mgeVDbiYC
    MD5:09AA44AF19C79E3819D72B9457599B70
    SHA1:FA3FAECF795BCD9DEBC23E0847CEEE26D8C93189
    SHA-256:36061C7DB32E33E738A46427A0C4BF264951BA6F246E6FCD3FA33DAFFACEA30B
    SHA-512:DF7251F6973E20FC21A39D3EAB7AFA88CF48BC12B5AF7CDC10FB8E2128FC198DDB301EA86484D29E0F8C3EBD6BB3808A0D3F2AEC00AD799D7C73F5F0AFA17598
    Malicious:false
    Reputation:low
    Preview:#.# Copyright (c) 2004, 2007, Oracle and/or its affiliates. All rights reserved..#.# Redistribution and use in source and binary forms, with or without.# modification, are permitted provided that the following conditions.# are met:.#.# - Redistributions of source code must retain the above copyright.# notice, this list of conditions and the following disclaimer..#.# - Redistributions in binary form must reproduce the above copyright.# notice, this list of conditions and the following disclaimer in the.# documentation and/or other materials provided with the distribution..#.# - Neither the name of Oracle nor the names of its.# contributors may be used to endorse or promote products derived.# from this software without specific prior written permission..#.# THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS.# IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,.# THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Zip archive data, at least v2.0 to extract, compression method=deflate
    Category:dropped
    Size (bytes):11673
    Entropy (8bit):7.949799283093398
    Encrypted:false
    SSDEEP:192:r8dTB0tewzMDvVKvQ8b1bC/fHuF0c2pDC8QCvXJ131osw5fcL1nI/IGcGCCC1:r8dJwAVKY8xG/fHxpDUuWBUpGC1
    MD5:402DD7BCE89D048D7F89125EC5F891BD
    SHA1:2900AC7088C5BCE2EC9FA290391A0A3DFD7AB4A4
    SHA-256:0F9620995F7F4D8308CC78B8D70E0EC8FFC49BB65DC3FC46D2E0B516A5BC641C
    SHA-512:A6ACB1B930711B517E5C0E8009E8D76BB626CA446DF1F81300968EE36BA998D56FFE34A28168121C19A842833EF254856228AACBEF5616F283524E36D72BE74E
    Malicious:false
    Reputation:low
    Preview:PK...........V....^....'......heapViewer.cUT...%..d%..dux..............Zms...._.q.<.B;N......m3.%.....:...$&....R....g..Kr...S~.I`....../zG.~.~H..2...W.......F...BAn.......<..7....aHr\J.HE.....1KK.A.%.l..q..h..."J.M.I.4."7y.y..R.>..0...7.sY.~0.<.yh.&.."Y.Y&|Z'.6..-..?.|.0..D.....xP.\x.Jd?.....K)..ry...M.A......[.....Eq.xB.I.R....[.....z...Dr..4..f.B.(.o .......+?.6+.en.?.@...V.~..aZ.@..9....8....4...,X..(...'..B....I.y.h&.G."&..h.....3A.D..........(i<.>3 r.Q...c.c.._.......sc.d...w.e....90.t......w.-.....p`X6..ZG.e^N.1..u.Y.....G.....2l.....wC..0.....52G..d`..5..........2g.)..=#i|E.....~i.M...tF<.....N...?...s..Xwc. .o`...n...3.....{c.}...-}..F...d,..{i@Z.rh.........zUo}X.R.5....fd.j@+.z..m..6.>...i....P..u..K..e..=....8.]...iw...a_.plK.MlC.$...Z..,..._NlS...9.eM..s<....`!H.c.@.{<.:.Xc.=.2'..t.F.n.tYl^i5..a.z}.N.)aL..,....C.....&.3.w.mt.=..]3W.....'Rwv.dS..Db.gMz..+...&.......G....[......jq..UE....V.0D.K.8.R..B....X....m..|8..o...6*K,....D....`
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:ASCII text
    Category:dropped
    Size (bytes):2380
    Entropy (8bit):5.1709818838433295
    Encrypted:false
    SSDEEP:48:RyOlrYJErYJFHvv432sDt32sWEtPu3tOH3/W2agLKVD6GfwVuzC:RPlrYJErYJFPQ3vt3S34mgeVDbiYC
    MD5:09AA44AF19C79E3819D72B9457599B70
    SHA1:FA3FAECF795BCD9DEBC23E0847CEEE26D8C93189
    SHA-256:36061C7DB32E33E738A46427A0C4BF264951BA6F246E6FCD3FA33DAFFACEA30B
    SHA-512:DF7251F6973E20FC21A39D3EAB7AFA88CF48BC12B5AF7CDC10FB8E2128FC198DDB301EA86484D29E0F8C3EBD6BB3808A0D3F2AEC00AD799D7C73F5F0AFA17598
    Malicious:false
    Reputation:low
    Preview:#.# Copyright (c) 2004, 2007, Oracle and/or its affiliates. All rights reserved..#.# Redistribution and use in source and binary forms, with or without.# modification, are permitted provided that the following conditions.# are met:.#.# - Redistributions of source code must retain the above copyright.# notice, this list of conditions and the following disclaimer..#.# - Redistributions in binary form must reproduce the above copyright.# notice, this list of conditions and the following disclaimer in the.# documentation and/or other materials provided with the distribution..#.# - Neither the name of Oracle nor the names of its.# contributors may be used to endorse or promote products derived.# from this software without specific prior written permission..#.# THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS.# IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,.# THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
    Category:dropped
    Size (bytes):23560
    Entropy (8bit):6.676363334186291
    Encrypted:false
    SSDEEP:384:CNzvb2UfUW2hoxSsY5rZSf+VIYinvyeMPxh8E9VF0NyBFDaG:ojb29hKSF5C/YinZMPxWET8
    MD5:2CD119CAD5DC9A529349EDF1FC9CDD92
    SHA1:CC2EDB8130780EC3F571FD5D698543DCDCFC2D3D
    SHA-256:36B207370C77E4A74DE4FDD95E1561DAFF84DA1852319670FF974A5B76F73EA5
    SHA-512:7CBA998166DE2990B77EFC25D8E21C5DA9F42C17D35D23C69306A409A110120871F24AB322CA0A5CBE3921B2F472C33A7F555BE740DFC1E2940F5CA738D40D98
    Malicious:false
    Antivirus:
    • Antivirus: ReversingLabs, Detection: 0%
    Reputation:low
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......*...n.v.n.v.n.v..O..l.v.....o.v.n.w.D.v.(.m.v.(.o.v.(.e.v.(.l.v.....l.v.....o.v.c.o.v.....o.v.Richn.v.........PE..d...`..d.........." .................................................................S....`......................................... 7..g....7..<....`.......P..t....,...0...p.. ...P1..8............................4..p............0.. ............................text............................... ..`.rdata..L....0......................@..@.data........@......."..............@....pdata..t....P.......$..............@..@.rsrc........`.......&..............@..@.reloc.. ....p.......*..............@..B........................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Intel amd64 COFF object file, not stripped, 2 sections, symbol offset=0x2b1, 10 symbols, created Fri Jul 14 19:39:12 2023, 1st section name ".edata"
    Category:dropped
    Size (bytes):901
    Entropy (8bit):4.574754661597359
    Encrypted:false
    SSDEEP:24:g35ahL4Na2JeKPb0d7qymxHxu3g41F6u9V:zhL4BJeKj0d7qtHxuQ41F6uv
    MD5:D07BF3F4851899BFFEE375EAA1AECF1F
    SHA1:582503F579044068468BD429E11F714303BD8CE3
    SHA-256:231465A620EDF8A39D87EBE63A68EADCDB6A2349E6C87924BC68C384F99DA696
    SHA-512:A151A6CBF2BA7D57647E664F3971CD734E0AA6B1BCAA33614331965E8DFCBE0541BB406A7E0E5FBE9CD5EEBC952058483D031C3A5891675C60C997EFA7657C66
    Malicious:false
    Reputation:low
    Preview:d...`..d.............edata..........g...d...............@..@.debug$S............................@..B....`..d....................................................heapViewer.dll.Agent_OnLoad.Agent_OnUnload...................... .........$.........(.........0.........,.........4.............................c:/wsjdk/Corretto8Src/installers/windows/zip/corretto-build/buildRoot/build/windows-x86_64-normal-server-release/jdk/demoobjs/jvmti/heapViewer/heapViewer.exp.+.<.......................Microsoft (R) LINK...=..cwd.C:\wsjdk\Corretto8Src\installers\windows\zip\corretto-build\buildRoot\jdk\make.exe.c:\progra~2\micros~3.0\vc\bin\amd64\link.exe....8.....Agent_OnLoad...8.....Agent_OnUnload.@comp.id...........edata............szName..<.........rgpv....(.........rgszName0.........rgwOrd..8.........$N00001.K.........$N00002.X............................................. ...Agent_OnLoad.Agent_OnUnload.
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:current ar archive
    Category:dropped
    Size (bytes):1956
    Entropy (8bit):4.759905730814353
    Encrypted:false
    SSDEEP:24:7+PPXyO72P9SuzPwxAqKHsryAOJsPJuWo+XqK//yWu0VcqKPIEqutmkuTV:7HOXWPU9K0yAOJ8/xaKL5V5KwLmEV
    MD5:B2B291AA826D3836723F0655FDA66127
    SHA1:BC5CC7E09A4BDDDBE5374EBF8B26B7476C099F32
    SHA-256:89FD84F5D4C7F0F4E8AAFD1AF4F73A12B9AD3C94798924E55DA1A792CF94FAB3
    SHA-512:82DC1AFE70489EF67B69DD77810D0F03B31CCA2B7C79CE12634DC094F524E0E8CB577F6EF2C8FFF8C05EF9774C8E97F073DA3FB5CCA32CB9EDE4D30D9DFDA40E
    Malicious:false
    Reputation:low
    Preview:!<arch>./ 1689363552 0 184 `............0...j...........6...6__IMPORT_DESCRIPTOR_heapViewer.__NULL_IMPORT_DESCRIPTOR..heapViewer_NULL_THUNK_DATA.Agent_OnLoad.__imp_Agent_OnLoad.Agent_OnUnload.__imp_Agent_OnUnload./ 1689363552 0 194 `.........0...j.......6.....................Agent_OnLoad.Agent_OnUnload.__IMPORT_DESCRIPTOR_heapViewer.__NULL_IMPORT_DESCRIPTOR.__imp_Agent_OnLoad.__imp_Agent_OnUnload..heapViewer_NULL_THUNK_DATA.heapViewer.dll/ 1689363552 0 506 `.d...`..d.............debug$S........D...................@..B.idata$2............................@.0..idata$6............................@. ..............heapViewer.dll'......................Microsoft (R) LINK..................................................heapViewer.dll..@comp.id.............................idata$2@.......h..idata$6...........idata$4@.......h..idata$5@.......h.....#.................<.............X...__IMPORT_DES
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:MSVC program database ver 7.00, 4096*83 bytes
    Category:dropped
    Size (bytes):339968
    Entropy (8bit):4.468207028071562
    Encrypted:false
    SSDEEP:6144:uv+oRwW2+f60Z456tPOomTmfCnUA0fJCM:GnuS1
    MD5:D125708367235176CEE9BF802DCDEC49
    SHA1:FFE5D269044281A95C179BF87FDC1468DDE3A9FD
    SHA-256:3D81BBF6A84220F6196D8AA682286E5AB81912A465C35A4618D65BA52D9B2491
    SHA-512:D603E35D2759EFA9DCC2DE6C2E3A693952F9FDD62C95FD623F3FA041AFCE1D23D4F97D954D89B6BF8EA1F5C95F2C51AA5EA59F26C5D1298F504F98FE0DF346EB
    Malicious:false
    Reputation:low
    Preview:Microsoft C/C++ MSF 7.00...DS...........S...........Q...................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:current ar archive
    Category:dropped
    Size (bytes):1956
    Entropy (8bit):4.759905730814353
    Encrypted:false
    SSDEEP:24:7+PPXyO72P9SuzPwxAqKHsryAOJsPJuWo+XqK//yWu0VcqKPIEqutmkuTV:7HOXWPU9K0yAOJ8/xaKL5V5KwLmEV
    MD5:B2B291AA826D3836723F0655FDA66127
    SHA1:BC5CC7E09A4BDDDBE5374EBF8B26B7476C099F32
    SHA-256:89FD84F5D4C7F0F4E8AAFD1AF4F73A12B9AD3C94798924E55DA1A792CF94FAB3
    SHA-512:82DC1AFE70489EF67B69DD77810D0F03B31CCA2B7C79CE12634DC094F524E0E8CB577F6EF2C8FFF8C05EF9774C8E97F073DA3FB5CCA32CB9EDE4D30D9DFDA40E
    Malicious:false
    Reputation:low
    Preview:!<arch>./ 1689363552 0 184 `............0...j...........6...6__IMPORT_DESCRIPTOR_heapViewer.__NULL_IMPORT_DESCRIPTOR..heapViewer_NULL_THUNK_DATA.Agent_OnLoad.__imp_Agent_OnLoad.Agent_OnUnload.__imp_Agent_OnUnload./ 1689363552 0 194 `.........0...j.......6.....................Agent_OnLoad.Agent_OnUnload.__IMPORT_DESCRIPTOR_heapViewer.__NULL_IMPORT_DESCRIPTOR.__imp_Agent_OnLoad.__imp_Agent_OnUnload..heapViewer_NULL_THUNK_DATA.heapViewer.dll/ 1689363552 0 506 `.d...`..d.............debug$S........D...................@..B.idata$2............................@.0..idata$6............................@. ..............heapViewer.dll'......................Microsoft (R) LINK..................................................heapViewer.dll..@comp.id.............................idata$2@.......h..idata$6...........idata$4@.......h..idata$5@.......h.....#.................<.............X...__IMPORT_DES
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:MSVC program database ver 7.00, 4096*83 bytes
    Category:dropped
    Size (bytes):339968
    Entropy (8bit):4.468207028071562
    Encrypted:false
    SSDEEP:6144:uv+oRwW2+f60Z456tPOomTmfCnUA0fJCM:GnuS1
    MD5:D125708367235176CEE9BF802DCDEC49
    SHA1:FFE5D269044281A95C179BF87FDC1468DDE3A9FD
    SHA-256:3D81BBF6A84220F6196D8AA682286E5AB81912A465C35A4618D65BA52D9B2491
    SHA-512:D603E35D2759EFA9DCC2DE6C2E3A693952F9FDD62C95FD623F3FA041AFCE1D23D4F97D954D89B6BF8EA1F5C95F2C51AA5EA59F26C5D1298F504F98FE0DF346EB
    Malicious:false
    Reputation:low
    Preview:Microsoft C/C++ MSF 7.00...DS...........S...........Q...................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
    Category:dropped
    Size (bytes):23560
    Entropy (8bit):6.676363334186291
    Encrypted:false
    SSDEEP:384:CNzvb2UfUW2hoxSsY5rZSf+VIYinvyeMPxh8E9VF0NyBFDaG:ojb29hKSF5C/YinZMPxWET8
    MD5:2CD119CAD5DC9A529349EDF1FC9CDD92
    SHA1:CC2EDB8130780EC3F571FD5D698543DCDCFC2D3D
    SHA-256:36B207370C77E4A74DE4FDD95E1561DAFF84DA1852319670FF974A5B76F73EA5
    SHA-512:7CBA998166DE2990B77EFC25D8E21C5DA9F42C17D35D23C69306A409A110120871F24AB322CA0A5CBE3921B2F472C33A7F555BE740DFC1E2940F5CA738D40D98
    Malicious:false
    Antivirus:
    • Antivirus: ReversingLabs, Detection: 0%
    Reputation:low
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......*...n.v.n.v.n.v..O..l.v.....o.v.n.w.D.v.(.m.v.(.o.v.(.e.v.(.l.v.....l.v.....o.v.c.o.v.....o.v.Richn.v.........PE..d...`..d.........." .................................................................S....`......................................... 7..g....7..<....`.......P..t....,...0...p.. ...P1..8............................4..p............0.. ............................text............................... ..`.rdata..L....0......................@..@.data........@......."..............@....pdata..t....P.......$..............@..@.rsrc........`.......&..............@..@.reloc.. ....p.......*..............@..B........................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Intel amd64 COFF object file, not stripped, 2 sections, symbol offset=0x2b1, 10 symbols, created Fri Jul 14 19:39:12 2023, 1st section name ".edata"
    Category:dropped
    Size (bytes):901
    Entropy (8bit):4.574754661597359
    Encrypted:false
    SSDEEP:24:g35ahL4Na2JeKPb0d7qymxHxu3g41F6u9V:zhL4BJeKj0d7qtHxuQ41F6uv
    MD5:D07BF3F4851899BFFEE375EAA1AECF1F
    SHA1:582503F579044068468BD429E11F714303BD8CE3
    SHA-256:231465A620EDF8A39D87EBE63A68EADCDB6A2349E6C87924BC68C384F99DA696
    SHA-512:A151A6CBF2BA7D57647E664F3971CD734E0AA6B1BCAA33614331965E8DFCBE0541BB406A7E0E5FBE9CD5EEBC952058483D031C3A5891675C60C997EFA7657C66
    Malicious:false
    Reputation:low
    Preview:d...`..d.............edata..........g...d...............@..@.debug$S............................@..B....`..d....................................................heapViewer.dll.Agent_OnLoad.Agent_OnUnload...................... .........$.........(.........0.........,.........4.............................c:/wsjdk/Corretto8Src/installers/windows/zip/corretto-build/buildRoot/build/windows-x86_64-normal-server-release/jdk/demoobjs/jvmti/heapViewer/heapViewer.exp.+.<.......................Microsoft (R) LINK...=..cwd.C:\wsjdk\Corretto8Src\installers\windows\zip\corretto-build\buildRoot\jdk\make.exe.c:\progra~2\micros~3.0\vc\bin\amd64\link.exe....8.....Agent_OnLoad...8.....Agent_OnUnload.@comp.id...........edata............szName..<.........rgpv....(.........rgszName0.........rgwOrd..8.........$N00001.K.........$N00002.X............................................. ...Agent_OnLoad.Agent_OnUnload.
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Zip archive data, at least v2.0 to extract, compression method=deflate
    Category:dropped
    Size (bytes):11673
    Entropy (8bit):7.949799283093398
    Encrypted:false
    SSDEEP:192:r8dTB0tewzMDvVKvQ8b1bC/fHuF0c2pDC8QCvXJ131osw5fcL1nI/IGcGCCC1:r8dJwAVKY8xG/fHxpDUuWBUpGC1
    MD5:402DD7BCE89D048D7F89125EC5F891BD
    SHA1:2900AC7088C5BCE2EC9FA290391A0A3DFD7AB4A4
    SHA-256:0F9620995F7F4D8308CC78B8D70E0EC8FFC49BB65DC3FC46D2E0B516A5BC641C
    SHA-512:A6ACB1B930711B517E5C0E8009E8D76BB626CA446DF1F81300968EE36BA998D56FFE34A28168121C19A842833EF254856228AACBEF5616F283524E36D72BE74E
    Malicious:false
    Reputation:low
    Preview:PK...........V....^....'......heapViewer.cUT...%..d%..dux..............Zms...._.q.<.B;N......m3.%.....:...$&....R....g..Kr...S~.I`....../zG.~.~H..2...W.......F...BAn.......<..7....aHr\J.HE.....1KK.A.%.l..q..h..."J.M.I.4."7y.y..R.>..0...7.sY.~0.<.yh.&.."Y.Y&|Z'.6..-..?.|.0..D.....xP.\x.Jd?.....K)..ry...M.A......[.....Eq.xB.I.R....[.....z...Dr..4..f.B.(.o .......+?.6+.en.?.@...V.~..aZ.@..9....8....4...,X..(...'..B....I.y.h&.G."&..h.....3A.D..........(i<.>3 r.Q...c.c.._.......sc.d...w.e....90.t......w.-.....p`X6..ZG.e^N.1..u.Y.....G.....2l.....wC..0.....52G..d`..5..........2g.)..=#i|E.....~i.M...tF<.....N...?...s..Xwc. .o`...n...3.....{c.}...-}..F...d,..{i@Z.rh.........zUo}X.R.5....fd.j@+.z..m..6.>...i....P..u..K..e..=....8.]...iw...a_.plK.MlC.$...Z..,..._NlS...9.eM..s<....`!H.c.@.{<.:.Xc.=.2'..t.F.n.tYl^i5..a.z}.N.)aL..,....C.....&.3.w.mt.=..]3W.....'Rwv.dS..Db.gMz..+...&.......G....[......jq..UE....V.0D.K.8.R..B....X....m..|8..o...6*K,....D....`
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:ASCII text
    Category:dropped
    Size (bytes):5581
    Entropy (8bit):4.943177839129917
    Encrypted:false
    SSDEEP:96:n6rYJdrYJQX3Z3r3dVeRL0WGZx9nH4pvKk73yEesnqz9ql+t+W:n6rsdrsQXJ3r37eRaTHxk73yzsqz9q8T
    MD5:20AEF922E9ED1221B4F0BAA7C3B9E0E0
    SHA1:48C8FB92DC677746A43E7FB713F3C56695AE3711
    SHA-256:BD59BB90AFFA888DE1D1567AC592B1EB5C6D2E1027FBFCCE704484D211F9347A
    SHA-512:BC89CE5B66FBD40C9BF6C601C4734B981102C3AC4DDEABD4B8763C981E79DE5C3C76B96D8C30F45EBF25F700CB91C8C343F7B72175D7A8D1F4F1D972B4D3C1A5
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2003, 2005, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABI
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Zip archive data, at least v2.0 to extract, compression method=deflate
    Category:dropped
    Size (bytes):220303
    Entropy (8bit):7.983492566341302
    Encrypted:false
    SSDEEP:6144:YnapMiZwEf5IiRsdLrExyxeTXMIzn4Xc/Xf0b:425IiSilzMy4XcG
    MD5:AC7596D9AE7C72398C5C03FF08C85E1A
    SHA1:6DED1DA1AE269C804C8337542E017C9F02CA76E2
    SHA-256:4CBD22888B8BC142C6EE768B8DB14A08BC2E361D2939C0368F6EDB98E26F147B
    SHA-512:B9F9757DC6D692130A9B452A767D0B5FC3D2E6FC509FA40E61DC90AB79E7EA5521A8D2B4EC6F8FB52D8ACDAB62C5E8438EF66F5CA9847661996411BB8CB4175C
    Malicious:false
    Reputation:low
    Preview:PK...........V,.gCC....g......debug_malloc.cUT...%..d%..dux..............\.s.8....Q.c.....eGI)....r.<.\.R..dqC..>.x/........l2{..K..h4.........-N..}..,2.L]qtp....=......R..l?ND....0.3..N.....D.2...=..$.r..Y.\.Y.GH@..A$.8O.DR\....y.,SO...B.,.7.3...g.<..H..~".J&. ..L...6...l.g...:a.......,.A)R.qK..+.....x....3..,)._.._....T...,.J...... .).5.......2.{.........<..?.!.k.f.4_.(.......!.K..$.....;.l..\b_.4..D.R"cJ...|M;.j....\..0...G..X.h.o%...3)XD..3`..Q..C;.%....*..2....u....|.jW.z...*.{#1....v.]........g..;h....w...c.zpq...D...o..a...x./Z....Z.............E...E.....N...<..^\....<.4D.0............m.)...;<}._;/{...;..7..t.0_G........).........w...^tz..=.L...[.?......z.o..!..|...]......r.z.....U~:.)..............Uu..<....u....A.8.\v^.".....tz5.^". .....7..w.....>....vG'.b0".]...L2.xjU@.$.=...Q.d.....qo.wa.......>#a...f..`..."%..m.'..B...KR.8F ......a...".~..E.U......$..7.{=...R...v`.+Z;n....{..Z.=.].;....z....1.).!.V.G.....g.`.*=
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:ASCII text
    Category:dropped
    Size (bytes):5581
    Entropy (8bit):4.943177839129917
    Encrypted:false
    SSDEEP:96:n6rYJdrYJQX3Z3r3dVeRL0WGZx9nH4pvKk73yEesnqz9ql+t+W:n6rsdrsQXJ3r37eRaTHxk73yzsqz9q8T
    MD5:20AEF922E9ED1221B4F0BAA7C3B9E0E0
    SHA1:48C8FB92DC677746A43E7FB713F3C56695AE3711
    SHA-256:BD59BB90AFFA888DE1D1567AC592B1EB5C6D2E1027FBFCCE704484D211F9347A
    SHA-512:BC89CE5B66FBD40C9BF6C601C4734B981102C3AC4DDEABD4B8763C981E79DE5C3C76B96D8C30F45EBF25F700CB91C8C343F7B72175D7A8D1F4F1D972B4D3C1A5
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2003, 2005, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABI
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
    Category:dropped
    Size (bytes):148032
    Entropy (8bit):6.521544879734357
    Encrypted:false
    SSDEEP:3072:QDQg7L3btjuV5ZrU3WDRpBa4CNBcndlKocSFEX9R/Gxr:e7L3JiVfrU3s9Ew7KNSFEXPQ
    MD5:5FF694B1DF85C69D62C086085FE6291E
    SHA1:CD22E444E550A0376B8A5326CAE5EC37F5B69414
    SHA-256:D914329AC8667FFD467DCEBE81AD599DEAF018B899F4F56D11A167F2A4000D53
    SHA-512:18720A25859C60ED023CE06B8B09AABE4661F4281EA3EC365E418E7811CBBC4768B0B185A1B94FA271E35E50814ABA9FDF23686B52F4122BE22B9FAB9D282603
    Malicious:false
    Antivirus:
    • Antivirus: ReversingLabs, Detection: 0%
    Reputation:low
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......C.................}.....A.g.....A.e.....A.Z.....A.[......@q.........\....!Z......!f.......a......!d.....Rich............................PE..d...`..d.........." .........................................................`......r.....`.........................................P...........d....@....... ..........@4...P..t... ...8...........................p...p............................................text...;........................... ..`.rdata...d.......f..................@..@.data... ...........................@....pdata....... ......................@..@.rsrc........@......................@..@.reloc..t....P......................@..B........................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Intel amd64 COFF object file, not stripped, 2 sections, symbol offset=0x339, 14 symbols, created Fri Jul 14 19:39:12 2023, 1st section name ".edata"
    Category:dropped
    Size (bytes):1147
    Entropy (8bit):4.502120887486947
    Encrypted:false
    SSDEEP:24:gdBElgVe+uMfX4Na2+weKPb0d7qydaBErxxrxu3oI10i5UX1gI:YEbMfX4B+weKj0d7qyayrxuYI10iKXL
    MD5:166D54924F6807F1E205B11B162E4CBE
    SHA1:EE8009E1D09B8088B3D5B43B093DF33AC40BB502
    SHA-256:9C4197DD149D9854CD447A83E84BFA19DBD718777DC9658C6EBDA07D3D6BB88C
    SHA-512:AF2E4449C9F8A4D548F2E81BEE6AF0B51ACD9B7437E6519E7DF625A8A1381BCDF8708BB8509DFFFF7D8F98C1E275657676268770DDFDAD93296127873100A748
    Malicious:false
    Reputation:low
    Preview:d...`..d9............edata..............d...............@..@.debug$S............x...............@..B....`..d........................................................................hprof.dll.Agent_OnLoad.Agent_OnUnload.java_crw_demo.java_crw_demo_classname..................... .........$.........(.........8.........,.........<.........0.........@.........4.........D.............................c:/wsjdk/Corretto8Src/installers/windows/zip/corretto-build/buildRoot/build/windows-x86_64-normal-server-release/jdk/demoobjs/jvmti/hprof/hprof.exp.+.<.......................Microsoft (R) LINK...=..cwd.C:\wsjdk\Corretto8Src\installers\windows\zip\corretto-build\buildRoot\jdk\make.exe.c:\progra~2\micros~3.0\vc\bin\amd64\link.exe....8.....Agent_OnLoad...8.....Agent_OnUnload...8.....java_crw_demo...8.....java_crw_demo_classname.@comp.id...........edata............szName..P.........rgpv....(.........rgszName8.........rgwOrd..H.........$N00001.Z.........$N00002.g.........$N00003.v.........$N00004......
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:current ar archive
    Category:dropped
    Size (bytes):2318
    Entropy (8bit):4.833774181475916
    Encrypted:false
    SSDEEP:24:InihAXykXor2i9D7g/NgJJeoJnqKksryAOuihddNAiFnqK//yugN+xUunqKPrz/5:I2uE/UKkUyAO5dzgK1ggulKvSXz+QRy
    MD5:4C40CB4E564F2C2A6E0131B94FC9375A
    SHA1:57B595046402CB2950454D5E68D88BD0FCCD76F8
    SHA-256:881FFC461DF9CC16F3D791FDCF78F1925570C43DD01DB623EA21F6977630D6AF
    SHA-512:E4BA81B4ED79C8B93F59E036BC7DF8C8D545994136D50ACB0675836826FE20A65C0BFC0862BE0C6B8612E645AC9FE311A378941C88F0678271787193CB3D7BB3
    Malicious:false
    Reputation:low
    Preview:!<arch>./ 1689363552 0 278 `....................b...b...........4...4........__IMPORT_DESCRIPTOR_hprof.__NULL_IMPORT_DESCRIPTOR..hprof_NULL_THUNK_DATA.Agent_OnLoad.__imp_Agent_OnLoad.Agent_OnUnload.__imp_Agent_OnUnload.__imp_java_crw_demo.java_crw_demo.__imp_java_crw_demo_classname.java_crw_demo_classname./ 1689363552 0 288 `.................b.......4.................................Agent_OnLoad.Agent_OnUnload.__IMPORT_DESCRIPTOR_hprof.__NULL_IMPORT_DESCRIPTOR.__imp_Agent_OnLoad.__imp_Agent_OnUnload.__imp_java_crw_demo.__imp_java_crw_demo_classname.java_crw_demo.java_crw_demo_classname..hprof_NULL_THUNK_DATA.hprof.dll/ 1689363552 0 485 `.d...`..d.............debug$S........?...................@..B.idata$2............................@.0..idata$6............................@. ..............hprof.dll'......................Microsoft (R) LINK...........................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:MSVC program database ver 7.00, 4096*233 bytes
    Category:dropped
    Size (bytes):954368
    Entropy (8bit):4.981288719088472
    Encrypted:false
    SSDEEP:24576:hP8QAFBOImV6Irdcdab+awc3qU6ohB+hxT:wcImV6Irdcdab+awc3qU6ohB+hxT
    MD5:E241D20BF60A0188E1828C4272FF1BF4
    SHA1:40DD5EB0982DD5D3E7FA9D6475F135A80D23E6A3
    SHA-256:1DF4F09F493BFDAE87B4E94EE6B6DB887823AB722F1803DB82897A2A8B8E4E2B
    SHA-512:E19208E91DC9551C1A6ECA5C3DBF7617F7D604E18E334AD27D599867C04712C1B10FC4DA5CF5E54C27F5C7EA340C8373C1E1BE26A496332F973C0E4F17A4A763
    Malicious:false
    Reputation:low
    Preview:Microsoft C/C++ MSF 7.00...DS...........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Intel amd64 COFF object file, not stripped, 2 sections, symbol offset=0x339, 14 symbols, created Fri Jul 14 19:39:12 2023, 1st section name ".edata"
    Category:dropped
    Size (bytes):1147
    Entropy (8bit):4.502120887486947
    Encrypted:false
    SSDEEP:24:gdBElgVe+uMfX4Na2+weKPb0d7qydaBErxxrxu3oI10i5UX1gI:YEbMfX4B+weKj0d7qyayrxuYI10iKXL
    MD5:166D54924F6807F1E205B11B162E4CBE
    SHA1:EE8009E1D09B8088B3D5B43B093DF33AC40BB502
    SHA-256:9C4197DD149D9854CD447A83E84BFA19DBD718777DC9658C6EBDA07D3D6BB88C
    SHA-512:AF2E4449C9F8A4D548F2E81BEE6AF0B51ACD9B7437E6519E7DF625A8A1381BCDF8708BB8509DFFFF7D8F98C1E275657676268770DDFDAD93296127873100A748
    Malicious:false
    Reputation:low
    Preview:d...`..d9............edata..............d...............@..@.debug$S............x...............@..B....`..d........................................................................hprof.dll.Agent_OnLoad.Agent_OnUnload.java_crw_demo.java_crw_demo_classname..................... .........$.........(.........8.........,.........<.........0.........@.........4.........D.............................c:/wsjdk/Corretto8Src/installers/windows/zip/corretto-build/buildRoot/build/windows-x86_64-normal-server-release/jdk/demoobjs/jvmti/hprof/hprof.exp.+.<.......................Microsoft (R) LINK...=..cwd.C:\wsjdk\Corretto8Src\installers\windows\zip\corretto-build\buildRoot\jdk\make.exe.c:\progra~2\micros~3.0\vc\bin\amd64\link.exe....8.....Agent_OnLoad...8.....Agent_OnUnload...8.....java_crw_demo...8.....java_crw_demo_classname.@comp.id...........edata............szName..P.........rgpv....(.........rgszName8.........rgwOrd..H.........$N00001.Z.........$N00002.g.........$N00003.v.........$N00004......
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:current ar archive
    Category:dropped
    Size (bytes):2318
    Entropy (8bit):4.833774181475916
    Encrypted:false
    SSDEEP:24:InihAXykXor2i9D7g/NgJJeoJnqKksryAOuihddNAiFnqK//yugN+xUunqKPrz/5:I2uE/UKkUyAO5dzgK1ggulKvSXz+QRy
    MD5:4C40CB4E564F2C2A6E0131B94FC9375A
    SHA1:57B595046402CB2950454D5E68D88BD0FCCD76F8
    SHA-256:881FFC461DF9CC16F3D791FDCF78F1925570C43DD01DB623EA21F6977630D6AF
    SHA-512:E4BA81B4ED79C8B93F59E036BC7DF8C8D545994136D50ACB0675836826FE20A65C0BFC0862BE0C6B8612E645AC9FE311A378941C88F0678271787193CB3D7BB3
    Malicious:false
    Reputation:low
    Preview:!<arch>./ 1689363552 0 278 `....................b...b...........4...4........__IMPORT_DESCRIPTOR_hprof.__NULL_IMPORT_DESCRIPTOR..hprof_NULL_THUNK_DATA.Agent_OnLoad.__imp_Agent_OnLoad.Agent_OnUnload.__imp_Agent_OnUnload.__imp_java_crw_demo.java_crw_demo.__imp_java_crw_demo_classname.java_crw_demo_classname./ 1689363552 0 288 `.................b.......4.................................Agent_OnLoad.Agent_OnUnload.__IMPORT_DESCRIPTOR_hprof.__NULL_IMPORT_DESCRIPTOR.__imp_Agent_OnLoad.__imp_Agent_OnUnload.__imp_java_crw_demo.__imp_java_crw_demo_classname.java_crw_demo.java_crw_demo_classname..hprof_NULL_THUNK_DATA.hprof.dll/ 1689363552 0 485 `.d...`..d.............debug$S........?...................@..B.idata$2............................@.0..idata$6............................@. ..............hprof.dll'......................Microsoft (R) LINK...........................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:MSVC program database ver 7.00, 4096*233 bytes
    Category:dropped
    Size (bytes):954368
    Entropy (8bit):4.981288719088472
    Encrypted:false
    SSDEEP:24576:hP8QAFBOImV6Irdcdab+awc3qU6ohB+hxT:wcImV6Irdcdab+awc3qU6ohB+hxT
    MD5:E241D20BF60A0188E1828C4272FF1BF4
    SHA1:40DD5EB0982DD5D3E7FA9D6475F135A80D23E6A3
    SHA-256:1DF4F09F493BFDAE87B4E94EE6B6DB887823AB722F1803DB82897A2A8B8E4E2B
    SHA-512:E19208E91DC9551C1A6ECA5C3DBF7617F7D604E18E334AD27D599867C04712C1B10FC4DA5CF5E54C27F5C7EA340C8373C1E1BE26A496332F973C0E4F17A4A763
    Malicious:false
    Reputation:low
    Preview:Microsoft C/C++ MSF 7.00...DS...........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
    Category:dropped
    Size (bytes):148032
    Entropy (8bit):6.521544879734357
    Encrypted:false
    SSDEEP:3072:QDQg7L3btjuV5ZrU3WDRpBa4CNBcndlKocSFEX9R/Gxr:e7L3JiVfrU3s9Ew7KNSFEXPQ
    MD5:5FF694B1DF85C69D62C086085FE6291E
    SHA1:CD22E444E550A0376B8A5326CAE5EC37F5B69414
    SHA-256:D914329AC8667FFD467DCEBE81AD599DEAF018B899F4F56D11A167F2A4000D53
    SHA-512:18720A25859C60ED023CE06B8B09AABE4661F4281EA3EC365E418E7811CBBC4768B0B185A1B94FA271E35E50814ABA9FDF23686B52F4122BE22B9FAB9D282603
    Malicious:false
    Antivirus:
    • Antivirus: ReversingLabs, Detection: 0%
    Reputation:low
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......C.................}.....A.g.....A.e.....A.Z.....A.[......@q.........\....!Z......!f.......a......!d.....Rich............................PE..d...`..d.........." .........................................................`......r.....`.........................................P...........d....@....... ..........@4...P..t... ...8...........................p...p............................................text...;........................... ..`.rdata...d.......f..................@..@.data... ...........................@....pdata....... ......................@..@.rsrc........@......................@..@.reloc..t....P......................@..B........................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Zip archive data, at least v2.0 to extract, compression method=deflate
    Category:dropped
    Size (bytes):220303
    Entropy (8bit):7.983492566341302
    Encrypted:false
    SSDEEP:6144:YnapMiZwEf5IiRsdLrExyxeTXMIzn4Xc/Xf0b:425IiSilzMy4XcG
    MD5:AC7596D9AE7C72398C5C03FF08C85E1A
    SHA1:6DED1DA1AE269C804C8337542E017C9F02CA76E2
    SHA-256:4CBD22888B8BC142C6EE768B8DB14A08BC2E361D2939C0368F6EDB98E26F147B
    SHA-512:B9F9757DC6D692130A9B452A767D0B5FC3D2E6FC509FA40E61DC90AB79E7EA5521A8D2B4EC6F8FB52D8ACDAB62C5E8438EF66F5CA9847661996411BB8CB4175C
    Malicious:false
    Reputation:low
    Preview:PK...........V,.gCC....g......debug_malloc.cUT...%..d%..dux..............\.s.8....Q.c.....eGI)....r.<.\.R..dqC..>.x/........l2{..K..h4.........-N..}..,2.L]qtp....=......R..l?ND....0.3..N.....D.2...=..$.r..Y.\.Y.GH@..A$.8O.DR\....y.,SO...B.,.7.3...g.<..H..~".J&. ..L...6...l.g...:a.......,.A)R.qK..+.....x....3..,)._.._....T...,.J...... .).5.......2.{.........<..?.!.k.f.4_.(.......!.K..$.....;.l..\b_.4..D.R"cJ...|M;.j....\..0...G..X.h.o%...3)XD..3`..Q..C;.%....*..2....u....|.jW.z...*.{#1....v.]........g..;h....w...c.zpq...D...o..a...x./Z....Z.............E...E.....N...<..^\....<.4D.0............m.)...;<}._;/{...;..7..t.0_G........).........w...^tz..=.L...[.?......z.o..!..|...]......r.z.....U~:.)..............Uu..<....u....A.8.\v^.".....tz5.^". .....7..w.....>....vG'.b0".]...L2.xjU@.$.=...Q.d.....qo.wa.......>#a...f..`..."%..m.'..B...KR.8F ......a...".~..E.U......$..7.{=...R...v`.+Z;n....{..Z.=.].;....z....1.).!.V.G.....g.`.*=
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:HTML document, ASCII text
    Category:dropped
    Size (bytes):12734
    Entropy (8bit):5.052758749182183
    Encrypted:false
    SSDEEP:384:Hf8AFRZ4f23xa2fHXCZEKW5QuMKvnI9UHcXBo8iL0v6laD:Hf8sPcGgEhFMSnIBXBo8iL0v6laD
    MD5:9C11FF417ABE1937DDE727D6DF069CA9
    SHA1:07AF59DC61A43BC6009F97A15D211EF1A1488EF8
    SHA-256:709E0EDBFD84525BF0AF52AD7C27CCC6A3AF0A8F66439F3A4D4C21D611D6D648
    SHA-512:BCF652E180C4EDF970F9389E3B700982D38A2B3D194463604F96D7E5D54CF4AEC142067C8DFDE2BBB28C27FC37D951CC291F2D4C60CBD6D85F7CA70E87DBDDF9
    Malicious:false
    Reputation:low
    Preview:<html>.<head> <title>JVM TI Demonstration Code</title> </head>..<h1>JVM TI Demonstration Code</h1>..<p>.The .Java<sup><font size=-2>TM</font></sup> Virtual Machine Tools Interface (JVM TI).is a native tool interface provided in JDK 5.0 and newer..Native libraries that use JVM TI and are loaded into the .Java Virtual Machine.via the -agentlib, -agentpath, or -Xrun (deprecated) interfaces, are.called Agents..<p>.<A HREF="http://java.sun.com/j2se/latest/docs/guide/jvmti">JVM TI</A>.was designed to work with the.Java Native Interface .(<A HREF="http://java.sun.com/j2se/latest/docs/guide/jni">JNI</A>),.and eventually displace the .Java Virtual Machine Debugging Interface .(<A HREF="http://java.sun.com/j2se/1.5.0/docs/guide/jpda/jvmdi-spec.html">JVMDI</A>).and the .Java Virtual Machine Profiling Interface .(<A HREF="http://java.sun.com/j2se/1.5.0/docs/guide/jvmpi/index.html">JVMPI</A>)...<p>.We have created a set of demonstration agents that should.help show many of the features and abilitie
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:HTML document, ASCII text
    Category:dropped
    Size (bytes):12734
    Entropy (8bit):5.052758749182183
    Encrypted:false
    SSDEEP:384:Hf8AFRZ4f23xa2fHXCZEKW5QuMKvnI9UHcXBo8iL0v6laD:Hf8sPcGgEhFMSnIBXBo8iL0v6laD
    MD5:9C11FF417ABE1937DDE727D6DF069CA9
    SHA1:07AF59DC61A43BC6009F97A15D211EF1A1488EF8
    SHA-256:709E0EDBFD84525BF0AF52AD7C27CCC6A3AF0A8F66439F3A4D4C21D611D6D648
    SHA-512:BCF652E180C4EDF970F9389E3B700982D38A2B3D194463604F96D7E5D54CF4AEC142067C8DFDE2BBB28C27FC37D951CC291F2D4C60CBD6D85F7CA70E87DBDDF9
    Malicious:false
    Reputation:low
    Preview:<html>.<head> <title>JVM TI Demonstration Code</title> </head>..<h1>JVM TI Demonstration Code</h1>..<p>.The .Java<sup><font size=-2>TM</font></sup> Virtual Machine Tools Interface (JVM TI).is a native tool interface provided in JDK 5.0 and newer..Native libraries that use JVM TI and are loaded into the .Java Virtual Machine.via the -agentlib, -agentpath, or -Xrun (deprecated) interfaces, are.called Agents..<p>.<A HREF="http://java.sun.com/j2se/latest/docs/guide/jvmti">JVM TI</A>.was designed to work with the.Java Native Interface .(<A HREF="http://java.sun.com/j2se/latest/docs/guide/jni">JNI</A>),.and eventually displace the .Java Virtual Machine Debugging Interface .(<A HREF="http://java.sun.com/j2se/1.5.0/docs/guide/jpda/jvmdi-spec.html">JVMDI</A>).and the .Java Virtual Machine Profiling Interface .(<A HREF="http://java.sun.com/j2se/1.5.0/docs/guide/jvmpi/index.html">JVMPI</A>)...<p>.We have created a set of demonstration agents that should.help show many of the features and abilitie
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:ASCII text
    Category:dropped
    Size (bytes):2129
    Entropy (8bit):5.154963231737359
    Encrypted:false
    SSDEEP:48:XyOlrYJErYJFHvv432sDt32sWEtPu3tOHwMNrbHZL26GfwlC:XPlrYJErYJFPQ3vt3S34Q8bHYbSC
    MD5:42062B711F7C2EB3657341AC362E62BA
    SHA1:DE0F5CE14E0D971465835FA713C7861CC7A51797
    SHA-256:568C24815AB90C26BB62E163B3F9A3839EA98944BB2A3E4BFF74B32FDBD10967
    SHA-512:D1D186D9ADD30E057C44B522004094244ACFFD538EF6B2FFE531C559263A67055E3B4330F0BC6E689FBA0E65FA21046DC32650E02D8FAEEA80BF16D757049CF0
    Malicious:false
    Reputation:low
    Preview:#.# Copyright (c) 2006, 2007, Oracle and/or its affiliates. All rights reserved..#.# Redistribution and use in source and binary forms, with or without.# modification, are permitted provided that the following conditions.# are met:.#.# - Redistributions of source code must retain the above copyright.# notice, this list of conditions and the following disclaimer..#.# - Redistributions in binary form must reproduce the above copyright.# notice, this list of conditions and the following disclaimer in the.# documentation and/or other materials provided with the distribution..#.# - Neither the name of Oracle nor the names of its.# contributors may be used to endorse or promote products derived.# from this software without specific prior written permission..#.# THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS.# IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,.# THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:ASCII text
    Category:dropped
    Size (bytes):2129
    Entropy (8bit):5.154963231737359
    Encrypted:false
    SSDEEP:48:XyOlrYJErYJFHvv432sDt32sWEtPu3tOHwMNrbHZL26GfwlC:XPlrYJErYJFPQ3vt3S34Q8bHYbSC
    MD5:42062B711F7C2EB3657341AC362E62BA
    SHA1:DE0F5CE14E0D971465835FA713C7861CC7A51797
    SHA-256:568C24815AB90C26BB62E163B3F9A3839EA98944BB2A3E4BFF74B32FDBD10967
    SHA-512:D1D186D9ADD30E057C44B522004094244ACFFD538EF6B2FFE531C559263A67055E3B4330F0BC6E689FBA0E65FA21046DC32650E02D8FAEEA80BF16D757049CF0
    Malicious:false
    Reputation:low
    Preview:#.# Copyright (c) 2006, 2007, Oracle and/or its affiliates. All rights reserved..#.# Redistribution and use in source and binary forms, with or without.# modification, are permitted provided that the following conditions.# are met:.#.# - Redistributions of source code must retain the above copyright.# notice, this list of conditions and the following disclaimer..#.# - Redistributions in binary form must reproduce the above copyright.# notice, this list of conditions and the following disclaimer in the.# documentation and/or other materials provided with the distribution..#.# - Neither the name of Oracle nor the names of its.# contributors may be used to endorse or promote products derived.# from this software without specific prior written permission..#.# THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS.# IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,.# THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java archive data (JAR)
    Category:dropped
    Size (bytes):11424
    Entropy (8bit):7.91403716248038
    Encrypted:false
    SSDEEP:192:UcMR50rFjpHztXE8XB70Eh3gxW68hrOeJFZkpLtkpIPPYGU66ncSIo:1m50FpTtXE8xVR6ckSKPYh
    MD5:7C640F7A4F9925557DF0BB7F7814D33D
    SHA1:D94CE482E5D8ED46BE844AADC5526E5155EF541D
    SHA-256:CA1BFF814EC2D03F126ED4EBE5A737105A9DB877D451BA1EB9DEB94F5B2599EB
    SHA-512:858E1BEF982A4F10B3D3CC5EB5CA055E1272FAFCF87BA04A0B78C103801F452FE3AC7A705374E70C6055F7457F80FF9F51122577A2E4B077CB605536A0E4EEEA
    Malicious:false
    Reputation:low
    Preview:PK..........V................META-INF/......PK..............PK..........V................META-INF/MANIFEST.MFm.=..0...=..p..-...nZ.*.........R.X._..~..=..^....B.%.i.9..D...,q.p.F......au.-..{.._.....d7.R).-).h...w>..Ge...[.o.o.~.6...-L..>.o.....'...f.g.I.....X9.%.x..{./(E....`.. ..gPK........G...PK..........V................minst.c.<.s.H........8.'WuW...l..m.b..v6....4...`%a....~.1#.. N6y...c...F.=..=.....C.W..Yf..._^..[..|..-F...R8.w.'..R.,.~.;.L;.....KE"S..I.....Xz~.%.|..q...:..D....@...9.F,.$L.........:C(a....u.F[8..+..~.IO......K.t2.C.. ....F.q...P.P.Pf..iB.....x..rc.V.....9@/Bv....Rlb(BDq..K.T......i.e....8~(...j....M.l.[... .{...].2..-?T...$"..'.....Hv.......Y\.9.D.rEqq.$.j.....\...w#....v...ypU....a.I.,.u.@.F.f...)i...Q!...t%].1x.G.KP.".45v1=.'b2:...-../.k.o....p.......}v>..A..ODw.....~{5...Fw...I..u......L.h,.......;...-.aop..gm.0.p4.......tY5O.....s..}k...{ByjO.....u.ew<.{W...!]^./G.K.....7...V.#..@,.kk8....`P...........}k.......v....
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Zip archive data, at least v2.0 to extract, compression method=deflate
    Category:dropped
    Size (bytes):35037
    Entropy (8bit):7.981492550687012
    Encrypted:false
    SSDEEP:768:640pTtDogqPQCBUpGPyLXoIOdRUBCLll3ZYdQ3ul+yPw9:64KhogqtOpGPMXojRhEjw9
    MD5:444A8A9FE5A95C64E2C782C06A8F2CCA
    SHA1:4ED966FE9CD45A880481A3E9E80B662F2BF19D0C
    SHA-256:88CFA64E7928F4F27DD23028B950C51A04CA3293098D9222382EAF8A36939C2D
    SHA-512:6308B27E0AE67A960257FB5E333E60C9A053DAF2132209C2C33E026F2D419F57013688D0D77FB55C929CB987610136CDB205F98BDBD323DBD5D5B33927740E47
    Malicious:false
    Reputation:low
    Preview:PK...........V..]96....F......minst.cUT...%..d%..dux..............<.s.H........8.'WuW...l..m.b..v6....4...`%a....~.1#.. N6y...c...F.=..=.....C.W..Yf..._^..[..|..-F...R8.w.'..R.,.~.;.L;.....KE"S..I.....Xz~.%.|..q...:..D....@...9.F,.$L.........:C(a....u.F[8..+..~.IO......K.t2.C.. ....F.q...P.P.Pf..iB.....x..rc.V.....9@/Bv....Rlb(BDq..K.T......i.e....8~(...j....M.l.[... .{...].2..-?T...$"..'.....Hv.......Y\.9.D.rEqq.$.j.....\...w#....v...ypU....a.I.,.u.@.F.f...)i...Q!...t%].1x.G.KP.".45v1=.'b2:...-../.k.o....p.......}v>..A..ODw.....~{5...Fw...I..u......L.h,.......;...-.aop..gm.0.p4.......tY5O.....s..}k...{ByjO.....u.ew<.{W...!]^./G.K.....7...V.#..@,.kk8....`P...........}k.......v....Mq_..p............Y.Z....}.y.`'..`.....E..6..<{@J...u...O&Wo'S{z5...h.'.O...&.b0...&V..L.m.+..........&...5._]N...B....J..t..=...Y..{.....$..xwn..1....EvL.{....P.3..f...:..g.g...zgO..H.....*"....W.w...._m.D..m...OE..m#.j=(..V.C..+.].....q.m...7........p.d...!......
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:current ar archive
    Category:dropped
    Size (bytes):2318
    Entropy (8bit):4.800767157628565
    Encrypted:false
    SSDEEP:24:OXyJkHX+2y9D7e/gJJeoKxKksryAOuyX/AiexK//yh/+xUrxKPrd/UXEK/I/u/6p:Ov+/KxKkUyAO1texK62urxKJsXJwmK
    MD5:E300BE86409011CB3E36F16323AC700F
    SHA1:A11F3EB706752651314D11F8A7007AD5061BECB5
    SHA-256:63D52652384383921D2A8483C0CD30F0551794B5C064B443A0D36BE197FB5EEE
    SHA-512:39E48833C0C895D4FA5A8AA7EB548EF42052E19B95D777E5C286FFEC4204D57E70478D5F423C4C4A058892E4A26C65751551448D62936A7DD5D8D99495186486
    Malicious:false
    Reputation:low
    Preview:!<arch>./ 1689363552 0 278 `....................4...4...........b...b........__IMPORT_DESCRIPTOR_minst.__NULL_IMPORT_DESCRIPTOR..minst_NULL_THUNK_DATA.__imp_java_crw_demo.java_crw_demo.__imp_java_crw_demo_classname.java_crw_demo_classname.Agent_OnLoad.__imp_Agent_OnLoad.Agent_OnUnload.__imp_Agent_OnUnload./ 1689363552 0 288 `.................4.......b.................................Agent_OnLoad.Agent_OnUnload.__IMPORT_DESCRIPTOR_minst.__NULL_IMPORT_DESCRIPTOR.__imp_Agent_OnLoad.__imp_Agent_OnUnload.__imp_java_crw_demo.__imp_java_crw_demo_classname.java_crw_demo.java_crw_demo_classname..minst_NULL_THUNK_DATA.minst.dll/ 1689363552 0 485 `.d...`..d.............debug$S........?...................@..B.idata$2............................@.0..idata$6............................@. ..............minst.dll'......................Microsoft (R) LINK...........................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Intel amd64 COFF object file, not stripped, 2 sections, symbol offset=0x339, 14 symbols, created Fri Jul 14 19:39:12 2023, 1st section name ".edata"
    Category:dropped
    Size (bytes):1147
    Entropy (8bit):4.481128035994935
    Encrypted:false
    SSDEEP:24:gdBENgVe+uMfX4Na27eKPb0d7qydaBErxxrxu3oI10i5UX1gI:YETMfX4B7eKj0d7qyayrxuYI10iKXL
    MD5:28B7C6F4AEDE4E9CDC9B2B0F375D99E9
    SHA1:93AFD7E7EABDF8244B080A62F8D8389DF8344589
    SHA-256:F00528CF6B2E8752A6315BD83ABECD80839B9CBE8E1C7ABADB53BB2C169B761D
    SHA-512:EE5401651302D5716226FD78E377D0E8B9C92AA53156014C0496390D2317757BC0234AA051E1519719F3FF364D4DA52C772459AAC598BF4B4E1ABE0609CE1773
    Malicious:false
    Reputation:low
    Preview:d...`..d9............edata..............d...............@..@.debug$S............x...............@..B....`..d........................................................................minst.dll.Agent_OnLoad.Agent_OnUnload.java_crw_demo.java_crw_demo_classname..................... .........$.........(.........8.........,.........<.........0.........@.........4.........D.............................c:/wsjdk/Corretto8Src/installers/windows/zip/corretto-build/buildRoot/build/windows-x86_64-normal-server-release/jdk/demoobjs/jvmti/minst/minst.exp.+.<.......................Microsoft (R) LINK...=..cwd.C:\wsjdk\Corretto8Src\installers\windows\zip\corretto-build\buildRoot\jdk\make.exe.c:\progra~2\micros~3.0\vc\bin\amd64\link.exe....8.....Agent_OnLoad...8.....Agent_OnUnload...8.....java_crw_demo...8.....java_crw_demo_classname.@comp.id...........edata............szName..P.........rgpv....(.........rgszName8.........rgwOrd..H.........$N00001.Z.........$N00002.g.........$N00003.v.........$N00004......
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:MSVC program database ver 7.00, 4096*93 bytes
    Category:dropped
    Size (bytes):380928
    Entropy (8bit):4.666964233957459
    Encrypted:false
    SSDEEP:6144:DpcdgiRh1G2o6jRJAI0uKbmNmqCCGRIVxCuKePs:lvID3KW
    MD5:D7558E1E7A3C3563CB883513E1A20510
    SHA1:F2574D354B5706CADD880143E8C316CCB14F0096
    SHA-256:C56ADE6C04FDF51ECB6796A18E307FF50484F314152D088215A1A3ECEBD8B277
    SHA-512:752D91F694B2453DD23957F70D26BFFB712A064D34943D28C2F794F27F360E306F8DF8F1B7ED09630BFDD26DF0463F5F8F880FE0271DDA834950C5A8FF7BAD1A
    Malicious:false
    Reputation:low
    Preview:Microsoft C/C++ MSF 7.00...DS...........]...........[...................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
    Category:dropped
    Size (bytes):41624
    Entropy (8bit):6.717051551405435
    Encrypted:false
    SSDEEP:768:YdNeAL9zJfcv4Yn4DYwlXriFDmCnIFc71SLRwHt/YinyWPxWEC+g:OUAZz+wBc71SL6N/7yWPxRg
    MD5:3BEE30D28E7141C69D793E0F9FE6D5FA
    SHA1:A614D1777DCAD59148B2B16314AB4B0B985CEC65
    SHA-256:3FB168C091F6E55B21B8D5689B1FF07AA1B031728C87256B212D5D4FDF71F68B
    SHA-512:132DC91B2267D282E7C984CBD6C9EED60BA31F3F02B54C2F110B61450969214AD7092568353A73877EEA698B063AF84EFD6E833CA1D71666CE1132D26BF288E8
    Malicious:false
    Antivirus:
    • Antivirus: ReversingLabs, Detection: 0%
    Reputation:low
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........J..C+..C+..C+....2.A+...>.B+..C+..s+...z$.@+...z&.B+...z..H+...z..A+......@+....%.B+..Ny".B+....'.B+..RichC+..........................PE..d...`..d.........." .....L...(.......T...............................................e....`..........................................o......\p..<...............T....r...0...........a..8............................k..p............`...............................text...KK.......L.................. ..`.rdata.......`.......P..............@..@.data................f..............@....pdata..T............h..............@..@.rsrc................l..............@..@.reloc...............p..............@..B........................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
    Category:dropped
    Size (bytes):41624
    Entropy (8bit):6.717051551405435
    Encrypted:false
    SSDEEP:768:YdNeAL9zJfcv4Yn4DYwlXriFDmCnIFc71SLRwHt/YinyWPxWEC+g:OUAZz+wBc71SL6N/7yWPxRg
    MD5:3BEE30D28E7141C69D793E0F9FE6D5FA
    SHA1:A614D1777DCAD59148B2B16314AB4B0B985CEC65
    SHA-256:3FB168C091F6E55B21B8D5689B1FF07AA1B031728C87256B212D5D4FDF71F68B
    SHA-512:132DC91B2267D282E7C984CBD6C9EED60BA31F3F02B54C2F110B61450969214AD7092568353A73877EEA698B063AF84EFD6E833CA1D71666CE1132D26BF288E8
    Malicious:false
    Antivirus:
    • Antivirus: ReversingLabs, Detection: 0%
    Reputation:low
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........J..C+..C+..C+....2.A+...>.B+..C+..s+...z$.@+...z&.B+...z..H+...z..A+......@+....%.B+..Ny".B+....'.B+..RichC+..........................PE..d...`..d.........." .....L...(.......T...............................................e....`..........................................o......\p..<...............T....r...0...........a..8............................k..p............`...............................text...KK.......L.................. ..`.rdata.......`.......P..............@..@.data................f..............@....pdata..T............h..............@..@.rsrc................l..............@..@.reloc...............p..............@..B........................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Intel amd64 COFF object file, not stripped, 2 sections, symbol offset=0x339, 14 symbols, created Fri Jul 14 19:39:12 2023, 1st section name ".edata"
    Category:dropped
    Size (bytes):1147
    Entropy (8bit):4.481128035994935
    Encrypted:false
    SSDEEP:24:gdBENgVe+uMfX4Na27eKPb0d7qydaBErxxrxu3oI10i5UX1gI:YETMfX4B7eKj0d7qyayrxuYI10iKXL
    MD5:28B7C6F4AEDE4E9CDC9B2B0F375D99E9
    SHA1:93AFD7E7EABDF8244B080A62F8D8389DF8344589
    SHA-256:F00528CF6B2E8752A6315BD83ABECD80839B9CBE8E1C7ABADB53BB2C169B761D
    SHA-512:EE5401651302D5716226FD78E377D0E8B9C92AA53156014C0496390D2317757BC0234AA051E1519719F3FF364D4DA52C772459AAC598BF4B4E1ABE0609CE1773
    Malicious:false
    Reputation:low
    Preview:d...`..d9............edata..............d...............@..@.debug$S............x...............@..B....`..d........................................................................minst.dll.Agent_OnLoad.Agent_OnUnload.java_crw_demo.java_crw_demo_classname..................... .........$.........(.........8.........,.........<.........0.........@.........4.........D.............................c:/wsjdk/Corretto8Src/installers/windows/zip/corretto-build/buildRoot/build/windows-x86_64-normal-server-release/jdk/demoobjs/jvmti/minst/minst.exp.+.<.......................Microsoft (R) LINK...=..cwd.C:\wsjdk\Corretto8Src\installers\windows\zip\corretto-build\buildRoot\jdk\make.exe.c:\progra~2\micros~3.0\vc\bin\amd64\link.exe....8.....Agent_OnLoad...8.....Agent_OnUnload...8.....java_crw_demo...8.....java_crw_demo_classname.@comp.id...........edata............szName..P.........rgpv....(.........rgszName8.........rgwOrd..H.........$N00001.Z.........$N00002.g.........$N00003.v.........$N00004......
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:current ar archive
    Category:dropped
    Size (bytes):2318
    Entropy (8bit):4.800767157628565
    Encrypted:false
    SSDEEP:24:OXyJkHX+2y9D7e/gJJeoKxKksryAOuyX/AiexK//yh/+xUrxKPrd/UXEK/I/u/6p:Ov+/KxKkUyAO1texK62urxKJsXJwmK
    MD5:E300BE86409011CB3E36F16323AC700F
    SHA1:A11F3EB706752651314D11F8A7007AD5061BECB5
    SHA-256:63D52652384383921D2A8483C0CD30F0551794B5C064B443A0D36BE197FB5EEE
    SHA-512:39E48833C0C895D4FA5A8AA7EB548EF42052E19B95D777E5C286FFEC4204D57E70478D5F423C4C4A058892E4A26C65751551448D62936A7DD5D8D99495186486
    Malicious:false
    Reputation:low
    Preview:!<arch>./ 1689363552 0 278 `....................4...4...........b...b........__IMPORT_DESCRIPTOR_minst.__NULL_IMPORT_DESCRIPTOR..minst_NULL_THUNK_DATA.__imp_java_crw_demo.java_crw_demo.__imp_java_crw_demo_classname.java_crw_demo_classname.Agent_OnLoad.__imp_Agent_OnLoad.Agent_OnUnload.__imp_Agent_OnUnload./ 1689363552 0 288 `.................4.......b.................................Agent_OnLoad.Agent_OnUnload.__IMPORT_DESCRIPTOR_minst.__NULL_IMPORT_DESCRIPTOR.__imp_Agent_OnLoad.__imp_Agent_OnUnload.__imp_java_crw_demo.__imp_java_crw_demo_classname.java_crw_demo.java_crw_demo_classname..minst_NULL_THUNK_DATA.minst.dll/ 1689363552 0 485 `.d...`..d.............debug$S........?...................@..B.idata$2............................@.0..idata$6............................@. ..............minst.dll'......................Microsoft (R) LINK...........................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:MSVC program database ver 7.00, 4096*93 bytes
    Category:dropped
    Size (bytes):380928
    Entropy (8bit):4.666964233957459
    Encrypted:false
    SSDEEP:6144:DpcdgiRh1G2o6jRJAI0uKbmNmqCCGRIVxCuKePs:lvID3KW
    MD5:D7558E1E7A3C3563CB883513E1A20510
    SHA1:F2574D354B5706CADD880143E8C316CCB14F0096
    SHA-256:C56ADE6C04FDF51ECB6796A18E307FF50484F314152D088215A1A3ECEBD8B277
    SHA-512:752D91F694B2453DD23957F70D26BFFB712A064D34943D28C2F794F27F360E306F8DF8F1B7ED09630BFDD26DF0463F5F8F880FE0271DDA834950C5A8FF7BAD1A
    Malicious:false
    Reputation:low
    Preview:Microsoft C/C++ MSF 7.00...DS...........]...........[...................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java archive data (JAR)
    Category:dropped
    Size (bytes):11424
    Entropy (8bit):7.91403716248038
    Encrypted:false
    SSDEEP:192:UcMR50rFjpHztXE8XB70Eh3gxW68hrOeJFZkpLtkpIPPYGU66ncSIo:1m50FpTtXE8xVR6ckSKPYh
    MD5:7C640F7A4F9925557DF0BB7F7814D33D
    SHA1:D94CE482E5D8ED46BE844AADC5526E5155EF541D
    SHA-256:CA1BFF814EC2D03F126ED4EBE5A737105A9DB877D451BA1EB9DEB94F5B2599EB
    SHA-512:858E1BEF982A4F10B3D3CC5EB5CA055E1272FAFCF87BA04A0B78C103801F452FE3AC7A705374E70C6055F7457F80FF9F51122577A2E4B077CB605536A0E4EEEA
    Malicious:false
    Reputation:low
    Preview:PK..........V................META-INF/......PK..............PK..........V................META-INF/MANIFEST.MFm.=..0...=..p..-...nZ.*.........R.X._..~..=..^....B.%.i.9..D...,q.p.F......au.-..{.._.....d7.R).-).h...w>..Ge...[.o.o.~.6...-L..>.o.....'...f.g.I.....X9.%.x..{./(E....`.. ..gPK........G...PK..........V................minst.c.<.s.H........8.'WuW...l..m.b..v6....4...`%a....~.1#.. N6y...c...F.=..=.....C.W..Yf..._^..[..|..-F...R8.w.'..R.,.~.;.L;.....KE"S..I.....Xz~.%.|..q...:..D....@...9.F,.$L.........:C(a....u.F[8..+..~.IO......K.t2.C.. ....F.q...P.P.Pf..iB.....x..rc.V.....9@/Bv....Rlb(BDq..K.T......i.e....8~(...j....M.l.[... .{...].2..-?T...$"..'.....Hv.......Y\.9.D.rEqq.$.j.....\...w#....v...ypU....a.I.,.u.@.F.f...)i...Q!...t%].1x.G.KP.".45v1=.'b2:...-../.k.o....p.......}v>..A..ODw.....~{5...Fw...I..u......L.h,.......;...-.aop..gm.0.p4.......tY5O.....s..}k...{ByjO.....u.ew<.{W...!]^./G.K.....7...V.#..@,.kk8....`P...........}k.......v....
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Zip archive data, at least v2.0 to extract, compression method=deflate
    Category:dropped
    Size (bytes):35037
    Entropy (8bit):7.981492550687012
    Encrypted:false
    SSDEEP:768:640pTtDogqPQCBUpGPyLXoIOdRUBCLll3ZYdQ3ul+yPw9:64KhogqtOpGPMXojRhEjw9
    MD5:444A8A9FE5A95C64E2C782C06A8F2CCA
    SHA1:4ED966FE9CD45A880481A3E9E80B662F2BF19D0C
    SHA-256:88CFA64E7928F4F27DD23028B950C51A04CA3293098D9222382EAF8A36939C2D
    SHA-512:6308B27E0AE67A960257FB5E333E60C9A053DAF2132209C2C33E026F2D419F57013688D0D77FB55C929CB987610136CDB205F98BDBD323DBD5D5B33927740E47
    Malicious:false
    Reputation:low
    Preview:PK...........V..]96....F......minst.cUT...%..d%..dux..............<.s.H........8.'WuW...l..m.b..v6....4...`%a....~.1#.. N6y...c...F.=..=.....C.W..Yf..._^..[..|..-F...R8.w.'..R.,.~.;.L;.....KE"S..I.....Xz~.%.|..q...:..D....@...9.F,.$L.........:C(a....u.F[8..+..~.IO......K.t2.C.. ....F.q...P.P.Pf..iB.....x..rc.V.....9@/Bv....Rlb(BDq..K.T......i.e....8~(...j....M.l.[... .{...].2..-?T...$"..'.....Hv.......Y\.9.D.rEqq.$.j.....\...w#....v...ypU....a.I.,.u.@.F.f...)i...Q!...t%].1x.G.KP.".45v1=.'b2:...-../.k.o....p.......}v>..A..ODw.....~{5...Fw...I..u......L.h,.......;...-.aop..gm.0.p4.......tY5O.....s..}k...{ByjO.....u.ew<.{W...!]^./G.K.....7...V.#..@,.kk8....`P...........}k.......v....Mq_..p............Y.Z....}.y.`'..`.....E..6..<{@J...u...O&Wo'S{z5...h.'.O...&.b0...&V..L.m.+..........&...5._]N...B....J..t..=...Y..{.....$..xwn..1....EvL.{....P.3..f...:..g.g...zgO..H.....*"....W.w...._m.D..m...OE..m#.j=(..V.C..+.].....q.m...7........p.d...!......
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:ASCII text
    Category:dropped
    Size (bytes):2243
    Entropy (8bit):5.138525753295447
    Encrypted:false
    SSDEEP:48:RyOlrYJErYJFHvv432sDt32sWEtPu3tOHjVOtAUZawc7x6GfwJ0C:RPlrYJErYJFPQ3vt3S34DVIAUZzcFbWn
    MD5:AD561189FA747302C33817BEC352D5D6
    SHA1:F2204ADE2DA91732630FE8A32F258E44168CD802
    SHA-256:079AF311BFB31869C27DDA71DCB1D5DA42CBE337627FD24440C1C93264C3F29A
    SHA-512:CDD2CB583340BEF9C4A49E39428A789D73E7E06EA2A1C9AE8A283647AD6672787E05A38AAE7F349CBE568DC2B8E412A2F84F8C74917412558A3F0596DA596A66
    Malicious:false
    Reputation:low
    Preview:#.# Copyright (c) 2004, 2007, Oracle and/or its affiliates. All rights reserved..#.# Redistribution and use in source and binary forms, with or without.# modification, are permitted provided that the following conditions.# are met:.#.# - Redistributions of source code must retain the above copyright.# notice, this list of conditions and the following disclaimer..#.# - Redistributions in binary form must reproduce the above copyright.# notice, this list of conditions and the following disclaimer in the.# documentation and/or other materials provided with the distribution..#.# - Neither the name of Oracle nor the names of its.# contributors may be used to endorse or promote products derived.# from this software without specific prior written permission..#.# THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS.# IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,.# THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java archive data (JAR)
    Category:dropped
    Size (bytes):13342
    Entropy (8bit):7.9315146878528955
    Encrypted:false
    SSDEEP:192:UO00pPhmKbytFFiFLyigKpEaFVbT9pBEjR1f8STn7tqjFsCKApcu/6qE6frtL4Ub:us6kzyt/z7gUApKqtL4h7y
    MD5:5B5C562231AC9920E1BF44F4D2EA16F1
    SHA1:02857F75E40349936861781948F51C55A0AE9AF7
    SHA-256:6FA27C8000AE365A8C36B0C01292C0A97069B6361E25C98FB54D2C6BA9717A5D
    SHA-512:1B240DD23E6EB28BC1D7B41C8B8B3A7D29DA69FFE94B3C45C7F3D51DA7943839D2DA9E0C0F2A09DFA4FFDC889478BE741910B735D98BEBF779B6FF6D5C879A3C
    Malicious:false
    Reputation:low
    Preview:PK..........V................META-INF/......PK..............PK..........V................META-INF/MANIFEST.MFm.=..0...=..p..-...nZ.*.........R.X._..~..=..^....B.%.i.9..D...,q.p.F......au.-..{.._.....d7.R).-).h...w>..Ge...[.o.o.~.6...-L..>.o.....'...f.g.I.....X9.%.x..{./(E....`.. ..gPK........G...PK..........V................mtrace.c.=ks....+P.i*9.lg...:g.[....$'...EA6.>T.........H..e9..s.-.q$.X,........}$v.q..K...L...xzp....=<.Q.z..n....g.p.K?..L.]...A.R..T&7r..x.r,.~.%.|..q...:..D....@.....X.I.v..].......B...=.at..H..I.g.\.U......].....'..[?..^.-|l.".l...BM...z....//^@.u...2..E..<..W.L.E.(.|Ov......"..o.c.1...\?.Iw.6.A....x.....B..A-bo..(s..!..P!.!.~.AZ....B6.b.q(}j.u"7...b.(..i&..4..;.......s.|......P*.e..0.`..;..A.F.f..(i..n.!...t%=.1h.#.%.]..Y.....:.1.......>_.G.....x.+......c...T...N....O.t8.;/..#(..O..3.w..b...x0...X8..g.........L:....].8.W..0.p4.g.3.j.Q...XZ..Kq>..........J].t.C..%.......9.<......b4....39>.;...$.c1x=.N...vV....p0....1..b..
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:ASCII text
    Category:dropped
    Size (bytes):2243
    Entropy (8bit):5.138525753295447
    Encrypted:false
    SSDEEP:48:RyOlrYJErYJFHvv432sDt32sWEtPu3tOHjVOtAUZawc7x6GfwJ0C:RPlrYJErYJFPQ3vt3S34DVIAUZzcFbWn
    MD5:AD561189FA747302C33817BEC352D5D6
    SHA1:F2204ADE2DA91732630FE8A32F258E44168CD802
    SHA-256:079AF311BFB31869C27DDA71DCB1D5DA42CBE337627FD24440C1C93264C3F29A
    SHA-512:CDD2CB583340BEF9C4A49E39428A789D73E7E06EA2A1C9AE8A283647AD6672787E05A38AAE7F349CBE568DC2B8E412A2F84F8C74917412558A3F0596DA596A66
    Malicious:false
    Reputation:low
    Preview:#.# Copyright (c) 2004, 2007, Oracle and/or its affiliates. All rights reserved..#.# Redistribution and use in source and binary forms, with or without.# modification, are permitted provided that the following conditions.# are met:.#.# - Redistributions of source code must retain the above copyright.# notice, this list of conditions and the following disclaimer..#.# - Redistributions in binary form must reproduce the above copyright.# notice, this list of conditions and the following disclaimer in the.# documentation and/or other materials provided with the distribution..#.# - Neither the name of Oracle nor the names of its.# contributors may be used to endorse or promote products derived.# from this software without specific prior written permission..#.# THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS.# IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,.# THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Zip archive data, at least v2.0 to extract, compression method=deflate
    Category:dropped
    Size (bytes):37212
    Entropy (8bit):7.982241610111096
    Encrypted:false
    SSDEEP:768:+iPmx8MFQXVBWS44hrBUpGPyLXoIOdRUBCLll3ZYdQ3ul+yPw4:dPm2MSXVAS4erOpGPMXojRhEjw4
    MD5:63B53861D3B24A239AFB15137BB6B6A4
    SHA1:0515A134F11FE231D878D2467DC524B8B73987FC
    SHA-256:28B39B911285639B4EDEF4B8469CFA133C5354CF655CAE5BD752174F6D2E194B
    SHA-512:82C22CF7522D43854C147002B476368F04C2F5367CC70E233CCCFFEB7A27B2C3D9C68F07CDD4F2E904DF86CF3AACD71EC3D42E34A0728AB43CEC9E73D925C839
    Malicious:false
    Reputation:low
    Preview:PK...........V.O3......v......mtrace.cUT...%..d%..dux..............=ks.6...+Pw.J.....CTgG...]Yr%9i&.h(......o'....@.$$+....;.H...s......bW.'.4...E.o.'............J....I*.<..b.....l_..PP.L.2....<.9.. ..`..$F.b.I.."KV.O .,...N,.4.:.6.....&...D.<X...0:.K.X.4..\..2Mn.9.....H....m._.?...v.....d.T.&.^..L$......*....|..7Kn.b.C."N....h.d"......h.".....D2....j.Fc...W..7BH0...<.W..sO... ....@.i..Y)...B6.1I...b..$"..+N..$.P3......4.q..L.........JT..#Jr).E..s@..Q.Y.{fJ.,.[T..e"[J.u....|)jW.z.e...3w,....W..#...h..=qN.........#..l"...g4....<.LF................p~..9....{~.w...0..&.3..wp.<q....0.`8.}..@...x9..b.B.;..3..=w...5....p..0^O\.F......!.....p........{.s./...X8/..D..z.~...3.....>w........'..9. ].c."`...s........U...............'...)...= ...s...O....wr9q..pxB|.;...3..pL...;..d..(...p.Z@..c.x..&.hty1q..6...p.0.A..b.p@4.......!!?H.....W#d/q.......'f3...91.E8...:.c.....+w.Az..w.Pq.W=...hG..n..%M...!.....t.....b.*.!...).]<~..1...V.A..9...a.N,..A...+r
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:MSVC program database ver 7.00, 4096*93 bytes
    Category:dropped
    Size (bytes):380928
    Entropy (8bit):4.761033289164925
    Encrypted:false
    SSDEEP:6144:StNabOJvqamtkw2RCa1oxlIik3volqZC/1Fmhm1CZjlYeRCE9:SlwXIZ99
    MD5:23408C0EEA9AC25E5FF9A6A302780FA6
    SHA1:10335F6C69E7A153F0A384B14A29AB4A03C5782C
    SHA-256:9F6D709E372B52FDA0430534F3D5A1265415D7D0C47D48860D90E37BEA64F3D6
    SHA-512:E5D1CB915E4F96384537DF90D1B7C6713B8774D35EF12F173D8E580897184DC0A1DFBB26BFEB4EC881886768A28C2F29316A57AF5A343A22C2B92C388B6F6DF6
    Malicious:false
    Reputation:low
    Preview:Microsoft C/C++ MSF 7.00...DS...........]...........\...................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:current ar archive
    Category:dropped
    Size (bytes):2334
    Entropy (8bit):4.796407024672707
    Encrypted:false
    SSDEEP:24:njXLQkHXJ2L9D7qcLcPsnNKLsryAOGLjcEmKK//yKcxBJKPwcEEcW0cfcho:nEnNKAyAOVKKYBJKF5
    MD5:66E387BFB12CB5261A4D29A215EF2D45
    SHA1:7885F4F5EC312640B2E468927F732DC36D9EDC70
    SHA-256:476050B3FDD263076F7907550DB82C03E6DE396BA6E533EA709D820B3958C352
    SHA-512:B520E2DC0AF8F48C82515002FB1B8337EBF4E9843A67CB03C62A8DCBF8A49D61329D439CD12C1FE9274F4A48E661C8395BEC9520324815C39EBFDD0CD551130F
    Malicious:false
    Reputation:low
    Preview:!<arch>./ 1689363552 0 280 `....................@...@...........n...n........__IMPORT_DESCRIPTOR_mtrace.__NULL_IMPORT_DESCRIPTOR..mtrace_NULL_THUNK_DATA.__imp_java_crw_demo.java_crw_demo.__imp_java_crw_demo_classname.java_crw_demo_classname.Agent_OnLoad.__imp_Agent_OnLoad.Agent_OnUnload.__imp_Agent_OnUnload./ 1689363552 0 290 `.................@.......n.................................Agent_OnLoad.Agent_OnUnload.__IMPORT_DESCRIPTOR_mtrace.__NULL_IMPORT_DESCRIPTOR.__imp_Agent_OnLoad.__imp_Agent_OnUnload.__imp_java_crw_demo.__imp_java_crw_demo_classname.java_crw_demo.java_crw_demo_classname..mtrace_NULL_THUNK_DATA.mtrace.dll/ 1689363552 0 490 `.d...`..d.............debug$S........@...................@..B.idata$2............................@.0..idata$6............................@. ..............mtrace.dll'......................Microsoft (R) LINK......................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Intel amd64 COFF object file, not stripped, 2 sections, symbol offset=0x33d, 14 symbols, created Fri Jul 14 19:39:12 2023, 1st section name ".edata"
    Category:dropped
    Size (bytes):1151
    Entropy (8bit):4.486046745595015
    Encrypted:false
    SSDEEP:24:guSZuy76gle+uMTT4Na2NeKPb0d7qydaBErxxrxu3oI1WUtLW1gI:x2cMTT4BNeKj0d7qyayrxuYI11tLWL
    MD5:6971945E9BB65158188AD097F23B954A
    SHA1:32998424A37FF9F44A8192CBAD491D65BD53A866
    SHA-256:55ECC097C3FE0BBABFA9A92F241700D749B3135AF958F97ADD5FE34A95394978
    SHA-512:78A049DDF37E08C54BABB4879DF0564B94AA1C86E7058408D786D038688BF4213011D9984DC769D566CFC236CDCDE0E787E0E30D314298630B33FB89546214AA
    Malicious:false
    Reputation:low
    Preview:d...`..d=............edata..............d...............@..@.debug$S............z...............@..B....`..d........................................................................mtrace.dll.Agent_OnLoad.Agent_OnUnload.java_crw_demo.java_crw_demo_classname...................... .........$.........(.........8.........,.........<.........0.........@.........4.........D.............................c:/wsjdk/Corretto8Src/installers/windows/zip/corretto-build/buildRoot/build/windows-x86_64-normal-server-release/jdk/demoobjs/jvmti/mtrace/mtrace.exp.+.<.......................Microsoft (R) LINK...=..cwd.C:\wsjdk\Corretto8Src\installers\windows\zip\corretto-build\buildRoot\jdk\make.exe.c:\progra~2\micros~3.0\vc\bin\amd64\link.exe....8.....Agent_OnLoad...8.....Agent_OnUnload...8.....java_crw_demo...8.....java_crw_demo_classname.@comp.id...........edata............szName..P.........rgpv....(.........rgszName8.........rgwOrd..H.........$N00001.[.........$N00002.h.........$N00003.w.........$N00004..
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
    Category:dropped
    Size (bytes):44216
    Entropy (8bit):6.731029420363749
    Encrypted:false
    SSDEEP:768:UkGFD7N/cAYIn4DYwNXriMsZrWqnlnD+kfCW73SbMLPK/YintuvPxWEC8Q:n2SPcFFfCW73SbES/7tmPxbQ
    MD5:5A973ECDC344EECDC8E186D057B2A1CC
    SHA1:4BA56BB44FE3998F695346855CAE4095AC3BD6AD
    SHA-256:FC1E3A5E78169708A9F564A97C7A8E58716A2535FCC5F0CFDD291750BE11A794
    SHA-512:6944B2CCB463E551223C59FAEBD9BEA49F569030B26CC2BB7A5DFC821B0A14F94DE3C700C41E0DBC53631508DED954CDB4B8F0CBB498562DDC3732E7849F496A
    Malicious:false
    Antivirus:
    • Antivirus: ReversingLabs, Detection: 0%
    Reputation:low
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........J..F+..F+..F+....2.D+...>.G+..F+..t+...z$.E+...z&.G+...z..M+...z..D+.....E+...%.G+..Ky".G+...'.G+..RichF+..........................PE..d...`..d.........." .....T...*.......\....................................................`.....................................................<....................|...0......(....q..8........................... }..p............p...............................text....S.......T.................. ..`.rdata..r....p.......X..............@..@.data...@............p..............@....pdata...............r..............@..@.rsrc................v..............@..@.reloc..(............z..............@..B........................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
    Category:dropped
    Size (bytes):44216
    Entropy (8bit):6.731029420363749
    Encrypted:false
    SSDEEP:768:UkGFD7N/cAYIn4DYwNXriMsZrWqnlnD+kfCW73SbMLPK/YintuvPxWEC8Q:n2SPcFFfCW73SbES/7tmPxbQ
    MD5:5A973ECDC344EECDC8E186D057B2A1CC
    SHA1:4BA56BB44FE3998F695346855CAE4095AC3BD6AD
    SHA-256:FC1E3A5E78169708A9F564A97C7A8E58716A2535FCC5F0CFDD291750BE11A794
    SHA-512:6944B2CCB463E551223C59FAEBD9BEA49F569030B26CC2BB7A5DFC821B0A14F94DE3C700C41E0DBC53631508DED954CDB4B8F0CBB498562DDC3732E7849F496A
    Malicious:false
    Antivirus:
    • Antivirus: ReversingLabs, Detection: 0%
    Reputation:low
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........J..F+..F+..F+....2.D+...>.G+..F+..t+...z$.E+...z&.G+...z..M+...z..D+.....E+...%.G+..Ky".G+...'.G+..RichF+..........................PE..d...`..d.........." .....T...*.......\....................................................`.....................................................<....................|...0......(....q..8........................... }..p............p...............................text....S.......T.................. ..`.rdata..r....p.......X..............@..@.data...@............p..............@....pdata...............r..............@..@.rsrc................v..............@..@.reloc..(............z..............@..B........................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Intel amd64 COFF object file, not stripped, 2 sections, symbol offset=0x33d, 14 symbols, created Fri Jul 14 19:39:12 2023, 1st section name ".edata"
    Category:dropped
    Size (bytes):1151
    Entropy (8bit):4.486046745595015
    Encrypted:false
    SSDEEP:24:guSZuy76gle+uMTT4Na2NeKPb0d7qydaBErxxrxu3oI1WUtLW1gI:x2cMTT4BNeKj0d7qyayrxuYI11tLWL
    MD5:6971945E9BB65158188AD097F23B954A
    SHA1:32998424A37FF9F44A8192CBAD491D65BD53A866
    SHA-256:55ECC097C3FE0BBABFA9A92F241700D749B3135AF958F97ADD5FE34A95394978
    SHA-512:78A049DDF37E08C54BABB4879DF0564B94AA1C86E7058408D786D038688BF4213011D9984DC769D566CFC236CDCDE0E787E0E30D314298630B33FB89546214AA
    Malicious:false
    Reputation:low
    Preview:d...`..d=............edata..............d...............@..@.debug$S............z...............@..B....`..d........................................................................mtrace.dll.Agent_OnLoad.Agent_OnUnload.java_crw_demo.java_crw_demo_classname...................... .........$.........(.........8.........,.........<.........0.........@.........4.........D.............................c:/wsjdk/Corretto8Src/installers/windows/zip/corretto-build/buildRoot/build/windows-x86_64-normal-server-release/jdk/demoobjs/jvmti/mtrace/mtrace.exp.+.<.......................Microsoft (R) LINK...=..cwd.C:\wsjdk\Corretto8Src\installers\windows\zip\corretto-build\buildRoot\jdk\make.exe.c:\progra~2\micros~3.0\vc\bin\amd64\link.exe....8.....Agent_OnLoad...8.....Agent_OnUnload...8.....java_crw_demo...8.....java_crw_demo_classname.@comp.id...........edata............szName..P.........rgpv....(.........rgszName8.........rgwOrd..H.........$N00001.[.........$N00002.h.........$N00003.w.........$N00004..
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:current ar archive
    Category:dropped
    Size (bytes):2334
    Entropy (8bit):4.796407024672707
    Encrypted:false
    SSDEEP:24:njXLQkHXJ2L9D7qcLcPsnNKLsryAOGLjcEmKK//yKcxBJKPwcEEcW0cfcho:nEnNKAyAOVKKYBJKF5
    MD5:66E387BFB12CB5261A4D29A215EF2D45
    SHA1:7885F4F5EC312640B2E468927F732DC36D9EDC70
    SHA-256:476050B3FDD263076F7907550DB82C03E6DE396BA6E533EA709D820B3958C352
    SHA-512:B520E2DC0AF8F48C82515002FB1B8337EBF4E9843A67CB03C62A8DCBF8A49D61329D439CD12C1FE9274F4A48E661C8395BEC9520324815C39EBFDD0CD551130F
    Malicious:false
    Reputation:low
    Preview:!<arch>./ 1689363552 0 280 `....................@...@...........n...n........__IMPORT_DESCRIPTOR_mtrace.__NULL_IMPORT_DESCRIPTOR..mtrace_NULL_THUNK_DATA.__imp_java_crw_demo.java_crw_demo.__imp_java_crw_demo_classname.java_crw_demo_classname.Agent_OnLoad.__imp_Agent_OnLoad.Agent_OnUnload.__imp_Agent_OnUnload./ 1689363552 0 290 `.................@.......n.................................Agent_OnLoad.Agent_OnUnload.__IMPORT_DESCRIPTOR_mtrace.__NULL_IMPORT_DESCRIPTOR.__imp_Agent_OnLoad.__imp_Agent_OnUnload.__imp_java_crw_demo.__imp_java_crw_demo_classname.java_crw_demo.java_crw_demo_classname..mtrace_NULL_THUNK_DATA.mtrace.dll/ 1689363552 0 490 `.d...`..d.............debug$S........@...................@..B.idata$2............................@.0..idata$6............................@. ..............mtrace.dll'......................Microsoft (R) LINK......................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:MSVC program database ver 7.00, 4096*93 bytes
    Category:dropped
    Size (bytes):380928
    Entropy (8bit):4.761033289164925
    Encrypted:false
    SSDEEP:6144:StNabOJvqamtkw2RCa1oxlIik3volqZC/1Fmhm1CZjlYeRCE9:SlwXIZ99
    MD5:23408C0EEA9AC25E5FF9A6A302780FA6
    SHA1:10335F6C69E7A153F0A384B14A29AB4A03C5782C
    SHA-256:9F6D709E372B52FDA0430534F3D5A1265415D7D0C47D48860D90E37BEA64F3D6
    SHA-512:E5D1CB915E4F96384537DF90D1B7C6713B8774D35EF12F173D8E580897184DC0A1DFBB26BFEB4EC881886768A28C2F29316A57AF5A343A22C2B92C388B6F6DF6
    Malicious:false
    Reputation:low
    Preview:Microsoft C/C++ MSF 7.00...DS...........]...........\...................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java archive data (JAR)
    Category:dropped
    Size (bytes):13342
    Entropy (8bit):7.9315146878528955
    Encrypted:false
    SSDEEP:192:UO00pPhmKbytFFiFLyigKpEaFVbT9pBEjR1f8STn7tqjFsCKApcu/6qE6frtL4Ub:us6kzyt/z7gUApKqtL4h7y
    MD5:5B5C562231AC9920E1BF44F4D2EA16F1
    SHA1:02857F75E40349936861781948F51C55A0AE9AF7
    SHA-256:6FA27C8000AE365A8C36B0C01292C0A97069B6361E25C98FB54D2C6BA9717A5D
    SHA-512:1B240DD23E6EB28BC1D7B41C8B8B3A7D29DA69FFE94B3C45C7F3D51DA7943839D2DA9E0C0F2A09DFA4FFDC889478BE741910B735D98BEBF779B6FF6D5C879A3C
    Malicious:false
    Reputation:low
    Preview:PK..........V................META-INF/......PK..............PK..........V................META-INF/MANIFEST.MFm.=..0...=..p..-...nZ.*.........R.X._..~..=..^....B.%.i.9..D...,q.p.F......au.-..{.._.....d7.R).-).h...w>..Ge...[.o.o.~.6...-L..>.o.....'...f.g.I.....X9.%.x..{./(E....`.. ..gPK........G...PK..........V................mtrace.c.=ks....+P.i*9.lg...:g.[....$'...EA6.>T.........H..e9..s.-.q$.X,........}$v.q..K...L...xzp....=<.Q.z..n....g.p.K?..L.]...A.R..T&7r..x.r,.~.%.|..q...:..D....@.....X.I.v..].......B...=.at..H..I.g.\.U......].....'..[?..^.-|l.".l...BM...z....//^@.u...2..E..<..W.L.E.(.|Ov......"..o.c.1...\?.Iw.6.A....x.....B..A-bo..(s..!..P!.!.~.AZ....B6.b.q(}j.u"7...b.(..i&..4..;.......s.|......P*.e..0.`..;..A.F.f..(i..n.!...t%=.1h.#.%.]..Y.....:.1.......>_.G.....x.+......c...T...N....O.t8.;/..#(..O..3.w..b...x0...X8..g.........L:....].8.W..0.p4.g.3.j.Q...XZ..Kq>..........J].t.C..%.......9.<......b4....39>.;...$.c1x=.N...vV....p0....1..b..
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Zip archive data, at least v2.0 to extract, compression method=deflate
    Category:dropped
    Size (bytes):37212
    Entropy (8bit):7.982241610111096
    Encrypted:false
    SSDEEP:768:+iPmx8MFQXVBWS44hrBUpGPyLXoIOdRUBCLll3ZYdQ3ul+yPw4:dPm2MSXVAS4erOpGPMXojRhEjw4
    MD5:63B53861D3B24A239AFB15137BB6B6A4
    SHA1:0515A134F11FE231D878D2467DC524B8B73987FC
    SHA-256:28B39B911285639B4EDEF4B8469CFA133C5354CF655CAE5BD752174F6D2E194B
    SHA-512:82C22CF7522D43854C147002B476368F04C2F5367CC70E233CCCFFEB7A27B2C3D9C68F07CDD4F2E904DF86CF3AACD71EC3D42E34A0728AB43CEC9E73D925C839
    Malicious:false
    Reputation:low
    Preview:PK...........V.O3......v......mtrace.cUT...%..d%..dux..............=ks.6...+Pw.J.....CTgG...]Yr%9i&.h(......o'....@.$$+....;.H...s......bW.'.4...E.o.'............J....I*.<..b.....l_..PP.L.2....<.9.. ..`..$F.b.I.."KV.O .,...N,.4.:.6.....&...D.<X...0:.K.X.4..\..2Mn.9.....H....m._.?...v.....d.T.&.^..L$......*....|..7Kn.b.C."N....h.d"......h.".....D2....j.Fc...W..7BH0...<.W..sO... ....@.i..Y)...B6.1I...b..$"..+N..$.P3......4.q..L.........JT..#Jr).E..s@..Q.Y.{fJ.,.[T..e"[J.u....|)jW.z.e...3w,....W..#...h..=qN.........#..l"...g4....<.LF................p~..9....{~.w...0..&.3..wp.<q....0.`8.}..@...x9..b.B.;..3..=w...5....p..0^O\.F......!.....p........{.s./...X8/..D..z.~...3.....>w........'..9. ].c."`...s........U...............'...)...= ...s...O....wr9q..pxB|.;...3..pL...;..d..(...p.Z@..c.x..&.hty1q..6...p.0.A..b.p@4.......!!?H.....W#d/q.......'f3...91.E8...:.c.....+w.Az..w.Pq.W=...hG..n..%M...!.....t.....b.*.!...).]<~..1...V.A..9...a.N,..A...+r
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:ASCII text
    Category:dropped
    Size (bytes):1907
    Entropy (8bit):5.172355085114734
    Encrypted:false
    SSDEEP:48:RyOlrYJErYJFHvv432sDt32sWEtPu3tOHc8IKEC:RPlrYJErYJFPQ3vt3S3488IBC
    MD5:358AFD873A0DCB284D0135F6D152CD08
    SHA1:AC5AACA33647CD7B35A7B4861A57D6F812F2CF71
    SHA-256:EBAA9E405F0CE78EB9D8BDFC1D1D788B8BBE8D6D562A0F180F81D5578D634175
    SHA-512:04161296C42BF7C8DEF3989BE501C9F07D1BEAC60C33AA7E4B70EAEE9903F47AEE06D67E27819F3A6B5F148827A79C95393AB427373FA1ACF4CB6908142903A4
    Malicious:false
    Reputation:low
    Preview:#.# Copyright (c) 2004, 2007, Oracle and/or its affiliates. All rights reserved..#.# Redistribution and use in source and binary forms, with or without.# modification, are permitted provided that the following conditions.# are met:.#.# - Redistributions of source code must retain the above copyright.# notice, this list of conditions and the following disclaimer..#.# - Redistributions in binary form must reproduce the above copyright.# notice, this list of conditions and the following disclaimer in the.# documentation and/or other materials provided with the distribution..#.# - Neither the name of Oracle nor the names of its.# contributors may be used to endorse or promote products derived.# from this software without specific prior written permission..#.# THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS.# IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,.# THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:ASCII text
    Category:dropped
    Size (bytes):1907
    Entropy (8bit):5.172355085114734
    Encrypted:false
    SSDEEP:48:RyOlrYJErYJFHvv432sDt32sWEtPu3tOHc8IKEC:RPlrYJErYJFPQ3vt3S3488IBC
    MD5:358AFD873A0DCB284D0135F6D152CD08
    SHA1:AC5AACA33647CD7B35A7B4861A57D6F812F2CF71
    SHA-256:EBAA9E405F0CE78EB9D8BDFC1D1D788B8BBE8D6D562A0F180F81D5578D634175
    SHA-512:04161296C42BF7C8DEF3989BE501C9F07D1BEAC60C33AA7E4B70EAEE9903F47AEE06D67E27819F3A6B5F148827A79C95393AB427373FA1ACF4CB6908142903A4
    Malicious:false
    Reputation:low
    Preview:#.# Copyright (c) 2004, 2007, Oracle and/or its affiliates. All rights reserved..#.# Redistribution and use in source and binary forms, with or without.# modification, are permitted provided that the following conditions.# are met:.#.# - Redistributions of source code must retain the above copyright.# notice, this list of conditions and the following disclaimer..#.# - Redistributions in binary form must reproduce the above copyright.# notice, this list of conditions and the following disclaimer in the.# documentation and/or other materials provided with the distribution..#.# - Neither the name of Oracle nor the names of its.# contributors may be used to endorse or promote products derived.# from this software without specific prior written permission..#.# THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS.# IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,.# THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Zip archive data, at least v2.0 to extract, compression method=deflate
    Category:dropped
    Size (bytes):10255
    Entropy (8bit):7.9389294340494105
    Encrypted:false
    SSDEEP:192:yfBkIMmaf86NvRw+p5iSdw/jP3vqVPj2q2N31osw5fcL1nI/IGcGCCL:AkNmafHNtiSdw/jPCVPqbwBUpGL
    MD5:4D542A29983FA61A2B529541E9130793
    SHA1:24B3B652C809DEAF411CEC8BCF80579BAFA5E9C0
    SHA-256:7AADFDE8EDEF4785D77B54E98F420C4E8FC0C71C799E5F14E8E835625A55BE25
    SHA-512:3D8BE85F006D592B4C14F42802ED89C3124B5A7EE53707A720F045F7AA7996EAC80E886D3FD014ED46A0403066A07B764BD49404F59C1D67F05527BE7D2BAB18
    Malicious:false
    Reputation:low
    Preview:PK...........V_.......s.......README.txtUT...%..d%..dux..............UMo.6...W.6=l...(...d..Y.+J..T...3..C...........m.S/.D...f8...P.._z.x..}yK?~....?{..EYk*.............._...Y...YW....S].;.fw.L..q:YM.%......E.B..o.G.f8.r..w...t...`...^.Q....].....p(..h..u.l.G*..2|....5z.w..>|G.R...Tv.bOv....W.-v..F...Q....."...x.....+)$-..4...+.......V'.....E.Tu...P.....a...%.MQ.7.]...Z..X.w.#...j.{[v%@g........I_h..w..#.VX..& .t...;h.....#....?l......."{.%.....;.......d..H%...O..y.&k...f[l....6..EF.$.E..C..Y*gy.`..$.;...[..W.P....r.I..?..L...(.e<....'.Er)3.e..X..8H..-E.,...d$.... ...= .O+?.d.G~..U...%..R../."..( -...3R.?....lb..?..k.3...,..l...T...z{.. 8F....$..#>.H....U._s.a.B......Z...y*.L.~.|.2..y...r%....DQ..k...rd.w......D.r%.}2.D..L&.-...;...p.|Nb'.F%....b/\!<.,.vRv.9......u.2...J)`b1..\....q6R.[.M..A9..G....r...Qr..v...J..p-....NPr..g]....09..Ep...$.[U<bJ`..z.WO<.....nMs.-/...L...Z.......i1W....N.hz.../c...h2...{{:.k....X/.....0...;!y.9....
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:current ar archive
    Category:dropped
    Size (bytes):2060
    Entropy (8bit):4.69099084863398
    Encrypted:false
    SSDEEP:24:nfT3XN72T9xBdPWv2ksKgOsryAO3WT+uoksK//y+jU2ksKP9rnHhXn:nJGBdPWv2JKgvyAO34oJKLj9JK1bH9n
    MD5:F5CFD40C2484365F3B012A2BAEEC3D17
    SHA1:4C97418481677B63FE1566C82D8A092683C3B5FB
    SHA-256:7685831FC481786E4FC40CF7924A940CB380008D128907D23A0DFEF51F5F2EEF
    SHA-512:969880977E2FBD38A0BD17AD186E178FBC6AB05C1E1F258DAB4703E030EE704263EAE108D642E1719E169C181E3493C709FE35EA6FAB71F671682AFDEF26B501
    Malicious:false
    Reputation:low
    Preview:!<arch>./ 1689363552 0 188 `........P........................__IMPORT_DESCRIPTOR_versionCheck.__NULL_IMPORT_DESCRIPTOR..versionCheck_NULL_THUNK_DATA.Agent_OnLoad.__imp_Agent_OnLoad.Agent_OnUnload.__imp_Agent_OnUnload./ 1689363552 0 198 `.....P.....................................Agent_OnLoad.Agent_OnUnload.__IMPORT_DESCRIPTOR_versionCheck.__NULL_IMPORT_DESCRIPTOR.__imp_Agent_OnLoad.__imp_Agent_OnUnload..versionCheck_NULL_THUNK_DATA.// 1689363552 0 17 `.versionCheck.dll../0 1689363552 0 514 `.d...`..d.............debug$S........F...................@..B.idata$2............................@.0..idata$6............................@. ..............versionCheck.dll'......................Microsoft (R) LINK..................................................versionCheck.dll..@comp.id.............................idata$2@.......h..idata$6........
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Intel amd64 COFF object file, not stripped, 2 sections, symbol offset=0x2b7, 10 symbols, created Fri Jul 14 19:39:12 2023, 1st section name ".edata"
    Category:dropped
    Size (bytes):907
    Entropy (8bit):4.58800241094702
    Encrypted:false
    SSDEEP:24:go65ad4Na2bBeKPb0d7qymxHxu3g41D/9V:bfd4BbBeKj0d7qtHxuQ41D/v
    MD5:6286C876C8EBE5428F43DE18592B2A87
    SHA1:013C5CEAE954AA1D9FF2533BC840E05AD0A19BF1
    SHA-256:3374DCCA674C5922EE7DCAEA01634C1248F3C4D27809053FE7A5E987925FD869
    SHA-512:CB5F23328516A68A9C7AFA03DB440B3F3494FA2628F7414362567876373F437C7477F5F4A4D7BB29501B1EFB7F8EA7633340596669B8AB4D9B390E6AB454846A
    Malicious:false
    Reputation:low
    Preview:d...`..d.............edata..........i...d...............@..@.debug$S............................@..B....`..d....................................................versionCheck.dll.Agent_OnLoad.Agent_OnUnload...................... .........$.........(.........0.........,.........4.............................c:/wsjdk/Corretto8Src/installers/windows/zip/corretto-build/buildRoot/build/windows-x86_64-normal-server-release/jdk/demoobjs/jvmti/versionCheck/versionCheck.exp.+.<.......................Microsoft (R) LINK...=..cwd.C:\wsjdk\Corretto8Src\installers\windows\zip\corretto-build\buildRoot\jdk\make.exe.c:\progra~2\micros~3.0\vc\bin\amd64\link.exe....8.....Agent_OnLoad...8.....Agent_OnUnload.@comp.id...........edata............szName..<.........rgpv....(.........rgszName0.........rgwOrd..8.........$N00001.M.........$N00002.Z............................................. ...Agent_OnLoad.Agent_OnUnload.
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
    Category:dropped
    Size (bytes):21472
    Entropy (8bit):6.719564204352197
    Encrypted:false
    SSDEEP:384:H9Nqf2pBMLk7TqsqQomAb+XZSf+VIYinvyrtPxh8E9VF0NyvcPQyQ:dNqfLMqrQomAbd/Yin4tPxWEtM0
    MD5:1CB07D6CDF054609E01D80BF959F0927
    SHA1:62ADAF407DEBF7F4A68F07474F37F6A63FD90EBE
    SHA-256:AD53D60DC5527AC1D627E88900CA6B0F9844D3B6BC78F7BF1C717A694C4CE6A6
    SHA-512:5D890E9B8A96B80A75C60E156F05903A1A532938C71D5D89A7752944C4D7E723333680FC840C0F10EF7B988BF5E8F9191B46389062DC42AE6E83981168738D81
    Malicious:false
    Antivirus:
    • Antivirus: ReversingLabs, Detection: 0%
    Reputation:low
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......v...2og.2og.2og...0og.2of..og.t>..1og.t>..3og.t>..9og.t>..0og...0og...3og.?=..3og...3og.Rich2og.........................PE..d...`..d.........." ................D........................................p...........`.........................................p%..i....%..<....P.......@.. ....$.../...`......@!..8............................"..p............ ...............................text............................... ..`.rdata..h.... ......................@..@.data........0......................@....pdata.. ....@......................@..@.rsrc........P......................@..@.reloc.......`......."..............@..B................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:MSVC program database ver 7.00, 4096*79 bytes
    Category:dropped
    Size (bytes):323584
    Entropy (8bit):4.564316215031779
    Encrypted:false
    SSDEEP:6144:bx0BqbM2pDfMYXBvMH4boNVEEvTpamymuCwXpOA/CLj7Hrqc:dnREZdrr
    MD5:79115DAE5C6510953F67177819206CAD
    SHA1:FCDFE8AF518A579B52326A022CDB25F1D97B4587
    SHA-256:1F97BA6FF5CC6593C148BAA2DD4D489D598AFDCCA0203F9674E0FDE8BB83A06F
    SHA-512:3F7DAD4E693443E81C255D68382EB64B8E3A953BB941EB26DD6588D5BF13BBBC8259394CD501A88AC4C1DF74F7FBEBB7DA42EE905F62EADEE921A096C8432C83
    Malicious:false
    Reputation:low
    Preview:Microsoft C/C++ MSF 7.00...DS...........O...........N...................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
    Category:dropped
    Size (bytes):21472
    Entropy (8bit):6.719564204352197
    Encrypted:false
    SSDEEP:384:H9Nqf2pBMLk7TqsqQomAb+XZSf+VIYinvyrtPxh8E9VF0NyvcPQyQ:dNqfLMqrQomAbd/Yin4tPxWEtM0
    MD5:1CB07D6CDF054609E01D80BF959F0927
    SHA1:62ADAF407DEBF7F4A68F07474F37F6A63FD90EBE
    SHA-256:AD53D60DC5527AC1D627E88900CA6B0F9844D3B6BC78F7BF1C717A694C4CE6A6
    SHA-512:5D890E9B8A96B80A75C60E156F05903A1A532938C71D5D89A7752944C4D7E723333680FC840C0F10EF7B988BF5E8F9191B46389062DC42AE6E83981168738D81
    Malicious:false
    Antivirus:
    • Antivirus: ReversingLabs, Detection: 0%
    Reputation:low
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......v...2og.2og.2og...0og.2of..og.t>..1og.t>..3og.t>..9og.t>..0og...0og...3og.?=..3og...3og.Rich2og.........................PE..d...`..d.........." ................D........................................p...........`.........................................p%..i....%..<....P.......@.. ....$.../...`......@!..8............................"..p............ ...............................text............................... ..`.rdata..h.... ......................@..@.data........0......................@....pdata.. ....@......................@..@.rsrc........P......................@..@.reloc.......`......."..............@..B................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Intel amd64 COFF object file, not stripped, 2 sections, symbol offset=0x2b7, 10 symbols, created Fri Jul 14 19:39:12 2023, 1st section name ".edata"
    Category:dropped
    Size (bytes):907
    Entropy (8bit):4.58800241094702
    Encrypted:false
    SSDEEP:24:go65ad4Na2bBeKPb0d7qymxHxu3g41D/9V:bfd4BbBeKj0d7qtHxuQ41D/v
    MD5:6286C876C8EBE5428F43DE18592B2A87
    SHA1:013C5CEAE954AA1D9FF2533BC840E05AD0A19BF1
    SHA-256:3374DCCA674C5922EE7DCAEA01634C1248F3C4D27809053FE7A5E987925FD869
    SHA-512:CB5F23328516A68A9C7AFA03DB440B3F3494FA2628F7414362567876373F437C7477F5F4A4D7BB29501B1EFB7F8EA7633340596669B8AB4D9B390E6AB454846A
    Malicious:false
    Reputation:low
    Preview:d...`..d.............edata..........i...d...............@..@.debug$S............................@..B....`..d....................................................versionCheck.dll.Agent_OnLoad.Agent_OnUnload...................... .........$.........(.........0.........,.........4.............................c:/wsjdk/Corretto8Src/installers/windows/zip/corretto-build/buildRoot/build/windows-x86_64-normal-server-release/jdk/demoobjs/jvmti/versionCheck/versionCheck.exp.+.<.......................Microsoft (R) LINK...=..cwd.C:\wsjdk\Corretto8Src\installers\windows\zip\corretto-build\buildRoot\jdk\make.exe.c:\progra~2\micros~3.0\vc\bin\amd64\link.exe....8.....Agent_OnLoad...8.....Agent_OnUnload.@comp.id...........edata............szName..<.........rgpv....(.........rgszName0.........rgwOrd..8.........$N00001.M.........$N00002.Z............................................. ...Agent_OnLoad.Agent_OnUnload.
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:current ar archive
    Category:dropped
    Size (bytes):2060
    Entropy (8bit):4.69099084863398
    Encrypted:false
    SSDEEP:24:nfT3XN72T9xBdPWv2ksKgOsryAO3WT+uoksK//y+jU2ksKP9rnHhXn:nJGBdPWv2JKgvyAO34oJKLj9JK1bH9n
    MD5:F5CFD40C2484365F3B012A2BAEEC3D17
    SHA1:4C97418481677B63FE1566C82D8A092683C3B5FB
    SHA-256:7685831FC481786E4FC40CF7924A940CB380008D128907D23A0DFEF51F5F2EEF
    SHA-512:969880977E2FBD38A0BD17AD186E178FBC6AB05C1E1F258DAB4703E030EE704263EAE108D642E1719E169C181E3493C709FE35EA6FAB71F671682AFDEF26B501
    Malicious:false
    Reputation:low
    Preview:!<arch>./ 1689363552 0 188 `........P........................__IMPORT_DESCRIPTOR_versionCheck.__NULL_IMPORT_DESCRIPTOR..versionCheck_NULL_THUNK_DATA.Agent_OnLoad.__imp_Agent_OnLoad.Agent_OnUnload.__imp_Agent_OnUnload./ 1689363552 0 198 `.....P.....................................Agent_OnLoad.Agent_OnUnload.__IMPORT_DESCRIPTOR_versionCheck.__NULL_IMPORT_DESCRIPTOR.__imp_Agent_OnLoad.__imp_Agent_OnUnload..versionCheck_NULL_THUNK_DATA.// 1689363552 0 17 `.versionCheck.dll../0 1689363552 0 514 `.d...`..d.............debug$S........F...................@..B.idata$2............................@.0..idata$6............................@. ..............versionCheck.dll'......................Microsoft (R) LINK..................................................versionCheck.dll..@comp.id.............................idata$2@.......h..idata$6........
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:MSVC program database ver 7.00, 4096*79 bytes
    Category:dropped
    Size (bytes):323584
    Entropy (8bit):4.564316215031779
    Encrypted:false
    SSDEEP:6144:bx0BqbM2pDfMYXBvMH4boNVEEvTpamymuCwXpOA/CLj7Hrqc:dnREZdrr
    MD5:79115DAE5C6510953F67177819206CAD
    SHA1:FCDFE8AF518A579B52326A022CDB25F1D97B4587
    SHA-256:1F97BA6FF5CC6593C148BAA2DD4D489D598AFDCCA0203F9674E0FDE8BB83A06F
    SHA-512:3F7DAD4E693443E81C255D68382EB64B8E3A953BB941EB26DD6588D5BF13BBBC8259394CD501A88AC4C1DF74F7FBEBB7DA42EE905F62EADEE921A096C8432C83
    Malicious:false
    Reputation:low
    Preview:Microsoft C/C++ MSF 7.00...DS...........O...........N...................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Zip archive data, at least v2.0 to extract, compression method=deflate
    Category:dropped
    Size (bytes):10255
    Entropy (8bit):7.9389294340494105
    Encrypted:false
    SSDEEP:192:yfBkIMmaf86NvRw+p5iSdw/jP3vqVPj2q2N31osw5fcL1nI/IGcGCCL:AkNmafHNtiSdw/jPCVPqbwBUpGL
    MD5:4D542A29983FA61A2B529541E9130793
    SHA1:24B3B652C809DEAF411CEC8BCF80579BAFA5E9C0
    SHA-256:7AADFDE8EDEF4785D77B54E98F420C4E8FC0C71C799E5F14E8E835625A55BE25
    SHA-512:3D8BE85F006D592B4C14F42802ED89C3124B5A7EE53707A720F045F7AA7996EAC80E886D3FD014ED46A0403066A07B764BD49404F59C1D67F05527BE7D2BAB18
    Malicious:false
    Reputation:low
    Preview:PK...........V_.......s.......README.txtUT...%..d%..dux..............UMo.6...W.6=l...(...d..Y.+J..T...3..C...........m.S/.D...f8...P.._z.x..}yK?~....?{..EYk*.............._...Y...YW....S].;.fw.L..q:YM.%......E.B..o.G.f8.r..w...t...`...^.Q....].....p(..h..u.l.G*..2|....5z.w..>|G.R...Tv.bOv....W.-v..F...Q....."...x.....+)$-..4...+.......V'.....E.Tu...P.....a...%.MQ.7.]...Z..X.w.#...j.{[v%@g........I_h..w..#.VX..& .t...;h.....#....?l......."{.%.....;.......d..H%...O..y.&k...f[l....6..EF.$.E..C..Y*gy.`..$.;...[..W.P....r.I..?..L...(.e<....'.Er)3.e..X..8H..-E.,...d$.... ...= .O+?.d.G~..U...%..R../."..( -...3R.?....lb..?..k.3...,..l...T...z{.. 8F....$..#>.H....U._s.a.B......Z...y*.L.~.|.2..y...r%....DQ..k...rd.w......D.r%.}2.D..L&.-...;...p.|Nb'.F%....b/\!<.,.vRv.9......u.2...J)`b1..\....q6R.[.M..A9..G....r...Qr..v...J..p-....NPr..g]....09..Ep...$.[U<bJ`..z.WO<.....nMs.-/...L...Z.......i1W....N.hz.../c...h2...{{:.k....X/.....0...;!y.9....
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:ASCII text
    Category:dropped
    Size (bytes):1912
    Entropy (8bit):5.170916550798276
    Encrypted:false
    SSDEEP:48:RyOlrYJErYJFHvv432sDt32sWEtPu3tOH9Rm6GfwhC:RPlrYJErYJFPQ3vt3S34XmbWC
    MD5:3DA6DA5B71B4E3D4E1093E34F7E67FB8
    SHA1:F2DC138E9164F0BE2F10D04831D60539F759BC3C
    SHA-256:468FE17D137FD990BB51F75860E8953A0EEDD2AC0C106CF4CAA4F39C1511DEE5
    SHA-512:4C800B2201BDD1354A647B434498A1AD591814AE456C6CBBE125D59D1F432606959CA15CDB5A8D1CD8B10BC1C68EA56616AD34753E38A64D4354E65BBECEDA3D
    Malicious:false
    Reputation:low
    Preview:#.# Copyright (c) 2004, 2007, Oracle and/or its affiliates. All rights reserved..#.# Redistribution and use in source and binary forms, with or without.# modification, are permitted provided that the following conditions.# are met:.#.# - Redistributions of source code must retain the above copyright.# notice, this list of conditions and the following disclaimer..#.# - Redistributions in binary form must reproduce the above copyright.# notice, this list of conditions and the following disclaimer in the.# documentation and/or other materials provided with the distribution..#.# - Neither the name of Oracle nor the names of its.# contributors may be used to endorse or promote products derived.# from this software without specific prior written permission..#.# THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS.# IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,.# THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:ASCII text
    Category:dropped
    Size (bytes):1912
    Entropy (8bit):5.170916550798276
    Encrypted:false
    SSDEEP:48:RyOlrYJErYJFHvv432sDt32sWEtPu3tOH9Rm6GfwhC:RPlrYJErYJFPQ3vt3S34XmbWC
    MD5:3DA6DA5B71B4E3D4E1093E34F7E67FB8
    SHA1:F2DC138E9164F0BE2F10D04831D60539F759BC3C
    SHA-256:468FE17D137FD990BB51F75860E8953A0EEDD2AC0C106CF4CAA4F39C1511DEE5
    SHA-512:4C800B2201BDD1354A647B434498A1AD591814AE456C6CBBE125D59D1F432606959CA15CDB5A8D1CD8B10BC1C68EA56616AD34753E38A64D4354E65BBECEDA3D
    Malicious:false
    Reputation:low
    Preview:#.# Copyright (c) 2004, 2007, Oracle and/or its affiliates. All rights reserved..#.# Redistribution and use in source and binary forms, with or without.# modification, are permitted provided that the following conditions.# are met:.#.# - Redistributions of source code must retain the above copyright.# notice, this list of conditions and the following disclaimer..#.# - Redistributions in binary form must reproduce the above copyright.# notice, this list of conditions and the following disclaimer in the.# documentation and/or other materials provided with the distribution..#.# - Neither the name of Oracle nor the names of its.# contributors may be used to endorse or promote products derived.# from this software without specific prior written permission..#.# THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS.# IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,.# THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Zip archive data, at least v2.0 to extract, compression method=deflate
    Category:dropped
    Size (bytes):20955
    Entropy (8bit):7.945333524159474
    Encrypted:false
    SSDEEP:384:rTYRF6ps8SGLB5qXfzjz9RaB6SZPFCGBUpGtuG:pO8SsfqvzjF6bBUpGtl
    MD5:C69F4110EBEF911D3BC38B66C5B54269
    SHA1:9E57CF13036CCA035FCB2A030865855A5556329F
    SHA-256:87CCB586111720E7DF87710F18999B19978D9762814A8468821FD9B1482B53C7
    SHA-512:18B036E9C2377AD366FFD296B529C38CA2218E397E405DC171DE212A779D7614BE87B0E3AF473BD87123D15B41097DBE467006357A16B0593333CBCCB7A64695
    Malicious:false
    Reputation:low
    Preview:PK...........V09..x...........Agent.cppUT...%..d%..dux..............Y.n.H.}.W.......d.O...Z.m.t.=.n .dKb....lx..o.S.M..|I&..Kd......j..w@=.d..<Z.J..]...?......Ms?...ix.......E.G~).>.qLR..\."..a..X.#.(..nSFY..hS..R*.M.H.t..~.H.,O....rEX...M.Z.,..Q....\.Z.IT.".u..G!.._.K@O.g.Q.. K.....r.(.i..v.+([Tv.Y....K..{Y.....#...B.fe...S..b(d=....aX5..(.y..k.j....8.n`..2.....0.6.HK.... ...D?....c c...4]..H...O....f....hVY...,/..#......H.!F.S.v$Y)HA.:.0.l..,.\.Rd....YF.Z..1.FL...*..E....v..{7.c.....=..tv.....W..}q...t4..........f......l.P>3'.d.~.X.KS.....>,....\...`4......&S.F...0......I....r...5.....%.mo..c=..L.......s5u-b...;.......F`a....G.9...;..X.<......k.....C....U_.."....^Y.......W.sk06P.Z..a.......p..:<..`.Xc.....3...g..t:....sm.,..FSW"7s-..x..... ...~6sm..=.,.]y.t.E.o..,5!=.`O'.g.5un..51.2...\Zx.0..5..p...kN...k8.z&....&..'LY..Z]D.}.....1..L..A.m..L..l..}N...f..|..5.$|.K.>......J..[u........1.X..!S}S.KY.|Z"OSZ.....p5..*.>m......=&."...+.....u..
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:current ar archive
    Category:dropped
    Size (bytes):1918
    Entropy (8bit):4.693554637407265
    Encrypted:false
    SSDEEP:24:3OeuiXPY72u9yjM2XKKwsryAO6ujjaZUK//yhq0qkKP7LO6:+nAM2XKKwUyAOIZUKX0qkKZ
    MD5:610F286AF73A98827119307F7F4B77C0
    SHA1:2D2BA1AF01EBBB561840380F1F64530700971B8F
    SHA-256:43ABFC116A4FFF9A226FE67A3C22826895E04BA9801548E8612009B006EFE6CF
    SHA-512:46CDEEF62FDEDC289D95857F01725F57CDA7F9DFFC0880EF64EA739C03B6CF538176B8ED5A9144CCD314C5388BE123EE5EB95CB435614252312F0A3025B5939D
    Malicious:false
    Reputation:low
    Preview:!<arch>./ 1689363552 0 178 `................N................__IMPORT_DESCRIPTOR_waiters.__NULL_IMPORT_DESCRIPTOR..waiters_NULL_THUNK_DATA.Agent_OnLoad.__imp_Agent_OnLoad.Agent_OnUnload.__imp_Agent_OnUnload./ 1689363552 0 188 `.............N.............................Agent_OnLoad.Agent_OnUnload.__IMPORT_DESCRIPTOR_waiters.__NULL_IMPORT_DESCRIPTOR.__imp_Agent_OnLoad.__imp_Agent_OnUnload..waiters_NULL_THUNK_DATA.waiters.dll/ 1689363552 0 493 `.d...`..d.............debug$S........A...................@..B.idata$2............................@.0..idata$6............................@. ..............waiters.dll'......................Microsoft (R) LINK..................................................waiters.dll.@comp.id.............................idata$2@.......h..idata$6...........idata$4@.......h..idata$5@.......h..... .................9.............R...__IMPORT_DESCRIPTOR_waiters.__N
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
    Category:dropped
    Size (bytes):27144
    Entropy (8bit):6.557705555745941
    Encrypted:false
    SSDEEP:384:gIuLlNClyGrzRsOSRtIVKi8TSsaXJ28EZSf+VIYinvy8ViMPxh8E9VF0Nyvy:VuP5GrVJVKbS5XJ28j/Yin7XPxWEt
    MD5:C448267CF8CD43D8B06259780CBB336B
    SHA1:401166ADBD1851E3E1054DF69C463147FBD1B9C9
    SHA-256:289F27FDB039D544741983511E38E6701DE9279DA9212D102BC254ABF7210FB1
    SHA-512:2E941EA7507E687F67D01BE4928F3DE09DADAFC68B4BC8B54228220C6A9DB5020CC8475D27DAC5586795B5C2BEE629F3686243DA06C774E5DC9D84E6953CD23D
    Malicious:false
    Antivirus:
    • Antivirus: ReversingLabs, Detection: 0%
    Reputation:low
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......\|....@...@...@.....@...A.3.@.^L....@.^L....@.^L....@.^L....@.......@.......@.......@..O....@.......@.Rich..@.........PE..d...`..d.........." .................#..............................................#.....`..........................................8..d...d8..<....`.......P..L....:...0...p......p1..8............................4..p............0..8............................text...{........................... ..`.rdata..j....0....... ..............@..@.data........@......................@....pdata..L....P.......0..............@..@.rsrc........`.......4..............@..@.reloc.......p.......8..............@..B........................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Intel amd64 COFF object file, not stripped, 2 sections, symbol offset=0x2a7, 10 symbols, created Fri Jul 14 19:39:12 2023, 1st section name ".edata"
    Category:dropped
    Size (bytes):891
    Entropy (8bit):4.543724211434498
    Encrypted:false
    SSDEEP:24:g0A7aUSlN4Na2gQeKPb0d7qymxHxu3g41G2n9V:VRUSlN4BgQeKj0d7qtHxuQ41G2nv
    MD5:C6321C6D5244E2F990C1E0ECACE1341D
    SHA1:B5253DABE24AC278DA56EB1D47F0FCB5ECD3A17C
    SHA-256:0E95C0EAAF165B6DFF4655F670BF5E46DF4CA313D0FE834351C5776C012B4AF8
    SHA-512:878D021A13C3EC55ED4D4A7D81A611F24DA4B48D55016D6D5A1998AD7DC0221A3636D63D31EE50AFF345223DE64B28BB26E7096D2B84B597100E649F8F2384C9
    Malicious:false
    Reputation:low
    Preview:d...`..d.............edata..........d...d...............@..@.debug$S............................@..B....`..d....................................................waiters.dll.Agent_OnLoad.Agent_OnUnload..................... .........$.........(.........0.........,.........4.............................c:/wsjdk/Corretto8Src/installers/windows/zip/corretto-build/buildRoot/build/windows-x86_64-normal-server-release/jdk/demoobjs/jvmti/waiters/waiters.exp.+.<.......................Microsoft (R) LINK...=..cwd.C:\wsjdk\Corretto8Src\installers\windows\zip\corretto-build\buildRoot\jdk\make.exe.c:\progra~2\micros~3.0\vc\bin\amd64\link.exe....8.....Agent_OnLoad...8.....Agent_OnUnload.@comp.id...........edata............szName..<.........rgpv....(.........rgszName0.........rgwOrd..8.........$N00001.H.........$N00002.U............................................. ...Agent_OnLoad.Agent_OnUnload.
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:MSVC program database ver 7.00, 4096*107 bytes
    Category:dropped
    Size (bytes):438272
    Entropy (8bit):4.648184109013776
    Encrypted:false
    SSDEEP:6144:eML5rb9Jc8vIZ7CwvBv9diB2v9ge3HRjUsLbFg+nQ2QevkZFR2jyyRzW3lLwdWgq:RsbxqNPMDJKL
    MD5:C6404350D9069AE3AB7ABAA7705DCB61
    SHA1:D0C5949F0B709C6E0D86DA513DF455FD150B02A6
    SHA-256:77C136466B6D2910594DCA25EB584AB097B5A7FF43D4609D183D1D99340562CE
    SHA-512:917C94B7AFF089246C50E397511D1F38AA331D94DE5B734E617D4517CFB920CF1BA650D8D63803313FF7B04409BA71C4ABFBB36CDBBE5218E8D911ABB5E199D3
    Malicious:false
    Reputation:low
    Preview:Microsoft C/C++ MSF 7.00...DS...........k...(.......i...................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
    Category:dropped
    Size (bytes):27144
    Entropy (8bit):6.557705555745941
    Encrypted:false
    SSDEEP:384:gIuLlNClyGrzRsOSRtIVKi8TSsaXJ28EZSf+VIYinvy8ViMPxh8E9VF0Nyvy:VuP5GrVJVKbS5XJ28j/Yin7XPxWEt
    MD5:C448267CF8CD43D8B06259780CBB336B
    SHA1:401166ADBD1851E3E1054DF69C463147FBD1B9C9
    SHA-256:289F27FDB039D544741983511E38E6701DE9279DA9212D102BC254ABF7210FB1
    SHA-512:2E941EA7507E687F67D01BE4928F3DE09DADAFC68B4BC8B54228220C6A9DB5020CC8475D27DAC5586795B5C2BEE629F3686243DA06C774E5DC9D84E6953CD23D
    Malicious:false
    Antivirus:
    • Antivirus: ReversingLabs, Detection: 0%
    Reputation:low
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......\|....@...@...@.....@...A.3.@.^L....@.^L....@.^L....@.^L....@.......@.......@.......@..O....@.......@.Rich..@.........PE..d...`..d.........." .................#..............................................#.....`..........................................8..d...d8..<....`.......P..L....:...0...p......p1..8............................4..p............0..8............................text...{........................... ..`.rdata..j....0....... ..............@..@.data........@......................@....pdata..L....P.......0..............@..@.rsrc........`.......4..............@..@.reloc.......p.......8..............@..B........................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Intel amd64 COFF object file, not stripped, 2 sections, symbol offset=0x2a7, 10 symbols, created Fri Jul 14 19:39:12 2023, 1st section name ".edata"
    Category:dropped
    Size (bytes):891
    Entropy (8bit):4.543724211434498
    Encrypted:false
    SSDEEP:24:g0A7aUSlN4Na2gQeKPb0d7qymxHxu3g41G2n9V:VRUSlN4BgQeKj0d7qtHxuQ41G2nv
    MD5:C6321C6D5244E2F990C1E0ECACE1341D
    SHA1:B5253DABE24AC278DA56EB1D47F0FCB5ECD3A17C
    SHA-256:0E95C0EAAF165B6DFF4655F670BF5E46DF4CA313D0FE834351C5776C012B4AF8
    SHA-512:878D021A13C3EC55ED4D4A7D81A611F24DA4B48D55016D6D5A1998AD7DC0221A3636D63D31EE50AFF345223DE64B28BB26E7096D2B84B597100E649F8F2384C9
    Malicious:false
    Reputation:low
    Preview:d...`..d.............edata..........d...d...............@..@.debug$S............................@..B....`..d....................................................waiters.dll.Agent_OnLoad.Agent_OnUnload..................... .........$.........(.........0.........,.........4.............................c:/wsjdk/Corretto8Src/installers/windows/zip/corretto-build/buildRoot/build/windows-x86_64-normal-server-release/jdk/demoobjs/jvmti/waiters/waiters.exp.+.<.......................Microsoft (R) LINK...=..cwd.C:\wsjdk\Corretto8Src\installers\windows\zip\corretto-build\buildRoot\jdk\make.exe.c:\progra~2\micros~3.0\vc\bin\amd64\link.exe....8.....Agent_OnLoad...8.....Agent_OnUnload.@comp.id...........edata............szName..<.........rgpv....(.........rgszName0.........rgwOrd..8.........$N00001.H.........$N00002.U............................................. ...Agent_OnLoad.Agent_OnUnload.
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:current ar archive
    Category:dropped
    Size (bytes):1918
    Entropy (8bit):4.693554637407265
    Encrypted:false
    SSDEEP:24:3OeuiXPY72u9yjM2XKKwsryAO6ujjaZUK//yhq0qkKP7LO6:+nAM2XKKwUyAOIZUKX0qkKZ
    MD5:610F286AF73A98827119307F7F4B77C0
    SHA1:2D2BA1AF01EBBB561840380F1F64530700971B8F
    SHA-256:43ABFC116A4FFF9A226FE67A3C22826895E04BA9801548E8612009B006EFE6CF
    SHA-512:46CDEEF62FDEDC289D95857F01725F57CDA7F9DFFC0880EF64EA739C03B6CF538176B8ED5A9144CCD314C5388BE123EE5EB95CB435614252312F0A3025B5939D
    Malicious:false
    Reputation:low
    Preview:!<arch>./ 1689363552 0 178 `................N................__IMPORT_DESCRIPTOR_waiters.__NULL_IMPORT_DESCRIPTOR..waiters_NULL_THUNK_DATA.Agent_OnLoad.__imp_Agent_OnLoad.Agent_OnUnload.__imp_Agent_OnUnload./ 1689363552 0 188 `.............N.............................Agent_OnLoad.Agent_OnUnload.__IMPORT_DESCRIPTOR_waiters.__NULL_IMPORT_DESCRIPTOR.__imp_Agent_OnLoad.__imp_Agent_OnUnload..waiters_NULL_THUNK_DATA.waiters.dll/ 1689363552 0 493 `.d...`..d.............debug$S........A...................@..B.idata$2............................@.0..idata$6............................@. ..............waiters.dll'......................Microsoft (R) LINK..................................................waiters.dll.@comp.id.............................idata$2@.......h..idata$6...........idata$4@.......h..idata$5@.......h..... .................9.............R...__IMPORT_DESCRIPTOR_waiters.__N
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:MSVC program database ver 7.00, 4096*107 bytes
    Category:dropped
    Size (bytes):438272
    Entropy (8bit):4.648184109013776
    Encrypted:false
    SSDEEP:6144:eML5rb9Jc8vIZ7CwvBv9diB2v9ge3HRjUsLbFg+nQ2QevkZFR2jyyRzW3lLwdWgq:RsbxqNPMDJKL
    MD5:C6404350D9069AE3AB7ABAA7705DCB61
    SHA1:D0C5949F0B709C6E0D86DA513DF455FD150B02A6
    SHA-256:77C136466B6D2910594DCA25EB584AB097B5A7FF43D4609D183D1D99340562CE
    SHA-512:917C94B7AFF089246C50E397511D1F38AA331D94DE5B734E617D4517CFB920CF1BA650D8D63803313FF7B04409BA71C4ABFBB36CDBBE5218E8D911ABB5E199D3
    Malicious:false
    Reputation:low
    Preview:Microsoft C/C++ MSF 7.00...DS...........k...(.......i...................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Zip archive data, at least v2.0 to extract, compression method=deflate
    Category:dropped
    Size (bytes):20955
    Entropy (8bit):7.945333524159474
    Encrypted:false
    SSDEEP:384:rTYRF6ps8SGLB5qXfzjz9RaB6SZPFCGBUpGtuG:pO8SsfqvzjF6bBUpGtl
    MD5:C69F4110EBEF911D3BC38B66C5B54269
    SHA1:9E57CF13036CCA035FCB2A030865855A5556329F
    SHA-256:87CCB586111720E7DF87710F18999B19978D9762814A8468821FD9B1482B53C7
    SHA-512:18B036E9C2377AD366FFD296B529C38CA2218E397E405DC171DE212A779D7614BE87B0E3AF473BD87123D15B41097DBE467006357A16B0593333CBCCB7A64695
    Malicious:false
    Reputation:low
    Preview:PK...........V09..x...........Agent.cppUT...%..d%..dux..............Y.n.H.}.W.......d.O...Z.m.t.=.n .dKb....lx..o.S.M..|I&..Kd......j..w@=.d..<Z.J..]...?......Ms?...ix.......E.G~).>.qLR..\."..a..X.#.(..nSFY..hS..R*.M.H.t..~.H.,O....rEX...M.Z.,..Q....\.Z.IT.".u..G!.._.K@O.g.Q.. K.....r.(.i..v.+([Tv.Y....K..{Y.....#...B.fe...S..b(d=....aX5..(.y..k.j....8.n`..2.....0.6.HK.... ...D?....c c...4]..H...O....f....hVY...,/..#......H.!F.S.v$Y)HA.:.0.l..,.\.Rd....YF.Z..1.FL...*..E....v..{7.c.....=..tv.....W..}q...t4..........f......l.P>3'.d.~.X.KS.....>,....\...`4......&S.F...0......I....r...5.....%.mo..c=..L.......s5u-b...;.......F`a....G.9...;..X.<......k.....C....U_.."....^Y.......W.sk06P.Z..a.......p..:<..`.Xc.....3...g..t:....sm.,..FSW"7s-..x..... ...~6sm..=.,.]y.t.E.o..,5!=.`O'.g.5un..51.2...\Zx.0..5..p...kN...k8.z&....&..'LY..Z]D.}.....1..L..A.m..L..l..}N...f..|..5.$|.K.>......J..[u........1.X..!S}S.KY.|Z"OSZ.....p5..*.>m......=&."...+.....u..
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java archive data (JAR)
    Category:dropped
    Size (bytes):9644
    Entropy (8bit):7.873235391371468
    Encrypted:false
    SSDEEP:192:vXDQDkkfCtpVGssQsWKS7sS8i+JPuZq+iMIuAw9BV41VxnDx:rSlqtpV3sQz8XuZq3DzGB+1Z
    MD5:DBF96996027AE6EBB2AFC66A5A35B5C9
    SHA1:7CD5C82DA6A8869FF87BCDA59C20D73D6E8E34ED
    SHA-256:2A0B3682B59F63B499C4209F2F2FE943FC19A3CED6EB8C8690E78D8F02B783F9
    SHA-512:9CD4C2F56B7615AE0F7B145057261FDBCD8E64D794897014A6DA0D021E28E4A198B0A96A1C9C209FDECF89F181522AD2C6D38DD96A98F460E3D671B4BAE737A7
    Malicious:false
    Reputation:low
    Preview:PK..........V................META-INF/......PK..............PK..........V................META-INF/MANIFEST.MFm....0.E....,u.Ru.t.U..(*neH..H&%M..z_.v;.p.9.....|.....)r[.......mt0...........>h.....oe.8...])..)]j. .p>..Ge.2.+.o.7...4.J.-..9|`../.)2O...F.R......X9.9......(..5G...Na...._..qc+).8.PK..b..z....U...PK..........V................Deadlock$DeadlockThread.class.V.O.e...{.2;..z.J......b[j..V.]..[..0.0.;...)......j...&F.j.=.Ml.R.#?X...@A..x..}...=.,7......0Y..<.`...S. ].... ........(.EJA.}2.(......Q.......B.q.."8............<)NOE....xV.&!......6..SZ.s.LR.-.s..r..5.L.v.uwJ.fmk..!.r.L.v$.=.e8].-.7..jR..mX.o+.t..h.{y....%H'$..Q3.m...dB..>.V.%h.yq.bF.F...cZ#.+.^Q...qu.....i.}^v.p....%]..|I.K%.}..,.8W...>..r...<.!...l..V.r....%!.-x+.o..V.....zJ..9.q...+.......U..P..*...........]hS..m2.W1"....c2.Ud...0_...5.....I...m....."...........Ss..p.......I...r.\3k..$...^f...F.....Q.1ZU< L...N.....H...pUx8E....3...N...F...W.....Y..>..j.i..../.=24f.:.t...lZa.9
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:ASCII text
    Category:dropped
    Size (bytes):2019
    Entropy (8bit):4.772815672113362
    Encrypted:false
    SSDEEP:48:J97PMiUB9p7G70WIYS503wrUNj4petIAQbWFIC4:JYS3Xcd
    MD5:DAE0753DD8AE51B9B4AA87A8E8DCB6CF
    SHA1:42799A27219162514D5605D66526DF54EEAB7F67
    SHA-256:899CEE7228B94D82B92D4ABA41A34E66394C0BD08C20DCB61043F1623CC5B557
    SHA-512:3A96148C999B0461016D5E8E25154108F41DA518B7B15428D3FF29F7457CAE362106E8198BBF3970417272382BC680E509607BF4E5E60938A3E960B4BCD0B8F5
    Malicious:false
    Reputation:low
    Preview:FullThreadDump demonstrates the use of the java.lang.management API .to print the full thread dump. JDK 6 defines a new API to dump.the information about monitors and java.util.concurrent ownable.synchronizers...This demo also illustrates how to monitor JDK 5 and JDK 6 VMs with.two versions of APIs...It contains two parts: .a) Local monitoring within the application.b) Remote monitoring by connecting to a JMX agent with a JMX service URL:. service:jmx:rmi:///jndi/rmi://<hostName>:<portNum>/jmxrmi. where <hostName> is the hostname and <portNum> is the port number. to which the JMX agent will be connected...To run the demo.---------------.a) Local Monitoring.. java -cp <JDK_HOME>/demo/management/FullThreadDump/FullThreadDump.jar Deadlock.. This will dump the stack trace and then detect deadlocks locally. within the application...b) Remote Monitoring.. (1) Start the Deadlock application (or any other application) . with the JMX agent as follows:. . java -Dcom.
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:ASCII text
    Category:dropped
    Size (bytes):2019
    Entropy (8bit):4.772815672113362
    Encrypted:false
    SSDEEP:48:J97PMiUB9p7G70WIYS503wrUNj4petIAQbWFIC4:JYS3Xcd
    MD5:DAE0753DD8AE51B9B4AA87A8E8DCB6CF
    SHA1:42799A27219162514D5605D66526DF54EEAB7F67
    SHA-256:899CEE7228B94D82B92D4ABA41A34E66394C0BD08C20DCB61043F1623CC5B557
    SHA-512:3A96148C999B0461016D5E8E25154108F41DA518B7B15428D3FF29F7457CAE362106E8198BBF3970417272382BC680E509607BF4E5E60938A3E960B4BCD0B8F5
    Malicious:false
    Reputation:low
    Preview:FullThreadDump demonstrates the use of the java.lang.management API .to print the full thread dump. JDK 6 defines a new API to dump.the information about monitors and java.util.concurrent ownable.synchronizers...This demo also illustrates how to monitor JDK 5 and JDK 6 VMs with.two versions of APIs...It contains two parts: .a) Local monitoring within the application.b) Remote monitoring by connecting to a JMX agent with a JMX service URL:. service:jmx:rmi:///jndi/rmi://<hostName>:<portNum>/jmxrmi. where <hostName> is the hostname and <portNum> is the port number. to which the JMX agent will be connected...To run the demo.---------------.a) Local Monitoring.. java -cp <JDK_HOME>/demo/management/FullThreadDump/FullThreadDump.jar Deadlock.. This will dump the stack trace and then detect deadlocks locally. within the application...b) Remote Monitoring.. (1) Start the Deadlock application (or any other application) . with the JMX agent as follows:. . java -Dcom.
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Zip archive data, at least v2.0 to extract, compression method=deflate
    Category:dropped
    Size (bytes):8351
    Entropy (8bit):7.941234216292513
    Encrypted:false
    SSDEEP:192:ssNBCL5P2e6GPAiemai+JPpfgDo3ZKSUSbp:s24LIe6GPAsaXpmYgSF
    MD5:8FFD4BC885E5A88ABD26B1BE51E940CE
    SHA1:20ADAFD6DB1CB449B448765B80952FF344A33C06
    SHA-256:5EC01DAC414B3D89080286500285DE00F1B62ADBCA1AB905CA712A89A3E769A3
    SHA-512:DB49429A4F1F8357D977A0ADFAD89C99437A68B016B0452939889B6B2AA1E0CD4088873C9453C3646276B553B6F89ED19C185C0D76ADD6453E53C56081DA0CE7
    Malicious:false
    Reputation:low
    Preview:PK...........V...............Deadlock.javaUT...%..d%..dux..............XKw.H...W.....d.I.....9.P......%.&...v......X.!;.y.Z...{..~.....G.$..T.,r...trt......>9.."I"....T....U.D.3..(".Q*3......C.2TY..Y..$f.*2I*.,).@C.L."..y...>.|A.....e..j....}....L.*.eH.4.U!n...%..E..o(H.P1S.(....jD/[.e..k..$.u..0)....,...M%.Q..*.}...".2.Z..qS1H."..25...R......a...G.Qik..&A..q...q.$ Hi..JD.:.:v..4.i.X*..4.XJV.J.8Y?.@..Z@...I3....<....8.S.).=.I..t..1.....f...)Y2..8!.,.l%..1.*N...+..,..V...G.s._..E.....{h.........k._.t...9....w.......1....3s|M..ky.9.....<.p.o[^...`4....>...O#...A.;.R/....3.....~........3....3.3ib..=..L..&Sw.x..}C...L.....% .....'....Z.:Wc....4.=...y:.Jy0wh...g..w.x.Z...M......>Z..t.....z./S...y.#{..Q.L].u.O........q....~.....F..=7..>..f...(..(@~:.l.C{.[.;...3>@..!hj.{....p..^.....:.}...p.{..Lv.....&.D.~.X..[.#....,&p......D.~...LH.j.9h...u&.....%...........].v...>.....aY.em.;.j4..."4...C.z.......Nc.K...n>..d..........A..H.$.D....*B.b....
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java archive data (JAR)
    Category:dropped
    Size (bytes):9644
    Entropy (8bit):7.873235391371468
    Encrypted:false
    SSDEEP:192:vXDQDkkfCtpVGssQsWKS7sS8i+JPuZq+iMIuAw9BV41VxnDx:rSlqtpV3sQz8XuZq3DzGB+1Z
    MD5:DBF96996027AE6EBB2AFC66A5A35B5C9
    SHA1:7CD5C82DA6A8869FF87BCDA59C20D73D6E8E34ED
    SHA-256:2A0B3682B59F63B499C4209F2F2FE943FC19A3CED6EB8C8690E78D8F02B783F9
    SHA-512:9CD4C2F56B7615AE0F7B145057261FDBCD8E64D794897014A6DA0D021E28E4A198B0A96A1C9C209FDECF89F181522AD2C6D38DD96A98F460E3D671B4BAE737A7
    Malicious:false
    Reputation:low
    Preview:PK..........V................META-INF/......PK..............PK..........V................META-INF/MANIFEST.MFm....0.E....,u.Ru.t.U..(*neH..H&%M..z_.v;.p.9.....|.....)r[.......mt0...........>h.....oe.8...])..)]j. .p>..Ge.2.+.o.7...4.J.-..9|`../.)2O...F.R......X9.9......(..5G...Na...._..qc+).8.PK..b..z....U...PK..........V................Deadlock$DeadlockThread.class.V.O.e...{.2;..z.J......b[j..V.]..[..0.0.;...)......j...&F.j.=.Ml.R.#?X...@A..x..}...=.,7......0Y..<.`...S. ].... ........(.EJA.}2.(......Q.......B.q.."8............<)NOE....xV.&!......6..SZ.s.LR.-.s..r..5.L.v.uwJ.fmk..!.r.L.v$.=.e8].-.7..jR..mX.o+.t..h.{y....%H'$..Q3.m...dB..>.V.%h.yq.bF.F...cZ#.+.^Q...qu.....i.}^v.p....%]..|I.K%.}..,.8W...>..r...<.!...l..V.r....%!.-x+.o..V.....zJ..9.q...+.......U..P..*...........]hS..m2.W1"....c2.Ud...0_...5.....I...m....."...........Ss..p.......I...r.\3k..$...^f...F.....Q.1ZU< L...N.....H...pUx8E....3...N...F...W.....Y..>..j.i..../.=24f.:.t...lZa.9
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Zip archive data, at least v2.0 to extract, compression method=deflate
    Category:dropped
    Size (bytes):8351
    Entropy (8bit):7.941234216292513
    Encrypted:false
    SSDEEP:192:ssNBCL5P2e6GPAiemai+JPpfgDo3ZKSUSbp:s24LIe6GPAsaXpmYgSF
    MD5:8FFD4BC885E5A88ABD26B1BE51E940CE
    SHA1:20ADAFD6DB1CB449B448765B80952FF344A33C06
    SHA-256:5EC01DAC414B3D89080286500285DE00F1B62ADBCA1AB905CA712A89A3E769A3
    SHA-512:DB49429A4F1F8357D977A0ADFAD89C99437A68B016B0452939889B6B2AA1E0CD4088873C9453C3646276B553B6F89ED19C185C0D76ADD6453E53C56081DA0CE7
    Malicious:false
    Reputation:low
    Preview:PK...........V...............Deadlock.javaUT...%..d%..dux..............XKw.H...W.....d.I.....9.P......%.&...v......X.!;.y.Z...{..~.....G.$..T.,r...trt......>9.."I"....T....U.D.3..(".Q*3......C.2TY..Y..$f.*2I*.,).@C.L."..y...>.|A.....e..j....}....L.*.eH.4.U!n...%..E..o(H.P1S.(....jD/[.e..k..$.u..0)....,...M%.Q..*.}...".2.Z..qS1H."..25...R......a...G.Qik..&A..q...q.$ Hi..JD.:.:v..4.i.X*..4.XJV.J.8Y?.@..Z@...I3....<....8.S.).=.I..t..1.....f...)Y2..8!.,.l%..1.*N...+..,..V...G.s._..E.....{h.........k._.t...9....w.......1....3s|M..ky.9.....<.p.o[^...`4....>...O#...A.;.R/....3.....~........3....3.3ib..=..L..&Sw.x..}C...L.....% .....'....Z.:Wc....4.=...y:.Jy0wh...g..w.x.Z...M......>Z..t.....z./S...y.#{..Q.L].u.O........q....~.....F..=7..>..f...(..(@~:.l.C{.[.;...3>@..!hj.{....p..^.....:.}...p.{..Lv.....&.D.~.X..[.#....,&p......D.~...LH.j.9h...u&.....%...........].v...>.....aY.em.;.j4..."4...C.z.......Nc.K...n>..d..........A..H.$.D....*B.b....
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java archive data (JAR)
    Category:dropped
    Size (bytes):11054
    Entropy (8bit):7.825944661182623
    Encrypted:false
    SSDEEP:192:1BCQHgl+FgaIv6+ndzD7BpEo2eseXFQXVBfWzNfNHf1VbhEt+hxYedUzCyed2T:14QHgl+F8Fnddp12ReXFQXVBfYldMt+Q
    MD5:BBE79069B0933E4DC09E17336C161BAB
    SHA1:15BA82B606369F6B4F6F338C59619A57FF09B233
    SHA-256:C434959AADB4116CE8010025DF253D715E5FD4E40B765F6BE6B8AB45746E5A59
    SHA-512:AEF7AF16CEB7F8F7E04B53DC8B9FAE97B01D6C6EB3B196E80A2BDADCD70C04FF6C551660589482FE093889A4CF9AE3EC30E9AA323CEAA2C6FE006CBDA3123BCA
    Malicious:false
    Reputation:low
    Preview:PK..........V................META-INF/......PK..............PK..........V................META-INF/MANIFEST.MFm....0.E....,u.u.t..E.QT.....HfJ.......v...3sd[Q..-.....O{Z..v.#..1...(......G..... |.~...Q...F.V...y.....".q...Z.-.&...c%..xY.....2........T.f..{<..F<.l..?._.Vs......b..Z+..PK...pL.....K...PK...........V................JTop$1.classuQMO.@.}#Hi.._..&VL.&.4^.&.............[&.....?.8[M..&;3.......w....1.......B.@.s..5T...mv"....]4..C..\.F...........-...+.U.k...4=FRA,.Z.d..8h.3W%tU..q............hb..&4dM..X...5....U..O0..........G.g7...vY.b..9.k)Y....9..G._..!/.>...tE@.X..sh....$y...R.M.E+...x...2...%....a...h...1.;/..+...&..{..v.....{F..>.FH...-0T+.0..)....d.....B.!..V..PK....!.l.......PK...........V................JTop$2.classEQ.N.0...A..h(.....B.HA.@\*...C....M...:U...B..8..|.b.".w.3.......p...9,..c.@.e........#...$.2.4..pxB./..Aw&..=C..v.C..Kq..:"j.N@H6J%EG..V.F...UCW.>.q..K/.c_..D..v5.........:.Mla..V".....RD.....,...p.so:}.%..)t.J9q.SzJ..
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:ASCII text
    Category:dropped
    Size (bytes):2154
    Entropy (8bit):4.852793383472569
    Encrypted:false
    SSDEEP:48:GLg+Lc95WabYS94dUyh/wuUpA1IIAQbWFICczKBaUn:dycRv4d/77EF
    MD5:8750629A101578D95F985C9F9B62732A
    SHA1:5199B6D5C9F93F502AF60BB2379C73EEFAC05FCB
    SHA-256:448A61647F74860DC1AB7E6468EFB23FE67278A4FE1C837DC3B6D2BA6605710B
    SHA-512:6BAB90D5A2CC200AF07E302CB19F4FC8B3717A237457CA0EB714042A662A259E04107B93B1F24A953E019CD169AE1DCBF08E67F20849CC2FED4D0398CD30BB8D
    Malicious:false
    Reputation:low
    Preview:JTop monitors the CPU usage of all threads in a remote application.which has remote management enabled. JTop demonstrates the use of .the java.lang.management API to obtain the CPU consumption for .each thread...JTop is also a JConsole Plugin. See below for details...JTop Standalone GUI.===================..JTop first establishes a connection to a JMX agent in a remote.application with a JMX service URL:. service:jmx:rmi:///jndi/rmi://<hostName>:<portNum>/jmxrmi..where <hostName> is the hostname and <portNum> is the port number.to which the JMX agent will be connected...To run the demo.---------------.(1) Start the application with the JMX agent - here's an example of . how the Java2D is started. . java -Dcom.sun.management.jmxremote.port=1090. -Dcom.sun.management.jmxremote.ssl=false. -Dcom.sun.management.jmxremote.authenticate=false. -jar <JDK_HOME>/demo/jfc/Java2D/Java2Demo.jar.. This instruction uses the Sun's built-in support to enabl
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java archive data (JAR)
    Category:dropped
    Size (bytes):11054
    Entropy (8bit):7.825944661182623
    Encrypted:false
    SSDEEP:192:1BCQHgl+FgaIv6+ndzD7BpEo2eseXFQXVBfWzNfNHf1VbhEt+hxYedUzCyed2T:14QHgl+F8Fnddp12ReXFQXVBfYldMt+Q
    MD5:BBE79069B0933E4DC09E17336C161BAB
    SHA1:15BA82B606369F6B4F6F338C59619A57FF09B233
    SHA-256:C434959AADB4116CE8010025DF253D715E5FD4E40B765F6BE6B8AB45746E5A59
    SHA-512:AEF7AF16CEB7F8F7E04B53DC8B9FAE97B01D6C6EB3B196E80A2BDADCD70C04FF6C551660589482FE093889A4CF9AE3EC30E9AA323CEAA2C6FE006CBDA3123BCA
    Malicious:false
    Reputation:low
    Preview:PK..........V................META-INF/......PK..............PK..........V................META-INF/MANIFEST.MFm....0.E....,u.u.t..E.QT.....HfJ.......v...3sd[Q..-.....O{Z..v.#..1...(......G..... |.~...Q...F.V...y.....".q...Z.-.&...c%..xY.....2........T.f..{<..F<.l..?._.Vs......b..Z+..PK...pL.....K...PK...........V................JTop$1.classuQMO.@.}#Hi.._..&VL.&.4^.&.............[&.....?.8[M..&;3.......w....1.......B.@.s..5T...mv"....]4..C..\.F...........-...+.U.k...4=FRA,.Z.d..8h.3W%tU..q............hb..&4dM..X...5....U..O0..........G.g7...vY.b..9.k)Y....9..G._..!/.>...tE@.X..sh....$y...R.M.E+...x...2...%....a...h...1.;/..+...&..{..v.....{F..>.FH...-0T+.0..)....d.....B.!..V..PK....!.l.......PK...........V................JTop$2.classEQ.N.0...A..h(.....B.HA.@\*...C....M...:U...B..8..|.b.".w.3.......p...9,..c.@.e........#...$.2.4..pxB./..Aw&..=C..v.C..Kq..:"j.N@H6J%EG..V.F...UCW.>.q..K/.c_..D..v5.........:.Mla..V".....RD.....,...p.so:}.%..)t.J9q.SzJ..
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Zip archive data, at least v2.0 to extract, compression method=deflate
    Category:dropped
    Size (bytes):8930
    Entropy (8bit):7.899687933994991
    Encrypted:false
    SSDEEP:192:ljGQT1mqQ6LZPR1DlA0lvGvPwMWdBSAz5X8z2Fpi4Uzo:kAFQ69J1hA0mYtzl8zI84UE
    MD5:BD6F2FFAFEBD6928C8C65BC8B5AD04BE
    SHA1:39EDF110BC9D6783CAB2FF564AC4437FFC601841
    SHA-256:9F3BE3DC5CDF76C1179BB1AEBB06289DBCB9FA2A15EA068F90370749DD988453
    SHA-512:6419E0F78C7F4036C8562E85573CAD891C2A525E09E7303FD5F10F7E324D8DACD2BAF9405FF6D7903429DDF29E1D3D761F5928501C855073DC97BA1EF430E6D2
    Malicious:false
    Reputation:low
    Preview:PK...........V.3..~...>:......JTop.javaUT...%..d%..dux..............[.s.F...G.f...D.|g(...H..;.l*..M.1.08t.T............e.-..w...u.......$X.2a...........w.(...^.....Tx.E..^&S[..P0\*....F.6....4K..<....<.".D...Q.. .{...u...A...B?.<#,......#...%Rld...L.b..7../......0.o.h).q.......[..fM...."^.|.c...4.H..~..w...+.&.E.(...`I.....OE.e.3......2....T....@`?...O..%k....ZF.W.. .D.a.$.....0...".e...&........c......+tq.....G.".2..T...u.I.T.w.. ..@..{..4^d.....D..s.1...|.yW..,M.)...DLF...{cG...x..=s.....tD.t.e._L..hp.'.7<...t..#<..M..;..w.....|5v&.1....j.....{..L:.....3wx...!.............i......../.k...../L.;.......W.......1a....F.G.|g.?..-.....3...Eo0h.;.<t..s.)..n{..G..g...OI..[.Z.....\9}._.....z./....N......Y.w.!....+.gc.x.N&......8...X..g...;.7b0...f...".^GK.,..V`..l.......gWSw4..?CC...3V.h.2CY....%L..6GG|.p.jL.e..H..h.?5..$.95.%<C.|..;.C.F..;q.a=....V"....3......W.=....[W..D..K...p..........8x..@....*..Fr@..a.$. qp......%.4...ey.......
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:ASCII text
    Category:dropped
    Size (bytes):2154
    Entropy (8bit):4.852793383472569
    Encrypted:false
    SSDEEP:48:GLg+Lc95WabYS94dUyh/wuUpA1IIAQbWFICczKBaUn:dycRv4d/77EF
    MD5:8750629A101578D95F985C9F9B62732A
    SHA1:5199B6D5C9F93F502AF60BB2379C73EEFAC05FCB
    SHA-256:448A61647F74860DC1AB7E6468EFB23FE67278A4FE1C837DC3B6D2BA6605710B
    SHA-512:6BAB90D5A2CC200AF07E302CB19F4FC8B3717A237457CA0EB714042A662A259E04107B93B1F24A953E019CD169AE1DCBF08E67F20849CC2FED4D0398CD30BB8D
    Malicious:false
    Reputation:low
    Preview:JTop monitors the CPU usage of all threads in a remote application.which has remote management enabled. JTop demonstrates the use of .the java.lang.management API to obtain the CPU consumption for .each thread...JTop is also a JConsole Plugin. See below for details...JTop Standalone GUI.===================..JTop first establishes a connection to a JMX agent in a remote.application with a JMX service URL:. service:jmx:rmi:///jndi/rmi://<hostName>:<portNum>/jmxrmi..where <hostName> is the hostname and <portNum> is the port number.to which the JMX agent will be connected...To run the demo.---------------.(1) Start the application with the JMX agent - here's an example of . how the Java2D is started. . java -Dcom.sun.management.jmxremote.port=1090. -Dcom.sun.management.jmxremote.ssl=false. -Dcom.sun.management.jmxremote.authenticate=false. -jar <JDK_HOME>/demo/jfc/Java2D/Java2Demo.jar.. This instruction uses the Sun's built-in support to enabl
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Zip archive data, at least v2.0 to extract, compression method=deflate
    Category:dropped
    Size (bytes):8930
    Entropy (8bit):7.899687933994991
    Encrypted:false
    SSDEEP:192:ljGQT1mqQ6LZPR1DlA0lvGvPwMWdBSAz5X8z2Fpi4Uzo:kAFQ69J1hA0mYtzl8zI84UE
    MD5:BD6F2FFAFEBD6928C8C65BC8B5AD04BE
    SHA1:39EDF110BC9D6783CAB2FF564AC4437FFC601841
    SHA-256:9F3BE3DC5CDF76C1179BB1AEBB06289DBCB9FA2A15EA068F90370749DD988453
    SHA-512:6419E0F78C7F4036C8562E85573CAD891C2A525E09E7303FD5F10F7E324D8DACD2BAF9405FF6D7903429DDF29E1D3D761F5928501C855073DC97BA1EF430E6D2
    Malicious:false
    Reputation:low
    Preview:PK...........V.3..~...>:......JTop.javaUT...%..d%..dux..............[.s.F...G.f...D.|g(...H..;.l*..M.1.08t.T............e.-..w...u.......$X.2a...........w.(...^.....Tx.E..^&S[..P0\*....F.6....4K..<....<.".D...Q.. .{...u...A...B?.<#,......#...%Rld...L.b..7../......0.o.h).q.......[..fM...."^.|.c...4.H..~..w...+.&.E.(...`I.....OE.e.3......2....T....@`?...O..%k....ZF.W.. .D.a.$.....0...".e...&........c......+tq.....G.".2..T...u.I.T.w.. ..@..{..4^d.....D..s.1...|.yW..,M.)...DLF...{cG...x..=s.....tD.t.e._L..hp.'.7<...t..#<..M..;..w.....|5v&.1....j.....{..L:.....3wx...!.............i......../.k...../L.;.......W.......1a....F.G.|g.?..-.....3...Eo0h.;.<t..s.)..n{..G..g...OI..[.Z.....\9}._.....z./....N......Y.w.!....+.gc.x.N&......8...X..g...;.7b0...f...".^GK.,..V`..l.......gWSw4..?CC...3V.h.2CY....%L..6GG|.p.jL.e..H..h.?5..$.95.%<C.|..;.C.F..;q.a=....V"....3......W.=....[W..D..K...p..........8x..@....*..Fr@..a.$. qp......%.4...ey.......
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java archive data (JAR)
    Category:dropped
    Size (bytes):11331
    Entropy (8bit):7.886856333184142
    Encrypted:false
    SSDEEP:192:Ojgxq3ARLW5ZpjBTG1aM1CbMrGrFsv0yDLo8okXrH8QqL2hKRnPBoC3UgAcOkXbR:O6KAC/GoM1fyrFsvXfrBqTR5oWyW
    MD5:1953B2080B8626F6976FD82DD550BEB9
    SHA1:80067DB98178A316739780C6E6F7B1E5AE30FA4E
    SHA-256:E467B391DF8CE5D734424E20D9DD2313467E1921E0EB7A983558E6C40E878DD3
    SHA-512:3D67AFE7BCF83968D33720D118FFDC620D2CFE96F5449B9555B2B1B3DA25289A1710BE337DD5A77EF79DE39F0803B86DBD3A22C369598F144AE88610AEBCE4FA
    Malicious:false
    Reputation:low
    Preview:PK..........V................META-INF/......PK..............PK..........V................META-INF/MANIFEST.MFm.Mk.A.........a.....t..R...1...d.....-m..&.o.(...-..*.L.wM.#%...kX.s.T......dN.K9...........l..[O.;..B.j....HP..j.[yy{.1wj......}....j#./...J/S...~..A.4..........R........U..w.PK...G`3....T...PK...........V................MemoryMonitor$1.classuT.R.@....BC.Z." .Z.RP.q.+(."Z...qi..I.N.\...S......?|._.7P......s...w6....w..X. .+:....W.$.J.._Y.T..tD1.c.7t..p.Rni..R..J..0.a..Jn.^. C]<!......t.Q...dN0..b}K.........vv]..|."..u.=....H3t..o....]..;...O+..T..<...B...Bk..2..t...1.p.....J.O.)..L;..r.IS..&L.h@.......1Lk.1.Hy.c......#.a..S,hxf..I..xa`......-ng..{)...c.x.`V.X.$.Q.[...0k..Y....v..Si...%....Z.K../.X..T.#.,.XJ;1..c.Bl.f.m...Z..O.u....).h.g...tr..c...........[.....4.._S.9.c..{...BRs-.p.bO..JS....m(#.z.f.%..\..T.....FHg..D...r..D.n....7.P.YB..@+..y*=.]..w.e..$.4W.iK\....>X....GV.=Mh..nzW.=..........V.U...$/.....>....C.<|J........
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:ASCII text
    Category:dropped
    Size (bytes):2226
    Entropy (8bit):5.13823044183685
    Encrypted:false
    SSDEEP:48:ZZyOlrYJErYJFHvv432sDt32sWEtPu3tOHD72cqv+hF7G25IAQbWFICi:ZZPlrYJErYJFPQ3vt3S34jinUdfct
    MD5:AFF77FDE354FF9A2F259F352722C6787
    SHA1:8A0F66BF350C6D76A03031D06D1A835E3BCE0329
    SHA-256:B570E8568251C5D6FE1588916A1E4BC7797FFA73EEAAD0E8B244CAEFFF1FC82F
    SHA-512:CD6A206E0D8CFB9724C9CCE47584DD3E5B7E3E05A54B5B3F990D30FE549F91978BE8F04AC601B412B2054DAC9F46A75289DA9E5B04B542B21425F5A399D39AC4
    Malicious:false
    Reputation:low
    Preview:#.# Copyright (c) 2004, 2012, Oracle and/or its affiliates. All rights reserved..#.# Redistribution and use in source and binary forms, with or without.# modification, are permitted provided that the following conditions.# are met:.#.# - Redistributions of source code must retain the above copyright.# notice, this list of conditions and the following disclaimer..#.# - Redistributions in binary form must reproduce the above copyright.# notice, this list of conditions and the following disclaimer in the.# documentation and/or other materials provided with the distribution..#.# - Neither the name of Oracle nor the names of its.# contributors may be used to endorse or promote products derived.# from this software without specific prior written permission..#.# THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS.# IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,.# THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Zip archive data, at least v2.0 to extract, compression method=deflate
    Category:dropped
    Size (bytes):6531
    Entropy (8bit):7.944360500091719
    Encrypted:false
    SSDEEP:192:7OsPj23e+k8BlRXxu7Be26UDE8Unv9mto7RtRnPBoC3UgBQ:isPSuABlRhME26U7C4YtR5oW+
    MD5:0C56ADD55917AE7F0A99BCDF44F506DB
    SHA1:3E79923EBC958FEE5D6D783565AFF7E5A431233B
    SHA-256:B6AF1A88D3FA616E21383E5735F4AC676A7969EE6734DF2C60E85028DC051B83
    SHA-512:D1E9EC312CAFDEFB66262B433A268A8BF16FD6189DA6AF9D5A42E51DE40BA6917EA527CC765AC62BB2BD8B17483A4A8F5E5CCF15DD6CD3EB7086EED4AD613409
    Malicious:false
    Reputation:low
    Preview:PK...........V..*.....)C......MemoryMonitor.javaUT...%..d%..dux..............[{s...?.....%...?2....cem....r.n.h.l!1.0...w...n.%.d.^M.K.............z...E..i.....:~..:.x....tf....g.|n..p_gm.f...<.s..t.#.C>....&..r.B..>g..|w.M.J6...{fs.[.u..........tg......L.....V...[y.5.M.0..p.mwc9wl.:3.:....-y.Q...N.=....;.... R`._.lN.GjRj.X.s....:@,..@Hxb.B.4c.:.Mk.=}.7..PM.........CL........;.........-1..e.~<.b..sR...}n....KN.).r......Y..x..\...g6.dG..e..-'...K7.L...8........R).;.6d.....S.1....<..G..'....#6..........p.........=..\.../gcv68...#..w.?..'W..^T.#Be.*...a....h..Cf\\......v.l.Fuf.;.W].......cvn\.c...u.W..'.....s....qn.o..Sc.'r...f.....\......jx9.....5F..q....L.0.}...lt.>?..;.....@...'=p.>9.Iz..k.{.1...u.Epy^g..^...!.}.A...N...Q...v.m_..@H.u.`.:W........NFcc|5./.AW.}..~3:...;....F.:...u%..@s.......:4...pxu96..*......m...e..Bf(k0..^.D...Qg.g=4.I.BkmR....` .e.....~.......`@...Q...3....J..|%d.A.o......s]..3NY... ..<.bd(....)._.{.+.C.V.A.Dp..Z.. .!p.W_....&
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java archive data (JAR)
    Category:dropped
    Size (bytes):11331
    Entropy (8bit):7.886856333184142
    Encrypted:false
    SSDEEP:192:Ojgxq3ARLW5ZpjBTG1aM1CbMrGrFsv0yDLo8okXrH8QqL2hKRnPBoC3UgAcOkXbR:O6KAC/GoM1fyrFsvXfrBqTR5oWyW
    MD5:1953B2080B8626F6976FD82DD550BEB9
    SHA1:80067DB98178A316739780C6E6F7B1E5AE30FA4E
    SHA-256:E467B391DF8CE5D734424E20D9DD2313467E1921E0EB7A983558E6C40E878DD3
    SHA-512:3D67AFE7BCF83968D33720D118FFDC620D2CFE96F5449B9555B2B1B3DA25289A1710BE337DD5A77EF79DE39F0803B86DBD3A22C369598F144AE88610AEBCE4FA
    Malicious:false
    Reputation:low
    Preview:PK..........V................META-INF/......PK..............PK..........V................META-INF/MANIFEST.MFm.Mk.A.........a.....t..R...1...d.....-m..&.o.(...-..*.L.wM.#%...kX.s.T......dN.K9...........l..[O.;..B.j....HP..j.[yy{.1wj......}....j#./...J/S...~..A.4..........R........U..w.PK...G`3....T...PK...........V................MemoryMonitor$1.classuT.R.@....BC.Z." .Z.RP.q.+(."Z...qi..I.N.\...S......?|._.7P......s...w6....w..X. .+:....W.$.J.._Y.T..tD1.c.7t..p.Rni..R..J..0.a..Jn.^. C]<!......t.Q...dN0..b}K.........vv]..|."..u.=....H3t..o....]..;...O+..T..<...B...Bk..2..t...1.p.....J.O.)..L;..r.IS..&L.h@.......1Lk.1.Hy.c......#.a..S,hxf..I..xa`......-ng..{)...c.x.`V.X.$.Q.[...0k..Y....v..Si...%....Z.K../.X..T.#.,.XJ;1..c.Bl.f.m...Z..O.u....).h.g...tr..c...........[.....4.._S.9.c..{...BRs-.p.bO..JS....m(#.z.f.%..\..T.....FHg..D...r..D.n....7.P.YB..@+..y*=.]..w.e..$.4W.iK\....>X....GV.=Mh..nzW.=..........V.U...$/.....>....C.<|J........
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:ASCII text
    Category:dropped
    Size (bytes):2226
    Entropy (8bit):5.13823044183685
    Encrypted:false
    SSDEEP:48:ZZyOlrYJErYJFHvv432sDt32sWEtPu3tOHD72cqv+hF7G25IAQbWFICi:ZZPlrYJErYJFPQ3vt3S34jinUdfct
    MD5:AFF77FDE354FF9A2F259F352722C6787
    SHA1:8A0F66BF350C6D76A03031D06D1A835E3BCE0329
    SHA-256:B570E8568251C5D6FE1588916A1E4BC7797FFA73EEAAD0E8B244CAEFFF1FC82F
    SHA-512:CD6A206E0D8CFB9724C9CCE47584DD3E5B7E3E05A54B5B3F990D30FE549F91978BE8F04AC601B412B2054DAC9F46A75289DA9E5B04B542B21425F5A399D39AC4
    Malicious:false
    Reputation:low
    Preview:#.# Copyright (c) 2004, 2012, Oracle and/or its affiliates. All rights reserved..#.# Redistribution and use in source and binary forms, with or without.# modification, are permitted provided that the following conditions.# are met:.#.# - Redistributions of source code must retain the above copyright.# notice, this list of conditions and the following disclaimer..#.# - Redistributions in binary form must reproduce the above copyright.# notice, this list of conditions and the following disclaimer in the.# documentation and/or other materials provided with the distribution..#.# - Neither the name of Oracle nor the names of its.# contributors may be used to endorse or promote products derived.# from this software without specific prior written permission..#.# THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS.# IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,.# THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Zip archive data, at least v2.0 to extract, compression method=deflate
    Category:dropped
    Size (bytes):6531
    Entropy (8bit):7.944360500091719
    Encrypted:false
    SSDEEP:192:7OsPj23e+k8BlRXxu7Be26UDE8Unv9mto7RtRnPBoC3UgBQ:isPSuABlRhME26U7C4YtR5oW+
    MD5:0C56ADD55917AE7F0A99BCDF44F506DB
    SHA1:3E79923EBC958FEE5D6D783565AFF7E5A431233B
    SHA-256:B6AF1A88D3FA616E21383E5735F4AC676A7969EE6734DF2C60E85028DC051B83
    SHA-512:D1E9EC312CAFDEFB66262B433A268A8BF16FD6189DA6AF9D5A42E51DE40BA6917EA527CC765AC62BB2BD8B17483A4A8F5E5CCF15DD6CD3EB7086EED4AD613409
    Malicious:false
    Reputation:low
    Preview:PK...........V..*.....)C......MemoryMonitor.javaUT...%..d%..dux..............[{s...?.....%...?2....cem....r.n.h.l!1.0...w...n.%.d.^M.K.............z...E..i.....:~..:.x....tf....g.|n..p_gm.f...<.s..t.#.C>....&..r.B..>g..|w.M.J6...{fs.[.u..........tg......L.....V...[y.5.M.0..p.mwc9wl.:3.:....-y.Q...N.=....;.... R`._.lN.GjRj.X.s....:@,..@Hxb.B.4c.:.Mk.=}.7..PM.........CL........;.........-1..e.~<.b..sR...}n....KN.).r......Y..x..\...g6.dG..e..-'...K7.L...8........R).;.6d.....S.1....<..G..'....#6..........p.........=..\.../gcv68...#..w.?..'W..^T.#Be.*...a....h..Cf\\......v.l.Fuf.;.W].......cvn\.c...u.W..'.....s....qn.o..Sc.'r...f.....\......jx9.....5F..q....L.0.}...lt.>?..;.....@...'=p.>9.Iz..k.{.1...u.Epy^g..^...!.}.A...N...Q...v.m_..@H.u.`.:W........NFcc|5./.AW.}..~3:...;....F.:...u%..@s.......:4...pxu96..*......m...e..Bf(k0..^.D...Qg.g=4.I.BkmR....` .e.....~.......`@...Q...3....J..|%d.A.o......s]..3NY... ..<.bd(....)._.{.+.C.V.A.Dp..Z.. .!p.W_....&
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:ASCII text
    Category:dropped
    Size (bytes):1360
    Entropy (8bit):4.786745295892349
    Encrypted:false
    SSDEEP:24:aCFKsvnWreYR/ngh/h/VAhZ6lpjCRN0DVs/NA9b21FIsXvev:1F5WSY+hh/V3pW3IAQbWFIC4
    MD5:0A4FFA3836C8F84D647F4F0FE6F912AC
    SHA1:1305BE174F49719D6229ABCE3BDCA8C5E676F261
    SHA-256:8B6074132F18183584FF92066E4FCA8842562CB9B94808DB574338E9BF8D093A
    SHA-512:6F419ADFE549CF91F4742505E5297B3ED17406076E8EA4BEBFB2C4E3DC5D7E045041D666C090306DDC167DA242CA64BF39B7BC6CF67128F3D2E888ACB7EAA9F8
    Malicious:false
    Reputation:low
    Preview:VerboseGC demonstrates the use of the java.lang.management API to .print the garbage collection statistics and memory usage remotely .by connecting to a JMX agent with a JMX service URL:. service:jmx:rmi:///jndi/rmi://<hostName>:<portNum>/jmxrmi.where <hostName> is the hostname and <portNum> is the port number.to which the JMX agent will be connected...To run the VerboseGC demo..(1) Start the application with the JMX agent - here's an example of . how the Java2D is started.. java -Dcom.sun.management.jmxremote.port=1090. -Dcom.sun.management.jmxremote.ssl=false. -Dcom.sun.management.jmxremote.authenticate=false. -jar <JDK_HOME>/demo/jfc/Java2D/Java2Demo.jar.. This instruction uses the Sun's built-in support to enable a JMX agent.. You can programmatically start a JMX agent with the RMI connector. using javax.management.remote API. See the javadoc and examples for. javax.management.remote API for details...(2) Run VerboseGC. . java
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java archive data (JAR)
    Category:dropped
    Size (bytes):5589
    Entropy (8bit):7.825176481665062
    Encrypted:false
    SSDEEP:96:VBkAwcolt+OpZjaEUy82Ya28gx5dw8XhRCHVn/3oE+FcYr5hx6lJ0pWb5FcCxK9n:nrLw9pZFUJ2M8gbpXnKVoEwH9T6MWdF6
    MD5:97D6F8EB483F78AC68677096BE76DDBD
    SHA1:2FEEFB7D2C77DAFC241D5C30FD380A4ADDDB28B6
    SHA-256:B11CDF1B5055B76C19E12A04A4688FC2BE6168B71743E4696DD62645F82FFDB0
    SHA-512:1DCF391340A4A4AA708C2409F389FA2800040AA9C91A6C5A4C0E00D24CC4B6F2255825F1C65BAEB445098A58FFE40E73AF393CDA2092D6E0A1F830834D689C3A
    Malicious:false
    Reputation:low
    Preview:PK..........V................META-INF/......PK..............PK..........V................META-INF/MANIFEST.MFm.A..0.....9.E.A.M.H....u..S.$3%....u.WW.:..o.d.RL.B..%..V...y..r.>lrT......'...|.A..z..&..s4)..vdlk...V..#.$t...+...v.Z......`......@.h..N.J..zS.g....M......U....a.%\..$..J.oPK..g.......P...PK...........V................PrintGCStat.class.W.|.W...d.3...$..0.p.rV.J....I..PR.8.....ev6M.-.R(.KK[.Z.Z.]....-V.Zm..Vm..x.G...}..=..b~..w..w....<.......%.r.........h6../.:......n..]p.z.7H..G.H..B.L7n.>.7.0.&..w...p. n..!^xX..7n....C....~........8.{$..."..>~.....w.c.}.....e<......e|.;....2>..B|L.C....!.......).|Z.gx.2>.F!....q.'\8.GX.)...3,cD.s........Q....,.O..xL...<.3.N3..!..;.~.:.....jH..Z....YzPk..@.:....E....a.&.Ya..D.rc...[..ES.z_H...&p.......A"..V.....6......&......^.0S..Y.F".i.F(.V..=../ .".W.!.Z)P^jK.H3..tjf.f..P.....e...>.O...!.=J...X..%...{m......._ ..[%<)...u..Z.6E..2KY......cD..^.e.a.U.M..t.A~i...;-...g...a...%.....qu.Q.Wk.......#.*
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Zip archive data, at least v2.0 to extract, compression method=deflate
    Category:dropped
    Size (bytes):5409
    Entropy (8bit):7.908710762896665
    Encrypted:false
    SSDEEP:96:g+ZdO+kwAeC6ZHhfAt3kloAUd2RCHVn/e++rujnoP6Oqx9ZAllXMd7WDJD2j:ZZE+60hfAt3klT9KiqLoCOI9Cllaa9Q
    MD5:9588E0D5CC19E86D983F57D2B9E4AF21
    SHA1:1C3DC37C29320DE91FC2B28908A2881CBF40F5C0
    SHA-256:09320C8FDB6502A7FB7297B21686725C7D658F708652C2EE3D08B2B07B92BBE2
    SHA-512:82962CD9B0B3164A0FA241EDC8E58A99F88F9134BBE2A0133835D5153C07CD63980B59AEEA1E44F8BF248EDABF4F04228B59001CB6CACC6EA235A41FB23564FD
    Malicious:false
    Reputation:low
    Preview:PK...........V.)t.N...........PrintGCStat.javaUT...%..d%..dux..............X.r.F.}.W..j. ........(dI..@..-...)$..Hf...{z. A...M.|.....O...x..^..o.E...H.O...7C.}.zHN.... ....`...8.D9"=IH.+...(.E4..C."....u....P]..3*..%$-.,(......C\........%.x...c.)(.mD..U%"...}.aP......$I..gk..,.yQ.(........=z%.W.G....!U..2r...y..I..ey..b.........-c<$..a..(F...4-....`.7.".k...a......q..0((E..8H.}.d....H7D[.r-.dA*.XS\Y..,3.2kY.....~...\G."'.Ex*.d.#.+AJ".c.....f.y%J..........k.kc....+SuV..(.+.#..ot.$..sm..1].b.$.....+g:6].t{....Z.......1....n..q.G.K.l>.....n.......bl.!..l..5.|...P.2..$.f.k\.~aM-.V...|..].Ns..-c1.]F./....-.......$...k.....^..m..@..n..&...SS.C.c.5.........!ys.0` ..t.v....3.Y...4.g..Aj..Y2..9c...[\x../|.&.3..{.{m......'.[x..N|}.D..(..._,<Kjh...o9.).~...T....e...qo..H..L.n.LL.,.TMg9<.g.]3...~'X......a...@7.g."{..M.......s..M.-Y.m=.ev.$}|m1.....YM.H...F}..g''gjs....q.9`..I.&V.q.^..Z.......DP.l>..Dx..kuJ..%.=."..K. ..8.$.8rH.T
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java archive data (JAR)
    Category:dropped
    Size (bytes):5589
    Entropy (8bit):7.825176481665062
    Encrypted:false
    SSDEEP:96:VBkAwcolt+OpZjaEUy82Ya28gx5dw8XhRCHVn/3oE+FcYr5hx6lJ0pWb5FcCxK9n:nrLw9pZFUJ2M8gbpXnKVoEwH9T6MWdF6
    MD5:97D6F8EB483F78AC68677096BE76DDBD
    SHA1:2FEEFB7D2C77DAFC241D5C30FD380A4ADDDB28B6
    SHA-256:B11CDF1B5055B76C19E12A04A4688FC2BE6168B71743E4696DD62645F82FFDB0
    SHA-512:1DCF391340A4A4AA708C2409F389FA2800040AA9C91A6C5A4C0E00D24CC4B6F2255825F1C65BAEB445098A58FFE40E73AF393CDA2092D6E0A1F830834D689C3A
    Malicious:false
    Reputation:low
    Preview:PK..........V................META-INF/......PK..............PK..........V................META-INF/MANIFEST.MFm.A..0.....9.E.A.M.H....u..S.$3%....u.WW.:..o.d.RL.B..%..V...y..r.>lrT......'...|.A..z..&..s4)..vdlk...V..#.$t...+...v.Z......`......@.h..N.J..zS.g....M......U....a.%\..$..J.oPK..g.......P...PK...........V................PrintGCStat.class.W.|.W...d.3...$..0.p.rV.J....I..PR.8.....ev6M.-.R(.KK[.Z.Z.]....-V.Zm..Vm..x.G...}..=..b~..w..w....<.......%.r.........h6../.:......n..]p.z.7H..G.H..B.L7n.>.7.0.&..w...p. n..!^xX..7n....C....~........8.{$..."..>~.....w.c.}.....e<......e|.;....2>..B|L.C....!.......).|Z.gx.2>.F!....q.'\8.GX.)...3,cD.s........Q....,.O..xL...<.3.N3..!..;.~.:.....jH..Z....YzPk..@.:....E....a.&.Ya..D.rc...[..ES.z_H...&p.......A"..V.....6......&......^.0S..Y.F".i.F(.V..=../ .".W.!.Z)P^jK.H3..tjf.f..P.....e...>.O...!.=J...X..%...{m......._ ..[%<)...u..Z.6E..2KY......cD..^.e.a.U.M..t.A~i...;-...g...a...%.....qu.Q.Wk.......#.*
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:ASCII text
    Category:dropped
    Size (bytes):1360
    Entropy (8bit):4.786745295892349
    Encrypted:false
    SSDEEP:24:aCFKsvnWreYR/ngh/h/VAhZ6lpjCRN0DVs/NA9b21FIsXvev:1F5WSY+hh/V3pW3IAQbWFIC4
    MD5:0A4FFA3836C8F84D647F4F0FE6F912AC
    SHA1:1305BE174F49719D6229ABCE3BDCA8C5E676F261
    SHA-256:8B6074132F18183584FF92066E4FCA8842562CB9B94808DB574338E9BF8D093A
    SHA-512:6F419ADFE549CF91F4742505E5297B3ED17406076E8EA4BEBFB2C4E3DC5D7E045041D666C090306DDC167DA242CA64BF39B7BC6CF67128F3D2E888ACB7EAA9F8
    Malicious:false
    Reputation:low
    Preview:VerboseGC demonstrates the use of the java.lang.management API to .print the garbage collection statistics and memory usage remotely .by connecting to a JMX agent with a JMX service URL:. service:jmx:rmi:///jndi/rmi://<hostName>:<portNum>/jmxrmi.where <hostName> is the hostname and <portNum> is the port number.to which the JMX agent will be connected...To run the VerboseGC demo..(1) Start the application with the JMX agent - here's an example of . how the Java2D is started.. java -Dcom.sun.management.jmxremote.port=1090. -Dcom.sun.management.jmxremote.ssl=false. -Dcom.sun.management.jmxremote.authenticate=false. -jar <JDK_HOME>/demo/jfc/Java2D/Java2Demo.jar.. This instruction uses the Sun's built-in support to enable a JMX agent.. You can programmatically start a JMX agent with the RMI connector. using javax.management.remote API. See the javadoc and examples for. javax.management.remote API for details...(2) Run VerboseGC. . java
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Zip archive data, at least v2.0 to extract, compression method=deflate
    Category:dropped
    Size (bytes):5409
    Entropy (8bit):7.908710762896665
    Encrypted:false
    SSDEEP:96:g+ZdO+kwAeC6ZHhfAt3kloAUd2RCHVn/e++rujnoP6Oqx9ZAllXMd7WDJD2j:ZZE+60hfAt3klT9KiqLoCOI9Cllaa9Q
    MD5:9588E0D5CC19E86D983F57D2B9E4AF21
    SHA1:1C3DC37C29320DE91FC2B28908A2881CBF40F5C0
    SHA-256:09320C8FDB6502A7FB7297B21686725C7D658F708652C2EE3D08B2B07B92BBE2
    SHA-512:82962CD9B0B3164A0FA241EDC8E58A99F88F9134BBE2A0133835D5153C07CD63980B59AEEA1E44F8BF248EDABF4F04228B59001CB6CACC6EA235A41FB23564FD
    Malicious:false
    Reputation:low
    Preview:PK...........V.)t.N...........PrintGCStat.javaUT...%..d%..dux..............X.r.F.}.W..j. ........(dI..@..-...)$..Hf...{z. A...M.|.....O...x..^..o.E...H.O...7C.}.zHN.... ....`...8.D9"=IH.+...(.E4..C."....u....P]..3*..%$-.,(......C\........%.x...c.)(.mD..U%"...}.aP......$I..gk..,.yQ.(........=z%.W.G....!U..2r...y..I..ey..b.........-c<$..a..(F...4-....`.7.".k...a......q..0((E..8H.}.d....H7D[.r-.dA*.XS\Y..,3.2kY.....~...\G."'.Ex*.d.#.+AJ".c.....f.y%J..........k.kc....+SuV..(.+.#..ot.$..sm..1].b.$.....+g:6].t{....Z.......1....n..q.G.K.l>.....n.......bl.!..l..5.|...P.2..$.f.k\.~aM-.V...|..].Ns..-c1.]F./....-.......$...k.....^..m..@..n..&...SS.C.c.5.........!ys.0` ..t.v....3.Y...4.g..Aj..Y2..9c...[\x../|.&.3..{.{m......'.[x..N|}.D..(..._,<Kjh...o9.).~...T....e...qo..H..L.n.LL.,.TMg9<.g.]3...~'X......a...@7.g."{..M.......s..M.-Y.m=.ev.$}|m1.....YM.H...F}..g''gjs....q.9`..I.&V.q.^..Z.......DP.l>..Dx..kuJ..%.=."..K. ..8.$.8rH.T
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:HTML document, ASCII text
    Category:dropped
    Size (bytes):802
    Entropy (8bit):5.002116665151789
    Encrypted:false
    SSDEEP:24:9h7b+KGrCgnyva6wH7d7pwU1eVc+d2bbn:9wDM+7M3daT
    MD5:B302B3CA7F544E6B62AEC9E599E5E9C4
    SHA1:75F7607F506960C112BA89C63FC6B97C60F86491
    SHA-256:0D009775D9BE6A7D97E2FFDCC04BD0C0E6F9607BCDF3BD52C82905679DCD4803
    SHA-512:667E26D7C88EF51EEAA43676094D6EEE9C58A75C5FC9213FFFF91224F645096D2DAE807991C3AB44483322B0512707147EEFF00B7F26768B9C4D739ABDB895EB
    Malicious:false
    Reputation:low
    Preview:<html>.<head> <title>java.lang.management Demonstration Code</title> </head>...<h1>java.lang.management Demonstration Code</h1>..<ul>..<li>.<A HREF="FullThreadDump">FullThreadDump</A>.<br>.Shows how to get thread dumps and look for deadlocks..</li>..<li>.<A HREF="VerboseGC">VerboseGC</A>.<br>.Shows how you can find out about Garbage Collection in the VM..</li>..<li>.<A HREF="MemoryMonitor">MemoryMonitor</A>.<br>.Shows how you can find out the memory usage in the VM..</li>..<li>.<A HREF="JTop">JTop</A>.<br>.Shows how you can find out the threads with top CPU usage..</li>...</ul>....<h2>Comments and Feedback</h2>..<p>.Comments regarding java.lang.management API or on any of these .demonstrations should be sent through .<A HREF="http://java.sun.com/mail">http://java.sun.com/mail/</A>...</html>.
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:HTML document, ASCII text
    Category:dropped
    Size (bytes):802
    Entropy (8bit):5.002116665151789
    Encrypted:false
    SSDEEP:24:9h7b+KGrCgnyva6wH7d7pwU1eVc+d2bbn:9wDM+7M3daT
    MD5:B302B3CA7F544E6B62AEC9E599E5E9C4
    SHA1:75F7607F506960C112BA89C63FC6B97C60F86491
    SHA-256:0D009775D9BE6A7D97E2FFDCC04BD0C0E6F9607BCDF3BD52C82905679DCD4803
    SHA-512:667E26D7C88EF51EEAA43676094D6EEE9C58A75C5FC9213FFFF91224F645096D2DAE807991C3AB44483322B0512707147EEFF00B7F26768B9C4D739ABDB895EB
    Malicious:false
    Reputation:low
    Preview:<html>.<head> <title>java.lang.management Demonstration Code</title> </head>...<h1>java.lang.management Demonstration Code</h1>..<ul>..<li>.<A HREF="FullThreadDump">FullThreadDump</A>.<br>.Shows how to get thread dumps and look for deadlocks..</li>..<li>.<A HREF="VerboseGC">VerboseGC</A>.<br>.Shows how you can find out about Garbage Collection in the VM..</li>..<li>.<A HREF="MemoryMonitor">MemoryMonitor</A>.<br>.Shows how you can find out the memory usage in the VM..</li>..<li>.<A HREF="JTop">JTop</A>.<br>.Shows how you can find out the threads with top CPU usage..</li>...</ul>....<h2>Comments and Feedback</h2>..<p>.Comments regarding java.lang.management API or on any of these .demonstrations should be sent through .<A HREF="http://java.sun.com/mail">http://java.sun.com/mail/</A>...</html>.
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):3002
    Entropy (8bit):5.008491069151138
    Encrypted:false
    SSDEEP:48:cU1OorYJTrYJEfDWQvs432sD32scMEtu33tYTHD2I8nwfDGhQKQQ0KHH14kN:boorYJTrYJEfiQX3f3jp2oxSq
    MD5:7371F7508D6208CD9F35C318DEB5EAAE
    SHA1:8DEBEE33AA82CB690837E0B695D0C8CB9AA11053
    SHA-256:AA89E750727FC85C87149F6A1D0D3EE78779C5525440DF11E61BD5531EF13FF8
    SHA-512:85FB9F90DF6753FDFFE85EBDC02C0C43CB628E639096A57FCB203CE18E8B7AA37180AD71FE28F47BDDD9B65A0A47B77608B72F2ADCE96DCF547EA3273354C2E4
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?>.. . Copyright (c) 2006, 2011, Oracle and/or its affiliates. All rights reserved... Redistribution and use in source and binary forms, with or without. modification, are permitted provided that the following conditions. are met:.. - Redistributions of source code must retain the above copyright. notice, this list of conditions and the following disclaimer... - Redistributions in binary form must reproduce the above copyright. notice, this list of conditions and the following disclaimer in the. documentation and/or other materials provided with the distribution... - Neither the name of Oracle nor the names of its. contributors may be used to endorse or promote products derived. from this software without specific prior written permission... THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. THE IMPLIED WARRANTIES OF MERCHANTA
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):3002
    Entropy (8bit):5.008491069151138
    Encrypted:false
    SSDEEP:48:cU1OorYJTrYJEfDWQvs432sD32scMEtu33tYTHD2I8nwfDGhQKQQ0KHH14kN:boorYJTrYJEfiQX3f3jp2oxSq
    MD5:7371F7508D6208CD9F35C318DEB5EAAE
    SHA1:8DEBEE33AA82CB690837E0B695D0C8CB9AA11053
    SHA-256:AA89E750727FC85C87149F6A1D0D3EE78779C5525440DF11E61BD5531EF13FF8
    SHA-512:85FB9F90DF6753FDFFE85EBDC02C0C43CB628E639096A57FCB203CE18E8B7AA37180AD71FE28F47BDDD9B65A0A47B77608B72F2ADCE96DCF547EA3273354C2E4
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?>.. . Copyright (c) 2006, 2011, Oracle and/or its affiliates. All rights reserved... Redistribution and use in source and binary forms, with or without. modification, are permitted provided that the following conditions. are met:.. - Redistributions of source code must retain the above copyright. notice, this list of conditions and the following disclaimer... - Redistributions in binary form must reproduce the above copyright. notice, this list of conditions and the following disclaimer in the. documentation and/or other materials provided with the distribution... - Neither the name of Oracle nor the names of its. contributors may be used to endorse or promote products derived. from this software without specific prior written permission... THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. THE IMPLIED WARRANTIES OF MERCHANTA
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java archive data (JAR)
    Category:dropped
    Size (bytes):2318582
    Entropy (8bit):7.872039367448507
    Encrypted:false
    SSDEEP:49152:X7HDhv4EVLcJMnz66N8M1IhpvQybDxJv50k:rD55V2Mz66AQyHx7
    MD5:5E382FD74334C625801881C8419640DD
    SHA1:158E1A1DD158265B3A65746302A3AB0AE1728F5D
    SHA-256:4D571EF0E8EBD94FFA7FBEC64F8EAEC21B631CA75DF489988E77318EB231192C
    SHA-512:DFA2396C77DDB23C751339C53C9DE3B4DC2828DAE9ED054D987B8340181813D5D5D371FBD3A4359434FB4BA2BCE3C685D9E7FB9752F7DE0D03A76A2323388AE5
    Malicious:false
    Reputation:low
    Preview:PK..........V................META-INF/......PK..............PK..........V................META-INF/MANIFEST.MF.M..LK-...K-*...R0.3..r.JM,IM.u...X......)h8.&V...%..*x.%.i.r.r..PK..>j..B...B...PK..........V................com/PK..........V................com/sun/PK..........V................com/sun/java/PK..........V................com/sun/java/swing/PK..........V................com/sun/java/swing/action/PK..........V............+...com/sun/java/swing/action/AboutAction.class.SkO.A.=.............<}!....}..M.D..P...d.E.Yh"F...?.xgZ....ag..3...........20.B?...C..l..H.H.x..9.....,.X.&b9..!..Q...x..)Y...T!...k.fv...d..J..{..<%Q.u.K.....j..[.4C...sV6..I........r.m..|:W.gR..mY...H6..{]...^K.S.......n....g_t.8..W.:cS%.@..*.....F.,.-^..u9.......[d..s...Y.%....E.......W&....-....b.{.b..v....h.bW[%..n..+Ge..9%..5."..x..2...8.a..8.h*.H....3.*..r..).V.r.8..q%...T./`....z....s.N....r../..}Q.:r..j\.Q........n...Q~pPul.:.....J..0F1.0pn.......W...5Q...S.../............b.V..
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java archive data (JAR)
    Category:dropped
    Size (bytes):18368064
    Entropy (8bit):6.012772110231048
    Encrypted:false
    SSDEEP:49152:krXa9wpbN7yAnNQwV07Z3fBLZfPwNqW6EXmlGE+oF6aZz9OUagsLhP/s1qg1lpuf:krXa9wBxV07ZZSLguhQ1lpbQ
    MD5:FC2766B3F050F91BA7DB627988D1D498
    SHA1:1FE3AD6D7585CA24C6586EB9CD41AC34F4051741
    SHA-256:306A392AE05EE4934ABE071C40D38455C4F6A39133FDBAD394DD40FFF1420F64
    SHA-512:0BAB84FF5C76D831F6106E9DEB5BA57884F8EFF7DD616EC78C2FEA4CE7C3FBFA884FD4CDB2A6E29723FDAA83077CECCB647A91F7328043E31D4F0999A58A3FD4
    Malicious:false
    Reputation:low
    Preview:PK...........V................META-INF/....PK...........V>j..B...B.......META-INF/MANIFEST.MFManifest-Version: 1.0..Created-By: 1.8.0_372 (Amazon.com Inc.)....PK........F..Vz.p........*...com/sun/codemodel/internal/ClassType.class.......4.-.... ....!.."..#....$....%..&....'..(....)..*....+..,...declarationToken...Ljava/lang/String;...CLASS..&Lcom/sun/codemodel/internal/ClassType;...INTERFACE...ANNOTATION_TYPE_DECL...ENUM...<init>...(Ljava/lang/String;)V...Code...LineNumberTable...LocalVariableTable...this...token...<clinit>...()V...SourceFile...ClassType.java............$com/sun/codemodel/internal/ClassType...class.............interface........@interface........enum........java/lang/Object.1...............................................................F........*...*+...................)...*...+.........................................U.......1...Y...........Y...........Y...........Y........................-......./.$.0..........PK........F..V.Fv........-...com/sun/codemodel/internal
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java archive data (JAR)
    Category:dropped
    Size (bytes):2318582
    Entropy (8bit):7.872039367448507
    Encrypted:false
    SSDEEP:49152:X7HDhv4EVLcJMnz66N8M1IhpvQybDxJv50k:rD55V2Mz66AQyHx7
    MD5:5E382FD74334C625801881C8419640DD
    SHA1:158E1A1DD158265B3A65746302A3AB0AE1728F5D
    SHA-256:4D571EF0E8EBD94FFA7FBEC64F8EAEC21B631CA75DF489988E77318EB231192C
    SHA-512:DFA2396C77DDB23C751339C53C9DE3B4DC2828DAE9ED054D987B8340181813D5D5D371FBD3A4359434FB4BA2BCE3C685D9E7FB9752F7DE0D03A76A2323388AE5
    Malicious:false
    Reputation:low
    Preview:PK..........V................META-INF/......PK..............PK..........V................META-INF/MANIFEST.MF.M..LK-...K-*...R0.3..r.JM,IM.u...X......)h8.&V...%..*x.%.i.r.r..PK..>j..B...B...PK..........V................com/PK..........V................com/sun/PK..........V................com/sun/java/PK..........V................com/sun/java/swing/PK..........V................com/sun/java/swing/action/PK..........V............+...com/sun/java/swing/action/AboutAction.class.SkO.A.=.............<}!....}..M.D..P...d.E.Yh"F...?.xgZ....ag..3...........20.B?...C..l..H.H.x..9.....,.X.&b9..!..Q...x..)Y...T!...k.fv...d..J..{..<%Q.u.K.....j..[.4C...sV6..I........r.m..|:W.gR..mY...H6..{]...^K.S.......n....g_t.8..W.:cS%.@..*.....F.,.-^..u9.......[d..s...Y.%....E.......W&....-....b.{.b..v....h.bW[%..n..+Ge..9%..5."..x..2...8.a..8.h*.H....3.*..r..).V.r.8..q%...T./`....z....s.N....r../..}Q.:r..j\.Q........n...Q~pPul.:.....J..0F1.0pn.......W...5Q...S.../............b.V..
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java archive data (JAR)
    Category:dropped
    Size (bytes):18368064
    Entropy (8bit):6.012772110231048
    Encrypted:false
    SSDEEP:49152:krXa9wpbN7yAnNQwV07Z3fBLZfPwNqW6EXmlGE+oF6aZz9OUagsLhP/s1qg1lpuf:krXa9wBxV07ZZSLguhQ1lpbQ
    MD5:FC2766B3F050F91BA7DB627988D1D498
    SHA1:1FE3AD6D7585CA24C6586EB9CD41AC34F4051741
    SHA-256:306A392AE05EE4934ABE071C40D38455C4F6A39133FDBAD394DD40FFF1420F64
    SHA-512:0BAB84FF5C76D831F6106E9DEB5BA57884F8EFF7DD616EC78C2FEA4CE7C3FBFA884FD4CDB2A6E29723FDAA83077CECCB647A91F7328043E31D4F0999A58A3FD4
    Malicious:false
    Reputation:low
    Preview:PK...........V................META-INF/....PK...........V>j..B...B.......META-INF/MANIFEST.MFManifest-Version: 1.0..Created-By: 1.8.0_372 (Amazon.com Inc.)....PK........F..Vz.p........*...com/sun/codemodel/internal/ClassType.class.......4.-.... ....!.."..#....$....%..&....'..(....)..*....+..,...declarationToken...Ljava/lang/String;...CLASS..&Lcom/sun/codemodel/internal/ClassType;...INTERFACE...ANNOTATION_TYPE_DECL...ENUM...<init>...(Ljava/lang/String;)V...Code...LineNumberTable...LocalVariableTable...this...token...<clinit>...()V...SourceFile...ClassType.java............$com/sun/codemodel/internal/ClassType...class.............interface........@interface........enum........java/lang/Object.1...............................................................F........*...*+...................)...*...+.........................................U.......1...Y...........Y...........Y...........Y........................-......./.$.0..........PK........F..V.Fv........-...com/sun/codemodel/internal
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:ASCII text
    Category:dropped
    Size (bytes):338
    Entropy (8bit):4.350342463353232
    Encrypted:false
    SSDEEP:6:HjqaAyDbn3TTEtUFKD6r2ZMRr+Lfpb+lMl/ELW1FKXyMdJJRqv/SSTECP00O3XM9:+aLbnDTEt7ur2uELfoWl4WPMvJEICZTV
    MD5:6F3A85984BC597891FEE4FBBA9BA33AC
    SHA1:8A722CBA49B9E881B7688590D17DBEDABA0D001C
    SHA-256:13A21B439A9EAD401BB28C54BB89E98DB1596FDB719FECE1262AD77CE66D0E6A
    SHA-512:4775B74ACB7E9AE6A9FFE6C6825C0AD85A40E6EA2E18A2FB603C70E189BAEF9B3D0F4C09A16703F6D855A365E5E27AAA8261A19B7F07CF22C5177A827D9DF065
    Malicious:false
    Reputation:low
    Preview:The source code provided with samples and demos for the JDK is meant.to illustrate the usage of a given feature or technique and has been.deliberately simplified. Additional steps required for a.production-quality application, such as security checks, input.validation, and proper error handling, might not be present in the.sample code..
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Perl5 module source, ASCII text
    Category:dropped
    Size (bytes):2624
    Entropy (8bit):5.135035557722361
    Encrypted:false
    SSDEEP:48:MXEO6rYJdrYJQSiz3y432sf32s5EtAJ3tcHEElM64WtLY9EtRGAH8u8oa/T4/w:U6rYJdrYJQX3Z3r3dVeE642LuE3Gwo
    MD5:4386A26379A3D50F990951151A911257
    SHA1:D0C02679FD6155971E00D5FDE3537B474BCA8975
    SHA-256:9BDC3BC6E27A5FB9C598CA11BB536F06AF1FD2FA4151856FEA85D1898E27DC21
    SHA-512:E2288F31B5B0551E1BC6DB871ABD7C30FCAA5482214382CDB0334C24D896367B25C587E6F3E678EAA6431994A37238F7324C23ED0138B85AF8B56E6EA2ED9FCC
    Malicious:false
    Reputation:low
    Preview:package checker;../*. * Copyright (c) 2014, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
    Category:dropped
    Size (bytes):2335
    Entropy (8bit):5.102169399510094
    Encrypted:false
    SSDEEP:48:cvSOVRrYJeRrYJbcSTn432sx/32s+Etn3o3tIHYElMr4WjjtC8MIuSKKil:yVRrYJeRrYJbF4393KyEigr4YQFJ5
    MD5:1228AACB451D169D82C9727DE1BA4D2C
    SHA1:8ACFEDF11ACECF5C57F4ADC9B4D961DB06D5ED9B
    SHA-256:CAD984BE8FAD05A9D9CB2D86C86A9F9C90A488B8B55EB9969FF9F01AF29F2DED
    SHA-512:A948D1125D5C02D452052CD5CE73EC3E6E884C009AED4E90057A96782FB9009340A75AFAD6E53DE0183B6F7EB96268699401CEB951BE30F820218FF8ED90713C
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8" standalone="yes"?>.. .. Copyright (c) 2014, Oracle and/or its affiliates. All rights reserved..... Redistribution and use in source and binary forms, with or without.. modification, are permitted provided that the following conditions.. are met:.... - Redistributions of source code must retain the above copyright.. notice, this list of conditions and the following disclaimer..... - Redistributions in binary form must reproduce the above copyright.. notice, this list of conditions and the following disclaimer in the.. documentation and/or other materials provided with the distribution..... - Neither the name of Oracle nor the names of its.. contributors may be used to endorse or promote products derived.. from this software without specific prior written permission..... THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS.. IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITE
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Perl5 module source, ASCII text
    Category:dropped
    Size (bytes):2061
    Entropy (8bit):5.101581951354758
    Encrypted:false
    SSDEEP:48:MXEO6rYJdrYJQSiz3y432sf32s5EtAJ3tcHEElM64WtLY9EtRfdFfHn:U6rYJdrYJQX3Z3r3dVeE642LuE3jHn
    MD5:F49D289F6A8B29E55A9B863458C7ACCC
    SHA1:0FF7E913BFF1BB952A313FEAA6F89F65FB5F6AF1
    SHA-256:F8238F15131C03083E1388CCA3B5F9DB4CF08FE61861603A9ADC6334629A35D0
    SHA-512:F22139DB1165E716ABAAE41158170E7C5A88B19FAF1AC187CE6E00491A656DD5697604AA414CD6B25909910FBF7D49426E9F9024988634823E156AC37CE07A59
    Malicious:false
    Reputation:low
    Preview:package checker;../*. * Copyright (c) 2014, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Perl5 module source, ASCII text
    Category:dropped
    Size (bytes):6195
    Entropy (8bit):4.663306894794236
    Encrypted:false
    SSDEEP:192:o6rsdrsQXJ3r37e6E386PAt41701kze5SCF/:RrsdrsU5D7u3fi4beT
    MD5:F8705F3E360DCDCFEBEE3EBEE24BFBA6
    SHA1:21915E3EB55D42C246779738C5063DC4440307AD
    SHA-256:292A3B1D9594FA611647FEB523E90979D70B853AE0BE01FD42E4496794EDB74B
    SHA-512:63F5A298A393F66B52E477B6E0920BB0EB1E9398790047CFD6DEE66E060A380ECB11C90AADA800A4998BF870A770A926F28DDEE8427719F93C4AFE6DCC11C984
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2014, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABILITY A
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Perl5 module source, ASCII text
    Category:dropped
    Size (bytes):3022
    Entropy (8bit):5.0081946534858215
    Encrypted:false
    SSDEEP:48:oXEO6rYJdrYJQSiz3y432sf32s5EtAJ3tcHEElM64WtLY9EtR85Hj+/i77/Ip7/u:o6rYJdrYJQX3Z3r3dVeE642LuE3c+aGm
    MD5:1E0EF359FD99707DFD0564EF14571985
    SHA1:B63356EF3400DF56E2E97C08C782ACB2DCA35F12
    SHA-256:ECB8D8BBF26D900652FFA8DE0B52B9EE752E81EAA8D15BCF0EDE5C7B2B514056
    SHA-512:C83802F97CCCCA4B70A1C98C141088B1E98C2934897B713C604AB4392AAF5216F2DBE7B7FD74F354C5869C88CADBBA0537046BE4A5A28262A2184735F33DA8B4
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2014, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABILITY A
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Perl5 module source, ASCII text
    Category:dropped
    Size (bytes):2179
    Entropy (8bit):5.1161128312454585
    Encrypted:false
    SSDEEP:48:MXEO6rYJdrYJQSiz3y432sf32s5EtAJ3tcHEElM64WtLY9EtR8qhF:U6rYJdrYJQX3Z3r3dVeE642LuE3RhF
    MD5:E69371C3324320BE47022DC3489E6A59
    SHA1:74D2148F438B2EF577D282670D938CD45C029D4E
    SHA-256:5DAAE31E86AA8F2F8A900CFE64AD3122B561B46D57D214B4C6CAA86560AB47C5
    SHA-512:F17C8783EAB45302D912020B925737D27878DF708E349E87A48C3BE4F0D5CD0AD21C5BDFA1BA6DCDA1AAC7D8C85FC35C03FCF082DF38E0B58585E4F2BFA5D536
    Malicious:false
    Reputation:low
    Preview:package checker;../*. * Copyright (c) 2014, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Perl5 module source, ASCII text
    Category:dropped
    Size (bytes):2061
    Entropy (8bit):5.101581951354758
    Encrypted:false
    SSDEEP:48:MXEO6rYJdrYJQSiz3y432sf32s5EtAJ3tcHEElM64WtLY9EtRfdFfHn:U6rYJdrYJQX3Z3r3dVeE642LuE3jHn
    MD5:F49D289F6A8B29E55A9B863458C7ACCC
    SHA1:0FF7E913BFF1BB952A313FEAA6F89F65FB5F6AF1
    SHA-256:F8238F15131C03083E1388CCA3B5F9DB4CF08FE61861603A9ADC6334629A35D0
    SHA-512:F22139DB1165E716ABAAE41158170E7C5A88B19FAF1AC187CE6E00491A656DD5697604AA414CD6B25909910FBF7D49426E9F9024988634823E156AC37CE07A59
    Malicious:false
    Reputation:low
    Preview:package checker;../*. * Copyright (c) 2014, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Perl5 module source, ASCII text
    Category:dropped
    Size (bytes):3022
    Entropy (8bit):5.0081946534858215
    Encrypted:false
    SSDEEP:48:oXEO6rYJdrYJQSiz3y432sf32s5EtAJ3tcHEElM64WtLY9EtR85Hj+/i77/Ip7/u:o6rYJdrYJQX3Z3r3dVeE642LuE3c+aGm
    MD5:1E0EF359FD99707DFD0564EF14571985
    SHA1:B63356EF3400DF56E2E97C08C782ACB2DCA35F12
    SHA-256:ECB8D8BBF26D900652FFA8DE0B52B9EE752E81EAA8D15BCF0EDE5C7B2B514056
    SHA-512:C83802F97CCCCA4B70A1C98C141088B1E98C2934897B713C604AB4392AAF5216F2DBE7B7FD74F354C5869C88CADBBA0537046BE4A5A28262A2184735F33DA8B4
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2014, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABILITY A
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Perl5 module source, ASCII text
    Category:dropped
    Size (bytes):2179
    Entropy (8bit):5.1161128312454585
    Encrypted:false
    SSDEEP:48:MXEO6rYJdrYJQSiz3y432sf32s5EtAJ3tcHEElM64WtLY9EtR8qhF:U6rYJdrYJQX3Z3r3dVeE642LuE3RhF
    MD5:E69371C3324320BE47022DC3489E6A59
    SHA1:74D2148F438B2EF577D282670D938CD45C029D4E
    SHA-256:5DAAE31E86AA8F2F8A900CFE64AD3122B561B46D57D214B4C6CAA86560AB47C5
    SHA-512:F17C8783EAB45302D912020B925737D27878DF708E349E87A48C3BE4F0D5CD0AD21C5BDFA1BA6DCDA1AAC7D8C85FC35C03FCF082DF38E0B58585E4F2BFA5D536
    Malicious:false
    Reputation:low
    Preview:package checker;../*. * Copyright (c) 2014, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Perl5 module source, ASCII text
    Category:dropped
    Size (bytes):6195
    Entropy (8bit):4.663306894794236
    Encrypted:false
    SSDEEP:192:o6rsdrsQXJ3r37e6E386PAt41701kze5SCF/:RrsdrsU5D7u3fi4beT
    MD5:F8705F3E360DCDCFEBEE3EBEE24BFBA6
    SHA1:21915E3EB55D42C246779738C5063DC4440307AD
    SHA-256:292A3B1D9594FA611647FEB523E90979D70B853AE0BE01FD42E4496794EDB74B
    SHA-512:63F5A298A393F66B52E477B6E0920BB0EB1E9398790047CFD6DEE66E060A380ECB11C90AADA800A4998BF870A770A926F28DDEE8427719F93C4AFE6DCC11C984
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2014, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABILITY A
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
    Category:dropped
    Size (bytes):2335
    Entropy (8bit):5.102169399510094
    Encrypted:false
    SSDEEP:48:cvSOVRrYJeRrYJbcSTn432sx/32s+Etn3o3tIHYElMr4WjjtC8MIuSKKil:yVRrYJeRrYJbF4393KyEigr4YQFJ5
    MD5:1228AACB451D169D82C9727DE1BA4D2C
    SHA1:8ACFEDF11ACECF5C57F4ADC9B4D961DB06D5ED9B
    SHA-256:CAD984BE8FAD05A9D9CB2D86C86A9F9C90A488B8B55EB9969FF9F01AF29F2DED
    SHA-512:A948D1125D5C02D452052CD5CE73EC3E6E884C009AED4E90057A96782FB9009340A75AFAD6E53DE0183B6F7EB96268699401CEB951BE30F820218FF8ED90713C
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8" standalone="yes"?>.. .. Copyright (c) 2014, Oracle and/or its affiliates. All rights reserved..... Redistribution and use in source and binary forms, with or without.. modification, are permitted provided that the following conditions.. are met:.... - Redistributions of source code must retain the above copyright.. notice, this list of conditions and the following disclaimer..... - Redistributions in binary form must reproduce the above copyright.. notice, this list of conditions and the following disclaimer in the.. documentation and/or other materials provided with the distribution..... - Neither the name of Oracle nor the names of its.. contributors may be used to endorse or promote products derived.. from this software without specific prior written permission..... THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS.. IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITE
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Perl5 module source, ASCII text
    Category:dropped
    Size (bytes):2624
    Entropy (8bit):5.135035557722361
    Encrypted:false
    SSDEEP:48:MXEO6rYJdrYJQSiz3y432sf32s5EtAJ3tcHEElM64WtLY9EtRGAH8u8oa/T4/w:U6rYJdrYJQX3Z3r3dVeE642LuE3Gwo
    MD5:4386A26379A3D50F990951151A911257
    SHA1:D0C02679FD6155971E00D5FDE3537B474BCA8975
    SHA-256:9BDC3BC6E27A5FB9C598CA11BB536F06AF1FD2FA4151856FEA85D1898E27DC21
    SHA-512:E2288F31B5B0551E1BC6DB871ABD7C30FCAA5482214382CDB0334C24D896367B25C587E6F3E678EAA6431994A37238F7324C23ED0138B85AF8B56E6EA2ED9FCC
    Malicious:false
    Reputation:low
    Preview:package checker;../*. * Copyright (c) 2014, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Perl5 module source, ASCII text
    Category:dropped
    Size (bytes):3152
    Entropy (8bit):4.9983333858951395
    Encrypted:false
    SSDEEP:96:76rYJdrYJQX3Z3r3dVeE642LuE356wDrPqaXVv3y:76rsdrsQXJ3r37e6E3EwPqkvi
    MD5:37E4F75E95E9A0E56757FE307E549939
    SHA1:3DAF245A74CDFEC547B4D6E4E71E27E8D19E1E5C
    SHA-256:3D3842E4CAB5092DDE8526FEE2E53489265F08C60D3229351EB00BC66A99663A
    SHA-512:5D469E858F8B270ADC5C87C474F945E49A00E0775E992FC617EFC1400B8AB37A21F979D1D4BC58B3375FE511916A52EFA02BE5454B81AF6644C26262969BF229
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2013, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABILITY A
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Perl5 module source, ASCII text
    Category:dropped
    Size (bytes):2982
    Entropy (8bit):5.05094415326601
    Encrypted:false
    SSDEEP:48:1EO6rYJdrYJQSiz3y432sf32s5EtAJ3tcHEElM64WtLY9EtRrkC846Z1/AZnW5yM:76rYJdrYJQX3Z3r3dVeE642LuE3tp6Z7
    MD5:5A1960E5F572E30BF501AFDDC5FB48A7
    SHA1:B80EE931C20DDD3AD65531FE3FA2374E8E11B152
    SHA-256:485838666681C025C43261DEFDF2D1627952B6CB8633BD37367F19C57131993E
    SHA-512:B1A888D0295B75E4F72E12D5075BF204516D477381614D61D7458104A5CB06928AE627499E3536EE9AE1CCF7F2387AD634280FA4184A3E2CCAC877DFA60A7DB2
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2013, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABILITY A
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Perl5 module source, ASCII text
    Category:dropped
    Size (bytes):2582
    Entropy (8bit):5.0358069385038675
    Encrypted:false
    SSDEEP:48:1EO6rYJdrYJQSiz3y432sf32s5EtAJ3tcHEElM64WtLY9EtRg7PgA/it/Q:76rYJdrYJQX3Z3r3dVeE642LuE3eOY
    MD5:B9654D84DC6979D88CD978CD74309758
    SHA1:700E7CAEA2667AD858CC619E03F10D3EFCA26629
    SHA-256:C08A9FB11B01A6446FDC21D48F91FA61D1601BBB80F891D67AE8B2B5C23699D0
    SHA-512:09E96E32D06941BF5A1DFCEEF9F594C8896BF7601BD3CB7C3F230C538198DB17F1AC38DA0F9EC2059905C2B8414DBBF8A2095565B9E029AEF06CEFA329BFD416
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2013, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABILITY A
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Perl5 module source, ASCII text
    Category:dropped
    Size (bytes):3152
    Entropy (8bit):4.9983333858951395
    Encrypted:false
    SSDEEP:96:76rYJdrYJQX3Z3r3dVeE642LuE356wDrPqaXVv3y:76rsdrsQXJ3r37e6E3EwPqkvi
    MD5:37E4F75E95E9A0E56757FE307E549939
    SHA1:3DAF245A74CDFEC547B4D6E4E71E27E8D19E1E5C
    SHA-256:3D3842E4CAB5092DDE8526FEE2E53489265F08C60D3229351EB00BC66A99663A
    SHA-512:5D469E858F8B270ADC5C87C474F945E49A00E0775E992FC617EFC1400B8AB37A21F979D1D4BC58B3375FE511916A52EFA02BE5454B81AF6644C26262969BF229
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2013, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABILITY A
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Perl5 module source, ASCII text
    Category:dropped
    Size (bytes):2982
    Entropy (8bit):5.05094415326601
    Encrypted:false
    SSDEEP:48:1EO6rYJdrYJQSiz3y432sf32s5EtAJ3tcHEElM64WtLY9EtRrkC846Z1/AZnW5yM:76rYJdrYJQX3Z3r3dVeE642LuE3tp6Z7
    MD5:5A1960E5F572E30BF501AFDDC5FB48A7
    SHA1:B80EE931C20DDD3AD65531FE3FA2374E8E11B152
    SHA-256:485838666681C025C43261DEFDF2D1627952B6CB8633BD37367F19C57131993E
    SHA-512:B1A888D0295B75E4F72E12D5075BF204516D477381614D61D7458104A5CB06928AE627499E3536EE9AE1CCF7F2387AD634280FA4184A3E2CCAC877DFA60A7DB2
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2013, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABILITY A
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Perl5 module source, ASCII text
    Category:dropped
    Size (bytes):2582
    Entropy (8bit):5.0358069385038675
    Encrypted:false
    SSDEEP:48:1EO6rYJdrYJQSiz3y432sf32s5EtAJ3tcHEElM64WtLY9EtRg7PgA/it/Q:76rYJdrYJQX3Z3r3dVeE642LuE3eOY
    MD5:B9654D84DC6979D88CD978CD74309758
    SHA1:700E7CAEA2667AD858CC619E03F10D3EFCA26629
    SHA-256:C08A9FB11B01A6446FDC21D48F91FA61D1601BBB80F891D67AE8B2B5C23699D0
    SHA-512:09E96E32D06941BF5A1DFCEEF9F594C8896BF7601BD3CB7C3F230C538198DB17F1AC38DA0F9EC2059905C2B8414DBBF8A2095565B9E029AEF06CEFA329BFD416
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2013, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABILITY A
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java source, ASCII text
    Category:dropped
    Size (bytes):2480
    Entropy (8bit):5.088333360536664
    Encrypted:false
    SSDEEP:48:oXEO6rYJdrYJQSiz3y432sf32s5EtAJ3tcHEElM64WtLY9EtR2QAVgDAmxQAlJdy:o6rYJdrYJQX3Z3r3dVeE642LuE32QA22
    MD5:F9252F8C3ACA1F3BF66EC16F202A5EAD
    SHA1:879440A09FA21CD3A3B24C7FD02FDFA558E8C140
    SHA-256:DB8D3A6E8F2321982FC6285A7801F28B01E6E3A5EF094857DB05AB8136BF17E9
    SHA-512:DF65671182121EFEC7BC6CD17021F767AD2B196509F0CBF77F84179C6322F4A189E71CF1E6B861609FB17C957ADAB02F7CF5F99BB13D872B5F44F3E9F5AF2DB6
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2014, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABILITY A
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java source, ASCII text
    Category:dropped
    Size (bytes):2730
    Entropy (8bit):4.98917217537018
    Encrypted:false
    SSDEEP:48:oXEO6rYJdrYJQSiz3y432sf32s5EtAJ3tcHEElM64WtLY9EtRVHpL0B/HGgNIbyM:o6rYJdrYJQX3Z3r3dVeE642LuE3VHpLV
    MD5:AB3FAF4DF3F33B41C62B8B2030702394
    SHA1:E9A99DF515CCA241924683244A76E68946C34102
    SHA-256:F59BC3BE92A904A47AB136D0F4A3F685C6CB488E385BD9B1671770A91DC3B791
    SHA-512:C3BE9353D9E2FA765C04A90A77DDC2E8289333EE191DA320926E6F2FC8CEA123CF792EE97091CB8DE4BC2BC2FA3616111506BEF6A146ABA8092986885C5F44FE
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2014, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABILITY A
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java source, ASCII text
    Category:dropped
    Size (bytes):2797
    Entropy (8bit):5.058630799035258
    Encrypted:false
    SSDEEP:48:oXEO6rYJdrYJQSiz3y432sf32s5EtAJ3tcHEElM64WtLY9EtRg5lfL8H7D/MPe/5:o6rYJdrYJQX3Z3r3dVeE642LuE3wfYHB
    MD5:391834B1289A7D701542EEDA6F9158E1
    SHA1:885C9152778C13BC4AAE3BD611EEE071BCF94179
    SHA-256:19422989A228292F0E630E9C7A7B2E2BADB103F554B326627ED3A1BBCCF5C687
    SHA-512:188F47E399EDC9B25B21E38789A2467C8460786AB45F0906B45339F46117379FE83A1BF8F582D8D9F264C576E1CB8DAE11EFF47D3E275DE5C6E9A73E3F55F021
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2014, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABILITY A
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java source, ASCII text
    Category:dropped
    Size (bytes):4060
    Entropy (8bit):4.616365658780371
    Encrypted:false
    SSDEEP:96:o6rYJdrYJQX3Z3r3dVeE642LuE3VtP1XSD2rQgSGOgD2rjWgSQZCJi8:o6rsdrsQXJ3r37e6E3VtP1iD2rQgSGLP
    MD5:210584E9C93C30F824317E88D39DDB5E
    SHA1:1D8F01529031FBF2685D56E28DACA956A275FB83
    SHA-256:32F9A0E60B2EC5A8CA40FBE74720EABC69E8D853BDC8CBD1A718FF489687A8DA
    SHA-512:0E441DC4EF1524CD2A680EC595738D7E8C3E771F49FCE3F8EF57253E4C869959CBCFCDD1BD56550E807153DDDFEFB3833A591E86A22E988219B6613473435A5B
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2014, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABILITY A
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java source, ASCII text
    Category:dropped
    Size (bytes):2730
    Entropy (8bit):4.98917217537018
    Encrypted:false
    SSDEEP:48:oXEO6rYJdrYJQSiz3y432sf32s5EtAJ3tcHEElM64WtLY9EtRVHpL0B/HGgNIbyM:o6rYJdrYJQX3Z3r3dVeE642LuE3VHpLV
    MD5:AB3FAF4DF3F33B41C62B8B2030702394
    SHA1:E9A99DF515CCA241924683244A76E68946C34102
    SHA-256:F59BC3BE92A904A47AB136D0F4A3F685C6CB488E385BD9B1671770A91DC3B791
    SHA-512:C3BE9353D9E2FA765C04A90A77DDC2E8289333EE191DA320926E6F2FC8CEA123CF792EE97091CB8DE4BC2BC2FA3616111506BEF6A146ABA8092986885C5F44FE
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2014, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABILITY A
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java source, ASCII text
    Category:dropped
    Size (bytes):4060
    Entropy (8bit):4.616365658780371
    Encrypted:false
    SSDEEP:96:o6rYJdrYJQX3Z3r3dVeE642LuE3VtP1XSD2rQgSGOgD2rjWgSQZCJi8:o6rsdrsQXJ3r37e6E3VtP1iD2rQgSGLP
    MD5:210584E9C93C30F824317E88D39DDB5E
    SHA1:1D8F01529031FBF2685D56E28DACA956A275FB83
    SHA-256:32F9A0E60B2EC5A8CA40FBE74720EABC69E8D853BDC8CBD1A718FF489687A8DA
    SHA-512:0E441DC4EF1524CD2A680EC595738D7E8C3E771F49FCE3F8EF57253E4C869959CBCFCDD1BD56550E807153DDDFEFB3833A591E86A22E988219B6613473435A5B
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2014, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABILITY A
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java source, ASCII text
    Category:dropped
    Size (bytes):2480
    Entropy (8bit):5.088333360536664
    Encrypted:false
    SSDEEP:48:oXEO6rYJdrYJQSiz3y432sf32s5EtAJ3tcHEElM64WtLY9EtR2QAVgDAmxQAlJdy:o6rYJdrYJQX3Z3r3dVeE642LuE32QA22
    MD5:F9252F8C3ACA1F3BF66EC16F202A5EAD
    SHA1:879440A09FA21CD3A3B24C7FD02FDFA558E8C140
    SHA-256:DB8D3A6E8F2321982FC6285A7801F28B01E6E3A5EF094857DB05AB8136BF17E9
    SHA-512:DF65671182121EFEC7BC6CD17021F767AD2B196509F0CBF77F84179C6322F4A189E71CF1E6B861609FB17C957ADAB02F7CF5F99BB13D872B5F44F3E9F5AF2DB6
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2014, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABILITY A
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java source, ASCII text
    Category:dropped
    Size (bytes):2797
    Entropy (8bit):5.058630799035258
    Encrypted:false
    SSDEEP:48:oXEO6rYJdrYJQSiz3y432sf32s5EtAJ3tcHEElM64WtLY9EtRg5lfL8H7D/MPe/5:o6rYJdrYJQX3Z3r3dVeE642LuE3wfYHB
    MD5:391834B1289A7D701542EEDA6F9158E1
    SHA1:885C9152778C13BC4AAE3BD611EEE071BCF94179
    SHA-256:19422989A228292F0E630E9C7A7B2E2BADB103F554B326627ED3A1BBCCF5C687
    SHA-512:188F47E399EDC9B25B21E38789A2467C8460786AB45F0906B45339F46117379FE83A1BF8F582D8D9F264C576E1CB8DAE11EFF47D3E275DE5C6E9A73E3F55F021
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2014, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABILITY A
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:HTML document, ASCII text, with CRLF line terminators
    Category:dropped
    Size (bytes):3433
    Entropy (8bit):4.489062491587569
    Encrypted:false
    SSDEEP:96:3LUD+TMG/IpiOvUQBlstEkgCfL8sXnyvU:gD+TM1vU2lsBfL8sXnyvU
    MD5:3751D94F38454726ABB1E8DCA5CDDDD2
    SHA1:8CF20A6BF2FBA6A284DDA8BDEDF2E010BB9D184D
    SHA-256:ED9E7057998BADC44D456C4E7D05281D181B2C6EC320CEB94C2CB546F989EB54
    SHA-512:7AB64CBB6967693C5764712974884EDFF60B0E16D9139B3374A97F78F8393723071278E584165F13C8C1FADB096EA779992C1D83E930F27E37ED228F6A450443
    Malicious:false
    Reputation:low
    Preview:<!DOCTYPE html>..<html>..<head>.. <title>Repeating Annotations Demo</title>..</head>..<body>..<h2>Repeating Annotations Demo</h2>....<p>.. This demo shows how to use repeating annotations at runtime and at compile time...</p>....<ul>.. <li><h3>Dependency checker.</h3>.... <p>.. Shows how to define repeating annotations and process them at compile time... The problem domain is some code that performs useful operations on hardware devices... The code relies on "modules" to be present on the devices. Applicability of the code to a particular.. device is checked while compiling the code for a particular device... A set of modules provided by a device is listed in an xml file that turns red during the compilation.. phase and is compared with the required module set specified by annotations... For instance, there is kettle with hardware modules: thermometer, display, and clock... There is
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:HTML document, ASCII text, with CRLF line terminators
    Category:dropped
    Size (bytes):3433
    Entropy (8bit):4.489062491587569
    Encrypted:false
    SSDEEP:96:3LUD+TMG/IpiOvUQBlstEkgCfL8sXnyvU:gD+TM1vU2lsBfL8sXnyvU
    MD5:3751D94F38454726ABB1E8DCA5CDDDD2
    SHA1:8CF20A6BF2FBA6A284DDA8BDEDF2E010BB9D184D
    SHA-256:ED9E7057998BADC44D456C4E7D05281D181B2C6EC320CEB94C2CB546F989EB54
    SHA-512:7AB64CBB6967693C5764712974884EDFF60B0E16D9139B3374A97F78F8393723071278E584165F13C8C1FADB096EA779992C1D83E930F27E37ED228F6A450443
    Malicious:false
    Reputation:low
    Preview:<!DOCTYPE html>..<html>..<head>.. <title>Repeating Annotations Demo</title>..</head>..<body>..<h2>Repeating Annotations Demo</h2>....<p>.. This demo shows how to use repeating annotations at runtime and at compile time...</p>....<ul>.. <li><h3>Dependency checker.</h3>.... <p>.. Shows how to define repeating annotations and process them at compile time... The problem domain is some code that performs useful operations on hardware devices... The code relies on "modules" to be present on the devices. Applicability of the code to a particular.. device is checked while compiling the code for a particular device... A set of modules provided by a device is listed in an xml file that turns red during the compilation.. phase and is compared with the required module set specified by annotations... For instance, there is kettle with hardware modules: thermometer, display, and clock... There is
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java source, ASCII text
    Category:dropped
    Size (bytes):11397
    Entropy (8bit):4.6442533073054255
    Encrypted:false
    SSDEEP:192:x6rsdrsQXJ3r37e6E3xb+6e5U4cEVqOoC6pRCyjIDOaBzi/aa5cfnUcywSnSSL2z:8rsdrsU5D7u3dL6gVxAGcfnUcjSnSXjN
    MD5:65AD4D107F8587F498193019C86AFB2A
    SHA1:3D054FF90235C9670104E4F8EEF1F0B60A8D82F3
    SHA-256:C99A9695A37307E37F5CEB3346291C947F88E77DE0A2057F322D62FCD5D0C171
    SHA-512:7390C1A705FBB2FD40985A0855893239466387787E01A3F24B70D90FFC3FBAB710F8D2FE011C2C5443C10D1C10C8BBF3C04A0A327A2FE801E9C342E8F298E332
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2011, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABILITY A
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java source, ASCII text
    Category:dropped
    Size (bytes):5632
    Entropy (8bit):4.784206234768054
    Encrypted:false
    SSDEEP:96:q06rYJdrYJQX3Z3r3dVeE642LuE3GeClGBcRefyv0DDwfLjE2XBZCyfQSVVTvo:x6rsdrsQXJ3r37e6E3JClGBc4fyvGwfa
    MD5:3453F5D2E90B8555F1C9443FCBD899D2
    SHA1:31A885056ECEC928FDF0C17D24AD92E8715D5BDC
    SHA-256:4FA6DD1FF4A5195959B3889FF02A4820D60E116A5CC28980A54DB94DDC65A185
    SHA-512:0E92295B766FE5259C3DD78AD171BBBA291A0D2BEEE23CFE472DAC80FCD69CEDC25F3A5190880C599EBBCC5E8FE894B7573F410A02608E37B82E0ADB076F6DB4
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2011, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABILITY A
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java source, ASCII text
    Category:dropped
    Size (bytes):5632
    Entropy (8bit):4.784206234768054
    Encrypted:false
    SSDEEP:96:q06rYJdrYJQX3Z3r3dVeE642LuE3GeClGBcRefyv0DDwfLjE2XBZCyfQSVVTvo:x6rsdrsQXJ3r37e6E3JClGBc4fyvGwfa
    MD5:3453F5D2E90B8555F1C9443FCBD899D2
    SHA1:31A885056ECEC928FDF0C17D24AD92E8715D5BDC
    SHA-256:4FA6DD1FF4A5195959B3889FF02A4820D60E116A5CC28980A54DB94DDC65A185
    SHA-512:0E92295B766FE5259C3DD78AD171BBBA291A0D2BEEE23CFE472DAC80FCD69CEDC25F3A5190880C599EBBCC5E8FE894B7573F410A02608E37B82E0ADB076F6DB4
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2011, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABILITY A
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java source, ASCII text
    Category:dropped
    Size (bytes):11397
    Entropy (8bit):4.6442533073054255
    Encrypted:false
    SSDEEP:192:x6rsdrsQXJ3r37e6E3xb+6e5U4cEVqOoC6pRCyjIDOaBzi/aa5cfnUcywSnSSL2z:8rsdrsU5D7u3dL6gVxAGcfnUcjSnSXjN
    MD5:65AD4D107F8587F498193019C86AFB2A
    SHA1:3D054FF90235C9670104E4F8EEF1F0B60A8D82F3
    SHA-256:C99A9695A37307E37F5CEB3346291C947F88E77DE0A2057F322D62FCD5D0C171
    SHA-512:7390C1A705FBB2FD40985A0855893239466387787E01A3F24B70D90FFC3FBAB710F8D2FE011C2C5443C10D1C10C8BBF3C04A0A327A2FE801E9C342E8F298E332
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2011, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABILITY A
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:ASCII text
    Category:dropped
    Size (bytes):338
    Entropy (8bit):4.350342463353232
    Encrypted:false
    SSDEEP:6:HjqaAyDbn3TTEtUFKD6r2ZMRr+Lfpb+lMl/ELW1FKXyMdJJRqv/SSTECP00O3XM9:+aLbnDTEt7ur2uELfoWl4WPMvJEICZTV
    MD5:6F3A85984BC597891FEE4FBBA9BA33AC
    SHA1:8A722CBA49B9E881B7688590D17DBEDABA0D001C
    SHA-256:13A21B439A9EAD401BB28C54BB89E98DB1596FDB719FECE1262AD77CE66D0E6A
    SHA-512:4775B74ACB7E9AE6A9FFE6C6825C0AD85A40E6EA2E18A2FB603C70E189BAEF9B3D0F4C09A16703F6D855A365E5E27AAA8261A19B7F07CF22C5177A827D9DF065
    Malicious:false
    Reputation:low
    Preview:The source code provided with samples and demos for the JDK is meant.to illustrate the usage of a given feature or technique and has been.deliberately simplified. Additional steps required for a.production-quality application, such as security checks, input.validation, and proper error handling, might not be present in the.sample code..
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:ASCII text
    Category:dropped
    Size (bytes):1634
    Entropy (8bit):4.895052250234343
    Encrypted:false
    SSDEEP:48:wu576L0I8JKIXyivzSk4CqVYdPiUz41Ij:9okJKIXFvzS5FYpBj
    MD5:1A5B2D8EFCD774FD9A37C6CA8C7CDCE8
    SHA1:47D42BF5BC6E73F1D7A508315FB7E7E91EF6EB31
    SHA-256:950705EE575D5BCEDFF131FDA90796A140FED644F0B4485FD2FCA96D1692A19C
    SHA-512:71DB604B92EE131180C0EEF530F42E133A466A540AE450288EFA48AF14A6BF71D0B3A590F32B9289DDAC50B891B21272D9787A5471CF4595021B47BFD7EE8CEC
    Malicious:false
    Reputation:low
    Preview:# IMPORTANT NOTE.#.# If you made a private copy of this project you may have to update the.# nbjdk.home variable at the end of this file..# .# To be able to run the test-suite, you will also have to set the.# variable:.#.# libs.junit.classpath=<junit.jar> .#..main.dir=...src.dir=${main.dir}/src.test.src.dir=${main.dir}/test..build.dir=build.classes.dir=${build.dir}/classes..dist.dir=dist.jar=${dist.dir}/jmx-scandir.jar.javadoc.dir=${dist.dir}/javadoc..build.test.classes.dir=${build.dir}/test/classes.build.test.results.dir=${build.dir}/test/results..build.sysclasspath=ignore.# E.g.: cp=lib/x.jar:lib/y.jar.cp=.extra.run.cp=..# To be able to run the test-suite, set the following property:.# libs.junit.classpath=.....javac.test.classpath=\. ${classes.dir}:\. ${libs.junit.classpath}..main.agent.class=com.sun.jmx.examples.scandir.ScanDirAgent.main.client.class=com.sun.jmx.examples.scandir.ScanDirClient.main.class=${main.client.class}..run.jvmargs=-Djava.util.logging.config.file=loggin
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):7417
    Entropy (8bit):4.895166150367526
    Encrypted:false
    SSDEEP:96:YorYJTrYJEfiQX3f3jp28yzTcHtpTrQz9RihmgIFEui42SvisT:YorsTrs+jX3f3d2JX6LTSRiBCUq
    MD5:A68BA7C3D00A52A4C182E4787710D052
    SHA1:78C4FB8B4962F0DDD8E6993594EE2ED2E44EED84
    SHA-256:11CAD03F4E3F5787E38CF044EB71CF115CE3339D8203CE03054F3A8DA87F5C70
    SHA-512:E420C80E1E9CF16CA4C6CB0BF7B78434329E4170C0A959491C05275D60758E03BB47DFCA89AB3EB834AA070A8F3745ADDEFDCF9500C55A3FAB980746E7211DA5
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?>.. . Copyright (c) 2006, Oracle and/or its affiliates. All rights reserved... Redistribution and use in source and binary forms, with or without. modification, are permitted provided that the following conditions. are met:.. - Redistributions of source code must retain the above copyright. notice, this list of conditions and the following disclaimer... - Redistributions in binary form must reproduce the above copyright. notice, this list of conditions and the following disclaimer in the. documentation and/or other materials provided with the distribution... - Neither the name of Oracle nor the names of its. contributors may be used to endorse or promote products derived. from this software without specific prior written permission... THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. THE IMPLIED WARRANTIES OF MERCHANTABILITY
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, comment: "", baseline, precision 8, 388x440, components 3
    Category:dropped
    Size (bytes):33121
    Entropy (8bit):7.818745948313405
    Encrypted:false
    SSDEEP:768:/X36NMNtuPXUcQ4tacjyhbOgLrZ1bcccsNQAY5KBw+Lh8LVdCCC:/6NMNtuVd7yhS43bcccMDy+Lh8LDCCC
    MD5:A2B9B1985473CCA2A2D0FD349C8BA07F
    SHA1:85E462B5C6365302F33DFBB930C2FED096E0589C
    SHA-256:5893EB84DF5062A0D6BA7814D8D4FD2F50DEF6322389DC2883943D623DD01311
    SHA-512:E6D4252E6AD8E553774397310D9402850AF11371B05F06CB074C042582235F15A4D4A034CADCEED2308859E422D201DC20BCAECA9BF5816D36B3680493DC6550
    Malicious:false
    Reputation:low
    Preview:......JFIF.............J..CREATOR: XV Version 3.10a Rev: 12/29/94 Quality = 75, Smoothing = 0....C................................... $.' ",#..(7),01444.'9=82<.342...C...........2!.!22222222222222222222222222222222222222222222222222..........."............................................................}........!1A..Qa."q.2....#B...R..$3br........%&'()*456789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz..............................................................................................................................w.......!1..AQ.aq."2...B.....#3R..br...$4.%.....&'()*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz....................................................................................?...7..I.n.'/...H.8..H9...K.r2.Z.$..#.!0ks...-.u8....?....1cu6.m$W..I....U....dpr+..i.m_C..M#.4..."..Ab..0?.S...._........_.&..>.w..u$..4j..H.RA.OS!........S...S..te.8.G#.....O..........4...........MbZx.Y..[D..'../-..D....Q.*....nl....[.4;.7Fy.V..&..5.-.bE..+.. ......}b.q.8.............M.
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, comment: "", baseline, precision 8, 387x423, components 3
    Category:dropped
    Size (bytes):30188
    Entropy (8bit):7.799638877613019
    Encrypted:false
    SSDEEP:768:/X36E2nQTY5cLKqPipNdDBRDXPciOiYhY+:/6xQT5KqaltZPciOiYS+
    MD5:DB94BA1453EE827A13F41206920D10E0
    SHA1:3612F1ED6574412823E3F3F5C3E7193F29728FFA
    SHA-256:08FA1526840D3A96BE183C5C65B3C52AE8923ED09136A6CB5582DF4912A332D0
    SHA-512:41CB8608C1E524FD8CE72B7BBED1B991313D4A1E5C20F4A551A671C8E67D8872E2C5AF54E8AADB80C0CB2C6B4C6A8B42BDE5323FE0AC2324BA430E11FE8B3621
    Malicious:false
    Reputation:low
    Preview:......JFIF.............J..CREATOR: XV Version 3.10a Rev: 12/29/94 Quality = 75, Smoothing = 0....C................................... $.' ",#..(7),01444.'9=82<.342...C...........2!.!22222222222222222222222222222222222222222222222222..........."............................................................}........!1A..Qa."q.2....#B...R..$3br........%&'()*456789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz..............................................................................................................................w.......!1..AQ.aq."2...B.....#3R..br...$4.%.....&'()*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz....................................................................................?...7..I.n.'/...H.8..H9...K.r2.Z.$..#.!0ks...-.u8....?....1cu6.m$W..I....U....dpr+..i.m_C..M#.4..."..Ab..0?.S...._........_.&..>.w..u$..4j..H.RA.OS!........S...S..te.8.G#.....O..........4...........MbZx.Y..[D..'../-..D....Q.*....nl....[.4;.7Fy.V..&..5.-.bE..+.. ......}b.q.8.............M.
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, comment: "", baseline, precision 8, 391x428, components 3
    Category:dropped
    Size (bytes):28942
    Entropy (8bit):7.813849737246345
    Encrypted:false
    SSDEEP:384:MrXsHZCZs9V9LRxQn7PzWfknDxkjvIkjLmdIgkgdXCEIvp4xkaGhjdGJmoXCnm3:M7K0CSLXCAALmdIEIB4mVMlXCn0
    MD5:1B37D6498EC0A5244F458B602B3D41A7
    SHA1:733D9822EDC4B7EAB1A14557CCF60E0E901E2812
    SHA-256:B82738F7516EE55227766813A2979925DDC27DDF0C6FE0B8A1A1DAC7C1B34741
    SHA-512:3AC701BCD6968C14CAAA16F215CD1F359AAACDD21E3AB26582F09AAEB1995262F8BCD334BED75804378E6DD1BA18DD7C8573FF798AF403E3A8DF2DA3D338080A
    Malicious:false
    Reputation:low
    Preview:......JFIF.............J..CREATOR: XV Version 3.10a Rev: 12/29/94 Quality = 75, Smoothing = 0....C................................... $.' ",#..(7),01444.'9=82<.342...C...........2!.!22222222222222222222222222222222222222222222222222..........."............................................................}........!1A..Qa."q.2....#B...R..$3br........%&'()*456789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz..............................................................................................................................w.......!1..AQ.aq."2...B.....#3R..br...$4.%.....&'()*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz....................................................................................?...GR.|Uq..w.....F6.I$......e...m?.....M8....n..U.Q.WZtZ..51=...p.UDn..(N.]q.=.^9.uJ|.I-.C.F.._............t}..............xj. ...8d....[.=..s..%(..Y.X...$......K../.j.G.|g..A[O....>..?..........k..:..se{l...M.{N...2..a1.9.9......sg..^!."..".Y..].....mV...C..........5.../....+i..|..7G.
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, comment: "CREATOR: XV Version 3.10a Rev: 12/29/94 Quality = 75, Smoothing = 0", baseline, precision 8, 790x563, components 3
    Category:dropped
    Size (bytes):88344
    Entropy (8bit):7.830818137367989
    Encrypted:false
    SSDEEP:1536:jdTCCvMZ2WGHafrWk+gaRGJ3OtAkGQc1v/5iiiiif/CbzWvCTHl60:hTCCEZw6frgiJ+tzGmC3mCTd
    MD5:9A0E83B52D3C7A757253EC43DC8381A0
    SHA1:D8D7974AD9AEDCBBBCE6A882EC3E4DBF0A417D3A
    SHA-256:8BED3EEF4C29A099B139F5200930505B970A6937B44765B6BF49BBF3A596F83D
    SHA-512:E4DDC2E777B8EA3E199D9CD0C2C958F5E63823129A1E24771B03910D67E0E99905EADE1993EDF5A635789D7CE4DC17B8A1BD53156935FCC4AB8A6D00A6CDA7E2
    Malicious:false
    Reputation:low
    Preview:......JFIF.............HCREATOR: XV Version 3.10a Rev: 12/29/94 Quality = 75, Smoothing = 0....C................................... $.' ",#..(7),01444.'9=82<.342...C...........2!.!22222222222222222222222222222222222222222222222222......3...."............................................................}........!1A..Qa."q.2....#B...R..$3br........%&'()*456789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz..............................................................................................................................w.......!1..AQ.aq."2...B.....#3R..br...$4.%.....&'()*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz....................................................................................?....xgA..:,..t.....Ik.gc..'..W..<+nPI.i ...G..R.L..........kY..M.2..X.~vo....^ej.".!.J........v.q.u.iq..D.J..bC...N....J......?.........T<X./.. .. iw o9?.?.A}5..%....(.....{..a.!..\,.`F.rA8m.:E..3i#....S........?....S........?.+.>..J...Lt.J.].....G&x...2.:.3c.......<w6.?.w...2..;.m.....}...v.
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, comment: "CREATOR: XV Version 3.10a Rev: 12/29/94 Quality = 75, Smoothing = 0", baseline, precision 8, 755x443, components 3
    Category:dropped
    Size (bytes):74983
    Entropy (8bit):7.807712031230282
    Encrypted:false
    SSDEEP:1536:4dTqjHjMcQQ9aImmYYXba6sw37f9Oj79S7aU4P8tZB:OT0DMcQQoImmYN2379zGVP8t
    MD5:31FB6B9321792DA2588B44A5B0185765
    SHA1:C20EAEC6E0D591E65275F8CED6DF1C264AACDF8C
    SHA-256:C617EDE6B57D90D43DE23F78EEC2CFD64A61843CDFB0A33E7BB5395C5AA7F8FF
    SHA-512:619EB873CF697C59385FAFFF3BEF039701AB8AD3B7117F24B88ABB38526817A91BB60FE2FD4B1335D54BE5950E9377ECE5163961FE66719CB22EBA95FE8CC3C8
    Malicious:false
    Reputation:low
    Preview:......JFIF.............HCREATOR: XV Version 3.10a Rev: 12/29/94 Quality = 75, Smoothing = 0....C................................... $.' ",#..(7),01444.'9=82<.342...C...........2!.!22222222222222222222222222222222222222222222222222..........."............................................................}........!1A..Qa."q.2....#B...R..$3br........%&'()*456789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz..............................................................................................................................w.......!1..AQ.aq."2...B.....#3R..br...$4.%.....&'()*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz....................................................................................?....xgA..:,..t.....Ik.gc..'..W..<+nPI.i ...G..R.L..........kY..M.2..X.~vo....^ej.".!.J........v.q.u.iq..D.J..bC...N....J......?.........T<X./.. .. iw o9?.?.A}5..%....(.....{..a.!..\,.`F.rA8m.:E..3i#....S........?....S........?.+.>..J...Lt.J.].....G&x...2.:.3c.......<w6.?.w...2..;.m.....}...v.
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, comment: "", baseline, precision 8, 391x428, components 3
    Category:dropped
    Size (bytes):28942
    Entropy (8bit):7.813849737246345
    Encrypted:false
    SSDEEP:384:MrXsHZCZs9V9LRxQn7PzWfknDxkjvIkjLmdIgkgdXCEIvp4xkaGhjdGJmoXCnm3:M7K0CSLXCAALmdIEIB4mVMlXCn0
    MD5:1B37D6498EC0A5244F458B602B3D41A7
    SHA1:733D9822EDC4B7EAB1A14557CCF60E0E901E2812
    SHA-256:B82738F7516EE55227766813A2979925DDC27DDF0C6FE0B8A1A1DAC7C1B34741
    SHA-512:3AC701BCD6968C14CAAA16F215CD1F359AAACDD21E3AB26582F09AAEB1995262F8BCD334BED75804378E6DD1BA18DD7C8573FF798AF403E3A8DF2DA3D338080A
    Malicious:false
    Reputation:low
    Preview:......JFIF.............J..CREATOR: XV Version 3.10a Rev: 12/29/94 Quality = 75, Smoothing = 0....C................................... $.' ",#..(7),01444.'9=82<.342...C...........2!.!22222222222222222222222222222222222222222222222222..........."............................................................}........!1A..Qa."q.2....#B...R..$3br........%&'()*456789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz..............................................................................................................................w.......!1..AQ.aq."2...B.....#3R..br...$4.%.....&'()*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz....................................................................................?...GR.|Uq..w.....F6.I$......e...m?.....M8....n..U.Q.WZtZ..51=...p.UDn..(N.]q.=.^9.uJ|.I-.C.F.._............t}..............xj. ...8d....[.=..s..%(..Y.X...$......K../.j.G.|g..A[O....>..?..........k..:..se{l...M.{N...2..a1.9.9......sg..^!."..".Y..].....mV...C..........5.../....+i..|..7G.
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, comment: "", baseline, precision 8, 390x393, components 3
    Category:dropped
    Size (bytes):27845
    Entropy (8bit):7.838899807550583
    Encrypted:false
    SSDEEP:768:E/tXnOWeNWa93d76/qQcBF5okFF3zhbKJ+K1oGf9II/:E/NnOWcW7CQdW6+Knf9Iu
    MD5:85761BF89B2EEC20DDC722D1EF330813
    SHA1:7A586A3F3D827389AE4B7D6AE3E44ED0C5019741
    SHA-256:7F6D2917E9905E3DCB92CC383A215EEE51F12FA841DAF8EBE854173D4E9DA584
    SHA-512:92B55FB117B30C00749C3B914E6695146BFE01B0E44C2508999001FC48C46B23CEC5F3C068068FF5FBE1335C87371E130C22CB1AF60C047EF3E6DD045E74BF8D
    Malicious:false
