Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
LisectAVT_2403002A_126.EXE.exe

Overview

General Information

Sample name:LisectAVT_2403002A_126.EXE.exe
Analysis ID:1482512
MD5:c98e7230adb1ba8d2f2082ca885068bb
SHA1:523a6fdf84bc1b0eec54d9532b3dbe564f29af38
SHA256:6cf41e72620cafb1577415d626dbb66c8c796d7167164ca091a27c4273378a20
Tags:exeWannaCry
Infos:

Detection

Wannacry
Score:100
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Antivirus / Scanner detection for submitted sample
Antivirus detection for dropped file
Malicious sample detected (through community Yara rule)
Yara detected Wannacry ransomware
AI detected suspicious sample
Command shell drops VBS files
Creates files in the recycle bin to hide itself
Deletes shadow drive data (may be related to ransomware)
Drops PE files to the document folder of the user
Machine Learning detection for dropped file
Machine Learning detection for sample
Modifies existing user documents (likely ransomware behavior)
Uses cmd line tools excessively to alter registry or file data
Writes many files with high entropy
Abnormal high CPU Usage
Creates a process in suspended mode (likely to inject code)
Dropped file seen in connection with other malware
Drops PE files
Drops files with a non-matching file extension (content does not match file extension)
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
Found dropped PE file which has not been started or loaded
May sleep (evasive loops) to hinder dynamic analysis
PE file contains executable resources (Code or Archives)
Queries the volume information (name, serial number etc) of a device
Sample execution stops while process was sleeping (likely an evasion)
Sample file is different than original file name gathered from version info
Sigma detected: Startup Folder File Write
Sigma detected: WSF/JSE/JS/VBA/VBE File Execution Via Cscript/Wscript
Stores files to the Windows start menu directory
Uses 32bit PE files
Uses cacls to modify the permissions of files
Yara signature match

Classification

  • System is w10x64
  • LisectAVT_2403002A_126.EXE.exe (PID: 7508 cmdline: "C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe" MD5: C98E7230ADB1BA8D2F2082CA885068BB)
    • attrib.exe (PID: 7560 cmdline: attrib +h . MD5: 0E938DD280E83B1596EC6AA48729C2B0)
      • conhost.exe (PID: 7576 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
    • icacls.exe (PID: 7568 cmdline: icacls . /grant Everyone:F /T /C /Q MD5: 2E49585E4E08565F52090B144062F97E)
      • conhost.exe (PID: 7584 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
    • taskdl.exe (PID: 7692 cmdline: taskdl.exe MD5: 4FEF5E34143E646DBF9907C4374276F5)
    • cmd.exe (PID: 7716 cmdline: C:\Windows\system32\cmd.exe /c 70341721944935.bat MD5: D0FCE3AFA6AA1D58CE9FA336CC2B675B)
      • conhost.exe (PID: 7724 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
      • cscript.exe (PID: 7780 cmdline: cscript.exe //nologo m.vbs MD5: CB601B41D4C8074BE8A84AED564A94DC)
    • taskdl.exe (PID: 7752 cmdline: taskdl.exe MD5: 4FEF5E34143E646DBF9907C4374276F5)
    • taskdl.exe (PID: 7816 cmdline: taskdl.exe MD5: 4FEF5E34143E646DBF9907C4374276F5)
    • taskdl.exe (PID: 7832 cmdline: taskdl.exe MD5: 4FEF5E34143E646DBF9907C4374276F5)
    • taskdl.exe (PID: 7848 cmdline: taskdl.exe MD5: 4FEF5E34143E646DBF9907C4374276F5)
    • taskdl.exe (PID: 7864 cmdline: taskdl.exe MD5: 4FEF5E34143E646DBF9907C4374276F5)
    • taskdl.exe (PID: 7880 cmdline: taskdl.exe MD5: 4FEF5E34143E646DBF9907C4374276F5)
    • taskdl.exe (PID: 7900 cmdline: taskdl.exe MD5: 4FEF5E34143E646DBF9907C4374276F5)
    • taskdl.exe (PID: 7916 cmdline: taskdl.exe MD5: 4FEF5E34143E646DBF9907C4374276F5)
    • taskdl.exe (PID: 7932 cmdline: taskdl.exe MD5: 4FEF5E34143E646DBF9907C4374276F5)
    • taskdl.exe (PID: 7948 cmdline: taskdl.exe MD5: 4FEF5E34143E646DBF9907C4374276F5)
    • taskdl.exe (PID: 7964 cmdline: taskdl.exe MD5: 4FEF5E34143E646DBF9907C4374276F5)
    • taskdl.exe (PID: 7996 cmdline: taskdl.exe MD5: 4FEF5E34143E646DBF9907C4374276F5)
    • taskdl.exe (PID: 8016 cmdline: taskdl.exe MD5: 4FEF5E34143E646DBF9907C4374276F5)
    • taskdl.exe (PID: 8044 cmdline: taskdl.exe MD5: 4FEF5E34143E646DBF9907C4374276F5)
    • taskdl.exe (PID: 8076 cmdline: taskdl.exe MD5: 4FEF5E34143E646DBF9907C4374276F5)
    • taskdl.exe (PID: 8108 cmdline: taskdl.exe MD5: 4FEF5E34143E646DBF9907C4374276F5)
    • taskdl.exe (PID: 8124 cmdline: taskdl.exe MD5: 4FEF5E34143E646DBF9907C4374276F5)
    • taskdl.exe (PID: 8140 cmdline: taskdl.exe MD5: 4FEF5E34143E646DBF9907C4374276F5)
    • taskdl.exe (PID: 8172 cmdline: taskdl.exe MD5: 4FEF5E34143E646DBF9907C4374276F5)
    • taskdl.exe (PID: 7244 cmdline: taskdl.exe MD5: 4FEF5E34143E646DBF9907C4374276F5)
    • taskdl.exe (PID: 7272 cmdline: taskdl.exe MD5: 4FEF5E34143E646DBF9907C4374276F5)
    • taskdl.exe (PID: 3168 cmdline: taskdl.exe MD5: 4FEF5E34143E646DBF9907C4374276F5)
    • taskdl.exe (PID: 6236 cmdline: taskdl.exe MD5: 4FEF5E34143E646DBF9907C4374276F5)
    • taskdl.exe (PID: 7152 cmdline: taskdl.exe MD5: 4FEF5E34143E646DBF9907C4374276F5)
    • taskdl.exe (PID: 7216 cmdline: taskdl.exe MD5: 4FEF5E34143E646DBF9907C4374276F5)
    • taskdl.exe (PID: 7320 cmdline: taskdl.exe MD5: 4FEF5E34143E646DBF9907C4374276F5)
    • taskdl.exe (PID: 7404 cmdline: taskdl.exe MD5: 4FEF5E34143E646DBF9907C4374276F5)
    • taskdl.exe (PID: 2696 cmdline: taskdl.exe MD5: 4FEF5E34143E646DBF9907C4374276F5)
    • taskdl.exe (PID: 7044 cmdline: taskdl.exe MD5: 4FEF5E34143E646DBF9907C4374276F5)
    • taskdl.exe (PID: 7300 cmdline: taskdl.exe MD5: 4FEF5E34143E646DBF9907C4374276F5)
    • taskdl.exe (PID: 7492 cmdline: taskdl.exe MD5: 4FEF5E34143E646DBF9907C4374276F5)
    • taskdl.exe (PID: 7556 cmdline: taskdl.exe MD5: 4FEF5E34143E646DBF9907C4374276F5)
    • taskdl.exe (PID: 7600 cmdline: taskdl.exe MD5: 4FEF5E34143E646DBF9907C4374276F5)
  • cleanup
No configs have been found
SourceRuleDescriptionAuthorStrings
LisectAVT_2403002A_126.EXE.exeJoeSecurity_WannacryYara detected Wannacry ransomwareJoe Security
    LisectAVT_2403002A_126.EXE.exeWannaCry_RansomwareDetects WannaCry RansomwareFlorian Roth (with the help of binar.ly)
    • 0xf4fc:$x1: icacls . /grant Everyone:F /T /C /Q
    • 0x342d41:$x2: taskdl.exe
    • 0x35962d:$x2: taskdl.exe
    • 0xf4d8:$x3: tasksche.exe
    • 0xf4b4:$x4: Global\MsWinZonesCacheCounterMutexA
    • 0xf52c:$x5: WNcry@2ol7
    • 0xf4fc:$x9: icacls . /grant Everyone:F /T /C /Q
    • 0x359d91:$s2: Windows 10 -->
    • 0xf42c:$s3: cmd.exe /c "%s"
    • 0x41980:$s4: msg/m_portuguese.wnry
    • 0x3591ff:$s4: msg/m_portuguese.wnry
    • 0x2a02:$op4: 09 FF 76 30 50 FF 56 2C 59 59 47 3B 7E 0C 7C
    • 0x26dc:$op5: C1 EA 1D C1 EE 1E 83 E2 01 83 E6 01 8D 14 56
    • 0x22c8:$op6: 8D 48 FF F7 D1 8D 44 10 FF 23 F1 23 C1
    LisectAVT_2403002A_126.EXE.exewanna_cry_ransomware_genericdetects wannacry ransomware on disk and in virtual pageus-cert code analysis team
    • 0xf4d8:$s11: 74 61 73 6B 73 63 68 65 2E 65 78 65 00 00 00 00 54 61 73 6B 53 74 61 72 74 00 00 00 74 2E 77 6E 72 79 00 00 69 63 61 63
    • 0xf500:$s12: 6C 73 20 2E 20 2F 67 72 61 6E 74 20 45 76 65 72 79 6F 6E 65 3A 46 20 2F 54 20 2F 43 20 2F 51 00 61 74 74 72 69 62 20 2B 68
    LisectAVT_2403002A_126.EXE.exeWin32_Ransomware_WannaCryunknownReversingLabs
    • 0x2016:$main_2: 68 08 02 00 00 33 DB 50 53 FF 15 8C 80 40 00 68 AC F8 40 00 E8 F6 F1 FF FF 59 FF 15 6C 81 40 00 83 38 02 75 53 68 38 F5 40 00 FF 15 68 81 40 00 8B 00 FF 70 04 E8 F0 56 00 00 59 85 C0 59 75 38 ...
    • 0x77ba:$entrypoint_all: 55 8B EC 6A FF 68 88 D4 40 00 68 F4 76 40 00 64 A1 00 00 00 00 50 64 89 25 00 00 00 00 83 EC 68 53 56 57 89 65 E8 33 DB 89 5D FC 6A 02 FF 15 C4 81 40 00 59 83 0D 4C F9 40 00 FF 83 0D 50 F9 40 ...
    SourceRuleDescriptionAuthorStrings
    C:\@Please_Read_Me@.txtWannaCry_RansomNoteDetects WannaCry Ransomware NoteFlorian Roth
    • 0x2c0:$s1: A: Don't worry about decryption.
    • 0x0:$s2: Q: What's wrong with my files?
    C:\Users\user\Desktop\70341721944935.batWannCry_BATDetects WannaCry Ransomware BATCH FileFlorian Roth
    • 0x2c0:$s1: A: Don't worry about decryption.
    • 0x0:$s2: Q: What's wrong with my files?
    C:\Users\user\Desktop\70341721944935.batWannCry_BATDetects WannaCry Ransomware BATCH FileFlorian Roth
    • 0x2c0:$s1: A: Don't worry about decryption.
    • 0x0:$s2: Q: What's wrong with my files?
    C:\Users\user\Desktop\70341721944935.batWannCry_BATDetects WannaCry Ransomware BATCH FileFlorian Roth
    • 0x2c0:$s1: A: Don't worry about decryption.
    • 0x0:$s2: Q: What's wrong with my files?
    C:\Users\user\Desktop\70341721944935.batWannCry_BATDetects WannaCry Ransomware BATCH FileFlorian Roth
    • 0x2c0:$s1: A: Don't worry about decryption.
    • 0x0:$s2: Q: What's wrong with my files?
    Click to see the 34 entries
    SourceRuleDescriptionAuthorStrings
    00000000.00000003.1788283067.0000000000AFE000.00000004.00000020.00020000.00000000.sdmpJoeSecurity_WannacryYara detected Wannacry ransomwareJoe Security
      00000000.00000000.1324912594.000000000040E000.00000008.00000001.01000000.00000003.sdmpwanna_cry_ransomware_genericdetects wannacry ransomware on disk and in virtual pageus-cert code analysis team
      • 0x14d8:$s11: 74 61 73 6B 73 63 68 65 2E 65 78 65 00 00 00 00 54 61 73 6B 53 74 61 72 74 00 00 00 74 2E 77 6E 72 79 00 00 69 63 61 63
      • 0x1500:$s12: 6C 73 20 2E 20 2F 67 72 61 6E 74 20 45 76 65 72 79 6F 6E 65 3A 46 20 2F 54 20 2F 43 20 2F 51 00 61 74 74 72 69 62 20 2B 68
      00000000.00000003.1374099272.0000000000ABF000.00000004.00000020.00020000.00000000.sdmpJoeSecurity_WannacryYara detected Wannacry ransomwareJoe Security
        00000000.00000003.1788065356.0000000000AFE000.00000004.00000020.00020000.00000000.sdmpJoeSecurity_WannacryYara detected Wannacry ransomwareJoe Security
          Process Memory Space: LisectAVT_2403002A_126.EXE.exe PID: 7508JoeSecurity_WannacryYara detected Wannacry ransomwareJoe Security
            SourceRuleDescriptionAuthorStrings
            0.0.LisectAVT_2403002A_126.EXE.exe.400000.0.unpackJoeSecurity_WannacryYara detected Wannacry ransomwareJoe Security
              0.0.LisectAVT_2403002A_126.EXE.exe.400000.0.unpackWannaCry_RansomwareDetects WannaCry RansomwareFlorian Roth (with the help of binar.ly)
              • 0xf4fc:$x1: icacls . /grant Everyone:F /T /C /Q
              • 0x342d41:$x2: taskdl.exe
              • 0x35962d:$x2: taskdl.exe
              • 0xf4d8:$x3: tasksche.exe
              • 0xf4b4:$x4: Global\MsWinZonesCacheCounterMutexA
              • 0xf52c:$x5: WNcry@2ol7
              • 0xf4fc:$x9: icacls . /grant Everyone:F /T /C /Q
              • 0x359d91:$s2: Windows 10 -->
              • 0xf42c:$s3: cmd.exe /c "%s"
              • 0x41980:$s4: msg/m_portuguese.wnry
              • 0x3591ff:$s4: msg/m_portuguese.wnry
              • 0x2a02:$op4: 09 FF 76 30 50 FF 56 2C 59 59 47 3B 7E 0C 7C
              • 0x26dc:$op5: C1 EA 1D C1 EE 1E 83 E2 01 83 E6 01 8D 14 56
              • 0x22c8:$op6: 8D 48 FF F7 D1 8D 44 10 FF 23 F1 23 C1
              0.0.LisectAVT_2403002A_126.EXE.exe.400000.0.unpackwanna_cry_ransomware_genericdetects wannacry ransomware on disk and in virtual pageus-cert code analysis team
              • 0xf4d8:$s11: 74 61 73 6B 73 63 68 65 2E 65 78 65 00 00 00 00 54 61 73 6B 53 74 61 72 74 00 00 00 74 2E 77 6E 72 79 00 00 69 63 61 63
              • 0xf500:$s12: 6C 73 20 2E 20 2F 67 72 61 6E 74 20 45 76 65 72 79 6F 6E 65 3A 46 20 2F 54 20 2F 43 20 2F 51 00 61 74 74 72 69 62 20 2B 68
              0.0.LisectAVT_2403002A_126.EXE.exe.400000.0.unpackWin32_Ransomware_WannaCryunknownReversingLabs
              • 0x2016:$main_2: 68 08 02 00 00 33 DB 50 53 FF 15 8C 80 40 00 68 AC F8 40 00 E8 F6 F1 FF FF 59 FF 15 6C 81 40 00 83 38 02 75 53 68 38 F5 40 00 FF 15 68 81 40 00 8B 00 FF 70 04 E8 F0 56 00 00 59 85 C0 59 75 38 ...
              • 0x77ba:$entrypoint_all: 55 8B EC 6A FF 68 88 D4 40 00 68 F4 76 40 00 64 A1 00 00 00 00 50 64 89 25 00 00 00 00 83 EC 68 53 56 57 89 65 E8 33 DB 89 5D FC 6A 02 FF 15 C4 81 40 00 59 83 0D 4C F9 40 00 FF 83 0D 50 F9 40 ...

              System Summary

              barindex
              Source: File createdAuthor: Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research): Data: EventID: 11, Image: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe, ProcessId: 7508, TargetFilename: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\StartUp\~SD3BE3.tmp
              Source: Process startedAuthor: Michael Haag: Data: Command: cscript.exe //nologo m.vbs, CommandLine: cscript.exe //nologo m.vbs, CommandLine|base64offset|contains: (, Image: C:\Windows\SysWOW64\cscript.exe, NewProcessName: C:\Windows\SysWOW64\cscript.exe, OriginalFileName: C:\Windows\SysWOW64\cscript.exe, ParentCommandLine: C:\Windows\system32\cmd.exe /c 70341721944935.bat, ParentImage: C:\Windows\SysWOW64\cmd.exe, ParentProcessId: 7716, ParentProcessName: cmd.exe, ProcessCommandLine: cscript.exe //nologo m.vbs, ProcessId: 7780, ProcessName: cscript.exe
              No Snort rule has matched
              Timestamp:2024-07-26T00:01:38.071384+0200
              SID:2028377
              Source Port:49713
              Destination Port:9001
              Protocol:TCP
              Classtype:Unknown Traffic
              Timestamp:2024-07-26T00:02:01.801265+0200
              SID:2022930
              Source Port:443
              Destination Port:49706
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:2024-07-26T00:02:40.197188+0200
              SID:2022930
              Source Port:443
              Destination Port:49709
              Protocol:TCP
              Classtype:A Network Trojan was detected

              Click to jump to signature section

              Show All Signature Results

              AV Detection

              barindex
              Source: LisectAVT_2403002A_126.EXE.exeAvira: detected
              Source: C:\@WanaDecryptor@.exeAvira: detection malicious, Label: TR/FileCoder.724645
              Source: Submited SampleIntegrated Neural Analysis Model: Matched 99.9% probability
              Source: C:\@WanaDecryptor@.exeJoe Sandbox ML: detected
              Source: LisectAVT_2403002A_126.EXE.exeJoe Sandbox ML: detected
              Source: LisectAVT_2403002A_126.EXE.exeStatic PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, 32BIT_MACHINE
              Source: Binary string: ntkrnlmp.pdb source: LisectAVT_2403002A_126.EXE.exe, 00000000.00000003.2608335757.0000000000B12000.00000004.00000020.00020000.00000000.sdmp
              Source: Binary string: NGLCLI~2.LOGntkrnlmp.pdbrx source: LisectAVT_2403002A_126.EXE.exe, 00000000.00000003.2608335757.0000000000B12000.00000004.00000020.00020000.00000000.sdmp
              Source: Binary string: WINLOA~1.PDBwinload_prod.pdb23.6.20320.6 2023-10-05 10-15-18-157.logT source: LisectAVT_2403002A_126.EXE.exe, 00000000.00000003.2608335757.0000000000B12000.00000004.00000020.00020000.00000000.sdmp
              Source: C:\Users\user\Desktop\taskdl.exeCode function: 6_2_00401080 GetDriveTypeW,Sleep,swprintf,swprintf,FindFirstFileW,swprintf,?_Tidy@?$basic_string@GU?$char_traits@G@std@@V?$allocator@G@2@@std@@AAEX_N@Z,wcslen,?_Grow@?$basic_string@GU?$char_traits@G@std@@V?$allocator@G@2@@std@@AAE_NI_N@Z,?_Eos@?$basic_string@GU?$char_traits@G@std@@V?$allocator@G@2@@std@@AAEXI@Z,?_Tidy@?$basic_string@GU?$char_traits@G@std@@V?$allocator@G@2@@std@@AAEX_N@Z,FindNextFileW,FindClose,DeleteFileW,?_C@?1??_Nullstr@?$basic_string@GU?$char_traits@G@std@@V?$allocator@G@2@@std@@CAPBGXZ@4GB,?_C@?1??_Nullstr@?$basic_string@GU?$char_traits@G@std@@V?$allocator@G@2@@std@@CAPBGXZ@4GB,DeleteFileW,?_Tidy@?$basic_string@GU?$char_traits@G@std@@V?$allocator@G@2@@std@@AAEX_N@Z,?_Tidy@?$basic_string@GU?$char_traits@G@std@@V?$allocator@G@2@@std@@AAEX_N@Z,6_2_00401080
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile opened: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\~SD1D8B.tmpJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile opened: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\ClipSVC\Archive\Apps\~SD746.tmpJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile opened: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\ClipSVC\GenuineTicket\~SD747.tmpJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile opened: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\ClipSVC\~SD1DAF.tmpJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile opened: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Caches\~SD1DAE.tmpJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile opened: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\ClipSVC\Archive\~SD1DC0.tmpJump to behavior
              Source: m_danish.wnry.0.drString found in binary or memory: http://schemas.micr
              Source: LisectAVT_2403002A_126.EXE.exe, 00000000.00000003.1788283067.0000000000AFE000.00000004.00000020.00020000.00000000.sdmp, LisectAVT_2403002A_126.EXE.exe, 00000000.00000003.1374099272.0000000000ABF000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://www.btcfrog.com/qr/bitcoinPNG.php?address=%s
              Source: LisectAVT_2403002A_126.EXE.exe, 00000000.00000003.1788283067.0000000000AFE000.00000004.00000020.00020000.00000000.sdmp, LisectAVT_2403002A_126.EXE.exe, 00000000.00000003.1374099272.0000000000ABF000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://www.btcfrog.com/qr/bitcoinPNG.php?address=%smailto:%shttps://www.google.com/search?q=how
              Source: LisectAVT_2403002A_126.EXE.exe, 00000000.00000003.1788283067.0000000000AFE000.00000004.00000020.00020000.00000000.sdmp, LisectAVT_2403002A_126.EXE.exe, 00000000.00000003.1374099272.0000000000ABF000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.google.com/search?q=how

              Spam, unwanted Advertisements and Ransom Demands

              barindex
              Source: Yara matchFile source: LisectAVT_2403002A_126.EXE.exe, type: SAMPLE
              Source: Yara matchFile source: 0.0.LisectAVT_2403002A_126.EXE.exe.400000.0.unpack, type: UNPACKEDPE
              Source: Yara matchFile source: 00000000.00000003.1788283067.0000000000AFE000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
              Source: Yara matchFile source: 00000000.00000003.1374099272.0000000000ABF000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
              Source: Yara matchFile source: 00000000.00000003.1788065356.0000000000AFE000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
              Source: Yara matchFile source: Process Memory Space: LisectAVT_2403002A_126.EXE.exe PID: 7508, type: MEMORYSTR
              Source: Yara matchFile source: C:\@WanaDecryptor@.exe, type: DROPPED
              Source: Yara matchFile source: C:\Users\user\Desktop\u.wnry, type: DROPPED
              Source: LisectAVT_2403002A_126.EXE.exe, 00000000.00000003.1788283067.0000000000AFE000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: /c vssadmin delete shadows /all /quiet & wmic shadowcopy delete & bcdedit /set {default} bootstatuspolicy ignoreallfailures & bcdedit /set {default} recoveryenabled no & wbadmin delete catalog -quiet
              Source: LisectAVT_2403002A_126.EXE.exe, 00000000.00000003.1788283067.0000000000AFE000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: A%s %scmd.exe/c vssadmin delete shadows /all /quiet & wmic shadowcopy delete & bcdedit /set {default} bootstatuspolicy ignoreallfailures & bcdedit /set {default} recoveryenabled no & wbadmin delete catalog -quietvscofi13AM4VW2dhxYgXeQepoHkHSQuy6NgaEb94Englishm_%s.wnrymsg\<https://<http://%d/%d/%d %02d:%02d:%02d00;00;00;00http://www.btcfrog.com/qr/bitcoinPNG.php?address=%smailto:%shttps://www.google.com/search?q=how+to+buy+bitcoinhttps://en.wikipedia.org/wiki/BitcoinSend %.1f BTC to this address:%.1f BTCSend $%d worth of bitcoin to this address:$%d%02d;%02d;%02d;%02d***b.wnry+++---%s%s%d%I64d%dFailed to send your message!
              Source: LisectAVT_2403002A_126.EXE.exe, 00000000.00000003.1374099272.0000000000ABF000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: /c vssadmin delete shadows /all /quiet &i
              Source: LisectAVT_2403002A_126.EXE.exe, 00000000.00000003.1374099272.0000000000ABF000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: A%s %scmd.exe/c vssadmin delete shadows /all /quiet &i
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile moved: C:\Users\user\Desktop\QVTVNIBKSD\NHPKIZUUSG.jpgJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile deleted: C:\Users\user\Desktop\QVTVNIBKSD\NHPKIZUUSG.jpgJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile moved: C:\Users\user\Desktop\MNULNCRIYC\ZBEDCJPBEY.mp3Jump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile moved: C:\Users\user\Desktop\MNULNCRIYC.jpgJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile deleted: C:\Users\user\Desktop\MNULNCRIYC.jpgJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\AC\AppCache\5NTP7FNT\7\5_KhThI0onehz_-3sl58j0dOeLI.br[1].js.WNCRYT entropy: 7.9987170807Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\AC\AppCache\5NTP7FNT\7\DccpWCpoNzCwM4Qymi_Ji67Ilso.br[1].js.WNCRYT entropy: 7.99868843082Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\AC\AppCache\5NTP7FNT\7\D_0mE1U1YmZvpLaz5wDHB6P-DAI.br[1].js.WNCRYT entropy: 7.99904183102Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\AC\AppCache\5NTP7FNT\7\hAbWEdFpz7sABSGHo92EV1SPXRQ.br[1].js.WNCRYT entropy: 7.99894651575Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\AC\AppCache\5NTP7FNT\7\KF9j9oJUfaaKiX-84yf0U337ge8.br[1].js.WNCRYT entropy: 7.99990192308Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\AC\AppCache\5NTP7FNT\7\Kwh038ybdvX_puLwdopqHydJtVM.br[1].js.WNCRYT entropy: 7.99963359074Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\AC\AppCache\5NTP7FNT\7\mb8fkd60iW7q4wvyDIlCm9OOn10.br[1].js.WNCRYT entropy: 7.99540661384Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\AC\AppCache\5NTP7FNT\7\MgSq5EEOyYvlI1qVlLOXfgRHmzM.br[1].js.WNCRYT entropy: 7.99833503001Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\AC\AppCache\5NTP7FNT\7\pqKAmz-4RXsuUf_YO-8_wQDepUQ.br[1].js.WNCRYT entropy: 7.99538494931Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\ShellFeeds\GLEAM-LIGHT.svg.WNCRYT entropy: 7.99389233803Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\AC\AppCache\5NTP7FNT\7\tIa_X3QDXj2Izj2HpQ_Mo9f1WiM.br[1].js.WNCRYT entropy: 7.99843592749Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.6_0\craw_background.js.WNCRYT entropy: 7.99968749169Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.6_0\craw_window.js.WNCRYT entropy: 7.99934891564Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.6_0\images\flapper.gif.WNCRYT entropy: 7.99762117995Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\AC\AppCache\5NTP7FNT\7\wokAADULDNIRJUcpGmEjmH9QAB0.br[1].js.WNCRYT entropy: 7.99933248051Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\AC\AppCache\5NTP7FNT\7\XDTV5Ztdmvo1jmUE21mPICYC5h8.br[1].js.WNCRYT entropy: 7.9996673097Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\AC\AppCache\5NTP7FNT\7\xIW3D5oXL8xIpGjHoiGVJS_B4mg.br[1].js.WNCRYT entropy: 7.99676836192Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\AC\AppCache\5NTP7FNT\7\YfXD9vOw8__a60l-k1HNCxSbem4.br[1].js.WNCRYT entropy: 7.99691012928Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\AC\AppCache\5NTP7FNT\7\yNwdh0ra_6sDoSuCVMI8Wjl58UM.br[1].js.WNCRYT entropy: 7.99792593802Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\Notification\notification.bundle.js.WNCRYT entropy: 7.99965323322Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\AC\INetCache\1VJI1O8Q\X4wIjRXDbKeGz0mzi-NAovdjKMM.br[1].js.WNCRYT entropy: 7.99732611903Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\Notification\notification_fast.bundle.js.WNCRYT entropy: 7.99945223672Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\Tokenized-Card\tokenized-card.bundle.js.WNCRYT entropy: 7.99966952215Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.MicrosoftOfficeHub_8wekyb3d8bbwe\AC\INetCache\HXWKPVWZ\pwa-vendors~left-nav-rc.b24d6b48aeb44c7b5bf6.chunk.v7[1].js.WNCRYT entropy: 7.99289268442Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.MicrosoftOfficeHub_8wekyb3d8bbwe\AC\INetCache\P24NZ9IW\pwa-left-nav-rc.68ab311bcca4f86f9ef5.chunk.v7[1].js.WNCRYT entropy: 7.99390922204Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\Wallet-Checkout\wallet-drawer.bundle.js.WNCRYT entropy: 7.99985774893Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.MicrosoftOfficeHub_8wekyb3d8bbwe\AC\INetCache\HXWKPVWZ\pwa-forms-group~mru~officeforms-group-forms~officeforms-my-forms~places.bcdc404c7fe22f14ccad.chunk.v7[1].js.WNCRYT entropy: 7.99582727857Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Users\user\AppData\Local\Microsoft\Windows\Caches\{1F3E7B1E-B905-4D30-88C9-B63C603DA134}.3.ver0x0000000000000001.db.WNCRYT entropy: 7.99956594086Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Users\user\AppData\Local\Microsoft\Windows\Caches\{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x0000000000000003.db.WNCRYT entropy: 7.9972087576Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Users\user\AppData\Local\Microsoft\Windows\Caches\{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x0000000000000004.db.WNCRYT entropy: 7.99821758441Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\WDKI0JR2\ConvergedLogin_PCore_tSc0Su-bb7Jt0QVuF6v9Cg2[1].js.WNCRYT entropy: 7.99963552222Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\ProgramData\Microsoft\Diagnosis\TenantStorage\P-ARIA\EventStore.db.WNCRYT entropy: 7.99302264369Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\ProgramData\Microsoft\Search\Data\Applications\Windows\tmp.edb.WNCRYT entropy: 7.99896243712Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Windows.edb.WNCRYT entropy: 7.99999027356Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\ProgramData\Microsoft\SmsRouter\MessageStore\SmsInterceptStore.db.WNCRYT entropy: 7.99909898076Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\ProgramData\Microsoft\Windows NT\MSFax\VirtualInbox\en-GB\WelcomeFax.tif.WNCRYT entropy: 7.99788521438Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\ProgramData\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\device.png.WNCRYT entropy: 7.99668514583Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\ProgramData\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\overlay.png.WNCRYT entropy: 7.99378226164Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.MicrosoftOfficeHub_8wekyb3d8bbwe\AC\INetCache\P24NZ9IW\sharedscripts-939520eada[1].js.WNCRYT entropy: 7.99640498775Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\ProgramData\Microsoft\ClickToRun\ProductReleases\A2C4612B-C11F-4E4C-8240-7294F3668696\operations.db.WNCRYT entropy: 7.99998437313Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.MicrosoftOfficeHub_8wekyb3d8bbwe\AppData\CacheStorage\CacheStorage.edb.WNCRYT entropy: 7.99988507517Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\ProgramData\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\background.png.WNCRYT entropy: 7.99847065788Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy\AppData\CacheStorage\CacheStorage.edb.WNCRYT entropy: 7.99988817093Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\ProgramData\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\superbar.png.WNCRYT entropy: 7.99497218578Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\AC\AppCache\5NTP7FNT\7\aABLNT_FV45QjYQfnRHrBCAk4GU[1].js.WNCRYT entropy: 7.99844294939Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\ProgramData\Microsoft\Device Stage\Device\{8702d817-5aad-4674-9ef3-4d3decd87120}\background.png.WNCRYT entropy: 7.99856064717Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\AC\INetCache\9AG3H7PO\6hU_LneafI_NFLeDvM367ebFaKQ[1].js.WNCRYT entropy: 7.99127442197Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\ProgramData\Microsoft\Device Stage\Device\{8702d817-5aad-4674-9ef3-4d3decd87120}\watermark.png.WNCRYT entropy: 7.99410816118Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\AC\INetCache\M1FDD3EN\4tiHI4cTzqiixje34Lb3KTOm39Q[1].js.WNCRYT entropy: 7.996526952Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\AC\INetCache\M1PE9Y29\X6j0qPgNij1n_IogMJrgYaT9Kp8[1].js.WNCRYT entropy: 7.99139906879Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.66.0_0\eventpage_bin_prod.js.WNCRYT entropy: 7.99801723994Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\ProgramData\Microsoft\Windows\Caches\{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000009.db.WNCRYT entropy: 7.99933304463Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\ProgramData\Microsoft\Windows\Caches\{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x000000000000000a.db.WNCRYT entropy: 7.99944602742Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\ProgramData\Microsoft\Windows\Caches\{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x000000000000000d.db.WNCRYT entropy: 7.99938184882Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\DeviceSearchCache\AppCache133409700847494859.txt.WNCRYT entropy: 7.99835379204Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\DeviceSearchCache\AppCache133409701041821502.txt.WNCRYT entropy: 7.99821821966Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\DeviceSearchCache\AppCache133409701427142301.txt.WNCRYT entropy: 7.99805119676Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\ProgramData\Microsoft\Windows\Caches\{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000001.db.WNCRYT entropy: 7.9997040124Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Web Applications\Manifest Resources\agimnkijcaahngcdmfeangaknmldooml\Icons\256.png.WNCRYT entropy: 7.99245214144Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\DeviceSearchCache\AppCache133409703539336388.txt.WNCRYT entropy: 7.99840439814Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-E40F86FA01C77D7D9BB0598F680933D3AB85396F.bin.DB.WNCRYT entropy: 7.99989192587Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\DeviceSearchCache\AppCache133409704901523875.txt.WNCRYT entropy: 7.99844723469Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\ProgramData\Microsoft\ClickToRun\ProductReleases\A2C4612B-C11F-4E4C-8240-7294F3668696\en-us.16\stream.x86.en-us.db.WNCRYT entropy: 7.9995755228Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\DeviceSearchCache\AppCache133409705198455190.txt.WNCRYT entropy: 7.998600263Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\ProgramData\Microsoft\ClickToRun\ProductReleases\A2C4612B-C11F-4E4C-8240-7294F3668696\x-none.16\stream.x86.x-none.db.WNCRYT entropy: 7.99989182936Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\DeviceSearchCache\AppCache133409705498789017.txt.WNCRYT entropy: 7.99850147178Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\DeviceSearchCache\AppCache133409706362564741.txt.WNCRYT entropy: 7.9983748959Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Users\user\AppData\Local\Temp\jones.bmp.WNCRYT entropy: 7.99966906383Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\DeviceSearchCache\AppCache133409706552534938.txt.WNCRYT entropy: 7.99833760614Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Users\user\AppData\Local\Temp\user.bmp.WNCRYT entropy: 7.99973154957Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\DeviceSearchCache\AppCache133409706620146268.txt.WNCRYT entropy: 7.99841076986Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Users\user\AppData\Local\Microsoft\Office\OTele\excel.exe.db.WNCRYT entropy: 7.99235798676Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\DeviceSearchCache\AppCache133409706852088195.txt.WNCRYT entropy: 7.99846585935Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Users\user\AppData\Local\ConnectedDevicesPlatform\L.user\ActivitiesCache.db.WNCRYT entropy: 7.99983870201Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\DeviceSearchCache\AppCache133409708018850913.txt.WNCRYT entropy: 7.99847568897Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Users\user\AppData\Local\Google\Chrome\User Data\first_party_sets.db.WNCRYT entropy: 7.99639884363Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\DeviceSearchCache\AppCache133409708318751933.txt.WNCRYT entropy: 7.99860767752Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\databases\Databases.db.WNCRYT entropy: 7.99343999919Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\DeviceSearchCache\AppCache133409708745795147.txt.WNCRYT entropy: 7.99843143582Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\DeviceSearchCache\AppCache133664184897943762.txt.WNCRYT entropy: 7.9984927715Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Users\user\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db.WNCRYT entropy: 7.99272444413Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\DeviceSearchCache\AppCache133664185202193242.txt.WNCRYT entropy: 7.99846531581Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Users\user\AppData\Local\Microsoft\Office\OTele\officeclicktorun.exe.db.WNCRYT entropy: 7.9926329475Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\ConstraintIndex\Input_{19865394-38c8-473b-8d88-bf07dc9221d0}\appsconversions.txt.WNCRYT entropy: 7.9998923764Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Users\user\AppData\Local\Microsoft\Office\OTele\officesetup.exe.db.WNCRYT entropy: 7.99362700149Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\ConstraintIndex\Input_{19865394-38c8-473b-8d88-bf07dc9221d0}\appsglobals.txt.WNCRYT entropy: 7.99941949843Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\ConstraintIndex\Input_{19865394-38c8-473b-8d88-bf07dc9221d0}\appssynonyms.txt.WNCRYT entropy: 7.99929259074Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Users\user\AppData\Local\Microsoft\Windows\Caches\cversions.3.db.WNCRYT entropy: 7.99006205374Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\ConstraintIndex\Input_{19865394-38c8-473b-8d88-bf07dc9221d0}\settingsglobals.txt.WNCRYT entropy: 7.9961803825Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\iconcache_16.db.WNCRYT entropy: 7.99984871629Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\ConstraintIndex\Apps_{1bd4368b-5a81-4340-bb70-c47e715ef59b}\0.0.filtertrie.intermediate.txt.WNCRYT entropy: 7.99496134561Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\iconcache_256.db.WNCRYT entropy: 7.99994382155Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\ConstraintIndex\Apps_{a88a3c12-5895-49c0-aebb-958acaa71fed}\0.0.filtertrie.intermediate.txt.WNCRYT entropy: 7.99483055468Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\iconcache_32.db.WNCRYT entropy: 7.99989904675Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\ConstraintIndex\Apps_{d3eb7398-595c-4598-92b2-c8e082ebc5c4}\0.0.filtertrie.intermediate.txt.WNCRYT entropy: 7.99492033993Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\iconcache_48.db.WNCRYT entropy: 7.99982909523Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\ConstraintIndex\Input_{19865394-38c8-473b-8d88-bf07dc9221d0}\settingsconversions.txt.WNCRYT entropy: 7.99962887231Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\iconcache_idx.db.WNCRYT entropy: 7.99688780056Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\ConstraintIndex\Input_{19865394-38c8-473b-8d88-bf07dc9221d0}\settingssynonyms.txt.WNCRYT entropy: 7.99846569771Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\thumbcache_16.db.WNCRYT entropy: 7.99983356198Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\ConstraintIndex\Settings_{69143257-42f5-46b5-8baf-30774e2e792c}\0.0.filtertrie.intermediate.txt.WNCRYT entropy: 7.99920940341Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\thumbcache_256.db.WNCRYT entropy: 7.99979610017Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\ConstraintIndex\Settings_{d7420b01-ee72-478b-af4f-6b44c9dc7707}\0.0.filtertrie.intermediate.txt.WNCRYT entropy: 7.99916175554Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\thumbcache_32.db.WNCRYT entropy: 7.99984028844Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\thumbcache_48.db.WNCRYT entropy: 7.99982880447Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\thumbcache_96.db.WNCRYT entropy: 7.99995972124Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\thumbcache_idx.db.WNCRYT entropy: 7.99695000034Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Users\user\AppData\Local\Microsoft\Windows\Notifications\wpndatabase.db.WNCRYT entropy: 7.99986256737Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Users\user\AppData\Local\Temp\18e190413af045db88dfbd29609eb877.db.WNCRYT entropy: 7.99205411173Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.66.0_0\eventpage_bin_prod.js.WNCRYT entropy: 7.99800105401Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\EdgeEDrop\EdgeEDropSQLite.db.WNCRYT entropy: 7.9934688865Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Edge Shopping\2.0.5975.0\edge_driver.js.WNCRYT entropy: 7.9998877703Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Edge Shopping\2.0.5975.0\product_page.js.WNCRYT entropy: 7.99980949928Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Edge Shopping\2.0.5975.0\shopping.js.WNCRYT entropy: 7.99996600996Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Edge Shopping\2.0.5975.0\shoppingfre.js.WNCRYT entropy: 7.99943099563Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\HI1BCF07\ConvergedLoginPaginatedStrings.en-gb_RP-iR89BipE4i7ZOqiqEgQ2[1].js.WNCRYT entropy: 7.99481570328Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.MicrosoftOfficeHub_8wekyb3d8bbwe\AC\INetCache\5451C91R\microsoft-365-logo-01d5ecd01a[1].png.WNCRYT entropy: 7.99133087553Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.MicrosoftOfficeHub_8wekyb3d8bbwe\AC\INetCache\5JD14XPQ\pwa-bootstrap-5e7af218e953d095fabf[1].js.WNCRYT entropy: 7.9970792307Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\edge_driver.js.WNCRYT entropy: 7.99990728554Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.MicrosoftOfficeHub_8wekyb3d8bbwe\AC\INetCache\5JD14XPQ\staticpwascripts-30998bff8f[1].js.WNCRYT entropy: 7.99049288266Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\EdgeHubAppUsage\EdgeHubAppUsageSQLite.db.WNCRYT entropy: 7.99139453579Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.MicrosoftOfficeHub_8wekyb3d8bbwe\AC\INetCache\HXWKPVWZ\otel-logger-104bffe9378b8041455c[1].js.WNCRYT entropy: 7.99801077257Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Edge Shopping\2.0.5975.0\auto_open_controller.js.WNCRYT entropy: 7.99988072528Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Edge Shopping\2.0.5975.0\edge_checkout_page_validator.js.WNCRYT entropy: 7.99981141382Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.MicrosoftOfficeHub_8wekyb3d8bbwe\AC\INetCache\P24NZ9IW\pwa-bundle-3a99f64809c6780df035[1].js.WNCRYT entropy: 7.99985958526Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Edge Shopping\2.0.5975.0\edge_confirmation_page_validator.js.WNCRYT entropy: 7.99982802091Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.MicrosoftOfficeHub_8wekyb3d8bbwe\AC\INetCache\P24NZ9IW\pwa-mru.2ce72562ad7c0ae7059c.chunk.v7[1].js.WNCRYT entropy: 7.9957320793Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Edge Shopping\2.0.5975.0\edge_tracking_page_validator.js.WNCRYT entropy: 7.99757404444Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.MicrosoftOfficeHub_8wekyb3d8bbwe\AC\INetCache\P24NZ9IW\pwa-vendor-bundle-ba2888a24179bf152f3d[1].js.WNCRYT entropy: 7.99974148719Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\AC\AppCache\5NTP7FNT\7\-U2ww19iycr3M_DiD25JdVUDdqk.br[1].js.WNCRYT entropy: 7.9979749682Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\AC\AppCache\5NTP7FNT\7\584482RVjBIoEvVSe0RsuS1I4YQ.br[1].js.WNCRYT entropy: 7.99606844557Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\AC\AppCache\5NTP7FNT\7\58urCM4ERwTmgZF8atjxpMnY4I4.br[1].js.WNCRYT entropy: 7.99950456979Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\AC\AppCache\5NTP7FNT\7\5fBhIWX2NfxoiM-aOLeKJczoLSY.br[1].js.WNCRYT entropy: 7.99927983862Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\shopping_iframe_driver.js.WNCRYT entropy: 7.99324064585Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Themes\CachedFiles\CachedImage_1280_1024_POS4.jpg.WNCRYT entropy: 7.9973389896Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\vendor.bundle.js.WNCRYT entropy: 7.9998598405Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\wallet.bundle.js.WNCRYT entropy: 7.99993578771Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\bnpl\bnpl.bundle.js.WNCRYT entropy: 7.99976664872Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\Mini-Wallet\miniwallet.bundle.js.WNCRYT entropy: 7.9994662137Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\4UK5I61J\oneDs_f2e0f4a029670f10d892[1].js.WNCRYT entropy: 7.9991296051Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\AC\INetCache\1VJI1O8Q\th[1].svg.WNCRYT entropy: 7.9935002224Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\AC\INetCache\9AG3H7PO\th[1].png.WNCRYT entropy: 7.99117650418Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\AC\INetCache\9AG3H7PO\th[2].png.WNCRYT entropy: 7.99090485459Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\AC\INetCache\M1FDD3EN\th[1].png.WNCRYT entropy: 7.99099021821Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\AC\INetCache\M1PE9Y29\th[1].png.WNCRYT entropy: 7.99245768797Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\AC\INetCache\M1PE9Y29\th[1].svg.WNCRYT entropy: 7.99415568527Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\AC\INetCache\M1PE9Y29\th[2].png.WNCRYT entropy: 7.99217347272Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\AppData\CacheStorage\CacheStorage.edb.WNCRYT entropy: 7.99987961695Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\ProgramData\Microsoft\Windows NT\MSScan\WelcomeScan.jpg.WNCRYT entropy: 7.99961931077Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\AppData\Indexed DB\IndexedDB.edb.WNCRYT entropy: 7.99991781494Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\ShellFeeds\GLEAM-DARK.svg.WNCRYT entropy: 7.99444957743Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Users\user\Desktop\s.wnry entropy: 7.998263053Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Users\user\Desktop\t.wnry entropy: 7.99727613788Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\DeviceSearchCache\AppCache133664185510902646.txt.WNCRYT entropy: 7.99833490946Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\ConstraintIndex\Apps_{67e6418b-1ac4-40f2-b8e8-9239c2e7a1ab}\0.0.filtertrie.intermediate.txt.WNCRYT entropy: 7.99448816077Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\DeviceSearchCache\AppCache133664185800176358.txt.WNCRYT entropy: 7.99852420098Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\ProgramData\Microsoft\Diagnosis\EventStore.db.WNCRYT entropy: 7.9982191542Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\ProgramData\Microsoft\Network\Downloader\qmgr.db.WNCRYT entropy: 7.99985862946Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\ProgramData\Microsoft\User Account Pictures\guest.bmp.WNCRYT entropy: 7.99968472751Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\ProgramData\Microsoft\User Account Pictures\user.bmp.WNCRYT entropy: 7.99971567493Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db.WNCRYT entropy: 7.99959620519Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\ProgramData\Microsoft\Diagnosis\ScenariosSqlStore\EventStore.db.WNCRYT entropy: 7.9948575216Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Users\user\AppData\Local\Temp\acrobat_sbx\acroNGLLog.txt.WNCRYT entropy: 7.9927548529Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\EADPData Component\4.0.2.33\data.txt.WNCRYT entropy: 7.99748474994Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\DeviceSearchCache\SettingsCache.txt.WNCRYT entropy: 7.99972982378Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.MicrosoftOfficeHub_8wekyb3d8bbwe\AC\INetCache\HXWKPVWZ\hero-image-desktop-f6720a4145[1].jpg.WNCRYT entropy: 7.99818369826Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\DeviceSearchCache\AppCache133409699892906782.txt.WNCRYT entropy: 7.99832452335Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\DeviceSearchCache\AppCache133409699906926699.txt.WNCRYT entropy: 7.99814209376Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\DeviceSearchCache\AppCache133409700426789434.txt.WNCRYT entropy: 7.99837744758Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\DeviceSearchCache\AppCache133409700490540470.txt.WNCRYT entropy: 7.99807327065Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\DeviceSearchCache\AppCache133409700559076731.txt.WNCRYT entropy: 7.99817706524Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\DeviceSearchCache\AppCache133409700655677854.txt.WNCRYT entropy: 7.99841098615Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows NT\MSScan\WelcomeScan.jpg.WNCRY (copy) entropy: 7.99961931077Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\acrobat_sbx\acroNGLLog.txt.WNCRY (copy) entropy: 7.9927548529Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Edge\User Data\EADPData Component\4.0.2.33\data.txt.WNCRY (copy) entropy: 7.99748474994Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\DeviceSearchCache\SettingsCache.txt.WNCRY (copy) entropy: 7.99972982378Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.MicrosoftOfficeHub_8wekyb3d8bbwe\AC\INetCache\HXWKPVWZ\hero-image-desktop-f6720a4145[1].jpg.WNCRY (copy) entropy: 7.99818369826Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\DeviceSearchCache\AppCache133409699892906782.txt.WNCRY (copy) entropy: 7.99832452335Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\DeviceSearchCache\AppCache133409699906926699.txt.WNCRY (copy) entropy: 7.99814209376Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\DeviceSearchCache\AppCache133409700426789434.txt.WNCRY (copy) entropy: 7.99837744758Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\DeviceSearchCache\AppCache133409700490540470.txt.WNCRY (copy) entropy: 7.99807327065Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\DeviceSearchCache\AppCache133409700559076731.txt.WNCRY (copy) entropy: 7.99817706524Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\DeviceSearchCache\AppCache133409700655677854.txt.WNCRY (copy) entropy: 7.99841098615Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\DeviceSearchCache\AppCache133409700847494859.txt.WNCRY (copy) entropy: 7.99835379204Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\DeviceSearchCache\AppCache133409701041821502.txt.WNCRY (copy) entropy: 7.99821821966Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\DeviceSearchCache\AppCache133409701427142301.txt.WNCRY (copy) entropy: 7.99805119676Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\DeviceSearchCache\AppCache133409703539336388.txt.WNCRY (copy) entropy: 7.99840439814Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\DeviceSearchCache\AppCache133409704901523875.txt.WNCRY (copy) entropy: 7.99844723469Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\DeviceSearchCache\AppCache133409705198455190.txt.WNCRY (copy) entropy: 7.998600263Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\DeviceSearchCache\AppCache133409705498789017.txt.WNCRY (copy) entropy: 7.99850147178Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\DeviceSearchCache\AppCache133409706362564741.txt.WNCRY (copy) entropy: 7.9983748959Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\DeviceSearchCache\AppCache133409706552534938.txt.WNCRY (copy) entropy: 7.99833760614Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\DeviceSearchCache\AppCache133409706620146268.txt.WNCRY (copy) entropy: 7.99841076986Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\DeviceSearchCache\AppCache133409706852088195.txt.WNCRY (copy) entropy: 7.99846585935Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\DeviceSearchCache\AppCache133409708018850913.txt.WNCRY (copy) entropy: 7.99847568897Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\DeviceSearchCache\AppCache133409708318751933.txt.WNCRY (copy) entropy: 7.99860767752Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\DeviceSearchCache\AppCache133409708745795147.txt.WNCRY (copy) entropy: 7.99843143582Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\DeviceSearchCache\AppCache133664184897943762.txt.WNCRY (copy) entropy: 7.9984927715Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\DeviceSearchCache\AppCache133664185202193242.txt.WNCRY (copy) entropy: 7.99846531581Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\ConstraintIndex\Input_{19865394-38c8-473b-8d88-bf07dc9221d0}\appsconversions.txt.WNCRY (copy) entropy: 7.9998923764Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\ConstraintIndex\Input_{19865394-38c8-473b-8d88-bf07dc9221d0}\appsglobals.txt.WNCRY (copy) entropy: 7.99941949843Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\ConstraintIndex\Input_{19865394-38c8-473b-8d88-bf07dc9221d0}\appssynonyms.txt.WNCRY (copy) entropy: 7.99929259074Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\ConstraintIndex\Input_{19865394-38c8-473b-8d88-bf07dc9221d0}\settingsglobals.txt.WNCRY (copy) entropy: 7.9961803825Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\ConstraintIndex\Apps_{1bd4368b-5a81-4340-bb70-c47e715ef59b}\0.0.filtertrie.intermediate.txt.WNCRY (copy) entropy: 7.99496134561Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\ConstraintIndex\Apps_{a88a3c12-5895-49c0-aebb-958acaa71fed}\0.0.filtertrie.intermediate.txt.WNCRY (copy) entropy: 7.99483055468Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\ConstraintIndex\Apps_{d3eb7398-595c-4598-92b2-c8e082ebc5c4}\0.0.filtertrie.intermediate.txt.WNCRY (copy) entropy: 7.99492033993Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\ConstraintIndex\Input_{19865394-38c8-473b-8d88-bf07dc9221d0}\settingsconversions.txt.WNCRY (copy) entropy: 7.99962887231Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\ConstraintIndex\Input_{19865394-38c8-473b-8d88-bf07dc9221d0}\settingssynonyms.txt.WNCRY (copy) entropy: 7.99846569771Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\ConstraintIndex\Settings_{69143257-42f5-46b5-8baf-30774e2e792c}\0.0.filtertrie.intermediate.txt.WNCRY (copy) entropy: 7.99920940341Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\ConstraintIndex\Settings_{d7420b01-ee72-478b-af4f-6b44c9dc7707}\0.0.filtertrie.intermediate.txt.WNCRY (copy) entropy: 7.99916175554Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Documents and Settings\user\AppData\Roaming\Microsoft\Windows\Themes\CachedFiles\CachedImage_1280_1024_POS4.jpg.WNCRY (copy) entropy: 7.9973389896Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Documents and Settings\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\DeviceSearchCache\AppCache133664185510902646.txt.WNCRY (copy) entropy: 7.99833490946Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Documents and Settings\user\Local Settings\Application Data\Application Data\Application Data\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\ConstraintIndex\Apps_{67e6418b-1ac4-40f2-b8e8-9239c2e7a1ab}\0.0.filtertrie.intermediate.txt.WNCRY (copy) entropy: 7.99448816077Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\DeviceSearchCache\AppCache133664185800176358.txt.WNCRY (copy) entropy: 7.99852420098Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Diagnosis\EventStore.db.WNCRY (copy) entropy: 7.9982191542Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Network\Downloader\qmgr.db.WNCRY (copy) entropy: 7.99985862946Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\User Account Pictures\guest.bmp.WNCRY (copy) entropy: 7.99968472751Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\User Account Pictures\user.bmp.WNCRY (copy) entropy: 7.99971567493Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows Defender\Scans\mpenginedb.db.WNCRY (copy) entropy: 7.99959620519Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Diagnosis\ScenariosSqlStore\EventStore.db.WNCRY (copy) entropy: 7.9948575216Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Diagnosis\TenantStorage\P-ARIA\EventStore.db.WNCRY (copy) entropy: 7.99302264369Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Search\Data\Applications\Windows\tmp.edb.WNCRY (copy) entropy: 7.99896243712Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Search\Data\Applications\Windows\Windows.edb.WNCRY (copy) entropy: 7.99999027356Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\SmsRouter\MessageStore\SmsInterceptStore.db.WNCRY (copy) entropy: 7.99909898076Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows NT\MSFax\VirtualInbox\en-GB\WelcomeFax.tif.WNCRY (copy) entropy: 7.99788521438Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\device.png.WNCRY (copy) entropy: 7.99668514583Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\overlay.png.WNCRY (copy) entropy: 7.99378226164Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\ClickToRun\ProductReleases\A2C4612B-C11F-4E4C-8240-7294F3668696\operations.db.WNCRY (copy) entropy: 7.99998437313Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\background.png.WNCRY (copy) entropy: 7.99847065788Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\superbar.png.WNCRY (copy) entropy: 7.99497218578Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Device Stage\Device\{8702d817-5aad-4674-9ef3-4d3decd87120}\background.png.WNCRY (copy) entropy: 7.99856064717Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Device Stage\Device\{8702d817-5aad-4674-9ef3-4d3decd87120}\watermark.png.WNCRY (copy) entropy: 7.99410816118Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Caches\{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000009.db.WNCRY (copy) entropy: 7.99933304463Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Caches\{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x000000000000000a.db.WNCRY (copy) entropy: 7.99944602742Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Caches\{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x000000000000000d.db.WNCRY (copy) entropy: 7.99938184882Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Caches\{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000001.db.WNCRY (copy) entropy: 7.9997040124Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows Defender\Scans\mpcache-E40F86FA01C77D7D9BB0598F680933D3AB85396F.bin.DB.WNCRY (copy) entropy: 7.99989192587Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\ClickToRun\ProductReleases\A2C4612B-C11F-4E4C-8240-7294F3668696\en-us.16\stream.x86.en-us.db.WNCRY (copy) entropy: 7.9995755228Jump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\ClickToRun\ProductReleases\A2C4612B-C11F-4E4C-8240-7294F3668696\x-none.16\stream.x86.x-none.db.WNCRY (copy) entropy: 7.99989182936Jump to dropped file

              System Summary

              barindex
              Source: LisectAVT_2403002A_126.EXE.exe, type: SAMPLEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (with the help of binar.ly)
              Source: LisectAVT_2403002A_126.EXE.exe, type: SAMPLEMatched rule: detects wannacry ransomware on disk and in virtual page Author: us-cert code analysis team
              Source: LisectAVT_2403002A_126.EXE.exe, type: SAMPLEMatched rule: Win32_Ransomware_WannaCry Author: ReversingLabs
              Source: 0.0.LisectAVT_2403002A_126.EXE.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (with the help of binar.ly)
              Source: 0.0.LisectAVT_2403002A_126.EXE.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: detects wannacry ransomware on disk and in virtual page Author: us-cert code analysis team
              Source: 0.0.LisectAVT_2403002A_126.EXE.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Win32_Ransomware_WannaCry Author: ReversingLabs
              Source: 00000000.00000000.1324912594.000000000040E000.00000008.00000001.01000000.00000003.sdmp, type: MEMORYMatched rule: detects wannacry ransomware on disk and in virtual page Author: us-cert code analysis team
              Source: C:\@Please_Read_Me@.txt, type: DROPPEDMatched rule: Detects WannaCry Ransomware Note Author: Florian Roth
              Source: C:\Users\user\Desktop\70341721944935.bat, type: DROPPEDMatched rule: Detects WannaCry Ransomware BATCH File Author: Florian Roth
              Source: C:\Users\user\Desktop\70341721944935.bat, type: DROPPEDMatched rule: Detects WannaCry Ransomware BATCH File Author: Florian Roth
              Source: C:\Users\user\Desktop\70341721944935.bat, type: DROPPEDMatched rule: Detects WannaCry Ransomware BATCH File Author: Florian Roth
              Source: C:\Users\user\Desktop\70341721944935.bat, type: DROPPEDMatched rule: Detects WannaCry Ransomware BATCH File Author: Florian Roth
              Source: C:\Users\user\Desktop\70341721944935.bat, type: DROPPEDMatched rule: Detects WannaCry Ransomware BATCH File Author: Florian Roth
              Source: C:\Users\user\Desktop\70341721944935.bat, type: DROPPEDMatched rule: Detects WannaCry Ransomware BATCH File Author: Florian Roth
              Source: C:\Users\user\Desktop\70341721944935.bat, type: DROPPEDMatched rule: Detects WannaCry Ransomware BATCH File Author: Florian Roth
              Source: C:\Users\user\Desktop\70341721944935.bat, type: DROPPEDMatched rule: Detects WannaCry Ransomware BATCH File Author: Florian Roth
              Source: C:\Users\user\Desktop\70341721944935.bat, type: DROPPEDMatched rule: Detects WannaCry Ransomware BATCH File Author: Florian Roth
              Source: C:\Users\user\Desktop\70341721944935.bat, type: DROPPEDMatched rule: Detects WannaCry Ransomware BATCH File Author: Florian Roth
              Source: C:\Users\user\Desktop\70341721944935.bat, type: DROPPEDMatched rule: Detects WannaCry Ransomware BATCH File Author: Florian Roth
              Source: C:\Users\user\Desktop\70341721944935.bat, type: DROPPEDMatched rule: Detects WannaCry Ransomware BATCH File Author: Florian Roth
              Source: C:\Users\user\Desktop\70341721944935.bat, type: DROPPEDMatched rule: Detects WannaCry Ransomware BATCH File Author: Florian Roth
              Source: C:\Users\user\Desktop\70341721944935.bat, type: DROPPEDMatched rule: Detects WannaCry Ransomware BATCH File Author: Florian Roth
              Source: C:\Users\user\Desktop\70341721944935.bat, type: DROPPEDMatched rule: Detects WannaCry Ransomware BATCH File Author: Florian Roth
              Source: C:\Users\user\Desktop\70341721944935.bat, type: DROPPEDMatched rule: Detects WannaCry Ransomware BATCH File Author: Florian Roth
              Source: C:\Users\user\Desktop\70341721944935.bat, type: DROPPEDMatched rule: Detects WannaCry Ransomware BATCH File Author: Florian Roth
              Source: C:\Users\user\Desktop\70341721944935.bat, type: DROPPEDMatched rule: Detects WannaCry Ransomware BATCH File Author: Florian Roth
              Source: C:\@WanaDecryptor@.exe, type: DROPPEDMatched rule: Win32_Ransomware_WannaCry Author: ReversingLabs
              Source: C:\@WanaDecryptor@.exe, type: DROPPEDMatched rule: Win32_Ransomware_WannaCry Author: ReversingLabs
              Source: C:\Users\user\Desktop\u.wnry, type: DROPPEDMatched rule: Win32_Ransomware_WannaCry Author: ReversingLabs
              Source: C:\Users\user\Desktop\u.wnry, type: DROPPEDMatched rule: Win32_Ransomware_WannaCry Author: ReversingLabs
              Source: C:\Users\user\Desktop\u.wnry, type: DROPPEDMatched rule: Win32_Ransomware_WannaCry Author: ReversingLabs
              Source: C:\Users\user\Desktop\u.wnry, type: DROPPEDMatched rule: Win32_Ransomware_WannaCry Author: ReversingLabs
              Source: C:\Users\user\Desktop\u.wnry, type: DROPPEDMatched rule: Win32_Ransomware_WannaCry Author: ReversingLabs
              Source: C:\Users\user\Desktop\u.wnry, type: DROPPEDMatched rule: Win32_Ransomware_WannaCry Author: ReversingLabs
              Source: C:\Users\user\Desktop\u.wnry, type: DROPPEDMatched rule: Win32_Ransomware_WannaCry Author: ReversingLabs
              Source: C:\Users\user\Desktop\u.wnry, type: DROPPEDMatched rule: Win32_Ransomware_WannaCry Author: ReversingLabs
              Source: C:\Users\user\Desktop\u.wnry, type: DROPPEDMatched rule: Win32_Ransomware_WannaCry Author: ReversingLabs
              Source: C:\Users\user\Desktop\r.wnry, type: DROPPEDMatched rule: Detects WannaCry Ransomware Note Author: Florian Roth
              Source: C:\Users\user\Desktop\r.wnry, type: DROPPEDMatched rule: Detects WannaCry Ransomware Note Author: Florian Roth
              Source: C:\Users\user\Desktop\r.wnry, type: DROPPEDMatched rule: Detects WannaCry Ransomware Note Author: Florian Roth
              Source: C:\Users\user\Desktop\r.wnry, type: DROPPEDMatched rule: Detects WannaCry Ransomware Note Author: Florian Roth
              Source: C:\Users\user\Desktop\r.wnry, type: DROPPEDMatched rule: Detects WannaCry Ransomware Note Author: Florian Roth
              Source: C:\Users\user\Desktop\r.wnry, type: DROPPEDMatched rule: Detects WannaCry Ransomware Note Author: Florian Roth
              Source: C:\Users\user\Desktop\r.wnry, type: DROPPEDMatched rule: Detects WannaCry Ransomware Note Author: Florian Roth
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess Stats: CPU usage > 49%
              Source: Joe Sandbox ViewDropped File: C:\@WanaDecryptor@.exe B9C5D4339809E0AD9A00D4D3DD26FDF44A32819A54ABF846BB9B560D81391C25
              Source: Joe Sandbox ViewDropped File: C:\Users\user\AppData\Local\@WanaDecryptor@.exe B9C5D4339809E0AD9A00D4D3DD26FDF44A32819A54ABF846BB9B560D81391C25
              Source: LisectAVT_2403002A_126.EXE.exeStatic PE information: Resource name: XIA type: Zip archive data, at least v2.0 to extract, compression method=deflate
              Source: taskdl.exe.0.drStatic PE information: Resource name: RT_VERSION type: COM executable for DOS
              Source: LisectAVT_2403002A_126.EXE.exe, 00000000.00000003.1332855923.00000000024A8000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenameLODCTR.EXEj% vs LisectAVT_2403002A_126.EXE.exe
              Source: LisectAVT_2403002A_126.EXE.exe, 00000000.00000003.1788283067.0000000000AFE000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenameLODCTR.EXEj% vs LisectAVT_2403002A_126.EXE.exe
              Source: LisectAVT_2403002A_126.EXE.exe, 00000000.00000003.1333158366.0000000002493000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenameLODCTR.EXEj% vs LisectAVT_2403002A_126.EXE.exe
              Source: LisectAVT_2403002A_126.EXE.exe, 00000000.00000003.1364421681.0000000000AAF000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenameLODCTR.EXEj% vs LisectAVT_2403002A_126.EXE.exe
              Source: LisectAVT_2403002A_126.EXE.exe, 00000000.00000003.1374099272.0000000000ABF000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenameLODCTR.EXEj% vs LisectAVT_2403002A_126.EXE.exe
              Source: LisectAVT_2403002A_126.EXE.exe, 00000000.00000003.1355372100.0000000000AAD000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenameLODCTR.EXEj% vs LisectAVT_2403002A_126.EXE.exe
              Source: LisectAVT_2403002A_126.EXE.exeBinary or memory string: OriginalFilenamediskpart.exej% vs LisectAVT_2403002A_126.EXE.exe
              Source: LisectAVT_2403002A_126.EXE.exeStatic PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, 32BIT_MACHINE
              Source: LisectAVT_2403002A_126.EXE.exe, type: SAMPLEMatched rule: WannaCry_Ransomware date = 2017-05-12, hash1 = ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa, author = Florian Roth (with the help of binar.ly), description = Detects WannaCry Ransomware, reference = https://goo.gl/HG2j5T
              Source: LisectAVT_2403002A_126.EXE.exe, type: SAMPLEMatched rule: wanna_cry_ransomware_generic date = 2017/05/12, hash0 = 4da1f312a214c07143abeeafb695d904, author = us-cert code analysis team, description = detects wannacry ransomware on disk and in virtual page, reference = not set
              Source: LisectAVT_2403002A_126.EXE.exe, type: SAMPLEMatched rule: Win32_Ransomware_WannaCry tc_detection_name = WannaCry, tc_detection_factor = , author = ReversingLabs, tc_detection_type = Ransomware
              Source: 0.0.LisectAVT_2403002A_126.EXE.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware date = 2017-05-12, hash1 = ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa, author = Florian Roth (with the help of binar.ly), description = Detects WannaCry Ransomware, reference = https://goo.gl/HG2j5T
              Source: 0.0.LisectAVT_2403002A_126.EXE.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: wanna_cry_ransomware_generic date = 2017/05/12, hash0 = 4da1f312a214c07143abeeafb695d904, author = us-cert code analysis team, description = detects wannacry ransomware on disk and in virtual page, reference = not set
              Source: 0.0.LisectAVT_2403002A_126.EXE.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Win32_Ransomware_WannaCry tc_detection_name = WannaCry, tc_detection_factor = , author = ReversingLabs, tc_detection_type = Ransomware
              Source: 00000000.00000000.1324912594.000000000040E000.00000008.00000001.01000000.00000003.sdmp, type: MEMORYMatched rule: wanna_cry_ransomware_generic date = 2017/05/12, hash0 = 4da1f312a214c07143abeeafb695d904, author = us-cert code analysis team, description = detects wannacry ransomware on disk and in virtual page, reference = not set
              Source: C:\@Please_Read_Me@.txt, type: DROPPEDMatched rule: WannaCry_RansomNote date = 2017-05-12, hash1 = 4a25d98c121bb3bd5b54e0b6a5348f7b09966bffeec30776e5a731813f05d49e, author = Florian Roth, description = Detects WannaCry Ransomware Note, reference = https://goo.gl/HG2j5T, license = https://creativecommons.org/licenses/by-nc/4.0/
              Source: C:\Users\user\Desktop\70341721944935.bat, type: DROPPEDMatched rule: WannCry_BAT date = 2017-05-12, hash1 = f01b7f52e3cb64f01ddc248eb6ae871775ef7cb4297eba5d230d0345af9a5077, author = Florian Roth, description = Detects WannaCry Ransomware BATCH File, reference = https://goo.gl/HG2j5T, license = https://creativecommons.org/licenses/by-nc/4.0/
              Source: C:\Users\user\Desktop\70341721944935.bat, type: DROPPEDMatched rule: WannCry_BAT date = 2017-05-12, hash1 = f01b7f52e3cb64f01ddc248eb6ae871775ef7cb4297eba5d230d0345af9a5077, author = Florian Roth, description = Detects WannaCry Ransomware BATCH File, reference = https://goo.gl/HG2j5T, license = https://creativecommons.org/licenses/by-nc/4.0/
              Source: C:\Users\user\Desktop\70341721944935.bat, type: DROPPEDMatched rule: WannCry_BAT date = 2017-05-12, hash1 = f01b7f52e3cb64f01ddc248eb6ae871775ef7cb4297eba5d230d0345af9a5077, author = Florian Roth, description = Detects WannaCry Ransomware BATCH File, reference = https://goo.gl/HG2j5T, license = https://creativecommons.org/licenses/by-nc/4.0/
              Source: C:\Users\user\Desktop\70341721944935.bat, type: DROPPEDMatched rule: WannCry_BAT date = 2017-05-12, hash1 = f01b7f52e3cb64f01ddc248eb6ae871775ef7cb4297eba5d230d0345af9a5077, author = Florian Roth, description = Detects WannaCry Ransomware BATCH File, reference = https://goo.gl/HG2j5T, license = https://creativecommons.org/licenses/by-nc/4.0/
              Source: C:\Users\user\Desktop\70341721944935.bat, type: DROPPEDMatched rule: WannCry_BAT date = 2017-05-12, hash1 = f01b7f52e3cb64f01ddc248eb6ae871775ef7cb4297eba5d230d0345af9a5077, author = Florian Roth, description = Detects WannaCry Ransomware BATCH File, reference = https://goo.gl/HG2j5T, license = https://creativecommons.org/licenses/by-nc/4.0/
              Source: C:\Users\user\Desktop\70341721944935.bat, type: DROPPEDMatched rule: WannCry_BAT date = 2017-05-12, hash1 = f01b7f52e3cb64f01ddc248eb6ae871775ef7cb4297eba5d230d0345af9a5077, author = Florian Roth, description = Detects WannaCry Ransomware BATCH File, reference = https://goo.gl/HG2j5T, license = https://creativecommons.org/licenses/by-nc/4.0/
              Source: C:\Users\user\Desktop\70341721944935.bat, type: DROPPEDMatched rule: WannCry_BAT date = 2017-05-12, hash1 = f01b7f52e3cb64f01ddc248eb6ae871775ef7cb4297eba5d230d0345af9a5077, author = Florian Roth, description = Detects WannaCry Ransomware BATCH File, reference = https://goo.gl/HG2j5T, license = https://creativecommons.org/licenses/by-nc/4.0/
              Source: C:\Users\user\Desktop\70341721944935.bat, type: DROPPEDMatched rule: WannCry_BAT date = 2017-05-12, hash1 = f01b7f52e3cb64f01ddc248eb6ae871775ef7cb4297eba5d230d0345af9a5077, author = Florian Roth, description = Detects WannaCry Ransomware BATCH File, reference = https://goo.gl/HG2j5T, license = https://creativecommons.org/licenses/by-nc/4.0/
              Source: C:\Users\user\Desktop\70341721944935.bat, type: DROPPEDMatched rule: WannCry_BAT date = 2017-05-12, hash1 = f01b7f52e3cb64f01ddc248eb6ae871775ef7cb4297eba5d230d0345af9a5077, author = Florian Roth, description = Detects WannaCry Ransomware BATCH File, reference = https://goo.gl/HG2j5T, license = https://creativecommons.org/licenses/by-nc/4.0/
              Source: C:\Users\user\Desktop\70341721944935.bat, type: DROPPEDMatched rule: WannCry_BAT date = 2017-05-12, hash1 = f01b7f52e3cb64f01ddc248eb6ae871775ef7cb4297eba5d230d0345af9a5077, author = Florian Roth, description = Detects WannaCry Ransomware BATCH File, reference = https://goo.gl/HG2j5T, license = https://creativecommons.org/licenses/by-nc/4.0/
              Source: C:\Users\user\Desktop\70341721944935.bat, type: DROPPEDMatched rule: WannCry_BAT date = 2017-05-12, hash1 = f01b7f52e3cb64f01ddc248eb6ae871775ef7cb4297eba5d230d0345af9a5077, author = Florian Roth, description = Detects WannaCry Ransomware BATCH File, reference = https://goo.gl/HG2j5T, license = https://creativecommons.org/licenses/by-nc/4.0/
              Source: C:\Users\user\Desktop\70341721944935.bat, type: DROPPEDMatched rule: WannCry_BAT date = 2017-05-12, hash1 = f01b7f52e3cb64f01ddc248eb6ae871775ef7cb4297eba5d230d0345af9a5077, author = Florian Roth, description = Detects WannaCry Ransomware BATCH File, reference = https://goo.gl/HG2j5T, license = https://creativecommons.org/licenses/by-nc/4.0/
              Source: C:\Users\user\Desktop\70341721944935.bat, type: DROPPEDMatched rule: WannCry_BAT date = 2017-05-12, hash1 = f01b7f52e3cb64f01ddc248eb6ae871775ef7cb4297eba5d230d0345af9a5077, author = Florian Roth, description = Detects WannaCry Ransomware BATCH File, reference = https://goo.gl/HG2j5T, license = https://creativecommons.org/licenses/by-nc/4.0/
              Source: C:\Users\user\Desktop\70341721944935.bat, type: DROPPEDMatched rule: WannCry_BAT date = 2017-05-12, hash1 = f01b7f52e3cb64f01ddc248eb6ae871775ef7cb4297eba5d230d0345af9a5077, author = Florian Roth, description = Detects WannaCry Ransomware BATCH File, reference = https://goo.gl/HG2j5T, license = https://creativecommons.org/licenses/by-nc/4.0/
              Source: C:\Users\user\Desktop\70341721944935.bat, type: DROPPEDMatched rule: WannCry_BAT date = 2017-05-12, hash1 = f01b7f52e3cb64f01ddc248eb6ae871775ef7cb4297eba5d230d0345af9a5077, author = Florian Roth, description = Detects WannaCry Ransomware BATCH File, reference = https://goo.gl/HG2j5T, license = https://creativecommons.org/licenses/by-nc/4.0/
              Source: C:\Users\user\Desktop\70341721944935.bat, type: DROPPEDMatched rule: WannCry_BAT date = 2017-05-12, hash1 = f01b7f52e3cb64f01ddc248eb6ae871775ef7cb4297eba5d230d0345af9a5077, author = Florian Roth, description = Detects WannaCry Ransomware BATCH File, reference = https://goo.gl/HG2j5T, license = https://creativecommons.org/licenses/by-nc/4.0/
              Source: C:\Users\user\Desktop\70341721944935.bat, type: DROPPEDMatched rule: WannCry_BAT date = 2017-05-12, hash1 = f01b7f52e3cb64f01ddc248eb6ae871775ef7cb4297eba5d230d0345af9a5077, author = Florian Roth, description = Detects WannaCry Ransomware BATCH File, reference = https://goo.gl/HG2j5T, license = https://creativecommons.org/licenses/by-nc/4.0/
              Source: C:\Users\user\Desktop\70341721944935.bat, type: DROPPEDMatched rule: WannCry_BAT date = 2017-05-12, hash1 = f01b7f52e3cb64f01ddc248eb6ae871775ef7cb4297eba5d230d0345af9a5077, author = Florian Roth, description = Detects WannaCry Ransomware BATCH File, reference = https://goo.gl/HG2j5T, license = https://creativecommons.org/licenses/by-nc/4.0/
              Source: C:\@WanaDecryptor@.exe, type: DROPPEDMatched rule: Win32_Ransomware_WannaCry tc_detection_name = WannaCry, tc_detection_factor = , author = ReversingLabs, tc_detection_type = Ransomware
              Source: C:\@WanaDecryptor@.exe, type: DROPPEDMatched rule: Win32_Ransomware_WannaCry tc_detection_name = WannaCry, tc_detection_factor = , author = ReversingLabs, tc_detection_type = Ransomware
              Source: C:\Users\user\Desktop\u.wnry, type: DROPPEDMatched rule: Win32_Ransomware_WannaCry tc_detection_name = WannaCry, tc_detection_factor = , author = ReversingLabs, tc_detection_type = Ransomware
              Source: C:\Users\user\Desktop\u.wnry, type: DROPPEDMatched rule: Win32_Ransomware_WannaCry tc_detection_name = WannaCry, tc_detection_factor = , author = ReversingLabs, tc_detection_type = Ransomware
              Source: C:\Users\user\Desktop\u.wnry, type: DROPPEDMatched rule: Win32_Ransomware_WannaCry tc_detection_name = WannaCry, tc_detection_factor = , author = ReversingLabs, tc_detection_type = Ransomware
              Source: C:\Users\user\Desktop\u.wnry, type: DROPPEDMatched rule: Win32_Ransomware_WannaCry tc_detection_name = WannaCry, tc_detection_factor = , author = ReversingLabs, tc_detection_type = Ransomware
              Source: C:\Users\user\Desktop\u.wnry, type: DROPPEDMatched rule: Win32_Ransomware_WannaCry tc_detection_name = WannaCry, tc_detection_factor = , author = ReversingLabs, tc_detection_type = Ransomware
              Source: C:\Users\user\Desktop\u.wnry, type: DROPPEDMatched rule: Win32_Ransomware_WannaCry tc_detection_name = WannaCry, tc_detection_factor = , author = ReversingLabs, tc_detection_type = Ransomware
              Source: C:\Users\user\Desktop\u.wnry, type: DROPPEDMatched rule: Win32_Ransomware_WannaCry tc_detection_name = WannaCry, tc_detection_factor = , author = ReversingLabs, tc_detection_type = Ransomware
              Source: C:\Users\user\Desktop\u.wnry, type: DROPPEDMatched rule: Win32_Ransomware_WannaCry tc_detection_name = WannaCry, tc_detection_factor = , author = ReversingLabs, tc_detection_type = Ransomware
              Source: C:\Users\user\Desktop\u.wnry, type: DROPPEDMatched rule: Win32_Ransomware_WannaCry tc_detection_name = WannaCry, tc_detection_factor = , author = ReversingLabs, tc_detection_type = Ransomware
              Source: C:\Users\user\Desktop\r.wnry, type: DROPPEDMatched rule: WannaCry_RansomNote date = 2017-05-12, hash1 = 4a25d98c121bb3bd5b54e0b6a5348f7b09966bffeec30776e5a731813f05d49e, author = Florian Roth, description = Detects WannaCry Ransomware Note, reference = https://goo.gl/HG2j5T, license = https://creativecommons.org/licenses/by-nc/4.0/
              Source: C:\Users\user\Desktop\r.wnry, type: DROPPEDMatched rule: WannaCry_RansomNote date = 2017-05-12, hash1 = 4a25d98c121bb3bd5b54e0b6a5348f7b09966bffeec30776e5a731813f05d49e, author = Florian Roth, description = Detects WannaCry Ransomware Note, reference = https://goo.gl/HG2j5T, license = https://creativecommons.org/licenses/by-nc/4.0/
              Source: C:\Users\user\Desktop\r.wnry, type: DROPPEDMatched rule: WannaCry_RansomNote date = 2017-05-12, hash1 = 4a25d98c121bb3bd5b54e0b6a5348f7b09966bffeec30776e5a731813f05d49e, author = Florian Roth, description = Detects WannaCry Ransomware Note, reference = https://goo.gl/HG2j5T, license = https://creativecommons.org/licenses/by-nc/4.0/
              Source: C:\Users\user\Desktop\r.wnry, type: DROPPEDMatched rule: WannaCry_RansomNote date = 2017-05-12, hash1 = 4a25d98c121bb3bd5b54e0b6a5348f7b09966bffeec30776e5a731813f05d49e, author = Florian Roth, description = Detects WannaCry Ransomware Note, reference = https://goo.gl/HG2j5T, license = https://creativecommons.org/licenses/by-nc/4.0/
              Source: C:\Users\user\Desktop\r.wnry, type: DROPPEDMatched rule: WannaCry_RansomNote date = 2017-05-12, hash1 = 4a25d98c121bb3bd5b54e0b6a5348f7b09966bffeec30776e5a731813f05d49e, author = Florian Roth, description = Detects WannaCry Ransomware Note, reference = https://goo.gl/HG2j5T, license = https://creativecommons.org/licenses/by-nc/4.0/
              Source: C:\Users\user\Desktop\r.wnry, type: DROPPEDMatched rule: WannaCry_RansomNote date = 2017-05-12, hash1 = 4a25d98c121bb3bd5b54e0b6a5348f7b09966bffeec30776e5a731813f05d49e, author = Florian Roth, description = Detects WannaCry Ransomware Note, reference = https://goo.gl/HG2j5T, license = https://creativecommons.org/licenses/by-nc/4.0/
              Source: C:\Users\user\Desktop\r.wnry, type: DROPPEDMatched rule: WannaCry_RansomNote date = 2017-05-12, hash1 = 4a25d98c121bb3bd5b54e0b6a5348f7b09966bffeec30776e5a731813f05d49e, author = Florian Roth, description = Detects WannaCry Ransomware Note, reference = https://goo.gl/HG2j5T, license = https://creativecommons.org/licenses/by-nc/4.0/
              Source: f.wnry.0.drBinary string: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\background.png.WNCRY
              Source: LisectAVT_2403002A_126.EXE.exe, 00000000.00000003.1788283067.0000000000AFE000.00000004.00000020.00020000.00000000.sdmp, LisectAVT_2403002A_126.EXE.exe, 00000000.00000003.1364421681.0000000000AAF000.00000004.00000020.00020000.00000000.sdmp, LisectAVT_2403002A_126.EXE.exe, 00000000.00000003.1374099272.0000000000ABF000.00000004.00000020.00020000.00000000.sdmp, LisectAVT_2403002A_126.EXE.exe, 00000000.00000003.1355372100.0000000000AAD000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: A.der.pfx.key.crt.csr.p12.pem.odt.ott.sxw.stw.uot.3ds.max.3dm.ods.ots.sxc.stc.dif.slk.wb2.odp.otp.sxd.std.uop.odg.otg.sxm.mml.lay.lay6.asc.sqlite3.sqlitedb.sql.accdb.mdb.db.dbf.odb.frm.myd.myi.ibd.mdf.ldf.sln.suo.cs.c.cpp.pas.h.asm.js.cmd.bat.ps1.vbs.vb.pl.dip.dch.sch.brd.jsp.php.asp.rb.java.jar.class.sh.mp3.wav.swf.fla.wmv.mpg.vob.mpeg.asf.avi.mov.mp4.3gp.mkv.3g2.flv.wma.mid.m3u.m4u.djvu.svg.ai.psd.nef.tiff.tif.cgm.raw.gif.png.bmp.jpg.jpeg.vcd.iso.backup.zip.rar.7z.gz.tgz.tar.bak.tbk.bz2.PAQ.ARC.aes.gpg.vmx.vmdk.vdi.sldm.sldx.sti.sxi.602.hwp.snt.onetoc2.dwg.pdf.wk1.wks.123.rtf.csv.txt.vsdx.vsd.edb.eml.msg.ost.pst.potm.potx.ppam.ppsx.ppsm.pps.pot.pptm.pptx.ppt.xltm.xltx.xlc.xlm.xlt.xlw.xlsb.xlsm.xlsx.xls.dotx.dotm.dot.docm.docb.docx.docConnecting to server...s.wnry%08X.eky%08X.res00000000.resrb%08X.dky%08X.pkyConnectedSent requestSucceedReceived responseCongratulations! Your payment has been checked!
              Source: iconcache_256.db.WNCRYT.0.drBinary or memory string: .SlnY
              Source: LisectAVT_2403002A_126.EXE.exeBinary or memory string: @.der.pfx.key.crt.csr.p12.pem.odt.ott.sxw.stw.uot.3ds.max.3dm.ods.ots.sxc.stc.dif.slk.wb2.odp.otp.sxd.std.uop.odg.otg.sxm.mml.lay.lay6.asc.sqlite3.sqlitedb.sql.accdb.mdb.db.dbf.odb.frm.myd.myi.ibd.mdf.ldf.sln.suo.cs.c.cpp.pas.h.asm.js.cmd.bat.ps1.vbs.vb.pl.dip.dch.sch.brd.jsp.php.asp.rb.java.jar.class.sh.mp3.wav.swf.fla.wmv.mpg.vob.mpeg.asf.avi.mov.mp4.3gp.mkv.3g2.flv.wma.mid.m3u.m4u.djvu.svg.ai.psd.nef.tiff.tif.cgm.raw.gif.png.bmp.jpg.jpeg.vcd.iso.backup.zip.rar.7z.gz.tgz.tar.bak.tbk.bz2.PAQ.ARC.aes.gpg.vmx.vmdk.vdi.sldm.sldx.sti.sxi.602.hwp.snt.onetoc2.dwg.pdf.wk1.wks.123.rtf.csv.txt.vsdx.vsd.edb.eml.msg.ost.pst.potm.potx.ppam.ppsx.ppsm.pps.pot.pptm.pptx.ppt.xltm.xltx.xlc.xlm.xlt.xlw.xlsb.xlsm.xlsx.xls.dotx.dotm.dot.docm.docb.docx.docWANACRY!%s\%sCloseHandleDeleteFileWMoveFileExWMoveFileWReadFileWriteFileCreateFileWkernel32.dll
              Source: classification engineClassification label: mal100.rans.evad.winEXE@790/973@0/0
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Users\user\Desktop\b.wnryJump to behavior
              Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:7584:120:WilError_03
              Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:7724:120:WilError_03
              Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:7576:120:WilError_03
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeMutant created: \Sessions\1\BaseNamedObjects\MsWinZonesCacheCounterMutexA
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeMutant created: \Sessions\1\BaseNamedObjects\Global\MsWinZonesCacheCounterMutexA0
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Diagnosis\Temp\~SD48A5.tmpJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c 70341721944935.bat
              Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\cscript.exe cscript.exe //nologo m.vbs
              Source: LisectAVT_2403002A_126.EXE.exeStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
              Source: C:\Windows\SysWOW64\cscript.exeFile read: C:\Users\desktop.ini
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
              Source: C:\Users\user\Desktop\taskdl.exeEvasive API call chain: __getmainargs,DecisionNodes,exitgraph_6-217
              Source: unknownProcess created: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe "C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe"
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: C:\Windows\SysWOW64\attrib.exe attrib +h .
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: C:\Windows\SysWOW64\icacls.exe icacls . /grant Everyone:F /T /C /Q
              Source: C:\Windows\SysWOW64\attrib.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
              Source: C:\Windows\SysWOW64\icacls.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: C:\Users\user\Desktop\taskdl.exe taskdl.exe
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c 70341721944935.bat
              Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: C:\Users\user\Desktop\taskdl.exe taskdl.exe
              Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\cscript.exe cscript.exe //nologo m.vbs
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: C:\Users\user\Desktop\taskdl.exe taskdl.exe
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: C:\Users\user\Desktop\taskdl.exe taskdl.exe
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: C:\Users\user\Desktop\taskdl.exe taskdl.exe
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: C:\Users\user\Desktop\taskdl.exe taskdl.exe
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: C:\Users\user\Desktop\taskdl.exe taskdl.exe
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: C:\Users\user\Desktop\taskdl.exe taskdl.exe
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: C:\Users\user\Desktop\taskdl.exe taskdl.exe
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: C:\Users\user\Desktop\taskdl.exe taskdl.exe
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: C:\Users\user\Desktop\taskdl.exe taskdl.exe
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: C:\Users\user\Desktop\taskdl.exe taskdl.exe
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: C:\Users\user\Desktop\taskdl.exe taskdl.exe
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: C:\Users\user\Desktop\taskdl.exe taskdl.exe
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: C:\Users\user\Desktop\taskdl.exe taskdl.exe
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: C:\Users\user\Desktop\taskdl.exe taskdl.exe
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: C:\Users\user\Desktop\taskdl.exe taskdl.exe
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: C:\Users\user\Desktop\taskdl.exe taskdl.exe
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: C:\Users\user\Desktop\taskdl.exe taskdl.exe
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: C:\Users\user\Desktop\taskdl.exe taskdl.exe
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: C:\Users\user\Desktop\taskdl.exe taskdl.exe
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: C:\Users\user\Desktop\taskdl.exe taskdl.exe
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: C:\Users\user\Desktop\taskdl.exe taskdl.exe
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: C:\Users\user\Desktop\taskdl.exe taskdl.exe
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: C:\Users\user\Desktop\taskdl.exe taskdl.exe
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: C:\Users\user\Desktop\taskdl.exe taskdl.exe
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: C:\Users\user\Desktop\taskdl.exe taskdl.exe
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: C:\Users\user\Desktop\taskdl.exe taskdl.exe
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: C:\Users\user\Desktop\taskdl.exe taskdl.exe
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: C:\Users\user\Desktop\taskdl.exe taskdl.exe
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: C:\Users\user\Desktop\taskdl.exe taskdl.exe
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: C:\Users\user\Desktop\taskdl.exe taskdl.exe
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: C:\Users\user\Desktop\taskdl.exe taskdl.exe
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: C:\Users\user\Desktop\taskdl.exe taskdl.exe
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: C:\Windows\SysWOW64\attrib.exe attrib +h .Jump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: C:\Windows\SysWOW64\icacls.exe icacls . /grant Everyone:F /T /C /QJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: C:\Users\user\Desktop\taskdl.exe taskdl.exeJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c 70341721944935.batJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: C:\Users\user\Desktop\taskdl.exe taskdl.exeJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: C:\Users\user\Desktop\taskdl.exe taskdl.exeJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: C:\Users\user\Desktop\taskdl.exe taskdl.exeJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: C:\Users\user\Desktop\taskdl.exe taskdl.exeJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: C:\Users\user\Desktop\taskdl.exe taskdl.exeJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: C:\Users\user\Desktop\taskdl.exe taskdl.exeJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: C:\Users\user\Desktop\taskdl.exe taskdl.exeJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: C:\Users\user\Desktop\taskdl.exe taskdl.exeJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: C:\Users\user\Desktop\taskdl.exe taskdl.exeJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: C:\Users\user\Desktop\taskdl.exe taskdl.exeJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: C:\Users\user\Desktop\taskdl.exe taskdl.exeJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: C:\Users\user\Desktop\taskdl.exe taskdl.exeJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: C:\Users\user\Desktop\taskdl.exe taskdl.exeJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: C:\Users\user\Desktop\taskdl.exe taskdl.exeJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: C:\Users\user\Desktop\taskdl.exe taskdl.exeJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: C:\Users\user\Desktop\taskdl.exe taskdl.exeJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: C:\Users\user\Desktop\taskdl.exe taskdl.exeJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: C:\Users\user\Desktop\taskdl.exe taskdl.exeJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: C:\Users\user\Desktop\taskdl.exe taskdl.exeJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: C:\Users\user\Desktop\taskdl.exe taskdl.exeJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: C:\Users\user\Desktop\taskdl.exe taskdl.exeJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: C:\Users\user\Desktop\taskdl.exe taskdl.exeJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: C:\Users\user\Desktop\taskdl.exe taskdl.exeJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: C:\Users\user\Desktop\taskdl.exe taskdl.exeJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: C:\Users\user\Desktop\taskdl.exe taskdl.exeJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: C:\Users\user\Desktop\taskdl.exe taskdl.exeJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: C:\Users\user\Desktop\taskdl.exe taskdl.exeJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: C:\Users\user\Desktop\taskdl.exe taskdl.exeJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: C:\Users\user\Desktop\taskdl.exe taskdl.exeJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: C:\Users\user\Desktop\taskdl.exe taskdl.exeJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: C:\Users\user\Desktop\taskdl.exe taskdl.exeJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: C:\Users\user\Desktop\taskdl.exe taskdl.exeJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: C:\Users\user\Desktop\taskdl.exe taskdl.exeJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: C:\Users\user\Desktop\taskdl.exe taskdl.exeJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: C:\Users\user\Desktop\taskdl.exe taskdl.exeJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: C:\Users\user\Desktop\taskdl.exe taskdl.exeJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: C:\Users\user\Desktop\taskdl.exe taskdl.exeJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: C:\Users\user\Desktop\taskdl.exe taskdl.exeJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1Jump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1Jump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: C:\Users\user\Desktop\taskdl.exe taskdl.exeJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: C:\Users\user\Desktop\taskdl.exe taskdl.exeJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: C:\Users\user\Desktop\taskdl.exe taskdl.exeJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: C:\Users\user\Desktop\taskdl.exe taskdl.exeJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: C:\Users\user\Desktop\taskdl.exe taskdl.exeJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: C:\Users\user\Desktop\taskdl.exe taskdl.exeJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: C:\Users\user\Desktop\taskdl.exe taskdl.exeJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: C:\Users\user\Desktop\taskdl.exe taskdl.exeJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c 70341721944935.batJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: C:\Users\user\Desktop\taskdl.exe taskdl.exeJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: C:\Users\user\Desktop\taskdl.exe taskdl.exeJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: C:\Windows\SysWOW64\icacls.exe icacls . /grant Everyone:F /T /C /QJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: C:\Users\user\Desktop\taskdl.exe taskdl.exeJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: C:\Users\user\Desktop\taskdl.exe taskdl.exeJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: C:\Users\user\Desktop\taskdl.exe taskdl.exeJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: C:\Users\user\Desktop\taskdl.exe taskdl.exeJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: C:\Users\user\Desktop\taskdl.exe taskdl.exeJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: C:\Users\user\Desktop\taskdl.exe taskdl.exeJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: C:\Users\user\Desktop\taskdl.exe taskdl.exeJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: C:\Users\user\Desktop\taskdl.exe taskdl.exeJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: C:\Users\user\Desktop\taskdl.exe taskdl.exeJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: C:\Users\user\Desktop\taskdl.exe taskdl.exeJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: C:\Users\user\Desktop\taskdl.exe taskdl.exeJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: unknown unknownJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeSection loaded: cryptsp.dllJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeSection loaded: rsaenh.dllJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeSection loaded: cryptbase.dllJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeSection loaded: msvcp60.dllJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeSection loaded: ntmarta.dllJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeSection loaded: apphelp.dllJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeSection loaded: windows.storage.dllJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeSection loaded: wldp.dllJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeSection loaded: sspicli.dllJump to behavior
              Source: C:\Windows\SysWOW64\attrib.exeSection loaded: ulib.dll
              Source: C:\Windows\SysWOW64\attrib.exeSection loaded: fsutilext.dll
              Source: C:\Windows\SysWOW64\icacls.exeSection loaded: ntmarta.dll
              Source: C:\Users\user\Desktop\taskdl.exeSection loaded: apphelp.dll
              Source: C:\Users\user\Desktop\taskdl.exeSection loaded: msvcp60.dll
              Source: C:\Windows\SysWOW64\cmd.exeSection loaded: cmdext.dll
              Source: C:\Users\user\Desktop\taskdl.exeSection loaded: msvcp60.dll
              Source: C:\Windows\SysWOW64\cscript.exeSection loaded: version.dll
              Source: C:\Windows\SysWOW64\cscript.exeSection loaded: kernel.appcore.dll
              Source: C:\Windows\SysWOW64\cscript.exeSection loaded: uxtheme.dll
              Source: C:\Windows\SysWOW64\cscript.exeSection loaded: sxs.dll
              Source: C:\Windows\SysWOW64\cscript.exeSection loaded: vbscript.dll
              Source: C:\Windows\SysWOW64\cscript.exeSection loaded: amsi.dll
              Source: C:\Windows\SysWOW64\cscript.exeSection loaded: userenv.dll
              Source: C:\Windows\SysWOW64\cscript.exeSection loaded: profapi.dll
              Source: C:\Windows\SysWOW64\cscript.exeSection loaded: wldp.dll
              Source: C:\Windows\SysWOW64\cscript.exeSection loaded: msasn1.dll
              Source: C:\Windows\SysWOW64\cscript.exeSection loaded: cryptsp.dll
              Source: C:\Windows\SysWOW64\cscript.exeSection loaded: rsaenh.dll
              Source: C:\Windows\SysWOW64\cscript.exeSection loaded: cryptbase.dll
              Source: C:\Windows\SysWOW64\cscript.exeSection loaded: msisip.dll
              Source: C:\Windows\SysWOW64\cscript.exeSection loaded: wshext.dll
              Source: C:\Windows\SysWOW64\cscript.exeSection loaded: scrobj.dll
              Source: C:\Windows\SysWOW64\cscript.exeSection loaded: mpr.dll
              Source: C:\Windows\SysWOW64\cscript.exeSection loaded: scrrun.dll
              Source: C:\Windows\SysWOW64\cscript.exeSection loaded: windows.storage.dll
              Source: C:\Windows\SysWOW64\cscript.exeSection loaded: propsys.dll
              Source: C:\Windows\SysWOW64\cscript.exeSection loaded: linkinfo.dll
              Source: C:\Windows\SysWOW64\cscript.exeSection loaded: ntshrui.dll
              Source: C:\Windows\SysWOW64\cscript.exeSection loaded: sspicli.dll
              Source: C:\Windows\SysWOW64\cscript.exeSection loaded: srvcli.dll
              Source: C:\Windows\SysWOW64\cscript.exeSection loaded: cscapi.dll
              Source: C:\Windows\SysWOW64\cscript.exeSection loaded: netutils.dll
              Source: C:\Users\user\Desktop\taskdl.exeSection loaded: msvcp60.dll
              Source: C:\Users\user\Desktop\taskdl.exeSection loaded: msvcp60.dll
              Source: C:\Users\user\Desktop\taskdl.exeSection loaded: msvcp60.dll
              Source: C:\Users\user\Desktop\taskdl.exeSection loaded: msvcp60.dll
              Source: C:\Users\user\Desktop\taskdl.exeSection loaded: msvcp60.dll
              Source: C:\Users\user\Desktop\taskdl.exeSection loaded: msvcp60.dll
              Source: C:\Users\user\Desktop\taskdl.exeSection loaded: msvcp60.dll
              Source: C:\Users\user\Desktop\taskdl.exeSection loaded: msvcp60.dll
              Source: C:\Users\user\Desktop\taskdl.exeSection loaded: msvcp60.dll
              Source: C:\Users\user\Desktop\taskdl.exeSection loaded: msvcp60.dll
              Source: C:\Users\user\Desktop\taskdl.exeSection loaded: msvcp60.dll
              Source: C:\Users\user\Desktop\taskdl.exeSection loaded: msvcp60.dll
              Source: C:\Users\user\Desktop\taskdl.exeSection loaded: msvcp60.dll
              Source: C:\Users\user\Desktop\taskdl.exeSection loaded: msvcp60.dll
              Source: C:\Users\user\Desktop\taskdl.exeSection loaded: msvcp60.dll
              Source: C:\Users\user\Desktop\taskdl.exeSection loaded: msvcp60.dll
              Source: C:\Users\user\Desktop\taskdl.exeSection loaded: msvcp60.dll
              Source: C:\Users\user\Desktop\taskdl.exeSection loaded: msvcp60.dll
              Source: C:\Users\user\Desktop\taskdl.exeSection loaded: msvcp60.dll
              Source: C:\Users\user\Desktop\taskdl.exeSection loaded: msvcp60.dll
              Source: C:\Users\user\Desktop\taskdl.exeSection loaded: msvcp60.dll
              Source: C:\Users\user\Desktop\taskdl.exeSection loaded: msvcp60.dll
              Source: C:\Users\user\Desktop\taskdl.exeSection loaded: msvcp60.dll
              Source: C:\Users\user\Desktop\taskdl.exeSection loaded: msvcp60.dll
              Source: C:\Users\user\Desktop\taskdl.exeSection loaded: msvcp60.dll
              Source: C:\Users\user\Desktop\taskdl.exeSection loaded: msvcp60.dll
              Source: C:\Users\user\Desktop\taskdl.exeSection loaded: msvcp60.dll
              Source: C:\Users\user\Desktop\taskdl.exeSection loaded: msvcp60.dll
              Source: C:\Users\user\Desktop\taskdl.exeSection loaded: msvcp60.dll
              Source: C:\Users\user\Desktop\taskdl.exeSection loaded: msvcp60.dll
              Source: C:\Users\user\Desktop\taskdl.exeSection loaded: msvcp60.dll
              Source: C:\Users\user\Desktop\taskdl.exeSection loaded: msvcp60.dll
              Source: C:\Windows\SysWOW64\cscript.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{B54F3741-5B07-11cf-A4B0-00AA004A55E8}\InprocServer32
              Source: LisectAVT_2403002A_126.EXE.exeStatic file information: File size 3514376 > 1048576
              Source: LisectAVT_2403002A_126.EXE.exeStatic PE information: Raw size of .rsrc is bigger than: 0x100000 < 0x34a000
              Source: Binary string: ntkrnlmp.pdb source: LisectAVT_2403002A_126.EXE.exe, 00000000.00000003.2608335757.0000000000B12000.00000004.00000020.00020000.00000000.sdmp
              Source: Binary string: NGLCLI~2.LOGntkrnlmp.pdbrx source: LisectAVT_2403002A_126.EXE.exe, 00000000.00000003.2608335757.0000000000B12000.00000004.00000020.00020000.00000000.sdmp
              Source: Binary string: WINLOA~1.PDBwinload_prod.pdb23.6.20320.6 2023-10-05 10-15-18-157.logT source: LisectAVT_2403002A_126.EXE.exe, 00000000.00000003.2608335757.0000000000B12000.00000004.00000020.00020000.00000000.sdmp