    Reputation:low
    Preview:......JFIF.............J..CREATOR: XV Version 3.10a Rev: 12/29/94 Quality = 75, Smoothing = 0....C................................... $.' ",#..(7),01444.'9=82<.342...C...........2!.!22222222222222222222222222222222222222222222222222..........."............................................................}........!1A..Qa."q.2....#B...R..$3br........%&'()*456789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz..............................................................................................................................w.......!1..AQ.aq."2...B.....#3R..br...$4.%.....&'()*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz....................................................................................?..Q.....6.}.0.k+'... ..$.....}..............|$Pk.#...?C...J.&=R.U.[.......\.1.s".........T.vIt.s.7W.c.3.......?...e...m?.........Z.as2h.Q..w..h.q.Lz.s...'...VM...fy..2..$..$.......s.e...m?....../....+i..|..7N...6:........kkkDG...t,......I.....o..3>.h..fH`h&.J....P.Wgl...{W.}..~f_.|g..A
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, comment: "CREATOR: XV Version 3.10a Rev: 12/29/94 Quality = 75, Smoothing = 0", baseline, precision 8, 774x499, components 3
    Category:dropped
    Size (bytes):70422
    Entropy (8bit):7.7964235424689665
    Encrypted:false
    SSDEEP:1536:6dThtfsXEQQPfEGGKv9kL0JgHoMusxKDjiQRcLL9ZUR:8T3kUQQEGGub4oM4jiQR0+
    MD5:9E0ED4D9EDAA4C024A504EC602935686
    SHA1:DF0584B71636584C552FC63AA007EDF261845AC3
    SHA-256:48CCFF886C9628BD5CE1A7B49B3B95C1EF06295C67EBB3D87FE10D4A41C56ED2
    SHA-512:AD3F77327ABACEFD56A95E43C912D54BF8E4985972A44389FE18C171DB80256828260030D22BA46737B1F739A0E05A9BA15B572A08DBE6920F6BDA3A18AF5EE5
    Malicious:false
    Reputation:low
    Preview:......JFIF.............HCREATOR: XV Version 3.10a Rev: 12/29/94 Quality = 75, Smoothing = 0....C................................... $.' ",#..(7),01444.'9=82<.342...C...........2!.!22222222222222222222222222222222222222222222222222..........."............................................................}........!1A..Qa."q.2....#B...R..$3br........%&'()*456789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz..............................................................................................................................w.......!1..AQ.aq."2...B.....#3R..br...$4.%.....&'()*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz....................................................................................?....xgA..:,..t.....Ik.gc..'..W..<+nPI.i ...G..R.L..........kY..M.2..X.~vo....^ej.".!.J........v.q.u.iq..D.J..bC...N....J......?.........T<X./.. .. iw o9?.?.A}5..%....(.....{..a.!..\,.`F.rA8m.:E..3i#....S........?....S........?.+.>..J...Lt.J.].....G&x...2.:.3c.......<w6.?.w...2..;.m.....}...v.
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, comment: "", baseline, precision 8, 388x440, components 3
    Category:dropped
    Size (bytes):33121
    Entropy (8bit):7.818745948313405
    Encrypted:false
    SSDEEP:768:/X36NMNtuPXUcQ4tacjyhbOgLrZ1bcccsNQAY5KBw+Lh8LVdCCC:/6NMNtuVd7yhS43bcccMDy+Lh8LDCCC
    MD5:A2B9B1985473CCA2A2D0FD349C8BA07F
    SHA1:85E462B5C6365302F33DFBB930C2FED096E0589C
    SHA-256:5893EB84DF5062A0D6BA7814D8D4FD2F50DEF6322389DC2883943D623DD01311
    SHA-512:E6D4252E6AD8E553774397310D9402850AF11371B05F06CB074C042582235F15A4D4A034CADCEED2308859E422D201DC20BCAECA9BF5816D36B3680493DC6550
    Malicious:false
    Reputation:low
    Preview:......JFIF.............J..CREATOR: XV Version 3.10a Rev: 12/29/94 Quality = 75, Smoothing = 0....C................................... $.' ",#..(7),01444.'9=82<.342...C...........2!.!22222222222222222222222222222222222222222222222222..........."............................................................}........!1A..Qa."q.2....#B...R..$3br........%&'()*456789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz..............................................................................................................................w.......!1..AQ.aq."2...B.....#3R..br...$4.%.....&'()*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz....................................................................................?...7..I.n.'/...H.8..H9...K.r2.Z.$..#.!0ks...-.u8....?....1cu6.m$W..I....U....dpr+..i.m_C..M#.4..."..Ab..0?.S...._........_.&..>.w..u$..4j..H.RA.OS!........S...S..te.8.G#.....O..........4...........MbZx.Y..[D..'../-..D....Q.*....nl....[.4;.7Fy.V..&..5.-.bE..+.. ......}b.q.8.............M.
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, comment: "", baseline, precision 8, 390x411, components 3
    Category:dropped
    Size (bytes):30815
    Entropy (8bit):7.825169735370681
    Encrypted:false
    SSDEEP:768:qkPUUIkyCt6rjwZhf96UO7JIRwUGDN7BplsvJ10IRJQAr:qGUUI7CtVKJbRQ1F
    MD5:5B7D384B5E064B990274EDBE081DEA68
    SHA1:8387AACB541E9FCDEA726D262BBF0BC0EE98372D
    SHA-256:994EABAAF4B83590570AB70CD1567E926493DCADD9C008601D25C65A1960CD35
    SHA-512:9CE8376B38A67A42AF493456E08208E93798EAE4EEC091607C122F46FB481A2C8B585BA13610B4F4E3BE87AC2ED90842BEF1A7E3E785FFDDD3AF166ABD6591DA
    Malicious:false
    Reputation:low
    Preview:......JFIF.............J..CREATOR: XV Version 3.10a Rev: 12/29/94 Quality = 75, Smoothing = 0....C................................... $.' ",#..(7),01444.'9=82<.342...C...........2!.!22222222222222222222222222222222222222222222222222..........."............................................................}........!1A..Qa."q.2....#B...R..$3br........%&'()*456789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz..............................................................................................................................w.......!1..AQ.aq."2...B.....#3R..br...$4.%.....&'()*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz....................................................................................?..4K-k..Oxu..JW..rq.. ....U..f.FG.+.!....v?......T...~....T.....o0...I.,.1.r.M.q....5.R...[z#.0M".i..".x.....{..U..E....o........i..Lt.(..7. ,2.~.zt.8<..k...*=..~H.N=N;..}c..[..{......}c..[..{....v.:./5.4.-...mb...WF1G..Y..l..p.*..1..x..I....m..y4.m..0%....J.!..]..B{O......J_.....2......].
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, comment: "", baseline, precision 8, 387x423, components 3
    Category:dropped
    Size (bytes):30188
    Entropy (8bit):7.799638877613019
    Encrypted:false
    SSDEEP:768:/X36E2nQTY5cLKqPipNdDBRDXPciOiYhY+:/6xQT5KqaltZPciOiYS+
    MD5:DB94BA1453EE827A13F41206920D10E0
    SHA1:3612F1ED6574412823E3F3F5C3E7193F29728FFA
    SHA-256:08FA1526840D3A96BE183C5C65B3C52AE8923ED09136A6CB5582DF4912A332D0
    SHA-512:41CB8608C1E524FD8CE72B7BBED1B991313D4A1E5C20F4A551A671C8E67D8872E2C5AF54E8AADB80C0CB2C6B4C6A8B42BDE5323FE0AC2324BA430E11FE8B3621
    Malicious:false
    Reputation:low
    Preview:......JFIF.............J..CREATOR: XV Version 3.10a Rev: 12/29/94 Quality = 75, Smoothing = 0....C................................... $.' ",#..(7),01444.'9=82<.342...C...........2!.!22222222222222222222222222222222222222222222222222..........."............................................................}........!1A..Qa."q.2....#B...R..$3br........%&'()*456789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz..............................................................................................................................w.......!1..AQ.aq."2...B.....#3R..br...$4.%.....&'()*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz....................................................................................?...7..I.n.'/...H.8..H9...K.r2.Z.$..#.!0ks...-.u8....?....1cu6.m$W..I....U....dpr+..i.m_C..M#.4..."..Ab..0?.S...._........_.&..>.w..u$..4j..H.RA.OS!........S...S..te.8.G#.....O..........4...........MbZx.Y..[D..'../-..D....Q.*....nl....[.4;.7Fy.V..&..5.-.bE..+.. ......}b.q.8.............M.
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, comment: "", baseline, precision 8, 390x411, components 3
    Category:dropped
    Size (bytes):30815
    Entropy (8bit):7.825169735370681
    Encrypted:false
    SSDEEP:768:qkPUUIkyCt6rjwZhf96UO7JIRwUGDN7BplsvJ10IRJQAr:qGUUI7CtVKJbRQ1F
    MD5:5B7D384B5E064B990274EDBE081DEA68
    SHA1:8387AACB541E9FCDEA726D262BBF0BC0EE98372D
    SHA-256:994EABAAF4B83590570AB70CD1567E926493DCADD9C008601D25C65A1960CD35
    SHA-512:9CE8376B38A67A42AF493456E08208E93798EAE4EEC091607C122F46FB481A2C8B585BA13610B4F4E3BE87AC2ED90842BEF1A7E3E785FFDDD3AF166ABD6591DA
    Malicious:false
    Reputation:low
    Preview:......JFIF.............J..CREATOR: XV Version 3.10a Rev: 12/29/94 Quality = 75, Smoothing = 0....C................................... $.' ",#..(7),01444.'9=82<.342...C...........2!.!22222222222222222222222222222222222222222222222222..........."............................................................}........!1A..Qa."q.2....#B...R..$3br........%&'()*456789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz..............................................................................................................................w.......!1..AQ.aq."2...B.....#3R..br...$4.%.....&'()*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz....................................................................................?..4K-k..Oxu..JW..rq.. ....U..f.FG.+.!....v?......T...~....T.....o0...I.,.1.r.M.q....5.R...[z#.0M".i..".x.....{..U..E....o........i..Lt.(..7. ,2.~.zt.8<..k...*=..~H.N=N;..}c..[..{......}c..[..{....v.:./5.4.-...mb...WF1G..Y..l..p.*..1..x..I....m..y4.m..0%....J.!..]..B{O......J_.....2......].
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, comment: "", baseline, precision 8, 390x393, components 3
    Category:dropped
    Size (bytes):27845
    Entropy (8bit):7.838899807550583
    Encrypted:false
    SSDEEP:768:E/tXnOWeNWa93d76/qQcBF5okFF3zhbKJ+K1oGf9II/:E/NnOWcW7CQdW6+Knf9Iu
    MD5:85761BF89B2EEC20DDC722D1EF330813
    SHA1:7A586A3F3D827389AE4B7D6AE3E44ED0C5019741
    SHA-256:7F6D2917E9905E3DCB92CC383A215EEE51F12FA841DAF8EBE854173D4E9DA584
    SHA-512:92B55FB117B30C00749C3B914E6695146BFE01B0E44C2508999001FC48C46B23CEC5F3C068068FF5FBE1335C87371E130C22CB1AF60C047EF3E6DD045E74BF8D
    Malicious:false
    Reputation:low
    Preview:......JFIF.............J..CREATOR: XV Version 3.10a Rev: 12/29/94 Quality = 75, Smoothing = 0....C................................... $.' ",#..(7),01444.'9=82<.342...C...........2!.!22222222222222222222222222222222222222222222222222..........."............................................................}........!1A..Qa."q.2....#B...R..$3br........%&'()*456789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz..............................................................................................................................w.......!1..AQ.aq."2...B.....#3R..br...$4.%.....&'()*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz....................................................................................?..Q.....6.}.0.k+'... ..$.....}..............|$Pk.#...?C...J.&=R.U.[.......\.1.s".........T.vIt.s.7W.c.3.......?...e...m?.........Z.as2h.Q..w..h.q.Lz.s...'...VM...fy..2..$..$.......s.e...m?....../....+i..|..7N...6:........kkkDG...t,......I.....o..3>.h..fH`h&.J....P.Wgl...{W.}..~f_.|g..A
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, comment: "CREATOR: XV Version 3.10a Rev: 12/29/94 Quality = 75, Smoothing = 0", baseline, precision 8, 755x443, components 3
    Category:dropped
    Size (bytes):74983
    Entropy (8bit):7.807712031230282
    Encrypted:false
    SSDEEP:1536:4dTqjHjMcQQ9aImmYYXba6sw37f9Oj79S7aU4P8tZB:OT0DMcQQoImmYN2379zGVP8t
    MD5:31FB6B9321792DA2588B44A5B0185765
    SHA1:C20EAEC6E0D591E65275F8CED6DF1C264AACDF8C
    SHA-256:C617EDE6B57D90D43DE23F78EEC2CFD64A61843CDFB0A33E7BB5395C5AA7F8FF
    SHA-512:619EB873CF697C59385FAFFF3BEF039701AB8AD3B7117F24B88ABB38526817A91BB60FE2FD4B1335D54BE5950E9377ECE5163961FE66719CB22EBA95FE8CC3C8
    Malicious:false
    Reputation:low
    Preview:......JFIF.............HCREATOR: XV Version 3.10a Rev: 12/29/94 Quality = 75, Smoothing = 0....C................................... $.' ",#..(7),01444.'9=82<.342...C...........2!.!22222222222222222222222222222222222222222222222222..........."............................................................}........!1A..Qa."q.2....#B...R..$3br........%&'()*456789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz..............................................................................................................................w.......!1..AQ.aq."2...B.....#3R..br...$4.%.....&'()*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz....................................................................................?....xgA..:,..t.....Ik.gc..'..W..<+nPI.i ...G..R.L..........kY..M.2..X.~vo....^ej.".!.J........v.q.u.iq..D.J..bC...N....J......?.........T<X./.. .. iw o9?.?.A}5..%....(.....{..a.!..\,.`F.rA8m.:E..3i#....S........?....S........?.+.>..J...Lt.J.].....G&x...2.:.3c.......<w6.?.w...2..;.m.....}...v.
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, comment: "CREATOR: XV Version 3.10a Rev: 12/29/94 Quality = 75, Smoothing = 0", baseline, precision 8, 790x563, components 3
    Category:dropped
    Size (bytes):88344
    Entropy (8bit):7.830818137367989
    Encrypted:false
    SSDEEP:1536:jdTCCvMZ2WGHafrWk+gaRGJ3OtAkGQc1v/5iiiiif/CbzWvCTHl60:hTCCEZw6frgiJ+tzGmC3mCTd
    MD5:9A0E83B52D3C7A757253EC43DC8381A0
    SHA1:D8D7974AD9AEDCBBBCE6A882EC3E4DBF0A417D3A
    SHA-256:8BED3EEF4C29A099B139F5200930505B970A6937B44765B6BF49BBF3A596F83D
    SHA-512:E4DDC2E777B8EA3E199D9CD0C2C958F5E63823129A1E24771B03910D67E0E99905EADE1993EDF5A635789D7CE4DC17B8A1BD53156935FCC4AB8A6D00A6CDA7E2
    Malicious:false
    Reputation:low
    Preview:......JFIF.............HCREATOR: XV Version 3.10a Rev: 12/29/94 Quality = 75, Smoothing = 0....C................................... $.' ",#..(7),01444.'9=82<.342...C...........2!.!22222222222222222222222222222222222222222222222222......3...."............................................................}........!1A..Qa."q.2....#B...R..$3br........%&'()*456789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz..............................................................................................................................w.......!1..AQ.aq."2...B.....#3R..br...$4.%.....&'()*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz....................................................................................?....xgA..:,..t.....Ik.gc..'..W..<+nPI.i ...G..R.L..........kY..M.2..X.~vo....^ej.".!.J........v.q.u.iq..D.J..bC...N....J......?.........T<X./.. .. iw o9?.?.A}5..%....(.....{..a.!..\,.`F.rA8m.:E..3i#....S........?....S........?.+.>..J...Lt.J.].....G&x...2.:.3c.......<w6.?.w...2..;.m.....}...v.
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, comment: "CREATOR: XV Version 3.10a Rev: 12/29/94 Quality = 75, Smoothing = 0", baseline, precision 8, 774x499, components 3
    Category:dropped
    Size (bytes):70422
    Entropy (8bit):7.7964235424689665
    Encrypted:false
    SSDEEP:1536:6dThtfsXEQQPfEGGKv9kL0JgHoMusxKDjiQRcLL9ZUR:8T3kUQQEGGub4oM4jiQR0+
    MD5:9E0ED4D9EDAA4C024A504EC602935686
    SHA1:DF0584B71636584C552FC63AA007EDF261845AC3
    SHA-256:48CCFF886C9628BD5CE1A7B49B3B95C1EF06295C67EBB3D87FE10D4A41C56ED2
    SHA-512:AD3F77327ABACEFD56A95E43C912D54BF8E4985972A44389FE18C171DB80256828260030D22BA46737B1F739A0E05A9BA15B572A08DBE6920F6BDA3A18AF5EE5
    Malicious:false
    Reputation:low
    Preview:......JFIF.............HCREATOR: XV Version 3.10a Rev: 12/29/94 Quality = 75, Smoothing = 0....C................................... $.' ",#..(7),01444.'9=82<.342...C...........2!.!22222222222222222222222222222222222222222222222222..........."............................................................}........!1A..Qa."q.2....#B...R..$3br........%&'()*456789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz..............................................................................................................................w.......!1..AQ.aq."2...B.....#3R..br...$4.%.....&'()*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz....................................................................................?....xgA..:,..t.....Ik.gc..'..W..<+nPI.i ...G..R.L..........kY..M.2..X.~vo....^ej.".!.J........v.q.u.iq..D.J..bC...N....J......?.........T<X./.. .. iw o9?.?.A}5..%....(.....{..a.!..\,.`F.rA8m.:E..3i#....S........?....S........?.+.>..J...Lt.J.].....G&x...2.:.3c.......<w6.?.w...2..;.m.....}...v.
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:HTML document, ASCII text
    Category:dropped
    Size (bytes):107470
    Entropy (8bit):4.549583570277271
    Encrypted:false
    SSDEEP:768:3GDvdV6mv0IoBK/CSkKFR+T3nmgKiOt4ggJPYeiT/TzsdsvWZLLOPLOv67VC9Bf2:3GZVZ8InKT3pOOggJaHsHtkOv/qW0w9e
    MD5:106C4C7AD865123E79F607BC7544F150
    SHA1:667F6B4CC766620194107DE134E9D9BCCECA58A0
    SHA-256:D81F4D4F6047A9A975E38E36EC53D32246C0B309D97CFD69B61FD6B152334D6F
    SHA-512:C1A87A17665F9A373FC016DFCF1FF6D8B2186E66F405D2BAD01900800767341C9005690D92B5F72E09C78B612E565C648314AB9122F8C21EA25C545AFD0D500C
    Malicious:false
    Reputation:low
    Preview:<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">..<html>. <head>. . Copyright (c) 2006, 2013, Oracle and/or its affiliates. All rights reserved... Redistribution and use in source and binary forms, with or without. modification, are permitted provided that the following conditions. are met:.. - Redistributions of source code must retain the above copyright. notice, this list of conditions and the following disclaimer... - Redistributions in binary form must reproduce the above copyright. notice, this list of conditions and the following disclaimer in the. documentation and/or other materials provided with the distribution... - Neither the name of Oracle nor the names of its. contributors may be used to endorse or promote products derived. from this software without specific prior written permission... THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:HTML document, ASCII text
    Category:dropped
    Size (bytes):107470
    Entropy (8bit):4.549583570277271
    Encrypted:false
    SSDEEP:768:3GDvdV6mv0IoBK/CSkKFR+T3nmgKiOt4ggJPYeiT/TzsdsvWZLLOPLOv67VC9Bf2:3GZVZ8InKT3pOOggJaHsHtkOv/qW0w9e
    MD5:106C4C7AD865123E79F607BC7544F150
    SHA1:667F6B4CC766620194107DE134E9D9BCCECA58A0
    SHA-256:D81F4D4F6047A9A975E38E36EC53D32246C0B309D97CFD69B61FD6B152334D6F
    SHA-512:C1A87A17665F9A373FC016DFCF1FF6D8B2186E66F405D2BAD01900800767341C9005690D92B5F72E09C78B612E565C648314AB9122F8C21EA25C545AFD0D500C
    Malicious:false
    Reputation:low
    Preview:<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">..<html>. <head>. . Copyright (c) 2006, 2013, Oracle and/or its affiliates. All rights reserved... Redistribution and use in source and binary forms, with or without. modification, are permitted provided that the following conditions. are met:.. - Redistributions of source code must retain the above copyright. notice, this list of conditions and the following disclaimer... - Redistributions in binary form must reproduce the above copyright. notice, this list of conditions and the following disclaimer in the. documentation and/or other materials provided with the distribution... - Neither the name of Oracle nor the names of its. contributors may be used to endorse or promote products derived. from this software without specific prior written permission... THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java KeyStore
    Category:dropped
    Size (bytes):1364
    Entropy (8bit):7.60619163165009
    Encrypted:false
    SSDEEP:24:KUAQ7w0wtZaxm+05DNdqnWygrBTkFsTM1osp0Tdh/SCSQ0lNi:TKdHdKWn9YFsPseh/5/0lNi
    MD5:62660642DA8A9DE5358F18D4807B1B40
    SHA1:DD01C24583ADEDE9E67E66F65F1F4CF2DC886475
    SHA-256:2A1266DC500758325CCA808CC6FC2E1C912C558FAB6EBB91D5C3C9A8B0B16DC0
    SHA-512:1B10F463A2EE97C7CBAD0C28F98032E8CB6F64E6762D9D5E0791530F9923908BB52DCDDDA143FD376135696FA39C4091191BDDEE46E109E797312475A96712D7
    Malicious:false
    Reputation:low
    Preview:..................duke............0...0...+....*..........U5{.......ZO\SAa.?..z ^K.P....r...O..k..c{2.+...yD^.....?.k-.....l.....9e\....Z..$..u.+.....>a.i.L..d....?.4.4...........2...Xy.........l...B.SS..%.;.$...H.".D......-.;..0.Q;.P<.....; Di.+......u..v.....:..M..@......i..5.A.s1..:.*w(.H.)9......66.e..|&...zA.U?..@cY.."#..#B[t.^s..p...e.o..!".....Z...y:.P=.....&Jga..1.F!....Bw..W?.F.......G...C.de..:..`b..x,...E..O.<;...?..K...........C.e'C...-.0EF..Z.u.3.z..CL..J.......q....[....zk...!..q5H>.*'Z1Y..I..u...Q...q;J...6....m..>..m..5x.........2..(..9...H.|a&......wv.......2...e.../.v.._...;4...=....Y...7i..^...Rt..PJ.....vL..J..k..Os...{.8..9.. ...O.M.'.&@..V.1.._.NM1$..q".y....']..H........X.509...T0..P0.....>...0...*.H........0o1.0...U....US1.0...U....CA1.0...U....Santa Clara1.0...U....Sun Microsystems, Inc.1.0...U....J2SE1.0...U....Duke0...030423130200Z..300908130200Z0o1.0...U....US1.0...U....CA1.0...U....Santa Clara1.0...U....Sun Microsystems,
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:ASCII text
    Category:dropped
    Size (bytes):82
    Entropy (8bit):4.644802346400103
    Encrypted:false
    SSDEEP:3:ZLCAWIzBE/fSRImKuMAF5qMGM5wMP3:1KItW8FUs5R3
    MD5:D6FE4AF2F67849F1C01635B0ED4C443D
    SHA1:C8EA91C65FB694C1161E4845011B712663A704A3
    SHA-256:ABA13EB4E4D2C16F718C4DB49E8FD5812A0064E0B12C52E147979240ABD019A0
    SHA-512:5FFF6E4D925D4D8F7290912A0FDED0435CB0202D6AE32734AFD9E4C95C6D38FD92473E58CAC210DF78C8244B0B46DD5ECD08EB9F196F01BC98DF42EF87ABC84B
    Malicious:false
    Reputation:low
    Preview:Manifest-Version: 1.0.X-COMMENT: Main-Class will be added automatically by build..
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):7417
    Entropy (8bit):4.895166150367526
    Encrypted:false
    SSDEEP:96:YorYJTrYJEfiQX3f3jp28yzTcHtpTrQz9RihmgIFEui42SvisT:YorsTrs+jX3f3d2JX6LTSRiBCUq
    MD5:A68BA7C3D00A52A4C182E4787710D052
    SHA1:78C4FB8B4962F0DDD8E6993594EE2ED2E44EED84
    SHA-256:11CAD03F4E3F5787E38CF044EB71CF115CE3339D8203CE03054F3A8DA87F5C70
    SHA-512:E420C80E1E9CF16CA4C6CB0BF7B78434329E4170C0A959491C05275D60758E03BB47DFCA89AB3EB834AA070A8F3745ADDEFDCF9500C55A3FAB980746E7211DA5
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?>.. . Copyright (c) 2006, Oracle and/or its affiliates. All rights reserved... Redistribution and use in source and binary forms, with or without. modification, are permitted provided that the following conditions. are met:.. - Redistributions of source code must retain the above copyright. notice, this list of conditions and the following disclaimer... - Redistributions in binary form must reproduce the above copyright. notice, this list of conditions and the following disclaimer in the. documentation and/or other materials provided with the distribution... - Neither the name of Oracle nor the names of its. contributors may be used to endorse or promote products derived. from this software without specific prior written permission... THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. THE IMPLIED WARRANTIES OF MERCHANTABILITY
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:ASCII text
    Category:dropped
    Size (bytes):482
    Entropy (8bit):4.6294631481613076
    Encrypted:false
    SSDEEP:12:hVGOOGXM1ZXGXMnlGXMGCGXMZ3HGmXGIXHG13HGMMmOHY:rX8g97O3vFk3qxY
    MD5:2AB6AA377CC5417C7D4EB859134768D6
    SHA1:D5F0107AB0E65293D0003796C41812F903FA26D8
    SHA-256:EB80B3210A5F1CABEE7695338CD21F1E03695F05F9ADE0419917A08B28BA81BC
    SHA-512:4C2D8AD7C81AC73B03DA7779BCCA9F22A186094CD36F82462207FFD7E6E79AB0098FA38161785E9099B6DDD3CF830CCD2FF42369C85DFE65FAC02E5EA262153B
    Malicious:false
    Reputation:low
    Preview:handlers= java.util.logging.ConsoleHandler...level=INFO...java.util.logging.FileHandler.pattern = %h/java%u.log.java.util.logging.FileHandler.limit = 50000.java.util.logging.FileHandler.count = 1.java.util.logging.FileHandler.formatter = java.util.logging.XMLFormatter..java.util.logging.ConsoleHandler.level = FINEST.java.util.logging.ConsoleHandler.formatter = java.util.logging.SimpleFormatter..javax.management.level=INFO.com.sun.jmx.level=INFO.com.sun.jmx.examples.level=FINE..
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:ASCII text
    Category:dropped
    Size (bytes):1634
    Entropy (8bit):4.895052250234343
    Encrypted:false
    SSDEEP:48:wu576L0I8JKIXyivzSk4CqVYdPiUz41Ij:9okJKIXFvzS5FYpBj
    MD5:1A5B2D8EFCD774FD9A37C6CA8C7CDCE8
    SHA1:47D42BF5BC6E73F1D7A508315FB7E7E91EF6EB31
    SHA-256:950705EE575D5BCEDFF131FDA90796A140FED644F0B4485FD2FCA96D1692A19C
    SHA-512:71DB604B92EE131180C0EEF530F42E133A466A540AE450288EFA48AF14A6BF71D0B3A590F32B9289DDAC50B891B21272D9787A5471CF4595021B47BFD7EE8CEC
    Malicious:false
    Reputation:low
    Preview:# IMPORTANT NOTE.#.# If you made a private copy of this project you may have to update the.# nbjdk.home variable at the end of this file..# .# To be able to run the test-suite, you will also have to set the.# variable:.#.# libs.junit.classpath=<junit.jar> .#..main.dir=...src.dir=${main.dir}/src.test.src.dir=${main.dir}/test..build.dir=build.classes.dir=${build.dir}/classes..dist.dir=dist.jar=${dist.dir}/jmx-scandir.jar.javadoc.dir=${dist.dir}/javadoc..build.test.classes.dir=${build.dir}/test/classes.build.test.results.dir=${build.dir}/test/results..build.sysclasspath=ignore.# E.g.: cp=lib/x.jar:lib/y.jar.cp=.extra.run.cp=..# To be able to run the test-suite, set the following property:.# libs.junit.classpath=.....javac.test.classpath=\. ${classes.dir}:\. ${libs.junit.classpath}..main.agent.class=com.sun.jmx.examples.scandir.ScanDirAgent.main.client.class=com.sun.jmx.examples.scandir.ScanDirClient.main.class=${main.client.class}..run.jvmargs=-Djava.util.logging.config.file=loggin
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java KeyStore
    Category:dropped
    Size (bytes):661
    Entropy (8bit):6.916795371890928
    Encrypted:false
    SSDEEP:12:bsDdTa3yK/oDdTM1Idy6nip0TdhNRSCP+1Mh52Hlis:0TkFsTM1osp0Tdh/SCSQ0lj
    MD5:3F6C4C59DA0271DACD9CEBEB66941475
    SHA1:87AA9F07BCF088D682E4402CC17E0A5C650BE918
    SHA-256:419C6009437117D4471DD64C1A01A288155ED46EB749036DD71B07AD5C55F77C
    SHA-512:75771E7597BFA94BE1B262BCBEF73131428E405C9FF76880479A8DEC895920267253E90103E69524869D8F8640DF043FE156225A6D57F7C3F02A16F5835F203E
    Malicious:false
    Reputation:low
    Preview:..................dukecert.......m..X.509...T0..P0.....>...0...*.H........0o1.0...U....US1.0...U....CA1.0...U....Santa Clara1.0...U....Sun Microsystems, Inc.1.0...U....J2SE1.0...U....Duke0...030423130200Z..300908130200Z0o1.0...U....US1.0...U....CA1.0...U....Santa Clara1.0...U....Sun Microsystems, Inc.1.0...U....J2SE1.0...U....Duke0..0...*.H............0........W....c.hC.....U..6K.......T.....R..l7...1Z.CY..@.o^..LK..9N.X.q.<..t)....k5q.....n..J...N\\...>.......... ...BVi.k..#.....0...*.H............E~.....a.....}a.j...C..w+....D..I(a_.r....<SH....D....X.T.S^.t[.....j...G>*..'..|.....@....$.*T=..96.cV.k...k......2.....]kk...8.".?...?.
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java KeyStore
    Category:dropped
    Size (bytes):1364
    Entropy (8bit):7.60619163165009
    Encrypted:false
    SSDEEP:24:KUAQ7w0wtZaxm+05DNdqnWygrBTkFsTM1osp0Tdh/SCSQ0lNi:TKdHdKWn9YFsPseh/5/0lNi
    MD5:62660642DA8A9DE5358F18D4807B1B40
    SHA1:DD01C24583ADEDE9E67E66F65F1F4CF2DC886475
    SHA-256:2A1266DC500758325CCA808CC6FC2E1C912C558FAB6EBB91D5C3C9A8B0B16DC0
    SHA-512:1B10F463A2EE97C7CBAD0C28F98032E8CB6F64E6762D9D5E0791530F9923908BB52DCDDDA143FD376135696FA39C4091191BDDEE46E109E797312475A96712D7
    Malicious:false
    Reputation:low
    Preview:..................duke............0...0...+....*..........U5{.......ZO\SAa.?..z ^K.P....r...O..k..c{2.+...yD^.....?.k-.....l.....9e\....Z..$..u.+.....>a.i.L..d....?.4.4...........2...Xy.........l...B.SS..%.;.$...H.".D......-.;..0.Q;.P<.....; Di.+......u..v.....:..M..@......i..5.A.s1..:.*w(.H.)9......66.e..|&...zA.U?..@cY.."#..#B[t.^s..p...e.o..!".....Z...y:.P=.....&Jga..1.F!....Bw..W?.F.......G...C.de..:..`b..x,...E..O.<;...?..K...........C.e'C...-.0EF..Z.u.3.z..CL..J.......q....[....zk...!..q5H>.*'Z1Y..I..u...Q...q;J...6....m..>..m..5x.........2..(..9...H.|a&......wv.......2...e.../.v.._...;4...=....Y...7i..^...Rt..PJ.....vL..J..k..Os...{.8..9.. ...O.M.'.&@..V.1.._.NM1$..q".y....']..H........X.509...T0..P0.....>...0...*.H........0o1.0...U....US1.0...U....CA1.0...U....Santa Clara1.0...U....Sun Microsystems, Inc.1.0...U....J2SE1.0...U....Duke0...030423130200Z..300908130200Z0o1.0...U....US1.0...U....CA1.0...U....Santa Clara1.0...U....Sun Microsystems,
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:ASCII text
    Category:dropped
    Size (bytes):482
    Entropy (8bit):4.6294631481613076
    Encrypted:false
    SSDEEP:12:hVGOOGXM1ZXGXMnlGXMGCGXMZ3HGmXGIXHG13HGMMmOHY:rX8g97O3vFk3qxY
    MD5:2AB6AA377CC5417C7D4EB859134768D6
    SHA1:D5F0107AB0E65293D0003796C41812F903FA26D8
    SHA-256:EB80B3210A5F1CABEE7695338CD21F1E03695F05F9ADE0419917A08B28BA81BC
    SHA-512:4C2D8AD7C81AC73B03DA7779BCCA9F22A186094CD36F82462207FFD7E6E79AB0098FA38161785E9099B6DDD3CF830CCD2FF42369C85DFE65FAC02E5EA262153B
    Malicious:false
    Reputation:low
    Preview:handlers= java.util.logging.ConsoleHandler...level=INFO...java.util.logging.FileHandler.pattern = %h/java%u.log.java.util.logging.FileHandler.limit = 50000.java.util.logging.FileHandler.count = 1.java.util.logging.FileHandler.formatter = java.util.logging.XMLFormatter..java.util.logging.ConsoleHandler.level = FINEST.java.util.logging.ConsoleHandler.formatter = java.util.logging.SimpleFormatter..javax.management.level=INFO.com.sun.jmx.level=INFO.com.sun.jmx.examples.level=FINE..
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:ASCII text
    Category:dropped
    Size (bytes):82
    Entropy (8bit):4.644802346400103
    Encrypted:false
    SSDEEP:3:ZLCAWIzBE/fSRImKuMAF5qMGM5wMP3:1KItW8FUs5R3
    MD5:D6FE4AF2F67849F1C01635B0ED4C443D
    SHA1:C8EA91C65FB694C1161E4845011B712663A704A3
    SHA-256:ABA13EB4E4D2C16F718C4DB49E8FD5812A0064E0B12C52E147979240ABD019A0
    SHA-512:5FFF6E4D925D4D8F7290912A0FDED0435CB0202D6AE32734AFD9E4C95C6D38FD92473E58CAC210DF78C8244B0B46DD5ECD08EB9F196F01BC98DF42EF87ABC84B
    Malicious:false
    Reputation:low
    Preview:Manifest-Version: 1.0.X-COMMENT: Main-Class will be added automatically by build..
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):2047
    Entropy (8bit):5.237073935754406
    Encrypted:false
    SSDEEP:48:ceOorYJTrYJEfDWQvs432sD32scMEtu33tYTHDoVKasrO:YorYJTrYJEfiQX3f3jp28MC
    MD5:AE74756726F9CA0DE5A542CB0F388485
    SHA1:819A76F3BD0A306B26E1389C32D24E46334F7C7A
    SHA-256:102067B80BA1BFE2EC083C14F8CC8C46A31BC5696853E2C7A0C10819D1209149
    SHA-512:9FDD57D588D348F02A4CDB86F4281B7F1508AE720E6FBD1B31E5FFBD86ADC3B24581498B9D2969FBA6CAA4B5EBDB14DC3F41FC97969223EB34D09694822AEEB4
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?>.. . Copyright (c) 2006, Oracle and/or its affiliates. All rights reserved... Redistribution and use in source and binary forms, with or without. modification, are permitted provided that the following conditions. are met:.. - Redistributions of source code must retain the above copyright. notice, this list of conditions and the following disclaimer... - Redistributions in binary form must reproduce the above copyright. notice, this list of conditions and the following disclaimer in the. documentation and/or other materials provided with the distribution... - Neither the name of Oracle nor the names of its. contributors may be used to endorse or promote products derived. from this software without specific prior written permission... THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. THE IMPLIED WARRANTIES OF MERCHANTABILITY
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):8938
    Entropy (8bit):4.135862341698505
    Encrypted:false
    SSDEEP:192:YorsTrs+jX3f3d2P3rPBBbdjDuDpDNY1JM:frsTrsinvdYJeV
    MD5:574DC5E47DDDB9FEFEFAAFEFCDEF38BF
    SHA1:DD95489683BC2E0A5556519B520C7D2E8C8FAFB3
    SHA-256:EBE48B4E9B3F14BF399205DC6688752A2685A77019B9AA20768966821C645788
    SHA-512:27642CBE107395AD51E55AF61A9C424492A60D0B4FA3AB6A1AE1D52B4805EF9BD397AE6B9BB3B2DC42D996767D65BF9553EFC0CF3E75AF42A5C90E8A49A39C90
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?>.. . Copyright (c) 2006, Oracle and/or its affiliates. All rights reserved... Redistribution and use in source and binary forms, with or without. modification, are permitted provided that the following conditions. are met:.. - Redistributions of source code must retain the above copyright. notice, this list of conditions and the following disclaimer... - Redistributions in binary form must reproduce the above copyright. notice, this list of conditions and the following disclaimer in the. documentation and/or other materials provided with the distribution... - Neither the name of Oracle nor the names of its. contributors may be used to endorse or promote products derived. from this software without specific prior written permission... THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. THE IMPLIED WARRANTIES OF MERCHANTABILITY
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):2047
    Entropy (8bit):5.237073935754406
    Encrypted:false
    SSDEEP:48:ceOorYJTrYJEfDWQvs432sD32scMEtu33tYTHDoVKasrO:YorYJTrYJEfiQX3f3jp28MC
    MD5:AE74756726F9CA0DE5A542CB0F388485
    SHA1:819A76F3BD0A306B26E1389C32D24E46334F7C7A
    SHA-256:102067B80BA1BFE2EC083C14F8CC8C46A31BC5696853E2C7A0C10819D1209149
    SHA-512:9FDD57D588D348F02A4CDB86F4281B7F1508AE720E6FBD1B31E5FFBD86ADC3B24581498B9D2969FBA6CAA4B5EBDB14DC3F41FC97969223EB34D09694822AEEB4
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?>.. . Copyright (c) 2006, Oracle and/or its affiliates. All rights reserved... Redistribution and use in source and binary forms, with or without. modification, are permitted provided that the following conditions. are met:.. - Redistributions of source code must retain the above copyright. notice, this list of conditions and the following disclaimer... - Redistributions in binary form must reproduce the above copyright. notice, this list of conditions and the following disclaimer in the. documentation and/or other materials provided with the distribution... - Neither the name of Oracle nor the names of its. contributors may be used to endorse or promote products derived. from this software without specific prior written permission... THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. THE IMPLIED WARRANTIES OF MERCHANTABILITY
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):4218
    Entropy (8bit):4.9575689298800985
    Encrypted:false
    SSDEEP:48:ceOorYJTrYJEfDWQvs432sD32scMEtu33tYTHD5wj9fV3ORoZVPp1TED2AZiUZGQ:YorYJTrYJEfiQX3f3jp2FBY0
    MD5:8F8DB67A23AE3EFD024E91710F1A6739
    SHA1:26C3F95E0007310A3F6A35CCE6B61AF71B9F1C8B
    SHA-256:5AB23ACF89B98778B5885B46D500429E6906C4389CD4427D8D5BDE6727BB6BE3
    SHA-512:7E3B2E9EF782B2D12FEEF7DDF78FCDF4500ECA641E03AF66181D03DC81B0CD5B54E5376B245B0460A25FEA1AF70D11CF974FBCE1A5787D3310B50D56099FC2A1
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?>.. . Copyright (c) 2006, Oracle and/or its affiliates. All rights reserved... Redistribution and use in source and binary forms, with or without. modification, are permitted provided that the following conditions. are met:.. - Redistributions of source code must retain the above copyright. notice, this list of conditions and the following disclaimer... - Redistributions in binary form must reproduce the above copyright. notice, this list of conditions and the following disclaimer in the. documentation and/or other materials provided with the distribution... - Neither the name of Oracle nor the names of its. contributors may be used to endorse or promote products derived. from this software without specific prior written permission... THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. THE IMPLIED WARRANTIES OF MERCHANTABILITY
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):3709
    Entropy (8bit):5.143831986848915
    Encrypted:false
    SSDEEP:48:ceOorYJTrYJEfDWQvs432sD32scMEtu33tYTHDKdNguTfhKaZzFKZzpzgDIx3YUy:YorYJTrYJEfiQX3f3jp2ahzFWzpz16so
    MD5:C7ACA3A90D56FD0E2AD391F9236F3FE6
    SHA1:E6CA50212B6795EBADE45453DC5F453F665E2E1D
    SHA-256:21694605753C849FADC975C3868FDEDCDD7AF7EDC9A85B6AAF499942AC2E36A6
    SHA-512:29DCF779EAB78A6625F8125D21E12C3ECD09D6E8EF0E7A49B19F35E547FAB7513D990F37E184BA7169102FC5749286E74A0FD3F457E0698C5F5174B3227AF61E
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?>.. . Copyright (c) 2006, Oracle and/or its affiliates. All rights reserved... Redistribution and use in source and binary forms, with or without. modification, are permitted provided that the following conditions. are met:.. - Redistributions of source code must retain the above copyright. notice, this list of conditions and the following disclaimer... - Redistributions in binary form must reproduce the above copyright. notice, this list of conditions and the following disclaimer in the. documentation and/or other materials provided with the distribution... - Neither the name of Oracle nor the names of its. contributors may be used to endorse or promote products derived. from this software without specific prior written permission... THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. THE IMPLIED WARRANTIES OF MERCHANTABILITY
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):4218
    Entropy (8bit):4.9575689298800985
    Encrypted:false
    SSDEEP:48:ceOorYJTrYJEfDWQvs432sD32scMEtu33tYTHD5wj9fV3ORoZVPp1TED2AZiUZGQ:YorYJTrYJEfiQX3f3jp2FBY0
    MD5:8F8DB67A23AE3EFD024E91710F1A6739
    SHA1:26C3F95E0007310A3F6A35CCE6B61AF71B9F1C8B
    SHA-256:5AB23ACF89B98778B5885B46D500429E6906C4389CD4427D8D5BDE6727BB6BE3
    SHA-512:7E3B2E9EF782B2D12FEEF7DDF78FCDF4500ECA641E03AF66181D03DC81B0CD5B54E5376B245B0460A25FEA1AF70D11CF974FBCE1A5787D3310B50D56099FC2A1
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?>.. . Copyright (c) 2006, Oracle and/or its affiliates. All rights reserved... Redistribution and use in source and binary forms, with or without. modification, are permitted provided that the following conditions. are met:.. - Redistributions of source code must retain the above copyright. notice, this list of conditions and the following disclaimer... - Redistributions in binary form must reproduce the above copyright. notice, this list of conditions and the following disclaimer in the. documentation and/or other materials provided with the distribution... - Neither the name of Oracle nor the names of its. contributors may be used to endorse or promote products derived. from this software without specific prior written permission... THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. THE IMPLIED WARRANTIES OF MERCHANTABILITY
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):3709
    Entropy (8bit):5.143831986848915
    Encrypted:false
    SSDEEP:48:ceOorYJTrYJEfDWQvs432sD32scMEtu33tYTHDKdNguTfhKaZzFKZzpzgDIx3YUy:YorYJTrYJEfiQX3f3jp2ahzFWzpz16so
    MD5:C7ACA3A90D56FD0E2AD391F9236F3FE6
    SHA1:E6CA50212B6795EBADE45453DC5F453F665E2E1D
    SHA-256:21694605753C849FADC975C3868FDEDCDD7AF7EDC9A85B6AAF499942AC2E36A6
    SHA-512:29DCF779EAB78A6625F8125D21E12C3ECD09D6E8EF0E7A49B19F35E547FAB7513D990F37E184BA7169102FC5749286E74A0FD3F457E0698C5F5174B3227AF61E
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?>.. . Copyright (c) 2006, Oracle and/or its affiliates. All rights reserved... Redistribution and use in source and binary forms, with or without. modification, are permitted provided that the following conditions. are met:.. - Redistributions of source code must retain the above copyright. notice, this list of conditions and the following disclaimer... - Redistributions in binary form must reproduce the above copyright. notice, this list of conditions and the following disclaimer in the. documentation and/or other materials provided with the distribution... - Neither the name of Oracle nor the names of its. contributors may be used to endorse or promote products derived. from this software without specific prior written permission... THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. THE IMPLIED WARRANTIES OF MERCHANTABILITY
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):8938
    Entropy (8bit):4.135862341698505
    Encrypted:false
    SSDEEP:192:YorsTrs+jX3f3d2P3rPBBbdjDuDpDNY1JM:frsTrsinvdYJeV
    MD5:574DC5E47DDDB9FEFEFAAFEFCDEF38BF
    SHA1:DD95489683BC2E0A5556519B520C7D2E8C8FAFB3
    SHA-256:EBE48B4E9B3F14BF399205DC6688752A2685A77019B9AA20768966821C645788
    SHA-512:27642CBE107395AD51E55AF61A9C424492A60D0B4FA3AB6A1AE1D52B4805EF9BD397AE6B9BB3B2DC42D996767D65BF9553EFC0CF3E75AF42A5C90E8A49A39C90
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?>.. . Copyright (c) 2006, Oracle and/or its affiliates. All rights reserved... Redistribution and use in source and binary forms, with or without. modification, are permitted provided that the following conditions. are met:.. - Redistributions of source code must retain the above copyright. notice, this list of conditions and the following disclaimer... - Redistributions in binary form must reproduce the above copyright. notice, this list of conditions and the following disclaimer in the. documentation and/or other materials provided with the distribution... - Neither the name of Oracle nor the names of its. contributors may be used to endorse or promote products derived. from this software without specific prior written permission... THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. THE IMPLIED WARRANTIES OF MERCHANTABILITY
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java source, ASCII text
    Category:dropped
    Size (bytes):22655
    Entropy (8bit):4.567518548023222
    Encrypted:false
    SSDEEP:384:srsdrsU5D7u3KQoPgnFZOw0ZqQBfpXotsh8Wu44CzUVf8dlLltacaWB2j:sAPD7UKfELNQBL4CzUKPlthaS2j
    MD5:1AAD2DB55409E26F75831F9F87DC91FA
    SHA1:7019490254706937E0B9DE42877326DDDCEDB9CA
    SHA-256:B6AE106C01DDF69AD95DB71073A29DF86D6DB96CBC68F78907F88A7AD763B39C
    SHA-512:334FDD3EC740D0EFBC871E25E4D18C3300627235C9C19B04F0083EACF3907C4A7CA6604A3287A5769F0D79E3ACF0899D348CE611C24B470BCC125915CFAC50AA
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2006, 2011, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABI
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java source, ASCII text
    Category:dropped
    Size (bytes):7364
    Entropy (8bit):4.8526590194522194
    Encrypted:false
    SSDEEP:192:h6rsdrsQXJ3r37e6E3KX7xiGtlTDboawdojdPcO/2AoibPQoMxgNo5oLF:srsdrsU5D7u3KX7xjnfbodid9/2ARjQu
    MD5:9A6CD13C1BC2AAF7D1438F94C677B4AE
    SHA1:761CFFA79ED5C7FF7D25D5DCF9BC9DA671AAF30D
    SHA-256:E33275B70CEA07D319B30FD042E04228055198920D1A30CC9C5205C5C08EC9C2
    SHA-512:FC0878107F61C6F3120189E0D9B9D6C6F6DAC98F40894E1CB5AB180A2D95887543B86AFBF3D5E435343CA2CF94D34E16440B050AB8F1BB83243934A2FCC2EBEC
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2006, 2011, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABI
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java source, ASCII text
    Category:dropped
    Size (bytes):19636
    Entropy (8bit):4.68765720443026
    Encrypted:false
    SSDEEP:384:srsdrsU5D7u3Kr4nh3sitx5jJHudgNczzOWwxUp8BxplFanOKBKAMqJ6L9lC:sAPD7UKMh3TjJHuyNmyPOpK/lFEONAlZ
    MD5:3C5D3E7EC398B7B30A6896C22EE32C03
    SHA1:51BDD780C5E70B8FD9B1C6448E7FAD057BD55892
    SHA-256:B66B30AAA8197765EACD9E4F497588AE0DA209030D8723C863718EF6D4544DC7
    SHA-512:7F884AD4D7C5838B03794D0363F7ECE17A2052A9FFF27DEDCF8322BD4E7E66341345179FA24889FD3BE0128BF095E080761122E728FF854F51E1168F9A52CF26
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2006, 2011, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABI
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java source, ASCII text
    Category:dropped
    Size (bytes):11676
    Entropy (8bit):4.681873347283984
    Encrypted:false
    SSDEEP:192:h6rsdrsQXJ3r37e6E3K404D01AVNoiRY8TooEoXVIqOojo8okxxopzokroXPo0oN:srsdrsU5D7u3KD4D0gmiRY8TiWxOCTLG
    MD5:BA2EFDBF12F38C60556DF6E64F4D8647
    SHA1:9AFA7FA0A2E91A50DB0D6C53C75CE0A19D04DD49
    SHA-256:8990C6DF649D2AE17A0F8C5748B1C0D734237CE2DF226522613334B21499812C
    SHA-512:D4F000A1310EF8F9872175C86902956D90A398D846B629EC8026363BC4E87101C35BCC962C0836B0D3C4C87614FE9E0254336005273F619375B9FEA26B51AF70
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2006, 2011, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABI
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:C source, ASCII text
    Category:dropped
    Size (bytes):9219
    Entropy (8bit):4.809637152686827
    Encrypted:false
    SSDEEP:192:h6rsdrsQXJ3r37e6E3KyfGj6e57oKzZCMO90SG+mktyGbyOBGWp+yN57EL:srsdrsU5D7u3KnDze39pbI
    MD5:B6CE10AC8E34F1607517963FD5C79A3D
    SHA1:21FF46C523AC4708E2B44F95E67EDF271E568E89
    SHA-256:9C5AB31AEBB1140F1BCAFFA78593315A2843E159D6317A785C370FD1458A755A
    SHA-512:3A730FD1A2593CD7BB167B8D158A568B9F3ED92D1FFD5C8254C6A600809B5A6C4366F4807FA02CD4C80A50A7949D83998CC8F190703684E9D8679489D2A72EFB
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2006, 2011, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABI
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java source, ASCII text
    Category:dropped
    Size (bytes):8480
    Entropy (8bit):4.722145068840168
    Encrypted:false
    SSDEEP:192:h6rsdrsQXJ3r37e6E3Kp0pMDTi6ESp8ewF8q8L:srsdrsU5D7u3K+Ms6
    MD5:03A528F30EA2AE152052567AB93193BA
    SHA1:C423581E9BC9725318858146C44D632C63CF290D
    SHA-256:C514E94B1E80FDB4EF421CB5BD8746D47146B8C8BC7BB44CC48C1FD7DB4E9646
    SHA-512:D28E98110340DC54CEF8D47AC834C69908C7569EB5038CBCB483FE4207047774628CF898519126369E9D0402FD9317F5B5C0FA24955D6100019C58659904CB0C
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2006, 2011, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABI
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java source, ASCII text
    Category:dropped
    Size (bytes):17249
    Entropy (8bit):4.784244367477672
    Encrypted:false
    SSDEEP:384:srsdrsU5D7u3KcUuKpvYikkNdPSK0Se7VJ5QX8:sAPD7UKcUHpvYlCStZ7SM
    MD5:ECF6C810131936A3FCDB45EAD933FC5E
    SHA1:466839E56D643E26DD556B500773E5B2F624F3B2
    SHA-256:374C9C9892A29C4AA996A751DC181E4CA7918DDBAB15C1F95FD5A698656754BA
    SHA-512:417356B92DECFAF7D465F5F53CDDFDB21B6EE445D860C4313663AF997E2AACBFCD956D1187E8D538591DFD75201CD4EF36196ADF02BCF905D26A256C037C8481
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2006, 2011, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABI
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java source, ASCII text
    Category:dropped
    Size (bytes):15392
    Entropy (8bit):4.695961776929103
    Encrypted:false
    SSDEEP:384:srsdrsU5D7u3KTZ4/JJEuTYSk8mgFFVj8Yl+:sAPD7UKTZ2tX5m
    MD5:DA59F489C78C8B82950B6CF5B18CB3BA
    SHA1:0C939EB554DB982BA8CBCA647061399BE0E99C93
    SHA-256:56B259249C7F2878BA9DB88FBE88A474C4F2E41E6A2BD2CA9738AE17A90CBB64
    SHA-512:1DD45F07C84F0C332368FDBC84AF5D0A5CB0EF936E170C4A97DCBF96B2C765FA3CCA574D3DE50F2BBF1C8B2D617E3CAEA35D898D327DF82793AC2AAA62B51EB2
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2006, 2011, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABI
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java source, ASCII text
    Category:dropped
    Size (bytes):45248
    Entropy (8bit):4.668565650552877
    Encrypted:false
    SSDEEP:768:sAPD7UK0ea4KX4WYBVWxSjH+VUp3/xKFcXqk3AgFGUBdvo3EKMpYFUhnj3jQJHMS:sA3UjeaLX4WY3WxSjHYUp3/xKFcXqk3M
    MD5:EB1AD84EF95A1580246C8D0113CBE330
    SHA1:BFDB0F1D2AB7AA4F37B0E2BF1EF541CAC15BCFD2
    SHA-256:1F0D766456D6430EFEC9EA142B29B1AD32FCD8895D8211E4A7BA097BB7E39E73
    SHA-512:93CC9DE7DA9E45A75A6486F6E28D9236BDA6617A0C6C35187BD3BA4CCE2FCAFE26EF8ACB67F130F7A825377068A5BD0A97137BC873D9FB09BB3BBFBFEB00D0B1
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2006, 2011, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABI
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java source, ASCII text
    Category:dropped
    Size (bytes):14006
    Entropy (8bit):4.681860528834789
    Encrypted:false
    SSDEEP:384:srsdrsU5D7u3K/Izu8LBzu62hXjXK8gHCMdJojA8/In:sAPD7UKj88g1
    MD5:48720087E7B5B0CD579CF93AE5CD844B
    SHA1:388079E0AD10EF2A4FF9CB5E0D6B57C26B7627D9
    SHA-256:BD8BD4E0900948F49DCF2C3E70F3904BE0FF0F318FB3993CB9361BCE0A45306D
    SHA-512:48AFB2FEB03F03631E6AE09DFEBB6B0D8E3DD173D60AF341E30DDC8F65444323B96F024B5FF327BA7995E6785186328BB873F0278031B847A5DCC495C32C6781
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2006, 2011, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABI
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java source, ASCII text
    Category:dropped
    Size (bytes):14134
    Entropy (8bit):4.652460675839428
    Encrypted:false
    SSDEEP:384:srsdrsU5D7u3Kxy7BKtWILA/a69mdNXanyIj8jUgPGrpDNAFhTLtsZ2j+1EFw1Go:sAPD7UKAKn69MX35P+
    MD5:D94D14FCB833530D73C6692F2FD1D177
    SHA1:63E4CC804AFCE3E64B6C48F52F67C0685C117C28
    SHA-256:C32720901652A29C08E08BB9B59843762DEBF08CAD918573AB7C0D5F94847EE2
    SHA-512:9A99C0648889928474D32D436F59120030E9A7E85DDA37E3F499F434EB1C1F14EA65FD3537C265B52B9DA85AA99457043AE38EC666D768D91CC083F6754477C0
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2006, 2011, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABI
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java source, ASCII text
    Category:dropped
    Size (bytes):11601
    Entropy (8bit):4.82300275089616
    Encrypted:false
    SSDEEP:192:h6rsdrsQXJ3r37e6E3KOOA8fP1Ao6w/uuQq8VJGfxuuPtPcIbt3ICaG:srsdrsU5D7u3KO9C018BkCD
    MD5:5B0AE61E741DA5D329EB8742319E3D23
    SHA1:DCB2DCD0239954CD6F12A9A33BB00F8ADC94C05A
    SHA-256:F791E255D06FD56B81D6594BC11113AED9518FF3399A6397517B84A159C5268F
    SHA-512:9CE16F31E8B2BA427BDED4D5072B87F2FFC5D7318CD603B99DFB9D0C4978B0BBF73A5BA75DD2B7E3B162C66F734D6061307D83DA2D4620C173C32BD5D5CBF481
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2006, 2011, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABI
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java source, ASCII text
    Category:dropped
    Size (bytes):6197
    Entropy (8bit):4.902188859512374
    Encrypted:false
    SSDEEP:192:h6rsdrsQXJ3r37e6E3KknRFSfdwtaN1zD31lwMVhtIbsv9z1RsTpDn:srsdrsU5D7u3KQsN5D3bX46o
    MD5:4E8325FC4F1250F24AC00B05E3B4F9F4
    SHA1:C321627D010115790B0C7429EE283F519BFEE4E0
    SHA-256:849B785801A922BA0E275E3CC755C2F441E62E67B3A4DCB2220F264E9E4F1F2D
    SHA-512:1AC8D499E1B41AF702E9040535D1E539968AA08DB4F71438548F54A1A41B0E5463ABEFF4CC24555EAE6075B0183D2DEBEF7F5AA5EDAB38BD2D86E335B691EE86
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2006, 2011, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABI
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java source, ASCII text
    Category:dropped
    Size (bytes):6880
    Entropy (8bit):4.862411094771836
    Encrypted:false
    SSDEEP:192:h6rsdrsQXJ3r37e6E3K+RScmcFdjnzcnSPJm22Uf2UdVJ4DK:srsdrsU5D7u3KaDF
    MD5:3A1A8C8990F76A3A79FC607B2A029B5B
    SHA1:1574A442DDAF3ACCCE711C312A9A7D46777C376E
    SHA-256:20C21D6295E7FD965A8FCE0AC74505AC8599432B79225C08FC20975DEEAAE05D
    SHA-512:1D378BF1932EA477561554F9AA515B6B0848609DCF169696CA675C4C57B2BE80335E69C1543BFF53F052B028194CD6BCA7B6676B66AE6208F970B8E2E86109C2
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2006, 2011, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABI
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java source, ASCII text
    Category:dropped
    Size (bytes):11413
    Entropy (8bit):4.827055588204934
    Encrypted:false
    SSDEEP:192:h6rsdrsQXJ3r37e6E3KyBncRr6muBOetu3sK8OK4uaMv4uoMn8CGPQcS58CGPncb:srsdrsU5D7u3KyBnhmuBOqu3sXH4uaiF
    MD5:689AD725F115A354D5726F7CC3473888
    SHA1:9FBAF615B0C51794972FF0FFF54324919C511A9F
    SHA-256:BF10FEEFF6D80361E4D1A1E8808133A6D330331B85DD5A52179957B499BD60F2
    SHA-512:EDC3CC8238A045D7B8E16E46FB3F70D234544A85DD1063D151B3AA42AB0E6FCA6DFD533CFF00E3058B32BCB0595D5B804FC7F5DF063AD114E938E8ED1569A371
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2006, 2011, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABI
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java source, ASCII text
    Category:dropped
    Size (bytes):14832
    Entropy (8bit):4.698568311704341
    Encrypted:false
    SSDEEP:384:srsdrsU5D7u3KpKZf31PbnU1PUx1Pbx5ARU6fhX6fbX6fBLm0+3iWb7:sAPD7UKpIf31PbnU1PUx1Pbx5ARU6ZXa
    MD5:B8E2E2B06C416B523CA1E3E891E063EA
    SHA1:57DB99A0FD23286AA6CCA2463D1D9ACD4FF41EE8
    SHA-256:7882AB634282F500DC60B4BEB91306F5E7489BAA9F67D276C2250A53CE82AD83
    SHA-512:1353205B3B4F6B7E5F8EAC9B1C15EEC70813959838CEE8779E4F7FF42AD558216006AE88A44A20A1939E6A3D16759BF0D473E7DE0768497D9EF1BDFBC9EF0A97
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2006, 2011, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABI
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java source, ASCII text
    Category:dropped
    Size (bytes):11601
    Entropy (8bit):4.82300275089616
    Encrypted:false
    SSDEEP:192:h6rsdrsQXJ3r37e6E3KOOA8fP1Ao6w/uuQq8VJGfxuuPtPcIbt3ICaG:srsdrsU5D7u3KO9C018BkCD
    MD5:5B0AE61E741DA5D329EB8742319E3D23
    SHA1:DCB2DCD0239954CD6F12A9A33BB00F8ADC94C05A
    SHA-256:F791E255D06FD56B81D6594BC11113AED9518FF3399A6397517B84A159C5268F
    SHA-512:9CE16F31E8B2BA427BDED4D5072B87F2FFC5D7318CD603B99DFB9D0C4978B0BBF73A5BA75DD2B7E3B162C66F734D6061307D83DA2D4620C173C32BD5D5CBF481
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2006, 2011, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABI
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java source, ASCII text
    Category:dropped
    Size (bytes):14832
    Entropy (8bit):4.698568311704341
    Encrypted:false
    SSDEEP:384:srsdrsU5D7u3KpKZf31PbnU1PUx1Pbx5ARU6fhX6fbX6fBLm0+3iWb7:sAPD7UKpIf31PbnU1PUx1Pbx5ARU6ZXa
    MD5:B8E2E2B06C416B523CA1E3E891E063EA
    SHA1:57DB99A0FD23286AA6CCA2463D1D9ACD4FF41EE8
    SHA-256:7882AB634282F500DC60B4BEB91306F5E7489BAA9F67D276C2250A53CE82AD83
    SHA-512:1353205B3B4F6B7E5F8EAC9B1C15EEC70813959838CEE8779E4F7FF42AD558216006AE88A44A20A1939E6A3D16759BF0D473E7DE0768497D9EF1BDFBC9EF0A97
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2006, 2011, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABI
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java source, ASCII text
    Category:dropped
    Size (bytes):6197
    Entropy (8bit):4.902188859512374
    Encrypted:false
    SSDEEP:192:h6rsdrsQXJ3r37e6E3KknRFSfdwtaN1zD31lwMVhtIbsv9z1RsTpDn:srsdrsU5D7u3KQsN5D3bX46o
    MD5:4E8325FC4F1250F24AC00B05E3B4F9F4
    SHA1:C321627D010115790B0C7429EE283F519BFEE4E0
    SHA-256:849B785801A922BA0E275E3CC755C2F441E62E67B3A4DCB2220F264E9E4F1F2D
    SHA-512:1AC8D499E1B41AF702E9040535D1E539968AA08DB4F71438548F54A1A41B0E5463ABEFF4CC24555EAE6075B0183D2DEBEF7F5AA5EDAB38BD2D86E335B691EE86
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2006, 2011, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABI
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java source, ASCII text
    Category:dropped
    Size (bytes):14134
    Entropy (8bit):4.652460675839428
    Encrypted:false
    SSDEEP:384:srsdrsU5D7u3Kxy7BKtWILA/a69mdNXanyIj8jUgPGrpDNAFhTLtsZ2j+1EFw1Go:sAPD7UKAKn69MX35P+
    MD5:D94D14FCB833530D73C6692F2FD1D177
    SHA1:63E4CC804AFCE3E64B6C48F52F67C0685C117C28
    SHA-256:C32720901652A29C08E08BB9B59843762DEBF08CAD918573AB7C0D5F94847EE2
    SHA-512:9A99C0648889928474D32D436F59120030E9A7E85DDA37E3F499F434EB1C1F14EA65FD3537C265B52B9DA85AA99457043AE38EC666D768D91CC083F6754477C0
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2006, 2011, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABI
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java source, ASCII text
    Category:dropped
    Size (bytes):11413
    Entropy (8bit):4.827055588204934
    Encrypted:false
    SSDEEP:192:h6rsdrsQXJ3r37e6E3KyBncRr6muBOetu3sK8OK4uaMv4uoMn8CGPQcS58CGPncb:srsdrsU5D7u3KyBnhmuBOqu3sXH4uaiF
    MD5:689AD725F115A354D5726F7CC3473888
    SHA1:9FBAF615B0C51794972FF0FFF54324919C511A9F
    SHA-256:BF10FEEFF6D80361E4D1A1E8808133A6D330331B85DD5A52179957B499BD60F2
    SHA-512:EDC3CC8238A045D7B8E16E46FB3F70D234544A85DD1063D151B3AA42AB0E6FCA6DFD533CFF00E3058B32BCB0595D5B804FC7F5DF063AD114E938E8ED1569A371
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2006, 2011, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABI
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:HTML document, ASCII text
    Category:dropped
    Size (bytes):3094
    Entropy (8bit):5.161297097086309
    Encrypted:false
    SSDEEP:96:EorYJTrYJEfiQX3f3jp2cAI3cPHcpNHeBHDnAHknCHljHqHB:EorsTrs+jX3f3d2Q3cKOFnuI
    MD5:C2B3325530EE758542D02550A2649A37
    SHA1:94034F9409B9DB3A215CF5F5B4BC4D0F389BDA75
    SHA-256:51C444AB66E8C93A59F6EC424AB09816357D71DFA35385286E554F2B3B327A25
    SHA-512:7C6877EE6A1980DA719BD97D5A4D6185C30CD840A70E52B48512B11B777F1A48C38A9100962D5A7A3D45C099A181235773DA9FB949D3F9424C4905A3584415CE
    Malicious:false
    Reputation:low
    Preview:<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">..<html>. <head>.. . Copyright (c) 2006, Oracle and/or its affiliates. All rights reserved... Redistribution and use in source and binary forms, with or without. modification, are permitted provided that the following conditions. are met:.. - Redistributions of source code must retain the above copyright. notice, this list of conditions and the following disclaimer... - Redistributions in binary form must reproduce the above copyright. notice, this list of conditions and the following disclaimer in the. documentation and/or other materials provided with the distribution... - Neither the name of Oracle nor the names of its. contributors may be used to endorse or promote products derived. from this software without specific prior written permission... THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,.
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java source, ASCII text
    Category:dropped
    Size (bytes):6880
    Entropy (8bit):4.862411094771836
    Encrypted:false
    SSDEEP:192:h6rsdrsQXJ3r37e6E3K+RScmcFdjnzcnSPJm22Uf2UdVJ4DK:srsdrsU5D7u3KaDF
    MD5:3A1A8C8990F76A3A79FC607B2A029B5B
    SHA1:1574A442DDAF3ACCCE711C312A9A7D46777C376E
    SHA-256:20C21D6295E7FD965A8FCE0AC74505AC8599432B79225C08FC20975DEEAAE05D
    SHA-512:1D378BF1932EA477561554F9AA515B6B0848609DCF169696CA675C4C57B2BE80335E69C1543BFF53F052B028194CD6BCA7B6676B66AE6208F970B8E2E86109C2
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2006, 2011, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABI
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:HTML document, ASCII text
    Category:dropped
    Size (bytes):3094
    Entropy (8bit):5.161297097086309
    Encrypted:false
    SSDEEP:96:EorYJTrYJEfiQX3f3jp2cAI3cPHcpNHeBHDnAHknCHljHqHB:EorsTrs+jX3f3d2Q3cKOFnuI
    MD5:C2B3325530EE758542D02550A2649A37
    SHA1:94034F9409B9DB3A215CF5F5B4BC4D0F389BDA75
    SHA-256:51C444AB66E8C93A59F6EC424AB09816357D71DFA35385286E554F2B3B327A25
    SHA-512:7C6877EE6A1980DA719BD97D5A4D6185C30CD840A70E52B48512B11B777F1A48C38A9100962D5A7A3D45C099A181235773DA9FB949D3F9424C4905A3584415CE
    Malicious:false
    Reputation:low
    Preview:<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">..<html>. <head>.. . Copyright (c) 2006, Oracle and/or its affiliates. All rights reserved... Redistribution and use in source and binary forms, with or without. modification, are permitted provided that the following conditions. are met:.. - Redistributions of source code must retain the above copyright. notice, this list of conditions and the following disclaimer... - Redistributions in binary form must reproduce the above copyright. notice, this list of conditions and the following disclaimer in the. documentation and/or other materials provided with the distribution... - Neither the name of Oracle nor the names of its. contributors may be used to endorse or promote products derived. from this software without specific prior written permission... THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,.
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:C source, ASCII text
    Category:dropped
    Size (bytes):9219
    Entropy (8bit):4.809637152686827
    Encrypted:false
    SSDEEP:192:h6rsdrsQXJ3r37e6E3KyfGj6e57oKzZCMO90SG+mktyGbyOBGWp+yN57EL:srsdrsU5D7u3KnDze39pbI
    MD5:B6CE10AC8E34F1607517963FD5C79A3D
    SHA1:21FF46C523AC4708E2B44F95E67EDF271E568E89
    SHA-256:9C5AB31AEBB1140F1BCAFFA78593315A2843E159D6317A785C370FD1458A755A
    SHA-512:3A730FD1A2593CD7BB167B8D158A568B9F3ED92D1FFD5C8254C6A600809B5A6C4366F4807FA02CD4C80A50A7949D83998CC8F190703684E9D8679489D2A72EFB
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2006, 2011, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABI
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java source, ASCII text
    Category:dropped
    Size (bytes):19636
    Entropy (8bit):4.68765720443026
    Encrypted:false
    SSDEEP:384:srsdrsU5D7u3Kr4nh3sitx5jJHudgNczzOWwxUp8BxplFanOKBKAMqJ6L9lC:sAPD7UKMh3TjJHuyNmyPOpK/lFEONAlZ
    MD5:3C5D3E7EC398B7B30A6896C22EE32C03
    SHA1:51BDD780C5E70B8FD9B1C6448E7FAD057BD55892
    SHA-256:B66B30AAA8197765EACD9E4F497588AE0DA209030D8723C863718EF6D4544DC7
    SHA-512:7F884AD4D7C5838B03794D0363F7ECE17A2052A9FFF27DEDCF8322BD4E7E66341345179FA24889FD3BE0128BF095E080761122E728FF854F51E1168F9A52CF26
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2006, 2011, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABI
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java source, ASCII text
    Category:dropped
    Size (bytes):22655
    Entropy (8bit):4.567518548023222
    Encrypted:false
    SSDEEP:384:srsdrsU5D7u3KQoPgnFZOw0ZqQBfpXotsh8Wu44CzUVf8dlLltacaWB2j:sAPD7UKfELNQBL4CzUKPlthaS2j
    MD5:1AAD2DB55409E26F75831F9F87DC91FA
    SHA1:7019490254706937E0B9DE42877326DDDCEDB9CA
    SHA-256:B6AE106C01DDF69AD95DB71073A29DF86D6DB96CBC68F78907F88A7AD763B39C
    SHA-512:334FDD3EC740D0EFBC871E25E4D18C3300627235C9C19B04F0083EACF3907C4A7CA6604A3287A5769F0D79E3ACF0899D348CE611C24B470BCC125915CFAC50AA
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2006, 2011, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABI
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java source, ASCII text
    Category:dropped
    Size (bytes):8480
    Entropy (8bit):4.722145068840168
    Encrypted:false
    SSDEEP:192:h6rsdrsQXJ3r37e6E3Kp0pMDTi6ESp8ewF8q8L:srsdrsU5D7u3K+Ms6
    MD5:03A528F30EA2AE152052567AB93193BA
    SHA1:C423581E9BC9725318858146C44D632C63CF290D
    SHA-256:C514E94B1E80FDB4EF421CB5BD8746D47146B8C8BC7BB44CC48C1FD7DB4E9646
    SHA-512:D28E98110340DC54CEF8D47AC834C69908C7569EB5038CBCB483FE4207047774628CF898519126369E9D0402FD9317F5B5C0FA24955D6100019C58659904CB0C
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2006, 2011, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABI
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java source, ASCII text
    Category:dropped
    Size (bytes):17249
    Entropy (8bit):4.784244367477672
    Encrypted:false
    SSDEEP:384:srsdrsU5D7u3KcUuKpvYikkNdPSK0Se7VJ5QX8:sAPD7UKcUHpvYlCStZ7SM
    MD5:ECF6C810131936A3FCDB45EAD933FC5E
    SHA1:466839E56D643E26DD556B500773E5B2F624F3B2
    SHA-256:374C9C9892A29C4AA996A751DC181E4CA7918DDBAB15C1F95FD5A698656754BA
    SHA-512:417356B92DECFAF7D465F5F53CDDFDB21B6EE445D860C4313663AF997E2AACBFCD956D1187E8D538591DFD75201CD4EF36196ADF02BCF905D26A256C037C8481
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2006, 2011, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABI
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java source, ASCII text
    Category:dropped
    Size (bytes):45248
    Entropy (8bit):4.668565650552877
    Encrypted:false
    SSDEEP:768:sAPD7UK0ea4KX4WYBVWxSjH+VUp3/xKFcXqk3AgFGUBdvo3EKMpYFUhnj3jQJHMS:sA3UjeaLX4WY3WxSjHYUp3/xKFcXqk3M
    MD5:EB1AD84EF95A1580246C8D0113CBE330
    SHA1:BFDB0F1D2AB7AA4F37B0E2BF1EF541CAC15BCFD2
    SHA-256:1F0D766456D6430EFEC9EA142B29B1AD32FCD8895D8211E4A7BA097BB7E39E73
    SHA-512:93CC9DE7DA9E45A75A6486F6E28D9236BDA6617A0C6C35187BD3BA4CCE2FCAFE26EF8ACB67F130F7A825377068A5BD0A97137BC873D9FB09BB3BBFBFEB00D0B1
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2006, 2011, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABI
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:HTML document, ASCII text
    Category:dropped
    Size (bytes):1834
    Entropy (8bit):5.176393417739283
    Encrypted:false
    SSDEEP:48:jOorYJTrYJEfDWQvs432sD32scMEtu33tYTH8eE:6orYJTrYJEfiQX3f3jp2ceE
    MD5:E7C1D66EDEF7E05DA0C1CA332F329367
    SHA1:3D9A65740A9D483A50BC60EFF0137C1DCEE2DBF6
    SHA-256:EE5382E5738F71DEDBDDFD9B252754DF32B3D22F501026813693373927D48DBF
    SHA-512:EC2AB57B2B5809CB5BABDC8F3FD45E13003BA22C9C9FBE3EEA3EA6D47061B5712BB16539A097553C12F47BDDAD7B97B030A7E70CE7A12A507ED47A3D4EA906E8
    Malicious:false
    Reputation:low
    Preview:<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">..<html>. <head>. . Copyright (c) 2006, Oracle and/or its affiliates. All rights reserved... Redistribution and use in source and binary forms, with or without. modification, are permitted provided that the following conditions. are met:.. - Redistributions of source code must retain the above copyright. notice, this list of conditions and the following disclaimer... - Redistributions in binary form must reproduce the above copyright. notice, this list of conditions and the following disclaimer in the. documentation and/or other materials provided with the distribution... - Neither the name of Oracle nor the names of its. contributors may be used to endorse or promote products derived. from this software without specific prior written permission... THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,.
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java source, ASCII text
    Category:dropped
    Size (bytes):15392
    Entropy (8bit):4.695961776929103
    Encrypted:false
    SSDEEP:384:srsdrsU5D7u3KTZ4/JJEuTYSk8mgFFVj8Yl+:sAPD7UKTZ2tX5m
    MD5:DA59F489C78C8B82950B6CF5B18CB3BA
    SHA1:0C939EB554DB982BA8CBCA647061399BE0E99C93
    SHA-256:56B259249C7F2878BA9DB88FBE88A474C4F2E41E6A2BD2CA9738AE17A90CBB64
    SHA-512:1DD45F07C84F0C332368FDBC84AF5D0A5CB0EF936E170C4A97DCBF96B2C765FA3CCA574D3DE50F2BBF1C8B2D617E3CAEA35D898D327DF82793AC2AAA62B51EB2
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2006, 2011, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABI
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java source, ASCII text
    Category:dropped
    Size (bytes):7364
    Entropy (8bit):4.8526590194522194
    Encrypted:false
    SSDEEP:192:h6rsdrsQXJ3r37e6E3KX7xiGtlTDboawdojdPcO/2AoibPQoMxgNo5oLF:srsdrsU5D7u3KX7xjnfbodid9/2ARjQu
    MD5:9A6CD13C1BC2AAF7D1438F94C677B4AE
    SHA1:761CFFA79ED5C7FF7D25D5DCF9BC9DA671AAF30D
    SHA-256:E33275B70CEA07D319B30FD042E04228055198920D1A30CC9C5205C5C08EC9C2
    SHA-512:FC0878107F61C6F3120189E0D9B9D6C6F6DAC98F40894E1CB5AB180A2D95887543B86AFBF3D5E435343CA2CF94D34E16440B050AB8F1BB83243934A2FCC2EBEC
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2006, 2011, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABI
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java source, ASCII text
    Category:dropped
    Size (bytes):11676
    Entropy (8bit):4.681873347283984
    Encrypted:false
    SSDEEP:192:h6rsdrsQXJ3r37e6E3K404D01AVNoiRY8TooEoXVIqOojo8okxxopzokroXPo0oN:srsdrsU5D7u3KD4D0gmiRY8TiWxOCTLG
    MD5:BA2EFDBF12F38C60556DF6E64F4D8647
    SHA1:9AFA7FA0A2E91A50DB0D6C53C75CE0A19D04DD49
    SHA-256:8990C6DF649D2AE17A0F8C5748B1C0D734237CE2DF226522613334B21499812C
    SHA-512:D4F000A1310EF8F9872175C86902956D90A398D846B629EC8026363BC4E87101C35BCC962C0836B0D3C4C87614FE9E0254336005273F619375B9FEA26B51AF70
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2006, 2011, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABI
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java source, ASCII text
    Category:dropped
    Size (bytes):14006
    Entropy (8bit):4.681860528834789
    Encrypted:false
    SSDEEP:384:srsdrsU5D7u3K/Izu8LBzu62hXjXK8gHCMdJojA8/In:sAPD7UKj88g1
    MD5:48720087E7B5B0CD579CF93AE5CD844B
    SHA1:388079E0AD10EF2A4FF9CB5E0D6B57C26B7627D9
    SHA-256:BD8BD4E0900948F49DCF2C3E70F3904BE0FF0F318FB3993CB9361BCE0A45306D
    SHA-512:48AFB2FEB03F03631E6AE09DFEBB6B0D8E3DD173D60AF341E30DDC8F65444323B96F024B5FF327BA7995E6785186328BB873F0278031B847A5DCC495C32C6781
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2006, 2011, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABI
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:HTML document, ASCII text
    Category:dropped
    Size (bytes):1834
    Entropy (8bit):5.176393417739283
    Encrypted:false
    SSDEEP:48:jOorYJTrYJEfDWQvs432sD32scMEtu33tYTH8eE:6orYJTrYJEfiQX3f3jp2ceE
    MD5:E7C1D66EDEF7E05DA0C1CA332F329367
    SHA1:3D9A65740A9D483A50BC60EFF0137C1DCEE2DBF6
    SHA-256:EE5382E5738F71DEDBDDFD9B252754DF32B3D22F501026813693373927D48DBF
    SHA-512:EC2AB57B2B5809CB5BABDC8F3FD45E13003BA22C9C9FBE3EEA3EA6D47061B5712BB16539A097553C12F47BDDAD7B97B030A7E70CE7A12A507ED47A3D4EA906E8
    Malicious:false
    Reputation:low
    Preview:<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">..<html>. <head>. . Copyright (c) 2006, Oracle and/or its affiliates. All rights reserved... Redistribution and use in source and binary forms, with or without. modification, are permitted provided that the following conditions. are met:.. - Redistributions of source code must retain the above copyright. notice, this list of conditions and the following disclaimer... - Redistributions in binary form must reproduce the above copyright. notice, this list of conditions and the following disclaimer in the. documentation and/or other materials provided with the distribution... - Neither the name of Oracle nor the names of its. contributors may be used to endorse or promote products derived. from this software without specific prior written permission... THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,.
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:ASCII text
    Category:dropped
    Size (bytes):2392
    Entropy (8bit):4.359284472723321
    Encrypted:false
    SSDEEP:48:Au+H0MsrW7TP75PAMpG12AEVH+MD+NYixKlStYrV5Say4WN+ZJYckHG:OWi7j7uZE8MCN/xK4iylgQcR
    MD5:A148F769A5FD8CA50D939D865C0FE8B3
    SHA1:74574DA1DBC79DC5673E83E191D59D54B7ADDC65
    SHA-256:F46C24606CC526E4A85F9EF9024D993CB8E158B2C45FA2FF9F5643F5FB92B7A4
    SHA-512:C670A1ED0737BDB8722FDD70ACD2C4617C7BEEE8A5F5F58AF761201EA7E97B763FBE1FF069F8C752174515E97D19E4D8BC2EEE50CD48D3EC3474A2C10AB484BC
    Malicious:false
    Reputation:low
    Preview:######################################################################.# Default Access Control File for Remote JMX(TM) Monitoring.######################################################################.#.# Access control file for Remote JMX API access to monitoring..# This file defines the allowed access for different roles. The.# password file (jmxremote.password by default) defines the roles and their.# passwords. To be functional, a role must have an entry in.# both the password and the access files..#.# Default location of this file is $JRE/lib/management/jmxremote.access.# You can specify an alternate location by specifying a property in .# the management config file $JRE/lib/management/management.properties.# (See that file for details).#.# The file format for password and access files is syntactically the same.# as the Properties file format. The syntax is described in the Javadoc.# for java.util.Properties.load..# Typical access file has multiple lines, where each line
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:ASCII text
    Category:dropped
    Size (bytes):2462
    Entropy (8bit):4.418434030385947
    Encrypted:false
    SSDEEP:48:Jmow7YNkjP9YZAuFovuAnNpG1GMV/BWEUHXYE9nN6k3:s7RT9tvuAnujaE0rN6+
    MD5:9EA19F3820E631BD935F88E9C6DCA82D
    SHA1:21F78153A2610EE734A4DB98C5E553969240E27B
    SHA-256:69665659F9BC27469DA4954C7C306BEF3741C0C2D03D0920CA906A18B8664360
    SHA-512:BA3F6F39373B7F28BA8C0ADCB0C89157825F4588C3325C20E76F4186369874EA144E75BF46C875E754BF53B8BEC5CC29BC1D28562F62E5DE3C806EBBC90EE3B2
    Malicious:false
    Reputation:low
    Preview:##############################################################.# Password File for Remote JMX Monitoring.##############################################################.#.# Password file for Remote JMX API access to monitoring. This.# file defines the different roles and their passwords. The access.# control file (jmxremote.access by default) defines the allowed.# access for each role. To be functional, a role must have an entry.# in both the password and the access files..#.# Default location of this file is $JRE/lib/management/jmxremote.password.# You can specify an alternate location by specifying a property in .# the management config file $JRE/lib/management/management.properties.# or by specifying a system property (See that file for details)....##############################################################.# File permissions of the jmxremote.password file.##############################################################.# Since there are cleartext passwords stored
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:ASCII text
    Category:dropped
    Size (bytes):11895
    Entropy (8bit):4.572697268538936
    Encrypted:false
    SSDEEP:192:pfqsmp18ivSPw/Z1ZJxtgb9xPjZpcNYLTnyuk:tqsmpea2w7ZJxtgBxPjANY/n1k
    MD5:2101B1825E1E35EE3CCC8D0138B1E127
    SHA1:63CC47155D0DA2AB9045F64BF4E0AE8736B697AD
    SHA-256:D3BEF7EA6C3CE9BBDA0126979D94EE214BB9D7AAA33F59C97634F56961F2CFB2
    SHA-512:4FC6FEA5D7A7B8F8589F05D22C317A225D17DF25CADBD467B43E6078B93DC4CE37D9802525022F6BEFAD18B1CBA1179ED6D8222D228EAACE4F6BD6ABCEEEA009
    Malicious:false
    Reputation:low
    Preview:#####################################################################.#.Default Configuration File for Java Platform Management.#####################################################################.#.# The Management Configuration file (in java.util.Properties format).# will be read if one of the following system properties is set:.# -Dcom.sun.management.jmxremote.port=<port-number>.# or -Dcom.sun.management.snmp.port=<port-number> .# or -Dcom.sun.management.config.file=<this-file>.#.# The default Management Configuration file is:.#.# $JRE/lib/management/management.properties.#.# Another location for the Management Configuration File can be specified.# by the following property on the Java command line:.#.# -Dcom.sun.management.config.file=<this-file>.# .# If -Dcom.sun.management.config.file=<this-file> is set, the port.# number for the management agent can be specified in the config file .# using the following lines:.# .# ################ Management Agent Port ############
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:ASCII text
    Category:dropped
    Size (bytes):2392
    Entropy (8bit):4.359284472723321
    Encrypted:false
    SSDEEP:48:Au+H0MsrW7TP75PAMpG12AEVH+MD+NYixKlStYrV5Say4WN+ZJYckHG:OWi7j7uZE8MCN/xK4iylgQcR
    MD5:A148F769A5FD8CA50D939D865C0FE8B3
    SHA1:74574DA1DBC79DC5673E83E191D59D54B7ADDC65
    SHA-256:F46C24606CC526E4A85F9EF9024D993CB8E158B2C45FA2FF9F5643F5FB92B7A4
    SHA-512:C670A1ED0737BDB8722FDD70ACD2C4617C7BEEE8A5F5F58AF761201EA7E97B763FBE1FF069F8C752174515E97D19E4D8BC2EEE50CD48D3EC3474A2C10AB484BC
    Malicious:false
    Reputation:low
    Preview:######################################################################.# Default Access Control File for Remote JMX(TM) Monitoring.######################################################################.#.# Access control file for Remote JMX API access to monitoring..# This file defines the allowed access for different roles. The.# password file (jmxremote.password by default) defines the roles and their.# passwords. To be functional, a role must have an entry in.# both the password and the access files..#.# Default location of this file is $JRE/lib/management/jmxremote.access.# You can specify an alternate location by specifying a property in .# the management config file $JRE/lib/management/management.properties.# (See that file for details).#.# The file format for password and access files is syntactically the same.# as the Properties file format. The syntax is described in the Javadoc.# for java.util.Properties.load..# Typical access file has multiple lines, where each line
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):2399
    Entropy (8bit):5.1359588753103305
    Encrypted:false
    SSDEEP:48:czOorYJTrYJEfDWQvs432sD32scMEtu33tYTHwbxeH0DGpmAJIAk3UhIA9HS:/orYJTrYJEfiQX3f3jp2QbxeH0Dm3bkZ
    MD5:D865747F248197F660A4E42B855716CC
    SHA1:042E28CC3AE05D3B0FF5D9B56B6019EF9D8154D0
    SHA-256:663735BEF5F866E10D4A374494F25CD1EEF12BA212F76A644E277DB1D5D64F94
    SHA-512:F30B481EF801C112BFDA176D03687A849FD5B186CF672BBFD2B06780D58B3951356B502081C84A94C5DCBD5C984F8C5B57780A650264D8312338518289745CC6
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8" standalone="yes"?>.. . Copyright (c) 2006, Oracle and/or its affiliates. All rights reserved... Redistribution and use in source and binary forms, with or without. modification, are permitted provided that the following conditions. are met:.. - Redistributions of source code must retain the above copyright. notice, this list of conditions and the following disclaimer... - Redistributions in binary form must reproduce the above copyright. notice, this list of conditions and the following disclaimer in the. documentation and/or other materials provided with the distribution... - Neither the name of Oracle nor the names of its. contributors may be used to endorse or promote products derived. from this software without specific prior written permission... THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. THE IMPLIED WARRANTIES O
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:ASCII text
    Category:dropped
    Size (bytes):11895
    Entropy (8bit):4.572697268538936
    Encrypted:false
    SSDEEP:192:pfqsmp18ivSPw/Z1ZJxtgb9xPjZpcNYLTnyuk:tqsmpea2w7ZJxtgBxPjANY/n1k
    MD5:2101B1825E1E35EE3CCC8D0138B1E127
    SHA1:63CC47155D0DA2AB9045F64BF4E0AE8736B697AD
    SHA-256:D3BEF7EA6C3CE9BBDA0126979D94EE214BB9D7AAA33F59C97634F56961F2CFB2
    SHA-512:4FC6FEA5D7A7B8F8589F05D22C317A225D17DF25CADBD467B43E6078B93DC4CE37D9802525022F6BEFAD18B1CBA1179ED6D8222D228EAACE4F6BD6ABCEEEA009
    Malicious:false
    Reputation:low
    Preview:#####################################################################.#.Default Configuration File for Java Platform Management.#####################################################################.#.# The Management Configuration file (in java.util.Properties format).# will be read if one of the following system properties is set:.# -Dcom.sun.management.jmxremote.port=<port-number>.# or -Dcom.sun.management.snmp.port=<port-number> .# or -Dcom.sun.management.config.file=<this-file>.#.# The default Management Configuration file is:.#.# $JRE/lib/management/management.properties.#.# Another location for the Management Configuration File can be specified.# by the following property on the Java command line:.#.# -Dcom.sun.management.config.file=<this-file>.# .# If -Dcom.sun.management.config.file=<this-file> is set, the port.# number for the management agent can be specified in the config file .# using the following lines:.# .# ################ Management Agent Port ############
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:ASCII text
    Category:dropped
    Size (bytes):2462
    Entropy (8bit):4.418434030385947
    Encrypted:false
    SSDEEP:48:Jmow7YNkjP9YZAuFovuAnNpG1GMV/BWEUHXYE9nN6k3:s7RT9tvuAnujaE0rN6+
    MD5:9EA19F3820E631BD935F88E9C6DCA82D
    SHA1:21F78153A2610EE734A4DB98C5E553969240E27B
    SHA-256:69665659F9BC27469DA4954C7C306BEF3741C0C2D03D0920CA906A18B8664360
    SHA-512:BA3F6F39373B7F28BA8C0ADCB0C89157825F4588C3325C20E76F4186369874EA144E75BF46C875E754BF53B8BEC5CC29BC1D28562F62E5DE3C806EBBC90EE3B2
    Malicious:false
    Reputation:low
    Preview:##############################################################.# Password File for Remote JMX Monitoring.##############################################################.#.# Password file for Remote JMX API access to monitoring. This.# file defines the different roles and their passwords. The access.# control file (jmxremote.access by default) defines the allowed.# access for each role. To be functional, a role must have an entry.# in both the password and the access files..#.# Default location of this file is $JRE/lib/management/jmxremote.password.# You can specify an alternate location by specifying a property in .# the management config file $JRE/lib/management/management.properties.# or by specifying a system property (See that file for details)....##############################################################.# File permissions of the jmxremote.password file.##############################################################.# Since there are cleartext passwords stored
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):2399
    Entropy (8bit):5.1359588753103305
    Encrypted:false
    SSDEEP:48:czOorYJTrYJEfDWQvs432sD32scMEtu33tYTHwbxeH0DGpmAJIAk3UhIA9HS:/orYJTrYJEfiQX3f3jp2QbxeH0Dm3bkZ
    MD5:D865747F248197F660A4E42B855716CC
    SHA1:042E28CC3AE05D3B0FF5D9B56B6019EF9D8154D0
    SHA-256:663735BEF5F866E10D4A374494F25CD1EEF12BA212F76A644E277DB1D5D64F94
    SHA-512:F30B481EF801C112BFDA176D03687A849FD5B186CF672BBFD2B06780D58B3951356B502081C84A94C5DCBD5C984F8C5B57780A650264D8312338518289745CC6
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8" standalone="yes"?>.. . Copyright (c) 2006, Oracle and/or its affiliates. All rights reserved... Redistribution and use in source and binary forms, with or without. modification, are permitted provided that the following conditions. are met:.. - Redistributions of source code must retain the above copyright. notice, this list of conditions and the following disclaimer... - Redistributions in binary form must reproduce the above copyright. notice, this list of conditions and the following disclaimer in the. documentation and/or other materials provided with the distribution... - Neither the name of Oracle nor the names of its. contributors may be used to endorse or promote products derived. from this software without specific prior written permission... THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. THE IMPLIED WARRANTIES O
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java source, ASCII text
    Category:dropped
    Size (bytes):12731
    Entropy (8bit):4.600405721766458
    Encrypted:false
    SSDEEP:384:srsdrsU5D7u3KOdwAPUArgJWYo7unRAtgKq6o:sAPD7UKOdwA8dncuRAtgKqZ
    MD5:5C6657FA66774D58B1F3BAC183EF8037
    SHA1:8B6AE277DDBDA8E0F9B305D0F3EA85251998263D
    SHA-256:11024596AEEAB4C673BE05BF1B2C39D65CC22D78AA8CF9952E5215207C5F162F
    SHA-512:57EEAC7ED9110009D1FE3CBD25ED56F5E7186E5402089B9913356EB6293E037D69CC8C28C4C6FDBBFA17B4965AE503035AD3DAC1F8F4A722B5F5ACE9044FECF6
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2006, 2011, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABI
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:C source, ASCII text
    Category:dropped
    Size (bytes):12806
    Entropy (8bit):4.716066717494799
    Encrypted:false
    SSDEEP:384:srsdrsU5D7u3Kl3pAZ+lEbStbuhi5La4sDhrkdOCcO1CIqeEmJ54Js2hrkEEo5Bn:sAPD7UKl3pAZ+lEbStbuhi5La4sDFkde
    MD5:089D0CBB02474AC83BDFC3AE42BC1A06
    SHA1:79DBABDE159AE4FC0A8A7D8A3271148A0E827506
    SHA-256:17E1C7CC5C5F1E0A7FAD6CEE2A3255DEBBF8C3C4CA387C3B162B978BA49B1E2F
    SHA-512:F0F6C88ADC319EB85997AD3F4C699B683DA27A6042508332271D1A2507F13AD3F342D070796B6086A35AACCCA6E661F70EF482A9D65B060AE48936DD45A6A289
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2006, 2011, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABI
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java source, ASCII text
    Category:dropped
    Size (bytes):13356
    Entropy (8bit):4.715018105639032
    Encrypted:false
    SSDEEP:384:srsdrsU5D7u3K0UARuKg545wGRGDYJTCe6V6ePda31xCoju:sAPD7UK0UARuKg5MwGRUYJTCe6V6ePdZ
    MD5:29D70CF3FC2714A5F921237A1531EF11
    SHA1:EAAEEE861665B16295A0B457E84D1A704B37B319
    SHA-256:AA3B804425B1D8AE56EE63138F354D9D6F976590D8108AE165A66543A5616F33
    SHA-512:EDA2394E30C2E53BF158FA2436C362D842E281BC3280AC5869F93D5DB744F386E627005B9E2CB32E68F00940D8CB8422A6F51342F895FCABC0D0335458A5ED9C
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2006, 2011, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABI
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java source, ASCII text
    Category:dropped
    Size (bytes):4523
    Entropy (8bit):5.0082173129042165
    Encrypted:false
    SSDEEP:96:a06rYJdrYJQX3Z3r3dVeE642LuE3KHHNs3CoeQWRwrIzlWJwouPdJur:h6rsdrsQXJ3r37e6E3KnNKUyIAwPw
    MD5:C8E781DE962DE5499E6EDC5E4CA50F70
    SHA1:10DB0427B8D9A5CD0670E76D984FA6DEE1657F1F
    SHA-256:F2FF7EF7BCD466B0E61CC8BAEB4F5272035110835AAE735F5E7513AA12EB488E
    SHA-512:FB563BE920CD61250F0FBFAF7638E6F3D6B3880AA212CA5E22C9FF7C9FC04AE11F1D637184D20896AD3F906A2E1F7CEFA310E61EC8C83196C5C7A56AF83E7E18
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2006, 2011, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABI
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java source, ASCII text
    Category:dropped
    Size (bytes):4060
    Entropy (8bit):5.04472208665288
    Encrypted:false
    SSDEEP:96:a06rYJdrYJQX3Z3r3dVeE642LuE3KH+gIiA6QwkO0rUi6SLQ0E2NPTjm:h6rsdrsQXJ3r37e6E3KegIiAlwkb4SL6
    MD5:4995E723E5AEF7AA35A18643A45FDFD7
    SHA1:23BE38C1F7FC21E457AAEEF463236782D50E0381
    SHA-256:5FAE28015AD81C2564690C83DB84D980158EC055D4F2F9CAAF0AB73901E01548
    SHA-512:1F0B25F92F22D8C2D816964350B316CE06214257D4C9C365E37F2D6EBEE6D9524B2547C3C1BF78DFDFBB97B3F588825A5118001EDC30ADF83C39BB3823951411
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2006, 2011, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABI
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java source, ASCII text
    Category:dropped
    Size (bytes):4060
    Entropy (8bit):5.04472208665288
    Encrypted:false
    SSDEEP:96:a06rYJdrYJQX3Z3r3dVeE642LuE3KH+gIiA6QwkO0rUi6SLQ0E2NPTjm:h6rsdrsQXJ3r37e6E3KegIiAlwkb4SL6
    MD5:4995E723E5AEF7AA35A18643A45FDFD7
    SHA1:23BE38C1F7FC21E457AAEEF463236782D50E0381
    SHA-256:5FAE28015AD81C2564690C83DB84D980158EC055D4F2F9CAAF0AB73901E01548
    SHA-512:1F0B25F92F22D8C2D816964350B316CE06214257D4C9C365E37F2D6EBEE6D9524B2547C3C1BF78DFDFBB97B3F588825A5118001EDC30ADF83C39BB3823951411
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2006, 2011, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABI
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java source, ASCII text
    Category:dropped
    Size (bytes):13356
    Entropy (8bit):4.715018105639032
    Encrypted:false
    SSDEEP:384:srsdrsU5D7u3K0UARuKg545wGRGDYJTCe6V6ePda31xCoju:sAPD7UK0UARuKg5MwGRUYJTCe6V6ePdZ
    MD5:29D70CF3FC2714A5F921237A1531EF11
    SHA1:EAAEEE861665B16295A0B457E84D1A704B37B319
    SHA-256:AA3B804425B1D8AE56EE63138F354D9D6F976590D8108AE165A66543A5616F33
    SHA-512:EDA2394E30C2E53BF158FA2436C362D842E281BC3280AC5869F93D5DB744F386E627005B9E2CB32E68F00940D8CB8422A6F51342F895FCABC0D0335458A5ED9C
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2006, 2011, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABI
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:C source, ASCII text
    Category:dropped
    Size (bytes):12806
    Entropy (8bit):4.716066717494799
    Encrypted:false
    SSDEEP:384:srsdrsU5D7u3Kl3pAZ+lEbStbuhi5La4sDhrkdOCcO1CIqeEmJ54Js2hrkEEo5Bn:sAPD7UKl3pAZ+lEbStbuhi5La4sDFkde
    MD5:089D0CBB02474AC83BDFC3AE42BC1A06
    SHA1:79DBABDE159AE4FC0A8A7D8A3271148A0E827506
    SHA-256:17E1C7CC5C5F1E0A7FAD6CEE2A3255DEBBF8C3C4CA387C3B162B978BA49B1E2F
    SHA-512:F0F6C88ADC319EB85997AD3F4C699B683DA27A6042508332271D1A2507F13AD3F342D070796B6086A35AACCCA6E661F70EF482A9D65B060AE48936DD45A6A289
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2006, 2011, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABI
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java source, ASCII text
    Category:dropped
    Size (bytes):12731
    Entropy (8bit):4.600405721766458
    Encrypted:false
    SSDEEP:384:srsdrsU5D7u3KOdwAPUArgJWYo7unRAtgKq6o:sAPD7UKOdwA8dncuRAtgKqZ
    MD5:5C6657FA66774D58B1F3BAC183EF8037
    SHA1:8B6AE277DDBDA8E0F9B305D0F3EA85251998263D
    SHA-256:11024596AEEAB4C673BE05BF1B2C39D65CC22D78AA8CF9952E5215207C5F162F
    SHA-512:57EEAC7ED9110009D1FE3CBD25ED56F5E7186E5402089B9913356EB6293E037D69CC8C28C4C6FDBBFA17B4965AE503035AD3DAC1F8F4A722B5F5ACE9044FECF6
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2006, 2011, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABI
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java source, ASCII text
    Category:dropped
    Size (bytes):4523
    Entropy (8bit):5.0082173129042165
    Encrypted:false
    SSDEEP:96:a06rYJdrYJQX3Z3r3dVeE642LuE3KHHNs3CoeQWRwrIzlWJwouPdJur:h6rsdrsQXJ3r37e6E3KnNKUyIAwPw
    MD5:C8E781DE962DE5499E6EDC5E4CA50F70
    SHA1:10DB0427B8D9A5CD0670E76D984FA6DEE1657F1F
    SHA-256:F2FF7EF7BCD466B0E61CC8BAEB4F5272035110835AAE735F5E7513AA12EB488E
    SHA-512:FB563BE920CD61250F0FBFAF7638E6F3D6B3880AA212CA5E22C9FF7C9FC04AE11F1D637184D20896AD3F906A2E1F7CEFA310E61EC8C83196C5C7A56AF83E7E18
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2006, 2011, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABI
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java KeyStore
    Category:dropped
    Size (bytes):661
    Entropy (8bit):6.916795371890928
    Encrypted:false
    SSDEEP:12:bsDdTa3yK/oDdTM1Idy6nip0TdhNRSCP+1Mh52Hlis:0TkFsTM1osp0Tdh/SCSQ0lj
    MD5:3F6C4C59DA0271DACD9CEBEB66941475
    SHA1:87AA9F07BCF088D682E4402CC17E0A5C650BE918
    SHA-256:419C6009437117D4471DD64C1A01A288155ED46EB749036DD71B07AD5C55F77C
    SHA-512:75771E7597BFA94BE1B262BCBEF73131428E405C9FF76880479A8DEC895920267253E90103E69524869D8F8640DF043FE156225A6D57F7C3F02A16F5835F203E
    Malicious:false
    Reputation:low
    Preview:..................dukecert.......m..X.509...T0..P0.....>...0...*.H........0o1.0...U....US1.0...U....CA1.0...U....Santa Clara1.0...U....Sun Microsystems, Inc.1.0...U....J2SE1.0...U....Duke0...030423130200Z..300908130200Z0o1.0...U....US1.0...U....CA1.0...U....Santa Clara1.0...U....Sun Microsystems, Inc.1.0...U....J2SE1.0...U....Duke0..0...*.H............0........W....c.hC.....U..6K.......T.....R..l7...1Z.CY..@.o^..LK..9N.X.q.<..t)....k5q.....n..J...N\\...>.......... ...BVi.k..#.....0...*.H............E~.....a.....}a.j...C..w+....D..I(a_.r....<SH....D....X.T.S^.t[.....j...G>*..'..|.....@....$.*T=..96.cV.k...k......2.....]kk...8.".?...?.
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:HTML document, ASCII text, with CRLF line terminators
    Category:dropped
    Size (bytes):1445
    Entropy (8bit):4.559116601576454
    Encrypted:false
    SSDEEP:24:hPZIerkXDrE1OShHFQTE1jI8kO+kp1+/jVUyV0i:tZ/kUJvQ4bCVUyf
    MD5:23FDFA1F1148D95DE4209F4A65562C8B
    SHA1:0D6ED1F7FF8A765FE45F691AACBCD1442653E0E6
    SHA-256:A6718B7F94BFADF061533DECCF43A005B31187208F5F8E7E67D7B603DF38C22D
    SHA-512:78B16827BD214F51B7B1556F063FCDA4E97037BD1E87B970B10284EED34CF0EBA327B0653772A394B1144DD76E2C9279279534D5EB8FEFC10268294EE39B9817
    Malicious:false
    Reputation:low
    Preview:<!DOCTYPE html>..<html>..<head>.. <title>Bulk Data Operations Demo</title>..</head>..<body>..<h2>Bulk Data Operations Demo</h2>....<p>.. This demo shows how to use bulk data operations with the new JDK8.. Collections API... The demo also demonstrates new features of JDK8 such as lambda expressions.. and method/constructor references...</p>....<ul>.. <li><h3>CSV Processor</h3>.... <p>.. Analyzes a CSV file, finds and collects useful information, computes.. different statistics. For more information, see the source file... </p>.. Source: <a href="src/CSVProcessor.java">src/CSVProcessor.java</a>.. <li><h3>Grep</h3>.... <p>.. Behaves like the standard Linux tool Grep. For more information, see.. the source file... </p>.. Source: <a href="src/Grep.java">src/Grep.java</a>.. <li><h3>PasswordGenerator</h3>.... <p>.. Produces a password of desired length. For more info
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:HTML document, ASCII text, with CRLF line terminators
    Category:dropped
    Size (bytes):1445
    Entropy (8bit):4.559116601576454
    Encrypted:false
    SSDEEP:24:hPZIerkXDrE1OShHFQTE1jI8kO+kp1+/jVUyV0i:tZ/kUJvQ4bCVUyf
    MD5:23FDFA1F1148D95DE4209F4A65562C8B
    SHA1:0D6ED1F7FF8A765FE45F691AACBCD1442653E0E6
    SHA-256:A6718B7F94BFADF061533DECCF43A005B31187208F5F8E7E67D7B603DF38C22D
    SHA-512:78B16827BD214F51B7B1556F063FCDA4E97037BD1E87B970B10284EED34CF0EBA327B0653772A394B1144DD76E2C9279279534D5EB8FEFC10268294EE39B9817
    Malicious:false
    Reputation:low
    Preview:<!DOCTYPE html>..<html>..<head>.. <title>Bulk Data Operations Demo</title>..</head>..<body>..<h2>Bulk Data Operations Demo</h2>....<p>.. This demo shows how to use bulk data operations with the new JDK8.. Collections API... The demo also demonstrates new features of JDK8 such as lambda expressions.. and method/constructor references...</p>....<ul>.. <li><h3>CSV Processor</h3>.... <p>.. Analyzes a CSV file, finds and collects useful information, computes.. different statistics. For more information, see the source file... </p>.. Source: <a href="src/CSVProcessor.java">src/CSVProcessor.java</a>.. <li><h3>Grep</h3>.... <p>.. Behaves like the standard Linux tool Grep. For more information, see.. the source file... </p>.. Source: <a href="src/Grep.java">src/Grep.java</a>.. <li><h3>PasswordGenerator</h3>.... <p>.. Produces a password of desired length. For more info
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java source, ASCII text
    Category:dropped
    Size (bytes):14394
    Entropy (8bit):4.515713937618355
    Encrypted:false
    SSDEEP:384:RrsdrsU5D7uLFK+eVay4P8B8nfxcSqGGc+A43CAPhiqK:RAPD7+M+eVay8qk+jGd+XPPk
    MD5:717B29CA774418C157B4A1F5939F9BA9
    SHA1:FBA625DBCECC9809396B4CF8D495B9D23425C095
    SHA-256:AC9023D9F0971D3FE89249C3FF9299D39785243C86D46FB7C331CDDDA6AC4E91
    SHA-512:A6137732C6D14A6144597EF548DC1048ED56A05E6AE29758211507D9275C0D9885E4A21B5CD127838EAD6D1E9E0E56BD9D2A23EA1192D03EF6848A9B5F0D7E4B
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2014, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABILITY A
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java source, ASCII text
    Category:dropped
    Size (bytes):7426
    Entropy (8bit):4.717204421962867
    Encrypted:false
    SSDEEP:192:o6rsdrsQXJ3r37e6ELrdc5IXX0+htcZjmFxwjzdYIi315L2j35VIfkseWVL:RrsdrsU5D7uLZs03YdSdxv0y
    MD5:D3DA7B35DFFE62971DA81552C4FAC2EC
    SHA1:635DF31CD88B9A5662AFFE987C85B0A879484204
    SHA-256:882124EE037F9ACEA4FFD031A086092EAAD4775CE038A6AB5EA3B6F6DF1234B9
    SHA-512:4B364DF71BC79DCC47980B8C9EEC72C20A7793BAF75D057E9944D16C6F232D35A0DD7B56CE9E310AD69703AB4D5EF1757DBEB74BCCAD4058B9B5FB469F6020BA
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2014, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABILITY A
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java source, ASCII text
    Category:dropped
    Size (bytes):4309
    Entropy (8bit):5.009998770170195
    Encrypted:false
    SSDEEP:96:o6rYJdrYJQX3Z3r3dVeE642LuELK/vvXiMMKsT6ctZuRmSE2CMf2NtM4:o6rsdrsQXJ3r37e6ELkHyxKs2qZuRHET
    MD5:EDD27AFEEB0F3DAD5A40DF87E738E430
    SHA1:A3B0248BDEBF0069E45D6BE7A19E949BA7797925
    SHA-256:2CEAC7328CE4A443D5891ED7068055785319153BEF12972A9612F3FD14024491
    SHA-512:376E3173272DFC772B93EB5EA84E9BFFEB98B95EB5630550602C8A5A5BF30072EF385DE9F51AF0501B0771A5F184BE5D175F96121891765448CE097B340AAEAE
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2014, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABILITY A
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java source, ASCII text
    Category:dropped
    Size (bytes):8525
    Entropy (8bit):4.715749287311231
    Encrypted:false
    SSDEEP:192:o6rsdrsQXJ3r37e6ELFKJ5lzHUkSIAMH8I4roF8iqgVo8gipyanC972u+cMrjrOL:RrsdrsU5D7uLFKJY5XMH3WmBqYo8dpyL
    MD5:F5B7A3DECC0A5C5A22EF880FD9DD107D
    SHA1:32B289965A2E1C215EC0287009D2E6907F72AE9E
    SHA-256:124D34323F21C2BF738B9DDD6A3CB06F98AED9F8AC796447E61BFA299FE65401
    SHA-512:C31D8DC7E78FDD9EEA447EE1BF7F82BEDBE8B8C95C164189E5C6CFE12C894E4122D40BD4B90EB03D095D231A9F679240198CB75FDCB890D9DDE6E1749A2BB6BA
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2014, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABILITY A
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java source, ASCII text
    Category:dropped
    Size (bytes):7426
    Entropy (8bit):4.717204421962867
    Encrypted:false
    SSDEEP:192:o6rsdrsQXJ3r37e6ELrdc5IXX0+htcZjmFxwjzdYIi315L2j35VIfkseWVL:RrsdrsU5D7uLZs03YdSdxv0y
    MD5:D3DA7B35DFFE62971DA81552C4FAC2EC
    SHA1:635DF31CD88B9A5662AFFE987C85B0A879484204
    SHA-256:882124EE037F9ACEA4FFD031A086092EAAD4775CE038A6AB5EA3B6F6DF1234B9
    SHA-512:4B364DF71BC79DCC47980B8C9EEC72C20A7793BAF75D057E9944D16C6F232D35A0DD7B56CE9E310AD69703AB4D5EF1757DBEB74BCCAD4058B9B5FB469F6020BA
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2014, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABILITY A
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java source, ASCII text
    Category:dropped
    Size (bytes):8525
    Entropy (8bit):4.715749287311231
    Encrypted:false
    SSDEEP:192:o6rsdrsQXJ3r37e6ELFKJ5lzHUkSIAMH8I4roF8iqgVo8gipyanC972u+cMrjrOL:RrsdrsU5D7uLFKJY5XMH3WmBqYo8dpyL
    MD5:F5B7A3DECC0A5C5A22EF880FD9DD107D
    SHA1:32B289965A2E1C215EC0287009D2E6907F72AE9E
    SHA-256:124D34323F21C2BF738B9DDD6A3CB06F98AED9F8AC796447E61BFA299FE65401
    SHA-512:C31D8DC7E78FDD9EEA447EE1BF7F82BEDBE8B8C95C164189E5C6CFE12C894E4122D40BD4B90EB03D095D231A9F679240198CB75FDCB890D9DDE6E1749A2BB6BA
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2014, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABILITY A
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java source, ASCII text
    Category:dropped
    Size (bytes):14394
    Entropy (8bit):4.515713937618355
    Encrypted:false
    SSDEEP:384:RrsdrsU5D7uLFK+eVay4P8B8nfxcSqGGc+A43CAPhiqK:RAPD7+M+eVay8qk+jGd+XPPk
    MD5:717B29CA774418C157B4A1F5939F9BA9
    SHA1:FBA625DBCECC9809396B4CF8D495B9D23425C095
    SHA-256:AC9023D9F0971D3FE89249C3FF9299D39785243C86D46FB7C331CDDDA6AC4E91
    SHA-512:A6137732C6D14A6144597EF548DC1048ED56A05E6AE29758211507D9275C0D9885E4A21B5CD127838EAD6D1E9E0E56BD9D2A23EA1192D03EF6848A9B5F0D7E4B
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2014, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABILITY A
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java source, ASCII text
    Category:dropped
    Size (bytes):4309
    Entropy (8bit):5.009998770170195
    Encrypted:false
    SSDEEP:96:o6rYJdrYJQX3Z3r3dVeE642LuELK/vvXiMMKsT6ctZuRmSE2CMf2NtM4:o6rsdrsQXJ3r37e6ELkHyxKs2qZuRHET
    MD5:EDD27AFEEB0F3DAD5A40DF87E738E430
    SHA1:A3B0248BDEBF0069E45D6BE7A19E949BA7797925
    SHA-256:2CEAC7328CE4A443D5891ED7068055785319153BEF12972A9612F3FD14024491
    SHA-512:376E3173272DFC772B93EB5EA84E9BFFEB98B95EB5630550602C8A5A5BF30072EF385DE9F51AF0501B0771A5F184BE5D175F96121891765448CE097B340AAEAE
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2014, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABILITY A
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java source, ASCII text
    Category:dropped
    Size (bytes):4342
    Entropy (8bit):4.6719805551162565
    Encrypted:false
    SSDEEP:96:o6rYJdrYJQX3Z3r3dVeMIKlB6ZVVjvOvY3rHyGOCyOHywisVSteTfL:o6rsdrsQXJ3r37eMxB6ZVV1S74SwiV0j
    MD5:2027E0017B703BDA68788C9B00C5B2B5
    SHA1:0EB6F162575CEF41C41AC5DCABC909D370D1838F
    SHA-256:6FF9730D8445E99FCF7367670E10796872BEFB6983F323DB6124AABBB5476FB9
    SHA-512:7D83A426849198561EC49CE50D54D889CD148D644E1F33C5548C5EE4ED492A9BBE29DBF382505ACB245B9843B0F9B1450F6815375ECEBECFAB492DCEB26B0FA8
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2014, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABILITY A
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java source, ASCII text
    Category:dropped
    Size (bytes):4735
    Entropy (8bit):4.700517105751413
    Encrypted:false
    SSDEEP:96:o6rYJdrYJQX3Z3r3dVeZFtFER3ljNfFk0Nm2+bNi2Feq4EXMf0tuST:o6rsdrsQXJ3r37enEF7Ksm2+xi2Feq4k
    MD5:4AB76DB5EBB3232D086BE4D4C46F3489
    SHA1:E146246D6C227CC2F1F205FC91CFB424BE6B3F06
    SHA-256:11F10E611A9A782C2D33EBAF725550D126662301E26932D41441BFF658625343
    SHA-512:4D213CE2EDBCA3F7572A17374CF65F84473370DB321B87908A26F068F4AD7667141C2721E4E9B494369EF8134F59C17BC1B98B67E27DD6799BBC44A797BD01AD
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2014, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABILITY A
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java source, ASCII text
    Category:dropped
    Size (bytes):5045
    Entropy (8bit):4.726377967178703
    Encrypted:false
    SSDEEP:96:o6rYJdrYJQX3Z3r3dVem3+MKRCazUMiQLk7kYecK0jWgqjBwSUN:o6rsdrsQXJ3r37etMKRCazUMiQLk7kYn
    MD5:596C55022CF5FF3B16AB1A60119F3FEE
    SHA1:CB646847332BD63DE1A387EA3DE3936ADB57775D
    SHA-256:9F46D9D3C6059EC317585D6FF8F6B4B6551171682D8626059DA7B74602058334
    SHA-512:589EF6C713F55A62A4C02C1EA57A44319F4745910DBC0B56093D54AAB2F618A5043E6F80ADF7A4279983C2E534CC7478C803B6EB1FBB44B22455E68C996A4121
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2014, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABILITY A
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java source, ASCII text
    Category:dropped
    Size (bytes):4057
    Entropy (8bit):4.81133558476052
    Encrypted:false
    SSDEEP:96:o6rYJdrYJQX3Z3r3dVeHMLt6QBMXKjqSCtVjxcR9pd8v7rf:o6rsdrsQXJ3r37e8t6QBMajqSCtV9cNm
    MD5:A90D1EDC2D8CCE7AE1B5E9A1AF9421DD
    SHA1:87C7E19F375C6B2A48AC48FF9574D7A568156995
    SHA-256:0B45CFC8DBB7EF8CA255D1E10A385845784F01326FA95F769E060F9D526CF54D
    SHA-512:E079546FAD7A7A00BCBD09629A19726D636C4E1476782D994AD56A0DC0A01E77E198E3503A5ECCC72457766B1F2DDE9E5E7F47233F8B0F2F60CC1049FDA604EC
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2014, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABILITY A
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java source, ASCII text
    Category:dropped
    Size (bytes):5092
    Entropy (8bit):4.737904096174729
    Encrypted:false
    SSDEEP:96:o6rYJdrYJQX3Z3r3dVegn3ZHX39WIkM7sVjbkfrVSakrg1R0N2Wj2r5v721B/SvU:o6rsdrsQXJ3r37ein9kOs2fr6myN2WjT
    MD5:EED59EE1CA8C19998D72771947A40ECC
    SHA1:038CEA5FA53D6E50B774B044F54098A0336B3730
    SHA-256:D22EC72B66A89C95A82B9A1DB8261A45B487DE2A7E673F72454B55E2D63A21E2
    SHA-512:AC95AF609F17141A699059BCFC8E4395A28DF2132355153F4ED1C6EC2A62778B31B7388121A2C96B92B5837630375FEC5C11217C5F3D5AE3EFC9B34B65901993
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2014, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABILITY A
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java source, ASCII text
    Category:dropped
    Size (bytes):3271
    Entropy (8bit):4.876558754300395
    Encrypted:false
    SSDEEP:96:o6rYJdrYJQX3Z3r3dVe/oQmWIkM7sVkT02Mv6yn0IiYS//B:o6rsdrsQXJ3r37e/ckOsSQ2Mvzn0Px/p
    MD5:2F70972B8E4A1B0326151C81679A66C6
    SHA1:DDA3D2A51AC0A688E8ACB8BD70952FACE43C485A
    SHA-256:A7678717DCB353FAAEF21C6143B0B7BA44E0978852A6D0F7F5894513CAD0DBEA
    SHA-512:C93DE0AA6DCEC0AD5334307DC344ACEE0913AAECE7712090463C4F6291470197BFEF553EAF98FE5BC8C2F899581A3D228B410E96C2E8FEF45A48D9FDEF1F1621
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2014, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABILITY A
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java source, ASCII text
    Category:dropped
    Size (bytes):5092
    Entropy (8bit):4.737904096174729
    Encrypted:false
    SSDEEP:96:o6rYJdrYJQX3Z3r3dVegn3ZHX39WIkM7sVjbkfrVSakrg1R0N2Wj2r5v721B/SvU:o6rsdrsQXJ3r37ein9kOs2fr6myN2WjT
    MD5:EED59EE1CA8C19998D72771947A40ECC
    SHA1:038CEA5FA53D6E50B774B044F54098A0336B3730
    SHA-256:D22EC72B66A89C95A82B9A1DB8261A45B487DE2A7E673F72454B55E2D63A21E2
    SHA-512:AC95AF609F17141A699059BCFC8E4395A28DF2132355153F4ED1C6EC2A62778B31B7388121A2C96B92B5837630375FEC5C11217C5F3D5AE3EFC9B34B65901993
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2014, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABILITY A
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java source, ASCII text
    Category:dropped
    Size (bytes):5045
    Entropy (8bit):4.726377967178703
    Encrypted:false
    SSDEEP:96:o6rYJdrYJQX3Z3r3dVem3+MKRCazUMiQLk7kYecK0jWgqjBwSUN:o6rsdrsQXJ3r37etMKRCazUMiQLk7kYn
    MD5:596C55022CF5FF3B16AB1A60119F3FEE
    SHA1:CB646847332BD63DE1A387EA3DE3936ADB57775D
    SHA-256:9F46D9D3C6059EC317585D6FF8F6B4B6551171682D8626059DA7B74602058334
    SHA-512:589EF6C713F55A62A4C02C1EA57A44319F4745910DBC0B56093D54AAB2F618A5043E6F80ADF7A4279983C2E534CC7478C803B6EB1FBB44B22455E68C996A4121
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2014, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABILITY A
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java source, ASCII text
    Category:dropped
    Size (bytes):4735
    Entropy (8bit):4.700517105751413
    Encrypted:false
    SSDEEP:96:o6rYJdrYJQX3Z3r3dVeZFtFER3ljNfFk0Nm2+bNi2Feq4EXMf0tuST:o6rsdrsQXJ3r37enEF7Ksm2+xi2Feq4k
    MD5:4AB76DB5EBB3232D086BE4D4C46F3489
    SHA1:E146246D6C227CC2F1F205FC91CFB424BE6B3F06
    SHA-256:11F10E611A9A782C2D33EBAF725550D126662301E26932D41441BFF658625343
    SHA-512:4D213CE2EDBCA3F7572A17374CF65F84473370DB321B87908A26F068F4AD7667141C2721E4E9B494369EF8134F59C17BC1B98B67E27DD6799BBC44A797BD01AD
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2014, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABILITY A
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java source, ASCII text
    Category:dropped
    Size (bytes):4057
    Entropy (8bit):4.81133558476052
    Encrypted:false
    SSDEEP:96:o6rYJdrYJQX3Z3r3dVeHMLt6QBMXKjqSCtVjxcR9pd8v7rf:o6rsdrsQXJ3r37e8t6QBMajqSCtV9cNm
    MD5:A90D1EDC2D8CCE7AE1B5E9A1AF9421DD
    SHA1:87C7E19F375C6B2A48AC48FF9574D7A568156995
    SHA-256:0B45CFC8DBB7EF8CA255D1E10A385845784F01326FA95F769E060F9D526CF54D
    SHA-512:E079546FAD7A7A00BCBD09629A19726D636C4E1476782D994AD56A0DC0A01E77E198E3503A5ECCC72457766B1F2DDE9E5E7F47233F8B0F2F60CC1049FDA604EC
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2014, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABILITY A
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java source, ASCII text
    Category:dropped
    Size (bytes):4342
    Entropy (8bit):4.6719805551162565
    Encrypted:false
    SSDEEP:96:o6rYJdrYJQX3Z3r3dVeMIKlB6ZVVjvOvY3rHyGOCyOHywisVSteTfL:o6rsdrsQXJ3r37eMxB6ZVV1S74SwiV0j
    MD5:2027E0017B703BDA68788C9B00C5B2B5
    SHA1:0EB6F162575CEF41C41AC5DCABC909D370D1838F
    SHA-256:6FF9730D8445E99FCF7367670E10796872BEFB6983F323DB6124AABBB5476FB9
    SHA-512:7D83A426849198561EC49CE50D54D889CD148D644E1F33C5548C5EE4ED492A9BBE29DBF382505ACB245B9843B0F9B1450F6815375ECEBECFAB492DCEB26B0FA8
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2014, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABILITY A
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java source, ASCII text
    Category:dropped
    Size (bytes):3271
    Entropy (8bit):4.876558754300395
    Encrypted:false
    SSDEEP:96:o6rYJdrYJQX3Z3r3dVe/oQmWIkM7sVkT02Mv6yn0IiYS//B:o6rsdrsQXJ3r37e/ckOsSQ2Mvzn0Px/p
    MD5:2F70972B8E4A1B0326151C81679A66C6
    SHA1:DDA3D2A51AC0A688E8ACB8BD70952FACE43C485A
    SHA-256:A7678717DCB353FAAEF21C6143B0B7BA44E0978852A6D0F7F5894513CAD0DBEA
    SHA-512:C93DE0AA6DCEC0AD5334307DC344ACEE0913AAECE7712090463C4F6291470197BFEF553EAF98FE5BC8C2F899581A3D228B410E96C2E8FEF45A48D9FDEF1F1621
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2014, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABILITY A
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):2217
    Entropy (8bit):5.123062675010409
    Encrypted:false
    SSDEEP:48:ceOorYJTrYJEfDWQvs432sD32scMEtu33tYTHDZKGRc:YorYJTrYJEfiQX3f3jp2G
    MD5:41F14DD4782C2214A9CBD6AA08D48FA7
    SHA1:F1C645C51C8A0D9887A2B07A624E2CB0CBC57AAC
    SHA-256:8EBA744018E2D6B5EA43D8396BC8D412415E4824966DCF99ECA651BC5F67FC66
    SHA-512:A8295E384AB5979409D8B1503D391EC2926F2AD0CDC9AD1D0C33CE951771D03776BFA6D6C5C7AA638CC1C7478BCF28525E9508CF09BC3BEF5E824EFB31AAD744
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?>.. . Copyright (c) 2006, Oracle and/or its affiliates. All rights reserved... Redistribution and use in source and binary forms, with or without. modification, are permitted provided that the following conditions. are met:.. - Redistributions of source code must retain the above copyright. notice, this list of conditions and the following disclaimer... - Redistributions in binary form must reproduce the above copyright. notice, this list of conditions and the following disclaimer in the. documentation and/or other materials provided with the distribution... - Neither the name of Oracle nor the names of its. contributors may be used to endorse or promote products derived. from this software without specific prior written permission... THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. THE IMPLIED WARRANTIES OF MERCHANTABILITY
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):2217
    Entropy (8bit):5.123062675010409
    Encrypted:false
    SSDEEP:48:ceOorYJTrYJEfDWQvs432sD32scMEtu33tYTHDZKGRc:YorYJTrYJEfiQX3f3jp2G
    MD5:41F14DD4782C2214A9CBD6AA08D48FA7
    SHA1:F1C645C51C8A0D9887A2B07A624E2CB0CBC57AAC
    SHA-256:8EBA744018E2D6B5EA43D8396BC8D412415E4824966DCF99ECA651BC5F67FC66
    SHA-512:A8295E384AB5979409D8B1503D391EC2926F2AD0CDC9AD1D0C33CE951771D03776BFA6D6C5C7AA638CC1C7478BCF28525E9508CF09BC3BEF5E824EFB31AAD744
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?>.. . Copyright (c) 2006, Oracle and/or its affiliates. All rights reserved... Redistribution and use in source and binary forms, with or without. modification, are permitted provided that the following conditions. are met:.. - Redistributions of source code must retain the above copyright. notice, this list of conditions and the following disclaimer... - Redistributions in binary form must reproduce the above copyright. notice, this list of conditions and the following disclaimer in the. documentation and/or other materials provided with the distribution... - Neither the name of Oracle nor the names of its. contributors may be used to endorse or promote products derived. from this software without specific prior written permission... THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. THE IMPLIED WARRANTIES OF MERCHANTABILITY
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java source, ASCII text
    Category:dropped
    Size (bytes):7061
    Entropy (8bit):4.779071879042719
    Encrypted:false
    SSDEEP:192:n6rsdrsQXJ3r37e6E36JAJk/8EhA3CNQEbfqhH4/HWk38yi7ulqfTwCyTEtLjym:6rsdrsU5D7u3xJ9EWlnHeWvYDsZ
    MD5:2E70CF9DEC247F7A5D701C47580B428F
    SHA1:5CC948D91BE0A57A41C4989B2B9C5B4C7C24DAAB
    SHA-256:FC71171EECEA787C38E5126B7D4E335CD118621DBD3927180C9A111808CC04E9
    SHA-512:5FEAE3D9E86A31788961BA8D36A09655220EE9BAB16E01F64E240754EF18366EC5AAEE5C041C12CCA86182E2309209DF3F1E1E93193670710ACD797392D77DC9
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2011 Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABILITY AN
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:C++ source, ASCII text
    Category:dropped
    Size (bytes):6806
    Entropy (8bit):4.733635020781278
    Encrypted:false
    SSDEEP:192:n6rsdrsQXJ3r37e6E3LTGXFPbJ30rX2D0oxNNmR9TkyX1e7BEjyJstCde7L:6rsdrsU5D7u3LIFbJgW1uyswi
    MD5:5910C14076D3D12E08B0B2BCE52D9211
    SHA1:895E73788C2C579C8876D176CE4879B81C2D2BC5
    SHA-256:37A175B507638F836AF9FF2AD97E014DD95A2DD855386D88CC80E80312F85EE3
    SHA-512:79AA8405B217C9BBBCF6AF668766EE1536195FCBF6A9B8F382EC3692DA51F5E1A27A5F443726C435A728372D692DB1BC1FDF7C65D673A14C8BD649C64DAA92F3
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2011 Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABILITY AN
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:C++ source, ASCII text
    Category:dropped
    Size (bytes):3588
    Entropy (8bit):4.846618514883506
    Encrypted:false
    SSDEEP:96:n6rYJdrYJQX3Z3r3dVeE642LuE3GbH3U83rv8ylE3kSnaotVrDU6u:n6rsdrsQXJ3r37e6E3Kdv8ylYDnao3rs
    MD5:DE9160C8384E3EC177031EDE22CE6B3F
    SHA1:996D583E157A5D0705C772255845921A6354E393
    SHA-256:20BE34B3D254C05D3508D9F9232BE9013CC7AD91B61BAAB40B960E0F06BAD248
    SHA-512:0453365ECF3F07958865ACC4B0090599030906FF3B92EAB6065D2DD8BA10CD9140CC01EE9399ADF37814C4A62431E9C7F19F906984D410B0CBF7EEE5948D05B6
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2011 Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABILITY AN
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java source, ASCII text
    Category:dropped
    Size (bytes):2107
    Entropy (8bit):5.0897629719622834
    Encrypted:false
    SSDEEP:48:JEO6rYJdrYJQSiz3y432sf32s5EtAJ3tcHEElM64WtLY9EtRGbRBG:n6rYJdrYJQX3Z3r3dVeE642LuE3GbRc
    MD5:B2B51ACA897632DA09200DF435E35A60
    SHA1:F138708C2A64A5A9B4679CF6212F7CC17DDEFC8C
    SHA-256:61DCDA7468A77642CDCDEA93E216471ACC12E51F780B204CDD2DE7CAF3DDC4E6
    SHA-512:9232CC65AFEAC16D20E2232F679CE1E7734D13741EBF1E173BA044747EA7C2094F84AC48F6D838B34CEFD0D66721AD88588AB664CB8C46FDAB54514E799B4AAB
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2011 Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABILITY AN
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java source, ASCII text
    Category:dropped
    Size (bytes):3279
    Entropy (8bit):4.95147547165526
    Encrypted:false
    SSDEEP:96:n6rYJdrYJQX3Z3r3dVeE642LuE3GbNGN+KqvjqY3:n6rsdrsQXJ3r37e6E3KN+LqvjR3
    MD5:F52B6463D9ADFDBAFFB87C71C0361237
    SHA1:001390EF179A69082333E2858ADA1CC2DF7BEFEE
    SHA-256:13FF48E11633D90F5DF8D3646D96BF292EAE5F7A42F7B5156BA6C1165F92F12C
    SHA-512:44EDE92A94A124B36FF61818E54C4F235C798AD28020E3AA49A19B162B85AB77D48DFD6D7357D6FF92F20D9AB9BF0F0DBCC23EF45BBD7CFAD6D90D999FED03FF
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2011 Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABILITY AN
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java source, ASCII text
    Category:dropped
    Size (bytes):4570
    Entropy (8bit):4.8638828652668264
    Encrypted:false
    SSDEEP:96:n6rYJdrYJQX3Z3r3dVeE642LuE3Gb4VGYIbF6KyHedKAmzuBp1YL:n6rsdrsQXJ3r37e6E3Kj9QKy+0HzuBpO
    MD5:7ED029F2EE9B069C26FD9CAAE8DAE07B
    SHA1:F9643DCD2B7025ECFD506041E9C8864A9B2F1850
    SHA-256:3AE6954013857993E3D6A00210DCFE392E77ED45892458EAFB18261A7351DBA6
    SHA-512:1DC53755DC4F67FC1479E8806FF08679886327DF83806F89AF076E35511A57272F83FE486AFFA4D940D3D3CA802F897DC498A35F6EB98A8608556A857B757CF1
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2011 Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABILITY AN
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:ASCII text
    Category:dropped
    Size (bytes):2098
    Entropy (8bit):4.662617653040848
    Encrypted:false
    SSDEEP:48:QPBeMeNWPtQ0pDWg4QLu+7YEL5Da2Q+16UctMF:QPBeutQ0paouxELM3FXtMF
    MD5:88BF68DE4970695F1E2127EDEB8D2D12
    SHA1:474FBC2F926B02F556351B1E4FEDAB28099A3D21
    SHA-256:87C4B3E2A8F39B3CA42749E10002A6FC0DBF0CD1E83D1A8B78AF634F4ACF5399
    SHA-512:411AC25B4DFAD0731D8F8864CD2FE4103A48282BCA2258B2C658427BD36FD3D3C59364ED2072712048C7955FC259AB5CF7C295FB55A8C4C401F69A6863CB4361
    Malicious:false
    Reputation:low
    Preview:A Simple Chat Server Example..INTRODUCTION.============.This directory contains a very simple chat server, the server takes input from a.socket ("user") and sends it to all other connected sockets ("users") along with.the provided name the user was asked for when first connecting...The server was written to demonstrate the asynchronous I/O API in JDK 7. .The sample assumes the reader has some familiarity with the subject matter...SETUP.=====..The server must be built with version 7 (or later) of the JDK..The server is built with:.. % mkdir build. % javac -source 7 -target 7 -d build *.java..EXECUTION.=========.. % java -classpath build ChatServer [-port <port number>].. Usage: ChatServer [options]. options:. -port port port number. default: 5000..CLIENT EXECUTION.================..No client binary is included in the sample..Connections can be made using for example the telnet command or any program.that supports a raw TCP connection to
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:C++ source, ASCII text
    Category:dropped
    Size (bytes):3588
    Entropy (8bit):4.846618514883506
    Encrypted:false
    SSDEEP:96:n6rYJdrYJQX3Z3r3dVeE642LuE3GbH3U83rv8ylE3kSnaotVrDU6u:n6rsdrsQXJ3r37e6E3Kdv8ylYDnao3rs
    MD5:DE9160C8384E3EC177031EDE22CE6B3F
    SHA1:996D583E157A5D0705C772255845921A6354E393
    SHA-256:20BE34B3D254C05D3508D9F9232BE9013CC7AD91B61BAAB40B960E0F06BAD248
    SHA-512:0453365ECF3F07958865ACC4B0090599030906FF3B92EAB6065D2DD8BA10CD9140CC01EE9399ADF37814C4A62431E9C7F19F906984D410B0CBF7EEE5948D05B6
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2011 Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABILITY AN
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:C++ source, ASCII text
    Category:dropped
    Size (bytes):6806
    Entropy (8bit):4.733635020781278
    Encrypted:false
    SSDEEP:192:n6rsdrsQXJ3r37e6E3LTGXFPbJ30rX2D0oxNNmR9TkyX1e7BEjyJstCde7L:6rsdrsU5D7u3LIFbJgW1uyswi
    MD5:5910C14076D3D12E08B0B2BCE52D9211
    SHA1:895E73788C2C579C8876D176CE4879B81C2D2BC5
    SHA-256:37A175B507638F836AF9FF2AD97E014DD95A2DD855386D88CC80E80312F85EE3
    SHA-512:79AA8405B217C9BBBCF6AF668766EE1536195FCBF6A9B8F382EC3692DA51F5E1A27A5F443726C435A728372D692DB1BC1FDF7C65D673A14C8BD649C64DAA92F3
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2011 Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABILITY AN
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java source, ASCII text
    Category:dropped
    Size (bytes):4570
    Entropy (8bit):4.8638828652668264
    Encrypted:false
    SSDEEP:96:n6rYJdrYJQX3Z3r3dVeE642LuE3Gb4VGYIbF6KyHedKAmzuBp1YL:n6rsdrsQXJ3r37e6E3Kj9QKy+0HzuBpO
    MD5:7ED029F2EE9B069C26FD9CAAE8DAE07B
    SHA1:F9643DCD2B7025ECFD506041E9C8864A9B2F1850
    SHA-256:3AE6954013857993E3D6A00210DCFE392E77ED45892458EAFB18261A7351DBA6
    SHA-512:1DC53755DC4F67FC1479E8806FF08679886327DF83806F89AF076E35511A57272F83FE486AFFA4D940D3D3CA802F897DC498A35F6EB98A8608556A857B757CF1
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2011 Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABILITY AN
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:ASCII text
    Category:dropped
    Size (bytes):2098
    Entropy (8bit):4.662617653040848
    Encrypted:false
    SSDEEP:48:QPBeMeNWPtQ0pDWg4QLu+7YEL5Da2Q+16UctMF:QPBeutQ0paouxELM3FXtMF
    MD5:88BF68DE4970695F1E2127EDEB8D2D12
    SHA1:474FBC2F926B02F556351B1E4FEDAB28099A3D21
    SHA-256:87C4B3E2A8F39B3CA42749E10002A6FC0DBF0CD1E83D1A8B78AF634F4ACF5399
    SHA-512:411AC25B4DFAD0731D8F8864CD2FE4103A48282BCA2258B2C658427BD36FD3D3C59364ED2072712048C7955FC259AB5CF7C295FB55A8C4C401F69A6863CB4361
    Malicious:false
    Reputation:low
    Preview:A Simple Chat Server Example..INTRODUCTION.============.This directory contains a very simple chat server, the server takes input from a.socket ("user") and sends it to all other connected sockets ("users") along with.the provided name the user was asked for when first connecting...The server was written to demonstrate the asynchronous I/O API in JDK 7. .The sample assumes the reader has some familiarity with the subject matter...SETUP.=====..The server must be built with version 7 (or later) of the JDK..The server is built with:.. % mkdir build. % javac -source 7 -target 7 -d build *.java..EXECUTION.=========.. % java -classpath build ChatServer [-port <port number>].. Usage: ChatServer [options]. options:. -port port port number. default: 5000..CLIENT EXECUTION.================..No client binary is included in the sample..Connections can be made using for example the telnet command or any program.that supports a raw TCP connection to
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java source, ASCII text
    Category:dropped
    Size (bytes):2107
    Entropy (8bit):5.0897629719622834
    Encrypted:false
    SSDEEP:48:JEO6rYJdrYJQSiz3y432sf32s5EtAJ3tcHEElM64WtLY9EtRGbRBG:n6rYJdrYJQX3Z3r3dVeE642LuE3GbRc
    MD5:B2B51ACA897632DA09200DF435E35A60
    SHA1:F138708C2A64A5A9B4679CF6212F7CC17DDEFC8C
    SHA-256:61DCDA7468A77642CDCDEA93E216471ACC12E51F780B204CDD2DE7CAF3DDC4E6
    SHA-512:9232CC65AFEAC16D20E2232F679CE1E7734D13741EBF1E173BA044747EA7C2094F84AC48F6D838B34CEFD0D66721AD88588AB664CB8C46FDAB54514E799B4AAB
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2011 Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABILITY AN
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java source, ASCII text
    Category:dropped
    Size (bytes):7061
    Entropy (8bit):4.779071879042719
    Encrypted:false
    SSDEEP:192:n6rsdrsQXJ3r37e6E36JAJk/8EhA3CNQEbfqhH4/HWk38yi7ulqfTwCyTEtLjym:6rsdrsU5D7u3xJ9EWlnHeWvYDsZ
    MD5:2E70CF9DEC247F7A5D701C47580B428F
    SHA1:5CC948D91BE0A57A41C4989B2B9C5B4C7C24DAAB
    SHA-256:FC71171EECEA787C38E5126B7D4E335CD118621DBD3927180C9A111808CC04E9
    SHA-512:5FEAE3D9E86A31788961BA8D36A09655220EE9BAB16E01F64E240754EF18366EC5AAEE5C041C12CCA86182E2309209DF3F1E1E93193670710ACD797392D77DC9
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2011 Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABILITY AN
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java source, ASCII text
    Category:dropped
    Size (bytes):3279
    Entropy (8bit):4.95147547165526
    Encrypted:false
    SSDEEP:96:n6rYJdrYJQX3Z3r3dVeE642LuE3GbNGN+KqvjqY3:n6rsdrsQXJ3r37e6E3KN+LqvjR3
    MD5:F52B6463D9ADFDBAFFB87C71C0361237
    SHA1:001390EF179A69082333E2858ADA1CC2DF7BEFEE
    SHA-256:13FF48E11633D90F5DF8D3646D96BF292EAE5F7A42F7B5156BA6C1165F92F12C
    SHA-512:44EDE92A94A124B36FF61818E54C4F235C798AD28020E3AA49A19B162B85AB77D48DFD6D7357D6FF92F20D9AB9BF0F0DBCC23EF45BBD7CFAD6D90D999FED03FF
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2011 Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABILITY AN
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java source, ASCII text
    Category:dropped
    Size (bytes):10821
    Entropy (8bit):4.586659320652855
    Encrypted:false
    SSDEEP:192:76rsdrsQXJ3r37e6E34hmoQy5PyURh3dFBiBcMTiaDmKj/ClfCye8aiwozyL:ursdrsU5D7u3s/PhOmohd
    MD5:65462797E3C7926639618E66E91EF303
    SHA1:F84F6EA0D2D069F8181A80C2F6AB41E2023A7198
    SHA-256:A983C4FBCDF7F90CBDD53346368B8F9D73FF0C1968F1C080DD986DFDEB17A3D0
    SHA-512:D34845C2A40D046FA1EDA0B9057068D4904B3956082768CCD04B8564758B3782554E36ECBD54FD4579C8DA54D5533F231F19C7D6B18DAADBE152151DDBF0A6CB
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2008, 2011, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABI
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:HTML document, ASCII text
    Category:dropped
    Size (bytes):12883
    Entropy (8bit):4.523839477935337
    Encrypted:false
    SSDEEP:192:76rsdrsQXJ3r37e6E34hd68ngrXjslkyqHAyztFTqzizOzCYzzznzC3lzrRzfTzD:ursdrsU5D7u3Cg4wAYF2LRrbroFPR/t
    MD5:5B9EE6AA716F440F85C9A04BE63848EF
    SHA1:2613F9AFADA1C889352E4EB56D0E6B52DDDA24C5
    SHA-256:202AEAD05B606004AEB5036D1CE53C4F671707F352CF22E9E0C51937F78E0A80
    SHA-512:E88830FC1272F029EFC9959DB3FC602F7EE93CF1137CFAD3E10D8373A52A9FA2422938DEF99E53A93B154A1906888753311BC38AF28BA672913F6FAC1AE49852
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2008, 2011, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABI
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java source, ASCII text
    Category:dropped
    Size (bytes):8206
    Entropy (8bit):4.680884831053104
    Encrypted:false
    SSDEEP:192:76rsdrsQXJ3r37e6E34Yh68b76TOkGOy5ljZKxC+7xCAUaNS50CvF877/yL:ursdrsU5D7u3n5k2KxP1NS5Vaa
    MD5:D1F035356AE363EEF2EFE77DFE7EF683
    SHA1:CABD0A683AFE866D7DD2EF82CF3C5680D0805D0E
    SHA-256:706E757CC9F0CBA101F360EC159EB42A38C01AFDA62AE97C816CA76A6A986BA9
    SHA-512:D5D70C1837295EE61FA9B5EE21270D8CE929BC473ECF576E9B7D71DE59FA9B53C5E174F3C022CCD5600D7DD6E35F62FAAFF8D47BB78AC9E78F603C1560729E3A
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2008, 2011, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABI
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java source, ASCII text
    Category:dropped
    Size (bytes):3184
    Entropy (8bit):5.044721240715907
    Encrypted:false
    SSDEEP:96:g06rYJdrYJQX3Z3r3dVeE642LuE3GXharOdnS8xxi8yL:76rsdrsQXJ3r37e6E34harOdnS8ji8yL
    MD5:FBCF013B0CA5F9549B35959E15289C02
    SHA1:50EEF0EB38B42AC934F887E4390430F32A28FD7B
    SHA-256:9521625B14A13FD4B7D635321B9A3262C64FEB4DBF1F296C5D3131BF254F8258
    SHA-512:12C93DB4BA3A1F4E05463AADE47587E7F53B87B970B92271F7874E83DAE3A37DFF9D5EB62AEF3B7CB7ADCFFB662F7B7DCFB9F73A5AD7BDB0AE520199E6D7DCB5
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2008, 2011, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABI
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java source, ASCII text
    Category:dropped
    Size (bytes):2619
    Entropy (8bit):5.009803690933648
    Encrypted:false
    SSDEEP:48:gcEO6rYJdrYJQSiz3y432sf32s5EtAJ3tcHEElM64WtLY9EtRGXJhbS8CdNJTFL:g06rYJdrYJQX3Z3r3dVeE642LuE3GXvm
    MD5:1FEB16B16C8BB323E1893755E54D1F61
    SHA1:DB9B11E356CEF3216DF3C98E8BC75206BFDAA395
    SHA-256:EF6C141D5054ADF74851C7B3C674D211F4DC2612A8A4886946A07ABE2E9B8F93
    SHA-512:648FEFFAE26D900F00F6F494297E62F4AB710D45BDA5185F76874448FA56B85015019FE1B8202090A7BE023A0A16BAB6E5C06EC9A7B55D998969BC049483657B
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2008, 2011, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABI
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java source, ASCII text
    Category:dropped
    Size (bytes):6295
    Entropy (8bit):4.681054392823467
    Encrypted:false
    SSDEEP:192:76rsdrsQXJ3r37e6E340ohU9E1yJHLXF1wJTv2KxkyhX6RBLGUj4P9wI5lS4jyDO:ursdrsU5D7u3j9kwTAvV6KRVaO
    MD5:3EF0F762529BFF125BBFD3AFB57A7A3C
    SHA1:1989E0F445DB8666FFCECD510D85B2303813AE69
    SHA-256:33CE0EC4D53CD7E87931E19A7B4A42B72054EEC7F68D53A00FC0C22FDFD2C084
    SHA-512:85D27480283855DB1D5C46B03F184C783F89F80538250F56CDD5AC4390FC1F7A8D0D49FEEBF957ECB8F6DBF9D5966291026D11E376F5825B874A755EAC7EDBC9
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2008, 2011, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABI
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java source, ASCII text
    Category:dropped
    Size (bytes):4612
    Entropy (8bit):4.9557913247400815
    Encrypted:false
    SSDEEP:96:g06rYJdrYJQX3Z3r3dVeE642LuE3GbPhasVGQtRva+aaGUKQ0RKKPKur:76rsdrsQXJ3r37e6E3KPhasVGGRva+ZM
    MD5:F4FEA5CEAC6DADBEBEE486609F8F70A8
    SHA1:7BCF716362F237AF7A7C1F0E4EE6DE480B54500B
    SHA-256:240A766EC961D2F4EB4EFA2F81A86563DD92019014D36C564B53AA7F3E4BF071
    SHA-512:1254BE6B13334A0DA69295B5F614873C079E52D98232C797CFF4CEE33B16D72CCA22846B82AB75D4275BD92202928237D70BE29B20E9C1EAEFF46C62B2526351
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2008, 2011, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABI
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java source, ASCII text
    Category:dropped
    Size (bytes):6295
    Entropy (8bit):4.681054392823467
    Encrypted:false
    SSDEEP:192:76rsdrsQXJ3r37e6E340ohU9E1yJHLXF1wJTv2KxkyhX6RBLGUj4P9wI5lS4jyDO:ursdrsU5D7u3j9kwTAvV6KRVaO
    MD5:3EF0F762529BFF125BBFD3AFB57A7A3C
    SHA1:1989E0F445DB8666FFCECD510D85B2303813AE69
    SHA-256:33CE0EC4D53CD7E87931E19A7B4A42B72054EEC7F68D53A00FC0C22FDFD2C084
    SHA-512:85D27480283855DB1D5C46B03F184C783F89F80538250F56CDD5AC4390FC1F7A8D0D49FEEBF957ECB8F6DBF9D5966291026D11E376F5825B874A755EAC7EDBC9
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2008, 2011, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABI
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:HTML document, ASCII text
    Category:dropped
    Size (bytes):12883
    Entropy (8bit):4.523839477935337
    Encrypted:false
    SSDEEP:192:76rsdrsQXJ3r37e6E34hd68ngrXjslkyqHAyztFTqzizOzCYzzznzC3lzrRzfTzD:ursdrsU5D7u3Cg4wAYF2LRrbroFPR/t
    MD5:5B9EE6AA716F440F85C9A04BE63848EF
    SHA1:2613F9AFADA1C889352E4EB56D0E6B52DDDA24C5
    SHA-256:202AEAD05B606004AEB5036D1CE53C4F671707F352CF22E9E0C51937F78E0A80
    SHA-512:E88830FC1272F029EFC9959DB3FC602F7EE93CF1137CFAD3E10D8373A52A9FA2422938DEF99E53A93B154A1906888753311BC38AF28BA672913F6FAC1AE49852
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2008, 2011, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABI
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java source, ASCII text
    Category:dropped
    Size (bytes):2619
    Entropy (8bit):5.009803690933648
    Encrypted:false
    SSDEEP:48:gcEO6rYJdrYJQSiz3y432sf32s5EtAJ3tcHEElM64WtLY9EtRGXJhbS8CdNJTFL:g06rYJdrYJQX3Z3r3dVeE642LuE3GXvm
    MD5:1FEB16B16C8BB323E1893755E54D1F61
    SHA1:DB9B11E356CEF3216DF3C98E8BC75206BFDAA395
    SHA-256:EF6C141D5054ADF74851C7B3C674D211F4DC2612A8A4886946A07ABE2E9B8F93
    SHA-512:648FEFFAE26D900F00F6F494297E62F4AB710D45BDA5185F76874448FA56B85015019FE1B8202090A7BE023A0A16BAB6E5C06EC9A7B55D998969BC049483657B
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2008, 2011, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABI
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java source, ASCII text
    Category:dropped
    Size (bytes):10821
    Entropy (8bit):4.586659320652855
    Encrypted:false
    SSDEEP:192:76rsdrsQXJ3r37e6E34hmoQy5PyURh3dFBiBcMTiaDmKj/ClfCye8aiwozyL:ursdrsU5D7u3s/PhOmohd
    MD5:65462797E3C7926639618E66E91EF303
    SHA1:F84F6EA0D2D069F8181A80C2F6AB41E2023A7198
    SHA-256:A983C4FBCDF7F90CBDD53346368B8F9D73FF0C1968F1C080DD986DFDEB17A3D0
    SHA-512:D34845C2A40D046FA1EDA0B9057068D4904B3956082768CCD04B8564758B3782554E36ECBD54FD4579C8DA54D5533F231F19C7D6B18DAADBE152151DDBF0A6CB
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2008, 2011, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABI
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java source, ASCII text
    Category:dropped
    Size (bytes):3184
    Entropy (8bit):5.044721240715907
    Encrypted:false
    SSDEEP:96:g06rYJdrYJQX3Z3r3dVeE642LuE3GXharOdnS8xxi8yL:76rsdrsQXJ3r37e6E34harOdnS8ji8yL
    MD5:FBCF013B0CA5F9549B35959E15289C02
    SHA1:50EEF0EB38B42AC934F887E4390430F32A28FD7B
    SHA-256:9521625B14A13FD4B7D635321B9A3262C64FEB4DBF1F296C5D3131BF254F8258
    SHA-512:12C93DB4BA3A1F4E05463AADE47587E7F53B87B970B92271F7874E83DAE3A37DFF9D5EB62AEF3B7CB7ADCFFB662F7B7DCFB9F73A5AD7BDB0AE520199E6D7DCB5
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2008, 2011, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABI
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java source, ASCII text
    Category:dropped
    Size (bytes):8206
    Entropy (8bit):4.680884831053104
    Encrypted:false
    SSDEEP:192:76rsdrsQXJ3r37e6E34Yh68b76TOkGOy5ljZKxC+7xCAUaNS50CvF877/yL:ursdrsU5D7u3n5k2KxP1NS5Vaa
    MD5:D1F035356AE363EEF2EFE77DFE7EF683
    SHA1:CABD0A683AFE866D7DD2EF82CF3C5680D0805D0E
    SHA-256:706E757CC9F0CBA101F360EC159EB42A38C01AFDA62AE97C816CA76A6A986BA9
    SHA-512:D5D70C1837295EE61FA9B5EE21270D8CE929BC473ECF576E9B7D71DE59FA9B53C5E174F3C022CCD5600D7DD6E35F62FAAFF8D47BB78AC9E78F603C1560729E3A
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2008, 2011, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABI
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java source, ASCII text
    Category:dropped
    Size (bytes):4612
    Entropy (8bit):4.9557913247400815
    Encrypted:false
    SSDEEP:96:g06rYJdrYJQX3Z3r3dVeE642LuE3GbPhasVGQtRva+aaGUKQ0RKKPKur:76rsdrsQXJ3r37e6E3KPhasVGGRva+ZM
    MD5:F4FEA5CEAC6DADBEBEE486609F8F70A8
    SHA1:7BCF716362F237AF7A7C1F0E4EE6DE480B54500B
    SHA-256:240A766EC961D2F4EB4EFA2F81A86563DD92019014D36C564B53AA7F3E4BF071
    SHA-512:1254BE6B13334A0DA69295B5F614873C079E52D98232C797CFF4CEE33B16D72CCA22846B82AB75D4275BD92202928237D70BE29B20E9C1EAEFF46C62B2526351
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2008, 2011, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABI
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:C++ source, ASCII text
    Category:dropped
    Size (bytes):4945
    Entropy (8bit):4.873252394951454
    Encrypted:false
    SSDEEP:96:n06rYJdrYJQX3Z3r3dVeE642LuE3GDqblmcbZWuUbSiUq/h/EblJYJte6e2md3Xu:06rsdrsQXJ3r37e6E36qb4cbEbSiUqU0
    MD5:662C966C3A2B64037977E95C5192A5F2
    SHA1:671B97118B354650B04B6F4B7439A98741C59335
    SHA-256:DF2A1B781DD7610C9BB7B26DCCA5B46D74F552E4481BCE8CD695EDD74F59E6DC
    SHA-512:0908B6DB506968C4067E352C72615FEAA0396B5003A4C72562E503014CFE27BEC8EDBA5A651F1DD1F888A89FCFB136D1B364DB17F28E1BC9660CC0FB1367BD40
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2007, 2011, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABI
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java source, ASCII text
    Category:dropped
    Size (bytes):5802
    Entropy (8bit):4.78494573099394
    Encrypted:false
    SSDEEP:96:n06rYJdrYJQX3Z3r3dVeE642LuE3GBvroMKxY48XatE0dLkckOokMT7LyZvgiJnS:06rsdrsQXJ3r37e6E3ivroMKxYrXatEv
    MD5:5DA5897BA294CEE9C1B79F82A5D23E5E
    SHA1:567807468ACFF1DAC818E8C12F24254051480A9D
    SHA-256:83EACD99E65BD99E2DC738633DF70A195B1B315A55FC9CE352DA4D6EAFBCC06B
    SHA-512:E628E157E3969EAC4EA42CF87955A3992670853A5A6C329BB220C91AD9D8FFFFD13B3DB3017224924255B39D2798AB59CBCD6C0EA7DA5B627C095B65F0ED6A39
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2007, 2011, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABI
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java source, ASCII text
    Category:dropped
    Size (bytes):3107
    Entropy (8bit):5.096423506756916
    Encrypted:false
    SSDEEP:96:n06rYJdrYJQX3Z3r3dVeE642LuE3GBcyY+MLRLLwvn:06rsdrsQXJ3r37e6E3icyrMLevn
    MD5:1B57226350986685E2E19C506B0C97A9
    SHA1:1036750066C7FC280B1AC2F19B49E62DA2F3444C
    SHA-256:8BA0153D933BA6BF95209071FA182844098D3BFBB664DDDF7D93F631DF1E2A47
    SHA-512:606E040E5088E34C01ADEA91F16E93EDE47C182A7EE21F84B704AB4FBBFF4601BDA15DED022B8F5BBD3C95659BA47BA2C2528A9771D3AB21F3D8A09FCCEBDC01
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2007, 2011, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABI
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:C++ source, ASCII text
    Category:dropped
    Size (bytes):4945
    Entropy (8bit):4.873252394951454
    Encrypted:false
    SSDEEP:96:n06rYJdrYJQX3Z3r3dVeE642LuE3GDqblmcbZWuUbSiUq/h/EblJYJte6e2md3Xu:06rsdrsQXJ3r37e6E36qb4cbEbSiUqU0
    MD5:662C966C3A2B64037977E95C5192A5F2
    SHA1:671B97118B354650B04B6F4B7439A98741C59335
    SHA-256:DF2A1B781DD7610C9BB7B26DCCA5B46D74F552E4481BCE8CD695EDD74F59E6DC
    SHA-512:0908B6DB506968C4067E352C72615FEAA0396B5003A4C72562E503014CFE27BEC8EDBA5A651F1DD1F888A89FCFB136D1B364DB17F28E1BC9660CC0FB1367BD40
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2007, 2011, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABI
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java source, ASCII text
    Category:dropped
    Size (bytes):3107
    Entropy (8bit):5.096423506756916
    Encrypted:false
    SSDEEP:96:n06rYJdrYJQX3Z3r3dVeE642LuE3GBcyY+MLRLLwvn:06rsdrsQXJ3r37e6E3icyrMLevn
    MD5:1B57226350986685E2E19C506B0C97A9
    SHA1:1036750066C7FC280B1AC2F19B49E62DA2F3444C
    SHA-256:8BA0153D933BA6BF95209071FA182844098D3BFBB664DDDF7D93F631DF1E2A47
    SHA-512:606E040E5088E34C01ADEA91F16E93EDE47C182A7EE21F84B704AB4FBBFF4601BDA15DED022B8F5BBD3C95659BA47BA2C2528A9771D3AB21F3D8A09FCCEBDC01
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2007, 2011, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABI
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java source, ASCII text
    Category:dropped
    Size (bytes):5802
    Entropy (8bit):4.78494573099394
    Encrypted:false
    SSDEEP:96:n06rYJdrYJQX3Z3r3dVeE642LuE3GBvroMKxY48XatE0dLkckOokMT7LyZvgiJnS:06rsdrsQXJ3r37e6E3ivroMKxYrXatEv
    MD5:5DA5897BA294CEE9C1B79F82A5D23E5E
    SHA1:567807468ACFF1DAC818E8C12F24254051480A9D
    SHA-256:83EACD99E65BD99E2DC738633DF70A195B1B315A55FC9CE352DA4D6EAFBCC06B
    SHA-512:E628E157E3969EAC4EA42CF87955A3992670853A5A6C329BB220C91AD9D8FFFFD13B3DB3017224924255B39D2798AB59CBCD6C0EA7DA5B627C095B65F0ED6A39
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2007, 2011, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABI
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java source, ASCII text
    Category:dropped
    Size (bytes):3101
    Entropy (8bit):5.01768552178975
    Encrypted:false
    SSDEEP:96:806rYJdrYJQX3Z3r3dVeE642LuE3GBRdofXkHphoh4cJgjIb:X6rsdrsQXJ3r37e6E3iRdofUK4cKjIb
    MD5:B6B28491DEEC8B717894361EA5D07227
    SHA1:AD8097ED5017CD3E6DDA277E28BEEB8F7A0D1663
    SHA-256:50D28D7F5083FADB64F79250C47FA6E449D6C97980933ED3502BF0E591A063F9
    SHA-512:D5C06FE4365C9965FD0F9BED149DFD0FBCD69BD0DF64E7729CF5E10A3FBCA2AD3AA8B28C841BF7C6D334437E4F25F11676E1E1788462E61C9E00E752B6F13121
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2004, 2011, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABI
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java source, ASCII text
    Category:dropped
    Size (bytes):3143
    Entropy (8bit):4.9380058095402015
    Encrypted:false
    SSDEEP:96:806rYJdrYJQX3Z3r3dVeE642LuE3GBRXoQTML3Pe4cjjIlyL:X6rsdrsQXJ3r37e6E3iRXoQTMLG4cjjj
    MD5:6EEC81F17D1698B46D79429135419273
    SHA1:B53A34257CC521734B24947FFF9F6658FE777A47
    SHA-256:A3284EEA056D581D7C1D2A3084ACCDFE86B109C1075B50A1F2B1C65428A72D79
    SHA-512:0F46E2693CCB1875FC8042E0C0BA7E09FB05659411762EEA4B551725926FA2D3E61AA0849768BA5B3F3696A0D08F6877DF3F624754CD105DD9D32260218F1E62
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2004, 2011, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABI
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java source, ASCII text
    Category:dropped
    Size (bytes):2717
    Entropy (8bit):5.01354227160186
    Encrypted:false
    SSDEEP:48:8cEO6rYJdrYJQSiz3y432sf32s5EtAJ3tcHEElM64WtLY9EtRGTH8cl65FnWuPXA:806rYJdrYJQX3Z3r3dVeE642LuE3GTHZ
    MD5:32F8ADEBCEC60CB1110466F99B48A1E3
    SHA1:EE826E8C136A5BA8EC0999F40958A435D0CC8FC4
    SHA-256:C56977E1BC85347BAC666BB3AE52F4CF46CD978B6E044F74BA76334852F99FDB
    SHA-512:2698B3B7D5D6E32FD6B27AEEE577DEB1E6BD36BB3BF32E43D6234F76DDD6BF3E38F7A5C22E6DDF143BDF59EEF93934544AFE4ADDAF9E03742078D5EAFE84B124
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2004, 2011, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABI
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java source, ASCII text
    Category:dropped
    Size (bytes):2814
    Entropy (8bit):4.998970334697864
    Encrypted:false
    SSDEEP:48:8cEO6rYJdrYJQSiz3y432sf32s5EtAJ3tcHEElM64WtLY9EtRGBigjAcl6xFnWu+:806rYJdrYJQX3Z3r3dVeE642LuE3GB37
    MD5:4131A06AFBB93E94F87521F739CB10CD
    SHA1:E17E98C96480413A918DCFC4C5AAB7C6881CCB78
    SHA-256:57DC130115D9F52A9B60B01ED5B532A668A78D8460E5803AE74CCB862EC8C081
    SHA-512:22B3D1EF872382601E2E97E0CA87EBC282D23203BFDC5D5F53933FE88A079F4447538F3DEB35C2B108660FC3572A2058B29B8EA102D9CA55CF1F4B7E47839011
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2004, 2011, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABI
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java source, ASCII text
    Category:dropped
    Size (bytes):2971
    Entropy (8bit):5.017318128651048
    Encrypted:false
    SSDEEP:48:8cEO6rYJdrYJQSiz3y432sf32s5EtAJ3tcHEElM64WtLY9EtRGB/5mzSBpcl6Z2l:806rYJdrYJQX3Z3r3dVeE642LuE3GBB0
    MD5:36A0C920D57FBED4B16E76099D63BDB4
    SHA1:E267E9FE18DB761DB9E80747E6D0FD93F4EAF6BF
    SHA-256:6C506D48B8391266E83A2F8E6CCA4E5845793AEF5AF1D9B47111B930786C986E
    SHA-512:28AA10331C79F1F982ECEA6862D18BBC1BC443D83120F01F1681E5C5DFB6942E1A00B08F9079D24E891814DD9C17DE6CE0F0CC9799F819065985B01BB1D45D34
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2004, 2011, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABI
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:C++ source, ASCII text
    Category:dropped
    Size (bytes):5975
    Entropy (8bit):4.816201739908655
    Encrypted:false
    SSDEEP:96:806rYJdrYJQX3Z3r3dVeE642LuE3GB1lrO4HfXBb0PcXYDA/F+I4Z4+UtXsV35oD:X6rsdrsQXJ3r37e6E3i1lyCPBAPcGA/r
    MD5:D125EB815BCAEB1C57AAFD34CC069105
    SHA1:2B022E6578058B0A590FE1EABEE4A584F0AB1383
    SHA-256:4BA27AA31A5EF1CC5D461DFA7107B8D58CC323C7CA028D2096C89CE60CD8F468
    SHA-512:76F592EA5BE2FAE5A8C669C882F1DCF6794E8D53567AF997124F6E5DD344040ED80CA26FBFEBF2ADD1F4BD6A8989FBD23E9D4A9276E76AA71F8F526CA4E7E937
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2004, 2011, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABI
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java source, ASCII text
    Category:dropped
    Size (bytes):20907
    Entropy (8bit):4.486158306476371
    Encrypted:false
    SSDEEP:384:qrsdrsU5D7u3mKa80+mS1owDiwfVoEzUdpze04pF45LJzc:qAPD7UY80+mS1oufVotpzqF45LJg
    MD5:08E12C59A8DFD8E3BE8A4193CD8FD4F0
    SHA1:9C205517A9474032D3B78EB02FEA7C66D00E5C62
    SHA-256:025FD9D1F487BC8B5F21D2684E19E2F464F5DA9E134ADB6924B2580FDA3C0B85
    SHA-512:598D63AD631413F08063E9FE34BD849B89C735E41194CE7D677B4581B457B2D329B0FE4DA15E39AA7DEC740E54C6D926A32AFC485C5661280E3EFFE82DD49BBE
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2004, 2011, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABI
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:ASCII text
    Category:dropped
    Size (bytes):2233
    Entropy (8bit):5.081294779946435
    Encrypted:false
    SSDEEP:48:8cEO6rYJdrYJQSiz3y432sf32s5EtAJ3tcHEElM64WtLY9EtRhIoz3oMK:806rYJdrYJQX3Z3r3dVeE642LuE3qobi
    MD5:BA487CB0174386228F7843CC8D3B53BD
    SHA1:65C01F6D2203A36A5969D858E38732618E4CB4C3
    SHA-256:B8828550DBE3359F216B61345C54016F4D298F8478E88E1EE47927165C7806E4
    SHA-512:643E6F928A74D9EB4C8251ECD6393DD7D48C3A1106CF2603C61EC7C4A4A9CD2FD7F8DE2856EA94F7C389BC6E812B8A617FD7CA482097D6AEF7F360CA3A460463
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2004, 2011, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABI
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java source, ASCII text
    Category:dropped
    Size (bytes):2280
    Entropy (8bit):5.093261350120955
    Encrypted:false
    SSDEEP:48:8cEO6rYJdrYJQSiz3y432sf32s5EtAJ3tcHEElM64WtLY9EtRGBI4z:806rYJdrYJQX3Z3r3dVeE642LuE3GBIY
    MD5:93C818045CBC472C0EDFB8F626217337
    SHA1:6C077B943AE4B32762CF096BB82E65D4BB948840
    SHA-256:4E84E9F4C7ECE024019730327FC75249EC8D06D7AD11235520CF6DA022053939
    SHA-512:C885FD3D43E2EE5D0B5DCAA8839B5664E47432FD295CB36D2907E5D77E282274BDE4055FF579E1839F9777D701B3358A09AA24636A7AB624D47AA2090A45D36E
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2004, 2011, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABI
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java source, ASCII text
    Category:dropped
    Size (bytes):3010
    Entropy (8bit):4.9913453623904855
    Encrypted:false
    SSDEEP:48:8cEO6rYJdrYJQSiz3y432sf32s5EtAJ3tcHEElM64WtLY9EtRGBRK2HCEUljryFp:806rYJdrYJQX3Z3r3dVeE642LuE3GBRj
    MD5:BF45212FD354ABA8C5CFF6B8BFBEE947
    SHA1:71B38165227264947C496AC411A4D56961631173
    SHA-256:E72E9FBB412FA03082A5DC97035520AA3CFD8387FECC6627B0D06F201495FA26
    SHA-512:F35C5AAE860C8766F3245D17BD25CBF579981960E1C3968BA5A646E32DB4E501DC1322994374EB21D6F5A8E9FAC1526D629911C3607818A461731CD22A6B21C4
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2004, 2011, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABI
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java source, ASCII text
    Category:dropped
    Size (bytes):3118
    Entropy (8bit):4.970042013258624
    Encrypted:false
    SSDEEP:96:806rYJdrYJQX3Z3r3dVeE642LuE3GBR5OO3EylHyu1/TiyxRJ2x:X6rsdrsQXJ3r37e6E3iR5OO3EuHyu1/m
    MD5:1CFE9D37418D42355AB76D53019F51E3
    SHA1:BBD3897625548E20D3B2CCC0A9D6D3B73D1CDB15
    SHA-256:5315DCD013D8CA6DE174CE3EF655A872B7942F17F55D1A8659F9832EBFBFE5E5
    SHA-512:C1EFFE51E96026EEC44CF32A2FE49F43C64768FEBE8AD37578A686A744D575767B6E0059FB807C12B219623E635DB5D8E4035CEF771970D58ED6C125E5D46C56
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2004, 2011, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABI
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java source, ASCII text
    Category:dropped
    Size (bytes):3906
    Entropy (8bit):4.888385338353618
    Encrypted:false
    SSDEEP:96:806rYJdrYJQX3Z3r3dVeE642LuE3GBCRWY7KZxGYZKSPRU7kDqL:X6rsdrsQXJ3r37e6E3iCRN7KvPZKe2ka
    MD5:F9BE8610FAF9085333F6B8B5075DD0F1
    SHA1:1B2CC09F98148ED873C9474E6A70E6EEB9FACF62
    SHA-256:E33225898782E365B77BDE75F3133D8B367A85C09F80D1E0FF096911F45E76B7
    SHA-512:FC688817C4F6E190DD734C68D6434A8D2EC559E91C34CB0256CCF41E171CA6B96CECF1962666F05D17A6A1F866C30F60031CF826F6D40A5515A69984028F20D6
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2004, 2011, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABI
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java source, ASCII text
    Category:dropped
    Size (bytes):2143
    Entropy (8bit):5.111719057178671
    Encrypted:false
    SSDEEP:48:8cEO6rYJdrYJQSiz3y432sf32s5EtAJ3tcHEElM64WtLY9EtRGBnMF:806rYJdrYJQX3Z3r3dVeE642LuE3GBMF
    MD5:C59B475D442419AAEBA3659C681B0D6F
    SHA1:0E053B35773CFCF62910A67DC15BEE4C6BF5C63F
    SHA-256:AA723153394F85A7B9E6C4FC841D82BA255EAC4C6EAD2A49023EFB5200B49C83
    SHA-512:8CA271951AF5208912D6B5EFD1EE7C0565B2B2D41837B450397BC351E7D5A53D94505960AC280F278EE50F10302409DBFBBAB32B190FE4102DC664EA800FA933
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2004, 2011, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABI
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:ASCII text
    Category:dropped
    Size (bytes):2284
    Entropy (8bit):5.106424334767198
    Encrypted:false
    SSDEEP:48:8cEO6rYJdrYJQSiz3y432sf32s5EtAJ3tcHEElM64WtLY9EtRq:806rYJdrYJQX3Z3r3dVeE642LuE3q
    MD5:6552686C0738F823818386FBBBAFDA90
    SHA1:47820E0EE8BD25853CE647E844C68AB9EFA52E77
    SHA-256:D12117BD1718A2D5E45C35A944A782F17C1AC6BED7836E842DE93E19F6D19BC9
    SHA-512:9FD299363118F41E511CF66F218B9EC11AB55AA99836D02E32FC69BF4BFDCAEC8F894216B47F40D7D677FFA5E2616A9CE8D683D7E55E9E5FD202ED91D058CA60
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2004, 2011, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABI
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java source, ASCII text
    Category:dropped
    Size (bytes):2604
    Entropy (8bit):5.084884389621657
    Encrypted:false
    SSDEEP:48:8cEO6rYJdrYJQSiz3y432sf32s5EtAJ3tcHEElM64WtLY9EtRGmvClc2f65GAu:806rYJdrYJQX3Z3r3dVeE642LuE3Gmvs
    MD5:B033A6F283C16728D939F4570A63B42E
    SHA1:06F1A681E5A3B43CB51CD740054F33A7516B8E40
    SHA-256:44939C6FED90AFC28AEC39398A7DBEB576DF3349A24C8435BEA7727890D20C27
    SHA-512:EE5D456476B3E690D9BFDBD6CCE7DD506D68CC80AE9837496001A0192D809A0C792EC05C483D21A45D0B959F2750D6AA4DF5285A94EF942B5E584A8CB2CEAB36
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2004, 2011, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABI
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:ASCII text
    Category:dropped
    Size (bytes):2462
    Entropy (8bit):5.078162382542755
    Encrypted:false
    SSDEEP:48:8cEO6rYJdrYJQSiz3y432sf32s5EtAJ3tcHEElM64WtLY9EtRSn6F2t0cl65tS2:806rYJdrYJQX3Z3r3dVeE642LuE3SnlU
    MD5:778BD613423E2F53C8658FC6EFB2FCC6
    SHA1:8E6287CD1E4A4C09AE230A4F2C24379EC62DE21A
    SHA-256:23410D57BE10B904BB131F93D293D1E9C0E79FD4E7B69797C77429EF70018233
    SHA-512:AEF15AB566BF846C1209AFD5258B20D9E9514ABF6DD661EC158FF5C24DCACC1A02F38452307B766363EDE39BF1221C6FD843FF0AED6B54B6C2AC9744BEC7AC75
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2004, 2011, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABI
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:ASCII text
    Category:dropped
    Size (bytes):10320
    Entropy (8bit):4.813348797131472
    Encrypted:false
    SSDEEP:192:upFgyHtQVQyQ4l4p4R3T2K+EPfy7mEpdxVeh6KBfyfT7xN7TYv42sN90zQhTjqYS:updHtQh4oKaUdHedaZFYv42sN9rdHAn
    MD5:804AA5AC5911A1BA4C07511AB8B54437
    SHA1:04FF8F0126BF34049DA4CD19CD0D2B097F2EAD26
    SHA-256:B31A8DBE756097F250AC0BDEF0AF23787B9977B7D8F3060C70596A5A8BC46F0B
    SHA-512:961B6B999C169C53A7EBE93AE10BF4992DA604F2E4AC448BAFB91B0B48B1DF3013A118ECBB8BB4BDCBD950670E57C543EEA5D54D25D8AC1CFB2D4A387119E467
    Malicious:false
    Reputation:low
    Preview: A Simple NIO-based HTTP/HTTPS Server Example...INTRODUCTION.============.This directory contains a simple HTTP/HTTPS server. HTTP/HTTPS are two.common network protocols that provide for data transfer, and are more.fully described in RFC 2616 and RFC 2818 (Available at.http://www.ietf.org ). HTTPS is essentially HTTP after the connection.has been secured with SSL/TLS. TLS is the successor to SSL, and is.described in RFC 2246...This server was written to demonstrate some of the functionality new to.the Java 2 platform. The demo is not meant to be a full tutorial, and.assumes the reader has some familiarity with the subject matter...In particular, it shows:.. New I/O (java.nio, java.nio.channels, java.util.regex, java.nio.charset).. Introduced in version 1.4 of the platform, NIO was designed to. overcome some of the scalability limitations found in the. existing blocking java.net.* API's, and to address other. concepts such as Regular Expression p
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java source, ASCII text
    Category:dropped
    Size (bytes):4515
    Entropy (8bit):4.90448178360166
    Encrypted:false
    SSDEEP:96:806rYJdrYJQX3Z3r3dVeE642LuE3GB1LRZGyId3XHxBbX6W9VymXCkP:X6rsdrsQXJ3r37e6E3i1LRZGNBBbKW9X
    MD5:79A0B4586FA9671BC431399E00B1085C
    SHA1:43880B6FABDEACC17C36F9CEB0BB09ED45CE5C13
    SHA-256:5060962ED0C46EEA0AF29E6E1AD679F871D1001951DB73B28BDFEFD95577DC5A
    SHA-512:6ECEFD52E0295D8331F497BE2E8378F5B604C0A8BCDA409D7358CE260A4C324CAA71E03877B9CDA4404B786C6D18A050DC1BAEF4D48754FA338F356BFA0ABF5A
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2004, 2011, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABI
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:C++ source, ASCII text
    Category:dropped
    Size (bytes):5383
    Entropy (8bit):4.8485831984950885
    Encrypted:false
    SSDEEP:96:806rYJdrYJQX3Z3r3dVeE642LuE3GS1vUZRUQ7hmHAZTwuU88UoqvXq+6VeTmItu:X6rsdrsQXJ3r37e6E3P1v0OQ78AplU8m
    MD5:82C586A12C6B996694BB8A0198AC4448
    SHA1:CE0574447B6FF8278FE2AE2FFE1D34B94708A64E
    SHA-256:95FB3F764BC1C857FEAA45B14307B64F22D836AC90C1A2086C203DADE57E003D
    SHA-512:C29D34D20FD8A37D2D5BD8C680E50F892437E8CF09AE67D3F93500E620386C6D52C5E9979F95329C2973652069F5A1243BE393BC9F6F7347C3FCB54F7A162626
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2004, 2011, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABI
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java source, ASCII text
    Category:dropped
    Size (bytes):6566
    Entropy (8bit):4.485149543133823
    Encrypted:false
    SSDEEP:192:X6rsdrsQXJ3r37e6E3i1+irynmK9GxCo+OW6QQIN8SaSCeEiB4qmsHL:qrsdrsU5D7u39i+B93ruw/W+
    MD5:C2A0D28DFDA2F41D55D1FAF3C044C724
    SHA1:0B576E076B3DCB900E26086C7803CE6467BD2CF2
    SHA-256:A61ADAC98BB8D8ED2A02D9FA484739F5E810FDDBD823EB5475F5C0F682DF12E0
    SHA-512:8E16FEB8CE76A9EA65050B8E56E59C964D176AD781803C46A2E43B2A56875BA0AE9A983E2ECFC45ADD46FD304C5735206184DA8B160B8FA9C3E2231DA300B788
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2004, 2011, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABI
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java source, ASCII text
    Category:dropped
    Size (bytes):5268
    Entropy (8bit):4.608624822490526
    Encrypted:false
    SSDEEP:96:806rYJdrYJQX3Z3r3dVeE642LuE3GBz2tLO4jAy2PZSbEiBLsmynNNcyHMF5OQAJ:X6rsdrsQXJ3r37e6E3iz2+y2PZoEiB4d
    MD5:B33905B314E9F92437D2D1F015FCDD4C
    SHA1:108209B69282B17D8A2C8A399F3FCB6A5A75C8EF
    SHA-256:E0FABAC3F1EB45385A2950C155D3E3472B59B6E479A2B1E6655910D4D825C228
    SHA-512:78F126BE64A55D69FAA29B468F851C5E93CFDDBD72EC8D6CB05F3765E8A4DB53160D419848077A52CA810C17269C97C809E6C55DCAE48BDAD32B386D86730BDA
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2004, 2011, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABI
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java source, ASCII text
    Category:dropped
    Size (bytes):2403
    Entropy (8bit):5.072993432653521
    Encrypted:false
    SSDEEP:48:8cEO6rYJdrYJQSiz3y432sf32s5EtAJ3tcHEElM64WtLY9EtRGeOPZNMQ9n:806rYJdrYJQX3Z3r3dVeE642LuE3GzZj
    MD5:4D5A93C304EF1A98F5283551FBAB4200
    SHA1:A06DEE3B7D0339741D957F851293B7E0525532ED
    SHA-256:3B59807FED795C58728D0A9D3D81DC2341A8A385E1800BC1058A6847A0114E1A
    SHA-512:FB05D9C8D4802EC4D9833F33482DF5A9CE83B63BB6FF484BDA5485396A13A1E9B4CF721087616B6BDB92527FD84D0C2DA1FCD601D4F5128E61658CE6BD438C4A
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2004, 2011, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABI
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java source, ASCII text
    Category:dropped
    Size (bytes):6277
    Entropy (8bit):4.764457118820292
    Encrypted:false
    SSDEEP:192:X6rsdrsQXJ3r37e6E3iCRLaX2JdU75sEezdAEaz/sa:qrsdrsU5D7u3OX20vezdAN4a
    MD5:C9B17593E143F0C9B1315F38266D66E9
    SHA1:55139097F6DD23399920B6C976DD14603573F72B
    SHA-256:CA17AEAF87D3FC2FE04B994462D6D893CD3D6FA5EFCBB80558F7ACB4092131C3
    SHA-512:63528F817A56C01A901D0440E5D1992631A182C4026813FD4CE5A10E2ED78C3EBCC29971BA775D7869B3CF9CC236A13A4C79BB30AD46B7FABBB7155EA2F72D0B
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2004, 2011, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABI
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java source, ASCII text
    Category:dropped
    Size (bytes):3397
    Entropy (8bit):5.021185510186404
    Encrypted:false
    SSDEEP:96:806rYJdrYJQX3Z3r3dVeE642LuE3GB1WV6F76CKSa5MHcPEi5:X6rsdrsQXJ3r37e6E3i1c+76CU5Cgl5
    MD5:1792C624138DAFD26F7E2FB04EAC1040
    SHA1:560E95650B32DAB6D78DEBE5A95E25C3FD4A60A0
    SHA-256:DD875DE80ACC3EF24535BD339F59BF17A85D49E7CF9C28534DC3A853A7FA41E4
    SHA-512:3E422BC9D91892EF8861EA43B3F4A4F996BE0438D4235C9CE539F6E7138CC1D697C8839E6AFBEA34F9BEE594926294B5A093667B6EF4346FFD143D0FB0E52783
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2004, 2011, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABI
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java source, ASCII text
    Category:dropped
    Size (bytes):2836
    Entropy (8bit):5.072565254261759
    Encrypted:false
    SSDEEP:48:8cEO6rYJdrYJQSiz3y432sf32s5EtAJ3tcHEElM64WtLY9EtRGB/rATHhacH5R7W:806rYJdrYJQX3Z3r3dVeE642LuE3GB/z
    MD5:94BC04503F40B58D58086BFB7C203AC0
    SHA1:D48DD48B58E49F49F9CEC68BA80642882003F689
    SHA-256:5C35804D270B05998638DE702895D32FC0FFADD24D315A1A65740480BC29F59F
    SHA-512:E2C9E456525E005997AEC5B79D2B2BBB2053A6458E1904398FE09EBF81B4F530485CF49E5A24EFA12FDF463D5D2CF14EB43FC5AB8022632761302C9CA1182FC7
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2004, 2011, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABI
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java source, ASCII text
    Category:dropped
    Size (bytes):3010
    Entropy (8bit):4.9913453623904855
    Encrypted:false
    SSDEEP:48:8cEO6rYJdrYJQSiz3y432sf32s5EtAJ3tcHEElM64WtLY9EtRGBRK2HCEUljryFp:806rYJdrYJQX3Z3r3dVeE642LuE3GBRj
    MD5:BF45212FD354ABA8C5CFF6B8BFBEE947
    SHA1:71B38165227264947C496AC411A4D56961631173
    SHA-256:E72E9FBB412FA03082A5DC97035520AA3CFD8387FECC6627B0D06F201495FA26
    SHA-512:F35C5AAE860C8766F3245D17BD25CBF579981960E1C3968BA5A646E32DB4E501DC1322994374EB21D6F5A8E9FAC1526D629911C3607818A461731CD22A6B21C4
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2004, 2011, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABI
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java source, ASCII text
    Category:dropped
    Size (bytes):3143
    Entropy (8bit):4.9380058095402015
    Encrypted:false
    SSDEEP:96:806rYJdrYJQX3Z3r3dVeE642LuE3GBRXoQTML3Pe4cjjIlyL:X6rsdrsQXJ3r37e6E3iRXoQTMLG4cjjj
    MD5:6EEC81F17D1698B46D79429135419273
    SHA1:B53A34257CC521734B24947FFF9F6658FE777A47
    SHA-256:A3284EEA056D581D7C1D2A3084ACCDFE86B109C1075B50A1F2B1C65428A72D79
    SHA-512:0F46E2693CCB1875FC8042E0C0BA7E09FB05659411762EEA4B551725926FA2D3E61AA0849768BA5B3F3696A0D08F6877DF3F624754CD105DD9D32260218F1E62
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2004, 2011, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABI
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java source, ASCII text
    Category:dropped
    Size (bytes):2717
    Entropy (8bit):5.01354227160186
    Encrypted:false
    SSDEEP:48:8cEO6rYJdrYJQSiz3y432sf32s5EtAJ3tcHEElM64WtLY9EtRGTH8cl65FnWuPXA:806rYJdrYJQX3Z3r3dVeE642LuE3GTHZ
    MD5:32F8ADEBCEC60CB1110466F99B48A1E3
    SHA1:EE826E8C136A5BA8EC0999F40958A435D0CC8FC4
    SHA-256:C56977E1BC85347BAC666BB3AE52F4CF46CD978B6E044F74BA76334852F99FDB
    SHA-512:2698B3B7D5D6E32FD6B27AEEE577DEB1E6BD36BB3BF32E43D6234F76DDD6BF3E38F7A5C22E6DDF143BDF59EEF93934544AFE4ADDAF9E03742078D5EAFE84B124
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2004, 2011, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABI
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java source, ASCII text
    Category:dropped
    Size (bytes):2836
    Entropy (8bit):5.072565254261759
    Encrypted:false
    SSDEEP:48:8cEO6rYJdrYJQSiz3y432sf32s5EtAJ3tcHEElM64WtLY9EtRGB/rATHhacH5R7W:806rYJdrYJQX3Z3r3dVeE642LuE3GB/z
    MD5:94BC04503F40B58D58086BFB7C203AC0
    SHA1:D48DD48B58E49F49F9CEC68BA80642882003F689
    SHA-256:5C35804D270B05998638DE702895D32FC0FFADD24D315A1A65740480BC29F59F
    SHA-512:E2C9E456525E005997AEC5B79D2B2BBB2053A6458E1904398FE09EBF81B4F530485CF49E5A24EFA12FDF463D5D2CF14EB43FC5AB8022632761302C9CA1182FC7
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2004, 2011, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABI
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java source, ASCII text
    Category:dropped
    Size (bytes):3118
    Entropy (8bit):4.970042013258624
    Encrypted:false
    SSDEEP:96:806rYJdrYJQX3Z3r3dVeE642LuE3GBR5OO3EylHyu1/TiyxRJ2x:X6rsdrsQXJ3r37e6E3iR5OO3EuHyu1/m
    MD5:1CFE9D37418D42355AB76D53019F51E3
    SHA1:BBD3897625548E20D3B2CCC0A9D6D3B73D1CDB15
    SHA-256:5315DCD013D8CA6DE174CE3EF655A872B7942F17F55D1A8659F9832EBFBFE5E5
    SHA-512:C1EFFE51E96026EEC44CF32A2FE49F43C64768FEBE8AD37578A686A744D575767B6E0059FB807C12B219623E635DB5D8E4035CEF771970D58ED6C125E5D46C56
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2004, 2011, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABI
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java source, ASCII text
    Category:dropped
    Size (bytes):2814
    Entropy (8bit):4.998970334697864
    Encrypted:false
    SSDEEP:48:8cEO6rYJdrYJQSiz3y432sf32s5EtAJ3tcHEElM64WtLY9EtRGBigjAcl6xFnWu+:806rYJdrYJQX3Z3r3dVeE642LuE3GB37
    MD5:4131A06AFBB93E94F87521F739CB10CD
    SHA1:E17E98C96480413A918DCFC4C5AAB7C6881CCB78
    SHA-256:57DC130115D9F52A9B60B01ED5B532A668A78D8460E5803AE74CCB862EC8C081
    SHA-512:22B3D1EF872382601E2E97E0CA87EBC282D23203BFDC5D5F53933FE88A079F4447538F3DEB35C2B108660FC3572A2058B29B8EA102D9CA55CF1F4B7E47839011
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2004, 2011, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABI
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java source, ASCII text
    Category:dropped
    Size (bytes):3101
    Entropy (8bit):5.01768552178975
    Encrypted:false
    SSDEEP:96:806rYJdrYJQX3Z3r3dVeE642LuE3GBRdofXkHphoh4cJgjIb:X6rsdrsQXJ3r37e6E3iRdofUK4cKjIb
    MD5:B6B28491DEEC8B717894361EA5D07227
    SHA1:AD8097ED5017CD3E6DDA277E28BEEB8F7A0D1663
    SHA-256:50D28D7F5083FADB64F79250C47FA6E449D6C97980933ED3502BF0E591A063F9
    SHA-512:D5C06FE4365C9965FD0F9BED149DFD0FBCD69BD0DF64E7729CF5E10A3FBCA2AD3AA8B28C841BF7C6D334437E4F25F11676E1E1788462E61C9E00E752B6F13121
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2004, 2011, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABI
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java source, ASCII text
    Category:dropped
    Size (bytes):6566
    Entropy (8bit):4.485149543133823
    Encrypted:false
    SSDEEP:192:X6rsdrsQXJ3r37e6E3i1+irynmK9GxCo+OW6QQIN8SaSCeEiB4qmsHL:qrsdrsU5D7u39i+B93ruw/W+
    MD5:C2A0D28DFDA2F41D55D1FAF3C044C724
    SHA1:0B576E076B3DCB900E26086C7803CE6467BD2CF2
    SHA-256:A61ADAC98BB8D8ED2A02D9FA484739F5E810FDDBD823EB5475F5C0F682DF12E0
    SHA-512:8E16FEB8CE76A9EA65050B8E56E59C964D176AD781803C46A2E43B2A56875BA0AE9A983E2ECFC45ADD46FD304C5735206184DA8B160B8FA9C3E2231DA300B788
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2004, 2011, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABI
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java source, ASCII text
    Category:dropped
    Size (bytes):2280
    Entropy (8bit):5.093261350120955
    Encrypted:false
    SSDEEP:48:8cEO6rYJdrYJQSiz3y432sf32s5EtAJ3tcHEElM64WtLY9EtRGBI4z:806rYJdrYJQX3Z3r3dVeE642LuE3GBIY
    MD5:93C818045CBC472C0EDFB8F626217337
    SHA1:6C077B943AE4B32762CF096BB82E65D4BB948840
    SHA-256:4E84E9F4C7ECE024019730327FC75249EC8D06D7AD11235520CF6DA022053939
    SHA-512:C885FD3D43E2EE5D0B5DCAA8839B5664E47432FD295CB36D2907E5D77E282274BDE4055FF579E1839F9777D701B3358A09AA24636A7AB624D47AA2090A45D36E
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2004, 2011, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABI
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java source, ASCII text
    Category:dropped
    Size (bytes):2403
    Entropy (8bit):5.072993432653521
    Encrypted:false
    SSDEEP:48:8cEO6rYJdrYJQSiz3y432sf32s5EtAJ3tcHEElM64WtLY9EtRGeOPZNMQ9n:806rYJdrYJQX3Z3r3dVeE642LuE3GzZj
    MD5:4D5A93C304EF1A98F5283551FBAB4200
    SHA1:A06DEE3B7D0339741D957F851293B7E0525532ED
    SHA-256:3B59807FED795C58728D0A9D3D81DC2341A8A385E1800BC1058A6847A0114E1A
    SHA-512:FB05D9C8D4802EC4D9833F33482DF5A9CE83B63BB6FF484BDA5485396A13A1E9B4CF721087616B6BDB92527FD84D0C2DA1FCD601D4F5128E61658CE6BD438C4A
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2004, 2011, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABI
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java source, ASCII text
    Category:dropped
    Size (bytes):2143
    Entropy (8bit):5.111719057178671
    Encrypted:false
    SSDEEP:48:8cEO6rYJdrYJQSiz3y432sf32s5EtAJ3tcHEElM64WtLY9EtRGBnMF:806rYJdrYJQX3Z3r3dVeE642LuE3GBMF
    MD5:C59B475D442419AAEBA3659C681B0D6F
    SHA1:0E053B35773CFCF62910A67DC15BEE4C6BF5C63F
    SHA-256:AA723153394F85A7B9E6C4FC841D82BA255EAC4C6EAD2A49023EFB5200B49C83
    SHA-512:8CA271951AF5208912D6B5EFD1EE7C0565B2B2D41837B450397BC351E7D5A53D94505960AC280F278EE50F10302409DBFBBAB32B190FE4102DC664EA800FA933
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2004, 2011, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABI
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java source, ASCII text
    Category:dropped
    Size (bytes):6277
    Entropy (8bit):4.764457118820292
    Encrypted:false
    SSDEEP:192:X6rsdrsQXJ3r37e6E3iCRLaX2JdU75sEezdAEaz/sa:qrsdrsU5D7u3OX20vezdAN4a
    MD5:C9B17593E143F0C9B1315F38266D66E9
    SHA1:55139097F6DD23399920B6C976DD14603573F72B
    SHA-256:CA17AEAF87D3FC2FE04B994462D6D893CD3D6FA5EFCBB80558F7ACB4092131C3
    SHA-512:63528F817A56C01A901D0440E5D1992631A182C4026813FD4CE5A10E2ED78C3EBCC29971BA775D7869B3CF9CC236A13A4C79BB30AD46B7FABBB7155EA2F72D0B
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2004, 2011, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABI
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:C++ source, ASCII text
    Category:dropped
    Size (bytes):5975
    Entropy (8bit):4.816201739908655
    Encrypted:false
    SSDEEP:96:806rYJdrYJQX3Z3r3dVeE642LuE3GB1lrO4HfXBb0PcXYDA/F+I4Z4+UtXsV35oD:X6rsdrsQXJ3r37e6E3i1lyCPBAPcGA/r
    MD5:D125EB815BCAEB1C57AAFD34CC069105
    SHA1:2B022E6578058B0A590FE1EABEE4A584F0AB1383
    SHA-256:4BA27AA31A5EF1CC5D461DFA7107B8D58CC323C7CA028D2096C89CE60CD8F468
    SHA-512:76F592EA5BE2FAE5A8C669C882F1DCF6794E8D53567AF997124F6E5DD344040ED80CA26FBFEBF2ADD1F4BD6A8989FBD23E9D4A9276E76AA71F8F526CA4E7E937
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2004, 2011, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABI
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java source, ASCII text
    Category:dropped
    Size (bytes):3397
    Entropy (8bit):5.021185510186404
    Encrypted:false
    SSDEEP:96:806rYJdrYJQX3Z3r3dVeE642LuE3GB1WV6F76CKSa5MHcPEi5:X6rsdrsQXJ3r37e6E3i1c+76CU5Cgl5
    MD5:1792C624138DAFD26F7E2FB04EAC1040
    SHA1:560E95650B32DAB6D78DEBE5A95E25C3FD4A60A0
    SHA-256:DD875DE80ACC3EF24535BD339F59BF17A85D49E7CF9C28534DC3A853A7FA41E4
    SHA-512:3E422BC9D91892EF8861EA43B3F4A4F996BE0438D4235C9CE539F6E7138CC1D697C8839E6AFBEA34F9BEE594926294B5A093667B6EF4346FFD143D0FB0E52783
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2004, 2011, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABI
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java source, ASCII text
    Category:dropped
    Size (bytes):2971
    Entropy (8bit):5.017318128651048
    Encrypted:false
    SSDEEP:48:8cEO6rYJdrYJQSiz3y432sf32s5EtAJ3tcHEElM64WtLY9EtRGB/5mzSBpcl6Z2l:806rYJdrYJQX3Z3r3dVeE642LuE3GBB0
    MD5:36A0C920D57FBED4B16E76099D63BDB4
    SHA1:E267E9FE18DB761DB9E80747E6D0FD93F4EAF6BF
    SHA-256:6C506D48B8391266E83A2F8E6CCA4E5845793AEF5AF1D9B47111B930786C986E
    SHA-512:28AA10331C79F1F982ECEA6862D18BBC1BC443D83120F01F1681E5C5DFB6942E1A00B08F9079D24E891814DD9C17DE6CE0F0CC9799F819065985B01BB1D45D34
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2004, 2011, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABI
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:C++ source, ASCII text
    Category:dropped
    Size (bytes):5383
    Entropy (8bit):4.8485831984950885
    Encrypted:false
    SSDEEP:96:806rYJdrYJQX3Z3r3dVeE642LuE3GS1vUZRUQ7hmHAZTwuU88UoqvXq+6VeTmItu:X6rsdrsQXJ3r37e6E3P1v0OQ78AplU8m
    MD5:82C586A12C6B996694BB8A0198AC4448
    SHA1:CE0574447B6FF8278FE2AE2FFE1D34B94708A64E
    SHA-256:95FB3F764BC1C857FEAA45B14307B64F22D836AC90C1A2086C203DADE57E003D
    SHA-512:C29D34D20FD8A37D2D5BD8C680E50F892437E8CF09AE67D3F93500E620386C6D52C5E9979F95329C2973652069F5A1243BE393BC9F6F7347C3FCB54F7A162626
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2004, 2011, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABI
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java source, ASCII text
    Category:dropped
    Size (bytes):2604
    Entropy (8bit):5.084884389621657
    Encrypted:false
    SSDEEP:48:8cEO6rYJdrYJQSiz3y432sf32s5EtAJ3tcHEElM64WtLY9EtRGmvClc2f65GAu:806rYJdrYJQX3Z3r3dVeE642LuE3Gmvs
    MD5:B033A6F283C16728D939F4570A63B42E
    SHA1:06F1A681E5A3B43CB51CD740054F33A7516B8E40
    SHA-256:44939C6FED90AFC28AEC39398A7DBEB576DF3349A24C8435BEA7727890D20C27
    SHA-512:EE5D456476B3E690D9BFDBD6CCE7DD506D68CC80AE9837496001A0192D809A0C792EC05C483D21A45D0B959F2750D6AA4DF5285A94EF942B5E584A8CB2CEAB36
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2004, 2011, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABI
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java source, ASCII text
    Category:dropped
    Size (bytes):4515
    Entropy (8bit):4.90448178360166
    Encrypted:false
    SSDEEP:96:806rYJdrYJQX3Z3r3dVeE642LuE3GB1LRZGyId3XHxBbX6W9VymXCkP:X6rsdrsQXJ3r37e6E3i1LRZGNBBbKW9X
    MD5:79A0B4586FA9671BC431399E00B1085C
    SHA1:43880B6FABDEACC17C36F9CEB0BB09ED45CE5C13
    SHA-256:5060962ED0C46EEA0AF29E6E1AD679F871D1001951DB73B28BDFEFD95577DC5A
    SHA-512:6ECEFD52E0295D8331F497BE2E8378F5B604C0A8BCDA409D7358CE260A4C324CAA71E03877B9CDA4404B786C6D18A050DC1BAEF4D48754FA338F356BFA0ABF5A
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2004, 2011, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABI
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:ASCII text
    Category:dropped
    Size (bytes):2462
    Entropy (8bit):5.078162382542755
    Encrypted:false
    SSDEEP:48:8cEO6rYJdrYJQSiz3y432sf32s5EtAJ3tcHEElM64WtLY9EtRSn6F2t0cl65tS2:806rYJdrYJQX3Z3r3dVeE642LuE3SnlU
    MD5:778BD613423E2F53C8658FC6EFB2FCC6
    SHA1:8E6287CD1E4A4C09AE230A4F2C24379EC62DE21A
    SHA-256:23410D57BE10B904BB131F93D293D1E9C0E79FD4E7B69797C77429EF70018233
    SHA-512:AEF15AB566BF846C1209AFD5258B20D9E9514ABF6DD661EC158FF5C24DCACC1A02F38452307B766363EDE39BF1221C6FD843FF0AED6B54B6C2AC9744BEC7AC75
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2004, 2011, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABI
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:ASCII text
    Category:dropped
    Size (bytes):2233
    Entropy (8bit):5.081294779946435
    Encrypted:false
    SSDEEP:48:8cEO6rYJdrYJQSiz3y432sf32s5EtAJ3tcHEElM64WtLY9EtRhIoz3oMK:806rYJdrYJQX3Z3r3dVeE642LuE3qobi
    MD5:BA487CB0174386228F7843CC8D3B53BD
    SHA1:65C01F6D2203A36A5969D858E38732618E4CB4C3
    SHA-256:B8828550DBE3359F216B61345C54016F4D298F8478E88E1EE47927165C7806E4
    SHA-512:643E6F928A74D9EB4C8251ECD6393DD7D48C3A1106CF2603C61EC7C4A4A9CD2FD7F8DE2856EA94F7C389BC6E812B8A617FD7CA482097D6AEF7F360CA3A460463
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2004, 2011, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABI
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java source, ASCII text
    Category:dropped
    Size (bytes):5268
    Entropy (8bit):4.608624822490526
    Encrypted:false
    SSDEEP:96:806rYJdrYJQX3Z3r3dVeE642LuE3GBz2tLO4jAy2PZSbEiBLsmynNNcyHMF5OQAJ:X6rsdrsQXJ3r37e6E3iz2+y2PZoEiB4d
    MD5:B33905B314E9F92437D2D1F015FCDD4C
    SHA1:108209B69282B17D8A2C8A399F3FCB6A5A75C8EF
    SHA-256:E0FABAC3F1EB45385A2950C155D3E3472B59B6E479A2B1E6655910D4D825C228
    SHA-512:78F126BE64A55D69FAA29B468F851C5E93CFDDBD72EC8D6CB05F3765E8A4DB53160D419848077A52CA810C17269C97C809E6C55DCAE48BDAD32B386D86730BDA
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2004, 2011, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABI
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:ASCII text
    Category:dropped
    Size (bytes):2284
    Entropy (8bit):5.106424334767198
    Encrypted:false
    SSDEEP:48:8cEO6rYJdrYJQSiz3y432sf32s5EtAJ3tcHEElM64WtLY9EtRq:806rYJdrYJQX3Z3r3dVeE642LuE3q
    MD5:6552686C0738F823818386FBBBAFDA90
    SHA1:47820E0EE8BD25853CE647E844C68AB9EFA52E77
    SHA-256:D12117BD1718A2D5E45C35A944A782F17C1AC6BED7836E842DE93E19F6D19BC9
    SHA-512:9FD299363118F41E511CF66F218B9EC11AB55AA99836D02E32FC69BF4BFDCAEC8F894216B47F40D7D677FFA5E2616A9CE8D683D7E55E9E5FD202ED91D058CA60
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2004, 2011, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABI
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:ASCII text
    Category:dropped
    Size (bytes):10320
    Entropy (8bit):4.813348797131472
    Encrypted:false
    SSDEEP:192:upFgyHtQVQyQ4l4p4R3T2K+EPfy7mEpdxVeh6KBfyfT7xN7TYv42sN90zQhTjqYS:updHtQh4oKaUdHedaZFYv42sN9rdHAn
    MD5:804AA5AC5911A1BA4C07511AB8B54437
    SHA1:04FF8F0126BF34049DA4CD19CD0D2B097F2EAD26
    SHA-256:B31A8DBE756097F250AC0BDEF0AF23787B9977B7D8F3060C70596A5A8BC46F0B
    SHA-512:961B6B999C169C53A7EBE93AE10BF4992DA604F2E4AC448BAFB91B0B48B1DF3013A118ECBB8BB4BDCBD950670E57C543EEA5D54D25D8AC1CFB2D4A387119E467
    Malicious:false
    Reputation:low
    Preview: A Simple NIO-based HTTP/HTTPS Server Example...INTRODUCTION.============.This directory contains a simple HTTP/HTTPS server. HTTP/HTTPS are two.common network protocols that provide for data transfer, and are more.fully described in RFC 2616 and RFC 2818 (Available at.http://www.ietf.org ). HTTPS is essentially HTTP after the connection.has been secured with SSL/TLS. TLS is the successor to SSL, and is.described in RFC 2246...This server was written to demonstrate some of the functionality new to.the Java 2 platform. The demo is not meant to be a full tutorial, and.assumes the reader has some familiarity with the subject matter...In particular, it shows:.. New I/O (java.nio, java.nio.channels, java.util.regex, java.nio.charset).. Introduced in version 1.4 of the platform, NIO was designed to. overcome some of the scalability limitations found in the. existing blocking java.net.* API's, and to address other. concepts such as Regular Expression p
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java source, ASCII text
    Category:dropped
    Size (bytes):3906
    Entropy (8bit):4.888385338353618
    Encrypted:false
    SSDEEP:96:806rYJdrYJQX3Z3r3dVeE642LuE3GBCRWY7KZxGYZKSPRU7kDqL:X6rsdrsQXJ3r37e6E3iCRN7KvPZKe2ka
    MD5:F9BE8610FAF9085333F6B8B5075DD0F1
    SHA1:1B2CC09F98148ED873C9474E6A70E6EEB9FACF62
    SHA-256:E33225898782E365B77BDE75F3133D8B367A85C09F80D1E0FF096911F45E76B7
    SHA-512:FC688817C4F6E190DD734C68D6434A8D2EC559E91C34CB0256CCF41E171CA6B96CECF1962666F05D17A6A1F866C30F60031CF826F6D40A5515A69984028F20D6
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2004, 2011, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABI
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java source, ASCII text
    Category:dropped
    Size (bytes):20907
    Entropy (8bit):4.486158306476371
    Encrypted:false
    SSDEEP:384:qrsdrsU5D7u3mKa80+mS1owDiwfVoEzUdpze04pF45LJzc:qAPD7UY80+mS1oufVotpzqF45LJg
    MD5:08E12C59A8DFD8E3BE8A4193CD8FD4F0
    SHA1:9C205517A9474032D3B78EB02FEA7C66D00E5C62
    SHA-256:025FD9D1F487BC8B5F21D2684E19E2F464F5DA9E134ADB6924B2580FDA3C0B85
    SHA-512:598D63AD631413F08063E9FE34BD849B89C735E41194CE7D677B4581B457B2D329B0FE4DA15E39AA7DEC740E54C6D926A32AFC485C5661280E3EFFE82DD49BBE
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2004, 2011, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABI
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:ASCII text
    Category:dropped
    Size (bytes):4102
    Entropy (8bit):4.7396630183246184
    Encrypted:false
    SSDEEP:48:xk8imYww2phmrUxdJqaEm7K4bnTiod5uLUqK+a8h80SPOrQp6u4W3j7TPdUGMy1M:xGwbiUxKaxTicMUU2Oa6u44jvddM
    MD5:E3E0D7C97E4B2AFA3B35DA1D0E6E2131
    SHA1:2AEE560CEB122E43BF79CD9D09FD5AC57CC017C5
    SHA-256:447460280A6C81A472BF648D052E7152D7C82821B1B14049D458FEFE82F40409
    SHA-512:6A44F686669841CE721BA01055896583E977438E767C20AD5F1C5A2A3110AF26A7DF877E878DBF7537FA29D155B7DB686ED645518E91CF42362E58B30742C2CD
    Malicious:false
    Reputation:low
    Preview:Scriptpad Sample..* Introduction..Scriptpad is a notepad like editor to open/edit/save and run .script (JavaScript) files. This sample demonstrates the use of .javax.script (JSR-223) API and JavaScript engine that is bundled .with JDK 6...Scriptpad sample demonstrates how to use Javascript to use Java .classes and objects to perform various tasks such as to modify,.customize Swing GUI or to connect to a running application and .monitor it using JMX (Java Management Extensions) API...* How to run Scriptpad?..Scriptpad can be run with the following command:. . java -jar ./build/scriptpad.jar..(be sure to use the correct version of java). You can.open/edit/save scripts using menu items under "File" menu..To run currently edited script, you can use "Tools->Run" menu...For example, you may enter.. alert("hello, world");..in the editor and run the same with "Tools->Run" menu. .You will see an alert box with the message "hello, world"...In addition to being a simple script editor/ru
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:ASCII text
    Category:dropped
    Size (bytes):375
    Entropy (8bit):4.606873970904808
    Encrypted:false
    SSDEEP:6:5ZDj4MzJXk5tNPwatu2qtv4fNbGSYcSH7xAdCqLstlHrZsWpDecXlL3XG4jnn:5ZphutDtTqtvAoH7igwgdemRnPnn
    MD5:9A809F55868AA6B2AABD92B669FC8CAD
    SHA1:81AB2E843ED1EBBCE5FD0F8DBA290850FC67057B
    SHA-256:F891C46DDBAE5D78044CEE0B1BB34566AEBB37B5ADCB70A65DD2C18E8619985D
    SHA-512:8EA886CC1B2CCCBA7EBA7F5F7645FC76D22EA7064C5A5CDFFAC768E7819EA363717AF6D12FA1553A58862F62811FCBB6A66A560E228655BEAB7FE150B339A4DC
    Malicious:false
    Reputation:low
    Preview:main.dir=...src.dir=${main.dir}/src..build.dir=build.classes.dir=${build.dir}/classes.jar=${build.dir}/scriptpad.jar.javadoc.dir=${build.dir}/javadoc..build.sysclasspath=ignore.# E.g.: cp=lib/x.jar:lib/y.jar.cp=.extra.run.cp=..main.class=com.sun.sample.scriptpad.Main..run.cp=${cp}:${classes.dir}:${extra.run.cp}..debug=true.deprecation=false..nbjdk.home=${basedir}/../../...
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):3803
    Entropy (8bit):5.086113644646646
    Encrypted:false
    SSDEEP:48:ceOorYJTrYJEfDWQvs432sD32scMEtu33tYTH6YrLZqxwKmlKas/PLSR3yhGQSb9:YorYJTrYJEfiQX3f3jp2ay5TcHnhmh
    MD5:49F8334BF542BDBEFA85B68303F78E97
    SHA1:CC5A86E553C301BBD772F16560D7A307A5BBED48
    SHA-256:71E52D2ADB88655A33175CAC27534A06B703B3002562A9D9AFB057C3D31DE8EB
    SHA-512:08990D36BCDE5D1BD0885B1382288A89EC59427360590BE7AADEF3ECEE1AC607BDC83FD7D94AA4863D5440502D6B0B2C5122BFD35716FA604A4B54C9743F74E0
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?>.. . Copyright (c) 2006, Oracle and/or its affiliates. All rights reserved... Redistribution and use in source and binary forms, with or without. modification, are permitted provided that the following conditions. are met:.. - Redistributions of source code must retain the above copyright. notice, this list of conditions and the following disclaimer... - Redistributions in binary form must reproduce the above copyright. notice, this list of conditions and the following disclaimer in the. documentation and/or other materials provided with the distribution... - Neither the name of Oracle nor the names of its. contributors may be used to endorse or promote products derived. from this software without specific prior written permission... THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. THE IMPLIED WARRANTIES OF MERCHANTABILITY
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):3803
    Entropy (8bit):5.086113644646646
    Encrypted:false
    SSDEEP:48:ceOorYJTrYJEfDWQvs432sD32scMEtu33tYTH6YrLZqxwKmlKas/PLSR3yhGQSb9:YorYJTrYJEfiQX3f3jp2ay5TcHnhmh
    MD5:49F8334BF542BDBEFA85B68303F78E97
    SHA1:CC5A86E553C301BBD772F16560D7A307A5BBED48
    SHA-256:71E52D2ADB88655A33175CAC27534A06B703B3002562A9D9AFB057C3D31DE8EB
    SHA-512:08990D36BCDE5D1BD0885B1382288A89EC59427360590BE7AADEF3ECEE1AC607BDC83FD7D94AA4863D5440502D6B0B2C5122BFD35716FA604A4B54C9743F74E0
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?>.. . Copyright (c) 2006, Oracle and/or its affiliates. All rights reserved... Redistribution and use in source and binary forms, with or without. modification, are permitted provided that the following conditions. are met:.. - Redistributions of source code must retain the above copyright. notice, this list of conditions and the following disclaimer... - Redistributions in binary form must reproduce the above copyright. notice, this list of conditions and the following disclaimer in the. documentation and/or other materials provided with the distribution... - Neither the name of Oracle nor the names of its. contributors may be used to endorse or promote products derived. from this software without specific prior written permission... THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. THE IMPLIED WARRANTIES OF MERCHANTABILITY
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:ASCII text
    Category:dropped
    Size (bytes):375
    Entropy (8bit):4.606873970904808
    Encrypted:false
    SSDEEP:6:5ZDj4MzJXk5tNPwatu2qtv4fNbGSYcSH7xAdCqLstlHrZsWpDecXlL3XG4jnn:5ZphutDtTqtvAoH7igwgdemRnPnn
    MD5:9A809F55868AA6B2AABD92B669FC8CAD
    SHA1:81AB2E843ED1EBBCE5FD0F8DBA290850FC67057B
    SHA-256:F891C46DDBAE5D78044CEE0B1BB34566AEBB37B5ADCB70A65DD2C18E8619985D
    SHA-512:8EA886CC1B2CCCBA7EBA7F5F7645FC76D22EA7064C5A5CDFFAC768E7819EA363717AF6D12FA1553A58862F62811FCBB6A66A560E228655BEAB7FE150B339A4DC
    Malicious:false
    Reputation:low
    Preview:main.dir=...src.dir=${main.dir}/src..build.dir=build.classes.dir=${build.dir}/classes.jar=${build.dir}/scriptpad.jar.javadoc.dir=${build.dir}/javadoc..build.sysclasspath=ignore.# E.g.: cp=lib/x.jar:lib/y.jar.cp=.extra.run.cp=..main.class=com.sun.sample.scriptpad.Main..run.cp=${cp}:${classes.dir}:${extra.run.cp}..debug=true.deprecation=false..nbjdk.home=${basedir}/../../...
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:ASCII text
    Category:dropped
    Size (bytes):4102
    Entropy (8bit):4.7396630183246184
    Encrypted:false
    SSDEEP:48:xk8imYww2phmrUxdJqaEm7K4bnTiod5uLUqK+a8h80SPOrQp6u4W3j7TPdUGMy1M:xGwbiUxKaxTicMUU2Oa6u44jvddM
    MD5:E3E0D7C97E4B2AFA3B35DA1D0E6E2131
    SHA1:2AEE560CEB122E43BF79CD9D09FD5AC57CC017C5
    SHA-256:447460280A6C81A472BF648D052E7152D7C82821B1B14049D458FEFE82F40409
    SHA-512:6A44F686669841CE721BA01055896583E977438E767C20AD5F1C5A2A3110AF26A7DF877E878DBF7537FA29D155B7DB686ED645518E91CF42362E58B30742C2CD
    Malicious:false
    Reputation:low
    Preview:Scriptpad Sample..* Introduction..Scriptpad is a notepad like editor to open/edit/save and run .script (JavaScript) files. This sample demonstrates the use of .javax.script (JSR-223) API and JavaScript engine that is bundled .with JDK 6...Scriptpad sample demonstrates how to use Javascript to use Java .classes and objects to perform various tasks such as to modify,.customize Swing GUI or to connect to a running application and .monitor it using JMX (Java Management Extensions) API...* How to run Scriptpad?..Scriptpad can be run with the following command:. . java -jar ./build/scriptpad.jar..(be sure to use the correct version of java). You can.open/edit/save scripts using menu items under "File" menu..To run currently edited script, you can use "Tools->Run" menu...For example, you may enter.. alert("hello, world");..in the editor and run the same with "Tools->Run" menu. .You will see an alert box with the message "hello, world"...In addition to being a simple script editor/ru
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):2045
    Entropy (8bit):5.23220799363624
    Encrypted:false
    SSDEEP:48:ceOorYJTrYJEfDWQvs432sD32scMEtu33tYTHDWVKasrO:YorYJTrYJEfiQX3f3jp2qMC
    MD5:5D8E92D874243D49E5037857A71C2B36
    SHA1:46DFF8552D340670D620FD6AA1A2EB9253C9A946
    SHA-256:FD1D0A3080059F9E3222AB842D4C23B9D6CE6DAB32D05DBBC047461261573571
    SHA-512:61EA1E1C17B578BFCFCF1887FD1BE8F62A93D3D0C86A3AF437E9296CF9B5039E5FF5630C6ECE8F8947AC56C46AE7A0BCDE4EBBD1C6AE514D7B9E6609266119B2
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?>.. . Copyright (c) 2006, Oracle and/or its affiliates. All rights reserved... Redistribution and use in source and binary forms, with or without. modification, are permitted provided that the following conditions. are met:.. - Redistributions of source code must retain the above copyright. notice, this list of conditions and the following disclaimer... - Redistributions in binary form must reproduce the above copyright. notice, this list of conditions and the following disclaimer in the. documentation and/or other materials provided with the distribution... - Neither the name of Oracle nor the names of its. contributors may be used to endorse or promote products derived. from this software without specific prior written permission... THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. THE IMPLIED WARRANTIES OF MERCHANTABILITY
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):7444
    Entropy (8bit):4.233784931000385
    Encrypted:false
    SSDEEP:96:YorYJTrYJEfiQX3f3jp2FsGrJfkD+BbzYDrjh+RyW:YorsTrs+jX3f3d2F3rRBBbzYDrV+Rx
    MD5:1B6BE63EDA6DDF22A53605C763FAA268
    SHA1:1C06E22ADA5ED864A7B7D7858F205FD1E0C344E3
    SHA-256:5A72F747B4F64FBE0300A86FFEA273A0683851CC2213C6CE079ED7A25C5318BE
    SHA-512:35F066656B9F609971DFFB9991283E59F76FB5E97A0E7C2F2A008FEA8088870F16CC1C542BA03F8C2418E78712D3D0CE0E8D883F55CFC16AE71B42AD2E790284
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?>.. . Copyright (c) 2006, Oracle and/or its affiliates. All rights reserved... Redistribution and use in source and binary forms, with or without. modification, are permitted provided that the following conditions. are met:.. - Redistributions of source code must retain the above copyright. notice, this list of conditions and the following disclaimer... - Redistributions in binary form must reproduce the above copyright. notice, this list of conditions and the following disclaimer in the. documentation and/or other materials provided with the distribution... - Neither the name of Oracle nor the names of its. contributors may be used to endorse or promote products derived. from this software without specific prior written permission... THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. THE IMPLIED WARRANTIES OF MERCHANTABILITY
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):2045
    Entropy (8bit):5.23220799363624
    Encrypted:false
    SSDEEP:48:ceOorYJTrYJEfDWQvs432sD32scMEtu33tYTHDWVKasrO:YorYJTrYJEfiQX3f3jp2qMC
    MD5:5D8E92D874243D49E5037857A71C2B36
    SHA1:46DFF8552D340670D620FD6AA1A2EB9253C9A946
    SHA-256:FD1D0A3080059F9E3222AB842D4C23B9D6CE6DAB32D05DBBC047461261573571
    SHA-512:61EA1E1C17B578BFCFCF1887FD1BE8F62A93D3D0C86A3AF437E9296CF9B5039E5FF5630C6ECE8F8947AC56C46AE7A0BCDE4EBBD1C6AE514D7B9E6609266119B2
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?>.. . Copyright (c) 2006, Oracle and/or its affiliates. All rights reserved... Redistribution and use in source and binary forms, with or without. modification, are permitted provided that the following conditions. are met:.. - Redistributions of source code must retain the above copyright. notice, this list of conditions and the following disclaimer... - Redistributions in binary form must reproduce the above copyright. notice, this list of conditions and the following disclaimer in the. documentation and/or other materials provided with the distribution... - Neither the name of Oracle nor the names of its. contributors may be used to endorse or promote products derived. from this software without specific prior written permission... THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. THE IMPLIED WARRANTIES OF MERCHANTABILITY
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):3500
    Entropy (8bit):5.1484813718784075
    Encrypted:false
    SSDEEP:48:ceOorYJTrYJEfDWQvs432sD32scMEtu33tYTHDUhxuTJKaZzFKVzgDIE3YUvK5cf:YorYJTrYJEfiQX3f3jp2RzFaz4bso
    MD5:FC6C87AC59C7FEB5EB63E01548A9F1DC
    SHA1:F42A001A006FEBF65E24F24D9055F4E7BEBB5F86
    SHA-256:669269E4C502F942153B4996CDFDE50D04E75574CB08E81A76442FE1CEBD059D
    SHA-512:66E4D9DA06AFAF1E73A59D9A5E48A69F7107D6B6B4DB55071BACCF252B4C068973DF15EA63717BE3F77B267C6AB84C96F0F6622185A6C7C6D42A1DC5E031F975
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?>.. . Copyright (c) 2006, Oracle and/or its affiliates. All rights reserved... Redistribution and use in source and binary forms, with or without. modification, are permitted provided that the following conditions. are met:.. - Redistributions of source code must retain the above copyright. notice, this list of conditions and the following disclaimer... - Redistributions in binary form must reproduce the above copyright. notice, this list of conditions and the following disclaimer in the. documentation and/or other materials provided with the distribution... - Neither the name of Oracle nor the names of its. contributors may be used to endorse or promote products derived. from this software without specific prior written permission... THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. THE IMPLIED WARRANTIES OF MERCHANTABILITY
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):4218
    Entropy (8bit):4.9575689298800985
    Encrypted:false
    SSDEEP:48:ceOorYJTrYJEfDWQvs432sD32scMEtu33tYTHD5wj9fV3ORoZVPp1TED2AZiUZGQ:YorYJTrYJEfiQX3f3jp2FBY0
    MD5:8F8DB67A23AE3EFD024E91710F1A6739
    SHA1:26C3F95E0007310A3F6A35CCE6B61AF71B9F1C8B
    SHA-256:5AB23ACF89B98778B5885B46D500429E6906C4389CD4427D8D5BDE6727BB6BE3
    SHA-512:7E3B2E9EF782B2D12FEEF7DDF78FCDF4500ECA641E03AF66181D03DC81B0CD5B54E5376B245B0460A25FEA1AF70D11CF974FBCE1A5787D3310B50D56099FC2A1
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?>.. . Copyright (c) 2006, Oracle and/or its affiliates. All rights reserved... Redistribution and use in source and binary forms, with or without. modification, are permitted provided that the following conditions. are met:.. - Redistributions of source code must retain the above copyright. notice, this list of conditions and the following disclaimer... - Redistributions in binary form must reproduce the above copyright. notice, this list of conditions and the following disclaimer in the. documentation and/or other materials provided with the distribution... - Neither the name of Oracle nor the names of its. contributors may be used to endorse or promote products derived. from this software without specific prior written permission... THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. THE IMPLIED WARRANTIES OF MERCHANTABILITY
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):4218
    Entropy (8bit):4.9575689298800985
    Encrypted:false
    SSDEEP:48:ceOorYJTrYJEfDWQvs432sD32scMEtu33tYTHD5wj9fV3ORoZVPp1TED2AZiUZGQ:YorYJTrYJEfiQX3f3jp2FBY0
    MD5:8F8DB67A23AE3EFD024E91710F1A6739
    SHA1:26C3F95E0007310A3F6A35CCE6B61AF71B9F1C8B
    SHA-256:5AB23ACF89B98778B5885B46D500429E6906C4389CD4427D8D5BDE6727BB6BE3
    SHA-512:7E3B2E9EF782B2D12FEEF7DDF78FCDF4500ECA641E03AF66181D03DC81B0CD5B54E5376B245B0460A25FEA1AF70D11CF974FBCE1A5787D3310B50D56099FC2A1
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?>.. . Copyright (c) 2006, Oracle and/or its affiliates. All rights reserved... Redistribution and use in source and binary forms, with or without. modification, are permitted provided that the following conditions. are met:.. - Redistributions of source code must retain the above copyright. notice, this list of conditions and the following disclaimer... - Redistributions in binary form must reproduce the above copyright. notice, this list of conditions and the following disclaimer in the. documentation and/or other materials provided with the distribution... - Neither the name of Oracle nor the names of its. contributors may be used to endorse or promote products derived. from this software without specific prior written permission... THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. THE IMPLIED WARRANTIES OF MERCHANTABILITY
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):3500
    Entropy (8bit):5.1484813718784075
    Encrypted:false
    SSDEEP:48:ceOorYJTrYJEfDWQvs432sD32scMEtu33tYTHDUhxuTJKaZzFKVzgDIE3YUvK5cf:YorYJTrYJEfiQX3f3jp2RzFaz4bso
    MD5:FC6C87AC59C7FEB5EB63E01548A9F1DC
    SHA1:F42A001A006FEBF65E24F24D9055F4E7BEBB5F86
    SHA-256:669269E4C502F942153B4996CDFDE50D04E75574CB08E81A76442FE1CEBD059D
    SHA-512:66E4D9DA06AFAF1E73A59D9A5E48A69F7107D6B6B4DB55071BACCF252B4C068973DF15EA63717BE3F77B267C6AB84C96F0F6622185A6C7C6D42A1DC5E031F975
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?>.. . Copyright (c) 2006, Oracle and/or its affiliates. All rights reserved... Redistribution and use in source and binary forms, with or without. modification, are permitted provided that the following conditions. are met:.. - Redistributions of source code must retain the above copyright. notice, this list of conditions and the following disclaimer... - Redistributions in binary form must reproduce the above copyright. notice, this list of conditions and the following disclaimer in the. documentation and/or other materials provided with the distribution... - Neither the name of Oracle nor the names of its. contributors may be used to endorse or promote products derived. from this software without specific prior written permission... THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. THE IMPLIED WARRANTIES OF MERCHANTABILITY
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):7444
    Entropy (8bit):4.233784931000385
    Encrypted:false
    SSDEEP:96:YorYJTrYJEfiQX3f3jp2FsGrJfkD+BbzYDrjh+RyW:YorsTrs+jX3f3d2F3rRBBbzYDrV+Rx
    MD5:1B6BE63EDA6DDF22A53605C763FAA268
    SHA1:1C06E22ADA5ED864A7B7D7858F205FD1E0C344E3
    SHA-256:5A72F747B4F64FBE0300A86FFEA273A0683851CC2213C6CE079ED7A25C5318BE
    SHA-512:35F066656B9F609971DFFB9991283E59F76FB5E97A0E7C2F2A008FEA8088870F16CC1C542BA03F8C2418E78712D3D0CE0E8D883F55CFC16AE71B42AD2E790284
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?>.. . Copyright (c) 2006, Oracle and/or its affiliates. All rights reserved... Redistribution and use in source and binary forms, with or without. modification, are permitted provided that the following conditions. are met:.. - Redistributions of source code must retain the above copyright. notice, this list of conditions and the following disclaimer... - Redistributions in binary form must reproduce the above copyright. notice, this list of conditions and the following disclaimer in the. documentation and/or other materials provided with the distribution... - Neither the name of Oracle nor the names of its. contributors may be used to endorse or promote products derived. from this software without specific prior written permission... THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. THE IMPLIED WARRANTIES OF MERCHANTABILITY
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:ASCII text
    Category:dropped
    Size (bytes):43
    Entropy (8bit):4.135940488298283
    Encrypted:false
    SSDEEP:3:ZML2bQWeiEcM9Cv:pbYZsv
    MD5:812541A050BA75D0B3E8A98EBE210BC1
    SHA1:3FB0E8540CD504969D612B895D25339B1146FC59
    SHA-256:0046C4725EE858616749895F1C580903810FCD574EB469BBCE141CE1F706AD08
    SHA-512:41E07E2AA07812AFD1651A21361E3A35F5C4E0D2B322D6D1B24ED17A41F3D8A62FBB44744A7D0A70D40FD56E4F0B23171F9D8D9DFBC0589F43F4DCCB2C09FA36
    Malicious:false
    Reputation:low
    Preview:Main-Class: com.sun.sample.scriptpad.Main..
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:ASCII text
    Category:dropped
    Size (bytes):43
    Entropy (8bit):4.135940488298283
    Encrypted:false
    SSDEEP:3:ZML2bQWeiEcM9Cv:pbYZsv
    MD5:812541A050BA75D0B3E8A98EBE210BC1
    SHA1:3FB0E8540CD504969D612B895D25339B1146FC59
    SHA-256:0046C4725EE858616749895F1C580903810FCD574EB469BBCE141CE1F706AD08
    SHA-512:41E07E2AA07812AFD1651A21361E3A35F5C4E0D2B322D6D1B24ED17A41F3D8A62FBB44744A7D0A70D40FD56E4F0B23171F9D8D9DFBC0589F43F4DCCB2C09FA36
    Malicious:false
    Reputation:low
    Preview:Main-Class: com.sun.sample.scriptpad.Main..
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java source, ASCII text
    Category:dropped
    Size (bytes):3441
    Entropy (8bit):4.983417166625343
    Encrypted:false
    SSDEEP:96:r6rYJdrYJQX3Z3r3dVeE642LuE3KMXEiHcbu5p49GcYczL0:r6rsdrsQXJ3r37e6E3KuEiHcS5p49LYB
    MD5:2C58D972C437200DBBE02EBD86C98391
    SHA1:0A4763FC8599B8AB46820FAC7426A1F58C45FF1B
    SHA-256:1F0AFBB449BCE4CDBB37A7EA490B8125D9289F15AA500568F5E426FC0A10F2A0
    SHA-512:C0BEBF7C2DFBBD4679150C33C3A86FB3CD3EE3CB67F929E55ADF1042BCC0B7EEEC951AAC9C4D51E336544C7187FEF028424A483A4B66946161B1A5447545C290
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2006, 2013, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABI
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java source, ASCII text
    Category:dropped
    Size (bytes):3441
    Entropy (8bit):4.983417166625343
    Encrypted:false
    SSDEEP:96:r6rYJdrYJQX3Z3r3dVeE642LuE3KMXEiHcbu5p49GcYczL0:r6rsdrsQXJ3r37e6E3KuEiHcS5p49LYB
    MD5:2C58D972C437200DBBE02EBD86C98391
    SHA1:0A4763FC8599B8AB46820FAC7426A1F58C45FF1B
    SHA-256:1F0AFBB449BCE4CDBB37A7EA490B8125D9289F15AA500568F5E426FC0A10F2A0
    SHA-512:C0BEBF7C2DFBBD4679150C33C3A86FB3CD3EE3CB67F929E55ADF1042BCC0B7EEEC951AAC9C4D51E336544C7187FEF028424A483A4B66946161B1A5447545C290
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2006, 2013, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABI
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:ASCII text
    Category:dropped
    Size (bytes):2100
    Entropy (8bit):5.129440543316367
    Encrypted:false
    SSDEEP:48:lEO6rYJdrYJQSiz3y432sf32s5EtAJ3tcHEElM64WtLY9EtRGC:r6rYJdrYJQX3Z3r3dVeE642LuE3GC
    MD5:764EE0CAE27958043182EDEEBF5B7AE8
    SHA1:6AFA1B2A123893BD3E0F39AA8C3C12C1DDCA43B0
    SHA-256:8D1B94EFCDCE2B0F66CF1859BC02A3AB3888D437308825809B99EBD8BDDBCF0E
    SHA-512:136177779B5D99098D1B642C58F06BB7461EB81474563C369CBF475C7E1AFCB184CE06560EA7048FB72B38D21AA3D641436107F8FD24F92B7569B182A7982774
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2006, 2013, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABI
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:ASCII text
    Category:dropped
    Size (bytes):9772
    Entropy (8bit):4.898549509051308
    Encrypted:false
    SSDEEP:192:r6rsdrsQXJ3r37e6E39nyLDdrBHHzBUeCwZbACwSQt+EHRyBIXDvp9VXhv8t9Mii:ersdrsU5D7u39nADdrVK2ZQRJXDPFhGQ
    MD5:6C1ACFCF8F02CAFAFA6F9BAC1DB6C83F
    SHA1:00AF5B88E726366480EE1B4CF843B353C545C072
    SHA-256:E8ADFDF05881632392B40F30EADF615B285C49B134DF8D3FD2375FB1C850F09D
    SHA-512:9D35B32530C1BB249C45614698D6784289797FE9C1BFC6ACAD836B721962A1EA28F32AE7BCBC812BC23869BFFEE295C7E89B4790C862F0EE369DDC005B25BE1F
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2006, 2013, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABI
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:ASCII text
    Category:dropped
    Size (bytes):8345
    Entropy (8bit):4.939409722600749
    Encrypted:false
    SSDEEP:192:r6rsdrsQXJ3r37e6E3f2ZM9trz5FxgFwIjh2dDZ9d:ersdrsU5D7u3t+wIgdF9d
    MD5:95C1831051E9CEEDDE3A275E774DFBEF
    SHA1:52B4654A52F6443D55303B02563B1FD7A9168BE3
    SHA-256:A3A6AD74D429C83F2AFE3E8F11AC4D0510D729785E2D3664FA0810C7DB03B9B5
    SHA-512:A5A3EB0A7E1DE3ACF38E0A25A6221F0DD427814A88103A5C96DC54B425CF26CDFC1F6085ECBF3E15301408772F5C5B275A5A0DAE26533A2BC0DAD23FC464E5FB
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2006, 2013, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABI
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:ASCII text
    Category:dropped
    Size (bytes):22382
    Entropy (8bit):4.521077659695302
    Encrypted:false
    SSDEEP:384:ersdrsU5D7u3xF1b82jkWJFPZDE3CMtwMfKx5mGmQ:eAPD7UxF1b82LPZE3CMhK9mQ
    MD5:A27F32364D9612E56A2C5DFC56745F1F
    SHA1:09E7CE7066616F45645649BCDCB2AA08FA3443BA
    SHA-256:B8B3CAF773AF83BB7516F601C9FD3E8864D515981C7BE36A5785DBC0B1948146
    SHA-512:AC44A8F037C2627BA29B7089BF47F0B8B7AED5D19C3EC9E82FAEC461DB47E095F75CE327C1D5EB5E3F424B1D0EE605E10BF1F105A169790294A57A9F2228715E
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2006, 2013, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABI
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:ASCII text
    Category:dropped
    Size (bytes):9772
    Entropy (8bit):4.898549509051308
    Encrypted:false
    SSDEEP:192:r6rsdrsQXJ3r37e6E39nyLDdrBHHzBUeCwZbACwSQt+EHRyBIXDvp9VXhv8t9Mii:ersdrsU5D7u39nADdrVK2ZQRJXDPFhGQ
    MD5:6C1ACFCF8F02CAFAFA6F9BAC1DB6C83F
    SHA1:00AF5B88E726366480EE1B4CF843B353C545C072
    SHA-256:E8ADFDF05881632392B40F30EADF615B285C49B134DF8D3FD2375FB1C850F09D
    SHA-512:9D35B32530C1BB249C45614698D6784289797FE9C1BFC6ACAD836B721962A1EA28F32AE7BCBC812BC23869BFFEE295C7E89B4790C862F0EE369DDC005B25BE1F
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2006, 2013, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABI
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:ASCII text
    Category:dropped
    Size (bytes):2100
    Entropy (8bit):5.129440543316367
    Encrypted:false
    SSDEEP:48:lEO6rYJdrYJQSiz3y432sf32s5EtAJ3tcHEElM64WtLY9EtRGC:r6rYJdrYJQX3Z3r3dVeE642LuE3GC
    MD5:764EE0CAE27958043182EDEEBF5B7AE8
    SHA1:6AFA1B2A123893BD3E0F39AA8C3C12C1DDCA43B0
    SHA-256:8D1B94EFCDCE2B0F66CF1859BC02A3AB3888D437308825809B99EBD8BDDBCF0E
    SHA-512:136177779B5D99098D1B642C58F06BB7461EB81474563C369CBF475C7E1AFCB184CE06560EA7048FB72B38D21AA3D641436107F8FD24F92B7569B182A7982774
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2006, 2013, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABI
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:ASCII text
    Category:dropped
    Size (bytes):8345
    Entropy (8bit):4.939409722600749
    Encrypted:false
    SSDEEP:192:r6rsdrsQXJ3r37e6E3f2ZM9trz5FxgFwIjh2dDZ9d:ersdrsU5D7u3t+wIgdF9d
    MD5:95C1831051E9CEEDDE3A275E774DFBEF
    SHA1:52B4654A52F6443D55303B02563B1FD7A9168BE3
    SHA-256:A3A6AD74D429C83F2AFE3E8F11AC4D0510D729785E2D3664FA0810C7DB03B9B5
    SHA-512:A5A3EB0A7E1DE3ACF38E0A25A6221F0DD427814A88103A5C96DC54B425CF26CDFC1F6085ECBF3E15301408772F5C5B275A5A0DAE26533A2BC0DAD23FC464E5FB