              Persistence and Installation Behavior

              barindex
              Source: C:\Windows\SysWOW64\cmd.exeFile created: C:\Users\user\Desktop\m.vbs
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Users\user\Documents\@WanaDecryptor@.exeJump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: attrib.exe
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: attrib.exeJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: attrib.exeJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Users\user\Downloads\@WanaDecryptor@.exeJump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Users\user\Desktop\@WanaDecryptor@.exeJump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Users\user\Documents\@WanaDecryptor@.exeJump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Users\user\AppData\Local\@WanaDecryptor@.exeJump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\@WanaDecryptor@.exeJump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Users\user\Desktop\taskdl.exeJump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Users\user\Desktop\u.wnryJump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Users\user\Desktop\taskse.exeJump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Users\user\Desktop\u.wnryJump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\~SDA7C1.tmpJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\~SDA7C2.tmpJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Java\~SDA7C3.tmpJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\~SD77B.tmpJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\~SD77C.tmpJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\~SD7CE7.tmpJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\~SD7CE8.tmpJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\7-Zip\~SD7CE9.tmpJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Accessibility\~SD7CEA.tmpJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Accessories\~SD7CEB.tmpJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Administrative Tools\~SD7CFC.tmpJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\AutoIt v3\~SD7CFD.tmpJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\AutoIt v3\Extras\~SD7CFE.tmpJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Java\~SD7D0E.tmpJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Maintenance\~SD7D0F.tmpJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\StartUp\~SD7D10.tmpJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\System Tools\~SD7D11.tmpJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Windows PowerShell\~SD7D12.tmpJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\~SD3BC9.tmpJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\~SD3BCA.tmpJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\7-Zip\~SD3BCB.tmpJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Accessibility\~SD3BCC.tmpJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Accessories\~SD3BCD.tmpJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Administrative Tools\~SD3BCE.tmpJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\AutoIt v3\~SD3BCF.tmpJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\AutoIt v3\Extras\~SD3BD0.tmpJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Java\~SD3BD1.tmpJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Maintenance\~SD3BE2.tmpJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\StartUp\~SD3BE3.tmpJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\System Tools\~SD3BE4.tmpJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\~SD3BF5.tmpJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\~SD860E.tmpJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\~SD860F.tmpJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\7-Zip\~SD8610.tmpJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Accessibility\~SD8611.tmpJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Accessories\~SD8612.tmpJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Accessories\System Tools\~SD8613.tmpJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Administrative Tools\~SD8614.tmpJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\AutoIt v3\~SDFAE7.tmpJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\AutoIt v3\Extras\~SDFAE8.tmpJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\AutoIt v3\Extras\AutoItX\~SDFAE9.tmpJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Java\~SDFAEA.tmpJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Maintenance\~SDFAEB.tmpJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Microsoft Office Tools\~SDFAEC.tmpJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\StartUp\~SDFAFD.tmpJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\System Tools\~SD6FC0.tmpJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Windows PowerShell\~SD6FC1.tmpJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\~SD665.tmpJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\~SD676.tmpJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\7-Zip\~SD677.tmpJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Accessibility\~SD678.tmpJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Accessories\~SD679.tmpJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\~SD689.tmpJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Administrative Tools\~SD69A.tmpJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\AutoIt v3\~SD69B.tmpJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\AutoIt v3\Extras\~SD7B6E.tmpJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\AutoIt v3\Extras\AutoItX\~SD7B6F.tmpJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Java\~SD7B70.tmpJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Maintenance\~SD7B81.tmpJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Microsoft Office Tools\~SD7B82.tmpJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\StartUp\~SD7B93.tmpJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\System Tools\~SD7BA3.tmpJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\~SD7BA4.tmpJump to behavior

              Hooking and other Techniques for Hiding and Protection

              barindex
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile created: C:\$Recycle.Bin\~SDE94A.tmpJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeProcess created: C:\Windows\SysWOW64\icacls.exe icacls . /grant Everyone:F /T /C /Q
              Source: C:\Windows\SysWOW64\cmd.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Windows\SysWOW64\cscript.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Windows\SysWOW64\cscript.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeWindow / User API: threadDelayed 1238
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeWindow / User API: threadDelayed 7152
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeDropped PE file which has not been started: C:\Users\user\Downloads\@WanaDecryptor@.exeJump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeDropped PE file which has not been started: C:\Users\user\Desktop\@WanaDecryptor@.exeJump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeDropped PE file which has not been started: C:\Users\user\Documents\@WanaDecryptor@.exeJump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\@WanaDecryptor@.exeJump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeDropped PE file which has not been started: C:\@WanaDecryptor@.exeJump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeDropped PE file which has not been started: C:\Users\user\Desktop\u.wnryJump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeDropped PE file which has not been started: C:\Users\user\Desktop\taskse.exeJump to dropped file
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe TID: 7680Thread sleep time: -35000s >= -30000s
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe TID: 7684Thread sleep count: 1238 > 30
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe TID: 7684Thread sleep time: -3714000s >= -30000s
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe TID: 7708Thread sleep time: -870000s >= -30000s
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe TID: 7688Thread sleep time: -210000s >= -30000s
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe TID: 7684Thread sleep count: 7152 > 30
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe TID: 7684Thread sleep time: -21456000s >= -30000s
              Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
              Source: C:\Users\user\Desktop\taskdl.exeLast function: Thread delayed
              Source: C:\Users\user\Desktop\taskdl.exeLast function: Thread delayed
              Source: C:\Users\user\Desktop\taskdl.exeLast function: Thread delayed
              Source: C:\Users\user\Desktop\taskdl.exeLast function: Thread delayed
              Source: C:\Users\user\Desktop\taskdl.exeLast function: Thread delayed
              Source: C:\Users\user\Desktop\taskdl.exeLast function: Thread delayed
              Source: C:\Users\user\Desktop\taskdl.exeLast function: Thread delayed
              Source: C:\Users\user\Desktop\taskdl.exeLast function: Thread delayed
              Source: C:\Users\user\Desktop\taskdl.exeLast function: Thread delayed
              Source: C:\Users\user\Desktop\taskdl.exeLast function: Thread delayed
              Source: C:\Users\user\Desktop\taskdl.exeLast function: Thread delayed
              Source: C:\Users\user\Desktop\taskdl.exeLast function: Thread delayed
              Source: C:\Users\user\Desktop\taskdl.exeLast function: Thread delayed
              Source: C:\Users\user\Desktop\taskdl.exeLast function: Thread delayed
              Source: C:\Users\user\Desktop\taskdl.exeLast function: Thread delayed
              Source: C:\Users\user\Desktop\taskdl.exeLast function: Thread delayed
              Source: C:\Users\user\Desktop\taskdl.exeLast function: Thread delayed
              Source: C:\Users\user\Desktop\taskdl.exeLast function: Thread delayed
              Source: C:\Users\user\Desktop\taskdl.exeLast function: Thread delayed
              Source: C:\Users\user\Desktop\taskdl.exeLast function: Thread delayed
              Source: C:\Users\user\Desktop\taskdl.exeLast function: Thread delayed
              Source: C:\Users\user\Desktop\taskdl.exeLast function: Thread delayed
              Source: C:\Users\user\Desktop\taskdl.exeLast function: Thread delayed
              Source: C:\Users\user\Desktop\taskdl.exeLast function: Thread delayed
              Source: C:\Users\user\Desktop\taskdl.exeLast function: Thread delayed
              Source: C:\Users\user\Desktop\taskdl.exeCode function: 6_2_00401080 GetDriveTypeW,Sleep,swprintf,swprintf,FindFirstFileW,swprintf,?_Tidy@?$basic_string@GU?$char_traits@G@std@@V?$allocator@G@2@@std@@AAEX_N@Z,wcslen,?_Grow@?$basic_string@GU?$char_traits@G@std@@V?$allocator@G@2@@std@@AAE_NI_N@Z,?_Eos@?$basic_string@GU?$char_traits@G@std@@V?$allocator@G@2@@std@@AAEXI@Z,?_Tidy@?$basic_string@GU?$char_traits@G@std@@V?$allocator@G@2@@std@@AAEX_N@Z,FindNextFileW,FindClose,DeleteFileW,?_C@?1??_Nullstr@?$basic_string@GU?$char_traits@G@std@@V?$allocator@G@2@@std@@CAPBGXZ@4GB,?_C@?1??_Nullstr@?$basic_string@GU?$char_traits@G@std@@V?$allocator@G@2@@std@@CAPBGXZ@4GB,DeleteFileW,?_Tidy@?$basic_string@GU?$char_traits@G@std@@V?$allocator@G@2@@std@@AAEX_N@Z,?_Tidy@?$basic_string@GU?$char_traits@G@std@@V?$allocator@G@2@@std@@AAEX_N@Z,6_2_00401080
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeThread delayed: delay time: 30000
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeThread delayed: delay time: 30000
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile opened: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\~SD1D8B.tmpJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile opened: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\ClipSVC\Archive\Apps\~SD746.tmpJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile opened: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\ClipSVC\GenuineTicket\~SD747.tmpJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile opened: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\ClipSVC\~SD1DAF.tmpJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile opened: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Caches\~SD1DAE.tmpJump to behavior
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeFile opened: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\ClipSVC\Archive\~SD1DC0.tmpJump to behavior
              Source: cscript.exe, 0000000A.00000003.1358094599.0000000002A48000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: \??\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#4&224f42ef&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}
              Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\cscript.exe cscript.exe //nologo m.vbs
              Source: C:\Windows\SysWOW64\cscript.exeQueries volume information: C:\ VolumeInformation
              Source: C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuidJump to behavior
              ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
              Gather Victim Identity Information12
              Scripting
              Valid Accounts12
              Command and Scripting Interpreter
              12
              Scripting
              11
              Process Injection
              11
              Masquerading
              OS Credential Dumping1
              Security Software Discovery
              Remote ServicesData from Local SystemData ObfuscationExfiltration Over Other Network Medium1
              Data Encrypted for Impact
              CredentialsDomainsDefault Accounts1
              Native API
              1
              Registry Run Keys / Startup Folder
              1
              Registry Run Keys / Startup Folder
              11
              Virtualization/Sandbox Evasion
              LSASS Memory11
              Virtualization/Sandbox Evasion
              Remote Desktop ProtocolData from Removable MediaJunk DataExfiltration Over BluetoothNetwork Denial of Service
              Email AddressesDNS ServerDomain AccountsAt1
              Services File Permissions Weakness
              1
              Services File Permissions Weakness
              11
              Process Injection
              Security Account Manager1
              Application Window Discovery
              SMB/Windows Admin SharesData from Network Shared DriveSteganographyAutomated ExfiltrationData Encrypted for Impact
              Employee NamesVirtual Private ServerLocal AccountsCron1
              DLL Side-Loading
              1
              DLL Side-Loading
              1
              Hidden Files and Directories
              NTDS3
              File and Directory Discovery
              Distributed Component Object ModelInput CaptureProtocol ImpersonationTraffic DuplicationData Destruction
              Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon Script1
              Services File Permissions Weakness
              LSA Secrets12
              System Information Discovery
              SSHKeyloggingFallback ChannelsScheduled TransferData Encrypted for Impact
              Domain PropertiesBotnetReplication Through Removable MediaScheduled TaskRC ScriptsRC Scripts1
              DLL Side-Loading
              Cached Domain CredentialsWi-Fi DiscoveryVNCGUI Input CaptureMultiband CommunicationData Transfer Size LimitsService Stop
              DNSWeb ServicesExternal Remote ServicesSystemd TimersStartup ItemsStartup Items1
              File Deletion
              DCSyncRemote System DiscoveryWindows Remote ManagementWeb Portal CaptureCommonly Used PortExfiltration Over C2 ChannelInhibit System Recovery
              Hide Legend

              Legend:

              • Process
              • Signature
              • Created File
              • DNS/IP Info
              • Is Dropped
              • Is Windows Process
              • Number of created Registry Values
              • Number of created Files
              • Visual Basic
              • Delphi
              • Java
              • .Net C# or VB.NET
              • C, C++ or other language
              • Is malicious
              • Internet
              behaviorgraph top1 signatures2 2 Behavior Graph ID: 1482512 Sample: LisectAVT_2403002A_126.EXE.exe Startdate: 26/07/2024 Architecture: WINDOWS Score: 100 39 Malicious sample detected (through community Yara rule) 2->39 41 Antivirus detection for dropped file 2->41 43 Antivirus / Scanner detection for submitted sample 2->43 45 4 other signatures 2->45 7 LisectAVT_2403002A_126.EXE.exe 2 1001 2->7         started        process3 file4 29 C:\Users\user\Downloads\@WanaDecryptor@.exe, PE32 7->29 dropped 31 C:\Users\user\Documents\...\HTAGVDFUIE.jpg, COM 7->31 dropped 33 C:\Users\user\Documents\@WanaDecryptor@.exe, PE32 7->33 dropped 35 250 other malicious files 7->35 dropped 47 Creates files in the recycle bin to hide itself 7->47 49 Drops PE files to the document folder of the user 7->49 51 Uses cmd line tools excessively to alter registry or file data 7->51 53 3 other signatures 7->53 11 cmd.exe 7->11         started        15 attrib.exe 7->15         started        17 icacls.exe 7->17         started        19 34 other processes 7->19 signatures5 process6 file7 37 C:\Users\user\Desktop\m.vbs, ASCII 11->37 dropped 55 Command shell drops VBS files 11->55 21 conhost.exe 11->21         started        23 cscript.exe 11->23         started        25 conhost.exe 15->25         started        27 conhost.exe 17->27         started        signatures8 process9

              This section contains all screenshots as thumbnails, including those not shown in the slideshow.