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2006, 2013, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABI
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:ASCII text
    Category:dropped
    Size (bytes):11129
    Entropy (8bit):4.842293019627944
    Encrypted:false
    SSDEEP:192:r6rsdrsQXJ3r37e6E32LqPze4Q/nlVFEzLxwTQCMQqpogEQOwUZyxF46m36E6yY2:ersdrsU5D7u39zY0TcZh
    MD5:5743DA06DFE0DA4DD9B4E1E3290CCA77
    SHA1:DFC3BBAFDEA45CE62EAE44693F86BFD50E4AD4FC
    SHA-256:795B3F9E0229E540D0A5C3B8E2DBC83EFD92BF9EE79AB5401B515F0E37997EC0
    SHA-512:F05FFB3C238E8CE34E4063CD8CE8C1DEA304337C31BC0E3373A15CA7C6DF40C938E09FE1A28A2AD3A850397FE02E47A8B6EEADBCC66685F162574C26071E1A4A
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2006, 2013, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABI
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:ASCII text
    Category:dropped
    Size (bytes):11129
    Entropy (8bit):4.842293019627944
    Encrypted:false
    SSDEEP:192:r6rsdrsQXJ3r37e6E32LqPze4Q/nlVFEzLxwTQCMQqpogEQOwUZyxF46m36E6yY2:ersdrsU5D7u39zY0TcZh
    MD5:5743DA06DFE0DA4DD9B4E1E3290CCA77
    SHA1:DFC3BBAFDEA45CE62EAE44693F86BFD50E4AD4FC
    SHA-256:795B3F9E0229E540D0A5C3B8E2DBC83EFD92BF9EE79AB5401B515F0E37997EC0
    SHA-512:F05FFB3C238E8CE34E4063CD8CE8C1DEA304337C31BC0E3373A15CA7C6DF40C938E09FE1A28A2AD3A850397FE02E47A8B6EEADBCC66685F162574C26071E1A4A
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2006, 2013, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABI
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:ASCII text
    Category:dropped
    Size (bytes):22382
    Entropy (8bit):4.521077659695302
    Encrypted:false
    SSDEEP:384:ersdrsU5D7u3xF1b82jkWJFPZDE3CMtwMfKx5mGmQ:eAPD7UxF1b82LPZE3CMhK9mQ
    MD5:A27F32364D9612E56A2C5DFC56745F1F
    SHA1:09E7CE7066616F45645649BCDCB2AA08FA3443BA
    SHA-256:B8B3CAF773AF83BB7516F601C9FD3E8864D515981C7BE36A5785DBC0B1948146
    SHA-512:AC44A8F037C2627BA29B7089BF47F0B8B7AED5D19C3EC9E82FAEC461DB47E095F75CE327C1D5EB5E3F424B1D0EE605E10BF1F105A169790294A57A9F2228715E
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2006, 2013, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABI
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:ASCII text
    Category:dropped
    Size (bytes):1827
    Entropy (8bit):4.53817505715394
    Encrypted:false
    SSDEEP:24:d93DURevI40vRsmTE/UzQAaqpO5Mn/KVV+xsFYB9tKuAXw68mz+vsRbg:d9kOI44zpnhpie/mExhBuuAA6nCsFg
    MD5:817CF97485B0E1141831B31C71354A24
    SHA1:76EE433C5F51E91073B27DB67563576C23694BBB
    SHA-256:55B70D182F421150CF3E60010C4B94B1F5938B5329AB2F5388F7C0BFF91F55C5
    SHA-512:49BD20B4310507B0CD0FE8E2D6C8E8AB3096DA2D63BADC7DA989B6A5F25B3A044085A94A53073C8F4A331FABAEBF45CDF10F50CB4A8FC355346457BA0CC8DD43
    Malicious:false
    Reputation:low
    Preview:Sample scripts:..(1) browse.js .. -- Open and run this script in scriptpad. You will see . Tools->Browse menu. Using this you can start your. desktop default browser with the given URL...(2) insertfile.js.. -- Open and run this script in scriptpad. You will see . "Tools->Insert File..." menu. Using this you can start . insert content of a selected file into currently. edited document..(3) linewrap.js.. -- Open and run this script in scriptpad. You will see . "Tools->Line Wrap" menu. Using this you can toggle. the line wrapping mode of the editor..(4) mail.js.. -- Open and run this script in scriptpad. You will see . Tools->Mail menu. Using this you can start your. desktop default mail client with the given "To" mail id...(5) memmonitor.js.. -- This is a simple Monitoring & Management script. To use this,. you need an application to monitor. You can use memory.bat. or memory.sh in the current directory to start an application. that will be monitored.
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:ASCII text
    Category:dropped
    Size (bytes):2834
    Entropy (8bit):5.092241483949803
    Encrypted:false
    SSDEEP:48:lEO6rYJdrYJQSiz3y432sf32s5EtAJ3tcHEElM64WtLY9EtRM/CMd9mqiSA96L5I:r6rYJdrYJQX3Z3r3dVeE642LuE3Mqhq2
    MD5:F576370118722788167DDC09A4787AF7
    SHA1:CB79BDA66C73447CAC42DA8BBC0EF8BCABFA90B3
    SHA-256:2CCA82B6D3460CB7CFF983421596C9C1675F270CF5412578FEB17B97B7BF204A
    SHA-512:73CA6DFCACEF585B281C70725A5CD7945CAEE5F8080BB7CC3B568F012C976705F5087B6D87010E520AC1697678FFCE38166C05476ECDBE7DAC700F0E6846598D
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2006, 2013, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABI
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:ASCII text
    Category:dropped
    Size (bytes):2930
    Entropy (8bit):4.950786178394661
    Encrypted:false
    SSDEEP:48:lEO6rYJdrYJQSiz3y432sf32s5EtAJ3tcHEElM64WtLY9EtRmAg8FL:r6rYJdrYJQX3Z3r3dVeE642LuE3mAL
    MD5:AA5F5E64E1CFB8C2642818B3155DDBD2
    SHA1:797E5EFADFC4F084F6036B734F547A703265811C
    SHA-256:F913D131CDD70CED6F0BFCDC973646A61DA60083C38EE64A0605264618F392FE
    SHA-512:85CCF7F51F057A249AC722A7A48B95195CD4464F056AF53A7DCCBE01953CA46F8FFDBF58CF3CAAD99C42B01FA9B385CCC1517742E99EB2E679C0B962DE6F831B
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2006, 2013, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABI
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:ASCII text
    Category:dropped
    Size (bytes):2797
    Entropy (8bit):5.099555175856046
    Encrypted:false
    SSDEEP:48:lEO6rYJdrYJQSiz3y432sf32s5EtAJ3tcHEElM64WtLY9EtRM/DMd9m1qUSU:r6rYJdrYJQX3Z3r3dVeE642LuE3MrhkQ
    MD5:54B1AB7EAFB483361FA1FB8EED708CDF
    SHA1:DD73B826695863FFB45E138538C795CA7B69E65C
    SHA-256:A3BB13C32AA77445DA4C3AD4562D8BE6BA51088CF77D5819B251DEC6A29988BD
    SHA-512:5D87E8094923904912F974C4C136E7388CCEAFB7705B9CA5091B725560F53ED0855A66C785F73C066A1666C474DDC007F0282893910AA193B3CFED793933D1DD
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2006, 2013, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABI
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:DOS batch file, ASCII text
    Category:dropped
    Size (bytes):1796
    Entropy (8bit):5.165728622497482
    Encrypted:false
    SSDEEP:48:muOsrYJdrYJM3qRM2432si3AF32s9EtvAD3tkHLB:m7srYJdrYJM6ud32I3JpmrB
    MD5:8E03A43EC00484D9D9B421B73BCDEF0D
    SHA1:0816B9D374EEB68824DC7C1C4B399375E766C544
    SHA-256:976E2B445089A4A77278935E9C51CE12D22026B9710BC03C158D7A2731E85BE1
    SHA-512:B88BF8F3986C8C376E1EC09A2307548B47BCC9CCE3C0A1590EAF7646D892DA29EB80736CE8D7F031724128A1682DD88CD2ED0810CD44425FA4580C3F2E0C7E63
    Malicious:false
    Reputation:low
    Preview:@echo off.REM.REM Copyright (c) 2006, Oracle and/or its affiliates. All rights reserved..REM.REM Redistribution and use in source and binary forms, with or without.REM modification, are permitted provided that the following conditions.REM are met:.REM.REM - Redistributions of source code must retain the above copyright.REM notice, this list of conditions and the following disclaimer..REM.REM - Redistributions in binary form must reproduce the above copyright.REM notice, this list of conditions and the following disclaimer in the.REM documentation and/or other materials provided with the distribution..REM.REM - Neither the name of Oracle nor the names of its.REM contributors may be used to endorse or promote products derived.REM from this software without specific prior written permission..REM.REM THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS.REM IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,.REM THE IMPLIED
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:ASCII text
    Category:dropped
    Size (bytes):3055
    Entropy (8bit):5.059821039868571
    Encrypted:false
    SSDEEP:48:lEO6rYJdrYJQSiz3y432sf32s5EtAJ3tcHEElM64WtLY9EtREBxtgwrO7vAJf5:r6rYJdrYJQX3Z3r3dVeE642LuE3m+v6h
    MD5:FF537CBE5559CBD632CD3989872E0624
    SHA1:9EA86B3739E42F513BF352CD02CB6AE9A8270892
    SHA-256:3C11D3984C482428E7511E8B2B29A3E10ECC20F02FA1798AE3DEE114FA510937
    SHA-512:94942313B7647515EAAD014B45152F690B125023990CC383CC0178FD6CF440775A30A5D7296BBEE88C428A42C9725CC54471E2B4A2A557BE0BBC41D3E8A6C747
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2006, 2013, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABI
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:ASCII text
    Category:dropped
    Size (bytes):2382
    Entropy (8bit):5.171057158824723
    Encrypted:false
    SSDEEP:48:lEO6rYJdrYJQSiz3y432sf32s5EtAJ3tcHEElM64WtLY9EtR4NLtbXojr:r6rYJdrYJQX3Z3r3dVeE642LuE34Ntby
    MD5:AD02B3CD135608D7C146EB13F155EAA9
    SHA1:5FDF746F52A83AE4631D5B5432555984485E5070
    SHA-256:F8160B887DBB3EE593CD150E0C5B06EB01D6614A622C4DAD9972EB86897418EF
    SHA-512:1CEA9E3A402DAB1C86ACC63232E22C787041ACFE35CBF8065BB3DA56F867E545651AFBE616B4FC728D258BE226ADFAB541E9976C7621F6CC6373A7C4041DEECA
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2006, 2013, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABI
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:ASCII text
    Category:dropped
    Size (bytes):2354
    Entropy (8bit):5.062026629464246
    Encrypted:false
    SSDEEP:48:lEO6rYJdrYJQSiz3y432sf32s5EtAJ3tcHEElM64WtLY9EtRkU4Bt7:r6rYJdrYJQX3Z3r3dVeE642LuE3kU4Bl
    MD5:D6D8E69A4A59DA9219CC1E9BCC24F35E
    SHA1:DB1DF089BC482C51B47E3A155F2C2580675F53E7
    SHA-256:70AED0CF687A2AB66601C14FC782528B36FF7137758C3238E51374CC49FF4CE7
    SHA-512:32174B0D1AA74779AEF23BEB343888E2E488600C3887FCB070384E45AAB45152ECDE7EFC64ACAC6A145A14FAF54BD2EA525F3EB82756A5BF129EDE5CE3BB1D8F
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2006, 2013, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABI
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:ASCII text
    Category:dropped
    Size (bytes):1827
    Entropy (8bit):4.53817505715394
    Encrypted:false
    SSDEEP:24:d93DURevI40vRsmTE/UzQAaqpO5Mn/KVV+xsFYB9tKuAXw68mz+vsRbg:d9kOI44zpnhpie/mExhBuuAA6nCsFg
    MD5:817CF97485B0E1141831B31C71354A24
    SHA1:76EE433C5F51E91073B27DB67563576C23694BBB
    SHA-256:55B70D182F421150CF3E60010C4B94B1F5938B5329AB2F5388F7C0BFF91F55C5
    SHA-512:49BD20B4310507B0CD0FE8E2D6C8E8AB3096DA2D63BADC7DA989B6A5F25B3A044085A94A53073C8F4A331FABAEBF45CDF10F50CB4A8FC355346457BA0CC8DD43
    Malicious:false
    Reputation:low
    Preview:Sample scripts:..(1) browse.js .. -- Open and run this script in scriptpad. You will see . Tools->Browse menu. Using this you can start your. desktop default browser with the given URL...(2) insertfile.js.. -- Open and run this script in scriptpad. You will see . "Tools->Insert File..." menu. Using this you can start . insert content of a selected file into currently. edited document..(3) linewrap.js.. -- Open and run this script in scriptpad. You will see . "Tools->Line Wrap" menu. Using this you can toggle. the line wrapping mode of the editor..(4) mail.js.. -- Open and run this script in scriptpad. You will see . Tools->Mail menu. Using this you can start your. desktop default mail client with the given "To" mail id...(5) memmonitor.js.. -- This is a simple Monitoring & Management script. To use this,. you need an application to monitor. You can use memory.bat. or memory.sh in the current directory to start an application. that will be monitored.
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:ASCII text
    Category:dropped
    Size (bytes):2834
    Entropy (8bit):5.092241483949803
    Encrypted:false
    SSDEEP:48:lEO6rYJdrYJQSiz3y432sf32s5EtAJ3tcHEElM64WtLY9EtRM/CMd9mqiSA96L5I:r6rYJdrYJQX3Z3r3dVeE642LuE3Mqhq2
    MD5:F576370118722788167DDC09A4787AF7
    SHA1:CB79BDA66C73447CAC42DA8BBC0EF8BCABFA90B3
    SHA-256:2CCA82B6D3460CB7CFF983421596C9C1675F270CF5412578FEB17B97B7BF204A
    SHA-512:73CA6DFCACEF585B281C70725A5CD7945CAEE5F8080BB7CC3B568F012C976705F5087B6D87010E520AC1697678FFCE38166C05476ECDBE7DAC700F0E6846598D
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2006, 2013, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABI
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:POSIX shell script, ASCII text executable
    Category:dropped
    Size (bytes):1740
    Entropy (8bit):5.218604115824527
    Encrypted:false
    SSDEEP:48:kyOlrYJErYJFHvv432sDt32sWEtPu3tOHap:kPlrYJErYJFPQ3vt3S346p
    MD5:85D50BCCE0F162428576D58612559E41
    SHA1:4D8C3102B1E83355291B37CDB125938E75F76D3B
    SHA-256:5DB26F962E5BB948D61F5F3AA12C9BBB5598CA8FD2D4011E3B8AE140BB1EB246
    SHA-512:41BB6E6C7C0D66E3355478ED4BEAD96930D215C1520625FA86BE9845FBC3EA7AA217FB37B4C7619FDF31A731A7DCAFC91CE148D652DF99A2BDE2EBF39D073638
    Malicious:false
    Antivirus:
    • Antivirus: ReversingLabs, Detection: 0%
    Reputation:low
    Preview:#!/bin/sh.#.# Copyright (c) 2006, 2013, Oracle and/or its affiliates. All rights reserved..#.# Redistribution and use in source and binary forms, with or without.# modification, are permitted provided that the following conditions.# are met:.#.# - Redistributions of source code must retain the above copyright.# notice, this list of conditions and the following disclaimer..#.# - Redistributions in binary form must reproduce the above copyright.# notice, this list of conditions and the following disclaimer in the.# documentation and/or other materials provided with the distribution..#.# - Neither the name of Oracle nor the names of its.# contributors may be used to endorse or promote products derived.# from this software without specific prior written permission..#.# THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS.# IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,.# THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FI
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:ASCII text
    Category:dropped
    Size (bytes):2243
    Entropy (8bit):5.101737380100649
    Encrypted:false
    SSDEEP:48:lEO6rYJdrYJQSiz3y432sf32s5EtAJ3tcHEElM64WtLY9EtRdcA:r6rYJdrYJQX3Z3r3dVeE642LuE3P
    MD5:A387495D4D43E5FF7FBC46ADAE9C8C84
    SHA1:E536AD653B2EE488B82F71CEE1B9638A4CB19018
    SHA-256:FE815E4621F8AE816757E428DD2FF77B2CDE4AC452D5766C5B8581133E8871F1
    SHA-512:3504106BFCB36992283C38ACE49F870B8D5263351C413543161DED177370D7E50757B532F8A14CBC0A5E85513C4810C20EF373D415CC18E7CFE7E07341B0338D
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2006, 2013, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABI
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:ASCII text
    Category:dropped
    Size (bytes):2930
    Entropy (8bit):4.950786178394661
    Encrypted:false
    SSDEEP:48:lEO6rYJdrYJQSiz3y432sf32s5EtAJ3tcHEElM64WtLY9EtRmAg8FL:r6rYJdrYJQX3Z3r3dVeE642LuE3mAL
    MD5:AA5F5E64E1CFB8C2642818B3155DDBD2
    SHA1:797E5EFADFC4F084F6036B734F547A703265811C
    SHA-256:F913D131CDD70CED6F0BFCDC973646A61DA60083C38EE64A0605264618F392FE
    SHA-512:85CCF7F51F057A249AC722A7A48B95195CD4464F056AF53A7DCCBE01953CA46F8FFDBF58CF3CAAD99C42B01FA9B385CCC1517742E99EB2E679C0B962DE6F831B
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2006, 2013, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABI
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:ASCII text
    Category:dropped
    Size (bytes):2243
    Entropy (8bit):5.101737380100649
    Encrypted:false
    SSDEEP:48:lEO6rYJdrYJQSiz3y432sf32s5EtAJ3tcHEElM64WtLY9EtRdcA:r6rYJdrYJQX3Z3r3dVeE642LuE3P
    MD5:A387495D4D43E5FF7FBC46ADAE9C8C84
    SHA1:E536AD653B2EE488B82F71CEE1B9638A4CB19018
    SHA-256:FE815E4621F8AE816757E428DD2FF77B2CDE4AC452D5766C5B8581133E8871F1
    SHA-512:3504106BFCB36992283C38ACE49F870B8D5263351C413543161DED177370D7E50757B532F8A14CBC0A5E85513C4810C20EF373D415CC18E7CFE7E07341B0338D
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2006, 2013, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABI
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:ASCII text
    Category:dropped
    Size (bytes):2797
    Entropy (8bit):5.099555175856046
    Encrypted:false
    SSDEEP:48:lEO6rYJdrYJQSiz3y432sf32s5EtAJ3tcHEElM64WtLY9EtRM/DMd9m1qUSU:r6rYJdrYJQX3Z3r3dVeE642LuE3MrhkQ
    MD5:54B1AB7EAFB483361FA1FB8EED708CDF
    SHA1:DD73B826695863FFB45E138538C795CA7B69E65C
    SHA-256:A3BB13C32AA77445DA4C3AD4562D8BE6BA51088CF77D5819B251DEC6A29988BD
    SHA-512:5D87E8094923904912F974C4C136E7388CCEAFB7705B9CA5091B725560F53ED0855A66C785F73C066A1666C474DDC007F0282893910AA193B3CFED793933D1DD
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2006, 2013, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABI
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:ASCII text
    Category:dropped
    Size (bytes):3055
    Entropy (8bit):5.059821039868571
    Encrypted:false
    SSDEEP:48:lEO6rYJdrYJQSiz3y432sf32s5EtAJ3tcHEElM64WtLY9EtREBxtgwrO7vAJf5:r6rYJdrYJQX3Z3r3dVeE642LuE3m+v6h
    MD5:FF537CBE5559CBD632CD3989872E0624
    SHA1:9EA86B3739E42F513BF352CD02CB6AE9A8270892
    SHA-256:3C11D3984C482428E7511E8B2B29A3E10ECC20F02FA1798AE3DEE114FA510937
    SHA-512:94942313B7647515EAAD014B45152F690B125023990CC383CC0178FD6CF440775A30A5D7296BBEE88C428A42C9725CC54471E2B4A2A557BE0BBC41D3E8A6C747
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2006, 2013, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABI
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:DOS batch file, ASCII text
    Category:dropped
    Size (bytes):1796
    Entropy (8bit):5.165728622497482
    Encrypted:false
    SSDEEP:48:muOsrYJdrYJM3qRM2432si3AF32s9EtvAD3tkHLB:m7srYJdrYJM6ud32I3JpmrB
    MD5:8E03A43EC00484D9D9B421B73BCDEF0D
    SHA1:0816B9D374EEB68824DC7C1C4B399375E766C544
    SHA-256:976E2B445089A4A77278935E9C51CE12D22026B9710BC03C158D7A2731E85BE1
    SHA-512:B88BF8F3986C8C376E1EC09A2307548B47BCC9CCE3C0A1590EAF7646D892DA29EB80736CE8D7F031724128A1682DD88CD2ED0810CD44425FA4580C3F2E0C7E63
    Malicious:false
    Reputation:low
    Preview:@echo off.REM.REM Copyright (c) 2006, Oracle and/or its affiliates. All rights reserved..REM.REM Redistribution and use in source and binary forms, with or without.REM modification, are permitted provided that the following conditions.REM are met:.REM.REM - Redistributions of source code must retain the above copyright.REM notice, this list of conditions and the following disclaimer..REM.REM - Redistributions in binary form must reproduce the above copyright.REM notice, this list of conditions and the following disclaimer in the.REM documentation and/or other materials provided with the distribution..REM.REM - Neither the name of Oracle nor the names of its.REM contributors may be used to endorse or promote products derived.REM from this software without specific prior written permission..REM.REM THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS.REM IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,.REM THE IMPLIED
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:ASCII text
    Category:dropped
    Size (bytes):2382
    Entropy (8bit):5.171057158824723
    Encrypted:false
    SSDEEP:48:lEO6rYJdrYJQSiz3y432sf32s5EtAJ3tcHEElM64WtLY9EtR4NLtbXojr:r6rYJdrYJQX3Z3r3dVeE642LuE34Ntby
    MD5:AD02B3CD135608D7C146EB13F155EAA9
    SHA1:5FDF746F52A83AE4631D5B5432555984485E5070
    SHA-256:F8160B887DBB3EE593CD150E0C5B06EB01D6614A622C4DAD9972EB86897418EF
    SHA-512:1CEA9E3A402DAB1C86ACC63232E22C787041ACFE35CBF8065BB3DA56F867E545651AFBE616B4FC728D258BE226ADFAB541E9976C7621F6CC6373A7C4041DEECA
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2006, 2013, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABI
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:POSIX shell script, ASCII text executable
    Category:dropped
    Size (bytes):1740
    Entropy (8bit):5.218604115824527
    Encrypted:false
    SSDEEP:48:kyOlrYJErYJFHvv432sDt32sWEtPu3tOHap:kPlrYJErYJFPQ3vt3S346p
    MD5:85D50BCCE0F162428576D58612559E41
    SHA1:4D8C3102B1E83355291B37CDB125938E75F76D3B
    SHA-256:5DB26F962E5BB948D61F5F3AA12C9BBB5598CA8FD2D4011E3B8AE140BB1EB246
    SHA-512:41BB6E6C7C0D66E3355478ED4BEAD96930D215C1520625FA86BE9845FBC3EA7AA217FB37B4C7619FDF31A731A7DCAFC91CE148D652DF99A2BDE2EBF39D073638
    Malicious:false
    Antivirus:
    • Antivirus: ReversingLabs, Detection: 0%
    Reputation:low
    Preview:#!/bin/sh.#.# Copyright (c) 2006, 2013, Oracle and/or its affiliates. All rights reserved..#.# Redistribution and use in source and binary forms, with or without.# modification, are permitted provided that the following conditions.# are met:.#.# - Redistributions of source code must retain the above copyright.# notice, this list of conditions and the following disclaimer..#.# - Redistributions in binary form must reproduce the above copyright.# notice, this list of conditions and the following disclaimer in the.# documentation and/or other materials provided with the distribution..#.# - Neither the name of Oracle nor the names of its.# contributors may be used to endorse or promote products derived.# from this software without specific prior written permission..#.# THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS.# IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,.# THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FI
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:ASCII text
    Category:dropped
    Size (bytes):2354
    Entropy (8bit):5.062026629464246
    Encrypted:false
    SSDEEP:48:lEO6rYJdrYJQSiz3y432sf32s5EtAJ3tcHEElM64WtLY9EtRkU4Bt7:r6rYJdrYJQX3Z3r3dVeE642LuE3kU4Bl
    MD5:D6D8E69A4A59DA9219CC1E9BCC24F35E
    SHA1:DB1DF089BC482C51B47E3A155F2C2580675F53E7
    SHA-256:70AED0CF687A2AB66601C14FC782528B36FF7137758C3238E51374CC49FF4CE7
    SHA-512:32174B0D1AA74779AEF23BEB343888E2E488600C3887FCB070384E45AAB45152ECDE7EFC64ACAC6A145A14FAF54BD2EA525F3EB82756A5BF129EDE5CE3BB1D8F
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2006, 2013, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABI
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:HTML document, ASCII text, with CRLF line terminators
    Category:dropped
    Size (bytes):986
    Entropy (8bit):4.744418008475161
    Encrypted:false
    SSDEEP:24:houG8verPmSxrfQoxaWz6VWWz6jGQMTPmu+ld0HB27xN:yp7eM9xaWzbWzUMTe0HB2L
    MD5:05DFD5E80116E299E836D3E36AD6464C
    SHA1:30D96F3F2ED5FC980D675B602DC8EAF6BE0BDFC7
    SHA-256:8492321176B8D2433CCE5B1046C604D350ABAA9635A7BC934A92D859D8D49411
    SHA-512:FED5864E36187213AC10DB6DEDB381CB891E61469C17E2426002CAED2ECB417D8D4C67EA0D741FFA224D0DCC7867910CB5369CAD23170C12036500AD70A51620
    Malicious:false
    Reputation:low
    Preview:<!DOCTYPE html>....<html>..<head>.. <title>Try-with-Resources Feature Demo</title>..</head>..<body>..<h2>Try-with-Resources Feature Demo</h2>....<p>.. This demo shows how to use the try-with-resources feature introduced in JDK7...</p>....<ul>.. <li><h3>Custom AutoCloseable.</h3>.... <p>.. Shows how to use a custom resource with the try-with-resources construct... For more information, see the source file... </p>.. Source: <a href="src/CustomAutoCloseableSample.java">src/CustomAutoCloseableSample.java</a>.... <li><h3>Unzip</h3>.... <p>.. Extracts archived files. For more information, see the source file... </p>.. Source: <a href="src/Unzip.java">src/Unzip.java</a>.. <li><h3>ZipCat</h3>.... <p>Prints data about a specified file from an archive. For more information, see the source file.</p>.. Source: <a href="src/ZipCat.java">src/ZipCat.java</a>....</ul>..</body>..</html>
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:HTML document, ASCII text, with CRLF line terminators
    Category:dropped
    Size (bytes):986
    Entropy (8bit):4.744418008475161
    Encrypted:false
    SSDEEP:24:houG8verPmSxrfQoxaWz6VWWz6jGQMTPmu+ld0HB27xN:yp7eM9xaWzbWzUMTe0HB2L
    MD5:05DFD5E80116E299E836D3E36AD6464C
    SHA1:30D96F3F2ED5FC980D675B602DC8EAF6BE0BDFC7
    SHA-256:8492321176B8D2433CCE5B1046C604D350ABAA9635A7BC934A92D859D8D49411
    SHA-512:FED5864E36187213AC10DB6DEDB381CB891E61469C17E2426002CAED2ECB417D8D4C67EA0D741FFA224D0DCC7867910CB5369CAD23170C12036500AD70A51620
    Malicious:false
    Reputation:low
    Preview:<!DOCTYPE html>....<html>..<head>.. <title>Try-with-Resources Feature Demo</title>..</head>..<body>..<h2>Try-with-Resources Feature Demo</h2>....<p>.. This demo shows how to use the try-with-resources feature introduced in JDK7...</p>....<ul>.. <li><h3>Custom AutoCloseable.</h3>.... <p>.. Shows how to use a custom resource with the try-with-resources construct... For more information, see the source file... </p>.. Source: <a href="src/CustomAutoCloseableSample.java">src/CustomAutoCloseableSample.java</a>.... <li><h3>Unzip</h3>.... <p>.. Extracts archived files. For more information, see the source file... </p>.. Source: <a href="src/Unzip.java">src/Unzip.java</a>.. <li><h3>ZipCat</h3>.... <p>Prints data about a specified file from an archive. For more information, see the source file.</p>.. Source: <a href="src/ZipCat.java">src/ZipCat.java</a>....</ul>..</body>..</html>
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java source, ASCII text
    Category:dropped
    Size (bytes):5184
    Entropy (8bit):4.752886565476414
    Encrypted:false
    SSDEEP:96:o6rYJdrYJQX3Z3r3dVeE642LuELF2JdxJrVO1hgu8N2IGVD8/qByLYpI6Gno5VCW:o6rsdrsQXJ3r37e6ELFudxJrVuSu8N29
    MD5:7D07E8864342A06EDDC74AC10EF47903
    SHA1:5F3A3615154D3DF0E2F7FA390DDE6B7EC3EDAAA9
    SHA-256:649682F7A08C17CBA01EC074F6D880D117FBFE87AA23C19536DBAC09697296FA
    SHA-512:34C77698DBB084F4BA48BEE512D716F9D62B7F34E099F27291C822768E362D68BCC75E897602FB76578E23C690F3CF2763D6FC69BB66B1484A0E6F888F2B6C0F
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2014, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABILITY A
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java source, ASCII text
    Category:dropped
    Size (bytes):3372
    Entropy (8bit):4.999071091983145
    Encrypted:false
    SSDEEP:96:o6rYJdrYJQX3Z3r3dVeE642LuELGvZx+F/ufL:o6rsdrsQXJ3r37e6ELAZx+pufL
    MD5:929CD3C67BDE7C76AA1DFF9DEB69EECD
    SHA1:F5B0E4F96D8807FA8ADED534A957FCA29695A38A
    SHA-256:C9C27F0431BA7663D98504EC8BA6A169C218B413C9AF0096A1101EF76989DB37
    SHA-512:E07FE4497A6F015EE412BBC4DC77E26E89AF8B7BB046DF2D02049389F63A7C8924E06BEC6EE6798523CA3E1446E4E0F5ACAF78E2196F81F79F3B7C688BA3A290
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2014, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABILITY A
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java source, ASCII text
    Category:dropped
    Size (bytes):3367
    Entropy (8bit):4.959839272630315
    Encrypted:false
    SSDEEP:96:o6rYJdrYJQX3Z3r3dVeE642LuEL+JQJzJgYq1/vi8V88L:o6rsdrsQXJ3r37e6EL2clgp1XiJ8L
    MD5:4E621D73C1D07CBEEF651CCC8BEF336B
    SHA1:FC646C309637EBEDA4F09EDB31641D49E2394B42
    SHA-256:7DD5F8BCBD5F47EEA6BD75C4A8D283AB7BD022452190757FE92D810CD65133B0
    SHA-512:0B9F9BA0A15F638666026C9058DE85AFD4BDF11B59E7DAFA1640AF70858831FF8704FF8D8D0244981867C9DB53572BD0955C6F937FA513A1FAB8C0553AE9C9CE
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2014, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABILITY A
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java source, ASCII text
    Category:dropped
    Size (bytes):5184
    Entropy (8bit):4.752886565476414
    Encrypted:false
    SSDEEP:96:o6rYJdrYJQX3Z3r3dVeE642LuELF2JdxJrVO1hgu8N2IGVD8/qByLYpI6Gno5VCW:o6rsdrsQXJ3r37e6ELFudxJrVuSu8N29
    MD5:7D07E8864342A06EDDC74AC10EF47903
    SHA1:5F3A3615154D3DF0E2F7FA390DDE6B7EC3EDAAA9
    SHA-256:649682F7A08C17CBA01EC074F6D880D117FBFE87AA23C19536DBAC09697296FA
    SHA-512:34C77698DBB084F4BA48BEE512D716F9D62B7F34E099F27291C822768E362D68BCC75E897602FB76578E23C690F3CF2763D6FC69BB66B1484A0E6F888F2B6C0F
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2014, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABILITY A
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java source, ASCII text
    Category:dropped
    Size (bytes):3367
    Entropy (8bit):4.959839272630315
    Encrypted:false
    SSDEEP:96:o6rYJdrYJQX3Z3r3dVeE642LuEL+JQJzJgYq1/vi8V88L:o6rsdrsQXJ3r37e6EL2clgp1XiJ8L
    MD5:4E621D73C1D07CBEEF651CCC8BEF336B
    SHA1:FC646C309637EBEDA4F09EDB31641D49E2394B42
    SHA-256:7DD5F8BCBD5F47EEA6BD75C4A8D283AB7BD022452190757FE92D810CD65133B0
    SHA-512:0B9F9BA0A15F638666026C9058DE85AFD4BDF11B59E7DAFA1640AF70858831FF8704FF8D8D0244981867C9DB53572BD0955C6F937FA513A1FAB8C0553AE9C9CE
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2014, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABILITY A
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java source, ASCII text
    Category:dropped
    Size (bytes):3372
    Entropy (8bit):4.999071091983145
    Encrypted:false
    SSDEEP:96:o6rYJdrYJQX3Z3r3dVeE642LuELGvZx+F/ufL:o6rsdrsQXJ3r37e6ELAZx+pufL
    MD5:929CD3C67BDE7C76AA1DFF9DEB69EECD
    SHA1:F5B0E4F96D8807FA8ADED534A957FCA29695A38A
    SHA-256:C9C27F0431BA7663D98504EC8BA6A169C218B413C9AF0096A1101EF76989DB37
    SHA-512:E07FE4497A6F015EE412BBC4DC77E26E89AF8B7BB046DF2D02049389F63A7C8924E06BEC6EE6798523CA3E1446E4E0F5ACAF78E2196F81F79F3B7C688BA3A290
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2014, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABILITY A
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:ASCII text
    Category:dropped
    Size (bytes):1522
    Entropy (8bit):4.747042537008044
    Encrypted:false
    SSDEEP:24:b0fFDmMbmRMAOJDcJb3W2zeD34eXqC/5Wx/kaRilV8hWrwr1:b09PbmqAOJIW2KT4eXqC/5WFkaEQW8Z
    MD5:D94F7C92FF61C5D3F8E9433F76E39F74
    SHA1:7A9B074CA8D783DBE5310ECC22F5538B65CC918E
    SHA-256:A44EB7B5CAF5534C6EF536B21EDB40B4D6BABF91BF97D9D45596868618B2C6FB
    SHA-512:D4044F6CEB094753075036920C0669631F4D3C13203CAF2BEA345E2CC4094905719732010BBE1CAE97BC78743AA6DEF7C2AA33F3E8FCA9971F2CA0457837D3B0
    Malicious:false
    Reputation:low
    Preview:.OPENJDK ASSEMBLY EXCEPTION..The OpenJDK source code made available by Oracle America, Inc. (Oracle) at.openjdk.java.net ("OpenJDK Code") is distributed under the terms of the GNU.General Public License <http://www.gnu.org/copyleft/gpl.html> version 2.only ("GPL2"), with the following clarification and special exception... Linking this OpenJDK Code statically or dynamically with other code. is making a combined work based on this library. Thus, the terms. and conditions of GPL2 cover the whole combination... As a special exception, Oracle gives you permission to link this. OpenJDK Code with certain code licensed by Oracle as indicated at. http://openjdk.java.net/legal/exception-modules-2007-05-08.html. ("Designated Exception Modules") to produce an executable,. regardless of the license terms of the Designated Exception Modules,. and to copy and distribute the resulting executable under GPL2,. provided that the Designated Exception Modules continue to be.
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:ISO-8859 text
    Category:dropped
    Size (bytes):3244
    Entropy (8bit):4.504892344419146
    Encrypted:false
    SSDEEP:96:3kjJXQSqgbiihCrRbo+Q/cV0rDcFBL3P0/r3:3cAaOi01E+xV0rDaBL3P0z3
    MD5:A762796B2A8989B8952B653A178607A1
    SHA1:C725183C757011E7BA96C83C1E86EE7E8B516A2B
    SHA-256:79CCB53E0DBDB8EC16747A516EB77C3737C797E544AAA0A552B8A886A70EEF69
    SHA-512:9D88BD2910A0D7820732D498B11B4676A5A122F24093640D8F07D417E4D7077A3D411F5F3E96CC124483DBED9C940B9526CA8B19FBC7CE69CB294476FCAA6C91
    Malicious:false
    Reputation:low
    Preview:Copyright . 1993, 2018, Oracle and/or its affiliates..All rights reserved...This software and related documentation are provided under a.license agreement containing restrictions on use and.disclosure and are protected by intellectual property laws..Except as expressly permitted in your license agreement or.allowed by law, you may not use, copy, reproduce, translate,.broadcast, modify, license, transmit, distribute, exhibit,.perform, publish, or display any part, in any form, or by.any means. Reverse engineering, disassembly, or.decompilation of this software, unless required by law for.interoperability, is prohibited...The information contained herein is subject to change.without notice and is not warranted to be error-free. If you.find any errors, please report them to us in writing...If this is software or related documentation that is.delivered to the U.S. Government or anyone licensing it on.behalf of the U.S. Government, the following notice is.applicable:..U.S. GOVERNMENT END US
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:ASCII text
    Category:dropped
    Size (bytes):19274
    Entropy (8bit):4.667864876938965
    Encrypted:false
    SSDEEP:384:sY2fSz/rGvS/66YsaZdIP3Lf4vAkMVhPGkupdDdicW:7vuvVmjkbylupdDdiZ
    MD5:3E0B59F8FAC05C3C03D4A26BBDA13F8F
    SHA1:A4FB972C240D89131EE9E16B845CD302E0ECB05F
    SHA-256:4B9ABEBC4338048A7C2DC184E9F800DEB349366BDF28EB23C2677A77B4C87726
    SHA-512:6732288C682A39ED9EDF11A151F6F48E742696F4A762C0C7D8872B99B9F6D5AB6C305064D4910B1A254862A873129F11FD0FA56FF11BC577D29303F4FB492673
    Malicious:false
    Reputation:low
    Preview:The GNU General Public License (GPL)..Version 2, June 1991..Copyright (C) 1989, 1991 Free Software Foundation, Inc..51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA..Everyone is permitted to copy and distribute verbatim copies of this license.document, but changing it is not allowed...Preamble..The licenses for most software are designed to take away your freedom to share.and change it. By contrast, the GNU General Public License is intended to.guarantee your freedom to share and change free software--to make sure the.software is free for all its users. This General Public License applies to.most of the Free Software Foundation's software and to any other program whose.authors commit to using it. (Some other Free Software Foundation software is.covered by the GNU Library General Public License instead.) You can apply it to.your programs, too...When we speak of free software, we are referring to freedom, not price. Our.General Public Licenses are designed to make sure that
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:ASCII text
    Category:dropped
    Size (bytes):46
    Entropy (8bit):4.197049999347145
    Encrypted:false
    SSDEEP:3:c3AXFshzhRSkU:c9hzhgkU
    MD5:0F1123976B959AC5E8B89EB8C245C4BD
    SHA1:F90331DF1E5BADEADC501D8DD70714C62A920204
    SHA-256:963095CF8DB76FB8071FD19A3110718A42F2AB42B27A3ADFD9EC58981C3E88D2
    SHA-512:E9136FDF42A4958138732318DF0B4BA363655D97F8449703A3B3A40DDB40EEFF56363267D07939889086A500CB9C9AAF887B73EEAD06231269116110A0C0A693
    Malicious:false
    Reputation:low
    Preview:Please refer to http://java.com/licensereadme.
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Unicode text, UTF-8 (with BOM) text
    Category:dropped
    Size (bytes):112724
    Entropy (8bit):4.842748696940968
    Encrypted:false
    SSDEEP:3072:ig3JrYrpltztZvepyFrqN7amC3jqN7amC3bqN7amC3w:L3mqN2pjqN2pbqN2pw
    MD5:CD510833A28BB88BFEF18E7084F83FF5
    SHA1:56FF42F87607B997B52AE0EF8BF315E36932E870
    SHA-256:18193FE6B7A04B12FBC04C6C383ED67982A3BFF62773087175FFF6DC05731B13
    SHA-512:B5D452CCAFE7F997EEA9B77735E11DFC13C916C8DBBD386CE0FE7304CFD995772A2AD7F5A8624889382D6706641A145975805D11B303F9711D0AAC253E9424E9
    Malicious:false
    Reputation:low
    Preview:.DO NOT TRANSLATE OR LOCALIZE..***************************************************************************..%%The following software may be included in this product:.Apple Computer: CoreAudio Utility Classes v2.0..Notice: This software is present only on Mac OS X systems...Disclaimer: IMPORTANT: This Apple software is supplied to you by Apple.Inc. ("Apple") in consideration of your agreement to the following.terms, and your use, installation, modification or redistribution of.this Apple software constitutes acceptance of these terms. If you do.not agree with these terms, please do not use, install, modify or.redistribute this Apple software...In consideration of your agreement to abide by the following terms, and.subject to these terms, Apple grants you a personal, non-exclusive.license, under Apple's copyrights in this original Apple software (the."Apple Software"), to use, reproduce, modify and redistribute the Apple.Software, with or without modifications, in source and/or binary
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Unicode text, UTF-8 text
    Category:dropped
    Size (bytes):153824
    Entropy (8bit):5.0228528661795355
    Encrypted:false
    SSDEEP:3072:Yj33DuJ8sY5sPfqN7amC35q2Fr4NZ1G8OAN6CflxDcw+4oHHZZvcm9lHNhJDXG85:HqN2p55O5cw+4oxHPN3Rj
    MD5:6EC6AB60B31FCFD0011C79DD90A9BDFE
    SHA1:B83C3F32261DE3E48CCD20614A11E066B1EC9027
    SHA-256:3114FC257CFF7E538C07E5CAE90FE53766725EFE7746614E4437695A0A89138A
    SHA-512:0F0AE546EFECFC915838ED704889FAEF30DCED7A374091EC1E3FE651A474FCA77363B02D9370C21AAA487900763001FACE181238D4F691039A657AD0DDC698D4
    Malicious:false
    Reputation:low
    Preview:DO NOT TRANSLATE OR LOCALIZE..-----------------------------..%% This notice is provided with respect to ASM Bytecode Manipulation .Framework v5.0.3, which may be included with JRE 8, and JDK 8, and .OpenJDK 8...--- begin of LICENSE ---..Copyright (c) 2000-2011 France T.l.com.All rights reserved...Redistribution and use in source and binary forms, with or without.modification, are permitted provided that the following conditions.are met:..1. Redistributions of source code must retain the above copyright. notice, this list of conditions and the following disclaimer...2. Redistributions in binary form must reproduce the above copyright. notice, this list of conditions and the following disclaimer in the. documentation and/or other materials provided with the distribution...3. Neither the name of the copyright holders nor the names of its. contributors may be used to endorse or promote products derived from. this software without specific prior written permission...THIS SOFTWAR
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:ASCII text
    Category:dropped
    Size (bytes):157063
    Entropy (8bit):5.019059096479156
    Encrypted:false
    SSDEEP:3072:8j33DuS8sY5sPfqN7amC3Xs4NZ1G8OANn16XBPb3Ucw+4oHmZ/bcm9GdNhJ75e5t:MqN2pZy3Ucw+4o7dfCRp
    MD5:37E7AAD9C0F238DF220F5F70707C6341
    SHA1:617AD547D6BE8756C859E2770D5301044B0BE505
    SHA-256:CA07B5A7569D691A0C717B6844440AEF29706BD81A787C989D95BA352B390F47
    SHA-512:779DDBE62E28628A6A64B62409377BFCC4AFBEF917C57EC01F1BEDA2849890D1FC182620F46A231D5DA6850B2DAC52D67BAEC5C02215F309CDEC3D5BD3DF5FE2
    Malicious:false
    Reputation:low
    Preview:DO NOT TRANSLATE OR LOCALIZE..-----------------------------..%% This notice is provided with respect to ASM Bytecode Manipulation .Framework v5.0.3, which may be included with JRE 8, and JDK 8, and .OpenJDK 8...--- begin of LICENSE ---..Copyright (c) 2000-2011 France T??l??com.All rights reserved...Redistribution and use in source and binary forms, with or without.modification, are permitted provided that the following conditions.are met:..1. Redistributions of source code must retain the above copyright. notice, this list of conditions and the following disclaimer...2. Redistributions in binary form must reproduce the above copyright. notice, this list of conditions and the following disclaimer in the. documentation and/or other materials provided with the distribution...3. Neither the name of the copyright holders nor the names of its. contributors may be used to endorse or promote products derived from. this software without specific prior written permission...THIS SOFTWAR
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:HTML document, ASCII text
    Category:dropped
    Size (bytes):955
    Entropy (8bit):5.096095653697231
    Encrypted:false
    SSDEEP:24:INMTdqcxtK4jXQ5VaJ2gjQo4pDW94m/DJn:TTdqIK4jXjJdso4V7E
    MD5:810EF9BE9BDF09983D41E244A6179A20
    SHA1:D98AE54F03DAC87419ABC19B97E315830C2DA55F
    SHA-256:DB34008B34B4BC3177436E71BD01557D45D52E710699758AB227E5FEC7FFADB8
    SHA-512:3DA4DE8D7A7D037AA64F9A771C9AEB743D43839294ACB773CECB2BA9B0C869CF3D7F3E3BC41D803238F297647E85ABD43F596F1C2DF46579EC0A34263744E406
    Malicious:false
    Reputation:low
    Preview:<html>.<head>.<title>.Welcome to the Java(TM) Platform.</title>.</head>.<body>..<h2>Welcome to the Java<SUP><FONT SIZE=-2>TM</FONT></SUP> Platform</h2>.<p> Welcome to the Java<SUP><FONT SIZE=-2>TM</FONT></SUP> Standard Edition Runtime . Environment. This provides complete runtime support for Java applications. .<p> The runtime environment includes the Java<SUP><FONT SIZE=-2>TM</FONT></SUP> . Plug-in product which supports the Java environment inside web browsers. .<h3>References</h3>.<p>.See the <a href="http://download.oracle.com/javase/7/docs/technotes/guides/plugin/">Java Plug-in</a> product.documentation for more information on using the Java Plug-in product..<p> See the <a href=."http://www.oracle.com/technetwork/java/javase/overview/".>Java Platform</a> web site for . more information on the Java Platform. .<hr>.<font size="-2">.Copyright (c) 2006, 2018, Oracle and/or its affiliates. All rights reserved..</font>.<p>.</body>.</html>.
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PE32+ executable (console) x86-64, for MS Windows
    Category:dropped
    Size (bytes):23008
    Entropy (8bit):6.636944311629935
    Encrypted:false
    SSDEEP:384:lbcl+NNUbmjifg4eE6UZSf+VIYinvyqPxh8E9VF0NyHaj3:dcgPtmfgNE6z/Yin3PxWEVs3
    MD5:7EB6BE4546D4F9CE1D2CE90FA9DC6400
    SHA1:5223D3F351280745812B36ACFE6813DB477A363A
    SHA-256:C1F3A45C8639ADA38A74F1AC3D369612CDB910FA9D941CF03003DD6CC31594BE
    SHA-512:50C4A96774A897F4D7B92BDEC01CE68DDD0C8E25762CD85DB7A7B9AF7D043604D61BD0F6DEF9B473B5E2A73FC480A10C8641D924006A43097AC235BB545653AF
    Malicious:false
    Antivirus:
    • Antivirus: ReversingLabs, Detection: 0%
    Reputation:low
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.............~...~...~..-....~......~......~......~.~L....~.......~.~L....~......~.~L....~.Rich..~.........................PE..d...>..d.........."............................@.............................p.......?....`..................................................$..P....P..T....@.......*.../...`..0....!..8............................"..p............ ..H............................text............................... ..`.rdata....... ......................@..@.data........0......................@....pdata.......@......................@..@.rsrc...T....P......................@..@.reloc..0....`.......(..............@..B........................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PE32+ executable (console) x86-64, for MS Windows
    Category:dropped
    Size (bytes):23008
    Entropy (8bit):6.645082142658608
    Encrypted:false
    SSDEEP:384:2yqDy0mqBGMi5ECeEaeZSf+VIYinvyYhPxh8E9VF0NyHlL:2yqDlVGV5EvEad/YinBPxWEVN
    MD5:5AAAFB8162899F2232A587827340D50F
    SHA1:EA9BB576BEEF5C518519494D2E565C5C951AD162
    SHA-256:D66BF245FA4A4D49E79D0CAD7A206AF705A7292580D032889835514A08942A4F
    SHA-512:583DDCF9D86BB46119A0EE39D18EC90E1FBB5679C202E6936D06C931E064E7A8F8A16B3A9F2784A6254AC5D10F816797200B3EB2F3C2C731029FCECC42887B3B
    Malicious:false
    Antivirus:
    • Antivirus: ReversingLabs, Detection: 0%
    Reputation:low
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.............~...~...~..-....~......~......~......~.~L....~.......~.~L....~......~.~L....~.Rich..~.........................PE..d...>..d.........."............................@.............................p......)=....`..................................................$..P....P..4....@.......*.../...`..0....!..8............................"..p............ ..H............................text............................... ..`.rdata....... ......................@..@.data........0......................@....pdata.......@......................@..@.rsrc...4....P......................@..@.reloc..0....`.......(..............@..B........................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PE32+ executable (console) x86-64, for MS Windows
    Category:dropped
    Size (bytes):23008
    Entropy (8bit):6.639969797680437
    Encrypted:false
    SSDEEP:384:QHLsl+NNS5cETkUibDN8eEfVZSf+VIYinvy+9Pxh8E9VF0NyH76:wsgPe5TkdbDN5Ef8/YinLPxWEVG
    MD5:4F9550E5F4644B764050F7C8149B769E
    SHA1:62C7C56B1157D1400F6BF6809D7BB5CBB4BF8342
    SHA-256:E8B9A838022C299CA975055C6DA410C23DB2CC6EFB85BF217A8917223AB7E8BC
    SHA-512:8DDD77CAFFACFD4093860AFB0008327706BBA07045ADC176E135CC49C5212DA2E54217B249CD423D44146A75C117ADDFE6D28FABE786C4652FB4BBFBFE3C2DE8
    Malicious:false
    Antivirus:
    • Antivirus: ReversingLabs, Detection: 0%
    Reputation:low
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.............~...~...~..-....~......~......~......~.~L....~.......~.~L....~......~.~L....~.Rich..~.........................PE..d...>..d.........."............................@.............................p.......u....`..................................................$..P....P..@....@.......*.../...`..0....!..8............................"..p............ ..H............................text............................... ..`.rdata....... ......................@..@.data........0......................@....pdata.......@......................@..@.rsrc...@....P......................@..@.reloc..0....`.......(..............@..B........................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PE32+ executable (console) x86-64, for MS Windows
    Category:dropped
    Size (bytes):23008
    Entropy (8bit):6.642612167595762
    Encrypted:false
    SSDEEP:384:eiyqDy0SbCGMiqyROeEISZSf+VIYinvyYyPxh8E9VF0NyHWZb:5yqDl/GVjRTEIZ/YinByPxWEV8
    MD5:B040388CB3B406405132A1449BAC8ACA
    SHA1:DF92129A0429CAB7C09393F5E18D21ADD66F6D98
    SHA-256:22E12450C1C03081FCFE488E4AAE6A1B2BAAF463081AF4AEF6136B65E5D0FF85
    SHA-512:88D09E089C20C5C76BEBD34722CF2663B2DD0862D9B65860C36E7548EEB60D013602B2A92082CF0564E93C0BE56E483CA6E035B71A43874565070D22320E7699
    Malicious:false
    Antivirus:
    • Antivirus: ReversingLabs, Detection: 0%
    Reputation:low
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.............~...~...~..-....~......~......~......~.~L....~.......~.~L....~......~.~L....~.Rich..~.........................PE..d...>..d.........."............................@.............................p.......P....`..................................................$..P....P..,....@.......*.../...`..0....!..8............................"..p............ ..H............................text............................... ..`.rdata....... ......................@..@.data........0......................@....pdata.......@......................@..@.rsrc...,....P......................@..@.reloc..0....`.......(..............@..B........................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PE32+ executable (console) x86-64, for MS Windows
    Category:dropped
    Size (bytes):23008
    Entropy (8bit):6.645636621643758
    Encrypted:false
    SSDEEP:384:tDUl+NNvZGfliWyfQeEH0ZSf+VIYinvyyBPxh8E9VF0NyWuz:9UgPI0/flEz/YinfPxWEQW
    MD5:772BAD737CCA7526184FABED220D2F87
    SHA1:542D5A47CC3B37FA4C0D630013D21D52D423BD26
    SHA-256:D42607F39D7FCE7D96846CD6EBA0273539D48CD6D6D734C89B3119144325BA3C
    SHA-512:789EF0C8108B19B0BF4C295EDE66C3B8A33D3E37C0DFAA3ECDAFAB608225FCB13C4BC7D13F15094C8616E1E0974302B234D094CDB859932FDB45F899014BC11A
    Malicious:false
    Antivirus:
    • Antivirus: ReversingLabs, Detection: 0%
    Reputation:low
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.............~...~...~..-....~......~......~......~.~L....~.......~.~L....~......~.~L....~.Rich..~.........................PE..d...>..d.........."............................@.............................p............`..................................................$..P....P..,....@.......*.../...`..0....!..8............................"..p............ ..H............................text............................... ..`.rdata....... ......................@..@.data........0......................@....pdata.......@......................@..@.rsrc...,....P......................@..@.reloc..0....`.......(..............@..B........................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PE32+ executable (console) x86-64, for MS Windows
    Category:dropped
    Size (bytes):23008
    Entropy (8bit):6.640792809075622
    Encrypted:false
    SSDEEP:384:gj0l+NNWTWrUjiW3KIeE9dZSf+VIYinvyUR4Pxh8E9VF0NyI4/4:i0gPxUmaK9Eq/YinNR4PxWEae4
    MD5:5653BE24EFCB4FD8C9C683459842B541
    SHA1:E90E09F6496E3B237E4C685E9558A66C161BE863
    SHA-256:0C7370943885EF82CB9F785ED285ADC0B4C1FC893BA543A1A7294CAFD55C79E8
    SHA-512:96E221DDCBA6EBD59DB2A927894BAD93708EAA12DE7C56B3D9A6004EB4CE047A63BD48E59549E1599485F51EF49FDA0FC500BAC6E3FC67ECE0CBC18AF049129F
    Malicious:false
    Antivirus:
    • Antivirus: ReversingLabs, Detection: 0%
    Reputation:low
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.............~...~...~..-....~......~......~......~.~L....~.......~.~L....~......~.~L....~.Rich..~.........................PE..d...>..d.........."............................@.............................p......h.....`..................................................$..P....P..,....@.......*.../...`..0....!..8............................"..p............ ..H............................text............................... ..`.rdata....... ......................@..@.data........0......................@....pdata.......@......................@..@.rsrc...,....P......................@..@.reloc..0....`.......(..............@..B........................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PE32+ executable (console) x86-64, for MS Windows
    Category:dropped
    Size (bytes):23008
    Entropy (8bit):6.641631256711606
    Encrypted:false
    SSDEEP:384:JEraVN+lDVjiT3KO/eEkZSf+VIYinvyA6Pxh8E9VF0NyF61:irm+3mTKOWED/Yinj6PxWErI
    MD5:08C3994278A24FD5CA99EC88AF6C0B0A
    SHA1:060139FE9086446D9E02798E16473314D2D6B920
    SHA-256:A5D4A3FE9573C3BA883C66A542D515B18CEEC095EBA71857498BA3A0455999DE
    SHA-512:3E9EF34A505309A5B69AF970F89E1CA720B2F25881603A11B1A5A1AC9F3D19AD9F802CFEE3B1C5139EA3462CD0E902B292FCB5EA2D585CFFE15F843267BA5A2F
    Malicious:false
    Antivirus:
    • Antivirus: ReversingLabs, Detection: 0%
    Reputation:low
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.............~...~...~..-....~......~......~......~.~L....~.......~.~L....~......~.~L....~.Rich..~.........................PE..d...>..d.........."............................@.............................p.......*....`..................................................$..P....P..,....@.......*.../...`..0....!..8............................"..p............ ..H............................text............................... ..`.rdata....... ......................@..@.data........0......................@....pdata.......@......................@..@.rsrc...,....P......................@..@.reloc..0....`.......(..............@..B........................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PE32+ executable (console) x86-64, for MS Windows
    Category:dropped
    Size (bytes):23008
    Entropy (8bit):6.664072311571862
    Encrypted:false
    SSDEEP:384:SbzlyFeFnmKiD3OaeEBZSf+VIYinvy6Pxh8E9VF0Ny6eZ:S/lYeNmnjOHEQ/YintPxWEou
    MD5:7B3BEE30444414ADAF67EF5DEB8F61D6
    SHA1:705DC88D2BBD784AEE572F2BCCF4198780D0A3E5
    SHA-256:A37A7E6228AF298550E91D3FB1AACB03E75A31F7B4C3BBCD1D5B78F995DB6333
    SHA-512:160261DDD93242BA57A3BD2EA468BA8E3BAA75D52368DD91243FC792A80B668B2803EA4F4E18D0A107F28F471F40D80B1C1FF361884F99B0B8655DC088916689
    Malicious:false
    Antivirus:
    • Antivirus: ReversingLabs, Detection: 0%
    Reputation:low
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.............~...~...~..-....~......~......~......~.~L....~.......~.~L....~......~.~L....~.Rich..~.........................PE..d...>..d.........."............................@.............................p.......r....`..................................................%..P....P..,....@.......*.../...`..4....!..8........................... #..p............ ..H............................text............................... ..`.rdata..&.... ......................@..@.data........0......................@....pdata.......@......................@..@.rsrc...,....P......................@..@.reloc..4....`.......(..............@..B........................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PE32+ executable (console) x86-64, for MS Windows
    Category:dropped
    Size (bytes):23008
    Entropy (8bit):6.6392938575138345
    Encrypted:false
    SSDEEP:384:Pj0l+NNqZ0ziTdyeElZSf+VIYinvyV6Pxh8E9VF0NyWgK:70gPPWTd/EM/YinvPxWEQj
    MD5:169DCE0BB61EE143FE96D7CA491C073B
    SHA1:3125F6969BB253A2A38695D900AF6B6EB5845FA7
    SHA-256:2A625E11A46928B50333C4D8E64E6433246F3FB9B57B7A507F5160F02E69ECFB
    SHA-512:610E879026BAE6AA26200F370CA06B176CFBE29C4BC5AEA703B2E4C804FAAC9D25CC0DB2B0FC89F791339D5F5E85512F9049FD9AFFBC0DA1B1A66BE6F473583C
    Malicious:false
    Antivirus:
    • Antivirus: ReversingLabs, Detection: 0%
    Reputation:low
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.............~...~...~..-....~......~......~......~.~L....~.......~.~L....~......~.~L....~.Rich..~.........................PE..d...>..d.........."............................@.............................p......v.....`..................................................$..P....P.. ....@.......*.../...`..0....!..8............................"..p............ ..H............................text............................... ..`.rdata....... ......................@..@.data........0......................@....pdata.......@......................@..@.rsrc... ....P......................@..@.reloc..0....`.......(..............@..B........................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PE32+ executable (console) x86-64, for MS Windows
    Category:dropped
    Size (bytes):23008
    Entropy (8bit):6.639136764254076
    Encrypted:false
    SSDEEP:384:MLsl+NN2EuUixGEeE5ZSf+VIYinvytXDNPxh8E9VF0NyLBLGLq:msgPEdxGhEI/YinEXDNPxWElb
    MD5:9289C42F4C171EEA7FE78EA7201EE9FD
    SHA1:34C181CE2BA8B4D4136C8FC7753FF1366A299AC6
    SHA-256:AEA89815A49AFBA3A4D2854539C5B538FF8ECBFC91014668E6A26A2B6178BB26
    SHA-512:3EF780238CCC96B428E4CC646075CEBDE08F01F205CCE999F3FE4B4C908738E6D564E21F2F277EB44192FE75A4748F0D7A9824A42D35E724BB12D6F4D60C3E80
    Malicious:false
    Antivirus:
    • Antivirus: ReversingLabs, Detection: 0%
    Reputation:low
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.............~...~...~..-....~......~......~......~.~L....~.......~.~L....~......~.~L....~.Rich..~.........................PE..d...>..d.........."............................@.............................p............`..................................................$..P....P..H....@.......*.../...`..0....!..8............................"..p............ ..H............................text............................... ..`.rdata....... ......................@..@.data........0......................@....pdata.......@......................@..@.rsrc...H....P......................@..@.reloc..0....`.......(..............@..B........................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PE32+ executable (console) x86-64, for MS Windows
    Category:dropped
    Size (bytes):23008
    Entropy (8bit):6.639969797680437
    Encrypted:false
    SSDEEP:384:QHLsl+NNS5cETkUibDN8eEfVZSf+VIYinvy+9Pxh8E9VF0NyH76:wsgPe5TkdbDN5Ef8/YinLPxWEVG
    MD5:4F9550E5F4644B764050F7C8149B769E
    SHA1:62C7C56B1157D1400F6BF6809D7BB5CBB4BF8342
    SHA-256:E8B9A838022C299CA975055C6DA410C23DB2CC6EFB85BF217A8917223AB7E8BC
    SHA-512:8DDD77CAFFACFD4093860AFB0008327706BBA07045ADC176E135CC49C5212DA2E54217B249CD423D44146A75C117ADDFE6D28FABE786C4652FB4BBFBFE3C2DE8
    Malicious:false
    Antivirus:
    • Antivirus: ReversingLabs, Detection: 0%
    Reputation:low
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.............~...~...~..-....~......~......~......~.~L....~.......~.~L....~......~.~L....~.Rich..~.........................PE..d...>..d.........."............................@.............................p.......u....`..................................................$..P....P..@....@.......*.../...`..0....!..8............................"..p............ ..H............................text............................... ..`.rdata....... ......................@..@.data........0......................@....pdata.......@......................@..@.rsrc...@....P......................@..@.reloc..0....`.......(..............@..B........................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PE32+ executable (console) x86-64, for MS Windows
    Category:dropped
    Size (bytes):23008
    Entropy (8bit):6.645082142658608
    Encrypted:false
    SSDEEP:384:2yqDy0mqBGMi5ECeEaeZSf+VIYinvyYhPxh8E9VF0NyHlL:2yqDlVGV5EvEad/YinBPxWEVN
    MD5:5AAAFB8162899F2232A587827340D50F
    SHA1:EA9BB576BEEF5C518519494D2E565C5C951AD162
    SHA-256:D66BF245FA4A4D49E79D0CAD7A206AF705A7292580D032889835514A08942A4F
    SHA-512:583DDCF9D86BB46119A0EE39D18EC90E1FBB5679C202E6936D06C931E064E7A8F8A16B3A9F2784A6254AC5D10F816797200B3EB2F3C2C731029FCECC42887B3B
    Malicious:false
    Antivirus:
    • Antivirus: ReversingLabs, Detection: 0%
    Reputation:low
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.............~...~...~..-....~......~......~......~.~L....~.......~.~L....~......~.~L....~.Rich..~.........................PE..d...>..d.........."............................@.............................p......)=....`..................................................$..P....P..4....@.......*.../...`..0....!..8............................"..p............ ..H............................text............................... ..`.rdata....... ......................@..@.data........0......................@....pdata.......@......................@..@.rsrc...4....P......................@..@.reloc..0....`.......(..............@..B........................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PE32+ executable (console) x86-64, for MS Windows
    Category:dropped
    Size (bytes):23008
    Entropy (8bit):6.6678172127000845
    Encrypted:false
    SSDEEP:384:jbzfCFelnKigemeEIZSf+VIYinvyw4whPxh8E9VF0NyIijF:j/foeFngeLEv/Yin34whPxWEae
    MD5:0B1CBD4C59E78A341B5FDBD33F4DE097
    SHA1:E2CD9214BF3B9FBC147C87F679B6727DEE232340
    SHA-256:C1AF81366E6B62CB4708952F6E4012F0668EE1E156E143DCBE94D22F9EEB57A9
    SHA-512:251C37EB7C6174472F08EF7D7E075AD09B90E7C329D6C67CD36392CDF1BBA514DD67D3E5AD94FFA394A52A52DFD1AB36B30312E4D9ED0E6367D7EF0D79E4B818
    Malicious:false
    Antivirus:
    • Antivirus: ReversingLabs, Detection: 0%
    Reputation:low
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.............~...~...~..-....~......~......~......~.~L....~.......~.~L....~......~.~L....~.Rich..~.........................PE..d...>..d.........."............................@.............................p............`..................................................%..P....P..4....@.......*.../...`..4....!..8........................... #..p............ ..H............................text............................... ..`.rdata..&.... ......................@..@.data........0......................@....pdata.......@......................@..@.rsrc...4....P......................@..@.reloc..4....`.......(..............@..B........................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PE32+ executable (console) x86-64, for MS Windows
    Category:dropped
    Size (bytes):23008
    Entropy (8bit):6.666393011633717
    Encrypted:false
    SSDEEP:384:xbzbyFeFJKiDyoGeEq6ZSf+VIYinvylPxh8E9VF0NyL8d1:x/bYePneorEqB/Yin0PxWElA
    MD5:6DE743CCEC2907C4CE417576BBB70202
    SHA1:8B02875D569CB51C37467B9180D77D83293D2D4D
    SHA-256:40C104F7C8ED0061F4C867984AB3418EFDA2BCEB8B53CA23AE5A3CFBE46786CD
    SHA-512:7185D918440584264036A0B5639F5673B147C7305FC25D3F0CBBA031F565F6DD5CA1748FA7995A6F571D33E8AE352F095DEA71EEBA268CD4C3413DF4F49D8732
    Malicious:false
    Antivirus:
    • Antivirus: ReversingLabs, Detection: 0%
    Reputation:low
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.............~...~...~..-....~......~......~......~.~L....~.......~.~L....~......~.~L....~.Rich..~.........................PE..d...>..d.........."............................@.............................p............`..................................................%..P....P..,....@.......*.../...`..4....!..8........................... #..p............ ..H............................text............................... ..`.rdata..&.... ......................@..@.data........0......................@....pdata.......@......................@..@.rsrc...,....P......................@..@.reloc..4....`.......(..............@..B........................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PE32+ executable (console) x86-64, for MS Windows
    Category:dropped
    Size (bytes):23008
    Entropy (8bit):6.641591593459454
    Encrypted:false
    SSDEEP:384:rEraVN+lLkjiT3GYeENyZSf+VIYinvyM75Pxh8E9VF0NyXn/u:Yrm+KmTGtE//YinDPxWEp/u
    MD5:A7DF947ACED57CA801D88FFC7176EE04
    SHA1:2903B259F2EF78CE7E5524685194260B20830B04
    SHA-256:B1FA8B87AAFA101E8D391F404BD10FA5754866C46AEDB8D69F5BAF7B686ACB75
    SHA-512:09F333E794C2A23906D3702A0D686C1EA1880333ADAD859E58927D2F884FCD309BBDAB69BFE1B2A2D80AAE61F1E49BCD2F5FCB71F044266503AA807562E04FD5
    Malicious:false
    Antivirus:
    • Antivirus: ReversingLabs, Detection: 0%
    Reputation:low
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.............~...~...~..-....~......~......~......~.~L....~.......~.~L....~......~.~L....~.Rich..~.........................PE..d...>..d.........."............................@.............................p............`..................................................$..P....P..,....@.......*.../...`..0....!..8............................"..p............ ..H............................text............................... ..`.rdata....... ......................@..@.data........0......................@....pdata.......@......................@..@.rsrc...,....P......................@..@.reloc..0....`.......(..............@..B........................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PE32+ executable (console) x86-64, for MS Windows
    Category:dropped
    Size (bytes):23008
    Entropy (8bit):6.636944311629935
    Encrypted:false
    SSDEEP:384:lbcl+NNUbmjifg4eE6UZSf+VIYinvyqPxh8E9VF0NyHaj3:dcgPtmfgNE6z/Yin3PxWEVs3
    MD5:7EB6BE4546D4F9CE1D2CE90FA9DC6400
    SHA1:5223D3F351280745812B36ACFE6813DB477A363A
    SHA-256:C1F3A45C8639ADA38A74F1AC3D369612CDB910FA9D941CF03003DD6CC31594BE
    SHA-512:50C4A96774A897F4D7B92BDEC01CE68DDD0C8E25762CD85DB7A7B9AF7D043604D61BD0F6DEF9B473B5E2A73FC480A10C8641D924006A43097AC235BB545653AF
    Malicious:false
    Antivirus:
    • Antivirus: ReversingLabs, Detection: 0%
    Reputation:low
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.............~...~...~..-....~......~......~......~.~L....~.......~.~L....~......~.~L....~.Rich..~.........................PE..d...>..d.........."............................@.............................p.......?....`..................................................$..P....P..T....@.......*.../...`..0....!..8............................"..p............ ..H............................text............................... ..`.rdata....... ......................@..@.data........0......................@....pdata.......@......................@..@.rsrc...T....P......................@..@.reloc..0....`.......(..............@..B........................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PE32+ executable (console) x86-64, for MS Windows
    Category:dropped
    Size (bytes):160352
    Entropy (8bit):6.3910842429106385
    Encrypted:false
    SSDEEP:3072:bkoaZzgXftbxm3sHLzJUIioULXVNJVs66yN/Dxi:bueUcHLWIJ6TNo
    MD5:EACCFEC82BDB4EE78333E40D6CEFF792
    SHA1:EB5B650AF53EFEA15F2724490C396038C7654DB6
    SHA-256:701BB1D21C8F73A8E385209405A8C62BB90DBB2110A7696E11C3555B454915BC
    SHA-512:30D61F38E6FB872530D10902D983986D1B3E1117F15C3007C60231CCA945FF89E56A21E7C362CEAB461ED42B014721C0A9CEBC18A0FAB8FDBF37E24AAC2F9779
    Malicious:false
    Antivirus:
    • Antivirus: ReversingLabs, Detection: 0%
    Reputation:low
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......%.O#a.!pa.!pa.!p..%qk.!p.."qd.!p..$q.!p3.%qq.!p3."qh.!p3.$qH.!p.. qd.!pa. p..!p..$q`.!p...p`.!p..#q`.!pRicha.!p................PE..d......d.........."......^...........<.........@..........................................`.....................................................<....`..D....@.......>..`4...p..\....................................................p...............................text....].......^.................. ..`.rdata.......p.......b..............@..@.data...h.... ......................@....pdata.......@......................@..@.rsrc...D....`......................@..@.reloc..\....p.......6..............@..B................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PE32+ executable (console) x86-64, for MS Windows
    Category:dropped
    Size (bytes):23008
    Entropy (8bit):6.643081216941077
    Encrypted:false
    SSDEEP:384:Rj0l+NNkSvjiWybUeEEKZSf+VIYinvym9Pxh8E9VF0Ny6o5S:R0gPtm/bREER/Yin/PxWEoAS
    MD5:AB5A1EB045022697E836FB4EA44901B5
    SHA1:847241C55F7F369B3CD5DC9CB6F7C37BD2AC30AA
    SHA-256:4535CAA6F3EED479ED695F23A0ADCBA9914FCD6409B86782DD6C066ACB7BC418
    SHA-512:35C8CD2E7952195E6B293A7A388DECE4282ED2B7F20D9B94595E81CBE00C640412AB624CD572BBDB2F0DF137D2B401DDA43C6C88648BF237900DC57E88E765AE
    Malicious:false
    Antivirus:
    • Antivirus: ReversingLabs, Detection: 0%
    Reputation:low
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.............~...~...~..-....~......~......~......~.~L....~.......~.~L....~......~.~L....~.Rich..~.........................PE..d...>..d.........."............................@.............................p.......G....`..................................................$..P....P..,....@.......*.../...`..0....!..8............................"..p............ ..H............................text............................... ..`.rdata....... ......................@..@.data........0......................@....pdata.......@......................@..@.rsrc...,....P......................@..@.reloc..0....`.......(..............@..B........................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PE32+ executable (console) x86-64, for MS Windows
    Category:dropped
    Size (bytes):160352
    Entropy (8bit):6.391343023203998
    Encrypted:false
    SSDEEP:3072:EkoaZzgXftbxm3sHLzJUIioULXVNJVs66yE/9xP:EueUcHLWIJ6TEH
    MD5:2787E8A4A1F9EF0FD4BE75EDA4B5F2E1
    SHA1:CB9E9EFFF84320C509165468BDB8B4DDC4CFE631
    SHA-256:49E0CFEAFDAB053D22134388CDC734CF88CCBBCA79799FF59C90C36D05AA3E0F
    SHA-512:BBB99FCBCE326D665028287C51BF40D511701EF7E6BDF299D327C7A2C15358849A25920AF3817C27BA14D1804F520FB51D230E44488C9A98810264611E2111E3
    Malicious:false
    Antivirus:
    • Antivirus: ReversingLabs, Detection: 0%
    Reputation:low
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......%.O#a.!pa.!pa.!p..%qk.!p.."qd.!p..$q.!p3.%qq.!p3."qh.!p3.$qH.!p.. qd.!pa. p..!p..$q`.!p...p`.!p..#q`.!pRicha.!p................PE..d......d.........."......^...........<.........@..........................................`.....................................................<....`..D....@.......>..`4...p..\....................................................p...............................text....].......^.................. ..`.rdata.......p.......b..............@..@.data...h.... ......................@....pdata.......@......................@..@.rsrc...D....`......................@..@.reloc..\....p.......6..............@..B................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PE32+ executable (console) x86-64, for MS Windows
    Category:dropped
    Size (bytes):23008
    Entropy (8bit):6.643061217808763
    Encrypted:false
    SSDEEP:384:0ysl+NNqQjzirYIeE2IZSf+VIYinvyhf+RbPxh8E9VF0NyFJ5S0:HsgPRWrY9E2v/Yink+RbPxWEr7S0
    MD5:1B53F35AA2503BA75D491ED5EEC9BE94
    SHA1:629876859CCE455A22DA1689B9D2AECA33E8C71F
    SHA-256:23F703B8AC7B32CE78678432FBD704063F3767E84EA731C3B7FF69E6C7816CD8
    SHA-512:BC85C064F27068FC40958F3FE6180650CD5851ED9EBC3D40AE2E32B92F92AB7D0A3B0A5ADC8387AF328F537C5F247EC494A72ED23E0225E7D2A82DF840D1B632
    Malicious:false
    Antivirus:
    • Antivirus: ReversingLabs, Detection: 0%
    Reputation:low
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.............~...~...~..-....~......~......~......~.~L....~.......~.~L....~......~.~L....~.Rich..~.........................PE..d...>..d.........."............................@.............................p............`..................................................$..P....P.. ....@.......*.../...`..0....!..8............................"..p............ ..H............................text............................... ..`.rdata....... ......................@..@.data........0......................@....pdata.......@......................@..@.rsrc... ....P......................@..@.reloc..0....`.......(..............@..B........................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PE32+ executable (console) x86-64, for MS Windows
    Category:dropped
    Size (bytes):232136
    Entropy (8bit):6.609986425638662
    Encrypted:false
    SSDEEP:6144:T8CFPz4JnbQsXT2cDnP5wgbG8YPu7k/jilL:ThPzWncs/nNBC7ilL
    MD5:0C1642BB54BD4ED8F283C7C5523376F4
    SHA1:1CBA8AED2C201DCBD76ED2AA0F0053DC310C727A
    SHA-256:FDC59B0002D1ED9314739ED97200C743A63E97C4D66ED1EBC9A35F483E50E4E3
    SHA-512:F900BAFC02566C63927562233AD4C24DBB5CE7D3D26C3E8AC0D5B202A8E6B68B1218FAEB32D10DAACF0997CE2508FCABB1140D1D9C05894062C431F943179CF0
    Malicious:false
    Antivirus:
    • Antivirus: ReversingLabs, Detection: 0%
    Reputation:low
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........As.. .L. .L. .LH..L. .L.q.L. .L.q.Lw .L.q.L. .L...L. .L. .L. .Lc..L. .L.r.L. .Lc..L. .LRich. .L................PE..d...>..d.........."..........r......8..........@.....................................7....`.....................................................d.... ...o...........T...6..............8..............................p...............P............................text...,........................... ..`.rdata..............................@..@.data....?..........................@....pdata..............................@..@.rsrc....o... ...p..................@..@.reloc...............N..............@..B................................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PE32+ executable (GUI) x86-64, for MS Windows
    Category:dropped
    Size (bytes):232136
    Entropy (8bit):6.61624654726625
    Encrypted:false
    SSDEEP:6144:+dTu3dFROMWcTJQ/Tg2H+HVr5sVmmjYvBw7k/G3GTS:+d63dF/WaJm+1vKmO3GTS
    MD5:E368F0B1DBE52E21C6B5BC21C1771238
    SHA1:A5DA68B3E689238B0BDB87E10B1C59DAF80FC40C
    SHA-256:DD886B61D4C9DC80268E0E0D77A8DA7C92CF95602FCAD7025317B7988693C097
    SHA-512:9C584A283F8F35C1CDECA3C02E96104949294A1A5CA527B8D219243C9FCA7C20388A6B44175BC293B7E8C2577B9601EBD94882695F8FDB59DC0579FF32BDE14A
    Malicious:false
    Antivirus:
    • Antivirus: ReversingLabs, Detection: 0%
    Reputation:low
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......&...b..Mb..Mb..M.c.Mj..M$.<MN..M$.=M...M$..Mi..M.<.Mk..Mb..M...M.]=Mm..Mo..Mc..M.].Mc..MRichb..M........................PE..d...>..d.........."..........r.................@.........................................`.....................................................d.... ...o...........T...6..............8..............................p...............P............................text............................... ..`.rdata..............................@..@.data....?..........................@....pdata..............................@..@.rsrc....o... ...p..................@..@.reloc...............N..............@..B........................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PE32+ executable (console) x86-64, for MS Windows
    Category:dropped
    Size (bytes):23008
    Entropy (8bit):6.642890265358554
    Encrypted:false
    SSDEEP:384:Mj0l+NNgTxjiWyaaeEvZSf+VIYinvyZHPxh8E9VF0NyEEs:O0gPum/aHEO/Yin6PxWEuZ
    MD5:55C052D299BC93D17FAA9FD392A618D3
    SHA1:388B283804D319DEB044E84B03EF54A547BC11EE
    SHA-256:6B1A296142BF6DBB31EAB27CB5EE2B29D479BCC0A1BE3068D4B8C6F190039E64
    SHA-512:5DB26D3AC6A3FBFF92A98D901CECB77CC762A0768427363FD4BFBB4CB6F0BAA5191DE037F31EFDE2BEE4700E232E28052CB122945540E2E7BBF5A8BC781F066D
    Malicious:false
    Antivirus:
    • Antivirus: ReversingLabs, Detection: 0%
    Reputation:low
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.............~...~...~..-....~......~......~......~.~L....~.......~.~L....~......~.~L....~.Rich..~.........................PE..d...?..d.........."............................@.............................p.......>....`..................................................$..P....P..,....@.......*.../...`..0....!..8............................"..p............ ..H............................text............................... ..`.rdata....... ......................@..@.data........0......................@....pdata.......@......................@..@.rsrc...,....P......................@..@.reloc..0....`.......(..............@..B........................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PE32+ executable (console) x86-64, for MS Windows
    Category:dropped
    Size (bytes):23008
    Entropy (8bit):6.623949798062602
    Encrypted:false
    SSDEEP:384:RraktFJ6XHiQLGeEvZSf+VIYinvy45Pxh8E9VF0NyR+B:IswCQLrEO/YinL5PxWEzW
    MD5:273C7024504D3BE89E458CD531E4D889
    SHA1:D1CAFEA271CBD749557F977F3F2323EF1CC46B2F
    SHA-256:988C96F0A02AC05B4D8767FF80A62A15F50DC8F0912AFF7B19CBB76C491BEC76
    SHA-512:9D07821432071672824F7E6235872E61F26F2F2AA714DB1E228E237E43150B3F6FC2C40DD919F521883A31EC4D1C752735D38D9BC604DD54E54F5D019F2325AC
    Malicious:false
    Antivirus:
    • Antivirus: ReversingLabs, Detection: 0%
    Reputation:low
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.............~...~...~..-....~......~......~......~.~L....~.......~.~L....~......~.~L....~.Rich..~.........................PE..d...?..d.........."............................@.............................p......2.....`.................................................p$..P....P..@....@.......*.../...`..(....!..8...........................p"..p............ ..H............................text............................... ..`.rdata..~.... ......................@..@.data........0......................@....pdata.......@......................@..@.rsrc...@....P......................@..@.reloc..(....`.......(..............@..B........................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PE32+ executable (console) x86-64, for MS Windows
    Category:dropped
    Size (bytes):23008
    Entropy (8bit):6.641642167930154
    Encrypted:false
    SSDEEP:384:wEraVN+lamjiT3TkeEAZSf+VIYinvyEa3Pxh8E9VF0NyXBEJ:brm+9mTTBEn/YinSPxWEpSJ
    MD5:72D81F3ABFB5A346528A2FDCC112B10B
    SHA1:B4FD7C934F48964C737CB6A8CBF52D6A209EDC54
    SHA-256:9C66A4790C8DF5FCDD8D81C3A17E70F6B2E113CE93AFC80E6574539FE7B1BB03
    SHA-512:FA67EC07A03A73258D8FC58ACCA2E699A22CEABE0D2BFEDF8935F8E8422A89FA572F41ABFFFCB68CDD21AF008F435B3D9526ED6F517E4FBFD1EAA489F405F7C6
    Malicious:false
    Antivirus:
    • Antivirus: ReversingLabs, Detection: 0%
    Reputation:low
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.............~...~...~..-....~......~......~......~.~L....~.......~.~L....~......~.~L....~.Rich..~.........................PE..d...>..d.........."............................@.............................p......8.....`..................................................$..P....P..,....@.......*.../...`..0....!..8............................"..p............ ..H............................text............................... ..`.rdata....... ......................@..@.data........0......................@....pdata.......@......................@..@.rsrc...,....P......................@..@.reloc..0....`.......(..............@..B........................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PE32+ executable (console) x86-64, for MS Windows
    Category:dropped
    Size (bytes):23008
    Entropy (8bit):6.648477422294025
    Encrypted:false
    SSDEEP:384:XyqDy0FLx6iYuUeELGZSf+VIYinvy5mmAPxh8E9VF0NyFGSNA5:XyqDl73YuRELl/YinaAPxWEra
    MD5:156741C0D599E84D3F3B8302A1C37168
    SHA1:BE7F4CD7A3CA1174C6E703B68F5DB4CADC1F7E94
    SHA-256:B5F007BA6DFC30CA9A7C6B1540DE8814B457C24382C7799CF076BA461EA109E4
    SHA-512:A03A8F9526BE85868492143F54BAC8DAD979B250BE61B816D1A106BFEAF65BAA2ECD1041384C63CD11B3FC372A946CD598F04C32B2ED09F93897D9EE0519F53A
    Malicious:false
    Antivirus:
    • Antivirus: ReversingLabs, Detection: 0%
    Reputation:low
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.............~...~...~..-....~......~......~......~.~L....~.......~.~L....~......~.~L....~.Rich..~.........................PE..d...>..d.........."............................@.............................p............`..................................................$..P....P.. ....@.......*.../...`..0....!..8............................"..p............ ..H............................text............................... ..`.rdata....... ......................@..@.data........0......................@....pdata.......@......................@..@.rsrc... ....P......................@..@.reloc..0....`.......(..............@..B........................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PE32+ executable (console) x86-64, for MS Windows
    Category:dropped
    Size (bytes):23008
    Entropy (8bit):6.6470305356718855
    Encrypted:false
    SSDEEP:384:OyqDy0MR/3iqBy3eEHaZSf+VIYinvyCrePxh8E9VF0NyIimQVB:OyqDFOSqByOEHh/YinPrePxWEa3QB
    MD5:BE9842199AD5D3A99720B14352BB42D8
    SHA1:35FA57318E0F72B69F2CB73A0A32F70711291E06
    SHA-256:9F850E7C0368FF003BC757EA6BF513A76A26672EB5641932C9E0F11E4A242670
    SHA-512:9F95DB97A77490D79C077296BA8B044AFD7C3E92C028E534BCC8231611C831AE99A509E6875F7946CB3809CE9C2FF959B6ABB9CC77597CDB9FF4A1C28BDCF8E2
    Malicious:false
    Antivirus:
    • Antivirus: ReversingLabs, Detection: 0%
    Reputation:low
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.............~...~...~..-....~......~......~......~.~L....~.......~.~L....~......~.~L....~.Rich..~.........................PE..d...>..d.........."............................@.............................p......|.....`..................................................$..P....P..@....@.......*.../...`..0....!..8............................"..p............ ..H............................text............................... ..`.rdata....... ......................@..@.data........0......................@....pdata.......@......................@..@.rsrc...@....P......................@..@.reloc..0....`.......(..............@..B........................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PE32+ executable (console) x86-64, for MS Windows
    Category:dropped
    Size (bytes):23008
    Entropy (8bit):6.642384484002845
    Encrypted:false
    SSDEEP:384:bTEl+NNCxV6iexUeEAXZSf+VIYinvyZPxh8E9VF0NyR9oG:XEgP63exRE5/YinWPxWEzh
    MD5:439C7524787125479B00BBE939941CD8
    SHA1:C9ECFA124F5B8BD0CAAA15C45A986306736282B0
    SHA-256:D7CA9A6871455075F268F79A3F61802475E9523E4C751AC9314DD1D43E42253B
    SHA-512:9CC92175C870F192B944B1CB4C8E1214BDF33A6B54940C0F4A648B22D487CAE30038643E7563297DCF79A7378F7A02AE467EE92D24FD70C5FC2A1855C6CB81B1
    Malicious:false
    Antivirus:
    • Antivirus: ReversingLabs, Detection: 0%
    Reputation:low
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.............~...~...~..-....~......~......~......~.~L....~.......~.~L....~......~.~L....~.Rich..~.........................PE..d...>..d.........."............................@.............................p...........`..................................................$..P....P..@....@.......*.../...`..0....!..8............................"..p............ ..H............................text............................... ..`.rdata....... ......................@..@.data........0......................@....pdata.......@......................@..@.rsrc...@....P......................@..@.reloc..0....`.......(..............@..B........................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PE32+ executable (console) x86-64, for MS Windows
    Category:dropped
    Size (bytes):23008
    Entropy (8bit):6.645636621643758
    Encrypted:false
    SSDEEP:384:tDUl+NNvZGfliWyfQeEH0ZSf+VIYinvyyBPxh8E9VF0NyWuz:9UgPI0/flEz/YinfPxWEQW
    MD5:772BAD737CCA7526184FABED220D2F87
    SHA1:542D5A47CC3B37FA4C0D630013D21D52D423BD26
    SHA-256:D42607F39D7FCE7D96846CD6EBA0273539D48CD6D6D734C89B3119144325BA3C
    SHA-512:789EF0C8108B19B0BF4C295EDE66C3B8A33D3E37C0DFAA3ECDAFAB608225FCB13C4BC7D13F15094C8616E1E0974302B234D094CDB859932FDB45F899014BC11A
    Malicious:false
    Antivirus:
    • Antivirus: ReversingLabs, Detection: 0%
    Reputation:low
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.............~...~...~..-....~......~......~......~.~L....~.......~.~L....~......~.~L....~.Rich..~.........................PE..d...>..d.........."............................@.............................p............`..................................................$..P....P..,....@.......*.../...`..0....!..8............................"..p............ ..H............................text............................... ..`.rdata....... ......................@..@.data........0......................@....pdata.......@......................@..@.rsrc...,....P......................@..@.reloc..0....`.......(..............@..B........................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PE32+ executable (console) x86-64, for MS Windows
    Category:dropped
    Size (bytes):23008
    Entropy (8bit):6.641929452262611
    Encrypted:false
    SSDEEP:384:0j0l+NNqPHziTV4eEJUZSf+VIYinvyklkPxh8E9VF0NyLQyBra:m0gP2WTVNEJz/YinJkPxWEl/ra
    MD5:ACE76717268E5B2A12E9D65326532A0F
    SHA1:9D948D31C21EB8B78EFE18F0EE3E08E49B271693
    SHA-256:ACC31348B33805AE592F50D693F99534B4016F1DA57125FF370E4159E7739FBD
    SHA-512:DDD8662D6E03031EE9D5F60B86CB0B6FCF47DDB7690E91DC93222F6A989CACA4FFF415D9BB296D870F447503F82D9407C7248746A627D2E568B88BE09DB4C3B0
    Malicious:false
    Antivirus:
    • Antivirus: ReversingLabs, Detection: 0%
    Reputation:low
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.............~...~...~..-....~......~......~......~.~L....~.......~.~L....~......~.~L....~.Rich..~.........................PE..d...>..d.........."............................@.............................p......o.....`..................................................$..P....P.. ....@.......*.../...`..0....!..8............................"..p............ ..H............................text............................... ..`.rdata....... ......................@..@.data........0......................@....pdata.......@......................@..@.rsrc... ....P......................@..@.reloc..0....`.......(..............@..B........................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PE32+ executable (GUI) x86-64, for MS Windows
    Category:dropped
    Size (bytes):23008
    Entropy (8bit):6.704398152183226
    Encrypted:false
    SSDEEP:384:dn31SUNDMjwjEPpieEaZZSf+VIYinvyx0LdNPxh8E9VF0NyElS:dnlSWDZ4PpPEF/Yiny0dNPxWEuo
    MD5:2443A3844F99D19CD4D1F49C2D509466
    SHA1:551E1E56BF8DB00C3D129EFDA098B061865831C4
    SHA-256:3BA4A178F6B06C386CD04107E6B4FF1B856E296C3585C4F34DEB1AE3B3D2F56E
    SHA-512:D641A43950412C634A94D1671AD67C892E83FCE8BCA8A9671EFCDA6AB31E0F6C362FC193DF5A9910FF0FAC3AFA336BEEA4D977DED7E83B7FAFCF3D2CAF886786
    Malicious:false
    Antivirus:
    • Antivirus: ReversingLabs, Detection: 0%
    Reputation:low
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........P...>...>...>..-....>......>......>......>.~L....>...?...>.~L....>......>.~L....>.Rich..>.................PE..d...>..d.........."............................@.............................p............`..................................................%..P....P..@....@.......*.../...`..4....!..8............................#..p............ ..`............................text............................... ..`.rdata..`.... ......................@..@.data........0......................@....pdata.......@......................@..@.rsrc...@....P......................@..@.reloc..4....`.......(..............@..B................................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PE32+ executable (console) x86-64, for MS Windows
    Category:dropped
    Size (bytes):23008
    Entropy (8bit):6.640345372216805
    Encrypted:false
    SSDEEP:384:9EraVN+lDxjiT3eYeEyZSf+VIYinvyvPxh8E9VF0NyExC:Wrm+7mTetE5/YinIPxWEuM
    MD5:68D720575A8976EC17A084AA4B255600
    SHA1:4DC4DFF16449E1004F50648A3FCC0FE92A37D0F6
    SHA-256:DE90B3A863F979691AA5AB90D4B3F0AA3493639BADC8BB66BCBD6B383F667C80
    SHA-512:872F2E57FDFD2EB132D33066B208837C2D5A55F289BC2C6B66A58C4DD07C39286932C818FFCF7484A4C4F925F7E7F4CB5C24DF01548FBE83FAAEACABD5AC8AF0
    Malicious:false
    Antivirus:
    • Antivirus: ReversingLabs, Detection: 0%
    Reputation:low
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.............~...~...~..-....~......~......~......~.~L....~.......~.~L....~......~.~L....~.Rich..~.........................PE..d...>..d.........."............................@.............................p.......B....`..................................................$..P....P..,....@.......*.../...`..0....!..8............................"..p............ ..H............................text............................... ..`.rdata....... ......................@..@.data........0......................@....pdata.......@......................@..@.rsrc...,....P......................@..@.reloc..0....`.......(..............@..B........................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PE32+ executable (console) x86-64, for MS Windows
    Category:dropped
    Size (bytes):23008
    Entropy (8bit):6.642141954281721
    Encrypted:false
    SSDEEP:384:YEraVN+hZrji9mieEkfZSf+VIYinvy4p6XPxh8E9VF0NyXq6:Trm+7m9mPEJ/YinZp6XPxWEpl
    MD5:59A3EA22792064D203B5933DD542ED82
    SHA1:176BEF99C538726EA4D9D573CFC407AE6876C7C7
    SHA-256:18CB199560F4ACBFD8C4F6C4864EC9BE0622B0A2CC52B953D8D78F56F38B9311
    SHA-512:79E4C9A5EC224C3A685FE999C1D331281279383D76480E757668F463B096B5093B8DB04E394510716E9B404C38A98629DC15ACF8B8A1F595F52BA3906385510C
    Malicious:false
    Antivirus:
    • Antivirus: ReversingLabs, Detection: 0%
    Reputation:low
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.............~...~...~..-....~......~......~......~.~L....~.......~.~L....~......~.~L....~.Rich..~.........................PE..d...>..d.........."............................@.............................p.......K....`..................................................$..P....P..4....@.......*.../...`..0....!..8............................"..p............ ..H............................text............................... ..`.rdata....... ......................@..@.data........0......................@....pdata.......@......................@..@.rsrc...4....P......................@..@.reloc..0....`.......(..............@..B........................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PE32+ executable (console) x86-64, for MS Windows
    Category:dropped
    Size (bytes):41072
    Entropy (8bit):6.1826051095475805
    Encrypted:false
    SSDEEP:768:iM1V+4JYjwaYJeSfrQQU89gb/YinzEPxWEQW:iM1V+tjPYJeSfro+gb/7zEPxJ
    MD5:F15BDBD16B90708B8D10CCB461E2F8E0
    SHA1:AC3AC081A7C1E56572103923E85AF14CBE495E07
    SHA-256:1B31066DF770D9289F7099E77908DC845295C3469EDC4C4A1CD8F4403142BF89
    SHA-512:1C1E13E133EDDEB5628E3EEFD746BE7D9C58C62A65845DE27E909CDCB5E26FE9A4A8F1495334E9E0301414DF96279D8A4C1B89B46BC07063736F5268524F3BBA
    Malicious:false
    Antivirus:
    • Antivirus: ReversingLabs, Detection: 0%
    Reputation:low
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..........n...=...=...=..3=...=..1=...=...=...=...=...=If%=...=...=...=!..=...=..5=...=!.0=...=Rich...=........................PE..d...?..d.........."..........>......d/.........@..........................................`.................................................tb..x...............L....p..p0...........C..8............................^..p............@...............................text...[-.......................... ..`.rdata.."+...@...,...2..............@..@.data...p....p.......^..............@....pdata..L............`..............@..@.rsrc................d..............@..@.reloc...............n..............@..B........................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PE32+ executable (console) x86-64, for MS Windows
    Category:dropped
    Size (bytes):23008
    Entropy (8bit):6.642612167595762
    Encrypted:false
    SSDEEP:384:eiyqDy0SbCGMiqyROeEISZSf+VIYinvyYyPxh8E9VF0NyHWZb:5yqDl/GVjRTEIZ/YinByPxWEV8
    MD5:B040388CB3B406405132A1449BAC8ACA
    SHA1:DF92129A0429CAB7C09393F5E18D21ADD66F6D98
    SHA-256:22E12450C1C03081FCFE488E4AAE6A1B2BAAF463081AF4AEF6136B65E5D0FF85
    SHA-512:88D09E089C20C5C76BEBD34722CF2663B2DD0862D9B65860C36E7548EEB60D013602B2A92082CF0564E93C0BE56E483CA6E035B71A43874565070D22320E7699
    Malicious:false
    Antivirus:
    • Antivirus: ReversingLabs, Detection: 0%
    Reputation:low
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.............~...~...~..-....~......~......~......~.~L....~.......~.~L....~......~.~L....~.Rich..~.........................PE..d...>..d.........."............................@.............................p.......P....`..................................................$..P....P..,....@.......*.../...`..0....!..8............................"..p............ ..H............................text............................... ..`.rdata....... ......................@..@.data........0......................@....pdata.......@......................@..@.rsrc...,....P......................@..@.reloc..0....`.......(..............@..B........................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PE32+ executable (console) x86-64, for MS Windows
    Category:dropped
    Size (bytes):23008
    Entropy (8bit):6.642814570037673
    Encrypted:false
    SSDEEP:384:6j0l+NNqTTziTnIeEPWZSf+VIYinvyNRPxh8E9VF0Ny6jC6:40gPKWTn9EP1/YinsPxWEoG6
    MD5:CB637136FD9F5EDA8285184902167167
    SHA1:CAB9F8B1BB05D7706C205E614ABAACE8B6B03251
    SHA-256:DC80E49165365E5D07957B55E218F5056DC32BFBA317DC36032BDAF715C1DDDE
    SHA-512:F94F17C4A5601DC14632ABEEA58FC4FEBDCC4386CEEE0FD383B3987AE038CF96CB58554F152C9C9EA6E16ECAE22768BED43519A8375C1B009C429E94BC9A934C
    Malicious:false
    Antivirus:
    • Antivirus: ReversingLabs, Detection: 0%
    Reputation:low
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.............~...~...~..-....~......~......~......~.~L....~.......~.~L....~......~.~L....~.Rich..~.........................PE..d...>..d.........."............................@.............................p...........`..................................................$..P....P.. ....@.......*.../...`..0....!..8............................"..p............ ..H............................text............................... ..`.rdata....... ......................@..@.data........0......................@....pdata.......@......................@..@.rsrc... ....P......................@..@.reloc..0....`.......(..............@..B........................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
    Category:dropped
    Size (bytes):204784
    Entropy (8bit):6.542303793169886
    Encrypted:false
    SSDEEP:6144:WDRaxCHkwXS8SFCoZTpt5zXe/VMkVmFw/E:oRaxCHBS8SF3D+msE
    MD5:6D9FDC2C0561A9B472A7152B681F6EC3
    SHA1:68379F82E028D7214743330AD9CEA02693A89814
    SHA-256:8465723EB3DFDE823A03E5DC63B79D93FECCFEA3C3E14A2217AE761CC8ABB81B
    SHA-512:026D51B4D5BCD5FFDBE3CE86E724C7B9A387AB48B2600C779E2A74D748F194C906D06D5849C2B499EDC83B62318EA3207A6897B83C74DA2B754EE86FA2E4519A
    Malicious:false
    Antivirus:
    • Antivirus: ReversingLabs, Detection: 0%
    Reputation:low
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........1N.._..._..._..0...._......._...../._......._.Po...._...^..._.8....._.8....._......_.8....._.Rich.._.........PE..d....d.........." .........,...............................................@............`.........................................@...m.......d.... ..x................5...0..........8...............................p...............P............................text............................... ..`.rdata..............................@..@.data....?..........................@....pdata..............................@..@.rsrc...x.... ......................@..@.reloc.......0......................@..B................................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PE32+ executable (console) x86-64, for MS Windows
    Category:dropped
    Size (bytes):41072
    Entropy (8bit):6.1826051095475805
    Encrypted:false
    SSDEEP:768:iM1V+4JYjwaYJeSfrQQU89gb/YinzEPxWEQW:iM1V+tjPYJeSfro+gb/7zEPxJ
    MD5:F15BDBD16B90708B8D10CCB461E2F8E0
    SHA1:AC3AC081A7C1E56572103923E85AF14CBE495E07
    SHA-256:1B31066DF770D9289F7099E77908DC845295C3469EDC4C4A1CD8F4403142BF89
    SHA-512:1C1E13E133EDDEB5628E3EEFD746BE7D9C58C62A65845DE27E909CDCB5E26FE9A4A8F1495334E9E0301414DF96279D8A4C1B89B46BC07063736F5268524F3BBA
    Malicious:false
    Antivirus:
    • Antivirus: ReversingLabs, Detection: 0%
    Reputation:low
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..........n...=...=...=..3=...=..1=...=...=...=...=...=If%=...=...=...=!..=...=..5=...=!.0=...=Rich...=........................PE..d...?..d.........."..........>......d/.........@..........................................`.................................................tb..x...............L....p..p0...........C..8............................^..p............@...............................text...[-.......................... ..`.rdata.."+...@...,...2..............@..@.data...p....p.......^..............@....pdata..L............`..............@..@.rsrc................d..............@..@.reloc...............n..............@..B........................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PE32+ executable (console) x86-64, for MS Windows
    Category:dropped
    Size (bytes):23008
    Entropy (8bit):6.6392938575138345
    Encrypted:false
    SSDEEP:384:Pj0l+NNqZ0ziTdyeElZSf+VIYinvyV6Pxh8E9VF0NyWgK:70gPPWTd/EM/YinvPxWEQj
    MD5:169DCE0BB61EE143FE96D7CA491C073B
    SHA1:3125F6969BB253A2A38695D900AF6B6EB5845FA7
    SHA-256:2A625E11A46928B50333C4D8E64E6433246F3FB9B57B7A507F5160F02E69ECFB
    SHA-512:610E879026BAE6AA26200F370CA06B176CFBE29C4BC5AEA703B2E4C804FAAC9D25CC0DB2B0FC89F791339D5F5E85512F9049FD9AFFBC0DA1B1A66BE6F473583C
    Malicious:false
    Antivirus:
    • Antivirus: ReversingLabs, Detection: 0%
    Reputation:low
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.............~...~...~..-....~......~......~......~.~L....~.......~.~L....~......~.~L....~.Rich..~.........................PE..d...>..d.........."............................@.............................p......v.....`..................................................$..P....P.. ....@.......*.../...`..0....!..8............................"..p............ ..H............................text............................... ..`.rdata....... ......................@..@.data........0......................@....pdata.......@......................@..@.rsrc... ....P......................@..@.reloc..0....`.......(..............@..B........................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PE32+ executable (console) x86-64, for MS Windows
    Category:dropped
    Size (bytes):23008
    Entropy (8bit):6.642384484002845
    Encrypted:false
    SSDEEP:384:bTEl+NNCxV6iexUeEAXZSf+VIYinvyZPxh8E9VF0NyR9oG:XEgP63exRE5/YinWPxWEzh
    MD5:439C7524787125479B00BBE939941CD8
    SHA1:C9ECFA124F5B8BD0CAAA15C45A986306736282B0
    SHA-256:D7CA9A6871455075F268F79A3F61802475E9523E4C751AC9314DD1D43E42253B
    SHA-512:9CC92175C870F192B944B1CB4C8E1214BDF33A6B54940C0F4A648B22D487CAE30038643E7563297DCF79A7378F7A02AE467EE92D24FD70C5FC2A1855C6CB81B1
    Malicious:false
    Antivirus:
    • Antivirus: ReversingLabs, Detection: 0%
    Reputation:low
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.............~...~...~..-....~......~......~......~.~L....~.......~.~L....~......~.~L....~.Rich..~.........................PE..d...>..d.........."............................@.............................p...........`..................................................$..P....P..@....@.......*.../...`..0....!..8............................"..p............ ..H............................text............................... ..`.rdata....... ......................@..@.data........0......................@....pdata.......@......................@..@.rsrc...@....P......................@..@.reloc..0....`.......(..............@..B........................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PE32+ executable (console) x86-64, for MS Windows
    Category:dropped
    Size (bytes):23008
    Entropy (8bit):6.623949798062602
    Encrypted:false
    SSDEEP:384:RraktFJ6XHiQLGeEvZSf+VIYinvy45Pxh8E9VF0NyR+B:IswCQLrEO/YinL5PxWEzW
    MD5:273C7024504D3BE89E458CD531E4D889
    SHA1:D1CAFEA271CBD749557F977F3F2323EF1CC46B2F
    SHA-256:988C96F0A02AC05B4D8767FF80A62A15F50DC8F0912AFF7B19CBB76C491BEC76
    SHA-512:9D07821432071672824F7E6235872E61F26F2F2AA714DB1E228E237E43150B3F6FC2C40DD919F521883A31EC4D1C752735D38D9BC604DD54E54F5D019F2325AC
    Malicious:false
    Antivirus:
    • Antivirus: ReversingLabs, Detection: 0%
    Reputation:low
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.............~...~...~..-....~......~......~......~.~L....~.......~.~L....~......~.~L....~.Rich..~.........................PE..d...?..d.........."............................@.............................p......2.....`.................................................p$..P....P..@....@.......*.../...`..(....!..8...........................p"..p............ ..H............................text............................... ..`.rdata..~.... ......................@..@.data........0......................@....pdata.......@......................@..@.rsrc...@....P......................@..@.reloc..(....`.......(..............@..B........................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PE32+ executable (console) x86-64, for MS Windows
    Category:dropped
    Size (bytes):232136
    Entropy (8bit):6.609986425638662
    Encrypted:false
    SSDEEP:6144:T8CFPz4JnbQsXT2cDnP5wgbG8YPu7k/jilL:ThPzWncs/nNBC7ilL
    MD5:0C1642BB54BD4ED8F283C7C5523376F4
    SHA1:1CBA8AED2C201DCBD76ED2AA0F0053DC310C727A
    SHA-256:FDC59B0002D1ED9314739ED97200C743A63E97C4D66ED1EBC9A35F483E50E4E3
    SHA-512:F900BAFC02566C63927562233AD4C24DBB5CE7D3D26C3E8AC0D5B202A8E6B68B1218FAEB32D10DAACF0997CE2508FCABB1140D1D9C05894062C431F943179CF0
    Malicious:false
    Antivirus:
    • Antivirus: ReversingLabs, Detection: 0%
    Reputation:low
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........As.. .L. .L. .LH..L. .L.q.L. .L.q.Lw .L.q.L. .L...L. .L. .L. .Lc..L. .L.r.L. .Lc..L. .LRich. .L................PE..d...>..d.........."..........r......8..........@.....................................7....`.....................................................d.... ...o...........T...6..............8..............................p...............P............................text...,........................... ..`.rdata..............................@..@.data....?..........................@....pdata..............................@..@.rsrc....o... ...p..................@..@.reloc...............N..............@..B................................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PE32+ executable (console) x86-64, for MS Windows
    Category:dropped
    Size (bytes):23008
    Entropy (8bit):6.641642167930154
    Encrypted:false
    SSDEEP:384:wEraVN+lamjiT3TkeEAZSf+VIYinvyEa3Pxh8E9VF0NyXBEJ:brm+9mTTBEn/YinSPxWEpSJ
    MD5:72D81F3ABFB5A346528A2FDCC112B10B
    SHA1:B4FD7C934F48964C737CB6A8CBF52D6A209EDC54
    SHA-256:9C66A4790C8DF5FCDD8D81C3A17E70F6B2E113CE93AFC80E6574539FE7B1BB03
    SHA-512:FA67EC07A03A73258D8FC58ACCA2E699A22CEABE0D2BFEDF8935F8E8422A89FA572F41ABFFFCB68CDD21AF008F435B3D9526ED6F517E4FBFD1EAA489F405F7C6
    Malicious:false
    Antivirus:
    • Antivirus: ReversingLabs, Detection: 0%
    Reputation:low
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.............~...~...~..-....~......~......~......~.~L....~.......~.~L....~......~.~L....~.Rich..~.........................PE..d...>..d.........."............................@.............................p......8.....`..................................................$..P....P..,....@.......*.../...`..0....!..8............................"..p............ ..H............................text............................... ..`.rdata....... ......................@..@.data........0......................@....pdata.......@......................@..@.rsrc...,....P......................@..@.reloc..0....`.......(..............@..B........................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PE32+ executable (console) x86-64, for MS Windows
    Category:dropped
    Size (bytes):23008
    Entropy (8bit):6.642141954281721
    Encrypted:false
    SSDEEP:384:YEraVN+hZrji9mieEkfZSf+VIYinvy4p6XPxh8E9VF0NyXq6:Trm+7m9mPEJ/YinZp6XPxWEpl
    MD5:59A3EA22792064D203B5933DD542ED82
    SHA1:176BEF99C538726EA4D9D573CFC407AE6876C7C7
    SHA-256:18CB199560F4ACBFD8C4F6C4864EC9BE0622B0A2CC52B953D8D78F56F38B9311
    SHA-512:79E4C9A5EC224C3A685FE999C1D331281279383D76480E757668F463B096B5093B8DB04E394510716E9B404C38A98629DC15ACF8B8A1F595F52BA3906385510C
    Malicious:false
    Antivirus:
    • Antivirus: ReversingLabs, Detection: 0%
    Reputation:low
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.............~...~...~..-....~......~......~......~.~L....~.......~.~L....~......~.~L....~.Rich..~.........................PE..d...>..d.........."............................@.............................p.......K....`..................................................$..P....P..4....@.......*.../...`..0....!..8............................"..p............ ..H............................text............................... ..`.rdata....... ......................@..@.data........0......................@....pdata.......@......................@..@.rsrc...4....P......................@..@.reloc..0....`.......(..............@..B........................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PE32+ executable (console) x86-64, for MS Windows
    Category:dropped
    Size (bytes):160352
    Entropy (8bit):6.391343023203998
    Encrypted:false
    SSDEEP:3072:EkoaZzgXftbxm3sHLzJUIioULXVNJVs66yE/9xP:EueUcHLWIJ6TEH
    MD5:2787E8A4A1F9EF0FD4BE75EDA4B5F2E1
    SHA1:CB9E9EFFF84320C509165468BDB8B4DDC4CFE631
    SHA-256:49E0CFEAFDAB053D22134388CDC734CF88CCBBCA79799FF59C90C36D05AA3E0F
    SHA-512:BBB99FCBCE326D665028287C51BF40D511701EF7E6BDF299D327C7A2C15358849A25920AF3817C27BA14D1804F520FB51D230E44488C9A98810264611E2111E3
    Malicious:false
    Antivirus:
    • Antivirus: ReversingLabs, Detection: 0%
    Reputation:low
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......%.O#a.!pa.!pa.!p..%qk.!p.."qd.!p..$q.!p3.%qq.!p3."qh.!p3.$qH.!p.. qd.!pa. p..!p..$q`.!p...p`.!p..#q`.!pRicha.!p................PE..d......d.........."......^...........<.........@..........................................`.....................................................<....`..D....@.......>..`4...p..\....................................................p...............................text....].......^.................. ..`.rdata.......p.......b..............@..@.data...h.... ......................@....pdata.......@......................@..@.rsrc...D....`......................@..@.reloc..\....p.......6..............@..B................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PE32+ executable (console) x86-64, for MS Windows
    Category:dropped
    Size (bytes):23008
    Entropy (8bit):6.641591593459454
    Encrypted:false
    SSDEEP:384:rEraVN+lLkjiT3GYeENyZSf+VIYinvyM75Pxh8E9VF0NyXn/u:Yrm+KmTGtE//YinDPxWEp/u
    MD5:A7DF947ACED57CA801D88FFC7176EE04
    SHA1:2903B259F2EF78CE7E5524685194260B20830B04
    SHA-256:B1FA8B87AAFA101E8D391F404BD10FA5754866C46AEDB8D69F5BAF7B686ACB75
    SHA-512:09F333E794C2A23906D3702A0D686C1EA1880333ADAD859E58927D2F884FCD309BBDAB69BFE1B2A2D80AAE61F1E49BCD2F5FCB71F044266503AA807562E04FD5
    Malicious:false
    Reputation:low
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.............~...~...~..-....~......~......~......~.~L....~.......~.~L....~......~.~L....~.Rich..~.........................PE..d...>..d.........."............................@.............................p............`..................................................$..P....P..,....@.......*.../...`..0....!..8............................"..p............ ..H............................text............................... ..`.rdata....... ......................@..@.data........0......................@....pdata.......@......................@..@.rsrc...,....P......................@..@.reloc..0....`.......(..............@..B........................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PE32+ executable (console) x86-64, for MS Windows
    Category:dropped
    Size (bytes):23008
    Entropy (8bit):6.640345372216805
    Encrypted:false
    SSDEEP:384:9EraVN+lDxjiT3eYeEyZSf+VIYinvyvPxh8E9VF0NyExC:Wrm+7mTetE5/YinIPxWEuM
    MD5:68D720575A8976EC17A084AA4B255600
    SHA1:4DC4DFF16449E1004F50648A3FCC0FE92A37D0F6
    SHA-256:DE90B3A863F979691AA5AB90D4B3F0AA3493639BADC8BB66BCBD6B383F667C80
    SHA-512:872F2E57FDFD2EB132D33066B208837C2D5A55F289BC2C6B66A58C4DD07C39286932C818FFCF7484A4C4F925F7E7F4CB5C24DF01548FBE83FAAEACABD5AC8AF0
    Malicious:false
    Reputation:low
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.............~...~...~..-....~......~......~......~.~L....~.......~.~L....~......~.~L....~.Rich..~.........................PE..d...>..d.........."............................@.............................p.......B....`..................................................$..P....P..,....@.......*.../...`..0....!..8............................"..p............ ..H............................text............................... ..`.rdata....... ......................@..@.data........0......................@....pdata.......@......................@..@.rsrc...,....P......................@..@.reloc..0....`.......(..............@..B........................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PE32+ executable (console) x86-64, for MS Windows
    Category:dropped
    Size (bytes):160352
    Entropy (8bit):6.3910842429106385
    Encrypted:false
    SSDEEP:3072:bkoaZzgXftbxm3sHLzJUIioULXVNJVs66yN/Dxi:bueUcHLWIJ6TNo
    MD5:EACCFEC82BDB4EE78333E40D6CEFF792
    SHA1:EB5B650AF53EFEA15F2724490C396038C7654DB6
    SHA-256:701BB1D21C8F73A8E385209405A8C62BB90DBB2110A7696E11C3555B454915BC
    SHA-512:30D61F38E6FB872530D10902D983986D1B3E1117F15C3007C60231CCA945FF89E56A21E7C362CEAB461ED42B014721C0A9CEBC18A0FAB8FDBF37E24AAC2F9779
    Malicious:false
    Reputation:low
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......%.O#a.!pa.!pa.!p..%qk.!p.."qd.!p..$q.!p3.%qq.!p3."qh.!p3.$qH.!p.. qd.!pa. p..!p..$q`.!p...p`.!p..#q`.!pRicha.!p................PE..d......d.........."......^...........<.........@..........................................`.....................................................<....`..D....@.......>..`4...p..\....................................................p...............................text....].......^.................. ..`.rdata.......p.......b..............@..@.data...h.... ......................@....pdata.......@......................@..@.rsrc...D....`......................@..@.reloc..\....p.......6..............@..B................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PE32+ executable (GUI) x86-64, for MS Windows
    Category:dropped
    Size (bytes):232136
    Entropy (8bit):6.61624654726625
    Encrypted:false
    SSDEEP:6144:+dTu3dFROMWcTJQ/Tg2H+HVr5sVmmjYvBw7k/G3GTS:+d63dF/WaJm+1vKmO3GTS
    MD5:E368F0B1DBE52E21C6B5BC21C1771238
    SHA1:A5DA68B3E689238B0BDB87E10B1C59DAF80FC40C
    SHA-256:DD886B61D4C9DC80268E0E0D77A8DA7C92CF95602FCAD7025317B7988693C097
    SHA-512:9C584A283F8F35C1CDECA3C02E96104949294A1A5CA527B8D219243C9FCA7C20388A6B44175BC293B7E8C2577B9601EBD94882695F8FDB59DC0579FF32BDE14A
    Malicious:false
    Reputation:low
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......&...b..Mb..Mb..M.c.Mj..M$.<MN..M$.=M...M$..Mi..M.<.Mk..Mb..M...M.]=Mm..Mo..Mc..M.].Mc..MRichb..M........................PE..d...>..d.........."..........r.................@.........................................`.....................................................d.... ...o...........T...6..............8..............................p...............P............................text............................... ..`.rdata..............................@..@.data....?..........................@....pdata..............................@..@.rsrc....o... ...p..................@..@.reloc...............N..............@..B........................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PE32+ executable (console) x86-64, for MS Windows
    Category:dropped
    Size (bytes):23008
    Entropy (8bit):6.642890265358554
    Encrypted:false
    SSDEEP:384:Mj0l+NNgTxjiWyaaeEvZSf+VIYinvyZHPxh8E9VF0NyEEs:O0gPum/aHEO/Yin6PxWEuZ
    MD5:55C052D299BC93D17FAA9FD392A618D3
    SHA1:388B283804D319DEB044E84B03EF54A547BC11EE
    SHA-256:6B1A296142BF6DBB31EAB27CB5EE2B29D479BCC0A1BE3068D4B8C6F190039E64
    SHA-512:5DB26D3AC6A3FBFF92A98D901CECB77CC762A0768427363FD4BFBB4CB6F0BAA5191DE037F31EFDE2BEE4700E232E28052CB122945540E2E7BBF5A8BC781F066D
    Malicious:false
    Reputation:low
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.............~...~...~..-....~......~......~......~.~L....~.......~.~L....~......~.~L....~.Rich..~.........................PE..d...?..d.........."............................@.............................p.......>....`..................................................$..P....P..,....@.......*.../...`..0....!..8............................"..p............ ..H............................text............................... ..`.rdata....... ......................@..@.data........0......................@....pdata.......@......................@..@.rsrc...,....P......................@..@.reloc..0....`.......(..............@..B........................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PE32+ executable (GUI) x86-64, for MS Windows
    Category:dropped
    Size (bytes):23008
    Entropy (8bit):6.704398152183226
    Encrypted:false
    SSDEEP:384:dn31SUNDMjwjEPpieEaZZSf+VIYinvyx0LdNPxh8E9VF0NyElS:dnlSWDZ4PpPEF/Yiny0dNPxWEuo
    MD5:2443A3844F99D19CD4D1F49C2D509466
    SHA1:551E1E56BF8DB00C3D129EFDA098B061865831C4
    SHA-256:3BA4A178F6B06C386CD04107E6B4FF1B856E296C3585C4F34DEB1AE3B3D2F56E
    SHA-512:D641A43950412C634A94D1671AD67C892E83FCE8BCA8A9671EFCDA6AB31E0F6C362FC193DF5A9910FF0FAC3AFA336BEEA4D977DED7E83B7FAFCF3D2CAF886786
    Malicious:false
    Reputation:low
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........P...>...>...>..-....>......>......>......>.~L....>...?...>.~L....>......>.~L....>.Rich..>.................PE..d...>..d.........."............................@.............................p............`..................................................%..P....P..@....@.......*.../...`..4....!..8............................#..p............ ..`............................text............................... ..`.rdata..`.... ......................@..@.data........0......................@....pdata.......@......................@..@.rsrc...@....P......................@..@.reloc..4....`.......(..............@..B................................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PE32+ executable (console) x86-64, for MS Windows
    Category:dropped
    Size (bytes):23008
    Entropy (8bit):6.648477422294025
    Encrypted:false
    SSDEEP:384:XyqDy0FLx6iYuUeELGZSf+VIYinvy5mmAPxh8E9VF0NyFGSNA5:XyqDl73YuRELl/YinaAPxWEra
    MD5:156741C0D599E84D3F3B8302A1C37168
    SHA1:BE7F4CD7A3CA1174C6E703B68F5DB4CADC1F7E94
    SHA-256:B5F007BA6DFC30CA9A7C6B1540DE8814B457C24382C7799CF076BA461EA109E4
    SHA-512:A03A8F9526BE85868492143F54BAC8DAD979B250BE61B816D1A106BFEAF65BAA2ECD1041384C63CD11B3FC372A946CD598F04C32B2ED09F93897D9EE0519F53A
    Malicious:false
    Reputation:low
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.............~...~...~..-....~......~......~......~.~L....~.......~.~L....~......~.~L....~.Rich..~.........................PE..d...>..d.........."............................@.............................p............`..................................................$..P....P.. ....@.......*.../...`..0....!..8............................"..p............ ..H............................text............................... ..`.rdata....... ......................@..@.data........0......................@....pdata.......@......................@..@.rsrc... ....P......................@..@.reloc..0....`.......(..............@..B........................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PE32+ executable (console) x86-64, for MS Windows
    Category:dropped
    Size (bytes):23008
    Entropy (8bit):6.641631256711606
    Encrypted:false
    SSDEEP:384:JEraVN+lDVjiT3KO/eEkZSf+VIYinvyA6Pxh8E9VF0NyF61:irm+3mTKOWED/Yinj6PxWErI
    MD5:08C3994278A24FD5CA99EC88AF6C0B0A
    SHA1:060139FE9086446D9E02798E16473314D2D6B920
    SHA-256:A5D4A3FE9573C3BA883C66A542D515B18CEEC095EBA71857498BA3A0455999DE
    SHA-512:3E9EF34A505309A5B69AF970F89E1CA720B2F25881603A11B1A5A1AC9F3D19AD9F802CFEE3B1C5139EA3462CD0E902B292FCB5EA2D585CFFE15F843267BA5A2F
    Malicious:false
    Reputation:low
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.............~...~...~..-....~......~......~......~.~L....~.......~.~L....~......~.~L....~.Rich..~.........................PE..d...>..d.........."............................@.............................p.......*....`..................................................$..P....P..,....@.......*.../...`..0....!..8............................"..p............ ..H............................text............................... ..`.rdata....... ......................@..@.data........0......................@....pdata.......@......................@..@.rsrc...,....P......................@..@.reloc..0....`.......(..............@..B........................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PE32+ executable (console) x86-64, for MS Windows
    Category:dropped
    Size (bytes):23008
    Entropy (8bit):6.643061217808763
    Encrypted:false
    SSDEEP:384:0ysl+NNqQjzirYIeE2IZSf+VIYinvyhf+RbPxh8E9VF0NyFJ5S0:HsgPRWrY9E2v/Yink+RbPxWEr7S0
    MD5:1B53F35AA2503BA75D491ED5EEC9BE94
    SHA1:629876859CCE455A22DA1689B9D2AECA33E8C71F
    SHA-256:23F703B8AC7B32CE78678432FBD704063F3767E84EA731C3B7FF69E6C7816CD8
    SHA-512:BC85C064F27068FC40958F3FE6180650CD5851ED9EBC3D40AE2E32B92F92AB7D0A3B0A5ADC8387AF328F537C5F247EC494A72ED23E0225E7D2A82DF840D1B632
    Malicious:false
    Reputation:low
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.............~...~...~..-....~......~......~......~.~L....~.......~.~L....~......~.~L....~.Rich..~.........................PE..d...>..d.........."............................@.............................p............`..................................................$..P....P.. ....@.......*.../...`..0....!..8............................"..p............ ..H............................text............................... ..`.rdata....... ......................@..@.data........0......................@....pdata.......@......................@..@.rsrc... ....P......................@..@.reloc..0....`.......(..............@..B........................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PE32+ executable (console) x86-64, for MS Windows
    Category:dropped
    Size (bytes):23008
    Entropy (8bit):6.643081216941077
    Encrypted:false
    SSDEEP:384:Rj0l+NNkSvjiWybUeEEKZSf+VIYinvym9Pxh8E9VF0Ny6o5S:R0gPtm/bREER/Yin/PxWEoAS
    MD5:AB5A1EB045022697E836FB4EA44901B5
    SHA1:847241C55F7F369B3CD5DC9CB6F7C37BD2AC30AA
    SHA-256:4535CAA6F3EED479ED695F23A0ADCBA9914FCD6409B86782DD6C066ACB7BC418
    SHA-512:35C8CD2E7952195E6B293A7A388DECE4282ED2B7F20D9B94595E81CBE00C640412AB624CD572BBDB2F0DF137D2B401DDA43C6C88648BF237900DC57E88E765AE
    Malicious:false
    Reputation:low
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.............~...~...~..-....~......~......~......~.~L....~.......~.~L....~......~.~L....~.Rich..~.........................PE..d...>..d.........."............................@.............................p.......G....`..................................................$..P....P..,....@.......*.../...`..0....!..8............................"..p............ ..H............................text............................... ..`.rdata....... ......................@..@.data........0......................@....pdata.......@......................@..@.rsrc...,....P......................@..@.reloc..0....`.......(..............@..B........................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PE32+ executable (console) x86-64, for MS Windows
    Category:dropped
    Size (bytes):23008
    Entropy (8bit):6.664072311571862
    Encrypted:false
    SSDEEP:384:SbzlyFeFnmKiD3OaeEBZSf+VIYinvy6Pxh8E9VF0Ny6eZ:S/lYeNmnjOHEQ/YintPxWEou
    MD5:7B3BEE30444414ADAF67EF5DEB8F61D6
    SHA1:705DC88D2BBD784AEE572F2BCCF4198780D0A3E5
    SHA-256:A37A7E6228AF298550E91D3FB1AACB03E75A31F7B4C3BBCD1D5B78F995DB6333
    SHA-512:160261DDD93242BA57A3BD2EA468BA8E3BAA75D52368DD91243FC792A80B668B2803EA4F4E18D0A107F28F471F40D80B1C1FF361884F99B0B8655DC088916689
    Malicious:false
    Reputation:low
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.............~...~...~..-....~......~......~......~.~L....~.......~.~L....~......~.~L....~.Rich..~.........................PE..d...>..d.........."............................@.............................p.......r....`..................................................%..P....P..,....@.......*.../...`..4....!..8........................... #..p............ ..H............................text............................... ..`.rdata..&.... ......................@..@.data........0......................@....pdata.......@......................@..@.rsrc...,....P......................@..@.reloc..4....`.......(..............@..B........................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PE32+ executable (console) x86-64, for MS Windows
    Category:dropped
    Size (bytes):23008
    Entropy (8bit):6.642814570037673
    Encrypted:false
    SSDEEP:384:6j0l+NNqTTziTnIeEPWZSf+VIYinvyNRPxh8E9VF0Ny6jC6:40gPKWTn9EP1/YinsPxWEoG6
    MD5:CB637136FD9F5EDA8285184902167167
    SHA1:CAB9F8B1BB05D7706C205E614ABAACE8B6B03251
    SHA-256:DC80E49165365E5D07957B55E218F5056DC32BFBA317DC36032BDAF715C1DDDE
    SHA-512:F94F17C4A5601DC14632ABEEA58FC4FEBDCC4386CEEE0FD383B3987AE038CF96CB58554F152C9C9EA6E16ECAE22768BED43519A8375C1B009C429E94BC9A934C
    Malicious:false
    Reputation:low
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.............~...~...~..-....~......~......~......~.~L....~.......~.~L....~......~.~L....~.Rich..~.........................PE..d...>..d.........."............................@.............................p...........`..................................................$..P....P.. ....@.......*.../...`..0....!..8............................"..p............ ..H............................text............................... ..`.rdata....... ......................@..@.data........0......................@....pdata.......@......................@..@.rsrc... ....P......................@..@.reloc..0....`.......(..............@..B........................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
    Category:dropped
    Size (bytes):204784
    Entropy (8bit):6.542303793169886
    Encrypted:false
    SSDEEP:6144:WDRaxCHkwXS8SFCoZTpt5zXe/VMkVmFw/E:oRaxCHBS8SF3D+msE
    MD5:6D9FDC2C0561A9B472A7152B681F6EC3
    SHA1:68379F82E028D7214743330AD9CEA02693A89814
    SHA-256:8465723EB3DFDE823A03E5DC63B79D93FECCFEA3C3E14A2217AE761CC8ABB81B
    SHA-512:026D51B4D5BCD5FFDBE3CE86E724C7B9A387AB48B2600C779E2A74D748F194C906D06D5849C2B499EDC83B62318EA3207A6897B83C74DA2B754EE86FA2E4519A
    Malicious:false
    Reputation:low
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........1N.._..._..._..0...._......._...../._......._.Po...._...^..._.8....._.8....._......_.8....._.Rich.._.........PE..d....d.........." .........,...............................................@............`.........................................@...m.......d.... ..x................5...0..........8...............................p...............P............................text............................... ..`.rdata..............................@..@.data....?..........................@....pdata..............................@..@.rsrc...x.... ......................@..@.reloc.......0......................@..B................................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PE32+ executable (console) x86-64, for MS Windows
    Category:dropped
    Size (bytes):23008
    Entropy (8bit):6.666393011633717
    Encrypted:false
    SSDEEP:384:xbzbyFeFJKiDyoGeEq6ZSf+VIYinvylPxh8E9VF0NyL8d1:x/bYePneorEqB/Yin0PxWElA
    MD5:6DE743CCEC2907C4CE417576BBB70202
    SHA1:8B02875D569CB51C37467B9180D77D83293D2D4D
    SHA-256:40C104F7C8ED0061F4C867984AB3418EFDA2BCEB8B53CA23AE5A3CFBE46786CD
    SHA-512:7185D918440584264036A0B5639F5673B147C7305FC25D3F0CBBA031F565F6DD5CA1748FA7995A6F571D33E8AE352F095DEA71EEBA268CD4C3413DF4F49D8732
    Malicious:false
    Reputation:low
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.............~...~...~..-....~......~......~......~.~L....~.......~.~L....~......~.~L....~.Rich..~.........................PE..d...>..d.........."............................@.............................p............`..................................................%..P....P..,....@.......*.../...`..4....!..8........................... #..p............ ..H............................text............................... ..`.rdata..&.... ......................@..@.data........0......................@....pdata.......@......................@..@.rsrc...,....P......................@..@.reloc..4....`.......(..............@..B........................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PE32+ executable (console) x86-64, for MS Windows
    Category:dropped
    Size (bytes):23008
    Entropy (8bit):6.641929452262611
    Encrypted:false
    SSDEEP:384:0j0l+NNqPHziTV4eEJUZSf+VIYinvyklkPxh8E9VF0NyLQyBra:m0gP2WTVNEJz/YinJkPxWEl/ra
    MD5:ACE76717268E5B2A12E9D65326532A0F
    SHA1:9D948D31C21EB8B78EFE18F0EE3E08E49B271693
    SHA-256:ACC31348B33805AE592F50D693F99534B4016F1DA57125FF370E4159E7739FBD
    SHA-512:DDD8662D6E03031EE9D5F60B86CB0B6FCF47DDB7690E91DC93222F6A989CACA4FFF415D9BB296D870F447503F82D9407C7248746A627D2E568B88BE09DB4C3B0
    Malicious:false
    Reputation:low
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.............~...~...~..-....~......~......~......~.~L....~.......~.~L....~......~.~L....~.Rich..~.........................PE..d...>..d.........."............................@.............................p......o.....`..................................................$..P....P.. ....@.......*.../...`..0....!..8............................"..p............ ..H............................text............................... ..`.rdata....... ......................@..@.data........0......................@....pdata.......@......................@..@.rsrc... ....P......................@..@.reloc..0....`.......(..............@..B........................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PE32+ executable (console) x86-64, for MS Windows
    Category:dropped
    Size (bytes):23008
    Entropy (8bit):6.639136764254076
    Encrypted:false
    SSDEEP:384:MLsl+NN2EuUixGEeE5ZSf+VIYinvytXDNPxh8E9VF0NyLBLGLq:msgPEdxGhEI/YinEXDNPxWElb
    MD5:9289C42F4C171EEA7FE78EA7201EE9FD
    SHA1:34C181CE2BA8B4D4136C8FC7753FF1366A299AC6
    SHA-256:AEA89815A49AFBA3A4D2854539C5B538FF8ECBFC91014668E6A26A2B6178BB26
    SHA-512:3EF780238CCC96B428E4CC646075CEBDE08F01F205CCE999F3FE4B4C908738E6D564E21F2F277EB44192FE75A4748F0D7A9824A42D35E724BB12D6F4D60C3E80
    Malicious:false
    Reputation:low
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.............~...~...~..-....~......~......~......~.~L....~.......~.~L....~......~.~L....~.Rich..~.........................PE..d...>..d.........."............................@.............................p............`..................................................$..P....P..H....@.......*.../...`..0....!..8............................"..p............ ..H............................text............................... ..`.rdata....... ......................@..@.data........0......................@....pdata.......@......................@..@.rsrc...H....P......................@..@.reloc..0....`.......(..............@..B........................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PE32+ executable (console) x86-64, for MS Windows
    Category:dropped
    Size (bytes):23008
    Entropy (8bit):6.6470305356718855
    Encrypted:false
    SSDEEP:384:OyqDy0MR/3iqBy3eEHaZSf+VIYinvyCrePxh8E9VF0NyIimQVB:OyqDFOSqByOEHh/YinPrePxWEa3QB
    MD5:BE9842199AD5D3A99720B14352BB42D8
    SHA1:35FA57318E0F72B69F2CB73A0A32F70711291E06
    SHA-256:9F850E7C0368FF003BC757EA6BF513A76A26672EB5641932C9E0F11E4A242670
    SHA-512:9F95DB97A77490D79C077296BA8B044AFD7C3E92C028E534BCC8231611C831AE99A509E6875F7946CB3809CE9C2FF959B6ABB9CC77597CDB9FF4A1C28BDCF8E2
    Malicious:false
    Reputation:low
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.............~...~...~..-....~......~......~......~.~L....~.......~.~L....~......~.~L....~.Rich..~.........................PE..d...>..d.........."............................@.............................p......|.....`..................................................$..P....P..@....@.......*.../...`..0....!..8............................"..p............ ..H............................text............................... ..`.rdata....... ......................@..@.data........0......................@....pdata.......@......................@..@.rsrc...@....P......................@..@.reloc..0....`.......(..............@..B........................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PE32+ executable (console) x86-64, for MS Windows
    Category:dropped
    Size (bytes):23008
    Entropy (8bit):6.6678172127000845
    Encrypted:false
    SSDEEP:384:jbzfCFelnKigemeEIZSf+VIYinvyw4whPxh8E9VF0NyIijF:j/foeFngeLEv/Yin34whPxWEae
    MD5:0B1CBD4C59E78A341B5FDBD33F4DE097
    SHA1:E2CD9214BF3B9FBC147C87F679B6727DEE232340
    SHA-256:C1AF81366E6B62CB4708952F6E4012F0668EE1E156E143DCBE94D22F9EEB57A9
    SHA-512:251C37EB7C6174472F08EF7D7E075AD09B90E7C329D6C67CD36392CDF1BBA514DD67D3E5AD94FFA394A52A52DFD1AB36B30312E4D9ED0E6367D7EF0D79E4B818
    Malicious:false
    Reputation:low
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.............~...~...~..-....~......~......~......~.~L....~.......~.~L....~......~.~L....~.Rich..~.........................PE..d...>..d.........."............................@.............................p............`..................................................%..P....P..4....@.......*.../...`..4....!..8........................... #..p............ ..H............................text............................... ..`.rdata..&.... ......................@..@.data........0......................@....pdata.......@......................@..@.rsrc...4....P......................@..@.reloc..4....`.......(..............@..B........................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PE32+ executable (console) x86-64, for MS Windows
    Category:dropped
    Size (bytes):23008
    Entropy (8bit):6.640792809075622
    Encrypted:false
    SSDEEP:384:gj0l+NNWTWrUjiW3KIeE9dZSf+VIYinvyUR4Pxh8E9VF0NyI4/4:i0gPxUmaK9Eq/YinNR4PxWEae4
    MD5:5653BE24EFCB4FD8C9C683459842B541
    SHA1:E90E09F6496E3B237E4C685E9558A66C161BE863
    SHA-256:0C7370943885EF82CB9F785ED285ADC0B4C1FC893BA543A1A7294CAFD55C79E8
    SHA-512:96E221DDCBA6EBD59DB2A927894BAD93708EAA12DE7C56B3D9A6004EB4CE047A63BD48E59549E1599485F51EF49FDA0FC500BAC6E3FC67ECE0CBC18AF049129F
    Malicious:false
    Reputation:low
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.............~...~...~..-....~......~......~......~.~L....~.......~.~L....~......~.~L....~.Rich..~.........................PE..d...>..d.........."............................@.............................p......h.....`..................................................$..P....P..,....@.......*.../...`..0....!..8............................"..p............ ..H............................text............................... ..`.rdata....... ......................@..@.data........0......................@....pdata.......@......................@..@.rsrc...,....P......................@..@.reloc..0....`.......(..............@..B........................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:MSVC program database ver 7.00, 4096*107 bytes
    Category:dropped
    Size (bytes):438272
    Entropy (8bit):4.648184109013776
    Encrypted:false
    SSDEEP:6144:eML5rb9Jc8vIZ7CwvBv9diB2v9ge3HRjUsLbFg+nQ2QevkZFR2jyyRzW3lLwdWgq:RsbxqNPMDJKL
    MD5:C6404350D9069AE3AB7ABAA7705DCB61
    SHA1:D0C5949F0B709C6E0D86DA513DF455FD150B02A6
    SHA-256:77C136466B6D2910594DCA25EB584AB097B5A7FF43D4609D183D1D99340562CE
    SHA-512:917C94B7AFF089246C50E397511D1F38AA331D94DE5B734E617D4517CFB920CF1BA650D8D63803313FF7B04409BA71C4ABFBB36CDBBE5218E8D911ABB5E199D3
    Malicious:false
    Reputation:low
    Preview:Microsoft C/C++ MSF 7.00...DS...........k...(.......i...................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:current ar archive
    Category:dropped
    Size (bytes):1918
    Entropy (8bit):4.693554637407265
    Encrypted:false
    SSDEEP:24:3OeuiXPY72u9yjM2XKKwsryAO6ujjaZUK//yhq0qkKP7LO6:+nAM2XKKwUyAOIZUKX0qkKZ
    MD5:610F286AF73A98827119307F7F4B77C0
    SHA1:2D2BA1AF01EBBB561840380F1F64530700971B8F
    SHA-256:43ABFC116A4FFF9A226FE67A3C22826895E04BA9801548E8612009B006EFE6CF
    SHA-512:46CDEEF62FDEDC289D95857F01725F57CDA7F9DFFC0880EF64EA739C03B6CF538176B8ED5A9144CCD314C5388BE123EE5EB95CB435614252312F0A3025B5939D
    Malicious:false
    Reputation:low
    Preview:!<arch>./ 1689363552 0 178 `................N................__IMPORT_DESCRIPTOR_waiters.__NULL_IMPORT_DESCRIPTOR..waiters_NULL_THUNK_DATA.Agent_OnLoad.__imp_Agent_OnLoad.Agent_OnUnload.__imp_Agent_OnUnload./ 1689363552 0 188 `.............N.............................Agent_OnLoad.Agent_OnUnload.__IMPORT_DESCRIPTOR_waiters.__NULL_IMPORT_DESCRIPTOR.__imp_Agent_OnLoad.__imp_Agent_OnUnload..waiters_NULL_THUNK_DATA.waiters.dll/ 1689363552 0 493 `.d...`..d.............debug$S........A...................@..B.idata$2............................@.0..idata$6............................@. ..............waiters.dll'......................Microsoft (R) LINK..................................................waiters.dll.@comp.id.............................idata$2@.......h..idata$6...........idata$4@.......h..idata$5@.......h..... .................9.............R...__IMPORT_DESCRIPTOR_waiters.__N
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
    Category:dropped
    Size (bytes):27144
    Entropy (8bit):6.557705555745941
    Encrypted:false
    SSDEEP:384:gIuLlNClyGrzRsOSRtIVKi8TSsaXJ28EZSf+VIYinvy8ViMPxh8E9VF0Nyvy:VuP5GrVJVKbS5XJ28j/Yin7XPxWEt
    MD5:C448267CF8CD43D8B06259780CBB336B
    SHA1:401166ADBD1851E3E1054DF69C463147FBD1B9C9
    SHA-256:289F27FDB039D544741983511E38E6701DE9279DA9212D102BC254ABF7210FB1
    SHA-512:2E941EA7507E687F67D01BE4928F3DE09DADAFC68B4BC8B54228220C6A9DB5020CC8475D27DAC5586795B5C2BEE629F3686243DA06C774E5DC9D84E6953CD23D
    Malicious:false
    Reputation:low
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......\|....@...@...@.....@...A.3.@.^L....@.^L....@.^L....@.^L....@.......@.......@.......@..O....@.......@.Rich..@.........PE..d...`..d.........." .................#..............................................#.....`..........................................8..d...d8..<....`.......P..L....:...0...p......p1..8............................4..p............0..8............................text...{........................... ..`.rdata..j....0....... ..............@..@.data........@......................@....pdata..L....P.......0..............@..@.rsrc........`.......4..............@..@.reloc.......p.......8..............@..B........................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Intel amd64 COFF object file, not stripped, 2 sections, symbol offset=0x2a7, 10 symbols, created Fri Jul 14 19:39:12 2023, 1st section name ".edata"
    Category:dropped
    Size (bytes):891
    Entropy (8bit):4.543724211434498
    Encrypted:false
    SSDEEP:24:g0A7aUSlN4Na2gQeKPb0d7qymxHxu3g41G2n9V:VRUSlN4BgQeKj0d7qtHxuQ41G2nv
    MD5:C6321C6D5244E2F990C1E0ECACE1341D
    SHA1:B5253DABE24AC278DA56EB1D47F0FCB5ECD3A17C
    SHA-256:0E95C0EAAF165B6DFF4655F670BF5E46DF4CA313D0FE834351C5776C012B4AF8
    SHA-512:878D021A13C3EC55ED4D4A7D81A611F24DA4B48D55016D6D5A1998AD7DC0221A3636D63D31EE50AFF345223DE64B28BB26E7096D2B84B597100E649F8F2384C9
    Malicious:false
    Reputation:low
    Preview:d...`..d.............edata..........d...d...............@..@.debug$S............................@..B....`..d....................................................waiters.dll.Agent_OnLoad.Agent_OnUnload..................... .........$.........(.........0.........,.........4.............................c:/wsjdk/Corretto8Src/installers/windows/zip/corretto-build/buildRoot/build/windows-x86_64-normal-server-release/jdk/demoobjs/jvmti/waiters/waiters.exp.+.<.......................Microsoft (R) LINK...=..cwd.C:\wsjdk\Corretto8Src\installers\windows\zip\corretto-build\buildRoot\jdk\make.exe.c:\progra~2\micros~3.0\vc\bin\amd64\link.exe....8.....Agent_OnLoad...8.....Agent_OnUnload.@comp.id...........edata............szName..<.........rgpv....(.........rgszName0.........rgwOrd..8.........$N00001.H.........$N00002.U............................................. ...Agent_OnLoad.Agent_OnUnload.
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
    Category:dropped
    Size (bytes):27144
    Entropy (8bit):6.557705555745941
    Encrypted:false
    SSDEEP:384:gIuLlNClyGrzRsOSRtIVKi8TSsaXJ28EZSf+VIYinvy8ViMPxh8E9VF0Nyvy:VuP5GrVJVKbS5XJ28j/Yin7XPxWEt
    MD5:C448267CF8CD43D8B06259780CBB336B
    SHA1:401166ADBD1851E3E1054DF69C463147FBD1B9C9
    SHA-256:289F27FDB039D544741983511E38E6701DE9279DA9212D102BC254ABF7210FB1
    SHA-512:2E941EA7507E687F67D01BE4928F3DE09DADAFC68B4BC8B54228220C6A9DB5020CC8475D27DAC5586795B5C2BEE629F3686243DA06C774E5DC9D84E6953CD23D
    Malicious:false
    Reputation:low
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......\|....@...@...@.....@...A.3.@.^L....@.^L....@.^L....@.^L....@.......@.......@.......@..O....@.......@.Rich..@.........PE..d...`..d.........." .................#..............................................#.....`..........................................8..d...d8..<....`.......P..L....:...0...p......p1..8............................4..p............0..8............................text...{........................... ..`.rdata..j....0....... ..............@..@.data........@......................@....pdata..L....P.......0..............@..@.rsrc........`.......4..............@..@.reloc.......p.......8..............@..B........................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Intel amd64 COFF object file, not stripped, 2 sections, symbol offset=0x2a7, 10 symbols, created Fri Jul 14 19:39:12 2023, 1st section name ".edata"
    Category:dropped
    Size (bytes):891
    Entropy (8bit):4.543724211434498
    Encrypted:false
    SSDEEP:24:g0A7aUSlN4Na2gQeKPb0d7qymxHxu3g41G2n9V:VRUSlN4BgQeKj0d7qtHxuQ41G2nv
    MD5:C6321C6D5244E2F990C1E0ECACE1341D
    SHA1:B5253DABE24AC278DA56EB1D47F0FCB5ECD3A17C
    SHA-256:0E95C0EAAF165B6DFF4655F670BF5E46DF4CA313D0FE834351C5776C012B4AF8
    SHA-512:878D021A13C3EC55ED4D4A7D81A611F24DA4B48D55016D6D5A1998AD7DC0221A3636D63D31EE50AFF345223DE64B28BB26E7096D2B84B597100E649F8F2384C9
    Malicious:false
    Reputation:low
    Preview:d...`..d.............edata..........d...d...............@..@.debug$S............................@..B....`..d....................................................waiters.dll.Agent_OnLoad.Agent_OnUnload..................... .........$.........(.........0.........,.........4.............................c:/wsjdk/Corretto8Src/installers/windows/zip/corretto-build/buildRoot/build/windows-x86_64-normal-server-release/jdk/demoobjs/jvmti/waiters/waiters.exp.+.<.......................Microsoft (R) LINK...=..cwd.C:\wsjdk\Corretto8Src\installers\windows\zip\corretto-build\buildRoot\jdk\make.exe.c:\progra~2\micros~3.0\vc\bin\amd64\link.exe....8.....Agent_OnLoad...8.....Agent_OnUnload.@comp.id...........edata............szName..<.........rgpv....(.........rgszName0.........rgwOrd..8.........$N00001.H.........$N00002.U............................................. ...Agent_OnLoad.Agent_OnUnload.
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:current ar archive
    Category:dropped
    Size (bytes):1918
    Entropy (8bit):4.693554637407265
    Encrypted:false
    SSDEEP:24:3OeuiXPY72u9yjM2XKKwsryAO6ujjaZUK//yhq0qkKP7LO6:+nAM2XKKwUyAOIZUKX0qkKZ
    MD5:610F286AF73A98827119307F7F4B77C0
    SHA1:2D2BA1AF01EBBB561840380F1F64530700971B8F
    SHA-256:43ABFC116A4FFF9A226FE67A3C22826895E04BA9801548E8612009B006EFE6CF
    SHA-512:46CDEEF62FDEDC289D95857F01725F57CDA7F9DFFC0880EF64EA739C03B6CF538176B8ED5A9144CCD314C5388BE123EE5EB95CB435614252312F0A3025B5939D
    Malicious:false
    Reputation:low
    Preview:!<arch>./ 1689363552 0 178 `................N................__IMPORT_DESCRIPTOR_waiters.__NULL_IMPORT_DESCRIPTOR..waiters_NULL_THUNK_DATA.Agent_OnLoad.__imp_Agent_OnLoad.Agent_OnUnload.__imp_Agent_OnUnload./ 1689363552 0 188 `.............N.............................Agent_OnLoad.Agent_OnUnload.__IMPORT_DESCRIPTOR_waiters.__NULL_IMPORT_DESCRIPTOR.__imp_Agent_OnLoad.__imp_Agent_OnUnload..waiters_NULL_THUNK_DATA.waiters.dll/ 1689363552 0 493 `.d...`..d.............debug$S........A...................@..B.idata$2............................@.0..idata$6............................@. ..............waiters.dll'......................Microsoft (R) LINK..................................................waiters.dll.@comp.id.............................idata$2@.......h..idata$6...........idata$4@.......h..idata$5@.......h..... .................9.............R...__IMPORT_DESCRIPTOR_waiters.__N
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:MSVC program database ver 7.00, 4096*107 bytes
    Category:dropped
    Size (bytes):438272
    Entropy (8bit):4.648184109013776
    Encrypted:false
    SSDEEP:6144:eML5rb9Jc8vIZ7CwvBv9diB2v9ge3HRjUsLbFg+nQ2QevkZFR2jyyRzW3lLwdWgq:RsbxqNPMDJKL
    MD5:C6404350D9069AE3AB7ABAA7705DCB61
    SHA1:D0C5949F0B709C6E0D86DA513DF455FD150B02A6
    SHA-256:77C136466B6D2910594DCA25EB584AB097B5A7FF43D4609D183D1D99340562CE
    SHA-512:917C94B7AFF089246C50E397511D1F38AA331D94DE5B734E617D4517CFB920CF1BA650D8D63803313FF7B04409BA71C4ABFBB36CDBBE5218E8D911ABB5E199D3
    Malicious:false
    Reputation:low
    Preview:Microsoft C/C++ MSF 7.00...DS...........k...(.......i...................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java archive data (JAR)
    Category:dropped
    Size (bytes):9644
    Entropy (8bit):7.873235391371468
    Encrypted:false
    SSDEEP:192:vXDQDkkfCtpVGssQsWKS7sS8i+JPuZq+iMIuAw9BV41VxnDx:rSlqtpV3sQz8XuZq3DzGB+1Z
    MD5:DBF96996027AE6EBB2AFC66A5A35B5C9
    SHA1:7CD5C82DA6A8869FF87BCDA59C20D73D6E8E34ED
    SHA-256:2A0B3682B59F63B499C4209F2F2FE943FC19A3CED6EB8C8690E78D8F02B783F9
    SHA-512:9CD4C2F56B7615AE0F7B145057261FDBCD8E64D794897014A6DA0D021E28E4A198B0A96A1C9C209FDECF89F181522AD2C6D38DD96A98F460E3D671B4BAE737A7
    Malicious:false
    Reputation:low
    Preview:PK..........V................META-INF/......PK..............PK..........V................META-INF/MANIFEST.MFm....0.E....,u.Ru.t.U..(*neH..H&%M..z_.v;.p.9.....|.....)r[.......mt0...........>h.....oe.8...])..)]j. .p>..Ge.2.+.o.7...4.J.-..9|`../.)2O...F.R......X9.9......(..5G...Na...._..qc+).8.PK..b..z....U...PK..........V................Deadlock$DeadlockThread.class.V.O.e...{.2;..z.J......b[j..V.]..[..0.0.;...)......j...&F.j.=.Ml.R.#?X...@A..x..}...=.,7......0Y..<.`...S. ].... ........(.EJA.}2.(......Q.......B.q.."8............<)NOE....xV.&!......6..SZ.s.LR.-.s..r..5.L.v.uwJ.fmk..!.r.L.v$.=.e8].-.7..jR..mX.o+.t..h.{y....%H'$..Q3.m...dB..>.V.%h.yq.bF.F...cZ#.+.^Q...qu.....i.}^v.p....%]..|I.K%.}..,.8W...>..r...<.!...l..V.r....%!.-x+.o..V.....zJ..9.q...+.......U..P..*...........]hS..m2.W1"....c2.Ud...0_...5.....I...m....."...........Ss..p.......I...r.\3k..$...^f...F.....Q.1ZU< L...N.....H...pUx8E....3...N...F...W.....Y..>..j.i..../.=24f.:.t...lZa.9
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:ASCII text
    Category:dropped
    Size (bytes):2019
    Entropy (8bit):4.772815672113362
    Encrypted:false
    SSDEEP:48:J97PMiUB9p7G70WIYS503wrUNj4petIAQbWFIC4:JYS3Xcd
    MD5:DAE0753DD8AE51B9B4AA87A8E8DCB6CF
    SHA1:42799A27219162514D5605D66526DF54EEAB7F67
    SHA-256:899CEE7228B94D82B92D4ABA41A34E66394C0BD08C20DCB61043F1623CC5B557
    SHA-512:3A96148C999B0461016D5E8E25154108F41DA518B7B15428D3FF29F7457CAE362106E8198BBF3970417272382BC680E509607BF4E5E60938A3E960B4BCD0B8F5
    Malicious:false
    Reputation:low
    Preview:FullThreadDump demonstrates the use of the java.lang.management API .to print the full thread dump. JDK 6 defines a new API to dump.the information about monitors and java.util.concurrent ownable.synchronizers...This demo also illustrates how to monitor JDK 5 and JDK 6 VMs with.two versions of APIs...It contains two parts: .a) Local monitoring within the application.b) Remote monitoring by connecting to a JMX agent with a JMX service URL:. service:jmx:rmi:///jndi/rmi://<hostName>:<portNum>/jmxrmi. where <hostName> is the hostname and <portNum> is the port number. to which the JMX agent will be connected...To run the demo.---------------.a) Local Monitoring.. java -cp <JDK_HOME>/demo/management/FullThreadDump/FullThreadDump.jar Deadlock.. This will dump the stack trace and then detect deadlocks locally. within the application...b) Remote Monitoring.. (1) Start the Deadlock application (or any other application) . with the JMX agent as follows:. . java -Dcom.
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Zip archive data, at least v2.0 to extract, compression method=deflate
    Category:dropped
    Size (bytes):8351
    Entropy (8bit):7.941234216292513
    Encrypted:false
    SSDEEP:192:ssNBCL5P2e6GPAiemai+JPpfgDo3ZKSUSbp:s24LIe6GPAsaXpmYgSF
    MD5:8FFD4BC885E5A88ABD26B1BE51E940CE
    SHA1:20ADAFD6DB1CB449B448765B80952FF344A33C06
    SHA-256:5EC01DAC414B3D89080286500285DE00F1B62ADBCA1AB905CA712A89A3E769A3
    SHA-512:DB49429A4F1F8357D977A0ADFAD89C99437A68B016B0452939889B6B2AA1E0CD4088873C9453C3646276B553B6F89ED19C185C0D76ADD6453E53C56081DA0CE7
    Malicious:false
    Reputation:low
    Preview:PK...........V...............Deadlock.javaUT...%..d%..dux..............XKw.H...W.....d.I.....9.P......%.&...v......X.!;.y.Z...{..~.....G.$..T.,r...trt......>9.."I"....T....U.D.3..(".Q*3......C.2TY..Y..$f.*2I*.,).@C.L."..y...>.|A.....e..j....}....L.*.eH.4.U!n...%..E..o(H.P1S.(....jD/[.e..k..$.u..0)....,...M%.Q..*.}...".2.Z..qS1H."..25...R......a...G.Qik..&A..q...q.$ Hi..JD.:.:v..4.i.X*..4.XJV.J.8Y?.@..Z@...I3....<....8.S.).=.I..t..1.....f...)Y2..8!.,.l%..1.*N...+..,..V...G.s._..E.....{h.........k._.t...9....w.......1....3s|M..ky.9.....<.p.o[^...`4....>...O#...A.;.R/....3.....~........3....3.3ib..=..L..&Sw.x..}C...L.....% .....'....Z.:Wc....4.=...y:.Jy0wh...g..w.x.Z...M......>Z..t.....z./S...y.#{..Q.L].u.O........q....~.....F..=7..>..f...(..(@~:.l.C{.[.;...3>@..!hj.{....p..^.....:.}...p.{..Lv.....&.D.~.X..[.#....,&p......D.~...LH.j.9h...u&.....%...........].v...>.....aY.em.;.j4..."4...C.z.......Nc.K...n>..d..........A..H.$.D....*B.b....
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:ASCII text
    Category:dropped
    Size (bytes):2019
    Entropy (8bit):4.772815672113362
    Encrypted:false
    SSDEEP:48:J97PMiUB9p7G70WIYS503wrUNj4petIAQbWFIC4:JYS3Xcd
    MD5:DAE0753DD8AE51B9B4AA87A8E8DCB6CF
    SHA1:42799A27219162514D5605D66526DF54EEAB7F67
    SHA-256:899CEE7228B94D82B92D4ABA41A34E66394C0BD08C20DCB61043F1623CC5B557
    SHA-512:3A96148C999B0461016D5E8E25154108F41DA518B7B15428D3FF29F7457CAE362106E8198BBF3970417272382BC680E509607BF4E5E60938A3E960B4BCD0B8F5
    Malicious:false
    Reputation:low
    Preview:FullThreadDump demonstrates the use of the java.lang.management API .to print the full thread dump. JDK 6 defines a new API to dump.the information about monitors and java.util.concurrent ownable.synchronizers...This demo also illustrates how to monitor JDK 5 and JDK 6 VMs with.two versions of APIs...It contains two parts: .a) Local monitoring within the application.b) Remote monitoring by connecting to a JMX agent with a JMX service URL:. service:jmx:rmi:///jndi/rmi://<hostName>:<portNum>/jmxrmi. where <hostName> is the hostname and <portNum> is the port number. to which the JMX agent will be connected...To run the demo.---------------.a) Local Monitoring.. java -cp <JDK_HOME>/demo/management/FullThreadDump/FullThreadDump.jar Deadlock.. This will dump the stack trace and then detect deadlocks locally. within the application...b) Remote Monitoring.. (1) Start the Deadlock application (or any other application) . with the JMX agent as follows:. . java -Dcom.
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java archive data (JAR)
    Category:dropped
    Size (bytes):9644
    Entropy (8bit):7.873235391371468
    Encrypted:false
    SSDEEP:192:vXDQDkkfCtpVGssQsWKS7sS8i+JPuZq+iMIuAw9BV41VxnDx:rSlqtpV3sQz8XuZq3DzGB+1Z
    MD5:DBF96996027AE6EBB2AFC66A5A35B5C9
    SHA1:7CD5C82DA6A8869FF87BCDA59C20D73D6E8E34ED
    SHA-256:2A0B3682B59F63B499C4209F2F2FE943FC19A3CED6EB8C8690E78D8F02B783F9
    SHA-512:9CD4C2F56B7615AE0F7B145057261FDBCD8E64D794897014A6DA0D021E28E4A198B0A96A1C9C209FDECF89F181522AD2C6D38DD96A98F460E3D671B4BAE737A7
    Malicious:false
    Reputation:low
    Preview:PK..........V................META-INF/......PK..............PK..........V................META-INF/MANIFEST.MFm....0.E....,u.Ru.t.U..(*neH..H&%M..z_.v;.p.9.....|.....)r[.......mt0...........>h.....oe.8...])..)]j. .p>..Ge.2.+.o.7...4.J.-..9|`../.)2O...F.R......X9.9......(..5G...Na...._..qc+).8.PK..b..z....U...PK..........V................Deadlock$DeadlockThread.class.V.O.e...{.2;..z.J......b[j..V.]..[..0.0.;...)......j...&F.j.=.Ml.R.#?X...@A..x..}...=.,7......0Y..<.`...S. ].... ........(.EJA.}2.(......Q.......B.q.."8............<)NOE....xV.&!......6..SZ.s.LR.-.s..r..5.L.v.uwJ.fmk..!.r.L.v$.=.e8].-.7..jR..mX.o+.t..h.{y....%H'$..Q3.m...dB..>.V.%h.yq.bF.F...cZ#.+.^Q...qu.....i.}^v.p....%]..|I.K%.}..,.8W...>..r...<.!...l..V.r....%!.-x+.o..V.....zJ..9.q...+.......U..P..*...........]hS..m2.W1"....c2.Ud...0_...5.....I...m....."...........Ss..p.......I...r.\3k..$...^f...F.....Q.1ZU< L...N.....H...pUx8E....3...N...F...W.....Y..>..j.i..../.=24f.:.t...lZa.9
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Zip archive data, at least v2.0 to extract, compression method=deflate
    Category:dropped
    Size (bytes):8351
    Entropy (8bit):7.941234216292513
    Encrypted:false
    SSDEEP:192:ssNBCL5P2e6GPAiemai+JPpfgDo3ZKSUSbp:s24LIe6GPAsaXpmYgSF
    MD5:8FFD4BC885E5A88ABD26B1BE51E940CE
    SHA1:20ADAFD6DB1CB449B448765B80952FF344A33C06
    SHA-256:5EC01DAC414B3D89080286500285DE00F1B62ADBCA1AB905CA712A89A3E769A3
    SHA-512:DB49429A4F1F8357D977A0ADFAD89C99437A68B016B0452939889B6B2AA1E0CD4088873C9453C3646276B553B6F89ED19C185C0D76ADD6453E53C56081DA0CE7
    Malicious:false
    Reputation:low
    Preview:PK...........V...............Deadlock.javaUT...%..d%..dux..............XKw.H...W.....d.I.....9.P......%.&...v......X.!;.y.Z...{..~.....G.$..T.,r...trt......>9.."I"....T....U.D.3..(".Q*3......C.2TY..Y..$f.*2I*.,).@C.L."..y...>.|A.....e..j....}....L.*.eH.4.U!n...%..E..o(H.P1S.(....jD/[.e..k..$.u..0)....,...M%.Q..*.}...".2.Z..qS1H."..25...R......a...G.Qik..&A..q...q.$ Hi..JD.:.:v..4.i.X*..4.XJV.J.8Y?.@..Z@...I3....<....8.S.).=.I..t..1.....f...)Y2..8!.,.l%..1.*N...+..,..V...G.s._..E.....{h.........k._.t...9....w.......1....3s|M..ky.9.....<.p.o[^...`4....>...O#...A.;.R/....3.....~........3....3.3ib..=..L..&Sw.x..}C...L.....% .....'....Z.:Wc....4.=...y:.Jy0wh...g..w.x.Z...M......>Z..t.....z./S...y.#{..Q.L].u.O........q....~.....F..=7..>..f...(..(@~:.l.C{.[.;...3>@..!hj.{....p..^.....:.}...p.{..Lv.....&.D.~.X..[.#....,&p......D.~...LH.j.9h...u&.....%...........].v...>.....aY.em.;.j4..."4...C.z.......Nc.K...n>..d..........A..H.$.D....*B.b....
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java archive data (JAR)
    Category:dropped
    Size (bytes):11054
    Entropy (8bit):7.825944661182623
    Encrypted:false
    SSDEEP:192:1BCQHgl+FgaIv6+ndzD7BpEo2eseXFQXVBfWzNfNHf1VbhEt+hxYedUzCyed2T:14QHgl+F8Fnddp12ReXFQXVBfYldMt+Q
    MD5:BBE79069B0933E4DC09E17336C161BAB
    SHA1:15BA82B606369F6B4F6F338C59619A57FF09B233
    SHA-256:C434959AADB4116CE8010025DF253D715E5FD4E40B765F6BE6B8AB45746E5A59
    SHA-512:AEF7AF16CEB7F8F7E04B53DC8B9FAE97B01D6C6EB3B196E80A2BDADCD70C04FF6C551660589482FE093889A4CF9AE3EC30E9AA323CEAA2C6FE006CBDA3123BCA
    Malicious:false
    Reputation:low
    Preview:PK..........V................META-INF/......PK..............PK..........V................META-INF/MANIFEST.MFm....0.E....,u.u.t..E.QT.....HfJ.......v...3sd[Q..-.....O{Z..v.#..1...(......G..... |.~...Q...F.V...y.....".q...Z.-.&...c%..xY.....2........T.f..{<..F<.l..?._.Vs......b..Z+..PK...pL.....K...PK...........V................JTop$1.classuQMO.@.}#Hi.._..&VL.&.4^.&.............[&.....?.8[M..&;3.......w....1.......B.@.s..5T...mv"....]4..C..\.F...........-...+.U.k...4=FRA,.Z.d..8h.3W%tU..q............hb..&4dM..X...5....U..O0..........G.g7...vY.b..9.k)Y....9..G._..!/.>...tE@.X..sh....$y...R.M.E+...x...2...%....a...h...1.;/..+...&..{..v.....{F..>.FH...-0T+.0..)....d.....B.!..V..PK....!.l.......PK...........V................JTop$2.classEQ.N.0...A..h(.....B.HA.@\*...C....M...:U...B..8..|.b.".w.3.......p...9,..c.@.e........#...$.2.4..pxB./..Aw&..=C..v.C..Kq..:"j.N@H6J%EG..V.F...UCW.>.q..K/.c_..D..v5.........:.Mla..V".....RD.....,...p.so:}.%..)t.J9q.SzJ..
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:ASCII text
    Category:dropped
    Size (bytes):2154
    Entropy (8bit):4.852793383472569
    Encrypted:false
    SSDEEP:48:GLg+Lc95WabYS94dUyh/wuUpA1IIAQbWFICczKBaUn:dycRv4d/77EF
    MD5:8750629A101578D95F985C9F9B62732A
    SHA1:5199B6D5C9F93F502AF60BB2379C73EEFAC05FCB
    SHA-256:448A61647F74860DC1AB7E6468EFB23FE67278A4FE1C837DC3B6D2BA6605710B
    SHA-512:6BAB90D5A2CC200AF07E302CB19F4FC8B3717A237457CA0EB714042A662A259E04107B93B1F24A953E019CD169AE1DCBF08E67F20849CC2FED4D0398CD30BB8D
    Malicious:false
    Reputation:low
    Preview:JTop monitors the CPU usage of all threads in a remote application.which has remote management enabled. JTop demonstrates the use of .the java.lang.management API to obtain the CPU consumption for .each thread...JTop is also a JConsole Plugin. See below for details...JTop Standalone GUI.===================..JTop first establishes a connection to a JMX agent in a remote.application with a JMX service URL:. service:jmx:rmi:///jndi/rmi://<hostName>:<portNum>/jmxrmi..where <hostName> is the hostname and <portNum> is the port number.to which the JMX agent will be connected...To run the demo.---------------.(1) Start the application with the JMX agent - here's an example of . how the Java2D is started. . java -Dcom.sun.management.jmxremote.port=1090. -Dcom.sun.management.jmxremote.ssl=false. -Dcom.sun.management.jmxremote.authenticate=false. -jar <JDK_HOME>/demo/jfc/Java2D/Java2Demo.jar.. This instruction uses the Sun's built-in support to enabl
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Zip archive data, at least v2.0 to extract, compression method=deflate
    Category:dropped
    Size (bytes):8930
    Entropy (8bit):7.899687933994991
    Encrypted:false
    SSDEEP:192:ljGQT1mqQ6LZPR1DlA0lvGvPwMWdBSAz5X8z2Fpi4Uzo:kAFQ69J1hA0mYtzl8zI84UE
    MD5:BD6F2FFAFEBD6928C8C65BC8B5AD04BE
    SHA1:39EDF110BC9D6783CAB2FF564AC4437FFC601841
    SHA-256:9F3BE3DC5CDF76C1179BB1AEBB06289DBCB9FA2A15EA068F90370749DD988453
    SHA-512:6419E0F78C7F4036C8562E85573CAD891C2A525E09E7303FD5F10F7E324D8DACD2BAF9405FF6D7903429DDF29E1D3D761F5928501C855073DC97BA1EF430E6D2
    Malicious:false
    Reputation:low
    Preview:PK...........V.3..~...>:......JTop.javaUT...%..d%..dux..............[.s.F...G.f...D.|g(...H..;.l*..M.1.08t.T............e.-..w...u.......$X.2a...........w.(...^.....Tx.E..^&S[..P0\*....F.6....4K..<....<.".D...Q.. .{...u...A...B?.<#,......#...%Rld...L.b..7../......0.o.h).q.......[..fM...."^.|.c...4.H..~..w...+.&.E.(...`I.....OE.e.3......2....T....@`?...O..%k....ZF.W.. .D.a.$.....0...".e...&........c......+tq.....G.".2..T...u.I.T.w.. ..@..{..4^d.....D..s.1...|.yW..,M.)...DLF...{cG...x..=s.....tD.t.e._L..hp.'.7<...t..#<..M..;..w.....|5v&.1....j.....{..L:.....3wx...!.............i......../.k...../L.;.......W.......1a....F.G.|g.?..-.....3...Eo0h.;.<t..s.)..n{..G..g...OI..[.Z.....\9}._.....z./....N......Y.w.!....+.gc.x.N&......8...X..g...;.7b0...f...".^GK.,..V`..l.......gWSw4..?CC...3V.h.2CY....%L..6GG|.p.jL.e..H..h.?5..$.95.%<C.|..;.C.F..;q.a=....V"....3......W.=....[W..D..K...p..........8x..@....*..Fr@..a.$. qp......%.4...ey.......
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:ASCII text
    Category:dropped
    Size (bytes):2154
    Entropy (8bit):4.852793383472569
    Encrypted:false
    SSDEEP:48:GLg+Lc95WabYS94dUyh/wuUpA1IIAQbWFICczKBaUn:dycRv4d/77EF
    MD5:8750629A101578D95F985C9F9B62732A
    SHA1:5199B6D5C9F93F502AF60BB2379C73EEFAC05FCB
    SHA-256:448A61647F74860DC1AB7E6468EFB23FE67278A4FE1C837DC3B6D2BA6605710B
    SHA-512:6BAB90D5A2CC200AF07E302CB19F4FC8B3717A237457CA0EB714042A662A259E04107B93B1F24A953E019CD169AE1DCBF08E67F20849CC2FED4D0398CD30BB8D
    Malicious:false
    Reputation:low
    Preview:JTop monitors the CPU usage of all threads in a remote application.which has remote management enabled. JTop demonstrates the use of .the java.lang.management API to obtain the CPU consumption for .each thread...JTop is also a JConsole Plugin. See below for details...JTop Standalone GUI.===================..JTop first establishes a connection to a JMX agent in a remote.application with a JMX service URL:. service:jmx:rmi:///jndi/rmi://<hostName>:<portNum>/jmxrmi..where <hostName> is the hostname and <portNum> is the port number.to which the JMX agent will be connected...To run the demo.---------------.(1) Start the application with the JMX agent - here's an example of . how the Java2D is started. . java -Dcom.sun.management.jmxremote.port=1090. -Dcom.sun.management.jmxremote.ssl=false. -Dcom.sun.management.jmxremote.authenticate=false. -jar <JDK_HOME>/demo/jfc/Java2D/Java2Demo.jar.. This instruction uses the Sun's built-in support to enabl
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java archive data (JAR)
    Category:dropped
    Size (bytes):11054
    Entropy (8bit):7.825944661182623
    Encrypted:false
    SSDEEP:192:1BCQHgl+FgaIv6+ndzD7BpEo2eseXFQXVBfWzNfNHf1VbhEt+hxYedUzCyed2T:14QHgl+F8Fnddp12ReXFQXVBfYldMt+Q
    MD5:BBE79069B0933E4DC09E17336C161BAB
    SHA1:15BA82B606369F6B4F6F338C59619A57FF09B233
    SHA-256:C434959AADB4116CE8010025DF253D715E5FD4E40B765F6BE6B8AB45746E5A59
    SHA-512:AEF7AF16CEB7F8F7E04B53DC8B9FAE97B01D6C6EB3B196E80A2BDADCD70C04FF6C551660589482FE093889A4CF9AE3EC30E9AA323CEAA2C6FE006CBDA3123BCA
    Malicious:false
    Reputation:low
    Preview:PK..........V................META-INF/......PK..............PK..........V................META-INF/MANIFEST.MFm....0.E....,u.u.t..E.QT.....HfJ.......v...3sd[Q..-.....O{Z..v.#..1...(......G..... |.~...Q...F.V...y.....".q...Z.-.&...c%..xY.....2........T.f..{<..F<.l..?._.Vs......b..Z+..PK...pL.....K...PK...........V................JTop$1.classuQMO.@.}#Hi.._..&VL.&.4^.&.............[&.....?.8[M..&;3.......w....1.......B.@.s..5T...mv"....]4..C..\.F...........-...+.U.k...4=FRA,.Z.d..8h.3W%tU..q............hb..&4dM..X...5....U..O0..........G.g7...vY.b..9.k)Y....9..G._..!/.>...tE@.X..sh....$y...R.M.E+...x...2...%....a...h...1.;/..+...&..{..v.....{F..>.FH...-0T+.0..)....d.....B.!..V..PK....!.l.......PK...........V................JTop$2.classEQ.N.0...A..h(.....B.HA.@\*...C....M...:U...B..8..|.b.".w.3.......p...9,..c.@.e........#...$.2.4..pxB./..Aw&..=C..v.C..Kq..:"j.N@H6J%EG..V.F...UCW.>.q..K/.c_..D..v5.........:.Mla..V".....RD.....,...p.so:}.%..)t.J9q.SzJ..
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Zip archive data, at least v2.0 to extract, compression method=deflate
    Category:dropped
    Size (bytes):8930
    Entropy (8bit):7.899687933994991
    Encrypted:false
    SSDEEP:192:ljGQT1mqQ6LZPR1DlA0lvGvPwMWdBSAz5X8z2Fpi4Uzo:kAFQ69J1hA0mYtzl8zI84UE
    MD5:BD6F2FFAFEBD6928C8C65BC8B5AD04BE
    SHA1:39EDF110BC9D6783CAB2FF564AC4437FFC601841
    SHA-256:9F3BE3DC5CDF76C1179BB1AEBB06289DBCB9FA2A15EA068F90370749DD988453
    SHA-512:6419E0F78C7F4036C8562E85573CAD891C2A525E09E7303FD5F10F7E324D8DACD2BAF9405FF6D7903429DDF29E1D3D761F5928501C855073DC97BA1EF430E6D2
    Malicious:false
    Reputation:low
    Preview:PK...........V.3..~...>:......JTop.javaUT...%..d%..dux..............[.s.F...G.f...D.|g(...H..;.l*..M.1.08t.T............e.-..w...u.......$X.2a...........w.(...^.....Tx.E..^&S[..P0\*....F.6....4K..<....<.".D...Q.. .{...u...A...B?.<#,......#...%Rld...L.b..7../......0.o.h).q.......[..fM...."^.|.c...4.H..~..w...+.&.E.(...`I.....OE.e.3......2....T....@`?...O..%k....ZF.W.. .D.a.$.....0...".e...&........c......+tq.....G.".2..T...u.I.T.w.. ..@..{..4^d.....D..s.1...|.yW..,M.)...DLF...{cG...x..=s.....tD.t.e._L..hp.'.7<...t..#<..M..;..w.....|5v&.1....j.....{..L:.....3wx...!.............i......../.k...../L.;.......W.......1a....F.G.|g.?..-.....3...Eo0h.;.<t..s.)..n{..G..g...OI..[.Z.....\9}._.....z./....N......Y.w.!....+.gc.x.N&......8...X..g...;.7b0...f...".^GK.,..V`..l.......gWSw4..?CC...3V.h.2CY....%L..6GG|.p.jL.e..H..h.?5..$.95.%<C.|..;.C.F..;q.a=....V"....3......W.=....[W..D..K...p..........8x..@....*..Fr@..a.$. qp......%.4...ey.......
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java archive data (JAR)
    Category:dropped
    Size (bytes):11331
    Entropy (8bit):7.886856333184142
    Encrypted:false
    SSDEEP:192:Ojgxq3ARLW5ZpjBTG1aM1CbMrGrFsv0yDLo8okXrH8QqL2hKRnPBoC3UgAcOkXbR:O6KAC/GoM1fyrFsvXfrBqTR5oWyW
    MD5:1953B2080B8626F6976FD82DD550BEB9
    SHA1:80067DB98178A316739780C6E6F7B1E5AE30FA4E
    SHA-256:E467B391DF8CE5D734424E20D9DD2313467E1921E0EB7A983558E6C40E878DD3
    SHA-512:3D67AFE7BCF83968D33720D118FFDC620D2CFE96F5449B9555B2B1B3DA25289A1710BE337DD5A77EF79DE39F0803B86DBD3A22C369598F144AE88610AEBCE4FA
    Malicious:false
    Reputation:low
    Preview:PK..........V................META-INF/......PK..............PK..........V................META-INF/MANIFEST.MFm.Mk.A.........a.....t..R...1...d.....-m..&.o.(...-..*.L.wM.#%...kX.s.T......dN.K9...........l..[O.;..B.j....HP..j.[yy{.1wj......}....j#./...J/S...~..A.4..........R........U..w.PK...G`3....T...PK...........V................MemoryMonitor$1.classuT.R.@....BC.Z." .Z.RP.q.+(."Z...qi..I.N.\...S......?|._.7P......s...w6....w..X. .+:....W.$.J.._Y.T..tD1.c.7t..p.Rni..R..J..0.a..Jn.^. C]<!......t.Q...dN0..b}K.........vv]..|."..u.=....H3t..o....]..;...O+..T..<...B...Bk..2..t...1.p.....J.O.)..L;..r.IS..&L.h@.......1Lk.1.Hy.c......#.a..S,hxf..I..xa`......-ng..{)...c.x.`V.X.$.Q.[...0k..Y....v..Si...%....Z.K../.X..T.#.,.XJ;1..c.Bl.f.m...Z..O.u....).h.g...tr..c...........[.....4.._S.9.c..{...BRs-.p.bO..JS....m(#.z.f.%..\..T.....FHg..D...r..D.n....7.P.YB..@+..y*=.]..w.e..$.4W.iK\....>X....GV.=Mh..nzW.=..........V.U...$/.....>....C.<|J........
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:ASCII text
    Category:dropped
    Size (bytes):2226
    Entropy (8bit):5.13823044183685
    Encrypted:false
    SSDEEP:48:ZZyOlrYJErYJFHvv432sDt32sWEtPu3tOHD72cqv+hF7G25IAQbWFICi:ZZPlrYJErYJFPQ3vt3S34jinUdfct
    MD5:AFF77FDE354FF9A2F259F352722C6787
    SHA1:8A0F66BF350C6D76A03031D06D1A835E3BCE0329
    SHA-256:B570E8568251C5D6FE1588916A1E4BC7797FFA73EEAAD0E8B244CAEFFF1FC82F
    SHA-512:CD6A206E0D8CFB9724C9CCE47584DD3E5B7E3E05A54B5B3F990D30FE549F91978BE8F04AC601B412B2054DAC9F46A75289DA9E5B04B542B21425F5A399D39AC4
    Malicious:false
    Reputation:low
    Preview:#.# Copyright (c) 2004, 2012, Oracle and/or its affiliates. All rights reserved..#.# Redistribution and use in source and binary forms, with or without.# modification, are permitted provided that the following conditions.# are met:.#.# - Redistributions of source code must retain the above copyright.# notice, this list of conditions and the following disclaimer..#.# - Redistributions in binary form must reproduce the above copyright.# notice, this list of conditions and the following disclaimer in the.# documentation and/or other materials provided with the distribution..#.# - Neither the name of Oracle nor the names of its.# contributors may be used to endorse or promote products derived.# from this software without specific prior written permission..#.# THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS.# IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,.# THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Zip archive data, at least v2.0 to extract, compression method=deflate
    Category:dropped
    Size (bytes):6531
    Entropy (8bit):7.944360500091719
    Encrypted:false
    SSDEEP:192:7OsPj23e+k8BlRXxu7Be26UDE8Unv9mto7RtRnPBoC3UgBQ:isPSuABlRhME26U7C4YtR5oW+
    MD5:0C56ADD55917AE7F0A99BCDF44F506DB
    SHA1:3E79923EBC958FEE5D6D783565AFF7E5A431233B
    SHA-256:B6AF1A88D3FA616E21383E5735F4AC676A7969EE6734DF2C60E85028DC051B83
    SHA-512:D1E9EC312CAFDEFB66262B433A268A8BF16FD6189DA6AF9D5A42E51DE40BA6917EA527CC765AC62BB2BD8B17483A4A8F5E5CCF15DD6CD3EB7086EED4AD613409
    Malicious:false
    Reputation:low
    Preview:PK...........V..*.....)C......MemoryMonitor.javaUT...%..d%..dux..............[{s...?.....%...?2....cem....r.n.h.l!1.0...w...n.%.d.^M.K.............z...E..i.....:~..:.x....tf....g.|n..p_gm.f...<.s..t.#.C>....&..r.B..>g..|w.M.J6...{fs.[.u..........tg......L.....V...[y.5.M.0..p.mwc9wl.:3.:....-y.Q...N.=....;.... R`._.lN.GjRj.X.s....:@,..@Hxb.B.4c.:.Mk.=}.7..PM.........CL........;.........-1..e.~<.b..sR...}n....KN.).r......Y..x..\...g6.dG..e..-'...K7.L...8........R).;.6d.....S.1....<..G..'....#6..........p.........=..\.../gcv68...#..w.?..'W..^T.#Be.*...a....h..Cf\\......v.l.Fuf.;.W].......cvn\.c...u.W..'.....s....qn.o..Sc.'r...f.....\......jx9.....5F..q....L.0.}...lt.>?..;.....@...'=p.>9.Iz..k.{.1...u.Epy^g..^...!.}.A...N...Q...v.m_..@H.u.`.:W........NFcc|5./.AW.}..~3:...;....F.:...u%..@s.......:4...pxu96..*......m...e..Bf(k0..^.D...Qg.g=4.I.BkmR....` .e.....~.......`@...Q...3....J..|%d.A.o......s]..3NY... ..<.bd(....)._.{.+.C.V.A.Dp..Z.. .!p.W_....&
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:ASCII text
    Category:dropped
    Size (bytes):2226
    Entropy (8bit):5.13823044183685
    Encrypted:false
    SSDEEP:48:ZZyOlrYJErYJFHvv432sDt32sWEtPu3tOHD72cqv+hF7G25IAQbWFICi:ZZPlrYJErYJFPQ3vt3S34jinUdfct
    MD5:AFF77FDE354FF9A2F259F352722C6787
    SHA1:8A0F66BF350C6D76A03031D06D1A835E3BCE0329
    SHA-256:B570E8568251C5D6FE1588916A1E4BC7797FFA73EEAAD0E8B244CAEFFF1FC82F
    SHA-512:CD6A206E0D8CFB9724C9CCE47584DD3E5B7E3E05A54B5B3F990D30FE549F91978BE8F04AC601B412B2054DAC9F46A75289DA9E5B04B542B21425F5A399D39AC4
    Malicious:false
    Reputation:low
    Preview:#.# Copyright (c) 2004, 2012, Oracle and/or its affiliates. All rights reserved..#.# Redistribution and use in source and binary forms, with or without.# modification, are permitted provided that the following conditions.# are met:.#.# - Redistributions of source code must retain the above copyright.# notice, this list of conditions and the following disclaimer..#.# - Redistributions in binary form must reproduce the above copyright.# notice, this list of conditions and the following disclaimer in the.# documentation and/or other materials provided with the distribution..#.# - Neither the name of Oracle nor the names of its.# contributors may be used to endorse or promote products derived.# from this software without specific prior written permission..#.# THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS.# IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,.# THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java archive data (JAR)
    Category:dropped
    Size (bytes):11331
    Entropy (8bit):7.886856333184142
    Encrypted:false
    SSDEEP:192:Ojgxq3ARLW5ZpjBTG1aM1CbMrGrFsv0yDLo8okXrH8QqL2hKRnPBoC3UgAcOkXbR:O6KAC/GoM1fyrFsvXfrBqTR5oWyW
    MD5:1953B2080B8626F6976FD82DD550BEB9
    SHA1:80067DB98178A316739780C6E6F7B1E5AE30FA4E
    SHA-256:E467B391DF8CE5D734424E20D9DD2313467E1921E0EB7A983558E6C40E878DD3
    SHA-512:3D67AFE7BCF83968D33720D118FFDC620D2CFE96F5449B9555B2B1B3DA25289A1710BE337DD5A77EF79DE39F0803B86DBD3A22C369598F144AE88610AEBCE4FA
    Malicious:false
    Reputation:low
    Preview:PK..........V................META-INF/......PK..............PK..........V................META-INF/MANIFEST.MFm.Mk.A.........a.....t..R...1...d.....-m..&.o.(...-..*.L.wM.#%...kX.s.T......dN.K9...........l..[O.;..B.j....HP..j.[yy{.1wj......}....j#./...J/S...~..A.4..........R........U..w.PK...G`3....T...PK...........V................MemoryMonitor$1.classuT.R.@....BC.Z." .Z.RP.q.+(."Z...qi..I.N.\...S......?|._.7P......s...w6....w..X. .+:....W.$.J.._Y.T..tD1.c.7t..p.Rni..R..J..0.a..Jn.^. C]<!......t.Q...dN0..b}K.........vv]..|."..u.=....H3t..o....]..;...O+..T..<...B...Bk..2..t...1.p.....J.O.)..L;..r.IS..&L.h@.......1Lk.1.Hy.c......#.a..S,hxf..I..xa`......-ng..{)...c.x.`V.X.$.Q.[...0k..Y....v..Si...%....Z.K../.X..T.#.,.XJ;1..c.Bl.f.m...Z..O.u....).h.g...tr..c...........[.....4.._S.9.c..{...BRs-.p.bO..JS....m(#.z.f.%..\..T.....FHg..D...r..D.n....7.P.YB..@+..y*=.]..w.e..$.4W.iK\....>X....GV.=Mh..nzW.=..........V.U...$/.....>....C.<|J........
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Zip archive data, at least v2.0 to extract, compression method=deflate
    Category:dropped
    Size (bytes):6531
    Entropy (8bit):7.944360500091719
    Encrypted:false
    SSDEEP:192:7OsPj23e+k8BlRXxu7Be26UDE8Unv9mto7RtRnPBoC3UgBQ:isPSuABlRhME26U7C4YtR5oW+
    MD5:0C56ADD55917AE7F0A99BCDF44F506DB
    SHA1:3E79923EBC958FEE5D6D783565AFF7E5A431233B
    SHA-256:B6AF1A88D3FA616E21383E5735F4AC676A7969EE6734DF2C60E85028DC051B83
    SHA-512:D1E9EC312CAFDEFB66262B433A268A8BF16FD6189DA6AF9D5A42E51DE40BA6917EA527CC765AC62BB2BD8B17483A4A8F5E5CCF15DD6CD3EB7086EED4AD613409
    Malicious:false
    Reputation:low
    Preview:PK...........V..*.....)C......MemoryMonitor.javaUT...%..d%..dux..............[{s...?.....%...?2....cem....r.n.h.l!1.0...w...n.%.d.^M.K.............z...E..i.....:~..:.x....tf....g.|n..p_gm.f...<.s..t.#.C>....&..r.B..>g..|w.M.J6...{fs.[.u..........tg......L.....V...[y.5.M.0..p.mwc9wl.:3.:....-y.Q...N.=....;.... R`._.lN.GjRj.X.s....:@,..@Hxb.B.4c.:.Mk.=}.7..PM.........CL........;.........-1..e.~<.b..sR...}n....KN.).r......Y..x..\...g6.dG..e..-'...K7.L...8........R).;.6d.....S.1....<..G..'....#6..........p.........=..\.../gcv68...#..w.?..'W..^T.#Be.*...a....h..Cf\\......v.l.Fuf.;.W].......cvn\.c...u.W..'.....s....qn.o..Sc.'r...f.....\......jx9.....5F..q....L.0.}...lt.>?..;.....@...'=p.>9.Iz..k.{.1...u.Epy^g..^...!.}.A...N...Q...v.m_..@H.u.`.:W........NFcc|5./.AW.}..~3:...;....F.:...u%..@s.......:4...pxu96..*......m...e..Bf(k0..^.D...Qg.g=4.I.BkmR....` .e.....~.......`@...Q...3....J..|%d.A.o......s]..3NY... ..<.bd(....)._.{.+.C.V.A.Dp..Z.. .!p.W_....&
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:ASCII text
    Category:dropped
    Size (bytes):1360
    Entropy (8bit):4.786745295892349
    Encrypted:false
    SSDEEP:24:aCFKsvnWreYR/ngh/h/VAhZ6lpjCRN0DVs/NA9b21FIsXvev:1F5WSY+hh/V3pW3IAQbWFIC4
    MD5:0A4FFA3836C8F84D647F4F0FE6F912AC
    SHA1:1305BE174F49719D6229ABCE3BDCA8C5E676F261
    SHA-256:8B6074132F18183584FF92066E4FCA8842562CB9B94808DB574338E9BF8D093A
    SHA-512:6F419ADFE549CF91F4742505E5297B3ED17406076E8EA4BEBFB2C4E3DC5D7E045041D666C090306DDC167DA242CA64BF39B7BC6CF67128F3D2E888ACB7EAA9F8
    Malicious:false
    Reputation:low
    Preview:VerboseGC demonstrates the use of the java.lang.management API to .print the garbage collection statistics and memory usage remotely .by connecting to a JMX agent with a JMX service URL:. service:jmx:rmi:///jndi/rmi://<hostName>:<portNum>/jmxrmi.where <hostName> is the hostname and <portNum> is the port number.to which the JMX agent will be connected...To run the VerboseGC demo..(1) Start the application with the JMX agent - here's an example of . how the Java2D is started.. java -Dcom.sun.management.jmxremote.port=1090. -Dcom.sun.management.jmxremote.ssl=false. -Dcom.sun.management.jmxremote.authenticate=false. -jar <JDK_HOME>/demo/jfc/Java2D/Java2Demo.jar.. This instruction uses the Sun's built-in support to enable a JMX agent.. You can programmatically start a JMX agent with the RMI connector. using javax.management.remote API. See the javadoc and examples for. javax.management.remote API for details...(2) Run VerboseGC. . java
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java archive data (JAR)
    Category:dropped
    Size (bytes):5589
    Entropy (8bit):7.825176481665062
    Encrypted:false
    SSDEEP:96:VBkAwcolt+OpZjaEUy82Ya28gx5dw8XhRCHVn/3oE+FcYr5hx6lJ0pWb5FcCxK9n:nrLw9pZFUJ2M8gbpXnKVoEwH9T6MWdF6
    MD5:97D6F8EB483F78AC68677096BE76DDBD
    SHA1:2FEEFB7D2C77DAFC241D5C30FD380A4ADDDB28B6
    SHA-256:B11CDF1B5055B76C19E12A04A4688FC2BE6168B71743E4696DD62645F82FFDB0
    SHA-512:1DCF391340A4A4AA708C2409F389FA2800040AA9C91A6C5A4C0E00D24CC4B6F2255825F1C65BAEB445098A58FFE40E73AF393CDA2092D6E0A1F830834D689C3A
    Malicious:false
    Reputation:low
    Preview:PK..........V................META-INF/......PK..............PK..........V................META-INF/MANIFEST.MFm.A..0.....9.E.A.M.H....u..S.$3%....u.WW.:..o.d.RL.B..%..V...y..r.>lrT......'...|.A..z..&..s4)..vdlk...V..#.$t...+...v.Z......`......@.h..N.J..zS.g....M......U....a.%\..$..J.oPK..g.......P...PK...........V................PrintGCStat.class.W.|.W...d.3...$..0.p.rV.J....I..PR.8.....ev6M.-.R(.KK[.Z.Z.]....-V.Zm..Vm..x.G...}..=..b~..w..w....<.......%.r.........h6../.:......n..]p.z.7H..G.H..B.L7n.>.7.0.&..w...p. n..!^xX..7n....C....~........8.{$..."..>~.....w.c.}.....e<......e|.;....2>..B|L.C....!.......).|Z.gx.2>.F!....q.'\8.GX.)...3,cD.s........Q....,.O..xL...<.3.N3..!..;.~.:.....jH..Z....YzPk..@.:....E....a.&.Ya..D.rc...[..ES.z_H...&p.......A"..V.....6......&......^.0S..Y.F".i.F(.V..=../ .".W.!.Z)P^jK.H3..tjf.f..P.....e...>.O...!.=J...X..%...{m......._ ..[%<)...u..Z.6E..2KY......cD..^.e.a.U.M..t.A~i...;-...g...a...%.....qu.Q.Wk.......#.*
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:ASCII text
    Category:dropped
    Size (bytes):1360
    Entropy (8bit):4.786745295892349
    Encrypted:false
    SSDEEP:24:aCFKsvnWreYR/ngh/h/VAhZ6lpjCRN0DVs/NA9b21FIsXvev:1F5WSY+hh/V3pW3IAQbWFIC4
    MD5:0A4FFA3836C8F84D647F4F0FE6F912AC
    SHA1:1305BE174F49719D6229ABCE3BDCA8C5E676F261
    SHA-256:8B6074132F18183584FF92066E4FCA8842562CB9B94808DB574338E9BF8D093A
    SHA-512:6F419ADFE549CF91F4742505E5297B3ED17406076E8EA4BEBFB2C4E3DC5D7E045041D666C090306DDC167DA242CA64BF39B7BC6CF67128F3D2E888ACB7EAA9F8
    Malicious:false
    Reputation:low
    Preview:VerboseGC demonstrates the use of the java.lang.management API to .print the garbage collection statistics and memory usage remotely .by connecting to a JMX agent with a JMX service URL:. service:jmx:rmi:///jndi/rmi://<hostName>:<portNum>/jmxrmi.where <hostName> is the hostname and <portNum> is the port number.to which the JMX agent will be connected...To run the VerboseGC demo..(1) Start the application with the JMX agent - here's an example of . how the Java2D is started.. java -Dcom.sun.management.jmxremote.port=1090. -Dcom.sun.management.jmxremote.ssl=false. -Dcom.sun.management.jmxremote.authenticate=false. -jar <JDK_HOME>/demo/jfc/Java2D/Java2Demo.jar.. This instruction uses the Sun's built-in support to enable a JMX agent.. You can programmatically start a JMX agent with the RMI connector. using javax.management.remote API. See the javadoc and examples for. javax.management.remote API for details...(2) Run VerboseGC. . java
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java archive data (JAR)
    Category:dropped
    Size (bytes):5589
    Entropy (8bit):7.825176481665062
    Encrypted:false
    SSDEEP:96:VBkAwcolt+OpZjaEUy82Ya28gx5dw8XhRCHVn/3oE+FcYr5hx6lJ0pWb5FcCxK9n:nrLw9pZFUJ2M8gbpXnKVoEwH9T6MWdF6
    MD5:97D6F8EB483F78AC68677096BE76DDBD
    SHA1:2FEEFB7D2C77DAFC241D5C30FD380A4ADDDB28B6
    SHA-256:B11CDF1B5055B76C19E12A04A4688FC2BE6168B71743E4696DD62645F82FFDB0
    SHA-512:1DCF391340A4A4AA708C2409F389FA2800040AA9C91A6C5A4C0E00D24CC4B6F2255825F1C65BAEB445098A58FFE40E73AF393CDA2092D6E0A1F830834D689C3A
    Malicious:false
    Reputation:low
    Preview:PK..........V................META-INF/......PK..............PK..........V................META-INF/MANIFEST.MFm.A..0.....9.E.A.M.H....u..S.$3%....u.WW.:..o.d.RL.B..%..V...y..r.>lrT......'...|.A..z..&..s4)..vdlk...V..#.$t...+...v.Z......`......@.h..N.J..zS.g....M......U....a.%\..$..J.oPK..g.......P...PK...........V................PrintGCStat.class.W.|.W...d.3...$..0.p.rV.J....I..PR.8.....ev6M.-.R(.KK[.Z.Z.]....-V.Zm..Vm..x.G...}..=..b~..w..w....<.......%.r.........h6../.:......n..]p.z.7H..G.H..B.L7n.>.7.0.&..w...p. n..!^xX..7n....C....~........8.{$..."..>~.....w.c.}.....e<......e|.;....2>..B|L.C....!.......).|Z.gx.2>.F!....q.'\8.GX.)...3,cD.s........Q....,.O..xL...<.3.N3..!..;.~.:.....jH..Z....YzPk..@.:....E....a.&.Ya..D.rc...[..ES.z_H...&p.......A"..V.....6......&......^.0S..Y.F".i.F(.V..=../ .".W.!.Z)P^jK.H3..tjf.f..P.....e...>.O...!.=J...X..%...{m......._ ..[%<)...u..Z.6E..2KY......cD..^.e.a.U.M..t.A~i...;-...g...a...%.....qu.Q.Wk.......#.*
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Zip archive data, at least v2.0 to extract, compression method=deflate
    Category:dropped
    Size (bytes):5409
    Entropy (8bit):7.908710762896665
    Encrypted:false
    SSDEEP:96:g+ZdO+kwAeC6ZHhfAt3kloAUd2RCHVn/e++rujnoP6Oqx9ZAllXMd7WDJD2j:ZZE+60hfAt3klT9KiqLoCOI9Cllaa9Q
    MD5:9588E0D5CC19E86D983F57D2B9E4AF21
    SHA1:1C3DC37C29320DE91FC2B28908A2881CBF40F5C0
    SHA-256:09320C8FDB6502A7FB7297B21686725C7D658F708652C2EE3D08B2B07B92BBE2
    SHA-512:82962CD9B0B3164A0FA241EDC8E58A99F88F9134BBE2A0133835D5153C07CD63980B59AEEA1E44F8BF248EDABF4F04228B59001CB6CACC6EA235A41FB23564FD
    Malicious:false
    Reputation:low
    Preview:PK...........V.)t.N...........PrintGCStat.javaUT...%..d%..dux..............X.r.F.}.W..j. ........(dI..@..-...)$..Hf...{z. A...M.|.....O...x..^..o.E...H.O...7C.}.zHN.... ....`...8.D9"=IH.+...(.E4..C."....u....P]..3*..%$-.,(......C\........%.x...c.)(.mD..U%"...}.aP......$I..gk..,.yQ.(........=z%.W.G....!U..2r...y..I..ey..b.........-c<$..a..(F...4-....`.7.".k...a......q..0((E..8H.}.d....H7D[.r-.dA*.XS\Y..,3.2kY.....~...\G."'.Ex*.d.#.+AJ".c.....f.y%J..........k.kc....+SuV..(.+.#..ot.$..sm..1].b.$.....+g:6].t{....Z.......1....n..q.G.K.l>.....n.......bl.!..l..5.|...P.2..$.f.k\.~aM-.V...|..].Ns..-c1.]F./....-.......$...k.....^..m..@..n..&...SS.C.c.5.........!ys.0` ..t.v....3.Y...4.g..Aj..Y2..9c...[\x../|.&.3..{.{m......'.[x..N|}.D..(..._,<Kjh...o9.).~...T....e...qo..H..L.n.LL.,.TMg9<.g.]3...~'X......a...@7.g."{..M.......s..M.-Y.m=.ev.$}|m1.....YM.H...F}..g''gjs....q.9`..I.&V.q.^..Z.......DP.l>..Dx..kuJ..%.=."..K. ..8.$.8rH.T
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Zip archive data, at least v2.0 to extract, compression method=deflate
    Category:dropped
    Size (bytes):5409
    Entropy (8bit):7.908710762896665
    Encrypted:false
    SSDEEP:96:g+ZdO+kwAeC6ZHhfAt3kloAUd2RCHVn/e++rujnoP6Oqx9ZAllXMd7WDJD2j:ZZE+60hfAt3klT9KiqLoCOI9Cllaa9Q
    MD5:9588E0D5CC19E86D983F57D2B9E4AF21
    SHA1:1C3DC37C29320DE91FC2B28908A2881CBF40F5C0
    SHA-256:09320C8FDB6502A7FB7297B21686725C7D658F708652C2EE3D08B2B07B92BBE2
    SHA-512:82962CD9B0B3164A0FA241EDC8E58A99F88F9134BBE2A0133835D5153C07CD63980B59AEEA1E44F8BF248EDABF4F04228B59001CB6CACC6EA235A41FB23564FD
    Malicious:false
    Reputation:low
    Preview:PK...........V.)t.N...........PrintGCStat.javaUT...%..d%..dux..............X.r.F.}.W..j. ........(dI..@..-...)$..Hf...{z. A...M.|.....O...x..^..o.E...H.O...7C.}.zHN.... ....`...8.D9"=IH.+...(.E4..C."....u....P]..3*..%$-.,(......C\........%.x...c.)(.mD..U%"...}.aP......$I..gk..,.yQ.(........=z%.W.G....!U..2r...y..I..ey..b.........-c<$..a..(F...4-....`.7.".k...a......q..0((E..8H.}.d....H7D[.r-.dA*.XS\Y..,3.2kY.....~...\G."'.Ex*.d.#.+AJ".c.....f.y%J..........k.kc....+SuV..(.+.#..ot.$..sm..1].b.$.....+g:6].t{....Z.......1....n..q.G.K.l>.....n.......bl.!..l..5.|...P.2..$.f.k\.~aM-.V...|..].Ns..-c1.]F./....-.......$...k.....^..m..@..n..&...SS.C.c.5.........!ys.0` ..t.v....3.Y...4.g..Aj..Y2..9c...[\x../|.&.3..{.{m......'.[x..N|}.D..(..._,<Kjh...o9.).~...T....e...qo..H..L.n.LL.,.TMg9<.g.]3...~'X......a...@7.g."{..M.......s..M.-Y.m=.ev.$}|m1.....YM.H...F}..g''gjs....q.9`..I.&V.q.^..Z.......DP.l>..Dx..kuJ..%.=."..K. ..8.$.8rH.T
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:HTML document, ASCII text
    Category:dropped
    Size (bytes):802
    Entropy (8bit):5.002116665151789
    Encrypted:false
    SSDEEP:24:9h7b+KGrCgnyva6wH7d7pwU1eVc+d2bbn:9wDM+7M3daT
    MD5:B302B3CA7F544E6B62AEC9E599E5E9C4
    SHA1:75F7607F506960C112BA89C63FC6B97C60F86491
    SHA-256:0D009775D9BE6A7D97E2FFDCC04BD0C0E6F9607BCDF3BD52C82905679DCD4803
    SHA-512:667E26D7C88EF51EEAA43676094D6EEE9C58A75C5FC9213FFFF91224F645096D2DAE807991C3AB44483322B0512707147EEFF00B7F26768B9C4D739ABDB895EB
    Malicious:false
    Reputation:low
    Preview:<html>.<head> <title>java.lang.management Demonstration Code</title> </head>...<h1>java.lang.management Demonstration Code</h1>..<ul>..<li>.<A HREF="FullThreadDump">FullThreadDump</A>.<br>.Shows how to get thread dumps and look for deadlocks..</li>..<li>.<A HREF="VerboseGC">VerboseGC</A>.<br>.Shows how you can find out about Garbage Collection in the VM..</li>..<li>.<A HREF="MemoryMonitor">MemoryMonitor</A>.<br>.Shows how you can find out the memory usage in the VM..</li>..<li>.<A HREF="JTop">JTop</A>.<br>.Shows how you can find out the threads with top CPU usage..</li>...</ul>....<h2>Comments and Feedback</h2>..<p>.Comments regarding java.lang.management API or on any of these .demonstrations should be sent through .<A HREF="http://java.sun.com/mail">http://java.sun.com/mail/</A>...</html>.
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:HTML document, ASCII text
    Category:dropped
    Size (bytes):802
    Entropy (8bit):5.002116665151789
    Encrypted:false
    SSDEEP:24:9h7b+KGrCgnyva6wH7d7pwU1eVc+d2bbn:9wDM+7M3daT
    MD5:B302B3CA7F544E6B62AEC9E599E5E9C4
    SHA1:75F7607F506960C112BA89C63FC6B97C60F86491
    SHA-256:0D009775D9BE6A7D97E2FFDCC04BD0C0E6F9607BCDF3BD52C82905679DCD4803
    SHA-512:667E26D7C88EF51EEAA43676094D6EEE9C58A75C5FC9213FFFF91224F645096D2DAE807991C3AB44483322B0512707147EEFF00B7F26768B9C4D739ABDB895EB
    Malicious:false
    Reputation:low
    Preview:<html>.<head> <title>java.lang.management Demonstration Code</title> </head>...<h1>java.lang.management Demonstration Code</h1>..<ul>..<li>.<A HREF="FullThreadDump">FullThreadDump</A>.<br>.Shows how to get thread dumps and look for deadlocks..</li>..<li>.<A HREF="VerboseGC">VerboseGC</A>.<br>.Shows how you can find out about Garbage Collection in the VM..</li>..<li>.<A HREF="MemoryMonitor">MemoryMonitor</A>.<br>.Shows how you can find out the memory usage in the VM..</li>..<li>.<A HREF="JTop">JTop</A>.<br>.Shows how you can find out the threads with top CPU usage..</li>...</ul>....<h2>Comments and Feedback</h2>..<p>.Comments regarding java.lang.management API or on any of these .demonstrations should be sent through .<A HREF="http://java.sun.com/mail">http://java.sun.com/mail/</A>...</html>.
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:ASCII text
    Category:dropped
    Size (bytes):1291
    Entropy (8bit):4.557548872768495
    Encrypted:false
    SSDEEP:24:ERmRizYXL3G+ZW8cBkkvPeCNz/yKXRCWFMitU:E8h7e/G5Aa
    MD5:555D1BB1D773E82813F23BC8A3FF6BBD
    SHA1:909DBB04B282A06FCF1D88E6F41BEC302C315925
    SHA-256:46C830EACD3128A41C3E0F086ACBBD3FAECF2E1388BC23CDC43179EF364C7384
    SHA-512:D2CB0A86E2FB117D32EAB52695DE4D496ECEBA944998E4C47AD53CB04F83EC0603DD1295A932828914C568B30EDD8257FA496B886102B8409749A8C945EC53CD
    Malicious:false
    Reputation:low
    Preview: NetBeans Project Files for JDK Demos..This directory contains project files for the NetBeans IDE for the all-Java.JDK demos (some of the demos involve C code; no NetBeans project files are.provided for them at this time). For example, to bring up the Java2D demo.in NetBeans, do the following:..1. If you do not already have NetBeans, download it from. http://www.netbeans.org/. and follow the directions for installation..2. Start NetBeans..3. From the main menu, choose File -> Open Project..4. In the popup window, navigate to the JDK distribution and within that to. the "demo" directory..5. Press the "Open Project Folder" button. That will open all of the demos. (for which there are project files) as subprojects..6. There should now be a Java2D project in the Projects tab of the IDE.. Right-click on the project name and choose an appropriate action, e.g.. Clean and Build Project. and then. Run Project. Some, but not all, of the projects can b
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:ASCII text
    Category:dropped
    Size (bytes):1291
    Entropy (8bit):4.557548872768495
    Encrypted:false
    SSDEEP:24:ERmRizYXL3G+ZW8cBkkvPeCNz/yKXRCWFMitU:E8h7e/G5Aa
    MD5:555D1BB1D773E82813F23BC8A3FF6BBD
    SHA1:909DBB04B282A06FCF1D88E6F41BEC302C315925
    SHA-256:46C830EACD3128A41C3E0F086ACBBD3FAECF2E1388BC23CDC43179EF364C7384
    SHA-512:D2CB0A86E2FB117D32EAB52695DE4D496ECEBA944998E4C47AD53CB04F83EC0603DD1295A932828914C568B30EDD8257FA496B886102B8409749A8C945EC53CD
    Malicious:false
    Reputation:low
    Preview: NetBeans Project Files for JDK Demos..This directory contains project files for the NetBeans IDE for the all-Java.JDK demos (some of the demos involve C code; no NetBeans project files are.provided for them at this time). For example, to bring up the Java2D demo.in NetBeans, do the following:..1. If you do not already have NetBeans, download it from. http://www.netbeans.org/. and follow the directions for installation..2. Start NetBeans..3. From the main menu, choose File -> Open Project..4. In the popup window, navigate to the JDK distribution and within that to. the "demo" directory..5. Press the "Open Project Folder" button. That will open all of the demos. (for which there are project files) as subprojects..6. There should now be a Java2D project in the Projects tab of the IDE.. Right-click on the project name and choose an appropriate action, e.g.. Clean and Build Project. and then. Run Project. Some, but not all, of the projects can b
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):3002
    Entropy (8bit):5.008491069151138
    Encrypted:false
    SSDEEP:48:cU1OorYJTrYJEfDWQvs432sD32scMEtu33tYTHD2I8nwfDGhQKQQ0KHH14kN:boorYJTrYJEfiQX3f3jp2oxSq
    MD5:7371F7508D6208CD9F35C318DEB5EAAE
    SHA1:8DEBEE33AA82CB690837E0B695D0C8CB9AA11053
    SHA-256:AA89E750727FC85C87149F6A1D0D3EE78779C5525440DF11E61BD5531EF13FF8
    SHA-512:85FB9F90DF6753FDFFE85EBDC02C0C43CB628E639096A57FCB203CE18E8B7AA37180AD71FE28F47BDDD9B65A0A47B77608B72F2ADCE96DCF547EA3273354C2E4
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?>.. . Copyright (c) 2006, 2011, Oracle and/or its affiliates. All rights reserved... Redistribution and use in source and binary forms, with or without. modification, are permitted provided that the following conditions. are met:.. - Redistributions of source code must retain the above copyright. notice, this list of conditions and the following disclaimer... - Redistributions in binary form must reproduce the above copyright. notice, this list of conditions and the following disclaimer in the. documentation and/or other materials provided with the distribution... - Neither the name of Oracle nor the names of its. contributors may be used to endorse or promote products derived. from this software without specific prior written permission... THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. THE IMPLIED WARRANTIES OF MERCHANTA
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:ASCII text
    Category:dropped
    Size (bytes):407
    Entropy (8bit):4.709067636108353
    Encrypted:false
    SSDEEP:6:jSNT32Dj4MzJXk5tNPDjDNT38ytv4fNbGSYcSH7xAdCqLstpWNT3kDecXlL3XG4k:jtphut9GytvAoH7igwkhemRnPIn
    MD5:735FF9E6D9CF1DB4C4377D033D16A222
    SHA1:BE94633CA3FE74BF5A31E4878A1C351C8BFA1E7F
    SHA-256:6EADD8527561D368ABD513D32F5BF1673454A498DDDEF6CEBBFD0A51FC7406C8
    SHA-512:7D2EB984E99AAEC62DD0883D6CB95181FE9B148C326829C0532C70EDAD179C3BF71DB2E0F8BB3BDCA3F6AE10F24979E47069CD74EF957C695525165497A8F9EA
    Malicious:false
    Reputation:low
    Preview:main.dir=${basedir}/../../../jfc/FileChooserDemo..src.dir=${main.dir}/src..build.dir=build.classes.dir=${build.dir}/classes.jar=${main.dir}/FileChooserDemo.jar.javadoc.dir=${build.dir}/javadoc..build.sysclasspath=ignore.# E.g.: cp=lib/x.jar:lib/y.jar.cp=.extra.run.cp=..main.class=FileChooserDemo..run.cp=${cp}:${classes.dir}:${extra.run.cp}..debug=true.deprecation=false..nbjdk.home=${basedir}/../../../...
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):3575
    Entropy (8bit):5.083119218956585
    Encrypted:false
    SSDEEP:48:ceOorYJTrYJEfDWQvs432sD32scMEtu33tYTHDqxwKmlKas/PLSR3yhGQSbZnrf:YorYJTrYJEfiQX3f3jp2bTcHnhmJ
    MD5:93F31D747469FFEDAA98DD407EA9AB16
    SHA1:EA8FB574BBA281275C08E20BD21D1E39F13A5668
    SHA-256:AE3C54B9B1FF7B6FB04E9729F99BBD36378E8DAD8855011C2DD2B4AE55CD511C
    SHA-512:CC6FB42B8C449666784B9D22EEC2A9BE15E838AD7EA6BC441FD094E2CE284736A5423B587A60D9D85B8749BDEB453AB324AD57C3805C2C6968BB1ACE6A01AA8C
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?>.. . Copyright (c) 2006, Oracle and/or its affiliates. All rights reserved... Redistribution and use in source and binary forms, with or without. modification, are permitted provided that the following conditions. are met:.. - Redistributions of source code must retain the above copyright. notice, this list of conditions and the following disclaimer... - Redistributions in binary form must reproduce the above copyright. notice, this list of conditions and the following disclaimer in the. documentation and/or other materials provided with the distribution... - Neither the name of Oracle nor the names of its. contributors may be used to endorse or promote products derived. from this software without specific prior written permission... THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. THE IMPLIED WARRANTIES OF MERCHANTABILITY
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):3575
    Entropy (8bit):5.083119218956585
    Encrypted:false
    SSDEEP:48:ceOorYJTrYJEfDWQvs432sD32scMEtu33tYTHDqxwKmlKas/PLSR3yhGQSbZnrf:YorYJTrYJEfiQX3f3jp2bTcHnhmJ
    MD5:93F31D747469FFEDAA98DD407EA9AB16
    SHA1:EA8FB574BBA281275C08E20BD21D1E39F13A5668
    SHA-256:AE3C54B9B1FF7B6FB04E9729F99BBD36378E8DAD8855011C2DD2B4AE55CD511C
    SHA-512:CC6FB42B8C449666784B9D22EEC2A9BE15E838AD7EA6BC441FD094E2CE284736A5423B587A60D9D85B8749BDEB453AB324AD57C3805C2C6968BB1ACE6A01AA8C
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?>.. . Copyright (c) 2006, Oracle and/or its affiliates. All rights reserved... Redistribution and use in source and binary forms, with or without. modification, are permitted provided that the following conditions. are met:.. - Redistributions of source code must retain the above copyright. notice, this list of conditions and the following disclaimer... - Redistributions in binary form must reproduce the above copyright. notice, this list of conditions and the following disclaimer in the. documentation and/or other materials provided with the distribution... - Neither the name of Oracle nor the names of its. contributors may be used to endorse or promote products derived. from this software without specific prior written permission... THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. THE IMPLIED WARRANTIES OF MERCHANTABILITY
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:ASCII text
    Category:dropped
    Size (bytes):407
    Entropy (8bit):4.709067636108353
    Encrypted:false
    SSDEEP:6:jSNT32Dj4MzJXk5tNPDjDNT38ytv4fNbGSYcSH7xAdCqLstpWNT3kDecXlL3XG4k:jtphut9GytvAoH7igwkhemRnPIn
    MD5:735FF9E6D9CF1DB4C4377D033D16A222
    SHA1:BE94633CA3FE74BF5A31E4878A1C351C8BFA1E7F
    SHA-256:6EADD8527561D368ABD513D32F5BF1673454A498DDDEF6CEBBFD0A51FC7406C8
    SHA-512:7D2EB984E99AAEC62DD0883D6CB95181FE9B148C326829C0532C70EDAD179C3BF71DB2E0F8BB3BDCA3F6AE10F24979E47069CD74EF957C695525165497A8F9EA
    Malicious:false
    Reputation:low
    Preview:main.dir=${basedir}/../../../jfc/FileChooserDemo..src.dir=${main.dir}/src..build.dir=build.classes.dir=${build.dir}/classes.jar=${main.dir}/FileChooserDemo.jar.javadoc.dir=${build.dir}/javadoc..build.sysclasspath=ignore.# E.g.: cp=lib/x.jar:lib/y.jar.cp=.extra.run.cp=..main.class=FileChooserDemo..run.cp=${cp}:${classes.dir}:${extra.run.cp}..debug=true.deprecation=false..nbjdk.home=${basedir}/../../../...
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):2051
    Entropy (8bit):5.232812333752839
    Encrypted:false
    SSDEEP:48:ceOorYJTrYJEfDWQvs432sD32scMEtu33tYTHDuVKasrO:YorYJTrYJEfiQX3f3jp2yMC
    MD5:A8C48999C201D6F6120A827504EAC780
    SHA1:EC287F1C31B41EC76C39A1319CF1AA775BB49F51
    SHA-256:1F2C9D4987E7C8F49B27D38D7825B3FFB5C83B163866042BA376F7EF4AF3668F
    SHA-512:4242412583C8479B317C19823F34D4C048C7879DE559045AA25B221FA0B82188E8F64C977D1E92145271761831A255A058CB41E07EFECC54BC6FE96E7A736D83
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?>.. . Copyright (c) 2006, Oracle and/or its affiliates. All rights reserved... Redistribution and use in source and binary forms, with or without. modification, are permitted provided that the following conditions. are met:.. - Redistributions of source code must retain the above copyright. notice, this list of conditions and the following disclaimer... - Redistributions in binary form must reproduce the above copyright. notice, this list of conditions and the following disclaimer in the. documentation and/or other materials provided with the distribution... - Neither the name of Oracle nor the names of its. contributors may be used to endorse or promote products derived. from this software without specific prior written permission... THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. THE IMPLIED WARRANTIES OF MERCHANTABILITY
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):3512
    Entropy (8bit):5.151648934898434
    Encrypted:false
    SSDEEP:48:ceOorYJTrYJEfDWQvs432sD32scMEtu33tYTHD8JxuTJKaZzFKVzgDIE3YUvK5cf:YorYJTrYJEfiQX3f3jp2hzFaz4bso
    MD5:9ECE949EBEF69296B21128B83568393E
    SHA1:AD683090605C003AD21EC00A8D94979EFA96C562
    SHA-256:EED731CAA9AA8D45BA871FE4D81B01E9AC90A749D8D37D8C58FE73432BEB7691
    SHA-512:6A4D3A4F10054E899F35CBCA0CC4285CA7368341E438BE94B4B772F7D5D43A198D2CAB0C74A67CAB35B9DE762AFEF0E96FE2FAA277B517DCE332C0EEA1F0E045
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?>.. . Copyright (c) 2006, Oracle and/or its affiliates. All rights reserved... Redistribution and use in source and binary forms, with or without. modification, are permitted provided that the following conditions. are met:.. - Redistributions of source code must retain the above copyright. notice, this list of conditions and the following disclaimer... - Redistributions in binary form must reproduce the above copyright. notice, this list of conditions and the following disclaimer in the. documentation and/or other materials provided with the distribution... - Neither the name of Oracle nor the names of its. contributors may be used to endorse or promote products derived. from this software without specific prior written permission... THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. THE IMPLIED WARRANTIES OF MERCHANTABILITY
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):4218
    Entropy (8bit):4.9575689298800985
    Encrypted:false
    SSDEEP:48:ceOorYJTrYJEfDWQvs432sD32scMEtu33tYTHD5wj9fV3ORoZVPp1TED2AZiUZGQ:YorYJTrYJEfiQX3f3jp2FBY0
    MD5:8F8DB67A23AE3EFD024E91710F1A6739
    SHA1:26C3F95E0007310A3F6A35CCE6B61AF71B9F1C8B
    SHA-256:5AB23ACF89B98778B5885B46D500429E6906C4389CD4427D8D5BDE6727BB6BE3
    SHA-512:7E3B2E9EF782B2D12FEEF7DDF78FCDF4500ECA641E03AF66181D03DC81B0CD5B54E5376B245B0460A25FEA1AF70D11CF974FBCE1A5787D3310B50D56099FC2A1
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?>.. . Copyright (c) 2006, Oracle and/or its affiliates. All rights reserved... Redistribution and use in source and binary forms, with or without. modification, are permitted provided that the following conditions. are met:.. - Redistributions of source code must retain the above copyright. notice, this list of conditions and the following disclaimer... - Redistributions in binary form must reproduce the above copyright. notice, this list of conditions and the following disclaimer in the. documentation and/or other materials provided with the distribution... - Neither the name of Oracle nor the names of its. contributors may be used to endorse or promote products derived. from this software without specific prior written permission... THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. THE IMPLIED WARRANTIES OF MERCHANTABILITY
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):7450
    Entropy (8bit):4.2355535987672015
    Encrypted:false
    SSDEEP:96:YorYJTrYJEfiQX3f3jp29sGrJfkD+BbzYDrjh+RyW:YorsTrs+jX3f3d293rRBBbzYDrV+Rx
    MD5:D59E4A33883E31A09478042A8DDF1D36
    SHA1:9A50CBC9312CCBA0025E12BCCD39398B612C6A53
    SHA-256:8A5F3E622282997D2C4652A72F76A98C0A8DA97DEDC36E6F876895F09FB7F1CC
    SHA-512:712D114047F257070D7D4B6909A23313354F16FC73A65258849D3325C5FF948D5FB99881017770F65F4240DDC3F32F77002F0FB1A9AC6B4D65756D6861273F82
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?>.. . Copyright (c) 2006, Oracle and/or its affiliates. All rights reserved... Redistribution and use in source and binary forms, with or without. modification, are permitted provided that the following conditions. are met:.. - Redistributions of source code must retain the above copyright. notice, this list of conditions and the following disclaimer... - Redistributions in binary form must reproduce the above copyright. notice, this list of conditions and the following disclaimer in the. documentation and/or other materials provided with the distribution... - Neither the name of Oracle nor the names of its. contributors may be used to endorse or promote products derived. from this software without specific prior written permission... THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. THE IMPLIED WARRANTIES OF MERCHANTABILITY
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):2051
    Entropy (8bit):5.232812333752839
    Encrypted:false
    SSDEEP:48:ceOorYJTrYJEfDWQvs432sD32scMEtu33tYTHDuVKasrO:YorYJTrYJEfiQX3f3jp2yMC
    MD5:A8C48999C201D6F6120A827504EAC780
    SHA1:EC287F1C31B41EC76C39A1319CF1AA775BB49F51
    SHA-256:1F2C9D4987E7C8F49B27D38D7825B3FFB5C83B163866042BA376F7EF4AF3668F
    SHA-512:4242412583C8479B317C19823F34D4C048C7879DE559045AA25B221FA0B82188E8F64C977D1E92145271761831A255A058CB41E07EFECC54BC6FE96E7A736D83
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?>.. . Copyright (c) 2006, Oracle and/or its affiliates. All rights reserved... Redistribution and use in source and binary forms, with or without. modification, are permitted provided that the following conditions. are met:.. - Redistributions of source code must retain the above copyright. notice, this list of conditions and the following disclaimer... - Redistributions in binary form must reproduce the above copyright. notice, this list of conditions and the following disclaimer in the. documentation and/or other materials provided with the distribution... - Neither the name of Oracle nor the names of its. contributors may be used to endorse or promote products derived. from this software without specific prior written permission... THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. THE IMPLIED WARRANTIES OF MERCHANTABILITY
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):4218
    Entropy (8bit):4.9575689298800985
    Encrypted:false
    SSDEEP:48:ceOorYJTrYJEfDWQvs432sD32scMEtu33tYTHD5wj9fV3ORoZVPp1TED2AZiUZGQ:YorYJTrYJEfiQX3f3jp2FBY0
    MD5:8F8DB67A23AE3EFD024E91710F1A6739
    SHA1:26C3F95E0007310A3F6A35CCE6B61AF71B9F1C8B
    SHA-256:5AB23ACF89B98778B5885B46D500429E6906C4389CD4427D8D5BDE6727BB6BE3
    SHA-512:7E3B2E9EF782B2D12FEEF7DDF78FCDF4500ECA641E03AF66181D03DC81B0CD5B54E5376B245B0460A25FEA1AF70D11CF974FBCE1A5787D3310B50D56099FC2A1
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?>.. . Copyright (c) 2006, Oracle and/or its affiliates. All rights reserved... Redistribution and use in source and binary forms, with or without. modification, are permitted provided that the following conditions. are met:.. - Redistributions of source code must retain the above copyright. notice, this list of conditions and the following disclaimer... - Redistributions in binary form must reproduce the above copyright. notice, this list of conditions and the following disclaimer in the. documentation and/or other materials provided with the distribution... - Neither the name of Oracle nor the names of its. contributors may be used to endorse or promote products derived. from this software without specific prior written permission... THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. THE IMPLIED WARRANTIES OF MERCHANTABILITY
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:ASCII text
    Category:dropped
    Size (bytes):433
    Entropy (8bit):4.769856680857408
    Encrypted:false
    SSDEEP:6:jAouDj4MzJXk5tNPDjPMttv4fNbGSYcSH7xAdCqLstvlwoWpDecXlL3XG4jI4eGD:jAnphut9PGtvAoH7igwXbemRnPI4eGPb
    MD5:5C5B5F3AFEFFE799E47A9A962F03F461
    SHA1:FF55DA8A5F1435F1883209315215FB34E23DAB60
    SHA-256:156690BEEB3915E527F57974DCD6381B9FB8B11AE04CB5D3CC9EC2CA3A5C654A
    SHA-512:BEED9B3799A49B30F710443B0A68919251D997B1123FCB4C5B90B4401E914B1982448130184E24E6C6D02E2B13D38725C9C207FCD28C99EDD90D9E5FFF3ED1C7
    Malicious:false
    Reputation:low
    Preview:main.dir=${basedir}/../../../jfc/Font2DTest..src.dir=${main.dir}/src..build.dir=build.classes.dir=${build.dir}/classes.jar=${main.dir}/Font2DTest.jar.javadoc.dir=${build.dir}/javadoc..build.sysclasspath=ignore.# E.g.: cp=lib/x.jar:lib/y.jar.cp=.extra.run.cp=..main.class=Font2DTest..run.cp=${cp}:${classes.dir}:${extra.run.cp}..debug=true.deprecation=false..nbjdk.home=${basedir}/../../../....applet.html=${main.dir}/Font2DTest.html.
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):3874
    Entropy (8bit):5.062530022218496
    Encrypted:false
    SSDEEP:48:ceOorYJTrYJEfDWQvs432sD32scMEtu33tYTHDzxwKmlKas/PLSR3yS6WCCGQSbt:YorYJTrYJEfiQX3f3jp2GTcHnS6WCCmJ
    MD5:B0FDAF1B39A65E5FEAA1B58BA23DDE24
    SHA1:58F74688FA8D33380421E764B1EF68205ABB8AC8
    SHA-256:656C17ACAE29C4F6F1CB3EE2DDBE79FBD367E1893F600193CBCC332F284449DF
    SHA-512:01D3EE6B60D52F80FF0274DEF81681C0DE9850DA4BC5EC416D88030948DB74771B99EBB51D6D9A149299876D4F2C5153BB0E9D1C743A79AF00F71896DD106601
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?>.. . Copyright (c) 2006, Oracle and/or its affiliates. All rights reserved... Redistribution and use in source and binary forms, with or without. modification, are permitted provided that the following conditions. are met:.. - Redistributions of source code must retain the above copyright. notice, this list of conditions and the following disclaimer... - Redistributions in binary form must reproduce the above copyright. notice, this list of conditions and the following disclaimer in the. documentation and/or other materials provided with the distribution... - Neither the name of Oracle nor the names of its. contributors may be used to endorse or promote products derived. from this software without specific prior written permission... THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. THE IMPLIED WARRANTIES OF MERCHANTABILITY