              windows-stand
              SourceDetectionScannerLabelLink
              LisectAVT_2403002A_126.EXE.exe100%AviraTR/Ransom.JB
              LisectAVT_2403002A_126.EXE.exe100%Joe Sandbox ML
              SourceDetectionScannerLabelLink
              C:\@WanaDecryptor@.exe100%AviraTR/FileCoder.724645
              C:\@WanaDecryptor@.exe100%Joe Sandbox ML
              No Antivirus matches
              No Antivirus matches
              SourceDetectionScannerLabelLink
              http://schemas.micr0%URL Reputationsafe
              https://www.google.com/search?q=how0%Avira URL Cloudsafe
              http://www.btcfrog.com/qr/bitcoinPNG.php?address=%smailto:%shttps://www.google.com/search?q=how0%Avira URL Cloudsafe
              http://www.btcfrog.com/qr/bitcoinPNG.php?address=%s0%Avira URL Cloudsafe
              No contacted domains info
              NameSourceMaliciousAntivirus DetectionReputation
              http://www.btcfrog.com/qr/bitcoinPNG.php?address=%sLisectAVT_2403002A_126.EXE.exe, 00000000.00000003.1788283067.0000000000AFE000.00000004.00000020.00020000.00000000.sdmp, LisectAVT_2403002A_126.EXE.exe, 00000000.00000003.1374099272.0000000000ABF000.00000004.00000020.00020000.00000000.sdmptrue
              • Avira URL Cloud: safe
              unknown
              http://schemas.micrm_danish.wnry.0.drfalse
              • URL Reputation: safe
              unknown
              https://www.google.com/search?q=howLisectAVT_2403002A_126.EXE.exe, 00000000.00000003.1788283067.0000000000AFE000.00000004.00000020.00020000.00000000.sdmp, LisectAVT_2403002A_126.EXE.exe, 00000000.00000003.1374099272.0000000000ABF000.00000004.00000020.00020000.00000000.sdmptrue
              • Avira URL Cloud: safe
              unknown
              http://www.btcfrog.com/qr/bitcoinPNG.php?address=%smailto:%shttps://www.google.com/search?q=howLisectAVT_2403002A_126.EXE.exe, 00000000.00000003.1788283067.0000000000AFE000.00000004.00000020.00020000.00000000.sdmp, LisectAVT_2403002A_126.EXE.exe, 00000000.00000003.1374099272.0000000000ABF000.00000004.00000020.00020000.00000000.sdmptrue
              • Avira URL Cloud: safe
              unknown
              No contacted IP infos
              Joe Sandbox version:40.0.0 Tourmaline
              Analysis ID:1482512
              Start date and time:2024-07-26 00:00:53 +02:00
              Joe Sandbox product:CloudBasic
              Overall analysis duration:0h 11m 48s
              Hypervisor based Inspection enabled:false
              Report type:full
              Cookbook file name:default.jbs
              Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
              Number of analysed new started processes analysed:44
              Number of new started drivers analysed:0
              Number of existing processes analysed:0
              Number of existing drivers analysed:0
              Number of injected processes analysed:0
              Technologies:
              • HCA enabled
              • EGA enabled
              • AMSI enabled
              Analysis Mode:default
              Analysis stop reason:Timeout
              Sample name:LisectAVT_2403002A_126.EXE.exe
              Detection:MAL
              Classification:mal100.rans.evad.winEXE@790/973@0/0
              EGA Information:
              • Successful, ratio: 100%
              HCA Information:
              • Successful, ratio: 100%
              • Number of executed functions: 3
              • Number of non-executed functions: 3
              Cookbook Comments:
              • Found application associated with file extension: .exe
              • Override analysis time to 240s for sample files taking high CPU consumption
              • Behavior information exceeds normal sizes, reducing to normal. Report will have missing behavior information.
              • Exclude process from analysis (whitelisted): dllhost.exe, SIHClient.exe
              • Excluded domains from analysis (whitelisted): ocsp.digicert.com, slscr.update.microsoft.com, fe3cr.delivery.mp.microsoft.com
              • Not all processes where analyzed, report is missing behavior information
              • Report size exceeded maximum capacity and may have missing behavior information.
              • Report size getting too big, too many NtCreateFile calls found.
              • Report size getting too big, too many NtCreateKey calls found.
              • Report size getting too big, too many NtOpenFile calls found.
              • Report size getting too big, too many NtOpenKeyEx calls found.
              • Report size getting too big, too many NtQueryAttributesFile calls found.
              • Report size getting too big, too many NtQueryValueKey calls found.
              • Report size getting too big, too many NtSetInformationFile calls found.
              • Report size getting too big, too many NtSetValueKey calls found.
              • Report size getting too big, too many NtWriteFile calls found.
              • Report size getting too big, too many NtWriteVirtualMemory calls found.
              • VT rate limit hit for: LisectAVT_2403002A_126.EXE.exe
              TimeTypeDescription
              18:01:45API Interceptor5290018x Sleep call for process: LisectAVT_2403002A_126.EXE.exe modified
              No context
              No context
              No context
              No context
              MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
              C:\@WanaDecryptor@.exeLisectAVT_2403002A_223.exeGet hashmaliciousWannacryBrowse
                https://github.com/limiteci/WannaCryGet hashmaliciousWannacryBrowse
                  https://github.com/chronosmiki/RANSOMWARE-WANNACRY-2.0/blob/master/Ransomware.WannaCry.zipGet hashmaliciousConti, WannacryBrowse
                    Request for Quotation (RFQ_196).zip.zipGet hashmaliciousWannacry, ContiBrowse
                      https://github.com/chronosmiki/RANSOMWARE-WANNACRY-2.0/raw/master/Ransomware.WannaCry.zipGet hashmaliciousWannacry, ContiBrowse
                        jTwrz6fY44.exeGet hashmaliciousWannacry, CryptolockerBrowse
                          ZN5KdHxjL1.exeGet hashmaliciousWannacryBrowse
                            wannacry.exeGet hashmaliciousWannacry, ContiBrowse
                              wannacry.exeGet hashmaliciousWannacryBrowse
                                Wannacry.exeGet hashmaliciousWannacry, ContiBrowse
                                  C:\Users\user\AppData\Local\@WanaDecryptor@.exeLisectAVT_2403002A_223.exeGet hashmaliciousWannacryBrowse
                                    https://github.com/limiteci/WannaCryGet hashmaliciousWannacryBrowse
                                      https://github.com/chronosmiki/RANSOMWARE-WANNACRY-2.0/blob/master/Ransomware.WannaCry.zipGet hashmaliciousConti, WannacryBrowse
                                        Request for Quotation (RFQ_196).zip.zipGet hashmaliciousWannacry, ContiBrowse
                                          https://github.com/chronosmiki/RANSOMWARE-WANNACRY-2.0/raw/master/Ransomware.WannaCry.zipGet hashmaliciousWannacry, ContiBrowse
                                            jTwrz6fY44.exeGet hashmaliciousWannacry, CryptolockerBrowse
                                              ZN5KdHxjL1.exeGet hashmaliciousWannacryBrowse
                                                wannacry.exeGet hashmaliciousWannacry, ContiBrowse
                                                  wannacry.exeGet hashmaliciousWannacryBrowse
                                                    Wannacry.exeGet hashmaliciousWannacry, ContiBrowse
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:ASCII text, with CRLF line terminators
                                                      Category:dropped
                                                      Size (bytes):933
                                                      Entropy (8bit):4.710902136409594
                                                      Encrypted:false
                                                      SSDEEP:24:ptrPzDVR5Gi3OzGm0EigS1xbnS4RQhbrW8PNAi0eEprY+Ai75wRZcet:DZD36W3ChvWmMo+S
                                                      MD5:7E6B6DA7C61FCB66F3F30166871DEF5B
                                                      SHA1:00F699CF9BBC0308F6E101283ECA15A7C566D4F9
                                                      SHA-256:4A25D98C121BB3BD5B54E0B6A5348F7B09966BFFEEC30776E5A731813F05D49E
                                                      SHA-512:E5A56137F325904E0C7DE1D0DF38745F733652214F0CDB6EF173FA0743A334F95BED274DF79469E270C9208E6BDC2E6251EF0CDD81AF20FA1897929663E2C7D3
                                                      Malicious:false
                                                      Yara Hits:
                                                      • Rule: WannaCry_RansomNote, Description: Detects WannaCry Ransomware Note, Source: C:\@Please_Read_Me@.txt, Author: Florian Roth
                                                      Preview:Q: What's wrong with my files?....A: Ooops, your important files are encrypted. It means you will not be able to access them anymore until they are decrypted... If you follow our instructions, we guarantee that you can decrypt all your files quickly and safely!.. Let's start decrypting!....Q: What do I do?....A: First, you need to pay service fees for the decryption... Please send $300 worth of bitcoin to this bitcoin address: 13AM4VW2dhxYgXeQepoHkHSQuy6NgaEb94.... Next, please find an application file named "@WanaDecryptor@.exe". It is the decrypt software... Run and follow the instructions! (You may need to disable your antivirus for a while.).. ..Q: How can I trust?....A: Don't worry about decryption... We will decrypt your files surely because nobody will trust us if we cheat users... ....* If you need our assistance, send a message by clicking <Contact Us> on the decryptor window....
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:PE32 executable (GUI) Intel 80386, for MS Windows
                                                      Category:dropped
                                                      Size (bytes):245760
                                                      Entropy (8bit):6.278920408390635
                                                      Encrypted:false
                                                      SSDEEP:3072:Rmrhd5U1eigWcR+uiUg6p4FLlG4tlL8z+mmCeHFZjoHEo3m:REd5+IZiZhLlG4AimmCo
                                                      MD5:7BF2B57F2A205768755C07F238FB32CC
                                                      SHA1:45356A9DD616ED7161A3B9192E2F318D0AB5AD10
                                                      SHA-256:B9C5D4339809E0AD9A00D4D3DD26FDF44A32819A54ABF846BB9B560D81391C25
                                                      SHA-512:91A39E919296CB5C6ECCBA710B780519D90035175AA460EC6DBE631324E5E5753BD8D87F395B5481BCD7E1AD623B31A34382D81FAAE06BEF60EC28B49C3122A9
                                                      Malicious:true
                                                      Yara Hits:
                                                      • Rule: JoeSecurity_Wannacry, Description: Yara detected Wannacry ransomware, Source: C:\@WanaDecryptor@.exe, Author: Joe Security
                                                      • Rule: Win32_Ransomware_WannaCry, Description: unknown, Source: C:\@WanaDecryptor@.exe, Author: ReversingLabs
                                                      • Rule: Win32_Ransomware_WannaCry, Description: unknown, Source: C:\@WanaDecryptor@.exe, Author: ReversingLabs
                                                      Antivirus:
                                                      • Antivirus: Avira, Detection: 100%
                                                      • Antivirus: Joe Sandbox ML, Detection: 100%
                                                      Joe Sandbox View:
                                                      • Filename: LisectAVT_2403002A_223.exe, Detection: malicious, Browse
                                                      • Filename: , Detection: malicious, Browse
                                                      • Filename: , Detection: malicious, Browse
                                                      • Filename: Request for Quotation (RFQ_196).zip.zip, Detection: malicious, Browse
                                                      • Filename: , Detection: malicious, Browse
                                                      • Filename: jTwrz6fY44.exe, Detection: malicious, Browse
                                                      • Filename: ZN5KdHxjL1.exe, Detection: malicious, Browse
                                                      • Filename: wannacry.exe, Detection: malicious, Browse
                                                      • Filename: wannacry.exe, Detection: malicious, Browse
                                                      • Filename: Wannacry.exe, Detection: malicious, Browse
                                                      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......%...a...a...a......b.......u.......`.....d.......j.......e...W...b...a.......W...s.......`...Richa...................PE..L.....[J.................@...p.......1.......P....@..................................................................................0..|............................................................................P...............................text....3.......@.................. ..`.rdata..h....P.......P..............@..@.data....2.......0..................@....rsrc...|....0....... ..............@..@........................................................................................................................................................................................................................................................................................................................................................
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):5256
                                                      Entropy (8bit):7.967184785067311
                                                      Encrypted:false
                                                      SSDEEP:96:oHWAr/YykH/V9GyeqnOYAlqlzMD7XxWpGH+XHl/sKwlbE4Pg5ottR2qrUj:EWAbXkH/q2Elqh27UpGH+XHl/ZwlwQkz
                                                      MD5:D63174EB3B49369C97D82DFA02E18400
                                                      SHA1:9F87D0C2DEB6DB8C7E71D7733D404AC123F0C629
                                                      SHA-256:1428B1D6334A8E9BCA4E8AD5F87BE2A9D63B5518C483A20DB2A9461803C7A958
                                                      SHA-512:DA2E5E10E56D073E158A57F29355C0673E4587E7F0A677689F4DABDC502070FE438475281550BBF24833C0A0F2D74CE8F54D7632E96D2EBF6831855E844C18B4
                                                      Malicious:false
                                                      Preview:WANACRY!.....8.Q.SI .2....I..U..Q..p&..B..FQR...-..y..XpF*d.jS....R.Vv.......j...4....-?..Z...........D...~_.|.y.....Rq.O..:...Xu...x..e.j3.......j.d#z..H..aX...]........X.Z..Q..m^...w....j.5...../...ct..T.ZS.`$.\@i.}d,2.V...{.>F..e..u.|.oM.._M..E...mw......h.........j.Z..%F....6...8..D......X....o.W...UK).0 A....[2.~>!g.&.&....[~:.H..%.'.R..Cr....V....D."L.W_E.T.......p......r....=.P`<Ux..p.{.!5}.-.K.`....V.iT0...uv}..c.a..<.p....q...X.q.Ym....NI..T.g.L_..V.l.v./.....w2C...C.]F..}.\Sx.=;uX.|.eB/...y.W$......t-.?a.#=.5...Q.\]#.-..J...0.R...I.=...U.M>2...z...Z^..w..~..`_s..x...B.}<<..kp..M6...D(T@\....8.nwK@IC!.i)....xA.^..5....*h%.S^S....R..|........w.....;)...'..e..-.....<..i..b....o..).......d.6.'T...5...@l..9.U.....aJ}Uv]...U.....H....*.&5..'.W.I.C.a..Y..@m..Y..]...#....f.<&xG..l...*w...5`...u.$G.PP..f0^...U...p_...v.....{#.W1Aq0_|.eFE..p.w...l.&.r....V..q|..H.d.$..v+....a........p...?.n:.Vb)9"..;...9p.Z...+lEG.@Y=....d
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):106776
                                                      Entropy (8bit):7.9982191541957395
                                                      Encrypted:true
                                                      SSDEEP:3072:eZVq6H2Hf8rjg8ef99uOlUfOkpr7rl1TlG8nkhKPiXwtQG+:mq6Hc0rjUfG5BDTlJnkhuI
                                                      MD5:B4900A8F0A31CAE8CB8AAED143D5E24A
                                                      SHA1:1DC0290378AE55428C5F4CCFC7BD0CFF798C71D8
                                                      SHA-256:C3C436CCEDA4C17E0DEEF89C24ABAF358B601D036075D8407B553F47F99CDF94
                                                      SHA-512:116233220DADC61231B33209A81A3575DE641E59C6A3C6F4F5B05F623CE0D5443123F5CD8E282E25A81364949FAD8E263ED5D722903BF6D932441C8ADF2D563B
                                                      Malicious:true
                                                      Preview:WANACRY!....+~..U]B {r..Ysy...F...%.r...^u ;1......n.h{gH..&.|^A.L...oF.7F.u..`.q..w....&.9=.a._...c..W._a.U..k.).*I.x...Ac.K.&.|.....p)..U....7KQ.4...~..O....WG..Y....t...(..}1...n.ob.w..*S%.S..m,{H...$.CzL.^.4.gH...j...k.8I.......YZ...X5...g...eh=m.%.....<............8}*.....3..";....Z....3..W......Ev.]A.t.....t[....X.T.....H.....H=..F..!.3...p.;......<@.h.C.ynD.T._T.*......{=s@...u..\%..M...dI+....Y.$.9D(~).%...."...=MJ..9.J7.u.U..2_Rl.M3o1n...K.x...u~.>=&....pC....K...-^......g.z\D..K..".%..n..;.q ....h.qT.K-S.l~..v.o.N.lO.5h..5..._..E..l.|^..t,......$.{.G._..5...5..%<......W`.nt.g..3+*.[...........0..&...m+.p..;...y<.VHY^1..S..Pu..3...#..}D.|i.R>....d.~S:Ua..H...J.c.'.....S...U.AH..f....5K....<.q.P...........1..0...;........;.7.jj.../.3b...4.T'u)).......P..T1p/U...3.k.o....8..5.T(.6..)......3....<v....Aq.X..V..T...K..+.t....h..V...Z.....i.0..f._..YU..(.[....n.....X.|.EJ<...5....u-...Y.!..c.w..3i.^...N.7....K....f.......F.^....L..\
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1311000
                                                      Entropy (8bit):7.999858629455369
                                                      Encrypted:true
                                                      SSDEEP:24576:Ungm/scxoxE+4NtweTG+8n+77GamNC9woGPYraF2j6huOw:UngUsQeELzweT8n67GayoGgraF2o5w
                                                      MD5:A2A56A6340946EF5E757731923007A07
                                                      SHA1:4DA7B8909DFFC0650CC2107F436B8EC180633FB1
                                                      SHA-256:797F0EE1CE61EA23C10F7B570D467317B452A9C5151EBDDB638D079AD822305B
                                                      SHA-512:68AA17CEBE9FB27011F0B3C354D7F13188E3B6012F443A8EEFAFF3D98989392C9547222D6F63A3665271C62346792847236EC7306CE888EDA9842CDE0518C105
                                                      Malicious:true
                                                      Preview:WANACRY!.....F..?.t...GdV^:<..>.|.o...L.$.9m..c..W.(.G.v|.....a.S@6.e......e....c).j..V==...R...H.b.;......A=.&zf.]y../k.R..f.P(."`.?..6./.V.I.28...;....O...e..'PP..>cbE;5...K._..N.t.z..ab?.)..U.UK....3N.. ..U_..B.,...f.=S.....V.H.A....O@.4.b..K...?.i.c.R.nC)GZ....................|..b.T/..'.....#y....S.n..C=J[..f.B........J[..Ne..{..v.3...b...S.`\$U.d....\t.H.Al~..........:...&8zR!......$.....68xGS3.t.D.@{.Rb....^...._....Ha..x3g...N.N.....;...6/...g.."/.b.{.j....%..`...?.:.4HbU.o.e.pT......~..IT0S...2../O.uLN..h..h...f.....O.._+=E.(..M...E.!.`../...a..v...J].F.l...C...W..c.X.../g...(.l..j(...F.uAC].9..".o.....F..cT..G.. a.Z.a...{.H...^fw..^.S+l.......?_u.vQ+......n.5 ....^~.G...&"....c.z:T....t.^....u..._,=x....F.;H..)/'...N..y}.....M...2..R6e.t..EQ=..$..>..k.....-..._k.&..>.k....../Y.BYE....m@.-.\%..i...............}...w....}w......$..N.......H....2...S.el..Mq..4'.yZ.....E....S#..L..I........[ww....u....p..U.!'.....(..yk.i.l..q...m.'.-s?3-
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):602456
                                                      Entropy (8bit):7.999684727513518
                                                      Encrypted:true
                                                      SSDEEP:12288:UhlcRCPMB7Ag/PhcAypmDq0A1Q9AZrOn0R3xYBTiPKNl2qs:iGR7RRp1DUUQ+0jKNw
                                                      MD5:784946D552F995399F2E3F6F8A836CE5
                                                      SHA1:5B8B8D7EEE5AF3501206F66B18C5FB6115D2191F
                                                      SHA-256:95ECD92A7DAE0B868777072D0CB5FE93999A6967C257ADC5F2F6DD669F9217C3
                                                      SHA-512:C46C933AB88CB7D125275F5A6184B6630DF91700E703EC2A1DC626FF805F5D8F5FD12EFCB72DAE9DAB60224C78CB0D26128C70F51B219A5403EA5A6D4A5AF2A6
                                                      Malicious:true
                                                      Preview:WANACRY!....q|.qn...#K@....5..:l.1.XGYO...#.(].9....X=R,.avWS.Q.{1.k.@:......_.G.{H.q...o{..+$....9...P1....z.c\.e.D..V.W./9..?...a.Lg.[AXq|.py<......Qn.SgS............l..X.9.........$....q.BH.. ...9.o.`.U..|@<.B.! ...........vS...Lb.......7..v......f..~6_....80.........c.G=.OQ.0..i.4Yk..&._*.q..a....u..J. ./.F...l,.P....k.g...U.> .C...AzY.....u.u(.3..$..q.B....d. )A..Y..g... ..m .......q...B..Uct.r. ..j....#.b...`...(s.K.m....X.yT}x....*../b*G..........T~E.Y.f...dLWL...h.^..L.!.....R..=..a.@.e...w.B.f.n.-g.?....[..( ..0....]N../we..*.-XY.\.T.m.\.E..5.#.d..;...../Wig..\...=..vvF.=.a. H..:.Q..p./Y..,.V.,.d.%....Q\=.=.V.>z.t..ar.......,..0.!ZW...k>....0.4.|.Gd..>.g..c.9.........{8X........u[....<Y.>....L.6*.AW...2.........@.49....^5:.O.\...G. ....4.?.WL..'.Y_..F......~$n..S...,g.J...]CY.-..@.....j.a...T.Q.'.....\....J.BL.YZ_..g.mp..%.*B......j.a...i.v..A.....o<H.S5..... ..nf..z..F_.'u..k.zm.....;z.L..=...dL......?.gN..6.au...b.."..la...z-.}3;.....
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):6344
                                                      Entropy (8bit):7.9710276044684765
                                                      Encrypted:false
                                                      SSDEEP:192:L0Z/JszbzlJ9IXtx9IBm+yKxRf409lv8GTi:L0ZBqzT2XQmHkRf/nTi
                                                      MD5:0E882DF9B42936DB567120AE3A8F0E40
                                                      SHA1:37B0B19906F89C1130A3E61C1D05D16B43BC8556
                                                      SHA-256:122FE537DE80B874EC33645EA748C2CF2239D2F49AF492481CA364A5706C017C
                                                      SHA-512:FA19828DBF66B5D486D041CB273E23663408B4254591B9A23F5D8FB37FF49A2B726F0748D570A2891FD043FAA9229A9CEAD1D3E32D4B891A80F7B6F671082C00
                                                      Malicious:false
                                                      Preview:WANACRY!..../E.".UIq..8.._3...+;....x71....9..|..D.I..._o16.d..s...r./..O.{.........}..Dz."... :.:8*"q{...c\u>3...K/....y.U...o8..l...].FY.N..p....^...bh%.Lc.S.....w..@.i.5,P..,B...B.g_..A....V.-G........rpW.VC...0.M,..u...].....%.(Ju......G:......[x...=..k...............3.t@!..N.R.kR..0.......z.....A7.NkSB....".FQ...-T^.$.m.;..%...d.I..Su.B.[.|4.5.W.......;.....p..{..."J+J.j/jd=.p...m.....+.Y@g.?X._.-.$...;...p.j.Q..8..[9.....>.h2..j%M%..B..o!1.e..U.C3$qVc.K..}.....?7.5X...ER....!...L..+.*....Pm.(?.......z.p.6..eLZ\K....IS..r........E\N...8..9...k1.T...d...]%.3..M....;-.:.*E.}D.vwL....r.BK.P.O..W...CW.^...{.*Q9..a....F.DG.Fv6..".<w....i...B/.:.qC..]b....n...&..r........lP......<....EPw:.@,...F=.xR.=.......T,.kfb..}...T.M.8....sK.x....b....~.]4.Pno.C..'.....R../?(...})Q.*q...(..._..PH....r.>Pm...fa.........mN$X..0.5y.hT..p.....Xj.x.;...3V..t.+[..4......*MS0..5...a..G.^T.#..H..+.VD... t..OiV].!..,...............M.!..a.x/..:....w. %.i..C.}T.M.l.?.W...(C..e(!
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):2680
                                                      Entropy (8bit):7.931803664115437
                                                      Encrypted:false
                                                      SSDEEP:48:bku+dDGZ89FEmOX45MLv3KoWLDvsw0MgtVpGD/sW+LDL4rp6LRzlrowCI+eSXNfh:o9dSqFEU5Mb3KoW/sAgTpGtGL4gdz9PS
                                                      MD5:CDEE27F0B4F02B4F55DFD679108CB3D4
                                                      SHA1:94EA664F0B87215EC3036F4B87F0CCBFA5565865
                                                      SHA-256:31F82683CFFFF8DCAC1E3D8F630AE21E9CEFC7F3D6B0223D7EA4BBBB946D5A6B
                                                      SHA-512:266E17BE3EFC4C3B8813CC4C6111C4DADF4406A4AE7E5F17AE6425C9775ABD85BF9CA25056653CC7B7898D8F68C053ED05C63175479CC63D77147B425211DCA7
                                                      Malicious:false
                                                      Preview:WANACRY!........3.m..!..yw......{.q.....Z..q..R...\..fJ...B.{.p..Rp...QPpC...&.h.....S9=&MA.9..8f.q.PY......n.~.3.U.....}...{e..a.\..........9#T1.L....e...z.M.../%=2P.3......W<...?...r....".j.|-....3u.U.Fg..X.;..:....Y.......V...(....X.3v.h..w...<O..Ko'..MF....X.........L@..\..A...n.b... .P..9.'..6....f)...i....g...Y.>h..6.....\".... .....!.@......3.PG....* ..z....+c.#..y...:..f.r...b]J...../R].b,.......!$h!...Q.g.:.......o.R.*.i..Y8..|.NG....`.w.m9hhR..(....r.Z.....;.{.J....:7-......t*....Ze...lN..{.xP.t3...@...g.kS....I....9D&%k....D....|.K.B.'Q.....j%^.fO*|....#...]....='so...H.Y8.d-I.r7..........K7.>.+5...0..W6....5.aol.....9.^.y..8.ox.h1)..2KR2........JA.I....w...]...;..^O...........2..............a.. ....Z.X......D..B........ZL.#-o.6!..D..l3../.;'."..9.........n.4..X..>...W.F_p.-.$[.D.peeUX....7rt.m.NA.Z..5D....=.D..j.3...S..#...#j6...=..!....(.0S.Y.3..bmN.P.....T.9..C0[6n.,G".Cz.{.(..4?._.`./C.....D...z..|.&.I..d....P......\!...c
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):602456
                                                      Entropy (8bit):7.999715674933676
                                                      Encrypted:true
                                                      SSDEEP:12288:7LyoZMYynLKnML4OdqRbczgWc0qcUPVC3rZGNH9NsjMV:7+oILKnM97sWcFnwNGNH9NAMV
                                                      MD5:1F1D939619590B8FE509D1CC8731B2C2
                                                      SHA1:F012745EEEFBF2605D5E9B4F7A62F6EF0D6F3352
                                                      SHA-256:3A9AAE4466DF0379772B0647F6C475455118693723D9D9D2D81917D25B931B08
                                                      SHA-512:18A1CCF620A1C3A85B632D12CA1A06F7370ADAB35E3ED1FC9F7BFC13A623F3444961E87A12D8536109F9C39D582043D28FE161989B7004F23E9022B5D6D14888
                                                      Malicious:true
                                                      Preview:WANACRY!....>..z.7...f>..2..5.c. ....0.......bC....Z..!.@...\..)z.!.%..._.LNV.z.a..J.....0.T]....S...E..).......d1..A......x....c....z..RU$.H+SS....T.z:..._.... ...w..$g.....AF...qJ.._..f)....3...."...Fh...v]...[+....$.~.P..{D.p*..T=.^U...]g..B...%.,c..`.....80........z...Q..P...w.....W.......y6c..;.....%...2T2.#.Zk..O....J.l........7."=.p......;.._...U...vnE.2r...m^....=.&......C.......I..W.."...|..$Gu....?..=.R......c.;e38.i...uq.U....B~.\[.i...H./K.F....a..[....X.c...fW......-..9.>....bvN.j.P..@.."...=:`z.B.M...P.......m......S..m5.z..p..........w..7.}...d...C.<.k.)4.Z....{.....Xm8......g../+....b.+OSt...1e*QQ]........'..8.x*_.i.(JC_...D>.......b.SB...6]~.Q..c.......&...t9v......?.|...:.Q.v....2.k.b.2..u.K.NSh..[g..B.q..D"\e..G..j.4'V...NH...vR\..@1.J....G..n...S*...H...g..k!.....r.zm.v.......ny..6I1B."U.-..n`.[5+.u.;M.q.\...h..1.@....%.....<j...Iq{..A..fs..d[V....89...:.!.3..j....`.u\.z.&....4z!....Vkf.0..e.!..v..)FP.;...L..}E.C
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):6344
                                                      Entropy (8bit):7.971318632490259
                                                      Encrypted:false
                                                      SSDEEP:192:mClf5MQhF9KdNDsQ2KcWlIBKgh+1z8sTAQ:rhxKNDsQcWQ+F8kR
                                                      MD5:DD9DE711CF214CCB101F4B57BE8C2CB2
                                                      SHA1:231EAACCC7A61D077D952C622958F3BF6441E8A5
                                                      SHA-256:2630744A18CA8F786725C0C5D22FDA6805274002EAB01EB944D426C26F1CC6DD
                                                      SHA-512:6105D6D949F82161DB3B7582C25A42D5C2BCF1F7F8B695FAA0A447A5F57ED32FEDDEF114C5A38FA15A839EE59566E55C9C28383BC5F4B7BD97632F7F85DE87C2
                                                      Malicious:false
                                                      Preview:WANACRY!....*O9..Kt.wCI|.....3............DI3Nn..Ha.8..:i..0......S..5.8.;.t...Qi..v./..z..?k.g.9.c...l..un.N..pEW..&..? .d.......tB..........H.6......c.......'.u.A=.'....X....}....<2\.,..`..R..W....j..W3K..t&.I......4sB'._...+..0..(.=b...".Ug.d.+.'..+.$E."a................D.'..X.H..]....!@..|H.m)4pSd.!............FO..#$..J.aV.ls.R`]..2..5.H..ZC....@...d...o....*.....w.d...;J....(.'....w.f.IR@".....:..3'H`_.....v.tu....&.kLO...)HH...QO.....y".Y._.;....$....&.+.j...CsL.o..^=Q....!..{....).f@.hn.d*..hu..&..7=.G!.?..V.?...v3.y.v.....3...zw<7..d.c..V..|....H'.......W....G..9..9M....=TX@.y.b....G.:...$ N......:I(..p..>6.T@..'..e.`.+t!.... M.f!.Q.2uHcv.R.,....... ..a..bJ.3..H.\.8....s....';.......`...8.)....q.J.../+p....e?..x....d.fPP].....?.7..7...~Zy......^.{.W...M.}=&.^k.g(.....s:%._....4.99....1...L..|.....G.~....n.ny.v.;.;.j....EVe.Q..~G..E....|!...#n2\..5f'...f..#8F.."c.Mz...-t..x...qK.L.z.y.T....F...4....V.I.x0.......r...&.M.Xj..^T..G1..q......
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):475416
                                                      Entropy (8bit):7.9995962051874745
                                                      Encrypted:true
                                                      SSDEEP:12288:bLimg7vyz+jTG2zdm7sNyOPLg+4te3A+x313v2u:DxS3GWm7s9k+4Shl+u
                                                      MD5:FA513023A165A7C1837DA11E376E8137
                                                      SHA1:42D6CB6595C94273AEB0288C3EEE54B5DD3A9D02
                                                      SHA-256:59ED6681F3A4A8C928AEB32B830DE060C00317E8F8CE031ACB9350325D28F8AD
                                                      SHA-512:06B6EC0F49B4D83606EB7625D8C7256E543BD38AA856012787CABD757CEA9B21129E36693BE410815067C18452DD4D3926970B964F9D482FB8BC17AF186DB30E
                                                      Malicious:true
                                                      Preview:WANACRY!.....]r...>S.6...*.Y>.-...KC.[.Bp....,H'..4.....Qi1....X7.....+..n.4...`.....j..g.;.!p.Z.......Q..L.E..lQ|...\....in..T.1..?.l#.z...@..0-...f.&...v.O.9...n..NA(.....b.a.@x<~....0!.6^..v`....C........a..*...&......r........srn..x...j.)J.2..:.....{..q*.....@......6.?.!.d.^...C.[...".d.."z.L.G.]..KU..@..#.;U...+....D.......J.......r...wk....C...Tk[.sq....u...]v...0.].w.0(-6.."%...|k2...........c.2..4...^TI.~....B..'.z..........K..;.[.. ..y`.e.....p<..V....WZ#...*b.."].^.y/.....J.BS..q.....0@@........eU.VQ%.Qc..........^A.......PGL.T"..[....../.9_\t. ......J...e .+j*...e..w.P[..... ......[n<......2....j....Ms....K...6.5...-....,&..".XS...hA........3[.<.O$L....H\W.=.y.l..)............>V^...l!.?.w.. .y<,..J...Y...H.~m.r.U..R...^..K<^1NTb.+F..db.{.v.|..h.O....=P.).m.E...8..W..yX.S....w}D..L.!f..<.W..}...DO......q[.Z...Q..;.....r..o.&;...Y...G\..$...,.}.+96...6./NY.nF.1..F..S.(~$4........FsGF.-.<^.....E%..J1...z.[P..:.'p.U...@Z.*.N.A.Tj...
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):516712
                                                      Entropy (8bit):7.999619310769483
                                                      Encrypted:true
                                                      SSDEEP:12288:qJBfi67VuAmK61OxPqFZxaR9lDGtd2xbImH+gD:KfDJHEO5QZxMDDoksmHn
                                                      MD5:D8C14576714A6C69E2946226B0C9B62D
                                                      SHA1:2DC6A6CEAB8C7E40316000DD0C95E1C9EC7355C2
                                                      SHA-256:FC8CB4C1DFC795403B47719EA91CD38EB2593195AC69E12C979185DDAC281650
                                                      SHA-512:C6E7770492195C4178C02B81959DEF24CF9E2B3A755E9444D619246082D84A28F58121C0CDFD287AA86E5175C4C3632FB71D0F9846D28FF02475612AFA168B65
                                                      Malicious:true
                                                      Preview:WANACRY!.....u0f..BH9.`..hi[.y...\2Pe.....!..p...Y>.x-...&.o.Z;...X....W....W..8.....gv.....D....1...].N?.....I.......(.G....]p..}.r.*..*{......Y3.5.......z.|r..)..........d.....C...w..l..z.].#..<.x9z.V.4..6._O.._.W4.F..V6).V....Y.......`:o.......H.......qyB...=...)..Wk.....O..2;.i...v../.~.l.+-.<(Yd...<....D'N.....3...1x.......H .(.x.....p.......g..>.U0.z....P.b..).kHc..r.....O.OZ....-YY.Bd..qY..V7.....C....*rM....p[.M..*..z..'....8.|F.i.p...`...<...R:z-(5)....[s....J...<....M..z...*.i.F.-|.;..,:........._.lm..]....Y0enE3...z..>..-y&.u.=..W.zm.~..Fuy4.%..p.g.'...;.].o......3.........r.AI.T)..=(.3.rA.4.J.m-......~j.Z..%....j..cLg.l Ec6.b.Q....9.....ni.O.._G.g[*....U...oP....F.(k.v.7..M....Ww...g./..&..(...E.il[?....H.r.......j:.G.-....dL_..j..[..#...2fN|~R.Nd...~./r.U...{....^..G.....v......5..I..f.w.x..F.z...Q........q.M.-.",.eE.$.I.B....Kl...a..a...aJ.P.<.~....1....Zd(...3..p..."K....[...b..OL+.b*A..n9.:Y..p.jSC.m....`.U..~-
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):16664
                                                      Entropy (8bit):7.987386273462885
                                                      Encrypted:false
                                                      SSDEEP:384:aV1TmGix+MoiR4XGaAGoi74xAcvzGhf9/kkSs:GSGixOXGaAJi74jwfVkk1
                                                      MD5:614040038A7C9E6E22CA3DFE6091619D
                                                      SHA1:4C00DC8A42CB82EE8754E5ECB6CC9918BAD1F9CA
                                                      SHA-256:829575DC41FA20988B87B9E49DAF79E433BC1181EBDEA20C253DA1DE472D21A0
                                                      SHA-512:4F3E9C7E8DA46141320B7F5C05039CE65A7B8C0BDF83ACDA9D6595AC23D44574102FD685E29623FB74D43C3BCDBB29364CC69CC56614095EEF0A7D227D705F69
                                                      Malicious:false
                                                      Preview:WANACRY!.....v......(.b...+.;.......Z.LIO....M.^.a".....(.wSW...1Wp..,fc...E!L......,b..b......=.*...+.]l.2..j\.Bb.oI.rTSF....~...2.i.b.nf..+.i.[J...n.xw7:.#`.,.~.Lx..g0.kC'+.n.%......=........i."....M"wF.w..6bm.c.....yBG"....I7...{.c\.L.....+m.q2)......@..........1..x.].uC...YBoH....X...j.A.).d...+........x..A...q;..n..a..PD2........~..z.#A{9.>....ACS6uR..j.l.O..b.y...Ju...X.a.'Di..lll...l.......{L.8.. ..+.......ZF.@.]q.)..;....z....w..-,..}....Kv+.....&..[..x...5..*..{..'4[....#..X..@.zm..k..p.HV2..e.|nij.xWB.t..m ...sQ'..9Q~..KF.U..d..'...U.DmO..x....y%.HnJa..Z..6...`n%x...C...A9d.p.A.j~....n7..h.=....X...Q...f|.........Q.8......l..J....e...X8..=....E..b.T-.|=@u..\=JT...3.p..)....8G.-..Mn..>...f...n%..&...t..+.....E..........#O._=..v`..._.._)T..5..p.^.h..$..*..v...T...*.. .Z.d=@.r..F/o.c......)t.."o .........C~a}Q...ac^.<{}>KO...~T..U.\...u.,..B.Y1m?..{..:.....p,*z(k.M.....c..S.....L.;.,....%...... 44...ww..=S.mP.........m
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):33048
                                                      Entropy (8bit):7.994857521600233
                                                      Encrypted:true
                                                      SSDEEP:768:+YsefdnhtQwM2lym7G83MV5GrNVHnkbXndooKZ/VKEkKosjtLLx:lfx9Km7BMVAHkbnqdKEggv
                                                      MD5:05D489B888207890609ABB8D7CD091A0
                                                      SHA1:17D74B9CDBABE11EE34A96D3A07037FC81FA667E
                                                      SHA-256:37077C1A7DD1A6AAE857A3453515A140CF9712C2B99E29A6B4C4ECCA166771C2
                                                      SHA-512:462622240CA50F7CC0169F863476C9D817ED29C4DBCC2F3C468455912EF9E0073F603936084A56672BA2746544D94CAC6169F580C4091AB83364671CE2FFDFB1
                                                      Malicious:true
                                                      Preview:WANACRY!.....~r...FG.U.A..q]..JA..rd_>Wa.t...L,.HC..y/..*y%.[.H.k.0E...N....h..;.#q..b...........^......h....Si..q...E4k..KI....R)...L..Z......l....DW..]....8EqJ..L.."...{...`...14O.....%>..P...6.....UN....yn..<.......y...2+...m.f.P5...}.>...\B.6X.1M................./...||.o....Cn.1.!..G<.n...40M...5....9.S.A..L..,......AY)..i.%JE....lu3.{.t.=(....NV...Z.nW.L....7i.+.f?.X.7.x?.n.$....t.X..r....tJ..Q8,....U.,.x.OP.[..r/HG..)F-.@..9.^..b...,..........}.(..w.`A...g.o%g~"Gx....9..h....5.xU......L..$ey[....o.^cR..&1....B....|.9.er......-.....i....[...x..........X..'".D..`.~....Y.......GI.R.l.X.%.o3..f*.H.....#..l...N.:..o...N.......A..v?...v..;......h.d+]..4....'.s..E...V.......i.".I..#...?..i#...&`...k#..N.UQ..SBbOV.,...tYx.....X.6(...u...h!..l............B.._...S..Jvt....?....=..Xy,...!....JZ3{..9,)?%]....@.e@......gP...}.[...@..}hIwt&o}...)HWwN~....}?.'...\.O.SJ.N....>%.(.........b.Z ...xK..b`..#..s\@.e....q......N..`w.-.K.D
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):28952
                                                      Entropy (8bit):7.993022643687484
                                                      Encrypted:true
                                                      SSDEEP:768:qXxY7CMFKNhGfpRmpaPNXvz9ITEgN9kBNypvuoS:QCH0NhsRmpaPN2wd0vS
                                                      MD5:FB46D4952608ACFD42BCE90C9AC6F02D
                                                      SHA1:D63F8CA82498F4563E03A8AEFA0456937B72BC01
                                                      SHA-256:A52CE616D6E53D14D06A7483688AB9DA1F30046C130DE59F03FF8AB55A7A482B
                                                      SHA-512:D3C4EC55CBB2355FA076355D4F11157E3864F2B7CCB9E5A66D592DFCAD21C165E63839F4E551EF716378891412EF961E225296090BB4209C65080D25354F606F
                                                      Malicious:true
                                                      Preview:WANACRY!.....i......#..M....p$k....g.m%..'...../.[...zn.c[+b.aZ.+...;.Kg0Fs.....F.<?.-I.o...x.h(..{;{Z.r..\G.<..[i8.8-E.~H%.p..L..K;]A..6Z.....d.P|Y...:k.8.........MD....F...q.%...Gg.Z....lY......~h#.a....T.,.!.jK.,qi1....Y...fj.......l\../...E.... .1.........p.......c3B.....@.......<../q/.;........C.e%.5o.p.\...&....>.....m....U.:..+^*.M...%C6/R.e...cYV....A9-.Y.@.sn.+.C.$...fA?!.{.q..x........m..lUR...z.....ZC.<....G..Z...0..........GK....V.R/1......9.....#.]..o.\|.L.......=H.....;.....B].<a..J......<...%..o...r.l&.UI......J.......nv._&.?...3.'.....d..!.^.l.......#F....Db.*l....J.......]e.x.V.....F...+H.[......D )...I.....~).......W+../.L.y.{.F. .N..roC..oXa....b...[.c.M.......S..3r/.. .../.%.e..].........\..k8...?Y..j.....p.I.d?U..0.0++..P.s...Tp....m.t..\-...$...X2.3RPlvz..H.He.;..........@}</[....L..V.E....B...."..9.,...f#.~pD ....D\.`t~.6.....j.|9 .].g...J/./...2.....".n^.oPW.B.OG.Cv[.....9A....{..P....FM....|.U...i.S;...P...(.nt....2
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):16777496
                                                      Entropy (8bit):7.999990273562919
                                                      Encrypted:true
                                                      SSDEEP:393216:wQG8zagZ/7y4LuOPJ9rrS+oFF2HYqniHj+hwB4VtQPc2g6mJo:lG8zagJILpnYNMyyB4VePFg6mJo
                                                      MD5:E34227BB634E42F14178032C9AF6A1C3
                                                      SHA1:DDB00F807D863E61CD5FB9B7FBE79560B1417C9D
                                                      SHA-256:85B6C66B1E3C041CEDE2C48268514D9B319C662B63FF4BE37312D51AF9F75E16
                                                      SHA-512:8187F1F9A2412BCB366A7CEA7567AB4A7920713FF64640B89AAC6868D696F63FB95DBB551AA5D297A1B9B5CF7C40E4BDDA3E38223D5FB6C07137203FF2FA8F2A
                                                      Malicious:true
                                                      Preview:WANACRY!.....:.....1.....t....~4..K...^....T......y.....'.....%tb.....>....X...;....[.1.!S..8..... C.,..wC..N&.fF{V.8.>.4e...;...E".d.........n..)f.4g.. ............h.Q.X.G`9b.....\l.s.,k.E.."...W.ay..A...%....;....P..~....6.v...I*.v...3..^.5...~Q..Y.fH...................R7..r.?|a.x.......:_.2.CW;C.2`8.+..H....u1...f{sDM....p!.tj.M.Cj..T.5.:.....W.8.z...)lQ...f.r.*.2.)..y.C/G.....z.l>.5...A.^7X..vl.g..WuLy7^=..R....m.?.id.._v.(C....It?......l.P...A..].!.......FQ.T...OA6...T......I...[.R........<.|k......C.L..y..A..!....}(....?j..|.U.|..^.U...j6.....$i....a...\..<.j.s- ....h..[....hR..h4..=.G....=5.N.%O6.K....y;.;\A..'...l}.t....&<....^.q.wu.#....b.8$..."W\.....|b[.b..(.H.a..7.a.8~..3i.^..B.;{..r.;T.9z......7>.9..y.4...&......oT...^*.w.T..Ed...;f"hWq^..b#R..2...J....+...=J;O{..h$.+.6.CR...&....62.x...*...JDMx.AL......i9.... ..ra.^...Y.{...}.7.....cW'.z`N..{..p9.i...gF....=....`.8..jl......%..c....sq....Z..z!...]wex.s_.K..E.c#...p.2K.../.y.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):164120
                                                      Entropy (8bit):7.9989624371209125
                                                      Encrypted:true
                                                      SSDEEP:3072:2Hlts444uUTrSyVSXNilUIiq7al5j84d9LjWHLyvrq2slpahZI6foekEY:olu4rbTIdoal5j17jil6PkEY
                                                      MD5:A606E5EC82ADE10F48BF75AC712FEB93
                                                      SHA1:BF8E2BB2566C76301842D6B8EC835C08D3E52B3A
                                                      SHA-256:F4D3757E63AE227265669A5552739574FB91B1D0C0E06F0E207B56E2FAE2B986
                                                      SHA-512:21FF146D8F835346093F163600778C04F00FAC56B5DB105488C2DAE9C345703C62D7EAFFB42F5D0B10877D93F181D97B971FE5EB2921433C4CDA7367D4AF9D2A
                                                      Malicious:true
                                                      Preview:WANACRY!....kf!..FjM..^Ki.,.,H.S`.... ...y....ra...I...`f.~FO.p...}.6w......{.w.1CK....(.l*...R.........`h{..3.6.{....Y!\}.....Va..m.."A-..Y........~..3.m._...[../...c,J.)...-Cs@pd..7.p.*.Y.ROp..7..re......\D.-..y..8.....|.j......e..1..(...8...Y6..x^aF.............8r.g.N.m.sJ\....h\.....f..9.....{.!.s4.........Eo...B........M...z..JM..x.o...h........e7......x{M.a*q....i...:...e..^.p..n....o..H.X.w>.....oS7\.(...pe}.3.....T.u'..R..->..4...l....B.4.YBr5..?7x...&"P...CewH(....2/3=o.,Q.k...G.aA..w.g.=..t..v.......[.....h.2....V.....u...Y..N...K...W.r.N.>{<..bBg*q..SVxJs=..f#..X;I>.....W!.....#....u..m...^...>>.n.<...KE...n.......V.........We.'.?3........O..;...J'..q,.F....n.F..Ou..~I...I(.r..C~c....&..a.C..:<.4.4g..pKo..A+..p.u'...l.?..J.....8.f6..1mbuA.V.X...6..@.....:.Z#.U..AB*...u.....\....... [7..J..,..me.T..NHj=.m..]I.3.P^.m(*...2..."...s.;.9....A.....H.<A.h...(..v..+...H..........K...n.T.Z!g]..K.6....'q.3>.[9.Y=?...d......},-6!1*.=...D..
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):196888
                                                      Entropy (8bit):7.9990989807582595
                                                      Encrypted:true
                                                      SSDEEP:6144:ODGjgzOiJsyUowSLWbSfyHM0xD+CKJ9j8er:djgCf/2yjxedr
                                                      MD5:288E26C9EF4AE14990B23F6AA82E7B50
                                                      SHA1:3BDE99EF5EACACA340558709B8A059CA841C274B
                                                      SHA-256:FC821DFD7AA10383DF097ED29F2D6EED67EEF5F3E8A9FEB31C9EBDE28D089FBF
                                                      SHA-512:669112EAAF7DBED7EB603B5A983C82E1581455E9FE268A8D6485592067701D8FABED82CC8594063A964FDE28A96EC9BD008F60E936AFD5E8A78A6E40696456F0
                                                      Malicious:true
                                                      Preview:WANACRY!...... .V..%.....~..h....q.......c4q6V.6...m....9.^..c9f....BweJK.ti.K.e..~+J.[3.;...Q.:.;...4..HA.7..........8.x.g.}.kd...V.g...8...4..H..1/.s.J.:q.I.......B26w*..4..yi.#!{..QeEa.....Q.k..Z....#h;..j.-...iz{...K....Y..T.*.V~m....O+5..-.*?,$.[".V..............}K<..B>y[....._|...qV..yX...Fz^P..w.G@....W..!...7.....s.@.X.g).4B..':\...3......_I..]O..m....`...a.....l.. v..p'F:!q.iUiQCg........;.......3...^.a.M$....)..W.......'.-.....+T>n.......!.S..A.....b.|..=;v.).`m....!..h]S..S?e..J..."h.o..=3..g......f)..C....=...4;.|w&].&..8.:....I..M..8.&!..Fk/X..-.~u.2....h......G...e.vy)'.J....../7....5H1=J.....!.^..;..V.R.s..%.%.bF|i.~.......>!/y..Fs.x.*...4.X....c.FI.....x.uY.......H.+.K.;..0....C.,......v.....-"...........}q........C....#W.ozv.'.B....%L..Y_..16.././...k.......ef.DQ..62B.aaXNGz...{.;.J4..:q..=...`..urs.`.....}.z*1......|...aV..=..bU.9....?..Uf4.x.X.r.z*.TSqNX..c{. ...h&C.v............[.b25r.M,({...66}.j....+.D..q<....A.D..'.^W.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):89816
                                                      Entropy (8bit):7.997885214375184
                                                      Encrypted:true
                                                      SSDEEP:1536:m30mzxW2dcNNdUloDlwcmlSGAa5eJTleTSgjPqjUTy5Ge+JKTxi/9IFtj/il4DEX:phR+lELZ2eJTleGgvTy5GeMt1ID/il9X
                                                      MD5:9DBA5CFD83AFCD83541AF046E2920CA0
                                                      SHA1:BD06D52D25CA45DB19F13E9B11B4683DE989645B
                                                      SHA-256:DE25C9DCDDAEDFF0B68BD1D9F239B58D226E12D55BDDCB0B5D42BB870B675A3C
                                                      SHA-512:2F696B633996EDFC37032FD78026DE4134C7891893EF0C046030C58A90D3CC0CE96D0643BBEEFE5533EE69F9071A24DB0CBC4ADC2CA9270DF9DEF13B1ACE6BBA
                                                      Malicious:true
                                                      Preview:WANACRY!....=X..]g..6.=..Z.AYn..*u.=[...0Z9..7g.F...t\0ds........H..qex2eu.B....T..a.5..!.-G..>.#v....X..2..D=..n......U...i\.%.Y....wk......,n.^...UTU.7?V.v.. .D.L.#.51...0b.(....E...,....b@...b.....T.RZ.i.l...~\.".s....e^`6X#LJa..2.%..$..F!...........].........W..E..So.-.{...n.c\..f...:..+....z".>.....#...W.....O..1...}.t.9 ..AIy...4;C.....5..:z.5h$.....4.L.J..h..\.3..9.M.O.07.W.M.Ce..?1. ..4...o..l>...Z:_..U...KL.H`...b..(..^...TP.!..Z...U..AA...p.......P}yu..h0..6nU..[n..D...d_}..|i.U..1...Y..u....wM.~{.`.0.'..e.r.L\X..........`"..X...=..W.t[T....X....@U...1tkz...%w5P.S~.Q...J...G...)...zc...c..5.9b...3.=9.U9...%.d..BG.............d&.~..k....S.}.3...;.R.Ak.O.".s..D/....w.......4..:<RN+..d...]!..5..I.@.+._.uW...w.c.......!..Ar4d..%.0XO.Rh/..kb......I$.&5.....,..=.|G.33........n.u.0q.t..?........4.Y.j..0...{....$.w...}.X.Ev.....yb.ww.K..<....@...{G...l.ua...>4...e..._.]....:7.x...vQ..l...O._O......kv..H....K.e'C.o.....l.kW`p........
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):44776
                                                      Entropy (8bit):7.9966851458277475
                                                      Encrypted:true
                                                      SSDEEP:768:DXy02NkTCP4q/+lCxNpxnQlsQUnFJrL5xbPFkmWDXKqn62Iv42B65Pixwneo:zp2XbSUNp1usvnDXfRgOq7Ej656w
                                                      MD5:B7D55DB004E645614A71455BA95419F2
                                                      SHA1:06F445412EEF63DF8D6EB5EFA3885162213CCACE
                                                      SHA-256:F729A7FCC1D3B605117E9EDC15AD1C20AA5C8F28D3A7D5734B0AAAC455254A67
                                                      SHA-512:13CFB6421F771E5EDD335CF6EF0463F7E46144A92D8006A1BD5B639D77221021D4F401239CC4278E26505F8939444492DE23D9F9677FB2F17CAD06822C3F3CE2
                                                      Malicious:true
                                                      Preview:WANACRY!......L..H....M.:.Y....[_...{.P._X"..W.:_t.......v8...g.Y....rw.+..J.w7..IXx...!.....f......'......!....s../.-]....4w.C._........_.N8........9j....\0.8..S.@.t.F4l...}..Z....F...$bd)r...z........MS.....;8"...S..`SIo_C..:.R.....SZ..v.r.......m-1J].)...........}...E...n...}.#...b...C...o{45..|.......I.^...|...v...8.{..*...{.......HE.ekvAg.....$.\.}Kz......X.....F?.Pb.._.......o[^.!.t.eg*.o..K1i:......._......%.F... ....[pW.s.{l .z6B!..fp....K..ZZ....SO0.-.....u.V.........C.x,......D...lU.RD..A_o.@...w:...'..9~\....-..y7...d+R.s.....*.....9!{....s.....r1J...jk.L[@.K.EH..1....X..&x..U....#...q.ch1.R.f:P=....A.k.b.W...8.;...J..=.5..8....k9.......6..Z......%.....N;........./.x.... I9S[....k.....!.7.E........[-.p@.I.I.]M?,....J[\F$S...*.>.L.K.EI.....8.M/.........J.o..J...z8..`8t.O..u..<!l..J...p.....0..T......SN#..E..........@..p...l.1Z....W..[.....~.2..+../.e..w5.o..s..E-.WC.....^.n..c@....=TOd..9..&.b...xL.4._...+..'.Q-..
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):29160
                                                      Entropy (8bit):7.993782261639286
                                                      Encrypted:true
                                                      SSDEEP:768:3nwdk9bxC47dqt9Ss8Mm07tdOue3loz8TWCp:3wdkpxy9Vk07Oue3loITW4
                                                      MD5:737D7C0ED80DDF2FFF0AB4BC2A57B83C
                                                      SHA1:2F32FCDA4D4CAE8BB82FBB4313627C9F264CC468
                                                      SHA-256:F926A44CC21A20185F80A819986310B13739DF27249DBAB4D7BADF0BDF20A781
                                                      SHA-512:0212A0C945AFF2D38EFEDFFB0AD88196B00A29F092AD5A580DC96596A83609012F07094CFED41D40D78F1C024CB29323EC8CE4F625104201CD3C38C607C52F67
                                                      Malicious:true
                                                      Preview:WANACRY!....'..).O..P........K..5.f_.Q..6.60Q....8.r.4.O&^.U....@...M'......d:....u(..*Rr...|rw\~...Y.....c"p...R..P..b..&..C.w&....(..7...^.tM...e%.Am76...i........8.7.../W;.`.E..-.q..,....F.g..Q....s..^sj . U;<B-.c....R.p.v..O..o....uE.qJ+...U.S..Z.....p.........?.....JS...........%}.E.Ph.../.3.4......2K........V..[..E.'.%S.J}.a.}uP.....%.#N...2.W\L...*c..Z...q....0..qq+..."..*.>.lL....*.."^...I.........F.r..5.....n....1'.$Z .q._.@..PZ....@o.6Gs...F.J...U.......c].....@.. v.P...k3.6i.j..W.!#R...Y...1..!.bW.6'..p..?Y...d.y_..X.:..#..y.L..JL....i....M..}..]~."}.+..V.[6).\.]..~.c..R..........(j...f...~.^.cV.BuC".Q.)..*<=Pt_1@.>..O.^.K`.'...hu:...<....#.R.~.f5..9..?7....c..o.S-<.T9.f...o....x..},&xP...F.*.....v...X.(.AC.~...q.rg1.....8euCSh...7...!Ob...ZI.q#....h|.~q...\............>..@..VrE.x....n.D....Z...z#.F.........1....._o...v>.8r..C...|.L...Ru.....M...bF.lR.x..s.^.....?t...$k..OU].....5....`...l7.Q...4|...qYrg..@v.9..K.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):7000
                                                      Entropy (8bit):7.975809598813545
                                                      Encrypted:false
                                                      SSDEEP:96:o8TnjtRUE4GsjgHuBX17L76KB1xLLd9aPNtMcbE/Jmpa1JrU/aaRyFxad7PijMO2:ltqzGsj7jTv9aPgjmpabrUyaRyFoRW2
                                                      MD5:2390503901272BCD098B1668A97F9DF3
                                                      SHA1:DAA5E2579867FDF049E51E0FF034D2FFC0C782A2
                                                      SHA-256:11DB4D76A411A6F91787CAF397A97C559668C65FEC3A37F5A484E62271571C62
                                                      SHA-512:A17823CC62D65C200643FC1AC20EB1CDB176F1C3BADAD922FC813B55CE6FDC8087BADCA8477087825517450ABCA6BAAC1CE10C786525A7AF4DBF5C998B452C22
                                                      Malicious:false
                                                      Preview:WANACRY!......QO..a...V.,.a..v....y.G.....(..k.5....A.LY..-.+...5...I..;.$..RO...Fy..!:.....o..?[....,c...h.D.1.............Z...j.....b?.....Z.l.].......Z=...#..*.M.[.M...3.`..uRBa.R.I..v. P..."..?...r.i...0]...=f...M..*..G.Z....-..d.j..}v..pF...i.....7....=.......^>.b.u..-}L....7.w.t..@.F....I,v.7.k...DF...(.D5....;...|.;.J.my..|Hv.F.Y...@R..S..p....,yH5...W.....U.LZM3.f*Y$.=ca..UxY.....X..`...Y....'...H8 .I..;...S../.....%.w!......A.>..z%&.@...4r.7.H. VR.........W....i.U_.I.(.....>....9....ZxH}.n..,'..Sj.......a...D..l.p..uGq-j...V.b.sD.Q.,^.....{8..-@{...U\V...d...`...'0.d.....A/..n...>.4.L>.bQE]R8QP`...H......P.h]w.=m...L........E..^.M.E.#..K_..4JQ"..[}..v.:j....Pa.. .....aNA...J...4...EK....~...io......]\..l..T...q...2.n....v...+i.^C...G...AS...A.A.Gm*fO...i|6.6sVc.;.[a.yC.........o8=.......q"F.E6.xcy......~.zg.r./.".L.k......6.....]........M.n.l.U.d.....x.....NI.[.@.O6b...}.99..qw._..CPC..1....1..9....[...........#`]j......?&6....?U_..
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):7000
                                                      Entropy (8bit):7.968602010503263
                                                      Encrypted:false
                                                      SSDEEP:192:s3DcHyCGbKcH9ecBnENdaPzoSPMjTttTDodwyzGtzz:2D6EjH9RtYa8T7TD0Jm/
                                                      MD5:77ADC6FAEFC6F2441F9BDE28D1C04055
                                                      SHA1:4682710DFB49D092904D0E56DFE71CD36E7631BD
                                                      SHA-256:C10EED862C3AF8CAAB7AE0B176FE3411A33F3C0907BE34FF9B38E0E9E591462B
                                                      SHA-512:B5C84D06EAC395024505211EF12D0C4770589C692EAB10871B3735329776AF8D851C582E71C8AF41135F0097B2F84208A459C6B4A3D964F515F70C1BA4A90BE0
                                                      Malicious:false
                                                      Preview:WANACRY!.......y..X......\...4....[...'7a.4...z.~.q..xE.gp..Y0..$..1..Y}o.JS)/.....*....h.,B..IEmF...B..8.P..............'.GK-..|t...,...S.c:Y/0.#..>o.m9.=...9...#.{...J.0....5.0e#......}QF......U.#_.G.......,P.....L.4...`]..W.:]nr..&.(o.6Q.XA2s....].........=.................q...L.C..m*....v..Y..0.HO) .p....B...2R.]..@.wp.[i*.x/.(3@..-......|n...Q.0.......g..V........G".....i...(..d.k.C.S......@..g.h.\Y.2.q..y...?..h(G.V{.`P....pw..z.{..iO...?....X....upR.....y.....d.H..h...D....=..0.G...I..s..<0\...Y0..........O:EI..vH.K......._2..R.....H..$...z.<..U.".|a.5...}...........=J.FjB.\...k....Xe.......&....S.m.......&...%a..>.......J.'1........z.I.L.......A2T.....5....&..(e$....n..j..sW...d...Xlc.?.o..b..+FnH...`a....':....3e.\.KYm.ql.I..W^..H...{.V.)m..u..-..\..2...8.T{.....:..i..V...\F.)...Tj.d..x>7.0.Q..2.r..V.8..~.W.W..."YJ.4.j....oj....Q...;.9....0...K.....k>...a.g....U..YCD...K.mn......$.a.).d.|..6.|.C.2.4T^.I........i)......G..
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):11251992
                                                      Entropy (8bit):7.99998437313119
                                                      Encrypted:true
                                                      SSDEEP:196608:ZUKRA2yoOmH5YRCZOFjzXyAXjlgtxT1AN0xc5Yw5yy5ClRN/d:CKEoOO5Y4OFjjbXjlSxT1ANO8x0N/d
                                                      MD5:739802CBB9A2A1B276241F73170A5612
                                                      SHA1:4AC16E1E5B4F43D515A7019BA2ACC89CB9E3C95F
                                                      SHA-256:E69043A09BD703C92AE0CD30CDA4A80D911E5B82AB00D04D254F8D5748526AC6
                                                      SHA-512:F28054AB065B45EA3235A6BE6363EC93023B0BDA6A6E9BEBFFCA80820262920B1BE5CAB23AA927E4BC79A10CFBC91E8B3479558F1303A167198602761043CCC8
                                                      Malicious:true
                                                      Preview:WANACRY!....... .L\.*....i...B..j{X+.Lo.....n..... 9..Bt.S...1G.5....X.....21...ZM,.c.\....r.Rl.Ni3.\.1...>.*..!....@g..w.B...w.....".|..C.^.DK..4...$._~....e...{.+.b.!..+5..t....:4....2.......83.(0..FZA.q.t.x.....yV+BX.\....R...^.....Q..(PAG..-............g.1S.GS*I....W.ea..7.H"....ju sV`/.Iu=.....6RHo;.{..Gj'..RF.?...........65.v.ZZ1.....(...B..#L..E7D..Yr..E.9........q...\..Q.$..|..\..F...i.8...DbO/."E..^{.6..=.o.K..O...m....D9+.H.}......g...;.|X!h.A.3.X..$..A....{....#.N.w.....N......R../.;<.#!t...P......r.u.2...dKs....R...V..f+...?.o~D...%..;7y.1.........l......j........?7N.....;....*.6'...#O[...I...sZ.....s5.......'S.rjT..a[.....8...'/..0..F......../:m.u..K.Z. .gr.Yz..5.b*..+t.6....gs.........8.....r...V..}.[...../...z.e.`.9.q,1...EI4."...=...2....mN...'..3TZ..6.cV6-7.,..l.[.}..W.\o)....]T....\.6Ra.&P...NMB..o...f.P._.y.@.c...2....C...ek<{b.E..u.....C.......N..p.D.1.$...?.k.t. |.3Q.X..}.'..#.......8..Q3k..F^.%F41f.>?l6pv..hK0F.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):130040
                                                      Entropy (8bit):7.998470657879962
                                                      Encrypted:true
                                                      SSDEEP:3072:r+lt6BAjUhZNCc7QNo7JcIldF5EFbDhBfck18KSgGNw1ZQrSmz:ri6BgOCcOhIeR11DHQTz
                                                      MD5:C54248B32B540B0E3B3ADC1BC9B9B890
                                                      SHA1:14F9B43E64E5433667390470E8649325C6A48F33
                                                      SHA-256:E395BAFC359C3BB0768565E26CD1719FC865AE5B40E51BDE25E40C2D2BB6DE0B
                                                      SHA-512:2A8D47FAE8CA4BC3532E02153E8D3CD89548DAB9FF242FC7D74F9438F2C72AEA8E876637BFBC924333D861C96401E3E2A5B228B7016BC92BCC9C3AFAB4C74C28
                                                      Malicious:true
                                                      Preview:WANACRY!.....L..BIr.-...E.O|.(.|7Y;.....}.L.$6._W...%..Jo...@.84.b.....+s......5..%h.=3..`..u.......^Bv..~...J....7.p....k.....E.<:....?...h.-.R...U.2.......ter.^.C:fDn..d....Q.....$p.P..MD..v6.h....dE\.DSb.T+U..Q\.h..4.....mq.L*..l(r.J.......X.U../.pM..............o<....o........X.O....E...].d.p^..cC.K...q\.B:d.F....1@.O......]R~n0.~...?z2....i. ....V2....22Z(>......$4.&.r*..p1....x.Q?&Y.,.\h..8...!}...''.....=...D.SD.M.+..n.......3..J/.n-..x..R.....h=u.........E..b.....O...K.Xb...vR..b..::...L...^..xCJ2..=....*.S..Sg.57_....Rif...x.&)UK....(..&.a.y.`...ro...P.F..sd.A..F..@.D].?....S..]...~ 1.mt..T...).....&..$j+#.....S.@).0<x.K/.^.......\(%./L..lLn......P..x...4Sv*..{=.;:.....DU....8yV.....t.y.9....Y....eH.r..X.(810o.?,[....:..L..Vf.2.P.:l..,..!RA`.]...1r... .9.TVI.dPp.(P..I_.o.k.O..!G_Y.........&.t.Xsy.~h.%........+.,.@....Y]...a. oRK.".l4...&".....Q......HI[..a,*u.00.E.......X.X.%......R....#"...J...<...$.^ p..q..v7.y.....t..w..c.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):39672
                                                      Entropy (8bit):7.9949721857810285
                                                      Encrypted:true
                                                      SSDEEP:768:TU+8glAGFMPVv1x7v8aB/WM3T7r5V6IHAxb9p9VpjRn:Tltu1xTPB/9T50xBjjRn
                                                      MD5:2810B6D5A64E94FB3F55E4C0CBA8239B
                                                      SHA1:E88BA135EB76FF1DFBF850B279543132A926AE00
                                                      SHA-256:A0F75A4B03A217E0AA7759BAD88251E24593BEB38C45DB7A74F9B2216C166348
                                                      SHA-512:1B18E2E12A8041CC13E7B4ECC45569222311E5B84544FEA6CF9CF56B9E226BD6BF5D7E40075EFA553ADFBCBB92A75E6F74A26EAB2873533B586EBA962A549D85
                                                      Malicious:true
                                                      Preview:WANACRY!....Y9.h.a..E:.5.N.5u.....3..C1P....s.\^h.@.t...g.8.].._h.......AI.YTgA.l..vS.:..a.u?R....8.xk.w)..{...7.ny}.V....U-..w.....a~..&/P`[..\..(2..6.{/......i..iKI....,..w....G.B..%.dvd.....kV.O.8..._.,..NQ.....;.F1...].5a....R.. ......A.D..U.N7..q.'.jd.J...............0...$......uB..#.D.g....!.q..&.|AX_.T}..*.....P,.[.....8].JrA...S.......2Pz......+..3X?.#.0..|...y.... ..1.o.........,R&....3.4...U.Cv..U.]...........!O*..G..$.O{....a.h..-e"|.!.....8...SE=.Z...FLQ...b~................F..\..e.....w$.c...M..#..1.Vv.W..psa..a&.....5n..../.n..No..L..m(.T~.'F..].......hNLi.v.Og..p..u.x.....;...."?......1....j!..4...'HuZLfI...<.%`,..;...x...L.@..X.. #...3..0....Yu.d..?..?...MF.x.!.X<G......7.Z.T.DS.".....4..X.=L...$..;..(...Y;..FO.Z.."}.O$..j.H...,.h..Q.90."F....y......{...A4.C'.I.u......."h#3..ejW.A.9.a.N.]......<~\...R.%.t\"...\...U...,.<.+.....H......*.e...C8....n<_q......$`.}.&.cq.Q...O.mn.e.%..$..3.....1b.hGzo>...nlQ.T..U.(....#.C8......LmD..
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):130040
                                                      Entropy (8bit):7.998560647169216
                                                      Encrypted:true
                                                      SSDEEP:3072:QuW+DmCPILTkEUSCKo6eucNsJpJbqfGH2r7lyb7fAHIftOk7R:hDm39sucNs7KGH2reOIft31
                                                      MD5:03DD865FC646C6307DBE462080C7DE94
                                                      SHA1:908BB0812804B81D2EA95B497622C2D37785FEFF
                                                      SHA-256:E9E8A549BDCDA7C8D7A096A7A0EC83E53D3CF24B13364AB7C702C529883ABC65
                                                      SHA-512:4831CA253D61C02D5FD37C28E7967D8A5144C13B2F9EEC9EA6D429A44FB66AB531DE0B7A4866CCD18FAEEE3EA0A37E22EC2901F3AA9418F4B623BC0B57F7BF45
                                                      Malicious:true
                                                      Preview:WANACRY!........Sj.....'..l..~@...........".Vb..;.\.|.$.:b.m....Z...1_.....E.p..........YS..O..\.."...J'{c..,.)..yT.)...p,9Y...9..-.....u?.-g-......3.........v.....I..T#;I.txo.yymYf....Nw......E.CIS..s=...M9VD.....l._.h.j.%.........:".,v-..cs..3.P..n..................s.Y.\'.....?F}.<..f.H.:...0..J....$.U...W.Jr...A?.g.$..ljC.X'.'..C.....@.G...y..H.%..7.A4.3..../T..R.......L..\..l.9...mf.....?.pD......{.VUk.!pf.8i>?/..P..x..c...S...HsrM..M..`....(.d.zsG......(...........Z...W9z.8.O..-...j..........".....2...T..P{..\|.v>-...ND.G.{...;Vh..)YD..U.. ...J. ..,..7.ON.Y...GUT.Y........L5S...............if...C........X.....}(..k..*...s...N..|Mn.b.{..w..T...8J..HZ.....6..8otb.02....|.......P....."cy...f0.a.6.lt.).j...@..).P.K"tN!.(*.T..J..U.g..L.6.....J.....vK..k......3.h+.>..j....c.m.No.9.~U^..K(.....q.......b:%..LY..}*]g.....U..Ml.Id.D..U.9GN.(..a}.....n....H....D........['.~...........;.......".......F.(.K..H.@....e...E....``.g.76.>...[.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):29160
                                                      Entropy (8bit):7.994108161183539
                                                      Encrypted:true
                                                      SSDEEP:384:+6vrUNskFDOAlUCp2AnohYjl4rx9XZY+bbhEIakzPFR7o4yb1lzNEmEN9D8Brudg:/r475lUOJyYj9+bb2CF+4aBd5uJTop
                                                      MD5:FCB776DA2C31466BE6E4A67CA9BCBEF9
                                                      SHA1:37BAA4677ACBAA48EE1277B720BB10C1BCC1538A
                                                      SHA-256:E4070CB2F0948748680C747A1BE6FA938665C5FFE61EAD7A059361523455E3FF
                                                      SHA-512:5EC39B96964637A9A93A138D3C0596D4F2CE3D90E7116A62D7C063B34D4DEEBB3A9ED79683FD6B0A934B8E4C456729CF5E0304BC5E2C937444FF4440A780B55E
                                                      Malicious:true
                                                      Preview:WANACRY!.....;....Dq....U..9s@.9..+.`.....(."._..K...`....U^.V....8z..RE......G..xQ...-..'.'/...v...4.k.dB.[...S..u .....<..Q.|.lK.....e,.D.&.".....t.,1/...3g.l..zM.w.I......pyqH.v.'.0..3..."..t..........Q./?4.a.......HVR.....C.0$..pL!..{..oqx>X.uS.veH.3.@......p........u,Z.....[\.4....-4.....>.u^>.&..y.......c].#j.R...S];......l.u.P....a9gR'....[..L..:z..s...../.........(..n.... ....'..#.f....y.P....JZ..}.$j.p.0i..M..w.o..Q..h............d.Y......t./u...~.U....3.8.....{...E|0.>..%....l<p...h....8.8.Rh.mnW.h..X....$..4.@b(.7:.n....Q...N5.]<.y;..Ti.....^....LCc`0..B..T>\$.....P.lA...`.a.@.S..~l._..Gw.oL.)....^...b,u......o.I....6..{.j.r...s...P...&e..Ye.p..|.=...a.l..L'.T.3F....~..+.)_GQhk..:zf*8.Y.\;..."..G.$.....,.....@.H.......ZU...*.U]lqF.z..Ni....\....e.u...$....h....<...dB8dN.J..9.".N,..'...(*=.7.o...7....oI.....dJ..n..g.|SI.\ M0...t.99...g..DA.\........u}.E...n.-.d.7b.GK2.u.t.,=.c..Z.m.`.....W.x....Z..u...,.{q...y.<i`....6._..-...:u.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1670040
                                                      Entropy (8bit):7.999891925869886
                                                      Encrypted:true
                                                      SSDEEP:24576:ovN+vUu7yIRupUxtGBb+TtGqi19PaHYCQ4qdB/o1UGAflSHoirtMwCpfE+mG6XFK:olem6xtL5GDY4CqIzmsr5DkOPFieTi
                                                      MD5:8C858F52286A266441B393E91789AF8C
                                                      SHA1:81B661D0D0020705EBF613D6D462FB8B06F06329
                                                      SHA-256:437D70FCAA97F43E4194D0048CC13666CA23BFB7B21D962A65C315ECB94094F6
                                                      SHA-512:5887C68EFF66BE488972D442390E0EC161C61949D16557823F1E0B2C5C3AC1603F5E576A658BE71175D82A3D6D84041B060914AA486A8B5358DE7ACEBDD46228
                                                      Malicious:true
                                                      Preview:WANACRY!......S.....f..B......K._ .*..........R%.Y1s...!..+..qRXa...Y.W..J..I../F.b...,T:......,-5l....\.5...|...#......#f.......@....2e...l...k5!....os.....E.v.*.K.Q..W...G..*...Zt.{..p....6..m:w.$Iq...7.*....&.f..I..G.$l1g...R.f..t.f......K..W#.p..%x....uz............U.B....r.T..hu.f....UE.t#.[z.".q..{>.....=oR..*....d8+t......w...a..#F.[..?...0G....x..V ......!.g..X.#.y.9f.;..<...K!w.q....D!....0d....h.1.Ru.j..a...2....j....\....24...2k..#....,..>..Z,.1...[8.J..#...Y...oa....vH?.....6..t..5..Do..}..u...M.G... $...m...2....=...)p.3X.........i. .&...c.4R.@F.2."..H..].].....c*?k..?..z.....O;.qr..NY0h.RH..A.......c....3........Q....Ai7v..b^.e.q....<......q..5].6.k.g.(...,....-.F.....{..._.X...LU|.MD...7.<ev7....H.......a.s.zm...M.m....:.#...NBc.u..9....Qa....7...X.`Z6..Q_.8a....).Q@..8..I..N_...7......@.;M...).......,..0.c.l...NY].....;..{..d....k.....q|....~/...:.8A-yu.A[_'.Y./........uB.C.u....J*.....R..`.........?...H...%...f(.P.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1528
                                                      Entropy (8bit):7.870369991841538
                                                      Encrypted:false
                                                      SSDEEP:24:bkRh76zDHmkjnFojaEi1GvOVMv+DlytSD2Pa6aP3Y/mY6Rvl/4vJA3Yb1d10q8X:bkf6rF+UQvOVplHMa6a5vAvmobuqK
                                                      MD5:1CE95F5E31104272902EEAFBCD2221BC
                                                      SHA1:B382FE25530C6F1A890E8DAF03AFFD9C3D56FD78
                                                      SHA-256:32F96C1E90F45AA82C9A22EE64E7DE5A527ABA7143968A00B037A8B529C31C02
                                                      SHA-512:3E4FAEB77DC8AB05220F890A8B844E26D67F89924FF01610CBD0EB6C07077B0F5FB97AC4A0D0E218BB9ADCAD3C0C1162904E7779E667DCB5BDFBFC10048C51BA
                                                      Malicious:false
                                                      Preview:WANACRY!.....2O)...rv...4...6......v..e]-.....{....a...A.`....B.C+... ..F"l...c....._.C.Z....=q..>~*...2...1.w.w.oZ.[..r+..ob.^..T..._- ..@../..: z.?}.....U8..>.+.$..8+ ........$....+S9...*./)...2...r.TZT...o.j.nY...E].,.}lP[.3.m.u......R.....]P./RH..gR...............Z..{.J.]I.H.h.VJ.E..l.r... S...b".D..+..aF...].a>o.w>......*......w..\T."M.....[..&[....D}nZ.......<J.^....'......fk1...@.[h"=.*.Ad.K.......'.F.7k.z.Kd.(q....` Oe.<.t.uUb.Q.\......#)..E...U...bexJ.s}.......G|)F.z.....q.D.K...@_...q.f.62.^01.p.[Z~..R.u......)......:E.I.2...-....(..1L{2..N.I.r+...}A.-.....u..%\... ...).la...d.....{.]".9.b.....`>..5n!>%.qv...9TeCG...i...?....*...._*.-y...H&-U..<[S.uprh...?.@..%f.}.@m.e..e...`....A.jJ.U$....^.... .......:`.v#A.v#<%5.k..'xa.IJ[V.....n.j....U.!a...j...)U6/.9...e.>A..i"......8.._1..#.......-. .d.(..y...0..F.Sb.&..Z.X..zO...e.Ig}.lm..7.....X v.D.l.X.Cl_..#;...;..B...V=..{.5hv....T..(...vS..q].n}..?.9..n.P.LB....W.. U&].MWK..
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1528
                                                      Entropy (8bit):7.855706374526433
                                                      Encrypted:false
                                                      SSDEEP:24:bkbLbrciYk/cDppSuXJAIlg3dysIeM3DDf3rdaOVaK+lBHVpmOdhH9p7tVaOr7Bg:bkbLbHYNDeIDl2oewDDplaKABHLhH9JC
                                                      MD5:E8967FAE3A89960FEA78E56BE6E12966
                                                      SHA1:3177088CA4997E865FC3EB425706C0A73353B8E8
                                                      SHA-256:8A3A45DD077D66BC6F6F99C4063F103684E31962D9B37D89492560B6797D54BB
                                                      SHA-512:DE3A4D1A5C3486628DBCF73775DEF160B617E7D8A732BD38115AF3782AB002E25935EAC6F0835B0D995F3AEA566D2DE72ED190D1472F3CC853E6C0B3D673A89A
                                                      Malicious:false
                                                      Preview:WANACRY!....J..!.$....Q.......q...f..5.5.Dx....D+<}.].....5^..k7..\....N,..'..gH..BbB..G=V..k..A.7.t.d:........>.b..{...TxD.Z...G.%s:.M.>zn.XU&;....tV..Uw.$.@M.t}Jt..y{..1....'..]\.6..7Xt.....C).O..]..,.....~>.f...w.......M.06T..........s?H.T}.............I..?..\..6.&..W....]...R;.=..YM...r4.sO..FY.q.M..^..Z.....r.Mrv/KS...h.......k.6&.f=..^...-..7%....u..bx...nKK..P...x.......tf....-...x/......<.v............>.3^45..rS.........m?B..0.DJ...*K..W.....y.3Hmm.*....!.....|d%....^ae...=...x......c.-.J.Z..Q...XDvY?..,\..R.....;-.\(.Z..#..7.'..Y..^...}P o..6y......m."....9R.\..Q.4M.(S..Z.....1?x~`....E..p.....Y}.......:..!.OG....~nu..-..!..!.....`.[..%:..k.tJ......In."....W4fW."a..O...c....>..3...B._.$......S.......T.3g...(W.o.......z\U..V......c?...Nv.s..k^..R....j.,i.......6..]....L..o..e.kq...6.O..}....]......t..~A3;...x\d.....Q...h...,.8GM.G..!.H.x...\p.XT.$p.i..#~....%.A...j....M....H.;Z.xp.2....T+.zo3.F...l...Q....{X..v.%G.I.l
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1352
                                                      Entropy (8bit):7.855609052397016
                                                      Encrypted:false
                                                      SSDEEP:24:bkJVM21VeS8bzQC6Cdeokvnq9iJfkJm+J5gMhx0mJojmwiCA2ErJayfOsZdecVX:bkc24UiufkJPrbh3TmEcyfDPeQ
                                                      MD5:DC8F2C84BD2D784555A8A4FD12AEAB3A
                                                      SHA1:B6CCCD3D253DD09C9791AAB38F5524EF2F9497E4
                                                      SHA-256:ADA2569D818377876AE2168262A549138445AC58987C618861666F9225376B71
                                                      SHA-512:0780952FD11FD793AD9D5339F88A76B39B76613BD1BBB25BC7CE6828402666FD17369FB41E4CAD94F22737BCF1DC95C0A135CFBA7034DFB7340396F4E7CC0415
                                                      Malicious:false
                                                      Preview:WANACRY!....]D=..f.2..9Y.l.Yq.......)....#5.`.9....q...H...3.1 .Q9.~...V..i|....L&SL.....9k...p/].a..c.]..`R....%.!....M.3..._..B.y.8e......IK...l.. ....WL......D.q.j....}oi..Pm.].......wh=v...U.r...'.....=!Zm..+..3....|...B....wo=..-.Kk.G..pR.)kL2,........(..........gX....m......z&..-...Y.3s.$_G.|Q.%.7.=..pq..t...khup.....6....{.,......8./.....0id.B.)E...$..e.)..62....'W.8....J.V.........n9.Fv9.o-D.lOs....M.....C....Cn.9....?..>. <{S...y....\@..<)p..~.f"$...7......T...Im0....u...|......lB...X......j..a...h9.F.&...{u.,..I&).V.-....s.....S..Y1.....C.......#.K.._.v.j.*Z.T.s....>.W!...8.\.c.F....>L.....>Y.....[..V.C..c.......s.q..N9.I.s:..\.L..*..-.(..sp.u...... ......6h+U..*:.,h.t.w..&\...5T...OGO.-...9..5...:Z.Q.@...."..M.U..c]..b....=.....Ude.q..-.#z,.d>.{.....*.-.r'G..];J)W.6.h?G.0.G.....P.D..j...j..$M........F.....<P......Y.0...1..4.....s........f6.rHM+....!......#.X........F7.u...}).6.L.G.e.1T=.......y..............n.gb. ..e
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1352
                                                      Entropy (8bit):7.816941046366024
                                                      Encrypted:false
                                                      SSDEEP:24:bkR3JpJMGjbv8l0s54USqPMwJrfZnYAIQiMnqiVP8L/v5cT5c5BQhrY1d17Z+nbX:bkR9MGjbvhs5hSqxJdnYAqiVgHeNY1ZA
                                                      MD5:48DE2E9F278CD0727726A766C465E183
                                                      SHA1:A4C5A6557FC8669B48786077D2BD476CEDF72998
                                                      SHA-256:63A6481398883AEB6CE5FE516871013BEEAF682BAD6E699FBA9E9F5ED3297C17
                                                      SHA-512:A1DF8C6708C8461EC3ECB99CD6109866C2EE5E45FC284045CBE74FD9FB56F091E0DC38B2CDE9900FED67FAEF3DEF7BB04749738EB56CA6B32AA62E1F186CD74D
                                                      Malicious:false
                                                      Preview:WANACRY!....=....`.L..6D)b.&.#..X.].J..X...JcY....J.m..>q.y......4.s.s.v*. ..l..i.GO..8............K..A....v..7d$..Bp...J...o}.~.u.$.....WF..Q.....l..m...)....}.n...-..*-.UU.._E.{...Ay...].;..2m.w.....Jc.....a.p.W)....(..h..b.,.!b../.......3.$;/.(xr.L.....e....(.........7...7....M...<e.w.b3.f.b..k......&)..G...l50....3^.\p.<......v.qe`...a...hE.1....;R.....4T..I2.f...c.:...d.W\.:..xz.M.n.=...[8.`$.....^......$...[.....}+....:..A(..5..bn>\...r.....eh..0.V..^I.!.....k.\d@..(<.C../a..Y.P.op.d..EgE<s.d9k2..pN.a..NAZ.L3.}...i/i......*..tA <.u...eD\........vV..W....A..J.....c.p...=bRi.+...,.hn+....0.;f...H......b/.Vb.l|.e!..C...4:.~.w....W......|.7?...>..3......s.|]....K...|....F..]fD..9(.w..F..4.g.....D..t..U.X.'..kFh.....Y...o.CE......^u...[....{...A...$.pl..>f.~.0J.M9...\...U._(...>.U.v..j+..<....\...IF.|.../.oyc.F.e..?..;.h........vZ....;.>.fk.P..c......Wj(....I.j...+...1.8..wo..}f/.....2..U.M)f.....!.y..0j!.*......r...3.|..>:..!......
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):297144
                                                      Entropy (8bit):7.9993330446253434
                                                      Encrypted:true
                                                      SSDEEP:6144:Myuzbao6vjKIDEyCoNa5KUvVR0kIoHFd7M0BZ6c8lCGMh97Uq:MyuH36eIxCX50krM0D1087t
                                                      MD5:F6074D9B507FCCD00E4ABDAC3213C847
                                                      SHA1:2D6AA18EF25D6A9F2EC91405BAD6DE4BD9AFB666
                                                      SHA-256:7D1EF0D5306C2F868B7D149761F7D152ADF1AAC015543C3ED9694F6A9DAC5BBB
                                                      SHA-512:7B9D112904A218B71167890D9F2D4EC1554FFA17EA400BB344F286B1A337664D357C90C21979DFC33E9E808A13EDD8428FEEDF18C580BF840602F887680F17E3
                                                      Malicious:true
                                                      Preview:WANACRY!....$..6.....A....$.-.W...N.\...a]../..?..u;.).UV.JT.j.:).....F;.M."?...F.%*.0......1v.w...{e>..v..O.....pBGO(...x......l..;.6....Z;.g?zU"O...q......E..q.&..*up.r..C-.?..7#.JI....e.%,...;s.....p.!z?.M.r..a.$r.e..i.........S.fE.g{..9....)B.m.f..............t...j\e..|.....?.4......~....iR.?....m............|.!...|.M..#..~]4.J.F.....|.xV.G...81.(R".Yrn...<\..A.?.Nn8:3.......k.j~|*%..Nc&u..>...q..q..T..Y.8..!9L|CU..f..Z..=-lJ.....g..}j.Am..X...N2....G...Q.I3....N...M..lU..F....c...q.T.z.T2...X.......G...=../piI....=i...]Q..'iqf.}.I.......J..W......I....zB ....R......c......G...F~/s.r..f..........>....`gtA...y.d=]5_.......:..oB...P.b..`.&F[{.. ...)^q.H.$....;..3[..(.:. ..nj.-7..=....].P....%.......Q..J..l.I..I.(O,\w.f.0K_..hF...u\.V.^.....&/...k*.@.....8.5.. B......mkT..nu..|z.-..&.}f4...d.cq.. NLK.%..Gh..I.....~.SZS....^8Lk..g....Ob.j....\u.E1..#...........|.s2Q..%.g.v.P~..S.S..'"..X..R).-.^.....C.T.!...RGI.....zT...V...)...
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):297144
                                                      Entropy (8bit):7.999446027422421
                                                      Encrypted:true
                                                      SSDEEP:6144:fuLHFC+TIt+dUwclhv2cMME749nLfFFcyAMkxHtT5Owh5OX+1BPCara2:fqHU+UwdTcvHMMEQNnwHtoscX+DPC+a2
                                                      MD5:0D544595DEE417053A21E0B43C7D4D94
                                                      SHA1:5242A426FF2EB987AC05A50CA312FF4AAE1BBFEF
                                                      SHA-256:97BD9D3C6846E6257AA4733F30AE6E012B6567ADBD5842EAA05D87F141CAACA4
                                                      SHA-512:872A6B5A4DD39EF92B29C0AA0A9B79057DC0304FDE4A0D93B064EB84260462AF6BACEB914C5F5052C99F58EA51938B02F7ADB7C26C11FD6E4AAA98174894A7CD
                                                      Malicious:true
                                                      Preview:WANACRY!......L;.dl..(....A..?Eh.S.V.}.A.|.}.>........N.<...............x....A....wjBG..1..l..."O.Y@..R.>.M..u....9.......c#............A.%hS.%..6..8.B.[t,...B.#@.!{..UR...b2..x..I.@..B.=.E}.O...y.t..F..p...}.._..d..$k.~...E].*....A9.g..u...5.0g.>..'2...kHT:f.............a?...S\....g!..{.`.....j...w...K...b^....d+.@...).."r.7=..ZR....>....(....8E.!.....&..-.....:..Gq.0^..$...4.P~...q.lw..\V....=.....Cl/.Ag0.Vq..g.. ..u.*n<.E..............Q:.m.y.21........Th.S.T.E...o......[.n....a..-F.....f.?..:.:'.h,...H.K.j.......,..OD..9.V.|....t>'.F..b.T<...o.......U..xo.y+l..%.-".a...R.G8...e.>.....O..f..P./..O..'....2J..n...MuqIB.9@.V...0.....Z)..#......X...J....P...<.@.a...<\..l......3.:.k....I.......5.^..h..i(....._Yx.F.y..,E..r!t<...E.B.[.!!$...u...%...!.J..27F..C. jGR5z.zAgL.8B.t/~rs.q......;..MT\e4.D.|..V...........dg.H}..WN(._..J....ou..`C..]..IF...W.]..|....?^.?<X...0#....o*7...H......9....h....K>..!{3..F.|V..u*Sv.z..V.D.cU......#.j...<!#(%7x
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):297144
                                                      Entropy (8bit):7.999381848824213
                                                      Encrypted:true
                                                      SSDEEP:6144:a/sYxiejqj+Tn+c6Q3e72Q5K0PovZ9xbMhBhsIoqy0CETz7C:GsYxiKG+8Q3e6QDW9x43sIV55rC
                                                      MD5:CF3247350693A8E66739A61D616A8364
                                                      SHA1:349D06E5D43B22187179C5AF39E5301D94C99B7E
                                                      SHA-256:6255DD145260523EC245CAB4AF6BAD878B3CC76D6862C4E11833C05E53F7DD06
                                                      SHA-512:5B5CFE81EC967AED2A19443A1B99CE3696A62627D92ACE260987DFB27EA8683F30407051CCDA0A7712B64C1E7881BBA1E9F5DB38B51BFB151C4436403037E0D3
                                                      Malicious:true
                                                      Preview:WANACRY!....`.x.j'.C..$M....p....J.]..Y]".+.9f..2.......Q.m.>W.7..`..'.0...:e2...N.y..\t..r....+...$z..Q.%2g.".<..wN..K...I|5.L.j..Kzx`)A....$....4L..J<?.^...W...Z.&G....N...F....#...E.b;.O)s...j..d....2.~.I.."^..kO.C....]t.2Q..w.L.9h....Pwy<.|.#LD.Nco!.-.f.............M.e.>M....JP.....F.$.)+.7.^....e#.f.H.E.4.F-*.......#2.HD...y-)..8=><IK.i...9.G..GF#......-..mO.....p.....I.W..`.".esR;...v..9.7Y......Ic....a..+.H.wcE:.s8...7.N.qX.1.J:u[k..j..h .x..,..Mx.L.1O....(....S...,..i.v6ZXUK...Ij..g..ak..w...o..s.#.d..+U.....s...i.B_s]..Zu...vY.&....x.n...NH7.5..A...]..e.W......klO......._...}%&.].&...|.."..>..1H.g.)....#.U.x ...*..'8]>.....K.pw..^e.?A..|AuLs....0..2..+St...5D.E.........o.:..9j....:..u...@om..<..h-.d..(...El.../k.........+*../~...)`.{...7c..z..N"...P.W...WI....x.$.S...T.0(V...Y..^K... ..L..#.c..".F.h.5R.5&..>w.^dB.....=..a.].Hr......4.........-....[`v...{Tv.U]..R@.0............U.#.~.. ......P. ..c.....E.`F..I.)..e!.go.R.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1352
                                                      Entropy (8bit):7.851888002555872
                                                      Encrypted:false
                                                      SSDEEP:24:bkNRifpof8AiIb1olzS0zTwNnbAFb/+2UagA93buWlsBz3+JijRKk8awNNevn:bkN0f2fDBbOl10NS/+2UaD93lij+gDwE
                                                      MD5:B90C88DBA8CD4AB632671D220B21C6AB
                                                      SHA1:F2B94DD80BAA006256EF80BA3392864FF550C218
                                                      SHA-256:0AC13DA12AEA84F091C29D99F9DB5502D7799AE305EF81B318226C9B56CCE038
                                                      SHA-512:AF57BF4CC7F36840920CD77B166434E9E533F161F3A20D098443D8EEC986FCAE5566BACC39008C2A2F744841E139A2937B75702AC277EE9D061EFE7BE654FE19
                                                      Malicious:false
                                                      Preview:WANACRY!..........SB>..eQe..?.....:,...6 G$a|..+,S.>3. .v..Am)N..AL|...s...~).j"h....m..7.H...@+1..+BcPS/.Y...W...|.b,7\.L..^Rx(v.[N.gO..Y.;.;z.-.Qq....p...L...P.(..QG.....Uz....Q[$./-.%....'...Ao...8..N4....kj.h..F.A..G..m.b.c..{\...AU..:"k...8bY\.?.#...n_....(........2rW.v..:?.<..........N.....b..B.R...[.~._c..H60...#.JC.c..g.......5..I..g..'.i2k3.9.#.+.A.iWL.JY?.Tz.....!.9 ..9sH....6J.CC.x:.S.W~w.=*q`.X%6}.3...9..Kr..f...tl}l..i.G....>7..D.i..../..+.y..W.....,@..I9#..A....p:..:... .....f..t.`d.].Y.G.... a!Tp..Vy........H.. ._&.D...n..>..k..NX...87..+Jz.r $...<.H9... .z M+S....1...(.......o+p.......l-..9."k.^.....y.*c..N......%].=../...j.g,Nf.y.;.Mqe;...&..=.Z......(q..Q.#R.P.S.@f#;.o..,OQ...*..........$.gX.]Vl.}7.)2<.6I...X..Q.r..p.*..b,rY.._..a.yo&.$<;C..Z..=....!........t%f...T...Vp.Ik..R.*N..1.^Q.<d4h}.l?y.....F.#.3;..~.....%.e.U?.......w......~....*.."?.........X.c+j..G....N.S*h6.....2...5.(8x...z..5.z_c.Z.@..r.u.s...).C....p<:.nm.2...
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1352
                                                      Entropy (8bit):7.825923300980943
                                                      Encrypted:false
                                                      SSDEEP:24:bk7YJ0pb8/amKmY7jwVYqLVtC0X1eOUFxe4oEs66LjLiMKS3elUVflLj:bkLxmavwVf10xetEqOxlUdlv
                                                      MD5:3DCC7AD13158CC2E550CEB47F06FCCA4
                                                      SHA1:2F7380AA24442B6DD3299421FE9EC1F136537BDD
                                                      SHA-256:7250E59FBA34E3A9B8E5EA35FA09C0711E148C11F00A4A6F1C50B67A630D0BD6
                                                      SHA-512:3B286A173461A5B6C6D6E65488CEFFBF7EDD58DC3FFCC2C51B7273C8C173D3E59EDA059E45B9D7B8006F8A5A47F40297787ADF50D008FF2DA690A85051A21FEC
                                                      Malicious:false
                                                      Preview:WANACRY!............pZF....A}76...L......F.B)......V........Z..qFR....}..{..6M..1...L.?.k..(!.I..8p.C.T..=.(.zH.M....&....^< ..U..S..v.vB95.i.s1.I....O..q;2yL...g3.....].f.1}H.L./...Xt9TV.f...a..";...7.NOW3e?..!.5.mbw..5.o.>f..G...K......>......a.._.......(........q.{...E(@t..J.....9.T.M..h.R..H...S.O....F)y..w8k_]T..O.=..P.|.r..u."i.i.f3.3uZ..J..&n...@...>..x..r.bs..q_.............C+{9..J.[......pU.\H.. d.V=....u....5....\M.`......{",.44q...0....X.....(..i.o.>..-%b.....X/....a..F......b...8.>{.....c/x.PS.qY....}2Ho#.I.R.........='...P=J.}oIFx;0w....".......5.'...B....<.i.8[T..Q..k.6>.,.L..d......b...A.C...B...#b.............K.)..m.T.g......a...S.p2..5.-.q.\..:G..>..QI..n.D..=.6...sN...).. ..............^.6.;@.{-...8..w.X.(...U......"...16.....t.=?...".qF.?....=N(.D....8MK.S}............O%x7.T..;YJ...V].b.,1(......r...m....k....E...0.O..Y.l.0Kl.......)...K.ed.*.......\.>8x.........$. ...m..B....v....x.;&...'...m.L...x..
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1528
                                                      Entropy (8bit):7.872137276295136
                                                      Encrypted:false
                                                      SSDEEP:24:bk3m/ZGBcQeiSoaR3WsepEhqMVJQogQyOWsQuItQ2I9FqTfLMkn:bkGAS9RNh5VJjgLOhQuItZII9
                                                      MD5:D0D79EAA8134B356A29E6AB5B5090488
                                                      SHA1:FC6A6469EB60FD6C97EF8F6B24C9F1A35D9D2385
                                                      SHA-256:9B986E753D5EF08A563CB20E73843F5A20D8668B745E506016F874FF343810C0
                                                      SHA-512:E74D0FBF52BC69956234B22F63EB3567D8C67D5536A06C95F7F96BA94772E0E5F91B2D8E10DDAC5F56BF1376FAAB13835096EA21255AF32469045ECD60868386
                                                      Malicious:false
                                                      Preview:WANACRY!.....~..[. .`... .O...[..|_..>,......Cu.k......q.6.F..#2........h..a#3.g)j..mu.\....o..!y......O..?..Ox.>A$..#A........8.a...).V7...I...."..>./.z.Ien.;.2..!S.cw^....*.:........`.. .V..<.$........H...c|/....L.'..rPR.R_e...B.{...[.(....g*..t....'..jY..9xO.q@..................6..y.P.j_N.i0.....tP..DB.!T.Yb.)c.ePL.Fr.R..T.....5..W..|U[.EX..6./.2....d9..V%.lH.AY.....a.W......1.1D?.\y.]...]V.k..S7CH:X.. ....y.....,;Cp...%.......r...4t|&Y..HC..>...D...|...*.z.fP...T.^.D..M.s.C..^=.f..f&...+..8.]:.D'......H_._....._t...)..'.......=.&h.%dt.Sov.(d.(..3...c...z........=..lE`..4dWo.........6..U..s$..]_@.B....X.i....M..hS...`..Z......3...ud...V.....;{..v.1.)...BK.....Ei.B.h_ED`N+.?..L.cX`.U.q......t.\.......t.]K...:n...yM#..=,.A(..@.7H.=.....U&.`......u....t..?.,.G...ll.E^e.#^_\....../.X. ...V...T..h.......<S.Bx.S..Iw...{..Sc...>C..I_vp.!..+6....>.D.E.g.m...{..../..T..N.o~...7.6....@S -fvcH...9.o.KN...=....k..5!h....j.f].MUL.1i..n..5.y.I%..X."5p.. .L)h
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1528
                                                      Entropy (8bit):7.871701710695792
                                                      Encrypted:false
                                                      SSDEEP:24:bk7qdUKJ6mJeBMDgL9NzbOGGCE2+yEiYc/cP//Zan6qorlIfqrG0QuA6K/HRZ:bk7qdUoBJ5DeNzqotEiYc/wanS5siQuI
                                                      MD5:9828391973580FD788869B041F0693C4
                                                      SHA1:6430E28499A8F65A39C3E44AEB56D38458FE1CAF
                                                      SHA-256:CE8CEE70EE583AB30F10684D4ED4BF183A0361D554A969BF31C8F91D6BC2713E
                                                      SHA-512:4A96E2D3B31DD60EB18C236AC3FDB766CAB67207A3173AF7768F21A1A61C32BD5246FF76B59C809398052F082A0AEB18A19C897D9CA4252ACCFA9CA17C92A0E4
                                                      Malicious:false
                                                      Preview:WANACRY!....k.Wg .*.&u.{b..c.9.D2.CU....g........@z.L......b.l,.k9...1.&.&..?K.0.N".....)L........@y..ns.@....@K*..B..}....[.V.=.3T..#v7...>..A..k..J.'..|..P14..7B..O.....pf.....p....''}..\8...@G8w..]#..!J....-N...QS_.W.............W../...).q).Z...~..............5...}...|N..C-..C1....z$..h.g....7.A...u.....B..W.Pvy8>...E..}.J.w|....k......K...1*z...FE..]..Z.k1y.(. ...7O.H...s../.....DW-.G.D...0..5h=y.......yS'.?.xK....@OX$n..I...../.`.]{q.........yC...v[.{n...a.SN4.G....r.Z..X..D.f87!.8.5..l..".......DA.0C.X.m.E.....8PP../9......Y.N.....{.T.I.".d...K..[.......Q...r4.].....v.]^..&.X.<N.:qWK0.."!./0g6.....b...I..l........(@\...h~.....$...LDIW.g.....1.......X..s.!|V...Z....h..{.Sl$;..*..32u....-..o..G..%v.".......:.Tz.2.c.]w...9.M.%..A..K.P.].i.6[.w.;....Y.j.0.....Rx....eD.../...Y.....s[.?E.E.oQ.~../.E2...P.....uA.y7......y?.A.O}....4..4...H2. }R.......a;Q...w..^.t..{,-......J......1`..8!..S.{...v.......q^..c...]z...Pwt+.:...m..
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):638136
                                                      Entropy (8bit):7.999704012397226
                                                      Encrypted:true
                                                      SSDEEP:12288:VZ3DgsuWTpipr1ozMI3KNZ8EcYS7X/ud291s9k:T3+Wpic6NZ8X7GIMW
                                                      MD5:ED814FC927897D25880B4FF67243439A
                                                      SHA1:08DCC31B750565832987F9CC43EC8FE3064E071D
                                                      SHA-256:D8C8386301FDA3A3FAF670411CA512F32E56DE2BD019BE242884A13B6A807035
                                                      SHA-512:B2519F05A390D8E5CF2BB60B44A47239AF94DDD1F6E64A088B973BB9935E32114C48A014BC9646DC5C19E877AA21433A446FCFBB153EEC69BFDCBB5E5A651129
                                                      Malicious:true
                                                      Preview:WANACRY!.....g..9.f.P...8G..b.gF.M..[..L.n.Q...|...$.......u3YX.T]..W..5. l...`b|....{x..N.........ut....VM.Y..1]@.{=....^.....`.D|e....!..n...a*.@...L.{.`..'n*V.)E...........*..>....ND.h..V..u...vI...|&c...>...%\us.g.B....Y.x .n.H.`...'y...!..D...............v5..F)....y...e...PR...c*..:.....Z6i.J..~.%.%.D.c*.V.....qtK.."sJ...n.lD.VW...>..^...+...._E...4...1.g.|X.u..6..=.WR..^u'...........MY.[....y.....^.(..75.....l?G..-.Y...;.w....2.jl.i....Y.....7...9..-....8...X^"...9...._..Z.i.ar.H.x....:P.z....e..6h...K..*X.....s..mzi...+r.D.ye#'..w...v.............Y/.....S.T7|.....-g..g.^F.;...<...%....j.^Kz..wC%........`!{......Dbk....?v.o.~\.........._.}...f-.+(....H.,6.>....>.J=..:e..(>M....N.;d.W...dq..9.AR*#I.z.b`.$@9.LHD...!....`<...o..8....z.Kwat...|..,..c9/...}C]I}>!.r.V....."..A..[..^4.0.....Bx........!..y=..1m.a .^...M|eVW&._d...8.pD.6.6..R....8...MT..$.r}d.....f...?h...".tx.a...j.3e....1.r..([?.oF..%.#....Du?.|... .{#N.;
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):443032
                                                      Entropy (8bit):7.999575522797635
                                                      Encrypted:true
                                                      SSDEEP:12288:W4todlrVoxG3vpQn5+WITaPCmRr0NSqTLtOnBlbGZKOHdoU8:DQrVKWGfIhjNSnBU8MWU8
                                                      MD5:3C76EC9FDA2DE3AF357B714D966BB6A7
                                                      SHA1:F219C36EF007AFA3C6E945481E9B3435FE92969F
                                                      SHA-256:5E96422589F1F1AC8395128A00B3D741B00F8EBDA72C2AE16FEEFE218A5EC7E6
                                                      SHA-512:980BC472187E82E4EC28B963DCEDDF2AF2E2BD4C6441FE6825DBF5DBAB8A495BE994D549B7DED7728D607C5CA9EB29105F0F43EB25319AE36405BF4EFEF8C838
                                                      Malicious:true
                                                      Preview:WANACRY!.....^.....{...qSt.".lt....d\.|..?.Ld..V5.. .`W*...F.a>L2..J.g..~..1.z.H.d......7*.p(F3..P..iF.].?...]...&.c.......O..~...%..4g..v....9:W...U....R....N+..bT.].._.e....}..J.............v......*..^.q...r./..{.......).Gj..3.(8.[..H/..5XC..y.L.%K.}6.......y.........&h..m.G...cH.7jn...../.35.y..N#Cg..{r..R..2.;'.6..5(Y4..:!..W;b0d. -......J?x.xR./..Kad)....W;!q.u~j.H......h..Se.zg....E..9.?]#'......9$.T{h.SY..]=...o....Y07p...8.0...q..G...7...#.#Ygm.h..#DE*r1.m...]c}....&.8.../.D..=.-0q.g..v.Z....a^5.B[.P.P......pj......M.+...q...s.>.Q......w.L...snI.mp..3....S...=Z.B......t/....{l........5K.9."..?...(.Ua:....B.J..r.......d....R......a.D....L.4^a....../G(+.Z...T.,)....^:2 ..b.n.lq.@..+.adq...=...#3c....w....em.e....@.5....`.\..,b.....>.....=S..G.k..I..)....#.3.Kn_-.F.Eq.@"..i..Z.|[.n......E.6,..K.........x3U..r1ed..'Y..,2./L...M........5%..t....`.T[o..R.{.........kf.....w.c.W.9..I.......J7.....}.j..d...C.E[.B.Je#S...E...k...q...V...h95.2.'.).3
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1729112
                                                      Entropy (8bit):7.999891829361466
                                                      Encrypted:true
                                                      SSDEEP:24576:VZsNmvhmeBkmhSDKDfaLQl77EM7uGeJiU/YobXYvmhOVRykjpHeuuMo6M6U7B:rNhXrrEj9FgobXYvmAVR9jpHUMov6qB
                                                      MD5:C8DBA00C995E85152BB790D7BA3B28D6
                                                      SHA1:F0382C435EBB962C6C1F368F2B62ADAC2F146CE0
                                                      SHA-256:562F7835335144E764222E8F5D3B2A993E696E2A571576E2B45EE984C813F874
                                                      SHA-512:9E48A206304855192875997F91CDCE326B2DE55D92ED527E6D1F8BD11D84F3080C7B767A45536DE3193EA0FE962C803C631442489D5154B8456217EDB4CA51E6
                                                      Malicious:true
                                                      Preview:WANACRY!......}O........ ..3V$.*.a<..o..<.P.u.8.....-.... \...,Hb.B...P.[..Q... .h.8.V..k).w.B.4_.......2...{.yk.PS..M..n.4...k........z.X..+Efe.#.....F.DI...F..jI..fDl.s0.fUW.B............<..WC.0G.....V^._-..V..Kr.!R'.sRA......[.7b]w"\rbg.... i....?UZ....1a.......AbeT.3.._.L...._.=K...u....w.y7....^.>b...o%...a....{.[9..!9.........mNN.x..e.O....:rp..x....V..$..*.i.?..P......Lydw.,A...w@1.F.e ..o.T./2.Ao~[.yA..........:...........6..>....C...w'=3.O83X.O...... .$.k..t3..gU...9..q.S....<.H)..G.7RU.d#..a....U........$C....dYO..(S.Y......d]}m=.aQ]..Y....D...z6L./Q"....cp.q..F..)....!(.r... I.G..z+.g..B.k.C.G.Q...^..d...rw...o...mx.....i.IV:_.m(..Y.t.?..ik`b.$..9.,.O..-E>#vO.8-.m6.....Wj#..*Q....!.2.:..l.,..t..W|...S .s..^.....iHj......|.G.....g.[.L....Q.....u..!...4.S..h.d..v...g.....>.VM...*;./4[..].P.T`ww,.T.4K....qy..pg`...I...t.R.)".T.w.......P...@eF`..tr.9..2.C...eO...1..._N../3.m..s.>.~F.c...D..V^K..>.=.X...,;...[.r}...../<.!
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):24168
                                                      Entropy (8bit):7.9927548528966375
                                                      Encrypted:true
                                                      SSDEEP:384:7Wc6mBfuEtJgg9YSUJXHBSOjki/38Ux/efIBw3Po2JIXCiTt7S1j2KOkEjL9Y/uH:i8BmEtJgaYSURgkh38UuIBIAyigkbku/
                                                      MD5:33BCFC016F8B49E76BD86AEEF76BA3FD
                                                      SHA1:341876625C70A25D2CE7357AF42BE68271D88AFC
                                                      SHA-256:A48657096E7CA7AB7928CE4F2A638144871385CB356A71921E745B6A58403CF6
                                                      SHA-512:7BB02FE92A16682D49BCD6E102AC2EFDCA5297D158E7E5B9EA5C9D1D71E50402E1B1453E530886F5046CB6DFE8BDCB94AEE699D2B9BB8BB2FF12C88A9F825885
                                                      Malicious:true
                                                      Preview:WANACRY!....-......5...D..i.^@n...I}UD....Q@p3.9<..(.@!.....Q..4`*.).......$:9..3..|.G..8.\...:P#.qw)..7..b...sh+...$...T.1.~.|..4....S......A.q:..d.EU.-.oJ.......3.I.F...Lp..+.......D...O.2.5Ze....0-..a...'..7..?..[.$Q..)Sb.........f8.Z...Mo..._r..a..,.7.8*l#.%.....D]........F.T>tt..9.7...NpgUJ...V...(.a...\84.pB..k.hmG+.6=..+.X^9O.~m..)..w*KX.Jq..9.EdK.......`V... .Sw...#@.)0....&............. .....v.[.4.||#..LAb_.n...o..........T...Y.+W......G....Y..T.......f.r.ds....8.u.........k...M/..h.....3?.s.GJEj.-`.2..[.J......e)&.^%K..2C...p..h.q^(...j..oV_G...o...e..w_.9.N.v.......C..v..2..V.Fwy..A....L.k.b.K...*S...5..N..5....Z..*_..u."..%y...)..:x......s1^Q......h~.,. %.H....L....`.V.HyS.x....z.T...K...'.U....>.@:...R1HT.d.`..p...!~.S.sP...Z...{Z........j....E....C.*w.^.|]8Y*5.fU......5....T..M.....W.A.Lm.@.2.....V*7..=.zu.....y...g"..u!...3a~c.-.e...['......p...}C:.s~..9..s"....&T.z.@.$7..h{..W.V.|8..X,y*...D.m...W,k.Y..G.6[4......J*..?p. b.`...K..7..;.....
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):6856
                                                      Entropy (8bit):7.974237685729908
                                                      Encrypted:false
                                                      SSDEEP:192:69+0GdWfLRSAEHdJ6FeWQsZjMHV645Sxi:gi+Lkh9JieWhmV6AF
                                                      MD5:03953EF6A109F3EC998377B193AA61C8
                                                      SHA1:442EDB9982F879B12423B4665713752EA9E5DD34
                                                      SHA-256:9F515AE9270C341B9FB52BDB1750D7D9194E6090EA36A773AB08C03573EF8C53
                                                      SHA-512:565E46ED05766147ED0BF1B82D0E6C35870117059C7B940B3B4DBE0B9919783BF50A957BDCAF9D0205B2A822292DAAAC3FA4708B1654EE96FDFB9A37B757F970
                                                      Malicious:false
                                                      Preview:WANACRY!.....].... .7T.ce..j%.ba..u.4..Y....z~B.`.@.......23...r..QY.t.Z'.nN.>J.Q...Vq!...`?.Dkj P..Z...M....Z<p.._u..r(..{.3..$.Wo.R..8x^...+..L.)....>k5.Q RP...S...E.d.............p...Z.......5...d....'.......(&.N..yI-S.<...r;5DL`jU...I.........&...vC8..............5..)QR.....P>...\\.:..PM.S.n.K.x....FyJ...$..$Y}t....*.cs...,k2,'m.M.....l.....A.hb>.?.H.....i...w.5..^F.....z5b.3.....b.k..g,...i........1.......^AM.8.....>l.S..EXOL..r3.?..nQqj.2......;.i5..F$.>.D........G34G".F..r..0.....q.M....`..X.i..PF.ijGJ:.h..,.\.x.h.e....z....'........G..1_.I84.0.3..!),..&.x..&...?........Yb..N?.......l.`Y?&..~...V...B4..U.....Da...P.7L....s..!HAEiu.)e............).].4e9n.....).!..K...L.'#.v..L !....P...o.. ......J...s..c0..b.E..#.S.t.......#......ql.."....D.nQ.S+...xn..i=.....T.w..p.9....os..B..4V.4..p(W.O!.")......mp..j.s~.U...=Nd.. a.....3.A#........mc...4z..n.of..m..s9.+yw.....5....,.d(f....._bq.......9o6.J_.s..t0a]....B.../!...5]n}S..?....Bj..h
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):80488
                                                      Entropy (8bit):7.997484749941876
                                                      Encrypted:true
                                                      SSDEEP:1536:bnn9dvxgVUtf77GpI/9VPeV2v5BvUV06xjHwE75R+sX8xf3T1ti3QmVH:f6VUtf75XPeWLvUV061QmbXiTS3Qm9
                                                      MD5:9FAD49AC7331B7B967300B52F4CD6D2F
                                                      SHA1:941B40744EEDAEC12F4A26510FC452731727C0B2
                                                      SHA-256:BD0EE6BF08C4216979F963FB74F603011133432293869281C7DF1634FDCAAD86
                                                      SHA-512:8A1448FB3903808C418469E7911E7C9A865BE8A34BB54F854C031F77E13B9D46F73EF448AA823DCD5745F59650D6CD49359D69DA56E0A908FDF60FB583F408EB
                                                      Malicious:true
                                                      Preview:WANACRY!......t.L....%..a......c ............e..HU.d+.......dx....].|p...........A......._...n~...Z.-......a~&cM..4..C......z{AE7.r<...2...TQ.s.a....W.y]...q\3C_.].m.FX&-$...=k....1].......O...>6...zbG..q3HT.8.7U.X....).x...Abv....*,2....... $Y./.Y....D9........+V.........o.l'1q....g...;...=.bd.M..;.[6..d .(.7....M..T......M....C...eY...C.}...#;G..@.$h.&..>.....gc49.YQ,...?U..F^..`..K......Y.7xhZT..5."....@....?.*.O!>...1..r.g'..Me1..Xv..D..p[u1lwUS.....`.W.a....6BSQ..'x..L..|u.X..2.Az.b.0....>B.3.l.p.?.h....{Md..:.?..s[.2s.\n....&../v.dU....l...c.,...".E...5...cL.......{....(.=.1<.....$,n(X...J.q.7.h.ue*.r.l2.n,.......;o..y.o|.I.OKY..>.....BK.0y8..J~/.Yb.t/}..d<K.............k..,p|o...RC................./...=.J..D..I...u.Kr >..../.3t..-i.R.y.m........#...{..cU.z.7..x.l&...~v.3..e...7.C...`.S.....6.7...9O..Q.-1....s!.7.L..y../....%....a..&%R..X. .........LK.m.+.(..Rmm......F.... ........r.}2.V....*..6Y..#..2...1....B.E...
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):2040
                                                      Entropy (8bit):7.913909627977196
                                                      Encrypted:false
                                                      SSDEEP:48:bkgadONL8UCotfdd+aZ1zchpyDAgOi1UG9wedoFmUbt:ogadOd8DoUMzchkD0wVVoFm2
                                                      MD5:4A238CD03838DB8A2B00EBCB06E7781D
                                                      SHA1:ABAC9151144E47F409E989F7259A4C577E12DB20
                                                      SHA-256:34DFB05826150BE84085320900445BF363CCB7E3D07B74E895B3CC86165178F7
                                                      SHA-512:9BF390A85E17C7E062B1711F164EE91DB8109A4C771D7B449A5B602D4DAADD79B8793EFC9D17977806D303770AC74C140A795307980C44A37C5CFFA93715D8D6
                                                      Malicious:false
                                                      Preview:WANACRY!.... ..^...Y}......).>75.v..g....s...;>#.....J-..#@zA....zZ.T.7<.7G....u.Y.d..m..~9.'.u..%.Y.%...>UD.`......Eo.P.....D.&*.....e.=w.f..}...3m+.zF..G.F......Izm.&.I.......*.s...X....$......3.(.........f*.Y..Q..mb..H.m.....R.k.....%..+......sa..O..............!.|_....6.KF.......JB=....].z_.X...;..0...7.\......R....0V......./..O".KM@...f.....1...Q...y..R)..q........LG.zJ../T.^....Z..%...#.am~./.>...%?qN...%H.......g.TQ..Q.jQ.]..)..8PW....".....F.9..DC.l.....I..B......]...."......!.?....rG..;W!..'..Nq...x..--F.F2.....uci..2_.dN~.V;.Z;1...m.2"V...C..aq.s.......^M...|......[..R.{......b~z.........(.KV.........:....)..LN,.n.=.-j.t.J2...Xv...*,g..;#.39!.vg.1..5..]zc.....z.. P.l......_.4..B..,...d...P7.~..L..F..W.G~1.O?...n.)..u.A.."......."....pl......k.\LEb'......c..;....G.......6....R.,..Z6m...O..b.t.p(X.V..l .q.-.".F{.....pi..k.J1.Uy..._.9..v...~N....o....K.B.j3H.............:.M......j...H.w..=5.'.'s.l\.Y..}...v..|..;..6..)%....|
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):14632
                                                      Entropy (8bit):7.988742141359834
                                                      Encrypted:false
                                                      SSDEEP:384:YQoAFeTaekHpkwrVCSq3EKsomw/QB1R94kBLiCLaGpHbMI2Rt6ref:HFeOekHZrVxq3Ebomw/QD4kLLaAHhMb
                                                      MD5:913C13D11DE9AF6AF60F0AD9A10B7CCE
                                                      SHA1:613665796E317B42D4433A1BC4522B900F3FD205
                                                      SHA-256:BD4ED422D6F36C0695DBE6CAE84F249968220857078F1557007728C801A8D192
                                                      SHA-512:03CD1B77B93541B8E17B2CF60134ECBCB86DE3EFF0ADDACF9E9637869711C33A5ADEA63B387BDF8D837471363477CA9A86A7D05266F2FC6A674296EF2D2C4257
                                                      Malicious:false
                                                      Preview:WANACRY!....ZZ...h...(.y.eV.:..[.!.?.1...&Cl7..7ew...A..Pd....;0g0.vT..u....f.]....j.[.h.0`.....}H. ;..e..M..Ev.ROc? .D... m.D...Y..1.(.,...F$..1....K./._..q..Q.c....]"./.`..A..N.q..|..:<....W88.[..o[....Ja..j...L....G.....t...G../_...YN..=..p........U..!......8......Xo......xN.Ku......c.OtwN...p^...f............Pm.....}a.3-....cp.......F..?u.g..h..........p..../........X.A..y....f.4.k.HV,....h...A..v.....4.Dl.Be.&....I........{.WOF....Pi6....6.nO`.4...7..x,?...h@.m.......5.'*.........,....(.T}.r..l......]../`P..(....q..]....%.....r-..6S.....H..<...5..ng;r..nJoq..e*.]3...<...QP_.)....d.....y.KBV...+..S=.g$.vT.p.... .6.^..#.z.........?.....r.3.W.S...El...o?....{x". .U...i(Z..........m6.*.s.d#........[.#!@..`....XKU.....^....T...t..e.......~...M.......X...>G...l%Y....#.Kw..).G..]..W.m<..w.w..{kIP....r.xr..l$.NFT.....=.>.F...j...(.....wC..@.....At....."]b".G.....`V.BM..DE.X.....7OA...2EL......C....X.x..P...;.S...]: ...J..M........>..?e.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):2920
                                                      Entropy (8bit):7.928838614480651
                                                      Encrypted:false
                                                      SSDEEP:48:bkiBLCQtpe8vUBjCIo9TaoxRLlPWlxW9eMN0BAwdzpEYYpzqwl/4OLbdkO86NxV/:obgpe6UBahaoxRlWX2e+CAwxSYizGydT
                                                      MD5:EA4B6FCC849B547EAFC6E15092C3A84B
                                                      SHA1:035D2D2B31DEA458556432E1EF9251EF2348EEF9
                                                      SHA-256:F1326069BD4A4186DC0CAB3BB2E32EC6F9188E5058834F6C8ADA275E68D99AFB
                                                      SHA-512:E0B18C53E3FCAC4F9550EF971D2FAE6040E1916EAEECDF7ABE1AD9B67AD9E0EE39F7ADD1CF9A9CA88AA759A94EA48B7809BF8C13A2E4F98C549A9C43D3C728C9
                                                      Malicious:false
                                                      Preview:WANACRY!....,!....K.x.A....i.a............C..E....j.h!.g.L.DF....=\.M..%..'.B...Z.t.\...m.x+...$.n.....e.....&.ME.z.ejHAh<M]`5..bVm.m.i..{7....VU...|......4.0Y...&.u....Q..q.5Q...G;..jqD..qC...R..j[..........."..Y,.Q....:..Rt.sY.W.i.....$..*.Z,`i..Hp*.T..........F.......D.`.:..XdL-....Z.....,..|x..EoN......8`G.."|.E.M.1.....p1..J.sJ...j.s.%".R.1b..Q.....i..&..2n%. o.J...-.....u.l...D...9...n.e...../-."..e.5)./.....F...!y|..l~....*.....1.........ZU...x...=!.=#.&nK..S.=...........u..J..j.......&..S.f.Al.}...Y..Q.}r..(.W.,."........]'....GF.hH...x..M.D.......*n.`.c.B.l.'...-M....z......k.../d).m35......m.h._......Y....S.c....dVo.*.C?..*u....!h$.B.=.sCS...R..J....r#e.:.I...l.RH.u}.Y2....Mtt.Kpx.r././W.......u...zNHW&.Q.....m.E.A...0..}......a..z.....7.../{Q..B.x.S.C>r.V...Y.j..i...s...M.V..~... .2...M~..M.wpn....%n6.y..CA .!....f..R.uv..q.k.'Q......;.R.L9nk..YU.....v...X.........@R.pb.m.vf......L....,...-..c*.......t.A..g..Xf.S
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1608
                                                      Entropy (8bit):7.860736249791203
                                                      Encrypted:false
                                                      SSDEEP:48:bkUa/S18Zyq/j+rZ3YpIZm9awdMaKMuvR+:oJqUmaiY93MhfvR+
                                                      MD5:E9EEB559A4B9FFEF21A9AD5B3CDEFC1E
                                                      SHA1:30DCF06C768B69EBEEE88077DE2651B8A0766892
                                                      SHA-256:3E99194CE8F218B6A82486FD7235B50F54C17C670727232A3F7930D823A5158C
                                                      SHA-512:C304952C50108DC3202556E2736AC9EAF4A6638007EF71CD4ABB2EA956D8FE2560ED487157309BE054868C3F43B94AFDD2D4F6964A6CEFFC90CAE782123366D9
                                                      Malicious:false
                                                      Preview:WANACRY!.......r.O.....%..*..7......R...o..^,6O.P.$.....,...g<......O...$.a.k.J......H..m...@.u.j+8.n>.F...H....[G.\$.H..g_.......i)Xl.......M.\ #q...)...Z...]|...(a.<....!.......f....{...ra../.L/.......e...|.F.+[....M6.N...fL...0H&....._0......,0+...F./$'F....%.........c.....".i........M.1m|h.....L.7..A.B;~.^h7xI.w.*.f.J...sX..}+..@.}~..6._..a...`a..8.... F..=,...$..y......#.W....dg....J..CMY:t._?e.2>..n.Hj.......K?u....a.q."T.U...f....1.G..zPgV.e.[).R..M\......k..[...jZ..q.?i.|.$^..*om)....T+....>l.E.s....?..Q.s[{J.Q.5..f.fw..A...L1.%..}...86......."....b....y....q...g_.... .'?S..B...vK.mZ.2h......a..w.....h...j.v......Mp.....n.nX.aN..E.8...5"...a.r......8.>..:._... .aPc../.>.K.D..geu...n.b...N..t.<.+..8.d.A.D....u5..D..'H...z.__m..,:.. ...+M.....Qg6w....Q..u_...wP.}y-.b..P%...TP......A.$.i{....S..i..".;F........N7...AmCF..D..n.I.~7..3lfT..N5..Z..y.o.X....Z..&....-.E../.%..0.J.H.........,..;x.l.q.~a^u..8d.o.y...&.=?6...._..6."..).vkq.....60..B....c
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):696888
                                                      Entropy (8bit):7.999729823779383
                                                      Encrypted:true
                                                      SSDEEP:12288:a9RcfokJq7viyc/SJ3ych/IRZiNc4hb9jI0ayc35bMGev:a9R86sSJCWIRB4hV4yc5RE
                                                      MD5:A58E25410C2F76FC38A52B3912140223
                                                      SHA1:6F36BA8CDBD842CA1548B4646ED1055A13170446
                                                      SHA-256:0155D8702A821EF510FB11402223CB0002863555DC550D3E5222AC9863678CD6
                                                      SHA-512:AC2F3CEB2C0DB8636016F600FC48EAA6DDFFFEDEC59E68E0895ECF4234159D2B1367A86BDA0177AF3EE47BF90816ED68E9D5B4DCB99F45ABD391B63C35565604
                                                      Malicious:true
                                                      Preview:WANACRY!.......;`R._...~..|>.&.w{fYL./a.J.....K.:..WgJ4yHS.... ...^...t..o..&mYF+...k=u...D...".G9i..o..''......)N... .Hdy..6.2:.j.$.......m.*.o.pqrr..*.m....#.r...N..HV.`.{..... ..(?...2..'}>"2.N......iy*g..&R....l.V..A.B...NH.a.Cg...o...U...i...'J9bQO...*@.^.............G<..&....\`..\....W.W].\.'......UET\......C...{.y..N<......n...?;PZ.o.9C......n[..s2..Q,.........]...8.V.[J..\..8\..L...}...3.<..Yzb.$.......;..".:.....L.3..4W9[..*...9,....Rm.)..O....*N..A....e......tX8h...o\...#.....[...`../..A..V....rH{.....kl"..o...>.O.T.....H].....4I.RlJ.M..[yDu...|....S<.(f..U.%..H......(.).p..A.&.......^o62.OO2.E(N../.Qgc....?..+..~..o.............`.....d...1lK....Z.....--.i.I.......<.gA.nR..]w.&).,..r..HlYPu..?./.M"..+r.P.\J".....kS.....D.i..z6.zY....+..y.O..I.A$.o."....q...;.~.....K.F...&#....ped.{.....`B.R.....d{W.?.Z......7.N..UmA.....Ic.:=.....zJ.b....w...|.8..GQ.0.?{...............?Lt.pBk.d..E..J..<..........CO+.+..U..Z.F.w..#..#O.I...6..&(E..u..
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1608
                                                      Entropy (8bit):7.886062008198423
                                                      Encrypted:false
                                                      SSDEEP:48:bkX9SEcISyvK2nVzfhX5zsU4CRpRjtV0MlmhnahqTR:oXEL2K2Vzf55AUfzv9kBr
                                                      MD5:EAC68266E75AE9ED6FDDDA4A2E662BF5
                                                      SHA1:3F0789711641B3320060034ABFDAFB7BC3C1983F
                                                      SHA-256:74AC5E5157169BFC3C048DADD33BBED6375B0D30763D5785583EC23FB91F783C
                                                      SHA-512:84D91CE9C038019EF34D1A26E74E7795C7C0E73F3346F7E7EE364322EFC853029C8FADADB997EEAFDBB57525F82FEDE851311B95DEE78A11EC12549CB17CEB20
                                                      Malicious:false
                                                      Preview:WANACRY!......<.+.......$.r.m8..m....k.|..^j ..\....(.o\.d.@.R...........{.H@{I..wUb....E..................D......SN.S.h.)R....'.X>J.2.3W5.....{H .=..~CkuB.,..yF.~J...W.K?.'`.k.Br.5..T%WF.B."..A....._.k.=.4. -)..S...p..([LF...[~.Ohwl.=i....8.@.3.-EC.G..*...b....%..........<...v.:...8....[...|.Y......._.....).}.%HP..!.km.M..Q.G..`....<Yj...^.8Ns..#_.Eox.{.............e'........&.VT..........F... \.r.p....b#..{d.I.Q.t...."....g....J.....G8...[..m.$..2.@g.>l..]$..?..,........".1.q..e.a..5#>...Ao.MqLX..L.....]v........D$..0h.1.....[L...l./6$......0..*^.F...k7'(.](.yvc.......p4..:........U...V~@.b|......8..:........../Aa..M...Y..]$..u..7.R.(.f...qfW.).vvy..!.Y.0[.\.#.CK#.o_.]..U..u...G.C|R8....v.(...OA.....0>..C^.u!.~..MK..x.+.D.5.^......j......d...?.............2K.|...fl(}B......&).%W....2..R/]4...t?\..O....-........8.....AD..3 ..5..#0.6c..@.?t ........j.48E^.>.1g..f. 4.b`a.....Q..k.4..y..?..x..d.....}.q....%O>...W_.......S...J..Nwh..+dT..".
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):2088
                                                      Entropy (8bit):7.902420675380799
                                                      Encrypted:false
                                                      SSDEEP:48:bkdQSeiKnIAktsTuIkgjmnhObSN/iTBaxEMH4A622U7J7Z3+c:odIiKDJkugk2CTUVQc
                                                      MD5:0EF024E55897E0DB3169345255C461B8
                                                      SHA1:8209CFF2A89D159915312F3D5E833EF72808E22D
                                                      SHA-256:85BB35D20CE6B03D22D9E9EA97FA985791FDDB7BACD447CCED88F98FE9BACE00
                                                      SHA-512:4AEBBC5E37A09DDD5CC09D754A6B0292501462BDAC9A3FC8B746A2DD3752C70D6F99D521990659A9C61B9FAF828CC5BA31C87F21708E14E8C6FD856541166DE5
                                                      Malicious:false
                                                      Preview:WANACRY!....K.:]..E.?6..\.....au.p...hb..V.....=.p..b..=.{...E..qm....n...).3...52.|.....W.h....G#j......].U4$..NJ...........]..jO.._).?;.j..J3.5.@.(.z....\(=...Nh..9.D..>.-.I....T..%..q*..J".[....-....:...k....^6..L8...D.vb.....R...}.3..).2....#......vW.i...............B..)...m....,...TJ.C.#h.".&...zs...l..T8....t.qD..6{a...5......3f.....HJ.6.6c..9.e..!.Z2..._....M..%./.Y.+F2..$...C*.C;I0.......o.....,..<......t.0...Rw.[?.......:...C.)...Mw.i....x...(.3.....[O..V......#.$.....}...)F....!.p+...Rj.V7...ao..D....E.aM...\....a%Tf......5mm.A.V........O.Z.9m.}.Z.....d6..V.9OT...1........B....^..>...O(....6a..>q.G..l.V.....>|.6?j.Ni..nPU.:<..B+.1..K.....1....<..1.=%.J.......&M.^.$4.#......~4~.;....=..T.....D.'.{....b.qJb.....7...8q..dw..d0.w.G.....T..~.....U.d..2}\...8].#...F5.tY.!./...nH........H......`..t ....M=e.k..ku...8...|n[.z.M}x..DX...;.......b.1..Z1.6.nVG.. G."2..A..J$.oA.@.2..u..o................[.....k?.V...l..X..h..-....N..Uax....B...
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):98584
                                                      Entropy (8bit):7.998183698264744
                                                      Encrypted:true
                                                      SSDEEP:3072:YUi51fTHa+6iZPh8XL4trkWl/K6VmMqAj+Ht15:JMTHa+/ZpSL4trkU3VmMqASf5
                                                      MD5:5FD168BD4D54DDC1571B7EBF83454F8D
                                                      SHA1:8CFF65C0BEF58998A9184F4E7310F4ED5F20C631
                                                      SHA-256:55DEAC3823776E575F82AC1CE6012EC2A5D578C65E9BAF0AD0705F31118AEA5D
                                                      SHA-512:73D1F25024D06FB3D9860DF873E6D828748A7D1C325303ED6CA5860961AEA69962050456791C175A9FC1CAD2F778BA3BADD4CAF108B9058D4E836D97A65E06C0
                                                      Malicious:true
                                                      Preview:WANACRY!....S'....t.9..s`0$.......B/.,....PI...../....B.t.m...NQ..g:...m....rY..V..........K J2C;.O....;..G~..6.M..s.1...Z...h.n.).)~.dw.......j.SM.......(.a......?.a.C....#..;z. ....;..]...4..?3..u.|........h2..$cn...0B.[..n.)......FR....o2....{....t.M.o.....................>....sb6.^...z...3...}L&.v|.yT....T... k...!*;...y...)..........$...`.Y.U.......rO...Q.1.n..*.a.L...G0.m.co..!.z.......R.)...=.68t..O.5...J.2..+..$.m...V..t..k..%m.(.2.~2..$|.b...3.6....)~&.e...-{I..u2..*n|#m>..4R..EY...,..A....Q.uY...2.C..a..^.fR..X5f.N..[J. ...XY<..W.c..b..Df."A.....Y..:.".I.K...j....".I...c.u.....I.....<..y_...d..BR..Wz...P............r.`..."..$...`t..xR...$.@.d......3.{k..r.}...#.........u6]W.zU...o.F.lx......uzs.M.....N.$.....}.....a.70`.B...VL..V3....DkX^.@c........J.g..g..,..v...Wi.z..G....@...?Y\m..w5..h..N....0.8....n...^.......W..g?o.._.X..)?.Y.F\.X:.....Z....$....w.D8..?...1.D...3L...`y..`.@...H5...x.......).....*....L.p1.h6./..b.K.N..V...a...}.+.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):101816
                                                      Entropy (8bit):7.998324523345451
                                                      Encrypted:true
                                                      SSDEEP:1536:RKllHmGwS0QN5QJzgPhCziDn6wyQHMluhVIrYrBaom5GD0V7XMd58AQhEqz0eAYB:elGsnsyyQ+yVIrYlaau8n8A8EPkj
                                                      MD5:FE197EE45E1FA24716B5126CE181F058
                                                      SHA1:AC1FB8E2BF8EBF5012D9E86B1BCA2A3D1BDCFB35
                                                      SHA-256:FCC8CD04AA585F32763B2BFE071D37583A7B61A92EA6DE209F6F252227CFE5BB
                                                      SHA-512:06310CBE5170D2DD23CC8C2F3BC42369879E7FE790F4CA6D559E3C79EB901DA61503E3B0FDD60D8508CD127AD94188065771A9762ADD7CB2E0271023262B82E0
                                                      Malicious:true
                                                      Preview:WANACRY!.....g..u...W....2..........P.>x..B#...n...P..Z 0.Z...%xU.kr ....*..^..Da.s...G%.`.llq.B^...<u.6.9....6!...0F]..Z..Q...w.|..'":...?%.Ug....&.D....I&..v.|<.<.w....F.4^.d.+5F*...E81.}?3.^....?k.B^N....-..Ap.L..c..B....@...p..H.>&......kAr=.M.o.A.7.Wu.q................!W...[_..W.R./..G......6....*.^...Z.9|............n...r....M.y......Z.I...O.6]..zF.x.'..f......... .....n........A.....\.}..F.H.........x.u@......L.m.qW.0.....4..>T]|.<7......h...WD........YxV.....a.7+....".I.mT.v..LD..)?.Dp..b.'].^.Z.G..F..n?..:.hY.+..`.'t.I.TL.......*1.......:.c..-0b.._.<...Z.....&.k.......%#+...f.'.E0.ch...p.....ij.)c.@...J ..C.XM...A.R....Q....?.}..tGJ..9KPe..m.A..%...\..w.\wm.TK..u.U.....|.U..6.....c.2.g...y.`s.a..|..........4...#H....q....Uk7.....1....G...7........k3APO{..K..[.|...1.Xk..1.f{v..\,(..Vv....?..?P.C..]..t NU.2&...v..._=N...S....6...h@U...........*Td.e~..Y.\|.#P...G{O...z.H..-...a?.V.H.E.....+.a.e....#K...aM...K ..8ef.C..*.d.n94..g..AV.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):102760
                                                      Entropy (8bit):7.998142093755336
                                                      Encrypted:true
                                                      SSDEEP:1536:7RBWO7DcLme2/3lO6uINZ5djnE2u7TWTiLJbBuq6evFTcDnDcqJwcHNdjb53tGgI:7eoDzMmZ5FE2OTWib0ST0wUNdZoglTy
                                                      MD5:0C361A9F6A432923D2006D270C0EC1CB
                                                      SHA1:16D1BDC3777C7E7AA1A0F40B4BA2536BC2C40AEA
                                                      SHA-256:3EA38FF2DCF1E622EA7666BB944E0EFD7AE04B538EEE942F762C24F98ACCE092
                                                      SHA-512:B1A439E35BD0AF460112BEEE73CA822E9A0E6A1AEE8DE519ACB5DA27A946DB48E1AA77737358A32949BCE4EFB638197F4C413AC47646EEA7C4090CE3132C54F5
                                                      Malicious:true
                                                      Preview:WANACRY!.....4.p.}.=O....W .....v.S.......na.w....,}.=T..q.,V.Z..3Un.....&.M#'..r.....LzK@...T..B|...G.....Rh`..8..C...e..6J,..../..R.r.&..:.J.....P.<&9OD.w..t#<..U..5...t...F}.B..q.Y..f.\U.......$...'$v...i .....y.1..lG.r.n..4...r../X...._0.'....C>..H]6.7x....P............F...\..+:....~p..Ow.....n.4..<x.......P.E.@.Fi......@.719Z.j.u..g..O..f\O\.A....... J..6..t......r............z{T.5j.yL:g.+..'A9#...g".Ay..M....|Q&.... ..rV.K.._....kv1.z..m.h.....S.[...1.....W.<.........]".VY_.:sk..".0.:..}....>}...A.j......2.mU9......]2vz<.C5N....8.YG.l2TvA.~....^.6.X..8,.}-..)G.AW.=$...5?M..O.l..XT....c8..y.[..6|. ..s.....A.D..M.B..Q...'x<.^8........vJ9G.xC...ty.+.t..$.....Xj.@O..7.|Z.8...k.L.q{IrU...l.:..m.-..WX...v)...RH.pa.s..J.p.I..}..d.y!...C..`.N;....5..ar0.....n\...-s..v.......Bd..c.c._..........A0.9..(....G...v.as.D......f.cB^...f..P(5..7..2_...)....s...K..-....<..#ZG....Rc.#K.._/....>].0.m....c...W.T...M=`...SD....{.57.1.!.dO.a.g....[.J....!..}.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):104072
                                                      Entropy (8bit):7.998377447581812
                                                      Encrypted:true
                                                      SSDEEP:3072:VxA8+mZsWD5EeLHuouynolFXdgpJqnjsVm0i8Yljo5QtGc:V02ssLHuouynox64YnBqjYeGc
                                                      MD5:16413ABB58E9C9119FF1B0CB17C1DD77
                                                      SHA1:53B5314C2830D9702575FF79C31FFA2C85FA0F04
                                                      SHA-256:23050F1B567D85DC317CD55D49AC762FDABCFA7106E5BAD485BC597E9877E480
                                                      SHA-512:7FA71BF1D7E7B2CC12E55F8A67609323128B23EC606819AB473FEEB324E957724E7C5211C937B980458658BE0544E3F8F04D8151C201797885B673E8825A852B
                                                      Malicious:true
                                                      Preview:WANACRY!....w......:.... ...m..wM..H.=.............c..q#l.....V.!G..f..d...lr@..g..M.q.].....*H_O.R..Z.(PV....a..Z...v.a.>A)G...#D...q.D..eK.....+..-G.>.H.D.P.j.....;>.3.d.}.....s.H.LwSD.Kw..'.0..TX..@Z.$.....P......MhM.w.....h bS.y.......(...X...%...#.I5....@<....h.......1n..H1.:..j...8.Aw................H..SG.......w&`,.x...[@.Sy...<....7.q....d..".5..n..Q...su7d.....(....=......i.,.)s.....]s.k.....u.\q%.......&k.H..5.E.~..@.r.48B..4Z......4.Eu.....B.n..b.0.l;...](..9....DZ.#.n...>[iJ.R4......71..#....I......cY....@aQ...dW............*L5.QQ....G..g...9j........h..NWAK.g..^.S...UG..^.n..kx*.....M...w..h...._Q.E..3.r.[`hK.......m..}l.T).c..`vK.J..T.j..Z...i.b..D.;kx./."q..Gi./..q....G%(9.0.....=.......Y.*...5n5/w1?...\..x....'&.0Kn..R.j.y.D......QR.tS..2....L......WL...p......6...9.U..]c....h.B.....$....z.;..i..G{,..^.G.ik..!R......\Y..s7H........%..r.u.%(|.%.....k.....-....G}5%.O..r/..*....2Ks$my...InwuTH .)..g......Yx.Ya!...!.Gw;...
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):104072
                                                      Entropy (8bit):7.9980732706473185
                                                      Encrypted:true
                                                      SSDEEP:3072:i024qaX+qf9tLZCogOKuzhPpRejXmEYZNlgIUI7073PRs:iv4jXdtLZCJIhPp4jXmEgNlgIb07G
                                                      MD5:457CA2E7E931BD97389E3EFE30A592F7
                                                      SHA1:BF25FBDF354A4795295617207966B7B0703E0F77
                                                      SHA-256:830E8E800B6745BB7D5186890342DEDA6B9F6321520B8B1F79213C07660A07D0
                                                      SHA-512:03C7493853AAB6A45ECBAE3EDDE8E299810D6F6A557DDC07B8B7CC6DFE59DC45D87FD79138AED0351531A3174E767C32A2821DB5524C0044DD17B45200011D71
                                                      Malicious:true
                                                      Preview:WANACRY!.......C.}x ./$.V(,.......J....F.HI.XK...8.`.}._...R.8....m.CaN....6M@...N\.,+V......z....T.H.....(.mZM..6..0........#$.u4.8........>........Sb#>tT i..t.....w....$...Qq'..+.t..bb.W"...KX....%...cJb.tKf..c._3.....+.=B...7<s9tR....t.._6.,e.c..F....&.........h........:d.;..g.Mga@....K......%...3+..>.6....}..A^...v;....6..h.........;.c..g.....5...(w.S...b...b.Q....u..l!.`"F*.S]...[=w..{.]/.0...)..G..R.6.2J-.!..a;...."KJ..tv.....q.....>>...6.!..=Z....iF..8.Ez.......J.B.hK.J...xq,..W.&@..[w>..E..O."[..#}Wd....H......,..+..s.=..u.x..F......m...OGo....t`A....9,+s...o.......-7.zk...4.l`h....s...../.?..+78.".t..H.......E...,2 .......x.<..._O.P*...l....Y......t{w...c..\....T.~&..O...nTj...=.......W@.YEt..>.F&.^.e..O(.XM.x}..eR5.P.g..667;@G..:..az...x..^...Srj.X.R..:.".c'..U.....4....X.!..[.p..3'9O.=.5...w..Y.#Ox[IN>.H.z/&q..x.[..u..p.P.~A4.3.J...X.....l4.........|..{m..?.|.:.x....Ff.>..So....z...[...cg.7.2....TF.s.V.!.....*:..i.....X...d..I...u(x....
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):104072
                                                      Entropy (8bit):7.99817706523581
                                                      Encrypted:true
                                                      SSDEEP:3072:ikPKObX4kPK0HC+fjjplOT35d83seefBA1HgQgEJ:ikPMmC6q5dNeefBA1R
                                                      MD5:9D2D0F8C2E38C387D3BF451BD8EBFAAA
                                                      SHA1:A3290AA91B74A06FEEF8A6C17EAAACB910DB382C
                                                      SHA-256:933D2A74389B1732F2619FE7AC921AB4307280ECC702C4B86412C1A386B75300
                                                      SHA-512:4F71F95F25FF7B4BC77C96880C498062C1A3474E82FF4C230404EBAEE10E935352D16206EA120CCCD8C341E3EB6A80289D96209EB3B96106BEDE2AD8C96AD252
                                                      Malicious:true
                                                      Preview:WANACRY!....m..d.....;..z.Y.5.....4ty.....k..kW..@H.{/.T..PeX.....j/..S'.j.0".c...@.W..y..e.q.....";..-......2.R..,..?~....B..y.I......z]...{.{...5X..y....?V...b(|..W...1.3....f..Mi...d..7...C.......r...h0G.Q.@.....?OdY..5......-.u.....~.~..~.S.8.\.~...@.."....h........c.3=........8....Cp.~.<T......`.T.4n... ..62.J.|.`y.J...8[(..]..j...v.J...b`}.~>.=Vz@....k..#q.a.;..`ND.....G..P.tVT..6...#.....b.. nz?.9...S....Ud.LP9vE..a.3Ji.. `2u.........p+..C5.>..`..[.....=%.Npy....mU.VI.#.IH.uDb...*..{X....8..q.....+..Q.|......m.+.RC}..w@$..R.;\...X9...@...1..fDZ.V.F..~.._..[X].aM.}#.:.+L@..!.;.DY`..ofe.\..._....O.2C.\......+~O.lXB...Q.,.!./jC..@......1.......Hm. .{5.r....Al.k}...._.)x.W..Z.,.1ei.[....c....)?.......,H.s......).D....wA.....i...s.O...."o..l...5.$.0C.h.A...k.r.EV....B.....'.r{.ile.K..=u.f..3.2..Q.#...u...F.c....&.........G.4&?5u....YpwF.s8}..... W.N....s....;#P.Ya.H..cP....3.`...v...R.....U,.......>H.D..$\.E..n............V..+R.....
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):105464
                                                      Entropy (8bit):7.998410986146707
                                                      Encrypted:true
                                                      SSDEEP:3072:ZL2IsjqV3oPmQsiapNQz9uI6mDwGBBg/N:QFZuis9CdBg/N
                                                      MD5:681521BA746BC5DB331043392819161E
                                                      SHA1:E015222F656E980531419B5E52EEDD8D67324752
                                                      SHA-256:73E8129987FF5A60C2AD4DA541D1B4175C89B8A9673B114B344FAEA400187F8E
                                                      SHA-512:6C36DF33B96CD968D3FBF61C04A7FA14159EB12448270A67757EFA82111740A3FCCBA90385CB8A8B51AA4D11C236E7C54850D6D34F71CAD53FF9279B76C87EA5
                                                      Malicious:true
                                                      Preview:WANACRY!.....S._...W........c.........Y<(...eE.3...x...$.y..?#.X.B....&.^B..K.D'.-..4s..........c-..tc.S0F..sWl9^{.....?.s....LhdB....T....U.GP..';.H+..Y....Q....H!...a..,.C...P^...<F.>...K...vX.-Ui..D...=X....H.3!.i*.['..S../|.An...nYJ.d..ts..._................*M}.+E...!q..h.^..5......(.=o....,Q.a..q.`@.N..f.O.Qzh..s!..F.t..A.....|..W.o...2Wb....A...E.`...(-.j_naa.V...q...L.|..{Tn.K..#Ui?....qW../nEq(:[.o..`..+......~.(L....0..ic..Ff\.B..@...(%..<f.S.o..k.D..W.)...I......T.bt.A.*..*..?....q..xoj...%.?...}-....k.3+c........s..n.OEj..a.^.4.........._..Q..y...SA.....AR..?.-x.r.=D.;?{P2.&.....F..w.9S.|.a.4..Y!H%z/.....]*q.&..q...UB.(...\......B_.I"z....4..d.....O.SdvJ8.//@..V..h.G.&.}.zD..][..I.`6h.....\i.}!5.i..g..!.D.r._..".......*..IF:.L..3.k...W!b...Y.._8...#O4.f..M.....&NiNg......C........7=..h...K..D.@RFG....,.J.n.......y...g.p.@G...o.Vxy1'.n.O.@...<n.*y....:...../UURHn.F?...B.^..)..9..H.@.i[.1....5l.e...F..HQ[.........q...a.O.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):105464
                                                      Entropy (8bit):7.998353792043287
                                                      Encrypted:true
                                                      SSDEEP:1536:G5FRMrlbQxVU9Ur5ieiyn/51r4No3+hdpvG9bezD4xoVOz6gMEPoSfSw8b8at4:GnRMrJyr5rxF4m+hdpWG7chMEPndat4
                                                      MD5:AE75E35807474A9564A74F8C0915D892
                                                      SHA1:D935343C4F1DF24EA6FD74818D71A35C1C1E8E33
                                                      SHA-256:AE121739BF1521740F9CD4ADD03913E9B2CF63D09F13E0F511814F1DB99CF5E2
                                                      SHA-512:7ABA134EE9695F229576C17ECBBAF9A9B28888488030CB3A41B1859888A2319D9563EFBC745903D0D8EFEDBAFABFC2AC1A9B568BCF77E294BDAE7F214008B6E3
                                                      Malicious:true
                                                      Preview:WANACRY!...........:o.h.....\.ZCb....Q.v.D...U.1F.*..E..2.l.t'.MS.Km....?." .d?.qR..:..N....K.)4.4.....x.E.P.A......%r.v.U......|gD.7|;,..*/|..B2..i.8..R..C[..Y..?B>iZ!=S....m.mU.Zh[9"..oq<=.......d..s..-..$......M.......?.P;+S>...... ..8W.W.t.m..S..^L..b7L.;..............=.A....lv...;..........j...%q..V..T.....=.sRs.\.=.......V..D....N5.y.t.,....[H.$.m..>v.T.........U.hp.].)..Ng..A...x...*c:/a.....M.i..o.a.x..E.............8.ov.t....tU....8..0.....C.......O_+....x...D.7.."..tB.)...U.w......Im....K..S..#..m...(J.O@..^Q.s-7....*...]..`;.j...].k...J.j$....h.|..J...=..w..B..|n9.5_.....g...7.P...CA.=.T..RZ..g."o.....Z>.,qRI&.S<L.J.........cp/......X........1..-.........DA.+T..Q...).9.bM=D*.5...!.J...2Y.&.>.|..'i.SsJ.x.{.p......w.wQp.._...$-..'...B. ....Y.....v...E...\czeR........9.Jf._.=..{......y'V.\.u.k...pc.c0..ud.......u...".....A...#.d.oE.M^.1L...z.,aA..[H&.2.[...._\.._E..R..#..s].S....zYP..lDG.g.-}|)...1..........r....[5.a.c.3../1y.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):105480
                                                      Entropy (8bit):7.998218219655311
                                                      Encrypted:true
                                                      SSDEEP:3072:drCcCtNuN8qn0jJIC495zA5RRNhhGJ9X82+7xQk:INbuN8q0xAZA5RrhhI9nyxR
                                                      MD5:1591F52743FDCC98CE58351E7E42AFBC
                                                      SHA1:3FB7BF6C9C7200E8210CDC30BA4A1FC417D28CC3
                                                      SHA-256:7CBA4BD7783B4BF934F68349784422C527FF90C14C05A8D943CA7C2E175903C1
                                                      SHA-512:CFB5299ADB67675DC873F466FF64C42F03057A1FC2E453D202DD8583CC162B3F7FF6903F5C161D6CA585FBED45B9EECF26D3E881DE4D30427A62B361F01468C7
                                                      Malicious:true
                                                      Preview:WANACRY!....O...-.A...^U..#U6.......(..#..ei7...:.....p.,?...M%.ax....lF.O4b.g/..&K.,..=..0......?f.v........`.q{..+...f..,..@.z.......8....nZ.;.....{g....#.rXegB.3...W....I3..{#.2...K.R..}x..Im..^{.#..Y.w..y...VYdMj.:.T6..B.;g"Bz...`..a.....{r")...-..s...R............dl.j$a...U...^].|.........4C9}h..K......Hn..7.*...2...E.....?m!..^.a.a..8.Uf*o...7..."..J..;..Q8...,a.xX....s......K.d...!..PByG.....%........b...B.......}...H5W....`yn..!....m.jr..;.S3}.W.|..xx....^z..s.3'Tzy..p....f~..jS_.Rt9..p.yim!X..ZR.V.)\..c1..2......U......@}....A...ya...5..<....d....d$.ql.T...5........6l....=.!....J..\CT.l$..1./NA)...{~j..+n.._'.\...Q.Q-u..!:*9.4...?..Nv.........(..Dg.....Lmf..o0>J.#...8_.k..8~o..:vr#....e.........&.:....c...^.a.K...`(G...P~.j}.Nx...)...u...G....9Z.....^..>.)m..cX...).$.d^`oar...._......J...}00,..o.....6....?U...u{;4.<...>.zGVU......c....UIJ...Xw.....^...}$.no..]._y..a.|..[-..3.......t.7.)u.t..%..\.)K:T.@.;+..1Hx.X..... J...y.M./....R.fKZ..
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):105496
                                                      Entropy (8bit):7.998051196764029
                                                      Encrypted:true
                                                      SSDEEP:3072:q5AW/i3KTg9zUPS0q4oqlpFgvv6aGQUq+SseiU:4K3IcUPS02qFcCaGQUxG
                                                      MD5:CA1113978E2D3F993928BFA6845D9444
                                                      SHA1:541E7768223D7DB09C26D81B5DE8F899B041082F
                                                      SHA-256:9471DC6ED30564CE37804DB5E9C38FCAF4C7FD2A71C3F56E6A065CE382091F0C
                                                      SHA-512:E73D72C390B4B38D671EFF98BA031D4FF66C7C699ED3E4C3C3862FF1B5899B1513047F9F2FAD86C3348B76F4BC2C073E462FED8C5FD9942810AC6A4C069A800A
                                                      Malicious:true
                                                      Preview:WANACRY!........+.H.Q.Sa.S_.p..'..hm...=....T.SG......kkM..E.B...8Bb,....R...i.....#F|h]}7o.......}.0.,X...0.e<.........@..^.s|..P..U.......@....._...=...j[..@J...,.S.....C.(.........1#..-6......dY.. ..[...V.b...M..z.&..?_?....&...\..|....{.... .CCRs..............Uc.aQ.f..l7..\..P...5..D...o.HG..j...k<.........Z.....u%Z-4.=L.)SSo.......[{..n.U..^b_,?.Ik.,f.p>.I...........GL.O...$.......O.F...Qa.#...y*D~..x_>........6Ez..x.Ob.....J.....)...t..I?;....k...73... .^8...4.....SY.....5M.s......M..a\....e..m.g....x>".jQ.3..Y.D[.p...`.b...C.[.vu.LF..5$.;.P.sF. ..%..B.._.....Aw(...^......l..I.H.....S.L...`.6......\...6..AJ7..0.}..ek.,......_...../.,nI.?.\.f]Su.x..R....m.h..o.Htu......l...6#....._.?z....8w..2....nr.y.......:E.{iGP.!!.;o...=.|..C<....J....>.5..<R....Z......3.J.X..zM..!2..._.m.K..'g........hY..M....r'.2...k.*....k...!.....TG../.. ....A....s..f..~.;c.......t.T.v.....d...1i.I.ud.&..P%.....c ...=8.ixx....C...![.c.CI.$..2:.,..B......y
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):118072
                                                      Entropy (8bit):7.998404398137297
                                                      Encrypted:true
                                                      SSDEEP:1536:DQTuxvhfYt2KIjWrKfl8vjvPXNjruOCJSyKHxNf79BJ1quJpBQrtg4dkYQSNxV7T:xvhfGSAFvfNuOcS9RNzexlNxVjz
                                                      MD5:33498FD3EA4C9F2AFA663B8B49CCDE7C
                                                      SHA1:0022CC0FFE2E50BD4AB8C3020A2ABE203ACBA31A
                                                      SHA-256:ABCE1E4AA7C733E58180E7A7F00CA442F967B44BB9D246F1741018D5D04A941F
                                                      SHA-512:A6AC1F7978537E29CBDAD72B65608AC674D9A85BE75D8AA4B81A5289964FC5515C16987F7BFA69B73B1739F2B0DE4F6BDFF67726C10CF3D848ED1E9F516EB096
                                                      Malicious:true
                                                      Preview:WANACRY!....DcK......)q...T......?.X.-Y.gd...h........t~..ah.n.+.e..8....*RB....f!~(gb._.-3.k=...d...U.N...|.|..z3G.:.y.f.Qg.......B@}(.h9............xt...i..CG8.My..,....d.QQ..Znr.0...6..u...,.v...J...Y/..@s..>6.....8..W.tn._G.$....2_C...".T'8=.gH.R...A..K..]................j!4.AU..8......Y........v.s..F...c....v-...x../S.;....f.q.GE..%wf....t...$zR....g.._..0.D9}%....[..H.+I.K&...D.J9...{JReK@........x).u$.~....T[.e.^F.a.e.;C.J....;.}....>^...O.hUE...V]....n....._K..ZtjA."c..p...I......oR...e.UF^^.v]..AW......s.....(.S.W....p..4.. X..M..*<....Ag...O...U..wLUN.Ko..!/...no...{./jU.$|...q...J.......L..C.......j.G../.R..v^.3...^.Y..%M...u`h&>'.+..\.z[...a..0..j.s...o4E?.N..`c.~.\.&ZlnL@...pi.......Xi...n.b.;.j.....~...$.Y...3Jb/C..]....U.....32...L0.O...7X{u.......S.|M...8.....&.il....Dn)..@..W0).v...a..l..p9.8,;....`.2....}.mrB..`...0sm............n....z...^....J..F..s M'...KZ../T...EG.,.7......A...!)n...#A......Q...g~...3~..e..^{.zw\...Uk.)..Ae...
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):118072
                                                      Entropy (8bit):7.998447234685394
                                                      Encrypted:true
                                                      SSDEEP:3072:nIASZEOI9kEb3oS8MFAM3BoZlgCEim3WaNddiR+tVAC:nJSZ4WyuvgtWaNuR+tV
                                                      MD5:BED00989A3DEA6981CA7B5C8C8015CE5
                                                      SHA1:5B50C66D040967FD4D0FA1656955439E003F6E33
                                                      SHA-256:374CDF79B51D11B33BF5BCA8E0763CB8C2A1DF9469B96D9B36E32792A0DFF491
                                                      SHA-512:5274DE3067C78AEACA27F9F957D6797B64284A83E8B841B559BE39E5DA6A77F3E6C0A3EB6D5264DFD9D9115B539A86E2F7B7B64A1E8320E5DB25D6F252B76499
                                                      Malicious:true
                                                      Preview:WANACRY!......Fh.z.)..O..G.......9c\.......b-..O....X..h...p.;.T..$.m[.3B6K._.....F...t....v.=.y.}.....R.qd.B....6.h........9.XE...js.Yhs..k7...x[/......0.f...;.BX..$73.y...4AAV...+..7.. i..bR..?Y..2.....,.|2$.y..g...m...RI.<...M0u\.....zV.....2.k...L..............h.....}O.FM.3.,.p..O...Q..lc..=."LMPAw.J^Q...]Y"|.zT.S^2lih'..j ..(4....-...:D0|)...?u.C......Y..1.5v...@f8.J........(.}Q...:...S..S.E(-._..^.#.(.c'....jdS....(0..J.V......E=s<....E.Gj..F.@.:sG*.u..b$..6.5.v.-R~..6.u...3..J.yRY-...L....S";.i...~N#K..=U.....[.br.....)..X....`..&.G/..$...+..%R.0...r...=uRsR.m..%...._...?.34..wu.kdM. .:.g..J.....b....a....;..;...}......SW.jD.....r..n.c...7.a...(5..;....j.6.]m}R.....%...}.1I9lbz3%.i.U.....:....g..c..3..c....e..L....c...u.......8J.i`..pl{..q.$:.n..i..?...>0.1..]...wPf..MY.4.....Ugp.%.Qht".}AS...w.&.E..phH....#3a...>7Q..i...N......D.d..Q........z.c.T....y....{.,(..@...._.8!...+...wk...l.8.37..1..r.J......^.Z./.B-......=
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):118072
                                                      Entropy (8bit):7.998600262997509
                                                      Encrypted:true
                                                      SSDEEP:3072:3h1gHepF0l/86e0tIEw8f3FlAAF/pWobORI:3hC+pFMv3KEwG7AAZQbG
                                                      MD5:09BFD0F3E90900F821D111972985B6A6
                                                      SHA1:5254DCE7F849DDB48867D0E19AD44F8B21D1CC67
                                                      SHA-256:7C22F017A37E4DFAACDD0AADF075FE0324AC9CDCAE011B7ECDEAB710A773620C
                                                      SHA-512:D98D998AFEF410F31C54BDDED4E0C96C31F444986EA5BC25511D5652B910FEB2143B8B528ED934A32F6C480AE82211E4A1B4D13D774F36E7145E35A943354A80
                                                      Malicious:true
                                                      Preview:WANACRY!......d.=....oX....Sb.a.6.k.. .AJ...4.K....R.5...e..0.s..Z.{8N.e....(r.R..K.L(..H...X..[.....E..-..Y.....O.b.n.qN...o|!..DI.....4A...Z..J.$..%......\.....T.U..A;..z....7...D.h.....:.>..%...!u:M.sab.ep1...+....jr...M@.i..O.....o../.Q.:&fB.@..s....... .......8._s...;..;...!v(T^..|l>.....=.l.3...a....5e..e..P.?.Gc?.?V..e_..vZ!-9..a+.d...s.....~.d......@..x.".P.f.#6w..}...M.x..1.....l. p....^-?.V..<-.e:.{.......J.!)rt.rB=S)..,.XB..?...u.....]..d;......A[..2i..!...e.7l^..2....b...pO.......h.).aV...Le.i......k...xZ....t..9.......X.?..C...|H.].|.U. Bi..OY.a>..Y..+.FD..`..].c......8n....c}....k.1.hbCa.T.fxq.%Y.:....z.6%.~...I."..<...z..=..`..AA.\..E..WO...j.T|.i.....~..S..Z......M..%....93.G.tv...HM....kR..0.....A.s....y...+..a. ....`.)..#.<.(.#f..Ej...../~...L6q....u.......t.'.2*x..?...}.G.Z../.m..+k...R0...u.VvIX.|u....=...t..]......C.ys.<,L.kp!@.U2*.~...'AAoOx_$.}G...}.].../o%)..SA..<U.<..U...iE8.z.o...1H..gz:i.u....l.#...7|.kO8)...Q.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):118104
                                                      Entropy (8bit):7.9985014717779785
                                                      Encrypted:true
                                                      SSDEEP:3072:yBLuzb0CSyzNAa44As/zqlIds6RDiI3q6/DZaCfprXp:yBsbSyzV44D/zqn6RDiI66/Vfpr5
                                                      MD5:194ECD56C575B6BE89CCEE2BB808BEC2
                                                      SHA1:D40AE8CEA9FEA1F73C0475667C5CBF9C221A0760
                                                      SHA-256:4B7A941CEB3A49C07EAC9E74D2C89EE0732B6F2B68382CB6D3D2F12920BF6CD0
                                                      SHA-512:DC79136566926387EF19688C2D5918A12682B186EA2FAFB7684934E4D9143F1A5A0DEB6B77207996E47D1A4DCE97BE67C104AAE3FFFE737BBC7E3507CAFED5F5
                                                      Malicious:true
                                                      Preview:WANACRY!....^H.5.M?.>.+/X...&..%.5m.*{.<...~....n.-TU0..<..\.......SU....4.....o....z..x..H|QJ...../..h..d.;H.n...2.....#...e......H[....m|..$........u\.p._z.Z..2....{x^\.NPq....Z7...t.....am.....I.~ox....].~T.2..9.."...6./.R..|.|?+........H..uO.Py.>....2..........4......-....2dW..[.96....W.cv..V...Z.W........@._.e.........Art...4..By.X...Q`%..X...oJ.C2..;I=K6..CD.n...&.&.P../~...A..J:.}...&F....s\.A....H1..09....#4......-....b;....;..t.TLM5j.....!.}&........;=.]h.mif....k.a..d{.Av..1..20v...Zr.O&(R.<....d..v..?7......#.|..... m.VrV.U..<.ha-b=l'.I..w...T..xz.!..F.D.(......$[=.Nzg.|Ci.=.............J\........U..B.D.Rqj.K...4?...}....R.>....[Z..0f.l....O......6...^.S.....z..[.Y..;l.._..CI.....J.j..-.,..}..9.:b..Yt&`..K...=........i.2ua.W..0....;p*....9....x....+.m........G.u?9E.o..|k./s..)|f..T.y%I...M..9.x.G.j.~U..7E.N.'d)r..Q1..O.m.....!.S..;~x......'..z....v.......'.w.._E.b..T]_..,..s...v..\F.uR.e...:.T........F'@...9...#...p...[..
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):117384
                                                      Entropy (8bit):7.998374895903503
                                                      Encrypted:true
                                                      SSDEEP:1536:LVjRUTUmQE/3d/QpSMX3KUtpVFBBH+FERoWq1VCnCH3ZxBxMwhSVAUxjmcp1mIX9:L7N7Eep9X3t9Rr8VbBxV8bpgIFlfQE
                                                      MD5:A83F6A88801CB13E8EFC8039CE40F134
                                                      SHA1:5BED1807B85EA0FF3493D79F93E8BE16849255E6
                                                      SHA-256:5BD7BC3CBAF4C7C3C86EAE2A0D037961D0E688C802C124C659879841EE5B11E2
                                                      SHA-512:5F0E6F1649EF47CCF23119B17E38D0F20C95D1B398687F11F60CA49AF8D0A22539B83C409D242BC032901A2BF99A9C28AD1B71D164FB6813ADDBD5ACA04EBAED
                                                      Malicious:true
                                                      Preview:WANACRY!....Jn..|A4.`..aO\...z.Z.<......W.._....Mk)..oOJl.+p..oP.u....A..xt.)..G(h...B|...&oX.H.Tv......~.wOo...|..z7...'...m.O..~.(,9..(._..5`.w....../..9;.I.....z........N..4...g...O.r.r.R.F..{.$uy....{..y.)g..G)..~X.S..d.T8!.....G.m.^c....q..u.....d..........G.V........<..j.;...A.sl"CGFcJ8o..r"Q.WJ....(..................b.yi....k.>.S..f>.'..I..T.........f..Ts#.q".,..}.=.:s...XVl......2....^..$.pD5...s..t....;..t.F0M.#..I}...|....EJ.8.......8.o.BC.h[.K.....2...A.....$.:.0<...<'.C..c:.Z.v..V1..A.n.$t9P.;.).yae.@...m..7a:..hUu......B.....q!..........3...a...g...m....."c.@.5..e......G...W..n.L....B"..<........t......=...0g.....(..T.....\....Tu..bx.XF.~h.-....q.....W..O........GR.g...g......D.FQ.h.t....)Z^H.....#m...I.._.8,!.......5....#.....A...|. _..e8...L.v....<...0.....'.#.....;d...Nr..)[..IE...v........kq..KB.p.`3......=.|T~pd....'..0...t....6f...n.h..K..f...........].G.'.l.n..?..U.../.'N5.h.Y..[9zY....hf.5..'.....,`./`
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):117384
                                                      Entropy (8bit):7.998337606138264
                                                      Encrypted:true
                                                      SSDEEP:1536:4SAr3KTUP/1pfPVEeiwpeOi2UjKPPTlWLSzYuXKeNjBOtZmXtvIizObp:j+KU3/PVEei0XffPBEuNJemqizC
                                                      MD5:5CE08E7BB4E554954C65789E40D7081E
                                                      SHA1:8C16341AC9C1BC9420D13AEA7964821D7DCD3905
                                                      SHA-256:326CD363EC98EB054FD7C4DA4C243CEED1E814B5D83038AA03A275A12EDC0F97
                                                      SHA-512:7F41A48F1E3A6E2910D6B6C7DB03BD067437E23E786537A6CA338966D98A035ED899A353EF64E2DBCF90F32F68AD9659EBD2102C3EC20FA5226A915F281C434A
                                                      Malicious:true
                                                      Preview:WANACRY!....%.+=..s.y%.97M....R..,...(...N.....(.0..o]x.=.5.......X..M..o.3.+......0.....5.b.(...{h..p..;.q.e.,.U(..Ba...8...".s.k.\.$...:.+j#c...[].}I7.".i.e....3....v{d.Mdb.Q|Z....5g...`{.Pn.m..e...`.....+mV4..d..B..q.+".....(...F......:.@!k.".9.......d.........m.B..u.......,....6I,..-...D`kW.rR.G#vB<n.&.T8.'.-.0....b......u...T@.}...4..@.......-z.j..{....\@..5=z.C].!..m....w..T....w.......O..@..m...O.g.\../<...Dz.!..j0_#0........\.z_...5.b.......~n.5.......0......v...<......i.....Mg$.xv]r..{...#"!.n.S...* .7.~l..m./].z...B.._Cvg....r..VC..!7..8..`~H{..*.(..r.)....L.....sc..........7...:+$`<....Q>B..~...S..X........<.D*R.[fT..P.KE......X..x.+..J...H.FH../.......m?..up...Y...>........Z._|....lU.J..=...U..t-.A=..51n...T...l.C.&.............>...G..s..n.b,Cs).........z...z.%..|.z...h=..xS.R....4..H....<=...f...Sg...-.......X.Q....W...+....Yi.`...g-...nw..........O,.J..k5.Q....\+..e.a.}h..q.....*.R...M|.^...b.f..\....Sl...>84....n..U#..%g..5.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):116952
                                                      Entropy (8bit):7.998410769863449
                                                      Encrypted:true
                                                      SSDEEP:3072:5OElbsnBQUGpvQg1J+ZAEqUUpDZ7twfyKA7DewTI:Bmn9Gyga6e6r7DeYI
                                                      MD5:B49CA61750788933FCEF6C11B0CEE82E
                                                      SHA1:49F7CF5CCF1C4C57377F7B1335756630477B1171
                                                      SHA-256:D0BC2A25345F15268531D3931024482C8635E2149BE7FF7379A732FBF1141D08
                                                      SHA-512:8DE297BB71C552CEA957EE86CB23E230D0919BCDDDAA93C97FDEDC9058F8D5B5DD63DECBB6C311FC8A00FD2CBFAFD2D7A5405BDBA7FD32E00DEC306729893562
                                                      Malicious:true
                                                      Preview:WANACRY!....U.....\v`.}D.O..S..]#..5..gk....n>.V..K..l.?....0.zc(........M..PF.,<..P.\.a/.!.CJQO..k....62..FP..R.PX-..7.:2P...#....L.o..)......L0.N..Z:.eWwr.p..._.`...m.......O....d....9_Ju...Y.I.....\....X...q.Hl0&.t.e=*.\..9..b..[.v....TzI....'..r.+S#....N............6.f..Wd.<..zAhC.n..@.....!..h........Q.;.Q..cfKr..#$..+....g;..x.A..*.3u..$.......O..`.[=..\$.U;..-MmRk..52..R.....}.y.5......H.V...@.~M...].CI.>/.9x...o..W.7.J.+vQ!.....s...m.....b.:.N......3&.r....a..$.;..<.~...:?Pg...vq...%. [.._qu.G-W.h.h..:.]5^.-..E3..?........YXfy.!J...'.=.).l...I+"@(.v.E...E.....z...3[..h.s..z..".nJ...]..S=.a|....L.$..>.uQ.v....v.!.x.V).....l..JY...5Q.Q..Z....}......b.0b.h...X..z..7j.....aE..W..?...r..%...|...Oh.lj../.px.\.........E.J.A.....P...b1....=....'..E........''.H..._....Q.8s...}.M....{.@..._`."'..7w....A.....^.....#...Mq^..<.1......ufT:...SP.H.9.al.u.....>..h......."M.t...k7...........i...[#w6..gf..Jxi%:....a.....[....)<U.Ae.....+A. a.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):116040
                                                      Entropy (8bit):7.9984658593487055
                                                      Encrypted:true
                                                      SSDEEP:3072:Ht9mCmhN/yGMXAvr2PK1nMuf/kF3Qwqf0aGR:N9MHqGUAj2PK1FnkMfNGR
                                                      MD5:4C445E50508115E3AD338C02BF24B8D6
                                                      SHA1:1C21826CD370D9B3512A4CBEC0CDB5485C10A67A
                                                      SHA-256:724523AAA4757BF5D38075F3BCCA8CB3F8D2A1F25C60CB0B90C9EC1C59972FC3
                                                      SHA-512:AAE8F8CC32664453096E33614D3ECA72C91400DD1E9FB2F1DE7454622E4BA685FD0FAB14529D693499ECD7EC60C7A1F15F43F7F917358C2D89286FE597B6E55A
                                                      Malicious:true
                                                      Preview:WANACRY!.........Yv.......G..g.4;:....J.........M.d&.X.E#".S.4....s?.2.o..#q.N&b\v.5.<.2.li.teF..o.4.....KsA,.....a.1.@\\V.....K..[b.....Ro;...}..6W.b.2o.xP...!.\.8.b...o...<...Q0.:.M...XA....&....(....a...r..e(..Z.}...5......F.*`^.4.U9i}.u,"O.....d..xn..=c...../............O..2...`w...u.[Eu.].o%..#......y.S...b....O.6...."N6e...9 Q...~.T.f.......7j..0..z..P.E..HA..IH....#....N',.eA.....}#(vH?.V0?.4.Z.jQ.Z'(...{0|/....1.....q..T..x|g......4^.M_...9?*.t)._...l.;z.xQ..[..A.7.oYWDu1....g.....p ]4n.c.A..~.`..H..w.....;...>y.qsW_.r..-...G.....C.......W.......5..v.e._OxF.-..}r/.[..&...Q......Re..n..".G.H}:.a.........;Svo.....Bc<..C...h.p..5.1..@..#...F..4.|;...9}.ZKS.c..o..*.....z....\.....V>./?..p..e#peh.)..3.._...r..Q.iWn...^.L...0....<.9.H.Zg.q.O.b05y.`.DC..RCn..-....T.nEf..N2...hl..Q.%JLN..h.M..L...G.c6..v..MO.-...6`L...k.3F.......=b...o.ha..:.#.%......J...?.{...Q.$.(.#5..."..Yy..C.Z...\..X.T.o.{..].o....Lxb.?/.wQ....a...v29F#.;...
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):115096
                                                      Entropy (8bit):7.998475688974396
                                                      Encrypted:true
                                                      SSDEEP:3072:AMVX2AOkEMU6daIn2+99kLLgEIvXvochgRQxNgVXFTMTRD6:AMVXjJPUIc+9yLMEcXwgaVTM9D6
                                                      MD5:FCFDF63B1E2468904F96AFDB8C35CD16
                                                      SHA1:46395EBCE09FA00D596BFAE0975AE358EC56A70E
                                                      SHA-256:4016D9A4BC03903CA1106D2791DF702902BA4D38BE79AB96846DECF0C8256B53
                                                      SHA-512:7416686252F4403C9C6A6D3513501634FAC469268628FF08B209E6D086FED2F488C9387E445629D942EAD19F20D1D475F9B2B542CC0A44DFB577F393CB009249
                                                      Malicious:true
                                                      Preview:WANACRY!.....W.....>1...#.~.C.g.:x#w.N&.....vn...(..@...v..\.Y.....c.,..4....m."..d..NV69y......Y...:S.....y....k......HL.......F..F7............loV\4A..l.....|....5..(.?...b.......2v..L.6..B"|...k4La...{.C..?.[......I.!c..B..B#<WA..0..+V...L..[..^<.../`.....~........b6...^..I.....y.|.. .8..Pi..26.H..%_..N}r..=..\.......#.I.....J,.....8V......P.C.:ag....R.......k...[.Zy..s..@.H.G_d&X....N.Q:.......?.]]...X.'.(.$X.*....o.,.....u..oV..5......)w. ...s...9Q_....T./$...'....{........"w;...'...}.w..9.4....#.+;...&V....&.>..k.*..R..v..?...../I.gI...d.-..=.......*F..~.LOG.....m.....@..'.L.<.4lL...t.=.......-Mk.(...qDCs...J?.(..%..........N'.J.|.Z.u.DC.L)B9rR.oO...s..:.3.}~..~D..i.):.X.....T9..@....2!.c...>G..fjs..Q........Y...5....Wm.Or..o..]..|....m.U.P..h...D.%...M..'.O....g....k....=...%...h..Ao...D..S.....z...v.0.T..v0r'..|.$...c.[....F..cwP...Eb.Sf....`.'....[.....5.....f.a.:.~.YJ....WZ_../,..]E..y.......=....Qy.42).....]../.*KJ....
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):115096
                                                      Entropy (8bit):7.998607677518114
                                                      Encrypted:true
                                                      SSDEEP:3072:GhIBmfBfxue2UUHapnUWD6I3Kw/YUJTXy1FkW+Mi:SjfGeMhWOIbJT+kXMi
                                                      MD5:95D354A21177379467EF0545FE8786B4
                                                      SHA1:BCEC649BF9C983EF918104B1AEC7129FCF691BFC
                                                      SHA-256:C74EE90686C881799A8F86777899FEEB4EB6F7486D22123F23FBE3EEA286F9C2
                                                      SHA-512:50CB05EBF87C09E16F14112EA967B24FBD13EC19B49ED283894C9092E35A57CDE6B5C15BC76FDA9956EEF0C647943853EACE827D256DBB6F0C13D74DC16C57A9
                                                      Malicious:true
                                                      Preview:WANACRY!....|.Gc.....Q......R|W..+.x8:P!..GC..6..1.{..#.PR..Xm.. $..Z.k...BO.w......h_.......9....%jr.vKd{..u...#.C'..H;..._*./...t......h",......_..d..h.......\G....J.._..X......q..2..r...W.... .vV.#..U.67W.e.5..<+..u}...'.0.........8<.....5<........;..e......~.........y{.Op..}P...q....!R...S(8|E."1..hX..J.Ko...C..IT.=.}...l;T./.g.....E..s.Da.....=.k.f.?m(g.k)...X......f..o:*..;.G.. o.RR.n...E.....b...j.r.V<I.t...vH.1.......!...WE....>..)g..#...G..'....d..u). S...f..P.l..j.p......3.{y..A.....CZ....V....9..$6$.$x..Y...k.z..V...8rZ.W..P..%.g.........c..v......\.G.;...?u....W....yC......7.Q.Y....@...../.B..Eb..x.... .y.N..2.*.Qj[20{.....]9.....Qr.B....$.g4.......m...Ot9.....M.].O.....=.~.e..tJgp.. .kt..cr............S...K...>^.*...<\kg....Ko2..t..B..J......y....l....o..)c.[.:.].AH.c..~y.......3.....^.}.tFR..R0.o....]v.6...0.a0X...%...PP,....r.....aE.. ..lV.-.~Q/.r.&..E........<m..a.....^.x.PU.............7.J...P..F\..,..jf.....*-[...G.!..
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):115096
                                                      Entropy (8bit):7.998431435823143
                                                      Encrypted:true
                                                      SSDEEP:1536:M0tVEm065SbBb4rhpuWOW2Id4mcJ2A6FqoA/4QHohOsZButrh9S0olgnC5M8:79SbxesIOJx2A/4QHf+BAGlM8
                                                      MD5:8A3299E92E3884D8D6662A769A5661D9
                                                      SHA1:F98BE7DEDC2E1113CD03C322F187D3B3DC5470F4
                                                      SHA-256:EE6DDD75ECC82BC3817D6D54C496F63E5C527A9E95816CC559357ECB53128653
                                                      SHA-512:5CF332025EB95A013E8C22591E737EE4F8F5FEBB5A3FCDE8D5CFDE20F48E25C07D2E41678B71C08171E3F0A73C266992413206778AF5B7977B0D3B9CC448630A
                                                      Malicious:true
                                                      Preview:WANACRY!....HV`YtM.O...W.|...r).....9...L\..c...8.+.8..%kB.S.M;..3+f.e-....FN..i.0K0...L G.I..,..A=i.?....|..B....>..dU.m......,.D.Z:........L.......M.0...y.S......C.J.....xhv.x.f..+........i..c...s.?.2'..d.R...:C.P.F.Z.F...tk.=.y2...:...kP...K."v.k.%.YT....~.......r!..R..?p...*..........cG....Y.m.oF>f6F.m..:.P..b.........RkZ_...P..g86qsu..:..4.^....E.5r....].$..;.M} ..k.<..b-...(-._QoAK:.h..:..U=$..*w..u.i....,n..5......h..nu.3{i...4LW>EM`..0G....S[....F...1..{e.... '"{...Z...?..........;.....F....%...<t.....{..V.........+_..:t(....}.O{y.{!..We...K..0.m.7......W.m.5&f]m.'..X....\E0....=.........(.x..G.....;.O+-.-P.K32.S.}.Y.Rg@...-...+.6..........ZC.w..Jro.;........z.y.eo:..!.w........E...;U:u[..71C.'..>A....'..8..;.|...;3...}X..1.5..:eO.O6+i.N.<.ja..+.w52....Z.t.f<_k..m...@V.|.>3........?d..dPG^.....P<0.w..!..oe[..x..[...{..8...wN.&.V..?..R.F.....?.#....9.L.,....6.....G...r...>.....g.F]z..*v..FQ.>x`.b.. ..9..^y.p?.%.. .r........3..G
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):114264
                                                      Entropy (8bit):7.998492771503279
                                                      Encrypted:true
                                                      SSDEEP:3072:uihEFr57Qg/k8g+egRV8zh8gqgqhm+rxF+1+:uPd7ZVUzmLrxw1+
                                                      MD5:D8EA699DE0BE7E974F049093549D2305
                                                      SHA1:FDBFFDF5D1BD3B67734BFD12306962A3FAFC7A2B
                                                      SHA-256:A47BCB33FC505B5628DF504604F818AC6A56838495602745ED1F10C951FF3864
                                                      SHA-512:E1C2FEA39ECEC5DC896DE88B583DE39FBAE67B4599E25D483910A1B4891C6037014FB3CA51D833CACC8ED44707416821F0BED15C12A723066C9A3FC11663B664
                                                      Malicious:true
                                                      Preview:WANACRY!......W$..?..2...n..f2..........TWl....'..-....X......[08.%.J..mb...D..9Z..*...........+..u.u.i!...........2.....!Q.Xrj.I.zn.,.....1M.<3.8.C)...w..q ..........2.6.Li.....9....!............7..pF.. .v..iy<..K..!z..~...g.r...=J.M..wf%.&..x...Y....6.........q...I.5....G4.B...m..}..4.+,.p.E.4..@...u..K...Y.2...Gu...$.Q..,/.=....o..Mf....[...$[G.n.0....{..h..p....-)....M...B...x..4.phmt.=...jc .9.|..Zs\.m.Z...3.../E+......4.....j..n......)5.e..#w...7*c........X..p.../..'8=.........&.>..8.1j.j....27}>#N.y.*9+.84R.c......e....>..54.d.....\... I...F-^..R......q.a....r..OF.:z.I.H.0\..g$.RR.8.3Y..._.....=lw.f.Q..0.`..#G...6....9T..hn....A.n.1..;..W..u..0.:E.a>..'\D..O$.K.I.X..Ob..HI....Z1.....?.D.H.7....R....oC..z..].sG.?.r....3.9....f..wQ..@.....^O....m!.B..s.?........m.i\..{..*..D..Uzg +.=~C.....Q....u..3......h.F%.e....h.Fg..G'..".is2UfW*.,....y*..m........U..H|..+.h..ED..a/...6......I....UKr}P.r..H.YzhT..Z.....t)^B..@.dzJ..2.D...s
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):114264
                                                      Entropy (8bit):7.998465315805634
                                                      Encrypted:true
                                                      SSDEEP:3072:mvmtb+kUjjG+MmPtASsIoe6gieb41AzuvW47j32u:mvUtIG+Zfoe6Ouvx2u
                                                      MD5:C91E3DE03D64408379374D101D309B73
                                                      SHA1:412DCC3A28360B5F5D90B0095854E1DC843128CD
                                                      SHA-256:159FBC60B68CC05091D361B6357B711741BED30B9EDE81D3E01B38E5D64B2A56
                                                      SHA-512:0ADC821F7C7E7C3AC59EB66BAADB25CB31DDADDB7277EDD2409C6E2FCA760EADEBC70286DB02190A9C593C30002A905B2BF029C9E2B0643BF20A5AA6CF3A93BF
                                                      Malicious:true
                                                      Preview:WANACRY!.......@l*./..6....^Memm.m.#$../"...G.....Z...J+n.^R.'..*...C..W-..p...;*.j.E+5$.......wT......OsG"m....oFN.G.',..ha..Q......p6.W.....@*...&qOe.W.\...k.......ef.b.7.a......sk....*......F..J.O......,.J..q.~.;D...y..5~..O"+...VU..5.b..a..N6..;..@3...-L.fd.....6..........i]..........>.q.\...M<..+4......\Qb.m7..M....l...8.DWz.r..O(...A.b...?......Il.c.]..j.H.X|...(..m8.:....JTV,...v{..e.K...ta..........rF.<...+...D.t..Gl....a;p.%........d..P2:...o..8#.....>...........w\_.....O^.....I.._kY.....5.....n.2.....d.b.q.Y.7..%.dPx3s...%.........%.....).Y+..#...(.;...........[p...D.rK..G.....J. ...U..n./....y.MQ....n..#.;Q.u[...C....YH."..p;....((...F.~Dc......~U.._@.g...m...g...N.<...w`H......j......O..:..4..PD...O..cG..*.T#....BL...$MA.K.i.`.ZQ.C....|..u:.*.Fu.....s..C..(...''.u%.q..T....B(._:l.2O.j/|.79}..Z..W...y....N...b........Z.L..6.8C..9m..Xw.i...^...y..&...(.Tr...@...!.5lg......:........._.3n.G.h.L+.}.I....3.2..J.....~.....f....4..f.E
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1426184
                                                      Entropy (8bit):7.999892376402034
                                                      Encrypted:true
                                                      SSDEEP:24576:o+vjBud5jTdP2zgjj40PDFiLyaWz2d3NcEsA7Xf03sJJhZ4RVOve+jqb8CoiU432:oyBuvjl2Ujj16Azs2R4Xf9JruSveV8Cm
                                                      MD5:E743F74965040346F5B556D6D227C5E8
                                                      SHA1:FBBB264E06074434308CFE7B8A91E3E027FE94E2
                                                      SHA-256:5309EA465CBD7216D00FBA8F237536A4317DD24CC2CE913D17C8357662D516B7
                                                      SHA-512:1B26548210172672281D395AA34BEEAEEE18BE839EF7D5402860EBE9F5412E02085CE6E0D16B63F9E8C778E6AF9498DD4E4A4C1B4EBC01ECEF3FC39519EA60E3
                                                      Malicious:true
                                                      Preview:WANACRY!.....:...s.[E....I.. Ei.r......N.Qx...X.D..2.....Y.r.._.q....>}.Q...tl.*..K.J........y..U..%..)....V..}...[......'.........*............q.. .A.'..U..$.....o.[.Q..DfQ.O...y.....J..3..`.N.C&.../....l.....n8."....T<.W.....lZ...Jd..k2..!.w...;.x+..Y.h{................Q4.O.cx.I'u74AH>.'.....Gd.. .bm..P..!x.I.?....y.I2P.<...tO....df?z.6h2... s..Tv.....b... ...;.6K.9.t.V...<..<../.w../...b...|.......+..Vp..W..)......3..v..........fl._..........g...>...6y.;.Hl!...q.~.o]z?..:p 4.*...q.n.....YT..H....h=v.l-.$o...M....}..!".E.j.f..R?..=16%..].5..T...........~{c~....X.....ft...........QD../D..Y.\.."....0...m.~...wf:.J.O... o&?...)...XU(.......U..{.O1.h.[..].>.O.f...+).@E.....z..f.z.......aU$@w"...A......2.n..=.1<...P.=.M.r3b.......`......IE..q@.<.,1.....~.....V.Y..wx.h...H....Z....f.Wv...g...0..q.....*....) ....f..[{. i...hQ.XX{....N.>.VY.*<mC.SG..&GX.f..w!.[.sa..Y...'.6..d8..B.ad.u..f.&^.....c. ....2..z..1.D.c.......B.9. X9o.Q..V...H..w..(}vr..lV\...H...
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):352008
                                                      Entropy (8bit):7.999419498427925
                                                      Encrypted:true
                                                      SSDEEP:6144:CrLfdKCkoKrbkDjdvvXXp3whUI/ZUzZUZNMgLXE/wgx3zXf6hiMm:IgClmbFUIxUzm7Mh/wgxDIo
                                                      MD5:4A1E4C0231A6830D2F10257739EACFD4
                                                      SHA1:B28FB3834AEE732B6DF06D9C3D84B959E6B683F5
                                                      SHA-256:3E40A764FDC2BAC82FE5181A29D5808D7335660A2E59FF99029C5C37CA3B5D41
                                                      SHA-512:F15F4AA12B6EB5C24CD3F810F68FB27F8A42EAEFFDD70A94C96D95C26E628CCD34447D6E3B5EF2FC5FF9EFD962D38BF4B5BFEF6E8FCE72E29D895B4C0A91877E
                                                      Malicious:true
                                                      Preview:WANACRY!....3.G.T..aI....o.]'.D.h+...M/.$..7.......2.jD.K..X..uuJ.`\/f..h..9.NC..I..E4.'H..!^....0f.H..OQ.N.6...Y.e..ptJ....D.F.....f<W..Y.7-..........L..v..|..RJ+.`.........M...m..........F..e3.D.}..F.&.v.x.W.......\.X.n..YZ{M....!24N.j..s.:..8!2.............]....... .h.......;.S...X.....Q...0...E..rW.}.......}8.....X~(..z.P..!C^..mu.NP=.Q.h.~.aZ.A.(...U.z.QSs.....jM8..gp).D.f.{.?..M"e>#....$8...c.P../2.x..r1'.........Rx..l.*...Fu..3....N..}F.C .h.T.X?..j.?f?..,.0S.{.N...A...a......!......&@.7p..~d.8.u.q8..}.&..1..-..z...&Y.H.w8.>:$...|.o.MH.4Y...................)....g..v.....A..-..45j.....3...........>.?....m..9..S....j..sDG....]..VOZ.6......86R.I..r.;.a.L....}..8L././d...^.Z.X...].V..p..Ff.;%....N.}.?..$.;!8O.ML}z.*.S$..........D3.......TD.Gt.za......ob..2.9H(...../..>.AMW.v.Y..w..#......-..ey.l+.O.6.ss.&Nj....1.e.7.."...c.:%P;..x.oP9.*.8.}......s@g.O...d..<.".oA.....9..fE.y........$...\...g.4..... s'.?..Y.....,,..j.&.yR.<.....qr.}.O..D...
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):243784
                                                      Entropy (8bit):7.99929259073878
                                                      Encrypted:true
                                                      SSDEEP:6144:oDlyZiGgIX7UEOf7EaFA1V9ggQcafQYrTVr+:YlyZiQUEpaFMbggQbZS
                                                      MD5:4504AFDEF179971D3ED631A019B84E4B
                                                      SHA1:C32D55756F77EE9352ECA4DC77DE436F34DF1F1D
                                                      SHA-256:ABA72E4CE71E0E48B54AF066F1254EC4AAF00E213B2B3ACDED932779788AD430
                                                      SHA-512:3DB1525EAF5F9CB1BD4C823FDACB1C54BDD852B95C3D91858FF458B33DFE876A29121A05B72F1F7E50DA6ED1BFBCD54961C2A9689DE853849B6B120796FE299C
                                                      Malicious:true
                                                      Preview:WANACRY!....|^.....g..0t..Y.Z.......k.-...;...<...N....2>.......a..Q..)_.2..|TdX..3^...E..^.2.2...-..<m/.A....!.q^.mA..!.X....x.{SR;.9...O"A.l.....C.8.s7P$.0.D..l.>.;....\d.5.=.q...3.!..S)..J.-V...b(.....!.W.9...]?2l.c.b.'.p.....E }9.:?.:b....|.`v.........&.......0E..R........cE.{..N.........+U..t..o....".....3Om.p...X...3R~..../.Yp...>r..........yl9V....3.....v.w.p...h.....N....U......9.k..p./o.E......o.\.@A.n.m3.3.O.........TMO...R.L;=)..3....MT.......y.Y..9|.uC.....w."9\!..Q....E..z;.V:...:(.g..a.`..nn{..v..^..Q.M..<.j.......<%tE.h......!p.NH.u.rh....&H.z.%v...`(...)/...........7..b./+......L.f}k.......V5)./..<..}.7.v.....a.R..Wg)t.5... .^.[~zJ.<..&..Hn..X.n.JC"...E.oY'......2K.3...s.l.d8"qN]..jp.y..1.- 0..8y..X...4...H.P{..ansnd...../0.+.@....V(.eLU..U..kj..D;._.n...<....Igt.*...o,...F.T............v.....[.m...(LE[.O..p.......^..........l.kD.u'...x......+.....R..8.....}.4..=<.......xo...(..XIX.+}o!..NSp_.r..J)..(E.P\.}....{.|Y.i...
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):44792
                                                      Entropy (8bit):7.996180382502978
                                                      Encrypted:true
                                                      SSDEEP:768:GqEIdyw5pG1XUXMgZplopuakr2lz/g1RsFTNXbRehFyOlQNb6hKz22/HBtb3FlXZ:GJIdLGqXM0rc/aiFTNrRJNUhZmhtnQu
                                                      MD5:6B960B3F4F6DD7EF11F23D15178083E9
                                                      SHA1:5FA0E3703CDCE48CABC4CCF3AE513EA531877F4F
                                                      SHA-256:8CB0213F8078902EBB5557F9AEFB9E55E8EEC6DCD99F3E1C62327E7F66A44AA3
                                                      SHA-512:FAB1914D90B646CC947C161729F970018561E98B76926F0504FC8BCC11E1FD9E7A08EFFE5A931DE25B3C8752CED479A3EBF4D9A8A9BD7371B21DB63DE03845CD
                                                      Malicious:true
                                                      Preview:WANACRY!....!J.~..1.eli.X.... ..!.}...0.g.Shw...F..;h]x\......./+.$m.H........x./-s%!...}ua)R.oZ.tW..........-....1.:.....S.\<.#.?V<...Y+..$..O "..F.^).G:.t..;..U.Xe.k.....).4.k.8I px.....s.Z4.G|..S..~.z5u...\..SHQI..Q...V..R..x5.T.3#....}I..W........h............}.^T./.ia=l...:....W.FNO............4.z.kT9.%.b.cQc..{..w5.g,..a..j=v.. ....QC..G....I..J.q.N.E.<9.}J..u........0R.#=..KC.........K.A..fZ;ggA....J..........W....e..B.e.kBy..5.....:.P.s..[.._f|..F..H.v4...P.A.r..^.i._.=.....aR0..<.^.H^.lOY..q.4W.#...qO0.......I....V..F...U..=..Wl......9.o.t...#.C<V..8.)..R:\.U..ii,.hVA.D..!....m.lxS.B........p..N...$.K3.+.f.{..C.U-.....Z...AKbt..@..M2..y...;....I.@.$..t..-..C....,.iR.......n..T..u.d...u{HUn...<o..Y..].........r..3...f.O.E-.g...#T9Y-.)d.......)..=P{..........&q.HC'M.....b9...+.%p...@Z..1]Y...L..,...S...:......|..~...5.e......}[Q7.L`.B...3.......i&..N...(NN..k....a.4b1.*....c["s.Cn.nA^...Z.*O.v.uc..........U.R..i\.W.`,pF.p+:...
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):37464
                                                      Entropy (8bit):7.994961345605732
                                                      Encrypted:true
                                                      SSDEEP:768:3PFt8kFEMng9qsEVDLbvRzGOaCUIRdyiolh2aKRFgdV+BIQi8XYx:39CMxVDsLISiolh2DFgdcIOg
                                                      MD5:06BC0C381BB5ADDB90C94698705DD177
                                                      SHA1:BF1BEC13BCAC46BB5E863F71F6DA5736E6F55F25
                                                      SHA-256:EBE2935B9827E80407888AA99C156B1731316F366EF3F9A734E158591FE47E8F
                                                      SHA-512:15E665599A27D614223AA0F2DA983F294E0BE4BC418E27865C753112C3AD16D255442B696DE3AE1019F3957AFF97052167821DEB33174DF6909C7D9438B7CF7B
                                                      Malicious:true
                                                      Preview:WANACRY!....E....../L..lE.-;wL..t Q....z...0h.........m.....I...F ...`.*r........G..qa.....j...f[i....4,B...tM......D+;..K^..4[.x....`N.O9.2B...z...}RPLp..N......y./[............0<?.../@..}>...9z.z......B.}.U..oV.......Q.#.n4.]?.......+L. .x.34[-..6C..n.AR........4........5...~..V9....|rD.H....Q..z..S.....I/.;.......zF'x....R.q`.>.MS%.&.QN........Z..c...........i..^RX.......h4@..a<..9v......#....g...e..G..'....?.pK.+..LB.G...L.1)X..0+..N.z.+{....o.v....1F.....Q!c...&.....h.Y!.m.../..dM..$.)!|N..z.1.7....t)..)._Db..9.cd........O|r....q.5nR....".5......s.5$9.THP..U,.3....`....@.6..#.../R.f.....T.fJ|Fh.............>..r.T....J.r...h%....UU\.......K.!@.=....n.8.FU.9.^8.R.(m....U.l+.!k....=...+.....-.P*.n#5..@....O...+E..Vm.m...J..W..9..rb|.z.B..."Dz..1w...Z...k.'...bV.?rq..=...K~.[Q.Ph\....4'.#..UE..b..g..R..'?[.WR).f....[........>$.......=.M..*C;...1.....G.O8O.M..&.....j.7...,..C.O....c8.e..sk..r..v..+......d.A...v..........,.Q.".X..O.P0.......
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):37464
                                                      Entropy (8bit):7.994830554682372
                                                      Encrypted:true
                                                      SSDEEP:768:8CieLA3vdFc29w4b5tUJ0vvwo4FSgcwBQX5zoGz7Cmqzalb2kwFcXBhx/PmbHuo:8CBLA3k29tb5WJRo4QgPMxw9oWh
                                                      MD5:39AC5890FD8CFE8E128A16FEEE9C7627
                                                      SHA1:E0B16E8A0ABAA83FA1E8FDA040E80DAF78159FBF
                                                      SHA-256:00AF58767AAF1F51CC71533882CC203EAADD2AE2751BAC7329DE9ADC8AAB6B53
                                                      SHA-512:B73D062C83089C191B94D16B85F683EFDD88CDD8F16D15FA745363496F9CB2A603E1077BE902A86DC449992C70B75E45206CCE2810A94D6689FA581D7A32E6ED
                                                      Malicious:true
                                                      Preview:WANACRY!....uQ...y.c4.F._:o.7G.R.~`..GtYo.k.\..m...U.......1..}..+{/ZsY..`S,..|M...S.^.u.Q.qn&p..7?Q.....~..b6.[kw#.....l.o7P.W.z.).....C.[.9.f~2@......}.$.....w..4...mx..E..=..i....... SBI.R._...?+....b...^~$L.r...."p_I.5;H.GFQg.A./.h..G..tg..;@......6..z........4.......y..X.l.K.->.....R..ZSF...A.qr.....k.G.j.H....<8...~3...+...,.P..'.m-.,..).J.$,....@.L...W.U.b?.....yA......9./.........H,.L..p...1(..~i...p..@.E....[.....D.r.[R.....R......N...|.'2.G...@..-.s.bc]e..,....L..jU;..m...`.~...fx......[.4F^.H.@.h...YG9.U....q..n:..D.4..k1p..\.^E.\0.N...@r?.6...cA......P......#.I..... ...iCo:.@.\4.&q.N_.z..>.n..<qF....._....2.g"F......i ^0.......0s]..@.'.8.....V.....6...j.fy+.'...%...M%.... c.I...c.e...C...(......`J")..|....?.."'4.M....}..*..........u..ES.|.x:.......X..%8.EP.....!..5.:.Z..!.{O?1...@....N...+_..+y..3.1$.#?..P.....=S......a,.pn.......K....o......l".3....N.@..$.,n[.l...@..t.....B....vI....._@k..Z.<}....6.1_...........Y....o0u?.h.X.....2g..r,
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):37464
                                                      Entropy (8bit):7.994920339931241
                                                      Encrypted:true
                                                      SSDEEP:768:Tb/djdVupqkUe0Ge4u8Bw1WE7g3JHBUVwbp/kuTVWTyBeGQL5P:TRfuwk1enBIB5SVkHw+BeGQL9
                                                      MD5:28F66AB691977E5E6B75BE028FB0E9FC
                                                      SHA1:4430CDEA8E4F39B69ACA7038E0538C9E2142ECCB
                                                      SHA-256:6C58E93405A42B916F6CFD3714768F2E6C98C5D58CC16CFE1795CD933B15CF4D
                                                      SHA-512:3CFFEDE390611068F8D8A8FCC5264B29043700B1D3F494D62ED1C71DBEA63EB7CD9CA7389E3839AED4815E24D5C87A36A118CF81FA47E2FE26D5BDDD0E441988
                                                      Malicious:true
                                                      Preview:WANACRY!........ .6.g=....H.[.........aC.......P....,7[-UH..=s.....W..s....~w{....'.=....z.K..~.xH.Wx..~...AM...S..!l...y.4.g..8.....@...>:.g.0....#e...A.'Y....jK..=.S$"..D..2r...,...K:..V."..oCW:^.Q.s-Y.P&Z...uiH....5FY..]...C.[a...g...<W..`A..9.....O0....4.......l.....X....J...{...........Y...........yP..p.v.2.. a....5..B..V;GU./.....J..rM.U..&..vZ...._r}..m. $.5....{....l.S..bl.....d.>.X5.....j.Q`....h..Z`.2$\2,.-.....i...K....G.......Kf..d.=F.8..y....Y.......E. 5.,......(....L...R}3I..$~*.4..hY].......h.<Q.,._m...0..l.1>.\.)._..S.r!..%>.....%5....b.8...K@!Bw.=..Wq0....o./X.....pgh?.,=u/.....:..k..N..4..-... u.Q.. ....YlJ]Y.Ac.A5.........@.3...\.`S....P[(.n....j.r.MQ&..pF....n..-...F~...SI....|..q.#vS.{.Etbc........ " .~>..;....r.d..$.r.d8].U}. ..p...m.WT..Da..l..........CTi...\Qkb\...[l...,P%...&w.0...iim..L. H1[KF..3 .kKm.X#..i....H.....)....j0..r:....uW...G...C..U.>.....K....n..jU.."..h5...C.:.GW.Ax.ayU!....+2.pQ......4...
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):533032
                                                      Entropy (8bit):7.999628872311894
                                                      Encrypted:true
                                                      SSDEEP:12288:2i3/urWQO8LIgQIrWU5ZURyQ0iMTyAElEAr0TcIal:L/AJO8ERSWU43MRArOal
                                                      MD5:55C3869E0D112976E9DA96AA7A3BC16C
                                                      SHA1:8AEA2F40F62098A91E2B2426C5CBD91438569481
                                                      SHA-256:2C82A9B34972120D539ADD84F4E27AACB28DDC1BC91B2CFB802DF7EA3DCC1EE7
                                                      SHA-512:23B5FFBD04EB9ED67F80D14A2BD9854E4DC6BBF7DDDA2482B968C169F8C9DEF45207C5E37264C40992CC111EA296D0856D963675E997BEE7ACDED40FFB27658D
                                                      Malicious:true
                                                      Preview:WANACRY!....~?G....0..4.....@j]/...S.....j...]6`........]35/?.C..s.8.0..u...%.U& ..>.N.r..J."F.E..R.Km....h....%,..|.w..q.!.J..%.n.K.(.f{{..Ry..;....o9..Q^l..fB..V.'....h..j..4P..$.g`.....V...a...1u.V.kM..e...-..~u.Q....b.B.p.=.H|..."..(.....,.'8.H....y........!.......j.`......."...|.K~.Y.9......-y...PR..e..F.r-...K.g.V.@.k..8l&.Q.Q..^....T...1..3.{.......@..x...@.g'..~L_.....8........2.-...[4..B..+...5....Y.,.*..V'b..W..m.....:../ M.FVn*...};kB..k.L..K......s...*.1k..@.&....Z.........|.w\.G#...y3......ZxO...D...Ic.t.._....TvT..}..........v?H[&soE...k.;..J(..o.m6._.I..b)vn.Q4.5.}..A..2..2N.B......../{..Fq.qZs..bh...k..Yw$q.A.K...=j..*;J..u....m.........-].V..9.gy..B...&...6...'D}...i.<.Z....(.. .WA.F|.w..cx\...h...w..3X".*....=A..1.H......=. z/Fp;A....!...t.q?r5..Iw9..K.<..U..Bf.=8...8.AP8....N.e....T.$.5....4..=..t..:...n_I...N...P.(..^dx+.,.l....O...&.e..<.....s...t.\z...C......@.:..Y.y....U....&.l .",...Y.) ...p.*X[F.,?.].4..wupwX.x$.r;
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):104008
                                                      Entropy (8bit):7.9984656977130175
                                                      Encrypted:true
                                                      SSDEEP:3072:P2fCSHpgPixiGjauzcAyLIE9eauOOGdWQUcwoGYNxaWLXZ+7:dSHm9cyUEETiWQ1ay07
                                                      MD5:09A01C55609135A3FBC291600E242630
                                                      SHA1:3E48B43C8B7A3363C44D09611A4CA4B2ED51A851
                                                      SHA-256:B9D5DDF0C7B4749E37EB4F6E0DB164B32FEA0F3FCE6051F6D1771793943FEF68
                                                      SHA-512:4718040FA5AF1606928AC6E58D85DF9BCFC8A17ACE0D4ADB66C96B400DED8E03310F91FA4449C766239B57E58945A8980DC13E96A1974A6E649AB28203107BBD
                                                      Malicious:true
                                                      Preview:WANACRY!.....Y3...%..k..X...4G..0k..0j2..@.V.e3.Z......c.. 7TKv....*e.X[..`.5.l.. t...r.....-..)JsR&..u..Le2..*.:.5.jC=...L..7#B.0,.5e....Z.....s........i....xx?_QuG.tf...u.yu.jl.....c..l. .....Q.&...&..M.K.J.y.L.......~.e..R.mm}.D..p..Et.r.f{R..ex.R,......%........1.z..6...P1...%T....a....g..i.\..0.9..v[8...O0K!...|.U.T..>.o........t...$..\0...SD.K^/Sk.n......o........(*2'.K....C.V........~..1K"...$..e.&.....f&K.?..&,...e..h....*iIh{........*4.....L...7R^...d.'r\},..C.x....Z{.s.:.P!'.=..W@h...l.89R..K....M!..*.C....5IN ...[.....b.....F+.8#.[.u.C..Z.t.m......*.U.~.-..).p.1..T.R...}(.D^.k.......{..H.W>DL]+-D...w.;p....Y....j..sw....~9...To........n....0[._..9;....j......UY..P-L"...{...J...O..].....f)........~.. T....&m.<.......{...V.t>........l.hI]..r.Y...j2w/M.....d.\>Gt...7.&y.p.....B....S.....l.....v..m`n5...Z..&..?\.T`G.D.D...!.I:j.C.4.^8..p.Z.....3.!.4g......W..T..\..).K..mb.@..k... .[..NB.U.I@.v...w......Y....%E..C\.f.y.Q`*.b{
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):217800
                                                      Entropy (8bit):7.99920940340715
                                                      Encrypted:true
                                                      SSDEEP:3072:6fyZKS4NARtOB2n4iuHH2RqgFuYE0ksK54DkOozCSjCBsY/CeYXaR3bjWumiHI4t:BZKJySB+9FlKYVSeBJ7YXaRLaumuXYw
                                                      MD5:33AB886284402A87048C2305571202D0
                                                      SHA1:937655FBB585388E4E9E64E822C00991AB4DD54D
                                                      SHA-256:36E38FEDEEDF786CC93E9222306D0121F73E856B728652E91A9572C6671479F9
                                                      SHA-512:F121035B14876BFAB109FFF4A61A887EAB8C2F095E10B956CFC6EDE9AD6CF79DFC9F9D6B33237B34EA7B76313A1BEB4D6A8F5B8719D36622C9DDA56528F7BF4D
                                                      Malicious:true
                                                      Preview:WANACRY!......]..|x....)&.. .u.....?..+...C;.,..../.,.$....V...E.?.$......3~.}..%..q..=e.r...|..`yI...j.n..G.....{.......Y.@.. ..x..G..1.6.....H(.{...zx#m.+.....^..7.KH@`.h.L#.~.e.....<....!p..`.....I....}..2.....w.'.*q.a..........m#..|...../.T...amO...Fp........Q......yj..c.W.2s..L.....,...t.K.-...P...p....W....E.Y.V:).@..3........mx~B.m.......z...Z..<.-..A..K`.D.Sk...$..g...HFWEl..(..v.7w..m..#....T./..rP..X"......:.U..U^..:'..`..m.\../N.l.....c.GNm.`.b.A...k{.t.V.`u...TX..ac(.FIL(..9....v.....A.kw..p4.5=I.w.......9N.q..`\....C...+.s...JE.U.....(.z.j...; .Y....O.M.E.P...........|=..O.H.`t#..b.[me..v.ie...h).:..6..Z.. ......B....Gj...........X.n.w.h.... .>........}R..ng...x..e...)!...E:0.....:...6..Jb.4ZO..T,....!E.0.p..C.2F..Ot\ ...2#..}6${..Q.8Y.I.{UD;....<^..n..ZU.sQ.......)N.p'.lc.dHM......*..p...&.8S.D1!.9.].e..Xm*.....)j....-.Z...q.*..J..v.5X....@.$..Q;9Yz. ..e..W..3..=.f.@....'..[.w.^..Oj.m#c.kD.8.........A..P..."I.............u
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):217800
                                                      Entropy (8bit):7.999161755535768
                                                      Encrypted:true
                                                      SSDEEP:6144:Ywb0qJxHrjZGp6UbJ2LefW6posOygAthXRheVGbyiqpH:ZRLji6AolaggWVMeh
                                                      MD5:4DF90683B08E76156D6C612B0E510311
                                                      SHA1:5B6D7E34A93CF846576ACE20D3DA9898C0D13402
                                                      SHA-256:E51BF35A800D1FE2B5C9F12C5CADB8BA4B5269490615FA3021E498D70F407CAA
                                                      SHA-512:3967603499927A64E3706C2A7AC3DCBE7B956078939A12A78F4165AF19719D097540850EEAB4A9512E46CAC50523C54539A474F094BA67F44C62A150B2B51856
                                                      Malicious:true
                                                      Preview:WANACRY!......b....S#..k.(h....N..Xh.?F..5....._.T...1.9..........A.....@].]......J.Y_./.XF..!."..7$.W1`..G.;,.\..4.F_....SZ.......G..}..~h+{.n?"..p.......S$.J.,..|..U...]4..(B.....T..y.qu....(1....?.,..xw.Q L.j,.Q..4.z...G.l...m.>q...>.....z.mTN........Q.........7s$....<e....D|.&.;.P..6..,....|.....7...!T.c.....9....f|..S\E$.w...j[.$...J.K.K.y......$...o.Z.O.[M.s...(f>.X.`l..w..Q.X*......v...~..L0ZL.5T....I`..|...(.........QV..94:%~2.e.,.j...A....(.J24"...V.G..6.4.I.E.f...A.In.. .x.%/T......m....0...1....n....R.y....X.,@.gC..........b.\..A%.r,...y.1.3.8.@.A.X6T..x....."...P@..1.y...c.8..T.Dq.w.f.......Ns...g.......WP.V;..h.....8..(=...* /F0.(h.o.?x...M..^:..">d.........m.yX.B....P...|....!3r.. m~..6.Rp.n...&....k.a..@......T...\6V..?s)8.......W.j;..L.&.../....'<..g=.=.Tqvv1..K...=.BH....a.Q.g...4....~.p<.:......c..&..5.............W....|k.|.Q.....G.e5.2.d......e.X.]0......'.."h0v..u*<=.W..>..z...u.kCE....h.|.....\z.}..H.d.........K.~l
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):11560
                                                      Entropy (8bit):7.982176206398047
                                                      Encrypted:false
                                                      SSDEEP:192:pFc32Kz1DMw5IS+WXdvkeghs4K5u4BP5+Pqcocy8S8tLvOX9Pr4aNNsZwR2mnItu:pFe2w1Ic9ghG5u4BP5+PEcy+LvOtT4aD
                                                      MD5:04E756B4CE2B77F8A2D4B06FFD6EFD86
                                                      SHA1:7D6729FB5506BD0900DA1ADDF9D98EF81F4EE9E7
                                                      SHA-256:3BF4E05304F928F229C632D3373CBEAD855D199F15D40E1266EDEC634D83DC19
                                                      SHA-512:C35C1ABA8A9AE8209679E2A1CCF2AAACBE6EA3F8869CD22E85B246E45C66389B6A74D50A11A4DB67D636472FCA37FA2F536F555877A9CC64C986A500135D25B4
                                                      Malicious:false
                                                      Preview:WANACRY!......GLi./s..*..crz...d....4.?.^..X=...k0...VR;...3.P.8.{......z..*..c...lb..a.....8.LB6._.X...G...us..E.yW...2..m/-WjS5WE.bFe..t@{.(........{..n.....!...u.z=T..<...Y.-.Y...o.d.....+...&......%.=.E.-.,..c.v.|.Ql,...p..~..K.JwB(..y[........5...c."......,......-a....M...tB..J.e1..@H.B..#.S.?.s.2..g.A......[.....#.......:.l}......F....t..,.1.e.X`'..8,..x.A.wg}..Qp..+.C_Pv.=b..o.xQx.....yk}.....*......Jrp...a.t.Ob..+..B.._:.M*.!>2.......).#........f].@..U.(...x.YvsQAG..c.......OmB..*c(....9i.Q.....2..y.<..(.t.'.?.O.=%..7:..`c.u3.]$/Q.TG.Q+".`..!.'.5Zx..9....>...#Wq...zZ6....qf.V+;....(S|..UO3z.?.#..+!..Ga..S....!...........R...u.uB...=....}....R...{..8..z.7...bR.F.8...=u.....UVj>.%......Qc...I.[.+`.7.p....!.N2.......`...&..y..z->..+..8'.0...'.FkG....=.%....d..2.\5...,.)[<.....q...e}j4fW.<.o+..N@'..u.......P......C...|P.L..."...U.Zf'(._%-.C...)..... ....\.Hp"...K...Y~...p..1..K.q..D.k....c........2.........D..|..`.o.)...|Z.I.......2.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.84240682110715
                                                      Encrypted:false
                                                      SSDEEP:24:bkQjT5zJbvIT5R2g3CY63XjQwMJqSS6CSqgs8UBti9d8/2PA8YjQ+9sVV4cdE:bk0TxxvIT5R2g43XJn6CYdUDiz8ePA5n
                                                      MD5:DCC624CA3A952A541CFFB5010A05974C
                                                      SHA1:E39390FAFD50209A51A8C9842E8C0B3F1607E8E2
                                                      SHA-256:D2ED9829019219FB2F0304C30BF1C33F22F818E100686F6FA106EBA0216D1BEA
                                                      SHA-512:13839CE1484394D58D9E2DAAAD9F3725802557EA0649661473705BC913B2BAEAE49E72339389250241D06D8B03A2CC2EB8E429292F88B1212572860D12833B3A
                                                      Malicious:false
                                                      Preview:WANACRY!......$.7.,,.A.:q..'......N..........U"..).3...~X.U..nkjf..h..+.03V.a$3r|..].m.m....K...&...3...(.0.{..B.....<.e.....N..=E.KPK/....Xt.._..Z..~5..'.-X....J.,.+.......#G...<.%..3(i..:..6.L.q........h../z.)j..g.A.....K...%.@a.T.:.Fsb.f.8.X.../#*..sk.............A..F....-...G..t.~Pa..bOk..*W.%HM.......|.....m...H"VL.....b...L.wk.Z.5.!....\.:qH.\+O.v.).p.J..8.b...#t.a.....<=....H..%...........P.....#>'........9.....HE.&a.>..".?.N.k.j,.;!...V....>.7$.....cA......k.H..`3...%..[Uv...)..*{:S4D.....{U.f.s$..lB.3..\.4eL.\.s....+..w.....Q...M.z....j!b@>..%;..(.(.L.%#....te.-...L>V.F.#qJ.R.cnj.y...ob...2...(Y.r.X#.>...l.....HA.5.......{...p.}t....>6....Y.H..+OQpe.= EM1(8....@;..../....e$.J..z.h..FP.N...&....gw.l...F.n.\.....<.e.x.fZ..i.py.n.7........*n....'..S.R.,.e=r28.U'...eWk..N>.....a..p..f....30....=..,2........$..y].........o.V.t*.h....:wV....;.........1....d......."......w....Gs...UJ.QH......yz....4k._...6^.O^... ..Eb..QN$?n.M.e..p
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.835577477337923
                                                      Encrypted:false
                                                      SSDEEP:24:bkhT6Jtnzhd+SEi/a/VodemAYeWLjbgFvm0DZCP2kFpnEcAJZlHmARfcV3jtSXNE:bkh2fhEiSKvuFvm0kP2kjnnAJKCO3xSm
                                                      MD5:6B18E80A407E37A87C85F8227B0F69D4
                                                      SHA1:3B128573C8F169017ACF56CE52A3F5FACD130832
                                                      SHA-256:B078F05B81B9E84772B4871EB739412E8FDEED76E0A896F331EFBB8C93C1A551
                                                      SHA-512:849C6BFDDBAE88BFF0013C440A250E486707806E8811C2CCC1C408CFC66130073D0C0BC152872E12EBE12AC50B9A472103E6DC5D36997F5C10538F300EAAEB7E
                                                      Malicious:false
                                                      Preview:WANACRY!.....=.^....;..Y...h.;4.H........i.,.\.......%.{4l.a.iP..6YrKn...O5..q.P#...%a...C.D..6.9|...a:.W.....a?x.#.....N..g..`.G..>&@.........5J.&.....X....b......S..{u|Rh].~..y.....O7"R..D..3yl)[.+......r.h....AE....Hz.W....H......~.^..=p.$.f. .#K..............6AK..../...F.R..Bb.U.VVTV.O.....l..&)\U"i.Z..*.....5....t{.m......X....{u.<. ....Q..E....B...O.m..Dpka.....d>. ..I.?......}..q{.Q\....P$..+-....m.....|^......R6...)..32..........*N=.&.... ...L.==...+. ...Hw...J|.HuU...N.+..V\.eD*...`..a...Iz.w.Y..kM........y..!.XE.........z..$.V.E........e...KS...q.u+..k./..d{......&8;Fu:....V.<....1O8?$..B.........g.T....g.3P....<N]jW!.u).|]U..k:(o.....M.y...LsL.B%.r...i...qF...1...cTa.n_...L>....f.'..L..T.2<..u.O..|`p..7.V>CF....i..=..... .......3:.\.>iJ.Q......v...........uz..........<.X..?...tB......:...l...y{.<. K.i.-....k.:+*.j.<...L...<`r.gx...n].+.........P..xB.".....a....f...'.Q...%&..,.....k...<...%L......`.)D..V....Xn..h..:.-.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.83064212852944
                                                      Encrypted:false
                                                      SSDEEP:24:bkE8qM7ZPiaagXV5btUVuxjzFdRLNxloKHu8Byo/l62E4p3ywzWp9Byrj+:bkE8hXagX3WVehRxlBc2E4N1qyn+
                                                      MD5:C27ABC6C5C9EFAEE5253DC2E70DED925
                                                      SHA1:DF4C69E7EAB28EA727AF8634A2330DC52C47B047
                                                      SHA-256:8915E98193B24ACEB40F995AD38D97FB04FF4C6AD2F7714E6313999A81723931
                                                      SHA-512:11B1DF85A8C44EF48E813D282F43C0ADE3AA6F298412208E148EE154A1EF1ECB04DD95BD40114362A68F3996A6185AD83412BAD9D05478B5616F430FC29DA2F4
                                                      Malicious:false
                                                      Preview:WANACRY!....?#.!.&....S..}.D..JE.. .o..=)i..D..W.M....f.(...f...v...ZqQ.._..vsp..A...A>.?.9t2{..'......nVH.d..%....d^.......|.!...H.B.*.6.:..=.d.0j.j.p....t.Hy.4!dO.c<V.....1.....;'....>.P$c.$(....4W}&4t.;g..[3.!.G.w....VR....}X....I.Q.}.,z...m..DG4...H2.............Am.....[....:..m..ccv%.79.+..e.@..u...b:.&o.N..._].X..........9..........|_.1`.q.p:.....u.!.?....w...X.U./.p=.E......)S..92o.. xt..y(..WY.......+.{K...V.-.-.YB....N..c...#..@2..8_.9#~.Xi2....>z....._.........G,.s....j.g+.....V..M...3.s..CO.....[Hu...C......:..Zhd3....'.H&S.(...\3.%.._,!...x....d...._Y....!.uF..[Z.}..}...N$7d.p^N.9..r$.9......&]..U.j."Z@.0;..L...g....! ..G&.......b. ..Ik.....G..Ut;...i.4..<..kC......J^..h&....D....>...o..fD.....3..9H6.<.K..lt..b...{.W...I.b..#..(Xl.M....4.{.8.8.6-i...=..$......<..../...c..f..>..2.. ..(....k..4$..=`.E"SAn....u.=......PL.x...T+{?......_.9.".]..?..C..;.#.@]..4B.!..Dc.S#4...;....`5. Z..'..F.1..(Ux9Q.........T...%s.>.L.ez..,$.j....;v..1.....
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.849099880792621
                                                      Encrypted:false
                                                      SSDEEP:24:bkZzY9tdNzpUp/0TWA8hgMzfdBGR8x74m+a2m4zP+U5vFhZpH4pOeJFlyn:bkZUrYMaAEgMrI8x7p4D+e4pJo
                                                      MD5:F64BAB5F427CD5EDE4B795CC2A44AECC
                                                      SHA1:2EE2E38FE13BB4B0746C6771C4BA1AA6A1A6C4F9
                                                      SHA-256:537CFCE9F1B1496AED03E0517605802E6BB5301D14B444FFA33C75C095302753
                                                      SHA-512:5D8062FC1AD439E37BDBC895927FA61A8227A8BF348AE46470FEB36CA2B9D379BE0221EE0EE32130C1BEA85760A6830595F43248209789D5B1F87D8879CABD5A
                                                      Malicious:false