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):3502
    Entropy (8bit):5.153489411749672
    Encrypted:false
    SSDEEP:48:ceOorYJTrYJEfDWQvs432sD32scMEtu33tYTHDJYxuTJKaZzFKVzgDIE3YUvK5cf:YorYJTrYJEfiQX3f3jp2fzFaz4bso
    MD5:16AABEA1BAECFF824B3AF4C900183A5C
    SHA1:D5E9FED8425B7C4870D0561BDDEEC46E4F1BF334
    SHA-256:433DE202F660F935F618FD51AE22CC6A768A2F1380B22231A5B0BA8B872B99A5
    SHA-512:1780F28B799808368DDD6AC80D5AE2E45C6CDE5F67C0EF423175FB82AAC10B5DAA98EBC608D871898EFA0F984CDED8958F0A3F3FF7A9F156F7BD0A2A72397796
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?>.. . Copyright (c) 2006, Oracle and/or its affiliates. All rights reserved... Redistribution and use in source and binary forms, with or without. modification, are permitted provided that the following conditions. are met:.. - Redistributions of source code must retain the above copyright. notice, this list of conditions and the following disclaimer... - Redistributions in binary form must reproduce the above copyright. notice, this list of conditions and the following disclaimer in the. documentation and/or other materials provided with the distribution... - Neither the name of Oracle nor the names of its. contributors may be used to endorse or promote products derived. from this software without specific prior written permission... THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. THE IMPLIED WARRANTIES OF MERCHANTABILITY
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):4218
    Entropy (8bit):4.9575689298800985
    Encrypted:false
    SSDEEP:48:ceOorYJTrYJEfDWQvs432sD32scMEtu33tYTHD5wj9fV3ORoZVPp1TED2AZiUZGQ:YorYJTrYJEfiQX3f3jp2FBY0
    MD5:8F8DB67A23AE3EFD024E91710F1A6739
    SHA1:26C3F95E0007310A3F6A35CCE6B61AF71B9F1C8B
    SHA-256:5AB23ACF89B98778B5885B46D500429E6906C4389CD4427D8D5BDE6727BB6BE3
    SHA-512:7E3B2E9EF782B2D12FEEF7DDF78FCDF4500ECA641E03AF66181D03DC81B0CD5B54E5376B245B0460A25FEA1AF70D11CF974FBCE1A5787D3310B50D56099FC2A1
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?>.. . Copyright (c) 2006, Oracle and/or its affiliates. All rights reserved... Redistribution and use in source and binary forms, with or without. modification, are permitted provided that the following conditions. are met:.. - Redistributions of source code must retain the above copyright. notice, this list of conditions and the following disclaimer... - Redistributions in binary form must reproduce the above copyright. notice, this list of conditions and the following disclaimer in the. documentation and/or other materials provided with the distribution... - Neither the name of Oracle nor the names of its. contributors may be used to endorse or promote products derived. from this software without specific prior written permission... THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. THE IMPLIED WARRANTIES OF MERCHANTABILITY
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):7746
    Entropy (8bit):4.202194914819453
    Encrypted:false
    SSDEEP:96:YorYJTrYJEfiQX3f3jp2esGrJfkD+BbzYDrUh+RPW:YorsTrs+jX3f3d2e3rRBBbzYDr6+Re
    MD5:E2EF350344A7AC8830A6C58263030A20
    SHA1:4807F5AF02E9669F5F320ACC0A2906668DCA56C5
    SHA-256:271F981BA9B1B86514C553D1E90F726013D1E6709163DD7DF3BF4656C3D1291B
    SHA-512:FFBB60F17E8A64572133F1B884F70A2DCA290C09E745076D456B044A38CD0F06A25527A44D7107C27CF0CF7DAAD5FBE5B9FBA01488EFB36B7380698FD6F77E11
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?>.. . Copyright (c) 2006, Oracle and/or its affiliates. All rights reserved... Redistribution and use in source and binary forms, with or without. modification, are permitted provided that the following conditions. are met:.. - Redistributions of source code must retain the above copyright. notice, this list of conditions and the following disclaimer... - Redistributions in binary form must reproduce the above copyright. notice, this list of conditions and the following disclaimer in the. documentation and/or other materials provided with the distribution... - Neither the name of Oracle nor the names of its. contributors may be used to endorse or promote products derived. from this software without specific prior written permission... THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. THE IMPLIED WARRANTIES OF MERCHANTABILITY
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):2046
    Entropy (8bit):5.234437729282258
    Encrypted:false
    SSDEEP:48:ceOorYJTrYJEfDWQvs432sD32scMEtu33tYTHD1VKasrO:YorYJTrYJEfiQX3f3jp2xMC
    MD5:F60AE0FE7D8703D28D632F42CCFD5790
    SHA1:9E321248BB024E725C185AD6AC0772F5B589EABA
    SHA-256:D8B5A53A6336DE764CE1C73076856BC251D8ECAA11954DE70C15493B7B6D039C
    SHA-512:068E118CC298E5259396348352A2226BEC3A2E95C97F5CF389FDE6AB2F61704EEE3D6111F9819C00D22D657403ED3668F394C99AEB4AF96F194A2B286705D04C
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?>.. . Copyright (c) 2006, Oracle and/or its affiliates. All rights reserved... Redistribution and use in source and binary forms, with or without. modification, are permitted provided that the following conditions. are met:.. - Redistributions of source code must retain the above copyright. notice, this list of conditions and the following disclaimer... - Redistributions in binary form must reproduce the above copyright. notice, this list of conditions and the following disclaimer in the. documentation and/or other materials provided with the distribution... - Neither the name of Oracle nor the names of its. contributors may be used to endorse or promote products derived. from this software without specific prior written permission... THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. THE IMPLIED WARRANTIES OF MERCHANTABILITY
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:ASCII text
    Category:dropped
    Size (bytes):392
    Entropy (8bit):4.6829332201492315
    Encrypted:false
    SSDEEP:6:j6RnDj4MzJXk5tNPDICjKtv4fNbGSYcSH7xAdCqLstQEkDecXlL3XG4jIn:jsphuti/tvAoH7igwUmemRnPIn
    MD5:76FE424BFFAEAE050FB0C9AC4C192AF0
    SHA1:22549FF68527A5F353A7B966BAD3DC0AF4588B45
    SHA-256:C3B5DAD5471FB91160B17C8BA94B9597C70718072BF5C7EC4596ADD03889FD12
    SHA-512:2D990E73E225C9784BA0DB1369840D544B4146250C2BF75DFF5AAFC08524BD6E58A91A55AA23BF6D539B953E2E5CA36A025B7872FE1731B434A47B807E81BA1F
    Malicious:false
    Reputation:low
    Preview:main.dir=${basedir}/../../../jfc/Metalworks..src.dir=${main.dir}/src..build.dir=build.classes.dir=${build.dir}/classes.jar=${main.dir}/Metalworks.jar.javadoc.dir=${build.dir}/javadoc..build.sysclasspath=ignore.# E.g.: cp=lib/x.jar:lib/y.jar.cp=.extra.run.cp=..main.class=Metalworks..run.cp=${cp}:${classes.dir}:${extra.run.cp}..debug=true.deprecation=false..nbjdk.home=${basedir}/../../../...
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):3570
    Entropy (8bit):5.0839152980908
    Encrypted:false
    SSDEEP:48:ceOorYJTrYJEfDWQvs432sD32scMEtu33tYTHDDxwKmlKas/PLSR3yhGQSbZnrf:YorYJTrYJEfiQX3f3jp22TcHnhmJ
    MD5:9694EA863FD40EA72EA0B93B681A69CB
    SHA1:D339B4553589DB2F20F934AD416890D76F754C95
    SHA-256:D025D3B0FF315E63A2213D6267DB74434651A947D624156D206626E07D1443A2
    SHA-512:CFA83D76431E872879BCFCA39CAA99800611E3E7880F0975D9A1ED2E7A374C33ABFF6D3734CBDCBAF0E08615F554F2A76BAC1AFCAFDE5C937107CFC2698DF6B5
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?>.. . Copyright (c) 2006, Oracle and/or its affiliates. All rights reserved... Redistribution and use in source and binary forms, with or without. modification, are permitted provided that the following conditions. are met:.. - Redistributions of source code must retain the above copyright. notice, this list of conditions and the following disclaimer... - Redistributions in binary form must reproduce the above copyright. notice, this list of conditions and the following disclaimer in the. documentation and/or other materials provided with the distribution... - Neither the name of Oracle nor the names of its. contributors may be used to endorse or promote products derived. from this software without specific prior written permission... THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. THE IMPLIED WARRANTIES OF MERCHANTABILITY
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):3502
    Entropy (8bit):5.152865747083722
    Encrypted:false
    SSDEEP:48:ceOorYJTrYJEfDWQvs432sD32scMEtu33tYTHDRoxuTJKaZzFKVzgDIE3YUvK5cf:YorYJTrYJEfiQX3f3jp2nzFaz4bso
    MD5:7FF4C16EB35F2EB6499C1EA430D64212
    SHA1:E15C02F8B5A11A3749B2999E68F2E9D37C1DEED3
    SHA-256:8FBC99A2A2C7C6FD572F71CEE5C9CFF387988F94A84F02574056921B021AC319
    SHA-512:3B5077100E87C90DBAA7B1E806841D11F39C2D5717E023E5B942AA205B5C9FC1C16FE1FF8847B10A234B5631377570A8C6C27033656833E2B04EE0D9AB460AC4
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?>.. . Copyright (c) 2006, Oracle and/or its affiliates. All rights reserved... Redistribution and use in source and binary forms, with or without. modification, are permitted provided that the following conditions. are met:.. - Redistributions of source code must retain the above copyright. notice, this list of conditions and the following disclaimer... - Redistributions in binary form must reproduce the above copyright. notice, this list of conditions and the following disclaimer in the. documentation and/or other materials provided with the distribution... - Neither the name of Oracle nor the names of its. contributors may be used to endorse or promote products derived. from this software without specific prior written permission... THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. THE IMPLIED WARRANTIES OF MERCHANTABILITY
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):7445
    Entropy (8bit):4.234906283124365
    Encrypted:false
    SSDEEP:96:YorYJTrYJEfiQX3f3jp2OsGrJfkD+BbzYDrjh+RyW:YorsTrs+jX3f3d2O3rRBBbzYDrV+Rx
    MD5:E92E63AB8259FB5A3BC5295C66F07B29
    SHA1:BBC9ED3A82AEF6F1936315899B6E0DB4E9A6E0F0
    SHA-256:378DC7C39D1D39DB6CEDC48F21731395EA9EA3AAE0521E462E0864F1D5C85288
    SHA-512:24E39C5C854C6CD91DBAD3B7D7C45A665E4956684A532CE824D32E879012269C1EB7AD3528248903EADFBD153F37F7E48EB97E8B15638D4902265CE20D080154
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?>.. . Copyright (c) 2006, Oracle and/or its affiliates. All rights reserved... Redistribution and use in source and binary forms, with or without. modification, are permitted provided that the following conditions. are met:.. - Redistributions of source code must retain the above copyright. notice, this list of conditions and the following disclaimer... - Redistributions in binary form must reproduce the above copyright. notice, this list of conditions and the following disclaimer in the. documentation and/or other materials provided with the distribution... - Neither the name of Oracle nor the names of its. contributors may be used to endorse or promote products derived. from this software without specific prior written permission... THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. THE IMPLIED WARRANTIES OF MERCHANTABILITY
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):4218
    Entropy (8bit):4.9575689298800985
    Encrypted:false
    SSDEEP:48:ceOorYJTrYJEfDWQvs432sD32scMEtu33tYTHD5wj9fV3ORoZVPp1TED2AZiUZGQ:YorYJTrYJEfiQX3f3jp2FBY0
    MD5:8F8DB67A23AE3EFD024E91710F1A6739
    SHA1:26C3F95E0007310A3F6A35CCE6B61AF71B9F1C8B
    SHA-256:5AB23ACF89B98778B5885B46D500429E6906C4389CD4427D8D5BDE6727BB6BE3
    SHA-512:7E3B2E9EF782B2D12FEEF7DDF78FCDF4500ECA641E03AF66181D03DC81B0CD5B54E5376B245B0460A25FEA1AF70D11CF974FBCE1A5787D3310B50D56099FC2A1
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?>.. . Copyright (c) 2006, Oracle and/or its affiliates. All rights reserved... Redistribution and use in source and binary forms, with or without. modification, are permitted provided that the following conditions. are met:.. - Redistributions of source code must retain the above copyright. notice, this list of conditions and the following disclaimer... - Redistributions in binary form must reproduce the above copyright. notice, this list of conditions and the following disclaimer in the. documentation and/or other materials provided with the distribution... - Neither the name of Oracle nor the names of its. contributors may be used to endorse or promote products derived. from this software without specific prior written permission... THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. THE IMPLIED WARRANTIES OF MERCHANTABILITY
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):2046
    Entropy (8bit):5.235970475978011
    Encrypted:false
    SSDEEP:48:ceOorYJTrYJEfDWQvs432sD32scMEtu33tYTHDtVKasrO:YorYJTrYJEfiQX3f3jp2JMC
    MD5:1C94096859350E254A1D64EC2172DC3E
    SHA1:9A0ACF0C87FCC550CA79EC16C582349CA7F6CDBE
    SHA-256:C2BC32FCB3E2BB363E288E9ED345C43C49A64C440CDC31FB6730659AC7E48075
    SHA-512:19F6EAB91040D5202544BD4C689B0FCACD3596A0F2D6FFAA439D1D3B6B7212165C62C695CB68296129CCE96E25D98B22A6D65FB4FF32131575821263CF83DFA6
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?>.. . Copyright (c) 2006, Oracle and/or its affiliates. All rights reserved... Redistribution and use in source and binary forms, with or without. modification, are permitted provided that the following conditions. are met:.. - Redistributions of source code must retain the above copyright. notice, this list of conditions and the following disclaimer... - Redistributions in binary form must reproduce the above copyright. notice, this list of conditions and the following disclaimer in the. documentation and/or other materials provided with the distribution... - Neither the name of Oracle nor the names of its. contributors may be used to endorse or promote products derived. from this software without specific prior written permission... THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. THE IMPLIED WARRANTIES OF MERCHANTABILITY
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:ASCII text
    Category:dropped
    Size (bytes):383
    Entropy (8bit):4.642880626078754
    Encrypted:false
    SSDEEP:6:jKZDj4MzJXk5tNPDrxgtv4fNbGSYcSH7xAdCqLst3irpDecXlL3XG4jIn:jKZphut16tvAoH7igwhJemRnPIn
    MD5:D852564DF8844E0EA25B10EF1B02E131
    SHA1:F65D20FE1A6794AD641CA98FAC0F5CEA59B56898
    SHA-256:2A5638D34F3B24EC787075123A446BB03C20FFB00377D5C1C299785A5F3F929B
    SHA-512:D337056F0DA61D05ED90A810781ECAFAB3714F65990C5379CBFEF21FD21AC63763CF46435A22B3C919F7E6E3C89A6457692938754FD4651117C12302C869C5A5
    Malicious:false
    Reputation:low
    Preview:main.dir=${basedir}/../../../jfc/Notepad..src.dir=${main.dir}/src..build.dir=build.classes.dir=${build.dir}/classes.jar=${main.dir}/Notepad.jar.javadoc.dir=${build.dir}/javadoc..build.sysclasspath=ignore.# E.g.: cp=lib/x.jar:lib/y.jar.cp=.extra.run.cp=..main.class=Notepad..run.cp=${cp}:${classes.dir}:${extra.run.cp}..debug=true.deprecation=false..nbjdk.home=${basedir}/../../../...
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):3567
    Entropy (8bit):5.081416637011461
    Encrypted:false
    SSDEEP:48:ceOorYJTrYJEfDWQvs432sD32scMEtu33tYTHD1xwKmlKas/PLSR3yhGQSbZnrf:YorYJTrYJEfiQX3f3jp2ATcHnhmJ
    MD5:F39C63E2D90432D45427D9E146A8AD29
    SHA1:C0A7494CC37901D515E76294B675AA600D898AD2
    SHA-256:CA9F673A0D10A1814126A978CAABC349ABD623F70BB5FC4A59C39169B8422A2B
    SHA-512:BAA86943BE27A4FB61EAF964892C41B967DC2FE12501915F5A39EFDE0B02A3B1F38A902A0DC03090D5926DF02C4576DD0702183A9E617FA67F2140BCAAC9AA92
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?>.. . Copyright (c) 2006, Oracle and/or its affiliates. All rights reserved... Redistribution and use in source and binary forms, with or without. modification, are permitted provided that the following conditions. are met:.. - Redistributions of source code must retain the above copyright. notice, this list of conditions and the following disclaimer... - Redistributions in binary form must reproduce the above copyright. notice, this list of conditions and the following disclaimer in the. documentation and/or other materials provided with the distribution... - Neither the name of Oracle nor the names of its. contributors may be used to endorse or promote products derived. from this software without specific prior written permission... THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. THE IMPLIED WARRANTIES OF MERCHANTABILITY
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):7442
    Entropy (8bit):4.233286762896708
    Encrypted:false
    SSDEEP:96:YorYJTrYJEfiQX3f3jp2YsGrJfkD+BbzYDrjh+RyW:YorsTrs+jX3f3d2Y3rRBBbzYDrV+Rx
    MD5:A2E69BC58BBC328DA03700381EA32103
    SHA1:E1F278A1CDC2F1E3D5635F01B04D954EC57DAEE4
    SHA-256:30AC99FDF624BDF49B50B63247DE9A841837D1FDE0A47E2EF8163D219135000F
    SHA-512:4B7F91A351BED908FA595A755EF3C3B41EF206EDE147EFA28B8DA6821B3F84502313FD2F3514A2973DAB352C63B3AA895B7A539E8684F0057BE6131617B66E9B
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?>.. . Copyright (c) 2006, Oracle and/or its affiliates. All rights reserved... Redistribution and use in source and binary forms, with or without. modification, are permitted provided that the following conditions. are met:.. - Redistributions of source code must retain the above copyright. notice, this list of conditions and the following disclaimer... - Redistributions in binary form must reproduce the above copyright. notice, this list of conditions and the following disclaimer in the. documentation and/or other materials provided with the distribution... - Neither the name of Oracle nor the names of its. contributors may be used to endorse or promote products derived. from this software without specific prior written permission... THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. THE IMPLIED WARRANTIES OF MERCHANTABILITY
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):3496
    Entropy (8bit):5.148449019800724
    Encrypted:false
    SSDEEP:48:ceOorYJTrYJEfDWQvs432sD32scMEtu33tYTHDVmxuTJKaZzFKVzgDIE3YUvK5cf:YorYJTrYJEfiQX3f3jp2lzFaz4bso
    MD5:E1300031E34FD2C1AC75A5B5168AB72F
    SHA1:E2FFFAED6047005188486462B48576BBD6007D5D
    SHA-256:3443221FD2E571BCCA388DF666F5BC0774D8E2205C16FD3121F65B5041FB9916
    SHA-512:F2DDD66CAD313FADC85D038C1DCB0106168C3DE54A1CD0F1917B2C96486DD4B72C98FC0DC6C90521962F559DE69132DE3C6BA59C21F0EB6C759A0BA984FE3F51
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?>.. . Copyright (c) 2006, Oracle and/or its affiliates. All rights reserved... Redistribution and use in source and binary forms, with or without. modification, are permitted provided that the following conditions. are met:.. - Redistributions of source code must retain the above copyright. notice, this list of conditions and the following disclaimer... - Redistributions in binary form must reproduce the above copyright. notice, this list of conditions and the following disclaimer in the. documentation and/or other materials provided with the distribution... - Neither the name of Oracle nor the names of its. contributors may be used to endorse or promote products derived. from this software without specific prior written permission... THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. THE IMPLIED WARRANTIES OF MERCHANTABILITY
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):2043
    Entropy (8bit):5.231722484314439
    Encrypted:false
    SSDEEP:48:ceOorYJTrYJEfDWQvs432sD32scMEtu33tYTHDBVKasrO:YorYJTrYJEfiQX3f3jp2dMC
    MD5:F34B1763FC27B733339E5AB532624449
    SHA1:FBFB28785EBA1D4B648BBE487DFFC65E2016AD84
    SHA-256:A1407334C8808635B4C7C04A7F1811DFADC0E647B4D391F1D53290290D6E1BBA
    SHA-512:D745DFDB783F9BCA15B8456F044C9D352122ACDD24AAF12FE527C446C80A2E3F315A5E4C3110068D5DC7B71D80C6BA39AC59A2EC43ACF66BF045F070B1B0F786
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?>.. . Copyright (c) 2006, Oracle and/or its affiliates. All rights reserved... Redistribution and use in source and binary forms, with or without. modification, are permitted provided that the following conditions. are met:.. - Redistributions of source code must retain the above copyright. notice, this list of conditions and the following disclaimer... - Redistributions in binary form must reproduce the above copyright. notice, this list of conditions and the following disclaimer in the. documentation and/or other materials provided with the distribution... - Neither the name of Oracle nor the names of its. contributors may be used to endorse or promote products derived. from this software without specific prior written permission... THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. THE IMPLIED WARRANTIES OF MERCHANTABILITY
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):4218
    Entropy (8bit):4.9575689298800985
    Encrypted:false
    SSDEEP:48:ceOorYJTrYJEfDWQvs432sD32scMEtu33tYTHD5wj9fV3ORoZVPp1TED2AZiUZGQ:YorYJTrYJEfiQX3f3jp2FBY0
    MD5:8F8DB67A23AE3EFD024E91710F1A6739
    SHA1:26C3F95E0007310A3F6A35CCE6B61AF71B9F1C8B
    SHA-256:5AB23ACF89B98778B5885B46D500429E6906C4389CD4427D8D5BDE6727BB6BE3
    SHA-512:7E3B2E9EF782B2D12FEEF7DDF78FCDF4500ECA641E03AF66181D03DC81B0CD5B54E5376B245B0460A25FEA1AF70D11CF974FBCE1A5787D3310B50D56099FC2A1
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?>.. . Copyright (c) 2006, Oracle and/or its affiliates. All rights reserved... Redistribution and use in source and binary forms, with or without. modification, are permitted provided that the following conditions. are met:.. - Redistributions of source code must retain the above copyright. notice, this list of conditions and the following disclaimer... - Redistributions in binary form must reproduce the above copyright. notice, this list of conditions and the following disclaimer in the. documentation and/or other materials provided with the distribution... - Neither the name of Oracle nor the names of its. contributors may be used to endorse or promote products derived. from this software without specific prior written permission... THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. THE IMPLIED WARRANTIES OF MERCHANTABILITY
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:ASCII text
    Category:dropped
    Size (bytes):392
    Entropy (8bit):4.655853929649387
    Encrypted:false
    SSDEEP:6:jumDj4MzJXk5tNPDdMPKtv4fNbGSYcSH7xAdCqLst1OUDecXlL3XG4jIn:jzphutNtvAoH7igwQHemRnPIn
    MD5:9A9C5FABB1DD32768342252C6BD7094A
    SHA1:C009C841BC826AF997DD12BBAF771A807CA28049
    SHA-256:BA0340F6AD6D18E0A0B0094ADCA0AF2CDF770FE8E31ED4B363E0E884DB5C6CFC
    SHA-512:3E108BEFA85632250B2487C558BB5E3E41774B33C030F62CB09A1E4D3A719834C195427E1E37B56A31ED82149F38285CE4680659B31AEBD63B2018F6238649DA
    Malicious:false
    Reputation:low
    Preview:main.dir=${basedir}/../../../jfc/SampleTree..src.dir=${main.dir}/src..build.dir=build.classes.dir=${build.dir}/classes.jar=${main.dir}/SampleTree.jar.javadoc.dir=${build.dir}/javadoc..build.sysclasspath=ignore.# E.g.: cp=lib/x.jar:lib/y.jar.cp=.extra.run.cp=..main.class=SampleTree..run.cp=${cp}:${classes.dir}:${extra.run.cp}..debug=true.deprecation=false..nbjdk.home=${basedir}/../../../...
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):3570
    Entropy (8bit):5.08173369856041
    Encrypted:false
    SSDEEP:48:ceOorYJTrYJEfDWQvs432sD32scMEtu33tYTHDUxwKmlKas/PLSR3yhGQSbZnrf:YorYJTrYJEfiQX3f3jp2NTcHnhmJ
    MD5:4CE7E70AF1449DE445E23DCAB2DC87A4
    SHA1:636EFE2E21FF9ADD881554D429454320B666622C
    SHA-256:BC397122476F3293A3E4E59FC8BB7F70A9B0506DD89DFE4D1444FB34E623165E
    SHA-512:958549C007C96AC3866C0E36B121E6C0884F3FD33C2F4D8591B1EFDF3D7960609BBAC017E87F3433BD2A48D1CDC5641D4FC60DAE4469425346A741FEE2B9F625
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?>.. . Copyright (c) 2006, Oracle and/or its affiliates. All rights reserved... Redistribution and use in source and binary forms, with or without. modification, are permitted provided that the following conditions. are met:.. - Redistributions of source code must retain the above copyright. notice, this list of conditions and the following disclaimer... - Redistributions in binary form must reproduce the above copyright. notice, this list of conditions and the following disclaimer in the. documentation and/or other materials provided with the distribution... - Neither the name of Oracle nor the names of its. contributors may be used to endorse or promote products derived. from this software without specific prior written permission... THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. THE IMPLIED WARRANTIES OF MERCHANTABILITY
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):3502
    Entropy (8bit):5.148949337121458
    Encrypted:false
    SSDEEP:48:ceOorYJTrYJEfDWQvs432sD32scMEtu33tYTHDcHxuTJKaZzFKVzgDIE3YUvK5cf:YorYJTrYJEfiQX3f3jp2ZzFaz4bso
    MD5:02FF6A8B75FC1D36ABAE3CE53EDB31A7
    SHA1:D8E0BD3A271A4088EA0144E55F473F4ACF23085E
    SHA-256:D33DDC951D31811EF1367135DA257CFDC1987BC5B2F9F5BB9638D6CD8B5CB84E
    SHA-512:85C0FF4711FF5372BB667E8AC7DC19919AD542D0B5D5366A34A8C31C23B8A4FF8CA660B68E4BD8A13E0855BF6D1C9F61BFA8FD7447527583C8CA782E9FDB0D0A
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?>.. . Copyright (c) 2006, Oracle and/or its affiliates. All rights reserved... Redistribution and use in source and binary forms, with or without. modification, are permitted provided that the following conditions. are met:.. - Redistributions of source code must retain the above copyright. notice, this list of conditions and the following disclaimer... - Redistributions in binary form must reproduce the above copyright. notice, this list of conditions and the following disclaimer in the. documentation and/or other materials provided with the distribution... - Neither the name of Oracle nor the names of its. contributors may be used to endorse or promote products derived. from this software without specific prior written permission... THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. THE IMPLIED WARRANTIES OF MERCHANTABILITY
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):4218
    Entropy (8bit):4.9575689298800985
    Encrypted:false
    SSDEEP:48:ceOorYJTrYJEfDWQvs432sD32scMEtu33tYTHD5wj9fV3ORoZVPp1TED2AZiUZGQ:YorYJTrYJEfiQX3f3jp2FBY0
    MD5:8F8DB67A23AE3EFD024E91710F1A6739
    SHA1:26C3F95E0007310A3F6A35CCE6B61AF71B9F1C8B
    SHA-256:5AB23ACF89B98778B5885B46D500429E6906C4389CD4427D8D5BDE6727BB6BE3
    SHA-512:7E3B2E9EF782B2D12FEEF7DDF78FCDF4500ECA641E03AF66181D03DC81B0CD5B54E5376B245B0460A25FEA1AF70D11CF974FBCE1A5787D3310B50D56099FC2A1
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?>.. . Copyright (c) 2006, Oracle and/or its affiliates. All rights reserved... Redistribution and use in source and binary forms, with or without. modification, are permitted provided that the following conditions. are met:.. - Redistributions of source code must retain the above copyright. notice, this list of conditions and the following disclaimer... - Redistributions in binary form must reproduce the above copyright. notice, this list of conditions and the following disclaimer in the. documentation and/or other materials provided with the distribution... - Neither the name of Oracle nor the names of its. contributors may be used to endorse or promote products derived. from this software without specific prior written permission... THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. THE IMPLIED WARRANTIES OF MERCHANTABILITY
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):7445
    Entropy (8bit):4.233972329703174
    Encrypted:false
    SSDEEP:96:YorYJTrYJEfiQX3f3jp2phsGrJfkD+BbzYDrjh+RyW:YorsTrs+jX3f3d2/3rRBBbzYDrV+Rx
    MD5:A8972C606F2854AF23FD903C2A3C367C
    SHA1:F76BC5862E63E6D3F55DE50C9CC4FA056385645A
    SHA-256:0A2E36EC9051977A56F3D0365D087794D8D6AA03A1A44AA92ECD6F259EBBC223
    SHA-512:DA4540F2FE9F26A068C1C4E6E87BB62AC0F44C65C985586E2AED2CA783DA41E008514C4892CA3D95A86C475A063C008259FD15C35D4B410C7443EA7B99656983
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?>.. . Copyright (c) 2006, Oracle and/or its affiliates. All rights reserved... Redistribution and use in source and binary forms, with or without. modification, are permitted provided that the following conditions. are met:.. - Redistributions of source code must retain the above copyright. notice, this list of conditions and the following disclaimer... - Redistributions in binary form must reproduce the above copyright. notice, this list of conditions and the following disclaimer in the. documentation and/or other materials provided with the distribution... - Neither the name of Oracle nor the names of its. contributors may be used to endorse or promote products derived. from this software without specific prior written permission... THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. THE IMPLIED WARRANTIES OF MERCHANTABILITY
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):2046
    Entropy (8bit):5.232133520997717
    Encrypted:false
    SSDEEP:48:ceOorYJTrYJEfDWQvs432sD32scMEtu33tYTHDOVKasrO:YorYJTrYJEfiQX3f3jp2qMC
    MD5:6025897CDD9522AB2437C16D1E96A0CF
    SHA1:685015CD7065F74C52D5A8A44F40330ED61EDE29
    SHA-256:35ED77965A96DEF17929D96AC572641F778ADB4E714FA618FCE8ACF1383A31B0
    SHA-512:31215B82D67188C89104F80B4AAD6421A777162F8F441D949F68960E4FBD4D2AC301EA1F03FC2BFD4CBDB722916DF1A453662210583258EA94D594501852BC31
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?>.. . Copyright (c) 2006, Oracle and/or its affiliates. All rights reserved... Redistribution and use in source and binary forms, with or without. modification, are permitted provided that the following conditions. are met:.. - Redistributions of source code must retain the above copyright. notice, this list of conditions and the following disclaimer... - Redistributions in binary form must reproduce the above copyright. notice, this list of conditions and the following disclaimer in the. documentation and/or other materials provided with the distribution... - Neither the name of Oracle nor the names of its. contributors may be used to endorse or promote products derived. from this software without specific prior written permission... THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. THE IMPLIED WARRANTIES OF MERCHANTABILITY
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:ASCII text
    Category:dropped
    Size (bytes):427
    Entropy (8bit):4.731348656148398
    Encrypted:false
    SSDEEP:6:jqiZDj4MzJXk5tNPDjltv4fNbGSYcSH7xAdCqLQuDecXlL3XG4jI4eGLhGv:jfphutvtvAoH7igwQIemRnPI4eM4
    MD5:0E028E1E7A94D4C92F36869DB13749EF
    SHA1:8CF5154A9FB4F1F01F89ACA2203E46C3A37366EE
    SHA-256:7FA31B72F7EF520509F60FBF87BE1176C762A3CE96516FD187DC0FFB57A88A9B
    SHA-512:F7EBF3E455B369B5C3679F02F6276577E164A723AB7BE13ADA4A7F7BE11E228AD803C69A11793756A689C9F44F1E142EAB154D71659FE6A9D0EBE781E72103FA
    Malicious:false
    Reputation:low
    Preview:main.dir=${basedir}/../../../jfc/SwingApplet..src.dir=${main.dir}/src..build.dir=build.classes.dir=${build.dir}/classes.jar=${main.dir}/SwingApplet.jar.javadoc.dir=${build.dir}/javadoc..build.sysclasspath=ignore.# E.g.: cp=lib/x.jar:lib/y.jar.cp=.extra.run.cp=..#main.class=..run.cp=${cp}:${classes.dir}:${extra.run.cp}..debug=true.deprecation=false..nbjdk.home=${basedir}/../../../....applet.html=${main.dir}/SwingApplet.html.
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):3875
    Entropy (8bit):5.061728490099849
    Encrypted:false
    SSDEEP:48:ceOorYJTrYJEfDWQvs432sD32scMEtu33tYTHD1CxwKmlKas/PLSR3yS6WCCGQSJ:YorYJTrYJEfiQX3f3jp29TcHnS6WCCmJ
    MD5:F107EB3DFBD6D896031FCD76B3ECBF0B
    SHA1:E015EDDDEC3DA2B2E548CCE9F0B92A0DC2281DCA
    SHA-256:FEB42A16EAEFB53E305069E95443C706528B91C54D5354ADA487AFFB4E8D9F19
    SHA-512:0A0F6DEC846024B83BD55ACDEADB8F12823439BD295F8F07815364C274BEFDEB7329AF9D9199EAC0D2FDB76ED6B3A7A02B0DB05F7F254C467E9E796E0CD5BF55
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?>.. . Copyright (c) 2006, Oracle and/or its affiliates. All rights reserved... Redistribution and use in source and binary forms, with or without. modification, are permitted provided that the following conditions. are met:.. - Redistributions of source code must retain the above copyright. notice, this list of conditions and the following disclaimer... - Redistributions in binary form must reproduce the above copyright. notice, this list of conditions and the following disclaimer in the. documentation and/or other materials provided with the distribution... - Neither the name of Oracle nor the names of its. contributors may be used to endorse or promote products derived. from this software without specific prior written permission... THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. THE IMPLIED WARRANTIES OF MERCHANTABILITY
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):7747
    Entropy (8bit):4.201963322179113
    Encrypted:false
    SSDEEP:96:YorYJTrYJEfiQX3f3jp2DsGrJfkD+BbzYDrUh+RPW:YorsTrs+jX3f3d2D3rRBBbzYDr6+Re
    MD5:D7C4B41E9B8B67908AA876F499FC31F9
    SHA1:A9F5E2FA53873C8C94C95D79F3AF426503E4A525
    SHA-256:DF2856DFC1718EC050CA2B8CAF27934CC7A00A6DAEF0B89D43251E15B803831E
    SHA-512:FEC45CA257C10884CED9E78CFC75F4EEDD264C777407CEFCEF47AC1EED9938A16BDFDDEB7D01A195BA0D2AA48BCC3F89216A06D682DB0FA6BC794C9BAE5E4141
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?>.. . Copyright (c) 2006, Oracle and/or its affiliates. All rights reserved... Redistribution and use in source and binary forms, with or without. modification, are permitted provided that the following conditions. are met:.. - Redistributions of source code must retain the above copyright. notice, this list of conditions and the following disclaimer... - Redistributions in binary form must reproduce the above copyright. notice, this list of conditions and the following disclaimer in the. documentation and/or other materials provided with the distribution... - Neither the name of Oracle nor the names of its. contributors may be used to endorse or promote products derived. from this software without specific prior written permission... THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. THE IMPLIED WARRANTIES OF MERCHANTABILITY
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):2047
    Entropy (8bit):5.2347476452074035
    Encrypted:false
    SSDEEP:48:ceOorYJTrYJEfDWQvs432sD32scMEtu33tYTHDSvVKasrO:YorYJTrYJEfiQX3f3jp2gMC
    MD5:09484439763D77FEC72D05FE3CFB1B12
    SHA1:429EB9B175DABFE8045BCE26EAFC9190B3E9433B
    SHA-256:8007351C96A7D751C4764BA28323E45A711330F187B6CB28C39AA3288FF438F1
    SHA-512:624D72A6955240C3C256163AD5AD53BFB7016217E4C7B81578CC7A3FC2678DBE3CCF88205847EB12D792E7549E088C2F2CE11C0F705AFFBFFDC07BC885D550B7
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?>.. . Copyright (c) 2006, Oracle and/or its affiliates. All rights reserved... Redistribution and use in source and binary forms, with or without. modification, are permitted provided that the following conditions. are met:.. - Redistributions of source code must retain the above copyright. notice, this list of conditions and the following disclaimer... - Redistributions in binary form must reproduce the above copyright. notice, this list of conditions and the following disclaimer in the. documentation and/or other materials provided with the distribution... - Neither the name of Oracle nor the names of its. contributors may be used to endorse or promote products derived. from this software without specific prior written permission... THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. THE IMPLIED WARRANTIES OF MERCHANTABILITY
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):4218
    Entropy (8bit):4.9575689298800985
    Encrypted:false
    SSDEEP:48:ceOorYJTrYJEfDWQvs432sD32scMEtu33tYTHD5wj9fV3ORoZVPp1TED2AZiUZGQ:YorYJTrYJEfiQX3f3jp2FBY0
    MD5:8F8DB67A23AE3EFD024E91710F1A6739
    SHA1:26C3F95E0007310A3F6A35CCE6B61AF71B9F1C8B
    SHA-256:5AB23ACF89B98778B5885B46D500429E6906C4389CD4427D8D5BDE6727BB6BE3
    SHA-512:7E3B2E9EF782B2D12FEEF7DDF78FCDF4500ECA641E03AF66181D03DC81B0CD5B54E5376B245B0460A25FEA1AF70D11CF974FBCE1A5787D3310B50D56099FC2A1
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?>.. . Copyright (c) 2006, Oracle and/or its affiliates. All rights reserved... Redistribution and use in source and binary forms, with or without. modification, are permitted provided that the following conditions. are met:.. - Redistributions of source code must retain the above copyright. notice, this list of conditions and the following disclaimer... - Redistributions in binary form must reproduce the above copyright. notice, this list of conditions and the following disclaimer in the. documentation and/or other materials provided with the distribution... - Neither the name of Oracle nor the names of its. contributors may be used to endorse or promote products derived. from this software without specific prior written permission... THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. THE IMPLIED WARRANTIES OF MERCHANTABILITY
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):3504
    Entropy (8bit):5.152305793843179
    Encrypted:false
    SSDEEP:48:ceOorYJTrYJEfDWQvs432sD32scMEtu33tYTHDSvhlxuTJKaZzFKVzgDIE3YUvKS:YorYJTrYJEfiQX3f3jp2NzFaz4bso
    MD5:274BDC3914EE974137B9AC8B64D5E14A
    SHA1:EC522E260A288BD8A727E7713E6FDDF6629D2E50
    SHA-256:28E39B0120AFB4AE1DC3F7F69FB28E5788A6DFAA75321645465EB06F81CF33C4
    SHA-512:C3F03B6D522CCED4F4B0708C3BAA96B8F298492150CC697C24A7EE748782E1C359E3315A0B81BB163CB06A1731C92A962A2947D72680212C0FCA70D2AD4EB956
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?>.. . Copyright (c) 2006, Oracle and/or its affiliates. All rights reserved... Redistribution and use in source and binary forms, with or without. modification, are permitted provided that the following conditions. are met:.. - Redistributions of source code must retain the above copyright. notice, this list of conditions and the following disclaimer... - Redistributions in binary form must reproduce the above copyright. notice, this list of conditions and the following disclaimer in the. documentation and/or other materials provided with the distribution... - Neither the name of Oracle nor the names of its. contributors may be used to endorse or promote products derived. from this software without specific prior written permission... THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. THE IMPLIED WARRANTIES OF MERCHANTABILITY
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:ASCII text
    Category:dropped
    Size (bytes):398
    Entropy (8bit):4.665813720138944
    Encrypted:false
    SSDEEP:6:jHDj4MzJXk5tNPDxEU+vPKtv4fNbGSYcSH7xAdCqLst5lVDecXlL3XG4jIn:jHphutcU+vytvAoH7igwsPemRnPIn
    MD5:E65642A8CF9760702E436DBEC5FDDB7E
    SHA1:7134CE9E0CA0DFCEF40C4C6FDB93B22331081C1B
    SHA-256:94BC5A2CC029842CB62C9EDCD22614C07CF5BDD96C933B898A9B8D034436DDE0
    SHA-512:A0F2F96FA1DFEDA39E0560160784BC86CCB6A8385BC1B5DD636A9A54C5B0208ED49D07090FDDA1C6A54337159C66A5B3CBE99C2C76289518D26A28F80F6CA430
    Malicious:false
    Reputation:low
    Preview:main.dir=${basedir}/../../../jfc/TableExample..src.dir=${main.dir}/src..build.dir=build.classes.dir=${build.dir}/classes.jar=${main.dir}/TableExample.jar.javadoc.dir=${build.dir}/javadoc..build.sysclasspath=ignore.# E.g.: cp=lib/x.jar:lib/y.jar.cp=.extra.run.cp=..main.class=TableExample..run.cp=${cp}:${classes.dir}:${extra.run.cp}..debug=true.deprecation=false..nbjdk.home=${basedir}/../../../...
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):3572
    Entropy (8bit):5.084034940742686
    Encrypted:false
    SSDEEP:48:ceOorYJTrYJEfDWQvs432sD32scMEtu33tYTHDkxwKmlKas/PLSR3yhGQSbZnrf:YorYJTrYJEfiQX3f3jp2lTcHnhmJ
    MD5:621FD9E47834BCFD2B26EBB6746A05B4
    SHA1:6B102342102224AFB15A38F0D28D214906BD99F8
    SHA-256:7EC84F70F138A8767E7D29971491B3861167921CF5E1DC2227ECE620BEE8DDD8
    SHA-512:B1FBD858899342E819F6EDE7ED17C35B00A4F888416195199FC1EED1AA8A04A78D37A558801E9F3737E5D2DCB3019EFCCCB38451393D6C909E70E9B8F07DE209
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?>.. . Copyright (c) 2006, Oracle and/or its affiliates. All rights reserved... Redistribution and use in source and binary forms, with or without. modification, are permitted provided that the following conditions. are met:.. - Redistributions of source code must retain the above copyright. notice, this list of conditions and the following disclaimer... - Redistributions in binary form must reproduce the above copyright. notice, this list of conditions and the following disclaimer in the. documentation and/or other materials provided with the distribution... - Neither the name of Oracle nor the names of its. contributors may be used to endorse or promote products derived. from this software without specific prior written permission... THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. THE IMPLIED WARRANTIES OF MERCHANTABILITY
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):4218
    Entropy (8bit):4.9575689298800985
    Encrypted:false
    SSDEEP:48:ceOorYJTrYJEfDWQvs432sD32scMEtu33tYTHD5wj9fV3ORoZVPp1TED2AZiUZGQ:YorYJTrYJEfiQX3f3jp2FBY0
    MD5:8F8DB67A23AE3EFD024E91710F1A6739
    SHA1:26C3F95E0007310A3F6A35CCE6B61AF71B9F1C8B
    SHA-256:5AB23ACF89B98778B5885B46D500429E6906C4389CD4427D8D5BDE6727BB6BE3
    SHA-512:7E3B2E9EF782B2D12FEEF7DDF78FCDF4500ECA641E03AF66181D03DC81B0CD5B54E5376B245B0460A25FEA1AF70D11CF974FBCE1A5787D3310B50D56099FC2A1
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?>.. . Copyright (c) 2006, Oracle and/or its affiliates. All rights reserved... Redistribution and use in source and binary forms, with or without. modification, are permitted provided that the following conditions. are met:.. - Redistributions of source code must retain the above copyright. notice, this list of conditions and the following disclaimer... - Redistributions in binary form must reproduce the above copyright. notice, this list of conditions and the following disclaimer in the. documentation and/or other materials provided with the distribution... - Neither the name of Oracle nor the names of its. contributors may be used to endorse or promote products derived. from this software without specific prior written permission... THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. THE IMPLIED WARRANTIES OF MERCHANTABILITY
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):7447
    Entropy (8bit):4.234947748534417
    Encrypted:false
    SSDEEP:96:YorYJTrYJEfiQX3f3jp2rsGrJfkD+BbzYDrjh+RyW:YorsTrs+jX3f3d2r3rRBBbzYDrV+Rx
    MD5:76439B86A486C48E01688D9A81C4BA75
    SHA1:8F89F3AC7D0AB5084415E41B884FBC2DFD82F2D4
    SHA-256:09C25072B17D74BC16FEC2B58E195A580A0B36D31E84AC7C75B5F567601538C5
    SHA-512:C912E5241C6284F6BE54B10F5CDE571F44AEBE464BCC6A09698A136184F61AC31F43B898E39734945538AF0966D59D24507D6471847FB83DFB70A3C75AC5FF85
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?>.. . Copyright (c) 2006, Oracle and/or its affiliates. All rights reserved... Redistribution and use in source and binary forms, with or without. modification, are permitted provided that the following conditions. are met:.. - Redistributions of source code must retain the above copyright. notice, this list of conditions and the following disclaimer... - Redistributions in binary form must reproduce the above copyright. notice, this list of conditions and the following disclaimer in the. documentation and/or other materials provided with the distribution... - Neither the name of Oracle nor the names of its. contributors may be used to endorse or promote products derived. from this software without specific prior written permission... THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. THE IMPLIED WARRANTIES OF MERCHANTABILITY
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):2048
    Entropy (8bit):5.235953789601284
    Encrypted:false
    SSDEEP:48:ceOorYJTrYJEfDWQvs432sD32scMEtu33tYTHD+VKasrO:YorYJTrYJEfiQX3f3jp2yMC
    MD5:40E3B0779991B720FD247535DE5B2CC2
    SHA1:B4292A9DF42E48FBEC21C620AD9AC002A28A0943
    SHA-256:DDEB3D7FD574DAEED8FE2EC5BB5835146F63ED5C4CF587912FC76C6E70139296
    SHA-512:6A8AA65F9487D60F970776BD1E099A5FE74CB9584AD2C43D29A002BF13E293285D4A9ADB9DF9E0EB445C20DFE568BD162FE4984F5494D6DFA2E20260E575215B
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?>.. . Copyright (c) 2006, Oracle and/or its affiliates. All rights reserved... Redistribution and use in source and binary forms, with or without. modification, are permitted provided that the following conditions. are met:.. - Redistributions of source code must retain the above copyright. notice, this list of conditions and the following disclaimer... - Redistributions in binary form must reproduce the above copyright. notice, this list of conditions and the following disclaimer in the. documentation and/or other materials provided with the distribution... - Neither the name of Oracle nor the names of its. contributors may be used to endorse or promote products derived. from this software without specific prior written permission... THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. THE IMPLIED WARRANTIES OF MERCHANTABILITY
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):3506
    Entropy (8bit):5.153003782543427
    Encrypted:false
    SSDEEP:48:ceOorYJTrYJEfDWQvs432sD32scMEtu33tYTHDM/xuTJKaZzFKVzgDIE3YUvK5cf:YorYJTrYJEfiQX3f3jp2xzFaz4bso
    MD5:9262B3BE4A2D8201262E73E23AB4DEC1
    SHA1:EB9988BCFAC16C50905A139946CE07A634495A1B
    SHA-256:B805C664512488407F0DCC012834C1972A13CFF03E834117EF55B4B765E59AC5
    SHA-512:2F61F1C16835498E6EC5B87A04D62325932B327634753ED271C7F4114060CA22E8D9FB8BF149E15ACC8370002C08D4868860FFE9AE95CAA74C9AA6ADBEEBEE8C
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?>.. . Copyright (c) 2006, Oracle and/or its affiliates. All rights reserved... Redistribution and use in source and binary forms, with or without. modification, are permitted provided that the following conditions. are met:.. - Redistributions of source code must retain the above copyright. notice, this list of conditions and the following disclaimer... - Redistributions in binary form must reproduce the above copyright. notice, this list of conditions and the following disclaimer in the. documentation and/or other materials provided with the distribution... - Neither the name of Oracle nor the names of its. contributors may be used to endorse or promote products derived. from this software without specific prior written permission... THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. THE IMPLIED WARRANTIES OF MERCHANTABILITY
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):3576
    Entropy (8bit):5.080865464518623
    Encrypted:false
    SSDEEP:48:ck1OorYJTrYJEfDWQvs432sD32scMEtu33tYTHDcxwKmlKas/PLSR3yhGQSbZnrf:noorYJTrYJEfiQX3f3jp2lTcHnhmJ
    MD5:C426BEE89C66F9AC905CBA91E3B85BD6
    SHA1:1CCFFDBF476553415534C2A66E1AD1E5CADC6837
    SHA-256:884FC201A315927E6C1DFAE460FFB2357933DF8BA6B62BE845A01B45492EC0A2
    SHA-512:34A9DEB36A4EA339E49747E382F6D065CD3F808AFFFFD08A4ADAB51DE9C385997F34E3E0D168B2DC335B7F8216A08F8758191A795EF5ACEC3A73781E7930DA83
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?>.. . Copyright (c) 2011, Oracle and/or its affiliates. All rights reserved... Redistribution and use in source and binary forms, with or without. modification, are permitted provided that the following conditions. are met:.. - Redistributions of source code must retain the above copyright. notice, this list of conditions and the following disclaimer... - Redistributions in binary form must reproduce the above copyright. notice, this list of conditions and the following disclaimer in the. documentation and/or other materials provided with the distribution... - Neither the name of Oracle nor the names of its. contributors may be used to endorse or promote products derived. from this software without specific prior written permission... THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. THE IMPLIED WARRANTIES OF MERCHANTABILITY
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:ASCII text
    Category:dropped
    Size (bytes):416
    Entropy (8bit):4.630339027669123
    Encrypted:false
    SSDEEP:6:j3fDj4MzJXk5tNPDx8Tqtv4fNbGSYcSH7xAdCqLstycbpDecXlL3XG4jIn:j3fphutUTqtvAoH7igw6bdemRnPIn
    MD5:657B229BD005F3D7E0B9C69FFA595CFC
    SHA1:036E0A187CA552071176498A44DA7C6E26923A7F
    SHA-256:793BAD3088A0BE654E0FB0C1B14B05B71771578DFC13BF8E6464A77B11DCB1C4
    SHA-512:42F688B4975E0626B65D0373D1966BFA1716FC6B6FC662A62243FBF88E67730DD4BE49D80D9B14A6A9216731C53E2A8A099A2619D3B9ACEE8382ECF6673ED91F
    Malicious:false
    Reputation:low
    Preview:main.dir=${basedir}/../../../jfc/TransparentRuler..src.dir=${main.dir}/src..build.dir=build.classes.dir=${build.dir}/classes.jar=${main.dir}/TransparentRuler.jar.javadoc.dir=${build.dir}/javadoc..build.sysclasspath=ignore.# E.g.: cp=lib/x.jar:lib/y.jar.cp=.extra.run.cp=..main.class=transparentruler.Ruler..run.cp=${cp}:${classes.dir}:${extra.run.cp}..debug=true.deprecation=false..nbjdk.home=${basedir}/../../../...
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):4218
    Entropy (8bit):4.957094771511203
    Encrypted:false
    SSDEEP:48:ck1OorYJTrYJEfDWQvs432sD32scMEtu33tYTHD5wj9fV3ORoZVPp1TED2AZiUZt:noorYJTrYJEfiQX3f3jp2FBY0
    MD5:F820A906A00583ED8730C2D4C343D0E2
    SHA1:DF43F5ECC34ED7C6445661E05D4FAED706D3FC77
    SHA-256:25D32A1AA9511F1617B6D6BED5026AFB3E9113A4893B1F800CBF670626D446CF
    SHA-512:D3C0DCDDC6C3B036C95B76C3D5FCB18698D9DDCF85AC7E3084A1D75AD74157D880296ACF2EE7E86FB69382D3E0733017CF44360E82BE773A18D2B2BCEE5C291A
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?>.. . Copyright (c) 2011, Oracle and/or its affiliates. All rights reserved... Redistribution and use in source and binary forms, with or without. modification, are permitted provided that the following conditions. are met:.. - Redistributions of source code must retain the above copyright. notice, this list of conditions and the following disclaimer... - Redistributions in binary form must reproduce the above copyright. notice, this list of conditions and the following disclaimer in the. documentation and/or other materials provided with the distribution... - Neither the name of Oracle nor the names of its. contributors may be used to endorse or promote products derived. from this software without specific prior written permission... THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. THE IMPLIED WARRANTIES OF MERCHANTABILITY
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):7451
    Entropy (8bit):4.234059265800569
    Encrypted:false
    SSDEEP:96:noorYJTrYJEfiQX3f3jp2zsGrJfkD+BbzYDrjh+RyW:oorsTrs+jX3f3d2z3rRBBbzYDrV+Rx
    MD5:6EF169EEA1501739A49997A2FC30D126
    SHA1:7919C12CCCDD42ADA508AD1B86672EC02F44DD89
    SHA-256:D0F0DA4901889BF9A9C3DDD85BC640DFA52B8201682B71DB5F3F99E92AA2DFF7
    SHA-512:3CE205CAF14EE9EC19BD4EFB8B805F6FCD5653273A102C0C81ED6D86C61E8C5BDF80002B13D51355BCEEED43214F7952DEE9008B4B5684ECD6741C08AC88872A
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?>.. . Copyright (c) 2011, Oracle and/or its affiliates. All rights reserved... Redistribution and use in source and binary forms, with or without. modification, are permitted provided that the following conditions. are met:.. - Redistributions of source code must retain the above copyright. notice, this list of conditions and the following disclaimer... - Redistributions in binary form must reproduce the above copyright. notice, this list of conditions and the following disclaimer in the. documentation and/or other materials provided with the distribution... - Neither the name of Oracle nor the names of its. contributors may be used to endorse or promote products derived. from this software without specific prior written permission... THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. THE IMPLIED WARRANTIES OF MERCHANTABILITY
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):2052
    Entropy (8bit):5.230849459614041
    Encrypted:false
    SSDEEP:48:ck1OorYJTrYJEfDWQvs432sD32scMEtu33tYTHDWVKasrO:noorYJTrYJEfiQX3f3jp2iMC
    MD5:F15A13AA28121FED1A2325C3BBBFF89C
    SHA1:41722F6DF72BB27090BFE1934B34A5B12BCDED81
    SHA-256:8B3BEBB490FCAB2D177D534422065CBC79E565C143FEB06E891B01085B1B7125
    SHA-512:7CB964EDC359E4F4F453B56A071A0CA666055C617E495BC42F2750AD01832CFD8E128992846E2FD9D959E035C72904B7C051F10EC440F6B986F3B38C38774A84
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?>.. . Copyright (c) 2011, Oracle and/or its affiliates. All rights reserved... Redistribution and use in source and binary forms, with or without. modification, are permitted provided that the following conditions. are met:.. - Redistributions of source code must retain the above copyright. notice, this list of conditions and the following disclaimer... - Redistributions in binary form must reproduce the above copyright. notice, this list of conditions and the following disclaimer in the. documentation and/or other materials provided with the distribution... - Neither the name of Oracle nor the names of its. contributors may be used to endorse or promote products derived. from this software without specific prior written permission... THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. THE IMPLIED WARRANTIES OF MERCHANTABILITY
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):3514
    Entropy (8bit):5.147520858044262
    Encrypted:false
    SSDEEP:48:ck1OorYJTrYJEfDWQvs432sD32scMEtu33tYTHDUVNxuTJKaZzFKVzgDIE3YUvKS:noorYJTrYJEfiQX3f3jp2i+zFaz4bso
    MD5:2083B5AB3437B3D683D84ACAFEF88860
    SHA1:F905002D3FBBEA8C462731F5FEB6D51E9B5E98B9
    SHA-256:531C318C6B8D15B0A9C1F45B373C0CB5669251A4693F9D649CA3DF9BDDFA822D
    SHA-512:871C00C28EDE28F1C77AC9654C84559538D566EDFCC4AF5A5CE81EE965B349DD67C07877B1DE5CB2996A9F910465FF6B568DA8843ED13705AD7A430C3B7B1B13
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?>.. . Copyright (c) 2011, Oracle and/or its affiliates. All rights reserved... Redistribution and use in source and binary forms, with or without. modification, are permitted provided that the following conditions. are met:.. - Redistributions of source code must retain the above copyright. notice, this list of conditions and the following disclaimer... - Redistributions in binary form must reproduce the above copyright. notice, this list of conditions and the following disclaimer in the. documentation and/or other materials provided with the distribution... - Neither the name of Oracle nor the names of its. contributors may be used to endorse or promote products derived. from this software without specific prior written permission... THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. THE IMPLIED WARRANTIES OF MERCHANTABILITY
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:ASCII text
    Category:dropped
    Size (bytes):411
    Entropy (8bit):4.704371968976003
    Encrypted:false
    SSDEEP:6:jI2AUvGDj4MzJXk5tNPDjmAwttv4fNbGSYcSH7xAdCqLst1HjAUvupDecXlL3XGn:jbuphut9gttvAoH7igw4HheemRnPIn
    MD5:011280D0DCC1ED8509C5B0910AB70B14
    SHA1:19373546AE513BAD7B72D4C4B33E89467405F2D6
    SHA-256:FC00853E61CEFC1006B541DA3B89762BDCA2DEED328EF252B8FAC9C8EE0777BE
    SHA-512:CDA12A629D1AC00F924CF8525D29016324BF809C044E6A3D8F56660209C010F5DBBAA63ACA237AE300F125EBDF0F9964043BB36FB0960670E9302BB0E2455A09
    Malicious:false
    Reputation:low
    Preview:main.dir=${basedir}/../../../management/FullThreadDump..src.dir=${main.dir}/src..build.dir=build.classes.dir=${build.dir}/classes.jar=${main.dir}/FullThreadDump.jar.javadoc.dir=${build.dir}/javadoc..build.sysclasspath=ignore.# E.g.: cp=lib/x.jar:lib/y.jar.cp=.extra.run.cp=..main.class=FullThreadDump..run.cp=${cp}:${classes.dir}:${extra.run.cp}..debug=true.deprecation=false..nbjdk.home=${basedir}/../../../...
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):3574
    Entropy (8bit):5.0845184993951
    Encrypted:false
    SSDEEP:48:ceOorYJTrYJEfDWQvs432sD32scMEtu33tYTHDTxwKmlKas/PLSR3yhGQSbZnrf:YorYJTrYJEfiQX3f3jp22TcHnhmJ
    MD5:52B4F98DCA0FE1FE8F97554FB9526DBC
    SHA1:1BCA4EC8C2B81CB7233E58303A96A51EEF8DB2B0
    SHA-256:9F1F85E7717D2D5C25896D0CC2ACB964D5054656C077F6562BD53842D539E0EC
    SHA-512:1EB4B8395D62880C100CFD546DFC9168D4D853952DA701817159F1A873D0985BBBC14F5E7D2C24D972987172AA1E4244FF68D2C2A9027FD5A694CBC125309768
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?>.. . Copyright (c) 2006, Oracle and/or its affiliates. All rights reserved... Redistribution and use in source and binary forms, with or without. modification, are permitted provided that the following conditions. are met:.. - Redistributions of source code must retain the above copyright. notice, this list of conditions and the following disclaimer... - Redistributions in binary form must reproduce the above copyright. notice, this list of conditions and the following disclaimer in the. documentation and/or other materials provided with the distribution... - Neither the name of Oracle nor the names of its. contributors may be used to endorse or promote products derived. from this software without specific prior written permission... THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. THE IMPLIED WARRANTIES OF MERCHANTABILITY
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):2050
    Entropy (8bit):5.235968985168122
    Encrypted:false
    SSDEEP:48:ceOorYJTrYJEfDWQvs432sD32scMEtu33tYTHDVVKasrO:YorYJTrYJEfiQX3f3jp2hMC
    MD5:0B8118C64D50AB723E47A94AC66D2A50
    SHA1:F940B0A571F224FAC7233DC5855962AF2E2C6D20
    SHA-256:CFB6A71BBF2FFB0FDF27FD793F1A6A43A1F4BCFE8E479DA9F760B22CB7FE9BF8
    SHA-512:057715E9720366765DD37B3E8DF426842BE48798C95F7DF0ECE9FAD7BD14EDC66698D9C01B186489460652E2B5C291EB932CF1FA02BB4E0B5639395506C662FF
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?>.. . Copyright (c) 2006, Oracle and/or its affiliates. All rights reserved... Redistribution and use in source and binary forms, with or without. modification, are permitted provided that the following conditions. are met:.. - Redistributions of source code must retain the above copyright. notice, this list of conditions and the following disclaimer... - Redistributions in binary form must reproduce the above copyright. notice, this list of conditions and the following disclaimer in the. documentation and/or other materials provided with the distribution... - Neither the name of Oracle nor the names of its. contributors may be used to endorse or promote products derived. from this software without specific prior written permission... THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. THE IMPLIED WARRANTIES OF MERCHANTABILITY
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):7449
    Entropy (8bit):4.236160473271319
    Encrypted:false
    SSDEEP:96:YorYJTrYJEfiQX3f3jp2qsGrJfkD+BbzYDrjh+RyW:YorsTrs+jX3f3d2q3rRBBbzYDrV+Rx
    MD5:B5D6A9326CBB93846E20684CE1887C26
    SHA1:81911511E547D38DFD17E10503BC81F778307FFF
    SHA-256:592F41E24196BCCEE61CDD52AFE48C7ABE0D2DE07E97B3432EACF13E44210FBB
    SHA-512:CCEA63EC5D833523ABCAD30A85EA1D63FBB9F9A1505B4004F4D9FDE9AF7FD7F6044A18981B5F6EE37B7A19ED92682E69C69DA4CCC180713D519F19311BB49281
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?>.. . Copyright (c) 2006, Oracle and/or its affiliates. All rights reserved... Redistribution and use in source and binary forms, with or without. modification, are permitted provided that the following conditions. are met:.. - Redistributions of source code must retain the above copyright. notice, this list of conditions and the following disclaimer... - Redistributions in binary form must reproduce the above copyright. notice, this list of conditions and the following disclaimer in the. documentation and/or other materials provided with the distribution... - Neither the name of Oracle nor the names of its. contributors may be used to endorse or promote products derived. from this software without specific prior written permission... THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. THE IMPLIED WARRANTIES OF MERCHANTABILITY
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):4218
    Entropy (8bit):4.9575689298800985
    Encrypted:false
    SSDEEP:48:ceOorYJTrYJEfDWQvs432sD32scMEtu33tYTHD5wj9fV3ORoZVPp1TED2AZiUZGQ:YorYJTrYJEfiQX3f3jp2FBY0
    MD5:8F8DB67A23AE3EFD024E91710F1A6739
    SHA1:26C3F95E0007310A3F6A35CCE6B61AF71B9F1C8B
    SHA-256:5AB23ACF89B98778B5885B46D500429E6906C4389CD4427D8D5BDE6727BB6BE3
    SHA-512:7E3B2E9EF782B2D12FEEF7DDF78FCDF4500ECA641E03AF66181D03DC81B0CD5B54E5376B245B0460A25FEA1AF70D11CF974FBCE1A5787D3310B50D56099FC2A1
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?>.. . Copyright (c) 2006, Oracle and/or its affiliates. All rights reserved... Redistribution and use in source and binary forms, with or without. modification, are permitted provided that the following conditions. are met:.. - Redistributions of source code must retain the above copyright. notice, this list of conditions and the following disclaimer... - Redistributions in binary form must reproduce the above copyright. notice, this list of conditions and the following disclaimer in the. documentation and/or other materials provided with the distribution... - Neither the name of Oracle nor the names of its. contributors may be used to endorse or promote products derived. from this software without specific prior written permission... THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. THE IMPLIED WARRANTIES OF MERCHANTABILITY
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):3510
    Entropy (8bit):5.154204887333239
    Encrypted:false
    SSDEEP:48:ceOorYJTrYJEfDWQvs432sD32scMEtu33tYTHDpIxuTJKaZzFKVzgDIE3YUvK5cf:YorYJTrYJEfiQX3f3jp2bzFaz4bso
    MD5:15CE323174CFF6AD107BD6FEA2C346C7
    SHA1:37B1839CB3700D829F5EFE0CE825D079BFAF2D5B
    SHA-256:92C5571B1E45825524EB1302A30C9BB1B1F26A8A795DED765DD2A1A4AD0027A0
    SHA-512:9AA727633091D49589946A2C78A84D2F896BD6C7CC02B4EDFA29C94F8C6E09B06B75D18FE725A352DBFDE1FADCD1544230D03DB06663E72A713F16F1AC3D8035
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?>.. . Copyright (c) 2006, Oracle and/or its affiliates. All rights reserved... Redistribution and use in source and binary forms, with or without. modification, are permitted provided that the following conditions. are met:.. - Redistributions of source code must retain the above copyright. notice, this list of conditions and the following disclaimer... - Redistributions in binary form must reproduce the above copyright. notice, this list of conditions and the following disclaimer in the. documentation and/or other materials provided with the distribution... - Neither the name of Oracle nor the names of its. contributors may be used to endorse or promote products derived. from this software without specific prior written permission... THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. THE IMPLIED WARRANTIES OF MERCHANTABILITY
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):3564
    Entropy (8bit):5.083271863868386
    Encrypted:false
    SSDEEP:48:ceOorYJTrYJEfDWQvs432sD32scMEtu33tYTHDpxwKmlKas/PLSR3yhGQSbZnrf:YorYJTrYJEfiQX3f3jp2kTcHnhmJ
    MD5:F143A78BC483D9083D23E582E01ADEB8
    SHA1:DB7A7021C89D98044A0F7376532FDDEA5B844A61
    SHA-256:32F847C3740B8E48DD939B87D0BBD63C858C9E3778C8745A9468D71C39F78F8D
    SHA-512:C7705D99C23A63C770EFA99E9DFBB7CC38236E45C075B3E9524F27E5AB4CB80C5F032C47B523C6961FA1E47D56C0EC295E1F82FB6E91713B8F37409C02E2DB3D
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?>.. . Copyright (c) 2006, Oracle and/or its affiliates. All rights reserved... Redistribution and use in source and binary forms, with or without. modification, are permitted provided that the following conditions. are met:.. - Redistributions of source code must retain the above copyright. notice, this list of conditions and the following disclaimer... - Redistributions in binary form must reproduce the above copyright. notice, this list of conditions and the following disclaimer in the. documentation and/or other materials provided with the distribution... - Neither the name of Oracle nor the names of its. contributors may be used to endorse or promote products derived. from this software without specific prior written permission... THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. THE IMPLIED WARRANTIES OF MERCHANTABILITY
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:ASCII text
    Category:dropped
    Size (bytes):411
    Entropy (8bit):4.700329995091541
    Encrypted:false
    SSDEEP:6:jIVNWiDj4MzJXk5tNPDvSttv4fNbGSYcWQ5H7xQLJNnGQ4fLst/FMDecXlL3XG4P:jRiphutxSttvAV5H7S/nGQ4joIemRnb
    MD5:EA23E84815097FD88E6CAAE48F803E25
    SHA1:87AB95809C96D18AE7B8B46A69E197B1DD4D2AB8
    SHA-256:20E3574F149A9EC63D0AD1DE1DF27B602D793F356DAC4832441B5A9173B35C41
    SHA-512:BED664A752941D46098FDEF3C636EE7E4B01D2C122FADD37AF281E4C281CE12D7D8880E146F4FF43F0CC9E251965B4C8AE2DA40F18E0710E54054E099A8F0824
    Malicious:false
    Reputation:low
    Preview:main.dir=${basedir}/../../../management/JTop..src.dir=${main.dir}/src..build.dir=build.classes.dir=${build.dir}/classes.jar=${main.dir}/JTop.jar.javadoc.dir=${build.dir}/javadoc..build.sysclasspath=ignore..nbjdk.home=${basedir}/../../../...# E.g.: cp=lib/x.jar:lib/y.jar.cp=${nbjdk.home}/lib/jconsole.jar.extra.run.cp=..main.class=JTop..run.cp=${cp}:${classes.dir}:${extra.run.cp}..debug=true.deprecation=false.
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):2040
    Entropy (8bit):5.235574053286524
    Encrypted:false
    SSDEEP:48:ceOorYJTrYJEfDWQvs432sD32scMEtu33tYTHDqArVKasrO:YorYJTrYJEfiQX3f3jp2frMC
    MD5:8257E3E32F7E5F29699D5E6C55593F79
    SHA1:38BF42C03ED3F0772A471AD649539950E365C8A3
    SHA-256:27510C415C29F435AD2903166E940D799932A526FB8B847DB252FFE8D04239BB
    SHA-512:9F5E4E6E235E19D0B3789777FF5684F306F5CB8C254788E61FE033FB3936F788E82E9C2F501B38D739BF5BFB1F95BFD8C42D79A51F6184FC2427E6C97892616E
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?>.. . Copyright (c) 2006, Oracle and/or its affiliates. All rights reserved... Redistribution and use in source and binary forms, with or without. modification, are permitted provided that the following conditions. are met:.. - Redistributions of source code must retain the above copyright. notice, this list of conditions and the following disclaimer... - Redistributions in binary form must reproduce the above copyright. notice, this list of conditions and the following disclaimer in the. documentation and/or other materials provided with the distribution... - Neither the name of Oracle nor the names of its. contributors may be used to endorse or promote products derived. from this software without specific prior written permission... THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. THE IMPLIED WARRANTIES OF MERCHANTABILITY
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):3490
    Entropy (8bit):5.153171497094086
    Encrypted:false
    SSDEEP:48:ceOorYJTrYJEfDWQvs432sD32scMEtu33tYTHDXqxuTJKaZzFKVzgDIE3YUvK5cf:YorYJTrYJEfiQX3f3jp2HzFaz4bso
    MD5:9ED62210F1C075259C676724C04836F9
    SHA1:91AA32D4D9B0720BB8A161D26D3C405B6DB6324A
    SHA-256:91C7B0E9CC78347DBF48E949D5835768F08C99011DC5E76F821134756E37C5CC
    SHA-512:407610C977034F7990B12C97A9FE8AFE41F5549BCAC44BE46564058F32E523459CD955D64FDF0B3BC04B30CC6FCA6F257FB9E8B344625084BEDDB2FB16C93EDF
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?>.. . Copyright (c) 2006, Oracle and/or its affiliates. All rights reserved... Redistribution and use in source and binary forms, with or without. modification, are permitted provided that the following conditions. are met:.. - Redistributions of source code must retain the above copyright. notice, this list of conditions and the following disclaimer... - Redistributions in binary form must reproduce the above copyright. notice, this list of conditions and the following disclaimer in the. documentation and/or other materials provided with the distribution... - Neither the name of Oracle nor the names of its. contributors may be used to endorse or promote products derived. from this software without specific prior written permission... THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. THE IMPLIED WARRANTIES OF MERCHANTABILITY
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):4218
    Entropy (8bit):4.9575689298800985
    Encrypted:false
    SSDEEP:48:ceOorYJTrYJEfDWQvs432sD32scMEtu33tYTHD5wj9fV3ORoZVPp1TED2AZiUZGQ:YorYJTrYJEfiQX3f3jp2FBY0
    MD5:8F8DB67A23AE3EFD024E91710F1A6739
    SHA1:26C3F95E0007310A3F6A35CCE6B61AF71B9F1C8B
    SHA-256:5AB23ACF89B98778B5885B46D500429E6906C4389CD4427D8D5BDE6727BB6BE3
    SHA-512:7E3B2E9EF782B2D12FEEF7DDF78FCDF4500ECA641E03AF66181D03DC81B0CD5B54E5376B245B0460A25FEA1AF70D11CF974FBCE1A5787D3310B50D56099FC2A1
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?>.. . Copyright (c) 2006, Oracle and/or its affiliates. All rights reserved... Redistribution and use in source and binary forms, with or without. modification, are permitted provided that the following conditions. are met:.. - Redistributions of source code must retain the above copyright. notice, this list of conditions and the following disclaimer... - Redistributions in binary form must reproduce the above copyright. notice, this list of conditions and the following disclaimer in the. documentation and/or other materials provided with the distribution... - Neither the name of Oracle nor the names of its. contributors may be used to endorse or promote products derived. from this software without specific prior written permission... THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. THE IMPLIED WARRANTIES OF MERCHANTABILITY
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):7439
    Entropy (8bit):4.233913981323902
    Encrypted:false
    SSDEEP:96:YorYJTrYJEfiQX3f3jp2gsGrJfkD+BbzYDrjh+RyW:YorsTrs+jX3f3d2g3rRBBbzYDrV+Rx
    MD5:F8BEBB69CB39B3F5EAEF6742853299EA
    SHA1:8402CD7561D4FDE70D1FDADD9A26E7DE30593D5F
    SHA-256:FAB2DDC7DE844F970C0DA99E30C4F30C11A7F33F7F8455239529D9053AD6E6CE
    SHA-512:292199F7DF797CF58C9D3A37DAB06073BAC2A78F2A120E56F6BBD32084C434B130AE06822B78271024EB68060FA5F446F983E4AA7211F21FDD7F9BE47C98909D
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?>.. . Copyright (c) 2006, Oracle and/or its affiliates. All rights reserved... Redistribution and use in source and binary forms, with or without. modification, are permitted provided that the following conditions. are met:.. - Redistributions of source code must retain the above copyright. notice, this list of conditions and the following disclaimer... - Redistributions in binary form must reproduce the above copyright. notice, this list of conditions and the following disclaimer in the. documentation and/or other materials provided with the distribution... - Neither the name of Oracle nor the names of its. contributors may be used to endorse or promote products derived. from this software without specific prior written permission... THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. THE IMPLIED WARRANTIES OF MERCHANTABILITY
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):3573
    Entropy (8bit):5.083396662545413
    Encrypted:false
    SSDEEP:48:ceOorYJTrYJEfDWQvs432sD32scMEtu33tYTHDj7xwKmlKas/PLSR3yhGQSbZnrf:YorYJTrYJEfiQX3f3jp2faTcHnhmJ
    MD5:C809E4B37D03620B42F29C2BD3D428DC
    SHA1:C5D13C8D2C09855248837BA84DF60980112002D3
    SHA-256:4DC11B6E4AEB79C756A5CCC8B911F0CBF78A2150999C39BCE7E5DE41677EBDE5
    SHA-512:9D7867ECAE070A218FED0F0E9264FF2C09E93ABC5CEB48C6313CC2D7BF8BDDB5732CD49FFCD7588AD63D6EB5D190F085EBF40028E080C816FD0C7C0D258DA130
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?>.. . Copyright (c) 2006, Oracle and/or its affiliates. All rights reserved... Redistribution and use in source and binary forms, with or without. modification, are permitted provided that the following conditions. are met:.. - Redistributions of source code must retain the above copyright. notice, this list of conditions and the following disclaimer... - Redistributions in binary form must reproduce the above copyright. notice, this list of conditions and the following disclaimer in the. documentation and/or other materials provided with the distribution... - Neither the name of Oracle nor the names of its. contributors may be used to endorse or promote products derived. from this software without specific prior written permission... THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. THE IMPLIED WARRANTIES OF MERCHANTABILITY
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:ASCII text
    Category:dropped
    Size (bytes):408
    Entropy (8bit):4.676627596560209
    Encrypted:false
    SSDEEP:6:jIOM0cTZDj4MzJXk5tNPD2cMtv4fNbGSYcSH7xAdCqLstLc3pDecXlL3XG4jIn:jO0yphut0NtvAoH7igwCydemRnPIn
    MD5:CE533AD50E9124A9B06B05971F12D74B
    SHA1:2C7837A43C9AD85FE59EFA32FB63509129637A53
    SHA-256:1108E2C1F4EBB485C8E713FE1BC3A2F8133FCCF838CEE7F9A70CA56C3DB8E3D5
    SHA-512:E7D7CD8A1F672F906467CBECFEFC79119E55A462DE727A998533E96FE903460653C4DDF0AA68C47D55497C628CD4E3DFD61698EDB787DBBAC78F80586915605D
    Malicious:false
    Reputation:low
    Preview:main.dir=${basedir}/../../../management/MemoryMonitor..src.dir=${main.dir}/src..build.dir=build.classes.dir=${build.dir}/classes.jar=${main.dir}/MemoryMonitor.jar.javadoc.dir=${build.dir}/javadoc..build.sysclasspath=ignore.# E.g.: cp=lib/x.jar:lib/y.jar.cp=.extra.run.cp=..main.class=MemoryMonitor..run.cp=${cp}:${classes.dir}:${extra.run.cp}..debug=true.deprecation=false..nbjdk.home=${basedir}/../../../...
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):7448
    Entropy (8bit):4.23502462741311
    Encrypted:false
    SSDEEP:96:YorYJTrYJEfiQX3f3jp2dcXsGrJfkD+BbzYDrjh+RyW:YorsTrs+jX3f3d2dcX3rRBBbzYDrV+Rx
    MD5:9914825B51775000BAD206898E54A2B8
    SHA1:FF096DFE828325C12AEDC0CCB68AFFE901CD8A87
    SHA-256:121669547A208BAF315F0B646F19854D4DD46F2EE7F0CEA2501A9793CA95DC8A
    SHA-512:5EF18C8F8BAD108861E2F8998403A6C089D991CC7094D08359A142F916A56994DA2A7146828D8BD70B06D6415A837E6F3A6ED47E82068C1132B88BD6BE72D611
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?>.. . Copyright (c) 2006, Oracle and/or its affiliates. All rights reserved... Redistribution and use in source and binary forms, with or without. modification, are permitted provided that the following conditions. are met:.. - Redistributions of source code must retain the above copyright. notice, this list of conditions and the following disclaimer... - Redistributions in binary form must reproduce the above copyright. notice, this list of conditions and the following disclaimer in the. documentation and/or other materials provided with the distribution... - Neither the name of Oracle nor the names of its. contributors may be used to endorse or promote products derived. from this software without specific prior written permission... THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. THE IMPLIED WARRANTIES OF MERCHANTABILITY
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):4218
    Entropy (8bit):4.9575689298800985
    Encrypted:false
    SSDEEP:48:ceOorYJTrYJEfDWQvs432sD32scMEtu33tYTHD5wj9fV3ORoZVPp1TED2AZiUZGQ:YorYJTrYJEfiQX3f3jp2FBY0
    MD5:8F8DB67A23AE3EFD024E91710F1A6739
    SHA1:26C3F95E0007310A3F6A35CCE6B61AF71B9F1C8B
    SHA-256:5AB23ACF89B98778B5885B46D500429E6906C4389CD4427D8D5BDE6727BB6BE3
    SHA-512:7E3B2E9EF782B2D12FEEF7DDF78FCDF4500ECA641E03AF66181D03DC81B0CD5B54E5376B245B0460A25FEA1AF70D11CF974FBCE1A5787D3310B50D56099FC2A1
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?>.. . Copyright (c) 2006, Oracle and/or its affiliates. All rights reserved... Redistribution and use in source and binary forms, with or without. modification, are permitted provided that the following conditions. are met:.. - Redistributions of source code must retain the above copyright. notice, this list of conditions and the following disclaimer... - Redistributions in binary form must reproduce the above copyright. notice, this list of conditions and the following disclaimer in the. documentation and/or other materials provided with the distribution... - Neither the name of Oracle nor the names of its. contributors may be used to endorse or promote products derived. from this software without specific prior written permission... THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. THE IMPLIED WARRANTIES OF MERCHANTABILITY
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):2049
    Entropy (8bit):5.233950202872972
    Encrypted:false
    SSDEEP:48:ceOorYJTrYJEfDWQvs432sD32scMEtu33tYTHDUGlVKasrO:YorYJTrYJEfiQX3f3jp2AuMC
    MD5:E603DC83410911DFCB417320110489D6
    SHA1:30414B0EF98C4CF41D716161055756C4D2609E3F
    SHA-256:A02AB3EE8EAA0C7CD7F96B7AA4397927E68EB61388F0873E581D58BC8F8372A3
    SHA-512:71FF94B07FAFAFB9F586C212C755D18D7D7E1CF7F254D677CFE3CC6E5F7E2D4B0E7AF040B824A1CFC036556DB86574A9C7A26B05FB5CD0AE87540E4E08991E1A
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?>.. . Copyright (c) 2006, Oracle and/or its affiliates. All rights reserved... Redistribution and use in source and binary forms, with or without. modification, are permitted provided that the following conditions. are met:.. - Redistributions of source code must retain the above copyright. notice, this list of conditions and the following disclaimer... - Redistributions in binary form must reproduce the above copyright. notice, this list of conditions and the following disclaimer in the. documentation and/or other materials provided with the distribution... - Neither the name of Oracle nor the names of its. contributors may be used to endorse or promote products derived. from this software without specific prior written permission... THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. THE IMPLIED WARRANTIES OF MERCHANTABILITY
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):3508
    Entropy (8bit):5.152605874475549
    Encrypted:false
    SSDEEP:48:ceOorYJTrYJEfDWQvs432sD32scMEtu33tYTHDUG5vCNxuTJKaZzFKVzgDIE3YUR:YorYJTrYJEfiQX3f3jp2AgC+zFaz4bso
    MD5:E9E794C040C9CCA5C584F8524DB949DF
    SHA1:D511DE8FB5470B9D210A4B79480BC568A2457F83
    SHA-256:142A84C2D68E29633291CA77C7BA1A990775A9F07146287772253FAA579D907F
    SHA-512:DB90CE9997ACE010409F67D06987AC36B17CCCA394E1B098C236039927A29A5287DAA43C2C0CFDC5139A1A8CE0D41819CEDD6EEEB6EA3EEAD002EFD4E0B7DBF4
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?>.. . Copyright (c) 2006, Oracle and/or its affiliates. All rights reserved... Redistribution and use in source and binary forms, with or without. modification, are permitted provided that the following conditions. are met:.. - Redistributions of source code must retain the above copyright. notice, this list of conditions and the following disclaimer... - Redistributions in binary form must reproduce the above copyright. notice, this list of conditions and the following disclaimer in the. documentation and/or other materials provided with the distribution... - Neither the name of Oracle nor the names of its. contributors may be used to endorse or promote products derived. from this software without specific prior written permission... THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. THE IMPLIED WARRANTIES OF MERCHANTABILITY
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):3569
    Entropy (8bit):5.083933942684068
    Encrypted:false
    SSDEEP:48:ceOorYJTrYJEfDWQvs432sD32scMEtu33tYTHD2xwKmlKas/PLSR3yhGQSbZnrf:YorYJTrYJEfiQX3f3jp2vTcHnhmJ
    MD5:B63974B094848F05BE23C6114F096BB3
    SHA1:563094788487A2069ED8FDB42026C26AB0299009
    SHA-256:FF3EE8520DADEEE5371261D70ECDD4C169182D9DD2B7F706C94F57B389488007
    SHA-512:FF6E5010C57113089DA92B0AC7F26917A52B8C62D12367EF4D2835B882F0BF12809DA88D214D4796765B87F08BF13D24D2FE6E401F581821A156627D0ABFD7CE
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?>.. . Copyright (c) 2006, Oracle and/or its affiliates. All rights reserved... Redistribution and use in source and binary forms, with or without. modification, are permitted provided that the following conditions. are met:.. - Redistributions of source code must retain the above copyright. notice, this list of conditions and the following disclaimer... - Redistributions in binary form must reproduce the above copyright. notice, this list of conditions and the following disclaimer in the. documentation and/or other materials provided with the distribution... - Neither the name of Oracle nor the names of its. contributors may be used to endorse or promote products derived. from this software without specific prior written permission... THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. THE IMPLIED WARRANTIES OF MERCHANTABILITY
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:ASCII text
    Category:dropped
    Size (bytes):396
    Entropy (8bit):4.688503146207048
    Encrypted:false
    SSDEEP:6:jI2XDj4MzJXk5tNPDzURTKtv4fNbGSYcSH7xAdCqLstVh/DecXlL3XG4jIn:j7XphuttURWtvAoH7igw4hLemRnPIn
    MD5:004A914D3B7831119755C4413237549B
    SHA1:042A7338560126751E683DCC841EA74237BD843E
    SHA-256:8BCF038E1DEE0F567B4E3A8B70B969BEE010FC01CA0632F4272DA204690D12F6
    SHA-512:B02129E989259C40C60399B75299BB8B29B8755006FE737ED735532765594787309E6080EA39654D1A1747D59DE8A3E34B76E815457D8CA6EC35E74B2152FA20
    Malicious:false
    Reputation:low
    Preview:main.dir=${basedir}/../../../management/VerboseGC..src.dir=${main.dir}/src..build.dir=build.classes.dir=${build.dir}/classes.jar=${main.dir}/VerboseGC.jar.javadoc.dir=${build.dir}/javadoc..build.sysclasspath=ignore.# E.g.: cp=lib/x.jar:lib/y.jar.cp=.extra.run.cp=..main.class=VerboseGC..run.cp=${cp}:${classes.dir}:${extra.run.cp}..debug=true.deprecation=false..nbjdk.home=${basedir}/../../../...
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):2045
    Entropy (8bit):5.234644892100995
    Encrypted:false
    SSDEEP:48:ceOorYJTrYJEfDWQvs432sD32scMEtu33tYTHDA5VKasrO:YorYJTrYJEfiQX3f3jp2s5MC
    MD5:9C7EFD30057F328FD7CDBD37E2390755
    SHA1:5C7B94E12A006D73F128FDA3A2258CCDC6F71300
    SHA-256:EE51C8D48C61C740F29BBAD51D4F97FC34C6EB954F9D96B77DB7A1C981256129
    SHA-512:CB12FC98B58EF521824E4439A20136DD58DC0E5C6371A94FBA9063104131143C2D7449F146EF838AF7E8ADE9D95790C669B1C8E677C5AFFB95929DDB509E193D
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?>.. . Copyright (c) 2006, Oracle and/or its affiliates. All rights reserved... Redistribution and use in source and binary forms, with or without. modification, are permitted provided that the following conditions. are met:.. - Redistributions of source code must retain the above copyright. notice, this list of conditions and the following disclaimer... - Redistributions in binary form must reproduce the above copyright. notice, this list of conditions and the following disclaimer in the. documentation and/or other materials provided with the distribution... - Neither the name of Oracle nor the names of its. contributors may be used to endorse or promote products derived. from this software without specific prior written permission... THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. THE IMPLIED WARRANTIES OF MERCHANTABILITY
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):3500
    Entropy (8bit):5.153373385629951
    Encrypted:false
    SSDEEP:48:ceOorYJTrYJEfDWQvs432sD32scMEtu33tYTHDYtxuTJKaZzFKVzgDIE3YUvK5cf:YorYJTrYJEfiQX3f3jp2ZzFaz4bso
    MD5:36EDC024701D631272C6AF8CF4CCEC86
    SHA1:134D7A14404F0B926F3AC7C3C090B7E0CE8D453C
    SHA-256:F482F35F43A620B5CC259EDD9FD21921BBDF96C234BE01DF11F3771AC0101320
    SHA-512:EFCC922301200708F6553D3C6CFE31BCC9B6401DE4465A143BC317B75D376223ABF6334C91FDC19EBD65CE7B886B0BF533E6D763A0174BADE483F0FBB618E821
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?>.. . Copyright (c) 2006, Oracle and/or its affiliates. All rights reserved... Redistribution and use in source and binary forms, with or without. modification, are permitted provided that the following conditions. are met:.. - Redistributions of source code must retain the above copyright. notice, this list of conditions and the following disclaimer... - Redistributions in binary form must reproduce the above copyright. notice, this list of conditions and the following disclaimer in the. documentation and/or other materials provided with the distribution... - Neither the name of Oracle nor the names of its. contributors may be used to endorse or promote products derived. from this software without specific prior written permission... THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. THE IMPLIED WARRANTIES OF MERCHANTABILITY
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):4218
    Entropy (8bit):4.9575689298800985
    Encrypted:false
    SSDEEP:48:ceOorYJTrYJEfDWQvs432sD32scMEtu33tYTHD5wj9fV3ORoZVPp1TED2AZiUZGQ:YorYJTrYJEfiQX3f3jp2FBY0
    MD5:8F8DB67A23AE3EFD024E91710F1A6739
    SHA1:26C3F95E0007310A3F6A35CCE6B61AF71B9F1C8B
    SHA-256:5AB23ACF89B98778B5885B46D500429E6906C4389CD4427D8D5BDE6727BB6BE3
    SHA-512:7E3B2E9EF782B2D12FEEF7DDF78FCDF4500ECA641E03AF66181D03DC81B0CD5B54E5376B245B0460A25FEA1AF70D11CF974FBCE1A5787D3310B50D56099FC2A1
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?>.. . Copyright (c) 2006, Oracle and/or its affiliates. All rights reserved... Redistribution and use in source and binary forms, with or without. modification, are permitted provided that the following conditions. are met:.. - Redistributions of source code must retain the above copyright. notice, this list of conditions and the following disclaimer... - Redistributions in binary form must reproduce the above copyright. notice, this list of conditions and the following disclaimer in the. documentation and/or other materials provided with the distribution... - Neither the name of Oracle nor the names of its. contributors may be used to endorse or promote products derived. from this software without specific prior written permission... THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. THE IMPLIED WARRANTIES OF MERCHANTABILITY
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):7444
    Entropy (8bit):4.234965284120005
    Encrypted:false
    SSDEEP:96:YorYJTrYJEfiQX3f3jp2RsGrJfkD+BbzYDrjh+RyW:YorsTrs+jX3f3d2R3rRBBbzYDrV+Rx
    MD5:327928B14ED861220050B939DB06BC42
    SHA1:BA4E14FAC2CDBB8643E13DC423D6873E94C1A563
    SHA-256:CBD01ADB82A497866AC602867CEA00068A59139267B2ED665F46F514B3BE6D25
    SHA-512:F2A97AB4F86DA94030D4855906D3749A4A71D7B4FB74FDC46DB2E7E23B67EE43A57803BF053CFB55307098B7FD076A8BCA02D3FF1FE1D455E4204C3315B9E365
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?>.. . Copyright (c) 2006, Oracle and/or its affiliates. All rights reserved... Redistribution and use in source and binary forms, with or without. modification, are permitted provided that the following conditions. are met:.. - Redistributions of source code must retain the above copyright. notice, this list of conditions and the following disclaimer... - Redistributions in binary form must reproduce the above copyright. notice, this list of conditions and the following disclaimer in the. documentation and/or other materials provided with the distribution... - Neither the name of Oracle nor the names of its. contributors may be used to endorse or promote products derived. from this software without specific prior written permission... THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. THE IMPLIED WARRANTIES OF MERCHANTABILITY
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):3002
    Entropy (8bit):5.008491069151138
    Encrypted:false
    SSDEEP:48:cU1OorYJTrYJEfDWQvs432sD32scMEtu33tYTHD2I8nwfDGhQKQQ0KHH14kN:boorYJTrYJEfiQX3f3jp2oxSq
    MD5:7371F7508D6208CD9F35C318DEB5EAAE
    SHA1:8DEBEE33AA82CB690837E0B695D0C8CB9AA11053
    SHA-256:AA89E750727FC85C87149F6A1D0D3EE78779C5525440DF11E61BD5531EF13FF8
    SHA-512:85FB9F90DF6753FDFFE85EBDC02C0C43CB628E639096A57FCB203CE18E8B7AA37180AD71FE28F47BDDD9B65A0A47B77608B72F2ADCE96DCF547EA3273354C2E4
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?>.. . Copyright (c) 2006, 2011, Oracle and/or its affiliates. All rights reserved... Redistribution and use in source and binary forms, with or without. modification, are permitted provided that the following conditions. are met:.. - Redistributions of source code must retain the above copyright. notice, this list of conditions and the following disclaimer... - Redistributions in binary form must reproduce the above copyright. notice, this list of conditions and the following disclaimer in the. documentation and/or other materials provided with the distribution... - Neither the name of Oracle nor the names of its. contributors may be used to endorse or promote products derived. from this software without specific prior written permission... THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. THE IMPLIED WARRANTIES OF MERCHANTA
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):3803
    Entropy (8bit):5.065585374355347
    Encrypted:false
    SSDEEP:48:ceOorYJTrYJEfDWQvs432sD32scMEtu33tYTHDlxwKmlKas/PLSR3y12Dr9GQSbt:YorYJTrYJEfiQX3f3jp2oTcHn12DRmJ
    MD5:4579D9EDCD4BDA809FD7C9B080921630
    SHA1:CB714478CEB073429AF0D6471B5A9169636F4E42
    SHA-256:81125B166B6721839160AF70EA46C3CE9310335CBE9838B4C1AD3B12C768F352
    SHA-512:C77272180FC147DE8307423F23E7ADD2226A2457ACA34D840D340A8DD84FF69CF92C0552A442E1680AFBEBD235F8322C1F4AD8CE02BFE90D64F93A7E056D1280
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?>.. . Copyright (c) 2006, Oracle and/or its affiliates. All rights reserved... Redistribution and use in source and binary forms, with or without. modification, are permitted provided that the following conditions. are met:.. - Redistributions of source code must retain the above copyright. notice, this list of conditions and the following disclaimer... - Redistributions in binary form must reproduce the above copyright. notice, this list of conditions and the following disclaimer in the. documentation and/or other materials provided with the distribution... - Neither the name of Oracle nor the names of its. contributors may be used to endorse or promote products derived. from this software without specific prior written permission... THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. THE IMPLIED WARRANTIES OF MERCHANTABILITY
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:ASCII text
    Category:dropped
    Size (bytes):444
    Entropy (8bit):4.673210051740485
    Encrypted:false
    SSDEEP:12:jpRovphuthLKtvAVRH7S/nGQ4jj9demRnb:lRch8lIvW/Q4jjDeEb
    MD5:4C70817773ECFFB899A298F6936F9A69
    SHA1:3848C76751B54716D20887E2C5474E60482032F2
    SHA-256:D3B25DCF80740EC8911121560046A091E23A9035F1C2014BA7410A30F6200B63
    SHA-512:C6161971EEB0C4631F3A8F8C7CCC2B6B31CA2496829B73D09DA1DB093D6C28F80BD140FA301E991F88639CE4DEEA5813C14F66539EF2016695B5F4DBF2CF2E4D
    Malicious:false
    Reputation:low
    Preview:main.dir=${basedir}/../../../scripting/jconsole-plugin..src.dir=${main.dir}/src..build.dir=build.classes.dir=${build.dir}/classes.jar=${main.dir}/jconsole-plugin.jar.javadoc.dir=${build.dir}/javadoc..build.sysclasspath=ignore..nbjdk.home=${basedir}/../../../....# E.g.: cp=lib/x.jar:lib/y.jar.cp=${nbjdk.home}/lib/jconsole.jar.extra.run.cp=..main.class=jconsole-plugin..run.cp=${cp}:${classes.dir}:${extra.run.cp}..debug=true.deprecation=false.
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):2051
    Entropy (8bit):5.236495092868881
    Encrypted:false
    SSDEEP:48:ceOorYJTrYJEfDWQvs432sD32scMEtu33tYTHD5VKasrO:YorYJTrYJEfiQX3f3jp2tMC
    MD5:288E33FD3A8BDFD311A1A3021878E2F8
    SHA1:377C50207538A41B329FB9923A14636BC35AA03F
    SHA-256:E805896682C38302A275A5148A64B0D91618CC5D5E5807374AF3A4FF4D541327
    SHA-512:1625726986838821FEADE632A7DD901986F5CF54D995B01A63A0794E11ED86EEDEC34EA7B1BC80CDCD6CBD2B62530EEFAB6A06F35B1FA01E3D42DAA7092F0426
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?>.. . Copyright (c) 2006, Oracle and/or its affiliates. All rights reserved... Redistribution and use in source and binary forms, with or without. modification, are permitted provided that the following conditions. are met:.. - Redistributions of source code must retain the above copyright. notice, this list of conditions and the following disclaimer... - Redistributions in binary form must reproduce the above copyright. notice, this list of conditions and the following disclaimer in the. documentation and/or other materials provided with the distribution... - Neither the name of Oracle nor the names of its. contributors may be used to endorse or promote products derived. from this software without specific prior written permission... THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. THE IMPLIED WARRANTIES OF MERCHANTABILITY
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):6191
    Entropy (8bit):4.383626704263291
    Encrypted:false
    SSDEEP:96:YorYJTrYJEfiQX3f3jp24dsGrJKkDZzYDrjh+RwrW:YorsTrs+jX3f3d24d3rA6zYDrV+Rwy
    MD5:3B08B76B8CB10CAA284F38CD4BEDBB7F
    SHA1:714662A07F137822F7DE9FC4CBA98E9840A82BF3
    SHA-256:99020A2B2035DBCE37D7D026D5EB1006E0FE1BFADAC9CABD5060D995832140FB
    SHA-512:45C30A767ACA935179DAE91504DF6E99FDA34162AA3BA2872BB57D806F80FB6BC90227EDEA2CEB6E7106DA30C497860D8C609996ABE319B8EB008C763E8ADAF8
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?>.. . Copyright (c) 2006, Oracle and/or its affiliates. All rights reserved... Redistribution and use in source and binary forms, with or without. modification, are permitted provided that the following conditions. are met:.. - Redistributions of source code must retain the above copyright. notice, this list of conditions and the following disclaimer... - Redistributions in binary form must reproduce the above copyright. notice, this list of conditions and the following disclaimer in the. documentation and/or other materials provided with the distribution... - Neither the name of Oracle nor the names of its. contributors may be used to endorse or promote products derived. from this software without specific prior written permission... THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. THE IMPLIED WARRANTIES OF MERCHANTABILITY
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):3512
    Entropy (8bit):5.152882496538987
    Encrypted:false
    SSDEEP:48:ceOorYJTrYJEfDWQvs432sD32scMEtu33tYTHDdOxuTJKaZzFKVzgDIE3YUvK5cf:YorYJTrYJEfiQX3f3jp2lzFaz4bso
    MD5:E72BAD671B6608D9BEDB7535B7A4DCC3
    SHA1:85C4BDDEAFD34B6BDF8F8C4F177979B52F3B8CDF
    SHA-256:439BF5A86E26C06ECDF1984413E96FDD0AA61F75DAC10A0D0EFD3BEA874335CC
    SHA-512:526FCDC2C27E043F1B968CD4FB8ADE6553BE3FB4814B97289134C7B81B1259E0A5CF314A16314F4A482234CE27D18810AAC0A0B13D4CC9302A11C3EE2D0974CC
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?>.. . Copyright (c) 2006, Oracle and/or its affiliates. All rights reserved... Redistribution and use in source and binary forms, with or without. modification, are permitted provided that the following conditions. are met:.. - Redistributions of source code must retain the above copyright. notice, this list of conditions and the following disclaimer... - Redistributions in binary form must reproduce the above copyright. notice, this list of conditions and the following disclaimer in the. documentation and/or other materials provided with the distribution... - Neither the name of Oracle nor the names of its. contributors may be used to endorse or promote products derived. from this software without specific prior written permission... THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. THE IMPLIED WARRANTIES OF MERCHANTABILITY
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):4302
    Entropy (8bit):4.9650321309649135
    Encrypted:false
    SSDEEP:48:ceOorYJTrYJEfDWQvs432sD32scMEtu33tYTHD5wj9fV3EoORoZVPp1TED2AZiU7:YorYJTrYJEfiQX3f3jp2FHY0
    MD5:1EA6982A122397F3EBD2AAC2604776BF
    SHA1:BC359F03AAE9E92F176000310AA89C2951EB9DD2
    SHA-256:6424EC56B4AC871D6ED374432072DAB6C41401BC9CCB45B71E7264E853CF0F51
    SHA-512:4360C72B3315FCB20EFC2BFAEDDD697DFFE274727526E12D82A288314550E174BED1F3DC20384039BD1562C94CD8ED62F935043454F355AA44933B78C5FD3F26
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?>.. . Copyright (c) 2006, Oracle and/or its affiliates. All rights reserved... Redistribution and use in source and binary forms, with or without. modification, are permitted provided that the following conditions. are met:.. - Redistributions of source code must retain the above copyright. notice, this list of conditions and the following disclaimer... - Redistributions in binary form must reproduce the above copyright. notice, this list of conditions and the following disclaimer in the. documentation and/or other materials provided with the distribution... - Neither the name of Oracle nor the names of its. contributors may be used to endorse or promote products derived. from this software without specific prior written permission... THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. THE IMPLIED WARRANTIES OF MERCHANTABILITY
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Zip archive data, at least v1.0 to extract, compression method=store
    Category:dropped
    Size (bytes):53857
    Entropy (8bit):7.965974945633614
    Encrypted:false
    SSDEEP:768:vF/SFy7vso/n0llQ1MBIQbq1qE7dvBKhhWGAxV2e/JSJP4EC1YfRcWwrPPxpHHi3:v9SHV/dqddgzWGAxRQaEWDW+fHAqwf
    MD5:252969676F8006CB09116356ABA8D542
    SHA1:26A16698D216F205A71A8099462606D61E0CA376
    SHA-256:5D1A3E7933E8FC3BAA1C835AA56288609E8870F2947C63AF00228618837E4578
    SHA-512:B504BEB13E1582893111A7C2E9B51B8F28D94CFC633A7EF0034C55CE84238F88C6792CCDBBC024D188CA9ED562DF129BDE52A65ECF7C916560FAD35A209D205D
    Malicious:false
    Reputation:low
    Preview:PK...........V................com/UT...%..d%..dux.............PK...........V................com/sun/UT...%..d%..dux.............PK...........V................com/sun/nio/UT...%..d%..dux.............PK...........V................com/sun/nio/zipfs/UT...%..d%..dux.............PK...........V.X..[...r...,...com/sun/nio/zipfs/JarFileSystemProvider.javaUT...%..d%..dux..............WQo.F.~...R.HMq..6.+-...dQ%...7.\J.R$.K..5...fI..........f.of.....YY=h...4J...?........u..."...Tm(.2....fBn..=gHK#..L'.c.@...Z.6.*....HR......[U....R.C.........e_.*SI....ZR%.^.L...J.P....$p.W...H..2.....>.B#z."<Cev.+)SX7.FJu.x.9.-.x...E!*.Z%..2...q.|......I.....D..=j.. .A..........I..E.....(a.i..k.....v..O...J*{.m.x/9.N\E..l+....@.-\...>.d.!..d.bU.d...%..A.)....0..[RL...,.Ned*...pV..4..hufL/.h!B......<..:.?..7...lz4..7..\D..s/..]....q..|,...D8.{.._.....$..K.<8..U$..!..-7s..t....#Z.+..,.6...I./...f....b)....BD+vw..... ......i...~...7..l.+o>!....}.V...w.|......d`gI?.s...K...t.".f....4...
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:ASCII text
    Category:dropped
    Size (bytes):835
    Entropy (8bit):4.844546571178631
    Encrypted:false
    SSDEEP:12:rcb4eJpfeJb3J+xvZ6tvGgmpTnlXYFwmWSBOn2IQ0EjCV+:rSJMJb3Ig8gmpTnl4wGOdV+
    MD5:539D243FCC2DAA789F6322C73A437C19
    SHA1:BB696C0AE647BD304D4A4E3B82DF52B888183AF3
    SHA-256:1CE694DC7FE37F8626F38737AEE1E1D021486CC74BC8A625F98534F8BEE09783
    SHA-512:55876FD07805B64B3A93A529C899D38D81CEC2E714EA69DBF15BA7B0BE459C6F2771EE82FD74C9EB92F25DD742FBA0A19FDF7268473500707A9E11569D282CB9
    Malicious:false
    Reputation:low
    Preview:ZipFileSystem is a file system provider that treats the contents of a zip or.JAR file as a java.nio.file.FileSystem...The factory methods defined by the java.nio.file.FileSystems class can be.used to create a FileSystem, eg:.. // use file type detection. Path jarfile = Paths.get("foo.jar");. FileSystem fs = FileSystems.newFileSystem(jarfile, null);..-or.. // locate file system by the legacy JAR URL syntax. Map<String,?> env = Collections.emptyMap();. URI uri = URI.create("jar:file:/mydir/foo.jar");. FileSystem fs = FileSystems.newFileSystem(uri, env);..Once a FileSystem is created then classes in the java.nio.file package.can be used to access files in the zip/JAR file, eg:.. Path mf = fs.getPath("/META-INF/MANIFEST.MF");. InputStream in = mf.newInputStream();..See Demo.java for more interesting usages....
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java source, ASCII text
    Category:dropped
    Size (bytes):27002
    Entropy (8bit):4.226582970094736
    Encrypted:false
    SSDEEP:192:A6rsdrsQXJ3r37e6E3i1RHThClkmg1aOcX4JSMDr99qK2PD2Y5gPJd+B1SRyhmaD:JrsdrsU5D7u3cmMbeDAHodHr94FDG
    MD5:0D2CF47786912D2F4D90E6D5C9BC1DB3
    SHA1:F1FB2B2DBF204BF2C5BABEB81E840A1EBD023E6C
    SHA-256:491954EA46550046077161A08162DDCA6CEF6A16746D561355DABA803C38843C
    SHA-512:9696E7A7DAA0D19AE2220BE02DE782FF6CD67BD19123297F7C48476EF97874362C5197BFB42AED043A661061FA35634E72733172C158870B8CB9C3094063CA18
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2010 Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABILITY AN
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java archive data (JAR)
    Category:dropped
    Size (bytes):72044
    Entropy (8bit):7.950601855071511
    Encrypted:false
    SSDEEP:1536:6X99o1vQrYrzR0s2JgLzW81JvkHTYaFU2jLxE4UsMMsp/Th:6t9o1v0YrD2KbHajBELh9h
    MD5:3EBA9B3DDA689517513838FD8B0418A2
    SHA1:28E9B4D0F4F38505CF519B44D2B9B2AF91F5B696
    SHA-256:74AE7E9D6732D3AD6262BD8256ABBF06666B902051E5167258FABBD2B649982E
    SHA-512:1E2454ABA7B546B02B1F6E5BED0C852AF9183F7A94BE294AF1058709E25C7AF68DD09DCDBFE05BC0255CA66A19AA58B7DE7006B2E035DE25B9C457DFE86198D1
    Malicious:false
    Reputation:low
    Preview:PK..........V................META-INF/......PK..............PK..........V................META-INF/MANIFEST.MFm.=..0...=..p..-...nZ.*.........R.X._..~..=..^....B.%.i.9..D...,q.p.F......au.-..{.._.....d7.R).-).h...w>..Ge...[.o.o.~.6...-L..>.o.....'...f.g.I.....X9.%.x..{./(E....`.. ..gPK........G...PK...........V............-...com/sun/nio/zipfs/JarFileSystemProvider.class.U]S.U.~NH.a.@..B.\.!.$.U[.X..J..H..G...$,Mv.....z....9...........Z.d..a.1.y...<..s.y...~....x&c......q..B.`B.......'b.4...'e.1%......i!f../aV.L......B,.XD..KX.......V..^..@....`SD..`[.C._0.'..p.2.EF...SV.3t-.&OW.Yn....i....vx..=..]}O.J.Y.2.m..q.Tmc.Z.....H.arW[[I.7.L...F.k.E&...../.z.J...,U. QD...%....v...".+s.-f.....e..3....."..bvu[..b..Ag.<I7U*.^J..j....~.W\.2....i.j..1C7..:..U.QM.UG.d.c`4.8.Pf..MA.E.;0...1.r..bX..$l>h..%..,h.*..."^=m.90]}.T.}'.&...B;m.-.9.\T....x.p.laD.....#..U.r..P..o...(.a.....`.E.....*1..4-......fT......H.*kN..1....r.Z"7.J+d....B5.'U...e.).!...rt...^.p3..k.8.j.:.
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java archive data (JAR)
    Category:dropped
    Size (bytes):31270
    Entropy (8bit):7.903762185774351
    Encrypted:false
    SSDEEP:768:e8RCcaUuOZM70Td4LmSWkYwMiwCSTGh7mHL6p/TqV29oWDNAJIKqbC9Y:e8CcazOZMAZOmS/YwQm7mrOrSkNAJIK2
    MD5:B44C69D35B19D6D47A282CCD453DF759
    SHA1:5BE2FDCA16FFC28B75C8F46C04455B7E483117E3
    SHA-256:D31E1320E3904A1AFC74985DFD181D10494EBE49C3783412600EDBA972ADBFA6
    SHA-512:500CC9C7F42259FD6ED6AE88770ECCAF8D896BC58B39A818586F70DB05BF40CC915A1E9257BA9DCCB8333FA00117A74CBD351F01EAFE71CAA8180E0ABAC4CFFF
    Malicious:false
    Reputation:low
    Preview:PK..........V................META-INF/......PK..............PK..........V................META-INF/MANIFEST.MFm.=..0...=..p..-...nZ.*.........R.X._..~..=..^....B.%.i.9..D...,q.p.F......au.-..{.._.....d7.R).-).h...w>..Ge...[.o.o.~.6...-L..>.o.....'...f.g.I.....X9.%.x..{./(E....`.. ..gPK........G...PK..........V............;...com/sun/demo/scripting/jconsole/EditableAtEndDocument.classmR.R.A.=.....@d...>.d..g|.(/.h@.....IW.Mf.IGY.t....*..J...........@A)N..}o.s.9.?~}....F.0q4..8..|.^!.....!....1p..I...:.2.....~..+M......0h(7P.n.)S7.~.y...}.d...LI }..|5*./.33.V.@{...L..(...b.....D.....g..3......GG...x...r..3.M%.....%O.P....../...J:..S..|.}.7%;..!.t<m.....]B.t...G .W.nDq.l.lF...k...*..cj*.L.^...5..Lt.2q.gL..^...e.".8.M......&.`..lc:.V..jf..)...F3p*d.4..g.%.<.......l...~.u C1.2......"...v.p.]...w>.1X..^..o.....L....!.6.-.....~.1.E..]/W.5e.B,...q.8IKAY..:H"..^A.......*Z....B{....p..............O....b*.L[I+...^+....^+..T.`4..t.....2*.0.cV..M|..wW
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Zip archive data, at least v1.0 to extract, compression method=store
    Category:dropped
    Size (bytes):28672
    Entropy (8bit):7.889525421105525
    Encrypted:false
    SSDEEP:768:PBgKBg2og+DPbnMiwCSTGhrmelL6CN/hqm9o1D7worc:PuKKVZDLQmrm+J54x7wV
    MD5:C8AAE8019004AF835AFF7546ECC709C2
    SHA1:D5F66D958BDC0609C2E1C5383CB061F6D7BED64C
    SHA-256:2A5D136C4235F9C1BCFF8C43E03AF506336238AB04BB2F1C3432BFCD364ADAF8
    SHA-512:F50F8E2DEB989E3BE07BFCA20607B93E3E8A473E332E88AFA3087F604EFDDC1F2709565B3D1045DB98CE520DFB8585A1D22DA2172D323532C874BFEDC7CC7635
    Malicious:false
    Reputation:low
    Preview:PK...........V................com/UT...%..d%..dux.............PK...........V................com/sun/UT...%..d%..dux.............PK...........V................com/sun/demo/UT...%..d%..dux.............PK...........V................com/sun/demo/scripting/UT...%..d%..dux.............PK...........V............ ...com/sun/demo/scripting/jconsole/UT...%..d%..dux.............PK...........VVV.UV.......:...com/sun/demo/scripting/jconsole/EditableAtEndDocument.javaUT...%..d%..dux..............V.r..}.W..IJ.9n..s.tJK...YTI..a...P...r<m..gA.<..{......8{...'....&.....a>........i@..y.HV.ImH;Kr...N.1.eI~.%..2;U....*.uF.7N...Pc..l..C...y.Um66.G..,..n..l.B.t..# i.m..h.TA[S.t.......p.~....uUh.d...m..OG....z..U.+..D7.$'....}..N.......U..m.. ..s....!k^J.Qf._. .4=..\4`./........f.*'......0.A............9,q....1..(&..WU._.N`.z......"...+.#TQ....U<2...V".c.....f..V.[..#.D7ed.*...^..gx..v.=."..RJ..6L..y..7.TL.....&......2..gS....x;..|..x.*L.*J_..p~G..E"....,...$.<.D.P4...h~..0h.g4....
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):3212
    Entropy (8bit):5.246795006915177
    Encrypted:false
    SSDEEP:48:ceOorYJTrYJEfDWQvs432sD32scMEtu33tYTH0AxeIIC3Qwfa+zEjEMk0rfPd9XL:YorYJTrYJEfiQX3f3jp2bNDouGrXRC6
    MD5:879AFF2438464F951813EEC981ACF8C7
    SHA1:50F6F48E4731A6C6F232F1E4A33219FE4501F6D2
    SHA-256:D823D07F983F2AE1FA0332D1C5D248B337F148F0269ECA5A7A83C4E67BDFBA62
    SHA-512:F63A8348BD939BBBC87DDDFF0DE35BB14871DE8687D160876FA0186CAD27BBA56001770AEC16AD7842A6A368BED4265AE76C9ADB379AE42E0A84CD5F116DDBA7
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?>.. . Copyright (c) 2006, Oracle and/or its affiliates. All rights reserved... Redistribution and use in source and binary forms, with or without. modification, are permitted provided that the following conditions. are met:.. - Redistributions of source code must retain the above copyright. notice, this list of conditions and the following disclaimer... - Redistributions in binary form must reproduce the above copyright. notice, this list of conditions and the following disclaimer in the. documentation and/or other materials provided with the distribution... - Neither the name of Oracle nor the names of its. contributors may be used to endorse or promote products derived. from this software without specific prior written permission... THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. THE IMPLIED WARRANTIES OF MERCHANTABILITY
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:ASCII text
    Category:dropped
    Size (bytes):2544
    Entropy (8bit):4.57084784556823
    Encrypted:false
    SSDEEP:48:BVm7Kj9BinIH7KeJSM3eOiHEauHSFDw+kwFLhMFZpDvOiGVEpZ4zLdZOREEpe54:BH9cIp/fiHW3+kwIF7DGiGVEuzLPcEE1
    MD5:72B91C24934510EC894E73C5B7029825
    SHA1:BD01CFA5FC6B5C1F0488874D0FAEA2AF882D68BB
    SHA-256:841AFBF96C296E9C7AFCB2FAE5C5AFAD13ADD6FEFC970A6A5EB83635FC9A214E
    SHA-512:68BFFFF2E6BEDFB5358178AE621CFF378A13F6F5A87E09596E1A899889ED846B31041351D45B17BC651CA9A76E589FBE32AAC91D4848A2F440F89020D6D9D2DD
    Malicious:false
    Reputation:low
    Preview:What is this demo about?..This is "script shell" plugin for jconsole - the monitoring and management .client tool shipped with JRE. This plugin adds "Script Shell" tab to jconsole..This serves as a demo for jconsole plugin API (com.sun.tools.jconsole) as well .as a demo for scripting API (javax.script) for the Java platform...Script console is an interactive read-eval-print interface that can be used.used to execute advanced monitoring and management queries. By default,.JavaScript is used as the scripting language. The scripting language can be .changed using the system property com.sun.demo.jconsole.console.language. To .use other scripting languages, you need to specify the corresponding engine.jar file in pluginpath along with this plugin's jar file...The following 3 global variables are exposed to the script engine:.. window javax.swing.JPanel. engine javax.script.ScriptEngine. plugin com.sun.tools.jconsole.JConsolePlugin..If you use JavaScript, there are
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:C source, ASCII text
    Category:dropped
    Size (bytes):4771
    Entropy (8bit):4.900342754473353
    Encrypted:false
    SSDEEP:96:YxMHNr1JAysNEVOF3E2wGJIgTpnT6I5FzVVvBVPjsB7w1:YxMHNrMNEkfwX6lL5VLsB7w1
    MD5:8C9749A3C6C08455FF6DF0B88B4F7761
    SHA1:D0A7C32C550E91100D88E6CE3E6C735B6BB5E32E
    SHA-256:6EE3E52D24BDB4F4D0312DFBAB3D47BD524CBDAC5540A4D790CAC0620C59B3C8
    SHA-512:0DB4A26E6AAF7BDDE0F1C9841B20D0355FEF9D45C920830FD6F54FFB7179CE00F83F794EF03B77D9E8A9486ABA93B57A8834691EDCDCB3B31335DE3608278ECC
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2010, Oracle and/or its affiliates. All rights reserved.. * DO NOT ALTER OR REMOVE COPYRIGHT NOTICES OR THIS FILE HEADER.. *. * This code is free software; you can redistribute it and/or modify it. * under the terms of the GNU General Public License version 2 only, as. * published by the Free Software Foundation. Oracle designates this. * particular file as subject to the "Classpath" exception as provided. * by Oracle in the LICENSE file that accompanied this code.. *. * This code is distributed in the hope that it will be useful, but WITHOUT. * ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or. * FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License. * version 2 for more details (a copy is included in the LICENSE file that. * accompanied this code).. *. * You should have received a copy of the GNU General Public License version. * 2 along with this work; if not, write to the Free Software Foundation,. * Inc., 51 Franklin St, Fif
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:C++ source, ASCII text
    Category:dropped
    Size (bytes):74698
    Entropy (8bit):4.745532817535851
    Encrypted:false
    SSDEEP:1536:4p294hWixXRL7pLv0PdV7PSiFfXsvb6JFpJrRuXXyl18CycfWYf8MtqIdACWDYT/:E294hWqhHNs116YFpJrRuXXyl18CyU3f
    MD5:7756575AF5344F8CAA05083993B01FBD
    SHA1:ED3EF6100C3634034A57B2B78D68F57D7A029B85
    SHA-256:ED99792DF48670072B78028FAF704A8DCB6868FE140CCC7ECED9B01DFA62FEF4
    SHA-512:9638D80834D73EE0FBC81FEA361A300B973AD958BC9F7DEB090FEE940DBE361AB77172E62830AB2D0554A6480C76EBCFF3CE0DB5D72726B9ED5DA129FDE719C8
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 1996, 2013, Oracle and/or its affiliates. All rights reserved.. * DO NOT ALTER OR REMOVE COPYRIGHT NOTICES OR THIS FILE HEADER.. *. * This code is free software; you can redistribute it and/or modify it. * under the terms of the GNU General Public License version 2 only, as. * published by the Free Software Foundation. Oracle designates this. * particular file as subject to the "Classpath" exception as provided. * by Oracle in the LICENSE file that accompanied this code.. *. * This code is distributed in the hope that it will be useful, but WITHOUT. * ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or. * FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License. * version 2 for more details (a copy is included in the LICENSE file that. * accompanied this code).. *. * You should have received a copy of the GNU General Public License version. * 2 along with this work; if not, write to the Free Software Foundation,. * Inc., 51 Franklin S
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:C source, ASCII text
    Category:dropped
    Size (bytes):79357
    Entropy (8bit):5.102390395017942
    Encrypted:false
    SSDEEP:1536:gpGtzpUsIBsiwKGd3PXwjullnXofSK1rrzwAlbnpyv4m76X0uvu/zPR:8sIBNwKGd3PXwj8lnXofSK1rrzwAlbna
    MD5:D5A4D33D4B7A37D1AEA1F230ADEB060E
    SHA1:82DAF49C44A6342105F131F8EF542FBC3BAA23EC
    SHA-256:61D9D3FAE26B19DC606A667C97A9E73461384EBE9774E782F09BC61CAB06A95D
    SHA-512:E294FDF5E7CB833AE105E8428711697A64BD9A9096D494DD1A4A57F056A65F9941FF1ACC95B6E0C1272975FB5E05FF9CDE648EE383155008BF9CC7223D4F22A4
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2003, 2011, Oracle and/or its affiliates. All rights reserved.. * DO NOT ALTER OR REMOVE COPYRIGHT NOTICES OR THIS FILE HEADER.. *. * This code is free software; you can redistribute it and/or modify it. * under the terms of the GNU General Public License version 2 only, as. * published by the Free Software Foundation. Oracle designates this. * particular file as subject to the "Classpath" exception as provided. * by Oracle in the LICENSE file that accompanied this code.. *. * This code is distributed in the hope that it will be useful, but WITHOUT. * ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or. * FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License. * version 2 for more details (a copy is included in the LICENSE file that. * accompanied this code).. *. * You should have received a copy of the GNU General Public License version. * 2 along with this work; if not, write to the Free Software Foundation,. * Inc., 51 Franklin S
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:C source, ASCII text
    Category:dropped
    Size (bytes):21125
    Entropy (8bit):3.670459143105224
    Encrypted:false
    SSDEEP:384:oyHNr7QWnTNKzmC1UetDA+ln11+uNn/QUsgspEWCoUqMJg0VNQkCkqRgr75+d:3HF8W4mC1UetDA+9vNnUGWIY
    MD5:3C402E692B2E1A2691AE14403891B52F
    SHA1:B96F4C7E6592E112A48A45761BF6D72B99BF4146
    SHA-256:DAA3C90D62EDEF8827A210B2F61304083AC9625EE23F077174303C78FA733674
    SHA-512:E66B95DC02F175101F4F54178AD445E8C3F3689B20F657425AE24CA5D4360B295A53D4DAD6F6FBE7C3C63BBF2CA307FCB1FE19ECB3DA5C00A34245E32ED112B6
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2004, 2012, Oracle and/or its affiliates. All rights reserved.. * DO NOT ALTER OR REMOVE COPYRIGHT NOTICES OR THIS FILE HEADER.. *. * This code is free software; you can redistribute it and/or modify it. * under the terms of the GNU General Public License version 2 only, as. * published by the Free Software Foundation. Oracle designates this. * particular file as subject to the "Classpath" exception as provided. * by Oracle in the LICENSE file that accompanied this code.. *. * This code is distributed in the hope that it will be useful, but WITHOUT. * ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or. * FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License. * version 2 for more details (a copy is included in the LICENSE file that. * accompanied this code).. *. * You should have received a copy of the GNU General Public License version. * 2 along with this work; if not, write to the Free Software Foundation,. * Inc., 51 Franklin S
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:C source, ASCII text
    Category:dropped
    Size (bytes):9687
    Entropy (8bit):4.941267729135147
    Encrypted:false
    SSDEEP:192:9MHNrpx01hC+EUx/G9sqBLn8hzfwwoQCw7fOmma2UuyJycxsMr5bw4ipr:qHNrpx01hCjQ/GxB+fwXJSr58Tpr
    MD5:D3B60D06C11B9B3009904EB90DDFB89F
    SHA1:9EF3996AF3E38E24E56BBA2AA7A5033B4468A1A5
    SHA-256:48C4DCD5B555F866624C32F34EB8348F2F1AC4D49550252483003106FDFB947B
    SHA-512:9757A5928FA8C3CC15C6793313B601B1AD1F4E77E863905DB660A1B324EB5A3A497F6150083F1AE28F1B639A3F0E05AB4FBF8C763BAECF92D56A20F2A7119DD9
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 1999, 2013, Oracle and/or its affiliates. All rights reserved.. * DO NOT ALTER OR REMOVE COPYRIGHT NOTICES OR THIS FILE HEADER.. *. * This code is free software; you can redistribute it and/or modify it. * under the terms of the GNU General Public License version 2 only, as. * published by the Free Software Foundation. Oracle designates this. * particular file as subject to the "Classpath" exception as provided. * by Oracle in the LICENSE file that accompanied this code.. *. * This code is distributed in the hope that it will be useful, but WITHOUT. * ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or. * FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License. * version 2 for more details (a copy is included in the LICENSE file that. * accompanied this code).. *. * You should have received a copy of the GNU General Public License version. * 2 along with this work; if not, write to the Free Software Foundation,. * Inc., 51 Franklin S
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:C source, ASCII text
    Category:dropped
    Size (bytes):7404
    Entropy (8bit):4.981848469737541
    Encrypted:false
    SSDEEP:192:1MHNr4HOIniDEOqtUk5yx5c29T/YOsH5snppf:CHNr6OeOqy7R
    MD5:16A0DF8EE3EB7BCF59904665551D96DD
    SHA1:CF406A8892A682BC3793029062C950CCEFC402A4
    SHA-256:43C7B6962D7A1DE8EABD0FDCD92B27190E1DBA4A983C7EBF3F22A5AF4DDC6F3D
    SHA-512:976C3E9228FDC07B50917EE19108E3F0645C3ABA646DBAFCC0723ED1DF4ACCA0E60D1A84A8BECD2E2E0D6FBF9B9351C6727D5E8E3A7C9EA1B3820A6E1B52AF51
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2003, 2016, Oracle and/or its affiliates. All rights reserved.. * DO NOT ALTER OR REMOVE COPYRIGHT NOTICES OR THIS FILE HEADER.. *. * This code is free software; you can redistribute it and/or modify it. * under the terms of the GNU General Public License version 2 only, as. * published by the Free Software Foundation. Oracle designates this. * particular file as subject to the "Classpath" exception as provided. * by Oracle in the LICENSE file that accompanied this code.. *. * This code is distributed in the hope that it will be useful, but WITHOUT. * ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or. * FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License. * version 2 for more details (a copy is included in the LICENSE file that. * accompanied this code).. *. * You should have received a copy of the GNU General Public License version. * 2 along with this work; if not, write to the Free Software Foundation,. * Inc., 51 Franklin S
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:C source, ASCII text
    Category:dropped
    Size (bytes):35103
    Entropy (8bit):4.746440556028395
    Encrypted:false
    SSDEEP:768:+HFuSCU+zjdh/Me++algpKeDviGq3pHkPwki0qr:PSCU+zjdh/Me++algpKeLiGq3pHkwr0I
    MD5:79A987C4728DDCFF84626FB3917A4537
    SHA1:34DE4EC3A638AF904B0581E355DFA86BD9CD39A5
    SHA-256:A01925CA281CF5D9EF6ED45F1C4A826D066E04D74BF64475ED8895FDDFB41AA4
    SHA-512:1B4054C5E33AFAE33E1DC817A72CEBACAE18D50C48F7EF03B7E3E66830245EDAFA3A592EB4DE6EE92633BE648E22D3EA6DBD817A5D2C5B9DEFD3A26610DE73EF
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2005, 2010, Oracle and/or its affiliates. All rights reserved.. * DO NOT ALTER OR REMOVE COPYRIGHT NOTICES OR THIS FILE HEADER.. *. * This code is free software; you can redistribute it and/or modify it. * under the terms of the GNU General Public License version 2 only, as. * published by the Free Software Foundation. Oracle designates this. * particular file as subject to the "Classpath" exception as provided. * by Oracle in the LICENSE file that accompanied this code.. *. * This code is distributed in the hope that it will be useful, but WITHOUT. * ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or. * FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License. * version 2 for more details (a copy is included in the LICENSE file that. * accompanied this code).. *. * You should have received a copy of the GNU General Public License version. * 2 along with this work; if not, write to the Free Software Foundation,. * Inc., 51 Franklin S
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:C source, ASCII text
    Category:dropped
    Size (bytes):77582
    Entropy (8bit):4.855766111010542
    Encrypted:false
    SSDEEP:1536:neW1RQYx3Fzv/Q+QRNYLxTC7QL0t37CXqqBO37/eqqBS:Lx3FjQF37937X
    MD5:8F62128E9699C4105AEEC9C7E1D3E4BB
    SHA1:A6B2A8E321771F18CB5BF72F24E97FDA12809B17
    SHA-256:06162DA96282AF5E707B9A63BACF2BC933DADDE7E92FF5C4F131F5661F1F7E06
    SHA-512:3593FE32E57BCB3DE5C9C42C25618A6213594E8595A1E150D34154873935EFEE9EFDC3DADA3A11F4EC4B72099E1DCFA935EE12019A4C4B7D31F5F7B56EEBBDFF
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2005, 2014, Oracle and/or its affiliates. All rights reserved.. * DO NOT ALTER OR REMOVE COPYRIGHT NOTICES OR THIS FILE HEADER.. *. * This code is free software; you can redistribute it and/or modify it. * under the terms of the GNU General Public License version 2 only, as. * published by the Free Software Foundation. Oracle designates this. * particular file as subject to the "Classpath" exception as provided. * by Oracle in the LICENSE file that accompanied this code.. *. * This code is distributed in the hope that it will be useful, but WITHOUT. * ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or. * FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License. * version 2 for more details (a copy is included in the LICENSE file that. * accompanied this code).. *. * You should have received a copy of the GNU General Public License version. * 2 along with this work; if not, write to the Free Software Foundation,. * Inc., 51 Franklin S
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:C source, ASCII text
    Category:dropped
    Size (bytes):5572
    Entropy (8bit):4.797617958740424
    Encrypted:false
    SSDEEP:96:vxMHNr1Jixu21272t2R2d232Y2J2h2iH2N2j2SH2STS2nL2Z2m2o2L2d2YE2n2Yy:vxMHNrPKwn
    MD5:0CFA4C0AF79342F29B3151A36058380B
    SHA1:60E56E9015557E2492866A8E256FFE30203527C8
    SHA-256:032E93DE306521EB43CABD75C21C68CE03BD0CB8505EE3E70C0732A3249A530B
    SHA-512:39DF0DFCEADDBA0746BED8C5D5F93F4CE2598062291ECA9A7D99FC60F6365BCA5DF6B7E381BA2C52030184535E66DDA4AD2E5098D67C59896089A0C9F8C6D6FB
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2005, 2010, Oracle and/or its affiliates. All rights reserved.. * DO NOT ALTER OR REMOVE COPYRIGHT NOTICES OR THIS FILE HEADER.. *. * This code is free software; you can redistribute it and/or modify it. * under the terms of the GNU General Public License version 2 only, as. * published by the Free Software Foundation. Oracle designates this. * particular file as subject to the "Classpath" exception as provided. * by Oracle in the LICENSE file that accompanied this code.. *. * This code is distributed in the hope that it will be useful, but WITHOUT. * ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or. * FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License. * version 2 for more details (a copy is included in the LICENSE file that. * accompanied this code).. *. * You should have received a copy of the GNU General Public License version. * 2 along with this work; if not, write to the Free Software Foundation,. * Inc., 51 Franklin S
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:C source, ASCII text
    Category:dropped
    Size (bytes):45857
    Entropy (8bit):4.729451898633349
    Encrypted:false
    SSDEEP:768:+HFy5P/2+U8DgiCru9pPareeHkPkjckiuqbJ99:FP/2+UYUu9FareeHkkjcruqbJ99
    MD5:737C0E25104257E7631C71DD3079CDBF
    SHA1:68458224CC00A08FD873C59A058ED71DB120A717
    SHA-256:21061C5F4F6C6BDACE38FE081584C0CCF0D735DC8F490E4659C714AF3BBE41FA
    SHA-512:D038181694AB86E2A8E4A1692AE06D3B19849988712F0795914215AE07341DDD74E454697DC0CAC66EFCAB85B3E318C1C7CF4A380639DEEFEEC5D65B42C11FC3
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2005, 2010, Oracle and/or its affiliates. All rights reserved.. * DO NOT ALTER OR REMOVE COPYRIGHT NOTICES OR THIS FILE HEADER.. *. * This code is free software; you can redistribute it and/or modify it. * under the terms of the GNU General Public License version 2 only, as. * published by the Free Software Foundation. Oracle designates this. * particular file as subject to the "Classpath" exception as provided. * by Oracle in the LICENSE file that accompanied this code.. *. * This code is distributed in the hope that it will be useful, but WITHOUT. * ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or. * FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License. * version 2 for more details (a copy is included in the LICENSE file that. * accompanied this code).. *. * You should have received a copy of the GNU General Public License version. * 2 along with this work; if not, write to the Free Software Foundation,. * Inc., 51 Franklin S
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:C source, ASCII text
    Category:dropped
    Size (bytes):1895
    Entropy (8bit):5.090380208148997
    Encrypted:false
    SSDEEP:48:z5Vw7kynPHNrF4UYPGWvXJfG7leDLZ/9w/F57:fMHNr1JEA6LZyN57
    MD5:A4415825D870A1773AEFA98181793A62
    SHA1:EB2CCF36D4B959B37A8ADA7494CA787FE97AE54C
    SHA-256:9C0F6287252019B77A1BAC18B92F28153AD46709423FE2CC9E1FA5D16BCA38E3
    SHA-512:DEB14A88B5264E3B2C0F4CB4A5DA3AD36AF1BD9D6ADA9C96A4F0E163B7D66E3B95AFE4450855BF68E4C26CF7A5D5B4BE8F3CD2033C131F189F03713BC2B1834D
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 1999, Oracle and/or its affiliates. All rights reserved.. * DO NOT ALTER OR REMOVE COPYRIGHT NOTICES OR THIS FILE HEADER.. *. * This code is free software; you can redistribute it and/or modify it. * under the terms of the GNU General Public License version 2 only, as. * published by the Free Software Foundation. Oracle designates this. * particular file as subject to the "Classpath" exception as provided. * by Oracle in the LICENSE file that accompanied this code.. *. * This code is distributed in the hope that it will be useful, but WITHOUT. * ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or. * FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License. * version 2 for more details (a copy is included in the LICENSE file that. * accompanied this code).. *. * You should have received a copy of the GNU General Public License version. * 2 along with this work; if not, write to the Free Software Foundation,. * Inc., 51 Franklin St, Fif
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:C source, ASCII text
    Category:dropped
    Size (bytes):1482
    Entropy (8bit):5.149202793516522
    Encrypted:false
    SSDEEP:24:mkDZ/2SjJ5VbEQCloJlynxOkHkbV6rF3TbVKUYPNHonmSXWNN00uS+tX2:p5Vw7kynPHNrF4UYPGWqfm
    MD5:1EA1808175BA5B9740CB94CDE3A9F925
    SHA1:AE2FB5BDA37A5F068BD19970DCF82C662F080EE3
    SHA-256:5479FB385EA1E11619F5C0CDFD9CCB3EA3A3FEA0F5BC6176FB3CE62BE29D759B
    SHA-512:F37EA148F732E2757AA61A293194EC958CA1ABDF46CDF795BA9882C93EEC24D0B28E712C5514EABD33B981BAFEE5045975208B3165D05907916DADB6F051E859
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 1996, 1998, Oracle and/or its affiliates. All rights reserved.. * DO NOT ALTER OR REMOVE COPYRIGHT NOTICES OR THIS FILE HEADER.. *. * This code is free software; you can redistribute it and/or modify it. * under the terms of the GNU General Public License version 2 only, as. * published by the Free Software Foundation. Oracle designates this. * particular file as subject to the "Classpath" exception as provided. * by Oracle in the LICENSE file that accompanied this code.. *. * This code is distributed in the hope that it will be useful, but WITHOUT. * ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or. * FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License. * version 2 for more details (a copy is included in the LICENSE file that. * accompanied this code).. *. * You should have received a copy of the GNU General Public License version. * 2 along with this work; if not, write to the Free Software Foundation,. * Inc., 51 Franklin S
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:ASCII text
    Category:dropped
    Size (bytes):46
    Entropy (8bit):4.197049999347145
    Encrypted:false
    SSDEEP:3:c3AXFshzhRSkU:c9hzhgkU
    MD5:0F1123976B959AC5E8B89EB8C245C4BD
    SHA1:F90331DF1E5BADEADC501D8DD70714C62A920204
    SHA-256:963095CF8DB76FB8071FD19A3110718A42F2AB42B27A3ADFD9EC58981C3E88D2
    SHA-512:E9136FDF42A4958138732318DF0B4BA363655D97F8449703A3B3A40DDB40EEFF56363267D07939889086A500CB9C9AAF887B73EEAD06231269116110A0C0A693
    Malicious:false
    Reputation:low
    Preview:Please refer to http://java.com/licensereadme.
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Unicode text, UTF-8 text
    Category:dropped
    Size (bytes):153824
    Entropy (8bit):5.0228528661795355
    Encrypted:false
    SSDEEP:3072:Yj33DuJ8sY5sPfqN7amC35q2Fr4NZ1G8OAN6CflxDcw+4oHHZZvcm9lHNhJDXG85:HqN2p55O5cw+4oxHPN3Rj
    MD5:6EC6AB60B31FCFD0011C79DD90A9BDFE
    SHA1:B83C3F32261DE3E48CCD20614A11E066B1EC9027
    SHA-256:3114FC257CFF7E538C07E5CAE90FE53766725EFE7746614E4437695A0A89138A
    SHA-512:0F0AE546EFECFC915838ED704889FAEF30DCED7A374091EC1E3FE651A474FCA77363B02D9370C21AAA487900763001FACE181238D4F691039A657AD0DDC698D4
    Malicious:false
    Reputation:low
    Preview:DO NOT TRANSLATE OR LOCALIZE..-----------------------------..%% This notice is provided with respect to ASM Bytecode Manipulation .Framework v5.0.3, which may be included with JRE 8, and JDK 8, and .OpenJDK 8...--- begin of LICENSE ---..Copyright (c) 2000-2011 France T.l.com.All rights reserved...Redistribution and use in source and binary forms, with or without.modification, are permitted provided that the following conditions.are met:..1. Redistributions of source code must retain the above copyright. notice, this list of conditions and the following disclaimer...2. Redistributions in binary form must reproduce the above copyright. notice, this list of conditions and the following disclaimer in the. documentation and/or other materials provided with the distribution...3. Neither the name of the copyright holders nor the names of its. contributors may be used to endorse or promote products derived from. this software without specific prior written permission...THIS SOFTWAR
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:ASCII text
    Category:dropped
    Size (bytes):19274
    Entropy (8bit):4.667864876938965
    Encrypted:false
    SSDEEP:384:sY2fSz/rGvS/66YsaZdIP3Lf4vAkMVhPGkupdDdicW:7vuvVmjkbylupdDdiZ
    MD5:3E0B59F8FAC05C3C03D4A26BBDA13F8F
    SHA1:A4FB972C240D89131EE9E16B845CD302E0ECB05F
    SHA-256:4B9ABEBC4338048A7C2DC184E9F800DEB349366BDF28EB23C2677A77B4C87726
    SHA-512:6732288C682A39ED9EDF11A151F6F48E742696F4A762C0C7D8872B99B9F6D5AB6C305064D4910B1A254862A873129F11FD0FA56FF11BC577D29303F4FB492673
    Malicious:false
    Reputation:low
    Preview:The GNU General Public License (GPL)..Version 2, June 1991..Copyright (C) 1989, 1991 Free Software Foundation, Inc..51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA..Everyone is permitted to copy and distribute verbatim copies of this license.document, but changing it is not allowed...Preamble..The licenses for most software are designed to take away your freedom to share.and change it. By contrast, the GNU General Public License is intended to.guarantee your freedom to share and change free software--to make sure the.software is free for all its users. This General Public License applies to.most of the Free Software Foundation's software and to any other program whose.authors commit to using it. (Some other Free Software Foundation software is.covered by the GNU Library General Public License instead.) You can apply it to.your programs, too...When we speak of free software, we are referring to freedom, not price. Our.General Public Licenses are designed to make sure that
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Unicode text, UTF-8 (with BOM) text
    Category:dropped
    Size (bytes):112724
    Entropy (8bit):4.842748696940968
    Encrypted:false
    SSDEEP:3072:ig3JrYrpltztZvepyFrqN7amC3jqN7amC3bqN7amC3w:L3mqN2pjqN2pbqN2pw
    MD5:CD510833A28BB88BFEF18E7084F83FF5
    SHA1:56FF42F87607B997B52AE0EF8BF315E36932E870
    SHA-256:18193FE6B7A04B12FBC04C6C383ED67982A3BFF62773087175FFF6DC05731B13
    SHA-512:B5D452CCAFE7F997EEA9B77735E11DFC13C916C8DBBD386CE0FE7304CFD995772A2AD7F5A8624889382D6706641A145975805D11B303F9711D0AAC253E9424E9
    Malicious:false
    Reputation:low
    Preview:.DO NOT TRANSLATE OR LOCALIZE..***************************************************************************..%%The following software may be included in this product:.Apple Computer: CoreAudio Utility Classes v2.0..Notice: This software is present only on Mac OS X systems...Disclaimer: IMPORTANT: This Apple software is supplied to you by Apple.Inc. ("Apple") in consideration of your agreement to the following.terms, and your use, installation, modification or redistribution of.this Apple software constitutes acceptance of these terms. If you do.not agree with these terms, please do not use, install, modify or.redistribute this Apple software...In consideration of your agreement to abide by the following terms, and.subject to these terms, Apple grants you a personal, non-exclusive.license, under Apple's copyrights in this original Apple software (the."Apple Software"), to use, reproduce, modify and redistribute the Apple.Software, with or without modifications, in source and/or binary
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:ASCII text
    Category:dropped
    Size (bytes):11
    Entropy (8bit):2.845350936622437
    Encrypted:false
    SSDEEP:3:Ydxb:YdF
    MD5:DB2434EBDDFA057BC3B6AA66F5377200
    SHA1:189EDAD68ABD285AB8AEA1DB4B8BF994F3A70F22
    SHA-256:E9CB3C344D45F1ADEEC27B213EB96BCD85870E6087443D395FC1DB3E1F542924
    SHA-512:8A1383340F073DFB5766100AA348BF4A1FBCB0F4B32E531E38B3D53000A80017482BB743EFC95E05572ADB1EEEF1D690FFD359EB5F52D46E029F20F29BEDBA32
    Malicious:false
    Reputation:low
    Preview:8.382.05.1.
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Zip archive data, at least v2.0 to extract, compression method=deflate
    Category:dropped
    Size (bytes):51769532
    Entropy (8bit):7.973707797716029
    Encrypted:false
    SSDEEP:786432:EMWqz/G0EApxor3pUI3WBF5zraiLiUkMJCr1ycC3xWB+OD13bg9mX0qMTDLQg:EMv7gAPG+Kibm/RVb00RM/LQg
    MD5:55F57124C25151D2CB62CF5A2E0003B1
    SHA1:5DE54459265E8EFD0833E9CEF44EEB1539560EF0
    SHA-256:B7F31482E59213847BFB2F35B49A3633A0080C001203C3E8090D492A37234CC1
    SHA-512:91827AA11786A26F033FE752E1927265EE4A2543FEF1A03D292647152F8543EA1414C7A9F06C095A0F5A1178B895029568591E760B8CB37371F9EE956A24A593
    Malicious:false
    Reputation:low
    Preview:PK...........V..f]...........com/oracle/net/Sdp.javaUT......d...dux..............X.n.9.}.W........Y`..w.Y..8. .3.#.,.[d/."....bw.o......"...S.....x....|X9.x.>....`b...0..h..Y`..%s..c.#,.a..($....'...,.3..`6.:.m....n6.r....`8....h.W..!\........b%-p.....F..z..s...8S8i$.3.>uh..7.:...6.N."a...8a......2../B..b.....p#.PV.F.+....U........]...w..|..>.....q!.Q.....B..d...<....#..M........ f.&....EB.d........].....p.......s.N...+by0.e...n.........{....4..Z.....vAX..........9...F.....\'1..Q2L..%..p6.F.....hq.....h1....>L.3...M.....t2.b`.B..=.*...l0...dl!`..dG...iT...B.:..n..;.......F ...X....j...G`.V.>..\[m..A.Ai.....%...#...a.~:C+..c\..._.%._.Z..|..5|.......g.;=..y.X.4....Z9..........<n...LD[.#..0...>......Dp..9.HKD.nC....UZ......(..?FH*.......2.#....R.%/O:...G.@^..`%.y.......l.%.k.H..v.,s.......]a|...3..5.0.:.+...mn9.~>gWq..5..&Gf.+.......].w[.Sd...s...`.cq.lj....D....b..B#.1*[.X.0)o.Y......xA|.t.6.{.,.y...dS.`.$.G.<M...O.W....8nQ.-.m.Z,...u8...@
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:HTML document, ASCII text
    Category:dropped
    Size (bytes):955
    Entropy (8bit):5.096095653697231
    Encrypted:false
    SSDEEP:24:INMTdqcxtK4jXQ5VaJ2gjQo4pDW94m/DJn:TTdqIK4jXjJdso4V7E
    MD5:810EF9BE9BDF09983D41E244A6179A20
    SHA1:D98AE54F03DAC87419ABC19B97E315830C2DA55F
    SHA-256:DB34008B34B4BC3177436E71BD01557D45D52E710699758AB227E5FEC7FFADB8
    SHA-512:3DA4DE8D7A7D037AA64F9A771C9AEB743D43839294ACB773CECB2BA9B0C869CF3D7F3E3BC41D803238F297647E85ABD43F596F1C2DF46579EC0A34263744E406
    Malicious:false
    Reputation:low
    Preview:<html>.<head>.<title>.Welcome to the Java(TM) Platform.</title>.</head>.<body>..<h2>Welcome to the Java<SUP><FONT SIZE=-2>TM</FONT></SUP> Platform</h2>.<p> Welcome to the Java<SUP><FONT SIZE=-2>TM</FONT></SUP> Standard Edition Runtime . Environment. This provides complete runtime support for Java applications. .<p> The runtime environment includes the Java<SUP><FONT SIZE=-2>TM</FONT></SUP> . Plug-in product which supports the Java environment inside web browsers. .<h3>References</h3>.<p>.See the <a href="http://download.oracle.com/javase/7/docs/technotes/guides/plugin/">Java Plug-in</a> product.documentation for more information on using the Java Plug-in product..<p> See the <a href=."http://www.oracle.com/technetwork/java/javase/overview/".>Java Platform</a> web site for . more information on the Java Platform. .<hr>.<font size="-2">.Copyright (c) 2006, 2018, Oracle and/or its affiliates. All rights reserved..</font>.<p>.</body>.</html>.
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Zip archive data, at least v1.0 to extract, compression method=deflate
    Category:dropped
    Size (bytes):6536402
    Entropy (8bit):7.974176338184181
    Encrypted:false
    SSDEEP:196608:JYZaBqmwquyHEcIqEMIo2J4UYn6cuEX5TWlU:bBkszZ2J4MCWlU
    MD5:A96A8402A835E4D547CA609A6FD3EC88
    SHA1:4FAA2545C47FFC006866B830B24676862DEC9E3D
    SHA-256:B879B1F6DA8CB9D139E9822BA9893096E78A34806143EF1191FE865711B6A431
    SHA-512:2BA75C590805594CE3E8431C9F6903AE0E0FB997677E4B029467BE76F8E4EAA7A245D32F2A3FD16624D3434660DBEE09BF6DE12DF66A1E010EB052593C168813
    Malicious:false
    Reputation:low
    Preview:PK........|..V................com/..PK........}..V................com/sun/..PK........|..V................com/sun/glass/..PK........|..V................com/sun/glass/events/..PK........|..V.........."...com/sun/glass/events/DndEvent.java.T...8....]9%)..L&U)j....U..l.Y.B..2Br$......@.a..........O.{?..0...}..-....h...}.k.......T...Zi..1$ZC_..I/.Q...fkX.+H.UZ..."}Z...t.o..qQ.i6MK:..Y..l.."MfiA..Q5...B...NJ..'.......6....v]@X..<X..3> .... 4..t.....<.6.(.tLC...T\./.(.W........'..@...v.aN..&.[l....psMH......uaa.(.i..mDc=.n.M.....o..y....7.-q..u....D...=..h.L/..a.....2.Pq.y.Ks_<.7..W.t..p.;...u.#@$|..zS.W....(.U.. 84...(/T..j..9f......./.2..`...j....LE.yR`F6..|S..2EcK)..="zY`...*.S..[.c.g.[..;.2.,$._...f..s.q\-.aG.y.R.%.k...5".....{./.N.=O@.`l.........._DL..q..#D1.q....F..E....hxJ`8....F...l..6Z.%C}..0...!.pxK^.....(.8Y+.l.i..4.........p.G.)H.Sl...]...".I...H?:..n..OC......{'==...n.2...$.....{.91%/..`.^....fF.t....?..V>`..W...tE.,.?..h4y...gI.^...yZ`..z....
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:ASCII text
    Category:dropped
    Size (bytes):94
    Entropy (8bit):4.741368340920021
    Encrypted:false
    SSDEEP:3:tqrYHUnPNeIKDKqvrYHQjPNLBLHvCmYnv2qlg8vn:GqIPHkKqzq8HvCmYvNTv
    MD5:8B4201948E4FE03F5A057C32D8028405
    SHA1:08BB93FF0371C56F02467F00C74D63741002DB1C
    SHA-256:341C7701C81CC9EA6DB8A0908B1BBEDEADBE8C1B5ADFAD8CAA9EBF5C08527E7B
    SHA-512:101330E0D635F1C0FC2C00F8B4ACB38BBCCD49CA866C9FE3C751FA82DF83F40A566BAED78EA0CE4E5FF764EADBEA0B48FF2D4090E1474FB3793F0DD77F02415D
    Malicious:false
    Reputation:low
    Preview:JAVA_VERSION="1.8.0_382".OS_NAME="Windows".OS_VERSION="5.2".OS_ARCH="amd64".LIBC="".SOURCE="".
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:ASCII text
    Category:dropped
    Size (bytes):157063
    Entropy (8bit):5.019059096479156
    Encrypted:false
    SSDEEP:3072:8j33DuS8sY5sPfqN7amC3Xs4NZ1G8OANn16XBPb3Ucw+4oHmZ/bcm9GdNhJ75e5t:MqN2pZy3Ucw+4o7dfCRp
    MD5:37E7AAD9C0F238DF220F5F70707C6341
    SHA1:617AD547D6BE8756C859E2770D5301044B0BE505
    SHA-256:CA07B5A7569D691A0C717B6844440AEF29706BD81A787C989D95BA352B390F47
    SHA-512:779DDBE62E28628A6A64B62409377BFCC4AFBEF917C57EC01F1BEDA2849890D1FC182620F46A231D5DA6850B2DAC52D67BAEC5C02215F309CDEC3D5BD3DF5FE2
    Malicious:false
    Reputation:low
    Preview:DO NOT TRANSLATE OR LOCALIZE..-----------------------------..%% This notice is provided with respect to ASM Bytecode Manipulation .Framework v5.0.3, which may be included with JRE 8, and JDK 8, and .OpenJDK 8...--- begin of LICENSE ---..Copyright (c) 2000-2011 France T??l??com.All rights reserved...Redistribution and use in source and binary forms, with or without.modification, are permitted provided that the following conditions.are met:..1. Redistributions of source code must retain the above copyright. notice, this list of conditions and the following disclaimer...2. Redistributions in binary form must reproduce the above copyright. notice, this list of conditions and the following disclaimer in the. documentation and/or other materials provided with the distribution...3. Neither the name of the copyright holders nor the names of its. contributors may be used to endorse or promote products derived from. this software without specific prior written permission...THIS SOFTWAR
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:ASCII text
    Category:dropped
    Size (bytes):1522
    Entropy (8bit):4.747042537008044
    Encrypted:false
    SSDEEP:24:b0fFDmMbmRMAOJDcJb3W2zeD34eXqC/5Wx/kaRilV8hWrwr1:b09PbmqAOJIW2KT4eXqC/5WFkaEQW8Z
    MD5:D94F7C92FF61C5D3F8E9433F76E39F74
    SHA1:7A9B074CA8D783DBE5310ECC22F5538B65CC918E
    SHA-256:A44EB7B5CAF5534C6EF536B21EDB40B4D6BABF91BF97D9D45596868618B2C6FB
    SHA-512:D4044F6CEB094753075036920C0669631F4D3C13203CAF2BEA345E2CC4094905719732010BBE1CAE97BC78743AA6DEF7C2AA33F3E8FCA9971F2CA0457837D3B0
    Malicious:false
    Reputation:low
    Preview:.OPENJDK ASSEMBLY EXCEPTION..The OpenJDK source code made available by Oracle America, Inc. (Oracle) at.openjdk.java.net ("OpenJDK Code") is distributed under the terms of the GNU.General Public License <http://www.gnu.org/copyleft/gpl.html> version 2.only ("GPL2"), with the following clarification and special exception... Linking this OpenJDK Code statically or dynamically with other code. is making a combined work based on this library. Thus, the terms. and conditions of GPL2 cover the whole combination... As a special exception, Oracle gives you permission to link this. OpenJDK Code with certain code licensed by Oracle as indicated at. http://openjdk.java.net/legal/exception-modules-2007-05-08.html. ("Designated Exception Modules") to produce an executable,. regardless of the license terms of the Designated Exception Modules,. and to copy and distribute the resulting executable under GPL2,. provided that the Designated Exception Modules continue to be.
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:ISO-8859 text
    Category:dropped
    Size (bytes):3244
    Entropy (8bit):4.504892344419146
    Encrypted:false
    SSDEEP:96:3kjJXQSqgbiihCrRbo+Q/cV0rDcFBL3P0/r3:3cAaOi01E+xV0rDaBL3P0z3
    MD5:A762796B2A8989B8952B653A178607A1
    SHA1:C725183C757011E7BA96C83C1E86EE7E8B516A2B
    SHA-256:79CCB53E0DBDB8EC16747A516EB77C3737C797E544AAA0A552B8A886A70EEF69
    SHA-512:9D88BD2910A0D7820732D498B11B4676A5A122F24093640D8F07D417E4D7077A3D411F5F3E96CC124483DBED9C940B9526CA8B19FBC7CE69CB294476FCAA6C91
    Malicious:false
    Reputation:low
    Preview:Copyright . 1993, 2018, Oracle and/or its affiliates..All rights reserved...This software and related documentation are provided under a.license agreement containing restrictions on use and.disclosure and are protected by intellectual property laws..Except as expressly permitted in your license agreement or.allowed by law, you may not use, copy, reproduce, translate,.broadcast, modify, license, transmit, distribute, exhibit,.perform, publish, or display any part, in any form, or by.any means. Reverse engineering, disassembly, or.decompilation of this software, unless required by law for.interoperability, is prohibited...The information contained herein is subject to change.without notice and is not warranted to be error-free. If you.find any errors, please report them to us in writing...If this is software or related documentation that is.delivered to the U.S. Government or anyone licensing it on.behalf of the U.S. Government, the following notice is.applicable:..U.S. GOVERNMENT END US
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Zip archive data, at least v1.0 to extract, compression method=deflate
    Category:dropped
    Size (bytes):6536402
    Entropy (8bit):7.974176338184181
    Encrypted:false
    SSDEEP:196608:JYZaBqmwquyHEcIqEMIo2J4UYn6cuEX5TWlU:bBkszZ2J4MCWlU
    MD5:A96A8402A835E4D547CA609A6FD3EC88
    SHA1:4FAA2545C47FFC006866B830B24676862DEC9E3D
    SHA-256:B879B1F6DA8CB9D139E9822BA9893096E78A34806143EF1191FE865711B6A431
    SHA-512:2BA75C590805594CE3E8431C9F6903AE0E0FB997677E4B029467BE76F8E4EAA7A245D32F2A3FD16624D3434660DBEE09BF6DE12DF66A1E010EB052593C168813
    Malicious:false
    Reputation:low
    Preview:PK........|..V................com/..PK........}..V................com/sun/..PK........|..V................com/sun/glass/..PK........|..V................com/sun/glass/events/..PK........|..V.........."...com/sun/glass/events/DndEvent.java.T...8....]9%)..L&U)j....U..l.Y.B..2Br$......@.a..........O.{?..0...}..-....h...}.k.......T...Zi..1$ZC_..I/.Q...fkX.+H.UZ..."}Z...t.o..qQ.i6MK:..Y..l.."MfiA..Q5...B...NJ..'.......6....v]@X..<X..3> .... 4..t.....<.6.(.tLC...T\./.(.W........'..@...v.aN..&.[l....psMH......uaa.(.i..mDc=.n.M.....o..y....7.-q..u....D...=..h.L/..a.....2.Pq.y.Ks_<.7..W.t..p.;...u.#@$|..zS.W....(.U.. 84...(/T..j..9f......./.2..`...j....LE.yR`F6..|S..2EcK)..="zY`...*.S..[.c.g.[..;.2.,$._...f..s.q\-.aG.y.R.%.k...5".....{./.N.=O@.`l.........._DL..q..#D1.q....F..E....hxJ`8....F...l..6Z.%C}..0...!.pxK^.....(.8Y+.l.i..4.........p.G.)H.Sl...]...".I...H?:..n..OC......{'==...n.2...$.....{.91%/..`.^....fF.t....?..V>`..W...tE.,.?..h4y...gI.^...yZ`..z....
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PE32+ executable (console) x86-64, for MS Windows
    Category:dropped
    Size (bytes):23008
    Entropy (8bit):6.642163669105578
    Encrypted:false
    SSDEEP:384:zj0l+NNqTTziTnIeEPWZSf+VIYinvyNYPxh8E9VF0NyTpk:v0gPKWTn9EP1/YindPxWE9i
    MD5:F001C8E9238D948756CC43EAC1780556
    SHA1:66895ED719D4EEABA17572174FCA0C6C2AA68653
    SHA-256:EE7CB828C17577E67F085CFC4F68EEDE286F13B65000593A6EDD45F7B69EECCF
    SHA-512:4E2E62DFE211F24F08E180A30F627123FD4ABA441EFBCCFD4D83A70D6ABF94CB5B50ED5D201E25C8F407392682FD406CAB21AEE1512F465E66926526FF44E09B
    Malicious:false
    Reputation:low
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.............~...~...~..-....~......~......~......~.~L....~.......~.~L....~......~.~L....~.Rich..~.........................PE..d...>..d.........."............................@.............................p......FE....`..................................................$..P....P.. ....@.......*.../...`..0....!..8............................"..p............ ..H............................text............................... ..`.rdata....... ......................@..@.data........0......................@....pdata.......@......................@..@.rsrc... ....P......................@..@.reloc..0....`.......(..............@..B........................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
    Category:dropped
    Size (bytes):17224
    Entropy (8bit):7.008578863517033
    Encrypted:false
    SSDEEP:384:2dv3V0dfpkXc0vVaOW2hWliZSf+VIYinvypPxh8E9VF0NyZ62B2:2dv3VqpkXc0vVam2p/Yin+PxWE/8
    MD5:D84D5D14D71AB4E38D8BDA5206FBE03D
    SHA1:CABB7F6189104B18E688F99ECEB0BAAE5F39A8A8
    SHA-256:4335D9F1938CAD1A301FF03BCD7A58979644F09268AB15B5E640BEBEA38617A7
    SHA-512:308FA57E408D67DAD29360A30E517B511552A089EA23E0DF671211489C2415AA1212330E9412F82389B2D0799C70457D309C8401A4EFD436415409A0944A88D9
    Malicious:false
    Reputation:low
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......m2..)S..)S..)S....].(S....A.+S....^.(S....C.(S..Rich)S..........................PE..d...48.U.........." .........................................................0............`.........................................`...V............ ..................H/..............8............................................................................rdata..l...........................@..@.rsrc........ ......................@..@................................................................................................................................................................................................................................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
    Category:dropped
    Size (bytes):172312
    Entropy (8bit):6.589730876956856
    Encrypted:false
    SSDEEP:3072:6acd2ZbbhWpJhjDXldqnTEsfJE5artK97cKxnRrj1SMNlCt4xtxItCDZkTT/Rxa:ud2ZBWX1qnTVE5arte7cKxRrj1Rl5Lua
    MD5:63AEFF30209102B56A0EA620412CB1F0
    SHA1:B92F2AD961811F8970444CC4AE0F6173458A5BA6
    SHA-256:E04C404DFE3F1EE243EB220272258368F241E5E24CF6180923DBA23168D3B835
    SHA-512:6F8988478E501AF68F3DCBC2746568F347E6EAB389EC287ED2544E0E60F65AF574CF5DE98F1969E8BAF751DE0CDC4A43233957C923EC880D803EE70A6143A9A7
    Malicious:false
    Reputation:low
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......X..9..uj..uj..uj...j..ujN.tk..ujy.tk..uj..tj0.uj.;.j..ujN.pk..ujN.qk..ujN.vk..uj..qk6.uj..uk..uj..j..uj..wk..ujRich..uj........PE..d......d.........." .........r............................................................`..........................................X......pZ..........p.......h....l...5...... ...0=..............................P=..................h............................text............................... ..`.rdata..HP.......R..................@..@.data........p.......R..............@....pdata..h............T..............@..@.rsrc...p............f..............@..@.reloc.. ............j..............@..B................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
    Category:dropped
    Size (bytes):15176
    Entropy (8bit):7.081890886688098
    Encrypted:false
    SSDEEP:384:SW2hWlDZSf+VIYinvyy7APxh8E9VF0NyNYiE9:qF/YinN7APxWE7pG
    MD5:D3B8D01E5BF195BCAADC9BCEEB5CBDA2
    SHA1:23A995B7C4126ABE2CBA09C162D97CA2B4CA6E93
    SHA-256:1D41C4AE5BADE8B3743605938C5D6CF53EC2B5049427325978E9D056F348F48F
    SHA-512:D2C380572C1CDC8A4266D703EEA60D6337D76B24A2D4304F2DBD9A922F96BB5B7714D69C59134A1D8D7F6DBE95F4FCCC6A0F693A2743453F6D9CDEBB998A61FD
    Malicious:false
    Reputation:low
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......m2..)S..)S..)S....].(S....A.+S....^.(S....C.(S..Rich)S..........................PE..d...38.U.........." .........................................................0............`.........................................`..._............ ..................H/..............8............................................................................rdata..t...........................@..@.rsrc........ ......................@..@................................................................................................................................................................................................................................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
    Category:dropped
    Size (bytes):67840
    Entropy (8bit):5.7951686300420056
    Encrypted:false
    SSDEEP:1536:q5W2wDe5c4bFR2JyhcvxXWpD7d3334BkZn+PzLq/7wPxP:QW2wDe5c4bFR2JyhcvxXWpD7d3334BkK
    MD5:F403DCFA2ACEB9DE6A28236BDA3F202F
    SHA1:EC81AA5E0CF6D15867E8A5570F298B5F8417F7CA
    SHA-256:FE74698756435E669F35D284C510B84B5B4FAE427159BEA72A01E9D96E0D0DA8
    SHA-512:AA5B74A2BB407D608BC721E4B421F2A6234232D4A775240497D668B818C57FEDAB1958E8D752282487F4039C6558BB3061EB59730A090F6C45BDAC7E5440E2F2
    Malicious:false
    Reputation:low
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......m2..)S..)S..)S....].(S....A.+S....^.(S....C.(S..Rich)S..........................PE..d...48.U.........." ......................................................................`.........................................`....................................1..............8............................................................................rdata..............................@..@.rsrc...............................@..@................................................................................................................................................................................................................................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
    Category:dropped
    Size (bytes):16200
    Entropy (8bit):7.038566953493795
    Encrypted:false
    SSDEEP:384:6k+W2hWVZSf+VIYinvyc5Pxh8E9VF0NyW+Emn4:6kW1/YinDPxWEA84
    MD5:A2654A793736627CBC3EC2380417D1C7
    SHA1:F62AF8A0E02DF90F0860EDDDD272218CCEDC111F
    SHA-256:2D89F65897F5CC6704610CBE62C8B442DB59088D5EA34E39CD87135B9E278A61
    SHA-512:4D21796C678967C8B5E5328C290412C54718F2FCDFD539DAB3397030044185D04748DBA4045F2ED06F7DF8F4B46FC6E84B61188B48EF24E42C0F77677C690F05
    Malicious:false
    Reputation:low
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......m2..)S..)S..)S....].(S....A.+S....^.(S....C.(S..Rich)S..........................PE..d...48.U.........." .........................................................0............`.........................................`...E............ ..................H/..............8............................................................................rdata..\...........................@..@.rsrc........ ......................@..@................................................................................................................................................................................................................................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
    Category:dropped
    Size (bytes):296744
    Entropy (8bit):6.369125051026215
    Encrypted:false
    SSDEEP:6144:DafMz5pewxPt0FgFn9FGMReiDaI2+DfoROhP3s4kp1:DkMz5pewxPsKnDGSGP7
    MD5:9BAF47076281CF52072DC306EC21CB09
    SHA1:565C0C6A28A51DCF377BDAA23EEE8907AC8D506B
    SHA-256:C5FBA0D87B42C5CFD011B53F4D0C742BC1C8858AFABD6C3434855F6BD5BC44FC
    SHA-512:1AC786CD4378F3D8AE9C61E1DC3F8041B5964DEC9E3E464BE3E1FBD5E46D2FE08B49BE56B55956941BBE931B36F62D07EA780DF91EC3ADF25E93255A579150A8
    Malicious:false
    Reputation:low
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........F.=.'.n.'.n.'.n.vgn.'.ne.}n.'.n.ven.'.n.vZn.'.n.v[n.'.n&.qn.'.nN.gn.'.n.'.n.'.nN.[n.'.nN.Zn.'.nN.fn.'.n.uan.'.nN.dn.'.nRich.'.n........................PE..d......d.........." .....d..........\j....................................................`.................................................,................`..h(...N..(9...... .......8..............................p............................................text...+b.......d.................. ..`.rdata...............h..............@..@.data.... ...0......................@....pdata..h(...`...*..................@..@.rsrc................D..............@..@.reloc.. ............H..............@..B........................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
    Category:dropped
    Size (bytes):24464
    Entropy (8bit):6.6204363253598535
    Encrypted:false
    SSDEEP:384:+ZVacWM4Oe59Ckb1hgmLtW2hWJZSf+VIYinvyhPxh8E9VF0Nye+y:+ZVJWMq59Bb1jbV/Yin+PxWEMP
    MD5:637F1184BEAC4D37210F064FA8DEEA7E
    SHA1:737CAA95985C9BC66B0AB981112A0FB4070953A7
    SHA-256:21300CC7DD3447A20A9C0B5D4BC2F9E32872228FBE78489ABD3F0535252D08DA
    SHA-512:04647560E3E3E197D0AB6AE8656938FF31EE5CFE7460B55B137A9C7D0245D39CCC82862BB537D310E624CD696BC072B7B3E3ABA90C8C4DCECD9926F556593667
    Malicious:false
    Reputation:low
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......m2..)S..)S..)S....].(S....A.+S....^.(S....C.(S..Rich)S..........................PE..d...48.U.........." .........,...............................................P............`.........................................`....%...........@...............0.../..............8............................................................................rdata...&.......(..................@..@.rsrc........@.......,..............@..@................................................................................................................................................................................................................................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
    Category:dropped
    Size (bytes):19312
    Entropy (8bit):6.867144693250673
    Encrypted:false
    SSDEEP:384:6DynW2hWvhZSf+VIYinvy6qPxh8E9VF0NyeH:Dmw/Yin4PxWEM
    MD5:D99ABDE7DA5443715BA575E97643C311
    SHA1:7994E9B09E6B8E8D82DCF4AFDD4E89F660B9A90D
    SHA-256:048812713CCB97999A2EBFAE44598AC119CB8A4F2350F152E7C5D5C5A942C37A
    SHA-512:971A343AB752A7989B349FF388CD2F605B47EB4060CD139F491C25A96ACB398486E77DA5435AB0F50E31932A010CFCC68BBFCD2172DF043DC03EDE6E7EDF1063
    Malicious:false
    Reputation:low
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......m2..)S..)S..)S....].(S....A.+S....^.(S....C.(S..Rich)S..........................PE..d...48.U.........." .........................................................@......,d....`.........................................`................0..................p/..............8............................................................................rdata..............................@..@.rsrc........0......................@..@................................................................................................................................................................................................................................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PE32+ executable (console) x86-64, for MS Windows
    Category:dropped
    Size (bytes):23008
    Entropy (8bit):6.622168838883876
    Encrypted:false
    SSDEEP:384:hraktFJ6XHiQLGeEcZSf+VIYinvyMhPxh8E9VF0NyR8ZQRM:YswCQLrE7/YinXhPxWEP+Qi
    MD5:0836CB1FD07121438AC1FB7AB8762500
    SHA1:65E67B3C17CC03D79B84283922B731CCAAF45A11
    SHA-256:B9986A1C153BC85C7646C8F2113F1DDD0A460DFAEFE75F68DCA435F2819F9452
    SHA-512:8915FFA424B2A10AD7A81240FAE033E472BE6D62BDA3BE61F2A7F7AADD676C554FA3AA88AE50E6FA4EDFDB9A63F5369C2B9DE107072574C0C1AD2B60C5B32831
    Malicious:false
    Reputation:low
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.............~...~...~..-....~......~......~......~.~L....~.......~.~L....~......~.~L....~.Rich..~.........................PE..d...?..d.........."............................@.............................p............`.................................................p$..P....P..@....@.......*.../...`..(....!..8...........................p"..p............ ..H............................text............................... ..`.rdata..~.... ......................@..@.data........0......................@....pdata.......@......................@..@.rsrc...@....P......................@..@.reloc..(....`.......(..............@..B........................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
    Category:dropped
    Size (bytes):17224
    Entropy (8bit):7.075288754264113
    Encrypted:false
    SSDEEP:384:yWXk1JzNcKSIsW2hWSZSf+VIYinvyaPxh8E9VF0NyKwL:ybcKS5s/YinfPxWEw+
    MD5:53EBABD707602FA82275C83200F7DBA1
    SHA1:D812A55CF0CDA3E62443CFB3E308D603BC94C0A6
    SHA-256:CE0E8E7DAA964E32E36A8E6B1942B205BC24D898FD9901AAF361060CA05F515F
    SHA-512:04B92609BC11805493D6B0ECA9A227E60D6FE7462663628F6EFB3A6184F8A080860DCE8348649DCB2213AE6C5D99F49A4241A3AFEE5ED04DCC8AB0A450BFCFA3
    Malicious:false
    Reputation:low
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......m2..)S..)S..)S....].(S....A.+S....^.(S....C.(S..Rich)S..........................PE..d...48.U.........." .........................................................0...........`.........................................`................ ..................H/..............8............................................................................rdata..............................@..@.rsrc........ ......................@..@................................................................................................................................................................................................................................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
    Category:dropped
    Size (bytes):249688
    Entropy (8bit):6.436323435137707
    Encrypted:false
    SSDEEP:6144:bcQ6uYsmqLg9uvQU1+74R9CIvLg9gmTIe9q7BZqrcLa9eLgrLavLgSq7YqrWLa6v:bcQ/YTqLg9uvT1+74RdLg9gmTx9q7BZr
    MD5:BECCF08F7ABCAAF648996E83E7338704
    SHA1:DFBAECF2565B45AE98F39C9A1FBFFB57EE633E9C
    SHA-256:894076E5CD343CB10BFF880041E27B50D75932D9BD44BC54EB256BFA46290E77
    SHA-512:396B8448AA5FF02EC280CDBBCC740FE52490533583B8E04FC920A2E7C3EC65A2B5042FED95798CFE819EE2051096289DB33F0077D0398574CE8178D871C96707
    Malicious:false
    Reputation:low
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........i:...i...i...iQB.i...i...i...i...i...i...i...i...i...i9#.i...i...i..i9#.i...i9#.i...i...i...i9#.i...iRich...i........PE..d......d.........." .........(............................................................`.........................................p6..A....8..d................-......X7..........P...8...........................`...p............................................text............................... ..`.rdata..(...........................@..@.data....O...@...0...0..............@....pdata...-...........`..............@..@.rsrc...............................@..@.reloc..............................@..B........................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
    Category:dropped
    Size (bytes):164520
    Entropy (8bit):6.476949454306881
    Encrypted:false
    SSDEEP:3072:P6q2qwcZrWByWh1i6lhpqMum+BcxvDgguSaz21v1kTa/w/xH:P5/riyWhQ6RhxvD5uSELa2
    MD5:ABCAFD00B972D39D69FA218124174CFC
    SHA1:1706B3C3537D6FD40F600F40F21019195A760B2B
    SHA-256:6BFDCA6D36A69715AF33BF2D9429D5938EAEA110ACF18804F10DA9FB0D0C4440
    SHA-512:3658500D2B9681AF81CFD4EEE11D64BFECA370C407A6AD9BF916D190EBEF47F36B354879E771508A9D45EE8527E313239ED8A2683C35E2D56DDE3CE02E30A0D4
    Malicious:false
    Reputation:low
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........U..4..4..4....p.4...ej.4...eh.4...eW.4...eV.4..A.|.4..4...4..).W.4..).k.4..fl.4..).i.4..Rich.4..........................PE..d......d.........." .................................................................:....`.........................................P7..b....7..d....p.......P.......N...4......t.......8...............................p............................................text...K........................... ..`.rdata...n.......p..................@..@.data...P....@.......(..............@....pdata.......P.......*..............@..@.rsrc........p.......H..............@..@.reloc..t............L..............@..B........................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
    Category:dropped
    Size (bytes):331336
    Entropy (8bit):6.206181234283503
    Encrypted:false
    SSDEEP:6144:WE2nafGOe42xdzpruPMjgTrmrRvO7bgLfnWzgcpw2e9My:WFaeOwpqPyabHzQqy
    MD5:09425CCED3EB6D3F9AABF8B0747FD85C
    SHA1:4B4D99E15E7753559821FB13011F7FA552CABAD3
    SHA-256:0E4E5DB3BBC90536FE3A070ED58B500627B1345067F5A462F5B26CEF7DC93D75
    SHA-512:784ED7ACD61273C566B21A922877402CF25200843F76FDD569FB9A9C44905177FDA7DF3DAD6C36E10697B3BCC1F965E50CE4766B10FF05305C49B86D7F6FAB69
    Malicious:false
    Reputation:low
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........\...2Q..2Q..2Qo..Q..2Q..Q..2Q..3P..2Q..3QR.2Q..6P..2Q..1P..2Q..7P..2Q..2P..2Q...Q..2Q..0P..2QRich..2Q........................PE..d....*.[.........." .................................................................{....`A........................................P....M..\Z...................6......H:......|...@l..8............................l..................`............................text...<........................... ..`.rdata...k.......l..................@..@.data....9...p...2...X..............@....pdata...6.......8..................@..@.rsrc...............................@..@.reloc..|...........................@..B................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
    Category:dropped
    Size (bytes):691368
    Entropy (8bit):6.546101425294333
    Encrypted:false
    SSDEEP:12288:scVrthpMVYt3UbZKFxITWBx2EKBSrP8/LA7kxCv:scVZj3UbZKFxkWBx2BBSrPyA7EU
    MD5:797280F5C681B2F67C4638C1E74041CC
    SHA1:ADD9557295CAB1C27268BA2E1A8DC61E40902042
    SHA-256:07E75CBF7D7A3CA1090AD629858BA5784CECB72EC0CA6A8B2F01298517A37A79
    SHA-512:5205F90AF28243BFF3D578D1830AE095D26CCA255A0B80C20BFEF2C5A25A94F883EA8D8C9E68EF1FDD84F655AF5940D59F861674F915EFE30BD96F0C2CFB2200
    Malicious:false
    Reputation:low
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........(PN.F.N.F.N.F..h..L.F.N.G.l.F....M.F....L.F....C.F....L.F.....y.F.....O.F.C..O.F.....O.F.RichN.F.........PE..d...:..d.........." .....*..........x1..............................................6z....`..........................................,.."....-..<....p.......P.......F...F..........0A..8...............................p............@...............................text....(.......*.................. ..`.rdata..6....@......................@..@.data........@....... ..............@....pdata.......P.......$..............@..@.rsrc........p.......@..............@..@.reloc...............D..............@..B................................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
    Category:dropped
    Size (bytes):15688
    Entropy (8bit):7.1225676531304805
    Encrypted:false
    SSDEEP:384:69kW2hWXZSf+VIYinvypPxh8E9VF0NyW8l:Lv/Yin8PxWEAk
    MD5:9A1F2B672A0975D928625BF5C88DBDC1
    SHA1:3D4FAA9527977C421B7101AF4CBF7EC24AF80844
    SHA-256:51C28CA9366E0591A9A89B8516EC68D5A9AEE4DD69DDCFFDFE5951DE60CDEAF6
    SHA-512:D70157731DD088364CB9ADD1B0792B6A15064772CF320AD425176C285B673592D335D65C3AC9AC44C401FA575E3691AF8E8443C35F1EC75E42E27276E80A735A
    Malicious:false
    Reputation:low
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......m2..)S..)S..)S....].(S....A.+S....^.(S....C.(S..Rich)S..........................PE..d...48.U.........." .........................................................0......iB....`.........................................`...e............ ..................H/..............8............................................................................rdata..|...........................@..@.rsrc........ ......................@..@................................................................................................................................................................................................................................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
    Category:dropped
    Size (bytes):278136
    Entropy (8bit):6.078551456971608
    Encrypted:false
    SSDEEP:3072:if5eZqNYcTKurDanheB7Mw2mrWgPodgPO+Fas2xFLxcYcHUdqo/7x:iRyehrDaheBji9KGW2xzcYcHUdD
    MD5:C1295A8DD0463FBDD805284F239E8449
    SHA1:8D9B4DA18C629106D73A4056B3AC53934F015944
    SHA-256:EAF40FD912C9A97DCFF7697EE1A7FB32A03F06D15BBD11D8431A67C114978481
    SHA-512:7C4A2D6CFBCD23280B8BDB07A836036E5D786379C974215BCFFD40B8527F733CFF1082D435D6A0777FD177B124EBD24E5DE0E920A0F1CBF836E72FF92F42EE86
    Malicious:false
    Reputation:low
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........1x".P.q.P.q.P.q.(.q.P.q.8.p.P.q.8.p.P.q.8.p.P.q.6.p.P.q.6.p.P.q.6.p.P.q.P.q.Q.q.8.p.P.qs9.p.P.qs9.p.P.qs9.q.P.qs9.p.P.qRich.P.q................PE..d......d.........." .....X...........9.......................................P............`..........................................e..4......@.......(&......X)......x8...@..h...............................(....................p.......S.......................text....W.......X.................. ..`.rdata...$...p...&...\..............@..@.data....7.......*..................@....pdata..X).......*..................@..@.rsrc...(&.......(..................@..@.reloc..h....@......................@..B................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
    Category:dropped
    Size (bytes):14664
    Entropy (8bit):7.191875916980909
    Encrypted:false
    SSDEEP:384:USeW2hW3ZSf+VIYinvytPxh8E9VF0NywStm+k:KD/YinuPxWEmd3
    MD5:978F312C0215F4BA02652DF131720C3F
    SHA1:AA4B280C7D5700D842BC98D53A9AA4DFC3BF7F56
    SHA-256:F317184260264F1FFDBEC326EA7D57FC282727BE808C8EA3FE4FFC45FBECC021
    SHA-512:5256ED02FB0188B5CC39542A8A8E1591A162D813985E2D703AE09056A907B6A2612879E1C214CFC7E4433672702FC633DC8FC5263E9B40AD41BDBAACE044D32B
    Malicious:false
    Reputation:low
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......m2..)S..)S..)S....].(S....A.+S....^.(S....C.(S..Rich)S..........................PE..d...48.U.........." .........................................................0...........`.........................................`................ ..................H/..............8............................................................................rdata..............................@..@.rsrc........ ......................@..@................................................................................................................................................................................................................................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
    Category:dropped
    Size (bytes):31272
    Entropy (8bit):6.484342523949209
    Encrypted:false
    SSDEEP:768:3QjEAigKZ7IZyDu+QKEiDtd/Yin6PxWEMn:3Qz8s/KEad/76PxA
    MD5:AB01ADB90CCD11952742FFBE70D8EDFD
    SHA1:C49F6B5067C0F59CE40B37319A27D9B924AA7D31
    SHA-256:8F4685DC2994909A76BF4A359D485370DBFF85EE6F617B4193988FCE43297ED4
    SHA-512:7F53426EC39FEDDA9491E2DA0DC640C1E35446D8FFFD839BB20E05CEF0CBDF06E5D94BD1789B6FFDB197798E41D08762196C2FE26B837B41AE082A73AF479E7E
    Malicious:false
    Reputation:low
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........o.gB..4B..4B..4._ 4@..4._"4C..4._.4H..4._.4@..4..64G..4B..4...4...4@..4..!4C..4O\&4C..4..#4C..4RichB..4................PE..d......d.........." ..... ...,......,*....................................................`.........................................PB..U....B..P....p.......`..@....J..(0......|...p2..8............................>..p............0..8............................text............ .................. ..`.rdata..<....0.......$..............@..@.data...`....P.......>..............@....pdata..@....`.......@..............@..@.rsrc........p.......D..............@..@.reloc..|............H..............@..B........................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
    Category:dropped
    Size (bytes):25096
    Entropy (8bit):6.67350085573742
    Encrypted:false
    SSDEEP:384:sAwWmBirTEWUTbizt3YHIP+UMy0SSsAy3LZSf+VIYinvy2Pxh8E9VF0Nyox:ntmIrTEWUTAtDmY1Sty3i/Yin1PxWE+
    MD5:B8BF176BFD0F14F8A28727BAC3BDF590
    SHA1:7DEDFDE057A6F4DA00B0F94FBDE05A81342A4F22
    SHA-256:08FC51E495E273771DC8377F4EDB214C1589FA0CF1984E5C7BA2DD5DAEF65A27
    SHA-512:FB229A315857BABC4A6C85F33A62078C1B78374618795F43CA2B294C73C68610169B500AF996F44A2B897B325F5DBA72F8F37BC7C34EA0EF4641574900950045
    Malicious:false
    Reputation:low
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......Jk~....................H[.....H[.....H[.....H[................'..................X............Rich............PE..d....d.........." ......................................................................`.........................................@5.......7..P....`.......P.......2...0...p.......1..8...........................P2..p............0..X............................text...;........................... ..`.rdata.......0......................@..@.data........@.......(..............@....pdata.......P.......*..............@..@.rsrc........`.......,..............@..@.reloc.......p.......0..............@..B........................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
    Category:dropped
    Size (bytes):15688
    Entropy (8bit):7.073671277747241
    Encrypted:false
    SSDEEP:384:oUW2hWGZSf+VIYinvyePxh8E9VF0NyeoaR3:bg/YinhPxWEMvR3
    MD5:001CF85AA32AC0F40217F7242B9D0705
    SHA1:0E4C2D965A60B248683606E74F3E112D3DD186BA
    SHA-256:B909CED8B59E8BAC343FAE704EF80BD447D3AF950707451D03670643719EC4E1
    SHA-512:BFA9629DA0CDD36290995E76F5A580CF08AC1A5BEAD90BE2507B70F352C3001D7EF70FFB4452EC71025C2453F26391E709F5C6D7C7C25704AAB71272C6A31430
    Malicious:false
    Reputation:low
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......m2..)S..)S..)S....].(S....A.+S....^.(S....C.(S..Rich)S..........................PE..d...48.U.........." .........................................................0............`.........................................`...l............ ..................H/..............8............................................................................rdata..............................@..@.rsrc........ ......................@..@................................................................................................................................................................................................................................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
    Category:dropped
    Size (bytes):16200
    Entropy (8bit):7.068886377382293
    Encrypted:false
    SSDEEP:384:ALW2hWTZSf+VIYinvygU3Pxh8E9VF0NyVpyl:Sr/YinxqPxWETk
    MD5:95E1D872BF23C3BA9D8E4D231CBC50C8
    SHA1:947C15CBB19E3300CC6FDC47B0E8C240B518B392
    SHA-256:0F86BA122D340C42489359DC4ADB2C4F9F74C43BCBAC970A15BBEE6B0E1D2CC8
    SHA-512:EDC8ACC0842412E105BD02EACBE26DE94AECC55C1009E4EA83844BBF2477A29ADD5CD581E132940E9F03B0B1BD3F7E975ACBD873064E52535C643FB6B95612D5
    Malicious:false
    Reputation:low
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......m2..)S..)S..)S....].(S....A.+S....^.(S....C.(S..Rich)S..........................PE..d...48.U.........." .........................................................0......W.....`.........................................`................ ..................H/..............8............................................................................rdata..............................@..@.rsrc........ ......................@..@................................................................................................................................................................................................................................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
    Category:dropped
    Size (bytes):16200
    Entropy (8bit):7.03987047510112
    Encrypted:false
    SSDEEP:384:SHW2hWMZSf+VIYinvyGCPxh8E9VF0Nyb7E:KC/YinWPxWEtw
    MD5:A7AC1A0EE5AE4F1AB2C43341440818C4
    SHA1:1EFB08453486A210521796A8BA9CFDCFD4641727
    SHA-256:2F4B9651F9CBB7BDA647604504D24C1597803B5457F229B4FF258F2B5D005FF3
    SHA-512:D1D7C70136EECF786B1F618F5F850C367CFCA5855179C58288EA235D4AA14A3E9FEF3A2859B49F85FD66AAA6BCFFFF5E487C09576CAF41E45928CEC9DC04288C
    Malicious:false
    Reputation:low
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......m2..)S..)S..)S....].(S....A.+S....^.(S....C.(S..Rich)S..........................PE..d...48.U.........." .........................................................0......l.....`.........................................`...G............ ..................H/..............8............................................................................rdata..h...........................@..@.rsrc........ ......................@..@................................................................................................................................................................................................................................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
    Category:dropped
    Size (bytes):16200
    Entropy (8bit):7.025015381904245
    Encrypted:false
    SSDEEP:384:kfW2hWpYZSf+VIYinvyJ5Ol2Pxh8E9VF0Ny/VA2:kBS//Yin+PxWE9N
    MD5:32448FEDA678DA73AB07ED2F1E169764
    SHA1:A6143ACC1C43F705CB2981A95A11FC87BA5EEAA9
    SHA-256:DADBF504956E9F9ADC8887F53B32D816026D352F02CE3CE4C8E21DC3AFB3F991
    SHA-512:E8A9EBCD879518CB4026772A4E3645D3759D8F8770833A171D7AAA54207B4176759DEF757B8ABD8B5FCFFF7A090EF715401A1FCD204478E7D095608FE3B593BE
    Malicious:false
    Reputation:low
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......m2..)S..)S..)S....].(S....A.+S....^.(S....C.(S..Rich)S..........................PE..d...48.U.........." .........................................................0............`.........................................`................ ..................H/..............8............................................................................rdata..(...........................@..@.rsrc........ ......................@..@................................................................................................................................................................................................................................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
    Category:dropped
    Size (bytes):15176
    Entropy (8bit):7.08233446539952
    Encrypted:false
    SSDEEP:384:hLW2hWnkZSf+VIYinvySq/Pxh8E9VF0Nyek8Yn9:hdC/YinXq/PxWEMun9
    MD5:11FD520B0B7C1BAA95C09C6E59A9B930
    SHA1:F7FE830509A63BBC1C98F376F7310496B3D740A4
    SHA-256:747E699772CBAB965AADD6C0D1FA3AF4F1CC5A30EAE64FA0E9903DD9E6874A11
    SHA-512:5584E6E5E7376C2D0E25C8838C175DE5C362B5183F9ADD0218A9CDEE035B210C44C586A62522C22AB011F94C7CE52C76C341D903D7C31BFA1E8E6EE71A7536FE
    Malicious:false
    Reputation:low
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......m2..)S..)S..)S....].(S....A.+S....^.(S....C.(S..Rich)S..........................PE..d...48.U.........." .........................................................0............`.........................................`...L............ ..................H/..............8............................................................................rdata..\...........................@..@.rsrc........ ......................@..@................................................................................................................................................................................................................................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
    Category:dropped
    Size (bytes):15688
    Entropy (8bit):7.098913755713641
    Encrypted:false
    SSDEEP:384:HDfIeWW2hWHZSf+VIYinvyKapPxh8E9VF0NyK2tB5E:se+f/YinRapPxWEwqa
    MD5:2B5248FB1080265FB6A165C2B04A2D92
    SHA1:99A2FE891971B91407E18F6D1EF0B6DB824734F7
    SHA-256:E7723E98C15E3C4A3D6BE46DDBC248A984E7C2BDA228D337188DDDFE79B9DB43
    SHA-512:36EEBB51760263BC26CDEE89DE4F53036B8600EB98E55BBF956BA65CDAE8B09B32C0EA0DCF2BDEF6AB7D30AA694899D7C8920594F72BEB48D6FE1BA5B4A65874
    Malicious:false
    Reputation:low
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......m2..)S..)S..)S....].(S....A.+S....^.(S....C.(S..Rich)S..........................PE..d...48.U.........." .........................................................0............`.........................................`................ ..................H/..............8............................................................................rdata..............................@..@.rsrc........ ......................@..@................................................................................................................................................................................................................................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
    Category:dropped
    Size (bytes):15688
    Entropy (8bit):7.13090091026014
    Encrypted:false
    SSDEEP:384:ttZ3zW2hWIZSf+VIYinvyk2YPxh8E9VF0NyioR:jC/Yinr2YPxWE4G
    MD5:B57E0C0560FF3603E31B15859CCA290C
    SHA1:F89FAED0AFFD12A5C80A69D2C09FDF4752E2EC3F
    SHA-256:B732FC1B150066A5E32CDF2A29C37F9E4B355DA2DD99DFBC0FAA2D6B9B8DC155
    SHA-512:FDE9846D23A85CB3F75EDBBD530BBEC8EAA91F6DA5F72EC8821DAE699BAE3CAC31EC4EABF8A6533937FBFC399D3F6C18C81CD9AADBAFEEFEE61F23219EDFD103
    Malicious:false
    Reputation:low
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......m2..)S..)S..)S....].(S....A.+S....^.(S....C.(S..Rich)S..........................PE..d...48.U.........." .........................................................0............`.........................................`...v............ ..................H/..............8............................................................................rdata..............................@..@.rsrc........ ......................@..@................................................................................................................................................................................................................................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PE32+ executable (console) x86-64, for MS Windows
    Category:dropped
    Size (bytes):23008
    Entropy (8bit):6.6418234733680865
    Encrypted:false
    SSDEEP:384:MTEl+NN3xJ9GMiW3yMkeE4ZSf+VIYinvyQPxh8E9VF0NytPN7ZFB:eEgPJGVadBEf/YinfPxWEjP1ZFB
    MD5:7D9CD00724C4017DCA821834D76D9BD5
    SHA1:5BD6FCAB8D882C05BF5D81F64C84304F0A67AC23
    SHA-256:C4D98CADD791E39E9FE76E731CA7DCD4883B77B22441B0894DF82BF78C4FB7F8
    SHA-512:6294D4D718FCD59FF0CA1B6FE0DFE55DAA248D2FE932A577A00577F4AE3BC1D6F993B4D580BE5A3B6EBCD9FE765D237467C3F52F3283AA97F73B2692A99C9BBD
    Malicious:false
    Reputation:low
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.............~...~...~..-....~......~......~......~.~L....~.......~.~L....~......~.~L....~.Rich..~.........................PE..d...?..d.........."............................@.............................p......>9....`..................................................$..P....P..,....@.......*.../...`..0....!..8............................"..p............ ..H............................text............................... ..`.rdata....... ......................@..@.data........0......................@....pdata.......@......................@..@.rsrc...,....P......................@..@.reloc..0....`.......(..............@..B........................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
    Category:dropped
    Size (bytes):684608
    Entropy (8bit):6.657342345196282
    Encrypted:false
    SSDEEP:12288:eRq7MLSK6G5uhM7EhzsBF++qevQNuLz35u0UfbyKmEguTuCEqzZajRfEWmOzpXPv:e47MLr6G5tEhzCF++qef3bUfbyAgunRS
    MD5:B5FFB51A3EB71ABA973D73916992FC52
    SHA1:C5D60440B220FEC0F7D207D9D4194C72462CA3DD
    SHA-256:670D96E597AFA4F932CB5C59423FE9694493E4803F083FB89D32AE5B35116D2E
    SHA-512:D493E0DA2DD25FEED00CB781891D0514D8E231B7B93113CC228C67052067F8A0EEFF956F0E44E3BEE97E3FA18DBA6F3D180ABA6E61B2DF3C0DFA85CAB677DCA7
    Malicious:false
    Reputation:low
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........D.w.%.$.%.$.%.$.tZ$.%.$.tX$.%.$.tg$.%.$.tf$.%.$T.L$.%.$.%.$.%.$<.g$.%.$<.[$.%.$.w\$.%.$.%.$.%.$<.Y$.%.$Rich.%.$........PE..d...n..b.........." ..... ...........).......................................`............`....................................................<....@..h........u...,..@F...P..(.......................................p............0...............................text...k........ .................. ..`.rdata..F|...0...~...$..............@..@.data...............................@....pdata...u.......v..................@..@.rsrc...h....@......................@..@.reloc..(....P....... ..............@..B........................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
    Category:dropped
    Size (bytes):20448
    Entropy (8bit):6.609836057172314
    Encrypted:false
    SSDEEP:384:5qugrrDncEH5vfoXZSf+VIYinvyhIPxh8E9VF0NyWKYoXD:5qugDcEdfoW/Yin0IPxWEcgXD
    MD5:2213ED7526E8896D195B30E342FC1DC6
    SHA1:6ED5D871B7AA7F7823069077EFD84AD5BAA72A1B
    SHA-256:60D52006D3A62A9D5FDB9E64D7F4723E24FD84F81012D6DE391C06C778CDAB2E
    SHA-512:01B2134C9BB60D7A61F32C176DC977B1F83B7FAA93974CAA5375BC456994C62F4C7F57BAADDC290B4704BE662E8B2363446B58061565D721E61CB58C30896897
    Malicious:false
    Reputation:low
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..........3..`..`..`.b2`..`..$`..`...`..`...`..`s.$`..`..`..`s..`..`s.%`..`.."`..`s.'`..`Rich..`........................PE..d......d.........." ................$........................................p.......I....`..........................................#..G....#..P....P.......@....... .../...`.......!..8............................!..p............ ...............................text............................... ..`.rdata....... ......................@..@.data...`....0......................@....pdata.......@......................@..@.rsrc........P......................@..@.reloc.......`......................@..B................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PE32+ executable (console) x86-64, for MS Windows
    Category:dropped
    Size (bytes):23008
    Entropy (8bit):6.6426979925450915
    Encrypted:false
    SSDEEP:384:oTEl+NN3j+GMiW3t+eE9ZSf+VIYinvyjZPxh8E9VF0NytPNu:qEgPqGVatjEk/YinGZPxWEjFu
    MD5:C4438FE282E3BBFA9F734F5E9369E91C
    SHA1:1FC0417F6331E3DF923B1CBA3FAAF6B596325A22
    SHA-256:3A671DBC61E87AF9BB5A352B2E3FDA2F3A463357C993168F3810CE375CAF42EF
    SHA-512:BCC7408ADDDE5D701AD883E49D1092B54F867D32B89F59D5A8D6099678FD371BDFF1B0B2ED7B71FB6424127DD0D11F8041934D074AF244106B0F3D0925155456
    Malicious:false
    Reputation:low
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.............~...~...~..-....~......~......~......~.~L....~.......~.~L....~......~.~L....~.Rich..~.........................PE..d...?..d.........."............................@.............................p......ld....`..................................................$..P....P..,....@.......*.../...`..0....!..8............................"..p............ ..H............................text............................... ..`.rdata....... ......................@..@.data........0......................@....pdata.......@......................@..@.rsrc...,....P......................@..@.reloc..0....`.......(..............@..B........................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
    Category:dropped
    Size (bytes):165032
    Entropy (8bit):6.488803132884622
    Encrypted:false
    SSDEEP:3072:eN0DIfu+d7K+TniSCP6KFinG2VZV2GNrAfdjpwlb/Ox3:eSiZVKod5lmVEbW
    MD5:E316240D5893A3CE2162AB5CA7A867B8
    SHA1:CB9F61557DD48E6C2CB1406CE23E58B5DFF52D58
    SHA-256:A1D09A04009D1482128BE2CD44E4B45F1082761EA2423B8437599CB44B727FC9
    SHA-512:80E6396A8967FD49AE028AFB73C312BBAA10718597B89FE72F9EC15F3103E93D4E0CC54C4314EA9F05C7C79609EEE846BB0186C56C3D112F38B850EFFBFEFAC6
    Malicious:false
    Reputation:low
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........\cC.=...=...=...l...=...l...=...l...=..a....=...l...=..a....=.......=...=...<.......=.......=...o...=.......=..Rich.=..........................PE..d......d.........." ................$...............................................5.....`..............................................=..8........p.......`..0....P...4..............8...........................@...p.......................@....................text............................... ..`.rdata.............................@..@.data...x....@......."..............@....pdata..0....`.......8..............@..@.rsrc........p.......H..............@..@.reloc...............L..............@..B................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
    Category:dropped
    Size (bytes):15688
    Entropy (8bit):7.05326929120364
    Encrypted:false
    SSDEEP:384:yW2hW2ZSf+VIYinvyE0Pxh8E9VF0NyiOChsK:Ko/YinN0PxWE4XhT
    MD5:47FCB0AB796453CE12AAED855A01D5C1
    SHA1:B27E44A34911ED245683D87BB5594AE10BD0287B
    SHA-256:440E754F694CA81753D14B575CB768B7C3EC74889AB9AEEBC75456F49829381D
    SHA-512:F507CA571BAA18900DB8FD5BDA8D89F816DA3487371F65D9E1ABD96A5C2D3B52361C8A33D9EDAB916CDDC1958A4F36ED1A39DCBE0DDE3A90192AF9AA52F67FF7
    Malicious:false
    Reputation:low
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......m2..)S..)S..)S....].(S....A.+S....^.(S....C.(S..Rich)S..........................PE..d...48.U.........." .........................................................0......8.....`.........................................`...+............ ..................H/..............8............................................................................rdata..@...........................@..@.rsrc........ ......................@..@................................................................................................................................................................................................................................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
    Category:dropped
    Size (bytes):17224
    Entropy (8bit):7.052904077087452
    Encrypted:false
    SSDEEP:384:K81nWm5C0W2hWdZSf+VIYinvyTGbYPxh8E9VF0NyRN8W:KOnWm5Co9/YinI8YPxWEjv
    MD5:8BD9CB1D60F83099F155E30A8DDFD4E9
    SHA1:BEFD7C80FF2459C3545C3B6879DD0DA28DA937EB
    SHA-256:1EF1C997B2967643E22380399CF8435B7D026A4A396834B77011C0D5883A97E3
    SHA-512:75099B27670B19A7FBB6CCFD2DCDAD37683568ABAF2818846DCDBED36ABDB54358346B7D5E714183B379D4FC1F69CAFC0BA164F213CDD36294AC84F4F32EDB24
    Malicious:false
    Reputation:low
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......m2..)S..)S..)S....].(S....A.+S....^.(S....C.(S..Rich)S..........................PE..d...48.U.........." .........................................................0............`.........................................`................ ..................H/..............8............................................................................rdata..............................@..@.rsrc........ ......................@..@................................................................................................................................................................................................................................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
    Category:dropped
    Size (bytes):28200
    Entropy (8bit):6.579489331505171
    Encrypted:false
    SSDEEP:384:YY7PzypxjIncO/+CL8bMz6wh2bQssx0xhKSZTTAMKfeZSf+VIYinvyqRTPxh8E9H:d7zXc6L8MdsCSWMKfd/YinXPxWEtFc4
    MD5:59B8BF75C9C46AE9137031AC2DA7F6A0
    SHA1:EA694303F7A02BBA4DB3BE00E81E1A4A7559F526
    SHA-256:9C0CC2F7993268A71FC74146B12870DE79CF4F3A135B9668201D41EE9417E53D
    SHA-512:D80AC56AD2C9FFF02FAE814D8A91BE532F3DD0BADCF3A9603157BE6F42449DC10A444C0F470EC4DBBEF49222494821EEEBE46FE6F93A90B64D55092AD8DA9C46
    Malicious:false
    Reputation:low
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......Z.A.../.../.../.XO.../.XO.../.XO.../.XO.../....../....../.....X./....../....../..L..../....../.Rich../.........................PE..d......d.........." .........$.......!....................................................`..........................................9.......<..d....p.......`.......>..(0...........2..8............................5..p............0..H............................text...;........................... ..`.rdata.......0......................@..@.data........P.......4..............@....pdata.......`.......6..............@..@.rsrc........p.......8..............@..@.reloc...............<..............@..B........................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
    Category:dropped
    Size (bytes):15176
    Entropy (8bit):7.065311182941968
    Encrypted:false
    SSDEEP:384:nW2hWPhZSf+VIYinvyf5Pxh8E9VF0NyUZJi:5l/YinE5PxWEWS
    MD5:B6A83D3B43CD2ED9BE0D07662AEF5A85
    SHA1:0AFDECCBD715EDA072339EA2323B69890972B072
    SHA-256:86DB6BF39F150D6C1CFE4BE61A6D588797FDAB8DB08C5392DB08C07619AB122B
    SHA-512:1650769E902B4BFABD2FCC27FD9E5CE24460086F4132053FF977DE61C983B7EF8E5388D1AF2BE86E46BB97CDE5FEFF187BFA4CBB6EC6ED29ABFEDE1975B2FB6B
    Malicious:false
    Reputation:low
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......m2..)S..)S..)S....].(S....A.+S....^.(S....C.(S..Rich)S..........................PE..d...48.U.........." .........................................................0............`.........................................`................ ..................H/..............8............................................................................rdata..0...........................@..@.rsrc........ ......................@..@................................................................................................................................................................................................................................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
    Category:dropped
    Size (bytes):16200
    Entropy (8bit):7.040979621733753
    Encrypted:false
    SSDEEP:384:2itIDW2hWIZSf+VIYinvyHPxh8E9VF0NyUAMGC:nma/YinkPxWEWPGC
    MD5:B7C9813E69B0D43BAEBBDB9B7CB27B00
    SHA1:D2E059DDF44192D22292E346FA7F7106E5D12932
    SHA-256:20F5B74259F95ADD4B397B60AB4AD77CE138A5F40483CE1A7B76B65F6EC55237
    SHA-512:FA5E012EFE6480CC6B6E38D8F7F16350459FDCD4F28A8FBA8653AE1CF56BD39BD8057E87614CE5337A1B83AD47CB6438454258EE660D8DCEB9634E8483D62679
    Malicious:false
    Reputation:low
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......m2..)S..)S..)S....].(S....A.+S....^.(S....C.(S..Rich)S..........................PE..d...48.U.........." .........................................................0......h.....`.........................................`...x............ ..................H/..............8............................................................................rdata..............................@..@.rsrc........ ......................@..@................................................................................................................................................................................................................................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
    Category:dropped
    Size (bytes):15688
    Entropy (8bit):7.108931656139864
    Encrypted:false
    SSDEEP:384:ABfKW2hWUZSf+VIYinvyx7o8Pxh8E9VF0NyVyQz:ufSa/YinidPxWETv
    MD5:E865E4BD39DECDDAAF42DBE9B7DB5D6C
    SHA1:47D92A6EA768D412DF5F8505B45ADEC3C2CF148A
    SHA-256:A2FE6FC1D817086482786612C645CC2CADA4329A6746FB1303AE3DBCA2BA47A3
    SHA-512:75A7E617C6F7437DFA33444AA2397DAB19E3921B530A0794D55207976E5C3F957686387F93BD66CF7A1809265316EEDB71848EF3DCDB30D0F61CE4167B442A1E
    Malicious:false
    Reputation:low
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......m2..)S..)S..)S....].(S....A.+S....^.(S....C.(S..Rich)S..........................PE..d...48.U.........." .........................................................0.......S....`.........................................`...^............ ..................H/..............8............................................................................rdata..t...........................@..@.rsrc........ ......................@..@................................................................................................................................................................................................................................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
    Category:dropped
    Size (bytes):15176
    Entropy (8bit):7.098352941489917
    Encrypted:false
    SSDEEP:384:WW2hWrZSf+VIYinvyIfAJwPxh8E9VF0NyVy/xE:+f/Yinz0wPxWETJ
    MD5:4FC47882F5ED024557EFC24ACE0BE4EB
    SHA1:1BDEC4C8E5965D9005E0BEC3523FC780B01A262B
    SHA-256:FDBE884E5F07D014633AEAC41DFE01D8D8AF87828A602E10F54440FD90914F46
    SHA-512:A997D1313EF6BC48115B83CA3C4246FF697BA1AC24D8D7495B34FA0BE03C339AE0775F57B1581B8F694C6D6E92FDDC543D3ED8DD80DEC74752815F954627D35A
    Malicious:false
    Reputation:low
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......m2..)S..)S..)S....].(S....A.+S....^.(S....C.(S..Rich)S..........................PE..d...48.U.........." .........................................................0......S5....`.........................................`................ ..................H/..............8............................................................................rdata..............................@..@.rsrc........ ......................@..@................................................................................................................................................................................................................................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
    Category:dropped
    Size (bytes):94280
    Entropy (8bit):6.409731774151164
    Encrypted:false
    SSDEEP:768:x0dJcSPNc9voEGsVjikhL0hqbTKgiPATI6BWUHo467ElkGOMW/DQdlS32pwOSEw4:Kdn2P2X4lkG/dpHS3zH9yKxP/7wPxH
    MD5:1D15987E31BEBBD79D8A96AD10FF35AB
    SHA1:53CA5AF9DEBE8586AF8C1EB8DA1B8BA9997B7FF7
    SHA-256:45DDDF94B9E0B01A16ED39701FBE03C259C6BA2A0894997816DE5BC9FDCF59B3
    SHA-512:01B90CD297D7D691F9D04F133AAE2B526C713E21B2EA2F0D873AE653F899B26D9F4E53DFAD4C148E8CEE87A6D5381BBB2A64613356EA0981B623D734D8ACC136
    Malicious:false
    Reputation:low
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..........W...........0....................................................\...........Rich...................PE..d......d.........." .........P.......................................................M....`.............................................h....+..d....`..x....P..<....>..H2...p...... ...............................@................................................text...3........................... ..`.rdata...0.......2..................@..@.data...H....@.......&..............@....pdata..<....P.......(..............@..@.rsrc...x....`.......8..............@..@.reloc.......p.......<..............@..B................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
    Category:dropped
    Size (bytes):15688
    Entropy (8bit):7.0530877782988215
    Encrypted:false
    SSDEEP:384:IGeV5W2hW+ZSf+VIYinvy6X6Pxh8E9VF0NyK/pt:IGeVXI/YinuPxWEwP
    MD5:65EA8AB1DE2390410E1A60AB28A9C8BF
    SHA1:050A44E3FB849FB958ECA9D8E30A0CBC3CE4A783
    SHA-256:0A5092F75CEB575A152215C0B0D90F48AB2BBA24F413830F2439723351802398
    SHA-512:87EB74229E110414BFCE5E4C43520BDBAC324DA098952763B1E1DBDE0230B059131C7E362E91B22831117C5B7237556135792E7ABC93EE019E49A552F598FF5E
    Malicious:false
    Reputation:low
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......m2..)S..)S..)S....].(S....A.+S....^.(S....C.(S..Rich)S..........................PE..d...48.U.........." .........................................................0............`.........................................`................ ..................H/..............8............................................................................rdata..,...........................@..@.rsrc........ ......................@..@................................................................................................................................................................................................................................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
    Category:dropped
    Size (bytes):15176
    Entropy (8bit):7.158949653786833
    Encrypted:false
    SSDEEP:384:qW2hWLJZSf+VIYinvyOmXPxh8E9VF0NyYGzB:yIY/YinUXPxWEC6B
    MD5:E7AEF54B5A6BB086E449684EA0EF3898
    SHA1:1406488BF0C755810C124461CB09E01EDBB845C4
    SHA-256:ED9E6E480CEB5DC30B5AC8D06F31DB9CD40D8022ED6EAC01EA53E50E54BB69AD
    SHA-512:316387F08BD64018EE349E787903A3EB739CBCF8C7B3475AE5F8201B5D444885F315675975C0CBE96384E357B6247BC4F10A5E2A19199641FB2B925E8FECB7E6
    Malicious:false
    Reputation:low
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......m2..)S..)S..)S....].(S....A.+S....^.(S....C.(S..Rich)S..........................PE..d...48.U.........." .........................................................0...........`.........................................`................ ..................H/..............8............................................................................rdata..............................@..@.rsrc........ ......................@..@................................................................................................................................................................................................................................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PE32+ executable (console) x86-64, for MS Windows
    Category:dropped
    Size (bytes):23008
    Entropy (8bit):6.644608185157491
    Encrypted:false
    SSDEEP:384:TTEl+NNBs+GMiWyOEeEqZSf+VIYinvybz0Pxh8E9VF0NyCAOlT:/EgP7GV/OhEx/YinCz0PxWEAZlT
    MD5:F2484459C1FAA94BD52A4B227FC16750
    SHA1:1408CFABF10956E8559B2E492E243C97A1AC7F29
    SHA-256:E4271F6FEFF943B1805ECA21DDF4800602C4FE18B7579F0F2F3A834B55FF5F3F