                                                      Preview:WANACRY!.....O..D^...u.....fU.I..].....i..%..}<./@..Jq.....F..-...!..8..(.P...............A.'.../.(z....R..W...7(...Huh.B..._.z<&6K.....3>.j.|.C......\...i...7....F_..nuN... ..3x^.8.M*..(.v.....?...$(.U.AD.....Q...L...._/-......a....f...s....'vP..Ml.8.3.K...............*......Pm..7x~.j..dY..gw..$.W.@.......l.....!...,..cZs.$...t].|.P.EO.2...#. "\G_W_..3...o,.FyP> 4.b........n#@....bl.g.5..k.4?.....#...W...D.}...!.|d.0.`kT.....q...}:.~........Mh6.............t..U......r..'>2.l...T..,......=.5.|..[....K...r..cc...._.05\.....*..?T...?....... ...@|H..Z...Q.!..v":j=+x\.Ho...>....&....a*.....q.y..Y.Lf....y.....!.X=~:.....'.}G'$.$P....'f..;...o.5.....K1..s..,...M..m.q.<..A<6>.<i-I....19%.......B./l...._..T_;3...X.=;.JT.)...AF...M.B.8.ig..[............J%..U....3..U..{.(..5Y...Sa....}C.i......V..Q.4.\._........W.....En:.6.c..Y....w..>.V)"....%og_..W....;......4X..p..k..Va...3...C.X]..J...F.h.x1>.}.z+.X..`X.D.h...I...d..+."....4....<...17..
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.853852133615042
                                                      Encrypted:false
                                                      SSDEEP:24:bkpaHscx9mAYwCzbu9iZqlr2Eg8UfgdyojXC8zKo74Ob:bkp4x9mgCzS9iZGNUROBr
                                                      MD5:2F4D2F0593A82183B99A74F046FEA296
                                                      SHA1:8150CF37C6DF8F6E43356CB1F2D7FB4B1A3EA843
                                                      SHA-256:DDC42FDDE86037B4A86610802992573B49C4E256D2DD0E670E2D25D6248C55D6
                                                      SHA-512:67ECF55637FA6754D927F50657D2D821653D6A6161E1750BA8ABAC700CA8DB8C4BFA745721F666513120159898A6F67900E98D29DBA83725A686C00391A2BEA4
                                                      Malicious:false
                                                      Preview:WANACRY!..........uD...X.e.C.../....b*.Kc....n=..X.....D..U3Z......l..Y.'Q..D........p3g..3...z..{G.J..m.A. ^-..,..m.....#.^.&..@4S`u.h..%.....Dk%...^O{h............;2^..+h.*...{M...W........5./.k:..}}...B.H@[..............(|.......8..t......=..O............}.....&.T.G.(...-....A._....UPga.aQ.a].&....qH.I=........_>S..i.b'....#.?.8...l.-&.....{..L..|0........M..N..~...&z.[..ijH....*|:.c..:.._..W.v.H..;.X....n....T..d..f.........N......!.;...%.....Qp&r......A...2.d"..i["z.w.Z.^........<.b..g.zh.Sw.=5...+.@....g..r...&..M].k.g7..)&:...%..^.K0yi3...$95..4Yo|..<#..j....8../M|~6&......oQ*tv..%.Y:_.>.tl.}..paX...6Sq.WKZ........:.O..g.2w.....5.g.?\.LP?.......=....w..Y...x..TN...89....b.u....k..E.fH.u....L...vI.....8..yx..hq.".J..B..r.?~..oX@....D...Lc..."_9?.G\..Z2....%.i........W.............U...."...-...X.G..R.".sj>..2.%).g..... .QMK.I.....5....k.`.9........Y..hT..oW..A""..XE.MX..?.2<.....4...H^Cj...}...@-B.}s0A..3..c.h
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.859509933467673
                                                      Encrypted:false
                                                      SSDEEP:24:bkGqHPtbVEwj5NRGUYyDO5Oayq4xhDlpQQrCPw3lRON/su2IA8q:bkGqrhj7Rwgaopuw3lc/su2I9q
                                                      MD5:A4E9964068EF0DAFE18B3248CCE299D8
                                                      SHA1:991221ED6125C8CBD485737D1FB6B84435E23DC6
                                                      SHA-256:EC0CEDA645E8AD0D4EA5596D603187466B77B33E24ACD107526B41F71090C6C3
                                                      SHA-512:1B347DF2323F4B47710C2B502C6B2D8F7EDCF7B965E121E5AEA5817E625A4393DCE91BCC5A1CE23A6716B944E88A33B508AF86DFFACE6852272FDD0B95256B5C
                                                      Malicious:false
                                                      Preview:WANACRY!....^.Ri..^..wW.'u]k..2.L....j.W...A![.x.....5p...E1...'..~...p..I...H.....f...\p..Q$9%0>..F..m|...@.n..N..._..J.H..l...%L w.Z...pr......H-......A#.,*...}X<.{v+.^.V..xU^..'.{7..N.9.x...J..j[v.S..".B.....q.....-G7.I.U.8..!..^..$N8E.?.4..H.._........................$.(.....t..w.W.$.G>......MC.C..)c%.,;.J.-.%g....>...Z'G<I...p...d..E......B..r..G.b....(.+..[<..Y%..A.S...7\.G.$......@b........bw.\..n.VAU%..[8k....T_.<......[..\3n.h7?...`......].},`.00R.oh3\z.....M.K.......\.|T.X...?..2J..iC;......]pO#.%..b)...h.._.E..$..r./u.I*q..s.....\..]*..&...Q."n.O.n.0qb..W....x.N^._.hTU......jz.S.w...b.t......l..'.b:........f.3.,....'.+|..1...5M..5>.........Q....m/......Wp/........XNZ..!2.B.PnX..q..dQ..D.V.c..t-..zd..R5.c..6C.....i.....%.!.QW).$..Y.m,O...(.N"-+.....yh...M,tf.k6u!...d.#....1...]H.!W........UoKe...g..21..... 0.D.r...t....x.HTQFIyQ.K...].`0.w..Q....:..m.I.'B.&~.},........Z..#O..,......ay.'.....2f.ID.....p..DP".vW..N..<.@...P...K..Jj^m.......
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.848832529091301
                                                      Encrypted:false
                                                      SSDEEP:24:bk9tlLSeJgwdhsGUi9X14/3rI/+fNTqyQFwtZLuqMdFFxbQbgq7K8jf8oNg59:bkLlVJgoX0PrHTJGFb4P8i09
                                                      MD5:9FD722E3C1EA4DF7CFCE9E83AD38EC67
                                                      SHA1:DF7D96E5ADDF1AF29D703DCF4C7875D33ABBBB20
                                                      SHA-256:0FE5CB9E453D8819D5052DC83A3631D9A62152C3625792B70B6E363839E7CC47
                                                      SHA-512:BC41631CD6E1043BF685E7B013F036493EA371094FB7D4317F5A21C6BF541226726A06884763AFCAE77834BAE2029F2E918D4DCC6E24CCF47490A7544CB6D3B8
                                                      Malicious:false
                                                      Preview:WANACRY!.....I..Ra.....].....,.bE.~tx..Y~.q.-5.......Ya.3p. C.~ev*...hv.s...g..giCJ.([.........t'..O....i!.1..p........u 9N..`..f.2..}.....s*.~.......bZ....}8|)..dM.8.....v.. @2uO.q...."...iI".#.....w.6........t.sB6lh\ZRSX.t.{`..t.p....=....}..LA...=.@.Z,...............Q..j....?...1.}..y...fcg....)Rt.D.|b.9...`9..I....%o..T.....1.....e.A..b...@h..C!hyR..r....w.PV..R....X.@....U....b....X.r.o.=..K._hU.....lf<..y.......u>......I.(..f{....xi..~...3.[.Y...M._.FXC`7.~.W&...,.'...(.H...C.B5(.z...l...........>.~.S..)...JB..n._.o..;..........^.A.|es.N.\{V...a..*...#.%m7G.@...S...U..1...8..v...Q.y..T....4.4P.W...g..l......{.1.Nm<<a.2....|W?.Qi..a....m....u4.w"V.....sl..>..u.r.!wt.X..>SO,.....g-AH.P...5.rgF.,....>]..S.C...M.}Qg../..g.#..;?R+)7..s...=.[.G..9.+.?AV....$Y.L..Oa...-a...U.........+.|...`.I...*."...<n.Ve2..sf.JFs..x."......,.7/..[P.?.(...p.....]$I...d.[.#....!....9f;........F.O..T:q4,....WH.x..H....I...#N..I....V/..".@e.;l>..}g.2.....
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.841922678554366
                                                      Encrypted:false
                                                      SSDEEP:24:bkBHjepKpqWz6YsBh85mjZL2g6vQemEkaG29TrAYLFHSaIZFjz7SeLX:bkBkKgWWphWmjZqg67mEkadh8Yx7AZjX
                                                      MD5:CFF1CAD89C81409EA691C6FDD2FC308B
                                                      SHA1:733C1E88D95F7247D883C4511C6DF07E380DA50D
                                                      SHA-256:78BFC5DE43B6F94422F33C48F04A853F74EDBAD6EFFF11333458EE6A13C87C10
                                                      SHA-512:D08B54446E63FCC610F8CF0894FADCAAA18D48C7DB800E2B1E603ACE79C3369BE62933545EE01030AD93B3511401041246FDA27F942B3E87948616DFABA6566B
                                                      Malicious:false
                                                      Preview:WANACRY!....].[\....._..i.J..c`.;..gU....in.|..`.V..G..hKR.j.,A2|.......>.2..V)...=....!....F..o.w.dw.p...tyi..uDT.i...Q.8\p..,.=..m...p..)......z...$.1o.E..p.D.yk.....S.!.....Xf_8....M.../..Y..=.........,......rI6.X......",.pD..~...hy~..O..Z..../N.d$b............!..{.R..b.....V........c.....+....2....^.y.......8.?^...v>o...e..U..p.nh.S.p.0.w....PH!....Z.!Q.yI........r4q..[....z...+.b.....rZB..g!.s..T..5-.(.....+...x..y..'..E..].&/.~[..ZS|.@V.2.!.k+2.<..-. E.#.....q.|.i....v......R....c.bL.....=8....i.io.D....<.c..?.^Q.6g.n.p....m..O.%.2.E"%V.a<a.q.S.S..Lp...Hz3.a}0).E.;4.o..2B....,c./.....h.&.2..l.&~..?...F..6~vO%.j;T~.k....T...|S.{TE.6.]1b ;N..`MQ..t.q&w.C.Y4.....)..K..{.(.+..M<..l...c^$.3.VXz2....G..=o*.Zsv..`.!~_..TRw:M....'F^m..0y4u.D...)...2..q......TiH..U.To.@\...dV8....../.br&.PN....K.HB...XB...t(....x..@Jx..CH...a..9=........Zf..[......j..Tu.}..G..8......<.#...z..z.T.k..p...."....a$..v.u..o.I........1.^..\.......V.G5.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.8376703702260535
                                                      Encrypted:false
                                                      SSDEEP:24:bk5o37sEtozG5H7fBNjfIV0OKoYREngs+inNxFK46hKScP6MZWB4OLA:bkIczYbBtfe0OKoYREng8NxFK7KjyMZJ
                                                      MD5:404FB19F7B5DF66F26E22F80E261DF6A
                                                      SHA1:484284828E197779F3364D01815D5BF96896C003
                                                      SHA-256:633416E29EEE784955DFD1787FBFE5318FDDA8945CCFD46903CF515352A2EBEC
                                                      SHA-512:1A774B1A6BEC8169B77BA542F07CC30C593C99EE6FE3CF487F2F32E6E6963C7B936CCDDAA6609A755932B79D2C6800A34792EE221426A7D5BBD73FC11EF08750
                                                      Malicious:false
                                                      Preview:WANACRY!.....B.^.7....\.m<y.+....X...I..!G..2.&...q$.. n.l.. E._....*'!...).u.M.....9.d.~.l.....-..oh.w...n.....y{...j.U.Kg.u^G;.o...wZ.z....v...... x...Cp....Z....Q.64..T.S..GJ.A..V.?..Q..>.r#.Z.<Kf...y.b.. Q.2....(...nG....@8..{.}P...}aL.J.83..C.D....`U...............6..]..d.".....6._....B).a...WX.x....$.sjtM.G..\...C...d?]P5~.i`.. <.#.....T[W.l..Hd...':.....%....)...N!..gT....2...2..>..7X.r..R^0!.....M..-.Ky..&c..{...6......-..%.0R...........Hy2>.bF.U\..C?....\9...;a.j<.e.P..]....c..}S~........em..?....DS..U..`.:...U.T...x5N....wE...E....I..#.~k..`(R......._.e%.yZvK..o....^..6.F..X....AQy..:.3..=v.......3V,...TP...K..(......G.U|...5.\.0F.>.-.t.Jk.*aC....vh..!.k..R."P.sht..M...>'.8.......h.p{....g..y'.o..lQ.....R....W<............aL}...5Dn....8C{T.%...f..4WxWU.0...|....k8.B}C|.k...A......dO.2e...{..,...J...,..F...;J...#.D.C?..2...[....n.y.U.......?6e@...T".~....v.......S...c..].&..L.q.i97.d.0j..F.I.^.v..=..Y.9.G.........U8..>oG.7G.qUN.iY3....
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.830078248714749
                                                      Encrypted:false
                                                      SSDEEP:24:bkGAnURPlnAiEylX0kKdByz/dTXv5hH1SroxckvcOEQyUYFosJ8iIG6:bkGAniNnjcPyTdbvn1SroS+fIUYF2iIZ
                                                      MD5:2D1D0E9AC3B9A79098B35DE4421FD385
                                                      SHA1:B330E8C61572A0850899203F7BB6BBC9CBEE0605
                                                      SHA-256:1ABB01972410D2306B03D951D5E90F73AE1067490204AD0828D13AC11D41BF2C
                                                      SHA-512:3EE506A8805C6A93BCD8C532D815BA2A3B7459000506A6792A0268A543519CAF5BBF627A44F24CFB2805A48C870CC1BB9952A58813C98A615643B6BF01CA6A37
                                                      Malicious:false
                                                      Preview:WANACRY!.....p.[S..s.'..}..ei.....e...S..aF7./...q.^sH#.t.c;.p.'Gh$)a..`.[.h. ..&.&D".1-G{.O.3?u.".....%.3pc.V..O.....<=...C...Mp......a......J...i..l.....sT.4OR..N.~.~>........e.|.P...vg!S.\y..rxo..9f. 8...;...n..9.3U\.f..f..3.{N.Y..L..}..H:Xl.G..... ..H.............p..'f...H...lJP5.{>.RF9m.X..",......6...>..c.tS..{..!..|........N.2.1..W.{*b....H.(........0..(...Vw.hm.C.._k:P..o..'q.../...JkD.v...A....}.s..ep{....~'/)m..s{.._.R.}O.$..R..z..e..W.....F....}..6iW....Y...b..A.......m.L....7.0.....}AF8...!.3...x5.F....d...|.Z..V.........`.B..\..V../.^...|..z0. ....|.B_u......Wj..9x..2.X.0T.Efv...#..YX)h...../..r.....b4..D.......^(./.KS.Z@..Qn.Y..+....m.=)..H.F,.&.c......p..l.../.....j..6...T.].. ...|....n>^..pr'Y...z.....)O.Fk.Um..@...qw8..z...5....X.(...&..[.2../.w.$.2b1...7.!.l$.~mA.....?N.p.....l...zO....0.I.....w.s..r....5...........xw0..O.i../~}.......6}..H.~7.[.I.N.........l..6E..:R.......bk..1..e..`..V.F#....+..a..4/...E..vG."4..
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.833806556747599
                                                      Encrypted:false
                                                      SSDEEP:24:bkIWR504WB+UcYsjkppaL+VDxcZEa3KtmscPF1ES1Zu4OvqjEGDd+zdLal3eyqTm:bkDW1xNpaSi3em/9LTjEGDyy3eFNNS
                                                      MD5:00E6C673EF5E378FE09F6CAF197DC3DF
                                                      SHA1:A415FE4D3D86B5BF7BDEEF10B8F99405A1C1DBA2
                                                      SHA-256:401675DBCBF38AB8C170ECE4210F1F1F50D55C43AC6A987E505BEAA441A7BA49
                                                      SHA-512:DA07BD2CB2952EB1F500CD64D363C58CBD6AEB01F2398AC111F1BB2B45CAC64ED343C41177566F4D8E9E15338526D4D0E504EF4B95D3D9A5F0A2158DB82EA8BC
                                                      Malicious:false
                                                      Preview:WANACRY!....s..8H.."....!..A.....NC..y..^....h.~.Vg>......3..w..z$...Q..cV..:i..3 ....s.V.*._...;.W1....p3....3P.....}P.zO..[n..Oj...2....y..._.5...`,&^4......'y.!..%#..X.5.....8.J2Y.{C.X....[.4...3.`%.se..G5.8x.A._..j.6-.+[..^...H4.o..8X..@D.J]..n!>..................\....8..R.zM..;.....l.........&..L...5..i..z{.6..5.l...u.FZ<..r ..Xi-.:..ba...h....0.-!..c:..E....D.D.s.I:*dL..T.v.....(.5...cvRPn.'7..).Z.Ej..dv.Tq..f....#.s.*.<|XA.l.d....B7.....j/.w?1m..].(E.6.J.g....S.{...X..&z....7.j.Zh1../..K4...TX............<$.Ey......m..v&.ZHM.,.XF....tv...p..R.......F1jY..8...Z.2VF.d....+..=.....&h8.b..T.%.s}..%........3.*..J..r...M..8.Nf....9zO`u.N....k.B..V4...+.:....,'a.P.wC..W.l.a..9fC....jM.....2.6.....|}....`.N......i#t. g._...FS.v.Kv........d......$....?Svk.....l.j..&.4E..-NH...N.'.D..3Y....9k.......6......YZ.W...*"zt.J.=...'.'Z.=.R...S..P....K}......2....u..M....5...c..+..O....p.b..<^,.>mD.fdng..f.....4...z..KO.E ..n4E]...........].W.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.845073724070644
                                                      Encrypted:false
                                                      SSDEEP:24:bklyyy1ru4M9gGthyvtl3rUwzvir2aKM84jyDq2+n8S/MpbwwCHkTNWH/:bklzzBtcvXTir2BM8bUn8S/MdrTN+
                                                      MD5:0465214736F89F05968EF43A44245032
                                                      SHA1:50B616D520AE4192C9EB1625A3E241709D83F268
                                                      SHA-256:6218A61C7F410A7505B55E0C3304BBD372532C2CEFC755D7DD339EB5D76A3C31
                                                      SHA-512:D263FA7D7D20BCE03C615F9A33F91C17B76B0578772B277FD90804F3673228013A16DB31F6513B16830D590E662566A40A3C8EF0144881EE7C40F857633B04E5
                                                      Malicious:false
                                                      Preview:WANACRY!....g..=A..v..-<....D.....{...,JS...,`..>..%....(&.<q.uU.=^./l.`|.6.\p..V...."+X..m'S.h...yK@r.....l.H....W..:..7..~B...1.h.Z.wD.rIQ.+.H. '..`..5....%r.5.:?.l...r....$...{.=..4.m.3....=F....V1...Uq%~.*t..R(.2c....L.%..../<fZ....S..<=....h..t[.. _y`<...............G.R\...pcZ.*..-1.<rLk....O.F....9J.....L%.I2#.U..{.!.&..V.r".!../.;..}..Ci..,.....{E.....|.k.j.h."d<.......'0......j.e...{y.8.......qr..?...a.."..^.j.........M..H.{%.....&p..q|7..^...8.v_..f.6..|..A.....|..~y......?.#^.V...I.KM..x..S..q.....M.p#..t.X/[0Clc.s.`.S..o..j..&.:$....G.`...3,.R..b.d........k.........V.F"i29.f]..S........hK:....z.../.....:.wa..Y.L....D...."..p...r...eu...C...I.v..o...b..) %0.f...ZcO..X.....d.F..!#..V...AT...8^c.....mA*c....{........g;I..E...3...h..4E....;S.D..*6?z..P.i.e..'D..0.#....;..Y.A..tM.xf.u...-..L.....'..M..<D...3i...{q.F.@...+D.....u8C.fS.'..p..$"........W......9...\.|...n.o.nd+....n....I...$/...x.$.*. d....=L..o........0.H.c.?....xx....P
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.846720563783398
                                                      Encrypted:false
                                                      SSDEEP:24:bkoLyXweRf2rApvXjyKe1P+3vNoQfGzJnSBXzew7CiqFO4BWp6IkRs5Qq:bkoyXNfUApbZe1P+3FoLFnawl84BI6ed
                                                      MD5:0A8CE0A2289D7B47DF0F842C801FA0AB
                                                      SHA1:078A94A21ACB6141BDF5B49E2B78A5F5EBADE03E
                                                      SHA-256:D984659E66C467BF2C17A1337BC9099332BEF4F566C5AE6710A35470BFF07CCE
                                                      SHA-512:1E1A327D89011AFFA7AA3F5BA0BFAB8A3D46D5DFBAF89F1328BAB3B066DC08E5900618E1EF0A381914E2C482944CBC98C493FBD2EA5FB18BED01306256036993
                                                      Malicious:false
                                                      Preview:WANACRY!.....A.=>.....P.S..../.K[5.hK^....C....QA.}.).u.s...jCm..b..P...;UKHs..uZ>.b.`.\....3t.....".q.$.Q...;.0Lc%.Q...HQI/..p.u...../....9...-jJ..8..Bm.c)..Q.#=..........e..E...r.....p.......!.[..........NLUqph.g..I.)m...`..n.0...G0Z.#.l.d..I..V.w..G.8..'..I(.............P.J(.GY.)0\.p.^..3......=...A1..A..~W:V..&...M..v...(+s..-..T.KO.~.@.....i.....~.SJH.iWE;.....7"..(......R....c..m...Fn..P...........ht.@7...&6.l.... .nK......-.N.k.....4../m8.....m.&$.V.>..w.<.XZ.W.C4...r...l._.....jm..tu....[.(:.....D.9.k{.%.!...#...'y.....vw...1.fO....cC.<I7=E..v...cst.........@O`.O...B...[...............g.L._`...>......G:.`~......K.O.Q..p/.]+......D...K......nNE....Q.....`\.fu8M..&p.X..9...<..e....[.C l....Kx.OB"..Q....L....~ =X..y..}c 7.7(.........?...*..#.....V..j]..G..M.i.v.u....|..%!x..YD.T.n.<....m.l.h<.q...b...6..E..e...[IYu?7)..Pt.g..l?...z.z.a.. .f.R...`.R...i|r..9.........p....i-RO[K.r_....:..!.W.>... .;.+...."..y..W1.....9x.............H.....X.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.855369680667037
                                                      Encrypted:false
                                                      SSDEEP:24:bkNpwV5p29a2/l5kaiAyX+XQXeMRLDp9Ya9pDA:bkNpN9BXkTJXZXeMnyCDA
                                                      MD5:3F7FAA4BB2C95068312514431D3CCBD1
                                                      SHA1:D37EF17E232F419124CD77C52E410682CD3090BB
                                                      SHA-256:5647784FBD6A1C3DAE848CFF5F3216A1F4CC0A460501AEEC6B26CB33176C82D3
                                                      SHA-512:58B029A27E99F76FE6B1B85CC04DF0A8AEA0163A03890C57FE3FD032B60AB5533B1968D29C44F3ABEC87FE9C8CF4C34AAAD8E5417F38F49AD7332E67E1962E6A
                                                      Malicious:false
                                                      Preview:WANACRY!....~...>.....u)...=#xZ_IB.......=...vl..0w.X.....B..]..B=..r.)5.0.j....G.Q.\_>.:..$i.....,F......V....l^.d....3.....m.,Wn..(..*?..';~....K..V...f/.!m=.b..t..d...R....~7..=.N.....7,,.`=.?i4h.}...D..^.@....GR..srT<...|.J..If..ap..........72..gV.S*................G....%.p#FsK.U...!..(r.q......^..si`+\.....'.h....0..UT.9G...].q..H.....R.0...x.B.S..8..h..}.....e#j._.....fP.-...T......:..|I...y.............s]...FE....!..E.....5=.q=d..G..".TB.....@..v..8y..D|.>....d).".. }..x..m...s+..`.....6.....Ji..?..K..Q...Th..5/....vV.C.d......;.@_..R+........(...........,AXJ..M.%=*.8%V....7e[..8..>.EL|...2.Q7S........... ....-. ..V....|{...sPJ.;|.........N?..gZ....Q#u..~.Ap.J.{.n...]FA.@..kt......n.....k..Z...>Y...Yn..id%....d..X.+......!..~!k.;KY"..1...F.z...4^U..?.....F...bP~)..4...@![.j.X.@...R....?.4...!z.!...).....+.nK.n.8L.7!...e..(/..1&[.[-.-...X..\.tgU.q.[.{....iH.@J.^...T....|.........6J.4..,mfkq.`.J...Ai.\*........]...CP.1.p6#.27..f...z
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.848926961787327
                                                      Encrypted:false
                                                      SSDEEP:24:bkJPt0DfF5NP9QSuZhY8MNXaZLB1CCoZNFIrLD6Jd/sPRvz3HmWYQlMn:bkBerdP9QLIdBaZWLZcLDodgZHD8n
                                                      MD5:41BE8B6D7D46E75D9C0DCEC78E0948A2
                                                      SHA1:DA4D11EF2F5D40A975F9C16B3756256FCF944259
                                                      SHA-256:64C77163BE65A6DE41010DBFBCBCD518890118562BD43798E14B3B1216FB960C
                                                      SHA-512:BF51CAF938E3BD2A98F9C8BF39641461D0A94FEAC9E3E27836D2FE63D87CBCDCC4F9A17E4E7FEDD6FB66CC755295C1B55A7CA9BBA2A84876E0BA5B269E10EBBD
                                                      Malicious:false
                                                      Preview:WANACRY!....d.L.&5iZ..l..qB.l3Thg.:Pls...#.Y....{.$..W..k...o@.w.H..K6qpM/0..W..(..'..y.-....A#....]...N..P..{.u..j\...i$.H~.;./.Ap,N.y.L.e$......lX..-0.<zw`..as.y_...\..0.!....O..M.aAL....KFh4..C...5.k.*|.??G.Q.sD.".....9..F.W}.8..3u%....&..4...f].W.z..+L.v..............ya.4..N......i.9/^...a......!.....p.\.l....d.......D.+n.a..o......:.f....UAR..-..F!..'4..XcL..%c...1..ul;j<.u...J%.G.(.j.;..~Aw....?.1...[4<ay&.@.cj.0f.K....3_..)1..V.9;...... ."..A........#.UT....Z....U*..x.;.8.I.|.}....3...'>...)...u.b..y...l]E.P...P..I.O.I.^.XD..Lv..*M...4.,tFlv.........K.~.h......?Q(m.\s.t.3s.h=..a.R..s....r5a2...mf..c..E.AC..JS[...r....QS'......d../.9..0.{.[.tt.....;.;..O...*......a.4...Y*}...I.... -dz..N./`.T. p0....1V....@.....$.= ..i.d...$h.U2yD./*.[.X#..]..D..p...M....3..g.;9..I1F......+..?|...-..5....O...(.k.}.........gZ..+r.W......X5...T..5Y..|..T.....S..{m4.+.....E..sI.F...........4.3._...._....[..EN.......4...GlW..k|rF.,...f,{..q....I?....d~...di..T%d
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.840858755238121
                                                      Encrypted:false
                                                      SSDEEP:24:bkihm7iZDZY6ChuyF1Q9nhJHqEMPMvLXOWXBMpWJMbVADD:bkVgCFF1WnrJMULXOlQJeQD
                                                      MD5:E90D50BE2E73ACF53F63BE1037473008
                                                      SHA1:220140488012D0729CA3EEE51A6D177858C4D642
                                                      SHA-256:67F0A0098FAD2275705C7FA0502EE8737252F8701152FF80F2B3CA24A23F4180
                                                      SHA-512:187D426845F1E429543131B939024701F10D74ADD25BEDB8C35370597D8A217D02EF384746B6FF109E29D82B0DB6540B00FCFD963EA7725440CC97B390DAA386
                                                      Malicious:false
                                                      Preview:WANACRY!....p>~..........Bw...o.Q$..q].f.Y..teU..,......h.....S.3.X.e.OMg..w6..}...........t.]...:...........".2..\.6.p..Px..\...*{.WF.7z..Ew.p.o.B.nM>...Vq.%.....P.Bm..g.N7r=e=`....Sr._.&.<..0eh.]..z......F..?].;....N3U&k0..l(..(BY.aVY.Ce9.3.H"..k .............8.F....f-Hn..2..z....\e.f..`XpF.!.j.N..8>.^/..g1...q.....c.9F....p......h.p......)..U.<.k...XL9{..t.)..I9^w#.+....-.p..wX..s..$K.../6M'..8..Ie.V..n.....9.O....c....O.0.c......K........sG...i...;...O.....b`.....$....W"...p.U..? ..+S...fK...D?....mC..brBwCD.....0~.lw@.2a.,..d..,..O.D.....g..B..hI^.......m.Pc6.w.j..7. .;".Y(m7.kO.[lT..D.......R...>.......[..m6s9w^...2!..8c... 0..(..*T.'.H....y]..........D4.....g...1E....q\A....'..pb'...IA..*..,Y..u......`.<h........k.A'....|...YoU.l..).m.s..ox}.2hpY.....1.pa...!..c...H..N/.R...4.P.Y.=......i3......em%.G....!...|........IX|.F.u/..^G+.......o.g.5.}H..........V.....2...z.}eR[.B..s...QP.|Q.|..)..>....?.>N.>N.]8..&...5WkQ.....VfP..#P..@
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.850505398526495
                                                      Encrypted:false
                                                      SSDEEP:24:bkUYEukah+f9CeT7ewpLfRw/BUGhVHTHJ+39pJO8NF0+:bkTEuFyT7ewxRw/mGTVEpJO8D9
                                                      MD5:44793C49CDDC8E09DB787CB2CEFD5A61
                                                      SHA1:D6AA1C4930796DF7F18C763A58727E9922033C85
                                                      SHA-256:E58F78A593A59C5C67DCD2BFA7171AC61F2FB01854A0F466BD0BE4CD5047CAE7
                                                      SHA-512:5BBE98FB889C58692A14B0A9FE6E47DEB8539482465E9063D91038023CC8D2EE97D5D52097E8B39568745F15DEA7A37FA32799A4CC23607EDEFBCD3E762A38AC
                                                      Malicious:false
                                                      Preview:WANACRY!......}+..v.T$...._...)]...K..7...J.C3B*....>.7.g..[....j....fM.w...&`g.....V...b0>.....(....Z.,%.*L....Mx./...[7.....m<.........m7.H......\:$.....x.L.B.....*..@....E..............S.....J...@I.v.}=w...8.......8k...#.M.f..U........7D..6A.1.5;...............h.}o.p...A?gKP[...z.._..MH~.,.(p\..C......;.Q..[Zm..[......F2........0..8<..bC...G}....'K{............c#..r.....&.z.p.JOM.E..|~@..?...:...S...../.@.d..=..h$7.%}..X.N.f...k.'"&.?.nd.m<.P."........@h9_.^V.3..S.^..z.i.-K.....}....F.:...............h./Ka..na..:..c.....b......8.1......#$.4...L.....[.#...$....i0.%....r...y....7..6.g..pU...Q..kr.!..E<....G...5....^3sV.c9!...dp=.......%...f...8.&..>.*..mf.9.........k@T....Tot...P..:....'.4.r7..D._..i.....DU?~....K...Sf9.5....:.&......rq....0.....8f....}...P.n>.t..k#..+b.yH...........=.+.Yf$d....2..]..."...H".~..?s.C..eAM.3.?.......U....=.]...-N.c.....gF..C{#m.LK....pu.C..)+..B..L....mV.hj......Z...;...[.o....%..z.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.831997077043649
                                                      Encrypted:false
                                                      SSDEEP:24:bke7iUk4dSg2VOCw+hTzCSNRHOagj3K0yXKWfnsUEa/ut5ypTQRaF:bke7iUlEVOCw+hnXRbgu00XPs2/utM6K
                                                      MD5:C6189BB12D06691A0558944173FB60C7
                                                      SHA1:5C4D7B1C7E09A6C963BBDF14DB265D736DC0CCBD
                                                      SHA-256:48C6B8A45CE25A7E123923E98E9C20BC4C9D2EE891C1A27A0B333ED80E52CB2D
                                                      SHA-512:4BD6DC2AE763B27BE0BAAFF386EF8BC7FF77C61949C7D4CDB7F6C37E3F9A28BECDE2257B193ACCA4ECE5BFA7C22ECBDCAB25D6932A5DA000DB5AB8EEEEDD7AD9
                                                      Malicious:false
                                                      Preview:WANACRY!.....w....x...I.....VZ.>u...]..t......H.r......t`../.S'$U......i<..R[....`...D;c.%.."No.Y.d.gDJ.*...[...N.}.+..).......KL..q.\.;"Z......_4...-..PKP...<..eB..<..O.....3.?)..~...O.....-.{B.........."..$Y.7....Y%..HS.t.sm.b\<<..#....y.....c....................n...~..P...o..E.3.}_JXg.......X\._J.gj3W...%3wj.......W.o2"..8..*g........*x;e.v.I....\D...p.!..R}...*...#.J.R/t._..e<.^...pm.$ ..r:.!*)..._.......-F..;%.^6...CjAH.).<..... .X.].XT..Xp-.q...m.....C.+Q.FE....d(....R..QE.=.y...T5.....d.....i.bGi.-YxQ.aNX...i.@~<..3}]h.... TO..+...8...m......N!.X.9....$e.E#S.df..].o......8.{HK..xv.#...j.MeL*......."...q2.F...Y.~...6.V.G.6............+.+ K...".V....P..!.....I...S.a...<.:..S..-c....C."D..1P.....=..H..n....L.._..D......a.f.N.p6G.1..G(4Y.n.o7...O..'...-.3......y..W.Ys...{.lD.TM..j..w.vM......^.._.L...)RAo..[...2.m,...*.........e.......:...?.......<K..*.=..'...B@sg.D..-..`&...Ma..j.,.)...QG..`S.)....3.A....H%}...u..uq..\Q.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.849377744430831
                                                      Encrypted:false
                                                      SSDEEP:24:bkT33MqzBN/AKMF71J7BTwaq9QNmhuGkGgSosqOga:bkbDT/AKGvyamQZGkGgXsPga
                                                      MD5:85AAE536A8EFACD6DAEBB0B423D6E712
                                                      SHA1:F9686A6A4F35BD0025D75B7E6751175118704F6D
                                                      SHA-256:ED583B5F8BB93AC30263BA0A3BC8C17357DA246A37ED0B677D8F703A0D33199C
                                                      SHA-512:955B03E098A3F181C0905A8A8C8C5C037D308CC5BD96916F3E90652DDDB64AE4B04E97F7516A89DBE4679C6EC1472438D83EF5901696EB18CAF0B47F427DA729
                                                      Malicious:false
                                                      Preview:WANACRY!....w.I_.[.*.8..p3.......'F.>.`...H.!..>P.~vGh*..n#fgTi1N..]..Z.xxIOK.T.i......Z...qa...26#.....}.3c...-...,,.&.P<1...D#.....6...+..s&..r....S%.+.:7.....|...^...d.\..[..%".....P%.4.`.M...R..)...........j.........*..........F...2...{..`..G.._..............."..(4P..........[..Z8~.Q..)05....C.Q...k..F..*j.[.v0.}1..'...i.Q<...Z....Cp.s..4h:.3.).=Y...I.o..%w....Bi./.%.s.....j..m.M4.F-......(..o)R.n.....,|G..-Z|..\...d@.r.._...B...2.$.%.W.80...!....!..?Q.......V...x.J.t_hLZ.I..O.Q<.3q.s..._.....{....1...>.r.n.Ke...L....^Krg..P...s...P.k..Z.ZHxB.1..3m....[f.7 ...s....G`...Pz.=`...Wr...9*...EX.....p..X....x...}-$.......h.5.)Wf/.0v.aJwqF,.....A....U..|}...G..*..i.u...v...)t=.!}..W...e..w...I.X...y`..+........o.6..FdQ..W.......<.U.....l.Ur9./~{......].&.z.).\Z.n..`.g_J...k..2...\!ls....q.A.?..g.H.HZ<P.X._;...{......Z{a....T.....S.....H..Z.s.......@0..;=.1oI.i$...k|..... .;-...7.....A.3........F.....N..n.V...(o.[.ai0(P......B...};
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.861282866650529
                                                      Encrypted:false
                                                      SSDEEP:24:bke+RPnSKNJ/H1aD9bieHEUV2jeg7KWmIexJce4sjeou7Zc5XkUuZ6vA:bk9nSwNaJ/HEUcjekNYilsiz7ZiXoB
                                                      MD5:7BD245B040FFCE6D8534B538864FFCD0
                                                      SHA1:489C99E74E4FE3F5EB8472025ECD099A4AE36D0F
                                                      SHA-256:E356F5FCCB713B8BC3A24207F55D3E28FC1DF10CEC3B52D3ABD766CA3F6626E8
                                                      SHA-512:3B81683A9C507971A36892B81AE9F143027EA039F78B0660160D533AC19774A578EA6E7FFBD005534E96909D3032492B19B7BE8B3B024CD08C5663DBE8639BAE
                                                      Malicious:false
                                                      Preview:WANACRY!........b..<.K]..I.~-).;...`...H...I.......Ew.njE.M(5O>Y3.@...A.U-E....g.JOG.,.*.B.Z(..m...:..J.}p.......y./1.|.6.Qa-Z?i...5sC.=J....c.,,.oL`1R.mh.N.'...E...W.[x.a......E...3..;...[E.lO...0..._....".^.w.n...I.9Y.1^.9F.5d. .9b.!.9..@.pN&_.86n.\;............Nhv|e.1PO.._.M.5......'A..dh..7..+.V|j.!..A.k.IF.l....aPcL.2..h....h..|.-7.e.....M6g.Y.(JU9.o. .......t..V..".b^.1.Q.>Q....V(Wqi.m/..`.+...>..`.r&...l1...!y.[...yB*.e....u..CS....S...!....r..en...]....p.vc....T.E~.c......."..s....dJ..@c..w.kqf.....a.x.<T.zQP......f.>6......4.8.].C.FR.9...p.Y..i.JR.7CN..~.cC.\.XwG.r].$.....0s.o....x......_..l;.u..tB......CUO.1z7.SX...!.Y.^n..b-........]......d.......?G.\.E9.i..~.9...q..s..W..vXY..*.....6O........s...%./|$[Z.m.,...O.........pc..>.B..6|....e;....S.3..S.......O.=.M...3..a.g.xy.q~.....mz^.p.,-..9..K}..;..@.J.V.pd......2..O....j......m.V.m...).(.o...t..1..?H..z.M.0!........m........A_...j.P....~N..XdE..6.i..<....$m...Z....2.F......
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.84769815507449
                                                      Encrypted:false
                                                      SSDEEP:24:bk5NDJhfIsQz5epAZ6kFgRcmRgcJ7Uj9Td9lX7y6PluBRQG95qIdCe6xM2pyR8VO:bkZhfvQNepAZfFtmxOh59lXCSsm9E
                                                      MD5:E0707019654ACF1EA41F0A0804EA2508
                                                      SHA1:71447C229C0C670A66588855A589D618BCBEC07E
                                                      SHA-256:44DBC4BB10EB7E290AB964704E3979D7A1DC3C526FC4E9F8F746F777B2556923
                                                      SHA-512:48C22485C58084C32AE6665E8C5E3511B9500299EA85E4FE6A65118863B6CFE774661C97B8C3C68756BA32B62CCEFDF8A274675F888C7AA90A898AEEEC1FE16E
                                                      Malicious:false
                                                      Preview:WANACRY!.....V..;z..D...}.n...........1I.....X.b.....;j.O..K0.....e7.6P.....Kd..PzR-.i.f.2..A...C-...o........W..=t.n.$....f..`..~.#\l...S.#.>..G..3^j:./.F.......r.. .'...Y....$G.5...6..,.kd....U'......r.O......`}z....b.+Xf...Z..~......!.q.M.p@..<..:H............$._U........J.JH>...w..f.....=..F..D...p.)..n%..D.k..9....E.Z...J.?.C8....x;>....|a.r.].'......J....&..^.Ff.v...//..X.M6c!.$..."..b..9.7.~.6......5..P.-^.e.vu......uy.=.....M...c.<`cu=2.^.....{...A!.U..n.......\...+..1X...F...J...bkZ1.'.....KE......a3..+6.....S.....ZRm-g..n....U.X......^...*.Ypa.e.P.R;...4V.N....p..".3....>R....F..._....6...`a#.......M............P..5..d.M.0............9.$..9;X...(;-......Q..N.....E+..s....}:ck..9&s.}._k.S6..ORQ..{.G..).MB....Z...).#2W...Z....fd......G.d..d...x9._.|...........+.......>._,...~.....*.....Y..........=.1.$,..Z=.xv..Rg.t.'...H...P."...x.m.3h.P.1-L.v..R.(.|U...^.......W.27h..2.J..#.Sa.l.a.DK.... .K.m..0...`.Gj..$0.2U.F.R...%.$...
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.824926567987749
                                                      Encrypted:false
                                                      SSDEEP:24:bkvW3FFcInzGsBq3zzf2W5vx4pwwXEW6WgLM0rOBUyAwDo4UfrRuwsD:bkkFvnBq3zK6ypOW6WUM0r8kwMB92D
                                                      MD5:FC98BA3CC9997236EDACA5A0003F9BED
                                                      SHA1:1210C39BF273670A42C4186CA231AF144E707F2C
                                                      SHA-256:0D0BF1E010E6CFC5594ACB78FFDDFE75EFFF806E9BA756FEB3115EAC603B07DE
                                                      SHA-512:9A2206CEEC94EA59AE3CA36A0492CC58FB5FFFB0957F73026A7029EA05E3C9B677988F7F577F5FA4953DA73A5505455806B00F8A6A8EE913FFE82D488E81EA96
                                                      Malicious:false
                                                      Preview:WANACRY!....&.T...T%.\.[..z!,..Ou....o.v...8GH...?..D.V.~ly.N......XX....|.;...`.......h.V.}i.~r.2.Ob~.....(.I.d..X...(.....`....G.A..0..8.Gx.....T."..]l.......>|.Zx[...N..g.]/t'.db.?[.3.....^.=.3B.}J..v.5."..._c(C.?.........).0by.....VnjO...9..({..Uh...;W............Y.W...c..5........9...M.>.+'-..!X....n..w.<.HS.Q..]..-..1d%...#L.../...#.m..0th......Ot.......c.J..4..$..*.K..fL*...4...*.D.......4..b.i#.W..r.m.......C7...*P.-......2..s.u....O.b.r1$.C*.+...2......`.-e..z...J......:...u..........j..h..$wC.~.R.:.,.b^|N.....R..o&>....,.s.....QRc....`V..r.g../k....=..*\.z91..,Ek...... w-....L.....p/Z.../....=......,V.Bid...+.#t.........A..q...K..!:.G.S[.]BN..;@8....~...'.m..'..g!,...g&.d.%..\....7..R..#YD.....l.h.:~t.....q..<j....B...v.[......7..x.I ....C>2...|X..x.W.B.........w9z.</.~..L............9..T.L..M.}x...B..~V...Z.9wr....D..\e.B.H];.qo..Z...u..U.;,B _.(K...i..._.p!..Z.g...h..|KV......P....0.%...^.^J./..7d....-.......2..K..:..t....VJa.K
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.843868701065443
                                                      Encrypted:false
                                                      SSDEEP:24:bk96YsroqSjr33x3bi9sqXgsAmjRK8gyYE6zzjZbZroSEFGPm1Rud7OZififwQbE:bkkBCr3dROK+wHj9ZxtPm1Rud7MifDQY
                                                      MD5:05165F009B11707ABDADD16C4C06BF3E
                                                      SHA1:D5463B1A0D2F6E59A9627611A0A3E391DC103A2E
                                                      SHA-256:163308119E14AF72048E413BD7C73C551EC6033F9A28C0C65BDCB492EF85FB3D
                                                      SHA-512:A1CD02D746FFA1F6610691A724985BC9A8AECB03953F129D788FB11E29236F4013D637A050B12F58848C1FDEFB6AA856B3BBE1872C16C8A9F78184E83E961DC2
                                                      Malicious:false
                                                      Preview:WANACRY!.......y8..,o.Ln....!.3.JG..........yu....Iy$.vz.X..R...:;.%.t.......is.).Qs_."o...C....rxSY.!{/r......U..\..(.H..?.q.O3.7w..*.a.3PQa.6..Q n.%_.............p.(8.....Nu.=.8........{....9C...(6j..Y.V...e.L..V{.7...(h{....a......h.......!....h.j..*.V................p.K#............=.ZX.!.OI..b(E.SN.Li......@...&S...(..7?yA...1.zk9H.H`..D.c.Qd...^..ro.NQ.a../.../.....%..#..u..5yi.|..E..x...[.o.!B...-..ur.......tG......V2}q.qr......:.t...,J.....rQ....Le*;.^..)-.....1...-..|.-1.n..@.../.s.....3v.P.|.._".L.x.yB.|h..F..g.....X.*.."....:.3.:........e.. .(....N.d2...l.T.../...$..\.;.j......WB..n.3..f..c"..W;.................f...8.Y.f.\.|7.%..VP..n>..<...g.!..[...>.....H.........%....L..9r.........)Z...i..f^.\b.Y4?.n........ao.=..4..#..$..Y...F.'H...El..<.]....T>...@.<.....?.o.r..a.....#..QG.+....q..v...o.M.\X].....E./}.j..s.=W.x.^y......J6\\:6..N...V9...5v$n./Zl..ef...[.?..8..Ph..e....9.]*....j...\.i.....YhT..ta .F..JQn|2...3X..e..
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.861138583655845
                                                      Encrypted:false
                                                      SSDEEP:24:bkky91L12mpQd7SIOzODsiGaj9EjQ3LrX6zbBHJkS5Xnk2rJhdTpvXF7V2X4Z:bkk21L7zSGajGjQ3LkYQXkIFtvXF7VyU
                                                      MD5:081687627151BF9A38093DF2728B2094
                                                      SHA1:E40AF3A184D06CFE12A9D6F8A0383CBC09829C11
                                                      SHA-256:C00E3A7F3E686FC75672BE3DFA1C87FB96CF75FDC5B1F58B8B7EBFAF33CB4380
                                                      SHA-512:5F03AB13828F3BA8B8EB71AAED9B695578F34E41616F8D1889FDF2934AA6AF4EA3A8DAA154245C05F4FDDA61D74A11CF98C90A3F7A3D94CF52EB1B85B8E09732
                                                      Malicious:false
                                                      Preview:WANACRY!....=..../e.b.r.l..L..$oB.!y..S..1.9...D.s..W.......q.^1.........H.ksp..=....g.......e7.v;.{/.;+.=,.*...o.......dQ~.F..G........nb5,...X....t.O..D.]..&Cys ..%.R....\..."z.Nfk.:...h._f..}Wy....}UQV=0kl..[/H.A.......".I.d.o.,......Oa.\5b.....{5.....9..................*i..J....r-.\J.%g.y_..%...Y......7.Y..[..12..c..As..t..L/g.^..R-...k.7'yO.&......p]..0pl%........>...k...'f\=^......f[..U...;.M..`q.N...F.iT?...%.r..9la.+....[.*......`.L...Ia.r...A....F..3..h.L#..e8_vS..;QYh..o.7..../G....|..j...C..r..x.d....n..p.x...m...r%..O...#.E.%6......(..70.8.(s.m..).E=....r.0.o..F..I$}.'.[;....-...~.m..y.LK.".PZ..L.4..t.6....[.z....[i.c.9-.$Rv....%.|vq&.....<....e.w.t..Tz........2.tE..H../L?.?.<>...r.......hC|$..NH.\p+.l...3R.y.-...`..)...@..8.KQ.M..M.;.A[....?....d..-......2&..)Fc..76....f+k.A..k...~..r.......rLs..J.4t:4.r....I.......,.U.o X ...J4.....*6./.{...h.?.k=......vv..L..].....s!.gYL..$!JVG....t.....%Z..;j...`..<.%.z.1..V...".?.s4
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.828956671353872
                                                      Encrypted:false
                                                      SSDEEP:24:bke0bT8A60RPhy+hWJV6LOGb9ex/WZsjjEO5/N4B+zrZ4RW6C:bkeUTfHP7m6Bept5/2eigR
                                                      MD5:266270670827FE51224CAF05D4867D55
                                                      SHA1:D1876730D71806C4D7912874A13F6C50CA377847
                                                      SHA-256:393127C34667A103471C6FF41371EBD2E0250C62324E81AB0410EBB5CBC209D5
                                                      SHA-512:E3A379FC28EA8DA9D2197A1229B29638C2DD8991088C4307DC5E7748C520B93B7A43C69E0276CC135D285BDA3CBBDEB4E171318E6113535C3C7D84833B520391
                                                      Malicious:false
                                                      Preview:WANACRY!......*......$.S%..].*./..X......e..7.,.....C.hA.Z...u+....h......v.[|../..e.B..Y..|!..>...B.;...w..ZKt/T.>.....A.R.s.$.....)k.] ..ao\d.."...R)3'...t$......M88...+^.P.......i..-..[........IKr^.B.:..0....j.x..t_E.A.{OE?f.5....i.........MQ...~.s....o............h....z.....?,.0I..P(...sTj....b@:.+%,jYBI....A.Uj.. ....7[/.g&..m^~.:2..l.]..Q8.J.$tB...!.G..t...B.?.N........d...^.KZ3.o'.8..6M.2L.._.....K|.....f.-.h.X.3.....T.'d........9(..}7y......;.(.......kY....a^*..2...(7..!..l..W....}..........8w..t... .k...;../c....~.f....}u..*Trj.*.;.4.+E.....Jc.....z...3..&.r....^...sAX+A......{1'B+U%......,|,..(..(.m0.M.m.^.6Z.).R....M......r..v.=WB..9..Z.u7..w>...V.R..l,..>..=Uv..o4q#..7un/}i.l.O.\%m.X[..|pJ.........vRt...`.=o....5#......q...^..<Mj..-.I*..3.V...7.....BIw. ......ZHo_.t.....1 ..O.......HP...*:...x..&...in..S....w&|)..m.*.G..y.Y>r...t....q.T...m..O.5C=._4.*...|..9B......}...>X.8..Y....s6.j";..m...v...4....).."..S...'1&..o.Si..,.....#O..*
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.847464372862753
                                                      Encrypted:false
                                                      SSDEEP:24:bk+Gy3ExJy4Tl5e4htdEtjhAHeg/qmcjOe0vwooIJ2e2L40K:bk+3ErNTlqtdqeIqPOE02e2Ub
                                                      MD5:7E874316DAF84E3EF4BED5141271E93F
                                                      SHA1:0FDC436AA6B4B3EF296613E4E3B070F57C5A922E
                                                      SHA-256:E5602A463D74CA9B53B4862F05D6C14604790E01E282955DE7E8FCA0BF7E9E8A
                                                      SHA-512:3AA44990E0D3CAC677F43FB52CD2EE951E1A775A34AF07F091718526C5A6F224834C3C9F7E7AABE532BD65D8FEC6352D9B30675F4B329CD7402C39D81AD6518D
                                                      Malicious:false
                                                      Preview:WANACRY!....9D.w".....,&..E(BM.zB.3.=R.Yv...IxH..M.j........`(E.w$<.{?n.^.Y.i/.c.@.F;W5S.AR&.6\......S.....%..b...w.u....c\rn...B.....{.....e..Nx...P.pn!^..%.....C..kb.|N............E..r....N..l.,..m...x.).(0.D..3..-..x..../e....3...@n....~o.G.S..O...g?u............p..r2WC..A1_E(...L.....^.O.&..../.....c`f..q.#..p..ArV}K.!.{..].)|-......If8?.].N..A....+.......$.....)z.GfK....H7.^.e.k9.V>.j.Q7..v.....'.y..[<....K.`)..5.*...:..b!....'.F..x..9................TKj....8...u.`s.h...wC|`..Q:O-.....H.....`..Aw...i %...[......j4.........Wf.b.z...t*<..>..ecr.[...$.n<..O....a4+~:`cC.....q.Y.$...&.".H.x...Z...2.RN..#c..5...n$..aQUEQ..@.e:*.[..U<.=......[.i.|uJ8..*.<.......GO..}Y@]..i4.I=;W..Z"..?..M!.{.j..i........k.4....f..0..M...7&".P6Q../..#rcR@..b.RJ]Z.v=W...L}.K.........J.i!D..>.,.......J{p.s.....C.R.S.>......P..BM ..1..#..2...m...w....h...|......c0.....L..B....u.P.+..4n.]...46..d.L~}#...t...J.V.)#..b...S;.H.O..O.\$O...3.e..2...m.pC.l>.5}.Z... .......j|7.Y.l
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.852675393523559
                                                      Encrypted:false
                                                      SSDEEP:24:bkryVTYH3N6M5jBmzG8isMTFms9HZkybHGOGMJ15ajVMSD7iNmoIbRLx6Y:bkr3Nbz6isMTFms9xbHGIJHauSD78lI7
                                                      MD5:F206AB6925F4D73AF7A66403D6DED522
                                                      SHA1:8F33B28A3FC12411C14F5093B1C090CBFF8B86D9
                                                      SHA-256:3F9DD3AAF96D0B8503A512865D292D4077CB7AB7214F93D8C465084F24C80C63
                                                      SHA-512:B431065C3E96B76A5FDD57539E0E4CF2C56748B449BABB1058C567685FA14FB22124A5DCB12EEC6452C06304649F45A12460D01AEAE020A07A8714FE0A1EE855
                                                      Malicious:false
                                                      Preview:WANACRY!....U...@.'.3g..&..ks.uX.[.z.p.o[...E.k..3}_.|0.".y...4.q..4.c.TCk..9d.S..5.........".i{`..?F6......O.6....N...TwN|f.)=....V...k050..W..)L...G... O..2...2....3...S..HJ(F.a.....t...?..9.x./ Y......:...SN.wY.'...4.XZM...K.....%."3/.......6i..O^S.|.....!}.J(6............._8=.O..E.o.`3...{....l.iF..Q.l..h.v.\...a.q....~..I..8......Ca..k.\.%z..w.t6..j..W............Y..Zx@.^.6U...VS..,..<=.En..8.H0L_;.N.AhpSx...1.4....k.....b..J5rH..I.@jo..h./.A..........~..b..tz.....P9...n.+..0DDf.i.u....L...J'.n.r..oB.$..`e..k.....OL.2....PK_!u..l.....>..n..Rn.....NXl......uT...G.L......dh...^f...]3mm.F.B..^..u...=.4Mr1.|[..Ce.. ............&..Z......A.s..7.d.'"..b.u..o.G..../....S..7%.PZ.....9.i.W.h..........o......q(.i|..|}8.i..<......7..\....3.mz`..%P0......c./.}?*..P.xz.[^.....x...x.....D[<.H..].9...}......*.H...$....Q.:Qp..9...<..,[.....L.e.N..]..d...2@Y..$A%-..z.v..$$.....)..T........T....H....2...{6.&.....8H...C6.I\|. ..)......gJ.K.`.|.r./v).[-...U.pX...1..&
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.835976584090721
                                                      Encrypted:false
                                                      SSDEEP:24:bkalU/0PBbr69gKJIaFgiu6kMhTloeO8yttfW/S/VvbhoGjBOnhSSbTMVCTfzL:bkl/0PBZKryNkhzF4PhOhSSbQQTbL
                                                      MD5:1E258AF49748DE511A7274804BBD5963
                                                      SHA1:965C9EFA655D1C36DAA7387FC35EAFE9B250842D
                                                      SHA-256:7080B5D4BE24689C42BFF8671D0A6C5B3896FB4BBE593D706F8375AAEFCBF7E6
                                                      SHA-512:8588B10BFAF535A1B511C431E43F7CEFB1B7D8EFBB31F38D184DB539B9959926B888778CFFC375C269A06E177BD80AAEB89EC1ECB981F1B0419CCF4F9DDB567C
                                                      Malicious:false
                                                      Preview:WANACRY!......A....XZ~.._.L.A35.}^...>......i.[a..q5..]\2.>.=...1....W...<..c......=.q..U...(-...8j.+a.P..W.E..?.&'._S.Q{.U...4.R./._0.><.......q .OpS.......`....z...!.~y.WU.....pK..\\.]..n.}...`..6...Dt.{.W....gl...2*...j!'P.....yj.W;.....G...._6ix...............t.*@.y..y...'....i....29.$...).f0.oO.....]Z...jbW2<.a..ek....`....@...h..,.a. ..~..GF...:...s.R=..=lE./.0s.. ..W.....(.n..8....YP)....E]=.j{.}..... .X.....?.Fo.p*..n[..ST..v...v..D..l.....CmE4..Pr#... 2.}.9.D'.Tv.yOQ7..9.9.l......3..qsHRK..3D.+.[....*0.r'...d.t........3.}.O.%.d.l.0.<..U.. ....(.....M.-....w....v.MSv6BK.d.....o..k...e4.-.O.m@.a....p.......@..T...~E.@...(..Z...?.k.%.FA....:........&...x7..Mb.0...<B=.<..E......\..d.p.P..tLr.4.......u>.D.dIN[..Y...Y5.a\.....a.-.aP$(O..v.]....,...p..I....../;..S.,..&k.\......l.E..:M...2Ms........{:muE.....m~.g.!5\.N2.Z%)..1NB\$...k.h.......Ic..c..a..d...}.<?..N...{`w..l.T#.....F..d.=uK.h....s.....2.7.Q%67..b~........'5'*+.+Me..
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.84247644543347
                                                      Encrypted:false
                                                      SSDEEP:24:bko69t7O7dNQ/25+t8nqIBTDGGv8eO5F2CZ/Y2fQypeWkbxVUFF+3ANnWEzI0mO:bkoWQBm/25wQqIViS8nHdfPotvUFs3Al
                                                      MD5:31BC2F1188846F7BD62C193BB6E2CDDC
                                                      SHA1:25A26CBC01F4AADF7B53D2585DA3C7824E93AA5E
                                                      SHA-256:FC5461A1715E858C0E1E9446DA384BAB3CBD08BDF510D53ED4832CA2D47DD890
                                                      SHA-512:997888B1583C4F83DD2BE5E15AC090A0F81F5210E6A15B62D7D9564945858C7E048E5B02E5381B19B8518038F86D024B8A523ECEA08C09378C1E82E3B59D7617
                                                      Malicious:false
                                                      Preview:WANACRY!.....$.c..1L...=$......V.P.>....\.....R..a..7.E.%".V...........4...mj...G@.\..-c........T.c..OY..)..........|../..ru.|f.uU...2.A.72...a.4.&.......W.W.-.m..O......K.;.}..._.D....?.C|7-...{..t.m.$.n.&`.AOFO...22....U.x....|....D\|'A.g.W.L............v.+.(.....X4Z`...\....>..U.s.........2 ..lf|i.r.".FF}sy.v:.wJ..;R.0_n1w.x..4.*_....+.H.)...]+..S.....xX.$.!.Uy..u.4..X...o].6...._.....A>.c.*.H.A..6...o..Hw.z.yA.?Sy.@...K..w&....O...5;......Y.+k..H..,7..F.Z....^..=.7..u...v.4...1...q........H*f...;.d=...HF./;$._.......U..R..H..4.2'.e....$]D.....`..7...C.|?.......-....Sp....QKz$.j.8...2.['.J.*r9.~.f..../..Y..*......=:4c.P..X1.Y........|.......v....9@.R..n.....*...|....R.a..y..Y...3..'5.'.I.%.K/SH<~\......_.....Q$...T...Qf..\i..,T..Ya....+..z...FQDA..}...S..''.%.m.^.Z._x..2j.b..{;e....-QH..3d.].....=.....Yu.....s.eC.......l...@......+"&s)..kG..-...2.DD.f._.nQ.........T..).nH?jw.?.C....b.B=.......%.<....."1..\.W..f.......G2..UCd.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.845494258042585
                                                      Encrypted:false
                                                      SSDEEP:24:bk2nIpuLy1tLrxoIArb/G8A2vLxqVbEduvzwIZ31QsrYPahnOXvpRoT4LV:bkEI8+PrxVArbO8ZMa0MA1QT0OfwT4LV
                                                      MD5:DF0184895E8E17693833C29B6B8189FC
                                                      SHA1:3E6C4433838AAE3805D655E1CB7B56D5DFF49E58
                                                      SHA-256:F97D23DF168B8CDA16E7CED04B3D3E4126AB91F8BF94E5D2B42586D68FBFF485
                                                      SHA-512:6D60D80D790195497CE85CF4D16D9E9BFC5A3796A3932849931F0EA08A44BCFAF99C193E6BD228BA52366FB6105E86E88FC404E2C4B216C2FB3E84A1C8F85C07
                                                      Malicious:false
                                                      Preview:WANACRY!..................D.._W...>w.\.k|k..L=7S.......'Q..o..|.....o.VI"./....#.R..=..%D....Q.P7..K.U5n}~E.x.......J.C....s.>wG.@...yD.....A...Zi.9A .%..F...Q!n.^5p.n|..../.&T...V...G.....:_J.."%......2...T.T..|.h......L..2..y......u..<.t.U..s..N\>.............%..n...;;.F.&..I..G...'..N...J..AH.P....@.I.<.;.G.9.'....a~...'fJo..7..f..{6..4..Z6..Q.9.Q.#.&[h....e(i....:J....&...5X!..{.....k..C....C..d.wV.rA..k..u.../....Y..`...........I.j.....T..`' ....?.......CA.T.s.....y.......\..?(..kY..s1A..r.u...[j{../....6..6.........E{...w.8.4aV...Q..@.....`...S.U..n..n.xU...{.>..gX.........p.Wv.....^....`..a...<..zy.......Q@Y.3.5...8...W..?N@...G..h.~..72..=.-Q..U.Z.....F.c.3J.........u,............$.3\....(...;.u8Z..a...%/.....).^|..v.......\:;e....~.....3...OT..8A..r..V.k(f..\.+...PPQ.<$8T..G..3....X$.....iXI./..B..2<]....w..A........'...7!..iFN.?t.....y'....+..:.r.@.a.qf.>.#....kX....%O..aT-..y...A...jm.E?.........)-xk...D.ZWSF......
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.859781572915098
                                                      Encrypted:false
                                                      SSDEEP:24:bk/0U7NUebq67I75e1mq4B+LxU2IfiuOCXNTSuz/Dnr8MDXMDmL1:bk/R7NUeZ7IsQiL/CXNTbvn+DmL1
                                                      MD5:037B98DC1B193ABD3FDA02F4C0CEA79B
                                                      SHA1:EB56EE12BB5E43744EE305F0F09218D8C7BCC259
                                                      SHA-256:C104DC39D3B2E9D4D721833503ADDFA5974A1581E7125BE809DAD1B296822D0B
                                                      SHA-512:4180225A3CF0D4FAC383633CC8CC27FD8E3A1B34814A4837C39AA024942A289F0A5FFB825F284A40E45FF66085CE22622B6C069F7011F19C2E71EF6B640CEDFD
                                                      Malicious:false
                                                      Preview:WANACRY!............=5...E.....!i.,...tn9....'.}...}s/....b...?`R.....UU....4.U.p..U..m...7.....l?s.#.1KT.3E.....r.Cf.m%.h.....+....!h>...T.|..AG../|...k...y.3.H'Ms?..:o._.e.s....0.\8...v...`|..b%....hK.o_.L..h{6...m...].B..eJ...n..]=...8.;.`p.........d.0.P.............WG,...)w.......a..:...io.....'.....Qg.........1F....i.. 6........N._.5..X.C..\ ./.U.W.<..+#f....sL....@.u.....mD....Y.W...2..).....H......#@..L$....n.>M...*V.x....?....x.<.uK.Xl.|....o...E..r.....{5..Xb...IJj.S...l-.<`b.@.%p{5.Vq....e2...X..V ....;0.e..............1......E...1y.....`m...?..w..x. 4.]D.B M..:....n....UP....T.....k.>.\J..&.b.:.Gy./.O.e..[.~..2.;.X-n.C.&b.6..w.yo..Q....+.......v...'.../..>...p......1..M4.~.&*(..r.e...P..ziE....P..U..yt.k..W.j.!.@..!N-$...{..!8.P..?K.9\.............(..........0.U.{...~l.S....-.O.)+....M .^@_..v+...d.e...N...]......c......B.G..m...v.Pr..%iq..{.......Z..?g.@..........e0b..._.3w..5J.eDZCi..4.......a3.m/.7..!."4.7$P.....sId,.;bx.T..
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.859669258324317
                                                      Encrypted:false
                                                      SSDEEP:24:bkg3xe3Ja8GuINOj93U4L7hplPqTYsTf7t0I6T8/6gCTPc5RAiN5/LsyXBGzDNH:bkgm1IIB39L7hplQTl6Tw6hPcDPN5/WB
                                                      MD5:CE5AE74791EEB54C14C436E336EFEB83
                                                      SHA1:67C3D15C1E8B2559F3291B7838E54E0126FD48B8
                                                      SHA-256:A1B4B876091ACF873B93CBA86E9233D3E8716B6BE05C8B8D6C741DA0C4133280
                                                      SHA-512:728824991CB8E18F964D196967F292C756FFA70F2E30F11228EB61751F139ED684DBB8CB13C1ED142F017D862C7AE404DBB4F5071A280F5381A0D685020E7A26
                                                      Malicious:false
                                                      Preview:WANACRY!.....i^M<.+u1..o.@8....H......".h.kt...T.:.:.... ..N.Zi.......Z..EL0.,.F,...^.~Z;.P..u..)S..S..|g9j..C.+..B..8^.@G..E?<..(l.~..&...1.\.UAN.J........4.k".._cp.Q.j.r..r.._y.C.1~l..... .t)........b.J[|M..[Hy...x.E.L.X...dNBk%f.b.L!.F..%...,.Z#.?..................,[...~..G.dS.^".2n=.E.K.....=#r..k.[h......;@N+u..g..m .N........t0....7..[.?..e....%..........FH...S..j...>...I0.4.s'..L.>..)...2.l..{..2..9x..2.J.......q4I^b....,......T..t.f#.D. ..+K....Fal....\.(..D.LCt.)..f/x.gIV.*%.b....>;...7.i...H6j..x.._'.......*.....tX[...O...y..r..p.|q...d....\.-N...HRL..{.e...Qb)..u"S.....E.....(Z.G.bT.J..S.O.....)9.....T.s.RO...Yn.>......WH.....u,]........+.....[M<O^$.$..n..Q......>...e.].(...7."h...A].....C..j2..&Il.F.....IE>..y.-".^;. U...J.D...=...wm.r..~..pG...H.....\....o........#G...h....K.<..4.g..Sy.`g.=.Ht..e...EM.F.Ze.Y>1.'..KI....$..W...p..5..Z.."U..'[.....-...g"..2p.v..7J..........1b..C...4)kx.8...sx.t.4>p...2.T...L/X.n.#A.}B
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):67976
                                                      Entropy (8bit):7.997338989601223
                                                      Encrypted:true
                                                      SSDEEP:1536:6nwXHjfvErF6qz8FB/hePbfTZAdrpDbbcqOahqsk9c8V2mVsn:6wXHjXSFsFB8BgrpD3cqOiHk9V2P
                                                      MD5:116F5E47839FB8B471CE5C26A2DBDDA2
                                                      SHA1:BAA192AB64B64D14048AF0754ED902B270780166
                                                      SHA-256:54FBC46C20A86E8931F48B96DD201DE733278612417C6D930090D432C8CD16DF
                                                      SHA-512:F70144B896044AF431089E69D7D41F89C264618FBA8B93D6A2A157C406B8DBF9A3B2F3838D776CB11CF6D73D40302172FC29FF933FF6C83F9DDF4D96E04C7C05
                                                      Malicious:true
                                                      Preview:WANACRY!....82..e7[.....}...x.., [....-...\n.E:..z^..<......"^....%V.f.H.p2..Cq.A...+2C.+.R.........k.....e....W.,h.o..NH.2M....(.\p...f..WT$..J..)X..+.6...$)P9..........$$.w$.Kv.^0..!..m.1..s.......g.MW.=i.eno.ve.l..3..I....]..8'G...%...]..%u,.6N.a...n/.S....d.......1...N..wY.....G.d...p..Y.[c.=...?e1...).....0U...q.8..S.v.T....Gj!.l."...S.U..x.n.H..lY...&...X.n.:.>x..;.F..RTF.{P.C ....-..I.o.{k.{...?.T.[....).y.z....d.3..f.3...JN..<.:.@.<Z...e...45W3.r#.T.(....PZ.....1.S^.T-...*<G..."..8.2..M..."..H.....a{.N.d.G...%.v!R...R.^..........N..2..D.\b>.&.."Wx.K.,....8ETG...a.F.._c-..a....d.FEb.Q..i.q./...\..."6.....!s........n%...T.<.O..A..........3....C(z..y#.M....!..~`G.Z...\k......<.).Ly...s..+[B.h.#e.ks...Z....$sC..l...`,Fi..F.L"*o.%Rr.-.yC..E5..K...g#..._..G......0..C..d.s.i{..G.c...X.tW.Q....h...Bze1..."..B...........wz.....R$..ic.,......wZ.q..@....C..x6Mi...|.F.......awN....M..-..m...q+.....a|.F..d.l&.3mC....#.9....;..0...q.....e......P5
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.857398962888969
                                                      Encrypted:false
                                                      SSDEEP:24:bkLQc3m4Bf1pWkERmIy2HiDyJtCQnlZfdDeuv8OEJHsFeDFh3:bkMsmw9pbERmIcyjbFLvX0sFe9
                                                      MD5:C8DD0E7B841DFB1CE71D8F517E480DD6
                                                      SHA1:D44C294AB095C2FAE41FA8DF443EA4520EB1717F
                                                      SHA-256:5E846A84881866FFC2E59A7376CA2B1AE37AFD21F407032104F674ECD66114E1
                                                      SHA-512:5AABFB26897039813FFBAF89033603E368B5D844E73113C987F60C3FF87B840EE8FB79E98C97768E2A0D16BE717E95D5D587AB8F6FD11EBF1103C4A8C0B652F4
                                                      Malicious:false
                                                      Preview:WANACRY!....E.... .......w.<...r.....F..:..}.......C9....;..m...Jq.)...].]....W.]ar.....mp....p.GP.Z.[..4h.D.*^.Q.G%....g.,..[US&.X.Q=nj..h.]S.%...<.b.W....g...K.6...O%.#.NE=...{..y.9L..l@..f...j+...;,^.&...H.z.gMn...........j~17np.!..Zd...q...5<.dEj....D..W.............Q....9.... .DH...c.D..\.....\....Lu.s..PJ...4.^.n....6.5n.Y...<'..y8W...~`...7,.^(...u..V.&.:.,.u....8.7..tFW.._.]...V.,.U.SV.....89j......'..q.'.o.x...OD.l..V...T.T....tr.6..I....|.PGZ{..~.Z..~.nm...0.n@.Ei....Q.W.......~.+5..p.W.v/....m.ix..C(9...y.....P\b.r.o....B....aN.31.L.F.g}..M.^..(1YYX...^DU..vK....w{.!D...R...E.=b...:f.ItH.8E.`............NR........Ns..Q.2.i.Zh....a`m...'.5.D.b7.K.Qi.Rp...|.W....B.".......2.OJb,...:.WI.3.+.<*.E.Kb.Q..>.CV..|..N.g.'~5X..7F.$....\.yIn.?..Npn.|...=.q...3....@dXYv..r.....G...v.Mp........&.........,G.~..o.nI.Z..-ll|...c.k..W.S....tV.......x|...,.z..C..R@.nJ...lZ.&.z.G..N....d.....m........M$.Z/..r.R...c.g....+..#.u*.g..`....O.d;7d(s
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.836754166639898
                                                      Encrypted:false
                                                      SSDEEP:24:bkcgOQkpfSxA8tQSTyvgAXvmosKgYYi4viV1wTyTNnpgMAC15td3JqgGc/iruxW5:bkcgGwx3QSTz5YYiH1SyT/ZBvtkgf/iz
                                                      MD5:AFDD6E15B8B30DAFD4DA2D3633ED78A9
                                                      SHA1:02A115EDDC823A6EA3AA4FEBBC040E4802E7B18B
                                                      SHA-256:A3EF798CEF0BAE8F6A3C41290E277342040ED1BBA6A6DD14390165B9AEF6E2D9
                                                      SHA-512:EEB68B62083494ECDBCFFE8BEE09D7BF19C9263118E500C78A36CBB42BEBB4A3DCDBDD6B122D0D801F0E852DBFDFEEC93BE16684D42CBE648591DFCCA1097805
                                                      Malicious:false
                                                      Preview:WANACRY!..........h....../JK.E...W.V|.....K.[.......Y.W.|.;..=Y.$....a.~Re`....-}.. |.M...'.!.Q.m........b.....k......V..\T......6.:Y.k...9>V...Y.._..5.{q..zkQe.L....R.w.}..k....G.dr.....X.'.O..tR..H.T.I..Ys.R.+5.....b8..v...c....@..s.39..]ef..f..<...(...............M[.F.tO..{H|.......W.wg."......".........w..(u.m.....R.e..c ....WCO% ...T.[......g.2.:8.&.......v..=...}H.Zo....5.Y8......^L..K.W....(wk.eK.WVc$..K......j..?.K...E..a.6....!.Qs}.X.a...":....../..x...=..mQ..?.....,Q.B.S...~.....p..f.....\}I\..r.,.1swm6>U..?..k{....F....b..._...;;..L.X...[.>2Z...../T..x........|K.p.a....sr....,...7Lp'..Y...H......O.?j.s.[.......f...e....d..q....%..#....G`..I8.r...($...yrm.rQ,-.6..<m.\.)...K.Li6M....S..!..P....}.O..'.....I..r.+.C.?..C..I..."...>|....(.....F......!...}.F...;(H.RO .e....Q.).e.z...s.l.......I>...$.....Jur.>~]...%p....#...Z@ze.....\.N.y..H.J...R..K.. ...g..K..gf.......E}.Kf.>.(.^..$LZ.=.h.u......9...6.R...8.........!.V...";
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.861741741335247
                                                      Encrypted:false
                                                      SSDEEP:24:bkcUTY1FSjJVPzYIbi+PlQtGgik7xzgxOAahmHeGxVINEFTVkn0qZNfL:bkc71FSjA1f8giYZgg/hm+GzINOoV
                                                      MD5:7171798F0FE80BC38068BDAC9000BA20
                                                      SHA1:1F60C15FF8E231D6BDF3DCDFED14F622A3F84376
                                                      SHA-256:41672B21427A452F92FF05B275F7549BEF28E1449D6F648C9224BC34F997331A
                                                      SHA-512:1A55CB1EDA4E7947E8401457FDBED6BDF3F5F24CF8DFCBC3B3ED0C2354BAB992604D9833A55EDE0A4C5D4603D5EE7DE3DD276531022D9F518719A14DF6E5489A
                                                      Malicious:false
                                                      Preview:WANACRY!......,...is.x.|.....}AM.x6...\..e...j[.....2>.......B...xQ...`.S....a..T[.E.%a....=.-..<w.??..Dv..o..>.].gv..............i.I_l........{g.+y.#......8..0.</...*.t..8..G..j`1U.&...M../.M...._.l..G]9.N....l..|}....6.%6i.?.a4=.1.K......@.X)V..G....T.O..............50@..G.].......:...@.....D.E.."-.j.x.....C.t....N.q....a..ob...p....].......v.>W.....)H..c.*...(n....QfI..L....X....W.8M....\#j3.. 4...]........c...*..SB.1.....?.cb?.b.p....>.W....~...%.q......../.....#.E....'. ...:...T....:.z.c....#I...i<.j.`...S..@......[..O7...8..*!......x+U..u.Y..-A'..T',.I.<\....P.Zh(P.6/.g..F...!.@..[...d.nxK..I...'...$}=._..C..6#.....a.....{.y.H...C.;VF.*...._Q../l.3.m....t.^.>y.i.P..t.3..Y..M..f F......7....I..g..}M._..-...{.....F...d...zN1.S.Hik...=.....4..x..y.tL.PbS....>...xs^....fi.......]6.r..w.&.@*\.p."..\.7B..n.......\9.:M.D..^c_n..@r....!...e........_.1...3.t5.*"..".....dg.!..v...?d.<.UV?..4..n.....a....V._3.f.U.[..c/.2..x..u..6..VG..g.`r8C (..
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.854860036280164
                                                      Encrypted:false
                                                      SSDEEP:24:bkp8Cz+slOx1yoL+g2PtgvBqHRXG4G7CjwnMFthNmehCfuZbJvCzFa0GfxdxGWFt:bkiAt4bctyYRWssithIehCfuZ9vbBrx7
                                                      MD5:C2E4CA2ED9E077C96B01C415D45A2DEA
                                                      SHA1:C915D75041769A1364B740C4124CDE7D01D0D1E7
                                                      SHA-256:41B78E114537D43A730DDF4E0D55FF5DAE9C45F792093D7DDEFA11C4CB55180C
                                                      SHA-512:8EFACDC5CCEA4B7FA32A30271D4A1B1A6EEDA03235C88B768A98D45E1C1B8BBBA40F9D550254D7528D3CB8613D65A9D3E24849AFA3F3C4FC75366B5F4AC32F3E
                                                      Malicious:false
                                                      Preview:WANACRY!.....{P.&.7.y).4a<^.m.@^c....;D..0..y7...S._.:..%m4.U.L...Z......d+..P.^A.LfQ....^.....7YK,..4t.h.K.....].P.^.^V....^.<.U.F*..'..S.:o..d.G...4?.N........yK.^.,.09.L....A.M..7@....nC..l'..MN...[T....L.^.U3n..b...6u..1j'3.3.....D....|.7L$.o...'...Nar.............8..c]...<....z.H.h...z...D ........i.+.-.s0..Y..3.........Kc....Yk...M......[Y.v.5._....wg.:..VM..>N.i.`@.....%..?Pcvg.[..<..kSz...q.._;....6"0kg.g.r.Tt...s4...^m......j(...`...k..k....$G*az....*Q.L..o......N.:^..........A..(....w.:..LI.8.WM.l.p3.m-.;.0..).Jd..8....F.AUwQy..<f..mI..jW1.../A S}._:.......W.a.;.s.m..W.t]..l...V:..7.]......a..1.4..'P$"..1..X.G.T...@_....g...=.*.....Y.....&.Q..&%.....=.-.*.......a..Ry.........!..].6.7......<.$b,.g...........c=...1.}....O.N.2/.<.J...T..i..=..]...fb...Wp^..-..n..?......0.+T..2...[...=....H=..*M.....88p....E...$Yx.....`..R.dQ..8(8.......}...F.........I.....d....F...........p7.=..E.}.Iz.z.....6.d..'..z..b.U..W...9.E.C.%@/px...L..D
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.860696110571382
                                                      Encrypted:false
                                                      SSDEEP:24:bkAQ3sEEUr5OX/OalYwmGXtFg6f4PRaRLEzYUP8pxk9e9goedq/RFvaI9wnksT:bkAcsEZ5OX5lYwm+HttEzw89Ete+jyIC
                                                      MD5:C781613BC0F03A3518FB257145E52DFC
                                                      SHA1:673E6FD6FED0FE9F3F220363FBBAFC4B75CC9541
                                                      SHA-256:47B7D2EA23142CBD1E1C8B5A879710D21A010B398543B68987A2C7528753C251
                                                      SHA-512:679596D43F74B0E21411432156A14302EE9EC9A3716A497C5EF4AAC7507D496ABC0A4DD9ECE2701E016A020FA1E5AB5D66CE37C0F3C4D20CC5F92EE296B41093
                                                      Malicious:false
                                                      Preview:WANACRY!..........1.._.PS.._.D.U.wu.i.:UH.FJ.....3FGl...Q...iO.%@O.A..........=gH.vG@...>[.(..%].C&.B.fTFs"O.a....w....H....T.....{...=-.*....p`...W`Y.... .5_.V...,......q..o-~S..3.<..7...........-..U...+$..t[xX...g...BE...O..(..N..d.P.4X.....$.|.w93[........C............._..S...!E\A.4."..q~....IA".f5...b..8_o.yt.5...*........p.6@x...)..<.....>....}.:....;.J....!..U.....]...A}..N0S%EXp....+3........}.l.....M..G...p.qs....;uB.7....Q...h,......8`....r.z.....E.$).r:.......^^|....3".-.$.*$..~...A....i).Jb.j.M..J.~.].+..<.$.D..UJm..S..7. .pAj...`{. .}......z...:f..Mk@..XN..I./]K..0?...<...>.0S.R......^-..Q...y.[(.2..;....o L.ubk...=O....#E.+V.j]..Q..2C.......*1{~.C4......;.....h.]....]....^|... .eX.CF/.q.T.`...cG....e.RV....L.hN.\..+&.......9.y.......r.o]......AT.`.\.....aL..l..*.....^...M`w...ul..~.W.....a.y.&...g4..A3%Q....&a.bt>qts8=..C..>.;:.^..g.......H.+r ...W-w..n5.+...y...6....B..{n.:.......!/3..9.[.1..v....1.CE...9..f....>I4.S.V.D.z
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.845998088932148
                                                      Encrypted:false
                                                      SSDEEP:24:bkn28U3VoX3R0LoaadXWH5UJUbKKbUZtElLUv7wusLLKUBwgtNb4C2Maw4s5x3:bkn2pV+W/alOaJUbKKbUgpUs6vgrUCtP
                                                      MD5:3259D385B50358141AC0B65EE301CFA7
                                                      SHA1:DCFB0F7EFF83138DC8429CCEABCF47C7E8BB888A
                                                      SHA-256:3C10395BB40A364C660C7D2DF04D6AD0BC9A55ABC72D0698FE869CD096FD7422
                                                      SHA-512:1B4622C8C988BBC17C11617BAB84B5D9FF6696523E0A9D3E7880688EAB346E7A9386BB3D0C0B8A2415CC8F7CF409FD42DDB52552918AAEF052458F4E4324C700
                                                      Malicious:false
                                                      Preview:WANACRY!.....2...K..A..f......D7=Sy0...<_........4.g...z..m.d..@.._.M....RZ_3.......u..<.......@..M.T.to.<........F.o...!$..t.P.Z...t4.p...=..P.v....a.s..25!.6e...=......w./.|g..D9.L..P..S.U...5w.._.O..%_.....T.nV...<.,..{".R.;IM...=v2.......?b.9|..4..dNZ..............O.....F...Z.r........{B...m.+V....w.N..F..T...p.5...m^"....)#.A........q......?.K:z..Ixli. #.Lh.:H...}.Ac...R>....m............O..gA..G. h.....qxU...;.T..v2...K.._...j.......W.....$.9+.v....,bf;.1..)... ..4.m..A*...$...N.-.)..g..n....2.O..Z).3>.}.....m....g1....MR(=../...rN.P>.ti...\...!1.o..@..k...)...k+b..x.f..b.=..\....q..a<..PN..|.C..;...zb......7-.j.6....0..{..`....J.....a.c}.za.BI....s.....5...*.D.B..lIz.V.c....wb..?.K.....6k.....`.g.3..~0..A.....B. ...q=.n..y.69.\...PUxJ\ .G"...t^...-..'....BZ=....U ..V......c.K....-.V..`.yU}..r.,.4...]._.$.dT.>.....+g#(q...UJ..f...u.U...|.....,;W...A._....I.I...'._..:..F......]]....g.Y..d.7:A.. ~.......%....b.$...K$
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.835803576620504
                                                      Encrypted:false
                                                      SSDEEP:24:bkGCYfxTvJZBAjjpZpMIFFqgrwFPm5426MMpmMNOQAc4iUIVUazDBjKg:bkGBxTvJ34pfFNy94MEPNisaHF/
                                                      MD5:EDC89AA619DCAA3B528EFE975BE2D7FF
                                                      SHA1:F12075DA01C9DCD4D20440960E1AB154D53CEC46
                                                      SHA-256:C26DCA0C1A09E4912891A2C1E7EF8C3745E0D628767A297BB67E3EF7818C6A57
                                                      SHA-512:DF7B1D9BD2A016DB538D9CD27A85558C45E59E069CEB3E777BAC591C432097EADD993351E1F2E1D5D11757F539710A401F78CE38DE51E211D9183A21F4EEFC46
                                                      Malicious:false
                                                      Preview:WANACRY!......{.h..)p.......%..m..;..^.<5;.@...9...Wa...<.. ..h.!.O..&Q...ac.Ug.........<...S.z%...-.6{..{#..6...%......[....>kS....W.d..E..T4...&.I....>SR....4p..9)Z.|"z....gk...i......G.*....[I9h....]....2..G&.)....R....?.5.......w.l......i.....w.]Yv..:...............)..Mo.O.Q..)..5../..C......5......=...D.~.z<..uoA..[....^..../..... .{.1....&..dV{5CE.............+k.s.B4.....X.=T.....Jm<.(.].82....!.N.-..;.o....L.5..-..y.Dt..|x.Vx...._D.J.q|eGR..S.c.%...&....A...O|3I...G..(....IH\y.69.!...<@.{....=[.V".\....|.gB...2..k....;.p/..r...>}...y:.7....C...Vd....A....@.z....02;QR$....M...]..[..8....yv....f...cp_5=hk.|.......Sx......_.....L..;..*C.D.d...H.R.C.....R.&d.3..T)p..as..........|.%i..?..z.t!.3}{....s.m..hG......d.6&w.....qoXC..=A&kd.Yj..5.......l..x]...p}...l.J..1.\.......6.u.... ....J..F]S..'..WS#._./. .0. ..Ww ..)...-.{.?(..z....I..uT2...B...m.....S.L.P.8@.E.!.R.E.....V.QW.?w!A.=......=..-F..P..1D.W.o..L!.I...e.:...iQ.".Y...F.N......2.WD..
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.869132879191293
                                                      Encrypted:false
                                                      SSDEEP:24:bkAAtGUhnRUoZ0aQd1MMiiTWjDdRvH41rt57FrxYsGLsJsaTutA585o2zKPGyn:bk9tjD6aQXQDdZ435P9Gbaew8EPGyn
                                                      MD5:EBFAA3FD4646B07614571F12DDCF7154
                                                      SHA1:0DCCA911A02D3DC928A656AB6CC947A3AF7B30F9
                                                      SHA-256:EDA1FFD7559CFDBFCF830168A499A064B56AF33442DBCCB8CE2F100F46ADEC66
                                                      SHA-512:A6E8DFB5C07E5482BE19597BA5910F66AEDA48008BC8B828B103C69F3012E466AE342CFFCBBC235C59565F57991C1A9DB6F8C0E2D7ABBD7251B3190FBF9837C4
                                                      Malicious:false
                                                      Preview:WANACRY!......Wmk..E...u...%.(W..kL....G.....>..e.......G..i..m."..)...w..n.....v...e.Z.oF..q.<.mu....%h@.l.!.".M.m.....!4(.B.g...fD.x....Kz.E.DQ]H..Y......;3........&K.X<...5H4.`...e.wl.9....nmi~..<z.....(D..../.b..8...sW.......0........P..W..0z...8cO.......................J.{jS:...cYa.......p....ys.z.6T....p>}.%....X&...............m..?..i^k...n.O.K..@r.....L9P..a.h.5..=...OQ./y....e00...*.X.p1..C..IE...w.mOG.]..X:..\.=.......?/..1.A..w...=...1...@...o....j..T....4..@.._B.~l#$w....oMAF.A1..s...Y2.w.s.U..n5?...3.4.......!...B(....).....0...M.N]#....g......3a]".. .?...S.(.&...T...}3..n.%..V..K..O.~.i...7j....I.VOc.f.qSZ..;J.%n...+.u.E:gp!^.gEG..ZqD*....1.!.o....]q. .l..w.b....0...-..<.gx ...sok.|.....w................{.../R.....:..../.Jy.&L|..j.......h0t.=.^..?..^.....V..i.....v..S9......w~d...FQ.A...s....!U)0a[..,..Cf.Fyv....JFiu...A.7..].j{C.C..!I.....\ P..,(......k....mV.g....e.{S%.X.Q@......z6...T.C..r...q...6..L..f...C...'Z._.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.840296169725666
                                                      Encrypted:false
                                                      SSDEEP:24:bkTMeEBn1vZdZOVnw/us6tGE3PTzKf+6gl0Ed8aoyIrLWF3ck3MxP8T:bkTMTXZdESus6tGG/KtNyIrLQ93MM
                                                      MD5:0243B1DD2CE4D8A95ECB18D0404B8934
                                                      SHA1:78F1A3F3B2396F29834D848EB23AD103C34B0962
                                                      SHA-256:2C047466491B436FA8D0497182B6AD605CBF0D29A1C846221745B8C8F0280FBF
                                                      SHA-512:6A19A890A0671A2E8E3A8A4E1526717A6C0B0BE71CC88593D291525B83138ED2D63D03F5EEEF8152FAC2D120F14CE2A97175F29F762BFAE8D3B4DC29D4FC8311
                                                      Malicious:false
                                                      Preview:WANACRY!......*Xe......:`..?..`..<........l0......O...|O.-.q..D.|@..'!..z..hx/....:!..S....)......@.q..Gy...,'mB.;.......hC....B4C.W....=Ie.GRL..[Li.t[>0_!......A.....N.S.....*....V.u.;..e....u.D .OvB.6G.yy...Q.E`.j...%.D...,R..${+z......-..k{..8.w...................RE+...i...@...x.9.....0:.7.*l.3.A.YC5..B...I...D..>S......g.3..}.4m.;.) ...(.i..#..2.=]....F......]..L.#>..x;..a....%..=.M.....9...c...5... ..0..,...u.....R..~?.>.+..]...nUg....J.Jr.K..W.W....{. . .. ..!A...e.....}.....1...L..Q*..? 4]....u..l..F.....VN.O....Hb..i.....C.{A{...jnK.E...-.|FvQ.......`.E.yy....q......7D.-..HN...SllnY.m.. .$...^..?.Z..iE.....`x...4.K......Tr.7.-?...b[.+.A...+.KW.ZQZ..c.3....I...xl~.'Aw.c.E..`...._..(.....V.m..JB...J....HQ...i..t..M...............4..."Z"..E.>.Q.H\...5..p.g.R.Q ....B.*.;..}i/0...u..C^:.%.e..s@>..."9Bz..#.3.]x8..K..b.~...2..D...d.@...4=..U.......2.&r>e..-...L.^.....2..d,*H.sC....I...0.lt...>.k...Vp....jr#...-...e;.n./.$B%LA..4.nQ.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.840781609888517
                                                      Encrypted:false
                                                      SSDEEP:24:bkIbSwCaYhckq88beIaB8iNGIjQZslqil94xq74WPb:bkIbSu4VqafNGIMsldl9CeD
                                                      MD5:A5CD3675800A5D024DF22BD3D73B7F28
                                                      SHA1:7DE4B247B2AAD727DFB59BF34C251CCAD6779A1F
                                                      SHA-256:0F20843E9269EDC52CFC4AE43EC3A6CD98A80223B0C37987B7DCCD2C4944158B
                                                      SHA-512:73278462BB952F5B44DC061A2B675A919DBFFF584E576AEB6724848F931741DFFB374E826D9E413E5A9C7DD5F0865ED40415873033664022D7E5D8049779D7D9
                                                      Malicious:false
                                                      Preview:WANACRY!.....o.......33....0.?.6..}.....'O...i..]*.\-^...eA.L.#..N..W.9....1_..U.L..G$Jlqwf.b.$!....D...{.'..0.=...D...3......;.Y..XC.).^..B.V1...,....P.D..a.rP.(..E.......B.b}......$C|.'.Bf.d.oT8.*.u...6`<p....y..< D...D..$?H.5.P....]s6%xEI..-....?....*...6.............`.-`.U.*...=..*...[F.......s4_w.ID.m.j...<.Z.d.E.d3g<j.61..y.I,l............>.....&.......%.".k..I.<rA6...;o.Y.|..4.t9..._...iFkL..2.Uc:..jtx.'.O1./SZ...ME.wc.%.......L.f.v..b..1.=.]~.."-c......c.R.Q...w-y+O.M....".:J.....F..a....4.F.D..e..n....'.pM.<nq...J.b.r[.......D.}<.)P{.k./..O.e......9.9TlyZ=..T.."..%....$n[?x"..6J)....N<!|J.!bI.....=,.-",.)R......:?........{^.gT..-.....e.;...&..]<.!....Q.=tc.6.{.J.f...o'{p\M....j..#KN.....f[m.....v.:g1...>.=M...L5.R.\...sW.....'H.^..[/......+.......S..o......;.l..O1.^..m..L k...Yc..a..8h.3.d.+O..z...y.x.\...4...~v...Q{.m..|.v.~.)......4..._:L..;+...5]...H..OU"..J........[.Y....C..%.(.8..F..9...|.`..B...;...Yl.9.N`. ...^.J~.7Y..s...
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.830863680690429
                                                      Encrypted:false
                                                      SSDEEP:24:bkgK3JKlV1CshbINmjS9XSUe6nDY+QeP2xkgrZv0xsW/jRaaXuVLly6PHcT:bkgK3aV1Cs7OCUe6nk1aWv0xpdaaXkRQ
                                                      MD5:9ECA795BF91F340CC15ACD5D3ACD6A0E
                                                      SHA1:B9CB8E5512E6D038999F38614801A5EDE76026EF
                                                      SHA-256:43F9C09ABBE9A2A592299C455C120E4F0BC68042DEC4F5821644E64B67CBD764
                                                      SHA-512:C54BDD438BBEEE445627E557085900C9DD382A1B95EE6FCE90F2B7A9280A3582C7E7DB7EADC26B5A778A686F8C89137FE52254498CF14C61CADB75F36ADB765D
                                                      Malicious:false
                                                      Preview:WANACRY!....O.L.5.p.e.....}D...#G.S.C..(d...M..a.I=+\5.JJ..'-.. ..Z.........])k...... .&..X[.u.E..*...P.....d.{.&#\.....6....(.Q..."M.._U*.0.$.xM..C....i..x....Xq_...gU..&...|.+......3........M.R.........b9Z%....@..w..."7n408..%..E&..k..h.......?d................rz....b.w....h.6..-....-.Yxn....^....`..O.n..5k<....g.2.=.K...~..../}..i...dK)...+..S..s..n..<..Z.."...?.....].~i$.......@.........|;....0........S._...4g.*FOm.0+5].E....W.&.......<...T.r.+.U.l=....0#......T...1a...v....4rD)K.-..7..9[....b.W....E.{.cq(.T.L.g.Z.?!....0G.{5.....i*.)...a.....[...~&Pa.....k....:......W..*PeIy)..`.......f.......M#`.HX.5..E....~.v....I...opW..,A..+.T>....&^.*P.Y.g~?....*(.[.k.d..f../7dB......b..G:.hWX....\AU.........cV.Ws..'...~...didRO.r..9\.... ...._.A.....Cx@pzW..]#..Z.gjLn.&.[..(.4.z.H?.6.{....zc.......Y..t.5dj..2Dq.+....~..r...'..nm..X..Agi.8.#..[...D.)r!%....TT$-Yi.. D.R...O..O..%-..U{....1\.i..V.rcEX0..:.r...O..%._q|(...L.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.830167876025704
                                                      Encrypted:false
                                                      SSDEEP:24:bkKwog4kjOnzAuV+wvxWK+XsuBn7TrzJHJbyWwbr6ZX24ZOLiWEa+H0GGqyQdmWI:bkK32OG0g1zzZJbXuryPc7EvUGnyIt5K
                                                      MD5:B15233316B73FF3B2B09DA00A5818BD5
                                                      SHA1:95A45032B465E1F592D9C63DCAB8BBE419491465
                                                      SHA-256:E0C21CFA2B86DD6E2D9AC92AC36EDE00D72B79BEFD5470D84084DAD3A8CAD2F4
                                                      SHA-512:C555F623C2421382D8138F681CAF8935C20C4C70C5814857A75B58A92C886CC16BA0ADFB22B178BE92A69E0436C87BDECDD4D299A4D1C11F3B356716FF924413
                                                      Malicious:false
                                                      Preview:WANACRY!.....jj....g....9.4G..B$.P{aM.%ge.>>.....F.>0.p...VN.\S.....(......}x....W.......%5.Ssd..dY.........Q.{X:u.BN...&.A..R..W...%..iS..[.e......T].....s.X..-k.a7Q..I.S.......\#../.P...>.J.....Mv.l..%.p..u...^.S...M/7...N. ......'....:%Zio*.8.s.d..E[z*]B.'............J0&?.x.xN.!.j.@e....uX..P..*..@.q......a.2.-.........D[...w_.....^t.j....[...."R...:....=..0.$a.<E.i.Gp/...t..1..Y4.`@-.l..&.vXQ..........&"r0ix=.-.....w.$.H5.to1......V..Z?.3..q...L.uY..C.7..c..y....9.......L..y.j..&.W.}ED.....R.....O.=<...~.3.....A..,..d.F.>.z.{z.........CK.U.JM...7.=?......I.....mz...*.!..RR...(g....u.z..y..&....5.L...\..j.NM..L.4x..K.Q8o.u........1..X....A.x.v..'.J.\......p.. bu...[.^..s..=wRx.5.p..u!..d....... /;......._..F.V.....Xu.<C...anM|...G.Tj...%B(-8..+..-W{....O^[6LL:e..l-.y.hF`.M.%...6f.{.6..M........8.\*.2......#.w.[....J.E..Z.D.3..D....> ...B....P.ZX._D4.B.....~.pe.k.......u...|)..b..r..X...'"........ZL.P..:Q+../...s..o5....t..*.]q.7.Q..UMJ...
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.847562504908324
                                                      Encrypted:false
                                                      SSDEEP:24:bknfYzD8jnN1lhVqrcOl9QWFV+Uf6vVHeNnIGY/ETxjyhdQBdtbwdN:bknKYLNxOl7UTvUZI5EkhSBdd6
                                                      MD5:B677E79DDD7DC51B99B53D1F57B59F68
                                                      SHA1:7DAFBA6A24E0BDA7D0CD189AF2964A9BCF00A786
                                                      SHA-256:EC2363A33D5CC072BBEFFC28D97EC57CF053D94F8D6AFC9C59A97D0C67A0EF56
                                                      SHA-512:2F441C1D2FBFAACA4A99A63E01A6463A1832B2A960CCEC0925C720180FFF63634A895FEFD568BA537F08E3F7BACA950D0E0AF8BF5D5DA2916C7BBA05A802385E
                                                      Malicious:false
                                                      Preview:WANACRY!....T6:.F.IGh<..E;..'.~..O(.....*N4...:.....i.(Z/I..(./..f..=..2z.3.....6...H......27..,....`.R.W.D.T..q`.....B...m;...V..O.....B!...u..q......p.b.m..."}..%4?..].............v.Pb...p........+I.r....aIR.0..~.].m=.$..R.7.........].......O\4S.3...J...^.S............&.m....E&...$-..X..|...T....PSd..r..n.C........'...|nz.K092rVf..C..Q..8a3"..dp..G.~8.D7....p.....~~.0....k...&).....e&.].....v:.F..qO@..!.}.7).......|...w......D..1-.... .......:;{.....h..}.O?.....b....=...w5[.<...)........a..h.1....a.......3,.-.[\.].c."$3....Ps.....)..h.C.9.m.,A........G..'........x.U......is[....]..@......>...xs.........v<..H....9d..#..]..K=....KdP..._.j...........(O.w`.._w.PwE..%.J3.^h. ....n..]...v./o.>.n..!..__...IX.w..)xG...Y..c....#j..l..~`Q'...e.'5........3u.sa.m...r..C..i=l...by...;.aX.V.L.Cd...Bb.H|....w,CF9.;M.f.m.K.y.|.{.<I...2<./......&...../.....t.Kr..........sw]z..c...S.n.....e.2..z.f.W..Do....uy..h.......:..........k.f"VJ..y.\.\....&J.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.85360645605731
                                                      Encrypted:false
                                                      SSDEEP:24:bkMEy3shjQgcmUepyHVx0igapT0/lNPgdZhwq8qWAfsK0m9Uvkg3:bkby3u7Hs12alOlNEZWoETmE53
                                                      MD5:085004A79BF03E8969A894D9CA1CC5E2
                                                      SHA1:13ECADB53D4B13C38B0361BDBC6562F1F0F24AB9
                                                      SHA-256:3F8FD80803925A7581E27C5FF6E93BD8BD9B5F8E7DFA9A80C7A6344A82E85BA4
                                                      SHA-512:DB7BB1E640D232F0D5DD8059B55DC619D58F1CE5FBA78C7210276EC60998E8DB9D6A356FD76A3D9675F065D7569643128BA01006BD6328CC1E56EE6B4256797D
                                                      Malicious:false
                                                      Preview:WANACRY!.....@^...%..h.h3@YV.&_......'.#...a_.5..V*.L..0s...gt...L..de.z.H.......s..T.B...*Nw....:.k...A..L...R..}^..#.....O3..t..$j.{j&..x....H.x...<....7.d..^*P ...eUN....x..T......<D... .......f...3.M......_.WV.k/..&.[P.....f..?.d"%...D...'t......e.n.".............}.p..]..M.D.T4..[..VAvl./M4.)wMZ$.....4._s.o..".lW.;.Q.B.j.e].yFX..~G..k...$1L.*.PW...a#,.#.:C..Eo...{.j....H. .pg..Sb.lw.......J.#...8$.3.(.*..[+.5|....ly..s....h.H...f.{...c.<...I....U..DtM..._...%..y.6...........8..p..0.xp.j.........]..:1....v...i.y.#......9g.6.R..[.o...e.-..=.....>F'.3*.....x.t"........[.vz...4..Y.a..y1.x..Zc.....W....9.c.....p.>....t....(.....J.#.Q...x.>..v.....N...&.U..O...H-..Nzc=.8;$...... ....O...s./.r..{P|t.9W=.s..5.B.'...t..c_..u&.....7.Kk.H..t.]...k.Mc'j<.\.K.y...Jn.+..y.W%}...V+...Y.......9.....*5..E......\=...yI.LrC.....w.2u.%@E....W..17.[6..,q,...Ak..H................O.<......@...G....6v....9NW..nZ..>f8OU......k.{.Y.....qj..../....z..y.p.?.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.844856836691295
                                                      Encrypted:false
                                                      SSDEEP:24:bk9PVymgvYfT+GfnudTVvTP5eZDfcSVQmwmqphOQwg/+pRDwAYKd97m2ioGs0:bk9PjA0+IwhvD5eZDfdVnZqp9o1TXf6f
                                                      MD5:F4CAEA23107B4DA5756E22B485AB9311
                                                      SHA1:FBE235D87B3D33F53CA7E708BABF2A886EBE9F8E
                                                      SHA-256:787433E7D5DC44FECA43B493C40EE4FDD4D84BFD6AF8407BDEA15E134E3582AC
                                                      SHA-512:447F448C2238101115FA1CFCAD85C2513CBF7D45B38703BA0212612D390F0F7F87FE74B152356732166B9B0BF828E7AF99203E87DEA9D5813AC1F53A90BC04E3
                                                      Malicious:false
                                                      Preview:WANACRY!......#...X<.\q.<..#.J|........4o..<.]4..+..6..FE.d..u.6*...D...Y%y&-.v.YHB`Tk...|.Qi..@>..j....?.P.2...NLB....u0.f.M......!h..Uh[.A..0......&L..&..'Y.....r;F.5^.Y..).a....*..fY.z..0.. ...F].).c.+.8.\.:.M4r..m..6.k..0u}.2.......v...f.$./.KXt..<\{.............y_v..eP..+.E...8...pG.......... !....$.*6B........l..bk..I<P..f%s..[...%.....~+./>D>S...=a+...]p.M...J.=);ap....=.C.ud..)/tJ.P\q......V...a..'..=.....F.a)A.....D.?%).V.J..b....~...z5..p..VJ3......$^.\w'.<..."./.<.'.^.........N.^..#.M.t..TC.....jt.......'..(...m].,..$,I,Q.$r...+.4..&.}.......2.@...!.J..{.....JL..7.N4..x......`W.......N..4 &d....bW..g.g....\R.2...kQ.!......,......s.N......n...1..:..y.....?..Ya3..,U..=.....y.....//.....YX8C.u.I..3j..df}t.6........f.V..t..-..X...`)...T.....7..?M..9...y.jlb!g`....Yhn.&Z2.U.....O...$._...T...a\g..x*.....f9/..7......&`.C..7......R...G.....z0a.X..})]oM.2....K..:.$.....9jt.f./...<.7\....g#.*.].j..D..6B...'#......F....}l.7zQ...V..1.K..).
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.849112094612508
                                                      Encrypted:false
                                                      SSDEEP:24:bkr4J2x5ZKhdwLDOl22ZAZt6L88PNKmiV88WzbPrDFzSbod2:bkr4J2x5ZywDOl22ZAZcymd8GPdS3
                                                      MD5:99E1456C8564F00017C5BE9F37E6018F
                                                      SHA1:0BACD5ECEC2D4259C0D1873CCF3B8FEBCF421054
                                                      SHA-256:387C03BE007542AC114E0B24173D8FBC1F0D5AFD91431A32E38A3766B7E6AE40
                                                      SHA-512:AF3B1279CEC56E359A20157B23ED80EFA4ABA66FB8E24B4A97620D567A5F62FDEC5ED84D3A16B15C18BDE7E7FA96961F5560792232C635B9BD792B378DD70DD8
                                                      Malicious:false
                                                      Preview:WANACRY!.........~..{.y...Jt.Wv.F.l0..S<...l....o+...b...}.....2.,....z...U...*....w.........j(....I.)...3.i.*e..Cg..+&!.Y...O#q...L$.#E|..I..V.q.....\@..........&.:/n..f76.PH.7..z.7g.@/..L.f....0Q.V.I.`...z1.QM..jG}.*w.i...z..Eb..../<....Y..............F................$o....Prz.*`.......t{s.j.y7|.VY..Ut.\s....}`n.j.s..#@..@..?..L[<|....B....E.O...a.5..o.T...Z.hsw:zw;Y.Z.|......X.s...I@..|2b,.v..B..X.....9..F..u...nO..*..Z....`QC.}t..}O....z....}..a....(...EA.l@..D}pa...3...z.h..C..`x.._>.0..I.9.S1......#ths.....A...}.-.....Oi...H..........b7..a..'.c&.}....T.K....qS.K`I.;.=.a]^T...C:. i;=>+.Ekb......r>.a...>....%r4...E.G......g...N........`7..+.".X..X.OI.......m-..._5.-g..B.|...P...}..'...~{.......5>...1..F.G.....=0...,fE%y.G(.3...........Jq..g.\..N..KB,R..[.B[..~..#.. .z~.=..C..Gel...M.{.4......d...8...U...Ut.......y..a.r......X..x|X....oLU.G.m...?/4~dC..,_.......18.....~..#..........^.....[?t..o V.......J..2..;F....V&.....Z.. .../!A.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):114264
                                                      Entropy (8bit):7.99833490946137
                                                      Encrypted:true
                                                      SSDEEP:1536:flO+Gp1rS4Xo4h3KKw1xoyntuqmLMhPofiqRPFABXh+gQYhkPCLly66hEs2rsmkB:flzGXrd4BL1SCZmQoaRXhHjM66h/2Ylv
                                                      MD5:FEA39436B72CCED3FA06606D545FE899
                                                      SHA1:126C69B172CF12B9CF28CC2C1060832A948A31FB
                                                      SHA-256:4D3CB14DF2D4168038E4960DA924A0961ED96984383745F712BB8CE472840604
                                                      SHA-512:186BC3F240A2941D6116996CA009231F5C9FB6959EFDA5E2EBA76235CF7855B19A69D88999DF675CE3F6A322204A93A87B8C59A8D911382D5EBD1642665A6E55
                                                      Malicious:true
                                                      Preview:WANACRY!....].....t.......q6._.q...v*"...........^i.(..1.U.-.kH^>.A..S..f..X.....oJ%*q0..Bh..........$rj?w>..:L..B.9..J.e..Pr...&.l.|e...T.j....U..8.-.6../o#...T..5.D$}.......A...a..>.5.#.}.Q-..G.\..IL..(&.<.`.S4.tX./..s:..4..:...X."w..f.0-...I.3..........6........qG...M.....:..o.f...4...qU...ohBYkoFf.....l|.x..d...hk..y..8a.^...'.0W2...C..Td..7.....R.b.V.......*.d....jTY1.........up..2..,..........:....&k%.<.z{.q.p<.A...'...fP.....[.....B..G....y..)..`.F.C9...!.(........C...K.t..*Wfs.R..k..a.b....>....0@+..r..Xg...9...<3....h.....ocM......&........2..v...n.....H.{c.H..%.e..&..}.Q..(6.,..|..p.P./4...k../x..q..i..WPo,".f.b..,.2..s...)A.i....`.'....2.A..D..,b.)(.P.F.<;E.%.....X....}0{..I..|o....!..D..G*.6)..3I......u)O...>.v.._HZ..w......<V...4..1.4.R}.A.'W.$.R.p.w.....|Es.MZ..{.0./0....p...!....EK..~".......1.(.u......J..O.(1!0....%C..-bi.|..k.D6..v.....(5]./..0B...*?y.)...*.T`....^T.?.Y9K.;Y..$).$...s..l.1.....h.1.9lr.....v.A.. ..]48Ec`
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):37464
                                                      Entropy (8bit):7.994488160774127
                                                      Encrypted:true
                                                      SSDEEP:768:S49MNUV95/fKw5Tw6pEII36WegCgjfg7zt:S4RV95/fguErnegCgcp
                                                      MD5:DEAB669EB6E634F5BED6A508477872F5
                                                      SHA1:941B371F9C5B4D9D0759DFBF65C3466627562A34
                                                      SHA-256:7792B02070FB475CE81656A0F7C724289664CCCC84D3118902132D2483FADD2A
                                                      SHA-512:D1531D43AFDAB895B04E1429BA5DF99BA4B89895873547EC1102A19C4B13BDFB28D78199E2A60FB4BA3D8F29F555A1F1AD7B6566EB3C525CB4AE845F708F1527
                                                      Malicious:true
                                                      Preview:WANACRY!.....|...&.E."..,..A.|.K-.#X.....Rf....$......^.h..!.....(qf...J.x..... |..P ..._.....E....iR}......L.VL..q?*+h....5.....&..J.......gB.......`.L..p.sqA..=.xN. *?.2$.<.A...O..<e6]...`.C.}.G$c..];.#g...c.|RY........]..z=.hvI...[U$q..2]..ux....h.$....4.......o........LL..7.@?gA8U..?5..*6.k..-.-(..o2.W..a.6........Q.K.z.N5.<....X.1H.....-jhZ.).b..Cl7b..W%......j..2fk.M.h3..`......Q....5... ..k.;...........S.2...tY.......6X.N...K.(b.....\. .....v.........x....L.^.g....9....7.....b /.Z'.UU........z\...E..G...D...D<.Z.,..|...lG....L....U.....m....c..1...:.L.D.H.j:)..i."e...@+..*M.....U..w....~...s..X93.Zf...#.....D......)....M..^.Z...."6o..n.-...b.........&y...+...`.. w.....;.....(.4qp)(f.f3'..[...cM.0...ID6....a.8$I...v.]...".p!^U.v...9..60f._+......=..6.1}......CC.1A...!....@V...a..(.M....Q.J=.......J...di.w...Tr...i-.De&..:..j.z(.Ll+..\.U...-.{/..47.|.....u.G.....xwC.....Z...H.E....7.....M6...\&..%.Ji....~{.S1+._.k......u.C
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:ASCII text, with CRLF line terminators
                                                      Category:dropped
                                                      Size (bytes):933
                                                      Entropy (8bit):4.710902136409594
                                                      Encrypted:false
                                                      SSDEEP:24:ptrPzDVR5Gi3OzGm0EigS1xbnS4RQhbrW8PNAi0eEprY+Ai75wRZcet:DZD36W3ChvWmMo+S
                                                      MD5:7E6B6DA7C61FCB66F3F30166871DEF5B
                                                      SHA1:00F699CF9BBC0308F6E101283ECA15A7C566D4F9
                                                      SHA-256:4A25D98C121BB3BD5B54E0B6A5348F7B09966BFFEEC30776E5A731813F05D49E
                                                      SHA-512:E5A56137F325904E0C7DE1D0DF38745F733652214F0CDB6EF173FA0743A334F95BED274DF79469E270C9208E6BDC2E6251EF0CDD81AF20FA1897929663E2C7D3
                                                      Malicious:false
                                                      Preview:Q: What's wrong with my files?....A: Ooops, your important files are encrypted. It means you will not be able to access them anymore until they are decrypted... If you follow our instructions, we guarantee that you can decrypt all your files quickly and safely!.. Let's start decrypting!....Q: What do I do?....A: First, you need to pay service fees for the decryption... Please send $300 worth of bitcoin to this bitcoin address: 13AM4VW2dhxYgXeQepoHkHSQuy6NgaEb94.... Next, please find an application file named "@WanaDecryptor@.exe". It is the decrypt software... Run and follow the instructions! (You may need to disable your antivirus for a while.).. ..Q: How can I trust?....A: Don't worry about decryption... We will decrypt your files surely because nobody will trust us if we cheat users... ....* If you need our assistance, send a message by clicking <Contact Us> on the decryptor window....
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Archive, ctime=Thu Jul 25 21:01:45 2024, mtime=Thu Jul 25 21:01:45 2024, atime=Fri May 12 05:22:56 2017, length=245760, window=hide
                                                      Category:dropped
                                                      Size (bytes):575
                                                      Entropy (8bit):5.140446565826782
                                                      Encrypted:false
                                                      SSDEEP:6:4xtQl3y03CpzeVs+bTNAUHUtxXCzaMmM7/gtrUod6tMljAlpdmqLEoJ4D6Vod6Nd:8iypzYNbd0thHZOgZUobjArozhmV
                                                      MD5:CCD2610ADD4080C4DCC35A11217DA6A6
                                                      SHA1:001ABA92D58B546C8BD54E0BC4103661F68CF92A
                                                      SHA-256:0E272CF58CC66E7B0CC4F42094232A46B6EC11AE5ED695BA4156A1A28DA41E6D
                                                      SHA-512:36DC5CE3027E8A77639783E31AC69C9FA61C4761FBEB9A819C1EB49F4A32BF2001C0441FB28D35C4EC9DD1B713576E7894DE8FD13BF14CE62A436F9619093DEC
                                                      Malicious:false
                                                      Preview:L..................F.... ....b{=.....b{=.....`.1.................................P.O. .:i.....+00.:...:..,.LB.)...A&...&........DDj....%.=....(..=......t.2......J.2 .@WANAD~1.EXE..X.......X7..X7...............................@.W.a.n.a.D.e.c.r.y.p.t.o.r.@...e.x.e.......X...............-.......W.............,p.....C:\Users\user\Desktop\@WanaDecryptor@.exe......\.@.W.a.n.a.D.e.c.r.y.p.t.o.r.@...e.x.e.`.......X.......216041...........hT..CrF.f4... .u.E._c...,...E...hT..CrF.f4... .u.E._c...,...E..E.......9...1SPS..mD..pH.H@..=x.....h....H.....K...YM...?................
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):5256
                                                      Entropy (8bit):7.967184785067311
                                                      Encrypted:false
                                                      SSDEEP:96:oHWAr/YykH/V9GyeqnOYAlqlzMD7XxWpGH+XHl/sKwlbE4Pg5ottR2qrUj:EWAbXkH/q2Elqh27UpGH+XHl/ZwlwQkz
                                                      MD5:D63174EB3B49369C97D82DFA02E18400
                                                      SHA1:9F87D0C2DEB6DB8C7E71D7733D404AC123F0C629
                                                      SHA-256:1428B1D6334A8E9BCA4E8AD5F87BE2A9D63B5518C483A20DB2A9461803C7A958
                                                      SHA-512:DA2E5E10E56D073E158A57F29355C0673E4587E7F0A677689F4DABDC502070FE438475281550BBF24833C0A0F2D74CE8F54D7632E96D2EBF6831855E844C18B4