    SHA-512:75CB92F2ACB4DB825B0407E7272295F09F360F72B87B9CF3A6116634C95B98219964F0EDA8906B13C5ACAEEE84EBDA20A6D0195C82BF10AED2BAF427128AEED5
    Malicious:false
    Reputation:low
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.............~...~...~..-....~......~......~......~.~L....~.......~.~L....~......~.~L....~.Rich..~.........................PE..d...?..d.........."............................@.............................p......T4....`..................................................$..P....P..,....@.......*.../...`..0....!..8............................"..p............ ..H............................text............................... ..`.rdata....... ......................@..@.data........0......................@....pdata.......@......................@..@.rsrc...,....P......................@..@.reloc..0....`.......(..............@..B........................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
    Category:dropped
    Size (bytes):155232
    Entropy (8bit):6.328721499283281
    Encrypted:false
    SSDEEP:3072:QioxYSuV5Qyrml5VtkWKrazkw60EKr65LizjUu/rNI7gIL8SL9wFxHBiKzXDwE/o:QioxYHV5QEmBtJljUADFqQe
    MD5:087A190AF59EEDB613177196A030D3DF
    SHA1:1EB5F3E90F12996FA0B86FB77BE4FEA24F73E7EF
    SHA-256:28E387F9B539C79D3F5D49481670B7DB74CC7E2C0050FC1EB1BF09F07CED103D
    SHA-512:BF5CB4CE67D1A49CFCB8B669F1DD1B019BF6F839E4CB5811CA1AE5913A194D91FC8CBE44DACEF6BA8FEEABCA883B1A6452B7B8C111E19359EFEC43257CD1EFA0
    Malicious:false
    Reputation:low
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......V.....{...{...{.T....{.T....{.T....{.T....{..}....{...z.Q.{......{......{......{......{.Rich..{.........PE..d....d.........." .........2......l........................................p............`.............................................8.......P....P..`....@.......*..`4...`......`...8...........................0...p...............(............................text............................... ..`.rdata..............................@..@.data...0....0......................@....pdata.......@......................@..@.rsrc...`....P....... ..............@..@.reloc.......`.......(..............@..B................................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
    Category:dropped
    Size (bytes):78264
    Entropy (8bit):6.380913876021054
    Encrypted:false
    SSDEEP:1536:UcL4pgJDdzpYJGTtDRU/4Y4tyJfMUQdY/7gPx:UcL4iDzSERDRU/4LtyJftQdY/8x
    MD5:D1F1BF9C12E0DA2B7F0440A09E09E4ED
    SHA1:F6DFBA5FC5AFA7F8DB5BE67D4378F2322238558B
    SHA-256:609E161541B732BD99E02D3234EBDA1187F1AC067A1CB92A54D7FE9DC453978A
    SHA-512:EA63D97FDF66A07DCE92C3772BFDECF682E48FA69CCEC53513DD4D38B887A68341916437E3658A6034EB0987E329B536783AE77373842ACEAEF9E07E93F79335
    Malicious:false
    Reputation:low
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$................................])[......................................k......k......k......k.c....k......Rich...........PE..d......d.........." .........z...............................................@......k.....`.............................................P...0........ ..x................1...0......@...............................`................................................text...<........................... ..`.rdata..2Y.......Z..................@..@.data...............................@....pdata..............................@..@.rsrc...x.... ......................@..@.reloc.......0......................@..B................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
    Category:dropped
    Size (bytes):41624
    Entropy (8bit):6.653820983565276
    Encrypted:false
    SSDEEP:768:hjJg1KaWGCzh5yRtxd9wE9NW2t8sGb/YindPxWEScv:hjBcmop9NWUTi/7dPxP
    MD5:F7F1FE8EA6BE1D347986CC28CF9EA99D
    SHA1:36C1B15442957BE6C6AC61B0754E3092BF5D7B98
    SHA-256:3D6797978F0ADDF7741CB98511FDB3CCFC499CDDA023E1AAD22255151C01D229
    SHA-512:B7FC9314F7201D647CD7B6FF7CE317E22049222C2231492D92647B65B3A88AC4D66B73F020D51839306E882C9E5BEC6EF5B4F9E6098E0B65EDF75160E00F2DF7
    Malicious:false
    Reputation:low
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$............hx..hx..hx.9...hx.9...hx.9...hx.9...hx.,....hx..hy.hx.D....hx.D....hx.D....hx..:...hx.D....hx.Rich.hx.........PE..d......d.........." .....B...2......\L....................................................`..........................................k..B....u..P....................r...0...........b..8...........................0g..p............`..h............................text....A.......B.................. ..`.rdata.......`.......F..............@..@.data................d..............@....pdata...............f..............@..@.rsrc................l..............@..@.reloc...............p..............@..B........................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
    Category:dropped
    Size (bytes):75192
    Entropy (8bit):6.445856214989772
    Encrypted:false
    SSDEEP:1536:w3otkkyrm/YX/Ft17Qwm69cNqxV6FSP59XvhRFPSe3QNsqVolyHbsPUNhUGhOBay:TtkZEYdt1kwm6KNPMScWn/8x
    MD5:259D58D221DE3F5504ADB2719147A13A
    SHA1:B3714C73519A828A1D3ED7E7298D30E30507240B
    SHA-256:F1FF565295ED163916B7ACD4A08438DCE54CA1F961E3D251474399BCB3DD91A8
    SHA-512:B96261ECA58C388F67A8D992F9E27D97C44F685845BD1CE8591DB614193B399F1D769D76FC03B28EE73C49DD41DFBDD286BBF5E3DD2C8B6F57B3960ACE62DEA4
    Malicious:false
    Reputation:low
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......f..."..."..."....(.. ...".......d...!...d... ...d.0.)...d.1. ...I0.,...I..#.../...#...I..#...Rich"...................PE..d......d.........." .........J..............................................@.......j....`.............................................;.......<.... ...................1...0..........8........................... ...p...............h............................text...{........................... ..`.rdata...1.......2..................@..@.data...............................@....pdata..............................@..@.rsrc........ ......................@..@.reloc.......0......................@..B........................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
    Category:dropped
    Size (bytes):21360
    Entropy (8bit):6.797954578755605
    Encrypted:false
    SSDEEP:384:97x0C5yguNvZ5VQgx3SbwA7yMVIkFGlHW2hWa/ZSf+VIYinvyT/JPxh8E9VF0Nyt:H5yguNvZ5VQgx3SbwA71IkFCPe/Ying5
    MD5:DFCFB8ADE4EDD7EF39B52C5997777576
    SHA1:8BA7BC223AB0740C8437C23479ED396BE9892AEC
    SHA-256:7F7AF4A9A22EE2CFF6932DD4BF810AA44A1AD474061D16B86DDBF5096B5AE8BF
    SHA-512:BCFE1AFAFD2D95885D063AD0327F6D6A4833317C9FF0E43F18726BB3A6D0CC6F5659AF642500EF9F3B10792CF238BED970616701245CDB3C3425EA198F36BBA9
    Malicious:false
    Reputation:low
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......m2..)S..)S..)S....].(S....A.+S....^.(S....C.(S..Rich)S..........................PE..d...48.U.........." ......... ...............................................@............`.........................................`................0...............$..p/..............8............................................................................rdata..............................@..@.rsrc........0....... ..............@..@................................................................................................................................................................................................................................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PE32+ executable (console) x86-64, for MS Windows
    Category:dropped
    Size (bytes):41072
    Entropy (8bit):6.182315734270929
    Encrypted:false
    SSDEEP:768:4M1V+4JYjwaYJeSfrQQU89ga/YinPEPxWE5bAku:4M1V+tjPYJeSfro+ga/7PEPxrc
    MD5:4FFC9AB02109273D5B0F7760E5E0B5C4
    SHA1:B211889B8F966A35C4E57F0975C74B8C909514EE
    SHA-256:B7EBCA9BF4E0B9CEAFA47964B2444B510615CDB61B495F375470FDE44C6467C5
    SHA-512:7733CB1F44876B7D1AC6068E4F55EB4E9FC2EEBA26C7E4AC81A578B461E5E891C36914B91213E88F17F72A24CE825933CBB05CC760F66E83EC331DC63B405BBC
    Malicious:false
    Reputation:low
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..........n...=...=...=..3=...=..1=...=...=...=...=...=If%=...=...=...=!..=...=..5=...=!.0=...=Rich...=........................PE..d...?..d.........."..........>......d/.........@....................................b.....`.................................................tb..x...............L....p..p0...........C..8............................^..p............@...............................text...[-.......................... ..`.rdata.."+...@...,...2..............@..@.data...p....p.......^..............@....pdata..L............`..............@..@.rsrc................d..............@..@.reloc...............n..............@..B........................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
    Category:dropped
    Size (bytes):661352
    Entropy (8bit):6.3542602532236145
    Encrypted:false
    SSDEEP:12288:vOB4p+q4N8d4l2ms4cTHN+m+gy/vEPYysExtvsIvX71A+2EKZm+GWodEEpvY/:sAtvsIvL2EKZm+GWodEEpvY
    MD5:BCFD4DFCEF123ED5216E930F41B2B135
    SHA1:44B5C3C3F204A754D852C88A166960145C781774
    SHA-256:C6F4BB7BE33BDA2DC8AAD57C3D67EF04A07C5210CCD7DD74FC286E548F0D1FEA
    SHA-512:AD2949DF34FA9AB3E1BB8FEC8402E3E173F414911FC86877E8ECD4DA4B317FADC600F94573A1F101D9CB3E74BE70B7068CCCE0319D498C36AECA3A32F1D77F5C
    Malicious:false
    Reputation:low
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......C..=...n...n...n..*n...n...n...n..<n...n.@&n...n..>n...n...n4..n...nJ..n...n...n..=n...n..:n...n..?n...nRich...n........................PE..d.....~W.........." .....>...................................................`............`.........................................PU.. ...p2..<....@...........G......hE...P.......X..................................p............P...............................text....=.......>.................. ..`.rdata.......P.......B..............@..@.data........P...8...@..............@....pdata...G.......H...x..............@..@.rsrc........@......................@..@.reloc.......P......................@..B........................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
    Category:dropped
    Size (bytes):15176
    Entropy (8bit):7.10981536413712
    Encrypted:false
    SSDEEP:384:ghRW2hWvZSf+VIYinvyrhRPxh8E9VF0NyMdy:ghf7/YinmPxWESE
    MD5:2A798C36507CB7DB1A4CFD491531D0EF
    SHA1:06EADD4701A89B1479152F8C90B882E33AAF9F29
    SHA-256:713BFF07B81FD4A05959272F890EE14C7285E6EB48D9F5399C6DE4265C8C9879
    SHA-512:67BF12BAE83F1CF7BAEA94D27C15F4C889C6A0A0FF53E61A652875261060C031F6BB50DC03598B4AF3AB6561B7C7316770B5B5331B7CD549DEBC68AA9D3D50BA
    Malicious:false
    Reputation:low
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......m2..)S..)S..)S....].(S....A.+S....^.(S....C.(S..Rich)S..........................PE..d...48.U.........." .........................................................0............`.........................................`................ ..................H/..............8............................................................................rdata..............................@..@.rsrc........ ......................@..@................................................................................................................................................................................................................................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
    Category:dropped
    Size (bytes):15176
    Entropy (8bit):7.068104874537084
    Encrypted:false
    SSDEEP:384:6W2hWJZSf+VIYinvy0MPxh8E9VF0NyYjbMq:CJ/Yin2PxWECP7
    MD5:F96F4ED83CFBE0B1D50D9F6F526260DA
    SHA1:B5ABB02C92875DB4E3344D71D72DF2F31A80A57A
    SHA-256:588AF1D06BEC72508B7D170D421E9454046430C6CD7C43707CE8E5014B4F4C9B
    SHA-512:A59D1F2C310BAED095A4C84F810A0C0BB49E3CA1E00BE224E3C4CF25721B591E86EF64377803F5936C879ADF6CB3B9563010A40404539A13D4B81E643DDE9279
    Malicious:false
    Reputation:low
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......m2..)S..)S..)S....].(S....A.+S....^.(S....C.(S..Rich)S..........................PE..d...48.U.........." .........................................................0......Ux....`.........................................`...9............ ..................H/..............8............................................................................rdata..L...........................@..@.rsrc........ ......................@..@................................................................................................................................................................................................................................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PE32+ executable (GUI) x86-64, for MS Windows
    Category:dropped
    Size (bytes):232136
    Entropy (8bit):6.61617857971722
    Encrypted:false
    SSDEEP:6144:UdTu3dFROMWcTJQ/Tg2H+HVr5sVmmjYvBw7k/GCGf:Ud63dF/WaJm+1vKmOCGf
    MD5:761037FC0CAB99034C289B4A34E3C4B8
    SHA1:CA8E146C8AB4596B75B2C7C40D1A7F0D39D6D952
    SHA-256:941990CA86AFF8417FBF053E6BBD1EF4103A422E5BEC584C62341F2D071C1C98
    SHA-512:6586657BF3A2230605FF771734D1048ABEB990B9E65FB1467E57EEF64A0A02B9F06B0C1D9EBB5B35901EFB16A0D43CFA1CF80BF8AF62A19043BCEB08F2C4266B
    Malicious:false
    Reputation:low
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......&...b..Mb..Mb..M.c.Mj..M$.<MN..M$.=M...M$..Mi..M.<.Mk..Mb..M...M.]=Mm..Mo..Mc..M.].Mc..MRichb..M........................PE..d...>..d.........."..........r.................@.....................................f....`.....................................................d.... ...o...........T...6..............8..............................p...............P............................text............................... ..`.rdata..............................@..@.data....?..........................@....pdata..............................@..@.rsrc....o... ...p..................@..@.reloc...............N..............@..B........................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
    Category:dropped
    Size (bytes):21472
    Entropy (8bit):6.5346553295047975
    Encrypted:false
    SSDEEP:384:qW2PbetIT2yJUYAMJyuzDZZZSf+VIYinvygmPxh8E9VF0NyTjgq0:t2P4+2yTAiyuzi/YinaPxWE9jc
    MD5:043DBADE6EAC1EC65A534660E16DAD94
    SHA1:F75ED332D151C701B457A628B9C62A7F1BC2F02B
    SHA-256:4F9667F1E260F2182F7D74CA73F5245FAF5815A94D7FE091DF952168CDD9B0EE
    SHA-512:1013AC52A9CA8DCABD13E74A35CA53FF42120F5F3A344DC447FD24AB6435AB221D0B3390B6759C9018DFE8CF015A7E2B4C15C55D71E0D736874615CDF2DC58A6
    Malicious:false
    Reputation:low
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........4...U...U...U....u..U....H..U....I..U..`.u..U....c..U...U...U..`.I..U..`.t..U....s..U..`.v..U..Rich.U..........PE..d......d.........." ................X........................................p.......,....`..........................................#......|$..P....P..`....@.......$.../...`....... ..8...........................0!..p............ ...............................text............................... ..`.rdata....... ......................@..@.data...X....0......................@....pdata.......@......................@..@.rsrc...`....P......................@..@.reloc.......`......."..............@..B................................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
    Category:dropped
    Size (bytes):15176
    Entropy (8bit):7.180093326471072
    Encrypted:false
    SSDEEP:384:eW2hWuyZSf+VIYinvymHPxh8E9VF0NybnyANvM:2P/YinbPxWEtS
    MD5:AEA82BFEBA0B64D79348A08E08F56977
    SHA1:29480C8B523EB5D986D8704AEBA57350A2339AC9
    SHA-256:A9B268A03B233362AF12F9AF5421F32D37B1E14B525D91EAF3E976CA8023AE5D
    SHA-512:84D954912396D7C830B7C2812A0AD2FC5468CCB871505E34E7903DCEAFE72899CB5B9446404C1423C6ABA39ECD0543EF7A89D10215BD14D400796876E558FBC6
    Malicious:false
    Reputation:low
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......m2..)S..)S..)S....].(S....A.+S....^.(S....C.(S..Rich)S..........................PE..d...48.U.........." .........................................................0......Z.....`.........................................`................ ..................H/..............8............................................................................rdata..............................@..@.rsrc........ ......................@..@................................................................................................................................................................................................................................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
    Category:dropped
    Size (bytes):15688
    Entropy (8bit):7.1119732703427525
    Encrypted:false
    SSDEEP:384:SvuBL3BaW2hWiZSf+VIYinvyOPxh8E9VF0NyWCJM:dBL3Bis/YinLPxWEAyM
    MD5:818E7DFABF5CB0EF89A3B62FDAE6630A
    SHA1:F1DAE6D4782A80ED1FE2661D56D4914DD649C210
    SHA-256:02A565B7C7101A44BC152DDC5D52BCF682FDF70C576B84931991E6622DA23243
    SHA-512:CD9BC4948E6AFD68E1D3165AD02EF533A9BAA0F17E43C7238E85A0222D159B36C9A9C1D94ECAC93FFB4B8131680BE9C4D22C79D04C5CD5581632D94DBC4C8A5A
    Malicious:false
    Reputation:low
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......m2..)S..)S..)S....].(S....A.+S....^.(S....C.(S..Rich)S..........................PE..d...48.U.........." .........................................................0......Eh....`.........................................`................ ..................H/..............8............................................................................rdata..(...........................@..@.rsrc........ ......................@..@................................................................................................................................................................................................................................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
    Category:dropped
    Size (bytes):27176
    Entropy (8bit):6.61133531112702
    Encrypted:false
    SSDEEP:768:6y8jFGOI56+FEJTAlw+/Yinh60bPxWE5D:rCUW+FEFAu+/7Q0bPxT
    MD5:3F5D3DF80B880FAF1089D0E72971981B
    SHA1:E059D3DE704E87C2920F42D6D5D0E3146110A87E
    SHA-256:B7D6263035D3C5AAD15EBE991BFD1B537591AF5E5C814534DC2FE276BB7CAC69
    SHA-512:134907ABD8215C0BA8FB9BD44A84325C94A284C3DCA2C1D377B87AD320B0B59FB44AA21523798E0F5D668FFDA2E8F214363AB8812C22BEB4DCD756CEE5434AE5
    Malicious:false
    Reputation:low
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......o...+..+..+..m...)..m.:."..m.;.)...j..,..+.......:.*......*..&...*......*..Rich+..................PE..d......d.........." ................<#..............................................!.....`.........................................P:.......;..d....p.......`..8....:..(0...........1..8............................7..p............0...............................text............................... ..`.rdata.......0......................@..@.data...X....P.......0..............@....pdata..8....`.......2..............@..@.rsrc........p.......4..............@..@.reloc...............8..............@..B................................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PE32+ executable (console) x86-64, for MS Windows
    Category:dropped
    Size (bytes):232136
    Entropy (8bit):6.610124494347498
    Encrypted:false
    SSDEEP:6144:s8CFPz4JnbQsXT2cDnP5wgbG8YPu7k/jily:shPzWncs/nNBC7ily
    MD5:E5A23D488E464346181A6139733DC2D9
    SHA1:ACDD3D93DC06D85351A50AD7D18A1C1FC34C8E7C
    SHA-256:0AC8A2595D15812C3E63FD5D65C6BBA672927263168712EA3BBCB2FD4F29132E
    SHA-512:C4FE04E9DCEB4A3D6246202D283245DAB8B0DE40A384A014E6FE960389B9692E2883E6749BFE432555C0033322C314851973584F5C72997233F56F8359722B1A
    Malicious:false
    Reputation:low
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........As.. .L. .L. .LH..L. .L.q.L. .L.q.Lw .L.q.L. .L...L. .L. .L. .Lc..L. .L.r.L. .Lc..L. .LRich. .L................PE..d...>..d.........."..........r......8..........@..........................................`.....................................................d.... ...o...........T...6..............8..............................p...............P............................text...,........................... ..`.rdata..............................@..@.data....?..........................@....pdata..............................@..@.rsrc....o... ...p..................@..@.reloc...............N..............@..B................................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
    Category:dropped
    Size (bytes):21352
    Entropy (8bit):6.813058782813075
    Encrypted:false
    SSDEEP:384:k3vAmiFVhEW2hWxQ7ZSf+VIYinvyaKyPxh8E9VF0NyZaND:avYWAQS/YiniyPxWE/8
    MD5:E84FA99E5CD3408538E706389D94F5BD
    SHA1:339C30956CBEE584D0E9A8280706022F3882C4E4
    SHA-256:706C13B91475DFFDEAE4DEE1F253C327AD44388E483B7D097B7FADADC9BC01CE
    SHA-512:CFD4908BD231D7B0C3F4CBF41905B031BEF7F533A8DAAA7AAE3A61B545BF9C691F319B616A530C3E8E66B85FE654D6F490F68AB294455FB0BB8275884AC6F119
    Malicious:false
    Reputation:low
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......m2..)S..)S..)S....].(S....A.+S....^.(S....C.(S..Rich)S..........................PE..d...48.U.........." ......... ...............................................@............`.........................................`...a............0...............$..h/..............8............................................................................rdata..t...........................@..@.rsrc........0....... ..............@..@................................................................................................................................................................................................................................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
    Category:dropped
    Size (bytes):37488
    Entropy (8bit):6.825595918688525
    Encrypted:false
    SSDEEP:768:+TpH1+idJ0t9atOLJ+wC5qRq/YinkPxWEjM:+9dJk9kwCCq/7kPxK
    MD5:78365ED409D9ACF1801C2A5AED311FEF
    SHA1:10F518CC1E24B0814555B8F9462E7E0F239AFF27
    SHA-256:C5DE12A3CAA27A923A6F5B1AA42F934D380FE22B03DC172703D831F6032FEE10
    SHA-512:3233791685BAFBE660EFDBE9AC98E5595B24CF4405F6C2631350AFC23D78D59E2B52BAA680273954AF251C1B8441CEEEFB2AD74986EC57B91E32188DC1D1C832
    Malicious:false
    Reputation:low
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........~W............................................(...............@d......@d......@d..............@d......Rich....................PE..d......d.........." .....@...,......8J....................................................`..........................................W......H\..................H....b..p0...........Q..8............................S..p............P...............................text....?.......@.................. ..`.rdata.......P.......D..............@..@.data........p.......V..............@....pdata..H............X..............@..@.rsrc................\..............@..@.reloc...............`..............@..B................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
    Category:dropped
    Size (bytes):17736
    Entropy (8bit):7.062774156491677
    Encrypted:false
    SSDEEP:384:FOMw3zdp3bwjGjue9/0jCRrndb4W2hWTZSf+VIYinvyLPxh8E9VF0NyVuyQIf:FOMwBprwjGjue9/0jCRrndbMf/YinuPH
    MD5:204616BB853998BAD4CC78286ADD8F5B
    SHA1:0BB90800777AF95E63B871486A1E9CBDD62A1E76
    SHA-256:6BBBFA284A0B6CA73CCAEB1DFB46856CF9D5A359BFD19E10F5C3B5F20E435599
    SHA-512:D2CEC912DFAF0D725B077F2A2872E9708A0DF4D55FDEBCB681EEFD81DD00D0087C0C1175FC41E61B07AEB05A6712151B41A3A899D1C16582B9712EB58997F695
    Malicious:false
    Reputation:low
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......m2..)S..)S..)S....].(S....A.+S....^.(S....C.(S..Rich)S..........................PE..d...48.U.........." .........................................................0............`.........................................`................ ..................H/..............8............................................................................rdata..............................@..@.rsrc........ ......................@..@................................................................................................................................................................................................................................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
    Category:dropped
    Size (bytes):1524424
    Entropy (8bit):6.377702228070813
    Encrypted:false
    SSDEEP:24576:TqMY/jwC90i25wZxKG1UjYvJmrciLAcZe938IuS6IyqD:TFY/jwm0i2iZxKG1UemRWaTSxF
    MD5:D24B649C20BB57635B81F1633AFA0119
    SHA1:290F6945F2506BA23B959E1D7A1ECE22DF713809
    SHA-256:F5EFCB6AB129D79E724D97563B832BC0D5768068031C01DB4796CFFB3142EF04
    SHA-512:7933F4C0787328527D51FD66ADEF9F0E365488F216D1D7625E77417234139438743C95932E9276819C2CB41ADC2B3545F73B098A6FECCB914A8054EE7900801B
    Malicious:false
    Reputation:low
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$............]..]..]...]..]q.4]..]..,]..]...]..]Z%.]..]...]..]2D=]..]2D8]..]..]..]Z%.]...]Z%.]...]Z%/]..]..(]..]Z%-]..]Rich..]........PE..d......d.........." .....p...................................................P......SY....`.............................................................;...............b.......:......8...............................p...............X.......`....................text....o.......p.................. ..`.rdata...H.......J...t..............@..@.data...............................@....pdata..............................@..@.rsrc....;.......<...j..............@..@.reloc...:.......:..................@..B................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
    Category:dropped
    Size (bytes):36432
    Entropy (8bit):6.708523643754813
    Encrypted:false
    SSDEEP:768:ThejNX+y0Wpown4DYwbJXriV8UDm9RL/NSROk0o/YinuEPxWEc:tiSWu+mb/NSTJ/7uEPx
    MD5:F7561ACFBC71805D1E5311AD86D23C98
    SHA1:745B05DDD98119791DC58EBEB431F9149D730962
    SHA-256:0AD0E7DE3F688C24FF2662B8EE3E57035457D325A5A597DB00A00DF8C56ABD0C
    SHA-512:95E62561090C2414BA1EA46EDE93936BF9FC66BFEF7000BA143E9F9E6A042AC5D117420AB920F35CAF81B747BE0E7C2225118D0AE20B1F4F91CEC8865251064B
    Malicious:false
    Reputation:low
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........P...1...1...1....m..1...1...1...`{..1...`y..1...`F..1...`G..1..}.F..1..}.z..1...c}..1..}.x..1..Rich.1..........................PE..d......d.........." .....>...".......E...............................................Q....`..........................................Y..t...DZ..<............p.......^..P0..........pQ..8............................U..p............P..@............................text...K<.......>.................. ..`.rdata..P....P.......B..............@..@.data........`.......R..............@....pdata.......p.......T..............@..@.rsrc................X..............@..@.reloc...............\..............@..B................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
    Category:dropped
    Size (bytes):170192
    Entropy (8bit):6.520041696714836
    Encrypted:false
    SSDEEP:3072:C57b+LWtLdEsZZRvB2vc8Zhbu2yD4QHTE0DUEE2Mvp/Hx2:C57b+LWlasHuHvCnEkUEI
    MD5:285421E6827D99B24A00A921958414E1
    SHA1:0737ABC23C7F002CC82B9BEDEBA6DF32B3C5A477
    SHA-256:867BD016B09C0CF54493FAEEEF4847826C8A1B99ED5C0C9C5B00F550CABDB49E
    SHA-512:ABDBABD929674A2706C308A2D5E55CF2984BFFFB956C16AD60C55C7EC46B5ECA087F93352DB0C25C2C96C6E724220944119256529E6B52636046DB00B87B45A8
    Malicious:false
    Reputation:low
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........F.;u(.;u(.;u(....9u(.}$..9u(.}$..:u(.}$..6u(.}$..9u(....8u(.;u)..u(.....u(....:u(.6'..:u(....:u(.Rich;u(.........................PE..d......d.........." ................T................................................J....`..........................................@.......F..P............`..t....d...4...... .......8...............................p...............h............................text............................... ..`.rdata..T[.......\..................@..@.data........P.......>..............@....pdata..t....`.......@..............@..@.rsrc................^..............@..@.reloc.. ............b..............@..B........................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
    Category:dropped
    Size (bytes):19824
    Entropy (8bit):6.873173691638693
    Encrypted:false
    SSDEEP:384:442r7eW2hWwkZSf+VIYinvyLPxh8E9VF0Ny/2jFa:442r72FD/YinaPxWE9E
    MD5:F3703E1CF2B89A50ABEDE3162CEDC6EC
    SHA1:DD5F057DA2E8EEB1B4D11FD4531A53EB3B0E81C3
    SHA-256:D7EE5DC79F08C2557C70398932F71DA5C4A95D6A73538BA43D949BA3E4FE04F5
    SHA-512:34CDF0640C6BFFEAC58BF009C7BD7ACCC14C93BDE72F6AC4A3AE74943C1C4C111BDC474FFA6897CE3AA38812E1F9B126D4DBC42240C6D6F3BC920C3F7B3B6EAE
    Malicious:false
    Reputation:low
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......m2..)S..)S..)S....].(S....A.+S....^.(S....C.(S..Rich)S..........................PE..d...48.U.........." .........................................................@............`.........................................`...4............0..................p/..............8............................................................................rdata..H...........................@..@.rsrc........0......................@..@................................................................................................................................................................................................................................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
    Category:dropped
    Size (bytes):18800
    Entropy (8bit):6.966765856004169
    Encrypted:false
    SSDEEP:384:RBPvVXgW2hW+GxZSf+VIYinvyyPxh8E9VF0NyYXn:fPvVXEdGA/Yin/PxWEC
    MD5:7DD002C34D6E460A70B0A0B3A5460FDC
    SHA1:9CDCC409BF58BE3FB6902CE5B45234089686847F
    SHA-256:363AFF24415D8F0117CA9A9EDB5391034A91132DF390513A787433501CD377F9
    SHA-512:B49F42355D3F87653FA4BE44C8CA83CBAEA5012CAC07B959CBFCDE6AD6A10C9A80836A3833C55C9653A4831364779D432104A0E70EBCEADAE6AA3A3FC0A9B22D
    Malicious:false
    Reputation:low
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......m2..)S..)S..)S....].(S....A.+S....^.(S....C.(S..Rich)S..........................PE..d...48.U.........." .........................................................@............`.........................................`................0..................p/..............8............................................................................rdata..............................@..@.rsrc........0......................@..@................................................................................................................................................................................................................................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
    Category:dropped
    Size (bytes):208952
    Entropy (8bit):6.444599567076751
    Encrypted:false
    SSDEEP:3072:xkX+gybD/ThD52MtmvLhVmD4VUnG7V1vl3xzPIo/bsTMKt/Mxg:ZNdx4jhH+UsTNF
    MD5:7C9CBD941F6F70725A95E0AA8BE03295
    SHA1:D622843BDD14214989C1A03279A350C4B2D7404A
    SHA-256:AA6E977C587589C4BA34A11F916A05168D2E67C0FF85DF6306878A7B8E4D08F5
    SHA-512:FA7B2942078DCA1277BE1432DB2E657E7C4A38872364A621C10D6D1CE2E490814217288B9918E1710A849D5A70CEC4EE6F54C8D135444DEB4DDBAACD35B8D3A5
    Malicious:false
    Reputation:low
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........{S..=...=...=.|.....=.?.....=...<...=..K....=..K..=..K...=..K...=......=.....=..H..=.....=.Rich..=.........................PE..d......d.........." .....Z...........c.......................................P......@.....`.............................................a...d...<....0..........h.......86...@......`r..8...........................0...p............p..(............................text....Y.......Z.................. ..`.rdata...v...p...x...^..............@..@.data...............................@....pdata..h...........................@..@.rsrc........0......................@..@.reloc.......@......................@..B........................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
    Category:dropped
    Size (bytes):25096
    Entropy (8bit):6.649189010222307
    Encrypted:false
    SSDEEP:384:AsVfOi5WFGf161//UtTJa7ghSPwPP+SnBv0uZSf+VIYinvyz7Pxh8E9VF0Nywq0t:xOKsG8OtTJavSF0t/YinQ7PxWESq3
    MD5:C862103FD4468C393352954598558865
    SHA1:84B5CE6D0118FB3F6F119B885B13C44BB8FFC028
    SHA-256:6F3CA25E3215EA1C898422F31CE03A999A40BA30CA092BFBFF8C2A7666E7C804
    SHA-512:09C7386FB84C48ECFBBF3AD7788BF09504697A7B05A7E60E4D48AEA30F2978D32D5E6953353421AEFAD52B1120DE9A379F582DF4F5AE6B1144FFC697493ED560
    Malicious:false
    Reputation:low
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......v...2o.2o.2o..#.0o.2o..o.t>5.1o.t>7.3o.t>..9o.t>..0o....0o..4.3o.?=3.3o..6.3o.Rich2o.........PE..d......d.........." ................................................................7.....`.........................................@7..'...h8..<....`.......P..h....2...0...p......@1..8............................4..p............0...............................text...[........................... ..`.rdata.......0......................@..@.data........@.......(..............@....pdata..h....P.......*..............@..@.rsrc........`.......,..............@..@.reloc.......p.......0..............@..B................................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PE32+ executable (console) x86-64, for MS Windows
    Category:dropped
    Size (bytes):23008
    Entropy (8bit):6.642311998154307
    Encrypted:false
    SSDEEP:384:ILsl+NN2fqjigLoeEfZSf+VIYinvyuOEPxh8E9VF0NytTjY:SsgPTmgLdE+/YinpPxWEjXY
    MD5:506E5184ADB360D2372C1C3FA707A279
    SHA1:C73C1ADE77E60D109FFDD154686F7B37DCE6D809
    SHA-256:CFC84744309D9A8B8FBD519F8BB3A39867C27CA9338D8710BE9BCDF69531112A
    SHA-512:AC5A3844C030ECFAE673C0B261B8F1B46BD94929B9C45A2A5D4F7AA2AEEDC33436CF09002623147CCB61DBD4A5C7BF7B8779567665500620FC8204DBEA6A1BDE
    Malicious:false
    Reputation:low
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.............~...~...~..-....~......~......~......~.~L....~.......~.~L....~......~.~L....~.Rich..~.........................PE..d...?..d.........."............................@.............................p......Q8....`..................................................$..P....P..4....@.......*.../...`..0....!..8............................"..p............ ..H............................text............................... ..`.rdata....... ......................@..@.data........0......................@....pdata.......@......................@..@.rsrc...4....P......................@..@.reloc..0....`.......(..............@..B........................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
    Category:dropped
    Size (bytes):23448
    Entropy (8bit):6.624420836622734
    Encrypted:false
    SSDEEP:384:VF7vLPmIHJI6/CpG3t2G3t4odXLeW2hWHZSf+VIYinvy/b73Pxh8E9VF0NyTn0:f/PmIHJI6QD/YinQbDPxWEh
    MD5:CEB2308972CC76DC64BF68271FDB72F3
    SHA1:83AD498393DEAED63B5792CAEF36F04E243AE963
    SHA-256:F984E82AEB5F2A89A453E16D10BE44D2A4D1A50BF37932790FB3CB22016B74E3
    SHA-512:3BB2777051AE75CE5CAC99C9D238147AAFEC7AF32641AD5411E74F0DA040D5183FA8308BC271E1714638C1DFDB4F2799D33EF4EB2A887B62D582EDB88C75CFC1
    Malicious:false
    Reputation:low
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......m2..)S..)S..)S....].(S....A.+S....^.(S....C.(S..Rich)S..........................PE..d...48.U.........." .........(...............................................P......y>....`.........................................`.... ...........@...............,.../..............8............................................................................rdata...".......$..................@..@.rsrc........@.......(..............@..@................................................................................................................................................................................................................................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
    Category:dropped
    Size (bytes):17736
    Entropy (8bit):6.961127226076746
    Encrypted:false
    SSDEEP:384:OPEzgW2hWbLZSf+VIYinvyd6XPxh8E9VF0NywEb/QNc:E0Eoi/Yink6XPxWEmM6c
    MD5:B2B543F86F840A000A0526DF52F053B3
    SHA1:ED07A2BCAC659F5B775631B0A7B72132F3249BF4
    SHA-256:F83BC6D68EC09274B5F1FB0185D57D04E40297CEBACA52BBB6312CE887657B7D
    SHA-512:4B4FA6249859938DFBA64AB236F8579C38024BA7F6FA7205B66AAF21EB5C9457ED620F6907A8609A06BB80C8C845EF29165155F0732B0AAAE5A312BE8F442B3B
    Malicious:false
    Reputation:low
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......m2..)S..)S..)S....].(S....A.+S....^.(S....C.(S..Rich)S..........................PE..d...48.U.........." .........................................................0............`.........................................`................ ..................H/..............8............................................................................rdata..............................@..@.rsrc........ ......................@..@................................................................................................................................................................................................................................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
    Category:dropped
    Size (bytes):167592
    Entropy (8bit):6.522716708004368
    Encrypted:false
    SSDEEP:3072:Cg05KPL4mlh5/Ged0odpuLiKTnQK2MTPSkOYmZuHZMoEezI/Dx5O:CgzVD0edfKTnQK7rSkOY7bzIm
    MD5:806356BBF9B4B72C80BE789E8D61FB43
    SHA1:4B7CEB0DBC180131922BF24DB6B0A052C43D19B6
    SHA-256:AD0CB9AF3332C4C6C6BF4726853AB7640DAC09C73F2D17A0E4E6FFA76CEF1ABC
    SHA-512:8471147DD217B77570A121B579D07B2B32515783C52EEF03A979EAE26954E246CE19A06F22649E4ABE66C06EEB98FD39FF7DFC00EC5D0042C5D502EF04225CCD
    Malicious:false
    Reputation:low
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......9...}..}..}..f'.~..}..&...9+.x..;..._..;......;.3.w......i....0.|..p.7.|....2.|..Rich}..........................PE..d......d.........." .....j..........................................................k^....`..........................................,..Y...,0..(...............x....Z...4......X.......8...............................p...............`............................text....i.......j.................. ..`.rdata..0............n..............@..@.data....;...@.......(..............@....pdata..x............@..............@..@.rsrc................P..............@..@.reloc..X............T..............@..B................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
    Category:dropped
    Size (bytes):43192
    Entropy (8bit):6.582905125161072
    Encrypted:false
    SSDEEP:768:Ueqz2z9x1HkP1gIpSHqz6cW8l71SmRWSN5CL/Yin2PxWEAmH:Zlq15pvw8l7gmRWSCL/72PxfH
    MD5:AD54B06DE7A0EA7675D68DA061875717
    SHA1:CBC3125366CB78B09F3A7317E829DCEC67D9B770
    SHA-256:C84C1FD828B0A5AC7DBAAC53BB290B0F9AF0DE53E4729A0F3FBE3D4E7C5C3987
    SHA-512:D6D1E141B1FBDCEA9CE84310CA7065166E0E16E6109B100390581ADA7FC4AC21097ABFA840EF7657EAD6FC232DBAD06146FC72F52D890FF9EBAECFEE82BCEE48
    Malicious:false
    Reputation:low
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......u.XM1.6.1.6.1.6.....3.6.w...3.6.w...0.6.w...=.6.w...3.6..H..5.6..)..4.6.1.7.z.6..)..>.6..)..0.6.<...0.6..)..0.6.Rich1.6.................PE..d......d.........." .....6...D.......>....................................................`..........................................`..-....x..x...............$....x...0......@....R..8...........................p\..p............P..p............................text...k5.......6.................. ..`.rdata...1...P...2...:..............@..@.data...`............l..............@....pdata..$............n..............@..@.rsrc................r..............@..@.reloc..@............v..............@..B........................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
    Category:dropped
    Size (bytes):35952
    Entropy (8bit):6.5851283230205935
    Encrypted:false
    SSDEEP:768:cg61bEvZPeSmuG2CUMhUyZpHSVuUH/YinXiPxWEMF:cg61KZPWVcwpHSrH/7yPx0
    MD5:284C355111A6E8DE8EDC0D386C2D6A75
    SHA1:B31272F91C9BC2FFEE8301C1888A4468E07269BD
    SHA-256:926A7A0FB7E141A962C48FE95DC40CB67BF5E95E83A1E3159648091E1A38D9C3
    SHA-512:A2741D386D8E47DB1F3371C6A37DD7A8B7A3F1A446D32FC91A569B2A73EAAC4C3CB301CA62A7CD4D2B24CE2D9CF302AABA540C7946806E7F82E9EF780CE70046
    Malicious:false
    Reputation:low
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.............x...x...x.#3....x...y...x.......x.......x.......x.......x.KR....x.KR....x.....x.KR....x.Rich..x.........PE..d......d.........." .....4...*......,<..............................................w.....`..........................................\..X...._..<...............,....\..p0......$....R..8............................X..p............P...............................text....2.......4.................. ..`.rdata.......P.......8..............@..@.data........p.......N..............@....pdata..,............P..............@..@.rsrc................V..............@..@.reloc..$............Z..............@..B................................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
    Category:dropped
    Size (bytes):15176
    Entropy (8bit):7.121016196416919
    Encrypted:false
    SSDEEP:384:ujyMvQW2hWrZSf+VIYinvyLPxh8E9VF0NyR8VGt:QyMv03/YiniPxWEjCGt
    MD5:A261648B4CD80C8F558F747EF7A03F15
    SHA1:B6CA13936AABBA3BD751C167B24F7B09E4EB72FA
    SHA-256:EA47908A41088F037F52364E2D15AA15A5FF35C0FB2D64F0642683D47C22C98F
    SHA-512:14AA01F8DDBA6987DF6B388579CC5F92DA05EEC1CE579AD7DC1DABF096D9CD8A4ADA292A85BD7210D378E0B40F261ABAD9B066E2CD0FB00784A2F7E0D6D6D24F
    Malicious:false
    Reputation:low
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......m2..)S..)S..)S....].(S....A.+S....^.(S....C.(S..Rich)S..........................PE..d...48.U.........." .........................................................0......Kg....`.........................................`................ ..................H/..............8............................................................................rdata..............................@..@.rsrc........ ......................@..@................................................................................................................................................................................................................................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
    Category:dropped
    Size (bytes):15176
    Entropy (8bit):7.0579621588873565
    Encrypted:false
    SSDEEP:384:1UW2hWWZSf+VIYinvy0KsPxh8E9VF0NyYAr:yY/Yin1KsPxWECG
    MD5:4A578D0C676E4F2623D395096CEC8047
    SHA1:5185F9F26FCD4E9DB0A0ECFFDFFB46B7C272CF4C
    SHA-256:830461E05BAFEF4C9ACD02E9815653C2467DD4BCDE5D829D4A77735874BADEE1
    SHA-512:055D2512E15923F94FF1BEE9B5288703249DA76A7FBF3902D7D5AA7A543708DD24CBE4AA497F7C0FE10970F173D13CFE9EA52F6DB4D407F9E9EE7032CE306979
    Malicious:false
    Reputation:low
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......m2..)S..)S..)S....].(S....A.+S....^.(S....C.(S..Rich)S..........................PE..d...48.U.........." .........................................................0.......O....`.........................................`................ ..................H/..............8............................................................................rdata..$...........................@..@.rsrc........ ......................@..@................................................................................................................................................................................................................................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
    Category:dropped
    Size (bytes):15688
    Entropy (8bit):7.046398119279025
    Encrypted:false
    SSDEEP:192:t4WVghWnwZSF8VG+VIYiYF81GmFy0q1Ytk+noPOJB3hy2sE9jBF0NyN2lM:SW2hWwZSf+VIYinvywPxh8E9VF0NyNOM
    MD5:CF3E975ED19BD2C0740715C49763BBA8
    SHA1:4B0B982BB0577C417FFD3968110E7DDD421685A7
    SHA-256:66D72C3FA06DBE87B4DCAB0D75C0846E2BEC74679E610203D39D539AB9D2E23B
    SHA-512:1E108DFFEE01AD5ED5CA2E2D9CD5BD43A4C443D02E40CEAE358C966DED64843C4589FB0CB9D176BB45C023D3CD5CE484D8F961917AC81FB175D397078B7CFED7
    Malicious:false
    Reputation:low
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......m2..)S..)S..)S....].(S....A.+S....^.(S....C.(S..Rich)S..........................PE..d...48.U.........." .........................................................0............`.........................................`..."............ ..................H/..............8............................................................................rdata..<...........................@..@.rsrc........ ......................@..@................................................................................................................................................................................................................................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
    Category:dropped
    Size (bytes):204784
    Entropy (8bit):6.542246412082115
    Encrypted:false
    SSDEEP:6144:9DRaxCHkwXS8SFCoZTpt5zXe/VMkVmFw/q:JRaxCHBS8SF3D+msq
    MD5:690198083182D4C41CD954C425766FD2
    SHA1:AF057730C4D620054A372661B5A63E76B2E15EB1
    SHA-256:E738C4FAF7DB902DE25AE9474D9358C860F4271FE7E95D4A3059E9658A703168
    SHA-512:A6BC5ACE312E2AACBE44EE6ED240BF422933E92009450B04951F6664EE319908AAD3E05EF75573E82C124E1C899A40CE0D6A1F783F5B7E77493E366256285B0C
    Malicious:false
    Reputation:low
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........1N.._..._..._..0...._......._...../._......._.Po...._...^..._.8....._.8....._......_.8....._.Rich.._.........PE..d....d.........." .........,...............................................@.......2....`.........................................@...m.......d.... ..x................5...0..........8...............................p...............P............................text............................... ..`.rdata..............................@..@.data....?..........................@....pdata..............................@..@.rsrc...x.... ......................@..@.reloc.......0......................@..B................................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
    Category:dropped
    Size (bytes):15688
    Entropy (8bit):7.0409157270450855
    Encrypted:false
    SSDEEP:384:RlrW2hWYZSf+VIYinvyWPxh8E9VF0Ny5Wti0c:xa/YinbPxWE7ai7
    MD5:FD573A9FBA749C0C04B423DEE8C5F13E
    SHA1:DF11EF3F58738D698CBA75ED2CBF6EC526BDAAF9
    SHA-256:3873C7A119F192DC59B4C4FD8DAE52315167BE70E0404A1DE15557469CDE9B13
    SHA-512:81632D948D1611B0EB9D543C0F4B42FFBE55C8CBAD11E7D24F4F9A71E0613AF5C3B36EE13DAA678A41E257A685CEB1F1A62E4784E4CBC23B3F473D163CF1C389
    Malicious:false
    Reputation:low
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......m2..)S..)S..)S....].(S....A.+S....^.(S....C.(S..Rich)S..........................PE..d...48.U.........." .........................................................0............`.........................................`................ ..................H/..............8............................................................................rdata..............................@..@.rsrc........ ......................@..@................................................................................................................................................................................................................................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
    Category:dropped
    Size (bytes):15176
    Entropy (8bit):7.161398040754558
    Encrypted:false
    SSDEEP:384:HV6W2hWHZSf+VIYinvya+oPxh8E9VF0NyZ88:HVCv/Yinp+oPxWE/5
    MD5:100F00FB4E3521AC5188813F9865FB60
    SHA1:C78E0FF9106503BF4882EC0E0A663A370F80795F
    SHA-256:3F77EA86DE22AFCB9FB5F40F202EC482EAE218F0632722CDB2271130C88522C4
    SHA-512:A4F29A218E294A5C9AB738E5C2FD0385CF820FB174D014417F965381463BA73CAFBC48555FD1A46A6621382F73067CDE958C9FBE666F8EF9FDC9EDF3AB4AFADB
    Malicious:false
    Reputation:low
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......m2..)S..)S..)S....].(S....A.+S....^.(S....C.(S..Rich)S..........................PE..d....8.U.........." .........................................................0.......<....`.........................................`................ ..................H/..............8............................................................................rdata..............................@..@.rsrc........ ......................@..@................................................................................................................................................................................................................................................................................................................................................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:ASCII text
    Category:dropped
    Size (bytes):1522
    Entropy (8bit):4.747042537008044
    Encrypted:false
    SSDEEP:24:b0fFDmMbmRMAOJDcJb3W2zeD34eXqC/5Wx/kaRilV8hWrwr1:b09PbmqAOJIW2KT4eXqC/5WFkaEQW8Z
    MD5:D94F7C92FF61C5D3F8E9433F76E39F74
    SHA1:7A9B074CA8D783DBE5310ECC22F5538B65CC918E
    SHA-256:A44EB7B5CAF5534C6EF536B21EDB40B4D6BABF91BF97D9D45596868618B2C6FB
    SHA-512:D4044F6CEB094753075036920C0669631F4D3C13203CAF2BEA345E2CC4094905719732010BBE1CAE97BC78743AA6DEF7C2AA33F3E8FCA9971F2CA0457837D3B0
    Malicious:false
    Reputation:low
    Preview:.OPENJDK ASSEMBLY EXCEPTION..The OpenJDK source code made available by Oracle America, Inc. (Oracle) at.openjdk.java.net ("OpenJDK Code") is distributed under the terms of the GNU.General Public License <http://www.gnu.org/copyleft/gpl.html> version 2.only ("GPL2"), with the following clarification and special exception... Linking this OpenJDK Code statically or dynamically with other code. is making a combined work based on this library. Thus, the terms. and conditions of GPL2 cover the whole combination... As a special exception, Oracle gives you permission to link this. OpenJDK Code with certain code licensed by Oracle as indicated at. http://openjdk.java.net/legal/exception-modules-2007-05-08.html. ("Designated Exception Modules") to produce an executable,. regardless of the license terms of the Designated Exception Modules,. and to copy and distribute the resulting executable under GPL2,. provided that the Designated Exception Modules continue to be.
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:ASCII text
    Category:dropped
    Size (bytes):19274
    Entropy (8bit):4.667864876938965
    Encrypted:false
    SSDEEP:384:sY2fSz/rGvS/66YsaZdIP3Lf4vAkMVhPGkupdDdicW:7vuvVmjkbylupdDdiZ
    MD5:3E0B59F8FAC05C3C03D4A26BBDA13F8F
    SHA1:A4FB972C240D89131EE9E16B845CD302E0ECB05F
    SHA-256:4B9ABEBC4338048A7C2DC184E9F800DEB349366BDF28EB23C2677A77B4C87726
    SHA-512:6732288C682A39ED9EDF11A151F6F48E742696F4A762C0C7D8872B99B9F6D5AB6C305064D4910B1A254862A873129F11FD0FA56FF11BC577D29303F4FB492673
    Malicious:false
    Reputation:low
    Preview:The GNU General Public License (GPL)..Version 2, June 1991..Copyright (C) 1989, 1991 Free Software Foundation, Inc..51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA..Everyone is permitted to copy and distribute verbatim copies of this license.document, but changing it is not allowed...Preamble..The licenses for most software are designed to take away your freedom to share.and change it. By contrast, the GNU General Public License is intended to.guarantee your freedom to share and change free software--to make sure the.software is free for all its users. This General Public License applies to.most of the Free Software Foundation's software and to any other program whose.authors commit to using it. (Some other Free Software Foundation software is.covered by the GNU Library General Public License instead.) You can apply it to.your programs, too...When we speak of free software, we are referring to freedom, not price. Our.General Public Licenses are designed to make sure that
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:ASCII text
    Category:dropped
    Size (bytes):157063
    Entropy (8bit):5.019059096479156
    Encrypted:false
    SSDEEP:3072:8j33DuS8sY5sPfqN7amC3Xs4NZ1G8OANn16XBPb3Ucw+4oHmZ/bcm9GdNhJ75e5t:MqN2pZy3Ucw+4o7dfCRp
    MD5:37E7AAD9C0F238DF220F5F70707C6341
    SHA1:617AD547D6BE8756C859E2770D5301044B0BE505
    SHA-256:CA07B5A7569D691A0C717B6844440AEF29706BD81A787C989D95BA352B390F47
    SHA-512:779DDBE62E28628A6A64B62409377BFCC4AFBEF917C57EC01F1BEDA2849890D1FC182620F46A231D5DA6850B2DAC52D67BAEC5C02215F309CDEC3D5BD3DF5FE2
    Malicious:false
    Reputation:low
    Preview:DO NOT TRANSLATE OR LOCALIZE..-----------------------------..%% This notice is provided with respect to ASM Bytecode Manipulation .Framework v5.0.3, which may be included with JRE 8, and JDK 8, and .OpenJDK 8...--- begin of LICENSE ---..Copyright (c) 2000-2011 France T??l??com.All rights reserved...Redistribution and use in source and binary forms, with or without.modification, are permitted provided that the following conditions.are met:..1. Redistributions of source code must retain the above copyright. notice, this list of conditions and the following disclaimer...2. Redistributions in binary form must reproduce the above copyright. notice, this list of conditions and the following disclaimer in the. documentation and/or other materials provided with the distribution...3. Neither the name of the copyright holders nor the names of its. contributors may be used to endorse or promote products derived from. this software without specific prior written permission...THIS SOFTWAR
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:ASCII text
    Category:dropped
    Size (bytes):94
    Entropy (8bit):4.741368340920021
    Encrypted:false
    SSDEEP:3:tqrYHUnPNeIKDKqvrYHQjPNLBLHvCmYnv2qlg8vn:GqIPHkKqzq8HvCmYvNTv
    MD5:8B4201948E4FE03F5A057C32D8028405
    SHA1:08BB93FF0371C56F02467F00C74D63741002DB1C
    SHA-256:341C7701C81CC9EA6DB8A0908B1BBEDEADBE8C1B5ADFAD8CAA9EBF5C08527E7B
    SHA-512:101330E0D635F1C0FC2C00F8B4ACB38BBCCD49CA866C9FE3C751FA82DF83F40A566BAED78EA0CE4E5FF764EADBEA0B48FF2D4090E1474FB3793F0DD77F02415D
    Malicious:false
    Reputation:low
    Preview:JAVA_VERSION="1.8.0_382".OS_NAME="Windows".OS_VERSION="5.2".OS_ARCH="amd64".LIBC="".SOURCE="".
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java source, ASCII text
    Category:dropped
    Size (bytes):3372
    Entropy (8bit):4.999071091983145
    Encrypted:false
    SSDEEP:96:o6rYJdrYJQX3Z3r3dVeE642LuELGvZx+F/ufL:o6rsdrsQXJ3r37e6ELAZx+pufL
    MD5:929CD3C67BDE7C76AA1DFF9DEB69EECD
    SHA1:F5B0E4F96D8807FA8ADED534A957FCA29695A38A
    SHA-256:C9C27F0431BA7663D98504EC8BA6A169C218B413C9AF0096A1101EF76989DB37
    SHA-512:E07FE4497A6F015EE412BBC4DC77E26E89AF8B7BB046DF2D02049389F63A7C8924E06BEC6EE6798523CA3E1446E4E0F5ACAF78E2196F81F79F3B7C688BA3A290
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2014, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABILITY A
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java source, ASCII text
    Category:dropped
    Size (bytes):3367
    Entropy (8bit):4.959839272630315
    Encrypted:false
    SSDEEP:96:o6rYJdrYJQX3Z3r3dVeE642LuEL+JQJzJgYq1/vi8V88L:o6rsdrsQXJ3r37e6EL2clgp1XiJ8L
    MD5:4E621D73C1D07CBEEF651CCC8BEF336B
    SHA1:FC646C309637EBEDA4F09EDB31641D49E2394B42
    SHA-256:7DD5F8BCBD5F47EEA6BD75C4A8D283AB7BD022452190757FE92D810CD65133B0
    SHA-512:0B9F9BA0A15F638666026C9058DE85AFD4BDF11B59E7DAFA1640AF70858831FF8704FF8D8D0244981867C9DB53572BD0955C6F937FA513A1FAB8C0553AE9C9CE
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2014, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABILITY A
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Java source, ASCII text
    Category:dropped
    Size (bytes):5184
    Entropy (8bit):4.752886565476414
    Encrypted:false
    SSDEEP:96:o6rYJdrYJQX3Z3r3dVeE642LuELF2JdxJrVO1hgu8N2IGVD8/qByLYpI6Gno5VCW:o6rsdrsQXJ3r37e6ELFudxJrVuSu8N29
    MD5:7D07E8864342A06EDDC74AC10EF47903
    SHA1:5F3A3615154D3DF0E2F7FA390DDE6B7EC3EDAAA9
    SHA-256:649682F7A08C17CBA01EC074F6D880D117FBFE87AA23C19536DBAC09697296FA
    SHA-512:34C77698DBB084F4BA48BEE512D716F9D62B7F34E099F27291C822768E362D68BCC75E897602FB76578E23C690F3CF2763D6FC69BB66B1484A0E6F888F2B6C0F
    Malicious:false
    Reputation:low
    Preview:/*. * Copyright (c) 2014, Oracle and/or its affiliates. All rights reserved.. *. * Redistribution and use in source and binary forms, with or without. * modification, are permitted provided that the following conditions. * are met:. *. * - Redistributions of source code must retain the above copyright. * notice, this list of conditions and the following disclaimer.. *. * - Redistributions in binary form must reproduce the above copyright. * notice, this list of conditions and the following disclaimer in the. * documentation and/or other materials provided with the distribution.. *. * - Neither the name of Oracle nor the names of its. * contributors may be used to endorse or promote products derived. * from this software without specific prior written permission.. *. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,. * THE IMPLIED WARRANTIES OF MERCHANTABILITY A
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:Zip archive data, at least v2.0 to extract, compression method=deflate
    Category:dropped
    Size (bytes):51769532
    Entropy (8bit):7.973707797716029
    Encrypted:false
    SSDEEP:786432:EMWqz/G0EApxor3pUI3WBF5zraiLiUkMJCr1ycC3xWB+OD13bg9mX0qMTDLQg:EMv7gAPG+Kibm/RVb00RM/LQg
    MD5:55F57124C25151D2CB62CF5A2E0003B1
    SHA1:5DE54459265E8EFD0833E9CEF44EEB1539560EF0
    SHA-256:B7F31482E59213847BFB2F35B49A3633A0080C001203C3E8090D492A37234CC1
    SHA-512:91827AA11786A26F033FE752E1927265EE4A2543FEF1A03D292647152F8543EA1414C7A9F06C095A0F5A1178B895029568591E760B8CB37371F9EE956A24A593
    Malicious:false
    Reputation:low
    Preview:PK...........V..f]...........com/oracle/net/Sdp.javaUT......d...dux..............X.n.9.}.W........Y`..w.Y..8. .3.#.,.[d/."....bw.o......"...S.....x....|X9.x.>....`b...0..h..Y`..%s..c.#,.a..($....'...,.3..`6.:.m....n6.r....`8....h.W..!\........b%-p.....F..z..s...8S8i$.3.>uh..7.:...6.N."a...8a......2../B..b.....p#.PV.F.+....U........]...w..|..>.....q!.Q.....B..d...<....#..M........ f.&....EB.d........].....p.......s.N...+by0.e...n.........{....4..Z.....vAX..........9...F.....\'1..Q2L..%..p6.F.....hq.....h1....>L.3...M.....t2.b`.B..=.*...l0...dl!`..dG...iT...B.:..n..;.......F ...X....j...G`.V.>..\[m..A.Ai.....%...#...a.~:C+..c\..._.%._.Z..|..5|.......g.;=..y.X.4....Z9..........<n...LD[.#..0...>......Dp..9.HKD.nC....UZ......(..?FH*.......2.#....R.%/O:...G.@^..`%.y.......l.%.k.H..v.,s.......]a|...3..5.0.:.+...mn9.~>gWq..5..&Gf.+.......].w[.Sd...s...`.cq.lj....D....b..B#.1*[.X.0)o.Y......xA|.t.6.{.,.y...dS.`.$.G.<M...O.W....8nQ.-.m.Z,...u8...@
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:ASCII text
    Category:dropped
    Size (bytes):11
    Entropy (8bit):2.845350936622437
    Encrypted:false
    SSDEEP:3:Ydxb:YdF
    MD5:DB2434EBDDFA057BC3B6AA66F5377200
    SHA1:189EDAD68ABD285AB8AEA1DB4B8BF994F3A70F22
    SHA-256:E9CB3C344D45F1ADEEC27B213EB96BCD85870E6087443D395FC1DB3E1F542924
    SHA-512:8A1383340F073DFB5766100AA348BF4A1FBCB0F4B32E531E38B3D53000A80017482BB743EFC95E05572ADB1EEEF1D690FFD359EB5F52D46E029F20F29BEDBA32
    Malicious:false
    Reputation:low
    Preview:8.382.05.1.
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:data
    Category:dropped
    Size (bytes):162
    Entropy (8bit):4.254856208708495
    Encrypted:false
    SSDEEP:3:iZx0XYwMq8ERTXm7rWx8WjN:Ix8dn8OXmo
    MD5:50FC63F70225BE376A84997A39867BEC
    SHA1:EDFA64A7346E24A28E1702F6DB5BB0BF4BFA9759
    SHA-256:5D5F3F65FF196153DDFC16F6BA9D3D2618FB7BC9C301B66B164B1B052F4FC2C8
    SHA-512:E91BE11DFFEFA650E4BFD928796EDE0943075A4F0F1B352A0C18547B6E2F7F573E1B3CC724D5CF7411E71AAC5E38A687863D8B8E1E5A25A3857B3BCB750D02CA
    Malicious:false
    Reputation:low
    Preview:...........................................................\f0\b\fs24 Bug introduced with HOBOmobile v1.9.1 corrected\..\f1\b0\fs2..........3J....}.-i.....R...=.h
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):1845
    Entropy (8bit):4.848278025748546
    Encrypted:false
    SSDEEP:24:2dPkggA6XNkA6kkkAA6+HsW4x88HeGPiN1JJkQZ9ZIVA64:cPAAWqA3EApsb8qobDIVAf
    MD5:E5B24364FCD6C638D0108F990048F1AE
    SHA1:DCC2424D63E7F766F21C43F08C1897DB6EA55346
    SHA-256:EC67FA0951E4DF0933BE6517D70EBCDA4CCE938AEB6F5B21D05DC70417AA2888
    SHA-512:9498747226CC2DBE703390F81707B604C34B322147780C124AA6C3927ED29D4A222CDB1274D01B1781C6B66AEFE492F53D952BEDE970142C81F8D9558EC1985A
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?> .<java version="1.5.0_04" class="java.beans.XMLDecoder"> . <object class="OLServices.OSensorChannel"> . <void property="decimal"> . <int>2</int> . </void> . <void property="displayHigh"> . <double>706.2068965517242</double> . </void> . <void property="firmware"> . <float>2.2</float> . </void> . <void property="gain"> . <int>2</int> . </void> . <void property="location"> . <string></string> . </void> . <void property="measurementHigh"> . <double>706.2068965517242</double> . </void> . <void property="measurementUnits">. <string>VAC</string> . </void> . <void property="moduleType"> . <int>2</int> . </void> . <void property="nativeHigh"> . <double>333.0</double>. </void> . <void property="nativeVoltageUnit"> . <string>&lt;HTML&gt;mV&lt;sub&gt;RMS&lt;/sub&gt;&lt;/HTML&gt;</string> . </void> . <void property="parentSensor"> . <object class="OLServices.OSensor"> . <void property="configurable"> . <boolean
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):2167
    Entropy (8bit):4.798005822265027
    Encrypted:false
    SSDEEP:24:2dPkggA6DT6OCkA6DB6OkbPhHAA68h6mhHsCRx88hovRoPiNWkOoZ2VA6DV:cPAAWThhAWBfegA3VsCr8efm2VAWV
    MD5:796989279568929A9D8D742FF1CEE424
    SHA1:8F2A12637260EB97E1688C2A417EB7E30E5BFAEB
    SHA-256:DB628C9C8B7632D1B6CB4229FF9B1F4000B349642D26A8899B6A5DEC5CB954F3
    SHA-512:E62B11D3FBC525DE2302A6B9DB51A0A5C7CF10ADB1F16A278996F8500804207C1149242AF0C0098ACCE60EEDE0EA11003125A051C0913FA86C24AA72EBA8C40C
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?> .<java version="1.5.0_04" class="java.beans.XMLDecoder"> . <object class="OLServices.OSensorChannel"> . <void property="decimal"> . <int>2</int> . </void> . <void property="displayHigh"> . <double>100.0</double> . </void> . <void property="displayLow"> . <double>0.9999999907799065</double> . </void> . <void property="firmware"> . <float>1.0</float> . </void> . <void property="gain"> . <int>2</int> . </void> . <void property="location"> . <string></string> . </void> . <void property="measurementHigh"> . <double>100.0</double> . </void> . <void property="measurementLow"> . <double>0.9999999907799065</double> . </void> . <void property="measurementUnits"> . <string>PSIG</string> . </void> . <void property="moduleType"> . <int>1</int> . </void> . <void property="nativeCurrentUnit"> . <string>mA</string> . </void> . <void property="nativeHigh"> . <double>5.0</double> . </void> . <void property="nativeLow
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):2190
    Entropy (8bit):4.697934587107499
    Encrypted:false
    SSDEEP:24:2degvA6sj6c0Ca9A6sx6cykbPhHAA6Jh6zjTtiHsCRx88hoBolPiNjkQZIVA6siz:chAHt0R9AltyegAoaMsCr8iefIVAetV
    MD5:80E0E3C275CFB5963D09423C21FEA791
    SHA1:56F5554659F53A78D8560C66B5D71C231556D838
    SHA-256:F71F7AD523FD547AA6E3A3F9B505218C668D000F7F50347B6FE3D0D609C95117
    SHA-512:99ADAAD828ECC83364B16D1977ED06312172B4BD5F5C246004737C0FACF4592AAD83E8A28751F4ABD3DE4D6139D53F6A623B0DC4313B480F891F7122B3C68215
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?> .<java version="1.6.0_14" class="java.beans.XMLDecoder"> . <object class="OLServices.OSensorChannel"> . <void property="decimal"> . <int>1</int> . </void> . <void property="displayHigh"> . <double>600.0</double> . </void> . <void property="displayLow"> . <double>0.0</double> . </void> . <void property="firmware"> . <float>1.0</float> . </void> . <void property="gain"> . <int>3</int> . </void> . <void property="label"> . <string></string> . </void> . <void property="measurementHigh"> . <double>600.0</double> . </void> . <void property="measurementLow"> . <double>0.0</double> . </void> . <void property="measurementUnits"> . <string>scfm</string> . </void> . <void property="moduleType"> . <int>1</int> . </void> . <void property="nativeCurrentUnit"> . <string>mA</string> . </void> . <void property="nativeHigh"> . <double>20.0</double> . </void> . <void property="nativeLow"> . <double>4.0</double> . <
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):2035
    Entropy (8bit):4.692465382123251
    Encrypted:false
    SSDEEP:24:2deggA6D0Ca9A6D6kbPhHAA6Jh6zjTtiHsCRx88hoBolPiNVhkQZIVA6DRD:cOAW0R9AW6egAoaMsCr8iIhfIVAWB
    MD5:339C4AF203E0878EB9CF04CF90B6E0DB
    SHA1:A549E4690483329574AC732B035C4158B16A8174
    SHA-256:00C91E54BF9CAA9EB857C19F20CE0E939FAE536D096B87B1422FBD738BE573D0
    SHA-512:6FF98EBD47ACC8FB295A11A3330EC811E17786F42CF41B2B1ECCBF87A67074BD41F26E7F1D42D3E14378054B76E983B674E11767DA05022B14E03CA958E3A7FA
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?> .<java version="1.6.0_14" class="java.beans.XMLDecoder"> . <object class="OLServices.OSensorChannel"> . <void property="decimal"> . <int>2</int> . </void> . <void property="displayHigh"> . <double>100.0</double> . </void> . <void property="firmware"> . <float>1.0</float> . </void> . <void property="gain"> . <int>3</int> . </void> . <void property="label"> . <string></string> . </void> . <void property="measurementHigh"> . <double>100.0</double> . </void> . <void property="measurementUnits"> . <string>ppm</string> . </void> . <void property="moduleType"> . <int>1</int> . </void> . <void property="nativeCurrentUnit"> . <string>mA</string> . </void> . <void property="nativeHigh"> . <double>20.0</double> . </void> . <void property="nativeLow"> . <double>4.0</double> . </void> . <void property="nativeUnits"> . <boolean>false</boolean> . </void> . <void property="nativeVoltageUnit"> . <string>V</string>
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):2037
    Entropy (8bit):4.693272176011847
    Encrypted:false
    SSDEEP:24:2deggA6s6hC5A666/kbPhHAA68HsCRx88hoBolPiNwkQZIVA6/:cOAL06AZOegApsCr8ibfIVAk
    MD5:73352B9DAED41416D95145EC3E584555
    SHA1:AEE0141B5DD8EC888C520CCE7B52B9DB4A3B6A63
    SHA-256:E98F577725973BE2ADF0A294D6B128501F9F94AF0542014FC5E71FFD59594EE9
    SHA-512:624C6C6703A208C389D52C3669D6AAF964B15B2F4DBB522DE7AB1B877921845C2A000AC32626543C845951221D6AE3114C1186E42B2FE6AA59F7C86D8045BFEE
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?> .<java version="1.6.0_14" class="java.beans.XMLDecoder"> . <object class="OLServices.OSensorChannel"> . <void property="decimal"> . <int>2</int> . </void> . <void property="displayHigh"> . <double>200.0</double> . </void> . <void property="displayLow"> . <double>2.0</double> . </void> . <void property="firmware"> . <float>1.0</float> . </void> . <void property="gain"> . <int>2</int> . </void> . <void property="label"> . <string></string> . </void> . <void property="measurementHigh"> . <double>200.0</double> . </void> . <void property="measurementLow"> . <double>2.0</double> . </void> . <void property="measurementUnits"> . <string>A</string> . </void> . <void property="moduleType"> . <int>1</int> . </void> . <void property="nativeCurrentUnit"> . <string>mA</string> . </void> . <void property="nativeHigh"> . <double>5.0</double> . </void> . <void property="nativeVoltageUnit"> . <string>V</string> .
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
    Category:dropped
    Size (bytes):1923
    Entropy (8bit):4.896226269888424
    Encrypted:false
    SSDEEP:48:cE7qIq2G81qEqiQGGySqXiG5N5NqMq2CoqlGlqLqbDWlP:N/5J1xWoS2vNlVRl8WW5
    MD5:4D6A69BE1E34C3ACE9E9381ADA837FD0
    SHA1:3D112AB0FA09A8A8756FFF31498CC08242A31FFC
    SHA-256:03CB8AD9BC946DE6AAEBB6166986B0EBB44CDE025A4F3A23863E3250B481966E
    SHA-512:802D70406C08C3EDC87D1E9478E2A7601D813D9E185929805730F6CB616438EBF68992F22EF871CAF3195970E7D6E6865A74DD8651A832DF1F8B53612A1901A2
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?> ..<java version="1.6.0_25" class="java.beans.XMLDecoder"> .. <object class="OLServices.OSensorChannel"> .. <void property="sampleSize"> .. <int>15</int> .. </void> .. <void property="decimal"> .. <int>2</int> .. </void> .. <void property="displayHigh"> .. <double>153.60153601536015</double> .. </void> .. <void property="firmware"> .. <float>2.8</float> .. </void> .. <void property="gain"> .. <int>2</int> .. </void> .. <void property="label"> .. <string></string> .. </void> .. <void property="measurementHigh"> .. <double>153.60153601536015</double> .. </void> .. <void property="measurementUnits"> .. <string>A</string> .. </void> .. <void property="moduleType"> .. <int>2</int> .. </void> .. <void property="nativeHigh"> .. <double>333.33</double> .. </void> .. <void property="nativeVoltageUnit"> .. <string>&lt;HTML&gt;mV&lt;sub&gt;RMS&lt;/sub&gt;&lt;/HTML&gt;</string> .. </void> .. <void property="parentSe
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):1845
    Entropy (8bit):4.833447895347986
    Encrypted:false
    SSDEEP:24:2dPkgNPA68NkA62kkAA6gHsW4x88HeGPiNwkQZ9ZIVA6sk:cPtPAZqAXEApsb8qbDIVAk
    MD5:462E684690B5AF682227AD9E70B6224B
    SHA1:873D1FD78EA277E1CB3BB9C7D23D87E1C81C4224
    SHA-256:230FC3D2DC1FE1589A02EC7DDEB8E39D23644015707CD62EF40CC9788DD115B5
    SHA-512:5ABB75C28EF6EF48B727DFEB55AFD9FE4F62ECBAD0B25ACB1B706F5339FAF0D606237C9D254AEF4779FEE8F9CEDC6C47E3BA295C362E4E62DBF15F7A2A1B57FE
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?> .<java version="1.5.0_04" class="java.beans.XMLDecoder"> . <object class="OLServices.OSensorChannel"> . <void property="decimal"> . <int>3</int> . </void> . <void property="displayHigh"> . <double>76.87687687687688</double> . </void> . <void property="firmware"> . <float>2.2</float> . </void> . <void property="gain"> . <int>2</int> . </void> . <void property="location"> . <string></string> . </void> . <void property="measurementHigh"> . <double>76.87687687687688</double> . </void> . <void property="measurementUnits"> . <string>A</string> . </void> . <void property="moduleType"> . <int>2</int> . </void> . <void property="nativeHigh"> . <double>333.0</double> . </void> . <void property="nativeVoltageUnit"> . <string>&lt;HTML&gt;mV&lt;sub&gt;RMS&lt;/sub&gt;&lt;/HTML&gt;</string> . </void> . <void property="parentSensor"> . <object class="OLServices.OSensor"> . <void property="configurable"> . <boolean
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):2177
    Entropy (8bit):4.807988649418293
    Encrypted:false
    SSDEEP:24:2dPkgaA6B6boCkA6n6bGkbPhHAA68h6mhHsCRx88hovRoPiNKqkOoZ2VA67:cP6AgdhA+3egA3VsCr8aWm2VAI
    MD5:84CE9FA099870C1D1C17955B7AD2260D
    SHA1:2519C9761239BCC975E7A881A13B59CE6B190DDC
    SHA-256:4843444464A0A10805D0A5F9AADE8513EE39566CE366146BA1EBA14E18657F06
    SHA-512:9E263B16DBEF03E1F9B6D4ABFDE4648357AB23BAA23B80328348D23291E82274376E6442BA1B94DFB3AA801F10918F19773723712CB71E40A01B561056AA62A0
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?> .<java version="1.5.0_04" class="java.beans.XMLDecoder"> . <object class="OLServices.OSensorChannel"> . <void property="decimal"> . <int>4</int> . </void> . <void property="displayHigh"> . <double>0.25</double> . </void> . <void property="displayLow"> . <double>0.0024999999769497665</double> . </void> . <void property="firmware"> . <float>1.0</float> . </void> . <void property="gain"> . <int>2</int> . </void> . <void property="location"> . <string></string> . </void> . <void property="measurementHigh"> . <double>0.25</double> . </void> . <void property="measurementLow"> . <double>0.0024999999769497665</double> . </void> . <void property="measurementUnits"> . <string>in WC</string> . </void> . <void property="moduleType"> . <int>1</int> . </void> . <void property="nativeCurrentUnit"> . <string>mA</string> . </void> . <void property="nativeHigh"> . <double>5.0</double> . </void> . <void property="nati
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):2261
    Entropy (8bit):4.717951616206955
    Encrypted:false
    SSDEEP:24:2dPkggA6T62fCagA6B62okbPhHAA6Jh6zjTtiHsCRx88hovnPiNh/k2Z2VA6y622:cPAAEFRgAymegAoaMsCr85CF2VAvQ
    MD5:DF0D0FFF34DE47065EFBDED21751EEB5
    SHA1:1123CCFACA02E76ADEEF9AD6C7D8E13E601D8A85
    SHA-256:E43B6FEE85C7EE658F1FB293FBA8FC91F679A24BBB8EC683E35B776F580F2B4D
    SHA-512:693634E7C92AA6B776FC9C58B3B4D21F2BFB231CDC5CAD03651FDF22BF59F4AB929B11987E6B503DEAFBADD2761BD32E3C49C2C0D6E8FA28B1AFA15F02982408
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?> .<java version="1.5.0_04" class="java.beans.XMLDecoder"> . <object class="OLServices.OSensorChannel"> . <void property="decimal"> . <int>2</int> . </void> . <void property="displayHigh"> . <double>140.0</double> . </void> . <void property="displayLow"> . <double>-40.0</double>. </void> . <void property="firmware"> . <float>1.0</float> . </void> . <void property="gain"> . <int>3</int> . </void> . <void property="location"> . <string></string> . </void> . <void property="measurementHigh"> . <double>140.0</double> . </void> . <void property="measurementLow"> . <double>-40.0</double>. </void> . <void property="measurementUnits"> . <string>F</string> . </void> . <void property="moduleType"> . <int>1</int> . </void> . <void property="nativeCurrentUnit"> . <string>mA</string> . </void> . <void property="nativeHigh"> . <double>20.0</double> . </void> . <void property="nativeLow"> . <double>4.0</double> .
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):2032
    Entropy (8bit):4.689642550944697
    Encrypted:false
    SSDEEP:24:2degNPA66Ca9A60kbPhHAA6Jh6zjTtiHsCRx88hoBolPiNVhkQZIVA67D:cfPAlR9A3egAoaMsCr8iIhfIVAO
    MD5:11FE9A5C542D09F6E4F8324DD98B3B02
    SHA1:42D9F594EE3DC0D9B99FF55FEAA32A77114C2A03
    SHA-256:B8206B54399C274412092867C9C3AE65B1C1ED6604A53831DE358CCBA90D9601
    SHA-512:CF6C3983C168DD0F7D0C414B61AE411C00061C2B26A4BA1B94E729F07A6D54D2109A40EFC392014CF152B7ED461CCEB23849ECB1F468CD031B2AE567F10FE7CE
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?> .<java version="1.6.0_14" class="java.beans.XMLDecoder"> . <object class="OLServices.OSensorChannel"> . <void property="decimal"> . <int>3</int> . </void> . <void property="displayHigh"> . <double>10.0</double> . </void> . <void property="firmware"> . <float>1.0</float> . </void> . <void property="gain"> . <int>3</int> . </void> . <void property="label"> . <string></string> . </void> . <void property="measurementHigh"> . <double>10.0</double> . </void> . <void property="measurementUnits"> . <string>ppm</string> . </void> . <void property="moduleType"> . <int>1</int> . </void> . <void property="nativeCurrentUnit"> . <string>mA</string> . </void> . <void property="nativeHigh"> . <double>20.0</double> . </void> . <void property="nativeLow"> . <double>4.0</double> . </void> . <void property="nativeUnits"> . <boolean>false</boolean> . </void> . <void property="nativeVoltageUnit"> . <string>V</string> .
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
    Category:dropped
    Size (bytes):2192
    Entropy (8bit):4.7432045939979135
    Encrypted:false
    SSDEEP:48:cxqGq2o8sqBlqiQo2yTqUXXjTJrGedN5uqMqBquqcoqlgqqqbDoTqP:W95LsSlW6T7T9TdulYyhpWWi
    MD5:2179ED42C4FE59D5CDD80ACD292BB949
    SHA1:FB37A2A1A1456F1D51FF5371A19A856B49F7EF7F
    SHA-256:1B697EA3324DD74E671C8071228E11F5AF7C8042B43D09B6AB267FFE1979D72D
    SHA-512:040A70F2EE3B02ACB5662567B509C72BBF07EFC4DA0CA604DE75A57D77E9E6442659CC444688987703E1FB66980784192C9B0E4606EB7C750AB6984EE0126292
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?> ..<java version="1.6.0_14" class="java.beans.XMLDecoder"> .. <object class="OLServices.OSensorChannel"> .. <void property="channelNum"> .. <int>1</int> .. </void> .. <void property="decimal"> .. <int>4</int> .. </void> .. <void property="displayHigh"> .. <double>0.5</double> .. </void> .. <void property="firmware"> .. <float>1.0</float> .. </void> .. <void property="gain"> .. <int>3</int> .. </void> .. <void property="label"> .. <string></string> .. </void> .. <void property="measurementHigh"> .. <double>0.5</double> .. </void> .. <void property="measurementUnits"> .. <string>in WC</string> .. </void> .. <void property="moduleType"> .. <int>1</int> .. </void> .. <void property="nativeCurrentUnit"> .. <string>mA</string> .. </void> .. <void property="nativeHigh"> .. <double>20.0</double> .. </void> .. <void property="nativeLow"> .. <double>4.0</double> .. </void> .. <void property="nativeUnits"> ..
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
    Category:dropped
    Size (bytes):1922
    Entropy (8bit):4.894896265387839
    Encrypted:false
    SSDEEP:48:cE7qIq2b280qEqiQb2GySqXiG5N5ZqMq2WoqlzqLqbDkP:N/5b50xWb4S2vZlNG8Wg
    MD5:1A6E55D722858DB40A80B4529450688D
    SHA1:52F510B4315A039DBBF50DC8408285453BF91DBF
    SHA-256:29E9F3341A7A493EC316284506BB161AD69F12ADDD0F7D3DAF3932CA90C6F852
    SHA-512:6D22E6B32ADC303B72061DAAB0C6E60C6C5DBA5D5844379DD60742F8BECF498FC7FE4C6995CEFA31D79FEC3CBD48A0B88A9B3E09AE0720C9D0940FB7056F0331
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?> ..<java version="1.6.0_25" class="java.beans.XMLDecoder"> .. <object class="OLServices.OSensorChannel"> .. <void property="sampleSize"> .. <int>15</int> .. </void> .. <void property="decimal"> .. <int>2</int> .. </void> .. <void property="displayHigh"> .. <double>76.80076800768008</double> .. </void> .. <void property="firmware"> .. <float>2.7</float> .. </void> .. <void property="gain"> .. <int>2</int> .. </void> .. <void property="label"> .. <string></string> .. </void> .. <void property="measurementHigh"> .. <double>76.80076800768008</double> .. </void> .. <void property="measurementUnits"> .. <string>A</string> .. </void> .. <void property="moduleType"> .. <int>2</int> .. </void> .. <void property="nativeHigh"> .. <double>333.33</double> .. </void> .. <void property="nativeVoltageUnit"> .. <string>&lt;HTML&gt;mV&lt;sub&gt;RMS&lt;/sub&gt;&lt;/HTML&gt;</string> .. </void> .. <void property="parentSens
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):2175
    Entropy (8bit):4.7191379804434614
    Encrypted:false
    SSDEEP:24:2dtNgRaA6y6zC5A6I6kykbPhHAA6zHsCRx88KsvlPiNGZGVA60A6a:ctLA5i6A/ryegAksCr8rK/GVANA1
    MD5:3905D44C6F9DA798A86975A882617A87
    SHA1:3AF31342F40BEE3C940370879FD043FD5B605D47
    SHA-256:E712AB85B169FD2E2229E4215C462BD5DC096EF5140B08813A4F1896734221E6
    SHA-512:9E2FDD90E3CEF99768D71F9C97C0754F3FD98BC23922366770E09B42B4C4411EBB9DFF475BC3EA8185EC1EB93E10FC818CA2A3825169C9C59E4E56E3A07C0B8D
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?> .<java version="1.6.0_24" class="java.beans.XMLDecoder"> . <object class="OLServices.OSensorChannel"> . <void property="bitSize"> . <int>12</int> . </void> . <void property="channelNum"> . <int>1</int> . </void> . <void property="decimal"> . <int>1</int> . </void> . <void property="displayHigh"> . <double>1231.25</double> . </void> . <void property="displayLow"> . <double>12.3125</double> . </void> . <void property="firmware"> . <float>1.0</float> . </void> . <void property="gain"> . <int>2</int> . </void> . <void property="label"> . <string></string> . </void> . <void property="measurementHigh"> . <double>1231.25</double> . </void> . <void property="measurementLow"> . <double>12.3125</double> . </void> . <void property="measurementUnits"> . <string>fpm</string> . </void> . <void property="moduleType"> . <int>1</int> . </void> . <void property="nativeCurrentUnit"> . <string>mA</string> . </void>
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):2102
    Entropy (8bit):4.697101824771924
    Encrypted:false
    SSDEEP:24:2dtNgRYPA6W6FC5A6c6dkbPhHAA6zHsCRx88KsvlPiNGZGVA6y:ctxPAbc6AJ4egAksCr8rK/GVAh
    MD5:C2AED002D4BCB9845E8F76E95C6A2F16
    SHA1:9355DBBD648633E17658B1215F1189384073B175
    SHA-256:1484764B5EC7B6F1B1FBAF72E3E8D0158E3EB743E0A6C9DA227EEB8FEDF93B53
    SHA-512:DE19021A208DB363831984C7CE8D83D6E17DAF545C9C74191FA4B0132CB90E15B43F83B8B58204299C0CA45F85DCBED58BCA24E7BD90611C59389C6E4F800E58
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?> .<java version="1.6.0_24" class="java.beans.XMLDecoder"> . <object class="OLServices.OSensorChannel"> . <void property="bitSize"> . <int>12</int> . </void> . <void property="channelNum"> . <int>1</int> . </void> . <void property="decimal"> . <int>3</int> . </void> . <void property="displayHigh"> . <double>12.5</double> . </void> . <void property="displayLow"> . <double>0.125</double> . </void> . <void property="firmware"> . <float>1.0</float> . </void> . <void property="gain"> . <int>2</int> . </void> . <void property="label"> . <string></string> . </void> . <void property="measurementHigh"> . <double>12.5</double> . </void> . <void property="measurementLow"> . <double>0.125</double> . </void> . <void property="measurementUnits"> . <string>m/s</string> . </void> . <void property="moduleType"> . <int>1</int> . </void> . <void property="nativeCurrentUnit"> . <string>mA</string> . </void> . <void p
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):4645
    Entropy (8bit):4.787865496391904
    Encrypted:false
    SSDEEP:48:cqC1/ttothioLlrdW8g3hTDxjNieIzAWK:xYFtothioLlrdjg3hTDxjQPEWK
    MD5:18D4AD6E400F30077BE6738D09053376
    SHA1:159F0B78DC1819E576ADB94AF46BE505D5BDDF77
    SHA-256:FF4F531BB4C21ED6FD3B6D51C398DCF947AFA2C03F2970925CBD11C1E2017AB7
    SHA-512:6184A7E251FEC52466DA3571CCDCC6A853157ED14E6995A48B32432675247CF3DD279EB5905B249E3F0821DC36B1DE173069CC4694B4196F0E0F67FEF99BDD30
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?>.<java version="1.8.0_31" class="java.beans.XMLDecoder">. <object class="OLServices.OSensorChannel" id="OSensorChannel0">. <void class="OLServices.OSensorChannel" method="getField">. <string>m_strNativeCurrentUnits</string>. <void method="set">. <object idref="OSensorChannel0"/>. <string>mA</string>. </void>. </void>. <void class="OLServices.OSensorChannel" method="getField">. <string>m_strNativeVoltageUnits</string>. <void method="set">. <object idref="OSensorChannel0"/>. <string>V</string>. </void>. </void>. <void class="OLServices.OSensorChannel" method="getField">. <string>m_OnsetPartValues</string>. <void method="set">. <object idref="OSensorChannel0"/>. <object class="java.util.ArrayList"/>. </void>. </void>. <void class="OLServices.OSensorChannel" method="getField">. <string>m_GainCurLow</string>. <void method="set">. <object idref="OSensorChannel0"/>. <object class="java.util.ArrayList">.
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):2253
    Entropy (8bit):4.708026908309753
    Encrypted:false
    SSDEEP:24:2dPkggA6sx62fCagA6s362DkbPhHAA6Jh6zjTtiHsCRx88hoBonPiNh/k2Z2VA6c:cPAANFRgADRegAoaMsCr8MCF2VA8Q
    MD5:865932A18700B21AF2E8FACB1ABC4060
    SHA1:C8F5D73A8A968EDB47D93B581F20E1FA88126E9C
    SHA-256:350748901BB0C8D571FD7B1D5051D70878EB97FCCE3ACC934BCE00D92D880A10
    SHA-512:2935E420185443902F999BCC7E1ADC8EC63CF46AF108FCFCBCEC0F148CDE2ACDAC8D533D355F37C83308B87B3AF533184AD96546A61274368FFD4DBD5075013C
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?> .<java version="1.5.0_04" class="java.beans.XMLDecoder"> . <object class="OLServices.OSensorChannel"> . <void property="decimal"> . <int>2</int> . </void> . <void property="displayHigh"> . <double>60.0</double> . </void> . <void property="displayLow"> . <double>-40.0</double>. </void> . <void property="firmware"> . <float>1.0</float> . </void> . <void property="gain"> . <int>3</int> . </void> . <void property="location"> . <string></string> . </void> . <void property="measurementHigh"> . <double>60.0</double> . </void> . <void property="measurementLow"> . <double>-40.0</double>. </void> . <void property="measurementUnits"> . <string>C</string> . </void> . <void property="moduleType"> . <int>1</int> . </void> . <void property="nativeCurrentUnit"> . <string>mA</string> . </void> . <void property="nativeHigh"> . <double>20.0</double> . </void> . <void property="nativeLow"> . <double>4.0</double> . <
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):4575
    Entropy (8bit):4.781062544023266
    Encrypted:false
    SSDEEP:24:2dqRQ1/tuees3ueeCWtgvvjx0S97Kg9z6Dx6ysT06DL6GktL6kmsTPyxenJeca03:cqC1/ttothi5WxPrWLJg3hTDx0NieIWK
    MD5:DA31CD45A81C5D18651A676AB7B9BDE1
    SHA1:AD210B1BC49B105C9E8AD9856BB4AF59580C9E05
    SHA-256:B1B43250A2B77581D5FD6BCDBBF46C9B4075F477BF363B6AB819AEBEF59453A3
    SHA-512:3F875C241DDCD1AB8308DC56FF0E657C963DF772CE63EBAC3A213713F76DE6A755A85EFB65271B25CFDA2C85C860AAB75FB0A27C52BB7A8E6039392F7CA99B33
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?>.<java version="1.8.0_31" class="java.beans.XMLDecoder">. <object class="OLServices.OSensorChannel" id="OSensorChannel0">. <void class="OLServices.OSensorChannel" method="getField">. <string>m_strNativeCurrentUnits</string>. <void method="set">. <object idref="OSensorChannel0"/>. <string>mA</string>. </void>. </void>. <void class="OLServices.OSensorChannel" method="getField">. <string>m_strNativeVoltageUnits</string>. <void method="set">. <object idref="OSensorChannel0"/>. <string>V</string>. </void>. </void>. <void class="OLServices.OSensorChannel" method="getField">. <string>m_OnsetPartValues</string>. <void method="set">. <object idref="OSensorChannel0"/>. <object class="java.util.ArrayList"/>. </void>. </void>. <void class="OLServices.OSensorChannel" method="getField">. <string>m_GainCurLow</string>. <void method="set">. <object idref="OSensorChannel0"/>. <object class="java.util.ArrayList">.
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):1848
    Entropy (8bit):4.850909873487343
    Encrypted:false
    SSDEEP:24:2dPkggA6XNkA64kkAA6+HsW4x88H2GPiN1JJkQZ9ZIVA64:cPAAWqAlEApsb8+obDIVAf
    MD5:89C7F5ED8EAD01EBDA0C040CF7B1B7AD
    SHA1:6418F778035CA809A88CFA3CF09F5D93E91A3823
    SHA-256:2D02433752B6CBD25663BB51B37F9C7AFA08AF9299F7421797490176F5D66ABC
    SHA-512:C912991746D7B60C2E9E4FEA5B9F0E790EC4AF7F7D316741BD7B19666901A74D925823B1910D3575E7645C59863420B181D0A77F90E8A802A4A338D76D02C34C
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?> .<java version="1.5.0_04" class="java.beans.XMLDecoder"> . <object class="OLServices.OSensorChannel"> . <void property="decimal"> . <int>2</int> . </void> . <void property="displayHigh"> . <double>706.2068965517242</double> . </void> . <void property="firmware"> . <float>2.2</float> . </void> . <void property="gain"> . <int>2</int> . </void> . <void property="location"> . <string></string> . </void> . <void property="measurementHigh"> . <double>706.2068965517242</double> . </void> . <void property="measurementUnits"> . <string>VAC</string> . </void> . <void property="moduleType"> . <int>2</int> . </void> . <void property="nativeHigh"> . <double>333.0</double>. </void> . <void property="nativeVoltageUnit"> . <string>&lt;HTML&gt;mV&lt;sub&gt;RMS&lt;/sub&gt;&lt;/HTML&gt;</string> . </void> . <void property="parentSensor"> . <object class="OLServices.OSensor"> . <void property="configurable"> . <boolea
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
    Category:dropped
    Size (bytes):1925
    Entropy (8bit):4.898726342725755
    Encrypted:false
    SSDEEP:48:cE7qIq2G80qEqiQGGySqXiG5N5ZqMq2WoqlzqLqbDWlP:N/5J0xWoS2vZlNG8WW5
    MD5:3EE13ED27F6E55A2F3DB840607BDF095
    SHA1:ECFA840AE511BE165655B3670B2F7BF60EF612EF
    SHA-256:BD92563A8C06B063A76F3598F2EEA6A5ED348D3B48F9DC8E701B9CD316C04B5E
    SHA-512:57959607ED5876166AE386181C821C75D40699984AF8E269210530C48D96FA6092C59A66EA3D8006D30D63A0F1683B0C5629A1B8A73F2A8E06A75269853388FE
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?> ..<java version="1.6.0_25" class="java.beans.XMLDecoder"> .. <object class="OLServices.OSensorChannel"> .. <void property="sampleSize"> .. <int>15</int> .. </void> .. <void property="decimal"> .. <int>2</int> .. </void> .. <void property="displayHigh"> .. <double>153.60153601536015</double> .. </void> .. <void property="firmware"> .. <float>2.7</float> .. </void> .. <void property="gain"> .. <int>2</int> .. </void> .. <void property="label"> .. <string></string> .. </void> .. <void property="measurementHigh"> .. <double>153.60153601536015</double> .. </void> .. <void property="measurementUnits"> .. <string>A</string> .. </void> .. <void property="moduleType"> .. <int>2</int> .. </void> .. <void property="nativeHigh"> .. <double>333.33</double> .. </void> .. <void property="nativeVoltageUnit"> .. <string>&lt;HTML&gt;mV&lt;sub&gt;RMS&lt;/sub&gt;&lt;/HTML&gt;</string> .. </void> .. <void property="parentSe
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):2167
    Entropy (8bit):4.7855365581451155
    Encrypted:false
    SSDEEP:24:2dPkgaA6P6tdCkA6t6t3kbPhHAA68h6mhHsCRx88hoBoRoPiNKqkOoZ2VA6R:cP6AQ0hAO6egA3VsCr8zWm2VA4
    MD5:324DEBD541887409BD48E5530415FDA1
    SHA1:013C96C4D371D73522748918B96A26CBFB706631
    SHA-256:EFBAEF2525F5DBB319E8580F08485D77CFD467CB23BFF040A64E67E4F4DA4A10
    SHA-512:0BDE095586502EC5AE490979D469174E09571A4D75B6BFA0E7751CF007500EC37B403B08EF43D727E9FAD6EBA782B22FB9BB084B524B103B265E1DDAB749BD58
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?> .<java version="1.5.0_04" class="java.beans.XMLDecoder"> . <object class="OLServices.OSensorChannel"> . <void property="decimal"> . <int>4</int> . </void> . <void property="displayHigh"> . <double>1.0</double> . </void> . <void property="displayLow"> . <double>0.009999999907799066</double> . </void> . <void property="firmware"> . <float>1.0</float> . </void> . <void property="gain"> . <int>2</int> . </void> . <void property="location"> . <string></string> . </void> . <void property="measurementHigh"> . <double>1.0</double> . </void> . <void property="measurementLow"> . <double>0.009999999907799066</double> . </void> . <void property="measurementUnits"> . <string>in WC</string> . </void> . <void property="moduleType"> . <int>1</int> . </void> . <void property="nativeCurrentUnit"> . <string>mA</string> . </void> . <void property="nativeHigh"> . <double>5.0</double> . </void> . <void property="nativeLo
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):1844
    Entropy (8bit):4.845499173067113
    Encrypted:false
    SSDEEP:24:2d2ggA68P5A62kkAA6gHsW4x88H2RPiNwkQZ+ZXGVA6sk:cmAZxAXEApsb8PbGXGVAk
    MD5:5F0FE3B49C78AF3C20F1C18DA2C7E2D9
    SHA1:2EAB4150DE30924A58160DCAE5E0E616BEA6D01E
    SHA-256:99E13E37758A11A4470495EDD1AC9D8D7BF86BACABDFBCCB942D1DD6EA5516DC
    SHA-512:BFFFF886A52906A80B54986C6369D079D0EE2A938A758336B1535BB6BA77CE9EB5F72484B662182A2E855B1B91C8E399EBB659071155E7BCBE5920B5A7995B49
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?> .<java version="1.6.0_21" class="java.beans.XMLDecoder"> . <object class="OLServices.OSensorChannel"> . <void property="decimal"> . <int>2</int> . </void> . <void property="displayHigh"> . <double>76.87687687687688</double> . </void> . <void property="firmware"> . <float>2.4</float> . </void> . <void property="gain"> . <int>2</int> . </void> . <void property="label"> . <string></string> . </void> . <void property="measurementHigh"> . <double>76.87687687687688</double> . </void> . <void property="measurementUnits"> . <string>A</string> . </void> . <void property="moduleType"> . <int>2</int> . </void> . <void property="nativeHigh"> . <double>333.0</double> . </void> . <void property="nativeVoltageUnit"> . <string>&lt;HTML&gt;mV&lt;sub&gt;RMS&lt;/sub&gt;&lt;/HTML&gt;</string> . </void> . <void property="parentSensor"> . <object class="OLServices.OSensor"> . <void property="configurable"> . <boolean>tr
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):4637
    Entropy (8bit):4.7844890259339685
    Encrypted:false
    SSDEEP:24:2dqRQ1/tuees3ueeCWtgvvjx0S97Kg9H06/6MsT06h6wktL6kmsTPyxenJeca0fC:cqC1/ttothip089rOXg3hTDxjNieIuA1
    MD5:6420E4CF0169150686C8912BF9DCF895
    SHA1:C9862BC6F9D8C7D1355C882FBDDE3FE19A7DA575
    SHA-256:FCE34E68681EC64C7338407D55607A705198C42475DFDDAE942B5B0C7849DF5A
    SHA-512:062E31568805BD525FFB144338B2BC5A51A782282237972D02D150FBB25ABADDD8B96D5C41B97C5F72CE495AE91DC00EAAF370BDF23FAE43C3A76F8B796F0E75
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?>.<java version="1.8.0_31" class="java.beans.XMLDecoder">. <object class="OLServices.OSensorChannel" id="OSensorChannel0">. <void class="OLServices.OSensorChannel" method="getField">. <string>m_strNativeCurrentUnits</string>. <void method="set">. <object idref="OSensorChannel0"/>. <string>mA</string>. </void>. </void>. <void class="OLServices.OSensorChannel" method="getField">. <string>m_strNativeVoltageUnits</string>. <void method="set">. <object idref="OSensorChannel0"/>. <string>V</string>. </void>. </void>. <void class="OLServices.OSensorChannel" method="getField">. <string>m_OnsetPartValues</string>. <void method="set">. <object idref="OSensorChannel0"/>. <object class="java.util.ArrayList"/>. </void>. </void>. <void class="OLServices.OSensorChannel" method="getField">. <string>m_GainCurLow</string>. <void method="set">. <object idref="OSensorChannel0"/>. <object class="java.util.ArrayList">.
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):2170
    Entropy (8bit):4.715346279692081
    Encrypted:false
    SSDEEP:24:2dtNgRaA6y6zC5A6I6kykbPhHAA6zHsCRx88hoBolPiNGZxVA60A6a:ctLA5i6A/ryegAksCr8i/xVANA1
    MD5:19E5A2551A102C33089D01B1EBD6ADBA
    SHA1:1717752564F6174D76AF2ABE468F6D248EC82FCC
    SHA-256:BE81B6D21537D00071A36104EBA38C02EF840DD254CF4CF8007FC5D20A43BAB4
    SHA-512:C377448842D7A5B3A105E35466EB19BF59F1A1C12F5475B43C8F53525E9CF5C1A646830DCFCC78106167646EB217C2E3D1198411A18CC8882721D0A18913BF7A
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?> .<java version="1.6.0_24" class="java.beans.XMLDecoder"> . <object class="OLServices.OSensorChannel"> . <void property="bitSize"> . <int>12</int> . </void> . <void property="channelNum"> . <int>1</int> . </void> . <void property="decimal"> . <int>1</int> . </void> . <void property="displayHigh"> . <double>1231.25</double> . </void> . <void property="displayLow"> . <double>12.3125</double> . </void> . <void property="firmware"> . <float>1.0</float> . </void> . <void property="gain"> . <int>2</int> . </void> . <void property="label"> . <string></string> . </void> . <void property="measurementHigh"> . <double>1231.25</double> . </void> . <void property="measurementLow"> . <double>12.3125</double> . </void> . <void property="measurementUnits"> . <string>fpm</string> . </void> . <void property="moduleType"> . <int>1</int> . </void> . <void property="nativeCurrentUnit"> . <string>mA</string> . </void>
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):2176
    Entropy (8bit):4.725357185022125
    Encrypted:false
    SSDEEP:24:2dtNgRaA6a6dC5A6w6eykbPhHAA6zHsCRx88KsvlPiNGZGVA6jA6a:ctLAtM6AjtyegAksCr8rK/GVA4A1
    MD5:51EC549EA5330018F000EC4131BCA195
    SHA1:FF6ED7D1DE2A92AD3C1FA8C5550997420F062BA0
    SHA-256:BA2C2D090C79CAF1F4852C62C20E7FAF5BFE9B2747D2D06DD63D0CCD9AD61ACF
    SHA-512:7878AFB10BD9DF81FF20F91C4D3F90C140853DD2E9DBD47EE59B5C03BFDA9908A54BE0E1939F40C0956EE5A191CA4D98B2623339614B629642AC499776C06E85
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?> .<java version="1.6.0_24" class="java.beans.XMLDecoder"> . <object class="OLServices.OSensorChannel"> . <void property="bitSize"> . <int>12</int> . </void> . <void property="channelNum"> . <int>1</int> . </void> . <void property="decimal"> . <int>1</int> . </void> . <void property="displayHigh"> . <double>2461.25</double> . </void> . <void property="displayLow"> . <double>24.6125</double> . </void> . <void property="firmware"> . <float>1.0</float> . </void> . <void property="gain"> . <int>2</int> . </void> . <void property="label"> . <string></string> . </void> . <void property="measurementHigh"> . <double>2461.25</double> . </void> . <void property="measurementLow"> . <double>24.6125</double> . </void> . <void property="measurementUnits"> . <string>fpm</string> . </void> . <void property="moduleType"> . <int>1</int> . </void> . <void property="nativeCurrentUnit"> . <string>mA</string> . </void>
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):2042
    Entropy (8bit):4.696043297520476
    Encrypted:false
    SSDEEP:24:2deggA6DT6YC5A6DB66kbPhHAA68HsCRx88KsvlPiNwkQZIVA6D8:cOAWT96AWBjegApsCr8rKbfIVAW8
    MD5:E7A76C164319DDDE78AEF84CA3FADD3C
    SHA1:936A077AA2B131DDF2D86545CE97B70EABF735CC
    SHA-256:4E00E8FC21CE049CF2ED5425A7BD5A8F4D5AC8414F21CF9D6098EA6F2DEB00C0
    SHA-512:180851E35F9151D8735651962257ABFBFDD8BAB82849EAE5B7DEE8BC1B58AB1A97A9ABD6C96D386C9D7D095688A62C96F016FA39BEE263B095C17D973C33AB58
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?> .<java version="1.6.0_14" class="java.beans.XMLDecoder"> . <object class="OLServices.OSensorChannel"> . <void property="decimal"> . <int>2</int> . </void> . <void property="displayHigh"> . <double>100.0</double> . </void> . <void property="displayLow"> . <double>1.0</double> . </void> . <void property="firmware"> . <float>1.0</float> . </void> . <void property="gain"> . <int>2</int> . </void> . <void property="label"> . <string></string> . </void> . <void property="measurementHigh"> . <double>100.0</double> . </void> . <void property="measurementLow"> . <double>1.0</double> . </void> . <void property="measurementUnits"> . <string>A</string> . </void> . <void property="moduleType"> . <int>1</int> . </void> . <void property="nativeCurrentUnit"> . <string>mA</string> . </void> . <void property="nativeHigh"> . <double>5.0</double> . </void> . <void property="nativeVoltageUnit"> . <string>V</string> .
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):1844
    Entropy (8bit):4.83914686553999
    Encrypted:false
    SSDEEP:24:2d2gNPA6GP5A68kkAA6gHsW4x88H2RPiNwkQZ+ZXGVA6k:cXPAPxA5EApsb8PbGXGVAT
    MD5:A7D652975DC6A845F6967B3CA7811812
    SHA1:3661F9F46C693B61D1933BC41AE33FB2732342E3
    SHA-256:538EED9E067889FE8E58068EB9E694A9DDF03129CC9FF59EA267AC7B85DF6112
    SHA-512:3025B686CAC5EFBD0FC31E03302A580FAEEC962BAB28E063CA511B537ED8759636A4A48A7D83529FB1161F3124060FD9B391DD27224F39D5ACD7EBEC1B0B4A05
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?> .<java version="1.6.0_21" class="java.beans.XMLDecoder"> . <object class="OLServices.OSensorChannel"> . <void property="decimal"> . <int>3</int> . </void> . <void property="displayHigh"> . <double>30.75075075075075</double> . </void> . <void property="firmware"> . <float>2.4</float> . </void> . <void property="gain"> . <int>2</int> . </void> . <void property="label"> . <string></string> . </void> . <void property="measurementHigh"> . <double>30.75075075075075</double> . </void> . <void property="measurementUnits"> . <string>A</string> . </void> . <void property="moduleType"> . <int>2</int> . </void> . <void property="nativeHigh"> . <double>333.0</double> . </void> . <void property="nativeVoltageUnit"> . <string>&lt;HTML&gt;mV&lt;sub&gt;RMS&lt;/sub&gt;&lt;/HTML&gt;</string> . </void> . <void property="parentSensor"> . <object class="OLServices.OSensor"> . <void property="configurable"> . <boolean>tr
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):4591
    Entropy (8bit):4.7929144448467875
    Encrypted:false
    SSDEEP:24:2dqRQ1/tuees3ueeCWtgvvjx0S97Kg9Y6G6ksT06w6X8ktL6kmsTPyxenJeca0fm:cqC1/ttothiuNJr3i8g3hTDxjNieIxAS
    MD5:17C67509C7782A0D242C522CDF8EC969
    SHA1:49CFD9510A4FD03F310154639B1864C313E932FA
    SHA-256:E37C98181CD5F5838D32D84A40683E0F419C4F4117BEDCD8A3926AE39BCF1B46
    SHA-512:2474E875D0B90AC380D2684CAA8F873FE6286252F88FBA03965F012B36F416E89898622E0886E3ACD045DD0ABB27E59B5BFC240BAA8EA30D6A8CD7613571040E
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?>.<java version="1.8.0_31" class="java.beans.XMLDecoder">. <object class="OLServices.OSensorChannel" id="OSensorChannel0">. <void class="OLServices.OSensorChannel" method="getField">. <string>m_strNativeCurrentUnits</string>. <void method="set">. <object idref="OSensorChannel0"/>. <string>mA</string>. </void>. </void>. <void class="OLServices.OSensorChannel" method="getField">. <string>m_strNativeVoltageUnits</string>. <void method="set">. <object idref="OSensorChannel0"/>. <string>V</string>. </void>. </void>. <void class="OLServices.OSensorChannel" method="getField">. <string>m_OnsetPartValues</string>. <void method="set">. <object idref="OSensorChannel0"/>. <object class="java.util.ArrayList"/>. </void>. </void>. <void class="OLServices.OSensorChannel" method="getField">. <string>m_GainCurLow</string>. <void method="set">. <object idref="OSensorChannel0"/>. <object class="java.util.ArrayList">.
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):1850
    Entropy (8bit):4.847725776532135
    Encrypted:false
    SSDEEP:24:2dPkggA6F/JKNkA6F/JJkkAA6+HsW4x88H2GPiN1JJkQZ9ZIVA65:cPAAyBKqAyBJEApsb8+obDIVAa
    MD5:79120B8CBE01876E0C445085A086605E
    SHA1:3A92452FE2665CE99FDC9756E05756FC86938B0E
    SHA-256:DF935A1539FC5BE688A2E87C747B4A1CE915E21A459F615A3CE0531ACE3CF317
    SHA-512:6A1D9ACDF66106E4EE51C2505FD91846D7124001BA0E3A3E604D73B49931AA24213E557A919E67754230AEC60836D6E6F1D02DE47D2B4D124C47B0ED1A3AE922
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?> .<java version="1.5.0_04" class="java.beans.XMLDecoder"> . <object class="OLServices.OSensorChannel"> . <void property="decimal"> . <int>2</int> . </void> . <void property="displayHigh"> . <double>176.55172413793105</double> . </void> . <void property="firmware"> . <float>2.2</float> . </void> . <void property="gain"> . <int>2</int> . </void> . <void property="location"> . <string></string> . </void> . <void property="measurementHigh"> . <double>176.55172413793105</double> . </void> . <void property="measurementUnits"> . <string>VAC</string> . </void> . <void property="moduleType"> . <int>2</int> . </void> . <void property="nativeHigh"> . <double>333.0</double>. </void> . <void property="nativeVoltageUnit"> . <string>&lt;HTML&gt;mV&lt;sub&gt;RMS&lt;/sub&gt;&lt;/HTML&gt;</string> . </void> . <void property="parentSensor"> . <object class="OLServices.OSensor"> . <void property="configurable"> . <bool
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):2043
    Entropy (8bit):4.699146054147112
    Encrypted:false
    SSDEEP:24:2degvA6iCa9A6skbPhHAA6Jh6zjTtiHsCRx88KsvlPiNVhkQZIVA6zD:chAlR9A3egAoaMsCr8rKIhfIVAO
    MD5:0B1FA0A4C92CF6D687580705CD4A8D57
    SHA1:10BA89BCB585281A0F7DF5684279F894E3306842
    SHA-256:76291A06E47A63FABA94F1A2E1E1D85035BD3CE234D6CA085219E956328D0046
    SHA-512:4F3F5EBD46F6A84A08FBB7418632B8C1FBE15750B8D6C77CACC273060CBEFA459D8BCB4BC381755BF6A00079AD76AD0A01A28CD693EEE3E749C24C441ECA0406
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?> .<java version="1.6.0_14" class="java.beans.XMLDecoder"> . <object class="OLServices.OSensorChannel"> . <void property="decimal"> . <int>1</int> . </void> . <void property="displayHigh"> . <double>1000.0</double> . </void> . <void property="firmware"> . <float>1.0</float> . </void> . <void property="gain"> . <int>3</int> . </void> . <void property="label"> . <string></string> . </void> . <void property="measurementHigh"> . <double>1000.0</double> . </void> . <void property="measurementUnits"> . <string>ppm</string> . </void> . <void property="moduleType"> . <int>1</int> . </void> . <void property="nativeCurrentUnit"> . <string>mA</string> . </void> . <void property="nativeHigh"> . <double>20.0</double> . </void> . <void property="nativeLow"> . <double>4.0</double> . </void> . <void property="nativeUnits"> . <boolean>false</boolean> . </void> . <void property="nativeVoltageUnit"> . <string>V</strin
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):1846
    Entropy (8bit):4.820073559111714
    Encrypted:false
    SSDEEP:24:2dPkggA6zwNkA6zykkAA6gHsW4x88HeGPiNwkQZ9ZIVA6E:cPAAewqAeyEApsb8qbDIVAd
    MD5:4245B074C0F39FAA93536CAB0763C752
    SHA1:C00AD2054CE212EFC9FC89D44323083859833945
    SHA-256:3D45E1748061083C1613C36E3211FAD4FC8962859FE7DFEB4E595C38DF983AF9
    SHA-512:E41FFAAD465AF9CCD4E8A647A79BEF056BD69623D614173514CA63B9B21B1736ECB624338DE00AF9806484D5192F4085D146C482B835DF262408E555B67FA3D6
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?> .<java version="1.5.0_04" class="java.beans.XMLDecoder"> . <object class="OLServices.OSensorChannel"> . <void property="decimal"> . <int>2</int> . </void> . <void property="displayHigh"> . <double>307.5075075075075</double> . </void> . <void property="firmware"> . <float>2.2</float> . </void> . <void property="gain"> . <int>2</int> . </void> . <void property="location"> . <string></string> . </void> . <void property="measurementHigh"> . <double>307.5075075075075</double> . </void> . <void property="measurementUnits"> . <string>A</string> . </void> . <void property="moduleType"> . <int>2</int> . </void> . <void property="nativeHigh"> . <double>333.0</double> . </void> . <void property="nativeVoltageUnit"> . <string>&lt;HTML&gt;mV&lt;sub&gt;RMS&lt;/sub&gt;&lt;/HTML&gt;</string> . </void> . <void property="parentSensor"> . <object class="OLServices.OSensor"> . <void property="configurable"> . <boolean
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
    Category:dropped
    Size (bytes):2197
    Entropy (8bit):4.7458662882733735
    Encrypted:false
    SSDEEP:48:cxqGq2I8sqBlqiQI2yTqUXXjTJrGedN5ODqMqBquqcoqlgqqqbDITqP:W95rsSlWaT7T9TdODlYyhpW2i
    MD5:00BDF057D9BFA6A288A37F50A65F770C
    SHA1:50D06EDC679D3C4CD53022CDEC44C54F23282404
    SHA-256:31AE6C513B012473AADDCF89606249F1B310AD654F50F406C60331AC90547D59
    SHA-512:D7F4FBC64C5EBD0C361767DB25BBF3D87A589B252E65DD2DAB658073AF29308AC65A2C6FB6183E635CBACC1D4BA20CCBDFCF62180D2091963F1C60D3321F40AC
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?> ..<java version="1.6.0_14" class="java.beans.XMLDecoder"> .. <object class="OLServices.OSensorChannel"> .. <void property="channelNum"> .. <int>1</int> .. </void> .. <void property="decimal"> .. <int>4</int> .. </void> .. <void property="displayHigh"> .. <double>1.0</double> .. </void> .. <void property="firmware"> .. <float>1.0</float> .. </void> .. <void property="gain"> .. <int>3</int> .. </void> .. <void property="label"> .. <string></string> .. </void> .. <void property="measurementHigh"> .. <double>1.0</double> .. </void> .. <void property="measurementUnits"> .. <string>in WC</string> .. </void> .. <void property="moduleType"> .. <int>1</int> .. </void> .. <void property="nativeCurrentUnit"> .. <string>mA</string> .. </void> .. <void property="nativeHigh"> .. <double>20.0</double> .. </void> .. <void property="nativeLow"> .. <double>4.0</double> .. </void> .. <void property="nativeUnits"> ..
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):2251
    Entropy (8bit):4.698086632799404
    Encrypted:false
    SSDEEP:24:2deggA6sM6CaBCa9A6sa6CafkbPhHAA6Jh6zjTtiHsCRx88KsvlPiNwkQZIVA6sM:cOAMUR9AauegAoaMsCr8rKbfIVAXc
    MD5:366D6DDE8039A519D609247A08FCE50D
    SHA1:E1E4757485F11A5CFB98A982014C7927491F9B0A
    SHA-256:40A32A436955148DB788AA36BC462552E81E7E9E0EF2A69593A6F5CD28089C9E
    SHA-512:AA292CB26E43D5D586A6F727F82A9ABD2A566C38CD3035EB742A9F0855EFEE1255EB1DB16B45BF58E88ACBACB32CE22E512A39708832BA0A11894E00CF307671
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?> .<java version="1.6.0_14" class="java.beans.XMLDecoder"> . <object class="OLServices.OSensorChannel"> . <void property="decimal"> . <int>2</int> . </void> . <void property="displayHigh"> . <double>50.0</double> . </void> . <void property="displayLow"> . <double>-50.0</double> . </void> . <void property="firmware"> . <float>1.0</float> . </void> . <void property="gain"> . <int>3</int> . </void> . <void property="label"> . <string></string> . </void> . <void property="measurementHigh"> . <double>50.0</double> . </void> . <void property="measurementLow"> . <double>-50.0</double> . </void> . <void property="measurementUnits"> . <string>A</string> . </void> . <void property="moduleType"> . <int>1</int> . </void> . <void property="nativeCurrentUnit"> . <string>mA</string> . </void> . <void property="nativeHigh"> . <double>20.0</double> . </void> . <void property="nativeLow"> . <double>4.0</double> . </
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):4637
    Entropy (8bit):4.7844890259339685
    Encrypted:false
    SSDEEP:24:2dqRQ1/tuees3ueeCWtgvvjx0S97Kg9H06/6MsT06h6wktL6kmsTPyxenJeca0fC:cqC1/ttothip089rOXg3hTDxjNieIuA1
    MD5:6420E4CF0169150686C8912BF9DCF895
    SHA1:C9862BC6F9D8C7D1355C882FBDDE3FE19A7DA575
    SHA-256:FCE34E68681EC64C7338407D55607A705198C42475DFDDAE942B5B0C7849DF5A
    SHA-512:062E31568805BD525FFB144338B2BC5A51A782282237972D02D150FBB25ABADDD8B96D5C41B97C5F72CE495AE91DC00EAAF370BDF23FAE43C3A76F8B796F0E75
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?>.<java version="1.8.0_31" class="java.beans.XMLDecoder">. <object class="OLServices.OSensorChannel" id="OSensorChannel0">. <void class="OLServices.OSensorChannel" method="getField">. <string>m_strNativeCurrentUnits</string>. <void method="set">. <object idref="OSensorChannel0"/>. <string>mA</string>. </void>. </void>. <void class="OLServices.OSensorChannel" method="getField">. <string>m_strNativeVoltageUnits</string>. <void method="set">. <object idref="OSensorChannel0"/>. <string>V</string>. </void>. </void>. <void class="OLServices.OSensorChannel" method="getField">. <string>m_OnsetPartValues</string>. <void method="set">. <object idref="OSensorChannel0"/>. <object class="java.util.ArrayList"/>. </void>. </void>. <void class="OLServices.OSensorChannel" method="getField">. <string>m_GainCurLow</string>. <void method="set">. <object idref="OSensorChannel0"/>. <object class="java.util.ArrayList">.
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):2049
    Entropy (8bit):4.717213097416067
    Encrypted:false
    SSDEEP:24:2dPkgNPA6BCagA6EkbPhHAA6Jh6zjTtiHsCRx88hovnPiNck2ZZVA6k:cPtPAERgADegAoaMsCr85zFZVAF
    MD5:730C1A4D1AC4C6CEECE1D1495B0C7EC8
    SHA1:989EB85BCB902A2FCEC50905C791F3FA6B5EC70F
    SHA-256:17AFE4E2BDC90E8FE3EAC13754EFE9E421225FF0EBB1D4974A61FF0410FAF02C
    SHA-512:08F13C015E6D9743052EAB89FC12C64BC23F90835E07AD4C3A258C35A52D352FA551127DA29A3A7772280D8687811BB0ABEACDAD5BBC3C691E8B5E30E7BE7D30
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?> .<java version="1.5.0_04" class="java.beans.XMLDecoder"> . <object class="OLServices.OSensorChannel"> . <void property="decimal"> . <int>3</int> . </void> . <void property="displayHigh"> . <double>83.14</double> . </void> . <void property="firmware"> . <float>1.0</float> . </void> . <void property="gain"> . <int>3</int> . </void> . <void property="location"> . <string></string> . </void> . <void property="measurementHigh"> . <double>83.14</double> . </void> . <void property="measurementUnits"> . <string>kW</string> . </void> . <void property="moduleType"> . <int>1</int> . </void> . <void property="nativeCurrentUnit"> . <string>mA</string> . </void> . <void property="nativeHigh"> . <double>20.0</double> . </void> . <void property="nativeLow"> . <double>4.0</double> . </void> . <void property="nativeUnits"> . <boolean>false</boolean> . </void> . <void property="nativeVoltageUnit"> . <string>V</strin
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):2098
    Entropy (8bit):4.69885864930346
    Encrypted:false
    SSDEEP:24:2dtNgRYPA6sa6QC5A6sw6UkbPhHAA6zHsCRx88hoBolPiNGZxVA6o:ctxPAev6AkzegAksCr8i/xVAF
    MD5:108FF73CF3C233E91F279B537B13CFAF
    SHA1:D0F5A820581ADEF28CBFE843EF62AB56CAEDA66D
    SHA-256:5AA5A59B99B30A31F87CB9A04AD23F3E18F86BA8597E4E5602D01015D17FD8CF
    SHA-512:981A9A6684D4807BEAFE2B0013E14E8EA50D6050B6B37FE149476509C98307FF0E4B8703AE14EE1CB986F8CDFC89506F5290608AE201351EAAE3D5FB9A8096A6
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?> .<java version="1.6.0_24" class="java.beans.XMLDecoder"> . <object class="OLServices.OSensorChannel"> . <void property="bitSize"> . <int>12</int> . </void> . <void property="channelNum"> . <int>1</int> . </void> . <void property="decimal"> . <int>3</int> . </void> . <void property="displayHigh"> . <double>6.25</double> . </void> . <void property="displayLow"> . <double>0.0625</double> . </void> . <void property="firmware"> . <float>1.0</float> . </void> . <void property="gain"> . <int>2</int> . </void> . <void property="label"> . <string></string> . </void> . <void property="measurementHigh"> . <double>6.25</double> . </void> . <void property="measurementLow"> . <double>0.0625</double> . </void> . <void property="measurementUnits"> . <string>m/s</string> . </void> . <void property="moduleType"> . <int>1</int> . </void> . <void property="nativeCurrentUnit"> . <string>mA</string> . </void> . <void
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):2197
    Entropy (8bit):4.705718077101039
    Encrypted:false
    SSDEEP:48:cmALt0g9AZtyegAoaMsCr8r5eRxIVAKtV:NALug9AZoegAoapCor58cAKz
    MD5:14D32366C410FB95AFAE68076F80A021
    SHA1:97E63109F9B702D155469426B78EF9FD716A87A3
    SHA-256:208CA225F997BA7DBEF15B407E18570C11809895717CB4045C351C9A563C709B
    SHA-512:88D530AEBC9E600783D675A482999B94E2902019A1E82BE4B232018435C24B56C3B3B9E4C93D301127255B7389DF6E15A6DA4E18F30F6062FE778AC7A770424F
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?> .<java version="1.6.0_21" class="java.beans.XMLDecoder"> . <object class="OLServices.OSensorChannel"> . <void property="decimal"> . <int>2</int> . </void> . <void property="displayHigh"> . <double>200.0</double> . </void> . <void property="displayLow"> . <double>0.0</double> . </void> . <void property="firmware"> . <float>1.5</float> . </void> . <void property="gain"> . <int>3</int> . </void> . <void property="label"> . <string></string> . </void> . <void property="measurementHigh"> . <double>200.0</double> . </void> . <void property="measurementLow"> . <double>0.0</double> . </void> . <void property="measurementUnits"> . <string>scfm</string> . </void> . <void property="moduleType"> . <int>1</int> . </void> . <void property="nativeCurrentUnit"> . <string>mA</string> . </void> . <void property="nativeHigh"> . <double>20.0</double> . </void> . <void property="nativeLow"> . <double>4.0</double> . <
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):2167
    Entropy (8bit):4.791888758562306
    Encrypted:false
    SSDEEP:24:2dPkgaA6T6UcuJTCkA6B6UcuJ1kbPhHAA68h6mhHsCRx88hoBoRoPiNKqkOoZ2V5:cP6AsB5hA6BregA3VsCr8zWm2VAE
    MD5:D6A8B90D86C8E95DD5DA85F65AF51B71
    SHA1:E2E3AC023B6437EF706B72EC7752E01F6C3298A2
    SHA-256:52412A445DEF3AC5E334B30A6831AA6ABE18E75FD1EEF2F353B9699F059B1351
    SHA-512:04106EC976253B4DB16F8E8F81D510400D62B8B638C8DC3D5B66E7BFAA7E5EEDBE88DD035C9790D5E74DAD5ADC905537A4B7376BACF85A893D617D00D97924AB
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?> .<java version="1.5.0_04" class="java.beans.XMLDecoder"> . <object class="OLServices.OSensorChannel"> . <void property="decimal"> . <int>4</int> . </void> . <void property="displayHigh"> . <double>5.0</double> . </void> . <void property="displayLow"> . <double>0.049999999538995324</double> . </void> . <void property="firmware"> . <float>1.0</float> . </void> . <void property="gain"> . <int>2</int> . </void> . <void property="location"> . <string></string> . </void> . <void property="measurementHigh"> . <double>5.0</double> . </void> . <void property="measurementLow"> . <double>0.049999999538995324</double> . </void> . <void property="measurementUnits"> . <string>in WC</string> . </void> . <void property="moduleType"> . <int>1</int> . </void> . <void property="nativeCurrentUnit"> . <string>mA</string> . </void> . <void property="nativeHigh"> . <double>5.0</double> . </void> . <void property="nativeLo
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):2040
    Entropy (8bit):4.6968526910296555
    Encrypted:false
    SSDEEP:24:2deggA6D0Ca9A6D6kbPhHAA6Jh6zjTtiHsCRx88KsvlPiNVhkQZIVA6DRD:cOAW0R9AW6egAoaMsCr8rKIhfIVAWB
    MD5:B76FF6FF23A12A51E026EC8C51399105
    SHA1:24B2B46DAD3CB56881E8CCAFF0DFF105E04E12D6
    SHA-256:D2295D68099365C9FF0C8DFC79B7782DBDE3A714967C2D72D606A89D63969662
    SHA-512:DFAF9BDC16FB880DC94B3200E8CD4F881CDB148D7D270F3FEA4D6FD9EFD05095813F08F339F8BFEB6548F383159C406FE985C7D2C28E180573329EE209B051EE
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?> .<java version="1.6.0_14" class="java.beans.XMLDecoder"> . <object class="OLServices.OSensorChannel"> . <void property="decimal"> . <int>2</int> . </void> . <void property="displayHigh"> . <double>100.0</double> . </void> . <void property="firmware"> . <float>1.0</float> . </void> . <void property="gain"> . <int>3</int> . </void> . <void property="label"> . <string></string> . </void> . <void property="measurementHigh"> . <double>100.0</double> . </void> . <void property="measurementUnits"> . <string>ppm</string> . </void> . <void property="moduleType"> . <int>1</int> . </void> . <void property="nativeCurrentUnit"> . <string>mA</string> . </void> . <void property="nativeHigh"> . <double>20.0</double> . </void> . <void property="nativeLow"> . <double>4.0</double> . </void> . <void property="nativeUnits"> . <boolean>false</boolean> . </void> . <void property="nativeVoltageUnit"> . <string>V</string>
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):2098
    Entropy (8bit):4.69885864930346
    Encrypted:false
    SSDEEP:24:2dtNgRYPA6sa6QC5A6sw6UkbPhHAA6zHsCRx88hoBolPiNGZxVA6o:ctxPAev6AkzegAksCr8i/xVAF
    MD5:108FF73CF3C233E91F279B537B13CFAF
    SHA1:D0F5A820581ADEF28CBFE843EF62AB56CAEDA66D
    SHA-256:5AA5A59B99B30A31F87CB9A04AD23F3E18F86BA8597E4E5602D01015D17FD8CF
    SHA-512:981A9A6684D4807BEAFE2B0013E14E8EA50D6050B6B37FE149476509C98307FF0E4B8703AE14EE1CB986F8CDFC89506F5290608AE201351EAAE3D5FB9A8096A6
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?> .<java version="1.6.0_24" class="java.beans.XMLDecoder"> . <object class="OLServices.OSensorChannel"> . <void property="bitSize"> . <int>12</int> . </void> . <void property="channelNum"> . <int>1</int> . </void> . <void property="decimal"> . <int>3</int> . </void> . <void property="displayHigh"> . <double>6.25</double> . </void> . <void property="displayLow"> . <double>0.0625</double> . </void> . <void property="firmware"> . <float>1.0</float> . </void> . <void property="gain"> . <int>2</int> . </void> . <void property="label"> . <string></string> . </void> . <void property="measurementHigh"> . <double>6.25</double> . </void> . <void property="measurementLow"> . <double>0.0625</double> . </void> . <void property="measurementUnits"> . <string>m/s</string> . </void> . <void property="moduleType"> . <int>1</int> . </void> . <void property="nativeCurrentUnit"> . <string>mA</string> . </void> . <void
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):2039
    Entropy (8bit):4.695841654053238
    Encrypted:false
    SSDEEP:24:2deggA6sM6wC5A6sa6ykbPhHAA68HsCRx88KsvlPiNwkQZIVA6sf:cOAMd6AaDegApsCr8rKbfIVAf
    MD5:118F730B99C6B7CA3242E6181952B215
    SHA1:BBA586313F8A577D4405403CA3560DEEDC1955FA
    SHA-256:59116DCBED34868897E283426360B6F0E2FCEFDC276E1AC0ECA167D5C819EEAB
    SHA-512:AFAB9AF146202C4F4521FE0DE9FE36377381B9A442398C48BC94F72EA51ADD64595F437984D958942BAFE46B5CA4FF35806EA4A4D98BAD6B933C49EE30E3EC4A
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?> .<java version="1.6.0_14" class="java.beans.XMLDecoder"> . <object class="OLServices.OSensorChannel"> . <void property="decimal"> . <int>2</int> . </void> . <void property="displayHigh"> . <double>50.0</double> . </void> . <void property="displayLow"> . <double>0.5</double> . </void> . <void property="firmware"> . <float>1.0</float> . </void> . <void property="gain"> . <int>2</int> . </void> . <void property="label"> . <string></string> . </void> . <void property="measurementHigh"> . <double>50.0</double> . </void> . <void property="measurementLow"> . <double>0.5</double> . </void> . <void property="measurementUnits"> . <string>A</string> . </void> . <void property="moduleType"> . <int>1</int> . </void> . <void property="nativeCurrentUnit"> . <string>mA</string> . </void> . <void property="nativeHigh"> . <double>5.0</double> . </void> . <void property="nativeVoltageUnit"> . <string>V</string> . <
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):2168
    Entropy (8bit):4.786077738497686
    Encrypted:false
    SSDEEP:24:2dPkgNPA6N6+CkA6D6EkbPhHAA68h6mhHsCRx88hoBoRoPiNKqkOoZ2VA6n:cPtPAYvhA2pegA3VsCr8zWm2VAw
    MD5:9BDD3BD21E679B7E6CCFF601C226581E
    SHA1:A77EEED73BB49A89D6FA4BD5BD8D93E24A16A61C
    SHA-256:F197A12544F6E1601566877CAD440AAF1370D01475C1D13B1ACB376EEF4E4769
    SHA-512:54CDD964A97F1E12A72B5984487EC93188F6F4A032925E7E8BC0B8C3CD821E2BF61528AE8C23A9481D685244459FDB38980A7BA4144492264F05AFF53E87461F
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?> .<java version="1.5.0_04" class="java.beans.XMLDecoder"> . <object class="OLServices.OSensorChannel"> . <void property="decimal"> . <int>3</int> . </void> . <void property="displayHigh"> . <double>10.0</double> . </void> . <void property="displayLow"> . <double>0.09999999907799065</double> . </void> . <void property="firmware"> . <float>1.0</float> . </void> . <void property="gain"> . <int>2</int> . </void> . <void property="location"> . <string></string> . </void> . <void property="measurementHigh"> . <double>10.0</double> . </void> . <void property="measurementLow"> . <double>0.09999999907799065</double> . </void> . <void property="measurementUnits"> . <string>in WC</string> . </void> . <void property="moduleType"> . <int>1</int> . </void> . <void property="nativeCurrentUnit"> . <string>mA</string> . </void> . <void property="nativeHigh"> . <double>5.0</double> . </void> . <void property="nativeLo
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):2171
    Entropy (8bit):4.720967811222828
    Encrypted:false
    SSDEEP:24:2dtNgRaA6a6dC5A6w6eykbPhHAA6zHsCRx88hoBolPiNGZxVA6jA6a:ctLAtM6AjtyegAksCr8i/xVA4A1
    MD5:745A386A56F4AF9412861B3B6F647C9C
    SHA1:156600A391D67DE1E04552E0EC7A7860CF2641F5
    SHA-256:ADD5677ACAD2C543840D8118CC151266CEDEFD7D3C2712118E9D6CD2765FAD64
    SHA-512:D6D9CB54BA49FD744349BA7E7E8C9AFE354E15642FD6A945203CE4A891499B2E56BB665A2A7390E853CFEEEB571A2D1F2B122B11C8C31BE5999F5F98604006B4
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?> .<java version="1.6.0_24" class="java.beans.XMLDecoder"> . <object class="OLServices.OSensorChannel"> . <void property="bitSize"> . <int>12</int> . </void> . <void property="channelNum"> . <int>1</int> . </void> . <void property="decimal"> . <int>1</int> . </void> . <void property="displayHigh"> . <double>2461.25</double> . </void> . <void property="displayLow"> . <double>24.6125</double> . </void> . <void property="firmware"> . <float>1.0</float> . </void> . <void property="gain"> . <int>2</int> . </void> . <void property="label"> . <string></string> . </void> . <void property="measurementHigh"> . <double>2461.25</double> . </void> . <void property="measurementLow"> . <double>24.6125</double> . </void> . <void property="measurementUnits"> . <string>fpm</string> . </void> . <void property="moduleType"> . <int>1</int> . </void> . <void property="nativeCurrentUnit"> . <string>mA</string> . </void>
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):1842
    Entropy (8bit):4.841008941594207
    Encrypted:false
    SSDEEP:24:2d2ggA68P5A62kkAA6gHsW4x88HeRPiNwkQZ+ZXGVA6sk:cmAZxAXEApsb8DbGXGVAk
    MD5:AACC7FFEEAABECE26445F14845D6308A
    SHA1:75E6D865417E23CD3B4BE0A97D1CFFEE4B4020FD
    SHA-256:85FEF4FC918F450AF07AE2CF2978AFAB2387410FC37A2B68F8E640C4F703EA6F
    SHA-512:8A3A4143760D2F42DC78F4E3DFFC850FF9D253777C3F5BECCC405212A16EFE1C2C6E0BBC25B158044436473A7924EE8351A0EBCE083B5FE494D4171C83AE8A1E
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?> .<java version="1.6.0_21" class="java.beans.XMLDecoder"> . <object class="OLServices.OSensorChannel"> . <void property="decimal"> . <int>2</int> . </void> . <void property="displayHigh"> . <double>76.87687687687688</double> . </void> . <void property="firmware"> . <float>2.4</float> . </void> . <void property="gain"> . <int>2</int> . </void> . <void property="label"> . <string></string> . </void> . <void property="measurementHigh"> . <double>76.87687687687688</double> . </void> . <void property="measurementUnits"> . <string>A</string> . </void> . <void property="moduleType"> . <int>2</int> . </void> . <void property="nativeHigh"> . <double>333.0</double> . </void> . <void property="nativeVoltageUnit"> . <string>&lt;HTML&gt;mV&lt;sub&gt;RMS&lt;/sub&gt;&lt;/HTML&gt;</string> . </void> . <void property="parentSensor"> . <object class="OLServices.OSensor"> . <void property="configurable"> . <boolean>tr
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):2165
    Entropy (8bit):4.798850979576279
    Encrypted:false
    SSDEEP:24:2dPkggA6s6xbCkA666xZkbPhHAA68h6mhHsCRx88hovRoPiNWkOoZ2VA6E:cPAALybhAZyZegA3VsCr8efm2VAd
    MD5:2DD5EF17E73787AE23B8F9434344D4CE
    SHA1:8046B12895C9B3390EA3B4C2F8BB22C3B7C527B4
    SHA-256:33BF7F4D569C84933377183C54097A5747E8FB7ABC861CC1497017023CE57D2D
    SHA-512:41FCC9AD76A5AE3755C0D90F351464F532D2D577DDFBE042A5639FC1E5FA7D5718263FC32E29E8D70E37AD306A9E863FD5682B4B7289BD9F81A05B40C700837F
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?> .<java version="1.5.0_04" class="java.beans.XMLDecoder"> . <object class="OLServices.OSensorChannel"> . <void property="decimal"> . <int>2</int> . </void> . <void property="displayHigh"> . <double>200.0</double> . </void> . <void property="displayLow"> . <double>1.999999981559813</double> . </void> . <void property="firmware"> . <float>1.0</float> . </void> . <void property="gain"> . <int>2</int> . </void> . <void property="location"> . <string></string> . </void> . <void property="measurementHigh"> . <double>200.0</double> . </void> . <void property="measurementLow"> . <double>1.999999981559813</double> . </void> . <void property="measurementUnits"> . <string>PSIG</string> . </void> . <void property="moduleType"> . <int>1</int> . </void> . <void property="nativeCurrentUnit"> . <string>mA</string> . </void> . <void property="nativeHigh"> . <double>5.0</double> . </void> . <void property="nativeLow">
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):1844
    Entropy (8bit):4.829670203039907
    Encrypted:false
    SSDEEP:24:2d2ggA6FP5A6LkkAA6gHsW4x88HeRPiNwkQZ+ZXGVA6u:cmACxAgEApsb8DbGXGVAR
    MD5:14BEC69534F024B97DAE6D7AB81C0D6D
    SHA1:387D2E46BDB4D38E3E8FE56D2B6506BB07B69BFE
    SHA-256:88AD4E184BD836F37AED12EE3BD8DCC52225DE50665B996C60F573D39EDE231E
    SHA-512:39BD68F771319646972DD9A0F7A25043A09C754863507EBB9660D899476FC4490C0915BE9877E82BDA52B85E9EBD35DFB3253421A0144B0CB87B6104BE3EC4AB
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?> .<java version="1.6.0_21" class="java.beans.XMLDecoder"> . <object class="OLServices.OSensorChannel"> . <void property="decimal"> . <int>2</int> . </void> . <void property="displayHigh"> . <double>115.31531531531532</double> . </void> . <void property="firmware"> . <float>2.4</float> . </void> . <void property="gain"> . <int>2</int> . </void> . <void property="label"> . <string></string> . </void> . <void property="measurementHigh"> . <double>115.31531531531532</double> . </void> . <void property="measurementUnits"> . <string>A</string> . </void> . <void property="moduleType"> . <int>2</int> . </void> . <void property="nativeHigh"> . <double>333.0</double> . </void> . <void property="nativeVoltageUnit"> . <string>&lt;HTML&gt;mV&lt;sub&gt;RMS&lt;/sub&gt;&lt;/HTML&gt;</string> . </void> . <void property="parentSensor"> . <object class="OLServices.OSensor"> . <void property="configurable"> . <boolean>
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):2103
    Entropy (8bit):4.703638612518744
    Encrypted:false
    SSDEEP:24:2dtNgRYPA6sa6QC5A6sw6UkbPhHAA6zHsCRx88KsvlPiNGZGVA6o:ctxPAev6AkzegAksCr8rK/GVAF
    MD5:F99EA010BF42D9A1ECC7F37CEAD87800
    SHA1:739C3F36DE8B2AFC4E72EE2D2CB4AA7106029B8E
    SHA-256:554097BDE2DFBFD8E9A241BADC6E45C6B80361E1938B8A7A6C050F105FCCA5D0
    SHA-512:C46C104416B96163D36213B5B1D6DC59ED5702084C485F1C95EC1C27243631C40D1F5869C9190048F9E1A305DCC0F33FB27D851222A099689AC2E27A80DF5D6C
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?> .<java version="1.6.0_24" class="java.beans.XMLDecoder"> . <object class="OLServices.OSensorChannel"> . <void property="bitSize"> . <int>12</int> . </void> . <void property="channelNum"> . <int>1</int> . </void> . <void property="decimal"> . <int>3</int> . </void> . <void property="displayHigh"> . <double>6.25</double> . </void> . <void property="displayLow"> . <double>0.0625</double> . </void> . <void property="firmware"> . <float>1.0</float> . </void> . <void property="gain"> . <int>2</int> . </void> . <void property="label"> . <string></string> . </void> . <void property="measurementHigh"> . <double>6.25</double> . </void> . <void property="measurementLow"> . <double>0.0625</double> . </void> . <void property="measurementUnits"> . <string>m/s</string> . </void> . <void property="moduleType"> . <int>1</int> . </void> . <void property="nativeCurrentUnit"> . <string>mA</string> . </void> . <void
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
    Category:dropped
    Size (bytes):2134
    Entropy (8bit):4.74909710980673
    Encrypted:false
    SSDEEP:48:c7q288sqBlqiQ82yTqUXXjTJrGedN5ODqMqBquqcoqlgqqqbD8TqP:S5XsSlWuT7T9TdODlYyhpW6i
    MD5:94CA047CE0D7B05614D78B3D8673A554
    SHA1:CD0AACDF3BFA611F09EE42FDAC17D1A497E30A7D
    SHA-256:832A28DEE2D270AF3849D14CDDC125AE071F74B2CDBCA51FC68797283AE62716
    SHA-512:F596DBDDF7659CA994E2A0F3B010B7DDB047DA3E5DF095DBD655C5DF024C3938F9E8C755F9CBEFD470F0015DAF5EB9469DFA71C039023E00B3B9F4602211402B
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?> ..<java version="1.6.0_21" class="java.beans.XMLDecoder"> .. <object class="OLServices.OSensorChannel"> .. <void property="decimal"> .. <int>5</int> .. </void> .. <void property="displayHigh"> .. <double>0.1</double> .. </void> .. <void property="firmware"> .. <float>1.0</float> .. </void> .. <void property="gain"> .. <int>3</int> .. </void> .. <void property="label"> .. <string></string> .. </void> .. <void property="measurementHigh"> .. <double>0.1</double> .. </void> .. <void property="measurementUnits"> .. <string>in WC</string> .. </void> .. <void property="moduleType"> .. <int>1</int> .. </void> .. <void property="nativeCurrentUnit"> .. <string>mA</string> .. </void> .. <void property="nativeHigh"> .. <double>20.0</double> .. </void> .. <void property="nativeLow"> .. <double>4.0</double> .. </void> .. <void property="nativeUnits"> .. <boolean>false</boolean> .. </void> .. <void property="nativ
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
    Category:dropped
    Size (bytes):2195
    Entropy (8bit):4.746955893969893
    Encrypted:false
    SSDEEP:48:cxqJq248sqBlqiQ42yTqUXXjTJrGedN5uqMqBquqcoqlgqqqbD4TqP:W65bsSlWKT7T9TdulYyhpWmi
    MD5:8BADB0A572B75514351CF8EA05A0CAC6
    SHA1:BCB59FE86DC4F75C0DD5BF86129ED9E533239182
    SHA-256:555C8352687CF6DF96D529E325EAE2C7D9C61B45533FC1781C04DA8952D6F75E
    SHA-512:64D822B80486FCCE036972465335C886E1D682672FF77B4F23AAA30B56C712FA56FB2C0D830A7AA400AE59085A68192FCDE6840465A1961F4A2FCC2D5864ECE6
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?> ..<java version="1.6.0_14" class="java.beans.XMLDecoder"> .. <object class="OLServices.OSensorChannel"> .. <void property="channelNum"> .. <int>1</int> .. </void> .. <void property="decimal"> .. <int>5</int> .. </void> .. <void property="displayHigh"> .. <double>0.25</double> .. </void> .. <void property="firmware"> .. <float>1.0</float> .. </void> .. <void property="gain"> .. <int>3</int> .. </void> .. <void property="label"> .. <string></string> .. </void> .. <void property="measurementHigh"> .. <double>0.25</double> .. </void> .. <void property="measurementUnits"> .. <string>in WC</string> .. </void> .. <void property="moduleType"> .. <int>1</int> .. </void> .. <void property="nativeCurrentUnit"> .. <string>mA</string> .. </void> .. <void property="nativeHigh"> .. <double>20.0</double> .. </void> .. <void property="nativeLow"> .. <double>4.0</double> .. </void> .. <void property="nativeUnits"> ..
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):2258
    Entropy (8bit):4.717404642998565
    Encrypted:false
    SSDEEP:24:2dPkggA6sx62fCagA6s362DkbPhHAA6Jh6zjTtiHsCRx88hovnPiNh/k2Z2VA6sP:cPAANFRgADRegAoaMsCr85CF2VA8Q
    MD5:3D55513237518F69C6077F0D35AFE27B
    SHA1:0DE507ABFB8B0ED005FD1A1F70DA15CB3EAF8936
    SHA-256:7CE5CFE47B28B4F8E6A1C4EBB8BD6939D41035CCB5EE02A6B847676A4F228049
    SHA-512:0E59E6512570EF1779368073AD8DF1C37656C9399E273595D8ABE0502016378A3A96CBEE1A267B6D70BBC19C847E4AB2C9CF63FE6EA1B781463C10171AEB1C36
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?> .<java version="1.5.0_04" class="java.beans.XMLDecoder"> . <object class="OLServices.OSensorChannel"> . <void property="decimal"> . <int>2</int> . </void> . <void property="displayHigh"> . <double>60.0</double> . </void> . <void property="displayLow"> . <double>-40.0</double>. </void> . <void property="firmware"> . <float>1.0</float> . </void> . <void property="gain"> . <int>3</int> . </void> . <void property="location"> . <string></string> . </void> . <void property="measurementHigh"> . <double>60.0</double> . </void> . <void property="measurementLow"> . <double>-40.0</double>. </void> . <void property="measurementUnits"> . <string>C</string> . </void> . <void property="moduleType"> . <int>1</int> . </void> . <void property="nativeCurrentUnit"> . <string>mA</string> . </void> . <void property="nativeHigh"> . <double>20.0</double> . </void> . <void property="nativeLow"> . <double>4.0</double> . <
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):2252
    Entropy (8bit):4.698524635664176
    Encrypted:false
    SSDEEP:24:2degvA6s6kCa9A666+kbPhHAA6Jh6zjTtiHsCRx88hoBolPiNwkQZIVA636M:chAL3R9AZhegAoaMsCr8ibfIVAK9
    MD5:4CA066EFA9AC01362378F2FCB4A1ACD3
    SHA1:DD6C4C3E944170DEB8D374B80F373E132DABFFF3
    SHA-256:5096E9D207A98F445987DC1D1CB1B0634DDC322D9B11435997865C48847300E4
    SHA-512:B1280B864D6B2EB27A5A23B8B0C3C2E3E6B3981D2447CFF84D3B436795497B97C2F2A82FDED1EDC0BB01C07AA0C7A0B6C4D1A73892F251B836371BE3B9EBE33E
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?> .<java version="1.6.0_14" class="java.beans.XMLDecoder"> . <object class="OLServices.OSensorChannel"> . <void property="decimal"> . <int>1</int> . </void> . <void property="displayHigh"> . <double>200.0</double> . </void> . <void property="displayLow"> . <double>-200.0</double> . </void> . <void property="firmware"> . <float>1.0</float> . </void> . <void property="gain"> . <int>3</int> . </void> . <void property="label"> . <string></string> . </void> . <void property="measurementHigh"> . <double>200.0</double> . </void> . <void property="measurementLow"> . <double>-200.0</double> . </void> . <void property="measurementUnits"> . <string>A</string> . </void> . <void property="moduleType"> . <int>1</int> . </void> . <void property="nativeCurrentUnit"> . <string>mA</string> . </void> . <void property="nativeHigh"> . <double>20.0</double> . </void> . <void property="nativeLow"> . <double>4.0</double> .
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):1846
    Entropy (8bit):4.84000400881574
    Encrypted:false
    SSDEEP:24:2d2gNPA6UP5A6ukkAA6gHsW4x88H2RPiNwkQZ+ZXGVA6n:cXPAXxABEApsb8PbGXGVAw
    MD5:437C8F425C4D854135174535CE58AB80
    SHA1:F6EEA4042ACE7C107BE14A65FD92702905CF93DB
    SHA-256:5F7A4B0F83F0F1E986F34A9DE712A3B561C39D3942258431D5B810AEBEF4F0CB
    SHA-512:7C2910F4F28C8716DFB902F72E7F50EE7F7EB365D5ADC16E76A8589EAAA7D3774A71B9B247EDEF6D5FE87B40370DC96A5A25D48452C7BFEEB07120C2F4E1C476
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?> .<java version="1.6.0_21" class="java.beans.XMLDecoder"> . <object class="OLServices.OSensorChannel"> . <void property="decimal"> . <int>3</int> . </void> . <void property="displayHigh"> . <double>15.375375375375375</double> . </void> . <void property="firmware"> . <float>2.4</float> . </void> . <void property="gain"> . <int>2</int> . </void> . <void property="label"> . <string></string> . </void> . <void property="measurementHigh"> . <double>15.375375375375375</double> . </void> . <void property="measurementUnits"> . <string>A</string> . </void> . <void property="moduleType"> . <int>2</int> . </void> . <void property="nativeHigh"> . <double>333.0</double> . </void> . <void property="nativeVoltageUnit"> . <string>&lt;HTML&gt;mV&lt;sub&gt;RMS&lt;/sub&gt;&lt;/HTML&gt;</string> . </void> . <void property="parentSensor"> . <object class="OLServices.OSensor"> . <void property="configurable"> . <boolean>
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):4635
    Entropy (8bit):4.783663504617974
    Encrypted:false
    SSDEEP:24:2dqRQ1/tuees3ueeCWtgvvjx0S97Kg9H06Y6CsT06a6OktL6kmsTPyxenJeca0fn:cqC1/ttothip0zVrFfg3hTDxjNieIbAV
    MD5:204EE035593E7DA0B05A6D12CC6C52E3
    SHA1:C1E77B5E60B7397C9C65BBDB309C687B76F93289
    SHA-256:146A221F2786367130E1061BCA75EA260DC0C4ED7D1E93F80FBA0A601E4B61E0
    SHA-512:93B9074668E4F7507977539B2433EAE54A3DA7387AB778F3877C7341853338DF7DD66F003CAF3469125A2DAD6CF2889F73A016306E017C5DAA6546A4FD9F2FAA
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?>.<java version="1.8.0_31" class="java.beans.XMLDecoder">. <object class="OLServices.OSensorChannel" id="OSensorChannel0">. <void class="OLServices.OSensorChannel" method="getField">. <string>m_strNativeCurrentUnits</string>. <void method="set">. <object idref="OSensorChannel0"/>. <string>mA</string>. </void>. </void>. <void class="OLServices.OSensorChannel" method="getField">. <string>m_strNativeVoltageUnits</string>. <void method="set">. <object idref="OSensorChannel0"/>. <string>V</string>. </void>. </void>. <void class="OLServices.OSensorChannel" method="getField">. <string>m_OnsetPartValues</string>. <void method="set">. <object idref="OSensorChannel0"/>. <object class="java.util.ArrayList"/>. </void>. </void>. <void class="OLServices.OSensorChannel" method="getField">. <string>m_GainCurLow</string>. <void method="set">. <object idref="OSensorChannel0"/>. <object class="java.util.ArrayList">.
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):2040
    Entropy (8bit):4.690944952938939
    Encrypted:false
    SSDEEP:24:2deggA6sBCa9A6sfkbPhHAA6Jh6zjTtiHsCRx88KsvlPiNwkQZIVA6sf:cOABR9AfegAoaMsCr8rKbfIVAf
    MD5:1D76C4113E2A57F1985805166D23FD9B
    SHA1:7DCA040F1D73DDCC48092438762093DF15D5A535
    SHA-256:6E652BD64DB875C7FF7E8A64F504921ED746D4C14B06B2F712861C5EE2A4BD89
    SHA-512:FAA6D029749E9F102EBB409104B3E16C934DEBC5DEE4311E1A2305AEC64EB4A285979598AA8C5C020001F5AA514ADD11C3DEF7621B5F75B2FE473F65C65B2CE7
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?> .<java version="1.6.0_14" class="java.beans.XMLDecoder"> . <object class="OLServices.OSensorChannel"> . <void property="decimal"> . <int>2</int> . </void> . <void property="displayHigh"> . <double>50.0</double> . </void> . <void property="firmware"> . <float>1.0</float> . </void> . <void property="gain"> . <int>3</int> . </void> . <void property="label"> . <string></string> . </void> . <void property="measurementHigh"> . <double>50.0</double> . </void> . <void property="measurementUnits"> . <string>A</string> . </void> . <void property="moduleType"> . <int>1</int> . </void> . <void property="nativeCurrentUnit"> . <string>mA</string> . </void> . <void property="nativeHigh"> . <double>20.0</double> . </void> . <void property="nativeLow"> . <double>4.0</double> . </void> . <void property="nativeUnits"> . <boolean>false</boolean> . </void> . <void property="nativeVoltageUnit"> . <string>V</string> .
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):2043
    Entropy (8bit):4.691923148601016
    Encrypted:false
    SSDEEP:24:2deggA6D0Ca9A6DOkbPhHAA6Jh6zjTtiHsCRx88KsvlPiNwkQZIVA6D8:cOAW0R9AWOegAoaMsCr8rKbfIVAW8
    MD5:1149B6441B3D58E0B7733C89E5547001
    SHA1:AF3A073A1C4A3E445521FC032D3DEF9618AECB18
    SHA-256:EAB294BDD295BADBCF4A18FBBB91881AA92604FD00382BB5FE905F8EED232F7E
    SHA-512:8435615E0A5C16E13C69154A8AB2D922D43F693B800B4DFD2174739B09F28A56B565365FF7C766CE18B9BF80E3A90A1C83BF65F03869785A575CE736133220AD
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?> .<java version="1.6.0_14" class="java.beans.XMLDecoder"> . <object class="OLServices.OSensorChannel"> . <void property="decimal"> . <int>2</int> . </void> . <void property="displayHigh"> . <double>100.0</double> . </void> . <void property="firmware"> . <float>1.0</float> . </void> . <void property="gain"> . <int>3</int> . </void> . <void property="label"> . <string></string> . </void> . <void property="measurementHigh"> . <double>100.0</double> . </void> . <void property="measurementUnits"> . <string>A</string> . </void> . <void property="moduleType"> . <int>1</int> . </void> . <void property="nativeCurrentUnit"> . <string>mA</string> . </void> . <void property="nativeHigh"> . <double>20.0</double> . </void> . <void property="nativeLow"> . <double>4.0</double> . </void> . <void property="nativeUnits"> . <boolean>false</boolean> . </void> . <void property="nativeVoltageUnit"> . <string>V</string> .
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):1846
    Entropy (8bit):4.832722618717603
    Encrypted:false
    SSDEEP:24:2d2ggA6FP5A6LkkAA6gHsW4x88H2RPiNwkQZ+ZXGVA6u:cmACxAgEApsb8PbGXGVAR
    MD5:01B473657F6FD80CF73027075B243B2B
    SHA1:C4F159962BA36FB22CE28D73C2633AB3BFB8741C
    SHA-256:7513C11F8C1738FB6AD4D6754F13BD99DC189A34FFB859791A2FFD3EDA50EB5E
    SHA-512:0123BF2606AEAD66F437A939FCEF846D16D5DCE9082F2C56B6457706AA52F348CF32EF83877A0D45F421D13B90521C28B557D51ABD72652A3FD2F236E3316961
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?> .<java version="1.6.0_21" class="java.beans.XMLDecoder"> . <object class="OLServices.OSensorChannel"> . <void property="decimal"> . <int>2</int> . </void> . <void property="displayHigh"> . <double>115.31531531531532</double> . </void> . <void property="firmware"> . <float>2.4</float> . </void> . <void property="gain"> . <int>2</int> . </void> . <void property="label"> . <string></string> . </void> . <void property="measurementHigh"> . <double>115.31531531531532</double> . </void> . <void property="measurementUnits"> . <string>A</string> . </void> . <void property="moduleType"> . <int>2</int> . </void> . <void property="nativeHigh"> . <double>333.0</double> . </void> . <void property="nativeVoltageUnit"> . <string>&lt;HTML&gt;mV&lt;sub&gt;RMS&lt;/sub&gt;&lt;/HTML&gt;</string> . </void> . <void property="parentSensor"> . <object class="OLServices.OSensor"> . <void property="configurable"> . <boolean>
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):4637
    Entropy (8bit):4.783861627938411
    Encrypted:false
    SSDEEP:48:cqC1/ttothizE2MrW2wg3hTDxjNieI2Ac:xYFtothizEfrWZg3hTDxjQPBc
    MD5:CDAC8A957E3FC7662222063F09290B9C
    SHA1:5132776E3C853318B5ED9C1CCC4A9E3F1A1D5803
    SHA-256:8D3CDCEA20D738CDE3A697E05DFA7BF62516044CE08701E52ADD3D06D2449100
    SHA-512:BF4BC3052F2F76A5A25B0664E6B0F5AD9BC15BC73A62263536D44C30735703283B6FDD1EA39E0773C94D5E054E3B057F4664AB50490F55A886CE287FEB7610AA
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?>.<java version="1.8.0_31" class="java.beans.XMLDecoder">. <object class="OLServices.OSensorChannel" id="OSensorChannel0">. <void class="OLServices.OSensorChannel" method="getField">. <string>m_strNativeCurrentUnits</string>. <void method="set">. <object idref="OSensorChannel0"/>. <string>mA</string>. </void>. </void>. <void class="OLServices.OSensorChannel" method="getField">. <string>m_strNativeVoltageUnits</string>. <void method="set">. <object idref="OSensorChannel0"/>. <string>V</string>. </void>. </void>. <void class="OLServices.OSensorChannel" method="getField">. <string>m_OnsetPartValues</string>. <void method="set">. <object idref="OSensorChannel0"/>. <object class="java.util.ArrayList"/>. </void>. </void>. <void class="OLServices.OSensorChannel" method="getField">. <string>m_GainCurLow</string>. <void method="set">. <object idref="OSensorChannel0"/>. <object class="java.util.ArrayList">.
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):2169
    Entropy (8bit):4.715999674519327
    Encrypted:false
    SSDEEP:24:2dtNgRaA6y6zC5A6I6kykbPhHAA6zHsCRx88hoBolPiNwZIVA60A6a:ctLA5i6A/ryegAksCr8ijIVANA1
    MD5:1B79817CB5367C3C44E0B01A220362DD
    SHA1:588633487A6281AB41EEE29ABB021C67DC53CAB4
    SHA-256:35F23027A65D35B74F0262CC1EC7B2F43E54D48A81D58C13D328DED42F0E9838
    SHA-512:5E275BE66063E3E5B03F5B4E0229FFE3F9D7898F343021FE056A262C896A7B6792A23BCA10274583410B5E001C5529ED71AACE20B4D466019AFB43F74C8437AC
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?> .<java version="1.6.0_24" class="java.beans.XMLDecoder"> . <object class="OLServices.OSensorChannel"> . <void property="bitSize"> . <int>12</int> . </void> . <void property="channelNum"> . <int>1</int> . </void> . <void property="decimal"> . <int>1</int> . </void> . <void property="displayHigh"> . <double>1231.25</double> . </void> . <void property="displayLow"> . <double>12.3125</double> . </void> . <void property="firmware"> . <float>1.0</float> . </void> . <void property="gain"> . <int>2</int> . </void> . <void property="label"> . <string></string> . </void> . <void property="measurementHigh"> . <double>1231.25</double> . </void> . <void property="measurementLow"> . <double>12.3125</double> . </void> . <void property="measurementUnits"> . <string>fpm</string> . </void> . <void property="moduleType"> . <int>1</int> . </void> . <void property="nativeCurrentUnit"> . <string>mA</string> . </void>
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
    Category:dropped
    Size (bytes):1924
    Entropy (8bit):4.893808562439816
    Encrypted:false
    SSDEEP:48:cE7q9lq2480qEqiQ4GySqXiG5N5ZqMq2WoqlzqLqbDXP:Nwl5b0xWaS2vZlNG8Wf
    MD5:C0507F23C31C0719C0083D7A6C0E47B7
    SHA1:F3BC6512AE80321124D7594F87211AF6A37C063F
    SHA-256:1FFF3DB9606E0D29A4D17A8F76D15881DE8F2E7B920CD9502B17D7A5AE8CB9A2
    SHA-512:C65CC21216137EEAE4F73BD3FE48C3FD9D5138CE39A3E0E9B5DB5C110C915F68AA72B9A0862AF15534205B635FF291946D346D069B9398D3E4F752292D0F4FE1
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?> ..<java version="1.6.0_25" class="java.beans.XMLDecoder"> .. <object class="OLServices.OSensorChannel"> .. <void property="sampleSize"> .. <int>15</int> .. </void> .. <void property="decimal"> .. <int>3</int> .. </void> .. <void property="displayHigh"> .. <double>30.720307203072032</double> .. </void> .. <void property="firmware"> .. <float>2.7</float> .. </void> .. <void property="gain"> .. <int>2</int> .. </void> .. <void property="label"> .. <string></string> .. </void> .. <void property="measurementHigh"> .. <double>30.720307203072032</double> .. </void> .. <void property="measurementUnits"> .. <string>A</string> .. </void> .. <void property="moduleType"> .. <int>2</int> .. </void> .. <void property="nativeHigh"> .. <double>333.33</double> .. </void> .. <void property="nativeVoltageUnit"> .. <string>&lt;HTML&gt;mV&lt;sub&gt;RMS&lt;/sub&gt;&lt;/HTML&gt;</string> .. </void> .. <void property="parentSe
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):2172
    Entropy (8bit):4.793436200652066
    Encrypted:false
    SSDEEP:24:2dPkgaA6P6tdCkA6t6t3kbPhHAA68h6mhHsCRx88hovRoPiNKqkOoZ2VA6R:cP6AQ0hAO6egA3VsCr8aWm2VA4
    MD5:4D9E736D77DD21390E6DCE27F962675E
    SHA1:0410CB32D51FE9C5C232AE983BACE753AFA0A3EB
    SHA-256:6383E33FABABF3DB5D6F2BC3C0B5AF11191C2CAB68862F407B662654DE073FE8
    SHA-512:9A74AF970BEFB30B533BE2274830C069A3BBEA5C565709AF0467CEF514640A02BE55336F6639C100378E101C6A5D6B980E2C6A4151A4AE76FA3CB8E86720F7E3
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?> .<java version="1.5.0_04" class="java.beans.XMLDecoder"> . <object class="OLServices.OSensorChannel"> . <void property="decimal"> . <int>4</int> . </void> . <void property="displayHigh"> . <double>1.0</double> . </void> . <void property="displayLow"> . <double>0.009999999907799066</double> . </void> . <void property="firmware"> . <float>1.0</float> . </void> . <void property="gain"> . <int>2</int> . </void> . <void property="location"> . <string></string> . </void> . <void property="measurementHigh"> . <double>1.0</double> . </void> . <void property="measurementLow"> . <double>0.009999999907799066</double> . </void> . <void property="measurementUnits"> . <string>in WC</string> . </void> . <void property="moduleType"> . <int>1</int> . </void> . <void property="nativeCurrentUnit"> . <string>mA</string> . </void> . <void property="nativeHigh"> . <double>5.0</double> . </void> . <void property="nativeLo
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):2172
    Entropy (8bit):4.799738986292041
    Encrypted:false
    SSDEEP:24:2dPkgaA6B6boCkA6n6bGkbPhHAA68h6mhHsCRx88hoBoRoPiNKqkOoZ2VA67:cP6AgdhA+3egA3VsCr8zWm2VAI
    MD5:70440CCA3B85F1BA5486B8246E2403F7
    SHA1:5BAD971B6ED85CE03757361DD73B442F32C84368
    SHA-256:596E058F8455BD6F343FA252136C828FBA615CAA2E2032AD419C6DCB546D456E
    SHA-512:7BB5E8A6E8F85FF3F932353E176B4BADE67DD4D5AA65CB950ADD7EE6028E1B5D5C1E31C3C8A1491FB1B93FA1FE8F89C34E18F5C56D118B8ED21CEB3AA73EEDD4
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?> .<java version="1.5.0_04" class="java.beans.XMLDecoder"> . <object class="OLServices.OSensorChannel"> . <void property="decimal"> . <int>4</int> . </void> . <void property="displayHigh"> . <double>0.25</double> . </void> . <void property="displayLow"> . <double>0.0024999999769497665</double> . </void> . <void property="firmware"> . <float>1.0</float> . </void> . <void property="gain"> . <int>2</int> . </void> . <void property="location"> . <string></string> . </void> . <void property="measurementHigh"> . <double>0.25</double> . </void> . <void property="measurementLow"> . <double>0.0024999999769497665</double> . </void> . <void property="measurementUnits"> . <string>in WC</string> . </void> . <void property="moduleType"> . <int>1</int> . </void> . <void property="nativeCurrentUnit"> . <string>mA</string> . </void> . <void property="nativeHigh"> . <double>5.0</double> . </void> . <void property="nati
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):2176
    Entropy (8bit):4.725357185022125
    Encrypted:false
    SSDEEP:24:2dtNgRaA6a6dC5A6w6eykbPhHAA6zHsCRx88KsvlPiNGZGVA6jA6a:ctLAtM6AjtyegAksCr8rK/GVA4A1
    MD5:51EC549EA5330018F000EC4131BCA195
    SHA1:FF6ED7D1DE2A92AD3C1FA8C5550997420F062BA0
    SHA-256:BA2C2D090C79CAF1F4852C62C20E7FAF5BFE9B2747D2D06DD63D0CCD9AD61ACF
    SHA-512:7878AFB10BD9DF81FF20F91C4D3F90C140853DD2E9DBD47EE59B5C03BFDA9908A54BE0E1939F40C0956EE5A191CA4D98B2623339614B629642AC499776C06E85
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?> .<java version="1.6.0_24" class="java.beans.XMLDecoder"> . <object class="OLServices.OSensorChannel"> . <void property="bitSize"> . <int>12</int> . </void> . <void property="channelNum"> . <int>1</int> . </void> . <void property="decimal"> . <int>1</int> . </void> . <void property="displayHigh"> . <double>2461.25</double> . </void> . <void property="displayLow"> . <double>24.6125</double> . </void> . <void property="firmware"> . <float>1.0</float> . </void> . <void property="gain"> . <int>2</int> . </void> . <void property="label"> . <string></string> . </void> . <void property="measurementHigh"> . <double>2461.25</double> . </void> . <void property="measurementLow"> . <double>24.6125</double> . </void> . <void property="measurementUnits"> . <string>fpm</string> . </void> . <void property="moduleType"> . <int>1</int> . </void> . <void property="nativeCurrentUnit"> . <string>mA</string> . </void>
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):2161
    Entropy (8bit):4.789862046378155
    Encrypted:false
    SSDEEP:24:2dPkggA6s6xbCkA666xZkbPhHAA68h6mhHsCRx88hoBoRoPiNWkOoZ2VA6E:cPAALybhAZyZegA3VsCr8zfm2VAd
    MD5:A105828FC7A874F3D835DA4190131492
    SHA1:A569793EDAED708DDF7A4971A0E45E68F5BFB2D3
    SHA-256:FC0BC03215E744AA5A5FEDB670D6ABCE5CED33B0B8AA7AEAFE52E05993DF6DA7
    SHA-512:41A7ACF69085E7B5D8A41ECABB768AC01E3C15F848EA213BFAF0DFFDB09D0EE9255902595B87E39B7253F49D9B21D69DA3EF75F2CEFCBF78FBB1E71828808217
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?> .<java version="1.5.0_04" class="java.beans.XMLDecoder"> . <object class="OLServices.OSensorChannel"> . <void property="decimal"> . <int>2</int> . </void> . <void property="displayHigh"> . <double>200.0</double> . </void> . <void property="displayLow"> . <double>1.999999981559813</double> . </void> . <void property="firmware"> . <float>1.0</float> . </void> . <void property="gain"> . <int>2</int> . </void> . <void property="location"> . <string></string> . </void> . <void property="measurementHigh"> . <double>200.0</double> . </void> . <void property="measurementLow"> . <double>1.999999981559813</double> . </void> . <void property="measurementUnits"> . <string>PSIG</string> . </void> . <void property="moduleType"> . <int>1</int> . </void> . <void property="nativeCurrentUnit"> . <string>mA</string> . </void> . <void property="nativeHigh"> . <double>5.0</double> . </void> . <void property="nativeLow">
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):2038
    Entropy (8bit):4.689226273251614
    Encrypted:false
    SSDEEP:24:2deggA6hCa9A6/kbPhHAA6Jh6zjTtiHsCRx88hoBolPiNwkQZIVA6/:cOAMR9AGegAoaMsCr8ibfIVAk
    MD5:D4534F544D630B37FFA32F3ABE101C77
    SHA1:035539C720F7ABF2758125DBDB568F004422C5BD
    SHA-256:E8B5B393884CC332CB82F8F3F6273D56E387AF36879BDEF6A3D11702B944C70D
    SHA-512:BBDC65E4A4DAAE72B46022B5E60B8F2A5C5BC8EE66B52C2350B4EDA92AD1938C376A4FD7BE67BA92563E80204F443DA64AE05B4D1E71B143DBA3F5ED0AE49684
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?> .<java version="1.6.0_14" class="java.beans.XMLDecoder"> . <object class="OLServices.OSensorChannel"> . <void property="decimal"> . <int>2</int> . </void> . <void property="displayHigh"> . <double>200.0</double> . </void> . <void property="firmware"> . <float>1.0</float> . </void> . <void property="gain"> . <int>3</int> . </void> . <void property="label"> . <string></string> . </void> . <void property="measurementHigh"> . <double>200.0</double> . </void> . <void property="measurementUnits"> . <string>A</string> . </void> . <void property="moduleType"> . <int>1</int> . </void> . <void property="nativeCurrentUnit"> . <string>mA</string> . </void> . <void property="nativeHigh"> . <double>20.0</double> . </void> . <void property="nativeLow"> . <double>4.0</double> . </void> . <void property="nativeUnits"> . <boolean>false</boolean> . </void> . <void property="nativeVoltageUnit"> . <string>V</string> .
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):2167
    Entropy (8bit):4.793536145319524
    Encrypted:false
    SSDEEP:24:2dPkgaA6t6rPKKCkA6j6rPKokbPhHAA68h6mhHsCRx88hoBoRoPiNKqkOoZ2VA6H:cP6AqzKhAgzoegA3VsCr8zWm2VAa
    MD5:6ADE984B05B0FF868F41B973E76082D6
    SHA1:6F51F844724480D9A0AC6DA0F51E0B5FF748CEA4
    SHA-256:15FEB41C48AA02D838CDB7B3FE3814929940F12F7476A8FCC720A994A1AF30E0
    SHA-512:80091AB122280D4BD1E889EA62A4CC8C396F1970F87AAFDF791EDF70A82EFC952AB74593B9717355976F7E69D76EA59CA053BEEB2F32F79F581B247A003FD708
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?> .<java version="1.5.0_04" class="java.beans.XMLDecoder"> . <object class="OLServices.OSensorChannel"> . <void property="decimal"> . <int>4</int> . </void> . <void property="displayHigh"> . <double>2.5</double> . </void> . <void property="displayLow"> . <double>0.024999999769497662</double> . </void> . <void property="firmware"> . <float>1.0</float> . </void> . <void property="gain"> . <int>2</int> . </void> . <void property="location"> . <string></string> . </void> . <void property="measurementHigh"> . <double>2.5</double> . </void> . <void property="measurementLow"> . <double>0.024999999769497662</double> . </void> . <void property="measurementUnits"> . <string>in WC</string> . </void> . <void property="moduleType"> . <int>1</int> . </void> . <void property="nativeCurrentUnit"> . <string>mA</string> . </void> . <void property="nativeHigh"> . <double>5.0</double> . </void> . <void property="nativeLo
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):2103
    Entropy (8bit):4.703638612518744
    Encrypted:false
    SSDEEP:24:2dtNgRYPA6sa6QC5A6sw6UkbPhHAA6zHsCRx88KsvlPiNGZGVA6o:ctxPAev6AkzegAksCr8rK/GVAF
    MD5:F99EA010BF42D9A1ECC7F37CEAD87800
    SHA1:739C3F36DE8B2AFC4E72EE2D2CB4AA7106029B8E
    SHA-256:554097BDE2DFBFD8E9A241BADC6E45C6B80361E1938B8A7A6C050F105FCCA5D0
    SHA-512:C46C104416B96163D36213B5B1D6DC59ED5702084C485F1C95EC1C27243631C40D1F5869C9190048F9E1A305DCC0F33FB27D851222A099689AC2E27A80DF5D6C
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?> .<java version="1.6.0_24" class="java.beans.XMLDecoder"> . <object class="OLServices.OSensorChannel"> . <void property="bitSize"> . <int>12</int> . </void> . <void property="channelNum"> . <int>1</int> . </void> . <void property="decimal"> . <int>3</int> . </void> . <void property="displayHigh"> . <double>6.25</double> . </void> . <void property="displayLow"> . <double>0.0625</double> . </void> . <void property="firmware"> . <float>1.0</float> . </void> . <void property="gain"> . <int>2</int> . </void> . <void property="label"> . <string></string> . </void> . <void property="measurementHigh"> . <double>6.25</double> . </void> . <void property="measurementLow"> . <double>0.0625</double> . </void> . <void property="measurementUnits"> . <string>m/s</string> . </void> . <void property="moduleType"> . <int>1</int> . </void> . <void property="nativeCurrentUnit"> . <string>mA</string> . </void> . <void
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
    Category:dropped
    Size (bytes):1923
    Entropy (8bit):4.900974258105984
    Encrypted:false
    SSDEEP:48:cE7qVq2LI80qEqiQLIGySqXiG5N5ZqMq2WoqlzqLqbDEP:NO5Lr0xWLKS2vZlNG8WA
    MD5:30B61B1FD5DEF073495794215CF0F4F1
    SHA1:5696C60BE8DC82FD2D7B10B955BB63077339985F
    SHA-256:3B930379E5E14BB662C3C2D31B2E2C424F3CB2DA45354F6AF44159DC019964F1
    SHA-512:B8080753874BD84EB6A376E98C3C266DDC517B9A50D1EC0685B913ADB841B9D82F2C3C48919A856114B57874AB37EB5AABCDEA5745D83D7ABB5F2B9C035D8310
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?> ..<java version="1.6.0_25" class="java.beans.XMLDecoder"> .. <object class="OLServices.OSensorChannel"> .. <void property="sampleSize"> .. <int>15</int> .. </void> .. <void property="decimal"> .. <int>1</int> .. </void> .. <void property="displayHigh"> .. <double>384.0038400384004</double> .. </void> .. <void property="firmware"> .. <float>2.7</float> .. </void> .. <void property="gain"> .. <int>2</int> .. </void> .. <void property="label"> .. <string></string> .. </void> .. <void property="measurementHigh"> .. <double>384.0038400384004</double> .. </void> .. <void property="measurementUnits"> .. <string>A</string> .. </void> .. <void property="moduleType"> .. <int>2</int> .. </void> .. <void property="nativeHigh"> .. <double>333.33</double> .. </void> .. <void property="nativeVoltageUnit"> .. <string>&lt;HTML&gt;mV&lt;sub&gt;RMS&lt;/sub&gt;&lt;/HTML&gt;</string> .. </void> .. <void property="parentSens
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):2163
    Entropy (8bit):4.789023565502049
    Encrypted:false
    SSDEEP:24:2dPkggA6DT6OCkA6DB6OkbPhHAA68h6mhHsCRx88hoBoRoPiNWkOoZ2VA6DV:cPAAWThhAWBfegA3VsCr8zfm2VAWV
    MD5:4844F2BE3A1308EF7E11D860B1D23E58
    SHA1:0519463E3B1CDCE7DB5CEBB9B973F5A751C91FF2
    SHA-256:A9DD209BBFB3DF8C190B76C5CA504855C54655B6C2813AD26D35EDB548FA9D91
    SHA-512:ABD14A998A55872BD79A372C4FFA7E3E5859376462DAB2B402FA01B8BDCADB2EB7FB4FFD8FBA93FF82931FCD7D7D25736F35954C19D51C063BA87838CE147826
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?> .<java version="1.5.0_04" class="java.beans.XMLDecoder"> . <object class="OLServices.OSensorChannel"> . <void property="decimal"> . <int>2</int> . </void> . <void property="displayHigh"> . <double>100.0</double> . </void> . <void property="displayLow"> . <double>0.9999999907799065</double> . </void> . <void property="firmware"> . <float>1.0</float> . </void> . <void property="gain"> . <int>2</int> . </void> . <void property="location"> . <string></string> . </void> . <void property="measurementHigh"> . <double>100.0</double> . </void> . <void property="measurementLow"> . <double>0.9999999907799065</double> . </void> . <void property="measurementUnits"> . <string>PSIG</string> . </void> . <void property="moduleType"> . <int>1</int> . </void> . <void property="nativeCurrentUnit"> . <string>mA</string> . </void> . <void property="nativeHigh"> . <double>5.0</double> . </void> . <void property="nativeLow
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
    Category:dropped
    Size (bytes):1920
    Entropy (8bit):4.893859464094678
    Encrypted:false
    SSDEEP:48:cE7qIq2b281qEqiQb2GySqXiG5N5NqMq2CoqlGlqLqbDkP:N/5b51xWb4S2vNlVRl8Wg
    MD5:B05FEBBE0296E80638CEC6611BFBFDFB
    SHA1:754F67AD1B1FEC4A474AF97C7495644501816B08
    SHA-256:A069FAA98011099986F67D8E896427BBA59000C03C3D242273C522B28586ABFF
    SHA-512:BDA222D47D39F870B819F01182E7260181791F829C76F366470FF8826C9B9464287D1D716C4C1C79F623A8555E33F352CECEB60FDE8D64E3D52459C18F14C35D
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?> ..<java version="1.6.0_25" class="java.beans.XMLDecoder"> .. <object class="OLServices.OSensorChannel"> .. <void property="sampleSize"> .. <int>15</int> .. </void> .. <void property="decimal"> .. <int>2</int> .. </void> .. <void property="displayHigh"> .. <double>76.80076800768008</double> .. </void> .. <void property="firmware"> .. <float>2.8</float> .. </void> .. <void property="gain"> .. <int>2</int> .. </void> .. <void property="label"> .. <string></string> .. </void> .. <void property="measurementHigh"> .. <double>76.80076800768008</double> .. </void> .. <void property="measurementUnits"> .. <string>A</string> .. </void> .. <void property="moduleType"> .. <int>2</int> .. </void> .. <void property="nativeHigh"> .. <double>333.33</double> .. </void> .. <void property="nativeVoltageUnit"> .. <string>&lt;HTML&gt;mV&lt;sub&gt;RMS&lt;/sub&gt;&lt;/HTML&gt;</string> .. </void> .. <void property="parentSens
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
    Category:dropped
    Size (bytes):1921
    Entropy (8bit):4.89396614621434
    Encrypted:false
    SSDEEP:48:cE7qVq2LI81qEqiQLIGySqXiG5N5NqMq2CoqlGlqLqbDEP:NO5Lr1xWLKS2vNlVRl8WA
    MD5:779C90DDDF1441701B73967508570842
    SHA1:09663703626D568C8A87E125CDD2D45A0CB6BC62
    SHA-256:A45AD7B38530BCC78427A4993D27F37E60F8BAC4D28EB9DD01675D0C91B4B7AE
    SHA-512:581BC677156A736976E20CC3AA9E670924B7CED8BC800BE34FC4DCBD259C86DD9E88173F2619BF743EDD9F44A091C49FE124F3685A68CCF269162507A3C370F7
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?> ..<java version="1.6.0_25" class="java.beans.XMLDecoder"> .. <object class="OLServices.OSensorChannel"> .. <void property="sampleSize"> .. <int>15</int> .. </void> .. <void property="decimal"> .. <int>1</int> .. </void> .. <void property="displayHigh"> .. <double>384.0038400384004</double> .. </void> .. <void property="firmware"> .. <float>2.8</float> .. </void> .. <void property="gain"> .. <int>2</int> .. </void> .. <void property="label"> .. <string></string> .. </void> .. <void property="measurementHigh"> .. <double>384.0038400384004</double> .. </void> .. <void property="measurementUnits"> .. <string>A</string> .. </void> .. <void property="moduleType"> .. <int>2</int> .. </void> .. <void property="nativeHigh"> .. <double>333.33</double> .. </void> .. <void property="nativeVoltageUnit"> .. <string>&lt;HTML&gt;mV&lt;sub&gt;RMS&lt;/sub&gt;&lt;/HTML&gt;</string> .. </void> .. <void property="parentSens
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):2165
    Entropy (8bit):4.801310540697106
    Encrypted:false
    SSDEEP:24:2dPkggA6L6W/cCkA6Z6W/UkbPhHAA68h6mhHsCRx88hovRoPiNWkOoZ2VA6d:cPAAswhA6QegA3VsCr8efm2VAE
    MD5:3F3BD3623265EBFC8F9544BA0F3E8118
    SHA1:FB7A5B3D1276BB05108DCC07536D97FAEADE573C
    SHA-256:10E87A717C87288A7A53FC34C7887ADDE2EBC1E72350605DC727E7F0A1764810
    SHA-512:DE5AC0BE6E54439A1D59774B46DC2DE0BC314B3E649CFB3D86D0960DC2A32AE557BB25BD35D22F995BDAC7C1E91290A81DCE9C5E233D4EF6CB4199C7E235C216
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?> .<java version="1.5.0_04" class="java.beans.XMLDecoder"> . <object class="OLServices.OSensorChannel"> . <void property="decimal"> . <int>2</int> . </void> . <void property="displayHigh"> . <double>500.0</double> . </void> . <void property="displayLow"> . <double>4.999999953899533</double> . </void> . <void property="firmware"> . <float>1.0</float> . </void> . <void property="gain"> . <int>2</int> . </void> . <void property="location"> . <string></string> . </void> . <void property="measurementHigh"> . <double>500.0</double> . </void> . <void property="measurementLow"> . <double>4.999999953899533</double> . </void> . <void property="measurementUnits"> . <string>PSIG</string> . </void> . <void property="moduleType"> . <int>1</int> . </void> . <void property="nativeCurrentUnit"> . <string>mA</string> . </void> . <void property="nativeHigh"> . <double>5.0</double> . </void> . <void property="nativeLow">
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):2043
    Entropy (8bit):4.693729841085976
    Encrypted:false
    SSDEEP:24:2deggA6hCa9A6/kbPhHAA6Jh6zjTtiHsCRx88KsvlPiNwkQZIVA6/:cOAMR9AGegAoaMsCr8rKbfIVAk
    MD5:569072D6FF46E80D4663546C3C9A982D
    SHA1:C9F531B3CEAFA6C1E0B8B5665A8963911373FBAE
    SHA-256:EB94BCD10B3B3B911E19470A7A13F046B64AC89DB50B2F1242FC191F58BD4597
    SHA-512:D9B65D2DA43556BF9553A21C02C7D53FD48C7F246D2546E3A4851C6C0B25B4704CF072489457AEE8A64802F37A88DC72E95656CB36079F6FEB082E859CDC447A
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?> .<java version="1.6.0_14" class="java.beans.XMLDecoder"> . <object class="OLServices.OSensorChannel"> . <void property="decimal"> . <int>2</int> . </void> . <void property="displayHigh"> . <double>200.0</double> . </void> . <void property="firmware"> . <float>1.0</float> . </void> . <void property="gain"> . <int>3</int> . </void> . <void property="label"> . <string></string> . </void> . <void property="measurementHigh"> . <double>200.0</double> . </void> . <void property="measurementUnits"> . <string>A</string> . </void> . <void property="moduleType"> . <int>1</int> . </void> . <void property="nativeCurrentUnit"> . <string>mA</string> . </void> . <void property="nativeHigh"> . <double>20.0</double> . </void> . <void property="nativeLow"> . <double>4.0</double> . </void> . <void property="nativeUnits"> . <boolean>false</boolean> . </void> . <void property="nativeVoltageUnit"> . <string>V</string> .
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):2175
    Entropy (8bit):4.7191379804434614
    Encrypted:false
    SSDEEP:24:2dtNgRaA6y6zC5A6I6kykbPhHAA6zHsCRx88KsvlPiNGZGVA60A6a:ctLA5i6A/ryegAksCr8rK/GVANA1
    MD5:3905D44C6F9DA798A86975A882617A87
    SHA1:3AF31342F40BEE3C940370879FD043FD5B605D47
    SHA-256:E712AB85B169FD2E2229E4215C462BD5DC096EF5140B08813A4F1896734221E6
    SHA-512:9E2FDD90E3CEF99768D71F9C97C0754F3FD98BC23922366770E09B42B4C4411EBB9DFF475BC3EA8185EC1EB93E10FC818CA2A3825169C9C59E4E56E3A07C0B8D
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?> .<java version="1.6.0_24" class="java.beans.XMLDecoder"> . <object class="OLServices.OSensorChannel"> . <void property="bitSize"> . <int>12</int> . </void> . <void property="channelNum"> . <int>1</int> . </void> . <void property="decimal"> . <int>1</int> . </void> . <void property="displayHigh"> . <double>1231.25</double> . </void> . <void property="displayLow"> . <double>12.3125</double> . </void> . <void property="firmware"> . <float>1.0</float> . </void> . <void property="gain"> . <int>2</int> . </void> . <void property="label"> . <string></string> . </void> . <void property="measurementHigh"> . <double>1231.25</double> . </void> . <void property="measurementLow"> . <double>12.3125</double> . </void> . <void property="measurementUnits"> . <string>fpm</string> . </void> . <void property="moduleType"> . <int>1</int> . </void> . <void property="nativeCurrentUnit"> . <string>mA</string> . </void>
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):1846
    Entropy (8bit):4.841055650209239
    Encrypted:false
    SSDEEP:24:2dPkggA6lT0KNkA6lT0JkkAA6+HsW4x88HeGPiN1JJkQZ9ZIVA69:cPAA04KqA04JEApsb8qobDIVA6
    MD5:175ED1362E98341308792533EF63C120
    SHA1:AF6EF70051917D0343C26BB4486692D7D6E0F7FF
    SHA-256:FF1191C1618BD1E59757DADDEE276F2DC37697AC5A575EB4D532B37D690D88A3
    SHA-512:70492074FC1FCB4819CD392D3D351443AA5BCAA1446738D2D40DB175FCBEED02EBE7A8D3A68B02322DAFDCEC6FFA627D8318788BCF234E51BCDCB0E2BC88DF36
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?> .<java version="1.5.0_04" class="java.beans.XMLDecoder"> . <object class="OLServices.OSensorChannel"> . <void property="decimal"> . <int>2</int> . </void> . <void property="displayHigh"> . <double>353.1034482758621</double> . </void> . <void property="firmware"> . <float>2.2</float> . </void> . <void property="gain"> . <int>2</int> . </void> . <void property="location"> . <string></string> . </void> . <void property="measurementHigh"> . <double>353.1034482758621</double> . </void> . <void property="measurementUnits"> . <string>VAC</string> . </void> . <void property="moduleType"> . <int>2</int> . </void> . <void property="nativeHigh"> . <double>333.0</double>. </void> . <void property="nativeVoltageUnit"> . <string>&lt;HTML&gt;mV&lt;sub&gt;RMS&lt;/sub&gt;&lt;/HTML&gt;</string> . </void> . <void property="parentSensor"> . <object class="OLServices.OSensor"> . <void property="configurable"> . <boolea
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):1842
    Entropy (8bit):4.83586329910079
    Encrypted:false
    SSDEEP:24:2d2gNPA6GP5A68kkAA6gHsW4x88HeRPiNwkQZ+ZXGVA6k:cXPAPxA5EApsb8DbGXGVAT
    MD5:3C0D233F427B0FA613F7A23E6387AAE9
    SHA1:74E81201DB46796A2DCDDFADB5AB09922C6ED253
    SHA-256:97BDD9B1D317FED661184B040E38E318BB375A92372F8D500A25C341D68E2441
    SHA-512:6BD2A00021284B3983E0A9A52D26B9C8E78687A64E54D36C08AB847DB27503C8549C963B2A0424C638774FF3F1F7C7254F6470B9113F8B8D8B8AF14C2FE62908
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?> .<java version="1.6.0_21" class="java.beans.XMLDecoder"> . <object class="OLServices.OSensorChannel"> . <void property="decimal"> . <int>3</int> . </void> . <void property="displayHigh"> . <double>30.75075075075075</double> . </void> . <void property="firmware"> . <float>2.4</float> . </void> . <void property="gain"> . <int>2</int> . </void> . <void property="label"> . <string></string> . </void> . <void property="measurementHigh"> . <double>30.75075075075075</double> . </void> . <void property="measurementUnits"> . <string>A</string> . </void> . <void property="moduleType"> . <int>2</int> . </void> . <void property="nativeHigh"> . <double>333.0</double> . </void> . <void property="nativeVoltageUnit"> . <string>&lt;HTML&gt;mV&lt;sub&gt;RMS&lt;/sub&gt;&lt;/HTML&gt;</string> . </void> . <void property="parentSensor"> . <object class="OLServices.OSensor"> . <void property="configurable"> . <boolean>tr
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):4639
    Entropy (8bit):4.787660286643185
    Encrypted:false
    SSDEEP:24:2dqRQ1/tuees3ueeCWtgvvjx0S97Kg9z646csT0666P8ktL6kmsTPyxenJeca0fR:cqC1/ttothi5ZLrzQ8g3hTDxjNieIdA/
    MD5:0CED8AD4D588A952B635D3A340A1BC88
    SHA1:9D8A3EA521BEF7BA8EFFA401000535785E55330B
    SHA-256:43504A2E538A08A632667225C38CF86D4F837DC368DFDAC86F5F2A29E45BC662
    SHA-512:592C5800FFF87C612E83733204382A9DEB934E1EBAC0291B30324A69E197CDEA7E4D4EE72887A2BBB73A379C118A17B599FC4B5DF9E1054E1A0BADED3609D9DD
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?>.<java version="1.8.0_31" class="java.beans.XMLDecoder">. <object class="OLServices.OSensorChannel" id="OSensorChannel0">. <void class="OLServices.OSensorChannel" method="getField">. <string>m_strNativeCurrentUnits</string>. <void method="set">. <object idref="OSensorChannel0"/>. <string>mA</string>. </void>. </void>. <void class="OLServices.OSensorChannel" method="getField">. <string>m_strNativeVoltageUnits</string>. <void method="set">. <object idref="OSensorChannel0"/>. <string>V</string>. </void>. </void>. <void class="OLServices.OSensorChannel" method="getField">. <string>m_OnsetPartValues</string>. <void method="set">. <object idref="OSensorChannel0"/>. <object class="java.util.ArrayList"/>. </void>. </void>. <void class="OLServices.OSensorChannel" method="getField">. <string>m_GainCurLow</string>. <void method="set">. <object idref="OSensorChannel0"/>. <object class="java.util.ArrayList">.
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):2257
    Entropy (8bit):4.701946999554782
    Encrypted:false
    SSDEEP:24:2degvA6s6kCa9A666+kbPhHAA6Jh6zjTtiHsCRx88KsvlPiNwkQZIVA636M:chAL3R9AZhegAoaMsCr8rKbfIVAK9
    MD5:6FD8ED2F4F251E14E299F41ABAFC0908
    SHA1:4B774E021FDC2985B82AACAF71CB205E1AD8A35D
    SHA-256:0CEE0396EF8E54B465F96C873B924AD31C2AAB87F43A39706CC5B07374555AC0
    SHA-512:75029C499EA03C4762AD24C566AB88BF00F6ADF1012F6A326DB555D9E15B3F0282EF0AA79CB6A34E9ED327D1630C04C7D67F7F398F14C50D95A54DF9E28FF659
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?> .<java version="1.6.0_14" class="java.beans.XMLDecoder"> . <object class="OLServices.OSensorChannel"> . <void property="decimal"> . <int>1</int> . </void> . <void property="displayHigh"> . <double>200.0</double> . </void> . <void property="displayLow"> . <double>-200.0</double> . </void> . <void property="firmware"> . <float>1.0</float> . </void> . <void property="gain"> . <int>3</int> . </void> . <void property="label"> . <string></string> . </void> . <void property="measurementHigh"> . <double>200.0</double> . </void> . <void property="measurementLow"> . <double>-200.0</double> . </void> . <void property="measurementUnits"> . <string>A</string> . </void> . <void property="moduleType"> . <int>1</int> . </void> . <void property="nativeCurrentUnit"> . <string>mA</string> . </void> . <void property="nativeHigh"> . <double>20.0</double> . </void> . <void property="nativeLow"> . <double>4.0</double> .
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):2034
    Entropy (8bit):4.690129032093012
    Encrypted:false
    SSDEEP:24:2deggA6sM6wC5A6sa6ykbPhHAA68HsCRx88hoBolPiNwkQZIVA6sf:cOAMd6AaDegApsCr8ibfIVAf
    MD5:7449B8421297CDB6DFC8C702D073ABC8
    SHA1:E2C7EA72BF96F94636837C763562A5D4F8B6B647
    SHA-256:44FFF878E5587ABE3EBCD9BE0BD09D847CEB73EBF1C7E7CF884E3403EC7B354D
    SHA-512:9A2764F6F379BB8B6AD4CC61F598BDF31DCBF923D38D1646B88DF652795EEE97A4B6D53531EC0738074A3A1BE4E8B894156EB149954963A763AECA3F3D0036EB
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?> .<java version="1.6.0_14" class="java.beans.XMLDecoder"> . <object class="OLServices.OSensorChannel"> . <void property="decimal"> . <int>2</int> . </void> . <void property="displayHigh"> . <double>50.0</double> . </void> . <void property="displayLow"> . <double>0.5</double> . </void> . <void property="firmware"> . <float>1.0</float> . </void> . <void property="gain"> . <int>2</int> . </void> . <void property="label"> . <string></string> . </void> . <void property="measurementHigh"> . <double>50.0</double> . </void> . <void property="measurementLow"> . <double>0.5</double> . </void> . <void property="measurementUnits"> . <string>A</string> . </void> . <void property="moduleType"> . <int>1</int> . </void> . <void property="nativeCurrentUnit"> . <string>mA</string> . </void> . <void property="nativeHigh"> . <double>5.0</double> . </void> . <void property="nativeVoltageUnit"> . <string>V</string> . <
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):1848
    Entropy (8bit):4.821056792459906
    Encrypted:false
    SSDEEP:24:2dPkggA6UKNkA6UokkAA6gHsW4x88H2GPiNwkQZ9ZIVA6sl:cPAAeqAUEApsb8+bDIVA5
    MD5:506F0D764BA17F46114FCA16E016FF7E
    SHA1:6ED7584E297ED010880C5B0ED510DC89EDA945E0
    SHA-256:2B0B07BB90C38535CB6B05B46D888E1F1BFF3585115248ACCD6E3198C290C3C1
    SHA-512:13E383D3F1373F518F5B42DEE57B7D090970988C8D745072DD17609ED0EE87D4FCC3E8CD0F30F51FB5216E98B570860353C5ACE35F9C99249ECA19D4C3F7ED47
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?> .<java version="1.5.0_04" class="java.beans.XMLDecoder"> . <object class="OLServices.OSensorChannel"> . <void property="decimal"> . <int>2</int> . </void> . <void property="displayHigh"> . <double>922.5225225225225</double> . </void> . <void property="firmware"> . <float>2.2</float> . </void> . <void property="gain"> . <int>2</int> . </void> . <void property="location"> . <string></string> . </void> . <void property="measurementHigh"> . <double>922.5225225225225</double> . </void> . <void property="measurementUnits"> . <string>A</string> . </void> . <void property="moduleType"> . <int>2</int> . </void> . <void property="nativeHigh"> . <double>333.0</double> . </void> . <void property="nativeVoltageUnit"> . <string>&lt;HTML&gt;mV&lt;sub&gt;RMS&lt;/sub&gt;&lt;/HTML&gt;</string> . </void> . <void property="parentSensor"> . <object class="OLServices.OSensor"> . <void property="configurable"> . <boolean
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):2170
    Entropy (8bit):4.715346279692081
    Encrypted:false
    SSDEEP:24:2dtNgRaA6y6zC5A6I6kykbPhHAA6zHsCRx88hoBolPiNGZxVA60A6a:ctLA5i6A/ryegAksCr8i/xVANA1
    MD5:19E5A2551A102C33089D01B1EBD6ADBA
    SHA1:1717752564F6174D76AF2ABE468F6D248EC82FCC
    SHA-256:BE81B6D21537D00071A36104EBA38C02EF840DD254CF4CF8007FC5D20A43BAB4
    SHA-512:C377448842D7A5B3A105E35466EB19BF59F1A1C12F5475B43C8F53525E9CF5C1A646830DCFCC78106167646EB217C2E3D1198411A18CC8882721D0A18913BF7A
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?> .<java version="1.6.0_24" class="java.beans.XMLDecoder"> . <object class="OLServices.OSensorChannel"> . <void property="bitSize"> . <int>12</int> . </void> . <void property="channelNum"> . <int>1</int> . </void> . <void property="decimal"> . <int>1</int> . </void> . <void property="displayHigh"> . <double>1231.25</double> . </void> . <void property="displayLow"> . <double>12.3125</double> . </void> . <void property="firmware"> . <float>1.0</float> . </void> . <void property="gain"> . <int>2</int> . </void> . <void property="label"> . <string></string> . </void> . <void property="measurementHigh"> . <double>1231.25</double> . </void> . <void property="measurementLow"> . <double>12.3125</double> . </void> . <void property="measurementUnits"> . <string>fpm</string> . </void> . <void property="moduleType"> . <int>1</int> . </void> . <void property="nativeCurrentUnit"> . <string>mA</string> . </void>
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):2098
    Entropy (8bit):4.69885864930346
    Encrypted:false
    SSDEEP:24:2dtNgRYPA6sa6QC5A6sw6UkbPhHAA6zHsCRx88hoBolPiNGZxVA6o:ctxPAev6AkzegAksCr8i/xVAF
    MD5:108FF73CF3C233E91F279B537B13CFAF
    SHA1:D0F5A820581ADEF28CBFE843EF62AB56CAEDA66D
    SHA-256:5AA5A59B99B30A31F87CB9A04AD23F3E18F86BA8597E4E5602D01015D17FD8CF
    SHA-512:981A9A6684D4807BEAFE2B0013E14E8EA50D6050B6B37FE149476509C98307FF0E4B8703AE14EE1CB986F8CDFC89506F5290608AE201351EAAE3D5FB9A8096A6
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?> .<java version="1.6.0_24" class="java.beans.XMLDecoder"> . <object class="OLServices.OSensorChannel"> . <void property="bitSize"> . <int>12</int> . </void> . <void property="channelNum"> . <int>1</int> . </void> . <void property="decimal"> . <int>3</int> . </void> . <void property="displayHigh"> . <double>6.25</double> . </void> . <void property="displayLow"> . <double>0.0625</double> . </void> . <void property="firmware"> . <float>1.0</float> . </void> . <void property="gain"> . <int>2</int> . </void> . <void property="label"> . <string></string> . </void> . <void property="measurementHigh"> . <double>6.25</double> . </void> . <void property="measurementLow"> . <double>0.0625</double> . </void> . <void property="measurementUnits"> . <string>m/s</string> . </void> . <void property="moduleType"> . <int>1</int> . </void> . <void property="nativeCurrentUnit"> . <string>mA</string> . </void> . <void
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):4591
    Entropy (8bit):4.7929144448467875
    Encrypted:false
    SSDEEP:24:2dqRQ1/tuees3ueeCWtgvvjx0S97Kg9Y6G6ksT06w6X8ktL6kmsTPyxenJeca0fm:cqC1/ttothiuNJr3i8g3hTDxjNieIxAS
    MD5:17C67509C7782A0D242C522CDF8EC969
    SHA1:49CFD9510A4FD03F310154639B1864C313E932FA
    SHA-256:E37C98181CD5F5838D32D84A40683E0F419C4F4117BEDCD8A3926AE39BCF1B46
    SHA-512:2474E875D0B90AC380D2684CAA8F873FE6286252F88FBA03965F012B36F416E89898622E0886E3ACD045DD0ABB27E59B5BFC240BAA8EA30D6A8CD7613571040E
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?>.<java version="1.8.0_31" class="java.beans.XMLDecoder">. <object class="OLServices.OSensorChannel" id="OSensorChannel0">. <void class="OLServices.OSensorChannel" method="getField">. <string>m_strNativeCurrentUnits</string>. <void method="set">. <object idref="OSensorChannel0"/>. <string>mA</string>. </void>. </void>. <void class="OLServices.OSensorChannel" method="getField">. <string>m_strNativeVoltageUnits</string>. <void method="set">. <object idref="OSensorChannel0"/>. <string>V</string>. </void>. </void>. <void class="OLServices.OSensorChannel" method="getField">. <string>m_OnsetPartValues</string>. <void method="set">. <object idref="OSensorChannel0"/>. <object class="java.util.ArrayList"/>. </void>. </void>. <void class="OLServices.OSensorChannel" method="getField">. <string>m_GainCurLow</string>. <void method="set">. <object idref="OSensorChannel0"/>. <object class="java.util.ArrayList">.
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):2038
    Entropy (8bit):4.687415148253197
    Encrypted:false
    SSDEEP:24:2deggA6D0Ca9A6DOkbPhHAA6Jh6zjTtiHsCRx88hoBolPiNwkQZIVA6D8:cOAW0R9AWOegAoaMsCr8ibfIVAW8
    MD5:15E85AFF1E7A41007090931DF90A6765
    SHA1:7A3356EDC057BC6E5CDBCFF432624002362EAB28
    SHA-256:E86C1D7D1FBCD97ED16E3757D5E23CEFC5BD9056F13DB47409759A80988B74B2
    SHA-512:10F4D765561D8E3C09A41F1CCD6ABDDD82A8928E2A7DA9C3FF1B6CB07C0C5370F976728D2060FACB40E3633DB4F900AD52284AF5C09AFCC2C7B98581AD0583B4
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?> .<java version="1.6.0_14" class="java.beans.XMLDecoder"> . <object class="OLServices.OSensorChannel"> . <void property="decimal"> . <int>2</int> . </void> . <void property="displayHigh"> . <double>100.0</double> . </void> . <void property="firmware"> . <float>1.0</float> . </void> . <void property="gain"> . <int>3</int> . </void> . <void property="label"> . <string></string> . </void> . <void property="measurementHigh"> . <double>100.0</double> . </void> . <void property="measurementUnits"> . <string>A</string> . </void> . <void property="moduleType"> . <int>1</int> . </void> . <void property="nativeCurrentUnit"> . <string>mA</string> . </void> . <void property="nativeHigh"> . <double>20.0</double> . </void> . <void property="nativeLow"> . <double>4.0</double> . </void> . <void property="nativeUnits"> . <boolean>false</boolean> . </void> . <void property="nativeVoltageUnit"> . <string>V</string> .
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):2195
    Entropy (8bit):4.702499989465588
    Encrypted:false
    SSDEEP:24:2degvA6sj6c0Ca9A6sx6cykbPhHAA6Jh6zjTtiHsCRx88KsvlPiNjkQZIVA6si6G:chAHt0R9AltyegAoaMsCr8rKefIVAetV
    MD5:378FCFDD7FF35BCD7B8E5CFF4AB17F9C
    SHA1:1FF4EBEBB28BCC4B32923B71F5159FB5CF862610
    SHA-256:4545AADD8B15AC911EA30D8F006DF9DFEDB21C8CA4B1074A2666A4534D17BAF4
    SHA-512:CE066F13425F2B4DF0382137218A7A7A9447EB07516D6C5B7417C7C5C0004FC6EE72199422C383F27AE7D962694DDAE00298FB3C8B334C4AF4D5BBED1C731EDC
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?> .<java version="1.6.0_14" class="java.beans.XMLDecoder"> . <object class="OLServices.OSensorChannel"> . <void property="decimal"> . <int>1</int> . </void> . <void property="displayHigh"> . <double>600.0</double> . </void> . <void property="displayLow"> . <double>0.0</double> . </void> . <void property="firmware"> . <float>1.0</float> . </void> . <void property="gain"> . <int>3</int> . </void> . <void property="label"> . <string></string> . </void> . <void property="measurementHigh"> . <double>600.0</double> . </void> . <void property="measurementLow"> . <double>0.0</double> . </void> . <void property="measurementUnits"> . <string>scfm</string> . </void> . <void property="moduleType"> . <int>1</int> . </void> . <void property="nativeCurrentUnit"> . <string>mA</string> . </void> . <void property="nativeHigh"> . <double>20.0</double> . </void> . <void property="nativeLow"> . <double>4.0</double> . <
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):2044
    Entropy (8bit):4.707664609309497
    Encrypted:false
    SSDEEP:24:2dPkggA6D0CagA6DmxkbPhHAA6Jh6zjTtiHsCRx88hovnPiN5k2ZBVA6DV:cPAAW0RgAWSegAoaMsCr85UFBVAWV
    MD5:469AE1D7DC67128DD71CE9DA227FD544
    SHA1:CB8391B3EE3818255E9099B2F7CDC2EB22EDD2BA
    SHA-256:B3E257F1B6BF6C3BB2FF55453A65997429C4B84AA5DA583F69852EBDF16EA899
    SHA-512:6C12103A84489D234CA44361D8284949E179FB4C3E52658136ECF8E436122B4F1100FCAD1E355A560B2ECC8D2A5E9703406A99C95C1C903D13246CBCE1C9468F
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?> .<java version="1.5.0_04" class="java.beans.XMLDecoder"> . <object class="OLServices.OSensorChannel"> . <void property="decimal"> . <int>2</int> . </void> . <void property="displayHigh"> . <double>100.0</double> . </void> . <void property="firmware"> . <float>1.0</float> . </void> . <void property="gain"> . <int>3</int> . </void> . <void property="location"> . <string></string> . </void> . <void property="measurementHigh"> . <double>100.0</double> . </void> . <void property="measurementUnits"> . <string>%</string> . </void> . <void property="moduleType"> . <int>1</int> . </void> . <void property="nativeCurrentUnit"> . <string>mA</string> . </void> . <void property="nativeHigh"> . <double>20.0</double> . </void> . <void property="nativeLow"> . <double>4.0</double> . </void> . <void property="nativeUnits"> . <boolean>false</boolean> . </void> . <void property="nativeVoltageUnit"> . <string>V</string
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):2103
    Entropy (8bit):4.703638612518744
    Encrypted:false
    SSDEEP:24:2dtNgRYPA6sa6QC5A6sw6UkbPhHAA6zHsCRx88KsvlPiNGZGVA6o:ctxPAev6AkzegAksCr8rK/GVAF
    MD5:F99EA010BF42D9A1ECC7F37CEAD87800
    SHA1:739C3F36DE8B2AFC4E72EE2D2CB4AA7106029B8E
    SHA-256:554097BDE2DFBFD8E9A241BADC6E45C6B80361E1938B8A7A6C050F105FCCA5D0
    SHA-512:C46C104416B96163D36213B5B1D6DC59ED5702084C485F1C95EC1C27243631C40D1F5869C9190048F9E1A305DCC0F33FB27D851222A099689AC2E27A80DF5D6C
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?> .<java version="1.6.0_24" class="java.beans.XMLDecoder"> . <object class="OLServices.OSensorChannel"> . <void property="bitSize"> . <int>12</int> . </void> . <void property="channelNum"> . <int>1</int> . </void> . <void property="decimal"> . <int>3</int> . </void> . <void property="displayHigh"> . <double>6.25</double> . </void> . <void property="displayLow"> . <double>0.0625</double> . </void> . <void property="firmware"> . <float>1.0</float> . </void> . <void property="gain"> . <int>2</int> . </void> . <void property="label"> . <string></string> . </void> . <void property="measurementHigh"> . <double>6.25</double> . </void> . <void property="measurementLow"> . <double>0.0625</double> . </void> . <void property="measurementUnits"> . <string>m/s</string> . </void> . <void property="moduleType"> . <int>1</int> . </void> . <void property="nativeCurrentUnit"> . <string>mA</string> . </void> . <void
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
    Category:dropped
    Size (bytes):2129
    Entropy (8bit):4.7440997825003866
    Encrypted:false
    SSDEEP:48:c7q288sqBlqiQ82yTqUXXjTJrGedN5uqMqBquqcoqlgqqqbD8TqP:S5XsSlWuT7T9TdulYyhpW6i
    MD5:3246D2AB84F762FF25CC25152364D7CF
    SHA1:03F83722A9FE20B2DA742D5CDECCA35B632FF053
    SHA-256:75222A1E667CA7BE7AF9B701A9E564C00E880873CFCDF830CE32D06DFF4A1325
    SHA-512:9EEB41B5CFF4832B8DF91D6FC4A43C4075A39B43838D2E9424A7263207E663B084555284E73C8D1557CFC826701DC81AFFCF909226E2E3B23C95119CB48773A3
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?> ..<java version="1.6.0_21" class="java.beans.XMLDecoder"> .. <object class="OLServices.OSensorChannel"> .. <void property="decimal"> .. <int>5</int> .. </void> .. <void property="displayHigh"> .. <double>0.1</double> .. </void> .. <void property="firmware"> .. <float>1.0</float> .. </void> .. <void property="gain"> .. <int>3</int> .. </void> .. <void property="label"> .. <string></string> .. </void> .. <void property="measurementHigh"> .. <double>0.1</double> .. </void> .. <void property="measurementUnits"> .. <string>in WC</string> .. </void> .. <void property="moduleType"> .. <int>1</int> .. </void> .. <void property="nativeCurrentUnit"> .. <string>mA</string> .. </void> .. <void property="nativeHigh"> .. <double>20.0</double> .. </void> .. <void property="nativeLow"> .. <double>4.0</double> .. </void> .. <void property="nativeUnits"> .. <boolean>false</boolean> .. </void> .. <void property="nativ
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):2102
    Entropy (8bit):4.697101824771924
    Encrypted:false
    SSDEEP:24:2dtNgRYPA6W6FC5A6c6dkbPhHAA6zHsCRx88KsvlPiNGZGVA6y:ctxPAbc6AJ4egAksCr8rK/GVAh
    MD5:C2AED002D4BCB9845E8F76E95C6A2F16
    SHA1:9355DBBD648633E17658B1215F1189384073B175
    SHA-256:1484764B5EC7B6F1B1FBAF72E3E8D0158E3EB743E0A6C9DA227EEB8FEDF93B53
    SHA-512:DE19021A208DB363831984C7CE8D83D6E17DAF545C9C74191FA4B0132CB90E15B43F83B8B58204299C0CA45F85DCBED58BCA24E7BD90611C59389C6E4F800E58
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?> .<java version="1.6.0_24" class="java.beans.XMLDecoder"> . <object class="OLServices.OSensorChannel"> . <void property="bitSize"> . <int>12</int> . </void> . <void property="channelNum"> . <int>1</int> . </void> . <void property="decimal"> . <int>3</int> . </void> . <void property="displayHigh"> . <double>12.5</double> . </void> . <void property="displayLow"> . <double>0.125</double> . </void> . <void property="firmware"> . <float>1.0</float> . </void> . <void property="gain"> . <int>2</int> . </void> . <void property="label"> . <string></string> . </void> . <void property="measurementHigh"> . <double>12.5</double> . </void> . <void property="measurementLow"> . <double>0.125</double> . </void> . <void property="measurementUnits"> . <string>m/s</string> . </void> . <void property="moduleType"> . <int>1</int> . </void> . <void property="nativeCurrentUnit"> . <string>mA</string> . </void> . <void p
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):1848
    Entropy (8bit):4.8457058308497984
    Encrypted:false
    SSDEEP:24:2dPkggA6lT0KNkA6lT0JkkAA6+HsW4x88H2GPiN1JJkQZ9ZIVA69:cPAA04KqA04JEApsb8+obDIVA6
    MD5:90422CB1D88DD65CEE620F6D012CC766
    SHA1:0F6176846D1895834C0777A40E42E5F5D3565884
    SHA-256:C1370EDFD73BB373A227A78570330A00ECC57C92E77DBB0C2A1826FBFAAD07CB
    SHA-512:296CDBA12200DF9C00714387FA18C3C6F86315EE3E6120284418908C7A0867A394A88C8913F98E55EABF944502FCE8DC3E5F9A311BA5F5000CA44F917F1F2A0F
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?> .<java version="1.5.0_04" class="java.beans.XMLDecoder"> . <object class="OLServices.OSensorChannel"> . <void property="decimal"> . <int>2</int> . </void> . <void property="displayHigh"> . <double>353.1034482758621</double> . </void> . <void property="firmware"> . <float>2.2</float> . </void> . <void property="gain"> . <int>2</int> . </void> . <void property="location"> . <string></string> . </void> . <void property="measurementHigh"> . <double>353.1034482758621</double> . </void> . <void property="measurementUnits"> . <string>VAC</string> . </void> . <void property="moduleType"> . <int>2</int> . </void> . <void property="nativeHigh"> . <double>333.0</double>. </void> . <void property="nativeVoltageUnit"> . <string>&lt;HTML&gt;mV&lt;sub&gt;RMS&lt;/sub&gt;&lt;/HTML&gt;</string> . </void> . <void property="parentSensor"> . <object class="OLServices.OSensor"> . <void property="configurable"> . <boolea
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):1850
    Entropy (8bit):4.835892551106481
    Encrypted:false
    SSDEEP:24:2dPkggA63NkA6hkkAA6gHsW4x88H2GPiNwkQZ9ZIVA6DV:cPAAQqASEApsb8+bDIVAWV
    MD5:72374B2E9C47CA877042A1EE3DD4A4D0
    SHA1:380C90F56FC49D5145A6A5ACDEFC6B698BEF356B
    SHA-256:C8EE9764DDCD6E668FA7A197C44C8FC8A71036EF433EC8120199DDEA4EF88BA0
    SHA-512:61523BADA1A21BFB30456D240EB22643FB3CF96E5C08815179C52E02C234B21C2F1FEA7321F63B0D5FB9C1977245A34B360C2D133359D87CC8802617BAF85B96
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?> .<java version="1.5.0_04" class="java.beans.XMLDecoder"> . <object class="OLServices.OSensorChannel"> . <void property="decimal"> . <int>2</int> . </void> . <void property="displayHigh"> . <double>153.75375375375376</double> . </void> . <void property="firmware"> . <float>2.2</float> . </void> . <void property="gain"> . <int>2</int> . </void> . <void property="location"> . <string></string> . </void> . <void property="measurementHigh"> . <double>153.75375375375376</double> . </void> . <void property="measurementUnits"> . <string>A</string> . </void> . <void property="moduleType"> . <int>2</int> . </void> . <void property="nativeHigh"> . <double>333.0</double> . </void> . <void property="nativeVoltageUnit"> . <string>&lt;HTML&gt;mV&lt;sub&gt;RMS&lt;/sub&gt;&lt;/HTML&gt;</string> . </void> . <void property="parentSensor"> . <object class="OLServices.OSensor"> . <void property="configurable"> . <boole
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
    Category:dropped
    Size (bytes):2200
    Entropy (8bit):4.751793460761203
    Encrypted:false
    SSDEEP:48:cxqJq248sqBlqiQ42yTqUXXjTJrGedN5ODqMqBquqcoqlgqqqbD4TqP:W65bsSlWKT7T9TdODlYyhpWmi
    MD5:76E466F409BBAFBF799102A3AA7433CB
    SHA1:DAE6DF40DD7F2F57B355957B9005F18336D91F95
    SHA-256:5A0B5E4F219E92F97CB746E3F1CD1A9B05DC24409A3868C8728265A3A67CAD43
    SHA-512:6A79D0ABA90DCFA077A8238408AE531A9C65EE36907A8F2E2294CB2E7A526DE5E0D3A5D8A17FD094B4540F886C725384B45C7FBAC2CE8F08446E32E54F816071
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?> ..<java version="1.6.0_14" class="java.beans.XMLDecoder"> .. <object class="OLServices.OSensorChannel"> .. <void property="channelNum"> .. <int>1</int> .. </void> .. <void property="decimal"> .. <int>5</int> .. </void> .. <void property="displayHigh"> .. <double>0.25</double> .. </void> .. <void property="firmware"> .. <float>1.0</float> .. </void> .. <void property="gain"> .. <int>3</int> .. </void> .. <void property="label"> .. <string></string> .. </void> .. <void property="measurementHigh"> .. <double>0.25</double> .. </void> .. <void property="measurementUnits"> .. <string>in WC</string> .. </void> .. <void property="moduleType"> .. <int>1</int> .. </void> .. <void property="nativeCurrentUnit"> .. <string>mA</string> .. </void> .. <void property="nativeHigh"> .. <double>20.0</double> .. </void> .. <void property="nativeLow"> .. <double>4.0</double> .. </void> .. <void property="nativeUnits"> ..
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):4645
    Entropy (8bit):4.787865496391904
    Encrypted:false
    SSDEEP:48:cqC1/ttothioLlrdW8g3hTDxjNieIzAWK:xYFtothioLlrdjg3hTDxjQPEWK
    MD5:18D4AD6E400F30077BE6738D09053376
    SHA1:159F0B78DC1819E576ADB94AF46BE505D5BDDF77
    SHA-256:FF4F531BB4C21ED6FD3B6D51C398DCF947AFA2C03F2970925CBD11C1E2017AB7
    SHA-512:6184A7E251FEC52466DA3571CCDCC6A853157ED14E6995A48B32432675247CF3DD279EB5905B249E3F0821DC36B1DE173069CC4694B4196F0E0F67FEF99BDD30
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?>.<java version="1.8.0_31" class="java.beans.XMLDecoder">. <object class="OLServices.OSensorChannel" id="OSensorChannel0">. <void class="OLServices.OSensorChannel" method="getField">. <string>m_strNativeCurrentUnits</string>. <void method="set">. <object idref="OSensorChannel0"/>. <string>mA</string>. </void>. </void>. <void class="OLServices.OSensorChannel" method="getField">. <string>m_strNativeVoltageUnits</string>. <void method="set">. <object idref="OSensorChannel0"/>. <string>V</string>. </void>. </void>. <void class="OLServices.OSensorChannel" method="getField">. <string>m_OnsetPartValues</string>. <void method="set">. <object idref="OSensorChannel0"/>. <object class="java.util.ArrayList"/>. </void>. </void>. <void class="OLServices.OSensorChannel" method="getField">. <string>m_GainCurLow</string>. <void method="set">. <object idref="OSensorChannel0"/>. <object class="java.util.ArrayList">.
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):4640
    Entropy (8bit):4.790030405722258
    Encrypted:false
    SSDEEP:24:2dqRQ1/tuees3ueeCWtgvvjx0S97Kg9z6n6C+sT06J6CtktL6kmsTPyxenJeca0j:cqC1/ttothi5qcrEXg3hTDx0NieIgA5
    MD5:676C060F748308A8AE89E5760A6FD948
    SHA1:1023B4279EC6CC26BD7183A60B0EA1494D5D14CF
    SHA-256:70F9F62E8F6F38D75B5442EB82819CEA20B28F7E358EEFB8D9A8701F2935D517
    SHA-512:0E0E643E2023520F9108761D2BE6B32093B4F58213F8A5DB6E9BA8514CD4515778E2DE88B923F5CA43D9264AB93AA67D0DBE114DF3DB00780DAB767621B502E3
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?>.<java version="1.8.0_31" class="java.beans.XMLDecoder">. <object class="OLServices.OSensorChannel" id="OSensorChannel0">. <void class="OLServices.OSensorChannel" method="getField">. <string>m_strNativeCurrentUnits</string>. <void method="set">. <object idref="OSensorChannel0"/>. <string>mA</string>. </void>. </void>. <void class="OLServices.OSensorChannel" method="getField">. <string>m_strNativeVoltageUnits</string>. <void method="set">. <object idref="OSensorChannel0"/>. <string>V</string>. </void>. </void>. <void class="OLServices.OSensorChannel" method="getField">. <string>m_OnsetPartValues</string>. <void method="set">. <object idref="OSensorChannel0"/>. <object class="java.util.ArrayList"/>. </void>. </void>. <void class="OLServices.OSensorChannel" method="getField">. <string>m_GainCurLow</string>. <void method="set">. <object idref="OSensorChannel0"/>. <object class="java.util.ArrayList">.
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):2173
    Entropy (8bit):4.793832670499144
    Encrypted:false
    SSDEEP:24:2dPkgNPA6N6+CkA6D6EkbPhHAA68h6mhHsCRx88hovRoPiNKqkOoZ2VA6n:cPtPAYvhA2pegA3VsCr8aWm2VAw
    MD5:1E196F1621F6DBA0017D0ACAE37DF2CD
    SHA1:D2980145DFC1184C636F5E316663EFA77F947954
    SHA-256:4F9F8EFE1D09F89CDC3440196DC020F030C0A23B20043B07BF1E25B0909682CD
    SHA-512:7E3DD755561621A3E39412830C7B7BE0F48F7B1FC564DE1F557B2F83D08CC3F69A972E3E7C99EBEEBC43DC0B1995B715D983094A707DAC318E5C86339E3D0723
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?> .<java version="1.5.0_04" class="java.beans.XMLDecoder"> . <object class="OLServices.OSensorChannel"> . <void property="decimal"> . <int>3</int> . </void> . <void property="displayHigh"> . <double>10.0</double> . </void> . <void property="displayLow"> . <double>0.09999999907799065</double> . </void> . <void property="firmware"> . <float>1.0</float> . </void> . <void property="gain"> . <int>2</int> . </void> . <void property="location"> . <string></string> . </void> . <void property="measurementHigh"> . <double>10.0</double> . </void> . <void property="measurementLow"> . <double>0.09999999907799065</double> . </void> . <void property="measurementUnits"> . <string>in WC</string> . </void> . <void property="moduleType"> . <int>1</int> . </void> . <void property="nativeCurrentUnit"> . <string>mA</string> . </void> . <void property="nativeHigh"> . <double>5.0</double> . </void> . <void property="nativeLo
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):1845
    Entropy (8bit):4.819194470301507
    Encrypted:false
    SSDEEP:24:2dPkgNPA6GNkA68kkAA6gHsW4x88HeGPiNwkQZ9ZIVA6k:cPtPAPqA5EApsb8qbDIVAT
    MD5:BD05E35AFE6A82578D2BDE609B709EC0
    SHA1:27C37A69F82B5D03E7400307464DAB3579E41EC6
    SHA-256:EDD8C1754BAE079170CA4CBADAEE536C0CA93296FE537C8A05B477D326BA12B2
    SHA-512:EB5DD2FCE74C48B95ECAD23B77DA9AF7ABC3619C1025C85C256A63429A5EA934298221EADAB27463EA4E003EBD1DA8CA41182439C208C464E0B30D99275CCB3D
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?> .<java version="1.5.0_04" class="java.beans.XMLDecoder"> . <object class="OLServices.OSensorChannel"> . <void property="decimal"> . <int>3</int> . </void> . <void property="displayHigh"> . <double>30.75075075075075</double> . </void> . <void property="firmware"> . <float>2.2</float> . </void> . <void property="gain"> . <int>2</int> . </void> . <void property="location"> . <string></string> . </void> . <void property="measurementHigh"> . <double>30.75075075075075</double> . </void> . <void property="measurementUnits"> . <string>A</string> . </void> . <void property="moduleType"> . <int>2</int> . </void> . <void property="nativeHigh"> . <double>333.0</double> . </void> . <void property="nativeVoltageUnit"> . <string>&lt;HTML&gt;mV&lt;sub&gt;RMS&lt;/sub&gt;&lt;/HTML&gt;</string> . </void> . <void property="parentSensor"> . <object class="OLServices.OSensor"> . <void property="configurable"> . <boolean