                                                      Malicious:false
                                                      Preview:WANACRY!.....8.Q.SI .2....I..U..Q..p&..B..FQR...-..y..XpF*d.jS....R.Vv.......j...4....-?..Z...........D...~_.|.y.....Rq.O..:...Xu...x..e.j3.......j.d#z..H..aX...]........X.Z..Q..m^...w....j.5...../...ct..T.ZS.`$.\@i.}d,2.V...{.>F..e..u.|.oM.._M..E...mw......h.........j.Z..%F....6...8..D......X....o.W...UK).0 A....[2.~>!g.&.&....[~:.H..%.'.R..Cr....V....D."L.W_E.T.......p......r....=.P`<Ux..p.{.!5}.-.K.`....V.iT0...uv}..c.a..<.p....q...X.q.Ym....NI..T.g.L_..V.l.v./.....w2C...C.]F..}.\Sx.=;uX.|.eB/...y.W$......t-.?a.#=.5...Q.\]#.-..J...0.R...I.=...U.M>2...z...Z^..w..~..`_s..x...B.}<<..kp..M6...D(T@\....8.nwK@IC!.i)....xA.^..5....*h%.S^S....R..|........w.....;)...'..e..-.....<..i..b....o..).......d.6.'T...5...@l..9.U.....aJ}Uv]...U.....H....*.&5..'.W.I.C.a..Y..@m..Y..]...#....f.<&xG..l...*w...5`...u.$G.PP..f0^...U...p_...v.....{#.W1Aq0_|.eFE..p.w...l.&.r....V..q|..H.d.$..v+....a........p...?.n:.Vb)9"..;...9p.Z...+lEG.@Y=....d
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):443032
                                                      Entropy (8bit):7.999575522797635
                                                      Encrypted:true
                                                      SSDEEP:12288:W4todlrVoxG3vpQn5+WITaPCmRr0NSqTLtOnBlbGZKOHdoU8:DQrVKWGfIhjNSnBU8MWU8
                                                      MD5:3C76EC9FDA2DE3AF357B714D966BB6A7
                                                      SHA1:F219C36EF007AFA3C6E945481E9B3435FE92969F
                                                      SHA-256:5E96422589F1F1AC8395128A00B3D741B00F8EBDA72C2AE16FEEFE218A5EC7E6
                                                      SHA-512:980BC472187E82E4EC28B963DCEDDF2AF2E2BD4C6441FE6825DBF5DBAB8A495BE994D549B7DED7728D607C5CA9EB29105F0F43EB25319AE36405BF4EFEF8C838
                                                      Malicious:true
                                                      Preview:WANACRY!.....^.....{...qSt.".lt....d\.|..?.Ld..V5.. .`W*...F.a>L2..J.g..~..1.z.H.d......7*.p(F3..P..iF.].?...]...&.c.......O..~...%..4g..v....9:W...U....R....N+..bT.].._.e....}..J.............v......*..^.q...r./..{.......).Gj..3.(8.[..H/..5XC..y.L.%K.}6.......y.........&h..m.G...cH.7jn...../.35.y..N#Cg..{r..R..2.;'.6..5(Y4..:!..W;b0d. -......J?x.xR./..Kad)....W;!q.u~j.H......h..Se.zg....E..9.?]#'......9$.T{h.SY..]=...o....Y07p...8.0...q..G...7...#.#Ygm.h..#DE*r1.m...]c}....&.8.../.D..=.-0q.g..v.Z....a^5.B[.P.P......pj......M.+...q...s.>.Q......w.L...snI.mp..3....S...=Z.B......t/....{l........5K.9."..?...(.Ua:....B.J..r.......d....R......a.D....L.4^a....../G(+.Z...T.,)....^:2 ..b.n.lq.@..+.adq...=...#3c....w....em.e....@.5....`.\..,b.....>.....=S..G.k..I..)....#.3.Kn_-.F.Eq.@"..i..Z.|[.n......E.6,..K.........x3U..r1ed..'Y..,2./L...M........5%..t....`.T[o..R.{.........kf.....w.c.W.9..I.......J7.....}.j..d...C.E[.B.Je#S...E...k...q...V...h95.2.'.).3
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):11251992
                                                      Entropy (8bit):7.99998437313119
                                                      Encrypted:true
                                                      SSDEEP:196608:ZUKRA2yoOmH5YRCZOFjzXyAXjlgtxT1AN0xc5Yw5yy5ClRN/d:CKEoOO5Y4OFjjbXjlSxT1ANO8x0N/d
                                                      MD5:739802CBB9A2A1B276241F73170A5612
                                                      SHA1:4AC16E1E5B4F43D515A7019BA2ACC89CB9E3C95F
                                                      SHA-256:E69043A09BD703C92AE0CD30CDA4A80D911E5B82AB00D04D254F8D5748526AC6
                                                      SHA-512:F28054AB065B45EA3235A6BE6363EC93023B0BDA6A6E9BEBFFCA80820262920B1BE5CAB23AA927E4BC79A10CFBC91E8B3479558F1303A167198602761043CCC8
                                                      Malicious:true
                                                      Preview:WANACRY!....... .L\.*....i...B..j{X+.Lo.....n..... 9..Bt.S...1G.5....X.....21...ZM,.c.\....r.Rl.Ni3.\.1...>.*..!....@g..w.B...w.....".|..C.^.DK..4...$._~....e...{.+.b.!..+5..t....:4....2.......83.(0..FZA.q.t.x.....yV+BX.\....R...^.....Q..(PAG..-............g.1S.GS*I....W.ea..7.H"....ju sV`/.Iu=.....6RHo;.{..Gj'..RF.?...........65.v.ZZ1.....(...B..#L..E7D..Yr..E.9........q...\..Q.$..|..\..F...i.8...DbO/."E..^{.6..=.o.K..O...m....D9+.H.}......g...;.|X!h.A.3.X..$..A....{....#.N.w.....N......R../.;<.#!t...P......r.u.2...dKs....R...V..f+...?.o~D...%..;7y.1.........l......j........?7N.....;....*.6'...#O[...I...sZ.....s5.......'S.rjT..a[.....8...'/..0..F......../:m.u..K.Z. .gr.Yz..5.b*..+t.6....gs.........8.....r...V..}.[...../...z.e.`.9.q,1...EI4."...=...2....mN...'..3TZ..6.cV6-7.,..l.[.}..W.\o)....]T....\.6Ra.&P...NMB..o...f.P._.y.@.c...2....C...ek<{b.E..u.....C.......N..p.D.1.$...?.k.t. |.3Q.X..}.'..#.......8..Q3k..F^.%F41f.>?l6pv..hK0F.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1729112
                                                      Entropy (8bit):7.999891829361466
                                                      Encrypted:true
                                                      SSDEEP:24576:VZsNmvhmeBkmhSDKDfaLQl77EM7uGeJiU/YobXYvmhOVRykjpHeuuMo6M6U7B:rNhXrrEj9FgobXYvmAVR9jpHUMov6qB
                                                      MD5:C8DBA00C995E85152BB790D7BA3B28D6
                                                      SHA1:F0382C435EBB962C6C1F368F2B62ADAC2F146CE0
                                                      SHA-256:562F7835335144E764222E8F5D3B2A993E696E2A571576E2B45EE984C813F874
                                                      SHA-512:9E48A206304855192875997F91CDCE326B2DE55D92ED527E6D1F8BD11D84F3080C7B767A45536DE3193EA0FE962C803C631442489D5154B8456217EDB4CA51E6
                                                      Malicious:true
                                                      Preview:WANACRY!......}O........ ..3V$.*.a<..o..<.P.u.8.....-.... \...,Hb.B...P.[..Q... .h.8.V..k).w.B.4_.......2...{.yk.PS..M..n.4...k........z.X..+Efe.#.....F.DI...F..jI..fDl.s0.fUW.B............<..WC.0G.....V^._-..V..Kr.!R'.sRA......[.7b]w"\rbg.... i....?UZ....1a.......AbeT.3.._.L...._.=K...u....w.y7....^.>b...o%...a....{.[9..!9.........mNN.x..e.O....:rp..x....V..$..*.i.?..P......Lydw.,A...w@1.F.e ..o.T./2.Ao~[.yA..........:...........6..>....C...w'=3.O83X.O...... .$.k..t3..gU...9..q.S....<.H)..G.7RU.d#..a....U........$C....dYO..(S.Y......d]}m=.aQ]..Y....D...z6L./Q"....cp.q..F..)....!(.r... I.G..z+.g..B.k.C.G.Q...^..d...rw...o...mx.....i.IV:_.m(..Y.t.?..ik`b.$..9.,.O..-E>#vO.8-.m6.....Wj#..*Q....!.2.:..l.,..t..W|...S .s..^.....iHj......|.G.....g.[.L....Q.....u..!...4.S..h.d..v...g.....>.VM...*;./4[..].P.T`ww,.T.4K....qy..pg`...I...t.R.)".T.w.......P...@eF`..tr.9..2.C...eO...1..._N../3.m..s.>.~F.c...D..V^K..>.=.X...,;...[.r}...../<.!
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):130040
                                                      Entropy (8bit):7.998470657879962
                                                      Encrypted:true
                                                      SSDEEP:3072:r+lt6BAjUhZNCc7QNo7JcIldF5EFbDhBfck18KSgGNw1ZQrSmz:ri6BgOCcOhIeR11DHQTz
                                                      MD5:C54248B32B540B0E3B3ADC1BC9B9B890
                                                      SHA1:14F9B43E64E5433667390470E8649325C6A48F33
                                                      SHA-256:E395BAFC359C3BB0768565E26CD1719FC865AE5B40E51BDE25E40C2D2BB6DE0B
                                                      SHA-512:2A8D47FAE8CA4BC3532E02153E8D3CD89548DAB9FF242FC7D74F9438F2C72AEA8E876637BFBC924333D861C96401E3E2A5B228B7016BC92BCC9C3AFAB4C74C28
                                                      Malicious:true
                                                      Preview:WANACRY!.....L..BIr.-...E.O|.(.|7Y;.....}.L.$6._W...%..Jo...@.84.b.....+s......5..%h.=3..`..u.......^Bv..~...J....7.p....k.....E.<:....?...h.-.R...U.2.......ter.^.C:fDn..d....Q.....$p.P..MD..v6.h....dE\.DSb.T+U..Q\.h..4.....mq.L*..l(r.J.......X.U../.pM..............o<....o........X.O....E...].d.p^..cC.K...q\.B:d.F....1@.O......]R~n0.~...?z2....i. ....V2....22Z(>......$4.&.r*..p1....x.Q?&Y.,.\h..8...!}...''.....=...D.SD.M.+..n.......3..J/.n-..x..R.....h=u.........E..b.....O...K.Xb...vR..b..::...L...^..xCJ2..=....*.S..Sg.57_....Rif...x.&)UK....(..&.a.y.`...ro...P.F..sd.A..F..@.D].?....S..]...~ 1.mt..T...).....&..$j+#.....S.@).0<x.K/.^.......\(%./L..lLn......P..x...4Sv*..{=.;:.....DU....8yV.....t.y.9....Y....eH.r..X.(810o.?,[....:..L..Vf.2.P.:l..,..!RA`.]...1r... .9.TVI.dPp.(P..I_.o.k.O..!G_Y.........&.t.Xsy.~h.%........+.,.@....Y]...a. oRK.".l4...&".....Q......HI[..a,*u.00.E.......X.X.%......R....#"...J...<...$.^ p..q..v7.y.....t..w..c.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):44776
                                                      Entropy (8bit):7.9966851458277475
                                                      Encrypted:true
                                                      SSDEEP:768:DXy02NkTCP4q/+lCxNpxnQlsQUnFJrL5xbPFkmWDXKqn62Iv42B65Pixwneo:zp2XbSUNp1usvnDXfRgOq7Ej656w
                                                      MD5:B7D55DB004E645614A71455BA95419F2
                                                      SHA1:06F445412EEF63DF8D6EB5EFA3885162213CCACE
                                                      SHA-256:F729A7FCC1D3B605117E9EDC15AD1C20AA5C8F28D3A7D5734B0AAAC455254A67
                                                      SHA-512:13CFB6421F771E5EDD335CF6EF0463F7E46144A92D8006A1BD5B639D77221021D4F401239CC4278E26505F8939444492DE23D9F9677FB2F17CAD06822C3F3CE2
                                                      Malicious:true
                                                      Preview:WANACRY!......L..H....M.:.Y....[_...{.P._X"..W.:_t.......v8...g.Y....rw.+..J.w7..IXx...!.....f......'......!....s../.-]....4w.C._........_.N8........9j....\0.8..S.@.t.F4l...}..Z....F...$bd)r...z........MS.....;8"...S..`SIo_C..:.R.....SZ..v.r.......m-1J].)...........}...E...n...}.#...b...C...o{45..|.......I.^...|...v...8.{..*...{.......HE.ekvAg.....$.\.}Kz......X.....F?.Pb.._.......o[^.!.t.eg*.o..K1i:......._......%.F... ....[pW.s.{l .z6B!..fp....K..ZZ....SO0.-.....u.V.........C.x,......D...lU.RD..A_o.@...w:...'..9~\....-..y7...d+R.s.....*.....9!{....s.....r1J...jk.L[@.K.EH..1....X..&x..U....#...q.ch1.R.f:P=....A.k.b.W...8.;...J..=.5..8....k9.......6..Z......%.....N;........./.x.... I9S[....k.....!.7.E........[-.p@.I.I.]M?,....J[\F$S...*.>.L.K.EI.....8.M/.........J.o..J...z8..`8t.O..u..<!l..J...p.....0..T......SN#..E..........@..p...l.1Z....W..[.....~.2..+../.e..w5.o..s..E-.WC.....^.n..c@....=TOd..9..&.b...xL.4._...+..'.Q-..
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):29160
                                                      Entropy (8bit):7.993782261639286
                                                      Encrypted:true
                                                      SSDEEP:768:3nwdk9bxC47dqt9Ss8Mm07tdOue3loz8TWCp:3wdkpxy9Vk07Oue3loITW4
                                                      MD5:737D7C0ED80DDF2FFF0AB4BC2A57B83C
                                                      SHA1:2F32FCDA4D4CAE8BB82FBB4313627C9F264CC468
                                                      SHA-256:F926A44CC21A20185F80A819986310B13739DF27249DBAB4D7BADF0BDF20A781
                                                      SHA-512:0212A0C945AFF2D38EFEDFFB0AD88196B00A29F092AD5A580DC96596A83609012F07094CFED41D40D78F1C024CB29323EC8CE4F625104201CD3C38C607C52F67
                                                      Malicious:true
                                                      Preview:WANACRY!....'..).O..P........K..5.f_.Q..6.60Q....8.r.4.O&^.U....@...M'......d:....u(..*Rr...|rw\~...Y.....c"p...R..P..b..&..C.w&....(..7...^.tM...e%.Am76...i........8.7.../W;.`.E..-.q..,....F.g..Q....s..^sj . U;<B-.c....R.p.v..O..o....uE.qJ+...U.S..Z.....p.........?.....JS...........%}.E.Ph.../.3.4......2K........V..[..E.'.%S.J}.a.}uP.....%.#N...2.W\L...*c..Z...q....0..qq+..."..*.>.lL....*.."^...I.........F.r..5.....n....1'.$Z .q._.@..PZ....@o.6Gs...F.J...U.......c].....@.. v.P...k3.6i.j..W.!#R...Y...1..!.bW.6'..p..?Y...d.y_..X.:..#..y.L..JL....i....M..}..]~."}.+..V.[6).\.]..~.c..R..........(j...f...~.^.cV.BuC".Q.)..*<=Pt_1@.>..O.^.K`.'...hu:...<....#.R.~.f5..9..?7....c..o.S-<.T9.f...o....x..},&xP...F.*.....v...X.(.AC.~...q.rg1.....8euCSh...7...!Ob...ZI.q#....h|.~q...\............>..@..VrE.x....n.D....Z...z#.F.........1....._o...v>.8r..C...|.L...Ru.....M...bF.lR.x..s.^.....?t...$k..OU].....5....`...l7.Q...4|...qYrg..@v.9..K.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):39672
                                                      Entropy (8bit):7.9949721857810285
                                                      Encrypted:true
                                                      SSDEEP:768:TU+8glAGFMPVv1x7v8aB/WM3T7r5V6IHAxb9p9VpjRn:Tltu1xTPB/9T50xBjjRn
                                                      MD5:2810B6D5A64E94FB3F55E4C0CBA8239B
                                                      SHA1:E88BA135EB76FF1DFBF850B279543132A926AE00
                                                      SHA-256:A0F75A4B03A217E0AA7759BAD88251E24593BEB38C45DB7A74F9B2216C166348
                                                      SHA-512:1B18E2E12A8041CC13E7B4ECC45569222311E5B84544FEA6CF9CF56B9E226BD6BF5D7E40075EFA553ADFBCBB92A75E6F74A26EAB2873533B586EBA962A549D85
                                                      Malicious:true
                                                      Preview:WANACRY!....Y9.h.a..E:.5.N.5u.....3..C1P....s.\^h.@.t...g.8.].._h.......AI.YTgA.l..vS.:..a.u?R....8.xk.w)..{...7.ny}.V....U-..w.....a~..&/P`[..\..(2..6.{/......i..iKI....,..w....G.B..%.dvd.....kV.O.8..._.,..NQ.....;.F1...].5a....R.. ......A.D..U.N7..q.'.jd.J...............0...$......uB..#.D.g....!.q..&.|AX_.T}..*.....P,.[.....8].JrA...S.......2Pz......+..3X?.#.0..|...y.... ..1.o.........,R&....3.4...U.Cv..U.]...........!O*..G..$.O{....a.h..-e"|.!.....8...SE=.Z...FLQ...b~................F..\..e.....w$.c...M..#..1.Vv.W..psa..a&.....5n..../.n..No..L..m(.T~.'F..].......hNLi.v.Og..p..u.x.....;...."?......1....j!..4...'HuZLfI...<.%`,..;...x...L.@..X.. #...3..0....Yu.d..?..?...MF.x.!.X<G......7.Z.T.DS.".....4..X.=L...$..;..(...Y;..FO.Z.."}.O$..j.H...,.h..Q.90."F....y......{...A4.C'.I.u......."h#3..ejW.A.9.a.N.]......<~\...R.%.t\"...\...U...,.<.+.....H......*.e...C8....n<_q......$`.}.&.cq.Q...O.mn.e.%..$..3.....1b.hGzo>...nlQ.T..U.(....#.C8......LmD..
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):130040
                                                      Entropy (8bit):7.998560647169216
                                                      Encrypted:true
                                                      SSDEEP:3072:QuW+DmCPILTkEUSCKo6eucNsJpJbqfGH2r7lyb7fAHIftOk7R:hDm39sucNs7KGH2reOIft31
                                                      MD5:03DD865FC646C6307DBE462080C7DE94
                                                      SHA1:908BB0812804B81D2EA95B497622C2D37785FEFF
                                                      SHA-256:E9E8A549BDCDA7C8D7A096A7A0EC83E53D3CF24B13364AB7C702C529883ABC65
                                                      SHA-512:4831CA253D61C02D5FD37C28E7967D8A5144C13B2F9EEC9EA6D429A44FB66AB531DE0B7A4866CCD18FAEEE3EA0A37E22EC2901F3AA9418F4B623BC0B57F7BF45
                                                      Malicious:true
                                                      Preview:WANACRY!........Sj.....'..l..~@...........".Vb..;.\.|.$.:b.m....Z...1_.....E.p..........YS..O..\.."...J'{c..,.)..yT.)...p,9Y...9..-.....u?.-g-......3.........v.....I..T#;I.txo.yymYf....Nw......E.CIS..s=...M9VD.....l._.h.j.%.........:".,v-..cs..3.P..n..................s.Y.\'.....?F}.<..f.H.:...0..J....$.U...W.Jr...A?.g.$..ljC.X'.'..C.....@.G...y..H.%..7.A4.3..../T..R.......L..\..l.9...mf.....?.pD......{.VUk.!pf.8i>?/..P..x..c...S...HsrM..M..`....(.d.zsG......(...........Z...W9z.8.O..-...j..........".....2...T..P{..\|.v>-...ND.G.{...;Vh..)YD..U.. ...J. ..,..7.ON.Y...GUT.Y........L5S...............if...C........X.....}(..k..*...s...N..|Mn.b.{..w..T...8J..HZ.....6..8otb.02....|.......P....."cy...f0.a.6.lt.).j...@..).P.K"tN!.(*.T..J..U.g..L.6.....J.....vK..k......3.h+.>..j....c.m.No.9.~U^..K(.....q.......b:%..LY..}*]g.....U..Ml.Id.D..U.9GN.(..a}.....n....H....D........['.~...........;.......".......F.(.K..H.@....e...E....``.g.76.>...[.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):29160
                                                      Entropy (8bit):7.994108161183539
                                                      Encrypted:true
                                                      SSDEEP:384:+6vrUNskFDOAlUCp2AnohYjl4rx9XZY+bbhEIakzPFR7o4yb1lzNEmEN9D8Brudg:/r475lUOJyYj9+bb2CF+4aBd5uJTop
                                                      MD5:FCB776DA2C31466BE6E4A67CA9BCBEF9
                                                      SHA1:37BAA4677ACBAA48EE1277B720BB10C1BCC1538A
                                                      SHA-256:E4070CB2F0948748680C747A1BE6FA938665C5FFE61EAD7A059361523455E3FF
                                                      SHA-512:5EC39B96964637A9A93A138D3C0596D4F2CE3D90E7116A62D7C063B34D4DEEBB3A9ED79683FD6B0A934B8E4C456729CF5E0304BC5E2C937444FF4440A780B55E
                                                      Malicious:true
                                                      Preview:WANACRY!.....;....Dq....U..9s@.9..+.`.....(."._..K...`....U^.V....8z..RE......G..xQ...-..'.'/...v...4.k.dB.[...S..u .....<..Q.|.lK.....e,.D.&.".....t.,1/...3g.l..zM.w.I......pyqH.v.'.0..3..."..t..........Q./?4.a.......HVR.....C.0$..pL!..{..oqx>X.uS.veH.3.@......p........u,Z.....[\.4....-4.....>.u^>.&..y.......c].#j.R...S];......l.u.P....a9gR'....[..L..:z..s...../.........(..n.... ....'..#.f....y.P....JZ..}.$j.p.0i..M..w.o..Q..h............d.Y......t./u...~.U....3.8.....{...E|0.>..%....l<p...h....8.8.Rh.mnW.h..X....$..4.@b(.7:.n....Q...N5.]<.y;..Ti.....^....LCc`0..B..T>\$.....P.lA...`.a.@.S..~l._..Gw.oL.)....^...b,u......o.I....6..{.j.r...s...P...&e..Ye.p..|.=...a.l..L'.T.3F....~..+.)_GQhk..:zf*8.Y.\;..."..G.$.....,.....@.H.......ZU...*.U]lqF.z..Ni....\....e.u...$....h....<...dB8dN.J..9.".N,..'...(*=.7.o...7....oI.....dJ..n..g.|SI.\ M0...t.99...g..DA.\........u}.E...n.-.d.7b.GK2.u.t.,=.c..Z.m.`.....W.x....Z..u...,.{q...y.<i`....6._..-...:u.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:ASCII text, with CRLF line terminators
                                                      Category:dropped
                                                      Size (bytes):933
                                                      Entropy (8bit):4.710902136409594
                                                      Encrypted:false
                                                      SSDEEP:24:ptrPzDVR5Gi3OzGm0EigS1xbnS4RQhbrW8PNAi0eEprY+Ai75wRZcet:DZD36W3ChvWmMo+S
                                                      MD5:7E6B6DA7C61FCB66F3F30166871DEF5B
                                                      SHA1:00F699CF9BBC0308F6E101283ECA15A7C566D4F9
                                                      SHA-256:4A25D98C121BB3BD5B54E0B6A5348F7B09966BFFEEC30776E5A731813F05D49E
                                                      SHA-512:E5A56137F325904E0C7DE1D0DF38745F733652214F0CDB6EF173FA0743A334F95BED274DF79469E270C9208E6BDC2E6251EF0CDD81AF20FA1897929663E2C7D3
                                                      Malicious:false
                                                      Preview:Q: What's wrong with my files?....A: Ooops, your important files are encrypted. It means you will not be able to access them anymore until they are decrypted... If you follow our instructions, we guarantee that you can decrypt all your files quickly and safely!.. Let's start decrypting!....Q: What do I do?....A: First, you need to pay service fees for the decryption... Please send $300 worth of bitcoin to this bitcoin address: 13AM4VW2dhxYgXeQepoHkHSQuy6NgaEb94.... Next, please find an application file named "@WanaDecryptor@.exe". It is the decrypt software... Run and follow the instructions! (You may need to disable your antivirus for a while.).. ..Q: How can I trust?....A: Don't worry about decryption... We will decrypt your files surely because nobody will trust us if we cheat users... ....* If you need our assistance, send a message by clicking <Contact Us> on the decryptor window....
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Archive, ctime=Thu Jul 25 21:01:45 2024, mtime=Thu Jul 25 21:01:45 2024, atime=Fri May 12 05:22:56 2017, length=245760, window=hide
                                                      Category:dropped
                                                      Size (bytes):575
                                                      Entropy (8bit):5.140446565826782
                                                      Encrypted:false
                                                      SSDEEP:6:4xtQl3y03CpzeVs+bTNAUHUtxXCzaMmM7/gtrUod6tMljAlpdmqLEoJ4D6Vod6Nd:8iypzYNbd0thHZOgZUobjArozhmV
                                                      MD5:CCD2610ADD4080C4DCC35A11217DA6A6
                                                      SHA1:001ABA92D58B546C8BD54E0BC4103661F68CF92A
                                                      SHA-256:0E272CF58CC66E7B0CC4F42094232A46B6EC11AE5ED695BA4156A1A28DA41E6D
                                                      SHA-512:36DC5CE3027E8A77639783E31AC69C9FA61C4761FBEB9A819C1EB49F4A32BF2001C0441FB28D35C4EC9DD1B713576E7894DE8FD13BF14CE62A436F9619093DEC
                                                      Malicious:false
                                                      Preview:L..................F.... ....b{=.....b{=.....`.1.................................P.O. .:i.....+00.:...:..,.LB.)...A&...&........DDj....%.=....(..=......t.2......J.2 .@WANAD~1.EXE..X.......X7..X7...............................@.W.a.n.a.D.e.c.r.y.p.t.o.r.@...e.x.e.......X...............-.......W.............,p.....C:\Users\user\Desktop\@WanaDecryptor@.exe......\.@.W.a.n.a.D.e.c.r.y.p.t.o.r.@...e.x.e.`.......X.......216041...........hT..CrF.f4... .u.E._c...,...E...hT..CrF.f4... .u.E._c...,...E..E.......9...1SPS..mD..pH.H@..=x.....h....H.....K...YM...?................
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):106776
                                                      Entropy (8bit):7.9982191541957395
                                                      Encrypted:true
                                                      SSDEEP:3072:eZVq6H2Hf8rjg8ef99uOlUfOkpr7rl1TlG8nkhKPiXwtQG+:mq6Hc0rjUfG5BDTlJnkhuI
                                                      MD5:B4900A8F0A31CAE8CB8AAED143D5E24A
                                                      SHA1:1DC0290378AE55428C5F4CCFC7BD0CFF798C71D8
                                                      SHA-256:C3C436CCEDA4C17E0DEEF89C24ABAF358B601D036075D8407B553F47F99CDF94
                                                      SHA-512:116233220DADC61231B33209A81A3575DE641E59C6A3C6F4F5B05F623CE0D5443123F5CD8E282E25A81364949FAD8E263ED5D722903BF6D932441C8ADF2D563B
                                                      Malicious:true
                                                      Preview:WANACRY!....+~..U]B {r..Ysy...F...%.r...^u ;1......n.h{gH..&.|^A.L...oF.7F.u..`.q..w....&.9=.a._...c..W._a.U..k.).*I.x...Ac.K.&.|.....p)..U....7KQ.4...~..O....WG..Y....t...(..}1...n.ob.w..*S%.S..m,{H...$.CzL.^.4.gH...j...k.8I.......YZ...X5...g...eh=m.%.....<............8}*.....3..";....Z....3..W......Ev.]A.t.....t[....X.T.....H.....H=..F..!.3...p.;......<@.h.C.ynD.T._T.*......{=s@...u..\%..M...dI+....Y.$.9D(~).%...."...=MJ..9.J7.u.U..2_Rl.M3o1n...K.x...u~.>=&....pC....K...-^......g.z\D..K..".%..n..;.q ....h.qT.K-S.l~..v.o.N.lO.5h..5..._..E..l.|^..t,......$.{.G._..5...5..%<......W`.nt.g..3+*.[...........0..&...m+.p..;...y<.VHY^1..S..Pu..3...#..}D.|i.R>....d.~S:Ua..H...J.c.'.....S...U.AH..f....5K....<.q.P...........1..0...;........;.7.jj.../.3b...4.T'u)).......P..T1p/U...3.k.o....8..5.T(.6..)......3....<v....Aq.X..V..T...K..+.t....h..V...Z.....i.0..f._..YU..(.[....n.....X.|.EJ<...5....u-...Y.!..c.w..3i.^...N.7....K....f.......F.^....L..\
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:ASCII text, with CRLF line terminators
                                                      Category:dropped
                                                      Size (bytes):933
                                                      Entropy (8bit):4.710902136409594
                                                      Encrypted:false
                                                      SSDEEP:24:ptrPzDVR5Gi3OzGm0EigS1xbnS4RQhbrW8PNAi0eEprY+Ai75wRZcet:DZD36W3ChvWmMo+S
                                                      MD5:7E6B6DA7C61FCB66F3F30166871DEF5B
                                                      SHA1:00F699CF9BBC0308F6E101283ECA15A7C566D4F9
                                                      SHA-256:4A25D98C121BB3BD5B54E0B6A5348F7B09966BFFEEC30776E5A731813F05D49E
                                                      SHA-512:E5A56137F325904E0C7DE1D0DF38745F733652214F0CDB6EF173FA0743A334F95BED274DF79469E270C9208E6BDC2E6251EF0CDD81AF20FA1897929663E2C7D3
                                                      Malicious:false
                                                      Preview:Q: What's wrong with my files?....A: Ooops, your important files are encrypted. It means you will not be able to access them anymore until they are decrypted... If you follow our instructions, we guarantee that you can decrypt all your files quickly and safely!.. Let's start decrypting!....Q: What do I do?....A: First, you need to pay service fees for the decryption... Please send $300 worth of bitcoin to this bitcoin address: 13AM4VW2dhxYgXeQepoHkHSQuy6NgaEb94.... Next, please find an application file named "@WanaDecryptor@.exe". It is the decrypt software... Run and follow the instructions! (You may need to disable your antivirus for a while.).. ..Q: How can I trust?....A: Don't worry about decryption... We will decrypt your files surely because nobody will trust us if we cheat users... ....* If you need our assistance, send a message by clicking <Contact Us> on the decryptor window....
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Archive, ctime=Thu Jul 25 21:01:45 2024, mtime=Thu Jul 25 21:01:45 2024, atime=Fri May 12 05:22:56 2017, length=245760, window=hide
                                                      Category:dropped
                                                      Size (bytes):575
                                                      Entropy (8bit):5.140446565826782
                                                      Encrypted:false
                                                      SSDEEP:6:4xtQl3y03CpzeVs+bTNAUHUtxXCzaMmM7/gtrUod6tMljAlpdmqLEoJ4D6Vod6Nd:8iypzYNbd0thHZOgZUobjArozhmV
                                                      MD5:CCD2610ADD4080C4DCC35A11217DA6A6
                                                      SHA1:001ABA92D58B546C8BD54E0BC4103661F68CF92A
                                                      SHA-256:0E272CF58CC66E7B0CC4F42094232A46B6EC11AE5ED695BA4156A1A28DA41E6D
                                                      SHA-512:36DC5CE3027E8A77639783E31AC69C9FA61C4761FBEB9A819C1EB49F4A32BF2001C0441FB28D35C4EC9DD1B713576E7894DE8FD13BF14CE62A436F9619093DEC
                                                      Malicious:false
                                                      Preview:L..................F.... ....b{=.....b{=.....`.1.................................P.O. .:i.....+00.:...:..,.LB.)...A&...&........DDj....%.=....(..=......t.2......J.2 .@WANAD~1.EXE..X.......X7..X7...............................@.W.a.n.a.D.e.c.r.y.p.t.o.r.@...e.x.e.......X...............-.......W.............,p.....C:\Users\user\Desktop\@WanaDecryptor@.exe......\.@.W.a.n.a.D.e.c.r.y.p.t.o.r.@...e.x.e.`.......X.......216041...........hT..CrF.f4... .u.E._c...,...E...hT..CrF.f4... .u.E._c...,...E..E.......9...1SPS..mD..pH.H@..=x.....h....H.....K...YM...?................
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):33048
                                                      Entropy (8bit):7.994857521600233
                                                      Encrypted:true
                                                      SSDEEP:768:+YsefdnhtQwM2lym7G83MV5GrNVHnkbXndooKZ/VKEkKosjtLLx:lfx9Km7BMVAHkbnqdKEggv
                                                      MD5:05D489B888207890609ABB8D7CD091A0
                                                      SHA1:17D74B9CDBABE11EE34A96D3A07037FC81FA667E
                                                      SHA-256:37077C1A7DD1A6AAE857A3453515A140CF9712C2B99E29A6B4C4ECCA166771C2
                                                      SHA-512:462622240CA50F7CC0169F863476C9D817ED29C4DBCC2F3C468455912EF9E0073F603936084A56672BA2746544D94CAC6169F580C4091AB83364671CE2FFDFB1
                                                      Malicious:true
                                                      Preview:WANACRY!.....~r...FG.U.A..q]..JA..rd_>Wa.t...L,.HC..y/..*y%.[.H.k.0E...N....h..;.#q..b...........^......h....Si..q...E4k..KI....R)...L..Z......l....DW..]....8EqJ..L.."...{...`...14O.....%>..P...6.....UN....yn..<.......y...2+...m.f.P5...}.>...\B.6X.1M................./...||.o....Cn.1.!..G<.n...40M...5....9.S.A..L..,......AY)..i.%JE....lu3.{.t.=(....NV...Z.nW.L....7i.+.f?.X.7.x?.n.$....t.X..r....tJ..Q8,....U.,.x.OP.[..r/HG..)F-.@..9.^..b...,..........}.(..w.`A...g.o%g~"Gx....9..h....5.xU......L..$ey[....o.^cR..&1....B....|.9.er......-.....i....[...x..........X..'".D..`.~....Y.......GI.R.l.X.%.o3..f*.H.....#..l...N.:..o...N.......A..v?...v..;......h.d+]..4....'.s..E...V.......i.".I..#...?..i#...&`...k#..N.UQ..SBbOV.,...tYx.....X.6(...u...h!..l............B.._...S..Jvt....?....=..Xy,...!....JZ3{..9,)?%]....@.e@......gP...}.[...@..}hIwt&o}...)HWwN~....}?.'...\.O.SJ.N....>%.(.........b.Z ...xK..b`..#..s\@.e....q......N..`w.-.K.D
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):28952
                                                      Entropy (8bit):7.993022643687484
                                                      Encrypted:true
                                                      SSDEEP:768:qXxY7CMFKNhGfpRmpaPNXvz9ITEgN9kBNypvuoS:QCH0NhsRmpaPN2wd0vS
                                                      MD5:FB46D4952608ACFD42BCE90C9AC6F02D
                                                      SHA1:D63F8CA82498F4563E03A8AEFA0456937B72BC01
                                                      SHA-256:A52CE616D6E53D14D06A7483688AB9DA1F30046C130DE59F03FF8AB55A7A482B
                                                      SHA-512:D3C4EC55CBB2355FA076355D4F11157E3864F2B7CCB9E5A66D592DFCAD21C165E63839F4E551EF716378891412EF961E225296090BB4209C65080D25354F606F
                                                      Malicious:true
                                                      Preview:WANACRY!.....i......#..M....p$k....g.m%..'...../.[...zn.c[+b.aZ.+...;.Kg0Fs.....F.<?.-I.o...x.h(..{;{Z.r..\G.<..[i8.8-E.~H%.p..L..K;]A..6Z.....d.P|Y...:k.8.........MD....F...q.%...Gg.Z....lY......~h#.a....T.,.!.jK.,qi1....Y...fj.......l\../...E.... .1.........p.......c3B.....@.......<../q/.;........C.e%.5o.p.\...&....>.....m....U.:..+^*.M...%C6/R.e...cYV....A9-.Y.@.sn.+.C.$...fA?!.{.q..x........m..lUR...z.....ZC.<....G..Z...0..........GK....V.R/1......9.....#.]..o.\|.L.......=H.....;.....B].<a..J......<...%..o...r.l&.UI......J.......nv._&.?...3.'.....d..!.^.l.......#F....Db.*l....J.......]e.x.V.....F...+H.[......D )...I.....~).......W+../.L.y.{.F. .N..roC..oXa....b...[.c.M.......S..3r/.. .../.%.e..].........\..k8...?Y..j.....p.I.d?U..0.0++..P.s...Tp....m.t..\-...$...X2.3RPlvz..H.He.;..........@}</[....L..V.E....B...."..9.,...f#.~pD ....D\.`t~.6.....j.|9 .].g...J/./...2.....".n^.oPW.B.OG.Cv[.....9A....{..P....FM....|.U...i.S;...P...(.nt....2
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:ASCII text, with CRLF line terminators
                                                      Category:dropped
                                                      Size (bytes):933
                                                      Entropy (8bit):4.710902136409594
                                                      Encrypted:false
                                                      SSDEEP:24:ptrPzDVR5Gi3OzGm0EigS1xbnS4RQhbrW8PNAi0eEprY+Ai75wRZcet:DZD36W3ChvWmMo+S
                                                      MD5:7E6B6DA7C61FCB66F3F30166871DEF5B
                                                      SHA1:00F699CF9BBC0308F6E101283ECA15A7C566D4F9
                                                      SHA-256:4A25D98C121BB3BD5B54E0B6A5348F7B09966BFFEEC30776E5A731813F05D49E
                                                      SHA-512:E5A56137F325904E0C7DE1D0DF38745F733652214F0CDB6EF173FA0743A334F95BED274DF79469E270C9208E6BDC2E6251EF0CDD81AF20FA1897929663E2C7D3
                                                      Malicious:false
                                                      Preview:Q: What's wrong with my files?....A: Ooops, your important files are encrypted. It means you will not be able to access them anymore until they are decrypted... If you follow our instructions, we guarantee that you can decrypt all your files quickly and safely!.. Let's start decrypting!....Q: What do I do?....A: First, you need to pay service fees for the decryption... Please send $300 worth of bitcoin to this bitcoin address: 13AM4VW2dhxYgXeQepoHkHSQuy6NgaEb94.... Next, please find an application file named "@WanaDecryptor@.exe". It is the decrypt software... Run and follow the instructions! (You may need to disable your antivirus for a while.).. ..Q: How can I trust?....A: Don't worry about decryption... We will decrypt your files surely because nobody will trust us if we cheat users... ....* If you need our assistance, send a message by clicking <Contact Us> on the decryptor window....
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Archive, ctime=Thu Jul 25 21:01:45 2024, mtime=Thu Jul 25 21:01:45 2024, atime=Fri May 12 05:22:56 2017, length=245760, window=hide
                                                      Category:dropped
                                                      Size (bytes):575
                                                      Entropy (8bit):5.140446565826782
                                                      Encrypted:false
                                                      SSDEEP:6:4xtQl3y03CpzeVs+bTNAUHUtxXCzaMmM7/gtrUod6tMljAlpdmqLEoJ4D6Vod6Nd:8iypzYNbd0thHZOgZUobjArozhmV
                                                      MD5:CCD2610ADD4080C4DCC35A11217DA6A6
                                                      SHA1:001ABA92D58B546C8BD54E0BC4103661F68CF92A
                                                      SHA-256:0E272CF58CC66E7B0CC4F42094232A46B6EC11AE5ED695BA4156A1A28DA41E6D
                                                      SHA-512:36DC5CE3027E8A77639783E31AC69C9FA61C4761FBEB9A819C1EB49F4A32BF2001C0441FB28D35C4EC9DD1B713576E7894DE8FD13BF14CE62A436F9619093DEC
                                                      Malicious:false
                                                      Preview:L..................F.... ....b{=.....b{=.....`.1.................................P.O. .:i.....+00.:...:..,.LB.)...A&...&........DDj....%.=....(..=......t.2......J.2 .@WANAD~1.EXE..X.......X7..X7...............................@.W.a.n.a.D.e.c.r.y.p.t.o.r.@...e.x.e.......X...............-.......W.............,p.....C:\Users\user\Desktop\@WanaDecryptor@.exe......\.@.W.a.n.a.D.e.c.r.y.p.t.o.r.@...e.x.e.`.......X.......216041...........hT..CrF.f4... .u.E._c...,...E...hT..CrF.f4... .u.E._c...,...E..E.......9...1SPS..mD..pH.H@..=x.....h....H.....K...YM...?................
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1311000
                                                      Entropy (8bit):7.999858629455369
                                                      Encrypted:true
                                                      SSDEEP:24576:Ungm/scxoxE+4NtweTG+8n+77GamNC9woGPYraF2j6huOw:UngUsQeELzweT8n67GayoGgraF2o5w
                                                      MD5:A2A56A6340946EF5E757731923007A07
                                                      SHA1:4DA7B8909DFFC0650CC2107F436B8EC180633FB1
                                                      SHA-256:797F0EE1CE61EA23C10F7B570D467317B452A9C5151EBDDB638D079AD822305B
                                                      SHA-512:68AA17CEBE9FB27011F0B3C354D7F13188E3B6012F443A8EEFAFF3D98989392C9547222D6F63A3665271C62346792847236EC7306CE888EDA9842CDE0518C105
                                                      Malicious:true
                                                      Preview:WANACRY!.....F..?.t...GdV^:<..>.|.o...L.$.9m..c..W.(.G.v|.....a.S@6.e......e....c).j..V==...R...H.b.;......A=.&zf.]y../k.R..f.P(."`.?..6./.V.I.28...;....O...e..'PP..>cbE;5...K._..N.t.z..ab?.)..U.UK....3N.. ..U_..B.,...f.=S.....V.H.A....O@.4.b..K...?.i.c.R.nC)GZ....................|..b.T/..'.....#y....S.n..C=J[..f.B........J[..Ne..{..v.3...b...S.`\$U.d....\t.H.Al~..........:...&8zR!......$.....68xGS3.t.D.@{.Rb....^...._....Ha..x3g...N.N.....;...6/...g.."/.b.{.j....%..`...?.:.4HbU.o.e.pT......~..IT0S...2../O.uLN..h..h...f.....O.._+=E.(..M...E.!.`../...a..v...J].F.l...C...W..c.X.../g...(.l..j(...F.uAC].9..".o.....F..cT..G.. a.Z.a...{.H...^fw..^.S+l.......?_u.vQ+......n.5 ....^~.G...&"....c.z:T....t.^....u..._,=x....F.;H..)/'...N..y}.....M...2..R6e.t..EQ=..$..>..k.....-..._k.&..>.k....../Y.BYE....m@.-.\%..i...............}...w....}w......$..N.......H....2...S.el..Mq..4'.yZ.....E....S#..L..I........[ww....u....p..U.!'.....(..yk.i.l..q...m.'.-s?3-
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):16777496
                                                      Entropy (8bit):7.999990273562919
                                                      Encrypted:true
                                                      SSDEEP:393216:wQG8zagZ/7y4LuOPJ9rrS+oFF2HYqniHj+hwB4VtQPc2g6mJo:lG8zagJILpnYNMyyB4VePFg6mJo
                                                      MD5:E34227BB634E42F14178032C9AF6A1C3
                                                      SHA1:DDB00F807D863E61CD5FB9B7FBE79560B1417C9D
                                                      SHA-256:85B6C66B1E3C041CEDE2C48268514D9B319C662B63FF4BE37312D51AF9F75E16
                                                      SHA-512:8187F1F9A2412BCB366A7CEA7567AB4A7920713FF64640B89AAC6868D696F63FB95DBB551AA5D297A1B9B5CF7C40E4BDDA3E38223D5FB6C07137203FF2FA8F2A
                                                      Malicious:true
                                                      Preview:WANACRY!.....:.....1.....t....~4..K...^....T......y.....'.....%tb.....>....X...;....[.1.!S..8..... C.,..wC..N&.fF{V.8.>.4e...;...E".d.........n..)f.4g.. ............h.Q.X.G`9b.....\l.s.,k.E.."...W.ay..A...%....;....P..~....6.v...I*.v...3..^.5...~Q..Y.fH...................R7..r.?|a.x.......:_.2.CW;C.2`8.+..H....u1...f{sDM....p!.tj.M.Cj..T.5.:.....W.8.z...)lQ...f.r.*.2.)..y.C/G.....z.l>.5...A.^7X..vl.g..WuLy7^=..R....m.?.id.._v.(C....It?......l.P...A..].!.......FQ.T...OA6...T......I...[.R........<.|k......C.L..y..A..!....}(....?j..|.U.|..^.U...j6.....$i....a...\..<.j.s- ....h..[....hR..h4..=.G....=5.N.%O6.K....y;.;\A..'...l}.t....&<....^.q.wu.#....b.8$..."W\.....|b[.b..(.H.a..7.a.8~..3i.^..B.;{..r.;T.9z......7>.9..y.4...&......oT...^*.w.T..Ed...;f"hWq^..b#R..2...J....+...=J;O{..h$.+.6.CR...&....62.x...*...JDMx.AL......i9.... ..ra.^...Y.{...}.7.....cW'.z`N..{..p9.i...gF....=....`.8..jl......%..c....sq....Z..z!...]wex.s_.K..E.c#...p.2K.../.y.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):164120
                                                      Entropy (8bit):7.9989624371209125
                                                      Encrypted:true
                                                      SSDEEP:3072:2Hlts444uUTrSyVSXNilUIiq7al5j84d9LjWHLyvrq2slpahZI6foekEY:olu4rbTIdoal5j17jil6PkEY
                                                      MD5:A606E5EC82ADE10F48BF75AC712FEB93
                                                      SHA1:BF8E2BB2566C76301842D6B8EC835C08D3E52B3A
                                                      SHA-256:F4D3757E63AE227265669A5552739574FB91B1D0C0E06F0E207B56E2FAE2B986
                                                      SHA-512:21FF146D8F835346093F163600778C04F00FAC56B5DB105488C2DAE9C345703C62D7EAFFB42F5D0B10877D93F181D97B971FE5EB2921433C4CDA7367D4AF9D2A
                                                      Malicious:true
                                                      Preview:WANACRY!....kf!..FjM..^Ki.,.,H.S`.... ...y....ra...I...`f.~FO.p...}.6w......{.w.1CK....(.l*...R.........`h{..3.6.{....Y!\}.....Va..m.."A-..Y........~..3.m._...[../...c,J.)...-Cs@pd..7.p.*.Y.ROp..7..re......\D.-..y..8.....|.j......e..1..(...8...Y6..x^aF.............8r.g.N.m.sJ\....h\.....f..9.....{.!.s4.........Eo...B........M...z..JM..x.o...h........e7......x{M.a*q....i...:...e..^.p..n....o..H.X.w>.....oS7\.(...pe}.3.....T.u'..R..->..4...l....B.4.YBr5..?7x...&"P...CewH(....2/3=o.,Q.k...G.aA..w.g.=..t..v.......[.....h.2....V.....u...Y..N...K...W.r.N.>{<..bBg*q..SVxJs=..f#..X;I>.....W!.....#....u..m...^...>>.n.<...KE...n.......V.........We.'.?3........O..;...J'..q,.F....n.F..Ou..~I...I(.r..C~c....&..a.C..:<.4.4g..pKo..A+..p.u'...l.?..J.....8.f6..1mbuA.V.X...6..@.....:.Z#.U..AB*...u.....\....... [7..J..,..me.T..NHj=.m..]I.3.P^.m(*...2..."...s.;.9....A.....H.<A.h...(..v..+...H..........K...n.T.Z!g]..K.6....'q.3>.[9.Y=?...d......},-6!1*.=...D..
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:ASCII text, with CRLF line terminators
                                                      Category:dropped
                                                      Size (bytes):933
                                                      Entropy (8bit):4.710902136409594
                                                      Encrypted:false
                                                      SSDEEP:24:ptrPzDVR5Gi3OzGm0EigS1xbnS4RQhbrW8PNAi0eEprY+Ai75wRZcet:DZD36W3ChvWmMo+S
                                                      MD5:7E6B6DA7C61FCB66F3F30166871DEF5B
                                                      SHA1:00F699CF9BBC0308F6E101283ECA15A7C566D4F9
                                                      SHA-256:4A25D98C121BB3BD5B54E0B6A5348F7B09966BFFEEC30776E5A731813F05D49E
                                                      SHA-512:E5A56137F325904E0C7DE1D0DF38745F733652214F0CDB6EF173FA0743A334F95BED274DF79469E270C9208E6BDC2E6251EF0CDD81AF20FA1897929663E2C7D3
                                                      Malicious:false
                                                      Preview:Q: What's wrong with my files?....A: Ooops, your important files are encrypted. It means you will not be able to access them anymore until they are decrypted... If you follow our instructions, we guarantee that you can decrypt all your files quickly and safely!.. Let's start decrypting!....Q: What do I do?....A: First, you need to pay service fees for the decryption... Please send $300 worth of bitcoin to this bitcoin address: 13AM4VW2dhxYgXeQepoHkHSQuy6NgaEb94.... Next, please find an application file named "@WanaDecryptor@.exe". It is the decrypt software... Run and follow the instructions! (You may need to disable your antivirus for a while.).. ..Q: How can I trust?....A: Don't worry about decryption... We will decrypt your files surely because nobody will trust us if we cheat users... ....* If you need our assistance, send a message by clicking <Contact Us> on the decryptor window....
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Archive, ctime=Thu Jul 25 21:01:45 2024, mtime=Thu Jul 25 21:01:45 2024, atime=Fri May 12 05:22:56 2017, length=245760, window=hide
                                                      Category:dropped
                                                      Size (bytes):575
                                                      Entropy (8bit):5.140446565826782
                                                      Encrypted:false
                                                      SSDEEP:6:4xtQl3y03CpzeVs+bTNAUHUtxXCzaMmM7/gtrUod6tMljAlpdmqLEoJ4D6Vod6Nd:8iypzYNbd0thHZOgZUobjArozhmV
                                                      MD5:CCD2610ADD4080C4DCC35A11217DA6A6
                                                      SHA1:001ABA92D58B546C8BD54E0BC4103661F68CF92A
                                                      SHA-256:0E272CF58CC66E7B0CC4F42094232A46B6EC11AE5ED695BA4156A1A28DA41E6D
                                                      SHA-512:36DC5CE3027E8A77639783E31AC69C9FA61C4761FBEB9A819C1EB49F4A32BF2001C0441FB28D35C4EC9DD1B713576E7894DE8FD13BF14CE62A436F9619093DEC
                                                      Malicious:false
                                                      Preview:L..................F.... ....b{=.....b{=.....`.1.................................P.O. .:i.....+00.:...:..,.LB.)...A&...&........DDj....%.=....(..=......t.2......J.2 .@WANAD~1.EXE..X.......X7..X7...............................@.W.a.n.a.D.e.c.r.y.p.t.o.r.@...e.x.e.......X...............-.......W.............,p.....C:\Users\user\Desktop\@WanaDecryptor@.exe......\.@.W.a.n.a.D.e.c.r.y.p.t.o.r.@...e.x.e.`.......X.......216041...........hT..CrF.f4... .u.E._c...,...E...hT..CrF.f4... .u.E._c...,...E..E.......9...1SPS..mD..pH.H@..=x.....h....H.....K...YM...?................
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):196888
                                                      Entropy (8bit):7.9990989807582595
                                                      Encrypted:true
                                                      SSDEEP:6144:ODGjgzOiJsyUowSLWbSfyHM0xD+CKJ9j8er:djgCf/2yjxedr
                                                      MD5:288E26C9EF4AE14990B23F6AA82E7B50
                                                      SHA1:3BDE99EF5EACACA340558709B8A059CA841C274B
                                                      SHA-256:FC821DFD7AA10383DF097ED29F2D6EED67EEF5F3E8A9FEB31C9EBDE28D089FBF
                                                      SHA-512:669112EAAF7DBED7EB603B5A983C82E1581455E9FE268A8D6485592067701D8FABED82CC8594063A964FDE28A96EC9BD008F60E936AFD5E8A78A6E40696456F0
                                                      Malicious:true
                                                      Preview:WANACRY!...... .V..%.....~..h....q.......c4q6V.6...m....9.^..c9f....BweJK.ti.K.e..~+J.[3.;...Q.:.;...4..HA.7..........8.x.g.}.kd...V.g...8...4..H..1/.s.J.:q.I.......B26w*..4..yi.#!{..QeEa.....Q.k..Z....#h;..j.-...iz{...K....Y..T.*.V~m....O+5..-.*?,$.[".V..............}K<..B>y[....._|...qV..yX...Fz^P..w.G@....W..!...7.....s.@.X.g).4B..':\...3......_I..]O..m....`...a.....l.. v..p'F:!q.iUiQCg........;.......3...^.a.M$....)..W.......'.-.....+T>n.......!.S..A.....b.|..=;v.).`m....!..h]S..S?e..J..."h.o..=3..g......f)..C....=...4;.|w&].&..8.:....I..M..8.&!..Fk/X..-.~u.2....h......G...e.vy)'.J....../7....5H1=J.....!.^..;..V.R.s..%.%.bF|i.~.......>!/y..Fs.x.*...4.X....c.FI.....x.uY.......H.+.K.;..0....C.,......v.....-"...........}q........C....#W.ozv.'.B....%L..Y_..16.././...k.......ef.DQ..62B.aaXNGz...{.;.J4..:q..=...`..urs.`.....}.z*1......|...aV..=..bU.9....?..Uf4.x.X.r.z*.TSqNX..c{. ...h&C.v............[.b25r.M,({...66}.j....+.D..q<....A.D..'.^W.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:ASCII text, with CRLF line terminators
                                                      Category:dropped
                                                      Size (bytes):933
                                                      Entropy (8bit):4.710902136409594
                                                      Encrypted:false
                                                      SSDEEP:24:ptrPzDVR5Gi3OzGm0EigS1xbnS4RQhbrW8PNAi0eEprY+Ai75wRZcet:DZD36W3ChvWmMo+S
                                                      MD5:7E6B6DA7C61FCB66F3F30166871DEF5B
                                                      SHA1:00F699CF9BBC0308F6E101283ECA15A7C566D4F9
                                                      SHA-256:4A25D98C121BB3BD5B54E0B6A5348F7B09966BFFEEC30776E5A731813F05D49E
                                                      SHA-512:E5A56137F325904E0C7DE1D0DF38745F733652214F0CDB6EF173FA0743A334F95BED274DF79469E270C9208E6BDC2E6251EF0CDD81AF20FA1897929663E2C7D3
                                                      Malicious:false
                                                      Preview:Q: What's wrong with my files?....A: Ooops, your important files are encrypted. It means you will not be able to access them anymore until they are decrypted... If you follow our instructions, we guarantee that you can decrypt all your files quickly and safely!.. Let's start decrypting!....Q: What do I do?....A: First, you need to pay service fees for the decryption... Please send $300 worth of bitcoin to this bitcoin address: 13AM4VW2dhxYgXeQepoHkHSQuy6NgaEb94.... Next, please find an application file named "@WanaDecryptor@.exe". It is the decrypt software... Run and follow the instructions! (You may need to disable your antivirus for a while.).. ..Q: How can I trust?....A: Don't worry about decryption... We will decrypt your files surely because nobody will trust us if we cheat users... ....* If you need our assistance, send a message by clicking <Contact Us> on the decryptor window....
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Archive, ctime=Thu Jul 25 21:01:45 2024, mtime=Thu Jul 25 21:01:45 2024, atime=Fri May 12 05:22:56 2017, length=245760, window=hide
                                                      Category:dropped
                                                      Size (bytes):575
                                                      Entropy (8bit):5.140446565826782
                                                      Encrypted:false
                                                      SSDEEP:6:4xtQl3y03CpzeVs+bTNAUHUtxXCzaMmM7/gtrUod6tMljAlpdmqLEoJ4D6Vod6Nd:8iypzYNbd0thHZOgZUobjArozhmV
                                                      MD5:CCD2610ADD4080C4DCC35A11217DA6A6
                                                      SHA1:001ABA92D58B546C8BD54E0BC4103661F68CF92A
                                                      SHA-256:0E272CF58CC66E7B0CC4F42094232A46B6EC11AE5ED695BA4156A1A28DA41E6D
                                                      SHA-512:36DC5CE3027E8A77639783E31AC69C9FA61C4761FBEB9A819C1EB49F4A32BF2001C0441FB28D35C4EC9DD1B713576E7894DE8FD13BF14CE62A436F9619093DEC
                                                      Malicious:false
                                                      Preview:L..................F.... ....b{=.....b{=.....`.1.................................P.O. .:i.....+00.:...:..,.LB.)...A&...&........DDj....%.=....(..=......t.2......J.2 .@WANAD~1.EXE..X.......X7..X7...............................@.W.a.n.a.D.e.c.r.y.p.t.o.r.@...e.x.e.......X...............-.......W.............,p.....C:\Users\user\Desktop\@WanaDecryptor@.exe......\.@.W.a.n.a.D.e.c.r.y.p.t.o.r.@...e.x.e.`.......X.......216041...........hT..CrF.f4... .u.E._c...,...E...hT..CrF.f4... .u.E._c...,...E..E.......9...1SPS..mD..pH.H@..=x.....h....H.....K...YM...?................
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:ASCII text, with CRLF line terminators
                                                      Category:dropped
                                                      Size (bytes):933
                                                      Entropy (8bit):4.710902136409594
                                                      Encrypted:false
                                                      SSDEEP:24:ptrPzDVR5Gi3OzGm0EigS1xbnS4RQhbrW8PNAi0eEprY+Ai75wRZcet:DZD36W3ChvWmMo+S
                                                      MD5:7E6B6DA7C61FCB66F3F30166871DEF5B
                                                      SHA1:00F699CF9BBC0308F6E101283ECA15A7C566D4F9
                                                      SHA-256:4A25D98C121BB3BD5B54E0B6A5348F7B09966BFFEEC30776E5A731813F05D49E
                                                      SHA-512:E5A56137F325904E0C7DE1D0DF38745F733652214F0CDB6EF173FA0743A334F95BED274DF79469E270C9208E6BDC2E6251EF0CDD81AF20FA1897929663E2C7D3
                                                      Malicious:false
                                                      Preview:Q: What's wrong with my files?....A: Ooops, your important files are encrypted. It means you will not be able to access them anymore until they are decrypted... If you follow our instructions, we guarantee that you can decrypt all your files quickly and safely!.. Let's start decrypting!....Q: What do I do?....A: First, you need to pay service fees for the decryption... Please send $300 worth of bitcoin to this bitcoin address: 13AM4VW2dhxYgXeQepoHkHSQuy6NgaEb94.... Next, please find an application file named "@WanaDecryptor@.exe". It is the decrypt software... Run and follow the instructions! (You may need to disable your antivirus for a while.).. ..Q: How can I trust?....A: Don't worry about decryption... We will decrypt your files surely because nobody will trust us if we cheat users... ....* If you need our assistance, send a message by clicking <Contact Us> on the decryptor window....
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Archive, ctime=Thu Jul 25 21:01:45 2024, mtime=Thu Jul 25 21:01:45 2024, atime=Fri May 12 05:22:56 2017, length=245760, window=hide
                                                      Category:dropped
                                                      Size (bytes):575
                                                      Entropy (8bit):5.140446565826782
                                                      Encrypted:false
                                                      SSDEEP:6:4xtQl3y03CpzeVs+bTNAUHUtxXCzaMmM7/gtrUod6tMljAlpdmqLEoJ4D6Vod6Nd:8iypzYNbd0thHZOgZUobjArozhmV
                                                      MD5:CCD2610ADD4080C4DCC35A11217DA6A6
                                                      SHA1:001ABA92D58B546C8BD54E0BC4103661F68CF92A
                                                      SHA-256:0E272CF58CC66E7B0CC4F42094232A46B6EC11AE5ED695BA4156A1A28DA41E6D
                                                      SHA-512:36DC5CE3027E8A77639783E31AC69C9FA61C4761FBEB9A819C1EB49F4A32BF2001C0441FB28D35C4EC9DD1B713576E7894DE8FD13BF14CE62A436F9619093DEC
                                                      Malicious:false
                                                      Preview:L..................F.... ....b{=.....b{=.....`.1.................................P.O. .:i.....+00.:...:..,.LB.)...A&...&........DDj....%.=....(..=......t.2......J.2 .@WANAD~1.EXE..X.......X7..X7...............................@.W.a.n.a.D.e.c.r.y.p.t.o.r.@...e.x.e.......X...............-.......W.............,p.....C:\Users\user\Desktop\@WanaDecryptor@.exe......\.@.W.a.n.a.D.e.c.r.y.p.t.o.r.@...e.x.e.`.......X.......216041...........hT..CrF.f4... .u.E._c...,...E...hT..CrF.f4... .u.E._c...,...E..E.......9...1SPS..mD..pH.H@..=x.....h....H.....K...YM...?................
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):602456
                                                      Entropy (8bit):7.999684727513518
                                                      Encrypted:true
                                                      SSDEEP:12288:UhlcRCPMB7Ag/PhcAypmDq0A1Q9AZrOn0R3xYBTiPKNl2qs:iGR7RRp1DUUQ+0jKNw
                                                      MD5:784946D552F995399F2E3F6F8A836CE5
                                                      SHA1:5B8B8D7EEE5AF3501206F66B18C5FB6115D2191F
                                                      SHA-256:95ECD92A7DAE0B868777072D0CB5FE93999A6967C257ADC5F2F6DD669F9217C3
                                                      SHA-512:C46C933AB88CB7D125275F5A6184B6630DF91700E703EC2A1DC626FF805F5D8F5FD12EFCB72DAE9DAB60224C78CB0D26128C70F51B219A5403EA5A6D4A5AF2A6
                                                      Malicious:true
                                                      Preview:WANACRY!....q|.qn...#K@....5..:l.1.XGYO...#.(].9....X=R,.avWS.Q.{1.k.@:......_.G.{H.q...o{..+$....9...P1....z.c\.e.D..V.W./9..?...a.Lg.[AXq|.py<......Qn.SgS............l..X.9.........$....q.BH.. ...9.o.`.U..|@<.B.! ...........vS...Lb.......7..v......f..~6_....80.........c.G=.OQ.0..i.4Yk..&._*.q..a....u..J. ./.F...l,.P....k.g...U.> .C...AzY.....u.u(.3..$..q.B....d. )A..Y..g... ..m .......q...B..Uct.r. ..j....#.b...`...(s.K.m....X.yT}x....*../b*G..........T~E.Y.f...dLWL...h.^..L.!.....R..=..a.@.e...w.B.f.n.-g.?....[..( ..0....]N../we..*.-XY.\.T.m.\.E..5.#.d..;...../Wig..\...=..vvF.=.a. H..:.Q..p./Y..,.V.,.d.%....Q\=.=.V.>z.t..ar.......,..0.!ZW...k>....0.4.|.Gd..>.g..c.9.........{8X........u[....<Y.>....L.6*.AW...2.........@.49....^5:.O.\...G. ....4.?.WL..'.Y_..F......~$n..S...,g.J...]CY.-..@.....j.a...T.Q.'.....\....J.BL.YZ_..g.mp..%.*B......j.a...i.v..A.....o<H.S5..... ..nf..z..F_.'u..k.zm.....;z.L..=...dL......?.gN..6.au...b.."..la...z-.}3;.....
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):6344
                                                      Entropy (8bit):7.9710276044684765
                                                      Encrypted:false
                                                      SSDEEP:192:L0Z/JszbzlJ9IXtx9IBm+yKxRf409lv8GTi:L0ZBqzT2XQmHkRf/nTi
                                                      MD5:0E882DF9B42936DB567120AE3A8F0E40
                                                      SHA1:37B0B19906F89C1130A3E61C1D05D16B43BC8556
                                                      SHA-256:122FE537DE80B874EC33645EA748C2CF2239D2F49AF492481CA364A5706C017C
                                                      SHA-512:FA19828DBF66B5D486D041CB273E23663408B4254591B9A23F5D8FB37FF49A2B726F0748D570A2891FD043FAA9229A9CEAD1D3E32D4B891A80F7B6F671082C00
                                                      Malicious:false
                                                      Preview:WANACRY!..../E.".UIq..8.._3...+;....x71....9..|..D.I..._o16.d..s...r./..O.{.........}..Dz."... :.:8*"q{...c\u>3...K/....y.U...o8..l...].FY.N..p....^...bh%.Lc.S.....w..@.i.5,P..,B...B.g_..A....V.-G........rpW.VC...0.M,..u...].....%.(Ju......G:......[x...=..k...............3.t@!..N.R.kR..0.......z.....A7.NkSB....".FQ...-T^.$.m.;..%...d.I..Su.B.[.|4.5.W.......;.....p..{..."J+J.j/jd=.p...m.....+.Y@g.?X._.-.$...;...p.j.Q..8..[9.....>.h2..j%M%..B..o!1.e..U.C3$qVc.K..}.....?7.5X...ER....!...L..+.*....Pm.(?.......z.p.6..eLZ\K....IS..r........E\N...8..9...k1.T...d...]%.3..M....;-.:.*E.}D.vwL....r.BK.P.O..W...CW.^...{.*Q9..a....F.DG.Fv6..".<w....i...B/.:.qC..]b....n...&..r........lP......<....EPw:.@,...F=.xR.=.......T,.kfb..}...T.M.8....sK.x....b....~.]4.Pno.C..'.....R../?(...})Q.*q...(..._..PH....r.>Pm...fa.........mN$X..0.5y.hT..p.....Xj.x.;...3V..t.+[..4......*MS0..5...a..G.^T.#..H..+.VD... t..OiV].!..,...............M.!..a.x/..:....w. %.i..C.}T.M.l.?.W...(C..e(!
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):2680
                                                      Entropy (8bit):7.931803664115437
                                                      Encrypted:false
                                                      SSDEEP:48:bku+dDGZ89FEmOX45MLv3KoWLDvsw0MgtVpGD/sW+LDL4rp6LRzlrowCI+eSXNfh:o9dSqFEU5Mb3KoW/sAgTpGtGL4gdz9PS
                                                      MD5:CDEE27F0B4F02B4F55DFD679108CB3D4
                                                      SHA1:94EA664F0B87215EC3036F4B87F0CCBFA5565865
                                                      SHA-256:31F82683CFFFF8DCAC1E3D8F630AE21E9CEFC7F3D6B0223D7EA4BBBB946D5A6B
                                                      SHA-512:266E17BE3EFC4C3B8813CC4C6111C4DADF4406A4AE7E5F17AE6425C9775ABD85BF9CA25056653CC7B7898D8F68C053ED05C63175479CC63D77147B425211DCA7
                                                      Malicious:false
                                                      Preview:WANACRY!........3.m..!..yw......{.q.....Z..q..R...\..fJ...B.{.p..Rp...QPpC...&.h.....S9=&MA.9..8f.q.PY......n.~.3.U.....}...{e..a.\..........9#T1.L....e...z.M.../%=2P.3......W<...?...r....".j.|-....3u.U.Fg..X.;..:....Y.......V...(....X.3v.h..w...<O..Ko'..MF....X.........L@..\..A...n.b... .P..9.'..6....f)...i....g...Y.>h..6.....\".... .....!.@......3.PG....* ..z....+c.#..y...:..f.r...b]J...../R].b,.......!$h!...Q.g.:.......o.R.*.i..Y8..|.NG....`.w.m9hhR..(....r.Z.....;.{.J....:7-......t*....Ze...lN..{.xP.t3...@...g.kS....I....9D&%k....D....|.K.B.'Q.....j%^.fO*|....#...]....='so...H.Y8.d-I.r7..........K7.>.+5...0..W6....5.aol.....9.^.y..8.ox.h1)..2KR2........JA.I....w...]...;..^O...........2..............a.. ....Z.X......D..B........ZL.#-o.6!..D..l3../.;'."..9.........n.4..X..>...W.F_p.-.$[.D.peeUX....7rt.m.NA.Z..5D....=.D..j.3...S..#...#j6...=..!....(.0S.Y.3..bmN.P.....T.9..C0[6n.,G".Cz.{.(..4?._.`./C.....D...z..|.&.I..d....P......\!...c
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):602456
                                                      Entropy (8bit):7.999715674933676
                                                      Encrypted:true
                                                      SSDEEP:12288:7LyoZMYynLKnML4OdqRbczgWc0qcUPVC3rZGNH9NsjMV:7+oILKnM97sWcFnwNGNH9NAMV
                                                      MD5:1F1D939619590B8FE509D1CC8731B2C2
                                                      SHA1:F012745EEEFBF2605D5E9B4F7A62F6EF0D6F3352
                                                      SHA-256:3A9AAE4466DF0379772B0647F6C475455118693723D9D9D2D81917D25B931B08
                                                      SHA-512:18A1CCF620A1C3A85B632D12CA1A06F7370ADAB35E3ED1FC9F7BFC13A623F3444961E87A12D8536109F9C39D582043D28FE161989B7004F23E9022B5D6D14888
                                                      Malicious:true
                                                      Preview:WANACRY!....>..z.7...f>..2..5.c. ....0.......bC....Z..!.@...\..)z.!.%..._.LNV.z.a..J.....0.T]....S...E..).......d1..A......x....c....z..RU$.H+SS....T.z:..._.... ...w..$g.....AF...qJ.._..f)....3...."...Fh...v]...[+....$.~.P..{D.p*..T=.^U...]g..B...%.,c..`.....80........z...Q..P...w.....W.......y6c..;.....%...2T2.#.Zk..O....J.l........7."=.p......;.._...U...vnE.2r...m^....=.&......C.......I..W.."...|..$Gu....?..=.R......c.;e38.i...uq.U....B~.\[.i...H./K.F....a..[....X.c...fW......-..9.>....bvN.j.P..@.."...=:`z.B.M...P.......m......S..m5.z..p..........w..7.}...d...C.<.k.)4.Z....{.....Xm8......g../+....b.+OSt...1e*QQ]........'..8.x*_.i.(JC_...D>.......b.SB...6]~.Q..c.......&...t9v......?.|...:.Q.v....2.k.b.2..u.K.NSh..[g..B.q..D"\e..G..j.4'V...NH...vR\..@1.J....G..n...S*...H...g..k!.....r.zm.v.......ny..6I1B."U.-..n`.[5+.u.;M.q.\...h..1.@....%.....<j...Iq{..A..fs..d[V....89...:.!.3..j....`.u\.z.&....4z!....Vkf.0..e.!..v..)FP.;...L..}E.C
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):6344
                                                      Entropy (8bit):7.971318632490259
                                                      Encrypted:false
                                                      SSDEEP:192:mClf5MQhF9KdNDsQ2KcWlIBKgh+1z8sTAQ:rhxKNDsQcWQ+F8kR
                                                      MD5:DD9DE711CF214CCB101F4B57BE8C2CB2
                                                      SHA1:231EAACCC7A61D077D952C622958F3BF6441E8A5
                                                      SHA-256:2630744A18CA8F786725C0C5D22FDA6805274002EAB01EB944D426C26F1CC6DD
                                                      SHA-512:6105D6D949F82161DB3B7582C25A42D5C2BCF1F7F8B695FAA0A447A5F57ED32FEDDEF114C5A38FA15A839EE59566E55C9C28383BC5F4B7BD97632F7F85DE87C2
                                                      Malicious:false
                                                      Preview:WANACRY!....*O9..Kt.wCI|.....3............DI3Nn..Ha.8..:i..0......S..5.8.;.t...Qi..v./..z..?k.g.9.c...l..un.N..pEW..&..? .d.......tB..........H.6......c.......'.u.A=.'....X....}....<2\.,..`..R..W....j..W3K..t&.I......4sB'._...+..0..(.=b...".Ug.d.+.'..+.$E."a................D.'..X.H..]....!@..|H.m)4pSd.!............FO..#$..J.aV.ls.R`]..2..5.H..ZC....@...d...o....*.....w.d...;J....(.'....w.f.IR@".....:..3'H`_.....v.tu....&.kLO...)HH...QO.....y".Y._.;....$....&.+.j...CsL.o..^=Q....!..{....).f@.hn.d*..hu..&..7=.G!.?..V.?...v3.y.v.....3...zw<7..d.c..V..|....H'.......W....G..9..9M....=TX@.y.b....G.:...$ N......:I(..p..>6.T@..'..e.`.+t!.... M.f!.Q.2uHcv.R.,....... ..a..bJ.3..H.\.8....s....';.......`...8.)....q.J.../+p....e?..x....d.fPP].....?.7..7...~Zy......^.{.W...M.}=&.^k.g(.....s:%._....4.99....1...L..|.....G.~....n.ny.v.;.;.j....EVe.Q..~G..E....|!...#n2\..5f'...f..#8F.."c.Mz...-t..x...qK.L.z.y.T....F...4....V.I.x0.......r...&.M.Xj..^T..G1..q......
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):7000
                                                      Entropy (8bit):7.975809598813545
                                                      Encrypted:false
                                                      SSDEEP:96:o8TnjtRUE4GsjgHuBX17L76KB1xLLd9aPNtMcbE/Jmpa1JrU/aaRyFxad7PijMO2:ltqzGsj7jTv9aPgjmpabrUyaRyFoRW2
                                                      MD5:2390503901272BCD098B1668A97F9DF3
                                                      SHA1:DAA5E2579867FDF049E51E0FF034D2FFC0C782A2
                                                      SHA-256:11DB4D76A411A6F91787CAF397A97C559668C65FEC3A37F5A484E62271571C62
                                                      SHA-512:A17823CC62D65C200643FC1AC20EB1CDB176F1C3BADAD922FC813B55CE6FDC8087BADCA8477087825517450ABCA6BAAC1CE10C786525A7AF4DBF5C998B452C22
                                                      Malicious:false
                                                      Preview:WANACRY!......QO..a...V.,.a..v....y.G.....(..k.5....A.LY..-.+...5...I..;.$..RO...Fy..!:.....o..?[....,c...h.D.1.............Z...j.....b?.....Z.l.].......Z=...#..*.M.[.M...3.`..uRBa.R.I..v. P..."..?...r.i...0]...=f...M..*..G.Z....-..d.j..}v..pF...i.....7....=.......^>.b.u..-}L....7.w.t..@.F....I,v.7.k...DF...(.D5....;...|.;.J.my..|Hv.F.Y...@R..S..p....,yH5...W.....U.LZM3.f*Y$.=ca..UxY.....X..`...Y....'...H8 .I..;...S../.....%.w!......A.>..z%&.@...4r.7.H. VR.........W....i.U_.I.(.....>....9....ZxH}.n..,'..Sj.......a...D..l.p..uGq-j...V.b.sD.Q.,^.....{8..-@{...U\V...d...`...'0.d.....A/..n...>.4.L>.bQE]R8QP`...H......P.h]w.=m...L........E..^.M.E.#..K_..4JQ"..[}..v.:j....Pa.. .....aNA...J...4...EK....~...io......]\..l..T...q...2.n....v...+i.^C...G...AS...A.A.Gm*fO...i|6.6sVc.;.[a.yC.........o8=.......q"F.E6.xcy......~.zg.r./.".L.k......6.....]........M.n.l.U.d.....x.....NI.[.@.O6b...}.99..qw._..CPC..1....1..9....[...........#`]j......?&6....?U_..
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):7000
                                                      Entropy (8bit):7.968602010503263
                                                      Encrypted:false
                                                      SSDEEP:192:s3DcHyCGbKcH9ecBnENdaPzoSPMjTttTDodwyzGtzz:2D6EjH9RtYa8T7TD0Jm/
                                                      MD5:77ADC6FAEFC6F2441F9BDE28D1C04055
                                                      SHA1:4682710DFB49D092904D0E56DFE71CD36E7631BD
                                                      SHA-256:C10EED862C3AF8CAAB7AE0B176FE3411A33F3C0907BE34FF9B38E0E9E591462B
                                                      SHA-512:B5C84D06EAC395024505211EF12D0C4770589C692EAB10871B3735329776AF8D851C582E71C8AF41135F0097B2F84208A459C6B4A3D964F515F70C1BA4A90BE0
                                                      Malicious:false
                                                      Preview:WANACRY!.......y..X......\...4....[...'7a.4...z.~.q..xE.gp..Y0..$..1..Y}o.JS)/.....*....h.,B..IEmF...B..8.P..............'.GK-..|t...,...S.c:Y/0.#..>o.m9.=...9...#.{...J.0....5.0e#......}QF......U.#_.G.......,P.....L.4...`]..W.:]nr..&.(o.6Q.XA2s....].........=.................q...L.C..m*....v..Y..0.HO) .p....B...2R.]..@.wp.[i*.x/.(3@..-......|n...Q.0.......g..V........G".....i...(..d.k.C.S......@..g.h.\Y.2.q..y...?..h(G.V{.`P....pw..z.{..iO...?....X....upR.....y.....d.H..h...D....=..0.G...I..s..<0\...Y0..........O:EI..vH.K......._2..R.....H..$...z.<..U.".|a.5...}...........=J.FjB.\...k....Xe.......&....S.m.......&...%a..>.......J.'1........z.I.L.......A2T.....5....&..(e$....n..j..sW...d...Xlc.?.o..b..+FnH...`a....':....3e.\.KYm.ql.I..W^..H...{.V.)m..u..-..\..2...8.T{.....:..i..V...\F.)...Tj.d..x>7.0.Q..2.r..V.8..~.W.W..."YJ.4.j....oj....Q...;.9....0...K.....k>...a.g....U..YCD...K.mn......$.a.).d.|..6.|.C.2.4T^.I........i)......G..
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:ASCII text, with CRLF line terminators
                                                      Category:dropped
                                                      Size (bytes):933
                                                      Entropy (8bit):4.710902136409594
                                                      Encrypted:false
                                                      SSDEEP:24:ptrPzDVR5Gi3OzGm0EigS1xbnS4RQhbrW8PNAi0eEprY+Ai75wRZcet:DZD36W3ChvWmMo+S
                                                      MD5:7E6B6DA7C61FCB66F3F30166871DEF5B
                                                      SHA1:00F699CF9BBC0308F6E101283ECA15A7C566D4F9
                                                      SHA-256:4A25D98C121BB3BD5B54E0B6A5348F7B09966BFFEEC30776E5A731813F05D49E
                                                      SHA-512:E5A56137F325904E0C7DE1D0DF38745F733652214F0CDB6EF173FA0743A334F95BED274DF79469E270C9208E6BDC2E6251EF0CDD81AF20FA1897929663E2C7D3
                                                      Malicious:false
                                                      Preview:Q: What's wrong with my files?....A: Ooops, your important files are encrypted. It means you will not be able to access them anymore until they are decrypted... If you follow our instructions, we guarantee that you can decrypt all your files quickly and safely!.. Let's start decrypting!....Q: What do I do?....A: First, you need to pay service fees for the decryption... Please send $300 worth of bitcoin to this bitcoin address: 13AM4VW2dhxYgXeQepoHkHSQuy6NgaEb94.... Next, please find an application file named "@WanaDecryptor@.exe". It is the decrypt software... Run and follow the instructions! (You may need to disable your antivirus for a while.).. ..Q: How can I trust?....A: Don't worry about decryption... We will decrypt your files surely because nobody will trust us if we cheat users... ....* If you need our assistance, send a message by clicking <Contact Us> on the decryptor window....
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Archive, ctime=Thu Jul 25 21:01:45 2024, mtime=Thu Jul 25 21:01:45 2024, atime=Fri May 12 05:22:56 2017, length=245760, window=hide
                                                      Category:dropped
                                                      Size (bytes):575
                                                      Entropy (8bit):5.140446565826782
                                                      Encrypted:false
                                                      SSDEEP:6:4xtQl3y03CpzeVs+bTNAUHUtxXCzaMmM7/gtrUod6tMljAlpdmqLEoJ4D6Vod6Nd:8iypzYNbd0thHZOgZUobjArozhmV
                                                      MD5:CCD2610ADD4080C4DCC35A11217DA6A6
                                                      SHA1:001ABA92D58B546C8BD54E0BC4103661F68CF92A
                                                      SHA-256:0E272CF58CC66E7B0CC4F42094232A46B6EC11AE5ED695BA4156A1A28DA41E6D
                                                      SHA-512:36DC5CE3027E8A77639783E31AC69C9FA61C4761FBEB9A819C1EB49F4A32BF2001C0441FB28D35C4EC9DD1B713576E7894DE8FD13BF14CE62A436F9619093DEC
                                                      Malicious:false
                                                      Preview:L..................F.... ....b{=.....b{=.....`.1.................................P.O. .:i.....+00.:...:..,.LB.)...A&...&........DDj....%.=....(..=......t.2......J.2 .@WANAD~1.EXE..X.......X7..X7...............................@.W.a.n.a.D.e.c.r.y.p.t.o.r.@...e.x.e.......X...............-.......W.............,p.....C:\Users\user\Desktop\@WanaDecryptor@.exe......\.@.W.a.n.a.D.e.c.r.y.p.t.o.r.@...e.x.e.`.......X.......216041...........hT..CrF.f4... .u.E._c...,...E...hT..CrF.f4... .u.E._c...,...E..E.......9...1SPS..mD..pH.H@..=x.....h....H.....K...YM...?................
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1670040
                                                      Entropy (8bit):7.999891925869886
                                                      Encrypted:true
                                                      SSDEEP:24576:ovN+vUu7yIRupUxtGBb+TtGqi19PaHYCQ4qdB/o1UGAflSHoirtMwCpfE+mG6XFK:olem6xtL5GDY4CqIzmsr5DkOPFieTi
                                                      MD5:8C858F52286A266441B393E91789AF8C
                                                      SHA1:81B661D0D0020705EBF613D6D462FB8B06F06329
                                                      SHA-256:437D70FCAA97F43E4194D0048CC13666CA23BFB7B21D962A65C315ECB94094F6
                                                      SHA-512:5887C68EFF66BE488972D442390E0EC161C61949D16557823F1E0B2C5C3AC1603F5E576A658BE71175D82A3D6D84041B060914AA486A8B5358DE7ACEBDD46228
                                                      Malicious:true
                                                      Preview:WANACRY!......S.....f..B......K._ .*..........R%.Y1s...!..+..qRXa...Y.W..J..I../F.b...,T:......,-5l....\.5...|...#......#f.......@....2e...l...k5!....os.....E.v.*.K.Q..W...G..*...Zt.{..p....6..m:w.$Iq...7.*....&.f..I..G.$l1g...R.f..t.f......K..W#.p..%x....uz............U.B....r.T..hu.f....UE.t#.[z.".q..{>.....=oR..*....d8+t......w...a..#F.[..?...0G....x..V ......!.g..X.#.y.9f.;..<...K!w.q....D!....0d....h.1.Ru.j..a...2....j....\....24...2k..#....,..>..Z,.1...[8.J..#...Y...oa....vH?.....6..t..5..Do..}..u...M.G... $...m...2....=...)p.3X.........i. .&...c.4R.@F.2."..H..].].....c*?k..?..z.....O;.qr..NY0h.RH..A.......c....3........Q....Ai7v..b^.e.q....<......q..5].6.k.g.(...,....-.F.....{..._.X...LU|.MD...7.<ev7....H.......a.s.zm...M.m....:.#...NBc.u..9....Qa....7...X.`Z6..Q_.8a....).Q@..8..I..N_...7......@.;M...).......,..0.c.l...NY].....;..{..d....k.....q|....~/...:.8A-yu.A[_'.Y./........uB.C.u....J*.....R..`.........?...H...%...f(.P.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):475416
                                                      Entropy (8bit):7.9995962051874745
                                                      Encrypted:true
                                                      SSDEEP:12288:bLimg7vyz+jTG2zdm7sNyOPLg+4te3A+x313v2u:DxS3GWm7s9k+4Shl+u
                                                      MD5:FA513023A165A7C1837DA11E376E8137
                                                      SHA1:42D6CB6595C94273AEB0288C3EEE54B5DD3A9D02
                                                      SHA-256:59ED6681F3A4A8C928AEB32B830DE060C00317E8F8CE031ACB9350325D28F8AD
                                                      SHA-512:06B6EC0F49B4D83606EB7625D8C7256E543BD38AA856012787CABD757CEA9B21129E36693BE410815067C18452DD4D3926970B964F9D482FB8BC17AF186DB30E
                                                      Malicious:true
                                                      Preview:WANACRY!.....]r...>S.6...*.Y>.-...KC.[.Bp....,H'..4.....Qi1....X7.....+..n.4...`.....j..g.;.!p.Z.......Q..L.E..lQ|...\....in..T.1..?.l#.z...@..0-...f.&...v.O.9...n..NA(.....b.a.@x<~....0!.6^..v`....C........a..*...&......r........srn..x...j.)J.2..:.....{..q*.....@......6.?.!.d.^...C.[...".d.."z.L.G.]..KU..@..#.;U...+....D.......J.......r...wk....C...Tk[.sq....u...]v...0.].w.0(-6.."%...|k2...........c.2..4...^TI.~....B..'.z..........K..;.[.. ..y`.e.....p<..V....WZ#...*b.."].^.y/.....J.BS..q.....0@@........eU.VQ%.Qc..........^A.......PGL.T"..[....../.9_\t. ......J...e .+j*...e..w.P[..... ......[n<......2....j....Ms....K...6.5...-....,&..".XS...hA........3[.<.O$L....H\W.=.y.l..)............>V^...l!.?.w.. .y<,..J...Y...H.~m.r.U..R...^..K<^1NTb.+F..db.{.v.|..h.O....=P.).m.E...8..W..yX.S....w}D..L.!f..<.W..}...DO......q[.Z...Q..;.....r..o.&;...Y...G\..$...,.}.+96...6./NY.nF.1..F..S.(~$4........FsGF.-.<^.....E%..J1...z.[P..:.'p.U...@Z.*.N.A.Tj...
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):89816
                                                      Entropy (8bit):7.997885214375184
                                                      Encrypted:true
                                                      SSDEEP:1536:m30mzxW2dcNNdUloDlwcmlSGAa5eJTleTSgjPqjUTy5Ge+JKTxi/9IFtj/il4DEX:phR+lELZ2eJTleGgvTy5GeMt1ID/il9X
                                                      MD5:9DBA5CFD83AFCD83541AF046E2920CA0
                                                      SHA1:BD06D52D25CA45DB19F13E9B11B4683DE989645B
                                                      SHA-256:DE25C9DCDDAEDFF0B68BD1D9F239B58D226E12D55BDDCB0B5D42BB870B675A3C
                                                      SHA-512:2F696B633996EDFC37032FD78026DE4134C7891893EF0C046030C58A90D3CC0CE96D0643BBEEFE5533EE69F9071A24DB0CBC4ADC2CA9270DF9DEF13B1ACE6BBA
                                                      Malicious:true
                                                      Preview:WANACRY!....=X..]g..6.=..Z.AYn..*u.=[...0Z9..7g.F...t\0ds........H..qex2eu.B....T..a.5..!.-G..>.#v....X..2..D=..n......U...i\.%.Y....wk......,n.^...UTU.7?V.v.. .D.L.#.51...0b.(....E...,....b@...b.....T.RZ.i.l...~\.".s....e^`6X#LJa..2.%..$..F!...........].........W..E..So.-.{...n.c\..f...:..+....z".>.....#...W.....O..1...}.t.9 ..AIy...4;C.....5..:z.5h$.....4.L.J..h..\.3..9.M.O.07.W.M.Ce..?1. ..4...o..l>...Z:_..U...KL.H`...b..(..^...TP.!..Z...U..AA...p.......P}yu..h0..6nU..[n..D...d_}..|i.U..1...Y..u....wM.~{.`.0.'..e.r.L\X..........`"..X...=..W.t[T....X....@U...1tkz...%w5P.S~.Q...J...G...)...zc...c..5.9b...3.=9.U9...%.d..BG.............d&.~..k....S.}.3...;.R.Ak.O.".s..D/....w.......4..:<RN+..d...]!..5..I.@.+._.uW...w.c.......!..Ar4d..%.0XO.Rh/..kb......I$.&5.....,..=.|G.33........n.u.0q.t..?........4.Y.j..0...{....$.w...}.X.Ev.....yb.ww.K..<....@...{G...l.ua...>4...e..._.]....:7.x...vQ..l...O._O......kv..H....K.e'C.o.....l.kW`p........
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:ASCII text, with CRLF line terminators
                                                      Category:dropped
                                                      Size (bytes):933
                                                      Entropy (8bit):4.710902136409594
                                                      Encrypted:false
                                                      SSDEEP:24:ptrPzDVR5Gi3OzGm0EigS1xbnS4RQhbrW8PNAi0eEprY+Ai75wRZcet:DZD36W3ChvWmMo+S
                                                      MD5:7E6B6DA7C61FCB66F3F30166871DEF5B
                                                      SHA1:00F699CF9BBC0308F6E101283ECA15A7C566D4F9
                                                      SHA-256:4A25D98C121BB3BD5B54E0B6A5348F7B09966BFFEEC30776E5A731813F05D49E
                                                      SHA-512:E5A56137F325904E0C7DE1D0DF38745F733652214F0CDB6EF173FA0743A334F95BED274DF79469E270C9208E6BDC2E6251EF0CDD81AF20FA1897929663E2C7D3
                                                      Malicious:false
                                                      Preview:Q: What's wrong with my files?....A: Ooops, your important files are encrypted. It means you will not be able to access them anymore until they are decrypted... If you follow our instructions, we guarantee that you can decrypt all your files quickly and safely!.. Let's start decrypting!....Q: What do I do?....A: First, you need to pay service fees for the decryption... Please send $300 worth of bitcoin to this bitcoin address: 13AM4VW2dhxYgXeQepoHkHSQuy6NgaEb94.... Next, please find an application file named "@WanaDecryptor@.exe". It is the decrypt software... Run and follow the instructions! (You may need to disable your antivirus for a while.).. ..Q: How can I trust?....A: Don't worry about decryption... We will decrypt your files surely because nobody will trust us if we cheat users... ....* If you need our assistance, send a message by clicking <Contact Us> on the decryptor window....
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Archive, ctime=Thu Jul 25 21:01:45 2024, mtime=Thu Jul 25 21:01:45 2024, atime=Fri May 12 05:22:56 2017, length=245760, window=hide
                                                      Category:dropped
                                                      Size (bytes):575
                                                      Entropy (8bit):5.140446565826782
                                                      Encrypted:false
                                                      SSDEEP:6:4xtQl3y03CpzeVs+bTNAUHUtxXCzaMmM7/gtrUod6tMljAlpdmqLEoJ4D6Vod6Nd:8iypzYNbd0thHZOgZUobjArozhmV
                                                      MD5:CCD2610ADD4080C4DCC35A11217DA6A6
                                                      SHA1:001ABA92D58B546C8BD54E0BC4103661F68CF92A
                                                      SHA-256:0E272CF58CC66E7B0CC4F42094232A46B6EC11AE5ED695BA4156A1A28DA41E6D
                                                      SHA-512:36DC5CE3027E8A77639783E31AC69C9FA61C4761FBEB9A819C1EB49F4A32BF2001C0441FB28D35C4EC9DD1B713576E7894DE8FD13BF14CE62A436F9619093DEC
                                                      Malicious:false
                                                      Preview:L..................F.... ....b{=.....b{=.....`.1.................................P.O. .:i.....+00.:...:..,.LB.)...A&...&........DDj....%.=....(..=......t.2......J.2 .@WANAD~1.EXE..X.......X7..X7...............................@.W.a.n.a.D.e.c.r.y.p.t.o.r.@...e.x.e.......X...............-.......W.............,p.....C:\Users\user\Desktop\@WanaDecryptor@.exe......\.@.W.a.n.a.D.e.c.r.y.p.t.o.r.@...e.x.e.`.......X.......216041...........hT..CrF.f4... .u.E._c...,...E...hT..CrF.f4... .u.E._c...,...E..E.......9...1SPS..mD..pH.H@..=x.....h....H.....K...YM...?................
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):516712
                                                      Entropy (8bit):7.999619310769483
                                                      Encrypted:true
                                                      SSDEEP:12288:qJBfi67VuAmK61OxPqFZxaR9lDGtd2xbImH+gD:KfDJHEO5QZxMDDoksmHn
                                                      MD5:D8C14576714A6C69E2946226B0C9B62D
                                                      SHA1:2DC6A6CEAB8C7E40316000DD0C95E1C9EC7355C2
                                                      SHA-256:FC8CB4C1DFC795403B47719EA91CD38EB2593195AC69E12C979185DDAC281650
                                                      SHA-512:C6E7770492195C4178C02B81959DEF24CF9E2B3A755E9444D619246082D84A28F58121C0CDFD287AA86E5175C4C3632FB71D0F9846D28FF02475612AFA168B65
                                                      Malicious:true
                                                      Preview:WANACRY!.....u0f..BH9.`..hi[.y...\2Pe.....!..p...Y>.x-...&.o.Z;...X....W....W..8.....gv.....D....1...].N?.....I.......(.G....]p..}.r.*..*{......Y3.5.......z.|r..)..........d.....C...w..l..z.].#..<.x9z.V.4..6._O.._.W4.F..V6).V....Y.......`:o.......H.......qyB...=...)..Wk.....O..2;.i...v../.~.l.+-.<(Yd...<....D'N.....3...1x.......H .(.x.....p.......g..>.U0.z....P.b..).kHc..r.....O.OZ....-YY.Bd..qY..V7.....C....*rM....p[.M..*..z..'....8.|F.i.p...`...<...R:z-(5)....[s....J...<....M..z...*.i.F.-|.;..,:........._.lm..]....Y0enE3...z..>..-y&.u.=..W.zm.~..Fuy4.%..p.g.'...;.].o......3.........r.AI.T)..=(.3.rA.4.J.m-......~j.Z..%....j..cLg.l Ec6.b.Q....9.....ni.O.._G.g[*....U...oP....F.(k.v.7..M....Ww...g./..&..(...E.il[?....H.r.......j:.G.-....dL_..j..[..#...2fN|~R.Nd...~./r.U...{....^..G.....v......5..I..f.w.x..F.z...Q........q.M.-.",.eE.$.I.B....Kl...a..a...aJ.P.<.~....1....Zd(...3..p..."K....[...b..OL+.b*A..n9.:Y..p.jSC.m....`.U..~-
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:ASCII text, with CRLF line terminators
                                                      Category:dropped
                                                      Size (bytes):933
                                                      Entropy (8bit):4.710902136409594
                                                      Encrypted:false
                                                      SSDEEP:24:ptrPzDVR5Gi3OzGm0EigS1xbnS4RQhbrW8PNAi0eEprY+Ai75wRZcet:DZD36W3ChvWmMo+S
                                                      MD5:7E6B6DA7C61FCB66F3F30166871DEF5B
                                                      SHA1:00F699CF9BBC0308F6E101283ECA15A7C566D4F9
                                                      SHA-256:4A25D98C121BB3BD5B54E0B6A5348F7B09966BFFEEC30776E5A731813F05D49E
                                                      SHA-512:E5A56137F325904E0C7DE1D0DF38745F733652214F0CDB6EF173FA0743A334F95BED274DF79469E270C9208E6BDC2E6251EF0CDD81AF20FA1897929663E2C7D3
                                                      Malicious:false
                                                      Preview:Q: What's wrong with my files?....A: Ooops, your important files are encrypted. It means you will not be able to access them anymore until they are decrypted... If you follow our instructions, we guarantee that you can decrypt all your files quickly and safely!.. Let's start decrypting!....Q: What do I do?....A: First, you need to pay service fees for the decryption... Please send $300 worth of bitcoin to this bitcoin address: 13AM4VW2dhxYgXeQepoHkHSQuy6NgaEb94.... Next, please find an application file named "@WanaDecryptor@.exe". It is the decrypt software... Run and follow the instructions! (You may need to disable your antivirus for a while.).. ..Q: How can I trust?....A: Don't worry about decryption... We will decrypt your files surely because nobody will trust us if we cheat users... ....* If you need our assistance, send a message by clicking <Contact Us> on the decryptor window....
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Archive, ctime=Thu Jul 25 21:01:45 2024, mtime=Thu Jul 25 21:01:45 2024, atime=Fri May 12 05:22:56 2017, length=245760, window=hide
                                                      Category:dropped
                                                      Size (bytes):575
                                                      Entropy (8bit):5.140446565826782
                                                      Encrypted:false
                                                      SSDEEP:6:4xtQl3y03CpzeVs+bTNAUHUtxXCzaMmM7/gtrUod6tMljAlpdmqLEoJ4D6Vod6Nd:8iypzYNbd0thHZOgZUobjArozhmV
                                                      MD5:CCD2610ADD4080C4DCC35A11217DA6A6
                                                      SHA1:001ABA92D58B546C8BD54E0BC4103661F68CF92A
                                                      SHA-256:0E272CF58CC66E7B0CC4F42094232A46B6EC11AE5ED695BA4156A1A28DA41E6D
                                                      SHA-512:36DC5CE3027E8A77639783E31AC69C9FA61C4761FBEB9A819C1EB49F4A32BF2001C0441FB28D35C4EC9DD1B713576E7894DE8FD13BF14CE62A436F9619093DEC
                                                      Malicious:false
                                                      Preview:L..................F.... ....b{=.....b{=.....`.1.................................P.O. .:i.....+00.:...:..,.LB.)...A&...&........DDj....%.=....(..=......t.2......J.2 .@WANAD~1.EXE..X.......X7..X7...............................@.W.a.n.a.D.e.c.r.y.p.t.o.r.@...e.x.e.......X...............-.......W.............,p.....C:\Users\user\Desktop\@WanaDecryptor@.exe......\.@.W.a.n.a.D.e.c.r.y.p.t.o.r.@...e.x.e.`.......X.......216041...........hT..CrF.f4... .u.E._c...,...E...hT..CrF.f4... .u.E._c...,...E..E.......9...1SPS..mD..pH.H@..=x.....h....H.....K...YM...?................
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):16664
                                                      Entropy (8bit):7.987386273462885
                                                      Encrypted:false
                                                      SSDEEP:384:aV1TmGix+MoiR4XGaAGoi74xAcvzGhf9/kkSs:GSGixOXGaAJi74jwfVkk1
                                                      MD5:614040038A7C9E6E22CA3DFE6091619D
                                                      SHA1:4C00DC8A42CB82EE8754E5ECB6CC9918BAD1F9CA
                                                      SHA-256:829575DC41FA20988B87B9E49DAF79E433BC1181EBDEA20C253DA1DE472D21A0
                                                      SHA-512:4F3E9C7E8DA46141320B7F5C05039CE65A7B8C0BDF83ACDA9D6595AC23D44574102FD685E29623FB74D43C3BCDBB29364CC69CC56614095EEF0A7D227D705F69
                                                      Malicious:false
                                                      Preview:WANACRY!.....v......(.b...+.;.......Z.LIO....M.^.a".....(.wSW...1Wp..,fc...E!L......,b..b......=.*...+.]l.2..j\.Bb.oI.rTSF....~...2.i.b.nf..+.i.[J...n.xw7:.#`.,.~.Lx..g0.kC'+.n.%......=........i."....M"wF.w..6bm.c.....yBG"....I7...{.c\.L.....+m.q2)......@..........1..x.].uC...YBoH....X...j.A.).d...+........x..A...q;..n..a..PD2........~..z.#A{9.>....ACS6uR..j.l.O..b.y...Ju...X.a.'Di..lll...l.......{L.8.. ..+.......ZF.@.]q.)..;....z....w..-,..}....Kv+.....&..[..x...5..*..{..'4[....#..X..@.zm..k..p.HV2..e.|nij.xWB.t..m ...sQ'..9Q~..KF.U..d..'...U.DmO..x....y%.HnJa..Z..6...`n%x...C...A9d.p.A.j~....n7..h.=....X...Q...f|.........Q.8......l..J....e...X8..=....E..b.T-.|=@u..\=JT...3.p..)....8G.-..Mn..>...f...n%..&...t..+.....E..........#O._=..v`..._.._)T..5..p.^.h..$..*..v...T...*.. .Z.d=@.r..F/o.c......)t.."o .........C~a}Q...ac^.<{}>KO...~T..U.\...u.,..B.Y1m?..{..:.....p,*z(k.M.....c..S.....L.;.,....%...... 44...ww..=S.mP.........m
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1528
                                                      Entropy (8bit):7.870369991841538
                                                      Encrypted:false
                                                      SSDEEP:24:bkRh76zDHmkjnFojaEi1GvOVMv+DlytSD2Pa6aP3Y/mY6Rvl/4vJA3Yb1d10q8X:bkf6rF+UQvOVplHMa6a5vAvmobuqK
                                                      MD5:1CE95F5E31104272902EEAFBCD2221BC
                                                      SHA1:B382FE25530C6F1A890E8DAF03AFFD9C3D56FD78
                                                      SHA-256:32F96C1E90F45AA82C9A22EE64E7DE5A527ABA7143968A00B037A8B529C31C02
                                                      SHA-512:3E4FAEB77DC8AB05220F890A8B844E26D67F89924FF01610CBD0EB6C07077B0F5FB97AC4A0D0E218BB9ADCAD3C0C1162904E7779E667DCB5BDFBFC10048C51BA
                                                      Malicious:false
                                                      Preview:WANACRY!.....2O)...rv...4...6......v..e]-.....{....a...A.`....B.C+... ..F"l...c....._.C.Z....=q..>~*...2...1.w.w.oZ.[..r+..ob.^..T..._- ..@../..: z.?}.....U8..>.+.$..8+ ........$....+S9...*./)...2...r.TZT...o.j.nY...E].,.}lP[.3.m.u......R.....]P./RH..gR...............Z..{.J.]I.H.h.VJ.E..l.r... S...b".D..+..aF...].a>o.w>......*......w..\T."M.....[..&[....D}nZ.......<J.^....'......fk1...@.[h"=.*.Ad.K.......'.F.7k.z.Kd.(q....` Oe.<.t.uUb.Q.\......#)..E...U...bexJ.s}.......G|)F.z.....q.D.K...@_...q.f.62.^01.p.[Z~..R.u......)......:E.I.2...-....(..1L{2..N.I.r+...}A.-.....u..%\... ...).la...d.....{.]".9.b.....`>..5n!>%.qv...9TeCG...i...?....*...._*.-y...H&-U..<[S.uprh...?.@..%f.}.@m.e..e...`....A.jJ.U$....^.... .......:`.v#A.v#<%5.k..'xa.IJ[V.....n.j....U.!a...j...)U6/.9...e.>A..i"......8.._1..#.......-. .d.(..y...0..F.Sb.&..Z.X..zO...e.Ig}.lm..7.....X v.D.l.X.Cl_..#;...;..B...V=..{.5hv....T..(...vS..q].n}..?.9..n.P.LB....W.. U&].MWK..
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1528
                                                      Entropy (8bit):7.855706374526433
                                                      Encrypted:false
                                                      SSDEEP:24:bkbLbrciYk/cDppSuXJAIlg3dysIeM3DDf3rdaOVaK+lBHVpmOdhH9p7tVaOr7Bg:bkbLbHYNDeIDl2oewDDplaKABHLhH9JC
                                                      MD5:E8967FAE3A89960FEA78E56BE6E12966
                                                      SHA1:3177088CA4997E865FC3EB425706C0A73353B8E8
                                                      SHA-256:8A3A45DD077D66BC6F6F99C4063F103684E31962D9B37D89492560B6797D54BB
                                                      SHA-512:DE3A4D1A5C3486628DBCF73775DEF160B617E7D8A732BD38115AF3782AB002E25935EAC6F0835B0D995F3AEA566D2DE72ED190D1472F3CC853E6C0B3D673A89A
                                                      Malicious:false
                                                      Preview:WANACRY!....J..!.$....Q.......q...f..5.5.Dx....D+<}.].....5^..k7..\....N,..'..gH..BbB..G=V..k..A.7.t.d:........>.b..{...TxD.Z...G.%s:.M.>zn.XU&;....tV..Uw.$.@M.t}Jt..y{..1....'..]\.6..7Xt.....C).O..]..,.....~>.f...w.......M.06T..........s?H.T}.............I..?..\..6.&..W....]...R;.=..YM...r4.sO..FY.q.M..^..Z.....r.Mrv/KS...h.......k.6&.f=..^...-..7%....u..bx...nKK..P...x.......tf....-...x/......<.v............>.3^45..rS.........m?B..0.DJ...*K..W.....y.3Hmm.*....!.....|d%....^ae...=...x......c.-.J.Z..Q...XDvY?..,\..R.....;-.\(.Z..#..7.'..Y..^...}P o..6y......m."....9R.\..Q.4M.(S..Z.....1?x~`....E..p.....Y}.......:..!.OG....~nu..-..!..!.....`.[..%:..k.tJ......In."....W4fW."a..O...c....>..3...B._.$......S.......T.3g...(W.o.......z\U..V......c?...Nv.s..k^..R....j.,i.......6..]....L..o..e.kq...6.O..}....]......t..~A3;...x\d.....Q...h...,.8GM.G..!.H.x...\p.XT.$p.i..#~....%.A...j....M....H.;Z.xp.2....T+.zo3.F...l...Q....{X..v.%G.I.l
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1352
                                                      Entropy (8bit):7.855609052397016
                                                      Encrypted:false
                                                      SSDEEP:24:bkJVM21VeS8bzQC6Cdeokvnq9iJfkJm+J5gMhx0mJojmwiCA2ErJayfOsZdecVX:bkc24UiufkJPrbh3TmEcyfDPeQ
                                                      MD5:DC8F2C84BD2D784555A8A4FD12AEAB3A
                                                      SHA1:B6CCCD3D253DD09C9791AAB38F5524EF2F9497E4
                                                      SHA-256:ADA2569D818377876AE2168262A549138445AC58987C618861666F9225376B71
                                                      SHA-512:0780952FD11FD793AD9D5339F88A76B39B76613BD1BBB25BC7CE6828402666FD17369FB41E4CAD94F22737BCF1DC95C0A135CFBA7034DFB7340396F4E7CC0415
                                                      Malicious:false
                                                      Preview:WANACRY!....]D=..f.2..9Y.l.Yq.......)....#5.`.9....q...H...3.1 .Q9.~...V..i|....L&SL.....9k...p/].a..c.]..`R....%.!....M.3..._..B.y.8e......IK...l.. ....WL......D.q.j....}oi..Pm.].......wh=v...U.r...'.....=!Zm..+..3....|...B....wo=..-.Kk.G..pR.)kL2,........(..........gX....m......z&..-...Y.3s.$_G.|Q.%.7.=..pq..t...khup.....6....{.,......8./.....0id.B.)E...$..e.)..62....'W.8....J.V.........n9.Fv9.o-D.lOs....M.....C....Cn.9....?..>. <{S...y....\@..<)p..~.f"$...7......T...Im0....u...|......lB...X......j..a...h9.F.&...{u.,..I&).V.-....s.....S..Y1.....C.......#.K.._.v.j.*Z.T.s....>.W!...8.\.c.F....>L.....>Y.....[..V.C..c.......s.q..N9.I.s:..\.L..*..-.(..sp.u...... ......6h+U..*:.,h.t.w..&\...5T...OGO.-...9..5...:Z.Q.@...."..M.U..c]..b....=.....Ude.q..-.#z,.d>.{.....*.-.r'G..];J)W.6.h?G.0.G.....P.D..j...j..$M........F.....<P......Y.0...1..4.....s........f6.rHM+....!......#.X........F7.u...}).6.L.G.e.1T=.......y..............n.gb. ..e
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1352
                                                      Entropy (8bit):7.816941046366024
                                                      Encrypted:false
                                                      SSDEEP:24:bkR3JpJMGjbv8l0s54USqPMwJrfZnYAIQiMnqiVP8L/v5cT5c5BQhrY1d17Z+nbX:bkR9MGjbvhs5hSqxJdnYAqiVgHeNY1ZA
                                                      MD5:48DE2E9F278CD0727726A766C465E183
                                                      SHA1:A4C5A6557FC8669B48786077D2BD476CEDF72998
                                                      SHA-256:63A6481398883AEB6CE5FE516871013BEEAF682BAD6E699FBA9E9F5ED3297C17
                                                      SHA-512:A1DF8C6708C8461EC3ECB99CD6109866C2EE5E45FC284045CBE74FD9FB56F091E0DC38B2CDE9900FED67FAEF3DEF7BB04749738EB56CA6B32AA62E1F186CD74D
                                                      Malicious:false
                                                      Preview:WANACRY!....=....`.L..6D)b.&.#..X.].J..X...JcY....J.m..>q.y......4.s.s.v*. ..l..i.GO..8............K..A....v..7d$..Bp...J...o}.~.u.$.....WF..Q.....l..m...)....}.n...-..*-.UU.._E.{...Ay...].;..2m.w.....Jc.....a.p.W)....(..h..b.,.!b../.......3.$;/.(xr.L.....e....(.........7...7....M...<e.w.b3.f.b..k......&)..G...l50....3^.\p.<......v.qe`...a...hE.1....;R.....4T..I2.f...c.:...d.W\.:..xz.M.n.=...[8.`$.....^......$...[.....}+....:..A(..5..bn>\...r.....eh..0.V..^I.!.....k.\d@..(<.C../a..Y.P.op.d..EgE<s.d9k2..pN.a..NAZ.L3.}...i/i......*..tA <.u...eD\........vV..W....A..J.....c.p...=bRi.+...,.hn+....0.;f...H......b/.Vb.l|.e!..C...4:.~.w....W......|.7?...>..3......s.|]....K...|....F..]fD..9(.w..F..4.g.....D..t..U.X.'..kFh.....Y...o.CE......^u...[....{...A...$.pl..>f.~.0J.M9...\...U._(...>.U.v..j+..<....\...IF.|.../.oyc.F.e..?..;.h........vZ....;.>.fk.P..c......Wj(....I.j...+...1.8..wo..}f/.....2..U.M)f.....!.y..0j!.*......r...3.|..>:..!......
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):297144
                                                      Entropy (8bit):7.9993330446253434
                                                      Encrypted:true
                                                      SSDEEP:6144:Myuzbao6vjKIDEyCoNa5KUvVR0kIoHFd7M0BZ6c8lCGMh97Uq:MyuH36eIxCX50krM0D1087t
                                                      MD5:F6074D9B507FCCD00E4ABDAC3213C847
                                                      SHA1:2D6AA18EF25D6A9F2EC91405BAD6DE4BD9AFB666
                                                      SHA-256:7D1EF0D5306C2F868B7D149761F7D152ADF1AAC015543C3ED9694F6A9DAC5BBB
                                                      SHA-512:7B9D112904A218B71167890D9F2D4EC1554FFA17EA400BB344F286B1A337664D357C90C21979DFC33E9E808A13EDD8428FEEDF18C580BF840602F887680F17E3
                                                      Malicious:true
                                                      Preview:WANACRY!....$..6.....A....$.-.W...N.\...a]../..?..u;.).UV.JT.j.:).....F;.M."?...F.%*.0......1v.w...{e>..v..O.....pBGO(...x......l..;.6....Z;.g?zU"O...q......E..q.&..*up.r..C-.?..7#.JI....e.%,...;s.....p.!z?.M.r..a.$r.e..i.........S.fE.g{..9....)B.m.f..............t...j\e..|.....?.4......~....iR.?....m............|.!...|.M..#..~]4.J.F.....|.xV.G...81.(R".Yrn...<\..A.?.Nn8:3.......k.j~|*%..Nc&u..>...q..q..T..Y.8..!9L|CU..f..Z..=-lJ.....g..}j.Am..X...N2....G...Q.I3....N...M..lU..F....c...q.T.z.T2...X.......G...=../piI....=i...]Q..'iqf.}.I.......J..W......I....zB ....R......c......G...F~/s.r..f..........>....`gtA...y.d=]5_.......:..oB...P.b..`.&F[{.. ...)^q.H.$....;..3[..(.:. ..nj.-7..=....].P....%.......Q..J..l.I..I.(O,\w.f.0K_..hF...u\.V.^.....&/...k*.@.....8.5.. B......mkT..nu..|z.-..&.}f4...d.cq.. NLK.%..Gh..I.....~.SZS....^8Lk..g....Ob.j....\u.E1..#...........|.s2Q..%.g.v.P~..S.S..'"..X..R).-.^.....C.T.!...RGI.....zT...V...)...
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):297144
                                                      Entropy (8bit):7.999446027422421
                                                      Encrypted:true
                                                      SSDEEP:6144:fuLHFC+TIt+dUwclhv2cMME749nLfFFcyAMkxHtT5Owh5OX+1BPCara2:fqHU+UwdTcvHMMEQNnwHtoscX+DPC+a2
                                                      MD5:0D544595DEE417053A21E0B43C7D4D94
                                                      SHA1:5242A426FF2EB987AC05A50CA312FF4AAE1BBFEF
                                                      SHA-256:97BD9D3C6846E6257AA4733F30AE6E012B6567ADBD5842EAA05D87F141CAACA4
                                                      SHA-512:872A6B5A4DD39EF92B29C0AA0A9B79057DC0304FDE4A0D93B064EB84260462AF6BACEB914C5F5052C99F58EA51938B02F7ADB7C26C11FD6E4AAA98174894A7CD
                                                      Malicious:true
                                                      Preview:WANACRY!......L;.dl..(....A..?Eh.S.V.}.A.|.}.>........N.<...............x....A....wjBG..1..l..."O.Y@..R.>.M..u....9.......c#............A.%hS.%..6..8.B.[t,...B.#@.!{..UR...b2..x..I.@..B.=.E}.O...y.t..F..p...}.._..d..$k.~...E].*....A9.g..u...5.0g.>..'2...kHT:f.............a?...S\....g!..{.`.....j...w...K...b^....d+.@...).."r.7=..ZR....>....(....8E.!.....&..-.....:..Gq.0^..$...4.P~...q.lw..\V....=.....Cl/.Ag0.Vq..g.. ..u.*n<.E..............Q:.m.y.21........Th.S.T.E...o......[.n....a..-F.....f.?..:.:'.h,...H.K.j.......,..OD..9.V.|....t>'.F..b.T<...o.......U..xo.y+l..%.-".a...R.G8...e.>.....O..f..P./..O..'....2J..n...MuqIB.9@.V...0.....Z)..#......X...J....P...<.@.a...<\..l......3.:.k....I.......5.^..h..i(....._Yx.F.y..,E..r!t<...E.B.[.!!$...u...%...!.J..27F..C. jGR5z.zAgL.8B.t/~rs.q......;..MT\e4.D.|..V...........dg.H}..WN(._..J....ou..`C..]..IF...W.]..|....?^.?<X...0#....o*7...H......9....h....K>..!{3..F.|V..u*Sv.z..V.D.cU......#.j...<!#(%7x
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):297144
                                                      Entropy (8bit):7.999381848824213
                                                      Encrypted:true
                                                      SSDEEP:6144:a/sYxiejqj+Tn+c6Q3e72Q5K0PovZ9xbMhBhsIoqy0CETz7C:GsYxiKG+8Q3e6QDW9x43sIV55rC
                                                      MD5:CF3247350693A8E66739A61D616A8364
                                                      SHA1:349D06E5D43B22187179C5AF39E5301D94C99B7E
                                                      SHA-256:6255DD145260523EC245CAB4AF6BAD878B3CC76D6862C4E11833C05E53F7DD06
                                                      SHA-512:5B5CFE81EC967AED2A19443A1B99CE3696A62627D92ACE260987DFB27EA8683F30407051CCDA0A7712B64C1E7881BBA1E9F5DB38B51BFB151C4436403037E0D3
                                                      Malicious:true
                                                      Preview:WANACRY!....`.x.j'.C..$M....p....J.]..Y]".+.9f..2.......Q.m.>W.7..`..'.0...:e2...N.y..\t..r....+...$z..Q.%2g.".<..wN..K...I|5.L.j..Kzx`)A....$....4L..J<?.^...W...Z.&G....N...F....#...E.b;.O)s...j..d....2.~.I.."^..kO.C....]t.2Q..w.L.9h....Pwy<.|.#LD.Nco!.-.f.............M.e.>M....JP.....F.$.)+.7.^....e#.f.H.E.4.F-*.......#2.HD...y-)..8=><IK.i...9.G..GF#......-..mO.....p.....I.W..`.".esR;...v..9.7Y......Ic....a..+.H.wcE:.s8...7.N.qX.1.J:u[k..j..h .x..,..Mx.L.1O....(....S...,..i.v6ZXUK...Ij..g..ak..w...o..s.#.d..+U.....s...i.B_s]..Zu...vY.&....x.n...NH7.5..A...]..e.W......klO......._...}%&.].&...|.."..>..1H.g.)....#.U.x ...*..'8]>.....K.pw..^e.?A..|AuLs....0..2..+St...5D.E.........o.:..9j....:..u...@om..<..h-.d..(...El.../k.........+*../~...)`.{...7c..z..N"...P.W...WI....x.$.S...T.0(V...Y..^K... ..L..#.c..".F.h.5R.5&..>w.^dB.....=..a.].Hr......4.........-....[`v...{Tv.U]..R@.0............U.#.~.. ......P. ..c.....E.`F..I.)..e!.go.R.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1352
                                                      Entropy (8bit):7.851888002555872
                                                      Encrypted:false
                                                      SSDEEP:24:bkNRifpof8AiIb1olzS0zTwNnbAFb/+2UagA93buWlsBz3+JijRKk8awNNevn:bkN0f2fDBbOl10NS/+2UaD93lij+gDwE
                                                      MD5:B90C88DBA8CD4AB632671D220B21C6AB
                                                      SHA1:F2B94DD80BAA006256EF80BA3392864FF550C218
                                                      SHA-256:0AC13DA12AEA84F091C29D99F9DB5502D7799AE305EF81B318226C9B56CCE038
                                                      SHA-512:AF57BF4CC7F36840920CD77B166434E9E533F161F3A20D098443D8EEC986FCAE5566BACC39008C2A2F744841E139A2937B75702AC277EE9D061EFE7BE654FE19
                                                      Malicious:false
                                                      Preview:WANACRY!..........SB>..eQe..?.....:,...6 G$a|..+,S.>3. .v..Am)N..AL|...s...~).j"h....m..7.H...@+1..+BcPS/.Y...W...|.b,7\.L..^Rx(v.[N.gO..Y.;.;z.-.Qq....p...L...P.(..QG.....Uz....Q[$./-.%....'...Ao...8..N4....kj.h..F.A..G..m.b.c..{\...AU..:"k...8bY\.?.#...n_....(........2rW.v..:?.<..........N.....b..B.R...[.~._c..H60...#.JC.c..g.......5..I..g..'.i2k3.9.#.+.A.iWL.JY?.Tz.....!.9 ..9sH....6J.CC.x:.S.W~w.=*q`.X%6}.3...9..Kr..f...tl}l..i.G....>7..D.i..../..+.y..W.....,@..I9#..A....p:..:... .....f..t.`d.].Y.G.... a!Tp..Vy........H.. ._&.D...n..>..k..NX...87..+Jz.r $...<.H9... .z M+S....1...(.......o+p.......l-..9."k.^.....y.*c..N......%].=../...j.g,Nf.y.;.Mqe;...&..=.Z......(q..Q.#R.P.S.@f#;.o..,OQ...*..........$.gX.]Vl.}7.)2<.6I...X..Q.r..p.*..b,rY.._..a.yo&.$<;C..Z..=....!........t%f...T...Vp.Ik..R.*N..1.^Q.<d4h}.l?y.....F.#.3;..~.....%.e.U?.......w......~....*.."?.........X.c+j..G....N.S*h6.....2...5.(8x...z..5.z_c.Z.@..r.u.s...).C....p<:.nm.2...
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1352
                                                      Entropy (8bit):7.825923300980943
                                                      Encrypted:false
                                                      SSDEEP:24:bk7YJ0pb8/amKmY7jwVYqLVtC0X1eOUFxe4oEs66LjLiMKS3elUVflLj:bkLxmavwVf10xetEqOxlUdlv
                                                      MD5:3DCC7AD13158CC2E550CEB47F06FCCA4
                                                      SHA1:2F7380AA24442B6DD3299421FE9EC1F136537BDD
                                                      SHA-256:7250E59FBA34E3A9B8E5EA35FA09C0711E148C11F00A4A6F1C50B67A630D0BD6
                                                      SHA-512:3B286A173461A5B6C6D6E65488CEFFBF7EDD58DC3FFCC2C51B7273C8C173D3E59EDA059E45B9D7B8006F8A5A47F40297787ADF50D008FF2DA690A85051A21FEC
                                                      Malicious:false
                                                      Preview:WANACRY!............pZF....A}76...L......F.B)......V........Z..qFR....}..{..6M..1...L.?.k..(!.I..8p.C.T..=.(.zH.M....&....^< ..U..S..v.vB95.i.s1.I....O..q;2yL...g3.....].f.1}H.L./...Xt9TV.f...a..";...7.NOW3e?..!.5.mbw..5.o.>f..G...K......>......a.._.......(........q.{...E(@t..J.....9.T.M..h.R..H...S.O....F)y..w8k_]T..O.=..P.|.r..u."i.i.f3.3uZ..J..&n...@...>..x..r.bs..q_.............C+{9..J.[......pU.\H.. d.V=....u....5....\M.`......{",.44q...0....X.....(..i.o.>..-%b.....X/....a..F......b...8.>{.....c/x.PS.qY....}2Ho#.I.R.........='...P=J.}oIFx;0w....".......5.'...B....<.i.8[T..Q..k.6>.,.L..d......b...A.C...B...#b.............K.)..m.T.g......a...S.p2..5.-.q.\..:G..>..QI..n.D..=.6...sN...).. ..............^.6.;@.{-...8..w.X.(...U......"...16.....t.=?...".qF.?....=N(.D....8MK.S}............O%x7.T..;YJ...V].b.,1(......r...m....k....E...0.O..Y.l.0Kl.......)...K.ed.*.......\.>8x.........$. ...m..B....v....x.;&...'...m.L...x..
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1528
                                                      Entropy (8bit):7.872137276295136
                                                      Encrypted:false
                                                      SSDEEP:24:bk3m/ZGBcQeiSoaR3WsepEhqMVJQogQyOWsQuItQ2I9FqTfLMkn:bkGAS9RNh5VJjgLOhQuItZII9
                                                      MD5:D0D79EAA8134B356A29E6AB5B5090488
                                                      SHA1:FC6A6469EB60FD6C97EF8F6B24C9F1A35D9D2385
                                                      SHA-256:9B986E753D5EF08A563CB20E73843F5A20D8668B745E506016F874FF343810C0
                                                      SHA-512:E74D0FBF52BC69956234B22F63EB3567D8C67D5536A06C95F7F96BA94772E0E5F91B2D8E10DDAC5F56BF1376FAAB13835096EA21255AF32469045ECD60868386
                                                      Malicious:false
                                                      Preview:WANACRY!.....~..[. .`... .O...[..|_..>,......Cu.k......q.6.F..#2........h..a#3.g)j..mu.\....o..!y......O..?..Ox.>A$..#A........8.a...).V7...I...."..>./.z.Ien.;.2..!S.cw^....*.:........`.. .V..<.$........H...c|/....L.'..rPR.R_e...B.{...[.(....g*..t....'..jY..9xO.q@..................6..y.P.j_N.i0.....tP..DB.!T.Yb.)c.ePL.Fr.R..T.....5..W..|U[.EX..6./.2....d9..V%.lH.AY.....a.W......1.1D?.\y.]...]V.k..S7CH:X.. ....y.....,;Cp...%.......r...4t|&Y..HC..>...D...|...*.z.fP...T.^.D..M.s.C..^=.f..f&...+..8.]:.D'......H_._....._t...)..'.......=.&h.%dt.Sov.(d.(..3...c...z........=..lE`..4dWo.........6..U..s$..]_@.B....X.i....M..hS...`..Z......3...ud...V.....;{..v.1.)...BK.....Ei.B.h_ED`N+.?..L.cX`.U.q......t.\.......t.]K...:n...yM#..=,.A(..@.7H.=.....U&.`......u....t..?.,.G...ll.E^e.#^_\....../.X. ...V...T..h.......<S.Bx.S..Iw...{..Sc...>C..I_vp.!..+6....>.D.E.g.m...{..../..T..N.o~...7.6....@S -fvcH...9.o.KN...=....k..5!h....j.f].MUL.1i..n..5.y.I%..X."5p.. .L)h
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1528
                                                      Entropy (8bit):7.871701710695792
                                                      Encrypted:false
                                                      SSDEEP:24:bk7qdUKJ6mJeBMDgL9NzbOGGCE2+yEiYc/cP//Zan6qorlIfqrG0QuA6K/HRZ:bk7qdUoBJ5DeNzqotEiYc/wanS5siQuI
                                                      MD5:9828391973580FD788869B041F0693C4
                                                      SHA1:6430E28499A8F65A39C3E44AEB56D38458FE1CAF
                                                      SHA-256:CE8CEE70EE583AB30F10684D4ED4BF183A0361D554A969BF31C8F91D6BC2713E
                                                      SHA-512:4A96E2D3B31DD60EB18C236AC3FDB766CAB67207A3173AF7768F21A1A61C32BD5246FF76B59C809398052F082A0AEB18A19C897D9CA4252ACCFA9CA17C92A0E4
                                                      Malicious:false
                                                      Preview:WANACRY!....k.Wg .*.&u.{b..c.9.D2.CU....g........@z.L......b.l,.k9...1.&.&..?K.0.N".....)L........@y..ns.@....@K*..B..}....[.V.=.3T..#v7...>..A..k..J.'..|..P14..7B..O.....pf.....p....''}..\8...@G8w..]#..!J....-N...QS_.W.............W../...).q).Z...~..............5...}...|N..C-..C1....z$..h.g....7.A...u.....B..W.Pvy8>...E..}.J.w|....k......K...1*z...FE..]..Z.k1y.(. ...7O.H...s../.....DW-.G.D...0..5h=y.......yS'.?.xK....@OX$n..I...../.`.]{q.........yC...v[.{n...a.SN4.G....r.Z..X..D.f87!.8.5..l..".......DA.0C.X.m.E.....8PP../9......Y.N.....{.T.I.".d...K..[.......Q...r4.].....v.]^..&.X.<N.:qWK0.."!./0g6.....b...I..l........(@\...h~.....$...LDIW.g.....1.......X..s.!|V...Z....h..{.Sl$;..*..32u....-..o..G..%v.".......:.Tz.2.c.]w...9.M.%..A..K.P.].i.6[.w.;....Y.j.0.....Rx....eD.../...Y.....s[.?E.E.oQ.~../.E2...P.....uA.y7......y?.A.O}....4..4...H2. }R.......a;Q...w..^.t..{,-......J......1`..8!..S.{...v.......q^..c...]z...Pwt+.:...m..
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):638136
                                                      Entropy (8bit):7.999704012397226
                                                      Encrypted:true
                                                      SSDEEP:12288:VZ3DgsuWTpipr1ozMI3KNZ8EcYS7X/ud291s9k:T3+Wpic6NZ8X7GIMW
                                                      MD5:ED814FC927897D25880B4FF67243439A
                                                      SHA1:08DCC31B750565832987F9CC43EC8FE3064E071D
                                                      SHA-256:D8C8386301FDA3A3FAF670411CA512F32E56DE2BD019BE242884A13B6A807035
                                                      SHA-512:B2519F05A390D8E5CF2BB60B44A47239AF94DDD1F6E64A088B973BB9935E32114C48A014BC9646DC5C19E877AA21433A446FCFBB153EEC69BFDCBB5E5A651129
                                                      Malicious:true
                                                      Preview:WANACRY!.....g..9.f.P...8G..b.gF.M..[..L.n.Q...|...$.......u3YX.T]..W..5. l...`b|....{x..N.........ut....VM.Y..1]@.{=....^.....`.D|e....!..n...a*.@...L.{.`..'n*V.)E...........*..>....ND.h..V..u...vI...|&c...>...%\us.g.B....Y.x .n.H.`...'y...!..D...............v5..F)....y...e...PR...c*..:.....Z6i.J..~.%.%.D.c*.V.....qtK.."sJ...n.lD.VW...>..^...+...._E...4...1.g.|X.u..6..=.WR..^u'...........MY.[....y.....^.(..75.....l?G..-.Y...;.w....2.jl.i....Y.....7...9..-....8...X^"...9...._..Z.i.ar.H.x....:P.z....e..6h...K..*X.....s..mzi...+r.D.ye#'..w...v.............Y/.....S.T7|.....-g..g.^F.;...<...%....j.^Kz..wC%........`!{......Dbk....?v.o.~\.........._.}...f-.+(....H.,6.>....>.J=..:e..(>M....N.;d.W...dq..9.AR*#I.z.b`.$@9.LHD...!....`<...o..8....z.Kwat...|..,..c9/...}C]I}>!.r.V....."..A..[..^4.0.....Bx........!..y=..1m.a .^...M|eVW&._d...8.pD.6.6..R....8...MT..$.r}d.....f...?h...".tx.a...j.3e....1.r..([?.oF..%.#....Du?.|... .{#N.;
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:ASCII text, with CRLF line terminators
                                                      Category:dropped
                                                      Size (bytes):933
                                                      Entropy (8bit):4.710902136409594
                                                      Encrypted:false
                                                      SSDEEP:24:ptrPzDVR5Gi3OzGm0EigS1xbnS4RQhbrW8PNAi0eEprY+Ai75wRZcet:DZD36W3ChvWmMo+S
                                                      MD5:7E6B6DA7C61FCB66F3F30166871DEF5B
                                                      SHA1:00F699CF9BBC0308F6E101283ECA15A7C566D4F9
                                                      SHA-256:4A25D98C121BB3BD5B54E0B6A5348F7B09966BFFEEC30776E5A731813F05D49E
                                                      SHA-512:E5A56137F325904E0C7DE1D0DF38745F733652214F0CDB6EF173FA0743A334F95BED274DF79469E270C9208E6BDC2E6251EF0CDD81AF20FA1897929663E2C7D3
                                                      Malicious:false
                                                      Preview:Q: What's wrong with my files?....A: Ooops, your important files are encrypted. It means you will not be able to access them anymore until they are decrypted... If you follow our instructions, we guarantee that you can decrypt all your files quickly and safely!.. Let's start decrypting!....Q: What do I do?....A: First, you need to pay service fees for the decryption... Please send $300 worth of bitcoin to this bitcoin address: 13AM4VW2dhxYgXeQepoHkHSQuy6NgaEb94.... Next, please find an application file named "@WanaDecryptor@.exe". It is the decrypt software... Run and follow the instructions! (You may need to disable your antivirus for a while.).. ..Q: How can I trust?....A: Don't worry about decryption... We will decrypt your files surely because nobody will trust us if we cheat users... ....* If you need our assistance, send a message by clicking <Contact Us> on the decryptor window....
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:PE32 executable (GUI) Intel 80386, for MS Windows
                                                      Category:dropped
                                                      Size (bytes):245760
                                                      Entropy (8bit):6.278920408390635
                                                      Encrypted:false
                                                      SSDEEP:3072:Rmrhd5U1eigWcR+uiUg6p4FLlG4tlL8z+mmCeHFZjoHEo3m:REd5+IZiZhLlG4AimmCo
                                                      MD5:7BF2B57F2A205768755C07F238FB32CC
                                                      SHA1:45356A9DD616ED7161A3B9192E2F318D0AB5AD10
                                                      SHA-256:B9C5D4339809E0AD9A00D4D3DD26FDF44A32819A54ABF846BB9B560D81391C25
                                                      SHA-512:91A39E919296CB5C6ECCBA710B780519D90035175AA460EC6DBE631324E5E5753BD8D87F395B5481BCD7E1AD623B31A34382D81FAAE06BEF60EC28B49C3122A9
                                                      Malicious:true
                                                      Joe Sandbox View:
                                                      • Filename: LisectAVT_2403002A_223.exe, Detection: malicious, Browse
                                                      • Filename: , Detection: malicious, Browse
                                                      • Filename: , Detection: malicious, Browse
                                                      • Filename: Request for Quotation (RFQ_196).zip.zip, Detection: malicious, Browse
                                                      • Filename: , Detection: malicious, Browse
                                                      • Filename: jTwrz6fY44.exe, Detection: malicious, Browse
                                                      • Filename: ZN5KdHxjL1.exe, Detection: malicious, Browse
                                                      • Filename: wannacry.exe, Detection: malicious, Browse
                                                      • Filename: wannacry.exe, Detection: malicious, Browse
                                                      • Filename: Wannacry.exe, Detection: malicious, Browse
                                                      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......%...a...a...a......b.......u.......`.....d.......j.......e...W...b...a.......W...s.......`...Richa...................PE..L.....[J.................@...p.......1.......P....@..................................................................................0..|............................................................................P...............................text....3.......@.................. ..`.rdata..h....P.......P..............@..@.data....2.......0..................@....rsrc...|....0....... ..............@..@........................................................................................................................................................................................................................................................................................................................................................
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Archive, ctime=Thu Jul 25 21:01:45 2024, mtime=Thu Jul 25 21:01:45 2024, atime=Fri May 12 05:22:56 2017, length=245760, window=hide
                                                      Category:dropped
                                                      Size (bytes):575
                                                      Entropy (8bit):5.140446565826782
                                                      Encrypted:false
                                                      SSDEEP:6:4xtQl3y03CpzeVs+bTNAUHUtxXCzaMmM7/gtrUod6tMljAlpdmqLEoJ4D6Vod6Nd:8iypzYNbd0thHZOgZUobjArozhmV
                                                      MD5:CCD2610ADD4080C4DCC35A11217DA6A6
                                                      SHA1:001ABA92D58B546C8BD54E0BC4103661F68CF92A
                                                      SHA-256:0E272CF58CC66E7B0CC4F42094232A46B6EC11AE5ED695BA4156A1A28DA41E6D
                                                      SHA-512:36DC5CE3027E8A77639783E31AC69C9FA61C4761FBEB9A819C1EB49F4A32BF2001C0441FB28D35C4EC9DD1B713576E7894DE8FD13BF14CE62A436F9619093DEC
                                                      Malicious:false
                                                      Preview:L..................F.... ....b{=.....b{=.....`.1.................................P.O. .:i.....+00.:...:..,.LB.)...A&...&........DDj....%.=....(..=......t.2......J.2 .@WANAD~1.EXE..X.......X7..X7...............................@.W.a.n.a.D.e.c.r.y.p.t.o.r.@...e.x.e.......X...............-.......W.............,p.....C:\Users\user\Desktop\@WanaDecryptor@.exe......\.@.W.a.n.a.D.e.c.r.y.p.t.o.r.@...e.x.e.`.......X.......216041...........hT..CrF.f4... .u.E._c...,...E...hT..CrF.f4... .u.E._c...,...E..E.......9...1SPS..mD..pH.H@..=x.....h....H.....K...YM...?................
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:ASCII text, with CRLF line terminators
                                                      Category:dropped
                                                      Size (bytes):933
                                                      Entropy (8bit):4.710902136409594
                                                      Encrypted:false
                                                      SSDEEP:24:ptrPzDVR5Gi3OzGm0EigS1xbnS4RQhbrW8PNAi0eEprY+Ai75wRZcet:DZD36W3ChvWmMo+S
                                                      MD5:7E6B6DA7C61FCB66F3F30166871DEF5B
                                                      SHA1:00F699CF9BBC0308F6E101283ECA15A7C566D4F9
                                                      SHA-256:4A25D98C121BB3BD5B54E0B6A5348F7B09966BFFEEC30776E5A731813F05D49E
                                                      SHA-512:E5A56137F325904E0C7DE1D0DF38745F733652214F0CDB6EF173FA0743A334F95BED274DF79469E270C9208E6BDC2E6251EF0CDD81AF20FA1897929663E2C7D3
                                                      Malicious:false
                                                      Preview:Q: What's wrong with my files?....A: Ooops, your important files are encrypted. It means you will not be able to access them anymore until they are decrypted... If you follow our instructions, we guarantee that you can decrypt all your files quickly and safely!.. Let's start decrypting!....Q: What do I do?....A: First, you need to pay service fees for the decryption... Please send $300 worth of bitcoin to this bitcoin address: 13AM4VW2dhxYgXeQepoHkHSQuy6NgaEb94.... Next, please find an application file named "@WanaDecryptor@.exe". It is the decrypt software... Run and follow the instructions! (You may need to disable your antivirus for a while.).. ..Q: How can I trust?....A: Don't worry about decryption... We will decrypt your files surely because nobody will trust us if we cheat users... ....* If you need our assistance, send a message by clicking <Contact Us> on the decryptor window....
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Archive, ctime=Thu Jul 25 21:01:45 2024, mtime=Thu Jul 25 21:01:45 2024, atime=Fri May 12 05:22:56 2017, length=245760, window=hide
                                                      Category:dropped
                                                      Size (bytes):575
                                                      Entropy (8bit):5.140446565826782
                                                      Encrypted:false
                                                      SSDEEP:6:4xtQl3y03CpzeVs+bTNAUHUtxXCzaMmM7/gtrUod6tMljAlpdmqLEoJ4D6Vod6Nd:8iypzYNbd0thHZOgZUobjArozhmV
                                                      MD5:CCD2610ADD4080C4DCC35A11217DA6A6
                                                      SHA1:001ABA92D58B546C8BD54E0BC4103661F68CF92A
                                                      SHA-256:0E272CF58CC66E7B0CC4F42094232A46B6EC11AE5ED695BA4156A1A28DA41E6D
                                                      SHA-512:36DC5CE3027E8A77639783E31AC69C9FA61C4761FBEB9A819C1EB49F4A32BF2001C0441FB28D35C4EC9DD1B713576E7894DE8FD13BF14CE62A436F9619093DEC
                                                      Malicious:false
                                                      Preview:L..................F.... ....b{=.....b{=.....`.1.................................P.O. .:i.....+00.:...:..,.LB.)...A&...&........DDj....%.=....(..=......t.2......J.2 .@WANAD~1.EXE..X.......X7..X7...............................@.W.a.n.a.D.e.c.r.y.p.t.o.r.@...e.x.e.......X...............-.......W.............,p.....C:\Users\user\Desktop\@WanaDecryptor@.exe......\.@.W.a.n.a.D.e.c.r.y.p.t.o.r.@...e.x.e.`.......X.......216041...........hT..CrF.f4... .u.E._c...,...E...hT..CrF.f4... .u.E._c...,...E..E.......9...1SPS..mD..pH.H@..=x.....h....H.....K...YM...?................
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1048856
                                                      Entropy (8bit):7.999838702012411
                                                      Encrypted:true
                                                      SSDEEP:24576:oYTPxRRyhWtyFEtMl798uMS/SwmNEwd6XoPfYYCLaHmM:3TPxLyVzGS/4Ezo4PaGM
                                                      MD5:6FDB0E7B40C40E856B531626843F9EF8
                                                      SHA1:40EF72F4106AF7DE4D96EC23C0DF96F75368FEF5
                                                      SHA-256:AB1E7A60A1A80BE8F5A0E76BFF0B606491454D6632FA9A1D9AD33C4F0E207BAA
                                                      SHA-512:AE7D2301615D1DCFFD1A31CB56776BC8431FFEC08D19FC65621EF064F7984434AB71A22BF28D762F84E10DE0C447FF24468FB694B31F894F2DF555BA0BDC96EF
                                                      Malicious:true
                                                      Preview:WANACRY!.....rDB.1..M./...X.sU7*j..w..1.U...rL.!..'Mj\s..w.c!..mD."...4H..pM..}.HySM.O9...Ve>..qjs&....r.,.0...V+.y....aN..n....e}..'..K.JPL[..&....E....U.+.A....u.....,.I...Z(.5...xTI.W.J....C...E...Z.-...0io..,.!X*.9-.....^.8zr...G.. ...#..w5...C..AO.U.- .V...............j3]....R.Z._t.8.../.Mi....P....:.*Q.l.YNY4(N...-..$.C.........1.?..wn...,<zr+....s.E.B!...]..'_....9.......4V...,...@%p.. ... :.T,...r1I.=*.C..$.....M.M9.K..d:......}#.b ......I.X7.qH5.X~....Y./].N>q......`...x...l1.\0....Z..m.. ..\.ik,..!..h.g.dql....!5b...w.N.j.kn...t.......W@l...0?)b...E%..=.z..(<...*..j.v}....&.E.........j.Q...*....o...j.2mo..;..F...A...o5,..d.2y_ot).yU..3j.[..$....z~DZ....`..x..J.....w(_u.P.1:.=.t.....a...........%e5I..k{....P..x.....>.a.%..V{...M5.I..8........0......tj..C..%.....]K274.e..q.1...8...W+um..[a....P72./.E...[.@.......[.$>*...RI...ZNA('w.....Q.q.4}(.x.b...'....].2^.x.8++.'O.@r.......@v..fC..5>3u...3N.R.f.t..e@.+.\5.L..|..$..hU...G:.3..-.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):5272
                                                      Entropy (8bit):7.965487658381255
                                                      Encrypted:false
                                                      SSDEEP:96:oAOP/4BI/29XGQLYBnidnl1i66ty5Z15XKxHEfSQgnVZ9YX4uoG:G/mt9Xr0klIk5ZKxHI5gnVZGX4uoG
                                                      MD5:EC9967FF8ADF3261B6D7CE969E7D4E6B
                                                      SHA1:663E66C0C4AD69AF01129FB42ACE1E5612241CDC
                                                      SHA-256:457E76B5B3F03D1741E46C54296F8EC5A31B866943B99ABD21ED8D2801E77D9B
                                                      SHA-512:A981885071827501DB2EB848ACC5728ADFAC98399E45534CC6F4B53CF63F11A1DD279941E98B1D84D37DC4696509F963B8E6243419EC920DB7F98EC90D043D89
                                                      Malicious:false
                                                      Preview:WANACRY!....e...|.{...E[...v.O_..u....@\.......4..;...e..._*.x......o[..t.......R...1.......h.#S..i.u..........z .E..s.{..=]....0.O...f..O....##,G.=.X..q....6.#.1.a.?\.K%_...U...?x../...ZlY.n..[..J.^..F...c.l......\.9(.....|.I9...C...y../.[1j/.w..Yp.....V.......v........&J.....$.)......|...?.aa..;.....vm...z`O...o..Z].6.C..k|i..%..fG......sq.Dr..>aFw.y^..05.!.#....|.K..G..........7.;....h..9>@..c....J..n..C.2......4.6......`Cur..fp.b.=8A..^.........<"...j....W3......eR.JO;.s......X8o.L..)."...u.l......A.*..9......'........WV.|..../...m..........XM<.......B.K.....*.X..A.\.#.X...-.#8.....f#8.....bX..QG.[.".`z.........q..$6g"QR..@........!%.z.jZ..5...|.?C..+<....Z._..z..2..Lc~O...v.....Q.}..Up.P.......k.)....|.....J0;....g%l.."tdp5.6... .".......D....p_B>....FD...spC..eGu..9.UV.o}n.y2.~/..Cq.......m...k..o.Zb.`.u1....b.X......:vn.....t.V..\.Z.4..".G............A'...|.o..H....q.G/....(..r.0I.n....|..>.).@(.w}.......x.*?|..7.a..f...
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):80552
                                                      Entropy (8bit):7.998017239936916
                                                      Encrypted:true
                                                      SSDEEP:1536:/Q5TOzbhNc3aaRhZpUSWewVhT3UmErcHK0DOvWRjRNGTUyKSZGbq:IBcNc3xVwVhzUmErcHK2UZGbq
                                                      MD5:78CD2DDCD1D361A74039B407935F2350
                                                      SHA1:834AB720C6E2DBE07D463234AC90799DBDB21E27
                                                      SHA-256:2A7C692E791E048026F6F21A8FF5EAE24D0862B51B17B9F892BABCC0D8C9F0D2
                                                      SHA-512:69674F5BE1B133296456E40BDE48D26E115E8975F7BAC7D1A6CE7238BB446ABCED07C5E35D578454B1D8EFD70C7C9FA069F5E30E9D503DEA2FDAA56521181E9A
                                                      Malicious:true
                                                      Preview:WANACRY!....t...m&.>.l......Pd>.P.%ju%.k?..%.............V5.B..c3n....a.....b6(w.....Y.$s\%...GX.\...c.e.>.........c.......q7.[P.W..}....:...tp...FS...YK...q.69..}m.:[\........!........9.^.....g...dy....a....Jb..W\..9..z:.....zG.n7.u.x.\...f.a...h.$..$........9.............I...K.z.....e.#P..v..;.w6^0....A....\.0....M\....j...3+..&......[.H.........B.:.~Y.._,..P....7}G.....v..o....OX...".y......x.2^k..].c\.....o.G.u.w..q.C..&...Z)....C..j....;..#7(..ojQ..E.p...C.w.k..<.....^:...d.\..q.../....U...`'&....'X......b...X...Gz.P.X.sx,.g.5?.....u.."%.cZ...}...!.[a...G..&j"..Z.\^........lC|.7.....^..Ag.&.... .X.U*.9Q.."....^..4...+.....].....CFv./...e....k....,.l...BM...&..g..i.D......m........s.%........K...,.....%..h.k.g$.>.s...:.t....v..~.f.Z.W.d.p$...3.u.....Z...~...T..=...l.zY..a!......$'WZ.H.gU;(.ZG...x.Y........y.e..Q..(6.+.mkx..o.i9...|hY...:.!.Y.V.Q(.1.:..a.....i3..<N.........O.... T....3;c..o.n....3Z......;.-.4..@..|.z<....j^.....
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):544936
                                                      Entropy (8bit):7.999687491689246
                                                      Encrypted:true
                                                      SSDEEP:12288:V+OD1GZCNnBpHcCvzywojGrAHhSD96oLAvWJ+dGt75Rxwf:V+61cSBSCvzyCLAvvdHf
                                                      MD5:C754B5B8A1C1FFC974A87457C7ABDAE7
                                                      SHA1:B0484D4489C32499F67FCC976CB75375C1C536A9
                                                      SHA-256:51860421365C93CC752B951F46E24E689ACBC64852CAE52DDEEFE8A6045BEA85
                                                      SHA-512:4683F6E648D9C39D2CA98907553C2E7C26B183FE60AE8D10702E0C80FBAE7CA38F3FEC0C24E0C9803B4EED05493482F6F0F1B874AAD08A66EEF44AFB5353F356
                                                      Malicious:true
                                                      Preview:WANACRY!......r.O....0R...w..z.H.|..C..n....#.Ai.7o....`..V.V.2k.g5.....u.....h...:m...&...z..D...q......L........s...M.u..b..........B.u..*.z..)..q.W..+....e....o\U......_...[.d....|.$.>.nT.......I..,..R.,_...d.......wf..DnD............n.I.|.m.......O........"]A.r...O...o.......Q..*.....EU.W.!..sZp..1..].&..5.3.Fbd...N..o].i4?G.]g8...".L...Nb.o..~.C.....#z%.......$.8..<...N.......}=.Ss.B.p.....T>.B..._.<.C...<h..Wa..hE..`....b-.....\K..*.A.MYd..RG...q...}.N.PVxe.6....\d.p....5...;........4..b...M..t.+.m.u...<..P.....Am.'K......HoRZ....f.. 3.*...eh.X.ia...Z......@..Y..>.>...n.G..6.{....,..`..3}..J. .q.d....$.k.&.o.. .J.[9n.......C".>...#4..oVx.?.v..d...K.Kn5K.o......p..).;p..J;f..;..mzT.d..,.t.....,..6....$.....k}......2.b].oau>.7M.3.B.qb.....j............].....B6)..@.....3.3TW.-...%s1Z...uJ.......a)(....q.=...w.9F......EH<i.[.[g..=...r.y..$x>.M.2.z..n4.I..x7.~|\..wW.cRj.i.|..Z.H.I...n....0!;.AJO).../81.2W.*I.EL-.....~.&1LLti..g6 ~.G.m...
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):261608
                                                      Entropy (8bit):7.9993489156380155
                                                      Encrypted:true
                                                      SSDEEP:6144:QtQyEhpdCqt1l1jCKVePBq3OnkX0l1FbwvQUSs7F11ug0XN0K63PZG:QayAz38pq3OkElrEYUSs7lugs63I
                                                      MD5:CC168B1BC4930F73E64F5BB0665603E2
                                                      SHA1:D3E1EF798BBE5AC35EC5AC6B3C8FF0CDD229A99D
                                                      SHA-256:D35038FB24FDFB0FD461FEA1DEED8F7ADE43B36AB6790C426526F9B6ACA3964B
                                                      SHA-512:A8487043A8D7803DBBD8080D10D663E4961D4E54E5FC32875816D2712DBBA75F0A7CD69F5611DA16557F96FCCBD918834D762E3542383EE5F3BABE876A4CE017
                                                      Malicious:true
                                                      Preview:WANACRY!............F...f4..C..2./.M..`....3.MYl%..K=.k*."^c.D...%....*...?...H..H.O8.&........(."R..RKC..!..v....6.. 2B..j...q......'.....<..8....A81.3..^.....iko.#x......9.?#...f.%6...u,*..7Z.....(`.QP..f3....fR.?..G.......N.2.R....d. ......{..t.[}..9;MC.7..............D...H.._2X$..,....e..`.PL.y...*.Y.WH._.gD..`.n....b.....l_.K.. ..H.s...y%..t.....N.\.\.(..8.i.c.w.$n.z..j..5.i['F.,.!...K...+T:..%:..;...z......`.I..L,b.L -.p......W?....<A.K...i..+..E..J..n.P....I..q..p.J.\.......T&.I.J~/q.wy.B_H.}_m._C..Tu.x(l.p....<.V.../.-....Z.?{.9,bG.}....l...[.y....h.9f..p.K.~...[Si....@vid...0M...[..[.M.6.z)p/....W<\..!D.......d.Ol~l..X9.a+o...L.p.b/[.+..../t.CB.>..u7U.S..9...$s].~..H.\. .e.c:..%`...[..d.P...l..q~..))..uU..-3....t....v.U.......%.....1..]....ik.........q...$.<....5.......c[p....s<A.......{>.......sM.E.[.....u.q(.....Lm...y.....u.......R..DW.U...,b..7..-..Qa.z.+./...*.......V4........Y..GyC.}..R...F.....6p....N..^g...ic<6.].H.J.2o..H.#}0}
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):70648
                                                      Entropy (8bit):7.99762117994951
                                                      Encrypted:true
                                                      SSDEEP:1536:aqaTFQtG1ikIq/6/DlFyGiH46/MFf9S0+zOMJJXAMzUEBDKoOE:a1yAOq/6/yNlMFf9rCQiUEIw
                                                      MD5:B2F32A59AE19AEA418D0C14E08609DFF
                                                      SHA1:505726258AD2D4F22B82080765BD027CD3EF9C80
                                                      SHA-256:05FD31E101A170F04DCEB4E55E986FCE85A26DC71B6743D12A1D058280F110EB
                                                      SHA-512:C84665C01CE99160EC2EB35AA212CCC96D7FC38E6C63E87B4B71A1D13E2A5B31AFB7799F45138E98FDE4CF0F94637554CD886CBC9AB2B7E2923965A907C1BE96
                                                      Malicious:true
                                                      Preview:WANACRY!......D..{..,...Y.......H.u...e..Z..m.....hX..Dk!...dZg%p..H.U,.e'.*;..w..'.0..a.\...c..C...10...9....f...6E.f..C8..tc=..e...;..........kC.......,....$.{..U#..F.>......;,..w.3...4.z@.^D.+e.C...T...`.-..\n.O....NX./5>..1.]_..OZIz.nQ..?......8...#.................. .H...V]...(^??.P...U..U.VC...nu..V9~G...&Z...p..a..*e.q.9c..ve;Mg_@)...LeaG.Qz.U7...V.7..I:O.Uy.I.........*&nr...0..3h`. .E.....Q.Fp.......<+QQ.n.......B.'t..e.D.L..3.f...$.=\f...Y4o.x,...n.q..*DP..}...d.6#;."X6.(.35[.kZc...w.f..z......U....-.E..".!N."4.G.io1...g.......%d5......x.6sq.)v....c.1....b...K.?.m....."uue..`{-......{.Bg.....E%.. :..../.....SA..%Q....f$...].e......tc...>..,..*Y..l....i.<...t.1,O.R:..V....y..4=E.B..Z...N..%.v.>.W.c.2.;.<.L...Tf.&.5..'.?'..U...'.i[.`9.....XO..`..f...[..4..8..K.u.....a.AT.b..RN=2....6.$..:-..Q..I.]...:=/...hn..k.{7.m%.QN..S..+..aBUZ..e:.#.B...L:q..;....g.J.{..NU....`:/%...O.....@?...>..."..I.f.z.x....#..9D...\.=1w.Q....X.~
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):4648
                                                      Entropy (8bit):7.957202186027406
                                                      Encrypted:false
                                                      SSDEEP:96:oFvqSwqDZodZONPWe81XPJAqXFRazYJA0CpoF9PUXetykMl:qJwqD6dZOdZuPJAq1Az0hCGgXeql
                                                      MD5:CE6188174964ED28699137EB203F4666
                                                      SHA1:64F2C1226D491146709D1A3C3DA13293F4AD090C
                                                      SHA-256:2F005B310002AB6F5B61A711FC31308D3DCE32C5142F27BE414D57D9529EC509
                                                      SHA-512:D2F9DB0B0985C8F79693F7AA4155C9AE5754DE0FF1E182CB61938790CDABFB224BF37C1AC5B6BC17FCE0EB6F29E56881FABB61972CE61FBC21DC9F37B5ADC76D
                                                      Malicious:false
                                                      Preview:WANACRY!......:.X.j...g..A[:.}.....0..+.R.......O(..{X.."r.....;..C.....|..[..oa}../|Q!C.z.r[dO9......._...<@.....I.}^.g!...\`<...C.2J.-....&.5.7.H..TZ.....KC....E6..... ...?..r....T!..w.}.......'.=.j............._.Y..a/M...A}J.A.o.2...m0b....?..3d.?. .f.............-....&A.k...h..].T..Z...&..5>...J.Yw....5...2..<.....m.......V.-vv.....I...e .L.....3Z.5.F....*.,....m..+G..&}.E=....P=..I.V.;.!...;.m...&......x.j.....|.....U.._..p...>....;.&...~.[....xb...L.J......._.h{*&g.,"....O0a..P............[.W.,1t!}.]..4...#}.....`.5.......w..'...v.n..).....]:q.<..F*.6<.Z..a.l._...x....n,.Mi.4p.<..W..e.....DK... P..!.'.i..........3.r.d..}$.../b,Z?....{..h...K....`..s..|....X...S.1.zz..>....R..Y..?..0o..~.....j..?q.....(#.l.^..l.<u.3..k.M.,.-N]......g.U...U..$...2._.._3i.....I..e.T......U..........GGSR./.0.....f...8.]U.T7......E.p...-.....r. k..3..5j..(...n.. .3.a...pw..'..]V_.../........MJ..|+...}.n...).T>!..9..#......../0.^.2.. F..x......p..
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):8248
                                                      Entropy (8bit):7.976216972753219
                                                      Encrypted:false
                                                      SSDEEP:192:k/C/LzWXtY2GSDjomGfyzRnt+4/MxKkFo:Hn2GSwdUNMAkFo
                                                      MD5:DAEC4F9968D39708230D42837DA8B164
                                                      SHA1:4E7800D38458C8CDECCD0C6E54424981CECC8519
                                                      SHA-256:AA029F2DF0430A7336CC01542D445EFB0C793AFE84FC65EC32FCD92142C60753
                                                      SHA-512:DAB9A4BB13F834010BE8E7D5811492BE42CF401DE7B7B17C2F2BEFB860CBD478C3CE59752A89CEC89B5CA4DB9C7459EF201292A9B8600D3B030D2648D82EB4B0
                                                      Malicious:false
                                                      Preview:WANACRY!.......D$..%...t..~.....B ^.$.R...5zrX@.^....e...%a.U..".]...j.5...C^.b..+.i.L...0.....|..j.:..g.......V.x.....!t)y.&G..........;....*.....,>..?.u}P...i....|.nJ.9]..B.l.R.wv..[....6..X.2...._.........l.......Y26ePj...|.\Z.$.D.e.wl.}.....mN..%..Q.............x...E3...0....5..a...o}Ws.y..x..S.G6.L.....Tq.......L....6l....Y....v..@dS(.dw.P.......{...!..A.g....Z..ji.7.5>Tz../...f..p.c...P~..8<... L.Bg.o..B....$.o.^......?....I.pJ%].....8..K..~_.i...b<.{.N{...x...l2......7..mz..3)..u...T.w8.U|.g...q.3.P.[C....ST..>..0...._..Kl.DU.-m..'G?.%..b.m1L..[h.J.X.IR..+.....h.y.M./...]..)..B"B.....~....(o..r2.?.j...wp.a...tx....~d...5../<{(.i).nkK...@T.8.n9.%d+.-D../rn_cd...........t......|..A..;2,J{O.W..:.'N}o$-.^i.e.pB...*5.c.I..^*z.....Y_r.om....o..TPa)..k... .....Jx...L4...F<u.Qd..[.....Q4$J.>G......a.....W.v...4k6..[W=.<.....#.eoG}......|.E....R..X<..7.x5~.l*....V}........sM.IL...;e...$..wm...;.PG.{..u...@.OL....%.`..J .U..y.q...`
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):5976
                                                      Entropy (8bit):7.973701766568983
                                                      Encrypted:false
                                                      SSDEEP:96:o7z+DaNwS/sp2u75grFzz0FKk4pP4mIHt1PZkLQ1FT3hcx3bgpolaZ9FTAelaiUV:lOfCp750z3pAmINwc3jpolsPA69Sr
                                                      MD5:1CFE4FB0FCFCE40DC799B9203FA4D638
                                                      SHA1:EA950C933816F12D32AFA09F6CEDA7B1EDB87314
                                                      SHA-256:7C3EC3CEFE194F6B505D80732A06608B01483E496644A461E852995917E5BAD8
                                                      SHA-512:029A20CBF89A8D098E95110F94EBEEE70A1F5EF8B7CC275D135C220BFEDDD2FFC1A694FF4E0011B1E0B03465DADE8E525FA07F51F6F22D9EFBF6706339DCAC3D
                                                      Malicious:false
                                                      Preview:WANACRY!.....T-...h........;9..)....3...=_.s..8....s.U<....7...B...=...).i..\j.:..a1......p'.w.R.R."......dP..ou..%.a1OE....p.us..I.ov...`J.7j3.+o..C..1.AF....Ko:...3.n.s..H...k....Ol..%.Y.....)...?....D.u.#.....B`.2..}.A....Lp..e..{P...(.6...%..c..PL;.........9........wP?...H.........t.]..._.x*.?MWF...S..[q.~U7..1.Lf...Lv4.L....#c...s.ln7.......1...)V..;8eh....Zx.p?.{'..+.....Y.Ugg..n:..O..(<.o....BU.E...E._.^K...'...$5.L...wPi7.~.1.....3..yb<...O..;|.......+...E.DUv.......un._<j..y..#]..I\q...2.sI.~~..*.4...8..[...#..E_j...AU|....4..]...........D..56w..1...H..-.....("..'4.*I....&..T.F`.p6.NqaiG.e0A.n....@\.A.."z..C0......pg.0...(..r..P.....iX.OcP..........1....r....M.'P,M.-.A.=......5.....0.....r.a..%H?....h.....D...l.10....`...OK.L....)v...5..3.G.j..4@.4x...w,.J.bD.Jz...~.........q..0..8.b+.+......?.L...=l@*H.M....C.K.. ..EZ.o7.....v.^.O......&>....U.x.*n..s4.y.TW.9L..1.."......y.......?..5...T]?lM.zAZ.w..t.i).cV.d.F...3.pJ..V.......^.Hzv=.0tm
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):19880
                                                      Entropy (8bit):7.988404188625772
                                                      Encrypted:false
                                                      SSDEEP:384:uxOm+kfeoRj9fC6BS6N0bJ5onxx1rCdSS/ZIz86Db/wz46J5ZXHLHBV:EO297f9SSnlQm1D7m4C5ZXjf
                                                      MD5:E553FB87826E0867C6A02966D654FAAA
                                                      SHA1:99E1563FC132381EAEE1D8ED38A23C6F4436D11E
                                                      SHA-256:0B06F0DF83E8E1507D3F0237279E31BB20564C9E6AB78A0EFFFDBC610695A740
                                                      SHA-512:8EF3323438C61ADC230E5E862B5DFFDE5EB0356133FBED989D81DF805BBEC47DFD853EC4E03D58CC8C45959A7C7D7E46C2F382FF65B160B9691CF4E0E26557E7
                                                      Malicious:false
                                                      Preview:WANACRY!....:..........>.....5..+ o......y.].."S..{.....Z..o..L......_.s.L....m8.^.d.....^..i.R.....W...]0._........Z.(...#LBW....lYF.U.5...Kt<.U...e....uM...j. .e.7.B....:.ayG%}....?.....x.vL...^`...;l.=;..M...c^...\..(%,....V.#P.mc..:.;K.:..D....s.C..........L......TH|;..G0......y]....S.v...7.(./s...+..w....L.1..U[...........].I.6.....,.....BZZ..EP..x`.)...*.U..c.f.g..._.......0M.%.J.......^.p..-...>....&r..Q.l.!.W [..).M=u..Zj.b"...8..l.$&...B....P...x_B[.....O...6X....#.........ZO..3.t.7....5..M.....1.d..3......#..9...#.L..u|..K.H....(.<...".....S.....P+MA.]..%\....g./...(9..t..S.V...$......f.B...nkJR8.7.G..c..S......B..xr...X....`..I..L.....?........0.su.5f..%..f=...V@.L..ZQ.\3....cLMO=}.;&..L...<....aKJj&,.+.)..L3....A(.h.=.!Y..$..#J..ad......f...}....|.G..A...e...b..f....d.>.s...W.J..._=.....;.'.....vi].R...%b......9..D^Vi.w..|^..;p.)\=Fjj{.L...yX....T..Ws.Q.....x\.......R)7....+.......J..............B.. ..z18.7@HE.^..69..K_....
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):2104
                                                      Entropy (8bit):7.920424024567635
                                                      Encrypted:false
                                                      SSDEEP:48:bkeRAaiLySjojJTUE6hT42aNpEXzUDC0hM5uK7Tqn:oeEyTjJ4E6mhNpE2ZIpm
                                                      MD5:B83772F798B54A1CFBDFBD89FA2C6A81
                                                      SHA1:CA4E4B74BA5CADBB3E11F895B52341CFC425D9B6
                                                      SHA-256:D5972EACBD517344B191FE0B3412C7F3ACCC755AA249D8FA5464FBFBC612C323
                                                      SHA-512:552548F41808C372152C6E4239061C654E27EC20DCB8BC352BEBC920149041B0B0DA077FEAEBCE77BF25DCA98433E4F44053D8A5DFA59E74BCAA58F414E9B413
                                                      Malicious:false
                                                      Preview:WANACRY!....._...a..n.3...[..v.#..|....._g..0h...JQv..'.....(...].n.-.N..!L..4.r...\...).a...G...C.W..7..Y..z.S..S$-.y..t..6...s.-`".e.....&..I.(...G.P.b...?+.....b..f..~8.*y....H.pO :p.n..+.lP.t-.R..eO......l.<...x...3..Xy.B.m.P2........N..O.......<.E..............m.x4D.>K.Z....*.C..jG*..5{...:/.XO.x.;..T.D|H../w~7...:...#.b.x..K.H..O.F.....M+[q.....=..|mg..u?......i........K..@{|....,.>.I.?.fw...w{.3.o^..>.l,....w......o.o,. C...QI,u.,.I.'..........g.t....@.....e.g...&..|3...e!...V...Zn....o.t..\[...0....~..j..D...A...(..2.n7L}'G."...J..7...\......t....W....4...wG..2.';..F....?.\_o.......d ....>..2....O..@nY.@..8m1.R........f...;2..4....X....sp..}T...E.f.G.\.&c"..St .8.k..s.U..i....`.V..-3.el.~..a|=e.%.!.....`..8........gf...h.fT..k?.^Oy.)....-f.......&G.@"..y....).q.m.333Y......].M,..#(Y..K..../....c.A....n..(.g1~(.L.~.E..M...b..".I.2...W....-...6].H.6....H.$.F>3...|.i.J.R{.{....C...m?...qC.h....uq...ta...q.*....1Nfj....#...y='.>j.l..
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):3160
                                                      Entropy (8bit):7.932862340419218
                                                      Encrypted:false
                                                      SSDEEP:48:bkUH8sSmbj2vWzuCWIEW+HzAD3pCcV020XYF3OrKoUL8GVyPJitQwYBR0P++Pc9s:oUHtbTyCWNvcDo+QZrzGVyPWO0tP9
                                                      MD5:BDD6EBDFE84066F3ECB42AD53289E380
                                                      SHA1:9089FD12A10F096C2C31C27A147DBFEA20230F6B
                                                      SHA-256:20277EDD49E226053375B592C6D5F4610D67176AE9310BCC8F97AD6558BB8877
                                                      SHA-512:216B19FC51B95ABBC0A9DFECD85BDACD7A178094D936763119A786EF53A0EDE588FAD6CA66FD8DD16A920867D6C3AC38D6ADA2396E0A717592092B653E285AEB
                                                      Malicious:false
                                                      Preview:WANACRY!....2.$.t...lhi.oM....'AT...:.....p...{..V....+....@..>K...zg.9. ...b...X<t..Z...<..z.B.-..Uz....a.4nQ.V.K>.|w....-.7.$...)........O......~......T......X.M...W..~...I9z..=D..".G|~...>CTB.....:...V.{*.Y.6.3XG.2.......iov.@.1......>.<..X...........3.........&w+...&vM.h....A.p(1>..#4.T..$.N.h.o*..2........R..!.X..5..2...^H....j&....?..o.@..F...v...h9_...I.I6\.W....A.......eC.....`..,.y9.Oa.I.Cc.G6..O.:W..xV.L.5 ...u......S..@T..L.'{K.PD~..Q.h......Q..9.L(..\m.lv.l...E....,..UI:.:.&.U..n..i.^..-.s..?.........mm.=$.xg..,+..pM.1...`L._....M~...s.J...o+8...U................m.U....*$IB..f..ob#.[-...H3.{..V..i.6..D....ZfB)..b...Y.)...L...Lq\....^.......$..F....;.R.M.>O....k....'......|......uf.......P8Z.@....h...e@.3..o.@...wL.yI......|>..On+%..[...J....w$%.Z.".n0..-v...B.E.$...C..O....x*.N?.],NnJ..or.t...m....Eu..k.?W..I...y.L...m#..`......e8..b.f._.n...y... .b.2)"F3..R.c...F.4.gE\I2..............*.]..{6.~...:......J@.ag.$.@>T5....
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):4120
                                                      Entropy (8bit):7.959766682741344
                                                      Encrypted:false
                                                      SSDEEP:48:bkgXnCE4qDpt8QAbm5+NuUgx2EvdXlRpS9u+/KPuMBN39YoJVJgtG95V/T2xy6Si:ogWAnB+wUq17ZPus395oo3zOlLuYKc1
                                                      MD5:77D5FCEAFE4C3EF589F4484705233340
                                                      SHA1:70DB6BBCE6667BE77D9EE0C76BF976C9A5D4A773
                                                      SHA-256:A0C046D8C5FD55E10B91B769D360F2043A469E07EED411DE267EB74E30C4352C
                                                      SHA-512:D93A716A3D75D5BB4474F409FE49276CFA7E1BA14080C5390B744005E32A1C72EE26F59A0B3078E9E64F5B0314BD6C4A4B6344E8A4E9643A4C0D4ABB4B9D347F
                                                      Malicious:false
                                                      Preview:WANACRY!.....>.B.An...y:...._..v.(D$3D..|-PZ.V...l.||.Z.sc........d.=..`..>...9a[.G...<.5..!.x.pu...<o.Eu..%e....r.w.6G.2...ci.o..Y'.(1.bK.'.W1...\M|.X-.?.Vy`S,v.........6Q/*.,.......E...A.v.....j..%f..A.9...5K .!K.rqF.4z.v...5.rI$`.Oo._a6...g?..&...^...............C2:._...=?h....5(..-l.L.pC.T..0+.../.>l....W..i.(!.b@.`]...7.zB.......`..%AR...CK........V.....Z.....".8xLa.9.G.K..&../..f<o.......5A..x..p..bb^.r'.C........*g..n`/.ps..S.r.p*qPu[\.`i....K.i3.. l>.....?.x4.Mt..G.L.P......2..8\d...YMh....p."8.c...4.&b.L0..`.^;.A...7.'V9.......fQ..#....$..K......\.^.iY7^I......HA}.._&l....P.H.<v..L.T.. 7.f.Y?.W.EgQi.yu......,;..2mo6.."....d..t&.!i}.k..so....r*i......3.m.yK.K..|W*..u^t/>0n.H..)..!..9.Zo.R.;.{...amz..U..S}.h.p....Y....L..~..D.q.^E.U-...8.D.u.V.."U..rr#?...L.%[j.2....t..#6M@f.y.>o.......*.8g..yM...)(.}R..*.i.fl.o....lL{:.....|:..VUJ..i..<.|.]?z.l....f......Z....=c...%...M..<..-_.n...!..D.....L.)ll.k.9...y.....Z6..-.P:.6..(Cl
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):6056
                                                      Entropy (8bit):7.962395818368464
                                                      Encrypted:false
                                                      SSDEEP:96:o1Ex1M3v+tcmG4egx/rODHZkRG06brH9ghPcsxHfARpbJ8+MhB8n4JW8Qo/y38p8:9DS0GMx/aD5QG06f96cCHf238vhB8n4O
                                                      MD5:017E475288DADE27A24F3F1E518B7051
                                                      SHA1:9CA4194A4535EA35DE92DD06ABAD9BD8D5C4DCB2
                                                      SHA-256:FECC53210B84C70943A2728C03FF497D7E6EF452B6F95663A4CA848A3DE4C726
                                                      SHA-512:C885C7980DD63EE827480CE4F697FB47021C1FDC584ADD8CE863C31D03CC52684D91E9891EC7BC2B65ADAAA3723935EACC75A4ACF9DE6121C0326835ACBDB9E5
                                                      Malicious:false
                                                      Preview:WANACRY!.......'.lm.?.............+...^(...A.".6....j.....l52.z|.$....ue0X\. @n..!](S/=.....j.\b..Y..u..1A..|..B...E.bZ..9....Y..Z{'g#...a.0.z......e1..L L...8.."M...r........ac....}x........../.P.....@9..W.-..Q.L..z.3..*)..(.~...*K...M+.....F.....f.FA.5................db.g`.!wd.vTb.]|...w<.?.Z.?bl.]N...H`D6DQ..rS.(.!.........>...v[.o..$.C.W.UJ.f.\ ..<...@0.'&=......asC...?....I...Q...8i..nku.....#XQ...{.H...{g.V....3.7....|..YHWA....3's,.u_dx<[...l...RUo.Ea......O..K.7I.&\....Z.C._..y..k2...K.bI,...I.K.?(.=..V....E......!o....2.>..)......}..V........)....S..L#B..G...o......O'.(e...C.f...t./.6%S..,...}l!.....d..j.%./....o.S.....t..9.....E.C..M.g...@W.a...a.I9|....!..d....(1.......3............8z..U.rg..8[<h.>....-i.X..7.$O...+\....\.c.|..+......J^....nSP5...*..6.e..qc....Q3.{B..*....5...........^$...J...n6e.h{.E......./../.......f..V...b.....#H..3.A..bI.....f.I...L..37h.o9..%yM...r%.#...i.._?.8eTx..\..*.cbL.....!.....V.`.5.3.hs..w...5X.P
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):10344
                                                      Entropy (8bit):7.982914447584355
                                                      Encrypted:false
                                                      SSDEEP:192:nK8OLBniDaIHw+jZIeuV1Ybahx3fjs3H1XCKZc4MKhw8JpJ8n1E1pWGWuBKr:K8OLBwxHdZuY+hpA3H1Jc47hLjynK1p6
                                                      MD5:AA08AC59EA253453D93736C79DC3D940
                                                      SHA1:7C42300306A3B0B1F207A867748E8C26CE652AF3
                                                      SHA-256:E0E0A170B4B8DECEE32D155334945F3C804B18BF5E2743C84B106258B65F8651
                                                      SHA-512:0A2964C92D3D903312723C437558EA7A1C87144CC86F3782426D7DA73B03F8D141FD17426BD41CF6E10A237CCBB9EE7E40E31392267CB04124FB5FED9CEDB530
                                                      Malicious:false
                                                      Preview:WANACRY!....._.......R..IH.l.........Y.Z..$.zA].{....o...].._vc.4...o.y....\...8h.m.8.. z.........=Z..*.P..K.%..N....Y....aX7.i...R.. .}.g..J{.>{..7..?Z..vY.>..$...th.....rT...f...:.`................`..Zt....6....X...Z.[{Jn......rq..K.`/..q0...(y.H....Z...z@r.....P'.......C.[j..Ku..8..v.!Z.w..<z"}..I..~.]cS.O~..k...#.R8.b...J(.('V...!..}G.G)..k..}...........O.7...g .'....n.4...F.M..2..&..e.b..?...#J.....h.u.X+6.Z.....K..R.9md..{.~.u.m;.I.......h..m.........6*..5.S..y.6,.......&w...~f..7@=.*.*..bE!.........R.8....A........9.y....d..&o.,.V..,L[.........&&.J..jG.x.@*....q.....a..v......s.y..K...:."....'_.....0F..z....=h......3.1|.VX.&.H<.,......E.6..,(..../..>t:.....+$EeL....J.F..d.w..X..h.2R..8...."M..<;KR.V:e'...\.*..$.. 2.....$.X.yp:.z1..p0q#U...h4..7.s*J....,.L.Z..^.....X.X..*.Y.1...~&=.......yp.E...H.C.Q).#.8....%..'.......u.W4....../7.K&.6....b>._a(.C.e...n."Y..o.0......"....d'...m........^:\3.........#..%".*...nlWg)J.HU...2...qWkWU..X..a
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):7240
                                                      Entropy (8bit):7.970439808073643
                                                      Encrypted:false
                                                      SSDEEP:192:YPQhxYi0E1lOC8iU0rBbcp0/b8D97ONBpRz1kHW:YIrAE1lWqbcpCu9QHRi2
                                                      MD5:C132CBC111D658423B1ECF3FF8E3F16E
                                                      SHA1:19F6987B947E42CDD239694D2F262C88C50EB82F
                                                      SHA-256:D4001A3C96E6645A64DFBC4350AD4811524615A9ECFE6AE25C12EBB02616262C
                                                      SHA-512:44F814E3CAFEA599DE794FB297559394A6189AF5787EE3017D9CD2FA419D62576CAE48687001369D2832C80AAEEA5F8B4C5706001DD3B5FEE3335A115F90252F
                                                      Malicious:false
                                                      Preview:WANACRY!....rs/........k(.!.u...xy.....=R......... qS.d"..i...AT2.ix.....'80.......4..70M....w.B+@.F.........p).......`JJ~K]-.e ....]D.7..2q..T.2.?vE.a&.#......Y|..#...o.la.;.. ....$.".}#ODa...Gj.......k..z....4.Ai..>..h.>Yf.....g/.D.K...`...,......z....bd........+........R{.8..+.6Xd....`.....}p.GI7..].bC.<.<.WK.....K.mX..;....Yu.5.....g.^|.....I.r^.A.......2....^<8.M.G.'...l...=`?....../ ..T.p......~.....Dr.G.?.9.e.)..x.....4m..-.F...m..2...T...p.Y.+.....s"!...|.l...e...19.c.0;Z..(....+@..j...C.....]...V......y...;............B...u.....7(...n{6..J{...a....].".&....S.....N...s.24>9..t.8.Yn}.w.....~...1.em.,q...b..c...t...K.~D..<...B..[..,..{....6....M|l..P./P...pN...7..R.....1.2.o.......~...2...7'.R.;.W..BE.t.. s.C x..Tw.......6.@`...z...b.=C...7..I.r.I6..h._b.., 9.)..fM.$.....c.+.b.....f.X.?.XV..K...<.h./..{..u..%k$...)_.S...'..t&Z..s....L.....#.f.U....0.M.<e......(...].....#u.A..E....rT.....BLO.r^.#u..y........\.6..M.#i^...K.7...
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):25624
                                                      Entropy (8bit):7.992452141442795
                                                      Encrypted:true
                                                      SSDEEP:384:I6lIWv+6YwTL3VNw34UYVsJ7syF8x5AN9cenl6EO4rv5osjNWrJlRPhpbAT8EO5:Io/v06q38Q7W5AN9x6WjrpeTfqk
                                                      MD5:E30478A126C1164283AC1EB00656A7CD
                                                      SHA1:C532E8768A7AA1E01F13F3DE09917BB7EA6E9C90
                                                      SHA-256:36F2D78F57BD1F80201FBFBD51C585380BC6801A6A20629087BD692AD812BC95
                                                      SHA-512:6767DDA590C976FA1D6B5BC3CFC5A98B5018BAA65EA7B41976F3E5B3C7833C9128C503C9370E4727E2197FF6790BD27A40EC09578054CB3392798A8875424261
                                                      Malicious:true
                                                      Preview:WANACRY!.......i..;.A.... RZ]y5H...0[......m.|...^Y..2..s.,....../..v.P....t.2x.PYv....p38.PA.Sk..!....!X~..JV...V...e.V.X..d.$.^ <...hxS.H.i.....^Da}...?...R.......L.T>.1.$r.B..Msq.,o.....x.8Cy.XhMNS.F..V.......t@#/......=z.].`2.y.P.......Ew..6{..5.pD&B./..........b........;7...p2.......k....$N..#b6.....qn.B+|...i6.c..6.z...J...+.D;.k.............ym%....pGE..wQ......b/..V/h]..).w..^L.K...t.:...$I.v....y..rHB.Bu.....$.z..jyx.y..!.(S2....CJ.+>J...`o...Q.........y.+\w@txl....$'.."R.Z.......\......T.3.....U...........L.G..dDuz3....B... ...............ZS?$..e.._...*.......S4....k.E.... .X/J......p...x.C..,C.....X1Ho...7=."\w...#.......ZX..Uu...P........k....EV...Q.........I..Z........I0..>.?@S..2.....4.aPw.^.....vP.Q...+^.6...f...S.|{H..m.?U.4.!7s..N..9vo..U'....0u.U|..US.!.mpt+j.?.g...mD..O..z...{..+...r.GV.....|C@.#.."61.1O#..' .H.MZ0...........)..).@zy;....|..BH...F..\.h.1Rn.V.0...14.M......L.....A...K.....t..1.E<Cu_j?.............*.Z.(..g..
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1784
                                                      Entropy (8bit):7.890645970166429
                                                      Encrypted:false
                                                      SSDEEP:48:bkuE66wv/xQ3umEShxBvKKY3EoWRmg5ablXtUlsguTd2QHRyHe:ouEsX/mEQBZoCtuQGd2QHqe
                                                      MD5:C72607308FBB2DCC50FE86768AA4F16B
                                                      SHA1:FCDA327553E3A726B55D3FC191CA4491F9655C32
                                                      SHA-256:8543304A70DFAE6936791C1683D68F414A44BF75E5EC0DC7965B03A61D184C9D
                                                      SHA-512:1F8657E301D10673B0D35233B8D7AB36E23C4AB6F7DBB6DC0F6B95847127D67191F32829776CB3C454BB92DB51CA9EA20CFDE12FEDD834BD7FEDF7877F6B4816
                                                      Malicious:false
                                                      Preview:WANACRY!......R0^=..>..a.kp,<......ga7.D.$..s.`B..Ix.z....B.".....*.%......aNX..\f...y....L!+......~`....l.#.....1..J.....@.........i.s.xw..g&................:O..>......a.-.ygh.n].g.]T...o.........lQ.c.^dk.e.....g....xm...[hz.d..}.........Eb`..g....~.rJt"U............ah.....E.N|.q.Q.].XW.M....'E..5l...Mf^.....a....4.J-.[.-......8wP7m.]..X.FC....1..?.;....^....`....H.r.sc.LG_i\...>f...K4.b...{..uP.8<....0Av......W...`....1O..2.{.....8.....n.(...kvr.....3^......B.q.Q...xC.m.....HZ.LB.+....10.'Q'<.}H.x.|:._..r.K..:`P.1...M.J.....d..E-.:...2G..<I..e....I =b..V.t2....R/..oQ...a...|.F.D..L........U4....*.....H.G+.&..d.\..f...'./......Dg.r...1Z.j*.X.<>..m......2.8^.43....3 )..e.#...*O......Lk.....@.G..l.......l.....]1...>.L...o..6..;....M.%0k'=Wg.......b .cF.(..R..5A.v.] .^..~A....HY....VV&.t.).....:..#.v..x<.z)D....@.".#^m.&HJ..7.>.;..+!p......2J..g..r80.v...v[....y..;..qC.....O.e..w2../......,.<.H..(.^...M....>..r..g1.Dd....0^4......DP3..@..u..k.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):2696
                                                      Entropy (8bit):7.925548260017795
                                                      Encrypted:false
                                                      SSDEEP:48:bkYJ/G1nyewmaKN6Vt958i+K2RjmGUru8kSkh4ww9Y:oyq10f8i+KamGUrdXkqY
                                                      MD5:505F461E5912FF91357C3D2DADCC63FF
                                                      SHA1:3FD011C3D0D9B9B10BC0F8A6EF63BC1438606B0C
                                                      SHA-256:62911AE5E5AEC204D82E1B194E459D95BEDE9D94BEB70FDC4C99DBB7D50BD0DF
                                                      SHA-512:1FD8990CC06641812596955F3ADEA2BABB2402BC2CD57B22474213B2C765482896CE18B66A28E7F064B2514BD370C0ED52D5BEF797EA59397324E8CA8AA9C40C
                                                      Malicious:false
                                                      Preview:WANACRY!.....K.2...#....sk.iA..H....uv ......t.L..Y...:.ci..RB.....vl0f..&...r.Gp...Z|....NhR..J.IX.-.?jo.0?..RLx....@..o...@|.:B..a........?...c..fH..R.]i...4...L....G/._S...r....-..e....Z.q....R..........#...q..A.Q.s..x..yR..CB......S6;.....b....j~..fC....m..........Q%..6.o8#/E........[.T..{.7.....g..=..#0%.....h....ZWj..Z<3....K.p..c...r.Z.+.Z...oA.Lp...^sE> .).m...*.... ..che.....%.S.k...T.)...e...Z...H.v.....B.....#......c....#....!..(._.....\$...X..p.0.]\..\]h.K..=...g'<..._C......izQ..F..."..o........P..._'?.([|ZnmL...9.dG5.;..y+.Z..F.Z...2.9NN........J.....Yy#`.........<V..6..=.v...(.Zs..h}..$d.p...?.....4.../2.r.D......"i.Ns5... _.....d.F> :J..m7.+k..V ...]".%q.H+..[..>.q..S.._d......v:...Q."<..K........2.l......H.y*.q.....3ZY.......'_K.ACn.g.OF.Uo6. ..?}Y8D.....BBG......$S6.H.\...t.8...c.i.9..fg.....rk..*....8.9....a2a....{m.......I...L OY..(..+]+..t}P..6.4W.....B..$%...W+Qtm.=0BK_%A....lb....z>c.,.l..g.....e.01...7}U@S....iz.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):4072
                                                      Entropy (8bit):7.949179900539146
                                                      Encrypted:false
                                                      SSDEEP:96:oDxjABLD5z2li5sL1GmTpemd7hxWUSU1UBQYEs5uVoCrwv5:aSpByLXYmlhNSU6/ELVk
                                                      MD5:8D0841D832D217730F816113D95BC11C
                                                      SHA1:AABD4845C25783ACFB9261B22ADAB1512ECCEF3B
                                                      SHA-256:837FA13485BA8C79E6566458A3D65A4FFA6F7981E96CE030914D6E6756A42E02
                                                      SHA-512:AE2DBEAE8DD643592DE32C04DE5652E8583670A1AF6C29A3252938871F2192CC45FC157D1E2B3ECB9DC2A641F4596C3E1D74382F8534968E5B6A655AE9A01F6F
                                                      Malicious:false
                                                      Preview:WANACRY!.......CI}i...8.,!..0....h?-.a...N+..$+..9g.F.N.J.$.....L.|........s.O`....,/x.(....s..H$...3Z.....W;j.[..<.......\.q.........z>.Y..R..l.ou.s.?...zJ:.<..d.w.....j...........j...$tn..E^....N4....1.D....)...C...S.0....i.(..J#uu.....lt.....7.z2G................@.sy..N$..V....U..K..p.[k28w.rl..z+.u...8<.,....H..R....8.Ri...%..K..0........s.e6..D.]K.s..........X. ......,#...v-.D...........W.Z.&J,...MeU.-2%.Bm0_.|....I......z.&0.M.|..v..A]\....].....:...$......\.$pj(.B./.=./.....Kk.......A..Py5. e..F.q.....B.WCq..,.Z.....z...t...l5.....{o.G...9jw(./..hf.j.j..%(...5.g.9cH/..R6......L(Tf...A*A.)'....a.}..).2e..........2.wN|.a..N).+...Ec(..A8..2zU.|..Q.k&j..@./.......@.x.~l;g.R....8.....EA.t.E8+D'....3......O.6..#......'r..r8..0P.#........pk...9."I.B.mz.~{N."...|.U..'..$....lJz.gE..,~....Y.d...'3..a..\..=.o?DZ.Z...........^...Y..L....?<.FR...5.A....*......4.....8......0..;.....(\.aK.!6h.<.......a|.FO`..5...m....o.=..P1.........HS...6#.:...5
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):7000
                                                      Entropy (8bit):7.973106555959625
                                                      Encrypted:false
                                                      SSDEEP:192:CbPwW1TtpKe33O+c1DhlIC3hgoYG6Xl0j:0xNtpKe33O+Q1Rgj72j
                                                      MD5:6C6E9419F272BA33DD4B89E5E5C69A4D
                                                      SHA1:8931AC352C604A4CDB32ADA14CDF502B8B8295A0
                                                      SHA-256:46BED21B6B4054A725C62C87212D203A116BA03AFAC7E845F846A14B350E57C0
                                                      SHA-512:F9F81DC8EC5DFB88A7A42EF0823712B56CB33022096F13F82B2EF7126B0A6310B081E5EA8A68932A9C99D183B393C8AE58C4680724E53E981B831E7B8F68F630
                                                      Malicious:false
                                                      Preview:WANACRY!....V......./...}E....6..yzG.'+..lD..D,..;.j...........UA..?4...............1....)sQ...$...b.1Vm..^..c.>%KuQ.....E?j]......3e.Sv.z.N....H`.kxl..p.k.8......T..n..{.w[.L..SH.{4A.-#Z.....&.[.L..`.....p...+*.v,.=..)..>..............<7..u..(j....u....*_.X....;.........0 .h.$.......)..4.......x...kE8.R.|..ud2...d,...i.nl..&QdE....N2.....:/...h&.^..].5.!./..7...?...<.....{...2>@.p}C.....{..4.q.O]u....'.../..w.ou.G......'O..64..ft=n...l#.:..&..3x>.e.L.Xn.D..|.af....$?X..Ag..;'.....P.<...V|.t......&U...!c.......d......i....L~^=$E....>......m.....d<.rE^..k......n....}....>....d.0[.<...E.c~9.F.O....T=.aL|.}$.!^.zTmC.(X{w."...WH.R.Aq...`..jZ.jjK#4:..../[.j..j........}2y.F};x.:[l..)..UD..%.T....!....*.:.....>L.v.....`.Q............)=...#..m....sv...N.....Zcw....V....P..z.^...L;Vq..`[5..\J.m{.O...A....d..4./..P..g3....pU.....:.p,.25..)...a.G`.....a. !.,../.{..X.i3>./h..M...H]i~.E..`.((h..@.C...<..GM..a..H$.x.......A..l..Y*.] .p...b.........2w.k...
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):2600
                                                      Entropy (8bit):7.918417022049414
                                                      Encrypted:false
                                                      SSDEEP:48:bku04mS34Uvvtkpt59HWQIeO9i5PR/9ZtKK8nZycu96rRnA90NPPxP7h:obqlSpt51WD6PRjtKK8Zyce6VC0tPlh
                                                      MD5:178A26A3BD239949226C5800CEEFC124
                                                      SHA1:1D02EB3ADE8C27DBEAB65617B2A52DB66499A787
                                                      SHA-256:F24453E8B1FD0AD12B0629D87C32A82B805B7429CEA9565C642B7A224B021B65
                                                      SHA-512:109994070902BFADE4373DB49E081264A0E241460D9524205F253A9D200750518F66ADA1593AACC159768658570E2174535629B6501C44D7A8255F6BE97ABE2E
                                                      Malicious:false
                                                      Preview:WANACRY!....R.........<.3..e[..<.IH.....]..../..U....5".......H-..J.x..qU...tkO`.Q..[..b..iv..lcy.".3Z..g&~..r.a*.......O.O#6..:,..^.g....S=.7...~..x!3.......,<.q..F!..J.g.d......|1..}y.QH..D..B..v.2..#..>..2.."hY.'....s.:.a.3.]....~.>.9s.$.(.........2..............%V..#..Ujwy...T<0..$.....i..3.=Y..,.e.w....7..).$...7.GR@f....o-..U..f..MS..[.k..kvv......}...Z;....\..*..S#.|...*8.. .....$.k....gK....vr....f|.;-..#;..M3.".....&.0.[..J.B8.q..`.({.`..=....J.U4WHm...y.C..e.F.9......^.....`k5.z6)..j...2..'.-M.......^".^w.2....N.'.,.*a.y.....P.W]-.<4.s.eN..$..n.>..=O.B.l.e...:...o....GH.H.....}QTl...6j....c/...F..!.!..?...u.M.X....u....G..l...<.....B....f.^2)..hZ..Q..&*P.B..97}.Z.J.[[!....B.}.M;.<..h..E.....Q.}g!..x....7h...^....8.....w...r1.~a09..s.#..Zz..I.'.......?.2..a..vG...D.....x.. .(.#..F........&q.. ....G...qus.nQ...rq0M....W.r.5EZ.C..ml.-.Pyi....o._...xX..*TL7.!.....?...'U...%..F&.eQ....S.T..a.F}.s3{h4....S.....+..n.q....T.:m."h...h2
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1576
                                                      Entropy (8bit):7.886141822014705
                                                      Encrypted:false
                                                      SSDEEP:48:bk83aKor+VgpgLuQTPnGYIPiSh56eq1L8sSg:oialpgSofGlPrU
                                                      MD5:BE4BF9E6E8A4283CA74D73562F2358C6
                                                      SHA1:92AD143EFD95398D79EA269365E09293CC8B6F5D
                                                      SHA-256:FCF8CEFF63CE1EA02A1F367D3DEE569617D2B9A3EBB9AC36995F737A82F546A4
                                                      SHA-512:7E715A93865D773AEFEA854FFD26D282BA77840D547DE2A878055A71FBDEEB602E4E02894BD99EEE89E5C0FCC000330D7BFAD1F04FF7E92FAA98C9CE16FCD4E6
                                                      Malicious:false
                                                      Preview:WANACRY!......k..&.9..G.x.tS..e......6-...x.6..._..u...........e.^....^..G..Y`...j.fD.....0bF.......U..DE......Wx<..au.}..v.B...M.L....(N.[.....BZ....O..r";n...-Wf..:..,...:.Yp2.t..<..2..........s7.g.{...&.k..?d..k....R7..r....m+..]:.....0.......z..j.HX...............D...+....f.j..^4vN,..$_.#Q.....=......p".....}L.....//=.)..9.....%U....].....q.'sg.b..q3n./g.....JH...`..x..<#.%..1..i.>}...$n.Y.i..f.M<.A..J..Cj...._5Wy..J..jUK1?@.5.vg......f_....$q6..3..Iq'^y./..n...FF...t..G...!,.2....0u.<....+..4.....?L..&...B..........~-]y.......2..g...,.L{..E~d0+T..aGb3..h\..Z.]....O.....*5.l(......U.l...C.e...&...1)b..O,....b.d.....*.v...]Q.......o......t....kE..Q....$.;.}."..R..3.?.,.~............?4....U.E(9..7c._.. 4.8g..1./I.f.._.*5.D......{xE8.n5*W...e......_....._..)..-.....<...E.x..../ych.m.n...P.r...P...N.@..+`..._B...TOh2.^...&..G.I..>..&....M...`....N.;.^.....o......T.{.`r...:x..G ......:....%...(.......r..{.q.9z.,W(`...E....C..ph.5b.,\..
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):5480
                                                      Entropy (8bit):7.968936048449525
                                                      Encrypted:false
                                                      SSDEEP:96:o06FLgn3INwDOx8aepNASpVY8YJOPJrmGHVsO6sbuYC6gFShC2czo9GHSQ:oi3ItNeLvVhYJOBpsdRb6gUYzgNQ
                                                      MD5:2EABF4EC418FDBE43BB94F51952BEAEF
                                                      SHA1:F0BEEB6B1F9F0E9F22B2BDDB1177BD781DC8F012
                                                      SHA-256:5B2882E66BF1DFB125F5369A6998495227EAFC9DB95954F71E13A63922C7E72C
                                                      SHA-512:81985BE810C1F6F90F63F0A5985586F785345C4A0A6A6D9FA8138D58B53CF6B14F81570B9844262475650786FCF3C4AB38EF2FE3D1AE4E0014D651E05BF6777D
                                                      Malicious:false
                                                      Preview:WANACRY!....p..0.om.v@z#...6..t.k....!.H...W.O.......3...Y...]1..#.:6(/...^.&.....@.i..ar.\....W.....5Tb........K.N.h1(...O.*....P.j,...}.%..w...@.k....4.x~8.........e.^..Q1.o..S.5u(@.a....L../k6.....n..S.Z...0.q.M ...P. ...i/W.^!...t:.CQ.....(9yJ..E-.....G.....G........3/.l...R.d<-H.;...o.{...rw...[V.....b.O2.z!...H ..|.N.W+...,...w.["L.M..C......)h...?T....!.......Sb..f6..p9....H~l.../.c..+..X..5...X.W.!N...2j:.S.)...1_....~.I.c&..S/.....an,..=-.....x.).N.q....}.I..=(.[].....S....z.Z..N+..HG......LA_........rk?.^..t]DAy!, O'...Bp..dr.G...%l..Eb.%.5..%.4A.R.;.....y.2.6...1.e...$...E....L.e.&...P.U=..y...+..].X.N..._..E..a..$-..$zi..:c.....V..R..Y)..s.Y".3_.Y..../.+...cC..k.)."..n*Q*..L...O6.XU`Q8.....,.+.s. w.h.>Has@.h.....ZMc.....i.r..M\fO#,I.#.6^.a.xF$...Ay.G.sb`YS..e....p..:...'@.....0......UD?a.:...j;.|..+.....d.'......L..i/u..RwK.=p.wd]D'...dD.s.(...s.{.t.j.N.?.>p..zZ..$v..I+&..5.v>..5.a.....LW.......+._.....PS..../G..'{.....v* .;,
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.843270357359076
                                                      Encrypted:false
                                                      SSDEEP:24:bk2NdYUzriGZxl8m5BEjzA4E7wIhtdhvLxKJKATGqEQQ/lzOIbFxuLBgt5f3Q:bkLi2GF8m5BEjzA4gwouZhEHOIZxuqQ
                                                      MD5:754B790520DAFFE8139F494C2ECEC21F
                                                      SHA1:64C1872B0697926A9E6E87424B0A1AA20E1B4223
                                                      SHA-256:90DD6360D6D40737A9AFFF4AC90870C2E1494D007421A4222450CC41101C3FE1
                                                      SHA-512:CB52A258701A407E72DCCAB55A3D30A232E708FF69924D65B3B8A94D3F7E2E7369E4FB458A680D79449AB364DBD02FD111256067B0C55A1D5D293966547A6FA1
                                                      Malicious:false
                                                      Preview:WANACRY!....?z)....}.e.jd.,...$D.D.=.{...q...p8u.o...G...|.JQr..o./:5...<.s.%n..".TlN...ZT..{.........i.N.9....n.......L.g7T5..0..u0....$q.,3.5.gN4.&M#.B...2...G..Y.L ..;.L'BWo...\.{...@b.5....[.p.,...G.=....^|...j.:Q......%...qy....#~.>.."..-.72...xd..`..W...............Z<X.-...g.a....1F.....HT..w..q.i..Q.........*:...qJF..VI.*6.W...@H...&....z.X.'a.....~<?|..T.t...NH.iR.8'...E..ecUk..F......".&.>.o..b...G.4.L..k.X....R....R...C.'.+...!Y.4....fkAU#.@67.....o@:.....;:.v...:..........y3..L...Q......*...(7...._.W.;....$.X...".Uc.0.l..H.}4j...........{..\.,..1......~Ma.I.........H....L..#..f......(.......%..8...G .D....h..3..E.=.... ..?.)_}..B..~....Ok..mW.7.....|.P..'....[5...:.0.dY..-...<`..... W~..S..H.A%-.T.d..i../.q..J.].=qjH(...d.+9....i.J.4..[u..(.Dx...<x$..[tP..jt............?...\.2.;=....Q.>..:Y..l;...<<d.S.LMj..p.K8...>A.r.._3..~I.l.q.}.5Y7..JN}J5...h.Kh..zH.h.kU. ....a.......\.....N...u.=.Y........Cd.><+..q.?.4.#...../C.h....
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1656
                                                      Entropy (8bit):7.876501552252094
                                                      Encrypted:false
                                                      SSDEEP:48:bkcmeUGfJzJjwqxFcbKxkS9TjuVOts+bR:oPe99jwZbKh9TyVOtT
                                                      MD5:BDB29C0996F3432DAC168C78B5CA6356
                                                      SHA1:AD2296F77860D12970E6F4E079EF8777223FEAE7
                                                      SHA-256:A0840D0D706AAFFE0D2D2C16E10C60D325ED17CDC80610C2975899493FAA6F03
                                                      SHA-512:98D08544CA0E54A9F35451143C924593CAB17BD0C555C1F731D00DB4136E1C22B7AB62706AD1C30547818559253B44D19895BC8C3C22E0004DD5935B755F534E
                                                      Malicious:false
                                                      Preview:WANACRY!.....q....r.<+.......qG.^...=...y..)e.u{[.Fd.r. >.^..$..p.N..]S./.J.....5.>..w4.;#.x3#5.l.mV.~A...!.9..p..W2..Gh.J...p+......e...3R..t....._..1.gC.R.1kE.'...S]q......?s.V......2...s...]...Q|\<Q......... {b....'............l..%.....&.cI..`..l..3......Y........|..tU....,@..~*\...]....n.8....H..xDG..R.^...@.....5q.S...."_..%.O.^......7~...T...pf...R.#.K..w.'+A.lH..q..Q...Bj.^'...n^a....RM.".......+#pO.......HT2......4I.&.a..A.*.Zz.../...O....E..e..8.....@..q..3..1..y....*{.6...A..S.qZ..9?>.|....!...*...._.$.X......!.2.zl.x.T...C.wm...........!Y...B....".u?......q.R<.k."....V.Q...........@.>Kw.u...M....p.Qk.{...Jk.TD...{.91.Y.K.{4.>..3.y.(i.S"...^].[....8"..p...."X}...xz../L.;...Tz...b..cb..H>6?}..Ht.&-n.T....H.\..c..'....b.S..]..+..f......}.d..w.0...q..r.Y.N7....q..L.{.).I...#....|..4.8.....d...K..t.~".m.....uW..t..........@;UNQ..k.I.1..cq.x.'...Z\g..b..B.VH3... :..*.Vb.....$RW..=...g....P@._.......U.=+..c. ...<.....xw..
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1800
                                                      Entropy (8bit):7.890162392155771
                                                      Encrypted:false
                                                      SSDEEP:48:bkL9NagldkvUgLIXycnvXz8AVh6UMTDeut3neNpmG/v4MT6922+wz:oDagDkpGycPz8whJMTDeI3eXmGn4Ms2E
                                                      MD5:A740E3DD5740C67C0B07CA8C6ADA4235
                                                      SHA1:C46CF5E9E24B090CB085152BD6E648113CD16F68
                                                      SHA-256:4BDF5AC300250AE01226ED82512305A77C7D9AC9853FB8EBBA741537BD618F8E
                                                      SHA-512:A73E46ACFF895C701EB08BF7C48CDFEF0C179C9FB1B0C7BE6FC6D3A0A3C9C41D3080F1B6CA9A444A3110DA39368DFC666431AD77651E422D736A3ACF65712566
                                                      Malicious:false
                                                      Preview:WANACRY!.....dGw..H.(B%.+.V.@.1.}.2...-$..ar.Y.^.[.........6..B..o.%......bX...)....O(J..c..&0..O.sq3..~L..>../.{.d.G.....#)xu4.o.<!.1q.5#.q.]....y..f,*S....+/.H.....e...!=.)..1....p...I.x..G..>,...M..>.f\.].%..s8.,7.z.A.[k*@.y......Y^.T....S.)..9..N..V.f ...................v....c.v9.JK9hY.>Oqr.z.3........CK>...........@.....K.D.).n..,.....t.g.&.*......:....P..v{....YpD.xw..K...XV#B.....t.CK.......Z....o.8..f.../+.%I..!.X}s.....K..{U...kY.6<.Nq...$...h.+...H..4{....j.X.5.+.ow...^VG9...h..Y...r...:2i.xg#...(..._.....\...\....@_...._.!..i.^.>.ol..D;H8Wts.5.9O....N..D..o.,.@s..~.(..\..."*.r...d.....@.\4z.,y.i.L..}.\.F*...PL.*....l.mA...i"zS..n..r<..86`;m..7.7..6mV..u...m..^...p.9[...X4....;..y9.......X.*...L.ki....W.n..4",g.?.0(F.. .....,...g.....:.X.....B..>p...\.)..KA.....Z$._p0.:..< ...t.5.R....X........,.a....v.z...^..#~]Fm..9K.}T.%.........T.:8..$.....V2[.%..s.z.l.M.i)oe.I....Y,L.Y.!....._....Ss52.7.8.=..0..#.r.\pT.BAz^<...n..
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):2136
                                                      Entropy (8bit):7.893694160912269
                                                      Encrypted:false
                                                      SSDEEP:48:bkhjTLG/Lkh30x62ttPtlqJ070XGdFIgFzbSkHDa0oEmBXLDw:ohyLkpKtwJifIgh/Dm/w
                                                      MD5:ED0745AEF783149978AFDBDB21759246
                                                      SHA1:A8DA255F62A6917286D31BEC5C3F96AAAD44920C
                                                      SHA-256:765605E893E6863C0117D5AD6BEB1FE3656D11FDE339F8F9B5744018495DD3A0
                                                      SHA-512:933B29F4EE173CD3C8206CD1BA122B854A98BAC6DAAEA5E54B5FCBED79767BB78AE6D8C6BEB90FCC86EA17F924561DFDAAEF85FB74BFEC6B4B81D66777E1F005
                                                      Malicious:false
                                                      Preview:WANACRY!....P...!x.<..<.Q..`....$... ....r.k....#S.I.....p(I..g..._..n...L...H....A.O.. .>.....*b.,....L......f.+1._d...#.N..#....u....aAQ>.[....2...B...U..Po:..M.d.U............8....<.A.I....P\;S.T.1Or.!...7.T..5o.U.y8!.".Z.t..-..[t.K.5F..<p..-..Z../.y....7.......N.-..}.........eZ....z.}T...O.3.NU`f.$.-.{.uC...{.62..g...u].A0.dP........O....oS..R...x.$...K...yY>3H.INM.....G..PX...........Z.M&..........m.+.w......Z.2....`ut..........`x..c.2...5.rpK.-.m/z.....=.d....KyJ7s......^....C.]...%......4E~>-....q.;.#..ok.Y..|.?..b3|O.b...o.p....VJa^.2..h.l..q..C...ZL7HD3 ....&...X..c...#.5.. .....nR.j.f}..rbk}t...G...!.+.....d.Q]...y..g'..c6.y.*.=.....2ty.h...[.Cu.8....u.w...BNML.rA...].;\.z.Mc.>\.Yn..~k.%..R.I.Q.........HKh.A.D!N.O5..U....|h..k.....g={...7.s5.hG[...y..x...$L.8:......4......$..O..B.EO2U.C=N"f.,..'G.C...f,..9Z...D..Z.l:L.!._....*.{._...%.M|.Wg3.0.e..<.,2.-+.N..l.}.).3..m..A.=...g0}..p(6..W.9.......O5.,M..ql..m...9O_
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):5656
                                                      Entropy (8bit):7.968862403635258
                                                      Encrypted:false
                                                      SSDEEP:96:ox5wSf7BEVstcjJv5QAIoLBf1tN7hwhs6yl7dklDp5MFiaKbQvcOc4:ODf7erJeAIm7BHl7ClDp5MFi7tOc4
                                                      MD5:5A94E020FDDFC7F625E6EFCFFA002117
                                                      SHA1:1CCBB595540856DD6E9700E72A8FF8CE8FE3B401
                                                      SHA-256:C799D4AB5DDA6ECAAC8251388258375DF7ED0376286070C82AE6A210E9892645
                                                      SHA-512:111C169DB06F2C52352BD546BBB9FF7A6631084946797708031D694CD1FB25D5F14F586289E0000A5FF896E93C454C578D1E7503ECA6ED9A7D7E033F74D96127
                                                      Malicious:false
                                                      Preview:WANACRY!...."R......s..l.>..G...U.$k...?5.8....'+.K.....=^.BH`...~..8Eg.*<IBHq...K9@3@-...-.JB%...F.|.U...T4S.[.rb... .S$.F.......h.._..@..QP.e.&..1.JNC.:..1/.5*=9'./.P#,5....C.9.]0.[..X...Qx.-0+2.,..x.v.~1b..J..E.b..Aw....Q.C.f.,E...u.S...J.3k3......d...9..................@i..]&1..r.Z.1.....Dp...[.!Q.Z...S..de....!.....%......._;.....HU..k......2Y.|...."L9.J.8...i..nP..sDl...I...E.9" U...L...]$..G.r6=...P....5NJ~........<.......B.nl....g..I..{.......A*.D.....w`.Ea.m.}.....<..K. ..1T7.E.0.(..Y..@p..X...F~.:.L....`..k.W:.a...c.....i-.N...#.....X....-..Y.=s......"@............n..MZ..Y....^...4 -/..G.2.H~oA..@/....1...d....w..-..Q.0y........$......s3....U.@.G..Q;N$_..H..*j......tP@.......Z4.<oi}V</...R.A......n.1..t.z.{3;...c.`.-a....}.......Y.4c.......MNC..._@..[T..G..."....8...lv...w.(...-.:..aG..S..T^^.G;.pJ.....=L..8&....`..A.?m.....\.dU..19.. ......W6.@);...G..;.C<=.....J.$X0...Q..M.:.w.=p1B..1..$.:.9......n,q..e..GBHp..@.9Ce\v.8.....b.VlI...._.\
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):3208
                                                      Entropy (8bit):7.932812698596299
                                                      Encrypted:false
                                                      SSDEEP:48:bkugH6Vaa2w3bBbVoccUueRGvaLH9zoneMTVAh2fmgy7zljXtnBdQBI6Oq9dvNWQ:ougyf3Nb6StRonLTVs2tSz9XNgiTqpWQ
                                                      MD5:B4ED1B5D7176E20A0E8FA7A79567E714
                                                      SHA1:2892C5BCCD475946252C3D8FEDA02D509975F9F4
                                                      SHA-256:77C5B36492F9672B0D9EFF1C341FD6D65BACFCB5AFD65E923FED7FB0C7FDC40D
                                                      SHA-512:25222126584A8AF0E71249C3A625A7244A5AF4C711E05DC1716C31045B89D984073D9B96A0995EC4A37DA3E780323E284B80BEB2BB13E01BA19DE8C2C3A50122
                                                      Malicious:false
                                                      Preview:WANACRY!....Ckl....[..@...;.J$..@.....Q.jL.{r...+,......j..P....b>!.<~.mu.b^..w#.....I.?....W...&..Wt.M..xF..y..6..w....X..3Eu...Fb.w+.%.........{xZ..W'.b...n.Y.}U..~FL.H.r.D..C.......*.T-..7..3,L.g.3.F336......_..E..c..*KB.@]U..yi.$F...}P..!2.....j.y@#...8....g.......HY~E.;Q4.y.$.....E...9= .3..y.d....1.L.4....c..!c.jr.....j.&...h./../$.....de}.....D..A`R.D[g......OH....f....np|...w.e..~M..Ku....q{.o....Y.t?......H....zp..Y.j|.....8..e^+.YAn.U....7q..<U>+.1.:}.K.Q..#<....C..}.U..F..3.O.TzB.......R(."1..l./A.7F...N.M......h..\.Pg.@.....I0.Y..z.-5..&`.Y=.i...5.`.}.&.?.....,.qu$8..{u.n..H*(]b..7..@........v.,D.S....Y....-....n.Z....@9!S..2.....j'.....M..wp...H.3..@i.....b...U.T....H^..E...AC Tn~.D@..%.[f.<.k...C.pM_..S...}...h....!A....<.._.(j0.....Nv..#.^w.uc".&..8.?}./$F.L.K..l..........m.........h?.......3...p....EH|X,/...!...z.S....._../....O5...@t............Q..?W.:,@w.....iN".c.T..m......q..w.-6.P.....d........Z4,g.'8.M.0(...5...o,.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):12520
                                                      Entropy (8bit):7.986264339924282
                                                      Encrypted:false
                                                      SSDEEP:192:0dvfcNdlUHi8CioFSxnyWNy2BtaiJ8U9rhPRBi/9ycBXT94kLQ0Qr8TCUfP2JRJp:ivExU8/Mn37g8prhP+DXGt0uOCU+uEZ
                                                      MD5:7315D4200695739B6642EBE9086CC76C
                                                      SHA1:683B9DB9020F28A00BC0D30A1BEA870D9A1BBA2D
                                                      SHA-256:2D318A9E83EAD5BD7DB5DD5AA5BC1BFADA7D93EAC86F4901CC86D166CF7E7E62
                                                      SHA-512:9B85BF6A46B55B3B4DC562182400DFC737C51380FD41889022C02AAEE7C74D61E8BDCE11C5980B33BFB3C1F69F5A2BC8AF138F9D4D0F043C738BBB9660E1056C
                                                      Malicious:false
                                                      Preview:WANACRY!....!.F..e.tQ."=.1. ...X..S.>.........Y .>I......{.?..'8>..-.......zk.>..E..$-.)..|...D.E..X........E...-1f..c....=FDGT..?...Z.H.....F.D....E5y)B...F}...C..qh..9..0.&...v.E.P...M}).r...<..Y.!.."........u#...K.bb...n._o:&%Z[...D....U.o.(......Z...#.0c...../.............\y@.T.#.6.-.7..*......D....?..]....}r..f....F...^. k.._....:.`,..W..v:...........9..#.........Y..OB9.:t.........j.#..0.S...l.|E.;........):.A.......V].;.Ka....RT.b..k......w3W....h...\..'...7.8.I..A..^.}...).R.........r._g..Y...H..6...j......md..H..t6.)..d...\^..$g....0?.;_eiVB3v...NO.YQ........-....V..*y^9.dI.B.q.)<...."....%;.tB./..x?6y...|)"....:.<....$....n...\..'&...}e.<d..`..K.B..P%....5...6..f..j....~.j...u...~9J.........)....LH!.PO.%$7.6v..r6^..[.].(...2.....X|v+..."\.6n......q0F.2..A...+......%..N.*..=..0..rf4v..*.Cg.P.......=...z..$......F...0.I/...+C.q;.m.7./..lX.....d(lj.3.P....q..Zwc......u...]{...s...?.Ou.[...........`.6J{o;.R..zG.\@..S..1..S.mq8../ ..xr..
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1848
                                                      Entropy (8bit):7.895091280870794
                                                      Encrypted:false
                                                      SSDEEP:48:bkm/5s39Hrs/sS46x2M7i7Ykrhz9QfISvSPnAunQgtxxjVkd5n:ofa/5PI59CIuSPnDQgflVkbn
                                                      MD5:0586ADB36B675920BC22AB564D965A31
                                                      SHA1:265115FAD291A81BE18F3D0C1E452C9DCBC0CF2B
                                                      SHA-256:56BA4366A3AA0BDC84CD53B7872BE0B528EC1A11173D3DAC89DD856CEC896072
                                                      SHA-512:0461FC36983DB038913E08411B3462D8D2184146E0E935A874CC6A94B02A7E547D790287AEB58180763FC5ADC22FBE42A99CABB79ED4DC432E8D5501B6445309
                                                      Malicious:false
                                                      Preview:WANACRY!..........Z.^h.{V....pi.....C...........:...0..$)l.....\....u...]GH.(gu..a.3.....U...^.D&@.<;._.#]b...,).!......L..D"j>.H..Z-.z.?.......Yfs...I<...^.O.S...X>t.a.}#...`... t^.P..^2..e .k..~X...f.#.r..v..e......C..'.%P.OTA.$.S}...r.\....}.]Z..t.s.t.....................a.l.,.....y.Rkwy..;|(y......3(v....Ni.V t.5.,....?...=.'...C......>"......XZ.w.51B1~..(.....w.n.6..^&/...K.G.......h..P|/..f....)..O.,E<#.R..r..4.V{....s.z...Y.*Hy.}j.)%o@.....%....f5..=T3.\Rj>.;.D..V....;.S......`...&.^`.0.!8....U..7#.O~./[!...W....j..-..^..$...R......A&.sVp...........I6."..Ww.C...i...*J.:".}..M&...G.&...OE...%.:...1l?wO0...Ly9>.=H.M.A..^.<...z.S/..6_..e..C...^.........D.b._.XP,.7..}I:...>..Qz.78%.o.I.l...(.$..|W.>.c./...@.>...hoWGQ......I....6.T.....p;..zn.....xzc...kF}l.V.8/........S..T.mt<6~...Ku.."..w.3&X.....X<.=.U...h...}..JD...A.a?7.....1a.y.Z..*..{\...|..=Pd8.V..}.9.G....K.E...nG.<.)...W..`...Et....jMj..-).Gw..$R?.........os......o.q..x...
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):2664
                                                      Entropy (8bit):7.926543431372223
                                                      Encrypted:false
                                                      SSDEEP:48:bkTSA/0gC2q51Pm6QvQF5yQEGstNIUI6AH2uL7BChFTdE3vHuXyfBvR8ZPGLINt5:omA1CxDOUF51EG1UMlL7WFhWHuXy0AL4
                                                      MD5:2B02C3CA362B71A19CB68E926B92F81A