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):2042
    Entropy (8bit):4.698832079634908
    Encrypted:false
    SSDEEP:24:2deggA6s6hC5A666/kbPhHAA68HsCRx88KsvlPiNwkQZIVA6/:cOAL06AZOegApsCr8rKbfIVAk
    MD5:3F543BE16ADCE6065B36C1A927F974AE
    SHA1:A6D520EFCF5A14778F218B41B7696FED4E74D6AE
    SHA-256:3EAD9A3BCC725F380B56EAF56F31CF622AFB9D011A257C6FAA1C93956BF57D4D
    SHA-512:F07E1925EDC5DC580A9954AC684480AF7DA8B5AE1126ED5C610D466E2D3D11B995C2509FACD18C56917F908B8F5F425D763BDF0E434EC4EBEBF74BCFA9AD4EBD
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?> .<java version="1.6.0_14" class="java.beans.XMLDecoder"> . <object class="OLServices.OSensorChannel"> . <void property="decimal"> . <int>2</int> . </void> . <void property="displayHigh"> . <double>200.0</double> . </void> . <void property="displayLow"> . <double>2.0</double> . </void> . <void property="firmware"> . <float>1.0</float> . </void> . <void property="gain"> . <int>2</int> . </void> . <void property="label"> . <string></string> . </void> . <void property="measurementHigh"> . <double>200.0</double> . </void> . <void property="measurementLow"> . <double>2.0</double> . </void> . <void property="measurementUnits"> . <string>A</string> . </void> . <void property="moduleType"> . <int>1</int> . </void> . <void property="nativeCurrentUnit"> . <string>mA</string> . </void> . <void property="nativeHigh"> . <double>5.0</double> . </void> . <void property="nativeVoltageUnit"> . <string>V</string> .
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):2161
    Entropy (8bit):4.792431431155869
    Encrypted:false
    SSDEEP:24:2dPkggA6L6W/cCkA6Z6W/UkbPhHAA68h6mhHsCRx88hoBoRoPiNWkOoZ2VA6d:cPAAswhA6QegA3VsCr8zfm2VAE
    MD5:B36BBCDA923E33165B634828C3A3D1BE
    SHA1:D5C7978598103CD80482904408295638C29B6315
    SHA-256:DE4D54F6F9C04D6066327FFAF07BADBC6084B3F7CE9D7E123B678037E6EB1FAE
    SHA-512:6FF6E1AB7FD6B5DFEE4936895B8717B027C1A944B6644CD361D385DA72964568FE8AEAB94966FEC240CDB3AD662EBFF2AF0320DF77ECD0D33698C06279CD41FB
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?> .<java version="1.5.0_04" class="java.beans.XMLDecoder"> . <object class="OLServices.OSensorChannel"> . <void property="decimal"> . <int>2</int> . </void> . <void property="displayHigh"> . <double>500.0</double> . </void> . <void property="displayLow"> . <double>4.999999953899533</double> . </void> . <void property="firmware"> . <float>1.0</float> . </void> . <void property="gain"> . <int>2</int> . </void> . <void property="location"> . <string></string> . </void> . <void property="measurementHigh"> . <double>500.0</double> . </void> . <void property="measurementLow"> . <double>4.999999953899533</double> . </void> . <void property="measurementUnits"> . <string>PSIG</string> . </void> . <void property="moduleType"> . <int>1</int> . </void> . <void property="nativeCurrentUnit"> . <string>mA</string> . </void> . <void property="nativeHigh"> . <double>5.0</double> . </void> . <void property="nativeLow">
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):2256
    Entropy (8bit):4.708514326001123
    Encrypted:false
    SSDEEP:24:2dPkggA6T62fCagA6B62okbPhHAA6Jh6zjTtiHsCRx88hoBonPiNh/k2Z2VA6y6T:cPAAEFRgAymegAoaMsCr8MCF2VAvQ
    MD5:23460BDF4032A17A99C3939A15DE5C65
    SHA1:02AF2321D518F983BECB5DC4C21D9FEF4FB2D189
    SHA-256:38AC7E0EC1A0A6669B773B31E9DBD50FB749513EC6A579965910687B831DE971
    SHA-512:A332160CAFD1CF434D876137D30FB755AF6314604C04BC89D9A39BC6B5A3914E49E6F700EC50C9E68B23CC54329006AAC883148F38666F042D7C8074DE6B12D6
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?> .<java version="1.5.0_04" class="java.beans.XMLDecoder"> . <object class="OLServices.OSensorChannel"> . <void property="decimal"> . <int>2</int> . </void> . <void property="displayHigh"> . <double>140.0</double> . </void> . <void property="displayLow"> . <double>-40.0</double>. </void> . <void property="firmware"> . <float>1.0</float> . </void> . <void property="gain"> . <int>3</int> . </void> . <void property="location"> . <string></string> . </void> . <void property="measurementHigh"> . <double>140.0</double> . </void> . <void property="measurementLow"> . <double>-40.0</double>. </void> . <void property="measurementUnits"> . <string>F</string> . </void> . <void property="moduleType"> . <int>1</int> . </void> . <void property="nativeCurrentUnit"> . <string>mA</string> . </void> . <void property="nativeHigh"> . <double>20.0</double> . </void> . <void property="nativeLow"> . <double>4.0</double> .
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):4639
    Entropy (8bit):4.787660286643185
    Encrypted:false
    SSDEEP:24:2dqRQ1/tuees3ueeCWtgvvjx0S97Kg9z646csT0666P8ktL6kmsTPyxenJeca0fR:cqC1/ttothi5ZLrzQ8g3hTDxjNieIdA/
    MD5:0CED8AD4D588A952B635D3A340A1BC88
    SHA1:9D8A3EA521BEF7BA8EFFA401000535785E55330B
    SHA-256:43504A2E538A08A632667225C38CF86D4F837DC368DFDAC86F5F2A29E45BC662
    SHA-512:592C5800FFF87C612E83733204382A9DEB934E1EBAC0291B30324A69E197CDEA7E4D4EE72887A2BBB73A379C118A17B599FC4B5DF9E1054E1A0BADED3609D9DD
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?>.<java version="1.8.0_31" class="java.beans.XMLDecoder">. <object class="OLServices.OSensorChannel" id="OSensorChannel0">. <void class="OLServices.OSensorChannel" method="getField">. <string>m_strNativeCurrentUnits</string>. <void method="set">. <object idref="OSensorChannel0"/>. <string>mA</string>. </void>. </void>. <void class="OLServices.OSensorChannel" method="getField">. <string>m_strNativeVoltageUnits</string>. <void method="set">. <object idref="OSensorChannel0"/>. <string>V</string>. </void>. </void>. <void class="OLServices.OSensorChannel" method="getField">. <string>m_OnsetPartValues</string>. <void method="set">. <object idref="OSensorChannel0"/>. <object class="java.util.ArrayList"/>. </void>. </void>. <void class="OLServices.OSensorChannel" method="getField">. <string>m_GainCurLow</string>. <void method="set">. <object idref="OSensorChannel0"/>. <object class="java.util.ArrayList">.
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):2246
    Entropy (8bit):4.694482745460734
    Encrypted:false
    SSDEEP:24:2deggA6sM6CaBCa9A6sa6CafkbPhHAA6Jh6zjTtiHsCRx88hoBolPiNwkQZIVA6j:cOAMUR9AauegAoaMsCr8ibfIVAXc
    MD5:65D67A8D90AB6ECAEB8EEB92217BC992
    SHA1:1A6FCC1C3DFAB8DA74B8BB51262F1EC95CB7530E
    SHA-256:05532F71D29CB14A5C168076D303538DB9C9ADCED1239A1178575A12E9EA6078
    SHA-512:6248F6684993DE0E9082C04DE99A642A0640FDB2096AA533F27F84224571E59FBE367EB1CF26F88680E11DFB4D98788BE722DD753627AC81BEB9957ACA8B515A
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?> .<java version="1.6.0_14" class="java.beans.XMLDecoder"> . <object class="OLServices.OSensorChannel"> . <void property="decimal"> . <int>2</int> . </void> . <void property="displayHigh"> . <double>50.0</double> . </void> . <void property="displayLow"> . <double>-50.0</double> . </void> . <void property="firmware"> . <float>1.0</float> . </void> . <void property="gain"> . <int>3</int> . </void> . <void property="label"> . <string></string> . </void> . <void property="measurementHigh"> . <double>50.0</double> . </void> . <void property="measurementLow"> . <double>-50.0</double> . </void> . <void property="measurementUnits"> . <string>A</string> . </void> . <void property="moduleType"> . <int>1</int> . </void> . <void property="nativeCurrentUnit"> . <string>mA</string> . </void> . <void property="nativeHigh"> . <double>20.0</double> . </void> . <void property="nativeLow"> . <double>4.0</double> . </
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):2035
    Entropy (8bit):4.686290801511974
    Encrypted:false
    SSDEEP:24:2deggA6sBCa9A6sfkbPhHAA6Jh6zjTtiHsCRx88hoBolPiNwkQZIVA6sf:cOABR9AfegAoaMsCr8ibfIVAf
    MD5:6A95E257A854316AF956859625731EBB
    SHA1:2EA3A8B48AF5496A6C444348C6C9EC01C5E3547C
    SHA-256:67F214144170FDE365927AFEF35DE68045137560276147A1C0EBAE1186988009
    SHA-512:A19ED9D94DB65C89EE4D9F7ADB5D0A45FABF9D838B7791C96E42EAA9CD7E6CC577B4BA6865E936BDD31603FD96A055A7F2CFEF5A2FBB7FB8C14686D6832CE53F
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?> .<java version="1.6.0_14" class="java.beans.XMLDecoder"> . <object class="OLServices.OSensorChannel"> . <void property="decimal"> . <int>2</int> . </void> . <void property="displayHigh"> . <double>50.0</double> . </void> . <void property="firmware"> . <float>1.0</float> . </void> . <void property="gain"> . <int>3</int> . </void> . <void property="label"> . <string></string> . </void> . <void property="measurementHigh"> . <double>50.0</double> . </void> . <void property="measurementUnits"> . <string>A</string> . </void> . <void property="moduleType"> . <int>1</int> . </void> . <void property="nativeCurrentUnit"> . <string>mA</string> . </void> . <void property="nativeHigh"> . <double>20.0</double> . </void> . <void property="nativeLow"> . <double>4.0</double> . </void> . <void property="nativeUnits"> . <boolean>false</boolean> . </void> . <void property="nativeVoltageUnit"> . <string>V</string> .
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):1848
    Entropy (8bit):4.831298464154022
    Encrypted:false
    SSDEEP:24:2dPkggA63NkA6hkkAA6gHsW4x88HeGPiNwkQZ9ZIVA6DV:cPAAQqASEApsb8qbDIVAWV
    MD5:001DFF88E3D4FE420528A4BC6C319AAC
    SHA1:2087184416CB0C1473AB62E2752A4FB4959B430A
    SHA-256:BBB6B42296A8296D00DB8DBB8E2A41E4DEFF3CF3D882E34050B49D1E80ACFF11
    SHA-512:B914612479B5FF22B8894B8ABD7F0A508AF1DC4BD0A50A388BBE472D1E7A445E82B22A3D82BF9E884BEF77E5181E203B4D62E313BF065105536E4B8D01C0AF97
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?> .<java version="1.5.0_04" class="java.beans.XMLDecoder"> . <object class="OLServices.OSensorChannel"> . <void property="decimal"> . <int>2</int> . </void> . <void property="displayHigh"> . <double>153.75375375375376</double> . </void> . <void property="firmware"> . <float>2.2</float> . </void> . <void property="gain"> . <int>2</int> . </void> . <void property="location"> . <string></string> . </void> . <void property="measurementHigh"> . <double>153.75375375375376</double> . </void> . <void property="measurementUnits"> . <string>A</string> . </void> . <void property="moduleType"> . <int>2</int> . </void> . <void property="nativeHigh"> . <double>333.0</double> . </void> . <void property="nativeVoltageUnit"> . <string>&lt;HTML&gt;mV&lt;sub&gt;RMS&lt;/sub&gt;&lt;/HTML&gt;</string> . </void> . <void property="parentSensor"> . <object class="OLServices.OSensor"> . <void property="configurable"> . <boole
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):1844
    Entropy (8bit):4.836716780827435
    Encrypted:false
    SSDEEP:24:2d2gNPA6UP5A6ukkAA6gHsW4x88HeRPiNwkQZ+ZXGVA6n:cXPAXxABEApsb8DbGXGVAw
    MD5:209677E452B465E8387680EB885A9BAA
    SHA1:4F0F32CE9D24682C513759648F1DB5B74D575BEB
    SHA-256:7201688C7D89847C92EA7CF75A4EBFCD48A25A63B13F002D2532CB5A09564BAE
    SHA-512:9EBC34F084448AF03AEB98D8743803ED3F3201340CACF93DD6C3C65630310F4BDE6643824C92FB7C6CB1ED6A7DDA5394CCA33DA397ED6467122EEB61252D2DAC
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?> .<java version="1.6.0_21" class="java.beans.XMLDecoder"> . <object class="OLServices.OSensorChannel"> . <void property="decimal"> . <int>3</int> . </void> . <void property="displayHigh"> . <double>15.375375375375375</double> . </void> . <void property="firmware"> . <float>2.4</float> . </void> . <void property="gain"> . <int>2</int> . </void> . <void property="label"> . <string></string> . </void> . <void property="measurementHigh"> . <double>15.375375375375375</double> . </void> . <void property="measurementUnits"> . <string>A</string> . </void> . <void property="moduleType"> . <int>2</int> . </void> . <void property="nativeHigh"> . <double>333.0</double> . </void> . <void property="nativeVoltageUnit"> . <string>&lt;HTML&gt;mV&lt;sub&gt;RMS&lt;/sub&gt;&lt;/HTML&gt;</string> . </void> . <void property="parentSensor"> . <object class="OLServices.OSensor"> . <void property="configurable"> . <boolean>
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):2252
    Entropy (8bit):4.6949229707629865
    Encrypted:false
    SSDEEP:24:2degvA6DT61Ca9A6DB67kbPhHAA6Jh6zjTtiHsCRx88hoBolPiNwkQZIVA6Dy6b:chAWTCR9AWBgegAoaMsCr8ibfIVAWy6
    MD5:7DEC21E94EB6744A828AE0C7B7A82B5F
    SHA1:9C57AF2F64475AFD1238FC9886159AB20EE5844F
    SHA-256:862D8C36C0153333AFE80656128C3B419963A6B738856172395A3F065C755BC5
    SHA-512:840B9152880E55AE3547715442B607D0DB97EC2A6161F0EF48D36EEA4B161DCC952571F56C4DC603876452A89ACAA61559535AAB64D734F956F043976F3FB1EA
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?> .<java version="1.6.0_14" class="java.beans.XMLDecoder"> . <object class="OLServices.OSensorChannel"> . <void property="decimal"> . <int>1</int> . </void> . <void property="displayHigh"> . <double>100.0</double> . </void> . <void property="displayLow"> . <double>-100.0</double> . </void> . <void property="firmware"> . <float>1.0</float> . </void> . <void property="gain"> . <int>3</int> . </void> . <void property="label"> . <string></string> . </void> . <void property="measurementHigh"> . <double>100.0</double> . </void> . <void property="measurementLow"> . <double>-100.0</double> . </void> . <void property="measurementUnits"> . <string>A</string> . </void> . <void property="moduleType"> . <int>1</int> . </void> . <void property="nativeCurrentUnit"> . <string>mA</string> . </void> . <void property="nativeHigh"> . <double>20.0</double> . </void> . <void property="nativeLow"> . <double>4.0</double> .
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):2097
    Entropy (8bit):4.69201219060219
    Encrypted:false
    SSDEEP:24:2dtNgRYPA6W6FC5A6c6dkbPhHAA6zHsCRx88hoBolPiNGZxVA6y:ctxPAbc6AJ4egAksCr8i/xVAh
    MD5:4D09221C4036DFDD4A5C8B2252CE4173
    SHA1:05C4DD0E633368E46E1238081A80D672114677BC
    SHA-256:DDC7ADF90B5D34873E92558D6195411F88CAEB88476DDD7E8C33B480A2C161B9
    SHA-512:B994FA1B2D94199824070A35ED1F7D577A294DEE548B84B97C62E385CC3A282ED971197EE356AA04ED522F27EB33591C3CBE63D48E9CA95216DBAD5D98F24434
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?> .<java version="1.6.0_24" class="java.beans.XMLDecoder"> . <object class="OLServices.OSensorChannel"> . <void property="bitSize"> . <int>12</int> . </void> . <void property="channelNum"> . <int>1</int> . </void> . <void property="decimal"> . <int>3</int> . </void> . <void property="displayHigh"> . <double>12.5</double> . </void> . <void property="displayLow"> . <double>0.125</double> . </void> . <void property="firmware"> . <float>1.0</float> . </void> . <void property="gain"> . <int>2</int> . </void> . <void property="label"> . <string></string> . </void> . <void property="measurementHigh"> . <double>12.5</double> . </void> . <void property="measurementLow"> . <double>0.125</double> . </void> . <void property="measurementUnits"> . <string>m/s</string> . </void> . <void property="moduleType"> . <int>1</int> . </void> . <void property="nativeCurrentUnit"> . <string>mA</string> . </void> . <void p
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
    Category:dropped
    Size (bytes):2197
    Entropy (8bit):4.748052818376892
    Encrypted:false
    SSDEEP:48:cxqGq2o8sqBlqiQo2yTqUXXjTJrGedN5ODqMqBquqcoqlgqqqbDoTqP:W95LsSlW6T7T9TdODlYyhpWWi
    MD5:358D0E4F30C893060FCB6B326457BE97
    SHA1:A66EE2C1491352F6869ABC1534A3258A1BD65B68
    SHA-256:6BBBDD8A859E586C064A5FC6292D46ADD565447B715F760F22A5D187870B49E6
    SHA-512:1BDE5CB87D678C8F4223C0ACDF1D9F551755DC46525E9BD97791EFCBDEAFAAD0E7B26295F48B9D9589DD4F784E8433E37D1654274638DE74C7B63867665157E4
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?> ..<java version="1.6.0_14" class="java.beans.XMLDecoder"> .. <object class="OLServices.OSensorChannel"> .. <void property="channelNum"> .. <int>1</int> .. </void> .. <void property="decimal"> .. <int>4</int> .. </void> .. <void property="displayHigh"> .. <double>0.5</double> .. </void> .. <void property="firmware"> .. <float>1.0</float> .. </void> .. <void property="gain"> .. <int>3</int> .. </void> .. <void property="label"> .. <string></string> .. </void> .. <void property="measurementHigh"> .. <double>0.5</double> .. </void> .. <void property="measurementUnits"> .. <string>in WC</string> .. </void> .. <void property="moduleType"> .. <int>1</int> .. </void> .. <void property="nativeCurrentUnit"> .. <string>mA</string> .. </void> .. <void property="nativeHigh"> .. <double>20.0</double> .. </void> .. <void property="nativeLow"> .. <double>4.0</double> .. </void> .. <void property="nativeUnits"> ..
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):4637
    Entropy (8bit):4.783861627938411
    Encrypted:false
    SSDEEP:48:cqC1/ttothizE2MrW2wg3hTDxjNieI2Ac:xYFtothizEfrWZg3hTDxjQPBc
    MD5:CDAC8A957E3FC7662222063F09290B9C
    SHA1:5132776E3C853318B5ED9C1CCC4A9E3F1A1D5803
    SHA-256:8D3CDCEA20D738CDE3A697E05DFA7BF62516044CE08701E52ADD3D06D2449100
    SHA-512:BF4BC3052F2F76A5A25B0664E6B0F5AD9BC15BC73A62263536D44C30735703283B6FDD1EA39E0773C94D5E054E3B057F4664AB50490F55A886CE287FEB7610AA
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?>.<java version="1.8.0_31" class="java.beans.XMLDecoder">. <object class="OLServices.OSensorChannel" id="OSensorChannel0">. <void class="OLServices.OSensorChannel" method="getField">. <string>m_strNativeCurrentUnits</string>. <void method="set">. <object idref="OSensorChannel0"/>. <string>mA</string>. </void>. </void>. <void class="OLServices.OSensorChannel" method="getField">. <string>m_strNativeVoltageUnits</string>. <void method="set">. <object idref="OSensorChannel0"/>. <string>V</string>. </void>. </void>. <void class="OLServices.OSensorChannel" method="getField">. <string>m_OnsetPartValues</string>. <void method="set">. <object idref="OSensorChannel0"/>. <object class="java.util.ArrayList"/>. </void>. </void>. <void class="OLServices.OSensorChannel" method="getField">. <string>m_GainCurLow</string>. <void method="set">. <object idref="OSensorChannel0"/>. <object class="java.util.ArrayList">.
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
    Category:dropped
    Size (bytes):1922
    Entropy (8bit):4.892770146010901
    Encrypted:false
    SSDEEP:48:cE7q9lq2481qEqiQ4GySqXiG5N5NqMq2CoqlGlqLqbDXP:Nwl5b1xWaS2vNlVRl8Wf
    MD5:1B17705070A7BBB40C4A35158D6D64F1
    SHA1:7B605AA02E81A15F24235BEA879B1799F4163C13
    SHA-256:41C642629E86C87450EE11B062C32736ECC7493A1705D3C014A34A040B554042
    SHA-512:6E2AA2A66A01C768912236FFF2447B006EDADA5A66835D589EE8AC60D9473F9BCB48B401A142E0FE536883E3C27DC45E31F8D793D568FE972DE6E1712847D256
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?> ..<java version="1.6.0_25" class="java.beans.XMLDecoder"> .. <object class="OLServices.OSensorChannel"> .. <void property="sampleSize"> .. <int>15</int> .. </void> .. <void property="decimal"> .. <int>3</int> .. </void> .. <void property="displayHigh"> .. <double>30.720307203072032</double> .. </void> .. <void property="firmware"> .. <float>2.8</float> .. </void> .. <void property="gain"> .. <int>2</int> .. </void> .. <void property="label"> .. <string></string> .. </void> .. <void property="measurementHigh"> .. <double>30.720307203072032</double> .. </void> .. <void property="measurementUnits"> .. <string>A</string> .. </void> .. <void property="moduleType"> .. <int>2</int> .. </void> .. <void property="nativeHigh"> .. <double>333.33</double> .. </void> .. <void property="nativeVoltageUnit"> .. <string>&lt;HTML&gt;mV&lt;sub&gt;RMS&lt;/sub&gt;&lt;/HTML&gt;</string> .. </void> .. <void property="parentSe
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):1843
    Entropy (8bit):4.843575519772842
    Encrypted:false
    SSDEEP:24:2d2gNPA6sP5A6mkkAA6gHsW4x88H2RPiNwkQZ+ZXGVA6V:cXPApxAnEApsb8PbGXGVAE
    MD5:F95B4CBA105D3C2ADECADB3027D5E14E
    SHA1:D4FAA0EB72CD30400CB9CFA9EF48E7E2793D347B
    SHA-256:FF8E8082033034CDE466B64B6D6AA6BEF05BF7F3C187E8AC6AE04D41A4D90500
    SHA-512:57B05F09D6C9C8CD9819B448E346A14B34E6714352DC6D8FCAFAEA67BDBBBFC3943D8FC719392531BECC8C12C7EB4DAE4E2E137D54BF153E3AFFE5BF32EEEB73
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?> .<java version="1.6.0_21" class="java.beans.XMLDecoder"> . <object class="OLServices.OSensorChannel"> . <void property="decimal"> . <int>3</int> . </void> . <void property="displayHigh"> . <double>7.687687687687688</double> . </void> . <void property="firmware"> . <float>2.4</float> . </void> . <void property="gain"> . <int>2</int> . </void> . <void property="label"> . <string></string> . </void> . <void property="measurementHigh"> . <double>7.687687687687688</double> . </void> . <void property="measurementUnits"> . <string>A</string> . </void> . <void property="moduleType"> . <int>2</int> . </void> . <void property="nativeHigh"> . <double>333.0</double> . </void> . <void property="nativeVoltageUnit"> . <string>&lt;HTML&gt;mV&lt;sub&gt;RMS&lt;/sub&gt;&lt;/HTML&gt;</string> . </void> . <void property="parentSensor"> . <object class="OLServices.OSensor"> . <void property="configurable"> . <boolean>tr
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):2037
    Entropy (8bit):4.693819862020537
    Encrypted:false
    SSDEEP:24:2degNPA66Ca9A60kbPhHAA6Jh6zjTtiHsCRx88KsvlPiNVhkQZIVA67D:cfPAlR9A3egAoaMsCr8rKIhfIVAO
    MD5:5608F9C007361A7B6FE43A7CD3B7B511
    SHA1:AC7FF66FB078C5CF37387E664E07E9502A202C10
    SHA-256:02B3F148EA38947D66957CDCDCD9391087F4C43E382EC6862B629DDF038D3039
    SHA-512:EED215B26AE32655211ADC11D5EB2DE1494B5F5BCF1068285051A94C0121DDE5650A6900C4015F912DDD2D967AE26496E109BD9F2022295D595F95A4C83FF426
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?> .<java version="1.6.0_14" class="java.beans.XMLDecoder"> . <object class="OLServices.OSensorChannel"> . <void property="decimal"> . <int>3</int> . </void> . <void property="displayHigh"> . <double>10.0</double> . </void> . <void property="firmware"> . <float>1.0</float> . </void> . <void property="gain"> . <int>3</int> . </void> . <void property="label"> . <string></string> . </void> . <void property="measurementHigh"> . <double>10.0</double> . </void> . <void property="measurementUnits"> . <string>ppm</string> . </void> . <void property="moduleType"> . <int>1</int> . </void> . <void property="nativeCurrentUnit"> . <string>mA</string> . </void> . <void property="nativeHigh"> . <double>20.0</double> . </void> . <void property="nativeLow"> . <double>4.0</double> . </void> . <void property="nativeUnits"> . <boolean>false</boolean> . </void> . <void property="nativeVoltageUnit"> . <string>V</string> .
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):2172
    Entropy (8bit):4.799819969799606
    Encrypted:false
    SSDEEP:24:2dPkgaA6T6UcuJTCkA6B6UcuJ1kbPhHAA68h6mhHsCRx88hovRoPiNKqkOoZ2VAE:cP6AsB5hA6BregA3VsCr8aWm2VAE
    MD5:DF4C4D8891A1E0CB041EB16CB354AA15
    SHA1:456FC6B91FDE7B70F0B4376CD556B3375A84D6C9
    SHA-256:5DEE1ADD96428A7C312AEF06A4B6FF79CFD98A32004632A8A425744540C5A3FE
    SHA-512:8BC0AC46639655A9717D3AC6D001F60D523ED69225E4819E849738A5A523E92B259CB05678065EC10DA2635901978B8BA2F0E45DBBE7935BD105A2E02C8EE18F
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?> .<java version="1.5.0_04" class="java.beans.XMLDecoder"> . <object class="OLServices.OSensorChannel"> . <void property="decimal"> . <int>4</int> . </void> . <void property="displayHigh"> . <double>5.0</double> . </void> . <void property="displayLow"> . <double>0.049999999538995324</double> . </void> . <void property="firmware"> . <float>1.0</float> . </void> . <void property="gain"> . <int>2</int> . </void> . <void property="location"> . <string></string> . </void> . <void property="measurementHigh"> . <double>5.0</double> . </void> . <void property="measurementLow"> . <double>0.049999999538995324</double> . </void> . <void property="measurementUnits"> . <string>in WC</string> . </void> . <void property="moduleType"> . <int>1</int> . </void> . <void property="nativeCurrentUnit"> . <string>mA</string> . </void> . <void property="nativeHigh"> . <double>5.0</double> . </void> . <void property="nativeLo
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):2172
    Entropy (8bit):4.802035013002614
    Encrypted:false
    SSDEEP:24:2dPkgaA6t6rPKKCkA6j6rPKokbPhHAA68h6mhHsCRx88hovRoPiNKqkOoZ2VA6H:cP6AqzKhAgzoegA3VsCr8aWm2VAa
    MD5:CE842DA4617DA176CE0E89F91DFC991A
    SHA1:F6376886034D205C1094F56301CC341F03F3DEF6
    SHA-256:5D512E07B52BF4944EE169405715BEA58AD73E5A03FD8459B8C198ABCD280C26
    SHA-512:671CE3F506BD66C3BB53EDF4D1FCB6ABFCB7745C38BEC66A20D3B11BECB96CF5462B14203CE39935B87F5C04DCED84C701E610A5C8FE678CC8AF724D394A7521
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?> .<java version="1.5.0_04" class="java.beans.XMLDecoder"> . <object class="OLServices.OSensorChannel"> . <void property="decimal"> . <int>4</int> . </void> . <void property="displayHigh"> . <double>2.5</double> . </void> . <void property="displayLow"> . <double>0.024999999769497662</double> . </void> . <void property="firmware"> . <float>1.0</float> . </void> . <void property="gain"> . <int>2</int> . </void> . <void property="location"> . <string></string> . </void> . <void property="measurementHigh"> . <double>2.5</double> . </void> . <void property="measurementLow"> . <double>0.024999999769497662</double> . </void> . <void property="measurementUnits"> . <string>in WC</string> . </void> . <void property="moduleType"> . <int>1</int> . </void> . <void property="nativeCurrentUnit"> . <string>mA</string> . </void> . <void property="nativeHigh"> . <double>5.0</double> . </void> . <void property="nativeLo
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):2171
    Entropy (8bit):4.720967811222828
    Encrypted:false
    SSDEEP:24:2dtNgRaA6a6dC5A6w6eykbPhHAA6zHsCRx88hoBolPiNGZxVA6jA6a:ctLAtM6AjtyegAksCr8i/xVA4A1
    MD5:745A386A56F4AF9412861B3B6F647C9C
    SHA1:156600A391D67DE1E04552E0EC7A7860CF2641F5
    SHA-256:ADD5677ACAD2C543840D8118CC151266CEDEFD7D3C2712118E9D6CD2765FAD64
    SHA-512:D6D9CB54BA49FD744349BA7E7E8C9AFE354E15642FD6A945203CE4A891499B2E56BB665A2A7390E853CFEEEB571A2D1F2B122B11C8C31BE5999F5F98604006B4
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?> .<java version="1.6.0_24" class="java.beans.XMLDecoder"> . <object class="OLServices.OSensorChannel"> . <void property="bitSize"> . <int>12</int> . </void> . <void property="channelNum"> . <int>1</int> . </void> . <void property="decimal"> . <int>1</int> . </void> . <void property="displayHigh"> . <double>2461.25</double> . </void> . <void property="displayLow"> . <double>24.6125</double> . </void> . <void property="firmware"> . <float>1.0</float> . </void> . <void property="gain"> . <int>2</int> . </void> . <void property="label"> . <string></string> . </void> . <void property="measurementHigh"> . <double>2461.25</double> . </void> . <void property="measurementLow"> . <double>24.6125</double> . </void> . <void property="measurementUnits"> . <string>fpm</string> . </void> . <void property="moduleType"> . <int>1</int> . </void> . <void property="nativeCurrentUnit"> . <string>mA</string> . </void>
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
    Category:dropped
    Size (bytes):1922
    Entropy (8bit):4.875699034882859
    Encrypted:false
    SSDEEP:48:cqhq2ep8DqEqHQepGySqXEG5N5EqMq2q7qpoqlgqLqbDtP:x5eGDxPeZS2BElgJh8Wh
    MD5:FF0DEFC7F4622D7A2DB431ED6C92AB73
    SHA1:9DA1210E98C72CFDECD96D42123FD3A2B65569D9
    SHA-256:FE19439199B28DC5C0E4BE0CE9E608DEC573E76B8CBCF5A1BA8C7230B4C18ABC
    SHA-512:F53CB2C34A27597B57C29835C1CB722554E4FB30FE41D31D7BC25DFFEE029E6876B07CEC271A0EDE8310730DC321CD288C775C348A8362E7D09A74A31C0AC075
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?> ..<java version="1.5.0_04" class="java.beans.XMLDecoder"> .. <object class="OLServices.OSensorChannel"> .. <void property="decimal"> .. <int>2</int> .. </void> .. <void property="displayHigh"> .. <double>307.5075075075075</double> .. </void> .. <void property="firmware"> .. <float>2.2</float> .. </void> .. <void property="gain"> .. <int>2</int> .. </void> .. <void property="location"> .. <string></string> .. </void> .. <void property="measurementHigh"> .. <double>307.5075075075075</double> .. </void> .. <void property="measurementUnits"> .. <string>A</string> .. </void> .. <void property="moduleType"> .. <int>2</int> .. </void> .. <void property="nativeHigh"> .. <double>333.0</double> .. </void> .. <void property="nativeVoltageUnit"> .. <string>&lt;HTML&gt;mV&lt;sub&gt;RMS&lt;/sub&gt;&lt;/HTML&gt;</string> .. </void> .. <void property="parentSensor"> .. <object class="OLServices.OSensor"> .. <void prop
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):1846
    Entropy (8bit):4.816928500889512
    Encrypted:false
    SSDEEP:24:2dPkggA6UKNkA6UokkAA6gHsW4x88HeGPiNwkQZ9ZIVA6sl:cPAAeqAUEApsb8qbDIVA5
    MD5:472DC012049E1A2C9374455980BFC9E2
    SHA1:3B33C0FF67EBB3DCDCD564EBEFEA0A57FC6FDBD9
    SHA-256:000A4550377487B87E1A126C5F32B13B204710EC88222654DEB6487F3A3E5832
    SHA-512:B312601B158C414007E5C18EC38C4D030F727ADA31191729708E8AF7C77635C914EEF420D7A543B244EA37CEBE32827813514B21A518F3A7552AEBF10A5BF453
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?> .<java version="1.5.0_04" class="java.beans.XMLDecoder"> . <object class="OLServices.OSensorChannel"> . <void property="decimal"> . <int>2</int> . </void> . <void property="displayHigh"> . <double>922.5225225225225</double> . </void> . <void property="firmware"> . <float>2.2</float> . </void> . <void property="gain"> . <int>2</int> . </void> . <void property="location"> . <string></string> . </void> . <void property="measurementHigh"> . <double>922.5225225225225</double> . </void> . <void property="measurementUnits"> . <string>A</string> . </void> . <void property="moduleType"> . <int>2</int> . </void> . <void property="nativeHigh"> . <double>333.0</double> . </void> . <void property="nativeVoltageUnit"> . <string>&lt;HTML&gt;mV&lt;sub&gt;RMS&lt;/sub&gt;&lt;/HTML&gt;</string> . </void> . <void property="parentSensor"> . <object class="OLServices.OSensor"> . <void property="configurable"> . <boolean
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):4635
    Entropy (8bit):4.783663504617974
    Encrypted:false
    SSDEEP:24:2dqRQ1/tuees3ueeCWtgvvjx0S97Kg9H06Y6CsT06a6OktL6kmsTPyxenJeca0fn:cqC1/ttothip0zVrFfg3hTDxjNieIbAV
    MD5:204EE035593E7DA0B05A6D12CC6C52E3
    SHA1:C1E77B5E60B7397C9C65BBDB309C687B76F93289
    SHA-256:146A221F2786367130E1061BCA75EA260DC0C4ED7D1E93F80FBA0A601E4B61E0
    SHA-512:93B9074668E4F7507977539B2433EAE54A3DA7387AB778F3877C7341853338DF7DD66F003CAF3469125A2DAD6CF2889F73A016306E017C5DAA6546A4FD9F2FAA
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?>.<java version="1.8.0_31" class="java.beans.XMLDecoder">. <object class="OLServices.OSensorChannel" id="OSensorChannel0">. <void class="OLServices.OSensorChannel" method="getField">. <string>m_strNativeCurrentUnits</string>. <void method="set">. <object idref="OSensorChannel0"/>. <string>mA</string>. </void>. </void>. <void class="OLServices.OSensorChannel" method="getField">. <string>m_strNativeVoltageUnits</string>. <void method="set">. <object idref="OSensorChannel0"/>. <string>V</string>. </void>. </void>. <void class="OLServices.OSensorChannel" method="getField">. <string>m_OnsetPartValues</string>. <void method="set">. <object idref="OSensorChannel0"/>. <object class="java.util.ArrayList"/>. </void>. </void>. <void class="OLServices.OSensorChannel" method="getField">. <string>m_GainCurLow</string>. <void method="set">. <object idref="OSensorChannel0"/>. <object class="java.util.ArrayList">.
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):1848
    Entropy (8bit):4.844579049011857
    Encrypted:false
    SSDEEP:24:2dPkggA6F/JKNkA6F/JJkkAA6+HsW4x88HeGPiN1JJkQZ9ZIVA65:cPAAyBKqAyBJEApsb8qobDIVAa
    MD5:76063942BC02982EC81BC104D3BC1A1B
    SHA1:D7B3AEAF4F869C87CF8777FB25AF87B62B07361F
    SHA-256:45DBEB55B5C6DCD4918AE925C45D6CE08050049595DEB65C565A4FA3B58F5966
    SHA-512:CC379AF317CC47B63CE95B41D85920B7C56C8EA08BC22BB16C7ED351990FBBFD4F6C594BF2E71F48AE61AC665771D5FC0BC133B889551EDB85ADCB52DDBC8CD0
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?> .<java version="1.5.0_04" class="java.beans.XMLDecoder"> . <object class="OLServices.OSensorChannel"> . <void property="decimal"> . <int>2</int> . </void> . <void property="displayHigh"> . <double>176.55172413793105</double> . </void> . <void property="firmware"> . <float>2.2</float> . </void> . <void property="gain"> . <int>2</int> . </void> . <void property="location"> . <string></string> . </void> . <void property="measurementHigh"> . <double>176.55172413793105</double> . </void> . <void property="measurementUnits"> . <string>VAC</string> . </void> . <void property="moduleType"> . <int>2</int> . </void> . <void property="nativeHigh"> . <double>333.0</double>. </void> . <void property="nativeVoltageUnit"> . <string>&lt;HTML&gt;mV&lt;sub&gt;RMS&lt;/sub&gt;&lt;/HTML&gt;</string> . </void> . <void property="parentSensor"> . <object class="OLServices.OSensor"> . <void property="configurable"> . <bool
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):2039
    Entropy (8bit):4.697291030177624
    Encrypted:false
    SSDEEP:24:2dPkggA6D0CagA6DmxkbPhHAA6Jh6zjTtiHsCRx88hoBonPiN5k2ZBVA6DV:cPAAW0RgAWSegAoaMsCr8MUFBVAWV
    MD5:8C792D4ACF29D5D68E458F08B1672DF8
    SHA1:010278D500115C43E365F05CBEA31A6B7DC4A4A7
    SHA-256:7408C3D90DC172DDB21E33C1B8582EA50EDF3D04E5827FBE45724676F84F48BE
    SHA-512:506613FF7BFE3A819B4F5097C68EAFF5D1935DF7CD66F31F9516B94FC7531D265C4451DE3A6090F0140366CE29F6D6137B8C5FC9001BF663475D9C5D55082B50
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?> .<java version="1.5.0_04" class="java.beans.XMLDecoder"> . <object class="OLServices.OSensorChannel"> . <void property="decimal"> . <int>2</int> . </void> . <void property="displayHigh"> . <double>100.0</double> . </void> . <void property="firmware"> . <float>1.0</float> . </void> . <void property="gain"> . <int>3</int> . </void> . <void property="location"> . <string></string> . </void> . <void property="measurementHigh"> . <double>100.0</double> . </void> . <void property="measurementUnits"> . <string>%</string> . </void> . <void property="moduleType"> . <int>1</int> . </void> . <void property="nativeCurrentUnit"> . <string>mA</string> . </void> . <void property="nativeHigh"> . <double>20.0</double> . </void> . <void property="nativeLow"> . <double>4.0</double> . </void> . <void property="nativeUnits"> . <boolean>false</boolean> . </void> . <void property="nativeVoltageUnit"> . <string>V</string
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):1841
    Entropy (8bit):4.839081610125668
    Encrypted:false
    SSDEEP:24:2d2gNPA6sP5A6mkkAA6gHsW4x88HeRPiNwkQZ+ZXGVA6V:cXPApxAnEApsb8DbGXGVAE
    MD5:613A4D9B84401E8EA9107A6C69BFCAFA
    SHA1:029F4EDA9B2C28CA16A7F492895C5C1E5DF5C066
    SHA-256:F53B2F81324078DA9FBF06A8A3B07939E2023B89F354AD741484826C250B79D5
    SHA-512:2FC4667D531A372337956986DAA2379506B2266E77138A4A2546F3DFA2B2A8497EF5FA3C960D33CB6E8E5920DD8013BCB360CE8FC03AE2052679EFEF27BEAC8D
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?> .<java version="1.6.0_21" class="java.beans.XMLDecoder"> . <object class="OLServices.OSensorChannel"> . <void property="decimal"> . <int>3</int> . </void> . <void property="displayHigh"> . <double>7.687687687687688</double> . </void> . <void property="firmware"> . <float>2.4</float> . </void> . <void property="gain"> . <int>2</int> . </void> . <void property="label"> . <string></string> . </void> . <void property="measurementHigh"> . <double>7.687687687687688</double> . </void> . <void property="measurementUnits"> . <string>A</string> . </void> . <void property="moduleType"> . <int>2</int> . </void> . <void property="nativeHigh"> . <double>333.0</double> . </void> . <void property="nativeVoltageUnit"> . <string>&lt;HTML&gt;mV&lt;sub&gt;RMS&lt;/sub&gt;&lt;/HTML&gt;</string> . </void> . <void property="parentSensor"> . <object class="OLServices.OSensor"> . <void property="configurable"> . <boolean>tr
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):1847
    Entropy (8bit):4.824114893481974
    Encrypted:false
    SSDEEP:24:2dPkgNPA6GNkA68kkAA6gHsW4x88H2GPiNwkQZ9ZIVA6k:cPtPAPqA5EApsb8+bDIVAT
    MD5:F9519B797450867863DA1140DA16AB3F
    SHA1:B8C88BD1B1F4F841EE534EA19A766128D4BA79B3
    SHA-256:E506DB14074B6A7D13C9C1EE05B7C3223876CA5CA50EDADF5AE2906442E3BDE2
    SHA-512:3E019F3D15978A63CE9C500D9981D7A788940D4CD5A49D8496559C347AB6A12C669E8F431643F45A56EEB8224998DB4C44AD2E11CE6EC1BCAB7CA912DFB3F7A1
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?> .<java version="1.5.0_04" class="java.beans.XMLDecoder"> . <object class="OLServices.OSensorChannel"> . <void property="decimal"> . <int>3</int> . </void> . <void property="displayHigh"> . <double>30.75075075075075</double> . </void> . <void property="firmware"> . <float>2.2</float> . </void> . <void property="gain"> . <int>2</int> . </void> . <void property="location"> . <string></string> . </void> . <void property="measurementHigh"> . <double>30.75075075075075</double> . </void> . <void property="measurementUnits"> . <string>A</string> . </void> . <void property="moduleType"> . <int>2</int> . </void> . <void property="nativeHigh"> . <double>333.0</double> . </void> . <void property="nativeVoltageUnit"> . <string>&lt;HTML&gt;mV&lt;sub&gt;RMS&lt;/sub&gt;&lt;/HTML&gt;</string> . </void> . <void property="parentSensor"> . <object class="OLServices.OSensor"> . <void property="configurable"> . <boolean
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):2097
    Entropy (8bit):4.69201219060219
    Encrypted:false
    SSDEEP:24:2dtNgRYPA6W6FC5A6c6dkbPhHAA6zHsCRx88hoBolPiNGZxVA6y:ctxPAbc6AJ4egAksCr8i/xVAh
    MD5:4D09221C4036DFDD4A5C8B2252CE4173
    SHA1:05C4DD0E633368E46E1238081A80D672114677BC
    SHA-256:DDC7ADF90B5D34873E92558D6195411F88CAEB88476DDD7E8C33B480A2C161B9
    SHA-512:B994FA1B2D94199824070A35ED1F7D577A294DEE548B84B97C62E385CC3A282ED971197EE356AA04ED522F27EB33591C3CBE63D48E9CA95216DBAD5D98F24434
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?> .<java version="1.6.0_24" class="java.beans.XMLDecoder"> . <object class="OLServices.OSensorChannel"> . <void property="bitSize"> . <int>12</int> . </void> . <void property="channelNum"> . <int>1</int> . </void> . <void property="decimal"> . <int>3</int> . </void> . <void property="displayHigh"> . <double>12.5</double> . </void> . <void property="displayLow"> . <double>0.125</double> . </void> . <void property="firmware"> . <float>1.0</float> . </void> . <void property="gain"> . <int>2</int> . </void> . <void property="label"> . <string></string> . </void> . <void property="measurementHigh"> . <double>12.5</double> . </void> . <void property="measurementLow"> . <double>0.125</double> . </void> . <void property="measurementUnits"> . <string>m/s</string> . </void> . <void property="moduleType"> . <int>1</int> . </void> . <void property="nativeCurrentUnit"> . <string>mA</string> . </void> . <void p
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):1843
    Entropy (8bit):4.843575519772842
    Encrypted:false
    SSDEEP:24:2d2gNPA6sP5A6mkkAA6gHsW4x88H2RPiNwkQZ+ZXGVA6V:cXPApxAnEApsb8PbGXGVAE
    MD5:F95B4CBA105D3C2ADECADB3027D5E14E
    SHA1:D4FAA0EB72CD30400CB9CFA9EF48E7E2793D347B
    SHA-256:FF8E8082033034CDE466B64B6D6AA6BEF05BF7F3C187E8AC6AE04D41A4D90500
    SHA-512:57B05F09D6C9C8CD9819B448E346A14B34E6714352DC6D8FCAFAEA67BDBBBFC3943D8FC719392531BECC8C12C7EB4DAE4E2E137D54BF153E3AFFE5BF32EEEB73
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?> .<java version="1.6.0_21" class="java.beans.XMLDecoder"> . <object class="OLServices.OSensorChannel"> . <void property="decimal"> . <int>3</int> . </void> . <void property="displayHigh"> . <double>7.687687687687688</double> . </void> . <void property="firmware"> . <float>2.4</float> . </void> . <void property="gain"> . <int>2</int> . </void> . <void property="label"> . <string></string> . </void> . <void property="measurementHigh"> . <double>7.687687687687688</double> . </void> . <void property="measurementUnits"> . <string>A</string> . </void> . <void property="moduleType"> . <int>2</int> . </void> . <void property="nativeHigh"> . <double>333.0</double> . </void> . <void property="nativeVoltageUnit"> . <string>&lt;HTML&gt;mV&lt;sub&gt;RMS&lt;/sub&gt;&lt;/HTML&gt;</string> . </void> . <void property="parentSensor"> . <object class="OLServices.OSensor"> . <void property="configurable"> . <boolean>tr
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):1841
    Entropy (8bit):4.839081610125668
    Encrypted:false
    SSDEEP:24:2d2gNPA6sP5A6mkkAA6gHsW4x88HeRPiNwkQZ+ZXGVA6V:cXPApxAnEApsb8DbGXGVAE
    MD5:613A4D9B84401E8EA9107A6C69BFCAFA
    SHA1:029F4EDA9B2C28CA16A7F492895C5C1E5DF5C066
    SHA-256:F53B2F81324078DA9FBF06A8A3B07939E2023B89F354AD741484826C250B79D5
    SHA-512:2FC4667D531A372337956986DAA2379506B2266E77138A4A2546F3DFA2B2A8497EF5FA3C960D33CB6E8E5920DD8013BCB360CE8FC03AE2052679EFEF27BEAC8D
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?> .<java version="1.6.0_21" class="java.beans.XMLDecoder"> . <object class="OLServices.OSensorChannel"> . <void property="decimal"> . <int>3</int> . </void> . <void property="displayHigh"> . <double>7.687687687687688</double> . </void> . <void property="firmware"> . <float>2.4</float> . </void> . <void property="gain"> . <int>2</int> . </void> . <void property="label"> . <string></string> . </void> . <void property="measurementHigh"> . <double>7.687687687687688</double> . </void> . <void property="measurementUnits"> . <string>A</string> . </void> . <void property="moduleType"> . <int>2</int> . </void> . <void property="nativeHigh"> . <double>333.0</double> . </void> . <void property="nativeVoltageUnit"> . <string>&lt;HTML&gt;mV&lt;sub&gt;RMS&lt;/sub&gt;&lt;/HTML&gt;</string> . </void> . <void property="parentSensor"> . <object class="OLServices.OSensor"> . <void property="configurable"> . <boolean>tr
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):2190
    Entropy (8bit):4.696325891457877
    Encrypted:false
    SSDEEP:24:2deggA6s6c0Ca9A666cykbPhHAA6Jh6zjTtiHsCRx88hoBolPiNjkQZIVA636cV:cOALt0R9AZtyegAoaMsCr8iefIVAKtV
    MD5:18DB5669BBA28508FE5533B61084E43A
    SHA1:24E1F2E338B13DED57DD2524250A488B2D848B99
    SHA-256:24A6F145F675330C4D05A7DF740EC01F049097E5A1FEDD7ABDE5F4E4B51998B3
    SHA-512:DAB6A91F2C28FE4D816CE21732CCB7A2AE78C09F0A2482B307E83996BE763776FAA765FDCFF779CFC4E6FEF189532AB0A6C01F22F42116B17CF60EEE0D2AA27F
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?> .<java version="1.6.0_14" class="java.beans.XMLDecoder"> . <object class="OLServices.OSensorChannel"> . <void property="decimal"> . <int>2</int> . </void> . <void property="displayHigh"> . <double>200.0</double> . </void> . <void property="displayLow"> . <double>0.0</double> . </void> . <void property="firmware"> . <float>1.0</float> . </void> . <void property="gain"> . <int>3</int> . </void> . <void property="label"> . <string></string> . </void> . <void property="measurementHigh"> . <double>200.0</double> . </void> . <void property="measurementLow"> . <double>0.0</double> . </void> . <void property="measurementUnits"> . <string>scfm</string> . </void> . <void property="moduleType"> . <int>1</int> . </void> . <void property="nativeCurrentUnit"> . <string>mA</string> . </void> . <void property="nativeHigh"> . <double>20.0</double> . </void> . <void property="nativeLow"> . <double>4.0</double> . <
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):2257
    Entropy (8bit):4.6983533135302
    Encrypted:false
    SSDEEP:24:2degvA6DT61Ca9A6DB67kbPhHAA6Jh6zjTtiHsCRx88KsvlPiNwkQZIVA6Dy6b:chAWTCR9AWBgegAoaMsCr8rKbfIVAWy6
    MD5:1E6CB13C8DB80C6A5CC5FAD82239AF73
    SHA1:3BAB79AAA774A50CBE7ACE7A9A12CA5B6C6BE94B
    SHA-256:7F1B61FB7EA9D23E63C5CBA4F3175DA3D89FCDD4E7D9131AE4078539844C8E31
    SHA-512:1B39D1476D3240997C00D176B3CF025D123C0F5997FC8EF4BE9025FFD8D7AEF421AE21FD0DCA0973B0BEDD79D0C1FFD5532463B7D5FB27E8C2461140AD8348D5
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?> .<java version="1.6.0_14" class="java.beans.XMLDecoder"> . <object class="OLServices.OSensorChannel"> . <void property="decimal"> . <int>1</int> . </void> . <void property="displayHigh"> . <double>100.0</double> . </void> . <void property="displayLow"> . <double>-100.0</double> . </void> . <void property="firmware"> . <float>1.0</float> . </void> . <void property="gain"> . <int>3</int> . </void> . <void property="label"> . <string></string> . </void> . <void property="measurementHigh"> . <double>100.0</double> . </void> . <void property="measurementLow"> . <double>-100.0</double> . </void> . <void property="measurementUnits"> . <string>A</string> . </void> . <void property="moduleType"> . <int>1</int> . </void> . <void property="nativeCurrentUnit"> . <string>mA</string> . </void> . <void property="nativeHigh"> . <double>20.0</double> . </void> . <void property="nativeLow"> . <double>4.0</double> .
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):2174
    Entropy (8bit):4.719863224531595
    Encrypted:false
    SSDEEP:24:2dtNgRaA6y6zC5A6I6kykbPhHAA6zHsCRx88KsvlPiNwZbVA60A6a:ctLA5i6A/ryegAksCr8rKjbVANA1
    MD5:884AEC362ADEA410177FFF17FECF7E12
    SHA1:DFD46C63E5B5F1A389DD8CAF23366CD8F5A4B9EF
    SHA-256:3B46BCA64BF260539D50275FB0AF5ED69DB7D7940FB54B00D6BB367245FC22E6
    SHA-512:0C95D19484F041130C2E34ADAE76A3C223DF573D8CB23A53AF24F78F1D18895AB90E754EBAD98884C4A04E9E9B68DF42A3C6E38E9F583699728218D45DF7A652
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?> .<java version="1.6.0_24" class="java.beans.XMLDecoder"> . <object class="OLServices.OSensorChannel"> . <void property="bitSize"> . <int>12</int> . </void> . <void property="channelNum"> . <int>1</int> . </void> . <void property="decimal"> . <int>1</int> . </void> . <void property="displayHigh"> . <double>1231.25</double> . </void> . <void property="displayLow"> . <double>12.3125</double> . </void> . <void property="firmware"> . <float>1.0</float> . </void> . <void property="gain"> . <int>2</int> . </void> . <void property="label"> . <string></string> . </void> . <void property="measurementHigh"> . <double>1231.25</double> . </void> . <void property="measurementLow"> . <double>12.3125</double> . </void> . <void property="measurementUnits"> . <string>fpm</string> . </void> . <void property="moduleType"> . <int>1</int> . </void> . <void property="nativeCurrentUnit"> . <string>mA</string> . </void>
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):2038
    Entropy (8bit):4.694890907725658
    Encrypted:false
    SSDEEP:24:2degvA6iCa9A6skbPhHAA6Jh6zjTtiHsCRx88hoBolPiNVhkQZIVA6zD:chAlR9A3egAoaMsCr8iIhfIVAO
    MD5:3258EB35E0F3AF016D1AA7D07FD65AC2
    SHA1:70AEE796D9B743CD7CDA800F018E484DE9E4137D
    SHA-256:BA612B84DDFF74967C2CCF4B1E49FF42147D2F99A85A59C1BE270E76B3E2E930
    SHA-512:3411988AC3C90EFDA020DA7A80B88971F164313788437FE9E27E8FCEDA87A322171759DD773BDCA1EB9446171693AB05637315E83896B29712A41CFB06E31996
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?> .<java version="1.6.0_14" class="java.beans.XMLDecoder"> . <object class="OLServices.OSensorChannel"> . <void property="decimal"> . <int>1</int> . </void> . <void property="displayHigh"> . <double>1000.0</double> . </void> . <void property="firmware"> . <float>1.0</float> . </void> . <void property="gain"> . <int>3</int> . </void> . <void property="label"> . <string></string> . </void> . <void property="measurementHigh"> . <double>1000.0</double> . </void> . <void property="measurementUnits"> . <string>ppm</string> . </void> . <void property="moduleType"> . <int>1</int> . </void> . <void property="nativeCurrentUnit"> . <string>mA</string> . </void> . <void property="nativeHigh"> . <double>20.0</double> . </void> . <void property="nativeLow"> . <double>4.0</double> . </void> . <void property="nativeUnits"> . <boolean>false</boolean> . </void> . <void property="nativeVoltageUnit"> . <string>V</strin
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):2044
    Entropy (8bit):4.706853824227946
    Encrypted:false
    SSDEEP:24:2dPkgNPA6BCagA6EkbPhHAA6Jh6zjTtiHsCRx88hoBonPiNck2ZZVA6k:cPtPAERgADegAoaMsCr8MzFZVAF
    MD5:BE4473C7269B89174235076577CFCD8F
    SHA1:145F88D93C0B5793D47893A895750E2945650230
    SHA-256:754733BF28AD35438623467A15BE89B4E80C2930E1A5975742402ECA9F40652A
    SHA-512:EDBBAF2F08B984F3BCCBEBCEA4EC0F771431A7D16BD1E683428901AF5579050A8190942A8332033344BEE991EC52F1A3E723F26F748ED74688B3B890D267A4DA
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?> .<java version="1.5.0_04" class="java.beans.XMLDecoder"> . <object class="OLServices.OSensorChannel"> . <void property="decimal"> . <int>3</int> . </void> . <void property="displayHigh"> . <double>83.14</double> . </void> . <void property="firmware"> . <float>1.0</float> . </void> . <void property="gain"> . <int>3</int> . </void> . <void property="location"> . <string></string> . </void> . <void property="measurementHigh"> . <double>83.14</double> . </void> . <void property="measurementUnits"> . <string>kW</string> . </void> . <void property="moduleType"> . <int>1</int> . </void> . <void property="nativeCurrentUnit"> . <string>mA</string> . </void> . <void property="nativeHigh"> . <double>20.0</double> . </void> . <void property="nativeLow"> . <double>4.0</double> . </void> . <void property="nativeUnits"> . <boolean>false</boolean> . </void> . <void property="nativeVoltageUnit"> . <string>V</strin
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):1847
    Entropy (8bit):4.838972554269954
    Encrypted:false
    SSDEEP:24:2dPkgNPA68NkA62kkAA6gHsW4x88H2GPiNwkQZ9ZIVA6sk:cPtPAZqAXEApsb8+bDIVAk
    MD5:0D785DD09688A28402B49F20D62188D5
    SHA1:B8CD03B85E29DC0C1AAB018B6D5E2D135C8BA115
    SHA-256:7653BBFB787E1F06EB20B14719D30ECAC03EEC1572718A888FF5874D2356BBCF
    SHA-512:008F563A95E0639C19A0BA664EBEC8D604EB482AC4A3D3FA69E8457F9579AD1150C66D63E2A815E9F5913330F9BBFA447C313ED5BB9611116C2814CAF2CA9F12
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?> .<java version="1.5.0_04" class="java.beans.XMLDecoder"> . <object class="OLServices.OSensorChannel"> . <void property="decimal"> . <int>3</int> . </void> . <void property="displayHigh"> . <double>76.87687687687688</double> . </void> . <void property="firmware"> . <float>2.2</float> . </void> . <void property="gain"> . <int>2</int> . </void> . <void property="location"> . <string></string> . </void> . <void property="measurementHigh"> . <double>76.87687687687688</double> . </void> . <void property="measurementUnits"> . <string>A</string> . </void> . <void property="moduleType"> . <int>2</int> . </void> . <void property="nativeHigh"> . <double>333.0</double> . </void> . <void property="nativeVoltageUnit"> . <string>&lt;HTML&gt;mV&lt;sub&gt;RMS&lt;/sub&gt;&lt;/HTML&gt;</string> . </void> . <void property="parentSensor"> . <object class="OLServices.OSensor"> . <void property="configurable"> . <boolean
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, ASCII text
    Category:dropped
    Size (bytes):2037
    Entropy (8bit):4.6904765485804925
    Encrypted:false
    SSDEEP:24:2deggA6DT6YC5A6DB66kbPhHAA68HsCRx88hoBolPiNwkQZIVA6D8:cOAWT96AWBjegApsCr8ibfIVAW8
    MD5:506660AA27EF48B42F42F97165EE09A7
    SHA1:6FD15DF8C6EB17D1A6BC7EDF378AB0C7452DAD3E
    SHA-256:AA7CFC802CCFBF8DE0DF9591C284B7E6419DBEFDA2476F2F20D70E0C94B83982
    SHA-512:838726EB99F12807BA4B86604C847F3D7D9DBEA8FA13101288CFF7A7E9515AF50402C311CAAEEC84480DE9115C5AFAADB5F54400D480EBC4D4E718848120EA7F
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?> .<java version="1.6.0_14" class="java.beans.XMLDecoder"> . <object class="OLServices.OSensorChannel"> . <void property="decimal"> . <int>2</int> . </void> . <void property="displayHigh"> . <double>100.0</double> . </void> . <void property="displayLow"> . <double>1.0</double> . </void> . <void property="firmware"> . <float>1.0</float> . </void> . <void property="gain"> . <int>2</int> . </void> . <void property="label"> . <string></string> . </void> . <void property="measurementHigh"> . <double>100.0</double> . </void> . <void property="measurementLow"> . <double>1.0</double> . </void> . <void property="measurementUnits"> . <string>A</string> . </void> . <void property="moduleType"> . <int>1</int> . </void> . <void property="nativeCurrentUnit"> . <string>mA</string> . </void> . <void property="nativeHigh"> . <double>5.0</double> . </void> . <void property="nativeVoltageUnit"> . <string>V</string> .
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:DOS executable (COM, 0x8C-variant)
    Category:dropped
    Size (bytes):805
    Entropy (8bit):6.446626934670998
    Encrypted:false
    SSDEEP:12:+TaG03/6zmRd3gBaJnVjFkgh6l2MnhbchD7d+aShMxRgldLd0BaHd7EbcvQ2mmmI:+TaN/6iJfkjl2MhbchDgXGRzaHd7EI7
    MD5:55E237E92AF26CC0D5BA92A1EF967C9B
    SHA1:30B7D6A41FBB4F8C9708BA19364FC83241E9E065
    SHA-256:8657F2FDD64B9D9B6764560E47F4A3BFBAECB45458F9564839C2709D2020699E
    SHA-512:4BF139F247F02E4B0C403B7A67EB8A3B5CC07CBFBF2E859C05F3C102A9D78F471E7E5FEE9A019E4843A222C93F79636EDFEF9167ADD65D1C725C5AAA066D75DD
    Malicious:false
    Reputation:low
    Preview:...................xR^..r..;:...z...fdeshaies...fdeshaies........!.......W....................HOBO......\......\."......%.....-.\...............5..............................................Onset Computer Corporation...HOBO U10-001 Temp...1013358.........:...........Office Temperature.4.HOBOware Pro-2.7.0_23_Windows.;.fdeshaies......-................................Eastern Standard Time...@N.{..............................................:....*....6..`.6..`.6..!.V....z.."..!..(.#."H.$.bX.&..h.&..h.&..x.'..x.(."x.(."..)....+..,.".-.b....../....0.#..0.c..1.c(.2..(.3..8.3..8.4.#H.4.#H.5.cX.5.cX.6..h.6..h.6..x.7..x.7..x.8.#..8.#..8.#..9.c..9.c..9.c..9....:....:....9.c..4.".'.!.v..a.r....,........0.#..0.#..0.#..0.#..0.#..0.#..0.#..0.#..0.#..0.#..0.#..0.#..0.#..0.#..0.#..0.#..0.#..0.#.......
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:data
    Category:dropped
    Size (bytes):640
    Entropy (8bit):5.959058261612387
    Encrypted:false
    SSDEEP:12:UknajTrNaM1mhFMBQPsypk3h+ynrzbfuJkw9G5yI:XQwdvMyPRk3HvrI79K
    MD5:D795ADA55CBF4DADFD57559FF8E46CC8
    SHA1:F93BEE13F0B573AA3CC52DC891DD4B13107786D5
    SHA-256:CEF5CBECE3BE8AF4371139B35C37352AA204F0B6DFBF17A9492F4C760147E391
    SHA-512:52BE42B24FE61F8F34DD20EB212273985447E2D3EA7577172521719F1F86FE9714418D49AF824A4C9AB9C09D761BA2F0274705E5DB1BDB9D6487506316F413CD
    Malicious:false
    Reputation:low
    Preview:HOBO..............."......)........................5..............................................Onset Computer Corporation...HOBO U9-001 State...2271016......... ...........Refrigerator Door.4.HOBOware Pro-2.7.2_03_Windows......................1(...............Eastern Standard Time...@L(......................................Door Open...Door State................Door Closed...Door State.....">..E.../...p......`..........oy..e...P)....82.h!Y....:.H(I....H#Y.......>..4~.X'...m.(*Y..#.85..h9h.H..8?.8A..!h5k..2.....H>.b.2............H................."..!..................................!..........................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:data
    Category:dropped
    Size (bytes):1280
    Entropy (8bit):6.374702639980285
    Encrypted:false
    SSDEEP:24:yn7/mGCv2grZw+75MNbchPchDYVHE/n2s+ANgw4LcDn6munokTJ+aFlfgR+8Chq:y7/u1SpcJc9YVoL9Dvunokd+26R+8/
    MD5:7A807316C528921107CD6404BD33D71D
    SHA1:8D819756ADEF011ADF3BCCF32C316550261455DF
    SHA-256:3693E1E5B9AF662D2B3C8857A48987E653E1B6BF5D89B90FB52118F5C2CD9CFC
    SHA-512:05A40932FCC8D1B64FE01531506AAC14531E3CB3898862F65979954EB0BBFB7A543475EF31370FC31C95BA349B0DDC7A42AED1B87443DDCFEC47FB343C9660BB
    Malicious:false
    Reputation:low
    Preview:HOBO......\......\."....=........,.\...............5..............................................Onset Computer Corporation...HOBO U12-011 Temp/RH...678858.........8...........Temp and RH.4.HOBOware Pro-2.6.0_09_Windows......,......=........':...............Eastern Standard Time...@C33.............................................................%..e..e..e...................%.....U..%..U..e..E..u..U..u............................5..%..U..5..e..5..e..U..u..e.............................................5..%..E..%..E..5..E..U..u..u..................................................%....................%.....E..%..E..5..E..U..E.....5.....U..5x.Eo.ui..d.%\.eU.ED.eR..N..T..U..S.eU.%N..T.%O..Q..N..J..L..H.eL..K..T.5Y.uX..U..U..T.eP..P..H..L..H..H..M.eG.UG.eC.U@.eB.e<.E>.e;.E8.E9.%2.%5.50..0.E0.%,.50.E*..4..*.U'.E'.E#.%#..$.. .. .. ..............................................................................................................................................
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:DOS executable (COM, 0x8C-variant)
    Category:dropped
    Size (bytes):805
    Entropy (8bit):6.441000443971642
    Encrypted:false
    SSDEEP:12:+TaG03/6zmRd3gBaJnVjFkgh6l2MnhbchD7d+aShMxRgldLd0BzPNHd7EbcvQ2mi:+TaN/6iJfkjl2MhbchDgXGRzDNHd7EI7
    MD5:C9E58B2D1C8C524EC8C1D4A6223DABC5
    SHA1:7C81CAE772E29A6FE1D2FC24D26E1ADC36C5E18E
    SHA-256:D55FE83D7691926A623792DE0C6D5F1C365F14018F232A473A6B653E1A1F8ADC
    SHA-512:580FD46F82D698ADEDCCB51192AECD60523A35D1A4E1BBEF10B260062EA911FCB5122EC946D808ED5405C4689FF9D0516C8C46F2E47BD10C4CA4DB440B0E1C96
    Malicious:false
    Reputation:low
    Preview:...................xR^..r..;:...z...fdeshaies...fdeshaies........!.......W....................HOBO......\......\."......%.....-.\...............5..............................................Onset Computer Corporation...HOBO U10-001 Temp...1013358.........:...........Office Temperature.4.HOBOware Pro-2.7.0_23_Windows.;.fdeshaies......-................................Eastern Standard Time...@N.{..............................................:....*....6..`.6..`.6..!.V....z.."..!..(.#."H.$.bX.&..h.&..h.&..x.'..x.(."x.(."..)....+..,.".-.b....../....0.#..0.c..1.c(.2..(.3..8.3..8.4.#H.4.#H.5.cX.5.cX.6..h.6..h.6..x.7..x.7..x.8.#..8.#..8.#..9.c..9.c..9.c..9....:....:....9.c..4.".'.!.v..a.r....,........0.#..0.#..0.#..0.#..0.#..0.#..0.#..0.#..0.#..0.#..0.#..0.#..0.#..0.#..0.#..0.#..0.#..0.#.......
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, Unicode text, UTF-8 text
    Category:dropped
    Size (bytes):491516
    Entropy (8bit):5.994705571437845
    Encrypted:false
    SSDEEP:6144:OCSFZOdATjx2UxhFRs6sw00ArDbgzSIAOSNC7489n/pLq6YfoGhgK5:OCCA2jxp3s6L00Argz3AOSgLhm/fjey
    MD5:B9941D18ADAB0DCBFF3744BAD6115566
    SHA1:2B0F74971F4DE79DC40EF72A9919E64FD615AB10
    SHA-256:61056D2A101AA8AE0BA70E599AC17B1F3B943F077E03F34B69AD86140905D939
    SHA-512:3F8D511FFA4A67BAB360B87F0E7BFEF4A1B184245429EAE37BDC00DEC2C1494840155876D67085215461B92445F46709AFD3A4A5F4F9A6E6B8283C42B575DCDB
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?> .<java version="1.6.0_17" class="java.beans.XMLDecoder"> . <object class="Appleseed.HOBOViewX"> . <void property="TFont"> . <string>Tahoma Bold</string> . </void> . <void property="TFontAttr"> . <int>1</int> . </void> . <void property="TFontSz"> . <int>12</int> . </void> . <void property="axes"> . <array class="Graphing.LGAxis" length="3"> . <void index="0"> . <object class="Graphing.LGAbsTimeAxis"> . <void property="boundsMax"> . <double>1.2202272E12</double> . </void> . <void property="boundsMin"> . <double>1.1991456E12</double> . </void> . <void property="grid"> . <boolean>true</boolean> . </void> . <void property="location"> . <int>2</int> . </void> . </object> . </void> . <void index="1"> . <object class="Graphing.LGValueAxis"> . <void property="boundsMax"> . <double>24.0</double> . </void> . <void property="boundsMin"> .
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:data
    Category:dropped
    Size (bytes):43520
    Entropy (8bit):6.485742746857401
    Encrypted:false
    SSDEEP:768:g0C5JpC0lMFJk/oRSQJFU+BxwE1rxOqk3tk/PXysW/kbkJTlCwxt:g0CzppDINJFUJEFxOqk94vybxy4t
    MD5:FD151F204BCA0E13961F0BF3E14E58E0
    SHA1:51D21FF92A9FE78D586B5A24068E08BC643284D2
    SHA-256:9E7A291D58E773FA064FE890A7A87FCDE581225C5C4D382AAC4378249800DC7E
    SHA-512:6A6D0134FC4B0B8831BF1EA743E57357AC2B67A97C78E7DCB85BD42A30B2989E258335E381AAC59EF0EB5096224DFFBDDF9941B051ECCA9D773F1A60A8D4ADAD
    Malicious:false
    Reputation:low
    Preview:HOBO.....................l.J.D...D...D...,...................Home Energy Audit.........................)@0........ ......!........................)(c) 2001-05 Onset Computer Corporation........3......O.. ...........5.............. ....)......#...3.HOBO FlexSmart ...2.H22-001......4.5........Reserved..................................................................................................................#..~..Outdoor Temp......Indoor Temp.4...B.hgustafson'X....~.(..)..#..:$..: ..&....Temperature.*C...F.@.....%.. ..B...2.S-TMB-XXXX3.12-bit Temp'W......(..)..#...$... ..&....Temperature.*C...F.@.....%.. ..B...2.S-TMA-XXXX3.8-bit Temp'Z.....U(..)..#..K$..K ........&....Counts.#.......E...%.....E...2.S-UCA-MXXX3.Pulse Adapter'..PD..x...A.................................................................@.(..).$.4..#...$... ..&...$Furnace Amps .A .......A...%.....A...2.S-FS-TRMSA3.FS TRMS AC1:CH1 '..PD......BH................................................................@.(
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, Unicode text, UTF-8 text
    Category:dropped
    Size (bytes):84481
    Entropy (8bit):5.847692466046714
    Encrypted:false
    SSDEEP:1536:m20WhbdwNMRwY1HhUpwNZGH2wNOWNuXhv3lwN2wNtOJDBMiJwNhL:++dwNhY7CwNQWwNOh/lwN2wNtObnwNhL
    MD5:AB44F02075FA9F97E51055467DC0AB68
    SHA1:2FB515DFD88B5C3BD9DCD6ED131AAC3935536343
    SHA-256:813F672E07136C6D53CF39E41423DA7534C8702B00280442D290EA04959B93D8
    SHA-512:93DE6FFD807D4EF2077E50BA1FDC263B50BA5FDC42851C095EE5CAD004AE55C0D130B3697E74DEEF37CA430AF9653B45428E4C5B458FA61B1A88EBBC34B9F23D
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?> .<java version="1.6.0_17" class="java.beans.XMLDecoder"> . <object class="Appleseed.HOBOViewX"> . <void property="TFont"> . <string>Tahoma Bold</string> . </void> . <void property="TFontAttr"> . <int>1</int> . </void> . <void property="TFontSz"> . <int>12</int> . </void> . <void property="axes"> . <array class="Graphing.LGAxis" length="6"> . <void index="0"> . <object class="Graphing.LGAbsTimeAxis"> . <void property="boundsMax"> . <double>1.1282112E12</double> . </void> . <void property="boundsMin"> . <double>1.1261376E12</double> . </void> . <void property="grid"> . <boolean>true</boolean> . </void> . <void property="location"> . <int>2</int> . </void> . </object> . </void> . <void index="1"> . <object class="Graphing.LGValueAxis"> . <void property="boundsMax"> . <double>30.400000000000002</double> . </void> . <void property="b
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:data
    Category:dropped
    Size (bytes):62592
    Entropy (8bit):5.407369491024811
    Encrypted:false
    SSDEEP:1536:LXj4UNCBNj9vYNnUeCbfJH2c5n069591y6cIpuCLAORwkIn:LXjcjqujJH2Q591XAORM
    MD5:02E51C66DA75BEF8262C51FD5801A9AB
    SHA1:3FE4625E05E0655AFF3651E13F291F80BBD07D0D
    SHA-256:345A586FBF6F64558A38D39563F7E9492D9C934B447CD1FCE7259184228B31F1
    SHA-512:5F02BDFB4B09CF16F7CD3341C1E07BE63921CB4640F365AAF1FECA467A3945AA62E0A2DD91724E24155CF5B96AFC3CA9AD03EBCAD32CA4DB9BD502B54828FD98
    Malicious:false
    Reputation:low
    Preview:HOBO......P......M... ........................Onset Computer Corporation...HOBO U20-001 Water Level...819633.........:...........819633_12_17......,................................Eastern Standard Time...@f.H...........................................................0.....2....3.......3"...........1.?o...hG3;...6.g...Z55.D...........Y.Pt....e...d.].c...b...a...b.\.a.].`...a...a.].b...b.].b...c.].c...c...c...d.].d...e...e...e...f...e.].e.].g...e...f...f...f...f...g...h...g...j...j...k...l...l...m...m...o...p...q...r.].u.].t.].u.].u.].x.].w.].w.].w.].x.].y.].y.].y.].z.].z.].{.].{.].|.].~.]...].~.]...]...]...]...]...]...]...]...]...]...]...]...]...]...]...]...]...]...]...]...]...]...]...]...]...]...]...]...]...]...]...]...]...]...]...]...]...]...]...]...]...]...]...]...]...]...]...]...]...]...]...]...]...]...]...]...]...]...]...]...]...]...]...]...]...]...]...]...]...]...]...]...]...]...]...]...]...]...]...]...]...]...]...]...]...]...]...]...]...]...]...]...]...]...]...]...]...]...]...].
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:data
    Category:dropped
    Size (bytes):62592
    Entropy (8bit):4.702029010601964
    Encrypted:false
    SSDEEP:1536:uOYRKS4OGQ3XlIegvl5UXehP7HLlJKE66X663q3S++Om+++++++Ga0ZsMW7ICeO1:rmJ3O1LR66X6631++Om+++++++GaKsLb
    MD5:63FB3A2E985F1F7F557C2B7744D1D1D6
    SHA1:A69C54B2834AC7149A18B36A821ABEE7C5D40AB9
    SHA-256:89F8D4BE3204C904217414C3A7398E85553C75FD416228464CBCA7FD00A745F1
    SHA-512:F913E26BE5FA1F91755F8173DE2EED145B800264E217E3498A6D1566C19B5F5244984360D8F48261BE52420507E1860F2FDF052B8CDC186FE1501ABF6FC970C1
    Malicious:false
    Reputation:low
    Preview:HOBO......P......M... ........................Onset Computer Corporation...HOBO U20-001 Water Level...819617........-:...........819617_12_17......,...............(................Eastern Standard Time...@d............................................................0.....2....3.......29...........1.?*#..#.;....M0...4.&............b.Vu...N(.9.6.m.6Jy.6:}.6:}.6*}.6*}.6*}.6:}.6:}.6*}.6:}.6:}.6:}.6J}.6Z}.6Z}.6Z}.6j}.6j}.6j}.6z}.6.}.6z}.6j}.6.}.6.}.6.}.6.}.6.}.6.}.6.}.6.}.6.}.6.}.6.}.6.}.7.}.7.}.7.}.7.}.7:}.7J}.7j}.7j}.7.}.7.}.7.}.7.}.7.}.7.}.7.}.7.}.7.}.7.}.8.}.8.}.8.}.8.}.8*}.8.}.8J}.8J}.8Z}.8j}.8z}.8Z}.8j}.8z}.8.}.8.}.8.}.8.}.8.}.8.}.8.}.8.}.8.}.8.}.9.}.9.}.9:}.9J}.9J}.9Z}.9J}.9Z}.9Z}.9z}.9.}.9.}.9.}.9.}.9.}.9.}.9.}.9.}.9.}.9.}.9.}.9.}.9..9..9.}.9.}.9.}.9.}.:.}.:...:.}.::}.:J}.::}.::}.::}.:J}.:J}.:Z}.:j..:z}.:z}.:.}.:...:.}.:.}.:...:.}.:...:...:...:.}.:.}.:.}.:..:.}.:...:..:.}.:.}.:..;.}.:.}.:.}.:.}.:.}.:.}.:.}.:.}.:.}.:.}.:.}.:..:.}.:.}.:.}.:.}.:.}.:.}.:.}.:.}.:..:.}.:..:.}.
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:data
    Category:dropped
    Size (bytes):14359
    Entropy (8bit):6.274790691965698
    Encrypted:false
    SSDEEP:384:eOPISeF3qfZc7Eh5sm0QML8h4KrhJAUM9+N:jASeY67I5smVo8xJAUww
    MD5:36D83354B89CFFEE47318DCCC4B31993
    SHA1:961F5A5A8E3B57BAAE68EBA97351A9248D9CFCF8
    SHA-256:E6A7AB0FADB292FED2F311CEB9B13CC3C1D5165E88443E6752732915653904D6
    SHA-512:AAFF0B1B553A0911EB488EF89EDD59EBC5ED67CAFD4584C165129B9278C7BB2E0ABE15D432D1CD941A4DD0B6516DD764212ED3B9C36B84A0263AE933AFBE63E5
    Malicious:false
    Reputation:low
    Preview:HOBO.......................J...s.........<......B............Sample Weather Data File..................)@0........ ......!........................)(c) 2001-07 Onset Computer Corporation........3......... ...........5.............. ....)......#...3.HOBO U30 Station .2.U30..........4.5........Reserved......................................................................................................................N..................................s....................................h...................................h................................4..Cranberry Demo'[.....N(..)..#..D$..D ....:..n&....Rain.mm.......D..I%.....D..I2.S-RGA-M0023.0.01" RainGauge'e....s.(..)..#..Z$..Z ..&... Solar Radiation.W/m^2.......D...%.....D...2.S-LIB-XXXX3.Si Pyranometer...'a.....h(..)..#...$....4.. ..&....Temperature.*C...F.@.....%.. ..B...2.S-THB-XXXX3.12-bit Temp/RH:T'X.....h(..)..#...$.MP.4.. ..&....RH.%.......B..%.....B...2.S-THB-XXXX3.12-bit Temp/RH:RH.....P......D.*p..5......[N....Q.J..
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:ASCII text
    Category:dropped
    Size (bytes):41213
    Entropy (8bit):3.7972340459046707
    Encrypted:false
    SSDEEP:192:Sa/liELEAqJMDxBem9QoI06DMJk7etYPiwF2TcBCv4PN+b4NKXEp2TfyxuDm1g1p:S6RIAqJMD3esb3vRLH3
    MD5:25C26B5D9A52580A3160A32034E2D737
    SHA1:9D33F505CB3329F7129FAD4249CA973AA6521A8F
    SHA-256:20D8F55B788C2790BE5B4239B3EAF625178059AA8074E8990CB28A8BA8AE5EC5
    SHA-512:F893B0F427B47FD0910C5F0808F26A185590D5850DB9798A6532CA9F01FA395009292E5C3DC6CF0F69F62D740207E9C9AA470F3D6CB457E9A27CAFA02BB99DA5
    Malicious:false
    Reputation:low
    Preview:Date Time.Temperature (*F) c:1.Temperature (*C) c:1.RH (%) c:1 2.Dew Point (*F) c:1 2.Dew Point (*C) c:1 2.Abs Humidity (gm/M3) c:1 2.Uncomp RH (%) c:2.Intensity (lum/sqf) c:3.10/03/05 15:29:35.72.46.22.48.38.8.46.7.78.7.7.39.39.10/03/05 15:29:36.72.46.22.48.38.8.46.7.78.7.7.39.39.10/03/05 15:29:37.72.46.22.48.38.7.45.9.7.73.7.7.38.8.39.10/03/05 15:29:38.72.46.22.48.38.7.45.9.7.73.7.7.38.8.39.10/03/05 15:29:39.72.46.22.48.38.7.45.9.7.73.7.7.38.8.39.10/03/05 15:29:40.72.46.22.48.38.7.45.9.7.73.7.7.38.8.37.10/03/05 15:29:41.72.46.22.48.38.7.45.9.7.73.7.7.38.8.22.10/03/05 15:29:42.72.46.22.48.38.8.46.7.78.7.7.39.34.10/03/05 15:29:43.72.46.22.48.38.8.46.7.78.7.7.39.37.10/03/05 15:29:44.72.46.22.48.38.8.46.7.78.7.7.39.37.10/03/05 15:29:45.72.46.22.48.38.8.46.7.78.7.7.39.37.10/03/05 15:29:46.72.46.22.48.38.8.46.7.78.7.7.39.37.10/03/05 15:29:47.72.46.22.48.38.8.46.7.78.7.7.39.37.10/03/05 15:29:48.72.46.22.48.38.8.46.7.78.7.7.39.37.10/03/05 15:29:49.72.46.22.48.38.8.46.7.78.7.7.39.37.10/03/05
    Process:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    File Type:XML 1.0 document, Unicode text, UTF-8 text
    Category:dropped
    Size (bytes):163746
    Entropy (8bit):6.002957258748671
    Encrypted:false
    SSDEEP:3072:E2GkngMsBRafl3liNdaDiNzHAuMKtsi8eN2EgluwV5863KZcpCusxLpIa8qr3ib7:EnMakl6RlsiKEIjPfrsVAb7
    MD5:8B75D3D45175086BFD8FBC8644A17438
    SHA1:1DAA8D715D54348163A6A2988E4F8B3213FDD6BE
    SHA-256:87459494518355B1EF38DE45264181A34603AD3745D6866DFCF3474A36AEB398
    SHA-512:9285797CE414A4CC71126B5DC4D5ED041C2D34BB3A77324F6D75AA6BD126B327BC03E06F1BB96ECF3B83B758551E094ADADB95D0C96AE53ADB7831A4DE1F088F
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="UTF-8"?> .<java version="1.6.0_17" class="java.beans.XMLDecoder"> . <object class="Appleseed.HOBOViewX"> . <void property="TFont"> . <string>Dialog.plain</string> . </void> . <void property="TFontSz"> . <int>12</int> . </void> . <void property="axes"> . <array class="Graphing.LGAxis" length="9"> . <void index="0"> . <object class="Graphing.LGAbsTimeAxis"> . <void property="boundsMax"> . <double>1.1087712E12</double> . </void> . <void property="boundsMin"> . <double>1.1032416E12</double> . </void> . <void property="crosshair"> . <boolean>true</boolean> . </void> . <void property="grid"> . <boolean>true</boolean> . </void> . <void property="location"> . <int>2</int> . </void> . </object> . </void> . <void index="1"> . <object class="Graphing.LGValueAxis"> . <void property="boundsMax"> . <double>22.0</double> . </void> . <void p
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:JSON data
    Category:dropped
    Size (bytes):521377
    Entropy (8bit):4.9084889265453135
    Encrypted:false
    SSDEEP:3072:gdTb5Sb3F2FqSrfZm+CnQsbzxZO7aYb6f5780K2:wb5q3umBnzT
    MD5:C37972CBD8748E2CA6DA205839B16444
    SHA1:9834B46ACF560146DD7EE9086DB6019FBAC13B4E
    SHA-256:D4CFBB0E8B9D3E36ECE921B9B51BD37EF1D3195A9CFA1C4586AEA200EB3434A7
    SHA-512:02B4D134F84122B6EE9A304D79745A003E71803C354FB01BAF986BD15E3BA57BA5EF167CC444ED67B9BA5964FF5922C50E2E92A8A09862059852ECD9CEF1A900
    Malicious:false
    Reputation:low
    Preview:{"MajorVersion":4,"MinorVersion":40,"Expiration":14,"Fonts":[{"a":[4294966911],"f":"Abadi","fam":[],"sf":[{"c":[1,0],"dn":"Abadi","fs":32696,"ful":[{"lcp":983041,"lsc":"Latn","ltx":"Abadi"}],"gn":"Abadi","id":"23643452060","p":[2,11,6,4,2,1,4,2,2,4],"sub":[],"t":"ttf","u":[2147483651,0,0,0],"v":197263,"w":26215680},{"c":[1,0],"dn":"Abadi Extra Light","fs":22180,"ful":[{"lcp":983042,"lsc":"Latn","ltx":"Abadi Extra Light"}],"gn":"Abadi Extra Light","id":"17656736728","p":[2,11,2,4,2,1,4,2,2,4],"sub":[],"t":"ttf","u":[2147483651,0,0,0],"v":197263,"w":13108480}]},{"a":[4294966911],"f":"ADLaM Display","fam":[],"sf":[{"c":[536870913,0],"dn":"ADLaM Display Regular","fs":140072,"ful":[{"lcp":983040,"lsc":"Latn","ltx":"ADLaM Display"}],"gn":"ADLaM Display","id":"31965479471","p":[2,1,0,0,0,0,0,0,0,0],"sub":[],"t":"ttf","u":[2147491951,1107296330,0,0],"v":131072,"w":26215680}]},{"a":[4294966911],"f":"Agency FB","fam":[],"sf":[{"c":[536870913,0],"dn":"Agency FB Bold","fs":54372,"ful":[{"lcp":9830
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:TrueType Font data, 10 tables, 1st "OS/2", 7 names, Microsoft, language 0x409, \251 2018 Microsoft Corporation. All Rights Reserved.msofp_4_40RegularVersion 4.40;O365
    Category:dropped
    Size (bytes):773040
    Entropy (8bit):6.55939673749297
    Encrypted:false
    SSDEEP:12288:Zn84XULLDs51UJQSOf9VvLXHyheIQ47gEFGHtAgk3+/cLQ/zhm1kjFKy6Nyjbqq+:N8XPDs5+ivOXgo1kYvyz2
    MD5:4296A064B917926682E7EED650D4A745
    SHA1:3953A6AA9100F652A6CA533C2E05895E52343718
    SHA-256:E04E41C74D6C78213BA1588BACEE64B42C0EDECE85224C474A714F39960D8083
    SHA-512:A25388DDCE58D9F06716C0F0BDF2AEFA7F68EBCA7171077533AF4A9BE99A08E3DCD8DFE1A278B7AA5DE65DA9F32501B4B0B0ECAB51F9AF0F12A3A8A75363FF2C
    Malicious:false
    Reputation:low
    Preview:........... OS/29....(...`cmap.s.,.......pglyf..&....|....head2..........6hheaE.@v.......$hmtx...........@loca.U.....8...Dmaxp........... name.P+........post...<...... .........b~1_.<...........<......r......Aa...................Q....Aa....Aa.........................~...................................................3..............................MS .@.......(...Q................. ...........d...........0...J.......8.......>..........+a..#...,................................................/...K.......z...............N......*...!...-...+........z.......h..%^..3...&j..+...+%..'R..+..."....................k......$A...,.......g...&...=.......X..&........*......&....B..(B...............#.......j...............+...P...5...@...)..........#...)Q...............*...{.. ....?..'...#....N...7......<...;>.............. ]...........5......#....s.......$.......$.......^..................+...>....H.......%...7.......6.......O...V...........K......"........c...N......!...............$...&...*p..
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:data
    Category:dropped
    Size (bytes):2278
    Entropy (8bit):3.860149951405785
    Encrypted:false
    SSDEEP:48:uiTrlKxsxxgxl9Il8uc8QJ15VzzUeDswWfBjMuY/IAamVr3ck1d1rc:vMYaxr5V3BDSJgbr3cZ
    MD5:4E71AB57A2A676F1BF37DB9A189BA67A
    SHA1:9912DCBEF6E73DDB029D1BCA927577E75F78BCD4
    SHA-256:F182A753DAC5308CC7729890CBA7BD397FD827A50914DF81933809145743B058
    SHA-512:1B4B423141422A30E42E0682D71208851D02AD7B56BC074036F3ECCE063AD2F6BD4DA9D413747706EA2436CFA0E7F6FA5C0D2477898DD63CDDA2AAD923F5EF71
    Malicious:false
    Reputation:low
    Preview:{.".T.B.D.a.t.a.S.t.o.r.e.O.b.j.e.c.t.".:.{.".H.e.a.d.e.r.".:.{.".O.b.j.e.c.t.T.y.p.e.".:.".T.o.k.e.n.R.e.s.p.o.n.s.e.".,.".S.c.h.e.m.a.V.e.r.s.i.o.n.M.a.j.o.r.".:.2.,.".S.c.h.e.m.a.V.e.r.s.i.o.n.M.i.n.o.r.".:.1.}.,.".O.b.j.e.c.t.D.a.t.a.".:.{.".S.y.s.t.e.m.D.e.f.i.n.e.d.P.r.o.p.e.r.t.i.e.s.".:.{.".R.e.q.u.e.s.t.I.n.d.e.x.".:.{.".T.y.p.e.".:.".I.n.l.i.n.e.B.y.t.e.s.".,.".I.s.P.r.o.t.e.c.t.e.d.".:.f.a.l.s.e.,.".V.a.l.u.e.".:.".C.J.1.m.u.g.S.o.z.s.S.9.x.S.Z./.Q.v.O.c.+.E.J.4.u.2.c.=.".}.,.".E.x.p.i.r.a.t.i.o.n.".:.{.".T.y.p.e.".:.".I.n.l.i.n.e.B.y.t.e.s.".,.".I.s.P.r.o.t.e.c.t.e.d.".:.f.a.l.s.e.,.".V.a.l.u.e.".:.".A.N.R.N.h.5.r.B.2.g.E.=.".}.,.".S.t.a.t.u.s.".:.{.".T.y.p.e.".:.".I.n.l.i.n.e.B.y.t.e.s.".,.".I.s.P.r.o.t.e.c.t.e.d.".:.f.a.l.s.e.,.".V.a.l.u.e.".:.".A.A.A.A.A.A.=.=.".}.,.".R.e.s.p.o.n.s.e.B.y.t.e.s.".:.{.".T.y.p.e.".:.".I.n.l.i.n.e.B.y.t.e.s.".,.".I.s.P.r.o.t.e.c.t.e.d.".:.t.r.u.e.,.".V.a.l.u.e.".:.".A.Q.A.A.A.N.C.M.n.d.8.B.F.d.E.R.j.H.o.A.w.E./.C.l.+.s.B.A.A.A.A.l.6.E.i.X.9.
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:data
    Category:dropped
    Size (bytes):4542
    Entropy (8bit):3.9932408287600945
    Encrypted:false
    SSDEEP:96:KYaxwlLVXl2ZeNIC/Xlk4b4D8VUrDJK3CYK2E2F:K/xwJV12Zil/4DMQVSXrF
    MD5:6DD423ADD363FA9D9BCC7D7855CE58E3
    SHA1:10B555CBCED0CC0B9D54F607CC03EC3EC22FED36
    SHA-256:7BB7F4B7C6C20D59F5042A9D159E246F87774476732E92F3ADFDF3EB506BB721
    SHA-512:DF7B117722D440B24811220F1DC6CBCC19D167D81AA2904173F534EC55946B39B1C1F0E000D65A9389FE057855EBF076D5E7BD9F806F82DC42B18A374657C70C
    Malicious:false
    Reputation:low
    Preview:{.".T.B.D.a.t.a.S.t.o.r.e.O.b.j.e.c.t.".:.{.".H.e.a.d.e.r.".:.{.".O.b.j.e.c.t.T.y.p.e.".:.".T.o.k.e.n.R.e.s.p.o.n.s.e.".,.".S.c.h.e.m.a.V.e.r.s.i.o.n.M.a.j.o.r.".:.2.,.".S.c.h.e.m.a.V.e.r.s.i.o.n.M.i.n.o.r.".:.1.}.,.".O.b.j.e.c.t.D.a.t.a.".:.{.".S.y.s.t.e.m.D.e.f.i.n.e.d.P.r.o.p.e.r.t.i.e.s.".:.{.".R.e.q.u.e.s.t.I.n.d.e.x.".:.{.".T.y.p.e.".:.".I.n.l.i.n.e.B.y.t.e.s.".,.".I.s.P.r.o.t.e.c.t.e.d.".:.f.a.l.s.e.,.".V.a.l.u.e.".:.".V.q.Y.a.6.3.X.Y.9.b.4.Y.b.C.Z.g.f.0.u.y.E.6.v.n.x.e.w.=.".}.,.".E.x.p.i.r.a.t.i.o.n.".:.{.".T.y.p.e.".:.".I.n.l.i.n.e.B.y.t.e.s.".,.".I.s.P.r.o.t.e.c.t.e.d.".:.f.a.l.s.e.,.".V.a.l.u.e.".:.".G.M.+.F.b.J.L.B.2.g.E.=.".}.,.".S.t.a.t.u.s.".:.{.".T.y.p.e.".:.".I.n.l.i.n.e.B.y.t.e.s.".,.".I.s.P.r.o.t.e.c.t.e.d.".:.f.a.l.s.e.,.".V.a.l.u.e.".:.".A.w.A.A.A.A.=.=.".}.,.".R.e.s.p.o.n.s.e.B.y.t.e.s.".:.{.".T.y.p.e.".:.".I.n.l.i.n.e.B.y.t.e.s.".,.".I.s.P.r.o.t.e.c.t.e.d.".:.t.r.u.e.,.".V.a.l.u.e.".:.".A.Q.A.A.A.N.C.M.n.d.8.B.F.d.E.R.j.H.o.A.w.E./.C.l.+.s.B.A.A.A.A.l.6.E.i.X.9.
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:data
    Category:dropped
    Size (bytes):1024
    Entropy (8bit):0.03351732319703582
    Encrypted:false
    SSDEEP:3:ol3lG:40
    MD5:830FBF83999E052538EAF156AB6ECB17
    SHA1:9F6C69FA4232801D3A4857C630BA7A719662135A
    SHA-256:D5098A2CEAE815DB29CD53C76F85240C95DC4D2E3FEDDD71D628617064C29869
    SHA-512:A83E2E9D5274F0065A26C306F355E9590D6126297EAD87AF053CC78FB64CB31694C533139F72686C77FC772148181D8AAE973E65978D04E5F20F6F6C6BA0A013
    Malicious:false
    Reputation:low
    Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:data
    Category:dropped
    Size (bytes):1024
    Entropy (8bit):0.03351732319703582
    Encrypted:false
    SSDEEP:3:ol3lG:40
    MD5:830FBF83999E052538EAF156AB6ECB17
    SHA1:9F6C69FA4232801D3A4857C630BA7A719662135A
    SHA-256:D5098A2CEAE815DB29CD53C76F85240C95DC4D2E3FEDDD71D628617064C29869
    SHA-512:A83E2E9D5274F0065A26C306F355E9590D6126297EAD87AF053CC78FB64CB31694C533139F72686C77FC772148181D8AAE973E65978D04E5F20F6F6C6BA0A013
    Malicious:false
    Reputation:low
    Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:data
    Category:dropped
    Size (bytes):1024
    Entropy (8bit):0.03351732319703582
    Encrypted:false
    SSDEEP:3:ol3lG:40
    MD5:830FBF83999E052538EAF156AB6ECB17
    SHA1:9F6C69FA4232801D3A4857C630BA7A719662135A
    SHA-256:D5098A2CEAE815DB29CD53C76F85240C95DC4D2E3FEDDD71D628617064C29869
    SHA-512:A83E2E9D5274F0065A26C306F355E9590D6126297EAD87AF053CC78FB64CB31694C533139F72686C77FC772148181D8AAE973E65978D04E5F20F6F6C6BA0A013
    Malicious:false
    Reputation:low
    Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:data
    Category:dropped
    Size (bytes):1024
    Entropy (8bit):0.03351732319703582
    Encrypted:false
    SSDEEP:3:ol3lG:40
    MD5:830FBF83999E052538EAF156AB6ECB17
    SHA1:9F6C69FA4232801D3A4857C630BA7A719662135A
    SHA-256:D5098A2CEAE815DB29CD53C76F85240C95DC4D2E3FEDDD71D628617064C29869
    SHA-512:A83E2E9D5274F0065A26C306F355E9590D6126297EAD87AF053CC78FB64CB31694C533139F72686C77FC772148181D8AAE973E65978D04E5F20F6F6C6BA0A013
    Malicious:false
    Reputation:low
    Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:data
    Category:dropped
    Size (bytes):69494
    Entropy (8bit):3.477845035120827
    Encrypted:false
    SSDEEP:768:5/ORLjiN/bt1IgiyuqhVMUPIYGGxb0GL4Uak4VoIn/IgUZOwU5P+Ao2c:hOC/bwgfMUwYGGxRitkqc
    MD5:5F6D75DEE2E8EB2D177016F0F2C531EA
    SHA1:C112325F4899535E00727D1B3D33FE48B4F5738B
    SHA-256:C0A85E82D160943BF56B1324178A7357672E87A6A57CC75595500CF0B52489E2
    SHA-512:86B2688D1923C357BE2B0805CC325AF4D21E6806AAD6B22E99356A7862CD378433892F1CB66D4F0B308944D5A582BC8E57806AB41CC1A7688D1DB9366529E2FC
    Malicious:false
    Reputation:low
    Preview:H.O.B.O.w.a.r.e. .f.o.r. .P.C. .a.n.d. .M.a.c.,. .V.e.r.s.i.o.n. .3...7...2.8. ...L.a.s.t. .u.p.d.a.t.e.d. .F.e.b.r.u.a.r.y.,. .2.0.2.4. ...........................................................................................................................................................................................................................................................................................................................................................................................N...P................... ...&...b...d...f...........................................................T...~...........D...J...L...........D!..F!..,%...%..2&..4&...&...&...&...&...&...&...&...&...&...&..2)..4)..r...t...&3..f3..l3..|3...........................................................>*.CJ..KH..OJ,.QJ,.^J,.aJ..!.j....CJ..KH..OJ,.QJ,.U..^J,.aJ..*>*.B*.CJ..KH..OJ,.QJ,.^J,.aJ..ph....wh......CJ..KH..OJ,.QJ,.^J,.aJ....CJ..KH..OJ,.QJ,.^J,.aJ....CJ..KH..OJ,.QJ,.^J,.aJ....5..CJ..
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:data
    Category:dropped
    Size (bytes):1536
    Entropy (8bit):1.3030575809016534
    Encrypted:false
    SSDEEP:3:ml+lGl+l+l+l1PPPXll1l7lhlJvl5hzldlxpxl/b1l/pl/Ppl/NllXljl/tl/rlF:mEMEEEul39lCgK1qVFgy2WkdQEn
    MD5:B1847A046535C933F3CB6C0CC6858704
    SHA1:6A525CE540436F889613F589E43FC895A4F91C7E
    SHA-256:F3D814C1DAC6995B8DC4742101EECD6548DEBB20B7C0D7398F57382542F774C1
    SHA-512:9FC0371BBBB38E8DC728D94AB8EE45E757AB1EC992920D9F96EF47C1D594938C8BAD0F70A35EABDE39BE63218ABE7DA77DDB991E9481065EBDF67B1A65EE680A
    Malicious:false
    Reputation:low
    Preview:....1.2.....1.2.....1.....1.....1.2.....1.2.....1.2.....1.2.....(.....(.....(.....(.....(............................................................................................................................................................................................................................................................................................................................................................................................................................................................................... ...&...(.......0...6...8...>...@...D...F...J...L...P...R...V...X...............................................................................................................................................................................................................................................................................................................................................................................................
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:data
    Category:dropped
    Size (bytes):1024
    Entropy (8bit):0.03351732319703582
    Encrypted:false
    SSDEEP:3:ol3lG:40
    MD5:830FBF83999E052538EAF156AB6ECB17
    SHA1:9F6C69FA4232801D3A4857C630BA7A719662135A
    SHA-256:D5098A2CEAE815DB29CD53C76F85240C95DC4D2E3FEDDD71D628617064C29869
    SHA-512:A83E2E9D5274F0065A26C306F355E9590D6126297EAD87AF053CC78FB64CB31694C533139F72686C77FC772148181D8AAE973E65978D04E5F20F6F6C6BA0A013
    Malicious:false
    Reputation:low
    Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:data
    Category:dropped
    Size (bytes):1024
    Entropy (8bit):0.2491520368908127
    Encrypted:false
    SSDEEP:3:YlXl3lldHzlblXllZrnlPlK:I4
    MD5:9A5F3325C368A02FABF00EC854202D3F
    SHA1:B423BAB6D74354C6705C813CE0246BA432D1BBF9
    SHA-256:759AD91E909277C421B0062454FDC8D9845FA506B64F8BF0341C2BBC3A9D4856
    SHA-512:7402FC0BCD09CB2A2F12D4B138ECD1C3DFF255DA9F11EFDEE640BEFB834A4F49F3884A1BFF0E84CB822349EF7E129AEDD77D58070A87AAD1EC2F96AA31B9EA64
    Malicious:false
    Reputation:low
    Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:data
    Category:dropped
    Size (bytes):1024
    Entropy (8bit):0.03351732319703582
    Encrypted:false
    SSDEEP:3:ol3lG:40
    MD5:830FBF83999E052538EAF156AB6ECB17
    SHA1:9F6C69FA4232801D3A4857C630BA7A719662135A
    SHA-256:D5098A2CEAE815DB29CD53C76F85240C95DC4D2E3FEDDD71D628617064C29869
    SHA-512:A83E2E9D5274F0065A26C306F355E9590D6126297EAD87AF053CC78FB64CB31694C533139F72686C77FC772148181D8AAE973E65978D04E5F20F6F6C6BA0A013
    Malicious:false
    Reputation:low
    Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:data
    Category:dropped
    Size (bytes):1024
    Entropy (8bit):0.03351732319703582
    Encrypted:false
    SSDEEP:3:ol3lG:40
    MD5:830FBF83999E052538EAF156AB6ECB17
    SHA1:9F6C69FA4232801D3A4857C630BA7A719662135A
    SHA-256:D5098A2CEAE815DB29CD53C76F85240C95DC4D2E3FEDDD71D628617064C29869
    SHA-512:A83E2E9D5274F0065A26C306F355E9590D6126297EAD87AF053CC78FB64CB31694C533139F72686C77FC772148181D8AAE973E65978D04E5F20F6F6C6BA0A013
    Malicious:false
    Reputation:low
    Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:data
    Category:dropped
    Size (bytes):1024
    Entropy (8bit):0.03351732319703582
    Encrypted:false
    SSDEEP:3:ol3lG:40
    MD5:830FBF83999E052538EAF156AB6ECB17
    SHA1:9F6C69FA4232801D3A4857C630BA7A719662135A
    SHA-256:D5098A2CEAE815DB29CD53C76F85240C95DC4D2E3FEDDD71D628617064C29869
    SHA-512:A83E2E9D5274F0065A26C306F355E9590D6126297EAD87AF053CC78FB64CB31694C533139F72686C77FC772148181D8AAE973E65978D04E5F20F6F6C6BA0A013
    Malicious:false
    Reputation:low
    Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:data
    Category:dropped
    Size (bytes):1024
    Entropy (8bit):0.03351732319703582
    Encrypted:false
    SSDEEP:3:ol3lG:40
    MD5:830FBF83999E052538EAF156AB6ECB17
    SHA1:9F6C69FA4232801D3A4857C630BA7A719662135A
    SHA-256:D5098A2CEAE815DB29CD53C76F85240C95DC4D2E3FEDDD71D628617064C29869
    SHA-512:A83E2E9D5274F0065A26C306F355E9590D6126297EAD87AF053CC78FB64CB31694C533139F72686C77FC772148181D8AAE973E65978D04E5F20F6F6C6BA0A013
    Malicious:false
    Reputation:low
    Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:data
    Category:dropped
    Size (bytes):1024
    Entropy (8bit):0.03351732319703582
    Encrypted:false
    SSDEEP:3:ol3lG:40
    MD5:830FBF83999E052538EAF156AB6ECB17
    SHA1:9F6C69FA4232801D3A4857C630BA7A719662135A
    SHA-256:D5098A2CEAE815DB29CD53C76F85240C95DC4D2E3FEDDD71D628617064C29869
    SHA-512:A83E2E9D5274F0065A26C306F355E9590D6126297EAD87AF053CC78FB64CB31694C533139F72686C77FC772148181D8AAE973E65978D04E5F20F6F6C6BA0A013
    Malicious:false
    Reputation:low
    Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:ASCII text, with very long lines (1980), with CRLF line terminators
    Category:dropped
    Size (bytes):20971520
    Entropy (8bit):0.012054995506622843
    Encrypted:false
    SSDEEP:768:vIThMngYuJlxOHai+hjhtrmrS15KFa3z:vIThMngYuJrO6i+hjht6+15Kyz
    MD5:1180AEF97FD63A7B565C64BF7EBFD07B
    SHA1:84D65CF2EF797F090AEAC4B5394926D31D4148A6
    SHA-256:4C5DF4193E42306D3C59A5105DE46FD3D549CBDCF2027D1D7F8C0E18DB87331A
    SHA-512:D8AD24937E66C644618081AED7D82123B14693733716CAC7BE6D4CFAAB99A99438A9E957F7E9E321B68F5109E8A03D9131A3B2201178137CBFEBEDB84EA35BEC
    Malicious:false
    Reputation:low
    Preview:Timestamp.Process.TID.Area.Category.EventID.Level.Message.Correlation..06/18/2024 15:13:56.777.WINWORD (0x1768).0x16A4.Microsoft Word.Telemetry Event.b7vzq.Medium.SendEvent {"EventName":"Office.Telemetry.LoadXmlRules","Flags":33777014401990913,"InternalSequenceNumber":22,"Time":"2024-06-18T15:13:56.777Z","Contract":"Office.System.Activity","Activity.CV":"6t3vzWgjS0ewV4Kx9sEzoA.7.1","Activity.Duration":288,"Activity.Count":1,"Activity.AggMode":0,"Activity.Success":false,"Activity.Result.Code":-2147024890,"Activity.Result.Type":"HRESULT","Activity.Result.Tag":528307459}...06/18/2024 15:13:56.777.WINWORD (0x1768).0x16A4.Microsoft Word.Telemetry Event.b7vzq.Medium.SendEvent {"EventName":"Office.Telemetry.ProcessIdleQueueJob","Flags":33777014401990913,"InternalSequenceNumber":23,"Time":"2024-06-18T15:13:56.777Z","Contract":"Office.System.Activity","Activity.CV":"6t3vzWgjS0ewV4Kx9sEzoA.7","Activity.Duration":4279,"Activity.Count":1,"Activity.AggMode":0,"Activity.Success":false,"Data.FailureD
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:data
    Category:dropped
    Size (bytes):20971520
    Entropy (8bit):0.0
    Encrypted:false
    SSDEEP:3::
    MD5:8F4E33F3DC3E414FF94E5FB6905CBA8C
    SHA1:9674344C90C2F0646F0B78026E127C9B86E3AD77
    SHA-256:CD52D81E25F372E6FA4DB2C0DFCEB59862C1969CAB17096DA352B34950C973CC
    SHA-512:7FB91E868F3923BBD043725818EF3A5D8D08EBF1059A18AC0FE07040D32EEBA517DA11515E6A4AFAEB29BCC5E0F1543BA2C595B0FE8E6167DDC5E6793EDEF5BB
    Malicious:false
    Reputation:low
    Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:data
    Category:dropped
    Size (bytes):288
    Entropy (8bit):3.523917709458511
    Encrypted:false
    SSDEEP:6:fxnxUXC1l8ME3QepmlJ0+3FbnKfZObdADryMluxHZypwwyv:fxnySvNGHmD0wbnKYZAH/lMZqiv
    MD5:4A9A2E8DB82C90608C96008A5B6160EF
    SHA1:A49110814D9546B142C132EBB5B9D8A1EC23E2E6
    SHA-256:4FA948EEB075DFCB8DCA773A3F994560C69D275690953625731C4743CD5729F7
    SHA-512:320B9CC860FFBDB0FD2DB7DA7B7B129EEFF3FFB2E4E4820C3FBBFEA64735EB8CFE1F4BB5980302770C0F77FF575825F2D9A8BB59FC80AD4C198789B3D581963B
    Malicious:false
    Reputation:low
    Preview:[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .c.h.i.c.a.g.o...x.s.l.....C.o.m.p.o.n.e.n.t.:. .W.o.r.d.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....E.x.e.c.u.t.a.b.l.e.:. .{.W.D.}.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.....C.o.m.m.a.n.d.:. ./.f. .{.F.i.l.e.P.a.t.h.}.........
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
    Category:dropped
    Size (bytes):296658
    Entropy (8bit):5.000002997029767
    Encrypted:false
    SSDEEP:6144:RwprAMk0qvtfL/vF/bkWPz9yv7EOMBPitjASjTQQr7IwR0TnyDkJb78plJwf33iV:M
    MD5:9AC6DE7B629A4A802A41F93DB2C49747
    SHA1:3D6E929AA1330C869D83F2BF8EBEBACD197FB367
    SHA-256:52984BC716569120D57C8E6A360376E9934F00CF31447F5892514DDCCF546293
    SHA-512:5736F14569E0341AFB5576C94B0A7F87E42499CEC5927AAC83BB5A1F77B279C00AEA86B5F341E4215076D800F085D831F34E4425AD9CFD52C7AE4282864B1E73
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="utf-8"?>....<xsl:stylesheet version="1.0" xmlns:xsl="http://www.w3.org/1999/XSL/Transform" xmlns:msxsl="urn:schemas-microsoft-com:xslt" xmlns:b="http://schemas.openxmlformats.org/officeDocument/2006/bibliography" xmlns:t="http://www.microsoft.com/temp">...<xsl:output method="html" encoding="us-ascii"/>............<xsl:template match="*" mode="outputHtml2">.....<xsl:apply-templates mode="outputHtml"/>.....</xsl:template>.....<xsl:template name="StringFormatDot">....<xsl:param name="format" />....<xsl:param name="parameters" />.... <xsl:variable name="prop_EndChars">.. <xsl:call-template name="templ_prop_EndChars"/>.. </xsl:variable>.... <xsl:choose>.....<xsl:when test="$format = ''"></xsl:when>.....<xsl:when test="substring($format, 1, 2) = '%%'">......<xsl:text>%</xsl:text>......<xsl:call-template name="StringFormatDot">.......<xsl:with-param name="format" select="substring($format, 3)" />.......<xsl:with-param name="parameters" select="$para
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:data
    Category:dropped
    Size (bytes):252
    Entropy (8bit):3.4680595384446202
    Encrypted:false
    SSDEEP:6:fxnxUXivlE3QepmlJ0+hdADryMluyS6Bkls0Lwv:fxnyydGHmD0+dAH/luWvv
    MD5:D79B5DE6D93AC06005761D88783B3EE6
    SHA1:E05BDCE2673B6AA8CBB17A138751EDFA2264DB91
    SHA-256:96125D6804544B8D4E6AE8638EFD4BD1F96A1BFB9EEF57337FFF40BA9FF4CDD1
    SHA-512:34057F7B2AB273964CB086D8A7DF09A4E05D244A1A27E7589BDC7E5679AB5F587FAB52A2261DB22070DA11EF016F7386635A2B8E54D83730E77A7B142C2E3929
    Malicious:false
    Reputation:low
    Preview:[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .a.r.c.h.i.t.e.c.t.u.r.e...g.l.o.x.....C.o.m.p.o.n.e.n.t.:. .W.o.r.d.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.\.S.m.a.r.t.A.r.t. .G.r.a.p.h.i.c.s.........
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:Microsoft OOXML
    Category:dropped
    Size (bytes):5783
    Entropy (8bit):7.88616857639663
    Encrypted:false
    SSDEEP:96:CDG4D+8VsXzXc2zLXTJ2XFY47pk2G7HVlwFzTXNbMfmn2ivLZcreFWw5fc9ADdZm:CDG4DRGY23l2Xu47GL7YtT9V29yWvWdk
    MD5:8109B3C170E6C2C114164B8947F88AA1
    SHA1:FC63956575842219443F4B4C07A8127FBD804C84
    SHA-256:F320B4BB4E57825AA4A40E5A61C1C0189D808B3EACE072B35C77F38745A4C416
    SHA-512:F8A8D7A6469CD3E7C31F3335DDCC349AD7A686730E1866F130EE36AA9994C52A01545CE73D60B642FFE0EE49972435D183D8CD041F2BB006A6CAF31BAF4924AC
    Malicious:false
    Reputation:low
    Preview:PK.........A;.h......F.......[Content_Types].xmlz.........MN.0...by.b.,.BI...X `...{..O.S...H\.'.XTP..K{.o.....rg..bL...XM.:.v..c.k...}.D....9.....Bb>.+..G.......+(.u}.w.]...v..{.M&.].>`....nB..B0Z@.e.u..R.......-.&#....aR..`.a..|. 1^......&..|..s.A.t..b..A.i7...7.&....bQK$O.......9....V....Wt_PK........pnB;.M.:....g......._rels/.rels...J.0.._%.n....xp..,{.i2M.........G..........7...3o/.......d.kyU....^..[>Q....j.#P.H......Z>..+!...B*|@...G...E....E]..".3.......!..7....,:..,.......Ot..0r....Z..&1..U..p.U-.[Uq&.......................Gyy.}n.(.C(i.x........?.vM..}..%.7.b.>L..]..PK........EV:5K..4....H......diagrams/layout1.xml.Yo.6........S.`......$M...Q8A...R..T.k...K.4CQG..}.A..9.?R....!&...Q..ZW.......Q....<8..z..g....4{d.>..;.{.>.X.....Y.2.......cR....9e.. ...}L.....yv&.&...r..h...._..M. e...[..}.>.k..........3.`.ygN...7.w..3..W.S.....w9....r(....Zb..1....z...&WM.D<......D9...ge......6+.Y....$f......wJ$O..N..FC..Er........?..is...-Z
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:data
    Category:dropped
    Size (bytes):292
    Entropy (8bit):3.5026803317779778
    Encrypted:false
    SSDEEP:6:fxnxUXC89ADni8ME3QepmlJ0+3FbnKfZObdADryMluxHZypwwyv:fxnyf9ADiNGHmD0wbnKYZAH/lMZqiv
    MD5:A0D51783BFEE86F3AC46A810404B6796
    SHA1:93C5B21938DA69363DBF79CE594C302344AF9D9E
    SHA-256:47B43E7DBDF8B25565D874E4E071547666B08D7DF4D736EA8521591D0DED640F
    SHA-512:CA3DB5A574745107E1D6CAA60E491F11D8B140637D4ED31577CC0540C12FDF132D8BC5EBABEA3222F4D7BA1CA016FF3D45FE7688D355478C27A4877E6C4D0D75
    Malicious:false
    Reputation:low
    Preview:[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .g.o.s.t.t.i.t.l.e...x.s.l.....C.o.m.p.o.n.e.n.t.:. .W.o.r.d.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....E.x.e.c.u.t.a.b.l.e.:. .{.W.D.}.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.....C.o.m.m.a.n.d.:. ./.f. .{.F.i.l.e.P.a.t.h.}.........
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
    Category:dropped
    Size (bytes):251032
    Entropy (8bit):5.102652100491927
    Encrypted:false
    SSDEEP:6144:hwprA5R95vtfb8p4bgWPwW6/m26AnV9IBgIkqm6HITUZJcjUZS1XkaNPQTlvB2zr:JA
    MD5:F425D8C274A8571B625EE66A8CE60287
    SHA1:29899E309C56F2517C7D9385ECDBB719B9E2A12B
    SHA-256:DD7B7878427276AF5DBF8355ECE0D1FE5D693DF55AF3F79347F9D20AE50DB938
    SHA-512:E567F283D903FA533977B30FD753AA1043B9DDE48A251A9AC6777A3B67667443FEAD0003765A630D0F840B6C275818D2F903B6CB56136BEDCC6D9BDD20776564
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="utf-8"?>......<xsl:stylesheet version="1.0" xmlns:xsl="http://www.w3.org/1999/XSL/Transform" xmlns:msxsl="urn:schemas-microsoft-com:xslt".xmlns:b="http://schemas.openxmlformats.org/officeDocument/2006/bibliography" xmlns:t="http://www.microsoft.com/temp">...<xsl:output method="html" encoding="us-ascii"/>..........<xsl:template match="*" mode="outputHtml2">.....<xsl:apply-templates mode="outputHtml"/>.....</xsl:template>.....<xsl:template name="StringFormatDot">....<xsl:param name="format" />....<xsl:param name="parameters" />.... <xsl:variable name="prop_EndChars">.. <xsl:call-template name="templ_prop_EndChars"/>.. </xsl:variable>.... <xsl:choose>.....<xsl:when test="$format = ''"></xsl:when>.....<xsl:when test="substring($format, 1, 2) = '%%'">......<xsl:text>%</xsl:text>......<xsl:call-template name="StringFormatDot">.......<xsl:with-param name="format" select="substring($format, 3)" />.......<xsl:with-param name="parameters" select="$para
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:data
    Category:dropped
    Size (bytes):254
    Entropy (8bit):3.4721586910685547
    Encrypted:false
    SSDEEP:6:fxnxUX9+RclTloE3QepmlJ0+hdADryMluyS6Bkls0Lwv:fxnyteUTloGHmD0+dAH/luWvv
    MD5:4DD225E2A305B50AF39084CE568B8110
    SHA1:C85173D49FC1522121AA2B0B2E98ADF4BB95B897
    SHA-256:6F00DD73F169C73D425CB9895DAC12387E21C6E4C9C7DDCFB03AC32552E577F4
    SHA-512:0493AB431004191381FF84AD7CC46BD09A1E0FEEC16B3183089AA8C20CC7E491FAE86FE0668A9AC677F435A203E494F5E6E9E4A0571962F6021D6156B288B28A
    Malicious:false
    Reputation:low
    Preview:[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .c.h.e.v.r.o.n.a.c.c.e.n.t...g.l.o.x.....C.o.m.p.o.n.e.n.t.:. .W.o.r.d.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.\.S.m.a.r.t.A.r.t. .G.r.a.p.h.i.c.s.........
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:Microsoft OOXML
    Category:dropped
    Size (bytes):4243
    Entropy (8bit):7.824383764848892
    Encrypted:false
    SSDEEP:96:22MQe4zHye8/djzF+JjvtmMkkBpF7e0LTkaf:22De4zHHCvF+nRBDXoaf
    MD5:7BC0A35807CD69C37A949BBD51880FF5
    SHA1:B5870846F44CAD890C6EFF2F272A037DA016F0D8
    SHA-256:BD3A013F50EBF162AAC4CED11928101554C511BD40C2488CF9F5842A375B50CA
    SHA-512:B5B785D693216E38B5AB3F401F414CADACCDCB0DCA4318D88FE1763CD3BAB8B7670F010765296613E8D3363E47092B89357B4F1E3242F156750BE86F5F7E9B8D
    Malicious:false
    Reputation:low
    Preview:PK........NnB;.h......F.......[Content_Types].xmlz.........MN.0...by.b.,.BI...X `...{..O.S...H\.'.XTP..K{.o.....rg..bL...XM.:.v..c.k...}.D....9.....Bb>.+..G.......+(.u}.w.]...v..{.M&.].>`....nB..B0Z@.e.u..R.......-.&#....aR..`.a..|. 1^......&..|..s.A.t..b..A.i7...7.&....bQK$O.......9....V....Wt_PK........TnB;..d.....h......._rels/.rels...J.0.._%.n..)"....<.w.&.4..!...y.|.........|.&3.o.....S..K.T5g.U....g..n.f....T*.hcf...D.V..Ft....d....c2".z.....N.s._2....7.0.V.]P.CO?...`...8....4&......_i..Y.T...Z...g....{-...]..pH..@.8....}tP.)..B>..A...S&......9..@...7........b_.PK........r};5.z..............diagrams/layout1.xml.X.n.8.}.........4.+.(...@......(..J..._.!)..b..v.}.H..zf8...dhM....E..I.H..V.Y.R..2zw5L~....^..]...J_..4.\.\......8..z..2T..".X.l.F#......5....,*....c....r.kR.I.E..,.2...&%..''.qF.R.2.....T;F...W.. ...3...AR.OR.O..J}.w6..<...,.x..x....`g?.t.I.{.I...|X..g.....<BR..^...Q.6..m.kp...ZuX.?.z.YO.g...$.......'.]..I.#...]$/~`${.
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:data
    Category:dropped
    Size (bytes):374
    Entropy (8bit):3.5414485333689694
    Encrypted:false
    SSDEEP:6:fxnxUX8FaE3f8AWqlQqr++lcWimqnKOE3QepmlJ0+3FbnKfZObdADryMluxHZypo:fxnyj9AWI+acgq9GHmD0wbnKYZAH/lMf
    MD5:2F7A8FE4E5046175500AFFA228F99576
    SHA1:8A3DE74981D7917E6CE1198A3C8E35C7E2100F43
    SHA-256:1495B4EC56B371148EA195D790562E5621FDBF163CDD8A5F3C119F8CA3BD2363
    SHA-512:4B8FBB692D91D88B584E46C2F01BDE0C05DCD5D2FF073D83331586FB3D201EACD777D48DB3751E534E22115AA1C3C30392D0D642B3122F21EF10E3EE6EA3BE82
    Malicious:false
    Reputation:low
    Preview:[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .T.e.x.t. .S.i.d.e.b.a.r. .(.A.n.n.u.a.l. .R.e.p.o.r.t. .R.e.d. .a.n.d. .B.l.a.c.k. .d.e.s.i.g.n.)...d.o.c.x.....C.o.m.p.o.n.e.n.t.:. .W.o.r.d.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....E.x.e.c.u.t.a.b.l.e.:. .{.W.D.}.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.....C.o.m.m.a.n.d.:. ./.f. .{.F.i.l.e.P.a.t.h.}.........
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:Microsoft Word 2007+
    Category:dropped
    Size (bytes):47296
    Entropy (8bit):6.42327948041841
    Encrypted:false
    SSDEEP:768:ftjI1BT8N37szq00s7dB2wMVJGHR97/RDU5naXUsT:fJIPTfq0ndB2w1bpsE
    MD5:5A53F55DD7DA8F10A8C0E711F548B335
    SHA1:035E685927DA2FECB88DE9CAF0BECEC88BC118A7
    SHA-256:66501B659614227584DA04B64F44309544355E3582F59DBCA3C9463F67B7E303
    SHA-512:095BD5D1ACA2A0CA3430DE2F005E1D576AC9387E096D32D556E4348F02F4D658D0E22F2FC4AA5BF6C07437E6A6230D2ABF73BBD1A0344D73B864BC4813D60861
    Malicious:false
    Reputation:low
    Preview:PK........<dSA4...T...P.......[Content_Types].xml ...(........................................................................................................................................................................................................................................................................................................................................................................................................................................`.I.%&/m.{.J.J..t...`.$.@........iG#).*..eVe]f.@....{...{...;.N'...?\fd.l..J..!....?~|.?"....|.{.[..e^7E......Gi..V.by..G..|.......U..t.|..mW...m..|.5.j./..^d-.Y_.]e..E~wog...j...v......?..u....c...W..G.4D_.}T,.@...}....R.Z..4k.....Y..mEkLor.f^..O..P...`..^\-o..D....n_d.jq...gwg.t........:?/..}..Vu5...rQ..7..X.Q."./g..o....f....YB......<..w?...ss..e.4Y}}...0.Y...........u3V.o..r...5....7bA..Us.z.`.r(.Y>.&DVy.........6.T...e.|..g.%<...9a.&...7...}3:B.......<...!...:..7w...y..
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:data
    Category:dropped
    Size (bytes):278
    Entropy (8bit):3.5280239200222887
    Encrypted:false
    SSDEEP:6:fxnxUXQAl8ME3QepmlJ0+3FbnKfZObdADryMluxHZypwwyv:fxnyllNGHmD0wbnKYZAH/lMZqiv
    MD5:877A8A960B2140E3A0A2752550959DB9
    SHA1:FBEC17B332CBC42F2F16A1A08767623C7955DF48
    SHA-256:FE07084A41CF7DB58B06D2C0D11BCACB603D6574261D1E7EBADCFF85F39AFB47
    SHA-512:B8B660374EC6504B3B5FCC7DAC63AF30A0C9D24306C36B33B33B23186EC96AEFE958A3851FF3BC57FBA72A1334F633A19C0B8D253BB79AA5E5AFE4A247105889
    Malicious:false
    Reputation:low
    Preview:[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .g.b...x.s.l.....C.o.m.p.o.n.e.n.t.:. .W.o.r.d.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....E.x.e.c.u.t.a.b.l.e.:. .{.W.D.}.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.....C.o.m.m.a.n.d.:. ./.f. .{.F.i.l.e.P.a.t.h.}.........
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
    Category:dropped
    Size (bytes):268317
    Entropy (8bit):5.05419861997223
    Encrypted:false
    SSDEEP:6144:JwprAJLR95vtfb8p4bgWPzDCvCmvQursq7vImej/yQzSS1apSiQhHDOruvoVeMUh:N9
    MD5:51D32EE5BC7AB811041F799652D26E04
    SHA1:412193006AA3EF19E0A57E16ACF86B830993024A
    SHA-256:6230814BF5B2D554397580613E20681752240AB87FD354ECECF188C1EABE0E97
    SHA-512:5FC5D889B0C8E5EF464B76F0C4C9E61BDA59B2D1205AC9417CC74D6E9F989FB73D78B4EB3044A1A1E1F2C00CE1CA1BD6D4D07EEADC4108C7B124867711C31810
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="utf-8"?>..<xsl:stylesheet version="1.0" xmlns:xsl="http://www.w3.org/1999/XSL/Transform" xmlns:msxsl="urn:schemas-microsoft-com:xslt".xmlns:b="http://schemas.openxmlformats.org/officeDocument/2006/bibliography" xmlns:t="http://www.microsoft.com/temp">...<xsl:output method="html" encoding="us-ascii"/>..............<xsl:template match="*" mode="outputHtml2">.....<xsl:apply-templates mode="outputHtml"/>.....</xsl:template>.....<xsl:template name="StringFormatDot">....<xsl:param name="format" />....<xsl:param name="parameters" />.... <xsl:variable name="prop_EndChars">.. <xsl:call-template name="templ_prop_EndChars"/>.. </xsl:variable>.... <xsl:choose>.....<xsl:when test="$format = ''"></xsl:when>.....<xsl:when test="substring($format, 1, 2) = '%%'">......<xsl:text>%</xsl:text>......<xsl:call-template name="StringFormatDot">.......<xsl:with-param name="format" select="substring($format, 3)" />.......<xsl:with-param name="parameters" select="$para
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:data
    Category:dropped
    Size (bytes):332
    Entropy (8bit):3.4871192480632223
    Encrypted:false
    SSDEEP:6:fxnxUXsdDUaw93Ti8ME3QepmlJ0+3FbnKfZObdADryMluxHZypwwyv:fxnyoRw9eNGHmD0wbnKYZAH/lMZqiv
    MD5:333BA58FCE326DEA1E4A9DE67475AA95
    SHA1:F51FAD5385DC08F7D3E11E1165A18F2E8A028C14
    SHA-256:66142D15C7325B98B199AB6EE6F35B7409DE64EBD5C0AB50412D18CBE6894097
    SHA-512:BFEE521A05B72515A8D4F7D13D8810846DC60F1E85C363FFEBD6CACD23AE8D2E664C563FC74700A4ED4E358F378508D25C46CB5BE1CF587E2E278EBC22BB2625
    Malicious:false
    Reputation:low
    Preview:[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .m.l.a.s.e.v.e.n.t.h.e.d.i.t.i.o.n.o.f.f.i.c.e.o.n.l.i.n.e...x.s.l.....C.o.m.p.o.n.e.n.t.:. .W.o.r.d.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....E.x.e.c.u.t.a.b.l.e.:. .{.W.D.}.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.....C.o.m.m.a.n.d.:. ./.f. .{.F.i.l.e.P.a.t.h.}.........
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
    Category:dropped
    Size (bytes):254875
    Entropy (8bit):5.003842588822783
    Encrypted:false
    SSDEEP:6144:MwprAnniNgtfbzbOWPuv7kOMBLitjAUjTQLrYHwR0TnyDkHqV3iPr1zHX5T6SSXj:a
    MD5:377B3E355414466F3E3861BCE1844976
    SHA1:0B639A3880ACA3FD90FA918197A669CC005E2BA4
    SHA-256:4AC5B26C5E66E122DE80243EF621CA3E1142F643DD2AD61B75FF41CFEE3DFFAF
    SHA-512:B050AD52A8161F96CBDC880DD1356186F381B57159F5010489B04528DB798DB955F0C530465AB3ECD5C653586508429D98336D6EB150436F1A53ABEE0697AEB9
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="utf-8"?>......<xsl:stylesheet version="1.0" xmlns:xsl="http://www.w3.org/1999/XSL/Transform" xmlns:msxsl="urn:schemas-microsoft-com:xslt" xmlns:b="http://schemas.openxmlformats.org/officeDocument/2006/bibliography" xmlns:t="http://www.microsoft.com/temp">...<xsl:output method="html" encoding="us-ascii"/>.....<xsl:template match="*" mode="outputHtml2">.....<xsl:apply-templates mode="outputHtml"/>...</xsl:template>.....<xsl:template name="StringFormatDot">....<xsl:param name="format" />....<xsl:param name="parameters" />......<xsl:variable name="prop_EndChars">.....<xsl:call-template name="templ_prop_EndChars"/>....</xsl:variable>......<xsl:choose>.....<xsl:when test="$format = ''"></xsl:when>.....<xsl:when test="substring($format, 1, 2) = '%%'">......<xsl:text>%</xsl:text>......<xsl:call-template name="StringFormatDot">.......<xsl:with-param name="format" select="substring($format, 3)" />.......<xsl:with-param name="parameters" select="$parameters" />......
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:data
    Category:dropped
    Size (bytes):290
    Entropy (8bit):3.5081874837369886
    Encrypted:false
    SSDEEP:6:fxnxUXCOzi8ME3QepmlJ0+3FbnKfZObdADryMluxHZypwwyv:fxnydONGHmD0wbnKYZAH/lMZqiv
    MD5:8D9B02CC69FA40564E6C781A9CC9E626
    SHA1:352469A1ABB8DA1DC550D7E27924E552B0D39204
    SHA-256:1D4483830710EF4A2CC173C3514A9F4B0ACA6C44DB22729B7BE074D18C625BAE
    SHA-512:8B7DB2AB339DD8085104855F847C48970C2DD32ADB0B8EEA134A64C5CC7DE772615F85D057F4357703B65166C8CF0C06F4F6FD3E60FFC80DA3DD34B16D5B1281
    Malicious:false
    Reputation:low
    Preview:[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .g.o.s.t.n.a.m.e...x.s.l.....C.o.m.p.o.n.e.n.t.:. .W.o.r.d.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....E.x.e.c.u.t.a.b.l.e.:. .{.W.D.}.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.....C.o.m.m.a.n.d.:. ./.f. .{.F.i.l.e.P.a.t.h.}.........
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
    Category:dropped
    Size (bytes):255948
    Entropy (8bit):5.103631650117028
    Encrypted:false
    SSDEEP:6144:gwprAm795vtfb8p4bgWPWEtTmtcRCDPThNPFQwB+26RxlsIBkAgRMBHcTCwsHe5a:kW
    MD5:9888A214D362470A6189DEFF775BE139
    SHA1:32B552EB3C73CD7D0D9D924C96B27A86753E0F97
    SHA-256:C64ED5C2A323C00E84272AD3A701CAEBE1DCCEB67231978DE978042F09635FA7
    SHA-512:8A75FC2713003FA40B9730D29C786C76A796F30E6ACE12064468DD2BB4BF97EF26AC43FFE1158AB1DB06FF715D2E6CDE8EF3E8B7C49AA1341603CE122F311073
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="utf-8"?>............<xsl:stylesheet version="1.0" xmlns:xsl="http://www.w3.org/1999/XSL/Transform" xmlns:msxsl="urn:schemas-microsoft-com:xslt".xmlns:b="http://schemas.openxmlformats.org/officeDocument/2006/bibliography" xmlns:t="http://www.microsoft.com/temp">...<xsl:output method="html" encoding="us-ascii"/>..........<xsl:template match="*" mode="outputHtml2">.....<xsl:apply-templates mode="outputHtml"/>.....</xsl:template>.....<xsl:template name="StringFormatDot">....<xsl:param name="format" />....<xsl:param name="parameters" />.... <xsl:variable name="prop_EndChars">.. <xsl:call-template name="templ_prop_EndChars"/>.. </xsl:variable>.... <xsl:choose>.....<xsl:when test="$format = ''"></xsl:when>.....<xsl:when test="substring($format, 1, 2) = '%%'">......<xsl:text>%</xsl:text>......<xsl:call-template name="StringFormatDot">.......<xsl:with-param name="format" select="substring($format, 3)" />.......<xsl:with-param name="parameters" select=
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:Microsoft OOXML
    Category:dropped
    Size (bytes):4026
    Entropy (8bit):7.809492693601857
    Encrypted:false
    SSDEEP:96:VpDCBFLhxaUGm5EWA07yNdKH1FQpy8tnX8Iz3b7TrT502+fPD:VpDYFFRMNU+RtXzLf35t+3D
    MD5:5D9BAD7ADB88CEE98C5203883261ACA1
    SHA1:FBF1647FCF19BCEA6C3CF4365C797338CA282CD2
    SHA-256:8CE600404BB3DB92A51B471D4AB8B166B566C6977C9BB63370718736376E0E2F
    SHA-512:7132923869A3DA2F2A75393959382599D7C4C05CA86B4B27271AB9EA95C7F2E80A16B45057F4FB729C9593F506208DC70AF2A635B90E4D8854AC06C787F6513D
    Malicious:false
    Reputation:low
    Preview:PK........YnB;.h......F.......[Content_Types].xmlz.........MN.0...by.b.,.BI...X `...{..O.S...H\.'.XTP..K{.o.....rg..bL...XM.:.v..c.k...}.D....9.....Bb>.+..G.......+(.u}.w.]...v..{.M&.].>`....nB..B0Z@.e.u..R.......-.&#....aR..`.a..|. 1^......&..|..s.A.t..b..A.i7...7.&....bQK$O.......9....V....Wt_PK........bnB;?.......f......._rels/.rels...J.1.._%..f....m/.,x...&.lt.dV.y.|.."v....q..|......r..F..)..;.T5g.eP..O..Z.^-.8...<.Y....Q.."....*D.%.!9.R&#".'0(.u}).!..l....b..J..rr....P.L.w..0.-......A..w..x.7U...Fu<mT.....^s...F./ ..( .4L..`.....}...O..4.L...+H.z...m..j[].=........oY}.PK........J.L6...m....,.......diagrams/layout1.xml.X.n.8.}N.....PG.............wZ.,.R.%.K...J.H]....y.3..9...O..5."J.1.\.1....Q....z......e.5].)...$b.C)...Gx!...J3..N..H...s....9.~...#..$...W.8..I`|..0xH}......L.|..(V;..1...kF..O=...j...G.X.....T.,d>.w.Xs.......3L.r..er\o..D..^....O.F.{:.>.R'....Y-...B.P.;....X.'c...{x*.M7..><l.1.w..{].46.>.z.E.J.......G......Hd..$..7....E.
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:data
    Category:dropped
    Size (bytes):250
    Entropy (8bit):3.4916022431157345
    Encrypted:false
    SSDEEP:6:fxnxUXsAl8xoE3QepmlJ0+hdADryMluyS6Bkls0Lwv:fxny8A8xoGHmD0+dAH/luWvv
    MD5:1A314B08BB9194A41E3794EF54017811
    SHA1:D1E70DB69CA737101524C75E634BB72F969464FF
    SHA-256:9025DD691FCAD181D5FD5952C7AA3728CD8A2CAF20DEA14930876419BED9B379
    SHA-512:AB29C8674A85711EABAE5F9559E9048FE91A2F51EB12D5A46152A310DE59F759DF8C617DA248798A7C20F60E26FBB1B0FC8DB47C46B098BCD26CF8CE78989ACA
    Malicious:false
    Reputation:low
    Preview:[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .B.r.a.c.k.e.t.L.i.s.t...g.l.o.x.....C.o.m.p.o.n.e.n.t.:. .W.o.r.d.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.\.S.m.a.r.t.A.r.t. .G.r.a.p.h.i.c.s.........
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:data
    Category:dropped
    Size (bytes):258
    Entropy (8bit):3.4692172273306268
    Encrypted:false
    SSDEEP:6:fxnxUXcq9DsoE3QepmlJ0+hdADryMluyS6Bkls0Lwv:fxnysmYoGHmD0+dAH/luWvv
    MD5:C1B36A0547FB75445957A619201143AC
    SHA1:CDB0A18152F57653F1A707D39F3D7FB504E244A7
    SHA-256:4DFF7D1CEF6DD85CC73E1554D705FA6586A1FBD10E4A73EEE44EAABA2D2FFED9
    SHA-512:0923FB41A6DB96C85B44186E861D34C26595E37F30A6F8E554BD3053B99F237D9AC893D47E8B1E9CF36556E86EFF5BE33C015CBBDD31269CDAA68D6947C47F3F
    Malicious:false
    Reputation:low
    Preview:[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .p.i.c.t.u.r.e.o.r.g.c.h.a.r.t...g.l.o.x.....C.o.m.p.o.n.e.n.t.:. .W.o.r.d.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.\.S.m.a.r.t.A.r.t. .G.r.a.p.h.i.c.s.........
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:Microsoft OOXML
    Category:dropped
    Size (bytes):7370
    Entropy (8bit):7.9204386289679745
    Encrypted:false
    SSDEEP:192:fYa+ngK2xG6HvLvoUnXxO+blKO1lt2Zg0AV:fYVn8Y6Hv3XxO+8uQZCV
    MD5:586CEBC1FAC6962F9E36388E5549FFE9
    SHA1:D1EF3BF2443AE75A78E9FDE8DD02C5B3E46F5F2E
    SHA-256:1595C0C027B12FE4C2B506B907C795D14813BBF64A2F3F6F5D71912D7E57BC40
    SHA-512:68DEAE9C59EA98BD597AE67A17F3029BC7EA2F801AC775CF7DECA292069061EA49C9DF5776CB5160B2C24576249DAF817FA463196A04189873CF16EFC4BEDC62
    Malicious:false
    Reputation:low
    Preview:PK........;nB;.h......F.......[Content_Types].xmlz.........MN.0...by.b.,.BI...X `...{..O.S...H\.'.XTP..K{.o.....rg..bL...XM.:.v..c.k...}.D....9.....Bb>.+..G.......+(.u}.w.]...v..{.M&.].>`....nB..B0Z@.e.u..R.......-.&#....aR..`.a..|. 1^......&..|..s.A.t..b..A.i7...7.&....bQK$O.......9....V....Wt_PK........HnB;..I)....j......._rels/.rels...J.@.._e..&6E.i/.,x..Lw'.j........G..\...................)...Y.3)..`...9r{v!......z...#>5.g.WJ%..T..>'m ..K.T.....j6[(:f.)S....C.mk5^.=:...X......C.... I......&5..e..H.1...).P.cw.kjT......C.......=.....}G!7E.y$.(...}b.........b=.<..^.....U..Y..PK.........^5a.2u............diagrams/layout1.xml..ko.8..+x.t.l..J.n.t.Mnw.x. ....B.t$.,.(&i.....(..d.mY......g.../[.<!.{ap>...L...p....G.9z?...._...e..`..%......8....G!..B8.....o...b.......Q.>|.......g..O\B...i.h...0B.}.....z...k...H..t~r.v........7o.E....$....Z.........ZDd..~......>......O.3.SI.Y.".O&I....#."._c.$.r..z.g0`...0...q:...^0.EF...%(.Ao$.#.o6..c'....$%.}
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:data
    Category:dropped
    Size (bytes):302
    Entropy (8bit):3.537169234443227
    Encrypted:false
    SSDEEP:6:fxnxUXfQIUA/e/Wl8ME3QepmlJ0+3FbnKfZObdADryMluxHZypwwyv:fxnyXZ/eulNGHmD0wbnKYZAH/lMZqiv
    MD5:9C00979164E78E3B890E56BE2DF00666
    SHA1:1FA3C439D214C34168ADF0FBA5184477084A0E51
    SHA-256:21CCB63A82F1E6ACD6BAB6875ABBB37001721675455C746B17529EE793382C7B
    SHA-512:54AC8732C2744B60DA744E54D74A2664658E4257A136ABE886FF21585E8322E028D8243579D131EF4E9A0ABDDA70B4540A051C8B8B60D65C3EC0888FD691B9A7
    Malicious:false
    Reputation:low
    Preview:[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .i.s.o.6.9.0.n.m.e.r.i.c.a.l...x.s.l.....C.o.m.p.o.n.e.n.t.:. .W.o.r.d.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....E.x.e.c.u.t.a.b.l.e.:. .{.W.D.}.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.....C.o.m.m.a.n.d.:. ./.f. .{.F.i.l.e.P.a.t.h.}.........
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
    Category:dropped
    Size (bytes):217137
    Entropy (8bit):5.068335381017074
    Encrypted:false
    SSDEEP:6144:AwprA3Z95vtf58pb1WP2DCvCmvQursq7vIme5QyQzSS1apSiQhHDlruvoVeMUwFj:4P
    MD5:3BF8591E1D808BCCAD8EE2B822CC156B
    SHA1:9CC1E5EFD715BD0EAE5AF983FB349BAC7A6D7BA0
    SHA-256:7194396E5C833E6C8710A2E5D114E8E24338C64EC9818D51A929D57A5E4A76C8
    SHA-512:D434A4C15DA3711A5DAAF5F7D0A5E324B4D94A04B3787CA35456BFE423EAC9D11532BB742CDE6E23C16FA9FD203D3636BD198B41C7A51E7D3562D5306D74F757
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="utf-8"?>..<xsl:stylesheet version="1.0" xmlns:xsl="http://www.w3.org/1999/XSL/Transform" xmlns:msxsl="urn:schemas-microsoft-com:xslt".xmlns:b="http://schemas.openxmlformats.org/officeDocument/2006/bibliography" xmlns:t="http://www.microsoft.com/temp">...<xsl:output method="html" encoding="us-ascii"/>..........<xsl:template match="*" mode="outputHtml2">.....<xsl:apply-templates mode="outputHtml"/>.....</xsl:template>.....<xsl:template name="StringFormatDot">....<xsl:param name="format" />....<xsl:param name="parameters" />.... <xsl:variable name="prop_EndChars">.. <xsl:call-template name="templ_prop_EndChars"/>.. </xsl:variable>...... <xsl:choose>.....<xsl:when test="$format = ''"></xsl:when>.....<xsl:when test="substring($format, 1, 2) = '%%'">......<xsl:text>%</xsl:text>......<xsl:call-template name="StringFormatDot">.......<xsl:with-param name="format" select="substring($format, 3)" />.......<xsl:with-param name="parameters" select="$parame
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:data
    Category:dropped
    Size (bytes):314
    Entropy (8bit):3.5230842510951934
    Encrypted:false
    SSDEEP:6:fxnxUXJuJaw93Ti8ME3QepmlJ0+3FbnKfZObdADryMluxHZypwwyv:fxnyZuUw9eNGHmD0wbnKYZAH/lMZqiv
    MD5:F25AC64EC63FA98D9E37782E2E49D6E6
    SHA1:97DD9CFA4A22F5B87F2B53EFA37332A9EF218204
    SHA-256:834046A829D1EA836131B470884905856DBF2C3C136C98ADEEFA0F206F38F8AB
    SHA-512:A0387239CDE98BCDE1668B582B046619C3B3505F9440343DAD22B1B7B9E05F3B74F2AE29E591EC37B6570A0C0E5FE571442873594B0684DDCCB4F6A1B5E10B1F
    Malicious:false
    Reputation:low
    Preview:[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .i.e.e.e.2.0.0.6.o.f.f.i.c.e.o.n.l.i.n.e...x.s.l.....C.o.m.p.o.n.e.n.t.:. .W.o.r.d.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....E.x.e.c.u.t.a.b.l.e.:. .{.W.D.}.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.....C.o.m.m.a.n.d.:. ./.f. .{.F.i.l.e.P.a.t.h.}.........
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:XML 1.0 document, Unicode text, UTF-8 text, with CRLF line terminators
    Category:dropped
    Size (bytes):294178
    Entropy (8bit):4.977758311135714
    Encrypted:false
    SSDEEP:6144:ydkJ3yU0orh0SCLVXyMFsoiOjWIm4vW2uo4hfhf7v3uH4NYYP4BpBaZTTSSamEUD:b
    MD5:0C9731C90DD24ED5CA6AE283741078D0
    SHA1:BDD3D7E5B0DE9240805EA53EF2EB784A4A121064
    SHA-256:ABCE25D1EB3E70742EC278F35E4157EDB1D457A7F9D002AC658AAA6EA4E4DCDF
    SHA-512:A39E6201D6B34F37C686D9BD144DDD38AE212EDA26E3B81B06F1776891A90D84B65F2ABC5B8F546A7EFF3A62D35E432AF0254E2F5BFE4AA3E0CF9530D25949C0
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="utf-8"?>....<xsl:stylesheet version="1.0" xmlns:xsl="http://www.w3.org/1999/XSL/Transform" xmlns:msxsl="urn:schemas-microsoft-com:xslt"......xmlns:b="http://schemas.openxmlformats.org/officeDocument/2006/bibliography" xmlns:t="http://www.microsoft.com/temp">.....<xsl:output method="html" encoding="us-ascii"/>.....<xsl:template match="/">....<xsl:call-template name="Start"/>...</xsl:template>.....<xsl:template name="Start">....<xsl:choose>.....<xsl:when test="b:Version">......<xsl:text>2010.2.02</xsl:text>.....</xsl:when>.......<xsl:when test="b:XslVersion">......<xsl:text>2006</xsl:text>.....</xsl:when>.. <xsl:when test="b:StyleNameLocalized">.. <xsl:choose>.. <xsl:when test="b:StyleNameLocalized/b:Lcid='1033'">.. <xsl:text>IEEE</xsl:text>.. </xsl:when>.. <xsl:when test="b:StyleNameLocalized/b:Lcid='1025'">.. <xsl:text>IEEE</xsl:text>.. </xsl:when>.. <xsl:when test="b:StyleNameL
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:Zip archive data, at least v2.0 to extract, compression method=deflate
    Category:dropped
    Size (bytes):16806
    Entropy (8bit):7.9519793977093505
    Encrypted:false
    SSDEEP:384:eSMjhqgJDGwOzHR3iCpK+QdLdfufFJ9aDn9LjDMVAwHknbz7OW:eSkhqglGwERSAHQdLhDn9AKokv7H
    MD5:950F3AB11CB67CC651082FEBE523AF63
    SHA1:418DE03AD2EF93D0BD29C3D7045E94D3771DACB4
    SHA-256:9C5E4D8966A0B30A22D92DB1DA2F0DBF06AC2EA75E7BB8501777095EA0196974
    SHA-512:D74BF52A58B0C0327DB9DDCAD739794020F00B3FA2DE2B44DAAEC9C1459ECAF3639A5D761BBBC6BDF735848C4FD7E124D13B23964B0055BB5AA4F6AFE76DFE00
    Malicious:false
    Reputation:low
    Preview:PK.........T.>................[Content_Types].xmlz.........=N.1...b.Eko(.B....(.Pp..=.u.?.....#q..ND.!$.J{.o....G..[Cv.....+.R.Nx..........0."u..S...$&.....Je..B..x......m......M^z....f....|...N..Q..z.!.- .2.9y.i.8j...........0.AE..p.s~@../jw.#8.I.#....4.~Cl.:#h..f.PU.s.~........(.)F..Y......^x..PK.........T.>...V....L......._rels/.rels...J.@.._e..]AD.....x....3.t..T.w.\ZpA<x......v..'....z.........Y..[...<..2.TT....Q$.!.=.....&C....b".F.q.7...X3...7.8.N.}.. ?..8...#..,.L.3.#e...wZpZ.]S..:....t.....{..6.7.|..,dH.e..K 7-}.~.v...5.......b..PK........Ul.<..<"I5...&......diagrams/layout1.xml.}.r.I..s........~Y.f.gzfv......E."w.K..J5m.e...4.0..Q... A.!...%...<...3.......O.......t~.u{...5.G......?,.........N......L......~.:....^,..r=./~7_..8............o.y......oo.3.f........f.......r.7../....qrr.v9.......,?..._O.....?9.O~]..zv.I'.W..........;..\..~....../........?~..n.....\}pt.........b,~...;>.=;>:..u.....?.......2]..]....i......9..<.p..4D..
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:data
    Category:dropped
    Size (bytes):254
    Entropy (8bit):3.4720677950594836
    Encrypted:false
    SSDEEP:6:fxnxUXOu9+MlWlk2E3QepmlJ0+hdADryMluyS6Bkls0Lwv:fxnycMlWlzGHmD0+dAH/luWvv
    MD5:D04EC08EFE18D1611BDB9A5EC0CC00B1
    SHA1:668FF6DFE64D5306220341FC2C1353199D122932
    SHA-256:FA60500F951AFAF8FFDB6D1828456D60004AE1558E8E1364ADC6ECB59F5450C9
    SHA-512:97EBCCAF64FA33238B7CFC0A6D853EFB050D877E21EE87A78E17698F0BB38382FCE7F6C4D97D550276BD6B133D3099ECAB9CFCD739F31BFE545F4930D896EEC3
    Malicious:false
    Reputation:low
    Preview:[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .C.i.r.c.l.e.P.r.o.c.e.s.s...g.l.o.x.....C.o.m.p.o.n.e.n.t.:. .W.o.r.d.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.\.S.m.a.r.t.A.r.t. .G.r.a.p.h.i.c.s.........
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:data
    Category:dropped
    Size (bytes):280
    Entropy (8bit):3.484503080761839
    Encrypted:false
    SSDEEP:6:fxnxUXGdQ1MecJZMlWlk2E3QepmlJ0+hdADryMluyS6Bkls0Lwv:fxny2dQ98MlWlzGHmD0+dAH/luWvv
    MD5:1309D172F10DD53911779C89A06BBF65
    SHA1:274351A1059868E9DEB53ADF01209E6BFBDFADFB
    SHA-256:C190F9E7D00E053596C3477455D1639C337C0BE01012C0D4F12DFCB432F5EC56
    SHA-512:31B38AD2D1FFF93E03BF707811F3A18AD08192F906E36178457306DDAB0C3D8D044C69DE575ECE6A4EE584800F827FB3C769F98EA650F1C208FEE84177070339
    Malicious:false
    Reputation:low
    Preview:[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .I.n.t.e.r.c.o.n.n.e.c.t.e.d.B.l.o.c.k.P.r.o.c.e.s.s...g.l.o.x.....C.o.m.p.o.n.e.n.t.:. .W.o.r.d.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.\.S.m.a.r.t.A.r.t. .G.r.a.p.h.i.c.s.........
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:Zip archive data, at least v2.0 to extract, compression method=deflate
    Category:dropped
    Size (bytes):9191
    Entropy (8bit):7.93263830735235
    Encrypted:false
    SSDEEP:192:oeAMExvPJMg+yE+AfJLi3+Xoj7F3sPgMG61J88eDhFWT7hFNsdJtnLYJ7tSh:v2d+hnfJLi3+4ja4WqhFWT7FsdHMA
    MD5:08D3A25DD65E5E0D36ADC602AE68C77D
    SHA1:F23B6DDB3DA0015B1D8877796F7001CABA25EA64
    SHA-256:58B45B9DBA959F40294DA2A54270F145644E810290F71260B90F0A3A9FCDEBC1
    SHA-512:77D24C272D67946A3413D0BEA700A7519B4981D3B4D8486A655305546CE6133456321EE94FD71008CBFD678433EA1C834CFC147179B31899A77D755008FCE489
    Malicious:false
    Reputation:low
    Preview:PK.........]w>....<...5.......diagrams/layout1.xmlz........].r.F.}......1w`.J..'.......w..Dn. d....~........pw...O.......s...?...p7.t>e.r<.]u.e..d..|8..\uo.......K...._.Y..E6.|..y;........y.*/:o./...:[.o.+/.....?.....Z.?..s..d}...S.`...b.^o9.e.ty9_d...y>M.....7...e....."....<.v.u...e:].N.t....a....0..}..bQ.Y..>.~..~...U.|..Ev.....N...bw....{...O..Y.Y.&........A.8Ik...N.Z.P.[}t........|m...E..v..,..6........_?..."..K<.=x....$..%@.e..%....$=F..G..e........<F..G51..;......=...e.e.q..d......A...&9'.N.\%.=N.Z.9.s......y.4.Q.c......|8.......Eg.:.ky.z.h.......).O...mz...N.wy.m...yv....~8.?Lg..o.l.y:.....z.i..j.irxI.w...r.......|.=....s};.\u.{t;i~S.......U7..mw...<.vO...M.o...W.U.....}.`V<|..%....l..`>]..".].I.i.N..Z..~Lt.........}?..E~:..>$......x...%.........N....'C.m.=...w.=.Y...+'M.].2 >.]_~...'.?...:....z.O..Y......6..5...sj?.....).B..>.3...G...p.9.K!..[H..1$v../...E V..?`....+[...C......h..!.QI5....<.>...A.d.......
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:data
    Category:dropped
    Size (bytes):332
    Entropy (8bit):3.547857457374301
    Encrypted:false
    SSDEEP:6:fxnxUXSpGLMeKlPaw93Ti8ME3QepmlJ0+3FbnKfZObdADryMluxHZypwwyv:fxnyipTIw9eNGHmD0wbnKYZAH/lMZqiv
    MD5:4EC6724CBBA516CF202A6BD17226D02C
    SHA1:E412C574D567F0BA68B4A31EDB46A6AB3546EA95
    SHA-256:18E408155A2C2A24D91CD45E065927FFDA726356AAB115D290A3C1D0B7100402
    SHA-512:DE45011A084AB94BF5B27F2EC274D310CF68DF9FB082E11726E08EB89D5D691EA086C9E0298E16AE7AE4B23753E5916F69F78AAD82F4627FC6F80A6A43D163DB
    Malicious:false
    Reputation:low
    Preview:[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .h.a.r.v.a.r.d.a.n.g.l.i.a.2.0.0.8.o.f.f.i.c.e.o.n.l.i.n.e...x.s.l.....C.o.m.p.o.n.e.n.t.:. .W.o.r.d.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....E.x.e.c.u.t.a.b.l.e.:. .{.W.D.}.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.....C.o.m.m.a.n.d.:. ./.f. .{.F.i.l.e.P.a.t.h.}.........
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:XML 1.0 document, Unicode text, UTF-8 text, with CRLF line terminators
    Category:dropped
    Size (bytes):284415
    Entropy (8bit):5.00549404077789
    Encrypted:false
    SSDEEP:6144:N9G5o7Fv0ZcxrStAtXWty8zRLYBQd8itHiYYPVJHMSo27hlwNR57johqBXlwNR2b:y
    MD5:33A829B4893044E1851725F4DAF20271
    SHA1:DAC368749004C255FB0777E79F6E4426E12E5EC8
    SHA-256:C40451CADF8944A9625DD690624EA1BA19CECB825A67081E8144AD5526116924
    SHA-512:41C1F65E818C2757E1A37F5255E98F6EDEAC4214F9D189AD09C6F7A51F036768C1A03D6CFD5845A42C455EE189D13BB795673ACE3B50F3E1D77DAFF400F4D708
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="utf-8"?>....<xsl:stylesheet version="1.0" xmlns:xsl="http://www.w3.org/1999/XSL/Transform" xmlns:msxsl="urn:schemas-microsoft-com:xslt"......xmlns:b="http://schemas.openxmlformats.org/officeDocument/2006/bibliography" xmlns:t="http://www.microsoft.com/temp">.....<xsl:output method="html" encoding="us-ascii"/>.....<xsl:template match="/">....<xsl:call-template name="Start"/>...</xsl:template>.....<xsl:template name="Start">....<xsl:choose>.....<xsl:when test="b:Version">......<xsl:text>2010.2.02</xsl:text>.....</xsl:when>.......<xsl:when test="b:XslVersion">......<xsl:text>2008</xsl:text>.....</xsl:when>.... <xsl:when test="b:StyleNameLocalized">.. <xsl:choose>.. <xsl:when test="b:StyleNameLocalized/b:Lcid='1033'">.. <xsl:text>Harvard - Anglia</xsl:text>.. </xsl:when>.. <xsl:when test="b:StyleNameLocalized/b:Lcid='1025'">.. <xsl:text>Harvard - Anglia</xsl:text>.. </xsl:when>.. <x
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:data
    Category:dropped
    Size (bytes):254
    Entropy (8bit):3.4845992218379616
    Encrypted:false
    SSDEEP:6:fxnxUXQFoElh/lE3QepmlJ0+hdADryMluyS6Bkls0Lwv:fxny8lLGHmD0+dAH/luWvv
    MD5:E8B30D1070779CC14FBE93C8F5CF65BE
    SHA1:9C87F7BC66CF55634AB3F070064AAF8CC977CD05
    SHA-256:2E90434BE1F6DCEA9257D42C331CD9A8D06B848859FD4742A15612B2CA6EFACB
    SHA-512:C0D5363B43D45751192EF06C4EC3C896A161BB11DBFF1FC2E598D28C644824413C78AE3A68027F7E622AF0D709BE0FA893A3A3B4909084DF1ED9A8C1B8267FCA
    Malicious:false
    Reputation:low
    Preview:[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .H.e.x.a.g.o.n.R.a.d.i.a.l...g.l.o.x.....C.o.m.p.o.n.e.n.t.:. .W.o.r.d.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.\.S.m.a.r.t.A.r.t. .G.r.a.p.h.i.c.s.........
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:Microsoft OOXML
    Category:dropped
    Size (bytes):6024
    Entropy (8bit):7.886254023824049
    Encrypted:false
    SSDEEP:96:bGa2onnLYHTSSxpHVTSH1bywZKmpRqiUtFvS9xrPooBpni6eDa16MUELHsrKjRBA:SJonLYzSSr1TuZNwtFZKpiiyrKXuCUd
    MD5:20621E61A4C5B0FFEEC98FFB2B3BCD31
    SHA1:4970C22A410DCB26D1BD83B60846EF6BEE1EF7C4
    SHA-256:223EA2602C3E95840232CACC30F63AA5B050FA360543C904F04575253034E6D7
    SHA-512:BDF3A8E3D6EE87D8ADE0767918603B8D238CAE8A2DD0C0F0BF007E89E057C7D1604EB3CCAF0E1BA54419C045FC6380ECBDD070F1BB235C44865F1863A8FA7EEA
    Malicious:false
    Reputation:low
    Preview:PK.........T.>................[Content_Types].xmlz.........=N.1...b.Eko(.B....(.Pp..=.u.?.....#q..ND.!$.J{.o....G..[Cv.....+.R.Nx..........0."u..S...$&.....Je..B..x......m......M^z....f....|...N..Q..z.!.- .2.9y.i.8j...........0.AE..p.s~@../jw.#8.I.#....4.~Cl.:#h..f.PU.s.~........(.)F..Y......^x..PK.........T.>...V....L......._rels/.rels...J.@.._e..]AD.....x....3.t..T.w.\ZpA<x......v..'....z.........Y..[...<..2.TT....Q$.!.=.....&C....b".F.q.7...X3...7.8.N.}.. ?..8...#..,.L.3.#e...wZpZ.]S..:....t.....{..6.7.|..,dH.e..K 7-}.~.v...5.......b..PK........2..<..]#.....'......diagrams/layout1.xml.].r.8...V.;0.;..aO........{.....V..3].d{..............\. .#.t... ........x<...@7o.]..7.N..@.NF..../....S.../.xC..U...<..Q.=...|..v.....cQ..Y=.....i`.. ..?.;...Go....x.O.$....7s..0..qg....|..r..l.w.a..p.3.Em7v...N............3..7...N.\\..f...9...U$..7...k.C..M.@\.s....G/..?...I...t.Yos...p..z...6.lnqi.6..<..1qg+......#]....|C/N..K\}.....#..".
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:data
    Category:dropped
    Size (bytes):290
    Entropy (8bit):3.5161159456784024
    Encrypted:false
    SSDEEP:6:fxnxUX+l8ME3QepmlJ0+3FbnKfZObdADryMluxHZypwwyv:fxnyulNGHmD0wbnKYZAH/lMZqiv
    MD5:C15EB3F4306EBF75D1E7C3C9382DEECC
    SHA1:A3F9684794FFD59151A80F97770D4A79F1D030A6
    SHA-256:23C262DF3AEACB125E88C8FFB7DBF56FD23F66E0D476AFD842A68DDE69658C7F
    SHA-512:ACDF7D69A815C42223FD6300179A991A379F7166EFAABEE41A3995FB2030CD41D8BCD46B566B56D1DFBAE8557AFA1D9FD55143900A506FA733DE9DA5D73389D6
    Malicious:false
    Reputation:low
    Preview:[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .t.u.r.a.b.i.a.n...x.s.l.....C.o.m.p.o.n.e.n.t.:. .W.o.r.d.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....E.x.e.c.u.t.a.b.l.e.:. .{.W.D.}.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.....C.o.m.m.a.n.d.:. ./.f. .{.F.i.l.e.P.a.t.h.}.........
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
    Category:dropped
    Size (bytes):344303
    Entropy (8bit):5.023195898304535
    Encrypted:false
    SSDEEP:6144:UwprANnsqvtfL/vF/bkWPRMMv7EOMBPitjASjTQQr7IwR0TnyDk1b78plJwf33iD:6
    MD5:F079EC5E2CCB9CD4529673BCDFB90486
    SHA1:FBA6696E6FA918F52997193168867DD3AEBE1AD6
    SHA-256:3B651258F4D0EE1BFFC7FB189250DED1B920475D1682370D6685769E3A9346DB
    SHA-512:4FFFA59863F94B3778F321DA16C43B92A3053E024BDD8C5317077EA1ECC7B09F67ECE3C377DB693F3432BF1E2D947EC5BF8E88E19157ED08632537D8437C87D6
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="utf-8"?>......<xsl:stylesheet version="1.0" xmlns:xsl="http://www.w3.org/1999/XSL/Transform" xmlns:msxsl="urn:schemas-microsoft-com:xslt" xmlns:b="http://schemas.openxmlformats.org/officeDocument/2006/bibliography" xmlns:t="http://www.microsoft.com/temp">...<xsl:output method="html" encoding="us-ascii"/>............<xsl:template match="*" mode="outputHtml2">.....<xsl:apply-templates mode="outputHtml"/>.....</xsl:template>.....<xsl:template name="StringFormatDot">....<xsl:param name="format" />....<xsl:param name="parameters" />.... <xsl:variable name="prop_EndChars">.. <xsl:call-template name="templ_prop_EndChars"/>.. </xsl:variable>.... <xsl:choose>.....<xsl:when test="$format = ''"></xsl:when>.....<xsl:when test="substring($format, 1, 2) = '%%'">......<xsl:text>%</xsl:text>......<xsl:call-template name="StringFormatDot">.......<xsl:with-param name="format" select="substring($format, 3)" />.......<xsl:with-param name="parameters" select="$pa
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
    Category:dropped
    Size (bytes):333258
    Entropy (8bit):4.654450340871081
    Encrypted:false
    SSDEEP:6144:ybW83Zb181+MKHZR5D7H3hgtfL/8mIDbEhPv9FHSVsioWUyGYmwxAw+GIfnUNv5J:i
    MD5:5632C4A81D2193986ACD29EADF1A2177
    SHA1:E8FF4FDFEB0002786FCE1CF8F3D25F8E9631E346
    SHA-256:06DE709513D7976690B3DD8F5FDF1E59CF456A2DFBA952B97EACC72FE47B238B
    SHA-512:676CE1957A374E0F36634AA9CFFBCFB1E1BEFE1B31EE876483B10763EA9B2D703F2F3782B642A5D7D0945C5149B572751EBD9ABB47982864834EF61E3427C796
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="utf-8"?>....<xsl:stylesheet version="1.0" xmlns:xsl="http://www.w3.org/1999/XSL/Transform" xmlns:msxsl="urn:schemas-microsoft-com:xslt".xmlns:b="http://schemas.openxmlformats.org/officeDocument/2006/bibliography" xmlns:t="http://www.microsoft.com/temp">.. <xsl:output method="html" encoding="us-ascii"/>.... <xsl:template match="*" mode="outputHtml2">.. <xsl:apply-templates mode="outputHtml"/>.. </xsl:template>.... <xsl:template name="StringFormatDot">.. <xsl:param name="format" />.. <xsl:param name="parameters" />.... <xsl:variable name="prop_EndChars">.. <xsl:call-template name="templ_prop_EndChars"/>.. </xsl:variable>.... <xsl:choose>.. <xsl:when test="$format = ''"></xsl:when>.. <xsl:when test="substring($format, 1, 2) = '%%'">.. <xsl:text>%</xsl:text>.. <xsl:call-template name="StringFormatDot">.. <xsl:with-param name="format" select="substring($format, 3)" />.. <xsl:with-param name=
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:data
    Category:dropped
    Size (bytes):328
    Entropy (8bit):3.541819892045459
    Encrypted:false
    SSDEEP:6:fxnxUXuqRDA5McaQVTi8ME3QepmlJ0+3FbnKfZObdADryMluxHZypwwyv:fxny+AASZQoNGHmD0wbnKYZAH/lMZqiv
    MD5:C3216C3FC73A4B3FFFE7ED67153AB7B5
    SHA1:F20E4D33BABE978BE6A6925964C57D6E6EF1A92E
    SHA-256:7CF1D6A4F0BE5E6184F59BFB1304509F38E480B59A3B091DBDC43B052D2137CB
    SHA-512:D3B78BE6E7633FF943F5E34063B5EFA4AF239CD49F437227FC7575F6CC65C497B7D6F6A979EA065065BEAF257CB368560B5462542692286052B5C7E5C01755BC
    Malicious:false
    Reputation:low
    Preview:[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .A.P.A.S.i.x.t.h.E.d.i.t.i.o.n.O.f.f.i.c.e.O.n.l.i.n.e...x.s.l.....C.o.m.p.o.n.e.n.t.:. .W.o.r.d.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....E.x.e.c.u.t.a.b.l.e.:. .{.W.D.}.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.....C.o.m.m.a.n.d.:. ./.f. .{.F.i.l.e.P.a.t.h.}.........
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:data
    Category:dropped
    Size (bytes):264
    Entropy (8bit):3.4866056878458096
    Encrypted:false
    SSDEEP:6:fxnxUX0XrZUloE3QepmlJ0+hdADryMluyS6Bkls0Lwv:fxnyEXWloGHmD0+dAH/luWvv
    MD5:6C489D45F3B56845E68BE07EA804C698
    SHA1:C4C9012C0159770CB882870D4C92C307126CEC3F
    SHA-256:3FE447260CDCDEE287B8D01CF5F9F53738BFD6AAEC9FB9787F2826F8DEF1CA45
    SHA-512:D1355C48A09E7317773E4F1613C4613B7EA42D21F5A6692031D288D69D47B19E8F4D5A29AFD8B751B353FC7DE865EAE7CFE3F0BEC05F33DDF79526D64A29EB18
    Malicious:false
    Reputation:low
    Preview:[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .T.h.e.m.e.P.i.c.t.u.r.e.A.c.c.e.n.t...g.l.o.x.....C.o.m.p.o.n.e.n.t.:. .W.o.r.d.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.\.S.m.a.r.t.A.r.t. .G.r.a.p.h.i.c.s.........
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:Zip archive data, at least v2.0 to extract, compression method=deflate
    Category:dropped
    Size (bytes):6448
    Entropy (8bit):7.897260397307811
    Encrypted:false
    SSDEEP:192:tgaoRbo1sMjb0NiJ85oPtqcS+yaXWoa8XBzdJYnLYFtWT7:LR1sk+i4o1qc1yaukzd8MK
    MD5:42A840DC06727E42D42C352703EC72AA
    SHA1:21AAAF517AFB76BF1AF4E06134786B1716241D29
    SHA-256:02CCE7D526F844F70093AC41731D1A1E9B040905DCBA63BA8BFFC0DBD4D3A7A7
    SHA-512:8886BFD240D070237317352DEB3D46C6B07E392EBD57730B1DED016BD8740E75B9965F7A3FCD43796864F32AAE0BE911AB1A670E9CCC70E0774F64B1BDA93488
    Malicious:false
    Reputation:low
    Preview:PK.........k.>........'......diagrams/layout1.xmlz........].r.8.}.V.?p.n....g*5..JUn.....(SU......T.l.......X.d."m."..S....F..P.........-..<Y^..=..e.L....m>.pG.....M~...+\....u}o...".Yn}Y.".-r......0...'/........{........F.~.M8.d....(.....q.D.....4\.;.D,.\.)n.S....Z.cl.|<..7._.dk..7..E.......kS...d.....i.....noX...o.W#9..}.^..I0....G.......+.K.[i.O.|G..8=.;.8.8.8.8.....{..-..^.y..[.....`...0..f...Q<^~..*.l....{...pA.z.$.$R.../...E.(..Q.(V.E_ ......X]Q..Y9.......>...8......l..--.ug.......I.;..].u.b.3Lv:.d.%H..l<...V...$.M..A>...^M./.[..I....o~,.U. .$d\..?........O.;..^M..O...A.$Yx..|f.n...H.=.|!cG)dd%..(... ..Xe......2B."i...n....P.R..E?... Y.I6...7n..Xs..J..K..'..JaU..d..|.(y.a.....d......D.Dr...._.._..m..Yu..6.o.\......&.m....wy...4k?..~........f....0.. \...}iS.i..R....q-#_..g........{Z.u.V.r(....j.I...,R..f.=.n.[.'..L'd.n C.0.I.....RpaV........c.k..NR....)B^k...d.i...d0.E. ^..G.']....x.c.>'..p...y.ny.P.x6..%.J\.....De.B\.
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:data
    Category:dropped
    Size (bytes):256
    Entropy (8bit):3.464918006641019
    Encrypted:false
    SSDEEP:6:fxnxUXR+EqRGRnRE3QepmlJ0+3FbnKfZObdADxp1RDWlVwv:fxnyB+5RmRGHmD0wbnKYZAH+Vwv
    MD5:93149E194021B37162FD86684ED22401
    SHA1:1B31CAEBE1BBFA529092BE834D3B4AD315A6F8F1
    SHA-256:50BE99A154A6F632D49B04FCEE6BCA4D6B3B4B7C1377A31CE9FB45C462D697B2
    SHA-512:410A7295D470EC85015720B2B4AC592A472ED70A04103D200FA6874BEA6A423AF24766E98E5ACAA3A1DBC32C44E8790E25D4611CD6C0DBFFFE8219D53F33ACA7
    Malicious:false
    Reputation:low
    Preview:[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .E.q.u.a.t.i.o.n.s...d.o.t.x.....C.o.m.p.o.n.e.n.t.:. .W.o.r.d.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....E.x.e.c.u.t.a.b.l.e.:. .{.W.D.}.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.W.D. .D.o.c.u.m.e.n.t. .P.a.r.t.s.}.........
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:Microsoft Word 2007+
    Category:dropped
    Size (bytes):51826
    Entropy (8bit):5.541375256745271
    Encrypted:false
    SSDEEP:384:erH5dYPCA4t3aEFGiSUDtYfEbi5Ry/AT7/6tHODaFlDSomurYNfT4A0VIwWNS89u:Q6Cbh9tENyWdaFUSYNfZS89/3qtEu
    MD5:2AB22AC99ACFA8A82742E774323C0DBD
    SHA1:790F8B56DF79641E83A16E443A75A66E6AA2F244
    SHA-256:BC9D45D0419A08840093B0BF4DCF96264C02DFE5BD295CD9B53722E1DA02929D
    SHA-512:E5715C0ECF35CE250968BD6DE5744D28A9F57D20FD6866E2AF0B2D8C8F80FEDC741D48F554397D61C5E702DA896BD33EED92D778DBAC71E2E98DCFB0912DE07B
    Malicious:false
    Reputation:low
    Preview:PK.........R.@c}LN4...........[Content_Types].xml ...(.....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................`.I.%&/m.{.J.J..t...`.$.@........iG#).*..eVe]f.@....{...{...;.N'...?\fd.l..J..!....?~|.?"....|.{.[..e^7E......Gi..V.by..G..|.......U..t.|..mW...m..|.5.j./..^d-.Y_.]e..E~wog...j...v......?..u....c.....D....>.V...f-}..r9....=..Mn..U..5.(.....a...E..b....*..w.$...,O_fu."[P..WU=.;.....5..wdt..y1.......i.44-.r....;./.biG.Cd.n.j.{/......V....c..^^.E.H?H.........B.........<...Ae.l.]..{....mK......B....
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:data
    Category:dropped
    Size (bytes):260
    Entropy (8bit):3.4895685222798054
    Encrypted:false
    SSDEEP:6:fxnxUX4cPBl4xoE3QepmlJ0+hdADryMluyS6Bkls0Lwv:fxnyPl4xoGHmD0+dAH/luWvv
    MD5:63E8B0621B5DEFE1EF17F02EFBFC2436
    SHA1:2D02AD4FD9BF89F453683B7D2B3557BC1EEEE953
    SHA-256:9243D99795DCDAD26FA857CB2740E58E3ED581E3FAEF0CB3781CBCD25FB4EE06
    SHA-512:A27CDA84DF5AD906C9A60152F166E7BD517266CAA447195E6435997280104CBF83037F7B05AE9D4617323895DCA471117D8C150E32A3855156CB156E15FA5864
    Malicious:false
    Reputation:low
    Preview:[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .V.a.r.y.i.n.g.W.i.d.t.h.L.i.s.t...g.l.o.x.....C.o.m.p.o.n.e.n.t.:. .W.o.r.d.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.\.S.m.a.r.t.A.r.t. .G.r.a.p.h.i.c.s.........
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:Microsoft OOXML
    Category:dropped
    Size (bytes):3075
    Entropy (8bit):7.716021191059687
    Encrypted:false
    SSDEEP:48:96yn4sOBoygpySCCxwKsZCB2oLEIK+aQpUNLRQWtmMamIZxAwCC2QnyODhVOzP4:l0vCxJsZQ2ofpKvtmMdIZxAwJyODhVOE
    MD5:67766FF48AF205B771B53AA2FA82B4F4
    SHA1:0964F8B9DC737E954E16984A585BDC37CE143D84
    SHA-256:160D05B4CB42E1200B859A2DE00770A5C9EBC736B70034AFC832A475372A1667
    SHA-512:AC28B0B4A9178E9B424E5893870913D80F4EE03D595F587AA1D3ACC68194153BAFC29436ADFD6EA8992F0B00D17A43CFB42C529829090AF32C3BE591BD41776D
    Malicious:false
    Reputation:low
    Preview:PK.........nB;.h......F.......[Content_Types].xmlz.........MN.0...by.b.,.BI...X `...{..O.S...H\.'.XTP..K{.o.....rg..bL...XM.:.v..c.k...}.D....9.....Bb>.+..G.......+(.u}.w.]...v..{.M&.].>`....nB..B0Z@.e.u..R.......-.&#....aR..`.a..|. 1^......&..|..s.A.t..b..A.i7...7.&....bQK$O.......9....V....Wt_PK.........nB;O.......k......._rels/.rels...J.@.._e..4...i/.,x..Lw'....v'.<....WpQ..,......7?....u.y..;bL../..3t.+.t.G....Y.v8.eG.MH,....(\..d..R....t>Z.<F-..G.(..\.x...l?..M..:#........2.#.[..H7..#g{...._j...(.....q......;.5'..Nt..."...A.h........>....\.'...L..D..DU<.....C.TKu.5Tu....bV..;PK.........C26.b..............diagrams/layout1.xml.T.n. .}N....).je./m.+u....`{..0P......p..U}c.9g..3....=h.(.."..D-.&....~.....y..I...(r.aJ.Y..e..;.YH...P.{b......hz.-..>k.i5..z>.l...f...c..Y...7.ND...=.%..1...Y.-.o.=)(1g.{.".E.>2.=...]Y..r0.Q...e.E.QKal,.....{f...r..9-.mH..C..\.w....c.4.JUbx.p Q...R......_...G.F...uPR...|um.+g..?..C..gT...7.0.8l$.*.=qx.......-8..8.
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:data
    Category:dropped
    Size (bytes):238
    Entropy (8bit):3.472155835869843
    Encrypted:false
    SSDEEP:6:fxnxUXGE2E3QepmlJ0+hdADryMluyS6Bkls0Lwv:fxny4GHmD0+dAH/luWvv
    MD5:2240CF2315F2EB448CEA6E9CE21B5AC5
    SHA1:46332668E2169E86760CBD975FF6FA9DB5274F43
    SHA-256:0F7D0BD5A8CED523CFF4F99D7854C0EE007F5793FA9E1BA1CD933B0894BFBD0D
    SHA-512:10BA73FF861112590BF135F4B337346F9D4ACEB10798E15DC5976671E345BC29AC8527C6052FEC86AA7058E06D1E49052E49D7BCF24A01DB259B5902DB091182
    Malicious:false
    Reputation:low
    Preview:[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .r.i.n.g.s...g.l.o.x.....C.o.m.p.o.n.e.n.t.:. .W.o.r.d.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.\.S.m.a.r.t.A.r.t. .G.r.a.p.h.i.c.s.........
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:Microsoft OOXML
    Category:dropped
    Size (bytes):5151
    Entropy (8bit):7.859615916913808
    Encrypted:false
    SSDEEP:96:WkV3UHhcZDEteEJqeSGzpG43GUR8m8b6dDLiCTfjKPnD6H5RhfuDKNtxx3+7tDLp:Wq3UBc9EJqIpGgD5dDL1DjKvDKhfnNti
    MD5:6C24ED9C7C868DB0D55492BB126EAFF8
    SHA1:C6D96D4D298573B70CF5C714151CF87532535888
    SHA-256:48AF17267AD75C142EFA7AB7525CA48FAB579592339FB93E92C4C4DA577D4C9F
    SHA-512:A3E9DC48C04DC8571289F57AE790CA4E6934FBEA4FDDC20CB780F7EA469FE1FC1D480A1DBB04D15301EF061DA5700FF0A793EB67D2811C525FEF618B997BCABD
    Malicious:false
    Reputation:low
    Preview:PK.........nB;.h......F.......[Content_Types].xmlz.........MN.0...by.b.,.BI...X `...{..O.S...H\.'.XTP..K{.o.....rg..bL...XM.:.v..c.k...}.D....9.....Bb>.+..G.......+(.u}.w.]...v..{.M&.].>`....nB..B0Z@.e.u..R.......-.&#....aR..`.a..|. 1^......&..|..s.A.t..b..A.i7...7.&....bQK$O.......9....V....Wt_PK........5nB;.ndX....`......._rels/.rels...J.1.._%..f.J.J..x..AJ.2M&......g..#............|.c..x{_._..^0e.|.gU..z.....#.._..[..JG.m.....(...e..r."....P)....3..M].E:..SO.;D..c..J..rt...c.,.....a.;.....$.../5..D.Ue.g...Q3......5.':...@...~t{.v..QA>.P.R.A~..^AR.S4G......].n...x41....PK.........^5..s.V....Z......diagrams/layout1.xml.[]o.F.}N~..S.......VU.U+m6R........&.d.}...{M....Q.S....p9.'./O..z."..t>q....."[..j>y..?...u....[.}..j-...?Y..Bdy.I./.....0.._.....-.s...rj...I..=..<..9.|>YK.....o.|.my.F.LlB..be/E.Y!.$6r.f/.p%.......U....e..W.R..fK....`+?.rwX.[.b..|..O>o.|.....>1.......trN`7g..Oi.@5..^...]4.r...-y...T.h...[.j1..v....G..........nS..m..E"L...s
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:data
    Category:dropped
    Size (bytes):260
    Entropy (8bit):3.494357416502254
    Encrypted:false
    SSDEEP:6:fxnxUX0XPE3QepmlJ0+hdADryMluyS6Bkls0Lwv:fxnyEXPGHmD0+dAH/luWvv
    MD5:6F8FE7B05855C203F6DEC5C31885DD08
    SHA1:9CC27D17B654C6205284DECA3278DA0DD0153AFF
    SHA-256:B7F58DF058C938CCF39054B31472DC76E18A3764B78B414088A261E440870175
    SHA-512:C518A243E51CB4A1E3C227F6A8A8D9532EE111D5A1C86EBBB23BD4328D92CD6A0587DF65B3B40A0BE2576D8755686D2A3A55E10444D5BB09FC4E0194DB70AFE6
    Malicious:false
    Reputation:low
    Preview:[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .T.h.e.m.e.P.i.c.t.u.r.e.G.r.i.d...g.l.o.x.....C.o.m.p.o.n.e.n.t.:. .W.o.r.d.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.\.S.m.a.r.t.A.r.t. .G.r.a.p.h.i.c.s.........
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:Zip archive data, at least v2.0 to extract, compression method=deflate
    Category:dropped
    Size (bytes):6193
    Entropy (8bit):7.855499268199703
    Encrypted:false
    SSDEEP:192:WavHMKgnU2HUGFhUnkbOKoztj1QfcnLYut3d8:YKeUlGXUnC+HQSMp
    MD5:031C246FFE0E2B623BBBD231E414E0D2
    SHA1:A57CA6134779D54691A4EFD344BC6948E253E0BA
    SHA-256:2D76C8D1D59EDB40D1FBBC6406A06577400582D1659A544269500479B6753CF7
    SHA-512:6A784C28E12C3740300883A0E690F560072A3EA8199977CBD7F260A21E8346B82BA8A4F78394D3BB53FA2E98564B764C2D0232C40B25FB6085C36D20D70A39D1
    Malicious:false
    Reputation:low
    Preview:PK........X..<..Zn|...........diagrams/layout1.xmlz........]..H.}......M,l#g.j:.G-eu.*S=.$......T_6..I...6...d.NJ....r.p.p.........|.z.K.M..L.T.(........<..ks.......o...t}...P..*.7...`.+.[...H..._..X.u.....N....n....n|..=.....K.:.G7.u....."g.n.h...O.,...c...f.b.P......>[l.....j.*.?..mxk..n..|A...,\o..j..wQ.....lw.~].Lh..{3Y..D..5.Y..n..Mh.r..J....6*.<.kO...Alv.._.qdKQ.5...-FMN......;.~..._..pv..&...%"Nz].n............vM.`..k..a.:.f]...a........y.....g0..`........|V...Yq.....#...8....n..i7w<2Rp...R.@.]..%.b%..~...a..<.j...&....?...Qp..Ow|&4>...d.O.|.|...Fk;t.P[A..i.6K.~...Y.N..9......~<Q..f...i.....6..U...l. ..E..4$Lw..p..Y%NR..;...B|B.U...\e......S...=...B{A.]..*....5Q.....FI..w....q.s{.K....(.]...HJ9........(.....[U|.....d71.Vv.....a.8...L.....k;1%.T.@+..uv.~v.]`.V....Z.....`.M.@..Z|.r........./C..Z.n0.....@.YQ.8..q.h.....c.%...p..<..zl.c..FS.D..fY..z..=O..%L..MU..c.:.~.....F]c......5.=.8.r...0....Y.\o.o....U.~n...`...Wk..2b......I~
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:data
    Category:dropped
    Size (bytes):252
    Entropy (8bit):3.48087342759872
    Encrypted:false
    SSDEEP:6:fxnxUXXt1MIae2E3QepmlJ0+hdADryMluyS6Bkls0Lwv:fxnyfMIaRGHmD0+dAH/luWvv
    MD5:69757AF3677EA8D80A2FBE44DEE7B9E4
    SHA1:26AF5881B48F0CB81F194D1D96E3658F8763467C
    SHA-256:0F14CA656CDD95CAB385F9B722580DDE2F46F8622E17A63F4534072D86DF97C3
    SHA-512:BDA862300BAFC407D662872F0BFB5A7F2F72FE1B7341C1439A22A70098FA50C81D450144E757087778396496777410ADCE4B11B655455BEDC3D128B80CFB472A
    Malicious:false
    Reputation:low
    Preview:[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .P.i.c.t.u.r.e.F.r.a.m.e...g.l.o.x.....C.o.m.p.o.n.e.n.t.:. .W.o.r.d.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.\.S.m.a.r.t.A.r.t. .G.r.a.p.h.i.c.s.........
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:Microsoft OOXML
    Category:dropped
    Size (bytes):4326
    Entropy (8bit):7.821066198539098
    Encrypted:false
    SSDEEP:96:+fF+Jrp7Yo5hnJiGa24TxEcpUeONo1w2NFocy2LQi33Z:2+f7YuhJdJ4TxEcmKwGkk3Z
    MD5:D32E93F7782B21785424AE2BEA62B387
    SHA1:1D5589155C319E28383BC01ED722D4C2A05EF593
    SHA-256:2DC7E71759D84EF8BB23F11981E2C2044626FEA659383E4B9922FE5891F5F478
    SHA-512:5B07D6764A6616A7EF25B81AB4BD4601ECEC1078727BFEAB4A780032AD31B1B26C7A2306E0DBB5B39FC6E03A3FC18AD67C170EA9790E82D8A6CEAB8E7F564447
    Malicious:false
    Reputation:low
    Preview:PK.........n.A...#............docProps/thumbnail.jpgz.........{4.i....1.n.v)..#.\*....A+..Q(."..D.......#Q)...SQ....2c.ei.JC...N.{......}.s.s..y>....d.(:.;.....q........$.OBaPbI..(.V...o.....'..b..edE.J.+.....".tq..dqX.......8...CA.@..........0.G.O.$Ph...%i.Q.CQ.>.%!j..F..."?@.1J.Lm$..`..*oO...}..6......(%....^CO..p......-,.....w8..t.k.#....d..'...O...8....s1....z.r...rr...,(.)...*.]Q]S.{X.SC{GgWw..O....X./FF9._&..L.....[z..^..*....C...qI.f... .Hq....d*.d..9.N{{.N.6..6)..n<...iU]3.._.....%./.?......(H4<.....}..%..Z..s...C@.d>.v...e.'WGW.....J..:....`....n..6.....]W~/.JX.Qf..^...}...._Sg.-.p..a..C_:..F..E.....k.H..........-Bl$._5...B.w2e...2...c2/y3.U...7.8[.S}H..r/..^...g...|...l..\M..8p$]..poX-/.2}..}z\.|.d<T.....1....2...{P...+Y...T...!............p..c.....D..o..%.d.f.~.;.;=4.J..]1"("`......d.0.....L.f0.l..r8..M....m,.p..Y.f....\2.q. ...d9q....P...K..o!..#o...=.........{.p..l.n...........&..o...!J..|)..q4.Z.b..PP....U.K..|.i.$v
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:data
    Category:dropped
    Size (bytes):286
    Entropy (8bit):3.4670546921349774
    Encrypted:false
    SSDEEP:6:fxnxUX0XPYDxUloE3QepmlJ0+hdADryMluyS6Bkls0Lwv:fxnyEXPYDCloGHmD0+dAH/luWvv
    MD5:3D52060B74D7D448DC733FFE5B92CB52
    SHA1:3FBA3FFC315DB5B70BF6F05C4FF84B52A50FCCBC
    SHA-256:BB980559C6FC38B703D1E9C41720D5CE8D00D2FF86D4F25136DB02B1E54B1518
    SHA-512:952EF139A72562A528C1052F1942DAE1C0509D67654BF5E7C0602C87F90147E8EE9E251D2632BCB5B511AB2FF8A3734293D0A4E3DBD3D187F5E3C042685F9A0C
    Malicious:false
    Reputation:low
    Preview:[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .T.h.e.m.e.P.i.c.t.u.r.e.A.l.t.e.r.n.a.t.i.n.g.A.c.c.e.n.t...g.l.o.x.....C.o.m.p.o.n.e.n.t.:. .W.o.r.d.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.\.S.m.a.r.t.A.r.t. .G.r.a.p.h.i.c.s.........
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:Zip archive data, at least v2.0 to extract, compression method=deflate
    Category:dropped
    Size (bytes):5630
    Entropy (8bit):7.87271654296772
    Encrypted:false
    SSDEEP:96:n5ni6jKZWsD+QJaUQ7R6qYFF5QS+BEgeJam6S7ZCHuKViGa2CnnLYLt/ht:nccqxIBdQ1QS+uDJanS7ZCHHVdJCnLY5
    MD5:2F8998AA9CF348F1D6DE16EAB2D92070
    SHA1:85B13499937B4A584BEA0BFE60475FD4C73391B6
    SHA-256:8A216D16DEC44E02B9AB9BBADF8A11F97210D8B73277B22562A502550658E580
    SHA-512:F10F7772985EDDA442B9558127F1959FF0A9909C7B7470E62D74948428BFFF7E278739209E8626AE5917FF728AFB8619AE137BEE2A6A4F40662122208A41ABB2
    Malicious:false
    Reputation:low
    Preview:PK...........<..W8...j.......diagrams/layout1.xmlz........]......Hy..{...n .l.:.D.vvW..s....-a..fg&.}.\..+......4M..'=...(._.U]U......_.....U...k}.y.,......C..._^.......w/."7....v..Ea........Q..u..D{..{v.x.]....AtB15u..o...w..o.1...f.L...I<[zk7..7^..,.h.&l3...#..)..'H..d.r.#w=b...Ocw.y.&.v..t.>.s..m^M7..8I?o7................H...b....Qv.;'..%.f..#vR....V.H.),g..`...)(..m...[l...b...,.....U...Q.{.y.y.....G.I.tT.n..N.....A.tR..tr....i.<.......,.n:.#.A..a!X.......DK..;v..._M..lSc../n...v.....}.....I.|8.!b.C..v..|.....4l..n.;<9.i./..}!&2.c/.r...>.X02[..|.a.-.....$#-....>...{.M].>3.,\o.x....X%;.F.k.)*".I8<.0..#......?.h..-..O.2.B.s..v....{Abd...h0....H..I.. ...%...$1.Fyd..Y....U...S.Y.#.V.....TH(....%..nk.3Y.e.m.-.S..Q...j.Ai..E..v......4.t.|..&"...{..4.!.h.....C.P.....W...d[.....U<Yb;B.+W.!.@B....!.=......b"...Y.N;.#..Q...0G.lW...]7:...#9!z......|f..r..x.....t........`.uL1u.:.....U.D.n.<Q.[%...ngC./..|...!..q;;.w.".D..lt.".l.4".mt...E..mt
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:data
    Category:dropped
    Size (bytes):242
    Entropy (8bit):3.4938093034530917
    Encrypted:false
    SSDEEP:6:fxnxUX44lWWoE3QepmlJ0+hdADryMluyS6Bkls0Lwv:fxnyvToGHmD0+dAH/luWvv
    MD5:A6B2731ECC78E7CED9ED5408AB4F2931
    SHA1:BA15D036D522978409846EA682A1D7778381266F
    SHA-256:6A2F9E46087B1F0ED0E847AF05C4D4CC9F246989794993E8F3E15B633EFDD744
    SHA-512:666926612E83A7B4F6259C3FFEC3185ED3F07BDC88D43796A24C3C9F980516EB231BDEA4DC4CC05C6D7714BA12AE2DCC764CD07605118698809DEF12A71F1FDD
    Malicious:false
    Reputation:low
    Preview:[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .T.a.b.L.i.s.t...g.l.o.x.....C.o.m.p.o.n.e.n.t.:. .W.o.r.d.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.\.S.m.a.r.t.A.r.t. .G.r.a.p.h.i.c.s.........
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:Zip archive data, at least v2.0 to extract, compression method=deflate
    Category:dropped
    Size (bytes):4888
    Entropy (8bit):7.8636569313247335
    Encrypted:false
    SSDEEP:96:StrFZ23/juILHPzms5UTuK9CuZGEoEuZ28H1HiGa2RnnLY+tUb:SPZQ7uCHPzms5UTlqauZVHdJRnLY+tUb
    MD5:0A4CA91036DC4F3CD8B6DBF18094CF25
    SHA1:6C7EED2530CD0032E9EEAB589AFBC296D106FBB9
    SHA-256:E5A56CCB3B3898F76ABF909209BFAB401B5DDCD88289AD43CE96B02989747E50
    SHA-512:7C69426F2250E8C84368E8056613C22977630A4B3F5B817FB5EA69081CE2A3CA6E5F93DF769264253D5411419AF73467A27F0BB61291CCDE67D931BD0689CB66
    Malicious:false
    Reputation:low
    Preview:PK.........e.>.......]>......diagrams/layout1.xmlz........Z..6....;..{......lw.E.o....i..T....&...G.+...$..(.6..>Y.pf8C.|3.?..m....xA8v.`.hW..@..Zn..(kb..(.......`.+....Y`...\..qh.0.!&w..)|...<..]Q.. _....m..Z.{3..~..5..R..d..A.O....gU.M..0..#...;.>$...T......T..z.Z.\a.+...?#.~.....1.>?...*..DD.1...'..,..(...5B...M..]..>.C..<[....,L.p..Q.v.v^q.Y...5.~^c..5........3.j.......BgJ.nv.. ............tt......Q..p..K....(M.(]@..E..~z.~...8...49.t.Q..Q.n..+.....*J.#J.... .P...P.1...!.#&...?A..&.."..|..D.I...:.....~/.....b..].........nI7.IC.a..%...9.....4...r....b..q....@o........O...y...d@+~.<.\....f.a`:...Qy/^..P....[....@i.I.._.?.X.x.8....)..s....I.0...|.....t...;...q=k.=..N.%!.(.1....B.Ps/."...#.%..&...j<..2x.=<.......s.....h..?..]?Y?...C.}E.O........{..6.d....I...A.....JN..w+....2..m>9.T7...t.6.}.i..f.Ga..t.].->...8U......G.D`......p..f.. ...qT.YX.t.F..X.u=.3r...4....4Q.D..l.6.+PR...+..T..h: H.&.1~....n.....)........2J.. O.W+vd..f....0.....6..9QhV..
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:data
    Category:dropped
    Size (bytes):262
    Entropy (8bit):3.4901887319218092
    Encrypted:false
    SSDEEP:6:fxnxUXqhBMl0OoE3QepmlJ0+hdADryMluyS6Bkls0Lwv:fxnyiMl0OoGHmD0+dAH/luWvv
    MD5:52BD0762F3DC77334807DDFC60D5F304
    SHA1:5962DA7C58F742046A116DDDA5DC8EA889C4CB0E
    SHA-256:30C20CC835E912A6DD89FD1BF5F7D92B233B2EC24594F1C1FE0CADB03A8C3FAB
    SHA-512:FB68B1CF9677A00D5651C51EC604B61DAC2D250D44A71D43CD69F41F16E4F0A7BAA7AD4A6F7BB870429297465A893013BBD7CC77A8F709AD6DB97F5A0927B1DD
    Malicious:false
    Reputation:low
    Preview:[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .R.a.d.i.a.l.P.i.c.t.u.r.e.L.i.s.t...g.l.o.x.....C.o.m.p.o.n.e.n.t.:. .W.o.r.d.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.\.S.m.a.r.t.A.r.t. .G.r.a.p.h.i.c.s.........
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:Microsoft OOXML
    Category:dropped
    Size (bytes):5596
    Entropy (8bit):7.875182123405584
    Encrypted:false
    SSDEEP:96:dGa2unnLYEB2EUAPOak380NQjqbHaPKJebgrEVws8Vw+BMa0EbdLVQaZJgDZh0pJ:UJunLYEB2EUAxk3pIYaScgYwsV4bdS0X
    MD5:CDC1493350011DB9892100E94D5592FE
    SHA1:684B444ADE2A8DBE760B54C08F2D28F2D71AD0FA
    SHA-256:F637A67799B492FEFFB65632FED7815226396B4102A7ED790E0D9BB4936E1548
    SHA-512:3699066A4E8A041079F12E88AB2E7F485E968619CB79175267842846A3AD64AA8E7778CBACDF1117854A7FDCFB46C8025A62F147C81074823778C6B4DC930F12
    Malicious:false
    Reputation:low
    Preview:PK.........T.>................[Content_Types].xmlz.........=N.1...b.Eko(.B....(.Pp..=.u.?.....#q..ND.!$.J{.o....G..[Cv.....+.R.Nx..........0."u..S...$&.....Je..B..x......m......M^z....f....|...N..Q..z.!.- .2.9y.i.8j...........0.AE..p.s~@../jw.#8.I.#....4.~Cl.:#h..f.PU.s.~........(.)F..Y......^x..PK.........T.>...V....L......._rels/.rels...J.@.._e..]AD.....x....3.t..T.w.\ZpA<x......v..'....z.........Y..[...<..2.TT....Q$.!.=.....&C....b".F.q.7...X3...7.8.N.}.. ?..8...#..,.L.3.#e...wZpZ.]S..:....t.....{..6.7.|..,dH.e..K 7-}.~.v...5.......b..PK.........V.<.S.....Y.......diagrams/layout1.xml.\.r.8...U....m.$.."3.....;...../3.XAn..O.?....V.;...")Nr.O.H....O......_..E..S...L7....8H.y<=............~...Ic......v9.X.%.\.^.,?g.v.?%w...f.).9.........Ld;.1..?~.%QQ...h.8;.gy..c4..]..0Ii.K&.[.9.......E4B.a..?e.B..4....E.......Y.?_&!.....i~..{.W..b....L.?..L..@.F....c.H..^..i...(d.......w...9..9,........q..%[..]K}.u.k..V.%.Y.....W.y..;e4[V..u.!T...).%.
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:data
    Category:dropped
    Size (bytes):274
    Entropy (8bit):3.438490642908344
    Encrypted:false
    SSDEEP:6:fxnxUXZlaWimoa2nRE3QepmlJ0+3FbnKfZObdADxp1RDWlVwv:fxnyplagN2RGHmD0wbnKYZAH+Vwv
    MD5:0F98498818DC28E82597356E2650773C
    SHA1:1995660972A978D17BC483FCB5EE6D15E7058046
    SHA-256:4587CA0B2A60728FF0A5B8E87D35BF6C6FDF396747E13436EC856612AC1C6288
    SHA-512:768562F20CFE15001902CCE23D712C7439721ECA6E48DDDCF8BFF4E7F12A3BC60B99C274CBADD0128EEA1231DB19808BAA878E825497F3860C381914C21B46FF
    Malicious:false
    Reputation:low
    Preview:[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .E.l.e.m.e.n.t. .d.e.s.i.g.n. .s.e.t...d.o.t.x.....C.o.m.p.o.n.e.n.t.:. .W.o.r.d.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....E.x.e.c.u.t.a.b.l.e.:. .{.W.D.}.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.W.D. .D.o.c.u.m.e.n.t. .P.a.r.t.s.}.........
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:Microsoft Word 2007+
    Category:dropped
    Size (bytes):34415
    Entropy (8bit):7.352974342178997
    Encrypted:false
    SSDEEP:768:ev13NPo9o5NGEVIi3kvH+3SMdk7zp3tE2:ev13xoOE+R3BkR7
    MD5:7CDFFC23FB85AD5737452762FA36AAA0
    SHA1:CFBC97247959B3142AFD7B6858AD37B18AFB3237
    SHA-256:68A8FBFBEE4C903E17C9421082E839144C205C559AFE61338CBDB3AF79F0D270
    SHA-512:A0685FD251208B772436E9745DA2AA52BC26E275537688E3AB44589372D876C9ACE14B21F16EC4053C50EB4C8E11787E9B9D922E37249D2795C5B7986497033E
    Malicious:false
    Reputation:low
    Preview:PK.........Y5B#.W ............[Content_Types].xml ...(...................................................................................................................................................................................................................................................................................................................................................................................................................................................`.I.%&/m.{.J.J..t...`.$.@........iG#).*..eVe]f.@....{...{...;.N'...?\fd.l..J..!....?~|.?"....|.{.[..e^7E......Gi..V.by..G..|.......U..t.|..mW...m..|.5.j./..^d-.Y_.]e..E~wog...j...v......?..u....c.....D....>.V...f-}..r9....=..Mn..U..5.(.....a...E..b....*..w.$...,O_fu."[P..WU=.;.....5..wdt..y1.......i.44-.r....;./.biG=.HK...........&o[B....z.7.o...&.......[.oL_7cuN..&e..ccAo...YW......8...Y>.&DVy...-&.*...Y.....4.u.., !po....9W....g..F...*+1....d,'...L.M[-~.Ey. ......[
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:data
    Category:dropped
    Size (bytes):246
    Entropy (8bit):3.5039994158393686
    Encrypted:false
    SSDEEP:6:fxnxUX4f+E3QepmlJ0+hdADryMluyS6Bkls0Lwv:fxnyvGHmD0+dAH/luWvv
    MD5:16711B951E1130126E240A6E4CC2E382
    SHA1:8095AA79AEE029FD06428244CA2A6F28408448DB
    SHA-256:855342FE16234F72DA0C2765455B69CF412948CFBE70DE5F6D75A20ACDE29AE9
    SHA-512:454EAA0FD669489583C317699BE1CE5D706C31058B08CF2731A7621FDEFB6609C2F648E02A7A4B2B3A3DFA8406A696D1A6FA5063DDA684BDA4450A2E9FEFB0EF
    Malicious:false
    Reputation:low
    Preview:[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .T.a.b.b.e.d.A.r.c...g.l.o.x.....C.o.m.p.o.n.e.n.t.:. .W.o.r.d.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.\.S.m.a.r.t.A.r.t. .G.r.a.p.h.i.c.s.........
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:Zip archive data, at least v2.0 to extract, compression method=deflate
    Category:dropped
    Size (bytes):3683
    Entropy (8bit):7.772039166640107
    Encrypted:false
    SSDEEP:96:GyfQZd6ZHNCWl9aXFkZwIq/QDsRYPf8P9QtDIs5r:G6wYtNZS1k99AmPfSOtD5r
    MD5:E8308DA3D46D0BC30857243E1B7D330D
    SHA1:C7F8E54A63EB254C194A23137F269185E07F9D10
    SHA-256:6534D4D7EF31B967DD0A20AFFF092F8B93D3C0EFCBF19D06833F223A65C6E7C4
    SHA-512:88AB7263B7A8D7DDE1225AE588842E07DF3CE7A07CBD937B7E26DA7DA7CFED23F9C12730D9EF4BC1ACF26506A2A96E07875A1A40C2AD55AD1791371EE674A09B
    Malicious:false
    Reputation:low
    Preview:PK.........a9;lq.ri...#.......diagrams/layout1.xmlz........WKn.0.];.`..J..AP...4E..!..hi$..I......z..D.d;...m.d...f.3o.._....9'.P.I1.F.C...d.D:.........Q..Z..5$..BO...e..(.9..2..+.Tsjp.. Vt.f.<...gA.h...8...>..p4..T...9.c...'.G.;.@.;xKE.A.uX.....1Q...>...B...!T.%.* ...0.....&......(.R.u..BW.yF.Grs...)..$..p^.s.c._..F4.*. .<%.BD..E....x... ..@...v.7f.Y......N.|.qW'..m..........im.?.64w..h...UI...J....;.0..[....G..\...?:.7.0.fGK.C.o^....j4............p...w:...V....cR..i...I...J=...%. &..#..[M....YG...u...I)F.l>.j.....f..6.....2.]..$7.....Fr..o.0...l&..6U...M..........%..47.a.[..s........[..r....Q./}.-.(.\..#. ..y`...a2..*....UA.$K.nQ:e!bB.H.-Q-a.$La.%.Z!...6L...@...j.5.....b..S.\c..u...R..dXWS.R.8"....o[..V...s0W..8:...U.#5..hK....ge.Q0$>...k.<...YA.g..o5...3.....~re.....>....:..$.~........pu ._Q..|Z...r...E.X......U....f)s^.?...%......459..XtL:M.).....x..n9..h...c...PK........Ho9<"..%...........diagrams/layoutHeader1.xmlMP.N.0.>oOa.
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:data
    Category:dropped
    Size (bytes):286
    Entropy (8bit):3.538396048757031
    Encrypted:false
    SSDEEP:6:fxnxUXcel8ME3QepmlJ0+3FbnKfZObdADryMluxHZypwwyv:fxnyMelNGHmD0wbnKYZAH/lMZqiv
    MD5:149948E41627BE5DC454558E12AF2DA4
    SHA1:DB72388C037F0B638FCD007FAB46C916249720A8
    SHA-256:1B981DC422A042CDDEBE2543C57ED3D468288C20D280FF9A9E2BB4CC8F4776ED
    SHA-512:070B55B305DB48F7A8CD549A5AECF37DE9D6DCD780A5EC546B4BB2165AF4600FA2AF350DDDB48BECCAA3ED954AEE90F5C06C3183310B081F555389060FF4CB01
    Malicious:false
    Reputation:low
    Preview:[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .s.i.s.t.0.2...x.s.l.....C.o.m.p.o.n.e.n.t.:. .W.o.r.d.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....E.x.e.c.u.t.a.b.l.e.:. .{.W.D.}.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.....C.o.m.m.a.n.d.:. ./.f. .{.F.i.l.e.P.a.t.h.}.........
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
    Category:dropped
    Size (bytes):250983
    Entropy (8bit):5.057714239438731
    Encrypted:false
    SSDEEP:6144:JwprA6OS95vtfb8p4bgWPzkhUh9I5/oBRSifJeg/yQzvapSiQhHZeruvoXMUw3im:uP
    MD5:F883B260A8D67082EA895C14BF56DD56
    SHA1:7954565C1F243D46AD3B1E2F1BAF3281451FC14B
    SHA-256:EF4835DB41A485B56C2EF0FF7094BC2350460573A686182BC45FD6613480E353
    SHA-512:D95924A499F32D9B4D9A7D298502181F9E9048C21DBE0496FA3C3279B263D6F7D594B859111A99B1A53BD248EE69B867D7B1768C42E1E40934E0B990F0CE051E
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="utf-8"?>..<xsl:stylesheet version="1.0" xmlns:xsl="http://www.w3.org/1999/XSL/Transform" xmlns:msxsl="urn:schemas-microsoft-com:xslt".xmlns:b="http://schemas.openxmlformats.org/officeDocument/2006/bibliography" xmlns:t="http://www.microsoft.com/temp">...<xsl:output method="html" encoding="us-ascii"/>..............<xsl:template match="*" mode="outputHtml2">.....<xsl:apply-templates mode="outputHtml"/>.....</xsl:template>.....<xsl:template name="StringFormatDot">....<xsl:param name="format" />....<xsl:param name="parameters" />.... <xsl:variable name="prop_EndChars">.. <xsl:call-template name="templ_prop_EndChars"/>.. </xsl:variable>.... <xsl:choose>.....<xsl:when test="$format = ''"></xsl:when>.....<xsl:when test="substring($format, 1, 2) = '%%'">......<xsl:text>%</xsl:text>......<xsl:call-template name="StringFormatDot">.......<xsl:with-param name="format" select="substring($format, 3)" />.......<xsl:with-param name="parameters" select="$para
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:data
    Category:dropped
    Size (bytes):256
    Entropy (8bit):3.4842773155694724
    Encrypted:false
    SSDEEP:6:fxnxUXDAlIJAFIloE3QepmlJ0+hdADryMluyS6Bkls0Lwv:fxnyMlI7loGHmD0+dAH/luWvv
    MD5:923D406B2170497AD4832F0AD3403168
    SHA1:A77DA08C9CB909206CDE42FE1543B9FE96DF24FB
    SHA-256:EBF9CF474B25DDFE0F6032BA910D5250CBA2F5EDF9CF7E4B3107EDB5C13B50BF
    SHA-512:A4CD8C74A3F916CA6B15862FCA83F17F2B1324973CCBCC8B6D9A8AEE63B83A3CD880DC6821EEADFD882D74C7EF58FA586781DED44E00E8B2ABDD367B47CE45B7
    Malicious:false
    Reputation:low
    Preview:[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .C.o.n.v.e.r.g.i.n.g.T.e.x.t...g.l.o.x.....C.o.m.p.o.n.e.n.t.:. .W.o.r.d.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.\.S.m.a.r.t.A.r.t. .G.r.a.p.h.i.c.s.........
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:Zip archive data, at least v2.0 to extract, compression method=deflate
    Category:dropped
    Size (bytes):11380
    Entropy (8bit):7.891971054886943
    Encrypted:false
    SSDEEP:192:VJcnLYnAVbOFLaCPLrGGbhaWEu6d3RmryqLkeAShObPb1AYcRMMXjkfa0nYBwggD:VcMC8lLrRbhy1ZqLyShYb1FHQ4C0nYQJ
    MD5:C9F9364C659E2F0C626AC0D0BB519062
    SHA1:C4036C576074819309D03BB74C188BF902D1AE00
    SHA-256:6FC428CA0DCFC27D351736EF16C94D1AB08DDA50CB047A054F37EC028DD08AA2
    SHA-512:173A5E68E55163B081C5A8DA24AE46428E3FB326EBE17AE9588C7F7D7E5E5810BFCF08C23C3913D6BEC7369E06725F50387612F697AC6A444875C01A2C94D0FF
    Malicious:false
    Reputation:low
    Preview:PK.........T.>................[Content_Types].xmlz.........=N.1...b.Eko(.B....(.Pp..=.u.?.....#q..ND.!$.J{.o....G..[Cv.....+.R.Nx..........0."u..S...$&.....Je..B..x......m......M^z....f....|...N..Q..z.!.- .2.9y.i.8j...........0.AE..p.s~@../jw.#8.I.#....4.~Cl.:#h..f.PU.s.~........(.)F..Y......^x..PK.........T.>...V....L......._rels/.rels...J.@.._e..]AD.....x....3.t..T.w.\ZpA<x......v..'....z.........Y..[...<..2.TT....Q$.!.=.....&C....b".F.q.7...X3...7.8.N.}.. ?..8...#..,.L.3.#e...wZpZ.]S..:....t.....{..6.7.|..,dH.e..K 7-}.~.v...5.......b..PK........q.~<.6..9 ...e......diagrams/layout1.xml..r.........{.]..u...xv7b.....HPd....t.q...b.i_a.'..P.f.3..F..1...U.u.*.2......?}..O..V.....yQ.Mf........w.....O....N.........t3;...e....j.^.o&.....w...../.w................e.................O..,./..6...8>^.^..........ru5...\.=>[M?......g..........w.N....i.........iy6.?........>.......>{yT...........x.........-...z5.L./.g......_.l.1.....#...|...pr.q
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:Microsoft OOXML
    Category:dropped
    Size (bytes):562113
    Entropy (8bit):7.67409707491542
    Encrypted:false
    SSDEEP:12288:/dy5Gtyp/FZ9QqjdxDfSp424XeavSktiAVE0:/dizp1ndpqpMZnV
    MD5:4A1657A3872F9A77EC257F41B8F56B3D
    SHA1:4DDEA85C649A2C1408B5B08A15DEF49BAA608A0B
    SHA-256:C17103ADE455094E17AC182AD4B4B6A8C942FD3ACB381F9A5E34E3F8B416AE60
    SHA-512:7A2932639E06D79A5CE1D3C71091890D9E329CA60251E16AE4095E4A06C6428B4F86B7FFFA097BF3EEFA064370A4D51CA3DF8C89EAFA3B1F45384759DEC72922
    Malicious:false
    Reputation:low
    Preview:PK..........1AE,.{E...#P......[Content_Types].xml..Mo.0.....Z..N7.=l......V0.-o..j?...H..sa......./UCb.'...r...w.i..e..<[....{2..U.m..N.{...r.....3.fj.o......2.*....;.L.6..&,D.Cld8...a.gZf.......r-v..><....~/......|Zk.......a.R&.d.(.$..6..}.:.....3......1..[.p.....?..+....R...y,.fod.....e...-.|..#..]j....n:...f...-J...i.^.:Y....T..........m^..~GNp../e}...N....a..5.d.8YcN..5.d.8Y...7..A..e...7Q."3...../.sL._...v...n..b..2].v....n.t....Z...Uk...j.&.Z....im|.r....B.....7DaBuN.... ...>..>..>..>..>..>..>.........V}-.....Q}#.&T..j...r..]..CZ..CZ..CZ..CZ..CZ..CZ..CZ..i.o.,-k..b....7FaBuN.... ...>..>..>..>..>..>..>.........V}-...Q}..&T..j...r..]..CZ..CZ..CZ..CZ..CZ..CZ..CZ..i.o.,-k..b....7EaBuN.... ...>..>..>..>..>..>..>.........V}-...Q}3.&T..j...r..]..CZ..CZ..CZ..CZ..CZ..CZ..CZ..i.o.,-k..b.\}..)...A.......[..PK..........1A.s@.....O......._rels/.rels...J.1.._%..d...t......}...n2!..}6.>..`(.v...K`2...70...........84P....
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
    Category:dropped
    Size (bytes):278
    Entropy (8bit):3.535736910133401
    Encrypted:false
    SSDEEP:6:Q+sxnxUXeAlFkRELpmlJ0+3FbnKf68dADryMluxHFpwwl:Q+sxnyRGymD0wbnKNAH/lMz1
    MD5:487E25E610F3FC2EEA27AB54324EA8F6
    SHA1:11C2BB004C5E44503704E9FFEEFA7EA7C2A9305C
    SHA-256:022EC5077279A8E447B590F7260E1DBFF764DE5F9CDFD4FDEE32C94C66D4A1A2
    SHA-512:B8DF351E2C0EF101CF91DC02E136A3EE9C1FDB18294BECB13A29D676FBBE791A80A58A18FBDEB953BC21EC54EB7608154D401407C461ABD10ACB94CE8AD0E092
    Malicious:false
    Reputation:low
    Preview:..[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .B.a.n.d.e.d...t.h.m.x.....C.o.m.p.o.n.e.n.t.:. .P.P.T.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....E.x.e.c.u.t.a.b.l.e.:. .{.P.P.}.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.....C.o.m.m.a.n.d.:. .{.F.i.l.e.P.a.t.h.}.....
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:data
    Category:dropped
    Size (bytes):286
    Entropy (8bit):3.5502940710609354
    Encrypted:false
    SSDEEP:6:fxnxUXfQICl8ME3QepmlJ0+3FbnKfZObdADryMluxHZypwwyv:fxnyXClNGHmD0wbnKYZAH/lMZqiv
    MD5:9B8D7EFE8A69E41CDC2439C38FE59FAF
    SHA1:034D46BEC5E38E20E56DD905E2CA2F25AF947ED1
    SHA-256:70042F1285C3CD91DDE8D4A424A5948AE8F1551495D8AF4612D59709BEF69DF2
    SHA-512:E50BB0C68A33D35F04C75F05AD4598834FEC7279140B1BB0847FF39D749591B8F2A0C94DA4897AAF6C33C50C1D583A836B0376015851910A77604F8396C7EF3C
    Malicious:false
    Reputation:low
    Preview:[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .i.s.o.6.9.0...x.s.l.....C.o.m.p.o.n.e.n.t.:. .W.o.r.d.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....E.x.e.c.u.t.a.b.l.e.:. .{.W.D.}.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.....C.o.m.m.a.n.d.:. ./.f. .{.F.i.l.e.P.a.t.h.}.........
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
    Category:dropped
    Size (bytes):270198
    Entropy (8bit):5.073814698282113
    Encrypted:false
    SSDEEP:6144:JwprAiaR95vtfb8pDbgWPzDCvCmvQursq7vImej/yQ4SS1apSiQhHDOruvoVeMUX:We
    MD5:FF0E07EFF1333CDF9FC2523D323DD654
    SHA1:77A1AE0DD8DBC3FEE65DD6266F31E2A564D088A4
    SHA-256:3F925E0CC1542F09DE1F99060899EAFB0042BB9682507C907173C392115A44B5
    SHA-512:B4615F995FAB87661C2DBE46625AA982215D7BDE27CAFAE221DCA76087FE76DA4B4A381943436FCAC1577CB3D260D0050B32B7B93E3EB07912494429F126BB3D
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="utf-8"?>..<xsl:stylesheet version="1.0" xmlns:xsl="http://www.w3.org/1999/XSL/Transform" xmlns:msxsl="urn:schemas-microsoft-com:xslt".xmlns:b="http://schemas.openxmlformats.org/officeDocument/2006/bibliography" xmlns:t="http://www.microsoft.com/temp">...<xsl:output method="html" encoding="us-ascii"/>..............<xsl:template match="*" mode="outputHtml2">.....<xsl:apply-templates mode="outputHtml"/>.....</xsl:template>.....<xsl:template name="StringFormatDot">....<xsl:param name="format" />....<xsl:param name="parameters" />.... <xsl:variable name="prop_EndChars">.. <xsl:call-template name="templ_prop_EndChars"/>.. </xsl:variable>.... <xsl:choose>.....<xsl:when test="$format = ''"></xsl:when>.....<xsl:when test="substring($format, 1, 2) = '%%'">......<xsl:text>%</xsl:text>......<xsl:call-template name="StringFormatDot">.......<xsl:with-param name="format" select="substring($format, 3)" />.......<xsl:with-param name="parameters" select="$para
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:Microsoft OOXML
    Category:dropped
    Size (bytes):570901
    Entropy (8bit):7.674434888248144
    Encrypted:false
    SSDEEP:6144:D2tTXiO/3GH5SkPQVAqWnGrkFxvay910UUTWZJarUv9TA0g8:kX32H+VWgkFxSgGTmarUv9T
    MD5:D676DE8877ACEB43EF0ED570A2B30F0E
    SHA1:6C8922697105CEC7894966C9C5553BEB64744717
    SHA-256:DF012D101DE808F6CD872DFBB619B16732C23CF4ABC64149B6C3CE49E9EFDA01
    SHA-512:F40BADA680EA5CA508947290BA73901D78DE79EAA10D01EAEF975B80612D60E75662BDA542E7F71C2BBA5CA9BA46ECAFE208FD6E40C1F929BB5E407B10E89FBD
    Malicious:false
    Reputation:low
    Preview:PK..........1AE,.{E...#P......[Content_Types].xml..Mo.0.....Z..N7.=l......V0.-o..j?...H..sa......./UCb.'...r...w.i..e..<[....{2..U.m..N.{...r.....3.fj.o......2.*....;.L.6..&,D.Cld8...a.gZf.......r-v..><....~/......|Zk.......a.R&.d.(.$..6..}.:.....3......1..[.p.....?..+....R...y,.fod.....e...-.|..#..]j....n:...f...-J...i.^.:Y....T..........m^..~GNp../e}...N....a..5.d.8YcN..5.d.8Y...7..A..e...7Q."3...../.sL._...v...n..b..2].v....n.t....Z...Uk...j.&.Z....im|.r....B.....7DaBuN.... ...>..>..>..>..>..>..>.........V}-.....Q}#.&T..j...r..]..CZ..CZ..CZ..CZ..CZ..CZ..CZ..i.o.,-k..b....7FaBuN.... ...>..>..>..>..>..>..>.........V}-...Q}..&T..j...r..]..CZ..CZ..CZ..CZ..CZ..CZ..CZ..i.o.,-k..b....7EaBuN.... ...>..>..>..>..>..>..>.........V}-...Q}3.&T..j...r..]..CZ..CZ..CZ..CZ..CZ..CZ..CZ..i.o.,-k..b.\}..)...A.......[..PK..........1A.s@.....O......._rels/.rels...J.1.._%..d...t......}...n2!..}6.>..`(.v...K`2...70...........84P....
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
    Category:dropped
    Size (bytes):282
    Entropy (8bit):3.5459495297497368
    Encrypted:false
    SSDEEP:6:Q+sxnxUXvBAuRELpmlJ0+3FbnKf68dADryMluxHFpwwl:Q+sxnypJymD0wbnKNAH/lMz1
    MD5:76340C3F8A0BFCEDAB48B08C57D9B559
    SHA1:E1A6672681AA6F6D525B1D17A15BF4F912C4A69B
    SHA-256:78FE546321EDB34EBFA1C06F2B6ADE375F3B7C12552AB2A04892A26E121B3ECC
    SHA-512:49099F040C099A0AED88E7F19338140A65472A0F95ED99DEB5FA87587E792A2D11081D59FD6A83B7EE68C164329806511E4F1B8D673BEC9074B4FF1C09E3435D
    Malicious:false
    Reputation:low
    Preview:..[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .D.i.v.i.d.e.n.d...t.h.m.x.....C.o.m.p.o.n.e.n.t.:. .P.P.T.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....E.x.e.c.u.t.a.b.l.e.:. .{.P.P.}.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.....C.o.m.m.a.n.d.:. .{.F.i.l.e.P.a.t.h.}.....
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:Microsoft OOXML
    Category:dropped
    Size (bytes):523048
    Entropy (8bit):7.715248170753013
    Encrypted:false
    SSDEEP:6144:WfmDdN6Zfv8q5rnM6vZ02PtMZRkfW5ipbnMHxVcsOWrCMxy0sD/mcKb4rYEY:xDdQXBrMi2YtggW5ObnMH1brJpUmBU0N
    MD5:C276F590BB846309A5E30ADC35C502AD
    SHA1:CA6D9D6902475F0BE500B12B7204DD1864E7DD02
    SHA-256:782996D93DEBD2AF9B91E7F529767A8CE84ACCC36CD62F24EBB5117228B98F58
    SHA-512:B85165C769DFE037502E125A04CFACDA7F7CC36184B8D0A54C1F9773666FFCC43A1B13373093F97B380871571788D532DEEA352E8D418E12FD7AAD6ADB75A150
    Malicious:false
    Reputation:low
    Preview:PK..........1AE,.{E...#P......[Content_Types].xml..Mo.0.....Z..N7.=l......V0.-o..j?...H..sa......./UCb.'...r...w.i..e..<[....{2..U.m..N.{...r.....3.fj.o......2.*....;.L.6..&,D.Cld8...a.gZf.......r-v..><....~/......|Zk.......a.R&.d.(.$..6..}.:.....3......1..[.p.....?..+....R...y,.fod.....e...-.|..#..]j....n:...f...-J...i.^.:Y....T..........m^..~GNp../e}...N....a..5.d.8YcN..5.d.8Y...7..A..e...7Q."3...../.sL._...v...n..b..2].v....n.t....Z...Uk...j.&.Z....im|.r....B.....7DaBuN.... ...>..>..>..>..>..>..>.........V}-.....Q}#.&T..j...r..]..CZ..CZ..CZ..CZ..CZ..CZ..CZ..i.o.,-k..b....7FaBuN.... ...>..>..>..>..>..>..>.........V}-...Q}..&T..j...r..]..CZ..CZ..CZ..CZ..CZ..CZ..CZ..i.o.,-k..b....7EaBuN.... ...>..>..>..>..>..>..>.........V}-...Q}3.&T..j...r..]..CZ..CZ..CZ..CZ..CZ..CZ..CZ..i.o.,-k..b.\}..)...A.......[..PK..........1A.s@.....O......._rels/.rels...J.1.._%..d...t......}...n2!..}6.>..`(.v...K`2...70...........84P....
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
    Category:dropped
    Size (bytes):276
    Entropy (8bit):3.5159096381406645
    Encrypted:false
    SSDEEP:6:Q+sxnxUXQIa3ARELpmlJ0+3FbnKf68dADryMluxHFpwwl:Q+sxnygIaqymD0wbnKNAH/lMz1
    MD5:71CCB69AF8DD9821F463270FB8CBB285
    SHA1:8FED3EB733A74B2A57D72961F0E4CF8BCA42C851
    SHA-256:8E63D7ABA97DABF9C20D2FAC6EB1665A5D3FDEAB5FA29E4750566424AE6E40B4
    SHA-512:E62FC5BEAEC98C5FDD010FABDAA8D69237D31CA9A1C73F168B1C3ED90B6A9B95E613DEAD50EB8A5B71A7422942F13D6B5A299EB2353542811F2EF9DA7C3A15DC
    Malicious:false
    Reputation:low
    Preview:..[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .F.r.a.m.e...t.h.m.x.....C.o.m.p.o.n.e.n.t.:. .P.P.T.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....E.x.e.c.u.t.a.b.l.e.:. .{.P.P.}.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.....C.o.m.m.a.n.d.:. .{.F.i.l.e.P.a.t.h.}.....
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:Microsoft OOXML
    Category:dropped
    Size (bytes):486596
    Entropy (8bit):7.668294441507828
    Encrypted:false
    SSDEEP:6144:A+JBmUx0Zo24n8z/2NSYFl2qGBuv8p6+LwwYmN59wBttsdJrmXMlP1NwQoGgeL:fNgxz/g5z2BT6+Eu0ntMcczNQG5L
    MD5:0E37AECABDB3FDF8AAFEDB9C6D693D2F
    SHA1:F29254D2476DF70979F723DE38A4BF41C341AC78
    SHA-256:7AC7629142C2508B070F09788217114A70DE14ACDB9EA30CBAB0246F45082349
    SHA-512:DE6AFE015C1D41737D50ADD857300996F6E929FED49CB71BC59BB091F9DAB76574C56DEA0488B0869FE61E563B07EBB7330C8745BC1DF6305594AC9BDEA4A6BF
    Malicious:false
    Reputation:low
    Preview:PK.........V'BE,.{....#P......[Content_Types].xml..`.I.%&/m.{.J.J..t...`.$.@........iG#).*..eVe]f.@....{...{...;.N'...?\fd.l..J..!....?~|.?"....|.{.[..e^7E......Gi..V.by..G..|.......U..t.|..mW...m..|.5.j./..^d-.Y_.]e..E~wog...j...v......?..u....c...W..G.4D_.}T,.@...}....R.Z..4k.....Y..mEkLor.f^..O..P...`.../.|u1..Y.....nK.......u=..2.tu~^L.Y5]/...~+.v...o....j.`?.S...../.by.|..>."kZbs....H.9..m.z.]W.V.?~v........;...N.......w....;.z..N.......w.....R.~n..Ofu.-..K.e....{..A.~.8.#D..)o.7..........:2........=......f...u....[..}...u.6b...xz.[...G..|#...$....)J./.......7.............oQ..]^.M........wy}7a.....&l................w.......l._...l..?.A..........r..9.|.8.........{w...........n...]^.M........wy}7a.....&l.................`..z..`.....2.o...wx}.....>..c.M..Arr#.....nD..[.....w......n...]^.M........wy}7a.....&l........w........... ..Fp....w_Q....g..tL.i.?H.o...]^..........n...]^.M........wy}7a.....&l.................`..z..`
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
    Category:dropped
    Size (bytes):274
    Entropy (8bit):3.535303979138867
    Encrypted:false
    SSDEEP:6:Q+sxnxUX3IlVARELpmlJ0+3FbnKf68dADryMluxHFpwwl:Q+sxnynG6ymD0wbnKNAH/lMz1
    MD5:35AFE8D8724F3E19EB08274906926A0B
    SHA1:435B528AAF746428A01F375226C5A6A04099DF75
    SHA-256:97B8B2E246E4DAB15E494D2FB5F8BE3E6361A76C8B406C77902CE4DFF7AC1A35
    SHA-512:ACF4F124207974CFC46A6F4EA028A38D11B5AF40E55809E5B0F6F5DABA7F6FC994D286026FAC19A0B4E2311D5E9B16B8154F8566ED786E5EF7CDBA8128FD62AF
    Malicious:false
    Reputation:low
    Preview:..[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .V.i.e.w...t.h.m.x.....C.o.m.p.o.n.e.n.t.:. .P.P.T.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....E.x.e.c.u.t.a.b.l.e.:. .{.P.P.}.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.....C.o.m.m.a.n.d.:. .{.F.i.l.e.P.a.t.h.}.....
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:Microsoft OOXML
    Category:dropped
    Size (bytes):777647
    Entropy (8bit):7.689662652914981
    Encrypted:false
    SSDEEP:6144:B04bNOJMngI856k0wwOGXMaXTLaTDmfBaN2Tx9iSUk1PdSnc0lnDlcGMcEFYYYYt:xbY6ngI46Aw5dmyYYYYYYYYY7p8d
    MD5:B30D2EF0FC261AECE90B62E9C5597379
    SHA1:4893C5B9BE04ECBB19EE45FFCE33CA56C7894FE3
    SHA-256:BB170D6DE4EE8466F56C93DC26E47EE8A229B9C4842EA8DD0D9CCC71BC8E2976
    SHA-512:2E728408C20C3C23C84A1C22DB28F0943AAA960B4436F8C77570448D5BEA9B8D53D95F7562883FA4F9B282DFE2FD07251EEEFDE5481E49F99B8FEDB66AAAAB68
    Malicious:false
    Reputation:low
    Preview:PK.........V'B.._<....-.......[Content_Types].xml..`.I.%&/m.{.J.J..t...`.$.@........iG#).*..eVe]f.@....{...{...;.N'...?\fd.l..J..!....?~|.?"....|.{.[..e^7E......Gi..V.by..G..|.......U..t.|..mW...m..|.5.j./..^d-.Y_.]e..E~wog...j...v......?..u....c...W..G.4D_.}T,.@...}....R.Z..4k.....Y..mEkLor.f^..O..P...`.../.|u1..Y.....nK.......u=..2.tu~^L.Y5]/...~+.v...o....j.`?.S...../.by.|..>."kZbs....H.9..m.z.]W.V.?~v........;...N.......w....;.z..N.......w.....R.~n..Ofu.-..K.e....{..A.~.8.#D..)o.7..........:2........=......f...u....[..}...u.6b...xz.[...G..|#...$....)J./.......7.............oQ..]^.M........wy}7a.....&l................w.......l._...l..?.A..........r..9.|.8.........{w...........n...]^.M........wy}7a.....&l.................`..z..`.....2.o...wx}.....>..c.M..Arr#.....nD..[.....w......n...]^.M........wy}7a.....&l........w........... ..Fp....w_Q....g..tL.i.?H.o...]^..........n...]^.M........wy}7a.....&l.................`..z..`
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
    Category:dropped
    Size (bytes):290
    Entropy (8bit):3.5091498509646044
    Encrypted:false
    SSDEEP:6:Q+sxnxUX1MiDuRELpmlJ0+3FbnKf68dADryMluxHFpwwl:Q+sxnyFdMymD0wbnKNAH/lMz1
    MD5:23D59577F4AE6C6D1527A1B8CDB9AB19
    SHA1:A345D683E54D04CC0105C4BFFCEF8C6617A0093D
    SHA-256:9ADD2C3912E01C2AC7FAD6737901E4EECBCCE6EC60F8E4D78585469A440E1E2C
    SHA-512:B85027276B888548ECB8A2FC1DB1574C26FF3FCA7AF1F29CD5074EC3642F9EC62650E7D47462837607E11DCAE879B1F83DF4762CA94667AE70CBF78F8D455346
    Malicious:false
    Reputation:low
    Preview:..[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .M.e.t.r.o.p.o.l.i.t.a.n...t.h.m.x.....C.o.m.p.o.n.e.n.t.:. .P.P.T.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....E.x.e.c.u.t.a.b.l.e.:. .{.P.P.}.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.....C.o.m.m.a.n.d.:. .{.F.i.l.e.P.a.t.h.}.....
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:Microsoft OOXML
    Category:dropped
    Size (bytes):558035
    Entropy (8bit):7.696653383430889
    Encrypted:false
    SSDEEP:12288:DQ/oYjRRRRRRRRYcdY/5ASWYqBMp8xsGGEOzI7vQQwOyP:DQ/nRRRRRRRRxY/5JWYZ3GGbI8YA
    MD5:3B5E44DDC6AE612E0346C58C2A5390E3
    SHA1:23BCF3FCB61F80C91D2CFFD8221394B1CB359C87
    SHA-256:9ED9AD4EB45E664800A4876101CBEE65C232EF478B6DE502A330D7C89C9AE8E2
    SHA-512:2E63419F272C6E411CA81945E85E08A6E3230A2F601C4D28D6312DB5C31321F94FAFA768B16BC377AE37B154C6869CA387005693A79C5AB1AC45ED73BCCC6479
    Malicious:false
    Reputation:low
    Preview:PK..........1AE,.{E...#P......[Content_Types].xml..Mo.0.....Z..N7.=l......V0.-o..j?...H..sa......./UCb.'...r...w.i..e..<[....{2..U.m..N.{...r.....3.fj.o......2.*....;.L.6..&,D.Cld8...a.gZf.......r-v..><....~/......|Zk.......a.R&.d.(.$..6..}.:.....3......1..[.p.....?..+....R...y,.fod.....e...-.|..#..]j....n:...f...-J...i.^.:Y....T..........m^..~GNp../e}...N....a..5.d.8YcN..5.d.8Y...7..A..e...7Q."3...../.sL._...v...n..b..2].v....n.t....Z...Uk...j.&.Z....im|.r....B.....7DaBuN.... ...>..>..>..>..>..>..>.........V}-.....Q}#.&T..j...r..]..CZ..CZ..CZ..CZ..CZ..CZ..CZ..i.o.,-k..b....7FaBuN.... ...>..>..>..>..>..>..>.........V}-...Q}..&T..j...r..]..CZ..CZ..CZ..CZ..CZ..CZ..CZ..i.o.,-k..b....7EaBuN.... ...>..>..>..>..>..>..>.........V}-...Q}3.&T..j...r..]..CZ..CZ..CZ..CZ..CZ..CZ..CZ..i.o.,-k..b.\}..)...A.......[..PK..........1A.s@.....O......._rels/.rels...J.1.._%..d...t......}...n2!..}6.>..`(.v...K`2...70...........84P....
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
    Category:dropped
    Size (bytes):276
    Entropy (8bit):3.5361139545278144
    Encrypted:false
    SSDEEP:6:Q+sxnxUXeMWMluRELpmlJ0+3FbnKf68dADryMluxHFpwwl:Q+sxnycMlMymD0wbnKNAH/lMz1
    MD5:133D126F0DE2CC4B29ECE38194983265
    SHA1:D8D701298D7949BE6235493925026ED405290D43
    SHA-256:08485EBF168364D846C6FD55CD9089FE2090D1EE9D1A27C1812E1247B9005E68
    SHA-512:75D7322BE8A5EF05CAA48B754036A7A6C56399F17B1401F3F501DA5F32B60C1519F2981043A773A31458C3D9E1EF230EC60C9A60CAC6D52FFE16147E2E0A9830
    Malicious:false
    Reputation:low
    Preview:..[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .B.a.s.i.s...t.h.m.x.....C.o.m.p.o.n.e.n.t.:. .P.P.T.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....E.x.e.c.u.t.a.b.l.e.:. .{.P.P.}.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.....C.o.m.m.a.n.d.:. .{.F.i.l.e.P.a.t.h.}.....
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:Microsoft OOXML
    Category:dropped
    Size (bytes):1649585
    Entropy (8bit):7.875240099125746
    Encrypted:false
    SSDEEP:24576:L368X6z95zf5BbQ6U79dYy2HiTIxRboyM/LZTl5KnCc:r68kb7UTYxGIxmnp65
    MD5:35200E94CEB3BB7A8B34B4E93E039023
    SHA1:5BB55EDAA4CDF9D805E36C36FB092E451BDDB74D
    SHA-256:6CE04E8827ABAEA9B292048C5F84D824DE3CEFDB493101C2DB207BD4475AF1FD
    SHA-512:ED80CEE7C22D10664076BA7558A79485AA39BE80582CEC9A222621764DAE5EFA70F648F8E8C5C83B6FE31C2A9A933C814929782A964A47157505F4AE79A3E2F9
    Malicious:false
    Reputation:low
    Preview:PK..........1A..u._....P......[Content_Types].xml..Ms.@.....!...=.7....;a.h.&Y..l..H~..`;...d..g/..e..,M..C...5...#g/."L..;...#. ]..f...w../._.2Y8..X.[..7._.[...K3..#.4......D.]l.?...~.&J&....p..wr-v.r.?...i.d.:o....Z.a|._....|.d...A....A".0.J......nz....#.s.m.......(.]........~..XC..J......+.|...(b}...K!._.D....uN....u..U..b=.^..[...f...f.,...eo..z.8.mz....."..D..SU.}ENp.k.e}.O.N....:^....5.d.9Y.N..5.d.q.^s..}R...._E..D...o..o...o...f.6;s.Z]...Uk6d.j..MW....5[C].f#...l;u.M..Z.../iM|...b...S.....0.zN.... ...>..>..>..>..>..>..>........e...,..7...F(L.....>.ku...i...i...i...i...i...i...i........yi.....G...1.....j...r.Z]..CZ..CZ..CZ..CZ..CZ..CZ..CZ..i.o|^Z....Q}.;.o...9.Z..\.V...............................jZ......k.pT...0.zN.... ...>..>..>..>..>..>..>........e...,..7...f(L.....>.ku...i...i...i...i...i...i...i........yi.......n.....{.._f...0...PK..........1A.s@.....O......._rels/.rels...J.1.._%..d...t......}...n2!..}6.>..`(.v...
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
    Category:dropped
    Size (bytes):284
    Entropy (8bit):3.5552837910707304
    Encrypted:false
    SSDEEP:6:Q+sxnxUXtLARELpmlJ0+3FbnKf68dADryMluxHFpwwl:Q+sxnygymD0wbnKNAH/lMz1
    MD5:5728F26DF04D174DE9BDFF51D0668E2A
    SHA1:C998DF970655E4AF9C270CC85901A563CFDBCC22
    SHA-256:979DAFD61C23C185830AA3D771EDDC897BEE87587251B84F61776E720ACF9840
    SHA-512:491B36AC6D4749F7448B9A3A6E6465E8D97FB30F33EF5019AF65660E98F4570711EFF5FC31CBB8414AD9355029610E6F93509BC4B2FB6EA79C7CB09069DE7362
    Malicious:false
    Reputation:low
    Preview:..[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .W.o.o.d._.T.y.p.e...t.h.m.x.....C.o.m.p.o.n.e.n.t.:. .P.P.T.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....E.x.e.c.u.t.a.b.l.e.:. .{.P.P.}.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.....C.o.m.m.a.n.d.:. .{.F.i.l.e.P.a.t.h.}.....
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:Zip archive data, at least v2.0 to extract, compression method=deflate
    Category:dropped
    Size (bytes):924687
    Entropy (8bit):7.824849396154325
    Encrypted:false
    SSDEEP:12288:lsadD3eLxI8XSh4yDwFw8oWR+6dmw2ZpQDKpazILv7Jzny/ApcWqyOpEZULn:qLxI8XSh4yUF/oWR+mLKpYIr7l3ZQ7n
    MD5:97EEC245165F2296139EF8D4D43BBB66
    SHA1:0D91B68CCB6063EB342CFCED4F21A1CE4115C209
    SHA-256:3C5CF7BDB27592791ADF4E7C5A09DDE4658E10ED8F47845064DB1153BE69487C
    SHA-512:8594C49CAB6FF8385B1D6E174431DAFB0E947A8D7D3F200E622AE8260C793906E17AA3E6550D4775573858EA1243CCBF7132973CD1CF7A72C3587B9691535FF8
    Malicious:false
    Reputation:low
    Preview:PK..........1AS'......ip......[Content_Types].xml..n.@.._......8ie'......}.......(y...H}......3Fi..%2.v?..3..._...d=..E.g.....7.i.-.t5.6......}}.m9r.......m...ML.g.M.eV$.r..*.M..l0...A...M..j;.w={o.f..F....i..v......5..d;..D.ySa...M&..qd*w>.O.{h...|w..5.]..'.CS<.:8C}.g.|E.../..>..].Tnml..I.......r.Gv.E....7.;.E......4/l.....6.K.C?1qz.O.v_..r......\c.c.>..lS........X.N.3N.sN..N.)'.%'..'..N.pL.E...T.!..CR....Ie..k.o..M..w.B.0}..3....v..+....,.q..pz.......v{.;....s3.|..V..ZZ......0.[.....x.....!.!~.8.e..n..&.}p....s.i.. ..[]...q.r....~..+.A\...q............e.-)h9..."Z.>...5-C..`..g.}........r.A.+..\...r.>.... .W.\...re?..%.-/hiA..ZR.r.W.D.\}.EK..kZ.>......5..9.&T......Wlu.b....}..+.A\...q......~.WK.Z^..........>.h..`......}.....^h....L...H...!...r.>... .W...\...rE?............-+hIA..\}..r...-}..i..`..G..j..).&T......Wlu.b....}..+.A\...q......~.WK.Z^..........>.h..`......}.....^j..K.L...H...!...r.>... .W...\...rE?............-+hIA..\}..r...-}..i.
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
    Category:dropped
    Size (bytes):282
    Entropy (8bit):3.51145753448333
    Encrypted:false
    SSDEEP:6:Q+sxnxUXKsWkRELpmlJ0+3FbnKf68dADryMluxHFpwwl:Q+sxny6svymD0wbnKNAH/lMz1
    MD5:7956D2B60E2A254A07D46BCA07D0EFF0
    SHA1:AF1AC8CA6FE2F521B2EE2B7ABAB612956A65B0B5
    SHA-256:C92B7FD46B4553FF2A656FF5102616479F3B503341ED7A349ECCA2E12455969E
    SHA-512:668F5D0EFA2F5168172E746A6C32820E3758793CFA5DB6791DE39CB706EF7123BE641A8134134E579D3E4C77A95A0F9983F90E44C0A1CF6CDE2C4E4C7AF1ECA0
    Malicious:false
    Reputation:low
    Preview:..[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .P.a.r.a.l.l.a.x...t.h.m.x.....C.o.m.p.o.n.e.n.t.:. .P.P.T.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....E.x.e.c.u.t.a.b.l.e.:. .{.P.P.}.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.....C.o.m.m.a.n.d.:. .{.F.i.l.e.P.a.t.h.}.....
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:Microsoft OOXML
    Category:dropped
    Size (bytes):976001
    Entropy (8bit):7.791956689344336
    Encrypted:false
    SSDEEP:24576:zHM7eZGgFiHMRej4N9tpytNZ+tIw5ErZBImlX0m:zHM7eZGgFiHMRej++NZ+F5WvllZ
    MD5:9E563D44C28B9632A7CF4BD046161994
    SHA1:D3DB4E5F5B1CC6DD08BB3EBF488FF05411348A11
    SHA-256:86A70CDBE4377C32729FD6C5A0B5332B7925A91C492292B7F9C636321E6FAD86
    SHA-512:8EB14A1B10CB5C7607D3E07E63F668CFC5FC345B438D39138D62CADF335244952FBC016A311D5CB8A71D50660C49087B909528FC06C1D10AF313F904C06CBD5C
    Malicious:false
    Reputation:low
    Preview:PK.........{MB.f}......p......[Content_Types].xml..`.I.%&/m.{.J.J..t...`.$.@........iG#).*..eVe]f.@....{...{...;.N'...?\fd.l..J..!....?~|.?"....|.{.[..e^7E......Gi..V.by..G..|.......U..t.|..mW...m..|.5.j./..^d-.Y_.]e..E~wog...j...v......?..u....c.v...(=.v........F_..U..G...T.e.y)[..b.......3.m....6.X5.P........_...b../..}.-......~.-..z..d.......j.^.+c..E.V..~3}..U.7..~p.>.E..9^d....4%}.E.$....N..r....<....%...%.?....w.u...h........D...w.....h........Dkw...x..T....T....T....T....T....T....j...."[.J.....;..!4...M...............t.n-.{..skp...[;.......F...j.7...4fC...K1..K/..K-..K+..K)..K'..f9......Fl._.........d0...?7K7].........A.......Fl.............Ft....u.......Ft........\.......w....R.......R.......R........o...].`.....A....#.`..\.....S.._...4...o.........W<x#..............w#...r.nD..]....\.~....|......b...^...Z...V...R...N..W<x......l._...l..?.A......xp_Q..y<h..tL.i.?HNn...]..........r.nD..]~.........wy~7......Ft...........E/|c.
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
    Category:dropped
    Size (bytes):278
    Entropy (8bit):3.5270134268591966
    Encrypted:false
    SSDEEP:6:Q+sxnxUXa3Y1kRELpmlJ0+3FbnKf68dADryMluxHFpwwl:Q+sxnyt1mymD0wbnKNAH/lMz1
    MD5:327DA4A5C757C0F1449976BE82653129
    SHA1:CF74ECDF94B4A8FD4C227313C8606FD53B8EEA71
    SHA-256:341BABD413AA5E8F0A921AC309A8C760A4E9BA9CFF3CAD3FB2DD9DF70FD257A6
    SHA-512:9184C3FB989BB271B4B3CDBFEFC47EA8ABEB12B8904EE89797CC9823F33952BD620C061885A5C11BBC1BD3978C4B32EE806418F3F21DA74F1D2DB9817F6E167E
    Malicious:false
    Reputation:low
    Preview:..[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .B.e.r.l.i.n...t.h.m.x.....C.o.m.p.o.n.e.n.t.:. .P.P.T.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....E.x.e.c.u.t.a.b.l.e.:. .{.P.P.}.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.....C.o.m.m.a.n.d.:. .{.F.i.l.e.P.a.t.h.}.....
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:Microsoft OOXML
    Category:dropped
    Size (bytes):608122
    Entropy (8bit):7.729143855239127
    Encrypted:false
    SSDEEP:6144:Ckl6KRKwg9jf2q/bN69OuGFlC/DUhq68xOcJzGYnTxlLqU8dmTW:8yKwgZ2qY9kA7Uhq68H3ybmq
    MD5:8BA551EEC497947FC39D1D48EC868B54
    SHA1:02FA15FDAF0D7E2F5D44CAE5FFAE49E8F91328DF
    SHA-256:DB2E99B969546E431548EBD58707FC001BBD1A4BDECAD387D194CC9C6D15AC89
    SHA-512:CC97F9B2C83FF7CAC32AB9A9D46E0ACDE13EECABECD653C88F74E4FC19806BB9498D2F49C4B5581E58E7B0CB95584787EA455E69D99899381B592BEA177D4D4B
    Malicious:false
    Reputation:low
    Preview:PK.........LGE,.{E...#P......[Content_Types].xml..Mo.0.....Z..N7.=l......V0.-o..j?...H..sa......./UCb.'...r...w.i..e..<[....{2..U.m..N.{...r.....3.fj.o......2.*....;.L.6..&,D.Cld8...a.gZf.......r-v..><....~/......|Zk.......a.R&.d.(.$..6..}.:.....3......1..[.p.....?..+....R...y,.fod.....e...-.|..#..]j....n:...f...-J...i.^.:Y....T..........m^..~GNp../e}...N....a..5.d.8YcN..5.d.8Y...7..A..e...7Q."3...../.sL._...v...n..b..2].v....n.t....Z...Uk...j.&.Z....im|.r....B.....7DaBuN.... ...>..>..>..>..>..>..>.........V}-.....Q}#.&T..j...r..]..CZ..CZ..CZ..CZ..CZ..CZ..CZ..i.o.,-k..b....7FaBuN.... ...>..>..>..>..>..>..>.........V}-...Q}..&T..j...r..]..CZ..CZ..CZ..CZ..CZ..CZ..CZ..i.o.,-k..b....7EaBuN.... ...>..>..>..>..>..>..>.........V}-...Q}3.&T..j...r..]..CZ..CZ..CZ..CZ..CZ..CZ..CZ..i.o.,-k..b.\}..)...A.......[..PK.........LG.s@.....O......._rels/.rels...J.1.._%..d...t......}...n2!..}6.>..`(.v...K`2...70...........84P....
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
    Category:dropped
    Size (bytes):278
    Entropy (8bit):3.516359852766808
    Encrypted:false
    SSDEEP:6:Q+sxnxUXKwRELpmlJ0+3FbnKf68dADryMluxHFpwwl:Q+sxny6qymD0wbnKNAH/lMz1
    MD5:960E28B1E0AB3522A8A8558C02694ECF
    SHA1:8387E9FD5179A8C811CCB5878BAC305E6A166F93
    SHA-256:2707FCA8CEC54DF696F19F7BCAD5F0D824A2AC01B73815DE58F3FCF0AAB3F6A0
    SHA-512:89EA06BA7D18B0B1EA624BBC052F73366522C231BD3B51745B92CF056B445F9D655F9715CBDCD3B2D02596DB4CD189D91E2FE581F2A2AA2F6D814CD3B004950A
    Malicious:false
    Reputation:low
    Preview:..[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .P.a.r.c.e.l...t.h.m.x.....C.o.m.p.o.n.e.n.t.:. .P.P.T.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....E.x.e.c.u.t.a.b.l.e.:. .{.P.P.}.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.....C.o.m.m.a.n.d.:. .{.F.i.l.e.P.a.t.h.}.....
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:Microsoft OOXML
    Category:dropped
    Size (bytes):966946
    Entropy (8bit):7.8785200658952
    Encrypted:false
    SSDEEP:24576:qBcvGBGhXQir6H1ws6+iU0YuA35VuinHX2NPs:ccvGBGdQ5CsMxQVj3yPs
    MD5:F03AB824395A8F1F1C4F92763E5C5CAD
    SHA1:A6E021918C3CEFFB6490222D37ECEED1FC435D52
    SHA-256:D96F7A63A912CA058FB140138C41DCB3AF16638BA40820016AF78DF5D07FAEDD
    SHA-512:0241146B63C938F11045FB9DF5360F63EF05B9B3DD1272A3E3E329A1BFEC5A4A645D5472461DE9C06CFE4ADB991FE96C58F0357249806C341999C033CD88A7AF
    Malicious:false
    Reputation:low
    Preview:PK..........1A.......F`......[Content_Types].xml..n.@.._.y.ac $..,........-..g@.u.G.+t.:........D1...itgt>...k..lz;].8Kg^....N.l..........0.~}....ykk.A`..N..\...2+.e.c..r..P+....I.e.......|.^/.vc{......s..z....f^...8...'.zcN&.<....}.K.'h..X..y.c.qnn.s%...V('~v.W.......I%nX`.....G.........r.Gz.E..M.."..M....6n.a..V.K6.G?Qqz..............\e.K.>..lkM...`...k.5...sb.rbM8..8..9..pb..R..{>$..C.>......X..iw.'..a.09CPk.n...v....5n..Uk\...SC...j.Y.....Vq..vk>mi......z..t....v.]...n...e(.....s.i......]...q.r....~.WV/.j.Y......K..-.. Z..@.\.P..W...A..X8.`$C.F(.P..H...W..r.>... .W.C..zAV+.....@.\..h....r)...R..-..........c..0F...@Z.....v.+.A\...q.......ZAV'p)...R.D....K..-...h....eP..........(.P..H...W..r.>... .W.C..zAV+.....@.\..h....r)...R..-.............0A...@Z.....v.+.A\...q.......ZAV'p)...R.D....K..-...h....eP.........w(.P..H...W..r.>... .W.C..zAV+.....@.\..h....r)...R..-..........T..GI..~.....~....PK..........1A.s@.....O......._rels/.rels...J.
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
    Category:dropped
    Size (bytes):282
    Entropy (8bit):3.5323495192404475
    Encrypted:false
    SSDEEP:6:Q+sxnxUXhduDARELpmlJ0+3FbnKf68dADryMluxHFpwwl:Q+sxnyxdumymD0wbnKNAH/lMz1
    MD5:BD6B5A98CA4E6C5DBA57C5AD167EDD00
    SHA1:CCFF7F635B31D12707DC0AC6D1191AB5C4760107
    SHA-256:F22248FE60A55B6C7C1EB31908FAB7726813090DE887316791605714E6E3CEF7
    SHA-512:A178299461015970AF23BA3D10E43FCA5A6FB23262B0DD0C5DDE01D338B4959F222FD2DC2CC5E3815A69FDDCC3B6B4CB8EE6EC0883CE46093C6A59FF2B042BC1
    Malicious:false
    Reputation:low
    Preview:..[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .Q.u.o.t.a.b.l.e...t.h.m.x.....C.o.m.p.o.n.e.n.t.:. .P.P.T.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....E.x.e.c.u.t.a.b.l.e.:. .{.P.P.}.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.....C.o.m.m.a.n.d.:. .{.F.i.l.e.P.a.t.h.}.....
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:Microsoft OOXML
    Category:dropped
    Size (bytes):1204049
    Entropy (8bit):7.92476783994848
    Encrypted:false
    SSDEEP:24576:+3zSQBxvOUIpHLYTCEmS1Wu09jRalJP3sdgnmAOFt0zU4L0MRx5QNn5:+bvI5UTCPu09qP3JPOFoR4N5
    MD5:FD5BBC58056522847B3B75750603DF0C
    SHA1:97313E85C0937739AF7C7FC084A10BF202AC9942
    SHA-256:44976408BD6D2703BDBE177259061A502552193B1CD05E09B698C0DAC3653C5F
    SHA-512:DBD72827044331215A7221CA9B0ECB8809C7C79825B9A2275F3450BAE016D7D320B4CA94095F7CEF4372AC63155C78CA4795E23F93166D4720032ECF9F932B8E
    Malicious:false
    Reputation:low
    Preview:PK..........1A..d T....P......[Content_Types].xml..Ms.@.....!...=.7....kX 5o.,L..<..........d..g/..dw.]...C...9...#g/."L..;...#. ]..f...w../._.3Y8..X.[..7._.[...K3..3.4......D.]l.?...~.&J&...s...;...H9...e.3.q.....k-.0>Lp:.7..eT...Y...P...OVg.....G..).aV...\Z.x...W.>f...oq.8.....I?Ky...g..."...J?....A$zL.].7.M.^..\....C..d/;.J0.7k.X4.e..?N{....r.."LZx.H?. ......;r.+...A<.;U.....4...!'k...s.&..)'k...d..d......._E..D...o..o...o...f.7;s..]...Uk6d.j..MW....5[C].f#...l;u.M..Z.../iM|...b...s.....0..O.... ...>..>..>..>..>..>..>.........2V}......Q}#.&T...rU....\..\..\..\..\..\..\..\.W..W.^Z....Q}c;.o...>.Z..\.v...............................*Z....K.X.5X8.obG.MP.P.'P.U}.k..rU..rU..rU..rU..rU..rU..rU..rU_EK_}.zi.....G.M.).....j...r..]..CZ..CZ..CZ..CZ..CZ..CZ..CZ..h.oZ/-c..`....7CaBu.@-W.A.]..U}H.U}H.U}H.U}H.U}H.U}H.U}H.U}.-}...e...,...|...].k.........PK..........1A.s@.....O......._rels/.rels...J.1.._%..d...t......}...n2!..}6.>..`(.v...K`2...70...
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
    Category:dropped
    Size (bytes):276
    Entropy (8bit):3.5364757859412563
    Encrypted:false
    SSDEEP:6:Q+sxnxUXARkRELpmlJ0+3FbnKf68dADryMluxHFpwwl:Q+sxnywMymD0wbnKNAH/lMz1
    MD5:CD465E8DA15E26569897213CA9F6BC9C
    SHA1:9EA9B5E6C9B7BF72A777A21EC17FD82BC4386D4C
    SHA-256:D4109317C2DBA1D7A94FC1A4B23FA51F4D0FC8E1D9433697AAFA72E335192610
    SHA-512:869A42679F96414FE01FE1D79AF7B33A0C9B598B393E57E0E4D94D68A4F2107EC58B63A532702DA96A1F2F20CE72E6E08125B38745CD960DF62FE539646EDD8D
    Malicious:false
    Reputation:low
    Preview:..[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .S.a.v.o.n...t.h.m.x.....C.o.m.p.o.n.e.n.t.:. .P.P.T.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....E.x.e.c.u.t.a.b.l.e.:. .{.P.P.}.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.....C.o.m.m.a.n.d.:. .{.F.i.l.e.P.a.t.h.}.....
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:Zip archive data, at least v2.0 to extract, compression method=deflate
    Category:dropped
    Size (bytes):1463634
    Entropy (8bit):7.898382456989258
    Encrypted:false
    SSDEEP:24576:75MGNW/UpLkupMAqDJhNHK4/TuiKbdhbZM+byLH/:7ZwUpLkulkHK46iiDZHeLH/
    MD5:ACBA78931B156E4AF5C4EF9E4AB3003B
    SHA1:2A1F506749A046ECFB049F23EC43B429530EC489
    SHA-256:943E4044C40ABA93BD7EA31E8B5EBEBD7976085E8B1A89E905952FA8DAC7B878
    SHA-512:2815D912088BA049F468CA9D65B92F8951A9BE82AB194DBFACCF0E91F0202820F5BC9535966654D28F69A8B92D048808E95FEA93042D8C5DEA1DCB0D58BE5175
    Malicious:false
    Reputation:low
    Preview:PK.........{MB.f}......p......[Content_Types].xml..`.I.%&/m.{.J.J..t...`.$.@........iG#).*..eVe]f.@....{...{...;.N'...?\fd.l..J..!....?~|.?"....|.{.[..e^7E......Gi..V.by..G..|.......U..t.|..mW...m..|.5.j./..^d-.Y_.]e..E~wog...j...v......?..u....c.v...(=.v........F_..U..G...T.e.y)[..b.......3.m....6.X5.P........_...b../..}.-......~.-..z..d.......j.^.+c..E.V..~3}..U.7..~p.>.E..9^d....4%}.E.$....N..r....<....%...%.?....w.u...h........D...w.....h........Dkw...x..T....T....T....T....T....T....j...."[.J.....;..!4...M...............t.n-.{..skp...[;.......F...j.7...4fC...K1..K/..K-..K+..K)..K'..f9......Fl._.........d0...?7K7].........A.......Fl.............Ft....u.......Ft........\.......w....R.......R.......R........o...].`.....A....#.`..\.....S.._...4...o.........W<x#..............w#...r.nD..]....\.~....|......b...^...Z...V...R...N..W<x......l._...l..?.A......xp_Q..y<h..tL.i.?HNn...]..........r.nD..]~.........wy~7......Ft...........E/|c.
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
    Category:dropped
    Size (bytes):280
    Entropy (8bit):3.5286004619027067
    Encrypted:false
    SSDEEP:6:Q+sxnxUXOzXkRELpmlJ0+3FbnKf68dADryMluxHFpwwl:Q+sxny6WymD0wbnKNAH/lMz1
    MD5:40FF521ED2BA1B015F17F0B0E5D95068
    SHA1:0F29C084311084B8FDFE67855884D8EB60BDE1A6
    SHA-256:CC3575BA195F0F271FFEBA6F6634BC9A2CF5F3BE448F58DBC002907D7C81CBBB
    SHA-512:9507E6145417AC730C284E58DC6B2063719400B395615C40D7885F78F57D55B251CB9C954D573CB8B6F073E4CEA82C0525AE90DEC68251C76A6F1B03FD9943C0
    Malicious:false
    Reputation:low
    Preview:..[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .C.i.r.c.u.i.t...t.h.m.x.....C.o.m.p.o.n.e.n.t.:. .P.P.T.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....E.x.e.c.u.t.a.b.l.e.:. .{.P.P.}.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.....C.o.m.m.a.n.d.:. .{.F.i.l.e.P.a.t.h.}.....
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:Microsoft OOXML
    Category:dropped
    Size (bytes):1091485
    Entropy (8bit):7.906659368807194
    Encrypted:false
    SSDEEP:24576:oBpmCkw3Tg/euEB+UdoC4k7ytHkHA6B/puqW2MIkTeSBmKrZHQ:MR3c/AseydwppC7veSBmWHQ
    MD5:2192871A20313BEC581B277E405C6322
    SHA1:1F9A6A5E10E1C3FFEB6B6725C5D2FA9ECDF51085
    SHA-256:A06B302954A4C9A6A104A8691864A9577B0BFEA240B0915D9BEA006E98CDFFEC
    SHA-512:6D8844D2807BB90AEA6FE0DDDB9C67542F587EC9B7FC762746164B2D4A1A99EF8368A70C97BAD7A986AAA80847F64408F50F4707BB039FCCC509133C231D53B9
    Malicious:false
    Reputation:low
    Preview:PK...........G`.jaV....P......[Content_Types].xml...n.@...W......T@.mwM.E....)....y...H}.N..ll8.h5g6Q.=3_......?...x..e^Di.p.^.ud...(Y/..{w..r..9.../M...Q*{..E...(.4..>..y,.>..~&..b-.a.?..4Q2Q=.2.......m....>-....;]......N'..A...g.D.m.@(}..'.3Z....#....(+....-q<uq.+....?....1.....Y?Oy......O"..J?....Q$zT.].7.N..Q Wi.....<.........-..rY....hy.x[9.b.%-<.V?.(......;r.+...Q<.;U.....4...!'k...s.&..)'k...d.s..}R....o".D.I..7..7.KL.7..Z.....v..b.5.2].f....l.t....Z...Uk...j.&.U-....&>.ia1..9lhG..Q.P.'P.U}.k..rU..rU..rU..rU..rU..rU..rU..rU_EK_}.zi.....G.........j...r..]..CZ..CZ..CZ..CZ..CZ..CZ..CZ..h.oT/-c..`....7FaBu.@-W.A.]..U}H.U}H.U}H.U}H.U}H.U}H.U}H.U}.-}...e...,..7...&(L.....>.kw...i...i...i...i...i...i...i.......I...U_.....vT.....}..\...v..W.!-W.!-W.!-W.!-W.!-W.!-W.!-W.U...7.....k.pT...0..O.... ...>..>..>..>..>..>..>......f..2V}....W>jO....5..].?.o..oPK...........G.s@.....O......._rels/.rels...J.1.._%..d...t......}...n2!..}6.>..`(.v...K`2...70.
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
    Category:dropped
    Size (bytes):280
    Entropy (8bit):3.5301133500353727
    Encrypted:false
    SSDEEP:6:Q+sxnxUXp2pRELpmlJ0+3FbnKf68dADryMluxHFpwwl:Q+sxnyZ2vymD0wbnKNAH/lMz1
    MD5:1C5D58A5ED3B40486BC22B254D17D1DD
    SHA1:69B8BB7B0112B37B9B5F9ADA83D11FBC99FEC80A
    SHA-256:EBE031C340F04BB0235FE62C5A675CF65C5CC8CE908F4621A4F5D7EE85F83055
    SHA-512:4736E4F26C6FAAB47718945BA54BD841FE8EF61F0DBA927E5C4488593757DBF09689ABC387A8A44F7C74AA69BA89BEE8EA55C87999898FEFEB232B1BA8CC7086
    Malicious:false
    Reputation:low
    Preview:..[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .G.a.l.l.e.r.y...t.h.m.x.....C.o.m.p.o.n.e.n.t.:. .P.P.T.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....E.x.e.c.u.t.a.b.l.e.:. .{.P.P.}.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.....C.o.m.m.a.n.d.:. .{.F.i.l.e.P.a.t.h.}.....
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:Microsoft OOXML
    Category:dropped
    Size (bytes):1750795
    Entropy (8bit):7.892395931401988
    Encrypted:false
    SSDEEP:24576:DyeAqDJpUDH3xk8ZKIBuX3TPtd36v4o5d4PISMETGBP6eUP+xSeW3v0HKPsc:uRqUjSTPtd36AFDM/BP6eUeW3v0Fc
    MD5:529795E0B55926752462CBF32C14E738
    SHA1:E72DFF8354DF2CB6A5698F14BBD1805D72FEEAFF
    SHA-256:8D341D1C24176DC6B67104C2AF90FABD3BFF666CCC0E269381703D7659A6FA05
    SHA-512:A51F440F1E19C084D905B721D0257F7EEE082B6377465CB94E677C29D4E844FD8021D0B6BA26C0907B72B84157C60A3EFEDFD96C16726F6ABEA8D896D78B08CE
    Malicious:false
    Reputation:low
    Preview:PK.........{MB.f}......p......[Content_Types].xml..`.I.%&/m.{.J.J..t...`.$.@........iG#).*..eVe]f.@....{...{...;.N'...?\fd.l..J..!....?~|.?"....|.{.[..e^7E......Gi..V.by..G..|.......U..t.|..mW...m..|.5.j./..^d-.Y_.]e..E~wog...j...v......?..u....c.v...(=.v........F_..U..G...T.e.y)[..b.......3.m....6.X5.P........_...b../..}.-......~.-..z..d.......j.^.+c..E.V..~3}..U.7..~p.>.E..9^d....4%}.E.$....N..r....<....%...%.?....w.u...h........D...w.....h........Dkw...x..T....T....T....T....T....T....j...."[.J.....;..!4...M...............t.n-.{..skp...[;.......F...j.7...4fC...K1..K/..K-..K+..K)..K'..f9......Fl._.........d0...?7K7].........A.......Fl.............Ft....u.......Ft........\.......w....R.......R.......R........o...].`.....A....#.`..\.....S.._...4...o.........W<x#..............w#...r.nD..]....\.~....|......b...^...Z...V...R...N..W<x......l._...l..?.A......xp_Q..y<h..tL.i.?HNn...]..........r.nD..]~.........wy~7......Ft...........E/|c.
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
    Category:dropped
    Size (bytes):280
    Entropy (8bit):3.528155916440219
    Encrypted:false
    SSDEEP:6:Q+sxnxUXcmlDuRELpmlJ0+3FbnKf68dADryMluxHFpwwl:Q+sxnyMmloymD0wbnKNAH/lMz1
    MD5:AA7B919B21FD42C457948DE1E2988CB3
    SHA1:19DA49CF5540E5840E95F4E722B54D44F3154E04
    SHA-256:5FFF5F1EC1686C138192317D5A67E22A6B02E5AAE89D73D4B19A492C2F5BE2F9
    SHA-512:01D27377942F69A0F2FE240DD73A1F97BB915E19D3D716EE4296C6EF8D8933C80E4E0C02F6C9FA72E531246713364190A2F67F43EDBE12826A1529BC2A629B00
    Malicious:false
    Reputation:low
    Preview:..[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .D.r.o.p.l.e.t...t.h.m.x.....C.o.m.p.o.n.e.n.t.:. .P.P.T.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....E.x.e.c.u.t.a.b.l.e.:. .{.P.P.}.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.....C.o.m.m.a.n.d.:. .{.F.i.l.e.P.a.t.h.}.....
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:Microsoft OOXML
    Category:dropped
    Size (bytes):2357051
    Entropy (8bit):7.929430745829162
    Encrypted:false
    SSDEEP:49152:tfVcGO3JiR6SgT7/bOCrKCsaFCX3CzwovQTSwW8nX:pVcG2iRedsaoXSzeOwWEX
    MD5:5BDE450A4BD9EFC71C370C731E6CDF43
    SHA1:5B223FB902D06F9FCC70C37217277D1E95C8F39D
    SHA-256:93BFC6AC1DC1CFF497DF92B30B42056C9D422B2321C21D65728B98E420D4ED50
    SHA-512:2365A9F76DA07D705A6053645FD2334D707967878F930061D451E571D9228C74A8016367525C37D09CB2AD82261B4B9E7CAEFBA0B96CE2374AC1FAC6B7AB5123
    Malicious:false
    Reputation:low
    Preview:PK.........{MB.f}......p......[Content_Types].xml..`.I.%&/m.{.J.J..t...`.$.@........iG#).*..eVe]f.@....{...{...;.N'...?\fd.l..J..!....?~|.?"....|.{.[..e^7E......Gi..V.by..G..|.......U..t.|..mW...m..|.5.j./..^d-.Y_.]e..E~wog...j...v......?..u....c.v...(=.v........F_..U..G...T.e.y)[..b.......3.m....6.X5.P........_...b../..}.-......~.-..z..d.......j.^.+c..E.V..~3}..U.7..~p.>.E..9^d....4%}.E.$....N..r....<....%...%.?....w.u...h........D...w.....h........Dkw...x..T....T....T....T....T....T....j...."[.J.....;..!4...M...............t.n-.{..skp...[;.......F...j.7...4fC...K1..K/..K-..K+..K)..K'..f9......Fl._.........d0...?7K7].........A.......Fl.............Ft....u.......Ft........\.......w....R.......R.......R........o...].`.....A....#.`..\.....S.._...4...o.........W<x#..............w#...r.nD..]....\.~....|......b...^...Z...V...R...N..W<x......l._...l..?.A......xp_Q..y<h..tL.i.?HNn...]..........r.nD..]~.........wy~7......Ft...........E/|c.
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
    Category:dropped
    Size (bytes):276
    Entropy (8bit):3.516423078177173
    Encrypted:false
    SSDEEP:6:Q+sxnxUX7kARELpmlJ0+3FbnKf68dADryMluxHFpwwl:Q+sxny5ymD0wbnKNAH/lMz1
    MD5:5402138088A9CF0993C08A0CA81287B8
    SHA1:D734BD7F2FB2E0C7D5DB8F70B897376ECA935C9A
    SHA-256:5C9F5E03EEA4415043E65172AD2729F34BBBFC1A1156A630C65A71CE578EF137
    SHA-512:F40A8704F16AB1D5DCD861355B07C7CB555934BB9DA85AACDCF869DC942A9314FFA12231F9149D28D438BE6A1A14FCAB332E54B6679E29AD001B546A0F48DE64
    Malicious:false
    Reputation:low
    Preview:..[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .S.l.a.t.e...t.h.m.x.....C.o.m.p.o.n.e.n.t.:. .P.P.T.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....E.x.e.c.u.t.a.b.l.e.:. .{.P.P.}.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.....C.o.m.m.a.n.d.:. .{.F.i.l.e.P.a.t.h.}.....
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:Microsoft OOXML
    Category:dropped
    Size (bytes):3078052
    Entropy (8bit):7.954129852655753
    Encrypted:false
    SSDEEP:49152:bSEjlpY8skyFHuj2yY0ciM9U2NCVBB4YFzYFw7IaJE2VRK+Xn9DOOe9pp9N9Hu:bfp5sksA3cimUVxV05aJE2fKaDOXdN9O
    MD5:CDF98D6B111CF35576343B962EA5EEC6
    SHA1:D481A70EC9835B82BD6E54316BF27FAD05F13A1C
    SHA-256:E3F108DDB3B8581A7A2290DD1E220957E357A802ECA5B3087C95ED13AD93A734
    SHA-512:95C352869D08C0FE903B15311622003CB4635DE8F3A624C402C869F1715316BE2D8D9C0AB58548A84BBB32757E5A1F244B1014120543581FDEA7D7D9D502EF9C
    Malicious:false
    Reputation:low
    Preview:PK..........1AS'......ip......[Content_Types].xml..n.@.._......8ie'......}.......(y...H}......3Fi..%2.v?..3..._...d=..E.g.....7.i.-.t5.6......}}.m9r.......m...ML.g.M.eV$.r..*.M..l0...A...M..j;.w={o.f..F....i..v......5..d;..D.ySa...M&..qd*w>.O.{h...|w..5.]..'.CS<.:8C}.g.|E.../..>..].Tnml..I.......r.Gv.E....7.;.E......4/l.....6.K.C?1qz.O.v_..r......\c.c.>..lS........X.N.3N.sN..N.)'.%'..'..N.pL.E...T.!..CR....Ie..k.o..M..w.B.0}..3....v..+....,.q..pz.......v{.;....s3.|..V..ZZ......0.[.....x.....!.!~.8.e..n..&.}p....s.i.. ..[]...q.r....~..+.A\...q............e.-)h9..."Z.>...5-C..`..g.}........r.A.+..\...r.>.... .W.\...re?..%.-/hiA..ZR.r.W.D.\}.EK..kZ.>......5..9.&T......Wlu.b....}..+.A\...q......~.WK.Z^..........>.h..`......}.....^h....L...H...!...r.>... .W...\...rE?............-+hIA..\}..r...-}..i..`..G..j..).&T......Wlu.b....}..+.A\...q......~.WK.Z^..........>.h..`......}.....^j..K.L...H...!...r.>... .W...\...rE?............-+hIA..\}..r...-}..i.
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
    Category:dropped
    Size (bytes):274
    Entropy (8bit):3.5303110391598502
    Encrypted:false
    SSDEEP:6:Q+sxnxUXzRELpmlJ0+3FbnKf68dADryMluxHFpwwl:Q+sxnylymD0wbnKNAH/lMz1
    MD5:8D1E1991838307E4C2197ECB5BA9FA79
    SHA1:4AD8BB98DC9C5060B58899B3E9DCBA6890BC9E93
    SHA-256:4ABA3D10F65D050A19A3C2F57A024DBA342D1E05706A8A3F66B6B8E16A980DB9
    SHA-512:DCDC9DB834303CC3EC8F1C94D950A104C504C588CE7631CE47E24268AABC18B1C23B6BEC3E2675E8A2A11C4D80EBF020324E0C7F985EA3A7BBC77C1101C23D01
    Malicious:false
    Reputation:low
    Preview:..[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .M.e.s.h...t.h.m.x.....C.o.m.p.o.n.e.n.t.:. .P.P.T.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....E.x.e.c.u.t.a.b.l.e.:. .{.P.P.}.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.....C.o.m.m.a.n.d.:. .{.F.i.l.e.P.a.t.h.}.....
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:Microsoft OOXML
    Category:dropped
    Size (bytes):2218943
    Entropy (8bit):7.942378408801199
    Encrypted:false
    SSDEEP:49152:8mwK3gH/l4hM06Wqnnl1IdO9wASFntrPEWNe7:863gHt4hM9WWnMdO9w35PEWK
    MD5:EE33FDA08FBF10EF6450B875717F8887
    SHA1:7DFA77B8F4559115A6BF186EDE51727731D7107D
    SHA-256:5CF611069F281584DE3E63DE8B99253AA665867299DC0192E8274A32A82CAA20
    SHA-512:AED6E11003AAAACC3FB28AE838EDA521CB5411155063DFC391ACE2B9CBDFBD5476FAB2B5CC528485943EBBF537B95F026B7B5AB619893716F0A91AEFF076D885
    Malicious:false
    Reputation:low
    Preview:PK.........{MBS'..t...ip......[Content_Types].xml..`.I.%&/m.{.J.J..t...`.$.@........iG#).*..eVe]f.@....{...{...;.N'...?\fd.l..J..!....?~|.?"....|.{.[..e^7E......Gi..V.by..G..|.......U..t.|..mW...m..|.5.j./..^d-.Y_.]e..E~wog...j...v......?..u....c...W..G.4D_.}T,.@...}....R.Z..4k.....Y..mEkLor.f^..O..P...`.../.|u1..Y.....nK.......u=..2.tu~^L.Y5]/...~+.v...o....j.`?.S...../.by.|..>."kZbs....H.9..m.z.]W.V.?~v........;...N.......w....;.z..N.......w.....R.._..w._..w._..w._..w._..w._..w.n..Ofu.-..K.e........T..q.F...R[...~.u.....Z..F....7.?.v....5O....zot..i.....b...^...Z...V...R...N...r./.?........=....#.`..\~n.n...)J./.......7........+......Q..]n............w......Ft........|......b...^...Z...V...R...N..W<x......l._...l..?.A......x....x.9.|.8..............u................w#.....nD..]...........R.......R.......R........o...].`.....A....#.`..\.....+J./.......7........+......Q..]n.........w9~7......Ft........|......b...^.c..-...-...-
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
    Category:dropped
    Size (bytes):278
    Entropy (8bit):3.544065206514744
    Encrypted:false
    SSDEEP:6:Q+sxnxUXCARELpmlJ0+3FbnKf68dADryMluxHFpwwl:Q+sxnyy6ymD0wbnKNAH/lMz1
    MD5:06B3DDEFF905F75FA5FA5C5B70DCB938
    SHA1:E441B94F0621D593DC870A27B28AC6BE3842E7DB
    SHA-256:72D49BDDE44DAE251AEADF963C336F72FA870C969766A2BB343951E756B3C28A
    SHA-512:058792BAA633516037E7D833C8F59584BA5742E050FA918B1BEFC6F64A226AB3821B6347A729BEC2DF68BB2DFD2F8E27947F74CD4F6BDF842606B9DEDA0B75CC
    Malicious:false
    Reputation:low
    Preview:..[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .D.a.m.a.s.k...t.h.m.x.....C.o.m.p.o.n.e.n.t.:. .P.P.T.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....E.x.e.c.u.t.a.b.l.e.:. .{.P.P.}.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.....C.o.m.m.a.n.d.:. .{.F.i.l.e.P.a.t.h.}.....
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:Microsoft OOXML
    Category:dropped
    Size (bytes):2924237
    Entropy (8bit):7.970803022812704
    Encrypted:false
    SSDEEP:49152:mc4NEo4XNd5wU5qTkdC4+K9u5b/i40RKRAO/cLf68wy9yxKrOUURBgmai2prH:mJef5yTSoKMF//DRGJwLx9DBaH
    MD5:5AF1581E9E055B6E323129E4B07B1A45
    SHA1:B849F85BCAF0E1C58FA841FFAE3476D20D33F2DD
    SHA-256:BDC9FBF81FBE91F5BF286B2CEA00EE76E70752F7E51FE801146B79F9ADCB8E98
    SHA-512:11BFEF500DAEC099503E8CDB3B4DE4EDE205201C0985DB4CA5EBBA03471502D79D6616D9E8F471809F6F388D7CBB8B0D0799262CBE89FEB13998033E601CEE09
    Malicious:false
    Reputation:low
    Preview:PK.........{MB.$<.~....p......[Content_Types].xml..`.I.%&/m.{.J.J..t...`.$.@........iG#).*..eVe]f.@....{...{...;.N'...?\fd.l..J..!....?~|.?"....|.{.[..e^7E......Gi..V.by..G..|.......U..t.|..mW...m..|.5.j./..^d-.Y_.]e..E~wog...j...v......?..u....c...W..G.4D_.}T,.@...}....R.Z..4k.....Y..mEkLor.f^..O..P...`..^.......H^..<}...lA-.D.....lI/...hD.Z....|VM..ze........L..tU...g....lQ....Y...>MI...5-....S......h=..u.h..?;h...@k...h...'Z...D...;.....h=..'Z...D...;.....)^./.../U.../..../U.../..../U..?...'.........Ngz..A.~.8.#D....xot.u.?...eyot.n..{..sk....[......Z..F....l...o)..o..o...oi..o)..o..,..b.s......2.C.z.~8.......f......x.9.|.8..............u................r.nD..]...........w.~7...-...-...-...-...-...-....x.&l........>.4.z.~8..........=E....As.1..q. 9....w.7...1........w.}7......Ft...................o)..o..o...oi..o)..o..w.7a...x0...........d0..............A.......Fl.............Ft................w#...r.nD..]..M...K1.0..7....
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
    Category:dropped
    Size (bytes):286
    Entropy (8bit):3.5434534344080606
    Encrypted:false
    SSDEEP:6:Q+sxnxUXIc5+RELpmlJ0+3FbnKf68dADryMluxHFpwwl:Q+sxny4KcymD0wbnKNAH/lMz1
    MD5:C9812793A4E94320C49C7CA054EE6AA4
    SHA1:CC1F88C8F3868B3A9DE7E0E5F928DBD015234ABA
    SHA-256:A535AE7DD5EDA6D31E1B5053E64D0D7600A7805C6C8F8AF1DB65451822848FFC
    SHA-512:D28AADEDE0473C5889F3B770E8D34B20570282B154CD9301932BF90BF6205CBBB96B51027DEC6788961BAF2776439ADBF9B56542C82D89280C0BEB600DF4B633
    Malicious:false
    Reputation:low
    Preview:..[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .M.a.i.n._.E.v.e.n.t...t.h.m.x.....C.o.m.p.o.n.e.n.t.:. .P.P.T.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....E.x.e.c.u.t.a.b.l.e.:. .{.P.P.}.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.....C.o.m.m.a.n.d.:. .{.F.i.l.e.P.a.t.h.}.....
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:Microsoft OOXML
    Category:dropped
    Size (bytes):3611324
    Entropy (8bit):7.965784120725206
    Encrypted:false
    SSDEEP:49152:ixc1kZBIabo4dTJyr3hJ50gd9OaFxTy+1Nn/M/noivF0po3M0h0Vsm:ixcaAabT83hJLdoaFxTygxcoiX3M0iCm
    MD5:FB88BFB743EEA98506536FC44B053BD0
    SHA1:B27A67A5EEC1B5F9E7A9C3B76223EDE4FCAF5537
    SHA-256:05057213BA7E5437AC3B8E9071A5577A8F04B1A67EFE25A08D3884249A22FBBF
    SHA-512:4270A19F4D73297EEC910B81FF17441F3FC7A6A2A84EBA2EA3F7388DD3AA0BA31E9E455CFF93D0A34F4EC7CA74672D407A1C4DC838A130E678CA92A2E085851C
    Malicious:false
    Reputation:low
    Preview:PK.........{MB.f}......p......[Content_Types].xml..`.I.%&/m.{.J.J..t...`.$.@........iG#).*..eVe]f.@....{...{...;.N'...?\fd.l..J..!....?~|.?"....|.{.[..e^7E......Gi..V.by..G..|.......U..t.|..mW...m..|.5.j./..^d-.Y_.]e..E~wog...j...v......?..u....c.v...(=.v........F_..U..G...T.e.y)[..b.......3.m....6.X5.P........_...b../..}.-......~.-..z..d.......j.^.+c..E.V..~3}..U.7..~p.>.E..9^d....4%}.E.$....N..r....<....%...%.?....w.u...h........D...w.....h........Dkw...x..T....T....T....T....T....T....j...."[.J.....;..!4...M...............t.n-.{..skp...[;.......F...j.7...4fC...K1..K/..K-..K+..K)..K'..f9......Fl._.........d0...?7K7].........A.......Fl.............Ft....u.......Ft........\.......w....R.......R.......R........o...].`.....A....#.`..\.....S.._...4...o.........W<x#..............w#...r.nD..]....\.~....|......b...^...Z...V...R...N..W<x......l._...l..?.A......xp_Q..y<h..tL.i.?HNn...]..........r.nD..]~.........wy~7......Ft...........E/|c.
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
    Category:dropped
    Size (bytes):288
    Entropy (8bit):3.5359188337181853
    Encrypted:false
    SSDEEP:6:Q+sxnxUXe46x8RELpmlJ0+3FbnKf68dADryMluxHFpwwl:Q+sxnyO3UymD0wbnKNAH/lMz1
    MD5:0FEA64606C519B78B7A52639FEA11492
    SHA1:FC9A6D5185088318032FD212F6BDCBD1CF2FFE76
    SHA-256:60059C4DD87A74A2DC36748941CF5A421ED394368E0AA19ACA90D850FA6E4A13
    SHA-512:E04102E435B8297BF33086C0AD291AD36B5B4A97A59767F9CAC181D17CFB21D3CAA3235C7CD59BB301C58169C51C05DDDF2D637214384B9CC0324DAB0BB1EF8D
    Malicious:false
    Reputation:low
    Preview:..[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .V.a.p.o.r._.T.r.a.i.l...t.h.m.x.....C.o.m.p.o.n.e.n.t.:. .P.P.T.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....E.x.e.c.u.t.a.b.l.e.:. .{.P.P.}.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.....C.o.m.m.a.n.d.:. .{.F.i.l.e.P.a.t.h.}.....
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:Microsoft Word 2007+
    Category:modified
    Size (bytes):3465076
    Entropy (8bit):7.898517227646252
    Encrypted:false
    SSDEEP:98304:n8ItVaN7vTMZ9IBbaETXbI8ItVaN7vTMZ9IBbaEiXbY:8ItwNX9BvTvItwNX9BvoM
    MD5:8BC84DB5A3B2F8AE2940D3FB19B43787
    SHA1:3A5FE7B14D020FAD0E25CD1DF67864E3E23254EE
    SHA-256:AF1FDEEA092169BF794CDC290BCA20AEA07AC7097D0EFCAB76F783FA38FDACDD
    SHA-512:558F52C2C79BF4A3FBB8BB7B1C671AFD70A2EC0B1BDE10AC0FED6F5398E53ED3B2087B38B7A4A3D209E4F1B34150506E1BA362E4E1620A47ED9A1C7924BB9995
    Malicious:false
    Reputation:low
    Preview:PK.........Y5B................[Content_Types].xml ...(.................................................................................................................................................................................................................................................................................................................................................................................................................................................`.I.%&/m.{.J.J..t...`.$.@........iG#).*..eVe]f.@....{...{...;.N'...?\fd.l..J..!....?~|.?"....|.{.[..e^7E......Gi..V.by..G..|.......U..t.|..mW...m..|.5.j./..^d-.Y_.]e..E~wog...j...v......?..u....c...W..G.4D_.}T,.@...}....R.Z..4k.....Y..mEkLor.f^..O..P...`..^.....g.../i..b../..}.-......U.....o.7B.......}@[..4o...E9n..h...Y....D.%......F....g..-!.|p.....7.pQVM.....B.g.-.7....:...d.2...7bA..Us.z.`.r..,.m."..n....s.O^.....fL.........7.....-...gn,J..iU..$.......i...(..dz.....3|
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:Microsoft Cabinet archive data, many, 17466 bytes, 2 files, at 0x4c "chicago.xsl", iFolder 0x1 "Content.inf", 2 cffolders, flags 0x4, number 1, extra bytes 20 in head, 10 datablocks, 0x1203 compression
    Category:dropped
    Size (bytes):33610
    Entropy (8bit):7.8340762758330476
    Encrypted:false
    SSDEEP:768:IlFYcxiahedKSDNAPk5WEEfA8Pi6xnOKMRA58:2JitdKsNAM5WBDP7xOKMq58
    MD5:51804E255C573176039F4D5B55C12AB2
    SHA1:A4822E5072B858A7CCA7DE948CAA7D2268F1BB4B
    SHA-256:3C6F66790C543D4E9D8E0E6F476B1ACADF0A5FCDD561B8484D8DDDADFDF8134B
    SHA-512:2AC8B1E433C9283377B725A03AE72374663FEC81ABBA4C049B80409819BB9613E135FCD640ED433701795BDF4D5822461D76A06859C4084E7BAE216D771BB091
    Malicious:false
    Reputation:low
    Preview:MSCF....:D......L...........................:D...?..................XC.....................chicago.xsl. ...............Content.inf.!..B...[...H."m..3C.6...WP!i/Z..vn._...^omvw+...^..L.4o...g..y......^..x...BH.B.K....w.....F........p ./gg.h.0I',.$..a.`.*...^..vi..mw..........K....oQ............P...#...3.......U(.=...q.~?..H..?.'I4'.......X...}w.vw.....f.n..f{3.....-....%dK&q..D.H.Z..h-..H.[$ %.."..e....1...$.............'.....B..%..4...&`S!DQ...M.......N~............S..'....M..4E.^..dej..i..+.`...6F%sJ....Q..d.(*.s.Z...U-5Eh.s.CK...K..X$......j..T.?.`.|...=..R...-7...*...TU.....7a...&I.noOK|.W.R-+S.d..rR.....{h.Y...)..xJ..=.XM..o...P'.I4m..~I..C..m.....f.....;{Mzg+Wm.~...z...r-.....eK...lj:^.1g5...7.h(T"..t?5......u.....G.Z<..sL.\{...8=t...Z...'tps.:...|....6.....S..X...I...6l.M.....aq.;YS....{:.&.'.&.F.l...\.[L.%.so\.v.Lo...zO.^^...p..*9k...).CC..F0>L...VUE4.......2..c..p.rCi..#...b.C@o.l.. E_b..{d...hX.\_!a#.E.....yS.H...aZ...~D3.pj: ss?.]....~
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:Microsoft Cabinet archive data, many, 15691 bytes, 2 files, at 0x4c "gb.xsl", iFolder 0x1 "Content.inf", 2 cffolders, flags 0x4, number 1, extra bytes 20 in head, 9 datablocks, 0x1203 compression
    Category:dropped
    Size (bytes):31835
    Entropy (8bit):7.81952379746457
    Encrypted:false
    SSDEEP:768:ltJDH8NmUekomvNufaqA8Pi6x5q3KQIGu:lvINukgzP7x5mRIGu
    MD5:92A819D434A8AAEA2C65F0CC2F33BB3A
    SHA1:85C3F1801EFFEA1EA10A8429B0875FC30893F2C8
    SHA-256:5D13F9907AC381D19F0A7552FD6D9FC07C9BD42C0F9CE017FFF75587E1890375
    SHA-512:01339E04130E08573DF7DBDFE25D82ED1D248B8D127BB90D536ECF4A26F5554E793E51E1A1800F61790738CC386121E443E942544246C60E47E25756F0C810A3
    Malicious:false
    Reputation:low
    Preview:MSCF....K=......L...........................K=...?..................q<......................gb.xsl.................Content.inf.EF/.....[...A....3D.4..oVP!i/......t.6..l&9r0.8......c..q.^........$/..(./H ...^_Z0\4.42WU......P.F..9.._....'.D..<H@..E.b,K..9o..wo..v|..[.{7m.......|}aI..|g....IF2au?.1,..3.H.......ed....-.........m....$..8&0..w........2....s....z..d.Z.e.....@$r[..r..4...."E.Q@...Hh.B"b>...$.L.$.P.._..~.?./T..@..F..?.~G...MS..O%Z3*k..:..._...!GF..U...!..W..$..7...j......xy0..../.j..~4......8...YV....Fe.LU..J.B.k%BT5.X.q.w.a4....5..r...W.6.u...]i...t.....e.\.K............#t.c5.6....j...?#..{.m3.L9...E/....B[R.k(.'....S.'.}!j.tL..v....L....{<.m4......d_kD..D.....4`aC....rg..S..F.b..^........g;.`?,......\..T.\.H.8W.!V...1.T1.....|.Uh....T..yD'..R.......,.`h..~.....=......4..6E..x#XcVlc_S54 ..Q.4!V..P...{w..z.*..u.v....DC...W.(>4..a..h.t.F.Z...C.....&..%v...kt....n..2....+.@...EW.GE..%.:R`,}v.%.nx.P.#.f.......:.5(...]...n3{...v........Q..
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:Microsoft Cabinet archive data, many, 30269 bytes, 2 files, at 0x4c "Text Sidebar (Annual Report Red and Black design).docx", iFolder 0x1 "Content.inf", 2 cffolders, flags 0x4, number 1, extra bytes 20 in head, 2 datablocks, 0x1203 compression
    Category:dropped
    Size (bytes):46413
    Entropy (8bit):7.9071408623961394
    Encrypted:false
    SSDEEP:768:WaxA0CH65GY3+fvCXCttfR8JEBrkquwDn+QV5V+vNWBatX/xG8Pi65sMuMjvU+mQ:hne65GYOfKXMSEBrBtDnzFAI4JxP75sM
    MD5:C455C4BC4BEC9E0DA67C4D1E53E46D5A
    SHA1:7674600C387114B0F98EC925BE74E811FB25C325
    SHA-256:40E9AF9284FF07FDB75C33A11A794F5333712BAA4A6CF82FA529FBAF5AD0FED0
    SHA-512:08166F6CB3F140E4820F86918F59295CAD8B4A17240C206DCBA8B46088110BDF4E4ADBAB9F6380315AD4590CA7C8ECDC9AFAC6BD1935B17AFB411F325FE81720
    Malicious:false
    Reputation:low
    Preview:MSCF....=v......L...........................=v...?..................5u......................Text Sidebar (Annual Report Red and Black design).docx.v...............Content.inf..C,.zd..[............... .w.....b...wwww]r..W\ww...... .hh...........o.nz.....Ku.7..-.oH...h;.N..#.._.D,}......!Q$..Un.tI11..$w.r3... ..p...=.1....""..n...*/....h.A...Y..c,.Q.,......",..b.1.w..$.....l../;..J.....~.. ....+.R#....7.-..1.x.feH.@.......u...(.DQ%.wL.N|.xh...R..#....C...'X.m.....I{W.....5.C.....\....z.Y.)w..i...%....M..n.p.....{..-G9..k.bT.6........7....).....6..ys.....R.e.....0.Xk`.3..X\xL..4J"#.f...:....r..2..Y.uW..052.n.+ ..o..o..f&u.v.&9y.P..6.K..in.DU.#.~....4i..6;.5.w..i...g.(....../..0*Vh...C..//....W..:w......7.6....]....4.*9...sL.0k...zHh..2N.H...*..]..(.x.:..........Y.+...-.....&.*^..Q.sW...v..w.....k.L.e.^.W4iFS..u.....l.g'...b~:Zm...S.2.|......5S..=.............l.../|....G|.9 ..#.q...W.Q...G=.."W..'.6....I....D._.{.g.47....V.1._..<?....m............)..T.
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:Microsoft Cabinet archive data, many, 15338 bytes, 2 files, at 0x4c "gosttitle.xsl", iFolder 0x1 "Content.inf", 2 cffolders, flags 0x4, number 1, extra bytes 20 in head, 8 datablocks, 0x1203 compression
    Category:dropped
    Size (bytes):31482
    Entropy (8bit):7.808057272318224
    Encrypted:false
    SSDEEP:768:LgHv7aLOcoLGQ4EykdrHwLa+A8Pi6Iv8ACIa:LwvWyx4EykdTwLaWP7I0ACIa
    MD5:F10DF902980F1D5BEEA96B2C668408A7
    SHA1:92D341581B9E24284B7C29E5623F8028DBBAAFE9
    SHA-256:E0100320A4F63E07C77138A89EA24A1CBD69784A89FE3BF83E35576114B4CE02
    SHA-512:00A8FBCD17D791289AC8F12DC3C404B0AFD240278492DF74D2C5F37609B11D91A26D737BE95D3FE01CDBC25EEDC6DA0C2D63A2CCC4AB208D6E054014083365FB
    Malicious:false
    Reputation:low
    Preview:MSCF.....;......L............................;...?...................;......................gosttitle.xsl.$...............Content.inf....v....[...=..Ic.32.E...`o.............m....4uk[.,.......{...}k{.R@(Hq..68nv...@.D.....$...j....8Q..........8.8........3...*.bi?Wt...:(..J.;&eii..io.w..z...`.'..i.MLR@.>....N..3`P.>$X@(r.#.D..(....P"_..I.$o.. L!y...I...H.........{.{....{.3....7..w..{w.2sn.dYn.lW...l...c$.UH....L6. .D$$...!F.!... .D............_..'.`.Q.v>..Z..f.n.l....0o.......bK...?s..eO....'.>t......S'..........~....h...v&7:q.x9|qs...%....:..D...ag.....e..'...".A.Y..?w"....p1t.9J.~.4.........~vj.n.8.;.O......../.}..io{p...e...\m.d`.gAm.......1"...N*...8..g"......~..[.e+.....\6i4.....%...Rq.U-p?..4P..4.f.?N.vI?.M\i.;.s..E.L.hu.*...\..5....N......]......\`...rS.\g.....2..!a).?.l.!i.^.t.u...x...g/.A..v.E...\.@.>kM...&.g.....%.......{.....2..E.g...'..[w...N.w..& 4M.a.cu.%:...\.D..Q..C.'fm..i....@._......QI.. ....h..|fB.il.(`..h.d;.l...`.s:
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:Microsoft Cabinet archive data, many, 5864 bytes, 2 files, at 0x44 "architecture.glox" "Content.inf", flags 0x4, number 1, extra bytes 20 in head, 1 datablock, 0x1203 compression
    Category:dropped
    Size (bytes):22008
    Entropy (8bit):7.662386258803613
    Encrypted:false
    SSDEEP:384:M7FUtfIdqSHQs7G8E0GftpBjED/C4RQrFLrHRN7TT8DlvQyUTL2mH:sWgdqR2G8Pi6D6YQZTTMvU+mH
    MD5:ABBF10CEE9480E41D81277E9538F98CB
    SHA1:F4EA53D180C95E78CC1DA88CD63F4C099BF0512C
    SHA-256:557E0714D5536070131E7E7CDD18F0EF23FE6FB12381040812D022EC0FEE7957
    SHA-512:9430DAACF3CA67A18813ECD842BE80155FD2DE0D55B7CD16560F4AAEFDA781C3E4B714D850D367259CAAB28A3BF841A5CB42140B19CFE04AC3C23C358CA87FFB
    Malicious:false
    Reputation:low
    Preview:MSCF............D................................?..................................architecture.glox.................Content.inf..q5.^...[.....0y......../..CL.C5.Q..U5g.z....UUUMPC...C..P....T.....=..s..4c...-3H..E...2..2*..T...../.i.;$..............%...................'h.........#0.......[........c.h.....O...%.61...[.J..:.,^....W.]$..u...N.R.....H.......:%I.g5Kd.n6...W2.#.UL..h.8NN../.P...H.;@.N.F...v."h..K.....~.....8...{.+...&.#A.Q'..A.....[NJ.X.....|.|.G5...vp.h.p..1.....-...gECV.,o{6W.#L....4v..x..z..)[.......T.....BQ.pf..D.}...H....V..[._.'.......3..1....?m..ad..c(K.......N.N.6F%.m......9...4..]?...l6..).\p;w.s....@...I%H.....;\...R......f...3~:C...A..x....X...>...:~.+..r@..."......I..m.y..)F.l..9...6....m...=..Q.F.z..u......J].{WX...V.Z.b.A0B..!....~.;Z.....K.`c..,X.MFz....].Q.2.9..L."...]...6...JOU..6...~../......4A.|.......i.LKrY...2.R.o..X.\....0.%......>H.....8.z..^....5d|...4|...C......R28.E......a....e...J.S..Ng.]<&..mm
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:Microsoft Cabinet archive data, many, 18672 bytes, 2 files, at 0x4c "APASixthEditionOfficeOnline.xsl", iFolder 0x1 "Content.inf", 2 cffolders, flags 0x4, number 1, extra bytes 20 in head, 11 datablocks, 0x1203 compression
    Category:dropped
    Size (bytes):34816
    Entropy (8bit):7.840826397575377
    Encrypted:false
    SSDEEP:768:i3R9VYnIYfPYmqX0CnF1SRHVnLG8Pi61YbEIFO:ih9VjYfPYlk+F1SJxP71YbEIFO
    MD5:62863124CDCDA135ECC0E722782CB888
    SHA1:2543B8A9D3B2304BB73D2ADBEC60DB040B732055
    SHA-256:23CCFB7206A8F77A13080998EC6EF95B59B3C3E12B72B2D2AD4E53B0B26BB8C3
    SHA-512:2734D1119DC14B7DFB417F217867EF8CE8E73D69C332587278C0896B91247A40C289426A1A53F1796CCB42190001273D35525FCEA8BA2932A69A581972A1EF00
    Malicious:false
    Reputation:low
    Preview:MSCF.....H......L............................H...?...................G......................APASixthEditionOfficeOnline.xsl.H...............Content.inf..h;.....[...Q..\..3S.5..oVP!i/Z.Ls...]q$...xY..+W.qm..B..y/.5.s..x$../K./.x.$.....}.......\........LNf..Hd.&."Ip.L.Mr-@.D..kW~i...^.....F.....T.U....../..0..2.{.q.T.`'{.00.{.B...>.R..2....1.~_.f..s...........~....~[..v..w..v....$[K.r$#[6...d;[...#.9.-...G..Z..eAR.0")%JI?&....$..$.H..$(........f.> k....hP...p...!j.T......l7..../3..(2^V...#..T9...3.@[0...le:...........E....YP.\.....au1...\.S|..-.duN.Z..g.O......X8....1.....|,.f/..w.|Wk]zJz.g'./7h..+.....}............x....s.2Z\..W.{...O....W.{j.U..Q....uO=.p.M k.E.S{SUd.@....S.Syo8>......r......8..............Z?>.mUAg....?o....f.7..W.n...P..........d.S?...\..W`...c.ua..........#.Y...45...F(d.o\09^..[.}...BsT.SD..[l.8..uw.7l..S.9T.KR..o......V..]...M .....t.r...:P...M....4.F.....@..t.1t..S...k.2.|5...i.%H..<.J..*.0n.....lZ.....?.*?.~..O .)..
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:Microsoft Cabinet archive data, many, 4313 bytes, 2 files, at 0x44 "chevronaccent.glox" "Content.inf", flags 0x4, number 1, extra bytes 20 in head, 1 datablock, 0x1203 compression
    Category:dropped
    Size (bytes):20457
    Entropy (8bit):7.612540359660869
    Encrypted:false
    SSDEEP:384:KyeISBuydn5rpmp77G8E0GftpBjE/kFLrHRN7ngslI66YVj:KHISBvd5rpmFG8Pi6/6nK666j
    MD5:4EFA48EC307EAF2F9B346A073C67FCFB
    SHA1:76A7E1234FF29A2B18C968F89082A14C9C851A43
    SHA-256:3EE9AE1F8DAB4C498BD561D8FCC66D83E58F11B7BB4B2776DF99F4CDA4B850C2
    SHA-512:2705644D501D85A821E96732776F61641FE82820FD6A39FFAF54A45AD126C886DC36C1398CDBDBB5FE282D9B09D27F9BFE7F26A646F926DA55DFF28E61FBD696
    Malicious:false
    Reputation:low
    Preview:MSCF............D................................?..................................chevronaccent.glox.................Content.inf..O.$N...[.........B.....?.....$Zy..Zkr...y<.....Di-.aVX/....h..-.~........#.../.Fz....T...p....A..eHMe[..p...=................f..../%o......F@..=..$.B!....}.0..g..^vlI......f.W.F...Nm..2`...)...,.HL4.nsl.F.ir.k..e.!^.j2.v.iT....t...*..!h..Y...2Q..-.x.,.Xj.U.cj,....9.....)..W..n3f.......(cH.D.4M.!.+..4..3r..y......|r..@.PD.R..#...F..nJAR..1{-.....u3..$..L.b+h....:lZ.>....q.?. ~l..^.%.m....a...cG.h.?.|.?7.'....b.G.4..'..A...o.Z...//..?...d..*.....C..Z.....]Yv.g.]..... .........]x.#=.../.7;R.j....G.....zq=O`[.'5g.D.u..)..../../.v.JmCW.da....3.f..C.z%...S=....;A.q.|....z.E.aRu........ k..J"+.f.S.@.........eD4....\0..t./U..%.H..........M:..U.......J...Z..H.DG..u^..D..P....`.^b.........`c......#.....c.?...#..C.V.&.'..f.'...f.[..F.O..a...&..{TiXg4; .X."..0...B.#..^..........N"..w.@f...gd.S..K.....E....ZR...;.twR>.z.
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:Microsoft Cabinet archive data, many, 14864 bytes, 2 files, at 0x4c "mlaseventheditionofficeonline.xsl", iFolder 0x1 "Content.inf", 2 cffolders, flags 0x4, number 1, extra bytes 20 in head, 8 datablocks, 0x1203 compression
    Category:dropped
    Size (bytes):31008
    Entropy (8bit):7.806058951525675
    Encrypted:false
    SSDEEP:768:ktH7oN/HbwiV+M+4Jc+5UrT3czi5uOHQA8Pi6DxUR/WTZIy:87sPEANXJc+eTMsuzP7DmN0ZIy
    MD5:E033CCBC7BA787A2F824CE0952E57D44
    SHA1:EEEA573BEA217878CD9E47D7EA94E56BDAFFE22A
    SHA-256:D250EB1F93B43EFB7654B831B4183C9CAEC2D12D4EFEE8607FEE70B9FAB20730
    SHA-512:B807B024B32E7F975AED408B77563A6B47865EECE32E8BA993502D9874B56580ECC9D9A3FEFA057FDD36FB8D519B6E184DB0593A65CC0ACF5E4ACCBEDE0F9417
    Malicious:false
    Reputation:low
    Preview:MSCF.....:......L............................:...?...................9......................mlaseventheditionofficeonline.xsl.L...............Content.inf.N.#.....[...>..9..3c.5...F.B.]Y.3..%d.8...v;....~Y.L.=..v..m.g...|K.B....$......s.......#CdE.p.p..@...j.Nl2'...L..N.G:-V:.d.....i..M........mK.w.....\W.<.`..b$.!..!3..rT.A..#.).;KZ...a.-..j&e`R.~7dIRS.I..f.ff....}.}....^[wo.uw..i.m7......v$.I..n....-.Z.M5...iH..Ea..., [..0.L...DH..." ..... .@...H.@..+...}.......*^..'.4*.tHa..f].gV..~.7V.....C..).(.U"..f.@l..j'..%\.u.UU.....9<13...5..=........./..Z..{..-.L].+Y.fL.<EJ.q..!.j....W..]E./.~Y>...GgQ..-....Q.C..5..T+...fO. .)..~.7..Y....+..U=.e..8w.m...._..S..v.d.* ......S3z.X)......u...t.......i.;.a...X.Ji....g.3.!.O.....T.f6..[U....O..Z.X.q.G....?.k]..?...8.u.;].8y.T.9D..!?R....:........3+.P.....7?m}..............1...y3.g.\c.ks^;?.f.U5...U.j....E.N.}.!.......).R1....~.....R.....3.J.f...l..E^:...&_..%..v...^..E...rC..O....M.#..<..H..bB.+.W..
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:Microsoft Cabinet archive data, many, 15327 bytes, 2 files, at 0x4c "sist02.xsl", iFolder 0x1 "Content.inf", 2 cffolders, flags 0x4, number 1, extra bytes 20 in head, 8 datablocks, 0x1203 compression
    Category:dropped
    Size (bytes):31471
    Entropy (8bit):7.818389271364328
    Encrypted:false
    SSDEEP:768:eNtFWk68dbr2QxbM971RqpzAA8Pi6TlHaGRA5yr:eNtEkpGSbuHAkP7TlHaGq54
    MD5:91AADBEC4171CFA8292B618492F5EF34
    SHA1:A47DEB62A21056376DD8F862E1300F1E7DC69D1D
    SHA-256:7E1A90CDB2BA7F03ABCB4687F0931858BF57E13552E0E4E54EC69A27325011EA
    SHA-512:1978280C699F7F739CD9F6A81F2B665643BD0BE42CE815D22528F0D57C5A646FC30AAE517D4A0A374EFB8BD3C53EB9B3D129660503A82BA065679BBBB39BD8D5
    Malicious:false
    Reputation:low
    Preview:MSCF.....;......L............................;...?...................;......g...............sist02.xsl.................Content.inf....!....[...=.rF..3U.5...g.i?..w.oY..If'.......Y.;.B.....Wo.{T.TA.~......8......u.p....@Q..k.?.....G....j.|*.*J69H.2.ee..23s..;3..i..L.,...0se.%J........%.....!.....qB...SC...GAu5.P..u7....:.|.$Fo............{.......v.v.g..{o....e.....m.JeRG..,.%.1..Lh.@8.i.....l.#.HB`B....C......D@....?....P?..................|.9..q.......9.n.....F...s,....3..Q..N......y......_i..9|.<w...'q.Tq...U.E.B...q.?.4..O(_O.A.......*jC.~.21.7.....u.C...]uc.....-.g.{C~9q.q.1.1...4..=.0.Z.^....'../....-.6.K.....K...A#.GR..t.@.{.O.......Q5..=....X...^...F3.e.E.Z..b+R..?Z..0T1.....gQz.&....%y=zx.f.....6-*...u.Rm..x<...?...!g@.}..).J...:*...9.s&.v..}..'...\..Sd..F...........kQr.....h..3..1....B...B{M...%O.59.\.#....s/.pE.:}...k_.P.>.zj....5|.9+....$M..L........(...@#.....N.....N.*..........E..7..R$.:9!r>7.....v...>..S.w....9..]..n.w.;&.W..<r\S....
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:Microsoft Cabinet archive data, many, 9170 bytes, 2 files, at 0x44 "InterconnectedBlockProcess.glox" "Content.inf", flags 0x4, number 1, extra bytes 20 in head, 1 datablock, 0x1203 compression
    Category:dropped
    Size (bytes):25314
    Entropy (8bit):7.729848360340861
    Encrypted:false
    SSDEEP:384:75V23GNhfG/YvmBqWDP7G8E0GftpBjEB1vrFLrHRN7mKll7PK/pRU0:LS/Yvc7TG8Pi6BLm6IS0
    MD5:C47E3430AF813DF8B02E1CB4829DD94B
    SHA1:35F1F1A18AA4FD2336A4EA9C6005DBE70013C7FC
    SHA-256:F2DB1E60533F0D108D5FB1004904C1F2E8557D4493F3B251A1B3055F8F1507A3
    SHA-512:6F8904E658EB7D04C6880F7CC3EC63FCFE31EF2C3A768F4ECF40B115314F23774DAEE66DCE9C55FAF0AD31075A3AC27C8967FD341C23C953CA28BDC120997287
    Malicious:false
    Reputation:low
    Preview:MSCF.....#......D............................#...?...................#..............InterconnectedBlockProcess.glox......#..........Content.inf...<.:#.$[......O..........5f.P.5CU..6..jT..U..U..UM.T.........h................-... .......6...`.....G...........'.,DN:........... "..4..1u.....%.u..{{,....@lp..}..`.......Z...K.....Z..... Z4.<?..C.BF.....k.!Hl...]...Tvf..g....)...vny6.'..f....Z.R.`.......+....!..!.....:..4fj....."q..f..E..^!k.....M.c....R...B......g...~.........o.'.7,.e.,..7.R.e,(.+..+:....Q....f...P.H.I..U.....Jl...l...z.]7...C...<...L.,..@...i.{..e]K...2..KRW..7.-'.G.l!.n7..J.v.C...%/.....q...@..l..e..$..N..sg8]oo.(q(_.?.X.s...Ua..r0...Rz.o.eT.j...b*..}",n.qou..M.[.;%../c.x.4.z.2*.U.]..D...h...-R.$.=\3..P......N.mP......J...}BPn...g]d.5k..C.ee.ml...\.g...[.......<..6$.%.I#S9..I...6.i........_..P.n....c$.3..zw.hF......_{.+...o...[.&........&...M..m.....;....0....D7...4nQ.=/.._`._.nh.D.m..h.+....8..p..q.4.w.\...iy...*...lN6F..c.
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:Microsoft Cabinet archive data, many, 12767 bytes, 2 files, at 0x4c "ieee2006officeonline.xsl", iFolder 0x1 "Content.inf", 2 cffolders, flags 0x4, number 1, extra bytes 20 in head, 9 datablocks, 0x1203 compression
    Category:dropped
    Size (bytes):28911
    Entropy (8bit):7.7784119983764715
    Encrypted:false
    SSDEEP:384:WnJY165YD0tPYoCKa3HueqRyzVscLk1Yj2GjcgbA8E0GftpBjE2kWTpjFLrHRN7N:X4rtPzCK6uRoljXBA8Pi62ZphL0HRA5p
    MD5:6D787B1E223DB6B91B69238062CCA872
    SHA1:A02F3D847D1F8973E854B89D4558413EA2E349F7
    SHA-256:DA2F261C3C82E229A097A9302C8580F014BB6442825DB47C008DA097CFCE0EE4
    SHA-512:9856D88D5C63CD6EBCF26E5D7521F194FA6B6E7BF55DD2E0238457A1B760EB8FB0D573A6E85E819BF8E5BE596537E99BC8C2DCE7EC6E2809A43490CACCD44169
    Malicious:false
    Reputation:low
    Preview:MSCF.....1......L............................1...?...................0......"}..............ieee2006officeonline.xsl.:...............Content.inf.........[...G."...3$pE...G B....m3o[...I2&.f.,\..........}.n..{..e.8!^.3.A@...x..... .D.52gU..]..."..N8....s..CS..J3..HV...m...y..o....F.z......V.j._....=~k.....'.dY........1........#...d13.g.&C...C.xw.`f.hf..........]M....m.m....ud...,+.H~..cL...e#;(RI...eA....I.b...E...2..(...$.j...L...$..A....'[...H9..&..G.Q....".M.yl....]..?j%+....O~.*....|.se...K\.B"W..F.5.......=s...l.Y...K..yN.TBH[...sTWR.N.d...WEa....T.d.K.^sauI......m..s=.,qso5.b.V.s.]..9..,k4.\..L.;D...........;r.C...7.w.j..:N8.V6..a.3..j:A.mA..To..$.5....:./..p.x.3.=..__...8.EB.K.*..].-."..5-XU..J.....=o..K.Wavg.o].z.9.gk.._.........MZ.<.5............OY.n.o...r.9v.c.......[n.[..D...d..}.j.....LB,]_.9..St.@..C....\...^....-&.njq..!P....G^.....w.7.p~.......M..g.J............t1......q.w.rx...qp.....E.........-...2..G.........z.]B........d....C.@...@.
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:Microsoft Cabinet archive data, many, 27509 bytes, 2 files, at 0x4c "Equations.dotx", iFolder 0x1 "Content.inf", 2 cffolders, flags 0x4, number 1, extra bytes 20 in head, 2 datablocks, 0x1203 compression
    Category:dropped
    Size (bytes):43653
    Entropy (8bit):7.899157106666598
    Encrypted:false
    SSDEEP:768:+bjfeR1OOZvv439PlDe5/QzhgFSo0UEDmJwkqTA8Pi63Bsgn66w:IM3CN9ZzhFbUUwaP73BsB6w
    MD5:DA3380458170E60CBEA72602FDD0D955
    SHA1:1D059F8CFD69F193D363DA337C87136885018F0F
    SHA-256:6F8FFB225F3B8C7ADE31A17A02F941FC534E4F7B5EE678B21CD9060282034701
    SHA-512:17080110000C66DF2282FF4B8FD332467AF8CEFFA312C617E958FDFEBEE8EEA9E316201E8ABC8B30797BB6124A5CC7F649119A9C496316434B5AB23D2FBD5BB8
    Malicious:false
    Reputation:low
    Preview:MSCF....uk......L...........................uk...?...................j......r...............Equations.dotx.................Content.inf.94v..R..[..... .............v........." Vw.w..r.....D.V5.p...W......b;....\x.....f.-...............l.....L.F..*..@..BnF.I.....%1..0....&.X.......X-.\.\.>..A....@..:...N .G./.Sp.A0.0.`.....q....b... ......S.{K...V....J............>\....\.E.#.,$.hxu.F.Fo....<...{..6../..#..l>d...w...&...S.....L.].....^..L......;~l.......qw.o. .....v.u.W`.4Z.A.....dC..Q)9.c..qgtfJ..G.(.J....q4V.).mK4;..zY..b.5&....V...0X.].Z..U.Lx..^..:8XQh.....7yy.._5............c.W...c...xY..%..G.$....kg^.1g.9.....z^.'...q."..K)a[.pW .LS.:Q8.....2..._q.os....y...d11.*.m....8.,.^.4_?i.e.u.,....._y.....zZZA.D.D<..+....{....Sfnv...t.....0...vV..y.r..3..%.<.t......;.h.wh.-.g.>..5...R...........y..]^..R..<...>$~.'...kk.n..H.EN.eQ.Q.O./='....)t.l0,/].....FNN......?...&..'.eS....K.K.v".^L..x=.^......1x|....=}@...B.kq;_a..C.q?..Y9.v......Q..u.G..V.
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:Microsoft Cabinet archive data, many, 14939 bytes, 2 files, at 0x44 "CircleProcess.glox" "Content.inf", flags 0x4, number 1, extra bytes 20 in head, 1 datablock, 0x1203 compression
    Category:dropped
    Size (bytes):31083
    Entropy (8bit):7.814202819173796
    Encrypted:false
    SSDEEP:384:0XbSq3W46TVZb5fOFo1HtZwGqtRT44hS+nyBoiuFgbA8E0GftpBjEcBFLrHRN7Ku:0XpOflfOFo1DMr/iuuA8Pi6cfKjW66b
    MD5:89A9818E6658D73A73B642522FF8701F
    SHA1:E66C95E957B74E90B444FF16D9B270ADAB12E0F4
    SHA-256:F747DD8B79FC69217FA3E36FAE0AB417C1A0759C28C2C4F8B7450C70171228E6
    SHA-512:321782B0B633380DA69BD7E98AA05BE7FA5D19A131294CC7C0A598A6A1A1AEF97AB1068427E4223AA30976E3C8246FF5C3C1265D4768FE9909B37F38CBC9E60D
    Malicious:false
    Reputation:low
    Preview:MSCF....[:......D...........................[:...?...................A..............CircleProcess.glox......A..........Content.inf......9.B[.....@*........!...(A.D..K.W.wwpwJj\.K\w...]...K.!.....@0..?,...}won`... ....&I..(;.....X.u..^.R..^......_:....W>f\....T...B..i`|q.....................i.5....(........0q7@.@..F...?A.`.....,L.......5.+../56..a`....1C5..9.*I.N.......@|<+./......... .ya....>l.,t.......y.y5...FF.,F..jCA...SA..H....8u.L..eM?.w8.......~^.Mr.[...(.._......u..+.......j..TJ.:<.3.X`...U.bz...[...r-...[...+..B.......}...\'.i...C.8.B_...c.8</..s.....VQ.Y..m.,.j~;y ...2.5.VQ...K..jP..2..r-...HA...."..9).7.....5.E._.wq.......!.+n+.f...s].4M'.1&...5....4..k..NV.M1.7`a..<.P4.|.mrd.i.R...u...............v.}..n\.C$.....[..2c.^..W..g..._.0.C.o....%.z.!.;.@y.`\..UO#i.)...Q...........L. .\:_..H.{.W...@...T.4..A.a...Wo?o$4.....#.V.s8M.Gh..p?A...Y.....)...........r|...!..o9...8..%#.[....;...3<Z...g....~.Z....,.(...qA.'x#..xC..@...HOuW.[.[....c.........
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:Microsoft Cabinet archive data, many, 14813 bytes, 2 files, at 0x4c "iso690nmerical.xsl", iFolder 0x1 "Content.inf", 2 cffolders, flags 0x4, number 1, extra bytes 20 in head, 7 datablocks, 0x1203 compression
    Category:dropped
    Size (bytes):30957
    Entropy (8bit):7.808231503692675
    Encrypted:false
    SSDEEP:384:rKfgT03jNkAFbgUQWtxq9OGh1bBkd/1MVHb5iVOdMgbA8E0GftpBjEl8tFLrHRNF:r303jOrUQAkfhopWHbA8Pi6l8zuUIq
    MD5:D3C9036E4E1159E832B1B4D2E9D42BF0
    SHA1:966E04B7A8016D7FDAFE2C611957F6E946FAB1B9
    SHA-256:434576EB1A16C2D14D666A33EDDE76717C896D79F45DF56742AFD90ACB9F21CE
    SHA-512:D28D7F467F072985BCFCC6449AD16D528D531EB81912D4C3D956CF8936F96D474B18E7992B16D6834E9D2782470D193A17598CAB55A7F9EB0824BC3F069216B6
    Malicious:false
    Reputation:low
    Preview:MSCF.....9......L............................9...?...................8......1P..............iso690nmerical.xsl.................Content.inf...A@...[...5.....33.E...P.../..........5sv.]3srm8.T.=.......}.v.T.. ..4IH.r.%Z.(.q.\+K..[,....E....A......#CEF..}p..Y/s$...YKI.#M.?.t.1#C....I..v.vn...-...v7../S.m.Ma.....!.Y....4.......3.3....c&R9..%......(J..BDMI.>7J.....".....}.w.}w.wg.v...^.n.{....{f.mlI..%.#..I..S....D..QJ U......4........K.(@....DH.....}...8;..z...&0%e..G.OAM..x.3......\....zS9....}......89.B...e.W.p{;.....m.m3...}....../...q.~..;.,..".j.g..^N............iC.../|...g.=..9.Q].Gf.....QA....74..v.....9.n[......0.}..jo{y./.2..Ym......;u...b.(Jz^.....~..uM...{s../..#.)n2..S.S.c..6)U.V....!.'R.......P.S.D..S.p/......D.......{......?.u.",...Mp._....N..+..=Y#..&0w....r.......$.xwC......P.e7.>O....7....].y%q^S'....*.C.`.?..}Q..k../u.TK...y........S...{T.?......[.H.'L..AS.Y.|*..b...J.H-.^U>'9..uD[.".b[.l.......o..6.L).h.B0RJa.b..|m:.):......F
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:Microsoft Cabinet archive data, many, 19375 bytes, 2 files, at 0x4c "turabian.xsl", iFolder 0x1 "Content.inf", 2 cffolders, flags 0x4, number 1, extra bytes 20 in head, 11 datablocks, 0x1203 compression
    Category:dropped
    Size (bytes):35519
    Entropy (8bit):7.846686335981972
    Encrypted:false
    SSDEEP:768:2LFougzHaUdBKUsM+Z56zBjA8Pi6bo+ld8IX:MFodzHaULR9P7bo+l6IX
    MD5:53EE9DA49D0B84357038ECF376838D2E
    SHA1:AB03F46783B2227F312187DD84DC0C517510DE20
    SHA-256:9E46B8BA0BAD6E534AF33015C86396C33C5088D3AE5389217A5E90BA68252374
    SHA-512:751300C76ECE4901801B1F9F51EACA7A758D5D4E6507E227558AAAAF8E547C3D59FA56153FEA96B6B2D7EB08C7AF2E4D5568ACE7E798D1A86CEDE363EFBECF7C
    Malicious:false
    Reputation:low
    Preview:MSCF.....K......L............................K...?...................J.......@..............turabian.xsl."...............Content.inf._.......[...T.....C4.5...E0B.]...+.-f....rc.[52.$...a..I....{z...`hx.r...!.. $...l..\....#3EF..r..c;<p...&n.\b..K..0Y..c+.2...i..B..wwY..77,...........}.q.C.......n..,.....prrx.QHy.B#..,.'....3....%1.``..hf...~...[.[n.v.s..y.vw....;..s.G293G&H....$E......m.&^..iy/.4.C...D...".(H&..&.I4._...!...... ........q.k1.d.....qc.3.c.....;.5.......y}...}&...+.WAN.,zVY.Q....V.Tz........g..H..c...E2jY...4g?.yf<....V.M.s.$..k.Id....+..?..._.\.s.k..9..I%;.yWQ..S..]..*.n<.7........=......"Q.*E.....MG..j.Yt..!U....Q.j...v.h-.~b..e&.......;...\.....:.....=..Xv1&q........6\...xw.%*.VdS..H...o...s.....+..%[../>.t..I....F.....".G|.....=....[..S..3..a.C.ZZ...tK.6N..b........)>........I..m..QE.M.nv.MVl.....vCG>,.suP.gqo.rr....J`m....J.b..},[F*....e.A.]..r....C4.?JJs6..l.].9...Q.B.~.......\d%.X ...8A....rH....&?#...^.....4.h.{>
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:Microsoft Cabinet archive data, many, 16689 bytes, 2 files, at 0x4c "iso690.xsl", iFolder 0x1 "Content.inf", 2 cffolders, flags 0x4, number 1, extra bytes 20 in head, 9 datablocks, 0x1203 compression
    Category:dropped
    Size (bytes):32833
    Entropy (8bit):7.825460303519308
    Encrypted:false
    SSDEEP:768:+0TU06CkaUYMoi//YX428RaFA8Pi6e9iA4I3w:vICTm/QorUpP7eAA4I3w
    MD5:205AF51604EF96EF1E8E60212541F742
    SHA1:D436FE689F8EF51FBA898454CF509DDB049C1545
    SHA-256:DF3FFF163924D08517B41455F2D06788BA4E49C68337D15ECF329BE48CF7DA2D
    SHA-512:BCBA80ED0E36F7ABC1AEF19E6FF6EB654B9E91268E79CA8F421CB8ADD6C2B0268AD6C45E6CC06652F59235084ECDA3BA2851A38E6BCD1A0387EB3420C6EC94AC
    Malicious:false
    Reputation:low
    Preview:MSCF....1A......L...........................1A...?..................S@......v...............iso690.xsl.................Content.inf.B.9.....[...A.c...32.E...P..'.^}.f...ikMJ....m..s..U.w{m{{...}n.4........I. ..9..d..I.......P|....F...F.......&&J.:I.34......+*M3..4mr.........m.r..m)....dK.wiw...H,...r........y.$..Cu...L...dH.../..V......g.PG$R39...4O..............{w..^....c.m.m.o.....#..Fgs..6.....b....3.I..O....B..B..1h"....K|f .41......_..g.N.<.>........(....o3a.M)....J..}....-......8.......g.hm!r<...-..1.1....q.?....S.m...`L.g#.K.igv.].ghD....L...p5..?.......iP.[JS.J..?z~.T/.Q...E.K.......P+\LW.-.c..[9.n.7.....P...*[.A1....m...4h.9...N[....h5 n%k.~RR.*c..n..=...4....).eH.-./..>....*.r..S.*..dE.........pF..s.A..?...f..u.+.{..?>N.4].}Xb.M......y......'.2..'..........J4{r..r.3........5>..a0.>.u_.y@g....+y.yu--,ZdD.........5]3..'.s...|.....K.....T..G.G.e...)..\x..OM.g...`..j0......BfH...+.....:......l`.qU...;.@...",.."........>;P.B.^F...3!......Rx.9..
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:Microsoft Cabinet archive data, many, 15418 bytes, 2 files, at 0x4c "harvardanglia2008officeonline.xsl", iFolder 0x1 "Content.inf", 2 cffolders, flags 0x4, number 1, extra bytes 20 in head, 9 datablocks, 0x1203 compression
    Category:dropped
    Size (bytes):31562
    Entropy (8bit):7.81640835713744
    Encrypted:false
    SSDEEP:384:yhsBScEWkrljntbzuMmWh7ezPnGgbA8E0GftpBjohgsRFLrHRN7ybll7PK/p:MsBScwtnBmWNeTzA8PiuWsvyDI
    MD5:1D6F8E73A0662A48D332090A4C8C898F
    SHA1:CF9AD4F157772F5EDC0FDDEEFD9B05958B67549C
    SHA-256:8077C92C66D15D7E03FBFF3A48BD9576B80F698A36A44316EABA81EE8043B673
    SHA-512:5C03A99ECD747FBC7A15F082DF08C0D26383DB781E1F70771D4970E354A962294CE11BE53BECAAD6746AB127C5B194A93B7E1B139C12E6E45423B3A509D771FC
    Malicious:false
    Reputation:low
    Preview:MSCF....:<......L...........................:<...?..................D;.......V..............harvardanglia2008officeonline.xsl.L...............Content.inf.Vu......[...E..o..3D.5..nF.A..+.e.....6r..f........M3...-.s.m.... $r.b.!.q!.....G...0.\.......fd......%m...'1Y..f..O...*.#.P.,{..m...|..ww.{.m...f...n%...,..y...0y...8.Q...`.../.q....a...',.V......8.7..8t..................6.]..6..nw..ynm..-l.Y..,.I?..$....+b9$E!S@"..) .4........H...lA...@!a.F.l$..0#!.....n&.5j.t+..1f|.+....E.zDk.l8.+<q.^.........\5.l..iT.9...........Y..6.^,.o.bn.E*5w..s.../...W.gS..j9..'W.F......].4\Mzz..Td..Ho..~.Q...Z..D..O.JP..m..s.j.:..........y._.....#.*.rD....60.\!y........p.o3,..Ub,......[[L.{.5.....5.7UDB9.{;;g.z.z..jM.G.MY.oe.....(r..B6..CV.7Fl.Z/....-.O.vY.c...-..........b.T)3.u..f~x2.?.8.g.x.-.....Qt_...$e.l..jtP..b....h..*.sW0.`.....c...F_....t.........LC..*5I.X$^.;&....#.._\J..........;..wP..wX.qy.qs...}46..fK.XN.&0........k1....8...............'t.......}.......O_.
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:Microsoft Cabinet archive data, many, 10800 bytes, 2 files, at 0x44 "ConvergingText.glox" "Content.inf", flags 0x4, number 1, extra bytes 20 in head, 1 datablock, 0x1203 compression
    Category:dropped
    Size (bytes):26944
    Entropy (8bit):7.7574645319832225
    Encrypted:false
    SSDEEP:384:sbUX16g8/atF4NB3TJOvqeMRD/8svIZj/OwgbA8E0GftpBjEYwFLrHRN7mYll7PY:sbhg8yY4nMZK2hA8Pi6Yum4IVR
    MD5:F913DD84915753042D856CEC4E5DABA5
    SHA1:FB1E423C8D09388C3F0B6D44364D94D786E8CF53
    SHA-256:AA03AFB681A76C86C1BD8902EE2BBA31A644841CE6BCB913C8B5032713265578
    SHA-512:C48850522C809B18208403B3E721ABEB1187F954045CE2F8C48522368171CC8FAF5F30FA44F6762AFDE130EC72284BB2E74097A35FE61F056656A27F9413C6B6
    Malicious:false
    Reputation:low
    Preview:MSCF....0*......D...........................0*...?..................t,..............ConvergingText.glox.....t,..........Content.inf..C..)t-[.....@.........=...xxA. ...E^....x.x.^.......x..^^...DF.......s..d.P.....5.;..]...2.t.w.....O9.G..;.'.T....@I.,.q.u.3..P...9... ....`J.......g.(....).,.h0.....$.3..;.._.....~.de.jj.....U..K.0....`.@.H.1.x.Z.@..q....?....x.wW.....+am8A".....I..)..]...s..-z.2S+|.Cb.t6f],.n.LV......OVg....O.at|..-..x.....:....]s...u..g}.P..v.3....^.".%..%...#.2.....l00...n.......r8.p.....^.....n.)..,..t.^$b...b.q.W...F..R...n.-.+..'........Aw=._OwH....8.:s..{.#..{N.hW..`.._........Wy....>U.?....-.8tg...=..y..@.,.v|......l...t..l#{...H....9..|......~...De..#@y.&K....U...q.c.zK..D.<pV.....Ql..&Y...=#...w....r.`#2....Ug.J(..T...KmW.@...!....j:......M......!..E.7#s.t..F.aU..N....-.i......|w.lr..G.n.,.......=Kl.-m.?F.....v]?.......{q.U.t...<.|..u.....3R.`.t.T.>;v.....KQ...S...7..1...N.kN.y.)v.....3H:..D.{.+.(......u..^W&.
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:Microsoft Cabinet archive data, many, 4091 bytes, 2 files, at 0x44 "BracketList.glox" "Content.inf", flags 0x4, number 1, extra bytes 20 in head, 1 datablock, 0x1203 compression
    Category:dropped
    Size (bytes):20235
    Entropy (8bit):7.61176626859621
    Encrypted:false
    SSDEEP:384:j3W3yGyjgbA8E0GftpBjEHvFLrHRN7pDAlI66Yv1:j3WFyAA8Pi6HVpDZ66c1
    MD5:E3C64173B2F4AA7AB72E1396A9514BD8
    SHA1:774E52F7E74B90E6A520359840B0CA54B3085D88
    SHA-256:16C08547239E5B969041AB201EB55A3E30EAD400433E926257331CB945DFF094
    SHA-512:7ED618578C6517ED967FB3521FD4DBED9CDFB7F7982B2B8437804786833207D246E4FCD7B85A669C305BE3B823832D2628105F01E2CF30B494172A17FC48576D
    Malicious:false
    Reputation:low
    Preview:MSCF............D................................?..................................BracketList.glox.................Content.inf....7r...[.... G.q..@...B.....?X!.A.......!........X..Vk.JK...Z..=......PD.....P....5...jp..+..T....b.)np5.7.....Zz........... ..!.....S......1....`....h......T?.Nq../......z....[..:..5f;....O...d.FxD...4...Z....[..a...w..W.[..P...5.]...6..."...+t].!...2\%%`Q.\..)...=>.)......a.$.2.,...2,.Lw.?..+..qf....h....T/B.....}T.E...'.%.....,.......X....b..gt.hPYc|.....a...j...=...{..a.`!8!..|...L.T..k..!,.R.z/W....{..,...+..w.m..sQ..7<x..B....?....\.)..l...d...}.....v..W.C..'=p1c.Z=.W.g.e....&wm..N,..K.T../.oV../=9.}.....".28...r.Q....dzj{....S...1m...x9_...2PXpa...Q.n.$z...c..SGq...k......}kPE..*...3.|.5A.>..6.......+)qCB....q....qNkGe...W]..o..Z...J.<.i......qq.8....q..BE.(...._h.U.\@3.F...KdO..=1j+....).*Q.|B..Z..%......LDYk....j.....{klDW..#CVy}...X..O!..}..s..&..DC.....tL.j..b.......[...n.'..1..Xc...9Q..gM.....n..3...v.....~.).
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:Microsoft Cabinet archive data, many, 7453 bytes, 2 files, at 0x44 "pictureorgchart.glox" "Content.inf", flags 0x4, number 1, extra bytes 20 in head, 1 datablock, 0x1203 compression
    Category:dropped
    Size (bytes):23597
    Entropy (8bit):7.692965575678876
    Encrypted:false
    SSDEEP:384:y6aR//q0bJi/Uj+957G8E0GftpBj/4YOFLrHRN7LxhKll7PK/ph:y6I/Li/UjmVG8PiZ4YsLxh6Ih
    MD5:7C645EC505982FE529D0E5035B378FFC
    SHA1:1488ED81B350938D68A47C7F0BCE8D91FB1673E2
    SHA-256:298FD9DADF0ACEBB2AA058A09EEBFAE15E5D1C5A8982DEE6669C63FB6119A13D
    SHA-512:9F410DA5DB24B0B72E7774B4CF4398EDF0D361B9A79FBE2736A1DDD770AFE280877F5B430E0D26147CCA0524A54EA8B41F88B771F3598C2744A7803237B314B2
    Malicious:false
    Reputation:low
    Preview:MSCF............D................................?..................................pictureorgchart.glox.................Content.inf.W..y....[.............../.jC....U.CUUUTU.5...jjPU..MP....T..0*....o0.......Y.=....P.({.3.p..."pA!>r../3.q..7...........!...TO....(..%......6...3E?....~......CZmndse.Qy....p....h....=.:5...F..%.E.&.v.`I~. ..%._..b]..Y..Q..R.........nN.q8c..a..L..X/.M...PP.q..SpZ.K]>D"Pf..B.c....0..|I.Q.,.g/..Kev.../..=......w..}3.....(....+#T.....K`N.u..Z.....rriK.(...(...6.<R.%.]..NX..b..].C.u....++......Ia.x. .7....J.#............w>....7..R...H>....@%....~.yA.......~.UB..*. .P..$...-...v.....=M."....hw..b....{.....2pR....].C..u@=G."Y..;..gc/N.N.YB.Z.q.#....$....j.D.*.P..!.)S.{..c....&'E.lJ%.|O.a...FG.|.....A..h.=c7.)d.5...D...L...IQ..TTE.*NL-.*M..>..p0.`......m..,.w#rZ..wR\@.Wn..@Q...}..&...E...0K.NY....M.71..`.M./:.>..._L..m...,U.l....._fi...nj9..,..w.s.kJ.m.s.M.vmw.!.....B.s.%.-').h.....)c.l....F..`3r...-.....0..7..&N.....n.#H...<7
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:Microsoft Cabinet archive data, many, 15461 bytes, 2 files, at 0x4c "gostname.xsl", iFolder 0x1 "Content.inf", 2 cffolders, flags 0x4, number 1, extra bytes 20 in head, 8 datablocks, 0x1203 compression
    Category:dropped
    Size (bytes):31605
    Entropy (8bit):7.820497014278096
    Encrypted:false
    SSDEEP:384:7SpOUxgQ9gFodHZktfHa2TSmcAg76j8/xorK0JoZgbA8E0GftpBjE2PzFLrHRN7S:OngHltf7Bcp/xoB3A8Pi625D8RA54
    MD5:69EDB3BF81C99FE8A94BBA03408C5AE1
    SHA1:1AC85B369A976F35244BEEFA9C06787055C869C1
    SHA-256:CEBE759BC4509700E3D23C6A5DF8D889132A60EBC92260A74947EAA1089E2789
    SHA-512:BEA70229A21FBA3FD6D47A3DC5BECBA3EAA0335C08D486FAB808344BFAA2F7B24DD9A14A0F070E13A42BE45DE3FF54D32CF38B43192996D20DF4176964E81A53
    Malicious:false
    Reputation:low
    Preview:MSCF....e<......L...........................e<...?...................;......................gostname.xsl."...............Content.inf.[.......[...>..|..32.E..o`h....W.>.^...v..5...m.w.$.U..U......m.mu...'4....m`.9F.. ...I..PTS..O.D...GM#...#CUE.`.`%n..N...G,.~..+.6cv.L...G.m.Y..vy.....Yh9/.m,..wtw..;....Ka.a.{.\...'.....<X....%)...G..d......R./..4$..32..@....f.h....w..ov.}w..[.....{.v.......dr..&w#G..$3.zI&f..(C..L.z5J... .`...!.!4. ...!.` .$........w.J.X7.w_..@.w..f]=.C.....I-....s.s_.x...~..A... ...z...nM..;....Z....vt....6...~.w.....*x.g.h.T.J..-.3=....G.n..ti.A...s...j$.Bf..?......6.t.<j...>.."....&=BO?w.uN.o.t.-r..K....>C..^G..p...k...>.xZ.[fL..n.."].W#...|.i.0W.q.F: ..<#w......w....s....."...n.qu.../rI.....q....P~.B..|b?.N.}..MyO..q..:q.7..-~.xa.S...|.....X.....g.W.3.mo..yy.GG.s>....qy....r........#.F.P..A.......A....b.2..14.8.i6..w.S...v~{0z.<.Z...^!.;2mSV.i....{...U...+...r.;...h.++..T6.a...$....j5F+..1t....b......|.Q\d-.S..2... ......Y..A...s....
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:Microsoft Cabinet archive data, many, 5647 bytes, 2 files, at 0x44 "RadialPictureList.glox" "Content.inf", flags 0x4, number 1, extra bytes 20 in head, 1 datablock, 0x1203 compression
    Category:dropped
    Size (bytes):21791
    Entropy (8bit):7.65837691872985
    Encrypted:false
    SSDEEP:384:PWew5RNDcvPgbA8E0GftpBjE0hsyaFLrHRN7BD9lI66YR:P3GRNDcEA8Pi60hsyABDo66g
    MD5:7BF88B3CA20EB71ED453A3361908E010
    SHA1:F75F86557051160507397F653D7768836E3B5655
    SHA-256:E555A610A61DB4F45A29A7FB196A9726C25772594252AD534453E69F05345283
    SHA-512:2C3DFB0F8913D1D8FF95A55E1A1FD58CE1F9D034268CD7BC0D2BF2DCEFEA8EF05DD62B9AFDE1F983CACADD0529538381632ADFE7195EAC19CE4143414C44DBE3
    Malicious:false
    Reputation:low
    Preview:MSCF............D................................?..................................RadialPictureList.glox.................Content.inf....8....[.... $nq......C...../U..........a......S.Q...Q....j............(..z,.g.........^...Y..D... #i.TH5.<.=N..$..7.p".7.............`.3..1~,=,(.d8.Z.1....4'G.....!W^gClf._j.-N..&k.....Y3` =.(S..B^...i.zB.U....0O..h...I.(.......L...5.X.8.Sc<=>w.=.?&.....mR.......x.......mpW.T..^.FU...SN.C)......vsa.,x......,....E..i>..[g...#t...M..GR.9..$/4.:..q.bc9..x{bC.0..K.)..t.Y.&.v.d.16.B..c..or..W.,.B.........O.0..k.v........*F+..U.w...d...o8......A).}...#......L.!?.U.r.^.$...e.(..PG)8..+.9.5.l}.)..b.7+. 4....-.lC...|..j..Q.,.....7.W...|;j...%...:...|H..........<..%...K.....Fy.q$.k..}..8.9.M.u.?$].......r.....e.|..._..iT.;Dq5[....f.s..P.......e.T....!Y{.....t.wm..A..w-..7...3..T.:8.4.a[.Oo.. V.l.@.}..........E.&..J.....+..+.9)9<.._R.Hb.....V..Qu....:v.t.Li.0..J..V..b...!..N....-mD..c..(.[&o>.M.b..H.q..lk../..........W.8..z..B...
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:Microsoft Cabinet archive data, many, 6005 bytes, 2 files, at 0x44 "HexagonRadial.glox" "Content.inf", flags 0x4, number 1, extra bytes 20 in head, 1 datablock, 0x1203 compression
    Category:dropped
    Size (bytes):22149
    Entropy (8bit):7.659898883631361
    Encrypted:false
    SSDEEP:384:b98FG/zdCbf7BOEawSi8E0GftpBjEPTFPxFLrHRN7S5ll7PK/pA2:N/zAbDae8Pi6PFPSRIA2
    MD5:66C5199CF4FB18BD4F9F3F2CCB074007
    SHA1:BA9D8765FFC938549CC19B69B3BF5E6522FB062E
    SHA-256:4A7DC4ED098E580C8D623C51B57C0BC1D601C45F40B60F39BBA5F063377C3C1F
    SHA-512:94C434A131CDE47CB64BCD2FB8AF442482F8ECFA63D958C832ECA935DEB10D360034EF497E2EBB720C72B4C1D7A1130A64811D362054E1D52A441B91C46034B0
    Malicious:false
    Reputation:low
    Preview:MSCF....u.......D...........................u....?..................................HexagonRadial.glox.................Content.inf.........[.....`........./.mT.T6...CP..z5...0.PcUmCUSUCU.Q.P.0..f............^...H..2e.[..8...ld......*F.%.j.w!R..NA.L............ .r..z....$&.........P.=.r...O...e..dfv_.i%.C....^......?..x...+d..].B.3..EU...|Cc..z.`lQp..fr.....8!;.8.p.ZwH\.........~..T.t..]..H.]..S.2..Vt.....r.H../..-8........!:.Y&..|A..J.U...-.%..k..U...4m.. .q../..b.8.vc~......_q1.?..Bh.v.....L..I.$I..s.".u.. Y....I^5.v...3.......].^)b.t.j...=...Ze~.O...|.}T.._9c........L....BV.^......X..?.....{.>.j..5.m...d.7........g[..f.nST...i..t..|.T.jjS..4p.Pxu..*..W...|.A)..|9;....H.e.^.8D..S...M..Lj.|...M.m+..H.....8.&-....=.L.....n.v..M.9...l....=r......K.F.j.(.(xD.3..r'9.K..-...5..Z..x....._....a[...J...`.b_a\\j.ed..\.3.5....S.T...ms.....E...Xl.y.LH=...}..0.T...04.4..B[..H.....B{B9.h..=.8Mn.*.TL.c..y.s.?.c9$l...).h).6..;.X../_>Pl...O...U.R..v.dy$A
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:Microsoft Cabinet archive data, many, 4967 bytes, 2 files, at 0x44 "TabList.glox" "Content.inf", flags 0x4, number 1, extra bytes 20 in head, 1 datablock, 0x1203 compression
    Category:dropped
    Size (bytes):21111
    Entropy (8bit):7.6297992466897675
    Encrypted:false
    SSDEEP:384:wWZsOvbMZGgbA8E0GftpBjEtnFLrHRN7Dfll7PK/pirk:xZRvuzA8Pi6t9DPISk
    MD5:D30AD26DBB6DECA4FDD294F48EDAD55D
    SHA1:CA767A1B6AF72CF170C9E10438F61797E0F2E8CE
    SHA-256:6B1633DD765A11E7ED26F8F9A4DD45023B3E4ADB903C934DF3917D07A3856BFF
    SHA-512:7B519F5D82BA0DA3B2EFFAD3029C7CAB63905D534F3CF1F7EA3446C42FA2130665CA7569A105C18289D65FA955C5624009C1D571E8960D2B7C52E0D8B42BE457
    Malicious:false
    Reputation:low
    Preview:MSCF....g.......D...........................g....?..........}.......................TabList.glox.................Content.inf....t....[......@..C...../.U5...........6...`.....T..>3.................=..09`..t......a..Y..BI.Z....=.'0...%...T..........H...>.:A.r......n..p...Pf.h...I.8... ....M.]&.#.vv'.....[c......g....>"......<c..f....i...sb!Z..iu<.%|......q.....G28.h-...7.....W.v...RtdK..F~.0.3.'.e..b7.c......a.3.....a\..]...gp8.+.u/}.w.qF........8.=.=|....\~..S.-q}]0...q.B.H.^J...!...a'.2Tn!..."..%........=.e_-.....{o..%o...a`.w..L.5..r.....e.8...pO..RE.Wgr..b.%.E...O.......8s...E....Um].C..M.....[...H.FZ..4...eZI.$..v.3<]..r....B..............8i......e<.D...Q4.q.^S.....H.b.......r.q..0o.......2..PP,."...JI...xU`.6f..K..Q9.Q..h..t....AI.S6...7............X..`dv..r..S....),7ES....#.....(...\.nh...X.ps%l..F...."<_....q....v........_.e.....P.........|&..fi..4..@..^0..v.]7.......^. ."..}(...w.g.X...=<....p.......L...P..XV....@:....N...Y....
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:Microsoft Cabinet archive data, many, 4410 bytes, 2 files, at 0x44 "PictureFrame.glox" "Content.inf", flags 0x4, number 1, extra bytes 20 in head, 1 datablock, 0x1203 compression
    Category:dropped
    Size (bytes):20554
    Entropy (8bit):7.612044504501488
    Encrypted:false
    SSDEEP:384:zEAH676iPi8+IS5iqn7G8E0GftpBjExDxIHFLrHRN7Ke/ll7PK/pGaz6:zEhG8+ISrG8Pi6xDxCKoIGaz6
    MD5:486CBCB223B873132FFAF4B8AD0AD044
    SHA1:B0EC82CD986C2AB5A51C577644DE32CFE9B12F92
    SHA-256:B217393FD2F95A11E2C594E736067870212E3C5242A212D6F9539450E8684616
    SHA-512:69A48BF2B1DB64348C63FC0A50B4807FB9F0175215E306E60252FFFD792B1300128E8E847A81A0E24757B5F999875DA9E662C0F0D178071DB4F9E78239109060
    Malicious:false
    Reputation:low
    Preview:MSCF....:.......D...........................:....?..................................PictureFrame.glox.................Content.inf........[.... '.q..@.........<./..+./. ...."o.o./..{^a.7^.D.HA....^J... ...........T%q..b...+pz.n.=....jT.+M..=H..A...py.3.........H...N...[..%..~....>.%....3.r...wx.....0.....7..94..2..45..7f.......D.. ...[...f.:H..../N..4.....8.....:x.I....u|.`."...\..N..%.M#..^v$.*....T.m.....?.-.wki.X..8..F.G..Y.^8...-....+.&.+&.No...e!.#.8.....YF.......<w.....=.Q.S..7....MW....M..9A.3..c..L....|.E-Y....]n".|....b9..l@.d.T...a.f...~.&k.[..yS..q..]L}..)w.....$.@..v...[9..X....V...a.NK....m9.5.....Kq.;9`.U.e...8.<..)Y.H........z.G...3n.yWa.g.>.w!e.B8:......f..h..z....o.1<.RT..WK...?g .N..+..p.B.|...1pR_......@...a....aA......ye..8...+M.l..(.d..f.;....g........8R.\.w.:ba....%...|p....`lrA.|....a.U.m=ld......7....#..?Dq..D.....(.5.K.a..c.G..7..]hF..%:}......}J.j$.....4...l];..v>.&j........Y.vk..$1.@X$...k...9..?...z..![..../...).a.=....aZ^.3?....
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:Microsoft Cabinet archive data, many, 6450 bytes, 2 files, at 0x44 "ThemePictureAccent.glox" "Content.inf", flags 0x4, number 1, extra bytes 20 in head, 1 datablock, 0x1203 compression
    Category:dropped
    Size (bytes):22594
    Entropy (8bit):7.674816892242868
    Encrypted:false
    SSDEEP:384:L7d2l8FbHaaIKbtv1gDISi8E0GftpBjEZRFLrHRN74bUll7PK/pd:LUlCIOt/8Pi6Zv4bMId
    MD5:EE0129C7CC1AC92BBC3D6CB0F653FCAE
    SHA1:4ABAA858176B349BDAB826A7C5F9F00AC5499580
    SHA-256:345AA5CA2496F975B7E33C182D5E57377F8B740F23E9A55F4B2B446723947B72
    SHA-512:CDDABE701C8CBA5BD5D131ABB85F9241212967CE6924E34B9D78D6F43D76A8DE017E28302FF13CE800456AD6D1B5B8FFD8891A66E5BE0C1E74CF19DF9A7AD959
    Malicious:false
    Reputation:low
    Preview:MSCF....2.......D...........................2....?..................0...............ThemePictureAccent.glox.....0...........Content.inf.o.@D..8.[.........B.....?. $...K.....~....aZ.WA"...k.......Z......."......"..X.fpB 2@d..87.[.A......p..e.'......F..P^%.%.RK...........T%0..........9..+8 ...&.q.....+.......^.fad^^n...d.....s1..... .3j.c-c7..y<.....6........C5n.KG...Rs[lt..ZkwI.!..Uj.ez_!A^: /.;.Rl4....^..<6..N...'.YY.n*.E{.`..s.7..z.......L.y.Y.....q.kx.....[5.+<to......1...L.r.m..kC.q.k.1..o.w8s.....xh.@.b.`l\...}z1.6..Y.</DY...Z5..D...0..4.;..XAA..0qD..E.....h...C..hH......S..Z.\.VBu......Rxs.+:RKzD......{......a..=......).<.....d.SM.......c!t.4.h..A=J~.>q?Hw.^.....?.....[..`....v.nl..A.u...S!...............c......b.J.I.....D...._?}..or.g.JZ#*."_``.>.....{...w......s...R.iXR..'z....S.z.\..f.....>7m..0q.c-8\..nZw.q..J.l....+..V....ZTs{.[yh..~..c........9;..D...V.s...#...JX~t8%......cP^...!.t......?..'.(.kT.T.y.I ...:..Y3..[Up.m...%.~
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:Microsoft Cabinet archive data, many, 5731 bytes, 2 files, at 0x44 "ThemePictureAlternatingAccent.glox" "Content.inf", flags 0x4, number 1, extra bytes 20 in head, 1 datablock, 0x1203 compression
    Category:dropped
    Size (bytes):21875
    Entropy (8bit):7.6559132103953305
    Encrypted:false
    SSDEEP:384:k73HRpZA6B3ulrnxtRT7G8E0GftpBjEdHqlFLrHRN7uhFlvQyUTL2m4c:k7XRgIkrG8Pi6dmuNvU+mp
    MD5:E532038762503FFA1371DF03FA2E222D
    SHA1:F343B559AE21DAEF06CBCD8B2B3695DE1B1A46F0
    SHA-256:5C70DD1551EB8B9B13EFAFEEAF70F08B307E110CAEE75AD9908A6A42BBCCB07E
    SHA-512:E0712B481F1991256A01C3D02ED56645F61AA46EB5DE47E5D64D5ECD20052CDA0EE7D38208B5EE982971CCA59F2717B7CAE4DFCF235B779215E7613AA5DCD976
    Malicious:false
    Reputation:low
    Preview:MSCF....c.......D...........................c....?..................................ThemePictureAlternatingAccent.glox.................Content.inf...3.....[.... .qq...........\<.^......o."......f.o...x.{..q..^.MH^...........{0.K....4pX.i...@6A4X.P.01d....'p.......zA.......... .......7.......a. `.=!@- ......>G.s.k~@.a.lfha:m....1...@.,G`....{....W..N..qs.......j.+TrsT.l.9..L...1+...d..-u..-.......).#u&...3......k.&C...DdZ.'.......8..<PF..r.eq.X6...u..v...s5.m.Q.l.G%.<.]....RV<...S..Dv..s.r.......dh.N.3-.Hf'.....3.GZ..E.kt.5......h...|...?!.L....~.)..v....:2.../F.,....o.qi.i7..E.|.mh.R_.@A.FO@i.....Feo...x.l...{E.\W9|V...=#..3..(......tP.:i....Ox.U.N...%6...p.6&.....<zh.z.|.<Z.?.k....y7m...F.Z$-.:.l.h...{T..7....?..T...d,r...z?../...`/Z......a.v@)....u......V..v.:.._.|.'..[..O.s.OAt-."b.In"..I...J*.~H.:-...?..uV....dZ;z:.l.{.E.,.Q..i]:.0r.I.y..f...../j.wN...^R.....u....>..}....f.f...]A..C~;/....%..^#..N.a..........99.....`.....%..iS....S......$....)
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:Microsoft Cabinet archive data, many, 3749 bytes, 2 files, at 0x44 "TabbedArc.glox" "Content.inf", flags 0x4, number 1, extra bytes 20 in head, 1 datablock, 0x1203 compression
    Category:dropped
    Size (bytes):19893
    Entropy (8bit):7.592090622603185
    Encrypted:false
    SSDEEP:384:v3Zh3VlkpSIcgbA8E0GftpBjEmm3UFLrHRN7GYvlvQyUTL2mTAp:v31qp/A8Pi6mUqGGvU+mcp
    MD5:EF9CB8BDFBC08F03BEF519AD66BA642F
    SHA1:D98C275E9402462BF52A4D28FAF57DF0D232AF6B
    SHA-256:93A2F873ACF5BEAD4BC0D1CC17B5E89A928D63619F70A1918B29E5230ABEAD8E
    SHA-512:4DFBDF389730370FA142DCFB6F7E1AC1C0540B5320FA55F94164C0693DB06C21E6D4A1316F0ABE51E51BCBDAB3FD33AE882D9E3CFDB4385AB4C3AF4C2536B0B3
    Malicious:false
    Reputation:low
    Preview:MSCF............D................................?..................c...............TabbedArc.glox.....c...........Content.inf.;....Y.[.........B.....?.T..ZD...........^C...U.R<Z....z+.I.....Z..-.V...f.....lB..\P.....=.-p....w ...\.kD..x'v..T..A..............".8...d.........FD.ZL.h..T...bp.)9B.v..i..VX...&..\..7.s..qy...l........Rty.Y...rU..>.9...8....L..\.^x.kDU.|TJ..{kN.G..E..$.kvy?.. mv......P..4.....q.1.6<u....e..dD...4.1E..Xi.5.=....1.P.c.K~S...YMO:.?..cL.g.tq\.(b1....E..0A.i..C...BT.m.S......:...}.&U..#QL..O.O../..K......=..........0a..O............BYP......>f.......iu...7.K..;QO~.t....%N.s.]>~#../7YN.....C..9.=cY.......y..U5.....,.....u.....#_..SG.`NR*.....?*..d.R.k.rX$...&.... ..h.4T.D^k-xA...............Hz..ep)e..4..P."fo Ne...o.....0n.Exr.........H..v...A.."..%)2......5...".}j.o8...E.HRQ;}.. .._L.+.jz....{.U..}...=B.o.^..vZ.:5.Z.M....y{\(...N..9...EB*MG...!N.vy..^...nE..2..@.;.4..C..t.4....h..O.8.=.m./...|Lu.|mCU..b.^.n39.h[M...%D{..w.1
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:Microsoft Cabinet archive data, many, 3144 bytes, 2 files, at 0x44 "VaryingWidthList.glox" "Content.inf", flags 0x4, number 1, extra bytes 20 in head, 1 datablock, 0x1203 compression
    Category:dropped
    Size (bytes):19288
    Entropy (8bit):7.570850633867256
    Encrypted:false
    SSDEEP:384:5ZII4Hf+7G8E0GftpBjCwBFLrHRN7bcClvQyUTL2mH:pG8PicgbcAvU+mH
    MD5:B9A6FF715719EE9DE16421AB983CA745
    SHA1:6B3F68B224020CD4BF142D7EDAAEC6B471870358
    SHA-256:E3BE3F1E341C0FA5E9CB79E2739CF0565C6EA6C189EA3E53ACF04320459A7070
    SHA-512:062A765AC4602DB64D0504B79BE7380C14C143091A09F98A5E03E18747B2166BD862CE7EF55403D27B54CEB397D95BFAE3195C15D5516786FEBDAC6CD5FBF9CD
    Malicious:false
    Reputation:low
    Preview:MSCF....H.......D...........................H....?..................................VaryingWidthList.glox.................Content.inf...O.....[.... v.q......R.....>.%i.I.HhD.V...qt.....'....N...!..aw$(J.%(..A..h......l|.D.p9`..Y09.:.u....p. :,.*.YD=0.p. ......w.........*..<..;.....u.."......7[....8.....?^........-..;q.|.....B....PJ....r.K#.#.0'...}.........+gpR...T....5.iu.^I...A\..gK....}..z.B.nT.../.m.......N....E'1.E.\..o.....W..R.#.#...8.7...R.SbW-...%......$.obj.F..W_@....sY!........s.O..."k. ..b....j....v...P.\....7d...|"J.T...2p..m.&..r..,2.).....X.`...xt].U...b.h..V.....|L..N.Z.O#....o...1R.w30.g..?;..C.T.:$..MGY.C"i\.f..#..<.k...m..s.w. ..Ga].....wt.h|.Ta<.......(SO.]9.%a..Z... r._JH.=O...P.9a.v.....Kj.".T...m...4.?...F...$...y.....hbW.UA..u.&)....py.C{.=t.....n...}|H3A9.=..W..JJ..y./Y.E.M9..Z..w. .HB.YoIi..i.e..9;n...SpHw,....f....d>..g.m..z...... ...f...KP.M..U.....~vFD.fQ.P?......2!.n.....`@C!G...XI.].s,.X.'...u.E.o..f
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:Microsoft Cabinet archive data, many, 5213 bytes, 2 files, at 0x44 "rings.glox" "Content.inf", flags 0x4, number 1, extra bytes 20 in head, 1 datablock, 0x1203 compression
    Category:dropped
    Size (bytes):21357
    Entropy (8bit):7.641082043198371
    Encrypted:false
    SSDEEP:384:zdx+NRrogu6fzCI7Th7G8E0GftpBjEzZq4FLrHRN7/Oll7PK/pB:/+NRrFf/G8Pi6zZb/GIB
    MD5:97F5B7B7E9E1281999468A5C42CB12E7
    SHA1:99481B2FA609D1D80A9016ADAA3D37E7707A2ED1
    SHA-256:1CF5C2D0F6188FFFF117932C424CC55D1459E0852564C09D7779263ABD116118
    SHA-512:ACE9718D724B51FE04B900CE1D2075C0C05C80243EA68D4731A63138F3A1287776E80BD67ECB14C323C69AA1796E9D8774A3611FE835BA3CA891270DE1E7FD1F
    Malicious:false
    Reputation:low
    Preview:MSCF....].......D...........................]....?..........{.......................rings.glox.................Content.inf..|^.....[......P........<.$.."..0R..xa.Ax#B..d... ....K,.....^.H.....H.........&.j.\f.. ..,....,..!k..R..e..!...E...........................><.RB.....~h...........Q................g..M|,...x.....qV7.u..\...F-N.{-..X..&Zig.~..{.A.p.Z...X..{,-n............`$.%.ND.....>].6cvZ.%d..*a.$..-.K.Hf....L..;.#...H....U,........P.@.*-$C.,.g...%YJE..$.jP........b...Y<..[U...MF]F.K...1... x.}3w.o.#,.}T.....w5+...=.=...c.F^....OM.=.......G_{n.*...WC.w!......{/.~.}..s..6_......)..Xy...4.....<..XZJ........#~._i....%..fM.V.?.q...q.....7...B..sVt...(.:..c....~.e...kGZ...C..(J..o...`...?.)-.T.l....&...gR.$.....g.:...2.e%F.....x....z0...K..a8B...........D..]....7....~.".DR...r)...}b)e.>.\h~f...(}.c........Q...o5H.........C.KC.(.L.l................R..a.pg{..\.......-b........}.C......qTS..%..r.lG..Q.1..Z.>a.D...tC..LV...Rs.C.M18x.:......%O.
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:Microsoft Cabinet archive data, many, 6196 bytes, 2 files, at 0x44 "ThemePictureGrid.glox" "Content.inf", flags 0x4, number 1, extra bytes 20 in head, 1 datablock, 0x1203 compression
    Category:dropped
    Size (bytes):22340
    Entropy (8bit):7.668619892503165
    Encrypted:false
    SSDEEP:384:GByvLdFHny7G8E0GftpBjE8upFLrHRN778lvQyUTL2mm2y:Oy3HkG8Pi6887mvU+ma
    MD5:8B29FAB506FD65C21C9CD6FE6BBBC146
    SHA1:CE1B8A57BB3C682F6A0AFC32955DAFD360720FDF
    SHA-256:773AC516C9B9B28058128EC9BE099F817F3F90211AC70DC68077599929683D6F
    SHA-512:AFA82CCBC0AEF9FAE4E728E4212E9C6EB2396D7330CCBE57F8979377D336B4DACF4F3BF835D04ABCEBCDB824B9A9147B4A7B5F12B8ADDADF42AB2C34A7450ADE
    Malicious:false
    Reputation:low
    Preview:MSCF....4.......D...........................4....?..................1...............ThemePictureGrid.glox.....1...........Content.inf....K..5.[.... V.q......B.....?.h.i.J.D...Z...>.....i~...A...Z....H.hy.D..X.....>...L.I..`. z w0}.K`.C{h....W\../.U..p\%...B...;............9..8.^M.....].lP.p...|..?..M....E..S.`..-n........Q'.'.o..C}=..?`.bQ...J"0f.. ....k3n..F.Pu..#...w].`<...."D.].-.#+):..fe..=<.M...4..s.q.f._.=.*T.M..U.[R.kbw.,......t6_I...~.X..$_.q....}2..BR...).[...<.l.3........h%....2.$`>..hG...0.6.S......._3.d~1.c.2g....7tTO..F.D.f.Y..WCG.B..T....Gg&.U'....u.S/......&6w..[bc.4....R.e..f.,....l."........I....J.=~...$x.&2...+,-.;.v.'.AQ.fc...v._..rZ..TYR...g?..Z..!.3mP dj...../...+...q.....>..../...]P.z?DW&.p..GZ....R5n......,..]{].0m.9...o.{...e."...8VH....w"%;.g\.K..p.}....#r.u..l.vS...Y.7U.N*-E@.....~....E...x.....C.......{NP....5Ymk.*._.K...Z...f..;.......b.....,._@B..\.S..d.'\rs..].}.5"XJU.J..'.zk}.+P.)C.X.?9sx.D....(K....P^N_D...Z.........
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:Microsoft Cabinet archive data, many, 26644 bytes, 2 files, at 0x4c "Element design set.dotx", iFolder 0x1 "Content.inf", 2 cffolders, flags 0x4, number 1, extra bytes 20 in head, 2 datablocks, 0x1203 compression
    Category:dropped
    Size (bytes):42788
    Entropy (8bit):7.89307894056
    Encrypted:false
    SSDEEP:768:Hx+UzBiwDQTXgBm029ClGn4BZz6i5kIew/jG8Pi6lYJz1gH:0ZXc29eGn2n5klwjxP7l2z1gH
    MD5:21A4B7B71631C2CCDA5FBBA63751F0D2
    SHA1:DE65DC641D188062EF9385CC573B070AAA8BDD28
    SHA-256:AE0C5A2C8377DBA613C576B1FF73F01AE8EF4A3A4A10B078B5752FB712B3776C
    SHA-512:075A9E95C6EC7E358EA8942CF55EFB72AC797DEE1F1FFCD27AD60472ED38A76048D356638EF6EAC22106F94AFEE9D543B502D5E80B964471FA7419D288867D5D
    Malicious:false
    Reputation:low
    Preview:MSCF.....h......L............................h...?..................@g......o...............Element design set.dotx.................Content.inf.Y/..Re..[......f........,..]....D.],....]..X.......XC4pE.....p........2..u;L.N.....]G..d.^d.$).e.=..;..Kb.../.../....H.."...w$._I..5.....a..4.Gd5p......v.8..1..%H..\..e...3.e..A..).d*.. . (.8.".......(>..<...@...~*v&.f..LWhqk]+Uep.d..%...o.....k.......e...nNN.&_.>.d.?H`"...r?..Z.p..q..<M.N.t....{*.y]#...._XW"qI...x.......}.. .N...;.}:..m8...[.r.F....^?...o...u..*...J3.V....~...~tn#.Kf6.s.|*..,s...M.$.f..?Yu.pE.1_wU...%....._..'..Z......y:.{.J5..7..Q.w}/.~.-3~Ctw=..IT.....mI.u@...y.M....2.%...y...Y..j.k<-.Q.r...7m..b...+.6..|.....U..}[...,....^....5..D..qW...[3).p.Y<.Hh..t...%cw=Z..W.~W.F....zr.4.g...O...P.g_^..3.-............3s...S..y...u...N...EsJz....tT../..c[w{cG....../6.....:.W<d5}.q..s..K"$........Ne..5..#.v'..n4.rj....Fc=....5..VN.....6..9`....|..........WX..-?..........W.)^`1.......].R2..s6...H.......
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:Microsoft Cabinet archive data, many, 291188 bytes, 2 files, at 0x44 +A "Banded.thmx" +A "content.inf", flags 0x4, ID 56338, number 1, extra bytes 20 in head, 18 datablocks, 0x1503 compression
    Category:dropped
    Size (bytes):307348
    Entropy (8bit):7.996451393909308
    Encrypted:true
    SSDEEP:6144:7vH3uG+yiWx0eVJyORloyyDqnHefzOs81MrXLXx7:b36yiWH/LRS2CJl1
    MD5:0EBC45AA0E67CC435D0745438371F948
    SHA1:5584210C4A8B04F9C78F703734387391D6B5B347
    SHA-256:3744BFA286CFCFF46E51E6A68823A23F55416CD6619156B5929FED1F7778F1C7
    SHA-512:31761037C723C515C1A9A404E235FE0B412222CB239B86162D17763565D0CCB010397376FB9B61B38A6AEBDD5E6857FD8383045F924AF8A83F2C9B9AF6B81407
    Malicious:false
    Reputation:low
    Preview:MSCF....tq......D...........................tq.. ?..........|..................Mn. .Banded.thmx............Mn. .content.inf..;.u.i..[...............?....^.j.{j.B...$M/!...W....{!..^0x/.6...&............w......$.B..J.?a.$=...P..L...d..........+./.\..E:h.....-.$..u-.I..L\.M.r..Y..:rtX:....8...........+8.}{......&.-..f.f..s3-P.''.r...Z-"/E../...^%^N(,.$..$.H..O........q>...|.|......y..m.)u....`.....z.n..-.[.5....xL....M...O..3uCX..=4.....7.yh...dg.;..c.x.4..6..e..p.e"..,.!.St{..E..^I.9j....;..`.Y..#.0..f...G.....9~./....QCz.93..u%hz.........t9.""........)..7K.c~E!..x.E.p...[......o..O.j.c.......6.t{...".....t9V;xv....n<.F.S2.gI.#6...u..O..F.9.[.L.....K....#..zL..I...o....k...qog.......V..BKM..#.bET.)..&4..m.w...*....E.a[.Q.y.B...w...r.nd...)...<..#..r[4.y...#.z.....m?.2K.^...R{..m..f......r?]..>@...ra$...C+..l].9...."..rM9=......]".'...b&2e...y..a..4....ML..f...f"..l..&.Rv=2LL..4...3t_x...G....w..I.K....s.t.....).......{ur.y2...O3.K*f.*P(..F..-.y.Z...
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:Microsoft Cabinet archive data, many, 259074 bytes, 2 files, at 0x44 +A "content.inf" +A "Dividend.thmx", flags 0x4, ID 58359, number 1, extra bytes 20 in head, 18 datablocks, 0x1503 compression
    Category:dropped
    Size (bytes):276650
    Entropy (8bit):7.995561338730199
    Encrypted:true
    SSDEEP:6144:H2a+HFkDF8gpmMt4kzwVVqhSYO6DITxPWgJl1CFExwXyo7N:mlZgFtIVVTuDExeWuv7N
    MD5:84D8F3848E7424CBE3801F9570E05018
    SHA1:71D7F2621DA8B295CE6885F8C7C81016D583C6B1
    SHA-256:B4BC3CD34BD328AAF68289CC0ED4D5CF8167F1EE1D7BE20232ED4747FF96A80A
    SHA-512:E27873BFD95E464CB58B3855F2DA404858B935530CF74C7F86FF8B3FC3086C2FAEA09FA479F0CA7B04D87595ED8C4D07D104426FF92DFB31BED405FA7A017DA8
    Malicious:false
    Reputation:low
    Preview:MSCF............D................................D..........~..................M. .content.inf............M. .Dividend.thmx..).}.b..[.....`.........?.R...T../..............4..yy....{...f.h..\U......sy.gV0Q.@..A..@..3a.A}........7.q.......8......R....sJ)E..ENr.S*B.1..).s.r.J.D.b."..........(.....E$.V........y.5.L....;gY..QK/nni..x..3.<..Q.Q..K.I.....T.z.,F.....{.p.....;8._.&../...........X...}.;[Gk..._.i`m.u.?...s.w...4.....m......l....5..n.?..c..m...,.....{.k.?......sC.............e..1....oL.8./......1._.K:.]..&......O............qo.....Dd/c...6.q.*......V.v........h....L..h..C+..V..;O.(7Z]{I%....S3.{h....\...b.......5.ES......Z.4...o.c`..YA....9i....M.s....Z3.oq`....>.i..@.@n.a...x.3.zp.<....vU/.|^CvE...aD.P&mhvM>.p..B~....."._.......v-.m..w..?._..=...:...k....i.}x.6....Y.i..n....h...j......LZ.....fk..f0.y.T..Vl.;...s.......B6.f.'z.c.\W?...4U)..aJ.;O....L.d7.J.V#Q.....\J.F.?].d}!..y].6..%..~....|......5...'N.#.....t6.,.E.O."..0fyz....
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:Microsoft Cabinet archive data, many, 279287 bytes, 2 files, at 0x44 +A "Basis.thmx" +A "content.inf", flags 0x4, ID 55632, number 1, extra bytes 20 in head, 18 datablocks, 0x1503 compression
    Category:dropped
    Size (bytes):295527
    Entropy (8bit):7.996203550147553
    Encrypted:true
    SSDEEP:6144:nwVaEqsf23c9shf6UyOGgDWDn/p3fd+zkPWnvGL3n9bQnkmVheyqtkl:MlPfW6sVEDn/pPdhWnvGL36zyyqal
    MD5:9A07035EF802BF89F6ED254D0DB02AB0
    SHA1:9A48C1962B5CF1EE37FEEC861A5B51CE11091E78
    SHA-256:6CB03CEBAB2C28BF5318B13EEEE49FBED8DCEDAF771DE78126D1BFE9BD81C674
    SHA-512:BE13D6D88C68FA16390B04130838D69CDB6169DC16AF0E198C905B22C25B345C541F8FCCD4690D88BE89383C19943B34EDC67793F5EB90A97CD6F6ECCB757F87
    Malicious:false
    Reputation:low
    Preview:MSCF.....B......D...............P............B..p?..........{.................M.. .Basis.thmx...........M.. .content.inf.`g..td..[...............5..$..WM.....R.......H\.+\./^...x.^..h..MU..\........v........+......g...$.......g.....~....U].7..T..1k.H...1...c.P.rp.6K..&......,.............U4.WoG.w.....;.....v..922.;]..5_-]..%E]b..5]... (..H..II..ttA4Q..BI!|...H.7J.2D....R.......CXhi`n....6..G.~&.[..N...v..Z"t.a..K..3..).w...._@.}.}.v.......4......h....R;.8.c&.F...B^....Q.....!Bm2...F.`.......M;...#.{....c...?...e...6t..C.-.E.V.v%I..H.....m.n...$D.....vU'.....=6}~...Gw...Y..?.@......G.....k......z...5d.h......1.}..O*;e..t......Y.0...3.v).X.-.2.....~....14.[.w=I....hN....eD..7G.u.z..7.do..!....d..o.wQ.:....@/.^..<e.-..=\.....6.C.'.rW$..Cp.M3.u6z......Q.F.9.5....juc..I...m4]7L....+n......).t......2[.3.p.:.....O5y..wA........^..!..H....{..S.3w.!&.'.;...(..|m.x.S..Z.j..3...n..WU...../w.......xe=.+.D...x..qy.S.....E..... ...uu.`.,..<.6[p
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:Microsoft Cabinet archive data, many, 704319 bytes, 2 files, at 0x44 +A "content.inf" +A "Wood_Type.thmx", flags 0x4, ID 5778, number 1, extra bytes 20 in head, 51 datablocks, 0x1503 compression
    Category:dropped
    Size (bytes):723359
    Entropy (8bit):7.997550445816903
    Encrypted:true
    SSDEEP:12288:NPnBZX7wR3tMwYqNDQGnXTtfzO5U7yo6O7bLhe8yE3LLDok4a:JBMbYE7xzO5U917bLh/DL3oJa
    MD5:748A53C6BDD5CE97BD54A76C7A334286
    SHA1:7DD9EEDB13AC187E375AD70F0622518662C61D9F
    SHA-256:9AF92B1671772E8E781B58217DAB481F0AFBCF646DE36BC1BFFC7D411D14E351
    SHA-512:EC8601D1A0DBD5D79C67AF2E90FAD44BBC0B890412842BF69065A2C7CB16C12B1C5FF594135C7B67B830779645801DA20C9BE8D629B6AD8A3BA656E0598F0540
    Malicious:false
    Reputation:low
    Preview:MSCF....?.......D...........................?...`J..............3..............M.. .content.inf..+.........M.. .Wood_Type.thmx......r..[.........................!.wwwwqwwwwwwwwwww..."....+......nR..x..\..w..r.5R.....(|.>.$e3.!..g....f..`9NL......o./.O.bxI...7.....|........6.n."J.....4^g.........?...................o.......s3.....8. .T.j...._.Z.Q.t.k,(o.c.t.......?Z....`o........?.a....6.)....6b..../.t...........Mz....q}......C.......+{.......o...K.tQjt............7.._....O.....\....` ..............@..`....%..t....V.]........m..m....u..1.yr;..t..F.'..+{....zqvd.g._..$H..Vl...m..../....g..rG.....:*......8....h...[...a06...U.W....5.Z.W..1I..#.2.....B3...x....$PRh...\{J.c.v.y..5+Y.W.N..hG......<..F..W.d8_....c...g....p|7.]..^.o.H.[$Zj..{4......m.KZ..n.T%...4.Z..Y."q7?kuB......U....).~.......W%..!.e.U.mp.o...h...?.w...T.s.YG#......Y.}....Z.O.i.r,...n..4.\....P..m..=....f........v....g....j...*.wP..4.VK.y.z...C..oum.b.1......?.Z.>.7.!?......A..Q>..Z....-
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:Microsoft Cabinet archive data, many, 252241 bytes, 2 files, at 0x44 +A "content.inf" +A "Frame.thmx", flags 0x4, ID 34169, number 1, extra bytes 20 in head, 16 datablocks, 0x1503 compression
    Category:dropped
    Size (bytes):271273
    Entropy (8bit):7.995547668305345
    Encrypted:true
    SSDEEP:6144:zfdvQnJMwXse4Vradf3mrC7woyWbjKlCVC7K:zfJwJse4VrS1AK
    MD5:21437897C9B88AC2CB2BB2FEF922D191
    SHA1:0CAD3D026AF2270013F67E43CB44F0568013162D
    SHA-256:372572DCBAD590F64F5D18727757CBDF9366DDE90955C79A0FCC9F536DAB0384
    SHA-512:A74DA3775C19A7AF4A689FA4D920E416AB9F40A8BDA82CCF651DDB3EACBC5E932A120ABF55F855474CEBED0B0082F45D091E211AAEA6460424BFD23C2A445CC7
    Malicious:false
    Reputation:low
    Preview:MSCF....Q.......D...............y...........Q...XJ..........{..................M.. .content.inf.(..........M.. .Frame.thmx.1....b..[.........B.....6....ZZ}....BH..-D..}..V.V-........Z..O.....H.f..........;..@d.`......!..=;.,bp..K.q....s.y....D.qZ)p......D...r.S....s=B.4.).8B....4.a6 ...~........."....#.....}....n.Q.1cH.%c/.U....E..E...!..Da*.p....X..G..:.....1.@.....W.'...._........W.c...<.v.k.....&.8......?.h.>d._:-.X.......9..tL}........3.;.N3.D~......>.^?..|:...}......oT.z.......w..[..}:...._fu........Kk.......L..9..p..e..^......K.%...Mapqhvv..E&.^.....[...9|"l...9...U......!..w..Nya...~C.yx...w.K..q.z.j.W?t.......DY.x.S2.....]..na.Qj...X.K..^...S.hK.W...Z....s.0...NF...8C.......j.'Zc...k.%...l....S.....OW..o.Qf.x...X.;<.rO].....W.m.e....T.1.6........".....Q.3........l..v.."..I...&......w..4vE...c.s[.3.m..8.q$.....a...)...&:6..,..#..?....;.!.....~.UP.r=.}h.&U......X...]..X.e\u.G<....E....lG.@.*Z...10.D@.]....z+-.S....p..Y.PK.:.S..p.....1E`..-
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:Microsoft Cabinet archive data, many, 206792 bytes, 2 files, at 0x44 +A "content.inf" +A "View.thmx", flags 0x4, ID 33885, number 1, extra bytes 20 in head, 15 datablocks, 0x1503 compression
    Category:dropped
    Size (bytes):222992
    Entropy (8bit):7.994458910952451
    Encrypted:true
    SSDEEP:6144:k8/c2cF9GTLqsTmYstUdx+dwb2ooiVOfiI17zWbQ:jbzqGdpbZ/Mf3h68
    MD5:26BEAB9CCEAFE4FBF0B7C0362681A9D2
    SHA1:F63DD970040CA9F6CFCF5793FF7D4F1F4A69C601
    SHA-256:217EC1B6E00A24583B166026DEC480D447FB564CF3BCA81984684648C272F767
    SHA-512:2BBEA62360E21E179014045EE95C7B330A086014F582439903F960375CA7E9C0CF5C0D5BB24E94279362965CA9D6A37E6AAA6A7C5969FC1970F6C50876582BE1
    Malicious:false
    Reputation:low
    Preview:MSCF.....'......D...............]............'..H?..........z..................M{. .content.inf..l.........M{. .View.thmx......R..[...........@...G...I..(J.....B....Q!....}Ju..(BR..._|.5.%.....6m...........?.w{.rm,....#....;Ba#.:v...Dv.."u.v{!...f}......!......:.S.......".z.f.......==.n.0Km0eh.Kbm.C.r.6.........d..h.....{..w..}....2sb...rvm..x...0(..B... ...BH.r#.@..d".*..F+...Q.sx.....?...d.d.eZ2W2.2d...q.I....4.e4....#.....K...3...1.p.y......>.~V....cm....n^..b.{..._D?..AG...'...k.L&..h}=p.....Wl....(.......>.~.].....'.4.W{......../......7.....'.s...w...6..hn..e.2.).l]u.v4...GF.X..X..X....G.i.\..y.g&.<&ti......Sp,j.....>I..S..%.y..........S..-).+...>...D..............[...d...jt.~<x.a(.MDW..a..ZI.;+..!,.$...~>#...).R4...K.$.Zm......b...........{..._..A{.}..r...X...T.ZI.T.).J...$.".U,.9...r.z.)......}...()<....m....QS.p...;?..5.W~2r.EZu..P.1.%'l.........+/6.Mm.|2....Ty..f.o.S.....3J.._...X,..m....:..1.<GqFy.QA9W4.=....n...ZP...O.\.[...:8.%.^..H.....
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:Microsoft Cabinet archive data, many, 243642 bytes, 2 files, at 0x44 +A "content.inf" +A "Metropolitan.thmx", flags 0x4, ID 19054, number 1, extra bytes 20 in head, 24 datablocks, 0x1503 compression
    Category:dropped
    Size (bytes):261258
    Entropy (8bit):7.99541965268665
    Encrypted:true
    SSDEEP:6144:9blShNYrHNn0JU+D+kh8CIjXHWC7X0nZLC9Ge2KY/WfI:9ZSTYrtn0Sk+CIDHWC7chVKYx
    MD5:65828DC7BE8BA1CE61AD7142252ACC54
    SHA1:538B186EAF960A076474A64F508B6C47B7699DD3
    SHA-256:849E2E915AA61E2F831E54F337A745A5946467D539CCBD0214B4742F4E7E94FF
    SHA-512:8C129F26F77B4E73BF02DE8F9A9F432BB7E632EE4ABAD560A331C2A12DA9EF5840D737BFC1CE24FDCBB7EF39F30F98A00DD17F42C51216F37D0D237145B8DE15
    Malicious:false
    Reputation:low
    Preview:MSCF............D...............nJ...............D.................."..........M. .content.inf....."......M. .Metropolitan.thmx...cVtP..[.....`Q..B.....=.T.....h.."...Z..|..}hZK.V....Z..Z................?..v...[S$."...H......^u.%.@...>....... f.........1.5......*&lm.tZ.msz:...Noc....1....D .........b..... ..3#pVp....}oo]{m......H*[%i.GNHB1D<......(*# ....H"....DP..b(B.<.....v......_..`.7..;.}............/.p}.:vp....~l0..].........S....G?.....}..U.;......dNi..?........-c..J.z....Z...._.O.....C..o.,......z....F....sOs$..w9......2G..:@...'....=.....M..am.....S......(`.._....'......[..K"....BD...D...^1k.....xi...Gt....{k@.W.....AZ+(,...+..o......I.+.....D..b. T.:..{..v.....g..........L.H.`...uU~C.d...{...4.N.N..m8..v.7..3.`.....,...W...s.;.fo.8.Y...2.i...T&.-...v8..v.U.Y=...8..F.hk..E.PlI.t.8......A.R....+.]lOei..2...... gS*.......%8H.....<.U.D..s.....>.....D_...../....l.......5O1S~.........B.g.++cV.z.f .R.Z.......@6....(..t^5"...#G...
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:Microsoft Cabinet archive data, many, 533290 bytes, 2 files, at 0x44 +A "content.inf" +A "Parallax.thmx", flags 0x4, ID 64081, number 1, extra bytes 20 in head, 29 datablocks, 0x1503 compression
    Category:dropped
    Size (bytes):550906
    Entropy (8bit):7.998289614787931
    Encrypted:true
    SSDEEP:12288:N4Ar9NyDhUQM0Hk86V1YnOIxQ9e6SJbj2OjK:jAG8wa5Qw6SZ2Oj
    MD5:1C12315C862A745A647DAD546EB4267E
    SHA1:B3FA11A511A634EEC92B051D04F8C1F0E84B3FD6
    SHA-256:4E2E93EBAC4AD3F8690B020040D1AE3F8E7905AB7286FC25671E07AA0282CAC0
    SHA-512:CA8916694D42BAC0AD38B453849958E524E9EED2343EBAA10DF7A8ACD13DF5977F91A4F2773F1E57900EF044CFA7AF8A94B3E2DCE734D7A467DBB192408BC240
    Malicious:false
    Reputation:low
    Preview:MSCF....*#......D...............Q...........*#...D..........~..................M{. .content.inf............M{. .Parallax.thmx.9... y..[......(..b.P...E.Q*.R.".RTH.%.T..F......u.{.*+.P.....FK*0].F...a{...D4`D..V.../.P,....2.Mx...u......0...E...{A-"J...)jl_.A..T......u.Y....ZG:....V.A.#~.. ..6..............o..X..<.... .......C.ce.f!nA.).p...p........n..................'6w6H6s.j....l...{?.h..........]..l.....v....%..l}A..................3...W_73.j......6...F.../..qG.?........H..).........7.&km....`m2..m.W.q.<../~<..6*.78..X~.e+..CC*w...T...6....AB..l..._.f......s.e....2....H..r.R.Z....a.,..\Q.q..._SJJ....7.S.R....=f..>....9=....NnC.....].-...\..Z..q..j...q.....Nj..^'..k...Zl.~PRvpz.J..+.C...k.z.w=l.#.............n...C..s.kM.@B{..vL.e....E..(/......f...g..=..V...}...).=s.....y!.,...X.[..[.....\31}..D%...%..+G66.j.v./.e9...P;.o.y..U+...g.g.S.../..B._L..h...Oi.._...:..5ls>>........n6.F.Q..v>..P.r:.a..Z....a...x..D....N...i..=L.u......<;Nv.X/*.
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:Microsoft Cabinet archive data, many, 214772 bytes, 2 files, at 0x44 +A "content.inf" +A "Parcel.thmx", flags 0x4, ID 26500, number 1, extra bytes 20 in head, 19 datablocks, 0x1503 compression
    Category:dropped
    Size (bytes):230916
    Entropy (8bit):7.994759087207758
    Encrypted:true
    SSDEEP:6144:OTIPtMXmJWnzPS3pqnkeuJXW+FNx1a72rLiQxEBTR:750nz63/FJRFLISnp+Bt
    MD5:93FA9F779520AB2D22AC4EA864B7BB34
    SHA1:D1E9F53A0E012A89978A3C9DED73FB1D380A9D8A
    SHA-256:6A3801C1D4CF0C19A990282D93AC16007F6CACB645F0E0684EF2EDAC02647833
    SHA-512:AA91B4565C88E5DA0CF294DC4A2C91EAEB6D81DCA96069DB032412E1946212A13C3580F5C0143DD28B33F4849D2C2DF2214CE1E20598D634E78663D20F03C4E6
    Malicious:false
    Reputation:low
    Preview:MSCF.....F......D................g...........F...?..........|..................L.. .content.inf.zG.........L.. .Parcel.thmx.>2...R..[...0...........7....B+...BH....{...^.../.....B{...1....+".....<.....$........{.......sD"..j...}... P..w..U..f...6.x8. ...C..F.q.7....T.6p......B.P..L..g......A..43.W`.....{{...u.4...:.bb.4"X..m..)$..@(H. H.tBPTF..,.&.B.'...6..2...n..c%...Z@.(.@.......(.<i.i....P......?......o.......F.M.L......i.....C..7..../.....MQ.0..l.U.s.Fu.......1...p.;.(.}..ogd..<.._.Z......._.......O.J......97...~<...4.c....i..........'k.5.......Q.$..C..E... ..5.7....N.a.[ns6hi..kM....?....X......*9q...!O\....0....n.^s.9.6..............;. ..r...rf..C6z..v #.H...O...v/.sl....J.m%.L.Dp.e....*uO..g.y....f...].5.*........W.....h^[..w.|.=.ru.|.M..+.-.B...D.Ma....o.<X SnI....l...{..G..,..y5\W.@..y.;.y ...M..l.....e..A...d.e!.E..3.......k1.......6gY).../....pQ..?..s.W.)+R.S5..../.0..vz.^.......k.....v..9..A.NG...N~#..$.B...*s,(.o.@.ar.!.J.....
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:Microsoft Cabinet archive data, many, 682092 bytes, 2 files, at 0x44 +A "Berlin.thmx" +A "content.inf", flags 0x4, ID 46672, number 1, extra bytes 20 in head, 30 datablocks, 0x1503 compression
    Category:dropped
    Size (bytes):698244
    Entropy (8bit):7.997838239368002
    Encrypted:true
    SSDEEP:12288:bUfKzAwwP7XAMWtr4FvMRt4lX0hnBdThiSb32+TdysrQgn7v4EemC6:sr7AMkJ34xu1bm4ZrQaY6
    MD5:E29CE2663A56A1444EAA3732FFB82940
    SHA1:767A14B51BE74D443B5A3FEFF4D870C61CB76501
    SHA-256:3732EB6166945DB2BF792DA04199B5C4A0FB3C96621ECBFDEAF2EA1699BA88EE
    SHA-512:6BC420F3A69E03D01A955570DC0656C83C9E842C99CF7B429122E612E1E54875C61063843D8A24DB7EC2035626F02DDABF6D84FC3902184C1EFF3583DBB4D3D8
    Malicious:false
    Reputation:low
    Preview:MSCF....lh......D...............P...........lh...?..........|..................M. .Berlin.thmx............M. .content.inf..lH.lj..[...............7.I..)........P..5x.B/^y5.xk^^......D.F........s....y...?D.....*.....&....".o..pl..Q.jm?_...6......=%.p.{.)S..y...$......,4..>#.........)..."-....K....4.E...L=.......4..p.c..nQ.0..ZO.#.....e.N..`U......oS....V..X[t.E)|.h..R....$..}.{.F.7....^.....w.,...5rBR.....{.......mi...h.b......w+..;.hV......q..(.7&.Z.l...C."j........[-E4h.....v&..~.p$|\X...8.....Fj'%,.)6w...u|C..,y..E..`*Up../(....2.(....Z.....,.'...d..s..Z....5.g.?Nq..04...f...D.x....q+.b.."v`{.NL....C..... ..n......1N+.I.{W9....2r.0...BaC.....O..=...k..."..8.D\jK.B...Aj....6,B..2...I.. B..^.4..1.K+.....DP...Mr....9..x[...>........?.Zd..'._2.._..>..'.F..#.w...2..~.|........q_Wy.W.....~..Qex.km/..f......t.q..p..gm.|.x.... ,.#\Z....p....a.}...%..v.J.Es......I.b.P?...0......F.x....E..j..6.%..E..-O.k...b .^.h.Cv...Z....D.n.d:.d.F..x...[1...B..
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:Microsoft Cabinet archive data, many, 624532 bytes, 2 files, at 0x44 +A "content.inf" +A "Quotable.thmx", flags 0x4, ID 13510, number 1, extra bytes 20 in head, 30 datablocks, 0x1503 compression
    Category:dropped
    Size (bytes):640684
    Entropy (8bit):7.99860205353102
    Encrypted:true
    SSDEEP:12288:eV7ivfl+kbkIrWu+2aoRjwv/cSUWauGPo2v65s4QqcT3ZCCz6CSj8aC:fdhr1+3y4MWaC2CO4V+3ZCCDsO
    MD5:F93364EEC6C4FFA5768DE545A2C34F07
    SHA1:166398552F6B7F4509732E148F93E207DD60420B
    SHA-256:296B915148B29751E68687AE37D3FAFD9FFDDF458C48EB059A964D8F2291E899
    SHA-512:4F0965B4C5F543B857D9A44C7A125DDD3E8B74837A0FDD80C1FDC841BF22FC4CE4ADB83ACA8AA65A64F8AE6D764FA7B45B58556F44CFCE92BFAC43762A3BC5F4
    Malicious:false
    Reputation:low
    Preview:MSCF............D................4...............?..........~..................M. .content.inf."..........M. .Quotable.thmx..^.u.n..[...............&...U..F.......UU.M.T5.UUQS..j..#>43fD.....`....Vr......19'...P..j.-...6n.0c....4$.c....$.4.k3aQ$.lCN.#.[.."qc....,Z...,Qt@!.@...... ...H.......9.9.y.{....[.`..s3.5.....B....W.g.d...[uv.UW..............P.8.(.?......3.....'/F...0...8.P. .O..B....K...g..L.......#s...%..|4.i....?.3b.".....g...?.........2.O23..'..O~.+..{...C.n.L......3......Y.L...?K...o......g....@.]...T..sU.....<.._.<G.......Tu.U2..v.&..<..^..e.].cY;..9.%..}...I.y.;...WM...3>.:.=.|.-.AtT2OJ.I.#...#.y....A....\]$r...lM.%5.."...+7M..J.....c...".&$.... Y.r.B;..81B. +H...b....@7K.*.F.Z...v..=..ES.f.~.."...f..ho.X.E.a`~*...C>.&..@\.[....(.....h..]...9&...sd.H .1.x.2..t.rj..o..A..^qF.S9.5.....E.{...C|.w.c/V...0Q.M...........O.7;A4u...R..Z.B.7a.C`....p.z.....f!|.u.3t....2e.wWH..'7p....E_...e.._;..k....*&E.^.f=V..{*..al.y:.4a...+.g...-..>e
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:Microsoft Cabinet archive data, many, 1049713 bytes, 2 files, at 0x44 +A "content.inf" +A "Savon.thmx", flags 0x4, ID 60609, number 1, extra bytes 20 in head, 37 datablocks, 0x1503 compression
    Category:dropped
    Size (bytes):1065873
    Entropy (8bit):7.998277814657051
    Encrypted:true
    SSDEEP:24576:qehtHA3nsAOx7yN7THwxdGpkw8R60aTcua5U4c:hhmnsBMNAxdGpV5za5Uv
    MD5:E1101CCA6E3FEDB28B57AF4C41B50D37
    SHA1:990421B1D858B756E6695B004B26CDCCAE478C23
    SHA-256:69B2675E47917A9469F771D0C634BD62B2DFA0F5D4AF3FD7AFE9196BF889C19E
    SHA-512:B1EDEA65B6D0705A298BFF85FC894A11C1F86B43FAC3C2149D0BD4A13EDCD744AF337957CBC21A33AB7A948C11EA9F389F3A896B6B1423A504E7028C71300C44
    Malicious:false
    Reputation:low
    Preview:MSCF....q.......D...........................q... ?..........{...%..............M. .content.inf.Q_.........M. .Savon.thmx...O>.o..[..............&.5....UUcC.C....A...`TU...F....".54.E.....g.-.7-D....1g...p.6......@..w(....h'?.....(..........p..J.2n$4.........A......?...........@.C.W.R.5X..:..*..I..?....r.y..~!.....!.A.a...!........O.........5.x<C...?.?....C.C.......'....F../....../.$................4.7...................P...(.w.}6.........7.....01.1r........._..?.............'.._..JOx.CFA<.........*0..2.?...>F.../...;..6-8..4...8&yb....".1%..v'..N...x......}.gYb..~L.....f[..!......Y.G.....p..r...?.p...F.Vy.....o.Whll...+...M.V...:.]...B.%.H....n..@.].zaVxf...y{.@....V.t.W....$Kp-.....7W.J..h..0A3mK.=.ub..R...W......*'T2..G#G,.^..T..XZu...U. ...76.d..#.I.JB.v...d...%.....6..O.K.[.:.L.\.....1.D..2a.>f......X...b5...ZgN.u.f...a!..."...sx....>..?.a.3.8.^._q..JS1.E..9..Lg.n.+....lE.f:j.9)Q..H1=..<.R.......{c>:.p[..S.9h.a.gL.U....8.z..z.!.....2I.~.b..2..c...
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:Microsoft Cabinet archive data, many, 937309 bytes, 2 files, at 0x44 +A "content.inf" +A "Gallery.thmx", flags 0x4, ID 44349, number 1, extra bytes 20 in head, 34 datablocks, 0x1503 compression
    Category:dropped
    Size (bytes):953453
    Entropy (8bit):7.99899040756787
    Encrypted:true
    SSDEEP:24576:9B1Onw3vg7aeYPagzbJ5Vhv6LnV2Dhl7GEYqVjcyd:vww3o7BYPJbJ5Vh6UCqZfd
    MD5:D4EAC009E9E7B64B8B001AE82B8102FA
    SHA1:D8D166494D5813DB20EA1231DA4B1F8A9B312119
    SHA-256:8B0631DA4DC79E036251379A0A68C3BA977F14BCC797BA0EB9692F8BB90DDB4D
    SHA-512:561653F9920661027D006E7DEF7FB27DE23B934E4860E0DF78C97D183B7CEBD9DCE0D395E2018EEF1C02FC6818A179A661E18A2C26C4180AFEE5EF4F9C9C6035
    Malicious:false
    Reputation:low
    Preview:MSCF....]M......D...............=...........]M...?..........}..."..............Li. .content.inf............Li. .Gallery.thmx.].(.Vq..[.....0Y..........v.....w.wwwww.wwwwww.w.....".83....y8..mg...o*..U..N(..@uD.:O<........{.G....~~.....c.c.5..6./|G .@#1O.B.............PT@...b.d.~..U....B.{.........0.H.....`.H.`..'S.......Ic..W..x...z....... .........g......._....o......S......p...$....._........._...K......x..?.6.U~...'./.r.................../.......5.8..2........2b.@j ....0.........``....H... ,5...........X........|..Y.QoiW..*|.......x.sO8...Yb....7...m..b.f.hv..b......=...:Ar.-...[..A\.D..g..u....].9..M...'.R-`.....<..+.....]...1.^..I.z..W{.._....L.. ...4;..6O.....9,.-.Vt+b/$7..}.O05.Y...-..S.....$*.....1."Z.r;.!..E.mMN..s .U...P%.[.P...cU...j...h.d.../.s..N/..:..X*...p5.7\}h.Q ..._.F.X.C..z$.nV..+.k..|.@.L...&.........^#.G.a..x..w!wx.8e+..E. i..$?9..8...:......|..[."..y..&y..?...W....s..._...3Z0c.....i.q.........1c.jI....W..^%xH.._...n.......&J..
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:Microsoft Cabinet archive data, many, 1081343 bytes, 2 files, at 0x44 +A "Circuit.thmx" +A "content.inf", flags 0x4, ID 11309, number 1, extra bytes 20 in head, 45 datablocks, 0x1503 compression
    Category:dropped
    Size (bytes):1097591
    Entropy (8bit):7.99825462915052
    Encrypted:true
    SSDEEP:24576:UE9BMy98gA4cDWHkSrDans3MfEE6w8OaVuCibol0j41dwD:UE9Bdy3D4keQWt7w85VuVoaj4/Q
    MD5:BF95E967E7D1CEC8EFE426BC0127D3DE
    SHA1:BA44C5500A36D748A9A60A23DB47116D37FD61BC
    SHA-256:4C3B008E0EB10A722D8FEDB325BFB97EDAA609B1E901295F224DD4CB4DF5FC26
    SHA-512:0697E394ABAC429B00C3A4F8DB9F509E5D45FF91F3C2AF2C2A330D465825F058778C06B129865B6107A0731762AD73777389BB0E319B53E6B28C363232FA2CE8
    Malicious:false
    Reputation:low
    Preview:MSCF............D...............-,..............x?..........}...-...RU.........M. .Circuit.thmx.....RU.....M. .content.inf.g...&|..[......=..R.....=.*,.!QA?h..Q.!....Uk!.HJ.......VKuk.....q.w.w.U.....;...K.@.URA..0..B..|rv.ND(.`{..@.1.}...s?.....-...O.(V.w..1..a.....aW...a.Z..aX....5.I...!..........(. ./.d...me.( ..f.........w.......Xp.s....c..vB.98.....C.J......V ..ML.M...B.n.>...|....u!.5@t..q4....(K...u qL.S....>/%v%.2..TF.].e..'..-..L.N..c].a..(WU\o.%^..;...|o.6..L..[..;&....^p.Lu.sr,-.R=.:.8.>VOB...:.?$.*h.o....Zh.h....`.B.c.../K......b^...;2..bY.[.V.Q8....@..V7....I0c.cQN7..I.p..}..!..M....1K....+....9.2......a..W.V..........;.J .i......]%O.-......CeQ.0.c....MbP3.0.w..8w..Y...|...H;#.J.+M......>.`y..aWk|.i.BF.pJv;.....S..6....F.....RLG~..........J.=......"..........H.....h..o...u........M.6F?.F.p.B.>./*l....J.R..#P.....K......<iu..gm^..n...#c..zO"7M.O......4'>A..(.E.Cy.N.)....6.tx.r[.....7.......m.t..E?.....5.5.6.\..{.V.T.D.j..=~a^.I
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:Microsoft Cabinet archive data, many, 1291243 bytes, 2 files, at 0x44 +A "content.inf" +A "Droplet.thmx", flags 0x4, ID 47417, number 1, extra bytes 20 in head, 54 datablocks, 0x1503 compression
    Category:dropped
    Size (bytes):1310275
    Entropy (8bit):7.9985829899274385
    Encrypted:true
    SSDEEP:24576:NN3M9UHpHZE4aubaPubP3M6d71FdtmFAjq+54/79LVzG+VnS:NN3M9UJHZE4abPyU4JtmFCq+q/7JlVS
    MD5:9C9F49A47222C18025CC25575337A965
    SHA1:E42EDB33471D7C1752DCC42C06DD3F9FDA8B25F0
    SHA-256:ADA7EFF0676D9CCE1935D5485F3DDE35C594D343658FB1DA42CB5A48FC3FC16A
    SHA-512:9FDCBAB988CBE97BFD931B727D31BA6B8ECF795D0679A714B9AFBC2C26E7DCF529E7A51289C7A1AE7EF04F4A923C2D7966D5AF7C0BC766DCD0FCA90251576794
    Malicious:false
    Reputation:low
    Preview:MSCF...........D...............9..............XJ..........}...6..............M.. .content.inf............M.. .Droplet.thmx..m7.>J..[...............2.QQPIj.*.."o^R.H5*^...^(e.W...R..x..^`..m...."..+.....{o.......Q.-....$V.N>...T]..L.... ..N.h..dOY.......S......N.%.d..d....Y.....e..$...<.m...`............@....=.z..n..[...,G..1Fn.qPDH{C<...3.Q...2..r..*...E.E.E.ErM"&a..'..W....:...?I..<.I..6o.`.d.?!..!..._.4\.._.E..).._O.S....; ..#..p.H.....c....o\.K..?$U.e.........!...J.v.....gNe._..[....#A.O.n_.....gm:P._.........{@..-g..j.69b.NH.I.$Hk?.6.n...@......'.C.._.U..:*,j.-G.....e.#.Sr.t.L......d[.[...s.....rx.3.F[.5o..:....K*.x..)M.fb...3IP.&h.Q.VX^%U.......x..l......@6.k.P..zSW.?....F..[L...4..b.l.w."&.....`.j...i.5}".~.-.....{\.:...o.'H\*+)....3.Y......\...f:.;....e........4't7..f...w..j...3....N..9`.J...P..?.....=3_.y]...f.<.......JM5.}Q/ .F.a..Z.._yh......V..>m .......a....f....!.hz..\.....F_..'z...,....h.=.......=.o..T....3.e..........$..g.2.
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:Microsoft Cabinet archive data, many, 1750009 bytes, 2 files, at 0x44 +A "content.inf" +A "Slate.thmx", flags 0x4, ID 28969, number 1, extra bytes 20 in head, 72 datablocks, 0x1503 compression
    Category:dropped
    Size (bytes):1766185
    Entropy (8bit):7.9991290831091115
    Encrypted:true
    SSDEEP:24576:O/gjMj+RP9Q07h9F75a0BXjBccHMVk2Hq2SkGa0QglyZtxmdPP2LcSUtfgfp16Yx:kJ6RP9Q07/X5V7yVF0QgktxAPutUt0zP
    MD5:828F96031F40BF8EBCB5E52AAEEB7E4C
    SHA1:CACC32738A0A66C8FE51A81ED8E27A6F82E69EB2
    SHA-256:640AD075B555D4A2143F909EAFD91F54076F5DDE42A2B11CD897BC564B5D7FF7
    SHA-512:61F6355FF4D984931E79624394CCCA217054AE0F61B9AF1A1EDED5ACCA3D6FEF8940E338C313BE63FC766E6E7161CAFA0C8AE44AD4E0BE26C22FF17E2E6ABAF7
    Malicious:false
    Reputation:low
    Preview:MSCF............D...............)q..............0?..........{...H..............M.. .content.inf.;.#........M.. .Slate.thmx.p.+..P..[......U..............p..K.!.......*...K..w..v........=....D$r...B....6 ...X.F0..d..m.s...$$r........m.)6.m3....vXn.l..o...a...V......Ru.:=2M.........T.....4S`EP......\..r,..v...G.P......'._H0]..%_............X.P.,.............H.?.-.H..".......M..&..o....R........<......`...D.H.._.G.Qv..(.*.U,.9..D...."..T..i.e../.e.."....,S...o.X.....c./..V....Z..o.O..2....{...+... ....0.@J.R.Q.m.....{.....h?u.q.O{...l.d)..Yk`.....#...u.-.m..#CXwrz4..7.>......v.E:.#.oGSKS.TX.Chm.4aQ......avH..{..j+@6[k].....`c..W8..j.v.Zh.]....4......K..#Hzyd..K}.....H|<H..\(l...+..%Z......~.S:^..d>..1..H%..7N-v.....Wu.*..b^.B.....k0gc.2.{.!...E7.}3.d...{.Ye...&#f6...:2......v..&!..k0d.p.b...,..$.....Y..60...h.N}.r...<[./........{...Es..&.nf.....2.@Fh3.9.G....l.[.C..SD/6.H.K....}..m....M..........gl.P.]..I......5....e.c...V....P...[.=.......O.eq+
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:Microsoft Cabinet archive data, many, 1865728 bytes, 2 files, at 0x44 +A "content.inf" +A "Damask.thmx", flags 0x4, ID 63852, number 1, extra bytes 20 in head, 68 datablocks, 0x1503 compression
    Category:dropped
    Size (bytes):1881952
    Entropy (8bit):7.999066394602922
    Encrypted:true
    SSDEEP:49152:6Wp9u/ZAvKz7ZFCejPiSmYXKIr6kBwBUA:6W6Bn7ZFNiiKo2l
    MD5:53C5F45B22E133B28D4BD3B5A350FDBD
    SHA1:D180CFB1438D27F76E1919DA3E84F307CB83434F
    SHA-256:8AF4C7CAC47D2B9C7ADEADF276EDAE830B4CC5FFE7E765E3C3D7B3FADCB5F273
    SHA-512:46AD3DA58C63CA62FCFC4FAF9A7B5B320F4898A1E84EEF4DE16E0C0843BAFE078982FC9F78C5AC6511740B35382400B5F7AC3AE99BB52E32AD9639437DB481D1
    Malicious:false
    Reputation:low
    Preview:MSCF.....x......D...............l............x..`?..........|...D..............M[. .content.inf...!........M[. .Damask.thmx...o.PI..[.............../.TU.jj0..3jCUPU.jF...m.UU.P}.....PU..*........w..#....E..].................A.. w.$..@..'g.......6%:..r9..d.M;M+.r.8[d{.s..dh..(P..........!.. ..ne..f.Nc..#..Y..q....KB}..b].@..F.&.t....E.........@&.m......$w......q...:.H....p.p.....?.9x.. .....?...ao....I....................o......g.u..;."....O;....{..(k..._.w/.Z......Jb..P.O?...........?....F....ty..72......! #....v..J......?.....!,.5.7..Em.....is.h.. \.H*)i1v..zwp.....P.....x].X{O//..\....Z>z....6...+..a.c...;.K..+...?014..p.w%o^.....]...MguF...`....r.S.......eF..):.dnk#.p{..<..{..Ym...>...H......x.}.hI..M....e......*G.&.?..~.~G6.....+...D..p...._...T....F6.[Cx./Q..Xe.>.;.}>.^..:..SB.X..2.......(A..&j9....\\.......Haf+]Y...$t^Y=........><.w....tL../E...%6.Vr~MI...l.....<.0.I....7.Q8y.f.uu...I.p..O..eYYS.O......9..Qo.......:..........o.............{
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:Microsoft Cabinet archive data, many, 2573508 bytes, 2 files, at 0x44 +A "content.inf" +A "Mesh.thmx", flags 0x4, ID 62129, number 1, extra bytes 20 in head, 94 datablocks, 0x1503 compression
    Category:dropped
    Size (bytes):2591108
    Entropy (8bit):7.999030891647433
    Encrypted:true
    SSDEEP:49152:ZSBBeAefkpB5iXfQJgi7JBaCCRZ3cM2VDHkvSJO6qzI1tE9Rn:EBI6gbCkMPDHKSJO6qsP6n
    MD5:BEB12A0464D096CA33BAEA4352CE800F
    SHA1:F678D650B4A41676BA05C836D462F34BDC5BF648
    SHA-256:A44166F5C9F2553555A43586BA5DB1C1DE54D72D308A48268F27C6A00076B1CA
    SHA-512:B6E7CCD1ECBB9A49FC72E40771725825DAF41DDB2FF8EA4ECCE18B8FA1A59D3B2C474ADD055F30DA58C7E833A6E6555EBB77CCC324B61CA337187B4B41F7008B
    Malicious:false
    Reputation:low
    Preview:MSCF.....D'.....D............................D'..D..........z...^..............M7. .content.inf............M7. .Mesh.thmx....&~j..[.....0.................]............ww,v.\....D......3m..m!f..0..E{..?..`..A...k.:....I..........|bmG.FS...f.;.J.vzb.......R.......-....|.......ESD.....".4M..M..t.N....y..,..#.4.5.2.......'.8.Q..3.D..T....!.......&rJg...s........(..9........Dw..'....9.-..G.c............E.. .O.....a..O.._..s..)7Wz~....bJ..D...o....0..R/.#...?.......~6.Q?....?y...g.?............TP..r-...>....-..!.6...B.....\../...2....4...p$...Oge.G.?.....S.#x(..$.A~.U.%f....dJ..S.f{.g.._..3{.fm2.....Z.\o&.[k.m....ko.8..r.-.Go.OQ..'!6..f.L...Ud.$.q*.L.....R.. J.T&4g...7.2K...#k.[.].:....lk.....;c..DRx.`..&L..cpv*.>.Ngz~.{..v5.\...'C.<R:.C8.|.fE{......K...).....T...gz}..rF..Q.dof7.....D.f=cm...U|.O.]F...5zg(.. ....S..._?D....^..+.i...Z.....+X..U!4qy..._..`I..>./.W.7......=.O....BG..=..%9|...3.?...}.$"..H..u...0.......a..:t?.....8...Z..#g.=<.e.`\......KQ..U....
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:Microsoft Cabinet archive data, many, 2511552 bytes, 2 files, at 0x44 +A "content.inf" +A "Main_Event.thmx", flags 0x4, ID 59889, number 1, extra bytes 20 in head, 90 datablocks, 0x1503 compression
    Category:dropped
    Size (bytes):2527736
    Entropy (8bit):7.992272975565323
    Encrypted:true
    SSDEEP:49152:NFXdpz4d98p/q5jA4q+9Uf5kx6wHR8WfPJZVhWzH4dRze76YP9nJ7yyAInT76nSY:NFXdKx5sM9SmxHKexZVhutJJVpCSqa0Z
    MD5:F256ACA509B4C6C0144D278C7036B0A8
    SHA1:93F6106D0759AFD0061F73B876AA9CAB05AA8EF6
    SHA-256:AD26761D59F1FA9783C2F49184A2E8FE55FCD46CD3C49FFC099C02310649DC67
    SHA-512:08C57661F8CC9B547BBE42B4A5F8072B979E93346679ADE23CA685C0085F7BC14C26707B3D3C02F124359EBB640816E13763C7546FF095C96D2BB090320F3A95
    Malicious:false
    Reputation:low
    Preview:MSCF.....R&.....D............................R&.8?..............Z..............M). .content.inf..,........M). .Main_Event.thmx......R..[...............=.1.^xa..^...../..^x....QA^"....^/.I.{/F..F..........6Vn. ..._Hmc......<....#.{.@.....Xl../Y....Ye..'V.f.S.Vf.T..0t+..y...5O...{.....-.dT...........!...[ .ns..k.....QAA.. ....B..u.`.....{.\u8.0.....@t........K....@..w.......>...-1F...........1.E....O............_M.m..CP.O......X......g......].../..:C...Q...i.._"...M..1o...S../...9....k;...}S........y..;1o....1h......t.CL.3...].@...T...4.6.}.....M...f...[.s.."f....nZ.W......0.c.{.`.^..Oo.[.JT.2].^.f..a....kO......Q..G..s.5...V.Wj.....e...I,]...SHa..U.N.N.....v.C.....x..J{.Z.t...]WN...77BO-J......g......3:i..2..EFeL.,n..t:..,~4gt.w...M.5.'h.L..#..A&.O.ys%K.Z....F.PW..=jH...jGB.i..j.J.^.#.\n...J@.....-5.f.1jZ68.o...H2.......$O...>..ld&,#$.&_....yl.fkP$.........l....s....i.tx.~<.z...>..2.Gx..B..z.E.3.N<....`$.....b..?.w.[.X..1.=q!.s......v.......r.w
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:Microsoft Cabinet archive data, many, 3239239 bytes, 2 files, at 0x44 +A "content.inf" +A "Vapor_Trail.thmx", flags 0x4, ID 19811, number 1, extra bytes 20 in head, 111 datablocks, 0x1503 compression
    Category:dropped
    Size (bytes):3256855
    Entropy (8bit):7.996842935632312
    Encrypted:true
    SSDEEP:98304:wh7I1aeH9YvgK+A+a7GiiQzP4YZDpQ2+Sd6Y:w21ay93aypQzzhpBL/
    MD5:8867BDF5FC754DA9DA6F5BA341334595
    SHA1:5067CCE84C6C682B75C1EF3DEA067A8D58D80FA9
    SHA-256:42323DD1D3E88C3207E16E0C95CA1048F2E4CD66183AD23B90171DA381D37B58
    SHA-512:93421D7FE305D27E7E2FD8521A8B328063CD22FE4DE67CCCF5D3B8F0258EF28027195C53062D179CD2EBA3A7E6F6A34A7A29297D4AF57650AA6DD19D1EF8413D
    Malicious:false
    Reputation:low
    Preview:MSCF....Gm1.....D...............cM..........Gm1..D..............o... ..........MP. .content.inf...7. ......MP. .Vapor_Trail.thmx..n...N..[......L........7...+I..x...P7/...BH..Rm.\yqi.x..B....{.m.............=.....p.%.@......BpV.[......C.4..X./..Y.'SB..........0.Gr.FG.).....R\...2..Jt..1..._.4_B..................cn7H.-.....Q...1..G{G.~.. '.$......@.(....=@=..`....@.@.A. ....'.4`. .@....D...'....S.s..9.7" /....?.aY.c.........LG....k...?_.....P.....?.1.....FB..m..t...['......:...?...W..../~..z.Tr...X.@...._....3..N..p.....b...t.....^..t...~..t.8A...t_....D..3R.Z.=..{.A.8).3-5..v.isz....0A~%.s.D.4....k.K......8......)R.}f.E..n.g&:W...'E....4%T..>......b.y..[..zI....e...j.s....F.....|7826U.C.,..BY.U.F.f......"..#.m..,..._...#.\.....gPP.2.}Kas......g..3.d0.Z.Z.]..n......MY]6.....].m..D.6...?.n.20.,.#...S...JK..#.W.%.Z4.....i..CBf...../..z......n.N...U.....8t...ny...=.!..#..SF..e...1.P..@.Qx*.f.;..t..S.>..... F..)...@.Y..5j....x....vI.mM....Z.W..77...
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:Microsoft Cabinet archive data, many, 3400898 bytes, 2 files, at 0x4c "Insight design set.dotx", iFolder 0x1 "Content.inf", 2 cffolders, flags 0x4, number 1, extra bytes 20 in head, 106 datablocks, 0x1203 compression
    Category:dropped
    Size (bytes):3417042
    Entropy (8bit):7.997652455069165
    Encrypted:true
    SSDEEP:98304:1YYkj2mRz6vkkB15AW4QD0ms+FdniD60bDUpS:qYkj7d6vP7NZDLn+PM8
    MD5:749C3615E54C8E6875518CFD84E5A1B2
    SHA1:64D51EB1156E850ECA706B00961C8B101F5AC2FC
    SHA-256:F2D2DF37366F8E49106980377D2448080879027C380D90D5A25DA3BDAD771F8C
    SHA-512:A5F591BA5C31513BD52BBFC5C6CAA79C036C7B50A55C4FDF96C84D311CCDCF1341F1665F1DA436D3744094280F98660481DCA4AA30BCEB3A7FCCB2A62412DC99
    Malicious:false
    Reputation:low
    Preview:MSCF......3.....L.............................3..?..............j.....3.....t.4.............Insight design set.dotx.................Content.inf...QJ.N..[.........R.....L....N).J|E.B.$.B).3,...n.....JW....k.U1..M...3#.5....$^.....;vR...Z.nj...#......^*......a.{..(..o.v...!L`...T.-&jZ`.\.*0.....G.."b.m..F.X......$>%..?.D..H.l.j....$.......MrQ......q-....hx...6.D.3...j....n..U#R..3....sm?..xJr..............$G8..t.g...?.g.}......$P._...7.#..w..9DR....*lu....?..'.Ai..v.vl..`......B..N_....W./.;...c=oYW.lL'bv.......+...9.P..B=...*Y.SX=EL.5o....?H.e|.Fn.M[...d.v.....i......9..U..H....uq.Nrn..@..e...3....8.....s8}z..$........B....26...d..?.l....=.aeM.[..|n....H.;..7A.`....=.F...V.Y.l..8.........%e.x0S.....~..2..%.....U..#.r_.0V.v.6w.l.......Y.........v..o+....*sn.$^'.Il...akUU....w....~.....&8.Vwj.....Q.uQ..&..G.($.2.s.?m.B.~j.*..+G.W..qi..g..5.)){O........o.ow.(;.{...y;n...J...&.F2.@.;......[{'w..........`....czW.........?W...}..w....x..........
    Process:C:\Users\user\Desktop\download\HOBOware_Free_Setup.exe
    File Type:PE32 executable (GUI) Intel 80386, for MS Windows
    Category:dropped
    Size (bytes):1214792
    Entropy (8bit):6.42135548765562
    Encrypted:false
    SSDEEP:24576:+nbbPImgK4brDi4IxgRqzwqNb+Yz73P2EMZbG0JEtoIIhqx9B12:EHeKh4nqzF3PYdSt7E
    MD5:461456B58784CAB0CA1D194B41A2D256
    SHA1:4617E34D1C3C857F88D1AD294DEEA4E8618EF170
    SHA-256:1984225264AE023B9AA9B4775AD88CE23C42C88F870CED806B98BBFD3150A9C1
    SHA-512:7D1D1A73CB437B34A67B468EFD31708379B98D45C6EABDBB4D09E2066BDD000EA6CB2C826983617EEEB55F7924908402659ABC71C37EAEEE0BCB4592606AAC98
    Malicious:true
    Reputation:low
    Preview:MZP.....................@.......................InUn....................!..L.!..This program must be run under Win32..$7........................................................................................................................................PE..L...Rm"[.....................T.......%.......0....@..........................0......!.....@......@..............................@8...@..|............n..H....................................0.......................................................text............................... ..`.itext.............................. ..`.data....0...0...2..................@....bss.....a...p.......L...................idata..@8.......:...L..............@....tls....<.... ...........................rdata.......0......................@..@.rsrc...|....@......................@..@....................................@..@........................................................................................................................................
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:data
    Category:dropped
    Size (bytes):30
    Entropy (8bit):1.2389205950315936
    Encrypted:false
    SSDEEP:3:Z3J//:j
    MD5:94BD9F12BD74E4986A33BC50457A9271
    SHA1:B8CEE1F3C82D9BEA00459D6203F439B5A108656D
    SHA-256:A87F00B3AD7CCB767BF1A85E1667FBF1117612EAC1B80B3AE4B8A4F031292C76
    SHA-512:F6D74863F763C5DDFEC5E0E2451A3D3CDC68E52BECD1D0355F71AFFDC0536C97822C67BA1A282C333DD2DEF9CAB77159824EAF2581930F941C6F38EC5298F9BA
    Malicious:false
    Reputation:low
    Preview:.....u........................
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Archive, ctime=Tue Jun 18 14:13:37 2024, mtime=Tue Jun 18 14:13:58 2024, atime=Mon Jan 29 20:51:40 2024, length=34531, window=hide
    Category:dropped
    Size (bytes):1020
    Entropy (8bit):4.577200263880704
    Encrypted:false
    SSDEEP:24:8pAduNGvYTiqUOQouczQAU+od5bH1Jw9Em:8pAduNGLqDQoucznxod5DU9E
    MD5:29E415DF96F4356BC59E5D94EA96E80A
    SHA1:0DCC5BD39ADE73C13D512C10BC26FAD4D73108DA
    SHA-256:0D7DA12299318332FCC5D8142C28303BCC7E70B2EE0D1D262AD189BECBF4D4E7
    SHA-512:1A4246D75A659DA795A12ED093FCB2F42C93A471523DB8536A97BA568FDF10AEE2BE48769E88DA8385BE51F296F1B4B0441BB53BCE4A0C1FE6335EB7B73A92FA
    Malicious:false
    Reputation:low
    Preview:L..................F.... .....M.....[qk$.......V.R..............................P.O. .:i.....+00.../C:\.....................1......X.y..PROGRA~1..t......O.I.X.y....B...............J.....?M..P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....~.1......X.y..ONSETC~1..f.......X.y.X.y..........................?M..O.n.s.e.t. .C.o.m.p.u.t.e.r. .C.o.r.p.o.r.a.t.i.o.n.....Z.1......X.y..HOBOware..B.......X.y.X.y...........................>_.H.O.B.O.w.a.r.e.....`.2....=Xt. .README.rtf..F.......X.y.X.y....hS........................R.E.A.D.M.E...r.t.f.......n...............-.......m............F.......C:\Program Files\Onset Computer Corporation\HOBOware\README.rtf..Q.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.O.n.s.e.t. .C.o.m.p.u.t.e.r. .C.o.r.p.o.r.a.t.i.o.n.\.H.O.B.O.w.a.r.e.\.R.E.A.D.M.E...r.t.f.`.......X.......093954...........hT..CrF.f4... ...S.-...,...W..hT..CrF.f4... ...S.-...,...W..E.......9...1SPS..mD..pH.H@..=x.....h....H.....K...YM
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:Generic INItialization configuration [folders]
    Category:dropped
    Size (bytes):73
    Entropy (8bit):3.830763837350312
    Encrypted:false
    SSDEEP:3:HIwovZom4pfov:HUZMfy
    MD5:A914DB2BC39D58C6D7858534A76A3AE3
    SHA1:1543279F2EF84D72D8C9BD95205D58F2A0B1F3AF
    SHA-256:8ACE9BA2A9DFBDD1AC05F87F47B1650ECC4BF3457517D2C521C5CF897AFE42B3
    SHA-512:AAFEFCB55A39F199A5056DD3F04C983E9B2671B05F64C0E9F6DADB1BBBC0D1807078D209D4FE70C68C06E7D26372C0575A4A75E33AB1C40748A1880BBE1D4F80
    Malicious:false
    Reputation:low
    Preview:[misc??????????????????????????]..README.LNK=0..[folders]..README.LNK=0..
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:Microsoft OOXML
    Category:dropped
    Size (bytes):562113
    Entropy (8bit):7.67409707491542
    Encrypted:false
    SSDEEP:12288:/dy5Gtyp/FZ9QqjdxDfSp424XeavSktiAVE0:/dizp1ndpqpMZnV
    MD5:4A1657A3872F9A77EC257F41B8F56B3D
    SHA1:4DDEA85C649A2C1408B5B08A15DEF49BAA608A0B
    SHA-256:C17103ADE455094E17AC182AD4B4B6A8C942FD3ACB381F9A5E34E3F8B416AE60
    SHA-512:7A2932639E06D79A5CE1D3C71091890D9E329CA60251E16AE4095E4A06C6428B4F86B7FFFA097BF3EEFA064370A4D51CA3DF8C89EAFA3B1F45384759DEC72922
    Malicious:false
    Reputation:low
    Preview:PK..........1AE,.{E...#P......[Content_Types].xml..Mo.0.....Z..N7.=l......V0.-o..j?...H..sa......./UCb.'...r...w.i..e..<[....{2..U.m..N.{...r.....3.fj.o......2.*....;.L.6..&,D.Cld8...a.gZf.......r-v..><....~/......|Zk.......a.R&.d.(.$..6..}.:.....3......1..[.p.....?..+....R...y,.fod.....e...-.|..#..]j....n:...f...-J...i.^.:Y....T..........m^..~GNp../e}...N....a..5.d.8YcN..5.d.8Y...7..A..e...7Q."3...../.sL._...v...n..b..2].v....n.t....Z...Uk...j.&.Z....im|.r....B.....7DaBuN.... ...>..>..>..>..>..>..>.........V}-.....Q}#.&T..j...r..]..CZ..CZ..CZ..CZ..CZ..CZ..CZ..i.o.,-k..b....7FaBuN.... ...>..>..>..>..>..>..>.........V}-...Q}..&T..j...r..]..CZ..CZ..CZ..CZ..CZ..CZ..CZ..i.o.,-k..b....7EaBuN.... ...>..>..>..>..>..>..>.........V}-...Q}3.&T..j...r..]..CZ..CZ..CZ..CZ..CZ..CZ..CZ..i.o.,-k..b.\}..)...A.......[..PK..........1A.s@.....O......._rels/.rels...J.1.._%..d...t......}...n2!..}6.>..`(.v...K`2...70...........84P....
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:Microsoft OOXML
    Category:dropped
    Size (bytes):1649585
    Entropy (8bit):7.875240099125746
    Encrypted:false
    SSDEEP:24576:L368X6z95zf5BbQ6U79dYy2HiTIxRboyM/LZTl5KnCc:r68kb7UTYxGIxmnp65
    MD5:35200E94CEB3BB7A8B34B4E93E039023
    SHA1:5BB55EDAA4CDF9D805E36C36FB092E451BDDB74D
    SHA-256:6CE04E8827ABAEA9B292048C5F84D824DE3CEFDB493101C2DB207BD4475AF1FD
    SHA-512:ED80CEE7C22D10664076BA7558A79485AA39BE80582CEC9A222621764DAE5EFA70F648F8E8C5C83B6FE31C2A9A933C814929782A964A47157505F4AE79A3E2F9
    Malicious:false
    Reputation:low
    Preview:PK..........1A..u._....P......[Content_Types].xml..Ms.@.....!...=.7....;a.h.&Y..l..H~..`;...d..g/..e..,M..C...5...#g/."L..;...#. ]..f...w../._.2Y8..X.[..7._.[...K3..#.4......D.]l.?...~.&J&....p..wr-v.r.?...i.d.:o....Z.a|._....|.d...A....A".0.J......nz....#.s.m.......(.]........~..XC..J......+.|...(b}...K!._.D....uN....u..U..b=.^..[...f...f.,...eo..z.8.mz....."..D..SU.}ENp.k.e}.O.N....:^....5.d.9Y.N..5.d.q.^s..}R...._E..D...o..o...o...f.6;s.Z]...Uk6d.j..MW....5[C].f#...l;u.M..Z.../iM|...b...S.....0.zN.... ...>..>..>..>..>..>..>........e...,..7...F(L.....>.ku...i...i...i...i...i...i...i........yi.....G...1.....j...r.Z]..CZ..CZ..CZ..CZ..CZ..CZ..CZ..i.o|^Z....Q}.;.o...9.Z..\.V...............................jZ......k.pT...0.zN.... ...>..>..>..>..>..>..>........e...,..7...f(L.....>.ku...i...i...i...i...i...i...i........yi.......n.....{.._f...0...PK..........1A.s@.....O......._rels/.rels...J.1.._%..d...t......}...n2!..}6.>..`(.v...
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:Microsoft OOXML
    Category:dropped
    Size (bytes):558035
    Entropy (8bit):7.696653383430889
    Encrypted:false
    SSDEEP:12288:DQ/oYjRRRRRRRRYcdY/5ASWYqBMp8xsGGEOzI7vQQwOyP:DQ/nRRRRRRRRxY/5JWYZ3GGbI8YA
    MD5:3B5E44DDC6AE612E0346C58C2A5390E3
    SHA1:23BCF3FCB61F80C91D2CFFD8221394B1CB359C87
    SHA-256:9ED9AD4EB45E664800A4876101CBEE65C232EF478B6DE502A330D7C89C9AE8E2
    SHA-512:2E63419F272C6E411CA81945E85E08A6E3230A2F601C4D28D6312DB5C31321F94FAFA768B16BC377AE37B154C6869CA387005693A79C5AB1AC45ED73BCCC6479
    Malicious:false
    Reputation:low
    Preview:PK..........1AE,.{E...#P......[Content_Types].xml..Mo.0.....Z..N7.=l......V0.-o..j?...H..sa......./UCb.'...r...w.i..e..<[....{2..U.m..N.{...r.....3.fj.o......2.*....;.L.6..&,D.Cld8...a.gZf.......r-v..><....~/......|Zk.......a.R&.d.(.$..6..}.:.....3......1..[.p.....?..+....R...y,.fod.....e...-.|..#..]j....n:...f...-J...i.^.:Y....T..........m^..~GNp../e}...N....a..5.d.8YcN..5.d.8Y...7..A..e...7Q."3...../.sL._...v...n..b..2].v....n.t....Z...Uk...j.&.Z....im|.r....B.....7DaBuN.... ...>..>..>..>..>..>..>.........V}-.....Q}#.&T..j...r..]..CZ..CZ..CZ..CZ..CZ..CZ..CZ..i.o.,-k..b....7FaBuN.... ...>..>..>..>..>..>..>.........V}-...Q}..&T..j...r..]..CZ..CZ..CZ..CZ..CZ..CZ..CZ..i.o.,-k..b....7EaBuN.... ...>..>..>..>..>..>..>.........V}-...Q}3.&T..j...r..]..CZ..CZ..CZ..CZ..CZ..CZ..CZ..i.o.,-k..b.\}..)...A.......[..PK..........1A.s@.....O......._rels/.rels...J.1.._%..d...t......}...n2!..}6.>..`(.v...K`2...70...........84P....
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:Microsoft OOXML
    Category:dropped
    Size (bytes):570901
    Entropy (8bit):7.674434888248144
    Encrypted:false
    SSDEEP:6144:D2tTXiO/3GH5SkPQVAqWnGrkFxvay910UUTWZJarUv9TA0g8:kX32H+VWgkFxSgGTmarUv9T
    MD5:D676DE8877ACEB43EF0ED570A2B30F0E
    SHA1:6C8922697105CEC7894966C9C5553BEB64744717
    SHA-256:DF012D101DE808F6CD872DFBB619B16732C23CF4ABC64149B6C3CE49E9EFDA01
    SHA-512:F40BADA680EA5CA508947290BA73901D78DE79EAA10D01EAEF975B80612D60E75662BDA542E7F71C2BBA5CA9BA46ECAFE208FD6E40C1F929BB5E407B10E89FBD
    Malicious:false
    Reputation:low
    Preview:PK..........1AE,.{E...#P......[Content_Types].xml..Mo.0.....Z..N7.=l......V0.-o..j?...H..sa......./UCb.'...r...w.i..e..<[....{2..U.m..N.{...r.....3.fj.o......2.*....;.L.6..&,D.Cld8...a.gZf.......r-v..><....~/......|Zk.......a.R&.d.(.$..6..}.:.....3......1..[.p.....?..+....R...y,.fod.....e...-.|..#..]j....n:...f...-J...i.^.:Y....T..........m^..~GNp../e}...N....a..5.d.8YcN..5.d.8Y...7..A..e...7Q."3...../.sL._...v...n..b..2].v....n.t....Z...Uk...j.&.Z....im|.r....B.....7DaBuN.... ...>..>..>..>..>..>..>.........V}-.....Q}#.&T..j...r..]..CZ..CZ..CZ..CZ..CZ..CZ..CZ..i.o.,-k..b....7FaBuN.... ...>..>..>..>..>..>..>.........V}-...Q}..&T..j...r..]..CZ..CZ..CZ..CZ..CZ..CZ..CZ..i.o.,-k..b....7EaBuN.... ...>..>..>..>..>..>..>.........V}-...Q}3.&T..j...r..]..CZ..CZ..CZ..CZ..CZ..CZ..CZ..i.o.,-k..b.\}..)...A.......[..PK..........1A.s@.....O......._rels/.rels...J.1.._%..d...t......}...n2!..}6.>..`(.v...K`2...70...........84P....
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:Microsoft OOXML
    Category:dropped
    Size (bytes):523048
    Entropy (8bit):7.715248170753013
    Encrypted:false
    SSDEEP:6144:WfmDdN6Zfv8q5rnM6vZ02PtMZRkfW5ipbnMHxVcsOWrCMxy0sD/mcKb4rYEY:xDdQXBrMi2YtggW5ObnMH1brJpUmBU0N
    MD5:C276F590BB846309A5E30ADC35C502AD
    SHA1:CA6D9D6902475F0BE500B12B7204DD1864E7DD02
    SHA-256:782996D93DEBD2AF9B91E7F529767A8CE84ACCC36CD62F24EBB5117228B98F58
    SHA-512:B85165C769DFE037502E125A04CFACDA7F7CC36184B8D0A54C1F9773666FFCC43A1B13373093F97B380871571788D532DEEA352E8D418E12FD7AAD6ADB75A150
    Malicious:false
    Reputation:low
    Preview:PK..........1AE,.{E...#P......[Content_Types].xml..Mo.0.....Z..N7.=l......V0.-o..j?...H..sa......./UCb.'...r...w.i..e..<[....{2..U.m..N.{...r.....3.fj.o......2.*....;.L.6..&,D.Cld8...a.gZf.......r-v..><....~/......|Zk.......a.R&.d.(.$..6..}.:.....3......1..[.p.....?..+....R...y,.fod.....e...-.|..#..]j....n:...f...-J...i.^.:Y....T..........m^..~GNp../e}...N....a..5.d.8YcN..5.d.8Y...7..A..e...7Q."3...../.sL._...v...n..b..2].v....n.t....Z...Uk...j.&.Z....im|.r....B.....7DaBuN.... ...>..>..>..>..>..>..>.........V}-.....Q}#.&T..j...r..]..CZ..CZ..CZ..CZ..CZ..CZ..CZ..i.o.,-k..b....7FaBuN.... ...>..>..>..>..>..>..>.........V}-...Q}..&T..j...r..]..CZ..CZ..CZ..CZ..CZ..CZ..CZ..i.o.,-k..b....7EaBuN.... ...>..>..>..>..>..>..>.........V}-...Q}3.&T..j...r..]..CZ..CZ..CZ..CZ..CZ..CZ..CZ..i.o.,-k..b.\}..)...A.......[..PK..........1A.s@.....O......._rels/.rels...J.1.._%..d...t......}...n2!..}6.>..`(.v...K`2...70...........84P....
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:Microsoft OOXML
    Category:dropped
    Size (bytes):3078052
    Entropy (8bit):7.954129852655753
    Encrypted:false
    SSDEEP:49152:bSEjlpY8skyFHuj2yY0ciM9U2NCVBB4YFzYFw7IaJE2VRK+Xn9DOOe9pp9N9Hu:bfp5sksA3cimUVxV05aJE2fKaDOXdN9O
    MD5:CDF98D6B111CF35576343B962EA5EEC6
    SHA1:D481A70EC9835B82BD6E54316BF27FAD05F13A1C
    SHA-256:E3F108DDB3B8581A7A2290DD1E220957E357A802ECA5B3087C95ED13AD93A734
    SHA-512:95C352869D08C0FE903B15311622003CB4635DE8F3A624C402C869F1715316BE2D8D9C0AB58548A84BBB32757E5A1F244B1014120543581FDEA7D7D9D502EF9C
    Malicious:false
    Reputation:low
    Preview:PK..........1AS'......ip......[Content_Types].xml..n.@.._......8ie'......}.......(y...H}......3Fi..%2.v?..3..._...d=..E.g.....7.i.-.t5.6......}}.m9r.......m...ML.g.M.eV$.r..*.M..l0...A...M..j;.w={o.f..F....i..v......5..d;..D.ySa...M&..qd*w>.O.{h...|w..5.]..'.CS<.:8C}.g.|E.../..>..].Tnml..I.......r.Gv.E....7.;.E......4/l.....6.K.C?1qz.O.v_..r......\c.c.>..lS........X.N.3N.sN..N.)'.%'..'..N.pL.E...T.!..CR....Ie..k.o..M..w.B.0}..3....v..+....,.q..pz.......v{.;....s3.|..V..ZZ......0.[.....x.....!.!~.8.e..n..&.}p....s.i.. ..[]...q.r....~..+.A\...q............e.-)h9..."Z.>...5-C..`..g.}........r.A.+..\...r.>.... .W.\...re?..%.-/hiA..ZR.r.W.D.\}.EK..kZ.>......5..9.&T......Wlu.b....}..+.A\...q......~.WK.Z^..........>.h..`......}.....^h....L...H...!...r.>... .W...\...rE?............-+hIA..\}..r...-}..i..`..G..j..).&T......Wlu.b....}..+.A\...q......~.WK.Z^..........>.h..`......}.....^j..K.L...H...!...r.>... .W...\...rE?............-+hIA..\}..r...-}..i.
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:Microsoft OOXML
    Category:dropped
    Size (bytes):777647
    Entropy (8bit):7.689662652914981
    Encrypted:false
    SSDEEP:6144:B04bNOJMngI856k0wwOGXMaXTLaTDmfBaN2Tx9iSUk1PdSnc0lnDlcGMcEFYYYYt:xbY6ngI46Aw5dmyYYYYYYYYY7p8d
    MD5:B30D2EF0FC261AECE90B62E9C5597379
    SHA1:4893C5B9BE04ECBB19EE45FFCE33CA56C7894FE3
    SHA-256:BB170D6DE4EE8466F56C93DC26E47EE8A229B9C4842EA8DD0D9CCC71BC8E2976
    SHA-512:2E728408C20C3C23C84A1C22DB28F0943AAA960B4436F8C77570448D5BEA9B8D53D95F7562883FA4F9B282DFE2FD07251EEEFDE5481E49F99B8FEDB66AAAAB68
    Malicious:false
    Reputation:low
    Preview:PK.........V'B.._<....-.......[Content_Types].xml..`.I.%&/m.{.J.J..t...`.$.@........iG#).*..eVe]f.@....{...{...;.N'...?\fd.l..J..!....?~|.?"....|.{.[..e^7E......Gi..V.by..G..|.......U..t.|..mW...m..|.5.j./..^d-.Y_.]e..E~wog...j...v......?..u....c...W..G.4D_.}T,.@...}....R.Z..4k.....Y..mEkLor.f^..O..P...`.../.|u1..Y.....nK.......u=..2.tu~^L.Y5]/...~+.v...o....j.`?.S...../.by.|..>."kZbs....H.9..m.z.]W.V.?~v........;...N.......w....;.z..N.......w.....R.~n..Ofu.-..K.e....{..A.~.8.#D..)o.7..........:2........=......f...u....[..}...u.6b...xz.[...G..|#...$....)J./.......7.............oQ..]^.M........wy}7a.....&l................w.......l._...l..?.A..........r..9.|.8.........{w...........n...]^.M........wy}7a.....&l.................`..z..`.....2.o...wx}.....>..c.M..Arr#.....nD..[.....w......n...]^.M........wy}7a.....&l........w........... ..Fp....w_Q....g..tL.i.?H.o...]^..........n...]^.M........wy}7a.....&l.................`..z..`
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:Zip archive data, at least v2.0 to extract, compression method=deflate
    Category:dropped
    Size (bytes):924687
    Entropy (8bit):7.824849396154325
    Encrypted:false
    SSDEEP:12288:lsadD3eLxI8XSh4yDwFw8oWR+6dmw2ZpQDKpazILv7Jzny/ApcWqyOpEZULn:qLxI8XSh4yUF/oWR+mLKpYIr7l3ZQ7n
    MD5:97EEC245165F2296139EF8D4D43BBB66
    SHA1:0D91B68CCB6063EB342CFCED4F21A1CE4115C209
    SHA-256:3C5CF7BDB27592791ADF4E7C5A09DDE4658E10ED8F47845064DB1153BE69487C
    SHA-512:8594C49CAB6FF8385B1D6E174431DAFB0E947A8D7D3F200E622AE8260C793906E17AA3E6550D4775573858EA1243CCBF7132973CD1CF7A72C3587B9691535FF8
    Malicious:false
    Reputation:low
    Preview:PK..........1AS'......ip......[Content_Types].xml..n.@.._......8ie'......}.......(y...H}......3Fi..%2.v?..3..._...d=..E.g.....7.i.-.t5.6......}}.m9r.......m...ML.g.M.eV$.r..*.M..l0...A...M..j;.w={o.f..F....i..v......5..d;..D.ySa...M&..qd*w>.O.{h...|w..5.]..'.CS<.:8C}.g.|E.../..>..].Tnml..I.......r.Gv.E....7.;.E......4/l.....6.K.C?1qz.O.v_..r......\c.c.>..lS........X.N.3N.sN..N.)'.%'..'..N.pL.E...T.!..CR....Ie..k.o..M..w.B.0}..3....v..+....,.q..pz.......v{.;....s3.|..V..ZZ......0.[.....x.....!.!~.8.e..n..&.}p....s.i.. ..[]...q.r....~..+.A\...q............e.-)h9..."Z.>...5-C..`..g.}........r.A.+..\...r.>.... .W.\...re?..%.-/hiA..ZR.r.W.D.\}.EK..kZ.>......5..9.&T......Wlu.b....}..+.A\...q......~.WK.Z^..........>.h..`......}.....^h....L...H...!...r.>... .W...\...rE?............-+hIA..\}..r...-}..i..`..G..j..).&T......Wlu.b....}..+.A\...q......~.WK.Z^..........>.h..`......}.....^j..K.L...H...!...r.>... .W...\...rE?............-+hIA..\}..r...-}..i.
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:Microsoft OOXML
    Category:dropped
    Size (bytes):966946
    Entropy (8bit):7.8785200658952
    Encrypted:false
    SSDEEP:24576:qBcvGBGhXQir6H1ws6+iU0YuA35VuinHX2NPs:ccvGBGdQ5CsMxQVj3yPs
    MD5:F03AB824395A8F1F1C4F92763E5C5CAD
    SHA1:A6E021918C3CEFFB6490222D37ECEED1FC435D52
    SHA-256:D96F7A63A912CA058FB140138C41DCB3AF16638BA40820016AF78DF5D07FAEDD
    SHA-512:0241146B63C938F11045FB9DF5360F63EF05B9B3DD1272A3E3E329A1BFEC5A4A645D5472461DE9C06CFE4ADB991FE96C58F0357249806C341999C033CD88A7AF
    Malicious:false
    Reputation:low
    Preview:PK..........1A.......F`......[Content_Types].xml..n.@.._.y.ac $..,........-..g@.u.G.+t.:........D1...itgt>...k..lz;].8Kg^....N.l..........0.~}....ykk.A`..N..\...2+.e.c..r..P+....I.e.......|.^/.vc{......s..z....f^...8...'.zcN&.<....}.K.'h..X..y.c.qnn.s%...V('~v.W.......I%nX`.....G.........r.Gz.E..M.."..M....6n.a..V.K6.G?Qqz..............\e.K.>..lkM...`...k.5...sb.rbM8..8..9..pb..R..{>$..C.>......X..iw.'..a.09CPk.n...v....5n..Uk\...SC...j.Y.....Vq..vk>mi......z..t....v.]...n...e(.....s.i......]...q.r....~.WV/.j.Y......K..-.. Z..@.\.P..W...A..X8.`$C.F(.P..H...W..r.>... .W.C..zAV+.....@.\..h....r)...R..-..........c..0F...@Z.....v.+.A\...q.......ZAV'p)...R.D....K..-...h....eP..........(.P..H...W..r.>... .W.C..zAV+.....@.\..h....r)...R..-.............0A...@Z.....v.+.A\...q.......ZAV'p)...R.D....K..-...h....eP.........w(.P..H...W..r.>... .W.C..zAV+.....@.\..h....r)...R..-..........T..GI..~.....~....PK..........1A.s@.....O......._rels/.rels...J.
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:Microsoft OOXML
    Category:dropped
    Size (bytes):1204049
    Entropy (8bit):7.92476783994848
    Encrypted:false
    SSDEEP:24576:+3zSQBxvOUIpHLYTCEmS1Wu09jRalJP3sdgnmAOFt0zU4L0MRx5QNn5:+bvI5UTCPu09qP3JPOFoR4N5
    MD5:FD5BBC58056522847B3B75750603DF0C
    SHA1:97313E85C0937739AF7C7FC084A10BF202AC9942
    SHA-256:44976408BD6D2703BDBE177259061A502552193B1CD05E09B698C0DAC3653C5F
    SHA-512:DBD72827044331215A7221CA9B0ECB8809C7C79825B9A2275F3450BAE016D7D320B4CA94095F7CEF4372AC63155C78CA4795E23F93166D4720032ECF9F932B8E
    Malicious:false
    Reputation:low
    Preview:PK..........1A..d T....P......[Content_Types].xml..Ms.@.....!...=.7....kX 5o.,L..<..........d..g/..dw.]...C...9...#g/."L..;...#. ]..f...w../._.3Y8..X.[..7._.[...K3..3.4......D.]l.?...~.&J&...s...;...H9...e.3.q.....k-.0>Lp:.7..eT...Y...P...OVg.....G..).aV...\Z.x...W.>f...oq.8.....I?Ky...g..."...J?....A$zL.].7.M.^..\....C..d/;.J0.7k.X4.e..?N{....r.."LZx.H?. ......;r.+...A<.;U.....4...!'k...s.&..)'k...d..d......._E..D...o..o...o...f.7;s..]...Uk6d.j..MW....5[C].f#...l;u.M..Z.../iM|...b...s.....0..O.... ...>..>..>..>..>..>..>.........2V}......Q}#.&T...rU....\..\..\..\..\..\..\..\.W..W.^Z....Q}c;.o...>.Z..\.v...............................*Z....K.X.5X8.obG.MP.P.'P.U}.k..rU..rU..rU..rU..rU..rU..rU..rU_EK_}.zi.....G.M.).....j...r..]..CZ..CZ..CZ..CZ..CZ..CZ..CZ..h.oZ/-c..`....7CaBu.@-W.A.]..U}H.U}H.U}H.U}H.U}H.U}H.U}H.U}.-}...e...,...|...].k.........PK..........1A.s@.....O......._rels/.rels...J.1.._%..d...t......}...n2!..}6.>..`(.v...K`2...70...
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:Microsoft OOXML
    Category:dropped
    Size (bytes):486596
    Entropy (8bit):7.668294441507828
    Encrypted:false
    SSDEEP:6144:A+JBmUx0Zo24n8z/2NSYFl2qGBuv8p6+LwwYmN59wBttsdJrmXMlP1NwQoGgeL:fNgxz/g5z2BT6+Eu0ntMcczNQG5L
    MD5:0E37AECABDB3FDF8AAFEDB9C6D693D2F
    SHA1:F29254D2476DF70979F723DE38A4BF41C341AC78
    SHA-256:7AC7629142C2508B070F09788217114A70DE14ACDB9EA30CBAB0246F45082349
    SHA-512:DE6AFE015C1D41737D50ADD857300996F6E929FED49CB71BC59BB091F9DAB76574C56DEA0488B0869FE61E563B07EBB7330C8745BC1DF6305594AC9BDEA4A6BF
    Malicious:false
    Reputation:low
    Preview:PK.........V'BE,.{....#P......[Content_Types].xml..`.I.%&/m.{.J.J..t...`.$.@........iG#).*..eVe]f.@....{...{...;.N'...?\fd.l..J..!....?~|.?"....|.{.[..e^7E......Gi..V.by..G..|.......U..t.|..mW...m..|.5.j./..^d-.Y_.]e..E~wog...j...v......?..u....c...W..G.4D_.}T,.@...}....R.Z..4k.....Y..mEkLor.f^..O..P...`.../.|u1..Y.....nK.......u=..2.tu~^L.Y5]/...~+.v...o....j.`?.S...../.by.|..>."kZbs....H.9..m.z.]W.V.?~v........;...N.......w....;.z..N.......w.....R.~n..Ofu.-..K.e....{..A.~.8.#D..)o.7..........:2........=......f...u....[..}...u.6b...xz.[...G..|#...$....)J./.......7.............oQ..]^.M........wy}7a.....&l................w.......l._...l..?.A..........r..9.|.8.........{w...........n...]^.M........wy}7a.....&l.................`..z..`.....2.o...wx}.....>..c.M..Arr#.....nD..[.....w......n...]^.M........wy}7a.....&l........w........... ..Fp....w_Q....g..tL.i.?H.o...]^..........n...]^.M........wy}7a.....&l.................`..z..`
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:Microsoft OOXML
    Category:dropped
    Size (bytes):976001
    Entropy (8bit):7.791956689344336
    Encrypted:false
    SSDEEP:24576:zHM7eZGgFiHMRej4N9tpytNZ+tIw5ErZBImlX0m:zHM7eZGgFiHMRej++NZ+F5WvllZ
    MD5:9E563D44C28B9632A7CF4BD046161994
    SHA1:D3DB4E5F5B1CC6DD08BB3EBF488FF05411348A11
    SHA-256:86A70CDBE4377C32729FD6C5A0B5332B7925A91C492292B7F9C636321E6FAD86
    SHA-512:8EB14A1B10CB5C7607D3E07E63F668CFC5FC345B438D39138D62CADF335244952FBC016A311D5CB8A71D50660C49087B909528FC06C1D10AF313F904C06CBD5C
    Malicious:false
    Reputation:low
    Preview:PK.........{MB.f}......p......[Content_Types].xml..`.I.%&/m.{.J.J..t...`.$.@........iG#).*..eVe]f.@....{...{...;.N'...?\fd.l..J..!....?~|.?"....|.{.[..e^7E......Gi..V.by..G..|.......U..t.|..mW...m..|.5.j./..^d-.Y_.]e..E~wog...j...v......?..u....c.v...(=.v........F_..U..G...T.e.y)[..b.......3.m....6.X5.P........_...b../..}.-......~.-..z..d.......j.^.+c..E.V..~3}..U.7..~p.>.E..9^d....4%}.E.$....N..r....<....%...%.?....w.u...h........D...w.....h........Dkw...x..T....T....T....T....T....T....j...."[.J.....;..!4...M...............t.n-.{..skp...[;.......F...j.7...4fC...K1..K/..K-..K+..K)..K'..f9......Fl._.........d0...?7K7].........A.......Fl.............Ft....u.......Ft........\.......w....R.......R.......R........o...].`.....A....#.`..\.....S.._...4...o.........W<x#..............w#...r.nD..]....\.~....|......b...^...Z...V...R...N..W<x......l._...l..?.A......xp_Q..y<h..tL.i.?HNn...]..........r.nD..]~.........wy~7......Ft...........E/|c.
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:Zip archive data, at least v2.0 to extract, compression method=deflate
    Category:dropped
    Size (bytes):1463634
    Entropy (8bit):7.898382456989258
    Encrypted:false
    SSDEEP:24576:75MGNW/UpLkupMAqDJhNHK4/TuiKbdhbZM+byLH/:7ZwUpLkulkHK46iiDZHeLH/
    MD5:ACBA78931B156E4AF5C4EF9E4AB3003B
    SHA1:2A1F506749A046ECFB049F23EC43B429530EC489
    SHA-256:943E4044C40ABA93BD7EA31E8B5EBEBD7976085E8B1A89E905952FA8DAC7B878
    SHA-512:2815D912088BA049F468CA9D65B92F8951A9BE82AB194DBFACCF0E91F0202820F5BC9535966654D28F69A8B92D048808E95FEA93042D8C5DEA1DCB0D58BE5175
    Malicious:false
    Reputation:low
    Preview:PK.........{MB.f}......p......[Content_Types].xml..`.I.%&/m.{.J.J..t...`.$.@........iG#).*..eVe]f.@....{...{...;.N'...?\fd.l..J..!....?~|.?"....|.{.[..e^7E......Gi..V.by..G..|.......U..t.|..mW...m..|.5.j./..^d-.Y_.]e..E~wog...j...v......?..u....c.v...(=.v........F_..U..G...T.e.y)[..b.......3.m....6.X5.P........_...b../..}.-......~.-..z..d.......j.^.+c..E.V..~3}..U.7..~p.>.E..9^d....4%}.E.$....N..r....<....%...%.?....w.u...h........D...w.....h........Dkw...x..T....T....T....T....T....T....j...."[.J.....;..!4...M...............t.n-.{..skp...[;.......F...j.7...4fC...K1..K/..K-..K+..K)..K'..f9......Fl._.........d0...?7K7].........A.......Fl.............Ft....u.......Ft........\.......w....R.......R.......R........o...].`.....A....#.`..\.....S.._...4...o.........W<x#..............w#...r.nD..]....\.~....|......b...^...Z...V...R...N..W<x......l._...l..?.A......xp_Q..y<h..tL.i.?HNn...]..........r.nD..]~.........wy~7......Ft...........E/|c.
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:Microsoft OOXML
    Category:dropped
    Size (bytes):2218943
    Entropy (8bit):7.942378408801199
    Encrypted:false
    SSDEEP:49152:8mwK3gH/l4hM06Wqnnl1IdO9wASFntrPEWNe7:863gHt4hM9WWnMdO9w35PEWK
    MD5:EE33FDA08FBF10EF6450B875717F8887
    SHA1:7DFA77B8F4559115A6BF186EDE51727731D7107D
    SHA-256:5CF611069F281584DE3E63DE8B99253AA665867299DC0192E8274A32A82CAA20
    SHA-512:AED6E11003AAAACC3FB28AE838EDA521CB5411155063DFC391ACE2B9CBDFBD5476FAB2B5CC528485943EBBF537B95F026B7B5AB619893716F0A91AEFF076D885
    Malicious:false
    Reputation:low
    Preview:PK.........{MBS'..t...ip......[Content_Types].xml..`.I.%&/m.{.J.J..t...`.$.@........iG#).*..eVe]f.@....{...{...;.N'...?\fd.l..J..!....?~|.?"....|.{.[..e^7E......Gi..V.by..G..|.......U..t.|..mW...m..|.5.j./..^d-.Y_.]e..E~wog...j...v......?..u....c...W..G.4D_.}T,.@...}....R.Z..4k.....Y..mEkLor.f^..O..P...`.../.|u1..Y.....nK.......u=..2.tu~^L.Y5]/...~+.v...o....j.`?.S...../.by.|..>."kZbs....H.9..m.z.]W.V.?~v........;...N.......w....;.z..N.......w.....R.._..w._..w._..w._..w._..w._..w.n..Ofu.-..K.e........T..q.F...R[...~.u.....Z..F....7.?.v....5O....zot..i.....b...^...Z...V...R...N...r./.?........=....#.`..\~n.n...)J./.......7........+......Q..]n............w......Ft........|......b...^...Z...V...R...N..W<x......l._...l..?.A......x....x.9.|.8..............u................w#.....nD..]...........R.......R.......R........o...].`.....A....#.`..\.....+J./.......7........+......Q..]n.........w9~7......Ft........|......b...^.c..-...-...-
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:Microsoft OOXML
    Category:dropped
    Size (bytes):1750795
    Entropy (8bit):7.892395931401988
    Encrypted:false
    SSDEEP:24576:DyeAqDJpUDH3xk8ZKIBuX3TPtd36v4o5d4PISMETGBP6eUP+xSeW3v0HKPsc:uRqUjSTPtd36AFDM/BP6eUeW3v0Fc
    MD5:529795E0B55926752462CBF32C14E738
    SHA1:E72DFF8354DF2CB6A5698F14BBD1805D72FEEAFF
    SHA-256:8D341D1C24176DC6B67104C2AF90FABD3BFF666CCC0E269381703D7659A6FA05
    SHA-512:A51F440F1E19C084D905B721D0257F7EEE082B6377465CB94E677C29D4E844FD8021D0B6BA26C0907B72B84157C60A3EFEDFD96C16726F6ABEA8D896D78B08CE
    Malicious:false
    Reputation:low
    Preview:PK.........{MB.f}......p......[Content_Types].xml..`.I.%&/m.{.J.J..t...`.$.@........iG#).*..eVe]f.@....{...{...;.N'...?\fd.l..J..!....?~|.?"....|.{.[..e^7E......Gi..V.by..G..|.......U..t.|..mW...m..|.5.j./..^d-.Y_.]e..E~wog...j...v......?..u....c.v...(=.v........F_..U..G...T.e.y)[..b.......3.m....6.X5.P........_...b../..}.-......~.-..z..d.......j.^.+c..E.V..~3}..U.7..~p.>.E..9^d....4%}.E.$....N..r....<....%...%.?....w.u...h........D...w.....h........Dkw...x..T....T....T....T....T....T....j...."[.J.....;..!4...M...............t.n-.{..skp...[;.......F...j.7...4fC...K1..K/..K-..K+..K)..K'..f9......Fl._.........d0...?7K7].........A.......Fl.............Ft....u.......Ft........\.......w....R.......R.......R........o...].`.....A....#.`..\.....S.._...4...o.........W<x#..............w#...r.nD..]....\.~....|......b...^...Z...V...R...N..W<x......l._...l..?.A......xp_Q..y<h..tL.i.?HNn...]..........r.nD..]~.........wy~7......Ft...........E/|c.
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:Microsoft OOXML
    Category:dropped
    Size (bytes):2924237
    Entropy (8bit):7.970803022812704
    Encrypted:false
    SSDEEP:49152:mc4NEo4XNd5wU5qTkdC4+K9u5b/i40RKRAO/cLf68wy9yxKrOUURBgmai2prH:mJef5yTSoKMF//DRGJwLx9DBaH
    MD5:5AF1581E9E055B6E323129E4B07B1A45
    SHA1:B849F85BCAF0E1C58FA841FFAE3476D20D33F2DD
    SHA-256:BDC9FBF81FBE91F5BF286B2CEA00EE76E70752F7E51FE801146B79F9ADCB8E98
    SHA-512:11BFEF500DAEC099503E8CDB3B4DE4EDE205201C0985DB4CA5EBBA03471502D79D6616D9E8F471809F6F388D7CBB8B0D0799262CBE89FEB13998033E601CEE09
    Malicious:false
    Reputation:low
    Preview:PK.........{MB.$<.~....p......[Content_Types].xml..`.I.%&/m.{.J.J..t...`.$.@........iG#).*..eVe]f.@....{...{...;.N'...?\fd.l..J..!....?~|.?"....|.{.[..e^7E......Gi..V.by..G..|.......U..t.|..mW...m..|.5.j./..^d-.Y_.]e..E~wog...j...v......?..u....c...W..G.4D_.}T,.@...}....R.Z..4k.....Y..mEkLor.f^..O..P...`..^.......H^..<}...lA-.D.....lI/...hD.Z....|VM..ze........L..tU...g....lQ....Y...>MI...5-....S......h=..u.h..?;h...@k...h...'Z...D...;.....h=..'Z...D...;.....)^./.../U.../..../U.../..../U..?...'.........Ngz..A.~.8.#D....xot.u.?...eyot.n..{..sk....[......Z..F....l...o)..o..o...oi..o)..o..,..b.s......2.C.z.~8.......f......x.9.|.8..............u................r.nD..]...........w.~7...-...-...-...-...-...-....x.&l........>.4.z.~8..........=E....As.1..q. 9....w.7...1........w.}7......Ft...................o)..o..o...oi..o)..o..w.7a...x0...........d0..............A.......Fl.............Ft................w#...r.nD..]..M...K1.0..7....
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:Microsoft OOXML
    Category:dropped
    Size (bytes):2357051
    Entropy (8bit):7.929430745829162
    Encrypted:false
    SSDEEP:49152:tfVcGO3JiR6SgT7/bOCrKCsaFCX3CzwovQTSwW8nX:pVcG2iRedsaoXSzeOwWEX
    MD5:5BDE450A4BD9EFC71C370C731E6CDF43
    SHA1:5B223FB902D06F9FCC70C37217277D1E95C8F39D
    SHA-256:93BFC6AC1DC1CFF497DF92B30B42056C9D422B2321C21D65728B98E420D4ED50
    SHA-512:2365A9F76DA07D705A6053645FD2334D707967878F930061D451E571D9228C74A8016367525C37D09CB2AD82261B4B9E7CAEFBA0B96CE2374AC1FAC6B7AB5123
    Malicious:false
    Reputation:low
    Preview:PK.........{MB.f}......p......[Content_Types].xml..`.I.%&/m.{.J.J..t...`.$.@........iG#).*..eVe]f.@....{...{...;.N'...?\fd.l..J..!....?~|.?"....|.{.[..e^7E......Gi..V.by..G..|.......U..t.|..mW...m..|.5.j./..^d-.Y_.]e..E~wog...j...v......?..u....c.v...(=.v........F_..U..G...T.e.y)[..b.......3.m....6.X5.P........_...b../..}.-......~.-..z..d.......j.^.+c..E.V..~3}..U.7..~p.>.E..9^d....4%}.E.$....N..r....<....%...%.?....w.u...h........D...w.....h........Dkw...x..T....T....T....T....T....T....j...."[.J.....;..!4...M...............t.n-.{..skp...[;.......F...j.7...4fC...K1..K/..K-..K+..K)..K'..f9......Fl._.........d0...?7K7].........A.......Fl.............Ft....u.......Ft........\.......w....R.......R.......R........o...].`.....A....#.`..\.....S.._...4...o.........W<x#..............w#...r.nD..]....\.~....|......b...^...Z...V...R...N..W<x......l._...l..?.A......xp_Q..y<h..tL.i.?HNn...]..........r.nD..]~.........wy~7......Ft...........E/|c.
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:Microsoft OOXML
    Category:dropped
    Size (bytes):1091485
    Entropy (8bit):7.906659368807194
    Encrypted:false
    SSDEEP:24576:oBpmCkw3Tg/euEB+UdoC4k7ytHkHA6B/puqW2MIkTeSBmKrZHQ:MR3c/AseydwppC7veSBmWHQ
    MD5:2192871A20313BEC581B277E405C6322
    SHA1:1F9A6A5E10E1C3FFEB6B6725C5D2FA9ECDF51085
    SHA-256:A06B302954A4C9A6A104A8691864A9577B0BFEA240B0915D9BEA006E98CDFFEC
    SHA-512:6D8844D2807BB90AEA6FE0DDDB9C67542F587EC9B7FC762746164B2D4A1A99EF8368A70C97BAD7A986AAA80847F64408F50F4707BB039FCCC509133C231D53B9
    Malicious:false
    Reputation:low
    Preview:PK...........G`.jaV....P......[Content_Types].xml...n.@...W......T@.mwM.E....)....y...H}.N..ll8.h5g6Q.=3_......?...x..e^Di.p.^.ud...(Y/..{w..r..9.../M...Q*{..E...(.4..>..y,.>..~&..b-.a.?..4Q2Q=.2.......m....>-....;]......N'..A...g.D.m.@(}..'.3Z....#....(+....-q<uq.+....?....1.....Y?Oy......O"..J?....Q$zT.].7.N..Q Wi.....<.........-..rY....hy.x[9.b.%-<.V?.(......;r.+...Q<.;U.....4...!'k...s.&..)'k...d.s..}R....o".D.I..7..7.KL.7..Z.....v..b.5.2].f....l.t....Z...Uk...j.&.U-....&>.ia1..9lhG..Q.P.'P.U}.k..rU..rU..rU..rU..rU..rU..rU..rU_EK_}.zi.....G.........j...r..]..CZ..CZ..CZ..CZ..CZ..CZ..CZ..h.oT/-c..`....7FaBu.@-W.A.]..U}H.U}H.U}H.U}H.U}H.U}H.U}H.U}.-}...e...,..7...&(L.....>.kw...i...i...i...i...i...i...i.......I...U_.....vT.....}..\...v..W.!-W.!-W.!-W.!-W.!-W.!-W.!-W.U...7.....k.pT...0..O.... ...>..>..>..>..>..>..>......f..2V}....W>jO....5..].?.o..oPK...........G.s@.....O......._rels/.rels...J.1.._%..d...t......}...n2!..}6.>..`(.v...K`2...70.
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:Microsoft OOXML
    Category:dropped
    Size (bytes):608122
    Entropy (8bit):7.729143855239127
    Encrypted:false
    SSDEEP:6144:Ckl6KRKwg9jf2q/bN69OuGFlC/DUhq68xOcJzGYnTxlLqU8dmTW:8yKwgZ2qY9kA7Uhq68H3ybmq
    MD5:8BA551EEC497947FC39D1D48EC868B54
    SHA1:02FA15FDAF0D7E2F5D44CAE5FFAE49E8F91328DF
    SHA-256:DB2E99B969546E431548EBD58707FC001BBD1A4BDECAD387D194CC9C6D15AC89
    SHA-512:CC97F9B2C83FF7CAC32AB9A9D46E0ACDE13EECABECD653C88F74E4FC19806BB9498D2F49C4B5581E58E7B0CB95584787EA455E69D99899381B592BEA177D4D4B
    Malicious:false
    Reputation:low
    Preview:PK.........LGE,.{E...#P......[Content_Types].xml..Mo.0.....Z..N7.=l......V0.-o..j?...H..sa......./UCb.'...r...w.i..e..<[....{2..U.m..N.{...r.....3.fj.o......2.*....;.L.6..&,D.Cld8...a.gZf.......r-v..><....~/......|Zk.......a.R&.d.(.$..6..}.:.....3......1..[.p.....?..+....R...y,.fod.....e...-.|..#..]j....n:...f...-J...i.^.:Y....T..........m^..~GNp../e}...N....a..5.d.8YcN..5.d.8Y...7..A..e...7Q."3...../.sL._...v...n..b..2].v....n.t....Z...Uk...j.&.Z....im|.r....B.....7DaBuN.... ...>..>..>..>..>..>..>.........V}-.....Q}#.&T..j...r..]..CZ..CZ..CZ..CZ..CZ..CZ..CZ..i.o.,-k..b....7FaBuN.... ...>..>..>..>..>..>..>.........V}-...Q}..&T..j...r..]..CZ..CZ..CZ..CZ..CZ..CZ..CZ..i.o.,-k..b....7EaBuN.... ...>..>..>..>..>..>..>.........V}-...Q}3.&T..j...r..]..CZ..CZ..CZ..CZ..CZ..CZ..CZ..i.o.,-k..b.\}..)...A.......[..PK.........LG.s@.....O......._rels/.rels...J.1.._%..d...t......}...n2!..}6.>..`(.v...K`2...70...........84P....
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:Microsoft OOXML
    Category:dropped
    Size (bytes):5783
    Entropy (8bit):7.88616857639663
    Encrypted:false
    SSDEEP:96:CDG4D+8VsXzXc2zLXTJ2XFY47pk2G7HVlwFzTXNbMfmn2ivLZcreFWw5fc9ADdZm:CDG4DRGY23l2Xu47GL7YtT9V29yWvWdk
    MD5:8109B3C170E6C2C114164B8947F88AA1
    SHA1:FC63956575842219443F4B4C07A8127FBD804C84
    SHA-256:F320B4BB4E57825AA4A40E5A61C1C0189D808B3EACE072B35C77F38745A4C416
    SHA-512:F8A8D7A6469CD3E7C31F3335DDCC349AD7A686730E1866F130EE36AA9994C52A01545CE73D60B642FFE0EE49972435D183D8CD041F2BB006A6CAF31BAF4924AC
    Malicious:false
    Reputation:low
    Preview:PK.........A;.h......F.......[Content_Types].xmlz.........MN.0...by.b.,.BI...X `...{..O.S...H\.'.XTP..K{.o.....rg..bL...XM.:.v..c.k...}.D....9.....Bb>.+..G.......+(.u}.w.]...v..{.M&.].>`....nB..B0Z@.e.u..R.......-.&#....aR..`.a..|. 1^......&..|..s.A.t..b..A.i7...7.&....bQK$O.......9....V....Wt_PK........pnB;.M.:....g......._rels/.rels...J.0.._%.n....xp..,{.i2M.........G..........7...3o/.......d.kyU....^..[>Q....j.#P.H......Z>..+!...B*|@...G...E....E]..".3.......!..7....,:..,.......Ot..0r....Z..&1..U..p.U-.[Uq&.......................Gyy.}n.(.C(i.x........?.vM..}..%.7.b.>L..]..PK........EV:5K..4....H......diagrams/layout1.xml.Yo.6........S.`......$M...Q8A...R..T.k...K.4CQG..}.A..9.?R....!&...Q..ZW.......Q....<8..z..g....4{d.>..;.{.>.X.....Y.2.......cR....9e.. ...}L.....yv&.&...r..h...._..M. e...[..}.>.k..........3.`.ygN...7.w..3..W.S.....w9....r(....Zb..1....z...&WM.D<......D9...ge......6+.Y....$f......wJ$O..N..FC..Er........?..is...-Z
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:Microsoft OOXML
    Category:dropped
    Size (bytes):4026
    Entropy (8bit):7.809492693601857
    Encrypted:false
    SSDEEP:96:VpDCBFLhxaUGm5EWA07yNdKH1FQpy8tnX8Iz3b7TrT502+fPD:VpDYFFRMNU+RtXzLf35t+3D
    MD5:5D9BAD7ADB88CEE98C5203883261ACA1
    SHA1:FBF1647FCF19BCEA6C3CF4365C797338CA282CD2
    SHA-256:8CE600404BB3DB92A51B471D4AB8B166B566C6977C9BB63370718736376E0E2F
    SHA-512:7132923869A3DA2F2A75393959382599D7C4C05CA86B4B27271AB9EA95C7F2E80A16B45057F4FB729C9593F506208DC70AF2A635B90E4D8854AC06C787F6513D
    Malicious:false
    Reputation:low
    Preview:PK........YnB;.h......F.......[Content_Types].xmlz.........MN.0...by.b.,.BI...X `...{..O.S...H\.'.XTP..K{.o.....rg..bL...XM.:.v..c.k...}.D....9.....Bb>.+..G.......+(.u}.w.]...v..{.M&.].>`....nB..B0Z@.e.u..R.......-.&#....aR..`.a..|. 1^......&..|..s.A.t..b..A.i7...7.&....bQK$O.......9....V....Wt_PK........bnB;?.......f......._rels/.rels...J.1.._%..f....m/.,x...&.lt.dV.y.|.."v....q..|......r..F..)..;.T5g.eP..O..Z.^-.8...<.Y....Q.."....*D.%.!9.R&#".'0(.u}).!..l....b..J..rr....P.L.w..0.-......A..w..x.7U...Fu<mT.....^s...F./ ..( .4L..`.....}...O..4.L...+H.z...m..j[].=........oY}.PK........J.L6...m....,.......diagrams/layout1.xml.X.n.8.}N.....PG.............wZ.,.R.%.K...J.H]....y.3..9...O..5."J.1.\.1....Q....z......e.5].)...$b.C)...Gx!...J3..N..H...s....9.~...#..$...W.8..I`|..0xH}......L.|..(V;..1...kF..O=...j...G.X.....T.,d>.w.Xs.......3L.r..er\o..D..^....O.F.{:.>.R'....Y-...B.P.;....X.'c...{x*.M7..><l.1.w..{].46.>.z.E.J.......G......Hd..$..7....E.
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:Microsoft OOXML
    Category:dropped
    Size (bytes):4243
    Entropy (8bit):7.824383764848892
    Encrypted:false
    SSDEEP:96:22MQe4zHye8/djzF+JjvtmMkkBpF7e0LTkaf:22De4zHHCvF+nRBDXoaf
    MD5:7BC0A35807CD69C37A949BBD51880FF5
    SHA1:B5870846F44CAD890C6EFF2F272A037DA016F0D8
    SHA-256:BD3A013F50EBF162AAC4CED11928101554C511BD40C2488CF9F5842A375B50CA
    SHA-512:B5B785D693216E38B5AB3F401F414CADACCDCB0DCA4318D88FE1763CD3BAB8B7670F010765296613E8D3363E47092B89357B4F1E3242F156750BE86F5F7E9B8D
    Malicious:false
    Reputation:low
    Preview:PK........NnB;.h......F.......[Content_Types].xmlz.........MN.0...by.b.,.BI...X `...{..O.S...H\.'.XTP..K{.o.....rg..bL...XM.:.v..c.k...}.D....9.....Bb>.+..G.......+(.u}.w.]...v..{.M&.].>`....nB..B0Z@.e.u..R.......-.&#....aR..`.a..|. 1^......&..|..s.A.t..b..A.i7...7.&....bQK$O.......9....V....Wt_PK........TnB;..d.....h......._rels/.rels...J.0.._%.n..)"....<.w.&.4..!...y.|.........|.&3.o.....S..K.T5g.U....g..n.f....T*.hcf...D.V..Ft....d....c2".z.....N.s._2....7.0.V.]P.CO?...`...8....4&......_i..Y.T...Z...g....{-...]..pH..@.8....}tP.)..B>..A...S&......9..@...7........b_.PK........r};5.z..............diagrams/layout1.xml.X.n.8.}.........4.+.(...@......(..J..._.!)..b..v.}.H..zf8...dhM....E..I.H..V.Y.R..2zw5L~....^..]...J_..4.\.\......8..z..2T..".X.l.F#......5....,*....c....r.kR.I.E..,.2...&%..''.qF.R.2.....T;F...W.. ...3...AR.OR.O..J}.w6..<...,.x..x....`g?.t.I.{.I...|X..g.....<BR..^...Q.6..m.kp...ZuX.?.z.YO.g...$.......'.]..I.#...]$/~`${.
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:Zip archive data, at least v2.0 to extract, compression method=deflate
    Category:dropped
    Size (bytes):16806
    Entropy (8bit):7.9519793977093505
    Encrypted:false
    SSDEEP:384:eSMjhqgJDGwOzHR3iCpK+QdLdfufFJ9aDn9LjDMVAwHknbz7OW:eSkhqglGwERSAHQdLhDn9AKokv7H
    MD5:950F3AB11CB67CC651082FEBE523AF63
    SHA1:418DE03AD2EF93D0BD29C3D7045E94D3771DACB4
    SHA-256:9C5E4D8966A0B30A22D92DB1DA2F0DBF06AC2EA75E7BB8501777095EA0196974
    SHA-512:D74BF52A58B0C0327DB9DDCAD739794020F00B3FA2DE2B44DAAEC9C1459ECAF3639A5D761BBBC6BDF735848C4FD7E124D13B23964B0055BB5AA4F6AFE76DFE00
    Malicious:false
    Reputation:low
    Preview:PK.........T.>................[Content_Types].xmlz.........=N.1...b.Eko(.B....(.Pp..=.u.?.....#q..ND.!$.J{.o....G..[Cv.....+.R.Nx..........0."u..S...$&.....Je..B..x......m......M^z....f....|...N..Q..z.!.- .2.9y.i.8j...........0.AE..p.s~@../jw.#8.I.#....4.~Cl.:#h..f.PU.s.~........(.)F..Y......^x..PK.........T.>...V....L......._rels/.rels...J.@.._e..]AD.....x....3.t..T.w.\ZpA<x......v..'....z.........Y..[...<..2.TT....Q$.!.=.....&C....b".F.q.7...X3...7.8.N.}.. ?..8...#..,.L.3.#e...wZpZ.]S..:....t.....{..6.7.|..,dH.e..K 7-}.~.v...5.......b..PK........Ul.<..<"I5...&......diagrams/layout1.xml.}.r.I..s........~Y.f.gzfv......E."w.K..J5m.e...4.0..Q... A.!...%...<...3.......O.......t~.u{...5.G......?,.........N......L......~.:....^,..r=./~7_..8............o.y......oo.3.f........f.......r.7../....qrr.v9.......,?..._O.....?9.O~]..zv.I'.W..........;..\..~....../........?~..n.....\}pt.........b,~...;>.=;>:..u.....?.......2]..]....i......9..<.p..4D..
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:Zip archive data, at least v2.0 to extract, compression method=deflate
    Category:dropped
    Size (bytes):11380
    Entropy (8bit):7.891971054886943
    Encrypted:false
    SSDEEP:192:VJcnLYnAVbOFLaCPLrGGbhaWEu6d3RmryqLkeAShObPb1AYcRMMXjkfa0nYBwggD:VcMC8lLrRbhy1ZqLyShYb1FHQ4C0nYQJ
    MD5:C9F9364C659E2F0C626AC0D0BB519062
    SHA1:C4036C576074819309D03BB74C188BF902D1AE00
    SHA-256:6FC428CA0DCFC27D351736EF16C94D1AB08DDA50CB047A054F37EC028DD08AA2
    SHA-512:173A5E68E55163B081C5A8DA24AE46428E3FB326EBE17AE9588C7F7D7E5E5810BFCF08C23C3913D6BEC7369E06725F50387612F697AC6A444875C01A2C94D0FF
    Malicious:false
    Reputation:low
    Preview:PK.........T.>................[Content_Types].xmlz.........=N.1...b.Eko(.B....(.Pp..=.u.?.....#q..ND.!$.J{.o....G..[Cv.....+.R.Nx..........0."u..S...$&.....Je..B..x......m......M^z....f....|...N..Q..z.!.- .2.9y.i.8j...........0.AE..p.s~@../jw.#8.I.#....4.~Cl.:#h..f.PU.s.~........(.)F..Y......^x..PK.........T.>...V....L......._rels/.rels...J.@.._e..]AD.....x....3.t..T.w.\ZpA<x......v..'....z.........Y..[...<..2.TT....Q$.!.=.....&C....b".F.q.7...X3...7.8.N.}.. ?..8...#..,.L.3.#e...wZpZ.]S..:....t.....{..6.7.|..,dH.e..K 7-}.~.v...5.......b..PK........q.~<.6..9 ...e......diagrams/layout1.xml..r.........{.]..u...xv7b.....HPd....t.q...b.i_a.'..P.f.3..F..1...U.u.*.2......?}..O..V.....yQ.Mf........w.....O....N.........t3;...e....j.^.o&.....w...../.w................e.................O..,./..6...8>^.^..........ru5...\.=>[M?......g..........w.N....i.........iy6.?........>.......>{yT...........x.........-...z5.L./.g......_.l.1.....#...|...pr.q
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:Microsoft OOXML
    Category:dropped
    Size (bytes):6024
    Entropy (8bit):7.886254023824049
    Encrypted:false
    SSDEEP:96:bGa2onnLYHTSSxpHVTSH1bywZKmpRqiUtFvS9xrPooBpni6eDa16MUELHsrKjRBA:SJonLYzSSr1TuZNwtFZKpiiyrKXuCUd
    MD5:20621E61A4C5B0FFEEC98FFB2B3BCD31
    SHA1:4970C22A410DCB26D1BD83B60846EF6BEE1EF7C4
    SHA-256:223EA2602C3E95840232CACC30F63AA5B050FA360543C904F04575253034E6D7
    SHA-512:BDF3A8E3D6EE87D8ADE0767918603B8D238CAE8A2DD0C0F0BF007E89E057C7D1604EB3CCAF0E1BA54419C045FC6380ECBDD070F1BB235C44865F1863A8FA7EEA
    Malicious:false
    Reputation:low
    Preview:PK.........T.>................[Content_Types].xmlz.........=N.1...b.Eko(.B....(.Pp..=.u.?.....#q..ND.!$.J{.o....G..[Cv.....+.R.Nx..........0."u..S...$&.....Je..B..x......m......M^z....f....|...N..Q..z.!.- .2.9y.i.8j...........0.AE..p.s~@../jw.#8.I.#....4.~Cl.:#h..f.PU.s.~........(.)F..Y......^x..PK.........T.>...V....L......._rels/.rels...J.@.._e..]AD.....x....3.t..T.w.\ZpA<x......v..'....z.........Y..[...<..2.TT....Q$.!.=.....&C....b".F.q.7...X3...7.8.N.}.. ?..8...#..,.L.3.#e...wZpZ.]S..:....t.....{..6.7.|..,dH.e..K 7-}.~.v...5.......b..PK........2..<..]#.....'......diagrams/layout1.xml.].r.8...V.;0.;..aO........{.....V..3].d{..............\. .#.t... ........x<...@7o.]..7.N..@.NF..../....S.../.xC..U...<..Q.=...|..v.....cQ..Y=.....i`.. ..?.;...Go....x.O.$....7s..0..qg....|..r..l.w.a..p.3.Em7v...N............3..7...N.\\..f...9...U$..7...k.C..M.@\.s....G/..?...I...t.Yos...p..z...6.lnqi.6..<..1qg+......#]....|C/N..K\}.....#..".
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:Zip archive data, at least v2.0 to extract, compression method=deflate
    Category:dropped
    Size (bytes):9191
    Entropy (8bit):7.93263830735235
    Encrypted:false
    SSDEEP:192:oeAMExvPJMg+yE+AfJLi3+Xoj7F3sPgMG61J88eDhFWT7hFNsdJtnLYJ7tSh:v2d+hnfJLi3+4ja4WqhFWT7FsdHMA
    MD5:08D3A25DD65E5E0D36ADC602AE68C77D
    SHA1:F23B6DDB3DA0015B1D8877796F7001CABA25EA64
    SHA-256:58B45B9DBA959F40294DA2A54270F145644E810290F71260B90F0A3A9FCDEBC1
    SHA-512:77D24C272D67946A3413D0BEA700A7519B4981D3B4D8486A655305546CE6133456321EE94FD71008CBFD678433EA1C834CFC147179B31899A77D755008FCE489
    Malicious:false
    Reputation:low
    Preview:PK.........]w>....<...5.......diagrams/layout1.xmlz........].r.F.}......1w`.J..'.......w..Dn. d....~........pw...O.......s...?...p7.t>e.r<.]u.e..d..|8..\uo.......K...._.Y..E6.|..y;........y.*/:o./...:[.o.+/.....?.....Z.?..s..d}...S.`...b.^o9.e.ty9_d...y>M.....7...e....."....<.v.u...e:].N.t....a....0..}..bQ.Y..>.~..~...U.|..Ev.....N...bw....{...O..Y.Y.&........A.8Ik...N.Z.P.[}t........|m...E..v..,..6........_?..."..K<.=x....$..%@.e..%....$=F..G..e........<F..G51..;......=...e.e.q..d......A...&9'.N.\%.=N.Z.9.s......y.4.Q.c......|8.......Eg.:.ky.z.h.......).O...mz...N.wy.m...yv....~8.?Lg..o.l.y:.....z.i..j.irxI.w...r.......|.=....s};.\u.{t;i~S.......U7..mw...<.vO...M.o...W.U.....}.`V<|..%....l..`>]..".].I.i.N..Z..~Lt.........}?..E~:..>$......x...%.........N....'C.m.=...w.=.Y...+'M.].2 >.]_~...'.?...:....z.O..Y......6..5...sj?.....).B..>.3...G...p.9.K!..[H..1$v../...E V..?`....+[...C......h..!.QI5....<.>...A.d.......
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:Microsoft OOXML
    Category:dropped
    Size (bytes):4326
    Entropy (8bit):7.821066198539098
    Encrypted:false
    SSDEEP:96:+fF+Jrp7Yo5hnJiGa24TxEcpUeONo1w2NFocy2LQi33Z:2+f7YuhJdJ4TxEcmKwGkk3Z
    MD5:D32E93F7782B21785424AE2BEA62B387
    SHA1:1D5589155C319E28383BC01ED722D4C2A05EF593
    SHA-256:2DC7E71759D84EF8BB23F11981E2C2044626FEA659383E4B9922FE5891F5F478
    SHA-512:5B07D6764A6616A7EF25B81AB4BD4601ECEC1078727BFEAB4A780032AD31B1B26C7A2306E0DBB5B39FC6E03A3FC18AD67C170EA9790E82D8A6CEAB8E7F564447
    Malicious:false
    Reputation:low
    Preview:PK.........n.A...#............docProps/thumbnail.jpgz.........{4.i....1.n.v)..#.\*....A+..Q(."..D.......#Q)...SQ....2c.ei.JC...N.{......}.s.s..y>....d.(:.;.....q........$.OBaPbI..(.V...o.....'..b..edE.J.+.....".tq..dqX.......8...CA.@..........0.G.O.$Ph...%i.Q.CQ.>.%!j..F..."?@.1J.Lm$..`..*oO...}..6......(%....^CO..p......-,.....w8..t.k.#....d..'...O...8....s1....z.r...rr...,(.)...*.]Q]S.{X.SC{GgWw..O....X./FF9._&..L.....[z..^..*....C...qI.f... .Hq....d*.d..9.N{{.N.6..6)..n<...iU]3.._.....%./.?......(H4<.....}..%..Z..s...C@.d>.v...e.'WGW.....J..:....`....n..6.....]W~/.JX.Qf..^...}...._Sg.-.p..a..C_:..F..E.....k.H..........-Bl$._5...B.w2e...2...c2/y3.U...7.8[.S}H..r/..^...g...|...l..\M..8p$]..poX-/.2}..}z\.|.d<T.....1....2...{P...+Y...T...!............p..c.....D..o..%.d.f.~.;.;=4.J..]1"("`......d.0.....L.f0.l..r8..M....m,.p..Y.f....\2.q. ...d9q....P...K..o!..#o...=.........{.p..l.n...........&..o...!J..|)..q4.Z.b..PP....U.K..|.i.$v
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:Microsoft OOXML
    Category:dropped
    Size (bytes):7370
    Entropy (8bit):7.9204386289679745
    Encrypted:false
    SSDEEP:192:fYa+ngK2xG6HvLvoUnXxO+blKO1lt2Zg0AV:fYVn8Y6Hv3XxO+8uQZCV
    MD5:586CEBC1FAC6962F9E36388E5549FFE9
    SHA1:D1EF3BF2443AE75A78E9FDE8DD02C5B3E46F5F2E
    SHA-256:1595C0C027B12FE4C2B506B907C795D14813BBF64A2F3F6F5D71912D7E57BC40
    SHA-512:68DEAE9C59EA98BD597AE67A17F3029BC7EA2F801AC775CF7DECA292069061EA49C9DF5776CB5160B2C24576249DAF817FA463196A04189873CF16EFC4BEDC62
    Malicious:false
    Reputation:low
    Preview:PK........;nB;.h......F.......[Content_Types].xmlz.........MN.0...by.b.,.BI...X `...{..O.S...H\.'.XTP..K{.o.....rg..bL...XM.:.v..c.k...}.D....9.....Bb>.+..G.......+(.u}.w.]...v..{.M&.].>`....nB..B0Z@.e.u..R.......-.&#....aR..`.a..|. 1^......&..|..s.A.t..b..A.i7...7.&....bQK$O.......9....V....Wt_PK........HnB;..I)....j......._rels/.rels...J.@.._e..&6E.i/.,x..Lw'.j........G..\...................)...Y.3)..`...9r{v!......z...#>5.g.WJ%..T..>'m ..K.T.....j6[(:f.)S....C.mk5^.=:...X......C.... I......&5..e..H.1...).P.cw.kjT......C.......=.....}G!7E.y$.(...}b.........b=.<..^.....U..Y..PK.........^5a.2u............diagrams/layout1.xml..ko.8..+x.t.l..J.n.t.Mnw.x. ....B.t$.,.(&i.....(..d.mY......g.../[.<!.{ap>...L...p....G.9z?...._...e..`..%......8....G!..B8.....o...b.......Q.>|.......g..O\B...i.h...0B.}.....z...k...H..t~r.v........7o.E....$....Z.........ZDd..~......>......O.3.SI.Y.".O&I....#."._c.$.r..z.g0`...0...q:...^0.EF...%(.Ao$.#.o6..c'....$%.}
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:Microsoft OOXML
    Category:dropped
    Size (bytes):5596
    Entropy (8bit):7.875182123405584
    Encrypted:false
    SSDEEP:96:dGa2unnLYEB2EUAPOak380NQjqbHaPKJebgrEVws8Vw+BMa0EbdLVQaZJgDZh0pJ:UJunLYEB2EUAxk3pIYaScgYwsV4bdS0X
    MD5:CDC1493350011DB9892100E94D5592FE
    SHA1:684B444ADE2A8DBE760B54C08F2D28F2D71AD0FA
    SHA-256:F637A67799B492FEFFB65632FED7815226396B4102A7ED790E0D9BB4936E1548
    SHA-512:3699066A4E8A041079F12E88AB2E7F485E968619CB79175267842846A3AD64AA8E7778CBACDF1117854A7FDCFB46C8025A62F147C81074823778C6B4DC930F12
    Malicious:false
    Reputation:low
    Preview:PK.........T.>................[Content_Types].xmlz.........=N.1...b.Eko(.B....(.Pp..=.u.?.....#q..ND.!$.J{.o....G..[Cv.....+.R.Nx..........0."u..S...$&.....Je..B..x......m......M^z....f....|...N..Q..z.!.- .2.9y.i.8j...........0.AE..p.s~@../jw.#8.I.#....4.~Cl.:#h..f.PU.s.~........(.)F..Y......^x..PK.........T.>...V....L......._rels/.rels...J.@.._e..]AD.....x....3.t..T.w.\ZpA<x......v..'....z.........Y..[...<..2.TT....Q$.!.=.....&C....b".F.q.7...X3...7.8.N.}.. ?..8...#..,.L.3.#e...wZpZ.]S..:....t.....{..6.7.|..,dH.e..K 7-}.~.v...5.......b..PK.........V.<.S.....Y.......diagrams/layout1.xml.\.r.8...U....m.$.."3.....;...../3.XAn..O.?....V.;...")Nr.O.H....O......_..E..S...L7....8H.y<=............~...Ic......v9.X.%.\.^.,?g.v.?%w...f.).9.........Ld;.1..?~.%QQ...h.8;.gy..c4..]..0Ii.K&.[.9.......E4B.a..?e.B..4....E.......Y.?_&!.....i~..{.W..b....L.?..L..@.F....c.H..^..i...(d.......w...9..9,........q..%[..]K}.u.k..V.%.Y.....W.y..;e4[V..u.!T...).%.
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:Zip archive data, at least v2.0 to extract, compression method=deflate
    Category:dropped
    Size (bytes):3683
    Entropy (8bit):7.772039166640107
    Encrypted:false
    SSDEEP:96:GyfQZd6ZHNCWl9aXFkZwIq/QDsRYPf8P9QtDIs5r:G6wYtNZS1k99AmPfSOtD5r
    MD5:E8308DA3D46D0BC30857243E1B7D330D
    SHA1:C7F8E54A63EB254C194A23137F269185E07F9D10
    SHA-256:6534D4D7EF31B967DD0A20AFFF092F8B93D3C0EFCBF19D06833F223A65C6E7C4
    SHA-512:88AB7263B7A8D7DDE1225AE588842E07DF3CE7A07CBD937B7E26DA7DA7CFED23F9C12730D9EF4BC1ACF26506A2A96E07875A1A40C2AD55AD1791371EE674A09B
    Malicious:false
    Reputation:low
    Preview:PK.........a9;lq.ri...#.......diagrams/layout1.xmlz........WKn.0.];.`..J..AP...4E..!..hi$..I......z..D.d;...m.d...f.3o.._....9'.P.I1.F.C...d.D:.........Q..Z..5$..BO...e..(.9..2..+.Tsjp.. Vt.f.<...gA.h...8...>..p4..T...9.c...'.G.;.@.;xKE.A.uX.....1Q...>...B...!T.%.* ...0.....&......(.R.u..BW.yF.Grs...)..$..p^.s.c._..F4.*. .<%.BD..E....x... ..@...v.7f.Y......N.|.qW'..m..........im.?.64w..h...UI...J....;.0..[....G..\...?:.7.0.fGK.C.o^....j4............p...w:...V....cR..i...I...J=...%. &..#..[M....YG...u...I)F.l>.j.....f..6.....2.]..$7.....Fr..o.0...l&..6U...M..........%..47.a.[..s........[..r....Q./}.-.(.\..#. ..y`...a2..*....UA.$K.nQ:e!bB.H.-Q-a.$La.%.Z!...6L...@...j.5.....b..S.\c..u...R..dXWS.R.8"....o[..V...s0W..8:...U.#5..hK....ge.Q0$>...k.<...YA.g..o5...3.....~re.....>....:..$.~........pu ._Q..|Z...r...E.X......U....f)s^.?...%......459..XtL:M.).....x..n9..h...c...PK........Ho9<"..%...........diagrams/layoutHeader1.xmlMP.N.0.>oOa.
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:Zip archive data, at least v2.0 to extract, compression method=deflate
    Category:dropped
    Size (bytes):4888
    Entropy (8bit):7.8636569313247335
    Encrypted:false
    SSDEEP:96:StrFZ23/juILHPzms5UTuK9CuZGEoEuZ28H1HiGa2RnnLY+tUb:SPZQ7uCHPzms5UTlqauZVHdJRnLY+tUb
    MD5:0A4CA91036DC4F3CD8B6DBF18094CF25
    SHA1:6C7EED2530CD0032E9EEAB589AFBC296D106FBB9
    SHA-256:E5A56CCB3B3898F76ABF909209BFAB401B5DDCD88289AD43CE96B02989747E50
    SHA-512:7C69426F2250E8C84368E8056613C22977630A4B3F5B817FB5EA69081CE2A3CA6E5F93DF769264253D5411419AF73467A27F0BB61291CCDE67D931BD0689CB66
    Malicious:false
    Reputation:low
    Preview:PK.........e.>.......]>......diagrams/layout1.xmlz........Z..6....;..{......lw.E.o....i..T....&...G.+...$..(.6..>Y.pf8C.|3.?..m....xA8v.`.hW..@..Zn..(kb..(.......`.+....Y`...\..qh.0.!&w..)|...<..]Q.. _....m..Z.{3..~..5..R..d..A.O....gU.M..0..#...;.>$...T......T..z.Z.\a.+...?#.~.....1.>?...*..DD.1...'..,..(...5B...M..]..>.C..<[....,L.p..Q.v.v^q.Y...5.~^c..5........3.j.......BgJ.nv.. ............tt......Q..p..K....(M.(]@..E..~z.~...8...49.t.Q..Q.n..+.....*J.#J.... .P...P.1...!.#&...?A..&.."..|..D.I...:.....~/.....b..].........nI7.IC.a..%...9.....4...r....b..q....@o........O...y...d@+~.<.\....f.a`:...Qy/^..P....[....@i.I.._.?.X.x.8....)..s....I.0...|.....t...;...q=k.=..N.%!.(.1....B.Ps/."...#.%..&...j<..2x.=<.......s.....h..?..]?Y?...C.}E.O........{..6.d....I...A.....JN..w+....2..m>9.T7...t.6.}.i..f.Ga..t.].->...8U......G.D`......p..f.. ...qT.YX.t.F..X.u=.3r...4....4Q.D..l.6.+PR...+..T..h: H.&.1~....n.....)........2J.. O.W+vd..f....0.....6..9QhV..
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:Zip archive data, at least v2.0 to extract, compression method=deflate
    Category:dropped
    Size (bytes):6448
    Entropy (8bit):7.897260397307811
    Encrypted:false
    SSDEEP:192:tgaoRbo1sMjb0NiJ85oPtqcS+yaXWoa8XBzdJYnLYFtWT7:LR1sk+i4o1qc1yaukzd8MK
    MD5:42A840DC06727E42D42C352703EC72AA
    SHA1:21AAAF517AFB76BF1AF4E06134786B1716241D29
    SHA-256:02CCE7D526F844F70093AC41731D1A1E9B040905DCBA63BA8BFFC0DBD4D3A7A7
    SHA-512:8886BFD240D070237317352DEB3D46C6B07E392EBD57730B1DED016BD8740E75B9965F7A3FCD43796864F32AAE0BE911AB1A670E9CCC70E0774F64B1BDA93488
    Malicious:false
    Reputation:low
    Preview:PK.........k.>........'......diagrams/layout1.xmlz........].r.8.}.V.?p.n....g*5..JUn.....(SU......T.l.......X.d."m."..S....F..P.........-..<Y^..=..e.L....m>.pG.....M~...+\....u}o...".Yn}Y.".-r......0...'/........{........F.~.M8.d....(.....q.D.....4\.;.D,.\.)n.S....Z.cl.|<..7._.dk..7..E.......kS...d.....i.....noX...o.W#9..}.^..I0....G.......+.K.[i.O.|G..8=.;.8.8.8.8.....{..-..^.y..[.....`...0..f...Q<^~..*.l....{...pA.z.$.$R.../...E.(..Q.(V.E_ ......X]Q..Y9.......>...8......l..--.ug.......I.;..].u.b.3Lv:.d.%H..l<...V...$.M..A>...^M./.[..I....o~,.U. .$d\..?........O.;..^M..O...A.$Yx..|f.n...H.=.|!cG)dd%..(... ..Xe......2B."i...n....P.R..E?... Y.I6...7n..Xs..J..K..'..JaU..d..|.(y.a.....d......D.Dr...._.._..m..Yu..6.o.\......&.m....wy...4k?..~........f....0.. \...}iS.i..R....q-#_..g........{Z.u.V.r(....j.I...,R..f.=.n.[.'..L'd.n C.0.I.....RpaV........c.k..NR....)B^k...d.i...d0.E. ^..G.']....x.c.>'..p...y.ny.P.x6..%.J\.....De.B\.
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:Zip archive data, at least v2.0 to extract, compression method=deflate
    Category:dropped
    Size (bytes):5630
    Entropy (8bit):7.87271654296772
    Encrypted:false
    SSDEEP:96:n5ni6jKZWsD+QJaUQ7R6qYFF5QS+BEgeJam6S7ZCHuKViGa2CnnLYLt/ht:nccqxIBdQ1QS+uDJanS7ZCHHVdJCnLY5
    MD5:2F8998AA9CF348F1D6DE16EAB2D92070
    SHA1:85B13499937B4A584BEA0BFE60475FD4C73391B6
    SHA-256:8A216D16DEC44E02B9AB9BBADF8A11F97210D8B73277B22562A502550658E580
    SHA-512:F10F7772985EDDA442B9558127F1959FF0A9909C7B7470E62D74948428BFFF7E278739209E8626AE5917FF728AFB8619AE137BEE2A6A4F40662122208A41ABB2
    Malicious:false
    Reputation:low
    Preview:PK...........<..W8...j.......diagrams/layout1.xmlz........]......Hy..{...n .l.:.D.vvW..s....-a..fg&.}.\..+......4M..'=...(._.U]U......_.....U...k}.y.,......C..._^.......w/."7....v..Ea........Q..u..D{..{v.x.]....AtB15u..o...w..o.1...f.L...I<[zk7..7^..,.h.&l3...#..)..'H..d.r.#w=b...Ocw.y.&.v..t.>.s..m^M7..8I?o7................H...b....Qv.;'..%.f..#vR....V.H.),g..`...)(..m...[l...b...,.....U...Q.{.y.y.....G.I.tT.n..N.....A.tR..tr....i.<.......,.n:.#.A..a!X.......DK..;v..._M..lSc../n...v.....}.....I.|8.!b.C..v..|.....4l..n.;<9.i./..}!&2.c/.r...>.X02[..|.a.-.....$#-....>...{.M].>3.,\o.x....X%;.F.k.)*".I8<.0..#......?.h..-..O.2.B.s..v....{Abd...h0....H..I.. ...%...$1.Fyd..Y....U...S.Y.#.V.....TH(....%..nk.3Y.e.m.-.S..Q...j.Ai..E..v......4.t.|..&"...{..4.!.h.....C.P.....W...d[.....U<Yb;B.+W.!.@B....!.=......b"...Y.N;.#..Q...0G.lW...]7:...#9!z......|f..r..x.....t........`.uL1u.:.....U.D.n.<Q.[%...ngC./..|...!..q;;.w.".D..lt.".l.4".mt...E..mt
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:Zip archive data, at least v2.0 to extract, compression method=deflate
    Category:dropped
    Size (bytes):6193
    Entropy (8bit):7.855499268199703
    Encrypted:false
    SSDEEP:192:WavHMKgnU2HUGFhUnkbOKoztj1QfcnLYut3d8:YKeUlGXUnC+HQSMp
    MD5:031C246FFE0E2B623BBBD231E414E0D2
    SHA1:A57CA6134779D54691A4EFD344BC6948E253E0BA
    SHA-256:2D76C8D1D59EDB40D1FBBC6406A06577400582D1659A544269500479B6753CF7
    SHA-512:6A784C28E12C3740300883A0E690F560072A3EA8199977CBD7F260A21E8346B82BA8A4F78394D3BB53FA2E98564B764C2D0232C40B25FB6085C36D20D70A39D1
    Malicious:false
    Reputation:low
    Preview:PK........X..<..Zn|...........diagrams/layout1.xmlz........]..H.}......M,l#g.j:.G-eu.*S=.$......T_6..I...6...d.NJ....r.p.p.........|.z.K.M..L.T.(........<..ks.......o...t}...P..*.7...`.+.[...H..._..X.u.....N....n....n|..=.....K.:.G7.u....."g.n.h...O.,...c...f.b.P......>[l.....j.*.?..mxk..n..|A...,\o..j..wQ.....lw.~].Lh..{3Y..D..5.Y..n..Mh.r..J....6*.<.kO...Alv.._.qdKQ.5...-FMN......;.~..._..pv..&...%"Nz].n............vM.`..k..a.:.f]...a........y.....g0..`........|V...Yq.....#...8....n..i7w<2Rp...R.@.]..%.b%..~...a..<.j...&....?...Qp..Ow|&4>...d.O.|.|...Fk;t.P[A..i.6K.~...Y.N..9......~<Q..f...i.....6..U...l. ..E..4$Lw..p..Y%NR..;...B|B.U...\e......S...=...B{A.]..*....5Q.....FI..w....q.s{.K....(.]...HJ9........(.....[U|.....d71.Vv.....a.8...L.....k;1%.T.@+..uv.~v.]`.V....Z.....`.M.@..Z|.r........./C..Z.n0.....@.YQ.8..q.h.....c.%...p..<..zl.c..FS.D..fY..z..=O..%L..MU..c.:.~.....F]c......5.=.8.r...0....Y.\o.o....U.~n...`...Wk..2b......I~
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:Microsoft OOXML
    Category:dropped
    Size (bytes):3075
    Entropy (8bit):7.716021191059687
    Encrypted:false
    SSDEEP:48:96yn4sOBoygpySCCxwKsZCB2oLEIK+aQpUNLRQWtmMamIZxAwCC2QnyODhVOzP4:l0vCxJsZQ2ofpKvtmMdIZxAwJyODhVOE
    MD5:67766FF48AF205B771B53AA2FA82B4F4
    SHA1:0964F8B9DC737E954E16984A585BDC37CE143D84
    SHA-256:160D05B4CB42E1200B859A2DE00770A5C9EBC736B70034AFC832A475372A1667
    SHA-512:AC28B0B4A9178E9B424E5893870913D80F4EE03D595F587AA1D3ACC68194153BAFC29436ADFD6EA8992F0B00D17A43CFB42C529829090AF32C3BE591BD41776D
    Malicious:false
    Reputation:low
    Preview:PK.........nB;.h......F.......[Content_Types].xmlz.........MN.0...by.b.,.BI...X `...{..O.S...H\.'.XTP..K{.o.....rg..bL...XM.:.v..c.k...}.D....9.....Bb>.+..G.......+(.u}.w.]...v..{.M&.].>`....nB..B0Z@.e.u..R.......-.&#....aR..`.a..|. 1^......&..|..s.A.t..b..A.i7...7.&....bQK$O.......9....V....Wt_PK.........nB;O.......k......._rels/.rels...J.@.._e..4...i/.,x..Lw'....v'.<....WpQ..,......7?....u.y..;bL../..3t.+.t.G....Y.v8.eG.MH,....(\..d..R....t>Z.<F-..G.(..\.x...l?..M..:#........2.#.[..H7..#g{...._j...(.....q......;.5'..Nt..."...A.h........>....\.'...L..D..DU<.....C.TKu.5Tu....bV..;PK.........C26.b..............diagrams/layout1.xml.T.n. .}N....).je./m.+u....`{..0P......p..U}c.9g..3....=h.(.."..D-.&....~.....y..I...(r.aJ.Y..e..;.YH...P.{b......hz.-..>k.i5..z>.l...f...c..Y...7.ND...=.%..1...Y.-.o.=)(1g.{.".E.>2.=...]Y..r0.Q...e.E.QKal,.....{f...r..9-.mH..C..\.w....c.4.JUbx.p Q...R......_...G.F...uPR...|um.+g..?..C..gT...7.0.8l$.*.=qx.......-8..8.
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:Microsoft OOXML
    Category:dropped
    Size (bytes):5151
    Entropy (8bit):7.859615916913808
    Encrypted:false
    SSDEEP:96:WkV3UHhcZDEteEJqeSGzpG43GUR8m8b6dDLiCTfjKPnD6H5RhfuDKNtxx3+7tDLp:Wq3UBc9EJqIpGgD5dDL1DjKvDKhfnNti
    MD5:6C24ED9C7C868DB0D55492BB126EAFF8
    SHA1:C6D96D4D298573B70CF5C714151CF87532535888
    SHA-256:48AF17267AD75C142EFA7AB7525CA48FAB579592339FB93E92C4C4DA577D4C9F
    SHA-512:A3E9DC48C04DC8571289F57AE790CA4E6934FBEA4FDDC20CB780F7EA469FE1FC1D480A1DBB04D15301EF061DA5700FF0A793EB67D2811C525FEF618B997BCABD
    Malicious:false
    Reputation:low
    Preview:PK.........nB;.h......F.......[Content_Types].xmlz.........MN.0...by.b.,.BI...X `...{..O.S...H\.'.XTP..K{.o.....rg..bL...XM.:.v..c.k...}.D....9.....Bb>.+..G.......+(.u}.w.]...v..{.M&.].>`....nB..B0Z@.e.u..R.......-.&#....aR..`.a..|. 1^......&..|..s.A.t..b..A.i7...7.&....bQK$O.......9....V....Wt_PK........5nB;.ndX....`......._rels/.rels...J.1.._%..f.J.J..x..AJ.2M&......g..#............|.c..x{_._..^0e.|.gU..z.....#.._..[..JG.m.....(...e..r."....P)....3..M].E:..SO.;D..c..J..rt...c.,.....a.;.....$.../5..D.Ue.g...Q3......5.':...@...~t{.v..QA>.P.R.A~..^AR.S4G......].n...x41....PK.........^5..s.V....Z......diagrams/layout1.xml.[]o.F.}N~..S.......VU.U+m6R........&.d.}...{M....Q.S....p9.'./O..z."..t>q....."[..j>y..?...u....[.}..j-...?Y..Bdy.I./.....0.._.....-.s...rj...I..=..<..9.|>YK.....o.|.my.F.LlB..be/E.Y!.$6r.f/.p%.......U....e..W.R..fK....`+?.rwX.[.b..|..O>o.|.....>1.......trN`7g..Oi.@5..^...]4.r...-y...T.h...[.j1..v....G..........nS..m..E"L...s
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
    Category:dropped
    Size (bytes):333258
    Entropy (8bit):4.654450340871081
    Encrypted:false
    SSDEEP:6144:ybW83Zb181+MKHZR5D7H3hgtfL/8mIDbEhPv9FHSVsioWUyGYmwxAw+GIfnUNv5J:i
    MD5:5632C4A81D2193986ACD29EADF1A2177
    SHA1:E8FF4FDFEB0002786FCE1CF8F3D25F8E9631E346
    SHA-256:06DE709513D7976690B3DD8F5FDF1E59CF456A2DFBA952B97EACC72FE47B238B
    SHA-512:676CE1957A374E0F36634AA9CFFBCFB1E1BEFE1B31EE876483B10763EA9B2D703F2F3782B642A5D7D0945C5149B572751EBD9ABB47982864834EF61E3427C796
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="utf-8"?>....<xsl:stylesheet version="1.0" xmlns:xsl="http://www.w3.org/1999/XSL/Transform" xmlns:msxsl="urn:schemas-microsoft-com:xslt".xmlns:b="http://schemas.openxmlformats.org/officeDocument/2006/bibliography" xmlns:t="http://www.microsoft.com/temp">.. <xsl:output method="html" encoding="us-ascii"/>.... <xsl:template match="*" mode="outputHtml2">.. <xsl:apply-templates mode="outputHtml"/>.. </xsl:template>.... <xsl:template name="StringFormatDot">.. <xsl:param name="format" />.. <xsl:param name="parameters" />.... <xsl:variable name="prop_EndChars">.. <xsl:call-template name="templ_prop_EndChars"/>.. </xsl:variable>.... <xsl:choose>.. <xsl:when test="$format = ''"></xsl:when>.. <xsl:when test="substring($format, 1, 2) = '%%'">.. <xsl:text>%</xsl:text>.. <xsl:call-template name="StringFormatDot">.. <xsl:with-param name="format" select="substring($format, 3)" />.. <xsl:with-param name=
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
    Category:dropped
    Size (bytes):296658
    Entropy (8bit):5.000002997029767
    Encrypted:false
    SSDEEP:6144:RwprAMk0qvtfL/vF/bkWPz9yv7EOMBPitjASjTQQr7IwR0TnyDkJb78plJwf33iV:M
    MD5:9AC6DE7B629A4A802A41F93DB2C49747
    SHA1:3D6E929AA1330C869D83F2BF8EBEBACD197FB367
    SHA-256:52984BC716569120D57C8E6A360376E9934F00CF31447F5892514DDCCF546293
    SHA-512:5736F14569E0341AFB5576C94B0A7F87E42499CEC5927AAC83BB5A1F77B279C00AEA86B5F341E4215076D800F085D831F34E4425AD9CFD52C7AE4282864B1E73
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="utf-8"?>....<xsl:stylesheet version="1.0" xmlns:xsl="http://www.w3.org/1999/XSL/Transform" xmlns:msxsl="urn:schemas-microsoft-com:xslt" xmlns:b="http://schemas.openxmlformats.org/officeDocument/2006/bibliography" xmlns:t="http://www.microsoft.com/temp">...<xsl:output method="html" encoding="us-ascii"/>............<xsl:template match="*" mode="outputHtml2">.....<xsl:apply-templates mode="outputHtml"/>.....</xsl:template>.....<xsl:template name="StringFormatDot">....<xsl:param name="format" />....<xsl:param name="parameters" />.... <xsl:variable name="prop_EndChars">.. <xsl:call-template name="templ_prop_EndChars"/>.. </xsl:variable>.... <xsl:choose>.....<xsl:when test="$format = ''"></xsl:when>.....<xsl:when test="substring($format, 1, 2) = '%%'">......<xsl:text>%</xsl:text>......<xsl:call-template name="StringFormatDot">.......<xsl:with-param name="format" select="substring($format, 3)" />.......<xsl:with-param name="parameters" select="$para
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
    Category:dropped
    Size (bytes):268317
    Entropy (8bit):5.05419861997223
    Encrypted:false
    SSDEEP:6144:JwprAJLR95vtfb8p4bgWPzDCvCmvQursq7vImej/yQzSS1apSiQhHDOruvoVeMUh:N9
    MD5:51D32EE5BC7AB811041F799652D26E04
    SHA1:412193006AA3EF19E0A57E16ACF86B830993024A
    SHA-256:6230814BF5B2D554397580613E20681752240AB87FD354ECECF188C1EABE0E97
    SHA-512:5FC5D889B0C8E5EF464B76F0C4C9E61BDA59B2D1205AC9417CC74D6E9F989FB73D78B4EB3044A1A1E1F2C00CE1CA1BD6D4D07EEADC4108C7B124867711C31810
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="utf-8"?>..<xsl:stylesheet version="1.0" xmlns:xsl="http://www.w3.org/1999/XSL/Transform" xmlns:msxsl="urn:schemas-microsoft-com:xslt".xmlns:b="http://schemas.openxmlformats.org/officeDocument/2006/bibliography" xmlns:t="http://www.microsoft.com/temp">...<xsl:output method="html" encoding="us-ascii"/>..............<xsl:template match="*" mode="outputHtml2">.....<xsl:apply-templates mode="outputHtml"/>.....</xsl:template>.....<xsl:template name="StringFormatDot">....<xsl:param name="format" />....<xsl:param name="parameters" />.... <xsl:variable name="prop_EndChars">.. <xsl:call-template name="templ_prop_EndChars"/>.. </xsl:variable>.... <xsl:choose>.....<xsl:when test="$format = ''"></xsl:when>.....<xsl:when test="substring($format, 1, 2) = '%%'">......<xsl:text>%</xsl:text>......<xsl:call-template name="StringFormatDot">.......<xsl:with-param name="format" select="substring($format, 3)" />.......<xsl:with-param name="parameters" select="$para
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
    Category:dropped
    Size (bytes):255948
    Entropy (8bit):5.103631650117028
    Encrypted:false
    SSDEEP:6144:gwprAm795vtfb8p4bgWPWEtTmtcRCDPThNPFQwB+26RxlsIBkAgRMBHcTCwsHe5a:kW
    MD5:9888A214D362470A6189DEFF775BE139
    SHA1:32B552EB3C73CD7D0D9D924C96B27A86753E0F97
    SHA-256:C64ED5C2A323C00E84272AD3A701CAEBE1DCCEB67231978DE978042F09635FA7
    SHA-512:8A75FC2713003FA40B9730D29C786C76A796F30E6ACE12064468DD2BB4BF97EF26AC43FFE1158AB1DB06FF715D2E6CDE8EF3E8B7C49AA1341603CE122F311073
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="utf-8"?>............<xsl:stylesheet version="1.0" xmlns:xsl="http://www.w3.org/1999/XSL/Transform" xmlns:msxsl="urn:schemas-microsoft-com:xslt".xmlns:b="http://schemas.openxmlformats.org/officeDocument/2006/bibliography" xmlns:t="http://www.microsoft.com/temp">...<xsl:output method="html" encoding="us-ascii"/>..........<xsl:template match="*" mode="outputHtml2">.....<xsl:apply-templates mode="outputHtml"/>.....</xsl:template>.....<xsl:template name="StringFormatDot">....<xsl:param name="format" />....<xsl:param name="parameters" />.... <xsl:variable name="prop_EndChars">.. <xsl:call-template name="templ_prop_EndChars"/>.. </xsl:variable>.... <xsl:choose>.....<xsl:when test="$format = ''"></xsl:when>.....<xsl:when test="substring($format, 1, 2) = '%%'">......<xsl:text>%</xsl:text>......<xsl:call-template name="StringFormatDot">.......<xsl:with-param name="format" select="substring($format, 3)" />.......<xsl:with-param name="parameters" select=
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
    Category:dropped
    Size (bytes):251032
    Entropy (8bit):5.102652100491927
    Encrypted:false
    SSDEEP:6144:hwprA5R95vtfb8p4bgWPwW6/m26AnV9IBgIkqm6HITUZJcjUZS1XkaNPQTlvB2zr:JA
    MD5:F425D8C274A8571B625EE66A8CE60287
    SHA1:29899E309C56F2517C7D9385ECDBB719B9E2A12B
    SHA-256:DD7B7878427276AF5DBF8355ECE0D1FE5D693DF55AF3F79347F9D20AE50DB938
    SHA-512:E567F283D903FA533977B30FD753AA1043B9DDE48A251A9AC6777A3B67667443FEAD0003765A630D0F840B6C275818D2F903B6CB56136BEDCC6D9BDD20776564
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="utf-8"?>......<xsl:stylesheet version="1.0" xmlns:xsl="http://www.w3.org/1999/XSL/Transform" xmlns:msxsl="urn:schemas-microsoft-com:xslt".xmlns:b="http://schemas.openxmlformats.org/officeDocument/2006/bibliography" xmlns:t="http://www.microsoft.com/temp">...<xsl:output method="html" encoding="us-ascii"/>..........<xsl:template match="*" mode="outputHtml2">.....<xsl:apply-templates mode="outputHtml"/>.....</xsl:template>.....<xsl:template name="StringFormatDot">....<xsl:param name="format" />....<xsl:param name="parameters" />.... <xsl:variable name="prop_EndChars">.. <xsl:call-template name="templ_prop_EndChars"/>.. </xsl:variable>.... <xsl:choose>.....<xsl:when test="$format = ''"></xsl:when>.....<xsl:when test="substring($format, 1, 2) = '%%'">......<xsl:text>%</xsl:text>......<xsl:call-template name="StringFormatDot">.......<xsl:with-param name="format" select="substring($format, 3)" />.......<xsl:with-param name="parameters" select="$para
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:XML 1.0 document, Unicode text, UTF-8 text, with CRLF line terminators
    Category:dropped
    Size (bytes):284415
    Entropy (8bit):5.00549404077789
    Encrypted:false
    SSDEEP:6144:N9G5o7Fv0ZcxrStAtXWty8zRLYBQd8itHiYYPVJHMSo27hlwNR57johqBXlwNR2b:y
    MD5:33A829B4893044E1851725F4DAF20271
    SHA1:DAC368749004C255FB0777E79F6E4426E12E5EC8
    SHA-256:C40451CADF8944A9625DD690624EA1BA19CECB825A67081E8144AD5526116924
    SHA-512:41C1F65E818C2757E1A37F5255E98F6EDEAC4214F9D189AD09C6F7A51F036768C1A03D6CFD5845A42C455EE189D13BB795673ACE3B50F3E1D77DAFF400F4D708
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="utf-8"?>....<xsl:stylesheet version="1.0" xmlns:xsl="http://www.w3.org/1999/XSL/Transform" xmlns:msxsl="urn:schemas-microsoft-com:xslt"......xmlns:b="http://schemas.openxmlformats.org/officeDocument/2006/bibliography" xmlns:t="http://www.microsoft.com/temp">.....<xsl:output method="html" encoding="us-ascii"/>.....<xsl:template match="/">....<xsl:call-template name="Start"/>...</xsl:template>.....<xsl:template name="Start">....<xsl:choose>.....<xsl:when test="b:Version">......<xsl:text>2010.2.02</xsl:text>.....</xsl:when>.......<xsl:when test="b:XslVersion">......<xsl:text>2008</xsl:text>.....</xsl:when>.... <xsl:when test="b:StyleNameLocalized">.. <xsl:choose>.. <xsl:when test="b:StyleNameLocalized/b:Lcid='1033'">.. <xsl:text>Harvard - Anglia</xsl:text>.. </xsl:when>.. <xsl:when test="b:StyleNameLocalized/b:Lcid='1025'">.. <xsl:text>Harvard - Anglia</xsl:text>.. </xsl:when>.. <x
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:XML 1.0 document, Unicode text, UTF-8 text, with CRLF line terminators
    Category:dropped
    Size (bytes):294178
    Entropy (8bit):4.977758311135714
    Encrypted:false
    SSDEEP:6144:ydkJ3yU0orh0SCLVXyMFsoiOjWIm4vW2uo4hfhf7v3uH4NYYP4BpBaZTTSSamEUD:b
    MD5:0C9731C90DD24ED5CA6AE283741078D0
    SHA1:BDD3D7E5B0DE9240805EA53EF2EB784A4A121064
    SHA-256:ABCE25D1EB3E70742EC278F35E4157EDB1D457A7F9D002AC658AAA6EA4E4DCDF
    SHA-512:A39E6201D6B34F37C686D9BD144DDD38AE212EDA26E3B81B06F1776891A90D84B65F2ABC5B8F546A7EFF3A62D35E432AF0254E2F5BFE4AA3E0CF9530D25949C0
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="utf-8"?>....<xsl:stylesheet version="1.0" xmlns:xsl="http://www.w3.org/1999/XSL/Transform" xmlns:msxsl="urn:schemas-microsoft-com:xslt"......xmlns:b="http://schemas.openxmlformats.org/officeDocument/2006/bibliography" xmlns:t="http://www.microsoft.com/temp">.....<xsl:output method="html" encoding="us-ascii"/>.....<xsl:template match="/">....<xsl:call-template name="Start"/>...</xsl:template>.....<xsl:template name="Start">....<xsl:choose>.....<xsl:when test="b:Version">......<xsl:text>2010.2.02</xsl:text>.....</xsl:when>.......<xsl:when test="b:XslVersion">......<xsl:text>2006</xsl:text>.....</xsl:when>.. <xsl:when test="b:StyleNameLocalized">.. <xsl:choose>.. <xsl:when test="b:StyleNameLocalized/b:Lcid='1033'">.. <xsl:text>IEEE</xsl:text>.. </xsl:when>.. <xsl:when test="b:StyleNameLocalized/b:Lcid='1025'">.. <xsl:text>IEEE</xsl:text>.. </xsl:when>.. <xsl:when test="b:StyleNameL
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
    Category:dropped
    Size (bytes):270198
    Entropy (8bit):5.073814698282113
    Encrypted:false
    SSDEEP:6144:JwprAiaR95vtfb8pDbgWPzDCvCmvQursq7vImej/yQ4SS1apSiQhHDOruvoVeMUX:We
    MD5:FF0E07EFF1333CDF9FC2523D323DD654
    SHA1:77A1AE0DD8DBC3FEE65DD6266F31E2A564D088A4
    SHA-256:3F925E0CC1542F09DE1F99060899EAFB0042BB9682507C907173C392115A44B5
    SHA-512:B4615F995FAB87661C2DBE46625AA982215D7BDE27CAFAE221DCA76087FE76DA4B4A381943436FCAC1577CB3D260D0050B32B7B93E3EB07912494429F126BB3D
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="utf-8"?>..<xsl:stylesheet version="1.0" xmlns:xsl="http://www.w3.org/1999/XSL/Transform" xmlns:msxsl="urn:schemas-microsoft-com:xslt".xmlns:b="http://schemas.openxmlformats.org/officeDocument/2006/bibliography" xmlns:t="http://www.microsoft.com/temp">...<xsl:output method="html" encoding="us-ascii"/>..............<xsl:template match="*" mode="outputHtml2">.....<xsl:apply-templates mode="outputHtml"/>.....</xsl:template>.....<xsl:template name="StringFormatDot">....<xsl:param name="format" />....<xsl:param name="parameters" />.... <xsl:variable name="prop_EndChars">.. <xsl:call-template name="templ_prop_EndChars"/>.. </xsl:variable>.... <xsl:choose>.....<xsl:when test="$format = ''"></xsl:when>.....<xsl:when test="substring($format, 1, 2) = '%%'">......<xsl:text>%</xsl:text>......<xsl:call-template name="StringFormatDot">.......<xsl:with-param name="format" select="substring($format, 3)" />.......<xsl:with-param name="parameters" select="$para
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
    Category:dropped
    Size (bytes):217137
    Entropy (8bit):5.068335381017074
    Encrypted:false
    SSDEEP:6144:AwprA3Z95vtf58pb1WP2DCvCmvQursq7vIme5QyQzSS1apSiQhHDlruvoVeMUwFj:4P
    MD5:3BF8591E1D808BCCAD8EE2B822CC156B
    SHA1:9CC1E5EFD715BD0EAE5AF983FB349BAC7A6D7BA0
    SHA-256:7194396E5C833E6C8710A2E5D114E8E24338C64EC9818D51A929D57A5E4A76C8
    SHA-512:D434A4C15DA3711A5DAAF5F7D0A5E324B4D94A04B3787CA35456BFE423EAC9D11532BB742CDE6E23C16FA9FD203D3636BD198B41C7A51E7D3562D5306D74F757
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="utf-8"?>..<xsl:stylesheet version="1.0" xmlns:xsl="http://www.w3.org/1999/XSL/Transform" xmlns:msxsl="urn:schemas-microsoft-com:xslt".xmlns:b="http://schemas.openxmlformats.org/officeDocument/2006/bibliography" xmlns:t="http://www.microsoft.com/temp">...<xsl:output method="html" encoding="us-ascii"/>..........<xsl:template match="*" mode="outputHtml2">.....<xsl:apply-templates mode="outputHtml"/>.....</xsl:template>.....<xsl:template name="StringFormatDot">....<xsl:param name="format" />....<xsl:param name="parameters" />.... <xsl:variable name="prop_EndChars">.. <xsl:call-template name="templ_prop_EndChars"/>.. </xsl:variable>...... <xsl:choose>.....<xsl:when test="$format = ''"></xsl:when>.....<xsl:when test="substring($format, 1, 2) = '%%'">......<xsl:text>%</xsl:text>......<xsl:call-template name="StringFormatDot">.......<xsl:with-param name="format" select="substring($format, 3)" />.......<xsl:with-param name="parameters" select="$parame
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
    Category:dropped
    Size (bytes):254875
    Entropy (8bit):5.003842588822783
    Encrypted:false
    SSDEEP:6144:MwprAnniNgtfbzbOWPuv7kOMBLitjAUjTQLrYHwR0TnyDkHqV3iPr1zHX5T6SSXj:a
    MD5:377B3E355414466F3E3861BCE1844976
    SHA1:0B639A3880ACA3FD90FA918197A669CC005E2BA4
    SHA-256:4AC5B26C5E66E122DE80243EF621CA3E1142F643DD2AD61B75FF41CFEE3DFFAF
    SHA-512:B050AD52A8161F96CBDC880DD1356186F381B57159F5010489B04528DB798DB955F0C530465AB3ECD5C653586508429D98336D6EB150436F1A53ABEE0697AEB9
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="utf-8"?>......<xsl:stylesheet version="1.0" xmlns:xsl="http://www.w3.org/1999/XSL/Transform" xmlns:msxsl="urn:schemas-microsoft-com:xslt" xmlns:b="http://schemas.openxmlformats.org/officeDocument/2006/bibliography" xmlns:t="http://www.microsoft.com/temp">...<xsl:output method="html" encoding="us-ascii"/>.....<xsl:template match="*" mode="outputHtml2">.....<xsl:apply-templates mode="outputHtml"/>...</xsl:template>.....<xsl:template name="StringFormatDot">....<xsl:param name="format" />....<xsl:param name="parameters" />......<xsl:variable name="prop_EndChars">.....<xsl:call-template name="templ_prop_EndChars"/>....</xsl:variable>......<xsl:choose>.....<xsl:when test="$format = ''"></xsl:when>.....<xsl:when test="substring($format, 1, 2) = '%%'">......<xsl:text>%</xsl:text>......<xsl:call-template name="StringFormatDot">.......<xsl:with-param name="format" select="substring($format, 3)" />.......<xsl:with-param name="parameters" select="$parameters" />......
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
    Category:dropped
    Size (bytes):344303
    Entropy (8bit):5.023195898304535
    Encrypted:false
    SSDEEP:6144:UwprANnsqvtfL/vF/bkWPRMMv7EOMBPitjASjTQQr7IwR0TnyDk1b78plJwf33iD:6
    MD5:F079EC5E2CCB9CD4529673BCDFB90486
    SHA1:FBA6696E6FA918F52997193168867DD3AEBE1AD6
    SHA-256:3B651258F4D0EE1BFFC7FB189250DED1B920475D1682370D6685769E3A9346DB
    SHA-512:4FFFA59863F94B3778F321DA16C43B92A3053E024BDD8C5317077EA1ECC7B09F67ECE3C377DB693F3432BF1E2D947EC5BF8E88E19157ED08632537D8437C87D6
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="utf-8"?>......<xsl:stylesheet version="1.0" xmlns:xsl="http://www.w3.org/1999/XSL/Transform" xmlns:msxsl="urn:schemas-microsoft-com:xslt" xmlns:b="http://schemas.openxmlformats.org/officeDocument/2006/bibliography" xmlns:t="http://www.microsoft.com/temp">...<xsl:output method="html" encoding="us-ascii"/>............<xsl:template match="*" mode="outputHtml2">.....<xsl:apply-templates mode="outputHtml"/>.....</xsl:template>.....<xsl:template name="StringFormatDot">....<xsl:param name="format" />....<xsl:param name="parameters" />.... <xsl:variable name="prop_EndChars">.. <xsl:call-template name="templ_prop_EndChars"/>.. </xsl:variable>.... <xsl:choose>.....<xsl:when test="$format = ''"></xsl:when>.....<xsl:when test="substring($format, 1, 2) = '%%'">......<xsl:text>%</xsl:text>......<xsl:call-template name="StringFormatDot">.......<xsl:with-param name="format" select="substring($format, 3)" />.......<xsl:with-param name="parameters" select="$pa
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
    Category:dropped
    Size (bytes):250983
    Entropy (8bit):5.057714239438731
    Encrypted:false
    SSDEEP:6144:JwprA6OS95vtfb8p4bgWPzkhUh9I5/oBRSifJeg/yQzvapSiQhHZeruvoXMUw3im:uP
    MD5:F883B260A8D67082EA895C14BF56DD56
    SHA1:7954565C1F243D46AD3B1E2F1BAF3281451FC14B
    SHA-256:EF4835DB41A485B56C2EF0FF7094BC2350460573A686182BC45FD6613480E353
    SHA-512:D95924A499F32D9B4D9A7D298502181F9E9048C21DBE0496FA3C3279B263D6F7D594B859111A99B1A53BD248EE69B867D7B1768C42E1E40934E0B990F0CE051E
    Malicious:false
    Reputation:low
    Preview:<?xml version="1.0" encoding="utf-8"?>..<xsl:stylesheet version="1.0" xmlns:xsl="http://www.w3.org/1999/XSL/Transform" xmlns:msxsl="urn:schemas-microsoft-com:xslt".xmlns:b="http://schemas.openxmlformats.org/officeDocument/2006/bibliography" xmlns:t="http://www.microsoft.com/temp">...<xsl:output method="html" encoding="us-ascii"/>..............<xsl:template match="*" mode="outputHtml2">.....<xsl:apply-templates mode="outputHtml"/>.....</xsl:template>.....<xsl:template name="StringFormatDot">....<xsl:param name="format" />....<xsl:param name="parameters" />.... <xsl:variable name="prop_EndChars">.. <xsl:call-template name="templ_prop_EndChars"/>.. </xsl:variable>.... <xsl:choose>.....<xsl:when test="$format = ''"></xsl:when>.....<xsl:when test="substring($format, 1, 2) = '%%'">......<xsl:text>%</xsl:text>......<xsl:call-template name="StringFormatDot">.......<xsl:with-param name="format" select="substring($format, 3)" />.......<xsl:with-param name="parameters" select="$para
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:Microsoft Word 2007+
    Category:dropped
    Size (bytes):51826
    Entropy (8bit):5.541375256745271
    Encrypted:false
    SSDEEP:384:erH5dYPCA4t3aEFGiSUDtYfEbi5Ry/AT7/6tHODaFlDSomurYNfT4A0VIwWNS89u:Q6Cbh9tENyWdaFUSYNfZS89/3qtEu
    MD5:2AB22AC99ACFA8A82742E774323C0DBD
    SHA1:790F8B56DF79641E83A16E443A75A66E6AA2F244
    SHA-256:BC9D45D0419A08840093B0BF4DCF96264C02DFE5BD295CD9B53722E1DA02929D
    SHA-512:E5715C0ECF35CE250968BD6DE5744D28A9F57D20FD6866E2AF0B2D8C8F80FEDC741D48F554397D61C5E702DA896BD33EED92D778DBAC71E2E98DCFB0912DE07B
    Malicious:false
    Reputation:low
    Preview:PK.........R.@c}LN4...........[Content_Types].xml ...(.....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................`.I.%&/m.{.J.J..t...`.$.@........iG#).*..eVe]f.@....{...{...;.N'...?\fd.l..J..!....?~|.?"....|.{.[..e^7E......Gi..V.by..G..|.......U..t.|..mW...m..|.5.j./..^d-.Y_.]e..E~wog...j...v......?..u....c.....D....>.V...f-}..r9....=..Mn..U..5.(.....a...E..b....*..w.$...,O_fu."[P..WU=.;.....5..wdt..y1.......i.44-.r....;./.biG.Cd.n.j.{/......V....c..^^.E.H?H.........B.........<...Ae.l.]..{....mK......B....
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:Microsoft Word 2007+
    Category:dropped
    Size (bytes):47296
    Entropy (8bit):6.42327948041841
    Encrypted:false
    SSDEEP:768:ftjI1BT8N37szq00s7dB2wMVJGHR97/RDU5naXUsT:fJIPTfq0ndB2w1bpsE
    MD5:5A53F55DD7DA8F10A8C0E711F548B335
    SHA1:035E685927DA2FECB88DE9CAF0BECEC88BC118A7
    SHA-256:66501B659614227584DA04B64F44309544355E3582F59DBCA3C9463F67B7E303
    SHA-512:095BD5D1ACA2A0CA3430DE2F005E1D576AC9387E096D32D556E4348F02F4D658D0E22F2FC4AA5BF6C07437E6A6230D2ABF73BBD1A0344D73B864BC4813D60861
    Malicious:false
    Reputation:low
    Preview:PK........<dSA4...T...P.......[Content_Types].xml ...(........................................................................................................................................................................................................................................................................................................................................................................................................................................`.I.%&/m.{.J.J..t...`.$.@........iG#).*..eVe]f.@....{...{...;.N'...?\fd.l..J..!....?~|.?"....|.{.[..e^7E......Gi..V.by..G..|.......U..t.|..mW...m..|.5.j./..^d-.Y_.]e..E~wog...j...v......?..u....c...W..G.4D_.}T,.@...}....R.Z..4k.....Y..mEkLor.f^..O..P...`..^\-o..D....n_d.jq...gwg.t........:?/..}..Vu5...rQ..7..X.Q."./g..o....f....YB......<..w?...ss..e.4Y}}...0.Y...........u3V.o..r...5....7bA..Us.z.`.r(.Y>.&DVy.........6.T...e.|..g.%<...9a.&...7...}3:B.......<...!...:..7w...y..
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:Microsoft Word 2007+
    Category:dropped
    Size (bytes):34415
    Entropy (8bit):7.352974342178997
    Encrypted:false
    SSDEEP:768:ev13NPo9o5NGEVIi3kvH+3SMdk7zp3tE2:ev13xoOE+R3BkR7
    MD5:7CDFFC23FB85AD5737452762FA36AAA0
    SHA1:CFBC97247959B3142AFD7B6858AD37B18AFB3237
    SHA-256:68A8FBFBEE4C903E17C9421082E839144C205C559AFE61338CBDB3AF79F0D270
    SHA-512:A0685FD251208B772436E9745DA2AA52BC26E275537688E3AB44589372D876C9ACE14B21F16EC4053C50EB4C8E11787E9B9D922E37249D2795C5B7986497033E
    Malicious:false
    Reputation:low
    Preview:PK.........Y5B#.W ............[Content_Types].xml ...(...................................................................................................................................................................................................................................................................................................................................................................................................................................................`.I.%&/m.{.J.J..t...`.$.@........iG#).*..eVe]f.@....{...{...;.N'...?\fd.l..J..!....?~|.?"....|.{.[..e^7E......Gi..V.by..G..|.......U..t.|..mW...m..|.5.j./..^d-.Y_.]e..E~wog...j...v......?..u....c.....D....>.V...f-}..r9....=..Mn..U..5.(.....a...E..b....*..w.$...,O_fu."[P..WU=.;.....5..wdt..y1.......i.44-.r....;./.biG=.HK...........&o[B....z.7.o...&.......[.oL_7cuN..&e..ccAo...YW......8...Y>.&DVy...-&.*...Y.....4.u.., !po....9W....g..F...*+1....d,'...L.M[-~.Ey. ......[
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:data
    Category:dropped
    Size (bytes):12
    Entropy (8bit):0.41381685030363374
    Encrypted:false
    SSDEEP:3:/l:
    MD5:E4A1661C2C886EBB688DEC494532431C
    SHA1:A2AE2A7DB83B33DC95396607258F553114C9183C
    SHA-256:B76875C50EF704DBBF7F02C982445971D1BBD61AEBE2E4B28DDC58A1D66317D5
    SHA-512:EFDCB76FB40482BC94E37EAE3701E844BF22C7D74D53AEF93AC7B6AE1C1094BA2F853875D2C66A49A7075EA8C69F5A348B786D6EE0FA711669279D04ADAAC22C
    Malicious:false
    Reputation:low
    Preview:............
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:data
    Category:dropped
    Size (bytes):12
    Entropy (8bit):0.41381685030363374
    Encrypted:false
    SSDEEP:3:/l:
    MD5:E4A1661C2C886EBB688DEC494532431C
    SHA1:A2AE2A7DB83B33DC95396607258F553114C9183C
    SHA-256:B76875C50EF704DBBF7F02C982445971D1BBD61AEBE2E4B28DDC58A1D66317D5
    SHA-512:EFDCB76FB40482BC94E37EAE3701E844BF22C7D74D53AEF93AC7B6AE1C1094BA2F853875D2C66A49A7075EA8C69F5A348B786D6EE0FA711669279D04ADAAC22C
    Malicious:false
    Reputation:low
    Preview:............
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:data
    Category:dropped
    Size (bytes):12
    Entropy (8bit):0.41381685030363374
    Encrypted:false
    SSDEEP:3:/l:
    MD5:E4A1661C2C886EBB688DEC494532431C
    SHA1:A2AE2A7DB83B33DC95396607258F553114C9183C
    SHA-256:B76875C50EF704DBBF7F02C982445971D1BBD61AEBE2E4B28DDC58A1D66317D5
    SHA-512:EFDCB76FB40482BC94E37EAE3701E844BF22C7D74D53AEF93AC7B6AE1C1094BA2F853875D2C66A49A7075EA8C69F5A348B786D6EE0FA711669279D04ADAAC22C
    Malicious:false
    Reputation:low
    Preview:............
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    File Type:data
    Category:dropped
    Size (bytes):12
    Entropy (8bit):0.41381685030363374
    Encrypted:false
    SSDEEP:3:/l:
    MD5:E4A1661C2C886EBB688DEC494532431C
    SHA1:A2AE2A7DB83B33DC95396607258F553114C9183C
    SHA-256:B76875C50EF704DBBF7F02C982445971D1BBD61AEBE2E4B28DDC58A1D66317D5
    SHA-512:EFDCB76FB40482BC94E37EAE3701E844BF22C7D74D53AEF93AC7B6AE1C1094BA2F853875D2C66A49A7075EA8C69F5A348B786D6EE0FA711669279D04ADAAC22C
    Malicious:false
    Reputation:low
    Preview:............
    Process:C:\Windows\SysWOW64\cmd.exe
    File Type:ASCII text, with CRLF line terminators
    Category:modified
    Size (bytes):390470
    Entropy (8bit):2.2486709787543195
    Encrypted:false
    SSDEEP:1536:oT/nNrcKQVrJip0yznZh9g19Nm6Dq5ehz9mQuHR50B2pJdPTulGZFC5:oT/5ct4nZ8N9MZq
    MD5:E8EBC0A0D77E5FA7931412BE6373AE1D
    SHA1:BEFFD88629903285AD28CF2088F8977D1547F284
    SHA-256:97C834A1A84CA428CB3266CC26397DC7927ECE943D7489C9F2DCB76C5C8F9057
    SHA-512:10E5D11406F7D3FA426901DCC5204719F05E0B11A9195857B469A974C2E69E84A45005DFD86ACDC66EA69DEB3BFBA902D72003307DA4EEE97E36A43FFE76C19F
    Malicious:false
    Reputation:low
    Preview:--2024-06-18 11:09:09-- https://onset2.onsetcomp.com/files/software/hoboware/3.7.28/HOBOware_Free_Setup.exe..Resolving onset2.onsetcomp.com (onset2.onsetcomp.com)... 54.225.184.108..Connecting to onset2.onsetcomp.com (onset2.onsetcomp.com)|54.225.184.108|:443... connected...HTTP request sent, awaiting response... 200 OK..Length: 253469944 (242M) [application/x-msdos-program]..Saving to: 'C:/Users/user/Desktop/download/HOBOware_Free_Setup.exe'.... 0K .......... .......... .......... .......... .......... 0% 300K 13m44s.. 50K .......... .......... .......... .......... .......... 0% 2.66M 7m37s.. 100K .......... .......... .......... .......... .......... 0% 612K 7m20s.. 150K .......... .......... .......... .......... .......... 0% 3.34M 5m48s.. 200K .......... .......... .......... .......... .......... 0% 496K 6m18s.. 250K .......... .......... .......... .......... .......... 0% 3.17M 5m28s.. 300K .......... .......... .......... .......... .......... 0%
    Process:C:\Windows\SysWOW64\wget.exe
    File Type:PE32 executable (GUI) Intel 80386, for MS Windows
    Category:dropped
    Size (bytes):253469944
    Entropy (8bit):7.999994627699843
    Encrypted:true
    SSDEEP:6291456:WVcpXoVGqOJ0Rz+3AI1rz5S8CPxpkeoaeHb:WVcp4Zh+3AIJz88INmb
    MD5:09A67AE954237BFCC0FA90FE805449AD
    SHA1:1464F27C227F8924DFB940E689865D5577DD8817
    SHA-256:8C8E9041F60CF3B9C0A08916E04EFEFEA2E3A07E115D202451268A7C3A999CAD
    SHA-512:564C8385F0F044B5BB3C14924C1930E5DCA233D3DF2CE2619E4E99840771ECBC24FB6370D682DAD587E41AB9D5BADC9B72B1C60120EA55AC4B301793954F63DA
    Malicious:false
    Reputation:low
    Preview:MZP.....................@...............................................!..L.!..This program must be run under Win32..$7........................................................................................................................................PE..L...Rm"[....................."............... ....@.......................................@......@......................................x...............H............................................................................................text...\........................... ..`.itext.............................. ..`.data........ ......................@....bss.....V...0...........................idata..............................@....tls.................&...................rdata...............&..............@..@.rsrc...x............(..............@..@....................................@..@........................................................................................................................................
    No static file info
    Skipped network analysis since the amount of network traffic is too extensive. Please download the PCAP and check manually.

    Click to jump to process

    Click to jump to process

    Click to dive into process behavior distribution

    Click to jump to process

    Target ID:0
    Start time:11:09:09
    Start date:18/06/2024
    Path:C:\Windows\SysWOW64\cmd.exe
    Wow64 process (32bit):true
    Commandline:C:\Windows\system32\cmd.exe /c wget -t 2 -v -T 60 -P "C:\Users\user\Desktop\download" --no-check-certificate --content-disposition --user-agent="Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; AS; rv:11.0) like Gecko" "https://onset2.onsetcomp.com/files/software/hoboware/3.7.28/HOBOware_Free_Setup.exe" > cmdline.out 2>&1
    Imagebase:0x790000
    File size:236'544 bytes
    MD5 hash:D0FCE3AFA6AA1D58CE9FA336CC2B675B
    Has elevated privileges:true
    Has administrator privileges:true
    Programmed in:C, C++ or other language
    Reputation:low
    Has exited:true

    Target ID:1
    Start time:11:09:09
    Start date:18/06/2024
    Path:C:\Windows\System32\conhost.exe
    Wow64 process (32bit):false
    Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
    Imagebase:0x7ff6d64d0000
    File size:862'208 bytes
    MD5 hash:0D698AF330FD17BEE3BF90011D49251D
    Has elevated privileges:true
    Has administrator privileges:true
    Programmed in:C, C++ or other language
    Reputation:low
    Has exited:true

    Target ID:2
    Start time:11:09:09
    Start date:18/06/2024
    Path:C:\Windows\SysWOW64\wget.exe
    Wow64 process (32bit):true
    Commandline:wget -t 2 -v -T 60 -P "C:\Users\user\Desktop\download" --no-check-certificate --content-disposition --user-agent="Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; AS; rv:11.0) like Gecko" "https://onset2.onsetcomp.com/files/software/hoboware/3.7.28/HOBOware_Free_Setup.exe"
    Imagebase:0x400000
    File size:3'895'184 bytes
    MD5 hash:3DADB6E2ECE9C4B3E1E322E617658B60
    Has elevated privileges:true
    Has administrator privileges:true
    Programmed in:C, C++ or other language
    Reputation:low
    Has exited:true

    Target ID:9
    Start time:11:12:15
    Start date:18/06/2024
    Path:C:\Users\user\Desktop\download\HOBOware_Free_Setup.exe
    Wow64 process (32bit):true
    Commandline:"C:\Users\user\Desktop\download\HOBOware_Free_Setup.exe"
    Imagebase:0x400000
    File size:253'469'944 bytes
    MD5 hash:09A67AE954237BFCC0FA90FE805449AD
    Has elevated privileges:true
    Has administrator privileges:true
    Programmed in:Borland Delphi
    Reputation:low
    Has exited:true

    Target ID:10
    Start time:11:12:15
    Start date:18/06/2024
    Path:C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp
    Wow64 process (32bit):true
    Commandline:"C:\Users\user\AppData\Local\Temp\is-BJ5P5.tmp\HOBOware_Free_Setup.tmp" /SL5="$8004E,252732992,141824,C:\Users\user\Desktop\download\HOBOware_Free_Setup.exe"
    Imagebase:0x400000
    File size:1'214'792 bytes
    MD5 hash:461456B58784CAB0CA1D194B41A2D256
    Has elevated privileges:true
    Has administrator privileges:true
    Programmed in:Borland Delphi
    Reputation:low
    Has exited:true

    Target ID:12
    Start time:11:12:46
    Start date:18/06/2024
    Path:C:\Users\user\AppData\Local\Temp\is-SE99M.tmp\_isetup\_setup64.tmp
    Wow64 process (32bit):false
    Commandline:helper 105 0x4C4
    Imagebase:0x140000000
    File size:6'144 bytes
    MD5 hash:E4211D6D009757C078A9FAC7FF4F03D4
    Has elevated privileges:true
    Has administrator privileges:true
    Programmed in:C, C++ or other language
    Reputation:low
    Has exited:true

    Target ID:13
    Start time:11:12:46
    Start date:18/06/2024
    Path:C:\Windows\System32\conhost.exe
    Wow64 process (32bit):false
    Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
    Imagebase:0x7ff6d64d0000
    File size:862'208 bytes
    MD5 hash:0D698AF330FD17BEE3BF90011D49251D
    Has elevated privileges:true
    Has administrator privileges:true
    Programmed in:C, C++ or other language
    Reputation:low
    Has exited:true

    Target ID:15
    Start time:11:13:53
    Start date:18/06/2024
    Path:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
    Wow64 process (32bit):true
    Commandline:"C:\Program Files (x86)\Microsoft Office\Root\Office16\WINWORD.EXE" /n "C:\Program Files\Onset Computer Corporation\HOBOware\README.rtf" /o ""
    Imagebase:0xb0000
    File size:1'620'872 bytes
    MD5 hash:1A0C2C2E7D9C4BC18E91604E9B0C7678
    Has elevated privileges:true
    Has administrator privileges:true
    Programmed in:C, C++ or other language
    Reputation:low
    Has exited:false

    Reset < >

      Execution Graph

      Execution Coverage:56.4%
      Dynamic/Decrypted Code Coverage:0%
      Signature Coverage:33.3%
      Total number of Nodes:33
      Total number of Limit Nodes:5
      execution_graph 64 1400014e0 67 1400012a4 8 API calls 64->67 68 140001317 GetLastError 67->68 69 140001329 67->69 70 140001330 ExitProcess 68->70 69->70 71 14000133a StrToIntW 69->71 71->70 72 140001353 StrToInt64ExW 71->72 72->70 79 140001372 72->79 73 140001468 ReadFile 74 140001490 GetLastError 73->74 73->79 76 1400014aa CloseHandle 74->76 77 14000149b GetLastError 74->77 75 1400014be 75->76 76->70 77->76 78 140001438 WriteFile 80 1400014c5 GetLastError 78->80 83 1400013d3 78->83 79->73 79->75 79->78 79->83 84 140001000 79->84 80->76 83->73 83->75 83->78 95 1400011dc LoadTypeLib 83->95 85 14000104b GetNamedSecurityInfoW 84->85 86 140001041 84->86 85->86 87 140001088 85->87 86->83 88 14000111d SetEntriesInAclW 87->88 89 1400010a8 AllocateAndInitializeSid 87->89 90 140001172 88->90 91 14000113e SetNamedSecurityInfoW LocalFree 88->91 89->87 92 1400011c5 GetLastError 89->92 93 140001197 LocalFree 90->93 94 140001187 FreeSid 90->94 91->90 92->90 93->86 94->90 96 140001276 95->96 97 14000120f 95->97 96->83 98 140001218 RegisterTypeLib 97->98 99 14000122b 97->99 98->96 99->96 100 140001241 UnRegisterTypeLib 99->100 100->96

      Callgraph

      • Executed
      • Not Executed
      • Opacity -> Relevance
      • Disassembly available
      callgraph 0 Function_00000001400012A4 1 Function_00000001400011DC 0->1 4 Function_0000000140001000 0->4 2 Function_000000014000129C 3 Function_00000001400014E0 3->0

      Control-flow Graph

      APIs
      Memory Dump Source
      • Source File: 0000000C.00000002.4851973328.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
      • Associated: 0000000C.00000002.4851944523.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
      • Associated: 0000000C.00000002.4852000845.0000000140002000.00000002.00000001.01000000.00000008.sdmpDownload File
      • Associated: 0000000C.00000002.4852027582.0000000140013000.00000004.00000001.01000000.00000008.sdmpDownload File
      • Associated: 0000000C.00000002.4852057082.0000000140025000.00000002.00000001.01000000.00000008.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_12_2_140000000__setup64.jbxd
      Similarity
      • API ID: Free$InfoLocalNamedSecurity$AllocateEntriesErrorInitializeLast
      • String ID:
      • API String ID: 1336570144-0
      • Opcode ID: b35f34b64a9d6aa6b81e16b13b2f1c0d38c8c3b1546899b34faa1a97c6582e21
      • Instruction ID: 9ad65f9ffd8baecdb197e09b536dbb51b96e9a581e15e5332d3d6b3fb358d4f4
      • Opcode Fuzzy Hash: b35f34b64a9d6aa6b81e16b13b2f1c0d38c8c3b1546899b34faa1a97c6582e21
      • Instruction Fuzzy Hash: A35147B2614B8186E765CF12F88078EB7E6F7887D4F504425EB8943B64DF38D9A5CB00

      Control-flow Graph

      APIs
      Strings
      Memory Dump Source
      • Source File: 0000000C.00000002.4851973328.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
      • Associated: 0000000C.00000002.4851944523.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
      • Associated: 0000000C.00000002.4852000845.0000000140002000.00000002.00000001.01000000.00000008.sdmpDownload File
      • Associated: 0000000C.00000002.4852027582.0000000140013000.00000004.00000001.01000000.00000008.sdmpDownload File
      • Associated: 0000000C.00000002.4852057082.0000000140025000.00000002.00000001.01000000.00000008.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_12_2_140000000__setup64.jbxd
      Similarity
      • API ID: Error$CommandDirectoryLastLine$ArgvCloseConsoleCtrlCurrentHandleHandlerModeParametersProcessShutdownSystem
      • String ID: @Lr$C:\Users\Public\Documents\HOBOware Public Files\Configs\TEL-7001-Temp-F.hcfg
      • API String ID: 1351133944-1646702975
      • Opcode ID: 9d6e473d000c958ab654ea6524e99b93636dd2550909cc2fdf2d0baeb0bae34d
      • Instruction ID: bed22989135500286ff082a5b8534ee6a98307118f748591786f601728a80f93
      • Opcode Fuzzy Hash: 9d6e473d000c958ab654ea6524e99b93636dd2550909cc2fdf2d0baeb0bae34d
      • Instruction Fuzzy Hash: 435106B160464686EB13DF27F8843E963A1F78C7C5F904125FB4A476B5CB3C8989CB50

      Control-flow Graph

      • Executed
      • Not Executed
      control_flow_graph 52 1400014e0-1400014eb call 1400012a4 ExitProcess
      APIs
        • Part of subcall function 00000001400012A4: #17.COMCTL32(?,?,?,?,?,?,00000001400014E9), ref: 00000001400012AF
        • Part of subcall function 00000001400012A4: SetErrorMode.KERNELBASE(?,?,?,?,?,?,00000001400014E9), ref: 00000001400012BA
        • Part of subcall function 00000001400012A4: GetSystemDirectoryW.KERNEL32 ref: 00000001400012CC
        • Part of subcall function 00000001400012A4: SetCurrentDirectoryW.KERNEL32(?,?,?,?,?,?,00000001400014E9), ref: 00000001400012D9
        • Part of subcall function 00000001400012A4: SetProcessShutdownParameters.KERNEL32(?,?,?,?,?,?,00000001400014E9), ref: 00000001400012E6
        • Part of subcall function 00000001400012A4: SetConsoleCtrlHandler.KERNEL32(?,?,?,?,?,?,00000001400014E9), ref: 00000001400012F5
        • Part of subcall function 00000001400012A4: GetCommandLineW.KERNEL32(?,?,?,?,?,?,00000001400014E9), ref: 00000001400012FB
        • Part of subcall function 00000001400012A4: CommandLineToArgvW.SHELL32(?,?,?,?,?,?,00000001400014E9), ref: 0000000140001309
        • Part of subcall function 00000001400012A4: GetLastError.KERNEL32(?,?,?,?,?,?,00000001400014E9), ref: 0000000140001317
      • ExitProcess.KERNEL32 ref: 00000001400014EB
      Memory Dump Source
      • Source File: 0000000C.00000002.4851973328.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
      • Associated: 0000000C.00000002.4851944523.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
      • Associated: 0000000C.00000002.4852000845.0000000140002000.00000002.00000001.01000000.00000008.sdmpDownload File
      • Associated: 0000000C.00000002.4852027582.0000000140013000.00000004.00000001.01000000.00000008.sdmpDownload File
      • Associated: 0000000C.00000002.4852057082.0000000140025000.00000002.00000001.01000000.00000008.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_12_2_140000000__setup64.jbxd
      Similarity
      • API ID: CommandDirectoryErrorLineProcess$ArgvConsoleCtrlCurrentExitHandlerLastModeParametersShutdownSystem
      • String ID:
      • API String ID: 596749235-0
      • Opcode ID: d409c78e300c7577bde50c236e3745e62975251c616abf16af35a2c2feadab5b
      • Instruction ID: 20a652f16b87ba7830b4ae42eb4563c7e1ed9e0c7b0ce7c62722bbd31286e835
      • Opcode Fuzzy Hash: d409c78e300c7577bde50c236e3745e62975251c616abf16af35a2c2feadab5b
      • Instruction Fuzzy Hash: CEA001B0E2168282EA0ABBB6695A3D911626FD8781F540414A242872A2DD7884698612