                                                      SHA1:0CDEEFDA34F4313AC3FA1B72E5C98ED37986CB75
                                                      SHA-256:419C066F5305E9F88ABD6570A8B8D4F6DEF7302A4DB2789D5833495629485CAE
                                                      SHA-512:33B879E22553CEDF52C4E036C55791369B579755517AA96CFF2DD4D1BA1F05FED203A11AC2C9E2C2739021C56083710DBB776D397B4EA62B00DCC3652AE0EA65
                                                      Malicious:false
                                                      Preview:WANACRY!....Zc=;.........|..7..r.B....Q.k%Y..{.1..2p..l.?.....9..^)D.f.fN.E..>.......O..m.......k........ij.....U..j.RS;W.9..hs....>sk.3..S[.Rf.e....".]....|.......jn.#...H...A=...._..3...F3..u(0....6....<..N..........L..D.tP.{.H];..f> ..l..@.\X4/.Oq.......M.........j./.B.t...y..9.yl.U>.l.+....{..<..t.....3......(.....U..=.........dn.6.b.....0...9...|.....`m...>... ..W..].......C.%o.......yO*|.....*)....f~.=..yC.Fv.*.5.9.U.....8..'/.p.Tk.P.....d.....".l.....qSX...r.l&.u?.Vf../.V....3...-;c+.u/.....-..\kaF..L...'...,O..B..q..~..3<'....1.....f...0........L.S(.............~...])... .1z.n..z.]Xy.}|.G]:...?.}.Ai...<....D.9.q.....2D.c.u....q.m...r.=...y0..U=w.IKi@......G...:.&>`.j..y.rW.st|...y..K......!|..r....+.....$f.bX!.".......g..<z...r7.h../....P.&..m]..~..e. .^..M...21.@...=....4gw....s...t&..K..e..H.~M.| 6....:l.)~...........?!.-....?......a..0..6..?.Fa..y.......B....yxr......%?.*..j...t4.o..9d.v[..>ZU....l..ej....xw.......,Km.l
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):3288
                                                      Entropy (8bit):7.940294157163627
                                                      Encrypted:false
                                                      SSDEEP:48:bk+pgsZ3TnFyOIPoD5uxQY8kIYLgi+nn3HmOv4D5BNFMAPZfHL4jGIc635kXxExf:oCZjnIboNjf17nXmLpkjGIc63pxjKP76
                                                      MD5:B0179E9FE14A06C7290A7B44D58D8EE3
                                                      SHA1:63EE94D1D91ABFAAFC7F9ED8268342DFBB460F89
                                                      SHA-256:EE608BC8071706CC51A217A939A759FBF824F20EFD9C8A37A34088C8AE6C0103
                                                      SHA-512:574064826F999F16CC198C4E79F5CCE29E88B0D7CAB2CD9B870B82CB15ABDFAB495827B0DDD9F138D9646AAF16895D4DA19B06A95FC35A719F929EA99A5E9B43
                                                      Malicious:false
                                                      Preview:WANACRY!....~.Z-"...Z...y_.?.6.A..........K..1...'.9.E.l..^...s\....1.k.'...K...s.&.f.w..a..UY...9vRo.....I#."_../lW{q..1]._<...{.m.......fH.U..2...L....3E..*q`...*..........H.O...T.U..b..\.+..F@...Kc.\#....t.v.o$(I=..u..d..bv..L.hBx4..ix'fF.e.e.Z._H#@................-.....4&&....<.q~.H..bBZ...n.o...1P....1..2.7^^h.$...du~.....<.N*MGo7....Y...>cRv:d..60......]oG.R.pkH*.p..6..$.;.....SFA..S.LI...R...5.w....ov....I....j...Rh...8n....\^..T.......}b>.x..&...."{x.}.'.Yr.....p....<..)..x..?.....CS..|...3.u.**.c.C.#..C..~..U'..T.T.'.?@.....P..K[.X..0.`...#hN...S..w....<o..;.l.(.;H.H.b.m.......e..z.A.....:..6@o.....e?7".....{...?..2*.tb.U4..KI.Fz..I...A.D...C.e..s.....C....X........".y.".bp.._.f..)..F.&k..0....G.1N..46..hr...& Z....!..&.3~!..|:.h)..En3.."...G...dU..Gy.Q.^.).64.......[...B.Bx..=.[.{..jt..._./..$.3T..b..8....;....eR.}D...ps..........4.....7..(....GJZ..<W\D..v...I....-...yIY...z..x..wm$8....N...)-9.wE(.46.JP<I..P!.<.?............
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):4136
                                                      Entropy (8bit):7.957678985543507
                                                      Encrypted:false
                                                      SSDEEP:96:oz184zCp+UQvEGNYNo5xJ1wHbqOEcDolC7ceV1:032p+FvpNYYLAb+M5RX
                                                      MD5:9EE1C5CD4DAACCCE995568CE2EA09484
                                                      SHA1:330DC625B00C2F6523B84DCE606069E8CFB1BAED
                                                      SHA-256:2D2CBF0490CC9EE57EE120E3FBE9B090DF28519D36CCC71D93FF86C2159230CC
                                                      SHA-512:B32C49D0167E3A85A0C08B26995867C1AB6528F8D25E7B5708F878FBB6F92B48E90136C60AB78BD4A755F0CBB69ECD83A45AC449BCE7F4A6D740229645F13747
                                                      Malicious:false
                                                      Preview:WANACRY!.......b.DJ..|.Z..g.eJ_.E.-oG'..7..J.m.e.f........^[G.....$p(..,.G...N..2CJ.....X.H..6d..4%<5.*.._...`.@..a^.../.e......y.f..@...l..qV........x....l..j6.X.L.2.4.L.h$.&.bP..k.....7O..[[..=..^..~w.{.._..}.W.O..O....S)j.H.l...&.}C.d....r.a.t.G....................0..5.[....d.cO..I.aN..&q..L.>..B.z ...3I.0rH.$.._M.%..jD{.qr....+.m..U.&...!.i3|uA....P..!.........^..<m1'.1....{Kq...:.c..;Z......@.2..B[.o..w..j/..#mA...'..d.e..{...XR.w.....>...v..&.\Q...m....i..,0f.l..v)C.N\.h.W@.+.^./.........U.y.....o.E..D.;.z......kwQ@..b.L.L.........:Rh..qG..T.MB.-/.....L(.7.~Ov.w&#..PO~..#m.....O6|..h..~..7..........Oy.Fl..0.c.i._.-..eU....H....IO<..D.G?.0..q.....Z..{TK...T.nl4....a!....1.a.."X#=.A.....'l....@....5~....^...S.....:...#...........m`E....|.$.K......$U....X).......h.5K....C%.p..`...;...%..q.nl#..z/)......J..7...\....\.F.#......2..........s.!0.#.3....=......T}.MR.....'<....BR<..xRs=rAq. 1tZ.5...../.6.H...M.m+af?......'..'..B...*I.Wp..9...I.[
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):2216
                                                      Entropy (8bit):7.916967685365945
                                                      Encrypted:false
                                                      SSDEEP:48:bkOk1z/fdThKvfE1tRlgQiR92NF63Os/hkL1IUb89OhuWGSrrvTmRL:otfpiE1WQRXLTYSrzaN
                                                      MD5:9F069E8772285F8AB4D9CCF2FC7988AB
                                                      SHA1:291E1974BF2A82575E905BE21C8E3214BB2120C7
                                                      SHA-256:04A1927992E38F6D575547093B862B0C89433D5CE814F37F404C6D6F99F84E83
                                                      SHA-512:F635205C1EF2AB2A81E1190D361E55FB632E372A4999EF3027BA3443951E843AE6C5C61404C9E47C12DF5727DD52E82020D612BC5A8AF1FBB8C475134577FDF7
                                                      Malicious:false
                                                      Preview:WANACRY!...........b.?....%...H..As...pY..k4...QyV=i..2...}.....O.."4a.=L.H....".r.&,...-...Kx...=d<.........k.+5..W..6..M.R..|.\1.~..i........;..[..u...f2.Q...(.v......E...z.....B...+.c.z<!.0m...g......hk1......V<....<[.C.U..7.+_.@*.v. {.zt......................$r....R.......!..F..d...U..{B.....j.f..n......N.wR.b.....e..M..8f2>1={.+...'.o}[..7',T.iKn......s...'....60.{....b?2oe..7.2..L.....E|2Pznfx...mjl.#.1.D.p>.....4.e..(y..&.1..........4}.Z`4$..w....8..|.fS.o"Q...8.f...M..Bc...<d8._..!..>......h.u4;...T(...%Q..a-...5..>S..@.hQK.g..a...V.......l.X9...{.(C..$.J.r..lT..iv....HL..E.....7......L...I.._J..`...L.W.....V.^.%.n.....!I.........lh.eNB...01$..6.eC..{...M.UN.~. ^...[..f.U"UN.wg.........]z..mKVi...v@....,.o...Y.....%@.}Oq`..........%.....!...K..!..@ND./p01.fKTT...!.=f...b.t.rn..L?.)..A.&........../9..T.tI..G5..DZ...B.=.qEw....;`.#a.......4..C......+..A.....<.B6..8_.4T.|.....^...H*(..7GiD..Z.e.gM.T.^E..c.C.R2..V-.\..&..p.....
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1496
                                                      Entropy (8bit):7.860975821247546
                                                      Encrypted:false
                                                      SSDEEP:24:bkye13+D5WMNmQHxkZbfiVtTtOms7XnRR8rCvJSBuLGDhdf1Em4tf2s7UuDZvKy:bkym3+DRHTtzyXnUAJSim4quDNKy
                                                      MD5:13D264CCA5F75DAC76D51311AE7F85C7
                                                      SHA1:894FDE1C87725F10E2ABB4299FFBE2BEFDECA7A0
                                                      SHA-256:2210232C3B1CD1C9945BFE0C18338F6F1557B6680C95B013E2CE5679992A3C05
                                                      SHA-512:E193BA68958CC5474ACB50EF8EE2768BB3E8328F87C95A799BAFFE207739517489064DFA414DEB38C6D2C7F4A79EFB7DEBCF84D332FA4DABC02EEDF6D56835B8
                                                      Malicious:false
                                                      Preview:WANACRY!....XP.7..^.Y..V6D.....U.m.ht..PoMi...1..M.o...X.&.z.r.4...F...A...W...q.!....9.+....C..y+....+..;........>..=..].R.N.r3eR..=Y.'*...:.=YE..Q.m..\.(h.sF...sa...&^.OS$e...$....J.IB..F..)N...y.....0..Oi.!.k..x.e........n..#..1.4.P..7.[.&A.....S...L.t.+..............t>....s......b.I..%..[......oT......e..jr.+~..........O..C7.[e..sM.v.P..A..4....:3..S..#......e.........K@e.^2K......V.G.`.Mv*.!.......y.?H..L...!w....B.......~.y.....s..8........Qs....sW.x..<.9u~ W.6.1.<...G...0O.=.Ym.D...YT.....a/...].W).....(?f..;...Q.Q.9m\zi.-...[E...5......ri...p......Pc.r.Gd>M...].Q...Z\..m.M\...|!O.,..2.!.F".....m.K.M ..W.....;5.?..;.X..K.6zO%A..A..]....W...Q..o.Q......t.o+..;......+.AK...C>.^dZ&z?.^/=b[..e......_..H\o..........z+.(.:;.|[.....t.o.<..#.)..h..L2zx..URP.A.rF...g...vyl.<.?..[.N.;.Wn.....i.HL.q...M;y.......k.u.<......."=......b...v.._....2....z....*m.AG.@.l...-/p.L....Z..6...p.1..?..e...a.....sp.. ...\...........Hai..W...9]...
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):4328
                                                      Entropy (8bit):7.961463562294402
                                                      Encrypted:false
                                                      SSDEEP:96:otZ40BYDl63Ny+Qh6Xz+OTqrR3xHstsh+c4goM6Pnnh0GIyVNGaA:ItYYdoez+OTqRksh+BgornhlF0
                                                      MD5:450BAD1CE1D7BADC8D93D9108F0ADB4A
                                                      SHA1:D6EBC1D386487AD6E3A1035F1E099692889073A4
                                                      SHA-256:0958297DA003A6A03015176E1CC6F495974F72853EA3B63573AF38AC6954D790
                                                      SHA-512:A074F7BA4D07088129C406EB55A1CF5818B59E9A99067A4825E97C539D97B06FE86052B5B716F2BDE43DADA47B1F1DC9801EB7D2D5FD2FCC015F14D42BA177C9
                                                      Malicious:false
                                                      Preview:WANACRY!..........b.A..8.d9..c.5?........K.}.....).qU..S..3.]....vF.d.......Z.!q:@...-...F'..."............y..T...2...8....j......@..91%...._.....M...@....+f.w}.4..yB...2%;...(bf.....7.!.s.U..I.....np...\ .. ......?..3ph7....~].?..,......O..N..t*...u6...`.................7.A.>....~.*{... B.^...6%..p@&a.U|.Q.x.'..2~.U...........O..>...GQ.6....w8.".[....g-....h......gu....I.>....c........_p............P.,..Q...B.W.v......h.M.0....T..A.?..cI.. t.4u.(61?.A....*w.Y.Rb*....@.%5`j....c....T.Q...N.)Q..Tx..L!/....Z...aIZ.c..X,........&.>.[..61.,{....F.H.M..i......n..!..Y..W.."..E5S...|J..p..W...*..G.......m.....~.5..B).f.\9L0.p.Rm1..eZ.1V.O._.=F0.`..qm.J.}.)>...)!..3u......N.\..&a.....H..D.U..n*....t=....M.....\B$%....C........8hZ....e.4.k....{.2<~....l>.z....Z..z..k.A..%.[3.7m&H...Ift<..$P>~....1E.f^.....K...ds.wPp 0.@.#i..-4.R.|...*..7....g.{..X..b..U...0..:..M+I.x..J....h.N/K1..%.......x.AT{b...4.8.>..4.X......{..$h..Mz.._./H..;&l....G..t.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1432
                                                      Entropy (8bit):7.858079027957077
                                                      Encrypted:false
                                                      SSDEEP:24:bk+da3nVkTH+APOrtm31INIQes6Q5rAFF/rL33w8z9dVj99qhG/AWo:bk+da3VkTH+PqqNIQesF5rOjL35z9jjU
                                                      MD5:5E0D49E911D6CDCDB1A18F50B5DB758D
                                                      SHA1:D200174E0446EA30607B4C08C7FB165D2206E13B
                                                      SHA-256:B9BB37740189C5C98F6AF0D9BFF72344216E2EA43E6D1BD197B14FCE3A82F522
                                                      SHA-512:2429EBE6920032BF30CBCF8B4EDD6E6F4D0237B71CC5F8E727DEC85CAAC63E39F72756C786926775F90662B58100B422E28FF5BB93FD4C59B976D5C5D9C5DB42
                                                      Malicious:false
                                                      Preview:WANACRY!.........D5@.....i.....Iip.!j..T.l.......!.!......v..Lq)LmL..*PD...DJI...}."z....^!sD3..-.1o.]<.D.u............v.....)\....i.Z......*.~...h.M..p.iElE{"...K.......Z@.B....$....mT.."`...[9t.M..~Q|.._......+*o6.}...R....T./&=.Kx~...z!9..?6^Y..|.... 4....|........\haY.....<.*..%b2.A..K2.D0..?.hOI..T@..H~.B?[O.z.].]..vE.v4u.J2:.X..m....Y.O..mO...u,"......g..L.Iw.h-d.=.Y.(..*.L.._....Z0.@f..k..#..C......".".*%Zs{.c.Gj6.\..I......M.!Q......../$K......Y....L.5.._..-GX.4.e..G.l...<j..Q...$7........n.1).g.K..+.......XL.aBG..H..`f..g.a..I...?O..J..;.......s.....;bL<S$.5...o$.m}......l.u............".w...Y....8.8n.^5.u....e......Zz~......o.....6.x.pNn..1D.3CR.V..3V.VA..cst..g/W... |....|Q..8.e...@<?..W...Y8.h?..o.@.Y...,..(.&=S]...nu<..'..f!....aq.'.$.;...6`R..9...(..r.W..M.......3...s...k....JL(..r...,...EH.TT.....Ye.yK(.S.\...O.....!.b.}$...t.....+.c...Z.~(g...`u...i....c.s.)Z..@..._.U.^...p0Z..W..i.'...-W|+.i,.l...K.....Y......B!H....{fZY..r.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1592
                                                      Entropy (8bit):7.869063361683754
                                                      Encrypted:false
                                                      SSDEEP:24:bkvOEGWPszFhJccTiKUwzPMlb1vv5rcqnNmkNS5YDrMCIMHZRVfYTCvuzG:bkvOXzFhrPylznvNrgtWbmzG
                                                      MD5:423252737C121EEE7CD79127A23CEBA4
                                                      SHA1:F3907DA534381C570545C774CE9CE608B71F92E8
                                                      SHA-256:335AF3E89FF9D767133EE1062A9AA0AB4608C51A6D25B5B0E9E335E885E5FEDA
                                                      SHA-512:6FC4E6982F8A59CF1881CECE703D6DCD83E545B7BC4F8BFF7A5DDD33553743A0F77CFB70A4BA48A062A8C55FB90EF9FD359997D9CA7ED1D739C30F03FACB6210
                                                      Malicious:false
                                                      Preview:WANACRY!.......Y.'.......G..z....Y.......D..@y...4)..:/.S!.U$Y.u..}#.6.(..x..M..D.C...&....v..+.$.S[..._..H.......X.zg."..@......".L......]sk.g`.0...3].RR...DX.0.y.y...7{|..]...`........1.&&Z..O#..4:!E..L...H.y.......1U...RUG.=rUa....G.;+.l"..T..~.f.............V.bL.x*eS.Yn..x.>...l..N.....PX...tr..,.).@[..h.Z..^+^..kz]..Q..x.b|(.2.<.... F..m|.%O.W...].}..L.3.......W..".Kq.+{...[W..;.X.k\..|k.d.....ANOrT.g.1.S.Z...wy.r.:..wLi...R..k..U.7..jq..^{.<....Dlo...r..\".l.r....R.!.......8'.@Z.../,O[F...cM........o.....<...........Z.W./..[........Uo_..=T..S.?.'.Qa.".....M.-.!...o~~>...~..o...3..7....V....J...O.@..w..;..}...;....\1..._..-...p...B.q..l......J-....[.CZ..!...2.OKX...5Da>2w.-..|..5\.......5i..2....A.k....nYW....~.?p*^.:.I].P.B..Cp_2.4V..../..~i... ....^.........U.o^S"../........ .B.....KI...J.w....c0P.a....1SD.0........U...(dt.F@F..W....>..(...,....7nf ..S...K@:.Fs y..q...1...[.h......G.Z...{.K{....,.I...<L..e...E~tY..q..N.......
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1800
                                                      Entropy (8bit):7.88572813697294
                                                      Encrypted:false
                                                      SSDEEP:48:bk+R3bHWadYsBsCL2P0muhVh+ElWyTRmA5U2jraUEUEn:o+LHWaCs2R0WyToA5U23atUEn
                                                      MD5:87CE2F0C5E8143014EEA858C7C929D87
                                                      SHA1:AA6EAD8B29410BE0006F26B2A5B78D3E43570741
                                                      SHA-256:20D55241CF85BD885270AE23E7F1AE63A13A39EC874E2A5345BB7D6ADD7262CD
                                                      SHA-512:D29C3402FDBCDA351484B6BC44A5BD0A7992A920FCB6FEA7695509DDF36FA92B96706303B9735DCFDBEA6CBAEB11ADBC858755A550B0458D11C0190B9ED51B9A
                                                      Malicious:false
                                                      Preview:WANACRY!....p].....@z...O...!..g.. ..........$z...9.1.=.....S~p..U.G..e.~3...N7.a:....QW;.A.%...bET...b......y..)..{o...O...,.^`~.R%..OJ.f..Z5j.!..g^~.b?1..J...J.....].c..|j.A^.o...\..?W.2@.0.4."Y<..4..u.....}.C....%....&......^......@K.......I.w..xR.i...%..............P..'...!Z.[tvE_..<..}........$.FJ...h..P....j../...n.8..GE..{1k..T...$tm..|.6J..;j=..oN................P..m$?..*/.J.g.L..X.0@.J......DC....f.0...ox?...QIP..{'..Y.....e..R.E.7...>..p. y.1..L.~...^a.$.p....'A.....e.......k{D....Y,.D.p.w.gl(F..u...J..'..H....n!.r..b..S...Q,.Z....N.<...$b..P ........J......^.7r......;(]n...?n.%}i%}..7L....Qd....E2f(aC.u...j.?5{..mi1P.....Z........#.nM...P..<.L.7D..C..R.\....}Lu.....:....7..9.7..Ud:T..=....8vR.|o3Yt&.O.`..X.....%..bCr....2.#[.5SI.E..Th..j/.v......NH..A.nA.:...b..mWr..?.A&|..u.A.i.$.:x...LT.v.$$>-i..\.i..:..c l.5.z.|.C.EY...l.Js]sd0.V.U.n../..L..>j./. .R.../..__.b.C].@.t:..Ks4I.[..K.y...y.^A...H..M.z....C..3.........K.o..y%U......p.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):2296
                                                      Entropy (8bit):7.916553676608596
                                                      Encrypted:false
                                                      SSDEEP:48:bkFqC8Wp4RhS8CRItWK/63TqRLIykSDY44fN1fimzvcTjJz5sEZbPcLQVgBxl8m:oFq/A4REZRIWk6etbE1fN1fR4Tx5CLQK
                                                      MD5:379BEE47F55DE05D8CE692D6D59C63F4
                                                      SHA1:E2812B0A3B49A66F4EC7E7D859047DD0BDD29C42
                                                      SHA-256:9BF0D6A9256CDCD04BF0388A62B543DE1449AC96169F41C275098B1760A19D13
                                                      SHA-512:044384E71F8A1AF7BEBD3327FA7603CCBC157178B82CB4A83517307800FF5649039FAF010DCE7646D37CD2E05FE9D697BF07567F5962A22B840FB71D53B36ACA
                                                      Malicious:false
                                                      Preview:WANACRY!....N....>[a.g.'c .6~..s.e...$..-..'3py...(......L..V.&&....F..#...;.^.2vAY;.d.0...w....,s..l.......,.........:j.z..7.EK.....=..p.(.~X,...|K..FM.7.mH.).7DM.........Q..3.j.#4..x........t...6..zC..H.#......2y.'g...e"...~.i..&=....N.....J....@iv..F.y............Q...gY....Uk...D.zy............. .K.f.vhC.L|.Xp..5..3.W..l..z...3...2,..,..y.](.....R..;{_.C>w#...l."..:...9.|....i.O....<Q..j.).&..L..p}pB.HP.7.4.91....`.AJ....u.-..+.....9i/...?X.PYw*.Z.Q...._...Q......M~.[Zq.>...|...e....[T\q.......[....Y..l..|....<.UB_+.$.....}..Ikf..|kJ..3.......(._J..Jv....b..Q.9...|f...h..X.O.m.K{?4,.JH.......&.^.....;..N.O./.tI16.;=X.....+`.(...mD.N.....#....''. h.q....u.'{m.@..x..G...'.V....C.&..:.N.../`..>j.L(..F..jW.KFb.9GFP....oG".....0{....R.s].=.q':T./.g^.^+.j@1.[S.Z...vl....%.,0....^62-;.1..k1..'.".Q.I9.k.q...y......wk...H..y.&...:G.N. ...B.[.mUh.0....S=..E... 1..~.....>Y8..R.]...J....L.....C.-..l..#.g............M.......d.G2.8.V1..d.z2..
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1528
                                                      Entropy (8bit):7.855628089566613
                                                      Encrypted:false
                                                      SSDEEP:24:bkAbz/FEgdv1tYM0TiARsjwckqcYYOYbhGOa8Aj+f04oKqjZTLT4Ii+ubGvhrBJC:bkKCgzciAKjwcknYabwT8Aj+M4oxv9Hi
                                                      MD5:66DA8CA3215CA32E110710D0A16E72D9
                                                      SHA1:B2845F5397D7A501DE7D889934C1936D66D784D1
                                                      SHA-256:9E7D33D1FA289BD2220118BDA46D3CAAA2FD9CEDA61C59056CFAF22FFD044898
                                                      SHA-512:39F09B1503DCE498E534DE0F6EAD8583E8AD9E2DDE75FEFC5903C83647E2F381DF8B20AC0BBEAF7D7F76EA4313A040F1983FD9587FA609A79E9E45A75AAEB2D8
                                                      Malicious:false
                                                      Preview:WANACRY!......#.....YJ...".....z.x]Ln;.."P..z...r..-..U.z..ZY..Iy<..Pu.L.V..:..|.^>Q....6Vc.K.Ri9...T..U..Q6.H....z...u.].I.......W......3.....m.z.[.5cs`....K.m}.UO............l......9..X..n<.O6.8....Y.....Y2/..;/,...ydQ.)X..'....tz>...v..vY..wZ'...>....(.W................i..Z.....J.@..R..h.8..NN....'.....?v..t`...X.883.U'....#.we..../..1.4....FA..........).uo.O..-#~ j=gApQ.pO..8.[.p.~=&..\*.K.[..j.{...,.<<?.".....CA...R'.. !N.?.....m...xSa.8....)Bbc...T.5#...R._.'.`n.3T...P.z...I..+..kU.m.W.u.=.c..X...y^.m....-.w5<.D.A.s.>.v..e......2mbJ.vt..~....{...&H.........eu.k..E.uqr...?7V..[..9..-.^(.W../+......+i..Y6..cvp.~...o.;.(yE..4.)..7..xd.5...I.'F.f.mL..8.O.W..R..M.m .I..D.iW.>..c.....'.7O.._...k...&z.B...o.....9..jN$.>.tW.....#.1~.!1%...I.TY..D.|Z..B.......K..k:.6..bz.<dS]][........H`....p...Y\.`hY...o.N..A7.5...j..A....l9d....+. .g....=.....X..r.....7......Q..........}]A.......F'zT.H....,.8.$...[.B.d=.D...g.........e.{.tP.3.......(..Go..
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):4856
                                                      Entropy (8bit):7.964248311322856
                                                      Encrypted:false
                                                      SSDEEP:96:omGy1bBaD/xWUr395GtgdZax8KTH9COPNdsELwsEs8l0Ia:p19O/xVp5ug/ax8KrpXNgTa
                                                      MD5:8318C9FFF88796126BF921D275AFB9EE
                                                      SHA1:F8BA649DB80F66C9F5F6A429FA26B7376B4DA679
                                                      SHA-256:C01DF982B8FFF6A36181E0C24DDF1C6014082B6C996A93205FF264026EFE6BC1
                                                      SHA-512:46D98E5353AC43CBE5EEA29C393FD2D43A74DCCB493A523DD5B935E8359D022ABA6C4A88FE6DCAB46DB4E4816F3F097A9B371FEB2CE2EC08153BD2668F62DDE8
                                                      Malicious:false
                                                      Preview:WANACRY!.........{.wZ.Km.........3.c<.|.>F..W@.... ..C}.~c..h.......=....#(.....(..K..*b..t..d.e@..U^..W...e..C.o.B 0..L^`S.F..(..=...f&...4.L..F...^...w..H.b....4v....K..,.....l.4$.3....bb....JP...>\..).......w*c.b`.#.kH..E.I..M..+.N\u..cd.{JR.x.5............2.9...^<x....m>..*-..#...~............u....S..ao.[p.-...L..g.`:....z...r..!...U.....7......5.....G.o..w6..7..I..$.."|..;U{.}T.+a..b....H...O./.vT%.. .....u..i..c..?....4]2.=...-...dB.W..H.n. $..'..E..2:.W*..G!.K..o.7-J..$.l......T.......uiy....2b.j.W.AC,G.4-.2.u.Y.T.J...............$.0u...2.$...AS.q...GD...y....7..&....&.^.9t.v......qjW.5`o.....#.zod.....u!j.P..P..l..K.~.................#.9H..c....+..+^.......hZ.tpH/.t.TXq...V.y...A..7a....t.. ...Kl...4../p....sFt=..F ..9y.^c?.]..By..P&_.@...M.B=...L..%...<..k.cI..{ z....OK...f..........n ..AuG.....+.x....XG..d B0k..E..ke*.f....:u.QaW..YG....2s.....I.V.W6....h.<..Z:z......*....U(qj.c...m...P.f..{..Jy.v..K.C....p....Wp.\&....
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1368
                                                      Entropy (8bit):7.853990204599943
                                                      Encrypted:false
                                                      SSDEEP:24:bkunILrbrwRutza5Z039mtRjFpbxLe6OAZYOn9kCL2tPIU4DWHArD:bkunSZagyvc6FZYOn9lL2tQrWHArD
                                                      MD5:0D7BC8B13F68106E3C9B7CAD77BAC5D9
                                                      SHA1:0279B15E24665635559327656EAD460CCC3FBD61
                                                      SHA-256:D724F50BE211B5E5A070FE9C30341D3DCDEFBD9730478EE615D4477F64EDAAFA
                                                      SHA-512:5346FF56A7A134395C494767A1D0DF9C92933FB33485095D31936613FC0DA4E2F2F5E1BB4B6A971B528D32CD3A5217B227598736F7A9ABE1477C1D9417974D32
                                                      Malicious:false
                                                      Preview:WANACRY!.....$Bpfxme.4..l..A.".j....P/...)...A.#/F^..f.u...e...FC..=..q..Q.q.?pWmF.. )..D.L.r.!..........-H?Ws...-uO.HBB.......+6%.....Y.....L..".....F...A,s..x.d.3.$...$X..h.....V...+.YD.5d..32m.._.Jo.rc...../.$>.u..x.{..C.`.."8.x...s...#...<.?..^pO1..|....K........@...........p'R.pg.|.. c......~@;...&.c...uOE:p@\.[._.L..).?.6/.3V..SX|;..o..n..p.U.9.1....@r&...+.[.. o.bH.3.*...A9..i$Pr=..@%.k..........;.(.I-b.T.(...}.......m3y.G{.o.......P....*`.p5....+......#I.,......4.J...B@...#.\".G.O.F.a......{aMB.....`......"..sSpf.....*.TjBC..7....QRc../..q.B.T.R.....B|.......b..>....7$...&...[.k.y..z.Yw..t....)...8.)..P"Je.....<j...c...Xh`..}.u\.at.d.T.....*...s....J..I....<.+.q#../'..T..).zk...L.1.R.<.?..|E....EE.].&..a.@..7...sr+.X-..(K. ..;...*@..._..p...].'..t.lZ$.1..ij.&.........r.P.........Q...g......"U4K..D..=...h.3".0.o.....p.....5\.6`...N.............C.#p...j..../....;.L.....z.6.......mkr.*H3....n..r.Ld.Q..E. .U.>.D.Q.b...Oa.g....:;@.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1512
                                                      Entropy (8bit):7.864185890016239
                                                      Encrypted:false
                                                      SSDEEP:24:bkzSlmWUSk2KGbMiqQWPQpNEjzrqC+l/nLfxhw/JvRlD+dxKURDNI7fm0GNh7bGL:bkz59AMiqQjp+zsZxhwBv2VNI7u0AdyL
                                                      MD5:DD00BCCCEC40D77DF26381CB56F0626C
                                                      SHA1:41D06FCFCC349A1A88121BBBBBD642592C9FD586
                                                      SHA-256:CF1888D7701C4644A32825782F1BD9402C976DAC185E6C91CD6F01F003E9B8C2
                                                      SHA-512:C826B18E187A964295EAAEE52E82C9ABB2AA6141A97EFF71B27701A5A8EAC7350D4207CCEE2E242C3B44E274E37C142D4CF0674534629901CA6F11AF779CDC9A
                                                      Malicious:false
                                                      Preview:WANACRY!......=Fu"..jt..'#3...].F..Ga.+A..x.T.S.",5@o..g.yd.:.......c1C...}J."...[.........0._.~..r..L..!ON......".d......%.....;=.....c.?C..J.f..r=..">.]..........3..2......xy...E.9.".U....8E......O..<.I(..OH........U..!b.x..\....1D.g.f.Z..0...=.w................Me....J.P2.......B.'.f...S...7\l.V...q<.y...l..cfJ...(....,......<....9.j0......\..T...d....FW..%.........%.U.g.`..g....bN!.....;d....t.......N.d....{...k..A...u.`.[_..u....d+g;....57...,.._Q2...qeP........P.A7.(.p.b.....A.lu..2.......U..v..p.K\...V.i..D....9.}4-.=..N.imW..f`..f.W.uM..O^N.Eqm$r..x...kq..Y|...v...vz...Acd.?......)...0....4..V\..+.l...r..J{.....`.O.Xj............G....>./>.zv...,...T.9...6...[.8...E..m....!....X._....*.`}.]..M4...eC].p.s..g..''.7@.....,...8.E.j~PY.J\j.....Y!|.J.F...m..7!...A.U...U.S.c.t......=..U...T..y.AE...eJH....V../.......O.8Vqa....7TF,..3<.@/3aQ<.V.[s.Y.k.S......|...Sw/..g~....b......S..]c.."ecWd.V..2[|p..l`..{^n....E/.....<..(5....D7\.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1752
                                                      Entropy (8bit):7.878249970131046
                                                      Encrypted:false
                                                      SSDEEP:24:bk8ncngknIaPZCKxskjepXIXODuFhuD1nnIyZ1MiCpRSrv+T3LUuHYL3FDpk533C:bkxngvSsLShM9Iyl8ROg3L6FDq53oZQw
                                                      MD5:5ACFD04AF61042183C5AEC514A9564C2
                                                      SHA1:4CF4FF7E1272AC7B8506AD1208E761FF98242E48
                                                      SHA-256:D55CEE792888F84212059EA3CB398731729406746B9AB25C84D1CBB7056116DC
                                                      SHA-512:EB0BA0AA556BAFE9D594BDC421F8AED4E4BB583A40C9FF15FBC0E6A029238FA44832B6201FBCA0C7B92A684169F7B0D357ED32555E243B0BC6FC7781A05ABE97
                                                      Malicious:false
                                                      Preview:WANACRY!......Ym6..../S.gZ.1.].hf@..qto.l..2.Y...e.....zr.... H.....g..AC(-I`.7..tA5U......u.o..@...L{...`.d..........?.3.t..z...a.........92.qn;G....V...#.._.:.[...S.[........;....sH......3............8..z.k.......0/.32.7.xA.......o....L...2.6_.DX.k.p.'..................5...G =8.k..g..t.3L_{.w.n....U...;]}`...O...`$5Sd<~5.*..3.yR..\Eo+.]..0..e...%..k...Z..T..O.r=C*..ru...4.{%^..>....!0.Q..w.D7..oP...I6...G./;...G....b..B3.y.6!..;.oX.e).3.i....S.t$..Z........}.'.b.....{..=.T.. |4%...^........m...v.0,...%/.R..17@.N}.-....9n.....J.....+t[2..c..gC.s5.B.ZX...B.2F....Z4..p..mh..}.PW.....6....l]....p..xS.iQ|#@".B^........E....F.....Tk.(...d.$M..4Z...x.4..<.*..u.BI....e...5&.......&.'e...|.a......1..r..,5...e-iC..w.f..F.&.a..w..eg'.t....6..rhg.....~.y,..:. ...cQ..5..)!p......?z{.${..u}.V*.%5....V......5.C@....#e..Bo..g..h..1s.......t~._.}D7.n...(o..S.<f..c.DD........W....F.rL;Q.{d..:."2....... .....\....U.u/..pp.6..d..H..5[........D.G.oG.#.K...
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):28952
                                                      Entropy (8bit):7.993439999190749
                                                      Encrypted:true
                                                      SSDEEP:768:0X2Q6LS18yriRBaXORWrO47BXdRw5Tc1eBOXXDiA:0Xf6eDr1ORcO47BXdOKjuA
                                                      MD5:050F9B2031D376EE9CEBC773EDD7B596
                                                      SHA1:860A82623280D0203EA15CC55DC6BCD744AB74A3
                                                      SHA-256:B1017BB894A9F64826E0F7A1BCFDA3541AF92C721785C0F7F97ABFAC62188588
                                                      SHA-512:8B3BD114FCBDC5784E550687AAF4C1A16430BF969018BA73A9997AF847D7C716E701D6620BF8AF76DC676FD26C0C9379E0CB13DF0F3B3585C507377A481229C5
                                                      Malicious:true
                                                      Preview:WANACRY!....c<j.4...4;.......P..I.L....[H...B........2>6.z8n.}d..`o.m.P.....|5..b0....e.~..=.e..*.M....6.l[...q.'G.t..E..[...)...y.~.'.=2.0.M..=|X...j.}.A..ag9.p[...A...w7.3|Ur...vM..#0M.._.^.)._.Y..B..61.....}....>.W{..5.ISv9..S.QW.x...V.5M.{......5.X..y..\.">.....p......;\.Q]...@.._.^.g.......]$..o@k...C..U.h.l[...8....M4.ot...O.{d...|EA.......V|C....Y..@..4s.8......X....a=...r..mYW`...d}$..d.....F.%..\).0="...v....t6.X.4...R.?....6v.v4.!......Z)...h..f.rb1A....~.....n....t+.b.?.S.Axj.eO..`.%{.ZM......m...Sf.z..S6%....p..f...p...r.Y....I..*!...!../.I.6..@Z+...t;Z.#..x.n/...4FZHWB:.$..7..w.>{..5...:;.mQ.)..eq.O.T.=..H....L+.v...`...s.coa...RVSR.q,.c.f....e......~.J.c...|g..~t_n.J.j=.d.1......[.g.Rp....B.....&....T.........'/c.U...}I.k.)p...V..../..l...1Y..A.(....$.4c...v.G.t...$..*..k.>>x9...Xz...x.%..cw'..."$?;.A[.M..[....'..P...@.......f...;..Mw.F3..X\@..R.6]..-...(.$..........V....d..#W...kh.....Z^xZ...T..j.M^........69H..o.Q.....&1.d.`Ib.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):16664
                                                      Entropy (8bit):7.989352982086615
                                                      Encrypted:false
                                                      SSDEEP:384:jD1v/Ge8Q7hH5DGEcYNeSvKtQe25Cqylt+4iIElJZGez:lXkOH5DGE7NeSC+eCCq7I8Dnz
                                                      MD5:226F14F6EE8087EB9E10586EFDD75A62
                                                      SHA1:DE9A9B9F5A2CEF7FD7B9F6759DA07FEDA2ED88AA
                                                      SHA-256:174AF6F205BFD091C967061C9806655489383FAB07F460CED2C3B4B1138BA40E
                                                      SHA-512:025B124FE6C01A52C8476779D9D889B0101CC86BB329A32D2C8B9047B075D6005B6FF8F0AB4982AA23DDB5EC5569A29B27FAE4D32F6B01854F1AC9DF8DFB22E9
                                                      Malicious:false
                                                      Preview:WANACRY!.....uT.8...J:t..>7....0.Xu.@{.I..C.7.>....H.k..h.W....Y...f.K...`=..o.~..g.........FjI|.s...E..sv9...4.(..Fnc.p..N.^.....J-jV.P.2U.Q...b6..W...~.U...!R...$Q>...2..L...L.f..U.....r..xHB.c.Q.....q..z....|...=..p..7...O...x.0o.v.eD.*....Q.a.U5;.i}.......@.......8...v._G....i0?.gh....S.B.R.p......J.....i.GDkA...... t(q..u..Zk.dU...wj/.8!..6k\..4...u........2.c.`....dX....C....T..!..oT!.+V).+ ....^yjj<.3.WO........,v....R...+!....6..x...?....6[_.O.D,I%ay.d.'.A.... ]..Sl/qwuN.h...i...N..N..EJ.!.).:..._..o~.+....W.v.....H...=FD.M..^.t.fgf..s(.5.^.r$.........+...(.._.z..^v..U..L^....8}.s.kn.;.@.T1.......\.'D.5...8.J.2x..:.@...m8...3.B#.p.\..S...a!-7.|Ub.5..uc...KE..9$r...<..;......<..d.....xR..@|.R...e:Z......t4.]Y_v."....J..K...s.r..+3.'..#fP...4...Zh..\.X..\..MO`._U.B|.W~..)..f.mUI.z.3...."p/..7.V....t.2.|gg..i..K7.....#.n.7d....q..a......%E.....$T.<nV.[.)..R..b`...8...&i#=.?.R..=...n.Pd m...,IDD$..K..=..r..J+.#,QD.?c.a.o.t..4..
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):49432
                                                      Entropy (8bit):7.996398843633125
                                                      Encrypted:true
                                                      SSDEEP:1536:wLrPRf3DAi4N0ymGO0bLjZp5Obqng7J3jKC768/nnnK:wPpf3DH4hmP0bZpkq23jp768/K
                                                      MD5:46F4E24035E03E98101AECCA7FBE67BC
                                                      SHA1:7CE105263627B6DEC044C3E68F2C7B80C299D62C
                                                      SHA-256:2B395F4BEDF5ECF02264F580B583E21FF201FA5E250CCFAEB0A7C2AE46E16766
                                                      SHA-512:253B5EE315F2CE4CE223E3E1573BF04CD257F48A6E3547A7E840BD78FDCAF162C43B259E7A7A69C868F110444881405DCB21050B14AEEE92709DC34C24A51618
                                                      Malicious:true
                                                      Preview:WANACRY!..........&.{.t.8......4.....6.gm...|..Y.....M...d......-.6...V...v......A[..A...`..0..Gg..|.._b...l!81.9F...s@..JO.B...)2..#.c..8s....h..#Jn/..7.-..A'....Q...|.....H......h;`./.<...:.Z...;...o.Z.../)k$*...x.#..?N..J%^k.;.x...M...6.n..T.xb..7.b.e...O.Dv...............l.E.g.Jh.. .V....5JNIU}.r.G........l..T`.3W.......\.qY.G..V.k......0b...P..;<.J..xs....\....Z...\.A?:............#/Ue...(.OmVEP....~B.oxs84U$......uh.&..-.....7....f.+...sJ..d....`.E.~.n...#.`....w.5.kR..........c.0..j.."`H.g...t.4....I..G....K.Q............?.Y..>...;./F...=.p..:..i;.....".#~QJ.ef.m*+.#.).......p..6.........|.g$5...NV...K...O...... ...]...(%.........H..b9......H.~.....E+}...M.....Il...a.......U.d....<.5u/....>vqJ......_.'u.].T.....w.....{.Onw..M.o.Xpq2....H.v...Zf.......A..-...S.3....s.\...n.....z..@......+.i<....j.:.\t..BBW..4.A..]).s7.......e..ek..M...w4..3....s...{../..u...B.....c.Aw.ba.4..$...`.&.~..V...x.RD....i.M....i..i7.EX.$....#E|..vS...8.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):11560
                                                      Entropy (8bit):7.982176206398047
                                                      Encrypted:false
                                                      SSDEEP:192:pFc32Kz1DMw5IS+WXdvkeghs4K5u4BP5+Pqcocy8S8tLvOX9Pr4aNNsZwR2mnItu:pFe2w1Ic9ghG5u4BP5+PEcy+LvOtT4aD
                                                      MD5:04E756B4CE2B77F8A2D4B06FFD6EFD86
                                                      SHA1:7D6729FB5506BD0900DA1ADDF9D98EF81F4EE9E7
                                                      SHA-256:3BF4E05304F928F229C632D3373CBEAD855D199F15D40E1266EDEC634D83DC19
                                                      SHA-512:C35C1ABA8A9AE8209679E2A1CCF2AAACBE6EA3F8869CD22E85B246E45C66389B6A74D50A11A4DB67D636472FCA37FA2F536F555877A9CC64C986A500135D25B4
                                                      Malicious:false
                                                      Preview:WANACRY!......GLi./s..*..crz...d....4.?.^..X=...k0...VR;...3.P.8.{......z..*..c...lb..a.....8.LB6._.X...G...us..E.yW...2..m/-WjS5WE.bFe..t@{.(........{..n.....!...u.z=T..<...Y.-.Y...o.d.....+...&......%.=.E.-.,..c.v.|.Ql,...p..~..K.JwB(..y[........5...c."......,......-a....M...tB..J.e1..@H.B..#.S.?.s.2..g.A......[.....#.......:.l}......F....t..,.1.e.X`'..8,..x.A.wg}..Qp..+.C_Pv.=b..o.xQx.....yk}.....*......Jrp...a.t.Ob..+..B.._:.M*.!>2.......).#........f].@..U.(...x.YvsQAG..c.......OmB..*c(....9i.Q.....2..y.<..(.t.'.?.O.=%..7:..`c.u3.]$/Q.TG.Q+".`..!.'.5Zx..9....>...#Wq...zZ6....qf.V+;....(S|..UO3z.?.#..+!..Ga..S....!...........R...u.uB...=....}....R...{..8..z.7...bR.F.8...=u.....UVj>.%......Qc...I.[.+`.7.p....!.N2.......`...&..y..z->..+..8'.0...'.FkG....=.%....d..2.\5...,.)[<.....q...e}j4fW.<.o+..N@'..u.......P......C...|P.L..."...U.Zf'(._%-.C...)..... ....\.Hp"...K...Y~...p..1..K.q..D.k....c........2.........D..|..`.o.)...|Z.I.......2.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):33048
                                                      Entropy (8bit):7.993468886496201
                                                      Encrypted:true
                                                      SSDEEP:768:hmc+taRYbDN19W+cvHplGjxjjZvptc4QabO+KGoaVZoKFLz3SXp:hma0N19W+cxujVvbRb1Xxrz8p
                                                      MD5:4A18046130A8F3B97AE7281DA65CF9BC
                                                      SHA1:E42163072CF50E4C3AD39A34C50ED47B2A9DA351
                                                      SHA-256:2A08420792C3D409B2ADC06CE9F38606D7C426799F9D583C191D889A611CFDB1
                                                      SHA-512:371C698FE4E2A5A88117D1E2DA7825B7B8014B0A8A2582A45C43C698A01D16D689A696C88E7B68D676F0E258E5CE29F577714FCF1154747DE55BC2EA2CA18E8C
                                                      Malicious:true
                                                      Preview:WANACRY!.....?.`<.Y."vxn.s/......Q.m.~.j=.C~..^...+).dhz...1U.....O..[...iy...W.-..i.>.Nh..JZ..kel....!.S+.0x.....V..;..,K.....o.E.R.y.....@*h[.$.u.l.8.i.!N,...\..`......P..........,..O.Z...=0q...L+T...g.O.-P..{...'.........z..[. ..m.....?.+p.9.V..5./X.1N..............xK W...z-v..}eDc.....BB...Q#.$...t}\.'v`rk..{A9.r.J../M.6@.9..<...%.<.....t..#..Y{.....tFL...G.Ur2..D..[U,1.%.e..3.V..@...-;.U..P4.%V'?..Zg..j..5\-`..I..h.Q.7:........q....7.2..&...")...~....qU1....]..?n8H%xF#.}. 5_.bVaw..I`~..j. ..2...8g...E:....Z.4F.h...f.....}.B(....0..... ...u....T>.'I..q"..f.!......byTo~..o.]...]N_...XE.)..=...e.^c......T\...d..m.....k.~..:.5{.rno4$.s....x..$.^.:.1.M....=.d&..G..g..j....f.J........d..].o!CcpS.-6|..>>.q].O.>l.K......L.W&.N....6..C.\),....fv..b.k...a....c....N..z...{L.N..%9..2..u;3..... .([t.....K..3.U..&N.<O.y..[).+.=.....b|.(..^.Zd...k..C..p..[0..:....w.J).SK#m#w....Y..H../.".p..w...a..^........Z;.....]..%.e.c6....es...(q.......P&ay
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):20760
                                                      Entropy (8bit):7.991394535790411
                                                      Encrypted:true
                                                      SSDEEP:384:3/3uMj8Z/uMN8dYD+30F2e06DkdXCk3YxVEfA6Wi9ar96R0y1JOSj2F1bP2W:P+Mj48dNJb2EffTAYzj2F5
                                                      MD5:C89521726BC9F1ECD896A92A863EBF5C
                                                      SHA1:2D1A2F27E29BCDF44CF980413CEB979F74741392
                                                      SHA-256:B159B4E1758004B252B3DB4E9887B38F3320681F2F8EE6D630590A7A619D666D
                                                      SHA-512:A7CD05C81946B6FE51EE9AE7080902DB474D2BC824C51F1D48CAF209EA4A796C8E0887C6EFCA1DD01D5B4C5957AA03C0609F5909D651051125681C3C94A3B675
                                                      Malicious:true
                                                      Preview:WANACRY!.....%.s1....|Z.u,[.R_.\.].A.Q#.4./.R..Gw..9.H)...O.. '..Y.>.9%.g.M..l...6(.i..."9_.?dp.Z..]...P....../S...5..".H...,.].K.*Y...>.x....o.X.Z.i.u...Qs.-.c.h%.....u..h*.E..Xo..#.$..T.....eE.'.....3..8...\j.)..Y.#.[.vi.?.u$..`6. .....j.[...Xv=9I;....H..K......P.......h..%/......... .Jh ..B..k.R..A.~...v.0..(.........\......g...GU<...i.l.P......PH..z...f.bf.oye5......J...Q...[.y;.j.6W.'...dqq....].V.]..2..?.'.YhLj.7..]5.T,.s..S....[C....._.. ..b.Y.4a9..a....X9.?.S<U..R-..%E]!.G.X.:....*d.)M....ckl..b..a.X..u..`/j(>......H.. X.E}....42D.:.As.G.y....V....sY.......;.u..H.4(DZ.N..,=Z..O.*>..r..8...|.-.......q.~..H.9.k;..9K.@..fG....`..,.)..5k....I.i..........4.4X....u........z...x3...G.2{+c.%.q...'./..Ah.z....HZ.F.vD.iL..2f..\...o....^....4.P....AV.4..lM....(.._.....A...'......M.V..h...Vw..97I...........j.P..#.\.Y....A..M...8.k-wB......Dfx2.s6.....)A}.=.'p.A...r.A.R.S..g...Jh3.+.Pk..|..s... .-.L2..."........["F.f....8..*.S...X...
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):5272
                                                      Entropy (8bit):7.964188251508517
                                                      Encrypted:false
                                                      SSDEEP:96:ozyjhGqVrl3LsAeAuOOev8K8fYod4SVWUdxFcEpVMvyKxGRubFDrh:8yFrRLsApuyv81fX4S31vM79Drh
                                                      MD5:C1C9DBCF927A4E2218171C43AEBC015C
                                                      SHA1:E1B4FEB6B78C4607A032F53F07671D5CAE1E7479
                                                      SHA-256:25DAA2F049678B08191DE3B71CE1EBC3D247BBBCABCE0F9F57E3CA02869D329C
                                                      SHA-512:13693B5793CD6FE4E281A0DE6A6E92B7FB0197AE39170A94D137EF3F5A3DE1B5CD44C6B24A8831BF7D2EDCB7A77FBAD56240022ACCFD52A739DB2D7D1C6BABD4
                                                      Malicious:false
                                                      Preview:WANACRY!....{.....n).N.....r.e...*...MG..VJX..f..P.o.V.~..3.W.;g+...+.'..dp...h....3.Q.8ts.gN.|....-{.'.#q..2]9>5....<...u.qf.,EK.........B....A.zRq...M....ZO....-....F..b.."..<..(...{..s.r.!'....h..u..2.....n..${...T...!.-..4.....L.|.'.M..#...]....c.).....v...............-.J.'...A... .D.C.S........l./l.....c..Y..f^....u.k/.:.Q.oe#.?......s)..S.,0Y.Y...ho.`.......u...3.X....%......%$p.Ys.\$.+t.>.}.....4VE..f7....L.|.#..D.?7....Z......=....u..S.,.t.LR....9|.. Y.....%...."......|x..(...o"...U....+.Zq~.G..N|/.q..%8K.....5...~:.Mf...2!.%....8GAS',"H..i:y..+N...../H..o ...~c...}.I\../.......w...R`.....c.j..|.^s.=Oh..U..hP...G5.....X.I.$...|...r...Z.Z...iX.. ..~. .....L5A:K0.v.w*.i<.|C...\.O..p..\...0/.0vU...Q.. =2b_.l>.V..V..nH..X1C:...B...8...y.G.v.....`+.~aN......XbU..e......G...~E...<..~....I....:....... >...^t8.y..H...M..>)....;.QO.8.....H"......R.jN.K._.".o..a..h...V|.VS.......I..-i.h.`..I.....,..1.3.......~N.V.XN9....g..(..
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):80552
                                                      Entropy (8bit):7.998001054010301
                                                      Encrypted:true
                                                      SSDEEP:1536:xW+1cNENlowAJnWacCB+lkXxLGXTn+lPCi+UgzhE5om2JTB70ZY:xN1cNAyqNlkhacqi+xhEGm2VB70ZY
                                                      MD5:43B0DF1888FC9890C847542AC98CD2CA
                                                      SHA1:A060AD8D45CF4322677508F2A127E0D5A3F608FD
                                                      SHA-256:35B6F3178C9AEFCFFA52450FE9D0BB4A3A59419216702C14B23F87511DD70EDF
                                                      SHA-512:F740152929EF9E6010640D03BCF4FA0119405E84ED832F46D47189CFA60556D6AFFE959C0814AEAE4458EEA00E19F05C3A43D0A512C3C1D525CBE2863B692E7A
                                                      Malicious:true
                                                      Preview:WANACRY!.....9.-.C....wr..|)..V|..a.i....!zZ...y..ok..J)9..r-...%.$..rX~[j.+p].."5..e........^.#C..`yo....x........<P......E.i..3....I..x:...;..R.J.F.-yoWo..k.....7..>......&m..Z....${K...$.$........a.P..U.H....`.xO.k.8{C...0<4..|...+........M8.kd.......d..........9......$....._...tq.1..Z.f...E...\~.S..0...Zm3.F:6P{............b!v.8..1.=..kg.o.z.v.5..Mmo.....b$w5...,C.q.....?..h.jY.,..nR..i^.@..|.Y..).+s9n...k.(f8p.D....3........5.."5.....I.h.B......z7..@....z.s...`.}.T.@_.....=}.].......}....0.)|....V......>..........^V......r...kwD......7y......zi10..:|$*bh.BW.u.7Y.....%...@..fx.u.....SU...,..s..Q.c.'..+...9.a.s.....q.e...a.c l........\.lL|G.2l?.2i.e..._.rF..r...H..?0..2....4..!..%..#.Ed..%....../z..(..O].)..&..p.-=4...:...t...S.)=P.{..N.x..+..Lf..W..2...V..=G.|.t.0.....y...U.+..e.j........$+.&5Kp..e.XI#.y.^0..Mq.,..j1W.avZ2...........|.......V..;.&.T...J..z..rO.!.....C0.KQ...Vl.dj..&..O........p..(o..P...j.;"..B(. .J>+....p..%..'3...2Z.....G.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):9704
                                                      Entropy (8bit):7.980818320524089
                                                      Encrypted:false
                                                      SSDEEP:192:qscINvYA1ZqzsGu3paBOlEHEcGiG8VqVgMPQi1wQF28wbMRAwRMLxkv78:DbqzK5acEHEMG8VcgMheQFNRAwRqX
                                                      MD5:D17446CFFD9BFB840B9E525FEF7276F3
                                                      SHA1:6799751B4D40F6906139F9624371C119A9A79F1D
                                                      SHA-256:2D1F5F3AA79217A50132D36CBC422B311A5D32D6B8464262CB1E55ED4FDC81B4
                                                      SHA-512:9232F4A75FB9D42305B77CEE6BB813396C27C4D40B14617929790DA12E647A9D1EDEADADA118A7BDAF8B2CE9574EADA31E8282B3190073C5EE04ECEF37E8C814
                                                      Malicious:false
                                                      Preview:WANACRY!.....I|[..L...3....../.*=k{I.p.k....y..X...u..E.Ahb.*..[y..w.e.`..P.0.h...@~........!..N...L7..@.4..5...=.0....$.c..o...WI..'.a..<.j...`~...UA(.;...v.....6Q...r.AvWN..4R..9k]ODB.y.[.-....&hRs.[./n......q..T{&..*.,.@|W.<..g.x.....|.6.p.....z.C.c!.....$......$8..2x.[:\.....lh..(.....&..#n8...1'..5.[.......K.BoB...x7....3e.X....SLa@..@...vW....WA.k.`"y.r?..}F..D{.x.7..t}k..i;.?...R,..PX..R...M?+...?.VZ.a...0GK.....$H......xQY.t.2..a..3..S...p..c..}.N>P...{..`.......:Ki.........,j....>...ca.&..|.e.....w.ii.D.C......Xb..k'...'...Q.....m.<y.$.D.\[.......P~r..z.w...e.w..>..,$...A..v _.@.*...Wz.V.G..../.....`.']...:....L..?.B;..t_Jf6.s....q.E.t.f.sBf..._....&....q.M....^..9..8......0........%."...gY.QgbH.2...$.y..-..u....4T*.2.=.*.<X;.$.0e .P..a.t.oq..$..&h.%Hu.4D...B+..}3...t<..3..b-.......,,>l.sC..!j.|}.o..,.73....ZA..7..I!...p..C\..M...P....-Ai._..G...?.`.....T....p)q...............8...6}r..1.c....oiY..!Px.t6.X....W..e..:Ur+.............t...
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):10056
                                                      Entropy (8bit):7.984092684629452
                                                      Encrypted:false
                                                      SSDEEP:192:HEX7iZwuKdHXb8JA8KDYmT+GorfPnmk7GCvTbvbpACgcHcHTdlOdr0Fv9:kXKB3JAjY1vTb2CrHczTOOH
                                                      MD5:5F375689BA8F80E773B1FBDC6D1F6B9A
                                                      SHA1:142103F629C9C5FB5F2ED6907F068783713AC208
                                                      SHA-256:DA642A2E7D1CA2AC8AA66E9A775825A85FDABBD6FC9BDD3E6226B5BBB621AF23
                                                      SHA-512:AA711E6F5984649FCBDA52168B0C1CA6DDFA7D4B224D5FF8815057F202818B63AEB0FA9BBBC9B736E73D5ECCC6B74E731FBA3C9573DD3D36053D5CF88F1EED1C
                                                      Malicious:false
                                                      Preview:WANACRY!....t.'.cb....y1.h^X...c$c..e>...|.i.].S.x.`..T...H.o....].M.....^R*.Q..H...|...M..P....W.Op.b..f.-T.|.....x.E.).....s..E.V..\Y5`a.....s........t.^K..D..k..~...[....VF....b6...}.z2}\....Vd.M.R.....].9.p{b.xx.....I...9/Z...y_.....x.-A.....r.....*&......D...S7.....Q.......D.)3.Ow.U..P....y'AD.l...x.#P...)..de/sa8..pC....D.g.w..v.GeU.5j.R"q`.d.z...=.<$...x..+f.|..ZR..A.....=}V.ZG..G..../,N...6[.....le.Ef.C.@kD.I..2X....Lt<...D.>...p7.&.../......,...1../.h+.).Z.yo."%..G.|0...Bp....h........A..R...Zj...v2v.j..Yuoz.s..s..F"..u3.6}^Id.7.`.S..... ...M..$....k#....+.m%`qq.....A:$e..G'w.dB....P[:......mZ......./....6....i...NMtsn.....N..r.`..D.<.v?.~...U?m.n......./.,..N..e.'...[.1...I.9:M.s.3...........7.dd+...."eE.A.f.3.@.B.......?..K.....C..._..)..\Z.c[...O.... .._..Wj..).....}....h.q..k.N.#...X...R....eQ..-c.....i...#.....o.1.j......S.....#e.4.Vd..c.g...W......H..uC..E.@...2...|..z_.x....1.*.....(.#...+......z6.).u
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):16664
                                                      Entropy (8bit):7.9892037478400315
                                                      Encrypted:false
                                                      SSDEEP:384:xdIVY2CVLw4hz7LKh6DbLimzthWKX3TeUorbkJQR:8d6LXh+h6vLiAWISUybkeR
                                                      MD5:3AC536B47BFA39FD3EF7FCC7074CC35C
                                                      SHA1:EF3FCFB586B76ADC78880C184FF47DEE0753C1FE
                                                      SHA-256:3755D2D31F3594694A0ED3EE05F87A3DF71474CB7CE8E06D47B3F6DFFE99105F
                                                      SHA-512:62BB851B83E633DCA951340D9D3B279E9D9408F7E4B0BED683482DFE51DD68D0701F6E5965FB8A002E0173B75DE35A557FEC93E1320DE977A7AE444CCC0839EB
                                                      Malicious:false
                                                      Preview:WANACRY!.....O..l....:.{/..a.?.0.........^.b...B...6..AU.8...,.....\..Nt..lhjT..F.q.c-.f.*$Q..j....a.#4.T.n.q..|N.....#...2.e...8..i.O.:.|.<.Bz_.N.........E!.S..;#Y.jcay3m.a|.../n6xR+.p...L.1.|..7..Z..f.t...B.P...A.....lE..\.1.d..MB.2.Q.&+,.B......f.[s..r.....n......@......D.t...Q......?...g[...Agk.!kYr ;w.)6.c.G."H..X...k.]2...`..F.B..sp.N. ."`...r.(*5..f...cn.....:.Y..y..UV.c#..d<..'.....$.'....L...=..7.98B!..-NW`.d.d.)..g.jq.=..|..1)e......{..$l....?7.....[6..Z.9nI...qd..\D ....|.G..... .G.9.....V.hX.Dv.7.|i.K..f.?...J...+.oiGz.W.....>.....&......q.....X...\.-......d.{.....M.f.....G...!..f..}.<..w.m.j.\VyN.$.%=(M.K;,.....s..4.!..q.T..WK...".1..d<..w....[..f....1}..;\n..G...qq.w.J\2..z=...0.73.#.`..n]-.Z.....?.....l..p)..JMu0._s.A%S6.>p.[..Wc.H.yz.........Q........x....|..%..3.z.....;..ST.~P!.....S..."..q...fE.....D.d..65.Nn.{....~..V.,...)..R.....2..:.....j ..[..n...;..U...p?QP.%..R......u..x.{.@.uh.....&H;..w,...........=...kk..Mv....q....c.a...I...
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):4376
                                                      Entropy (8bit):7.957019347669758
                                                      Encrypted:false
                                                      SSDEEP:96:o2lSKLmcwTmQv309AGkf7IY+dzgSbp9QcBMqhBDiuLhy01Dwu:hMKVQf09AFffeXBbhTVwu
                                                      MD5:D76A8E03A07F7FDDC1BB7E04CE61FF0E
                                                      SHA1:7F7FA8AB6834FD42D579E9A9E95E42E4C424D8CC
                                                      SHA-256:F94F3B710D4253BD9C731B776816CBA3DE7BD07ACC06FCD633BEF38D34D2DAC0
                                                      SHA-512:19E5B4CFC0B9F56DD256D8C3A4C11E72E5DDF3CA37719876F809360EE9994E4624C349B80C262A934ED3274D605839344235B33FE6FD2694E1537D6CC189EA68
                                                      Malicious:false
                                                      Preview:WANACRY!......."'_.!K.C.g-`.....G=.9.!D..7..@.../5h...._M..Pz[...=2b...8..h.4/9fE...@.F..k...X...S~h.....m...c;...\Q..DU..H.?.#..}...n>.C.#.\.I...8..W,..>..'I.J..K....S.#.[...........,...,~n.z..0MT$xD..G....D..N..uQ.r.)l..<.?f|q.....J.>.[.....,B...................BeJ...\..6....`.T.....Uv...#..+.F.5.:._.P....q.0..j.<.2..O..K..s.`.z:...`$u...W.Zb.1..........v....j.9NB..F!%....3...R=..l.o"......V.np.^.u.........;..#.2.'&..r.R.o.$g!...*.u....Z({-b<.Y\x>..r..&.P.J....Z........1.^nf._.l.G\.-....R..Hx./_...n../ru...E...........'...W...L~.;......\8.......D..K.....,.......k..[TU/.w.Z5......].pB.}R.y..e.f....X.s.U...u.}..M3mP....?VN]7...P../...H..z...."n.Vz.asbm...]..lu........BHE....Xz.9..M...cN.".J.. ..;.!.....s...`.T.hgk|iK....lY.A.L*...w.i..W...B..(<....-...........;..r..3t...i.^.....e.-&.H.Q5...I>.....mm.....mmp.>g*.....P..2$..Z.1d..I..a.@).m......0...Y.5yY.Z)...R........}..4A....(^.L'..S....+c+........],..`..y.....#m.N.`./..1W..j[K'....
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):80488
                                                      Entropy (8bit):7.997484749941876
                                                      Encrypted:true
                                                      SSDEEP:1536:bnn9dvxgVUtf77GpI/9VPeV2v5BvUV06xjHwE75R+sX8xf3T1ti3QmVH:f6VUtf75XPeWLvUV061QmbXiTS3Qm9
                                                      MD5:9FAD49AC7331B7B967300B52F4CD6D2F
                                                      SHA1:941B40744EEDAEC12F4A26510FC452731727C0B2
                                                      SHA-256:BD0EE6BF08C4216979F963FB74F603011133432293869281C7DF1634FDCAAD86
                                                      SHA-512:8A1448FB3903808C418469E7911E7C9A865BE8A34BB54F854C031F77E13B9D46F73EF448AA823DCD5745F59650D6CD49359D69DA56E0A908FDF60FB583F408EB
                                                      Malicious:true
                                                      Preview:WANACRY!......t.L....%..a......c ............e..HU.d+.......dx....].|p...........A......._...n~...Z.-......a~&cM..4..C......z{AE7.r<...2...TQ.s.a....W.y]...q\3C_.].m.FX&-$...=k....1].......O...>6...zbG..q3HT.8.7U.X....).x...Abv....*,2....... $Y./.Y....D9........+V.........o.l'1q....g...;...=.bd.M..;.[6..d .(.7....M..T......M....C...eY...C.}...#;G..@.$h.&..>.....gc49.YQ,...?U..F^..`..K......Y.7xhZT..5."....@....?.*.O!>...1..r.g'..Me1..Xv..D..p[u1lwUS.....`.W.a....6BSQ..'x..L..|u.X..2.Az.b.0....>B.3.l.p.?.h....{Md..:.?..s[.2s.\n....&../v.dU....l...c.,...".E...5...cL.......{....(.=.1<.....$,n(X...J.q.7.h.ue*.r.l2.n,.......;o..y.o|.I.OKY..>.....BK.0y8..J~/.Yb.t/}..d<K.............k..,p|o...RC................./...=.J..D..I...u.Kr >..../.3t..-i.R.y.m........#...{..cU.z.7..x.l&...~v.3..e...7.C...`.S.....6.7...9O..Q.-1....s!.7.L..y../....%....a..&%R..X. .........LK.m.+.(..Rmm......F.... ........r.}2.V....*..6Y..#..2...1....B.E...
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):11848
                                                      Entropy (8bit):7.98647993215199
                                                      Encrypted:false
                                                      SSDEEP:192:WMs3eMF0TgUXqf7bCT3JfnwWmcxkQu+HNtHyO/e2rl5Gkwy3SPSC4MkddKcU4Iu3:WM8eo0TBX0u3JFXKEttHyseA5GFi0kDn
                                                      MD5:997398A908ED77FD0E571072D65D1145
                                                      SHA1:ADCE4AA5E325EBDF778B0784EB02FECE92F199D8
                                                      SHA-256:142DDA4930DC9C10DE275E4BA67CD245A4E977EDB93A6D2E4B05621E52EB2775
                                                      SHA-512:E24B5FFFF1C756E9DAFA4A53B9E0A7823B46CBD769FBCCD51287CFA149356995DE2249A3B590945220441EF4F82ABC9A177AD1213EA1C0D93CD1B2C8EEDA1778
                                                      Malicious:false
                                                      Preview:WANACRY!....c..$\..N.f.D>7..........3..]...a;O4.2.........9.xd...^a..n...s.wjt...<Q.9N../[Ul......%..Xi.....^....T..?g._...Q0V....E.@...T....9..~..x.U...Un.....^4o.=.I^M/c....A....}vo..ml...."..)..6a.~.?.VOt.<...>l...u.O.s..%';.jHa.I..{.....Q,..C..vH.uD..>..../-.......8.ys.@x/..... h...+m...?."o..w.....=e..i]7....A...wj....z.....T.#...M.....h..._f...Xl.....(..=....'.|...b..a..<..K.|q.....G..*...n....H..k...?.....>Qd.?....D.."(1:9..fE.L.Uv.L.f.g.N../.o..._.^..4.^u..H...X..U.....V...E.p6+.Vo..'..%dJ..Rw<.JE.q..!..|....RmU2.Qim.`GHhtp.....J...A..r+..h..\....I.3....>...e.m...5O.F$\..!........G....-.PV.%.q..w.3}jc.XGO.1...^.5.2r.O"b8=.....~......m.$.&V...9...XoY.N.....h......^.B.Fb.....Q..}.=Q1.. .....W...s..b..K...L.....l.%.[...}W..XY .mMR..$$2.59.....-..../.A*...%.RB.S..**.~..za!....NS.Bx...n...27......L.}4..U[.....4...#g.R-y.3W.M.......N.[[.P..-..^..g.M..x.2..p.}.=........r...@.(....M..~Zb D.Mz....z..E.r......Sa1..~..9......m\.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1179240
                                                      Entropy (8bit):7.999880725276868
                                                      Encrypted:true
                                                      SSDEEP:24576:oE2V/AHk26cKOvgq87nFMmSqcS8FH0ve/wpAO+L1oHVhQIvJkHH5:V2CE26bHq6oxp+e/wpXX5vJkHZ
                                                      MD5:D1AC169426E641BCA62F8869578F880A
                                                      SHA1:C62397D47275A1C17004C9C5F1CC99ED051C7FA2
                                                      SHA-256:501A9A5A351A8D97EBE03F4FF1C304D607B9F7EB95300036DB35E3C5B0C4EB75
                                                      SHA-512:B162388A93A1A41CC12023549D7ACA0E18596AE98BA6D02718BFA7C0F21B18606962838EE33CCED31C8F6CBF8BFB83EC9308E307978EDC09E75CAB7A55679193
                                                      Malicious:true
                                                      Preview:WANACRY!.....*7b....UPZ4..J..jw6.X..$.14.l/.3SRJ#.u3:NtD.....f+..=....`...K.......c...,b.*....^=...%.R..m.hE.n.M...A..-Af|..7.....c.\S.K.2..sL#.4.}......<.~h...e..M}K.M.1n.F.{.../...^\hN..."....j.4.$.x...3.T.}.;E.p3......,.......!...+..b...U.*6C.CG.N`j....D..........84.......#.......t..."....j/.....E.(P...,i.....W..Y.?....Y....!./...b.e.+].W@a...v...P.]pAz.V.P|h..9...).l...w".....Wg.2.f..J.q.z.g..... >...X.`..0.8.hbUj}..<.G.c..c.[.D.,...N.d^.....%.t..a...?m.....9...l..|...g.y[$.*.....@.N..i.[.R.5..F&...+.....$,.9.Uj....._.n.q..o..95|o.WD..."G.i.i.AY..v..o...|}.).w.'.eP9..K.p.g=..)..#.$.cE......_yGD...#w&uJv...2.;P..."...xe.Yk..~.J&@u.k&(...r...W[o.#......{.m-..J..\..$nN.]z.|. ?mD..j.o...5.h...#q....LR.R...E..u.bM.........HI.D5%0.`...b...E}....r2;.......J...|...S!g.[.~.EB..xZj........m.2.G.......wmS.....Y....Q....j....N.C.F...p.|.o.....@.K......H....$aN....*.]...o.#.3v..P..E..d.=+....WR'..e*.4\...`.u...E.k........Cp.2<{.e..8yat..y|..}
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1010680
                                                      Entropy (8bit):7.999811413817516
                                                      Encrypted:true
                                                      SSDEEP:24576:Qm0oZoeFFZX5ZTZanJknWEOOoo+FHUjUbA1lHcDX:Qm0CFOJkWrs+FHUjUE1lw
                                                      MD5:C1B41F2BDE1602677E82130F092CF300
                                                      SHA1:BFC5F1D0D7D3DAC1C9C2B8B5C109D95991AA0385
                                                      SHA-256:7D2E0CDF86CE02F2A165C927186B1B082CE3AF30527A6F62C98BE4171883518D
                                                      SHA-512:60F635A5D7901E5FF6DE43F4782A08131ED3A9397DDB86B1EAEBB0D2C542FD515C182176C4A1A8ACB49914DD2D8914B0A6DCD6298061199693DB39468B11FD47
                                                      Malicious:true
                                                      Preview:WANACRY!.....)..!.9r.m....6.j..I.g.-&.........`k.r..!R...c..o.a....\y)!G._....Nf....."..s]........Zt.=.9g..-s.Oj.uj.i..p.,.u..n>A[r."...$........Z$).I.....\.Y.B.h.gB.s..)~...m..~D..G@....a..^+....T...[...~!..9l..L..V ......^{;JW.j.j..,.n..-uu.v.o.u.h......k.}.......j........d._rZmK...Za'..............|T.r.....TyV..C.............*n..u..<.[Ql.:...1N........x..D..a..F...Zt..8..O`g.Yn}.......TRz...j..p..3*.e.NV..\.J...G.]R\..l...;......+...D.:.......+.!:....1.S...s...x..SE..:W...a..w+X.S.Q.....%XX#.....y.6........Uih......./$\..Dn.Y..Ooa.w....1..p.......X.Wp7..'.....4k.6.qZ.7...9...f.{..r....!.).S.y;......p2.!KL...<U.'T..T....xq.......N...#z.Du........e.....O.&..9m.y9:...x..B..MP...aR.7.....q...1H..(..{...F.O...*Qv.K..Z...|h...wDl..5 W..U....x#.xA0.....x.W...{.\.....3V?..?.C..3.-Y...a...~.#.jc....u.6..3...\/.X.S..K..iBZ..)!].?..#.W..{ZI2H.Y&..)..WL.)..|G.O.K%...|.Lj`[].....MO.Ud+k.....}.I...8...1NU..H....}J{.....:r(.`.X._.{......s..x.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1042184
                                                      Entropy (8bit):7.999828020908294
                                                      Encrypted:true
                                                      SSDEEP:24576:+b18G5SgbdUIyeoR7EV4GpXZkU3mITHF0Kdb:w755DyF1ZG3kU3DTHlV
                                                      MD5:1D51C4EDD1755971A43AE80E41C21AA5
                                                      SHA1:236180FC61E20140CC440AD7EA75C1E3DB1EDEEB
                                                      SHA-256:E2C90394BFB741058758C26E725AAB3314045DBAFCE4E3BBEB0B09624B4EC511
                                                      SHA-512:C2223CA5E2130ED5E085619B6E96B3B02B4ECEE9D5CFEFBEB104B75DB6BBC7BD4B54D4A75070F4EE9064BA461B2EE59D333E46D5F0E0C3161F3FBE3EF3F4EEE7
                                                      Malicious:true
                                                      Preview:WANACRY!......M.#.\.......5O\.*...~._H....x@.E. .,.x.2..:.f\.......#.1...._.P..I...)P.bS&..........B+.._B..z.....I.$.hU"..S.}.^.v.?.H....K....ftP...Rju(.ly.R..K....lmv... ...S4..w,../.!..F.P.}..8.......5..2.D......n......N.h.....[....K.....Y.w...1.....#)............._.#..0.%...)6...gs...'.>..S*uM.G..+vDc.....LL+~...IgsdK,tn.-..&Z.G].......'k6b.G..|.i....w..)&..D.{c.zo..\..Lh.Hr%*..I...NX.H.M..x..*:..>g...J..*)}s4...L...3W..n.RuD....Ax..sN..2\Jj.oG./J.....,n.Z.w...V.9.5...%OI..9:V"tK.f..Lk.+)...ni.:W.....}.......#/........heFn..i....i.Z8a...J...(0.Y..wL.T.U..rs.y.I.......,....[.B\.>p..rB ....5..d....$.T)/.V..tN.v.9h.G~...[\...;..v.H...|..l|.2..F W.W\.....qQc.?|.6.|.m,.R........_..c.$.zX...W..xrJ...{'o.)..X.......AEC,5N{/........ ..r.(kkRP.x...:...K.....^V.X..=.<..)Dm....9 .^/.8.>..S9(.0M.L=...z.....*..F.C....o.U....#....b.b.Ymr.+.{.PT.Y# X..J.....$....X..P.,..x....FmC......$.a...X.....!.Y.A.)....`...3].\{.|....AK.!.eksx.JMk{..\...=V..o.~.~Gf..|
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1681000
                                                      Entropy (8bit):7.999887770300436
                                                      Encrypted:true
                                                      SSDEEP:49152:niWtVpQuWOjQG6VfQPx4Ube8GqX+PzCiOy4UYd2Gn:i0zuOjD6pQPeUpX+bjOy4HQGn
                                                      MD5:F23C49E0EC366726756B5595C705CC96
                                                      SHA1:E59557A5C5A17D1EE69FBD70FEAC5F5855879902
                                                      SHA-256:11B57C00EBD734151DDA73C8AFF11B8F018674FFC9F73EB93C781E3EDF172C4F
                                                      SHA-512:CFF6C297D201CA3EEE3636C6E95E2AF188EEEEB019B09512AAC6A10100007D9EACFB877CC3888E86449B6E809061A8FD87C8E1EB335D9BA286A314C777703D9D
                                                      Malicious:true
                                                      Preview:WANACRY!....C@.E.".[.R.....4.|.J..g..VJ....@_...=i..X9x....(....#...3.U....i...'.w....qjh..?.>.D..J..l.{..u..5..d.G@.;.....](.......,.h.:..t'.;.3+Z..k..V$...uC...JJ......."K.<'..2....d0...in.i...O.I.0..u-.'Bo.8.....x.u...:.^...:@1..i...L<x...#!...v.~.........K.......>.... ...r.\.}...7....d..u.uLv|...9!.N.C.p.f..RgH....).(..yANO.t......J?......v...e|G...&$}... .b...%.%}....B..8....|j'O.%...O..h.......}....LB...R...;d.z.o..@C=e..%"..af.}......m..wm..4i..S[}...}....s.p..a..K.<4.,...r.=5..]..{q.....?..V...~.....f....q.k....OY.y7S....%..*...b-l.?..i,..|...}.|(1z....%....i.y/S..E.T.sA...@..$s,$@..s.z/.7_..?Cu....y.d.B...sP...p_...!.YX.=... ,.6.ai.} j.....8.X.&.C.Hq:hQ.w.mr........@.D.+.N].p.q............y...sXe....)...?9.?O.,.V.....;.O!....@.:.O....r q....8.....$q.`/6..pYT_..`y..........`..I..=Q+..`Z....S.....W.0.l!..Fu..G....3~.$.~.\.A..7.".)|..h.ub...5~u./..TYY..i..l......~.b?...d...C.....}.$....L..t..Q..h5.Z.:qTJ..L.T..._..Q.[
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):80072
                                                      Entropy (8bit):7.9975740444406345
                                                      Encrypted:true
                                                      SSDEEP:1536:T/lvoar9GRanKdNxWcQ3z4JpX/Ph69PBpCcK0OT5iHLjFk3:mar9GgnKwhz4JpvPI9mQ3Fk3
                                                      MD5:309F1589850835978E7146DC3696F7F6
                                                      SHA1:19940DC5EE9AD49AC064E3B73B9B4B58314C25D6
                                                      SHA-256:223BE00C5CFA41CE0740B0711650B8A4ACE3EC25697AA96718D3B1B0059B0C4E
                                                      SHA-512:6E6FCD130EF830E661B72B01F11D86E040CB0304C418044A8D4E7E650BD9C7C5C38A834728CF7702FE35FC4B60299E7BB0CB7841A2D46C9E6DDA5526AF0DAF80
                                                      Malicious:true
                                                      Preview:WANACRY!......q..*..s$/dZ.&......G6.f.~Q..z....N.}..Fv&.j.#....vD....}..S.t'.....U.f..l*u.@A....M..{..?....BT.4.A...11..9.]...|....>...;.p<L..2..x.6 ../..6.c0....LZjbS.m.........".QN....>.'. 4k......Sv0~...|^Y..lM..b.....A8....0`WQ0.....;.....ZZ5.l....K~.....7......(.p...@4..... zTmp!.@o<......KX..._7~;..~F.%.-u..V....@..@K..3......(..jH].Z.6.B@M......].....fH%@...k....9K.5.v......Vw....(.U....I.~.@.ae..0[2...*....?dJ>..C...sk...Y...B.._{b.....c..*..&...o.b...o..<t...z........d...i*..w........^-.[..v ~JY.#.[..'e.'.rm...u.R.Q2.u...H?..T.h......H.I)..R.W.S..Bz.c.0.p..w....y...#.....W.7..e...tL.... ]..@rH.A...%.KK........4..\..x..im:.....i..)..G....~......NU.uS.J$.Y.}....*..-.....Se..46m....{LF.U...f..bbheI...Z.CP..H.i..y.o....Fd)dOY...M.....[X....>........*.R.`.......o..$Z.../.J78...r.il-..<...@....Z<...=.q......".2S;0.W..~...|.85l..K.I.(.^~..d+.........0|^..F$.p.v(r!)v..G.%...v......9..lb...W...=.'......4t..z..Qg=...Z.#..i. .6^R
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):988600
                                                      Entropy (8bit):7.999809499277885
                                                      Encrypted:true
                                                      SSDEEP:24576:P1wF1p1N5jXp0yotHD5eHNj+4VB7ygjtGHy0xU:P121p1NRZ0yoRUHV+8IguNe
                                                      MD5:402778F9CF84A7ABBC82103B8221E063
                                                      SHA1:D96B7A366663AC174ABDE2868E9B9F45E2E63C63
                                                      SHA-256:22FB1030D63E15E8EB7A5592A84A93B79AFCE6B7A246C0F0DC7D9189424F9FD0
                                                      SHA-512:4239202BD8E6E215E8B0BABA247BD970C001B75221F16046690CCC59FB431D79C0F513C52AEBBD8A895F9635674501C04C83885A9A8058778B7C029E7EAF9085
                                                      Malicious:true
                                                      Preview:WANACRY!.....f.D..=`.p\.G&..@.l.......?.....?...SwA=oFK...$:.*..?.qy...x^wE.M.5iQBk8.L.$..'.9=......MDG.lk.....w...5b-9)......Kk8.a.T...1l.s@)6.P...qG...wn.W...Y.N..Q.P.7.......S&...N+..%..*..i..tro5c...N..E.{..t<.....0.`u..W...&t..`.u.<.....5%.@.G...'..............c.h......T..q..e~jYal....pw....ky.;..|\.(..+....+D...y...\sw.*.G4.%...........:P.^QM'iY...>J~....E..V../.Ei}..>..cT'.A.]..F....x...z...m..1~........m.Ja.#.7?..~.......i.`4W{.Y...67B....@U.5..8.@..J..S..j.b.u.r.v...S.a..q<...+.l.o).Z..........5).....%"..v[.s.W.>.U..:../.Q.16J$..z7.~2..8........3p4Hu.'..2..Y..D]..._..l.{...._u.(.M[...@.1.... R.K.... ..Q0M..t...q#~'...|.%...z. U.S..I9U;6s_33.......(.Y..{.L.6@........E.).\.ns.g...y8W...L,R,t.Lx.u......'|...m..`.q...$.~.......&...`...M....WNL..:...hR....k.EA0D.2...x.og,..s _8...\.....C.......|.kZ|..5...Gs)..u..-.7]F......l.i....2nW.....i>3.!...J,..}...|7.....~f.U......8o].%..!M_...R.Ot.zi.m......(...........=.@....H*.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):5653560
                                                      Entropy (8bit):7.999966009962498
                                                      Encrypted:true
                                                      SSDEEP:98304:xGqCkShzWpQ/5mNPnon+klO8kBepetWFsjQREhGNM9mY3KvIPMH9:cmYuPPonMpCOWFXRKG29mY3Kv6Md
                                                      MD5:9C8C71B5BE3F6BE5F74F40D723FB36D5
                                                      SHA1:78B18A8F09868DBEACC27FC93F762B5E2536AE71
                                                      SHA-256:6FD63B06E814B75977D8BA13C07ACA10F717FF523BFCB187737CB95660380B05
                                                      SHA-512:7B302C6E4B8D1C1220E49ADC3F71C0CBFC67940F739AE00B0535B004CB2B58B7536CC58F82BCE5519A36E378876093617309268519B350D15B8CBCF26DF4BE51
                                                      Malicious:true
                                                      Preview:WANACRY!....\....F*.*G...PVL.g....|t...c.3..-.P...r..e..a.@.0...c. T.W.zg.......eCl`...:|..p...:...v..F>..r..*...V......wP..w*2t.,=..I.dL..IY.(..-.7k.....?`..@%^1/.%....A*[.}..".1:$.:......w.`...:R..j...H"8.QY........_........%....5m...Y.`../3i..c2.......CV.......g2..;.i.............0...V.zZoc...n..[j.'.u\/<....4..*....4^.>.W...t.^hS...7o.MW.Z..yS.D....".dA......GrT..Z............g..*..G..V..&d. =.si".m............`H....MY[@.n.MM..ie....?.A..6@.N....?o.'...S......GL1...o.)eEM.w..j.]..3..C-m.R\..d{..}..f....u....eC........b._"..px... A4.>U.../W.$t....G....MW.`. ......>...c-.... ...\Y)P5\.7.............N.g.....I4.S.A....l.^......d.95$....K.(.'..A...H.I..HS..e..K.i.......X.W..8w..1s..ud.......Z....}.M....)&.....{.8.ZH...=........:.......,.z9.......g..-E+X+Y..[....%..;<..13....[s......\.....2>./...83.X.[..k...N.R.V#e.k.=<$..->v?..i.z....'..O.>.1.F&.f..._..>...|..d.Cr4......-!ut.s.......t.....>.%SrG.+.... p>.w.J...K...dh!..=.....e.|..F.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):12216
                                                      Entropy (8bit):7.984213569704731
                                                      Encrypted:false
                                                      SSDEEP:192:8wNSTArsIVNR0WVb9+4d/ef92twOoL4IStthQtJ5:FSTDIbR0WVR3dwoLdXthe3
                                                      MD5:F889C9ADE14FEF18A53532D29266EEFD
                                                      SHA1:C8C47F54670A7C657D6F5A3F406524E188E87182
                                                      SHA-256:34B804FEDC687F1AD03155D99F8BF0A495E502CC140193EDD6A1267029C5AE67
                                                      SHA-512:65C5558AC4221ED45A14094484387F85032390F5D75A99101E2ADD2F2F696A0ACC4E3DFB876D05FE52F0296738D1E388B4B259E892231764DD98698AEAAA79D9
                                                      Malicious:false
                                                      Preview:WANACRY!....2..t.W.#.+...q.:.}..<.x...O.z...c.7{afQ<.s"=)Q.V.f..3...Z......P..3.Z.Eq;3....F......1........)..`.}.u.~.t.........)......s.8.........{bFu..M...._..._.[...I2.....N.E..V,..>mn....L.L.....X.YX...Us.._k.5s..3...F..A.....b..Uy...<.~.>.sH....g..u.9.............gPn.2$.."....A...m...G..1...B..+.d%.[.c.-..Na_.Rgg...>.$B...f..>.$* 0.>...y.l^U.3*}......y.Z%.P7...6.;.....d.9R..-T.[....=)S.Q~.L.s11..=..zs..QJ...UX.../....-.s.L.in..`.N..1ngy.?N.+.hH.n...6vj......@.0tk.g...^.9......O.:.h[.2.7..P...Wa..m....p..)..S Op...........A..q+Wp....\s.r ]./....I.f(...s=.?..fU.)).s6...cEI6........L...N...n...|'..qS.l.>."....,N..V.Z.-.K.C.>.rr.. |..Cgd..:.(l.....o.V?O.....r/!.>....R.."...E...@..7l...eY:+......m4g.cUN..f.u>I..l.\h..=..,p/.r..q.|....y.!..x@X....G..=.d.ao..1.......O).'g)..Vj.D....Q.3.4.;..R......,..em".....C.T<$"...>M.u....`..e-...(T}..<X.V'..3T...b...[EB...I..$K...S........`:.89.tz>....n.~.S...V{......&.v...^....p:..cAX....D-Z.r.....%..<
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):358056
                                                      Entropy (8bit):7.999430995631548
                                                      Encrypted:true
                                                      SSDEEP:6144:doyB8cqGULGaExbSzdIpB9if75uDMfRdShWYo0oPpHY1HK:doO8cqNMx+pkoT5u4pdShDoRPGJK
                                                      MD5:8C3B85A48E71E62CE227E663C2733A51
                                                      SHA1:F8988CAEF4B7A82B5C5D878793EE4DA40E5293E1
                                                      SHA-256:CEB7D1D7BF0493E05C5BE7A8CADAF403E2CD126584EDB22C4BD41BADB325A5A6
                                                      SHA-512:6CF4F03524CE4129B1F7F65DFC3CD8BF06E9EAB4F3223B41094E9DA7DA434A4AD15EB2DFBBB9F2C96121368DA38A1ED529930843FD1D36FFB35CDDA3D82422CB
                                                      Malicious:true
                                                      Preview:WANACRY!....=.,.F5.E....2..._a6... ]...ZeU..+B....I...O..1o........^\..:."..@.q.._.".z..N..M..+.^...}.P..Lg.3.`..[/...J...@g..&...`..D.q...z....xS..,...)..D_._02...F...\.8J..=Y...$.".........j?..]`..1.\..0meR.=0..$.....'\.H12... .)."..c......,..7...r..<..@#.....u........>....X\2./...R.y.^E!.3.:y....+.(..=S.*D..8....T.{%...X......U. .....-.^-v#..Z.l).J.....-=-2y?4l'h_I.........P..2}@.....=5.DC.o..b[.m8.....a.%.]...{.G.......iP.,).w.f.iE...........#T..1]....+......%...X...>.j...&m...L.!.$..?..8.l]~.#.]....v..OMAv.?k...;.....R.t8...o.a.o........i;....Z~./.i..;V.,....if.VM:..?.... .#.....@.\G$..h-.c..-..nwqp.;.......Ya..?p,.X..ci..Q).".]..X..CbmX, ..nk [.*9.3....K.....d..._.)..CI..8c...i.2.I.;.O?d.i...#*.s(.....(J.=J....3[....c.1.......v.T...I..D...*._..*d.J..q/(.B+. .d3S..F.....t... P...o....l.._Q.tx.....}...w.}&.....h....O...^...nNl.F([.Ba.z..-...@_.O.z...P...\..r.D9.K..N....l......48.2....$.b..8bv..o.i....w...T..{..x.^d...`...n.%..n.I.{
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):4552
                                                      Entropy (8bit):7.9571143547920995
                                                      Encrypted:false
                                                      SSDEEP:96:ojrY+6elKYv+UOZe94xkogx2boK2xQjjd8BWXQlMtQxmjNXPkyn:+f6mbqeax22boajGBe+MtQxOX5n
                                                      MD5:DD4FC085A9018EA606535FA67FF71453
                                                      SHA1:0FBDDE24C0EEC0D8E701DF672285C5F955AB91E4
                                                      SHA-256:1E73BCC04BD3DFC44A91B8E3743009E6493CFFCB6AA1A6BE55010BCAC4269EA1
                                                      SHA-512:C29F139C63027BAC861D92FC8A4682623FE84A46046DEC29039870223F5ABB15BB3C844EF1042A6170E1989383DDE324A7798E2650A75AF19240F4FEE6743149
                                                      Malicious:false
                                                      Preview:WANACRY!....h..+\.8.gb...yp.Oc..V..N.)L..F2[.x....u............x.25.C...\ .3.}. ..@=..]..,t..69.....<...t.t/.:.....g.,o...c../....",...P.-;. .D.'Z.=.hy..........0...k;..iz)..o>p}.BX.=..$w.;..w,...3GF.&......S.t..[...F.b.M.&......O#.eO.._8.....=e.x..^C;Q..............5....M..M8.82M.v...9".F......PPX{.p....o..B2:..{QJVQ5.<.fC~..Bkz..._(..<...D0.T....<&q.4....d.sO.B.3..p...S..G.2.;.F..=..tn9.s.X....KmL...r....A.T...c.....n.bo4.ZB7..gJ.....S..>..%..... ?....!.US..].........1p..O.tb.3u....hy.)..C..eF.....o...6.....7.d...+V.m(.5J....wU...K%....{U.)..S..h..v...........jqW..bh!..LHIl ..QT..A.g....6..Fi.p.....V-.pu.hn..ym.h..s....'e.|...~.o..?.jt........Q........W.....f.q...*X.f....e%?........J.l.C.ph......;..........s.....;..X.f.-.E.m./.........y....!..j=.....M....,.....\.c.....D........S)>........,Fo4..?j}....#.......gn.o.k.).V.o9...L....XH.8..h)..[09....|...`Vl...U95>.......;.l..x%.m]...k.>.P.b..\WnC..\`WQ[.......\.e,E...?x...&+.R..$..f.!...nc
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):5608
                                                      Entropy (8bit):7.966747709888233
                                                      Encrypted:false
                                                      SSDEEP:96:oIaITH3Ox55HhfFmkZDnK6aER9zW0P7DRIfyduQaIGdbxWUeSL7vg1KWAZvxNdQ9:/3j3k5jLpK619zW0P7NIaMQaJtxWUpLU
                                                      MD5:CA8862AFB7CB7A09068287E53B81DE0D
                                                      SHA1:21780AB722D5230D8B39977A495CED7ED8271524
                                                      SHA-256:8AE555E4AB58E8E8084F38295909F11A6EDF03B51D4BD91C84BE5BB10B5305C4
                                                      SHA-512:31349D41EA9489CC660A180374807826C0517B1B580F393F208103E3ABECE35600457A951C8C88EB9FC4AFE086B6E2B50EAB4FC2832A1203AB81A0D3F6A42449
                                                      Malicious:false
                                                      Preview:WANACRY!.....=.?d......-(...x....B.U..\/.Lhw...@...LP.4K.. .E....m..x..o.[..E.&R.I./..D.k<9Ij..b"Q*...Q.g.\%.........1...t_...g....<Q...$......L.f.;$#.v...%*.p........Z.B!e..cY...'%`|D.X.....y...dxn"`M...A.e...0....M4hG...'..[IGSw..K..x..I...:......l.P...............B.$.n?4&.\.......7...~...K...a..V.p0..r3....)@)...b......P...#K.q.t..},....Ia@...J.cZ.:..ZV.xQ4...M.b....?B&JO.}.e....dnn....7/...9n=(.../..`..L.$......X...Q...+..... M.ey....#d.U)H......]jQ...R=v.yp~...HH..e......V..`...G....sF.{;..c.. }hH.mI...............S.M...n...........v.b....`w3&....w.....R..(*.l..`..u.3^.*.....<...P......z>.W..U..YM.'.6..Q[..U..q[w.<`.5......DM..w...b.x...bj>.c.S....).XC"t$-.n..tua...l...(v....,....t5].;W.L.....A.u.B..U..$........2i.O..R....2.s..U...PpJ.%.p.('..~....^>0...gT.1.N..i....E:?T=.<.eq..6.,....7.......X....v.m../F.....x..O0L....O]...yF....cP6....).(*..4..F..........d;Q.....!...)..hZ.N}O.(E.$.0........P.-.Rt:.".;.W..c]@...!...}"....4.......
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):2696
                                                      Entropy (8bit):7.92545666872912
                                                      Encrypted:false
                                                      SSDEEP:48:bk6xPL0cl5hB3dmDLmO7vTQ81BdB6dV0uhTP6a8eCtIKaPDRYCs6g6H26r:ogT3LB3dsB7E81BdsdTTCeaaLas9v
                                                      MD5:0C3FDDD23C0895D7B37CF2ED6C77E023
                                                      SHA1:559BDFDE17299D56552AB6C014AD20D27B9A9DD6
                                                      SHA-256:002962A558BF2B02295E9457EEEDF4DA2C0FE50F6B50C50F7CF159286DD9CB72
                                                      SHA-512:BA6FFA06BF67511ADBB8243925BB61B568768C44306DCE140F61BAA1D4E1CA8E95CA7EC1410A2CEBB8F37545DD2137C8C72F936DB26C049E81E9D0472B888E65
                                                      Malicious:false
                                                      Preview:WANACRY!....6.3M.M~.!RF.0.....<...3.X.0......nO...1"E."&..^.......T{...-?..O..p...Cb.&.v.......I......dE|....|...I...fxn.V....FE....tW...,[.O....K..v$e/.b...u.)f.6..J.7.:......m....6..-:{.J..2..o....Mo~e,xv.s.~....9...1H.......Z.....x.b.I......#..........g.......'D7)%..N..0v.......}.....X..E.as..3R>7....E..&.l;.~.Ll...L...`.q5C..h....&.`..3>@..ia...p."3Hv....#q.,/y....../...g0\v.(.^M.."w....%......bwo{..?.p.&.....x.#..7:s..:...~9v.....M)..7...H....@.u\..G..t1@...@.aE|.*.R.......N...@.'O...o=....'-'... ..?...^..!<n..Q.Y.d....8....`1R.r...Qt...9...38..I....V&V.^fE.o.g...O.>..8.....R...p.."k2...9.|3(L.B....xQ.+@..Qt..P..H.7..X&.L..g..>Y...... Jt...hy.....;.%...q...:./..W.H,(...."..%..'p.+t9.2...13.6../-.3..c..yp......-rr`G...-.G...pB........z*.Y(l.9.Oi.......z.q....[....A.[......tn..R8.:..fE..8...r#b.M:..p.....0...7T.Eoc....I....M.K"KaW..B.......f.....]}.y...1.3......dI51..;.F.m.;.G6..S..Zw.z1>.^..y...>M...#.......g{0.b*.W.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):6136
                                                      Entropy (8bit):7.965309045050234
                                                      Encrypted:false
                                                      SSDEEP:96:ocNdCBWKosD40IZFdH0tgRtNwtnUHPiwgPqiM5VleyPk317SFWH/BGpDE43/p6B2:Mo6BI7dMgRQ1eiM5VebH/Bg443aFDe
                                                      MD5:ACED8C05F587EE4E47633C5258DDEFBB
                                                      SHA1:FD20F20C30AAF89578A9042AF9EB201F6ECCC58D
                                                      SHA-256:8510698358762BEE6CD069B8B8922B0D17610D033DE32096F71E2034B718B00D
                                                      SHA-512:EBB7B3EFF3CA5C26B27FECCAF5E51ED30A9D7FCE60D5C19B43C32BEE64466B33EAFAD9AF839C10E72A14724777F9BB18D15E8746972212A11D34D5534976DB00
                                                      Malicious:false
                                                      Preview:WANACRY!....o.......f......BeY.c^.. ...;Z. .N.s....P...c....6s*...rBJ...?.2.f..T%.^...'...Hkx..*$..i...[..ONW.i_..Ls...$&..#....V..?,../..".x...y..@...3..$..d...._..Ek..z.zY.%.!..* .v.L...w...[(kH..4W.@T.iC."|..#...........e..4@......0PK..w..,4|.64\.....b...............b^.\gl.j....8.* ~.F.S....Nha7TI.!d..M2Qr..{.J.c..e..;T.r.Y........--b.N.N......q.....'..#.\R._.LZ.4.r^.(B.......?8../..i+].}@D.P..zu..i.....l...v....x.yTN..v......v.....V.#......&,..^..)......o6z.=.......O..g(lp.........q.B@..?=X..m...~O.=v?...7^,...Z...A{..!..N.....1.`.6..I?vF........sy.?:.h2...>.T\...9.7v.Q..\...../.Wf.Z....@./..aw.<~|hZm.)..........>p$.U.S.bw...rM.\.J$.T .*./3....3g.A.:........W...i.++:.)yy..u..&1sC......>._......y......h.#..m.[?..p..z3.a...^..uc.....3..4......Y.xa.{.gqR.-.egr.R.p..o.....d|.....X....AJ/.5....f...0W.v.).A..&..v..~.._I..{g..e..<...+S.&.g.....;..A;3.*.`.R.9a....f.}.Y..~.?d.&B........+4].2P7.%...........)....wR<{.....B..'..v.}<.h.....8.....zH
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):363208
                                                      Entropy (8bit):7.99946621369543
                                                      Encrypted:true
                                                      SSDEEP:6144:noSQQ8UDOx4D+i8CGopnysyBZq+AMCXfWSNdZQAX7PqLR2z2Y:oSmUDo4D+i8C7pnysyBMvfNNX7iL42Y
                                                      MD5:694A98210168B21CCAC438924C3974BE
                                                      SHA1:9B7B2DF01912D2348F650DE76CA652D38C9ECAEC
                                                      SHA-256:AA3CAFC05359B2EBCC0DE90A22A06A91408B27FC2C45A2F4C86C14A78104F93B
                                                      SHA-512:CF2E647C62384BDCB0DD8089080DBC9422414017DD4840A55C80367A7CF9E521B151F6F19BEE221FDDCDBBEE2E68AF4382159903FE81829F4B3A4961051BA069
                                                      Malicious:true
                                                      Preview:WANACRY!....r......+...p..AD..........s.......A>.~......V..T.L.........M...Pp.......N.n|D1..hT.$..J.d..K............y.....~/.,. ,..}..I..Y'.....i#6.....o.....TD.{o...cU.b...h..5......2.;C.X.UTd..w..ac.)..g.a.^......._`d".e...)p........+..o.YI.*...*...<.............Y...............k~o.....g......j...c.;.`b.......D.....E.w....D..D.:k..z...r.......a..@.>.h.b...K&...'....D..@g.L....}a.h./.v.]~..7.5.+f.0.N//..zuV..)O...|D...xTe9.oW..*.gU..]......3..`.|.Q...fy..8o..q...$b..d9@jO.u.~*:|...U..?.P..z.X]....i..p..<Y.;...v...'....p.e...o...........E.(....w7..........(.+.T9hJ!.z..g`.}s.b_..#..g*0 ..R..OPw.A."ox...O.............&...C..!:....vX...u($.D:R....4.....s....r..2R.;<.:..U.q.:g1R ...I.X-..M...13d..(.CdY5...,_..t@j.A.6.@.....>@5...7........+o..d.=..?.>0.......u...d.!.3.E>.z.!...ol.Nq3..W.B...P..........2}.s...u..F.ok..p'",.F.]..M..9cgq/....sv?6I.i...W...k...l.....Y..P"6<....Oht.&....f~.m.X.S..+s*.Z.!)5*......|.T..j.....y...6..M..6....~..M
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1336
                                                      Entropy (8bit):7.870632467427484
                                                      Encrypted:false
                                                      SSDEEP:24:bkjswdVyNFeWs6L3QRAKVvbSvO1wZrTmYMsX18WNsvgY4wDiLTcs3wyLo4QTRDhK:bkjpdYNHs6L38AKZT1w5mYt1BalivcW/
                                                      MD5:25DF72A3EABA9C60D8D617DF1550B235
                                                      SHA1:9E833ABC25687115792D3E82CFA6C3DCCDC70153
                                                      SHA-256:61D26A682B54E124BEE54D135B9B5458C4DC3537F2741E647566763C2F5EBFDB
                                                      SHA-512:F79D1FE5D101B69562DE4E1D9E4A03DFD19C1A3D5955FE92136FB753540E97E7588692EBDB400467B712BEAD25CC7246A7A0E5C8FD9F5DB95697FF4469A17B61
                                                      Malicious:false
                                                      Preview:WANACRY!.....$+..........$....}..Z..g.m....<u.e...2......,h.......t..:Q_....]h.p.>..Z{^y.B..A..:c..:C.I.o....6.2K%.|...w#h..p......'...>j...N...Y......|6AWf......8MN..:.3.T8/zO.4o.|a....@0...{g.q.Flx..<..C..;....C...........8..s../..{..6.g..)...9.Wt]`B.v.\F6..>..............!io*{1a......@}{k.[A..9.!.T...U.p.Q.'..k.M..^.RC...^r~..B.2=..y9....LOU..8...06.d..`".."...A......U.>.g....b....-.B.fN....../~.A. .-~c-...$ZQ......(.......uE_#-A...7....6.p..NP...MsA..+..>.w.'.U,.y.....>..{mV............*..u...b#....;.....b.I.36.M....|.P.....5.J..s.p.O....h...)$.GX2F+dG.RV.....]<8<6.v+..&.!...........X.).._i..$F.};..l"..d.K...,{...#..2....4.d"D..7.=YE.o..w.fGZ>...gE~.F.v4....am......e'..CS}n.;....r.X....:.kv`..._.+.Q|j.=.....)..n.I`.~.p.7......q29U#..~....n\...9.?.........;L.-I........&r"..=".#.6..x.....@?@EQ3.Y.a]\..>..D..3. ..$....Y...w..K..JS..`..........Iz......K<Pq...\S3...on.!q...L..].......P.7...&RiN....}...]K.."7..f)\m5.t....v.H.n...x...eo.F
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1608
                                                      Entropy (8bit):7.860736249791203
                                                      Encrypted:false
                                                      SSDEEP:48:bkUa/S18Zyq/j+rZ3YpIZm9awdMaKMuvR+:oJqUmaiY93MhfvR+
                                                      MD5:E9EEB559A4B9FFEF21A9AD5B3CDEFC1E
                                                      SHA1:30DCF06C768B69EBEEE88077DE2651B8A0766892
                                                      SHA-256:3E99194CE8F218B6A82486FD7235B50F54C17C670727232A3F7930D823A5158C
                                                      SHA-512:C304952C50108DC3202556E2736AC9EAF4A6638007EF71CD4ABB2EA956D8FE2560ED487157309BE054868C3F43B94AFDD2D4F6964A6CEFFC90CAE782123366D9
                                                      Malicious:false
                                                      Preview:WANACRY!.......r.O.....%..*..7......R...o..^,6O.P.$.....,...g<......O...$.a.k.J......H..m...@.u.j+8.n>.F...H....[G.\$.H..g_.......i)Xl.......M.\ #q...)...Z...]|...(a.<....!.......f....{...ra../.L/.......e...|.F.+[....M6.N...fL...0H&....._0......,0+...F./$'F....%.........c.....".i........M.1m|h.....L.7..A.B;~.^h7xI.w.*.f.J...sX..}+..@.}~..6._..a...`a..8.... F..=,...$..y......#.W....dg....J..CMY:t._?e.2>..n.Hj.......K?u....a.q."T.U...f....1.G..zPgV.e.[).R..M\......k..[...jZ..q.?i.|.$^..*om)....T+....>l.E.s....?..Q.s[{J.Q.5..f.fw..A...L1.%..}...86......."....b....y....q...g_.... .'?S..B...vK.mZ.2h......a..w.....h...j.v......Mp.....n.nX.aN..E.8...5"...a.r......8.>..:._... .aPc../.>.K.D..geu...n.b...N..t.<.+..8.d.A.D....u5..D..'H...z.__m..,:.. ...+M.....Qg6w....Q..u_...wP.}y-.b..P%...TP......A.$.i{....S..i..".;F........N7...AmCF..D..n.I.~7..3lfT..N5..Z..y.o.X....Z..&....-.E../.%..0.J.H.........,..;x.l.q.~a^u..8d.o.y...&.=?6...._..6."..).vkq.....60..B....c
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):493400
                                                      Entropy (8bit):7.999653233222641
                                                      Encrypted:true
                                                      SSDEEP:12288:fdOEtGouHaqP9RqN1denOjeTAB7DxA89+YuHMp:fx4ouHacRajvB75+PHMp
                                                      MD5:7DC9E5C25E2C3CA7E8DC4FCF38244903
                                                      SHA1:E711B73553CF2A4AF16BD2ADFBF57D27A7132D15
                                                      SHA-256:E2C3388DA039E928EABE28A915E4E37EF5955441D0DDD749E63AB473D1288D63
                                                      SHA-512:2B73D37AB4660765DF45CD653823775D8BAA6BAB54FA89FB5F0A0BDF568C0F64E4DDEAE4D0F6239FEE7E4BF607C5B63849D4A53C658844A72033C79AC9151F5F
                                                      Malicious:true
                                                      Preview:WANACRY!....=l.=...Q.M.>.......tm...G6X.....N....\...S.diq.x3:R....a.I.'..<c(d.8...}..].qX.k.......P..+^k?F..9.^UHX.ip..p.../.1U.....n....ny:.||S.E.V>....n..w5...&...1.9?..G.u..Y.8m..SVE.Rx.`.[:h$kG.%i.....I,.~U.jR.....})^C.{.....l.`.._"M..m..5.Ti../......2........g.....%A.SQ..+....*..]... U..B.Q0S........k...!.(....2I.d.......*7.5.w.....8..]..y.P.,..%b7ul...b_.p....c.b#Y*..Y........y)..tE./....*;xP..M<...4.t0...3.6.j...7........9)....:..8 ....[.t...q.{....\.pK.C. %....Q)&T.7..8..-].....%h.K...6..T2.&.0........ .x.%CXWS-..Mx........z*..g..T2.3.0..t...;d&J........v..\|k.Rv+....f.}....z^Qe../lw.]M7..C^..H..qc..l...3.....~"..gS./..Mb...7..3v...7.yn.;.T#6+.......>=q."....@..1...T.Ot|.N3..-a{.!.....[....%uw!t*...u....p2.4.....3.c?..7.X..n.o..y...RB.*.^.9+*..a.H0.@..n.!..v#Zv3.h...xQ$tZ.N.sofY\.NX.By..g.>..Nc.}gq...!.....A.h|..,[A.).9..>..dkL.....{.u.....].P..sa.....^...."A"R.o.Ax)......5..U...L....Ax.<.1...vx...?.T.............u?..k..
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):329976
                                                      Entropy (8bit):7.999452236717312
                                                      Encrypted:true
                                                      SSDEEP:6144:GLPwySkIa7M3tEZ+dHg5lhOVGRiFsKH2iUc06PtorSEkLOXtGWtjwF:GLPwwI73tk5iDFjH2F6VomfLOsHF
                                                      MD5:CEEE807A40D5F489D94BC8EF5B3B522D
                                                      SHA1:AB700B84560526E5FA666EAD5BF12928B0CE7795
                                                      SHA-256:A63E1B88CA2F0FA58001041C6F2EF778FBCABDE386AE26586FE6A50620091A81
                                                      SHA-512:B9D1C65CDF7A9F61BE4608B37FE8A4F3F38CBAF5417568DD97874A28DB6A150CA205BCB811FB2FE713E3D5E705E9375D07FE43EF39A9945AFFC6EA484324493C
                                                      Malicious:true
                                                      Preview:WANACRY!..../2.;.W.O..n..T.l...s...v..E{.8.=.l.......}2..`.%..<n.m.v..........U.@...q.n... ..f.......E.D.F.w......I5..9}N.d.=.}......;...^.{b...'..f{..c.....(3T.\I.!.=>..^..J..K..:....2-....`.C...p....8nA".....hH..^.............gL.G..G.@.......j..p.............~_.[.........bz. .I,........,.<(....'..S.t...-....n.6......#....6>P...o..!.....z4.A.].X....1JvH..8.....f.^..."./...*h...D*`....*..f.....f.!...K.3.J..e%.H..* ...w...)Z..|}...n..`H..C.8.+.zn..hbL...q.@.....2..s|.}.D...T.Ua..j).../...^.XC......7.kDBzG..^...nq.......*..2.Dj.....N.E.~.>.6.v).J;...G*...W.........C.Q......K..l.]DKP...'.....R.b_..C....q.e-...y..u.... d#....o.Z;.}.;Y#.`9=...:.m7.m_@......L.s..0..:.:..'GW.G....}......-........}.U1.........((..."".d....lJ. a..1.W....1/.T.9_....Ai.B.a.J..&^Z..._0....N<@b..#?AF./.VY...3.NW.....Yxk.d.?.A....W.......M.[..4..~.....(.UI4.E..d+Zl..h2....R/=a..&K=..q.v.......cN.*x.6.z<e{l..0.H....<......m.....+R._.Uu{yi_...Q.U....
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1608
                                                      Entropy (8bit):7.886062008198423
                                                      Encrypted:false
                                                      SSDEEP:48:bkX9SEcISyvK2nVzfhX5zsU4CRpRjtV0MlmhnahqTR:oXEL2K2Vzf55AUfzv9kBr
                                                      MD5:EAC68266E75AE9ED6FDDDA4A2E662BF5
                                                      SHA1:3F0789711641B3320060034ABFDAFB7BC3C1983F
                                                      SHA-256:74AC5E5157169BFC3C048DADD33BBED6375B0D30763D5785583EC23FB91F783C
                                                      SHA-512:84D91CE9C038019EF34D1A26E74E7795C7C0E73F3346F7E7EE364322EFC853029C8FADADB997EEAFDBB57525F82FEDE851311B95DEE78A11EC12549CB17CEB20
                                                      Malicious:false
                                                      Preview:WANACRY!......<.+.......$.r.m8..m....k.|..^j ..\....(.o\.d.@.R...........{.H@{I..wUb....E..................D......SN.S.h.)R....'.X>J.2.3W5.....{H .=..~CkuB.,..yF.~J...W.K?.'`.k.Br.5..T%WF.B."..A....._.k.=.4. -)..S...p..([LF...[~.Ohwl.=i....8.@.3.-EC.G..*...b....%..........<...v.:...8....[...|.Y......._.....).}.%HP..!.km.M..Q.G..`....<Yj...^.8Ns..#_.Eox.{.............e'........&.VT..........F... \.r.p....b#..{d.I.Q.t...."....g....J.....G8...[..m.$..2.@g.>l..]$..?..,........".1.q..e.a..5#>...Ao.MqLX..L.....]v........D$..0h.1.....[L...l./6$......0..*^.F...k7'(.](.yvc.......p4..:........U...V~@.b|......8..:........../Aa..M...Y..]$..u..7.R.(.f...qfW.).vvy..!.Y.0[.\.#.CK#.o_.]..U..u...G.C|R8....v.(...OA.....0>..C^.u!.~..MK..x.+.D.5.^......j......d...?.............2K.|...fl(}B......&).%W....2..R/]4...t?\..O....-........8.....AD..3 ..5..#0.6c..@.?t ........j.48E^.>.1g..f. 4.b`a.....Q..k.4..y..?..x..d.....}.q....%O>...W_.......S...J..Nwh..+dT..".
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):552536
                                                      Entropy (8bit):7.999669522150112
                                                      Encrypted:true
                                                      SSDEEP:12288:cO0W2/+ZRdYpeZCbeQKnpN89reEsgyK2vjsvs5DymlvWU0:N0Wsy64npa9XVy1JGAvWU0
                                                      MD5:0F219ABB52A9F8528789CC93FDB95834
                                                      SHA1:F988FACD0D1BC7D70247642C8B27F3D2D7BCF757
                                                      SHA-256:64DA472CD24ECA0DA70B6A2111D60CD14070B5BAAA657DCCA9FF27678CCD2CBB
                                                      SHA-512:023A9B8B8974A3BB5870189E35213E8990956FFA81B749345BCD8B6D854AEB16D24BEB90BD0C3FE920BCC3D3FAFE8FE043D4AA408156F3C2192808F7D7F92B09
                                                      Malicious:true
                                                      Preview:WANACRY!.....I/.3....Az.k..:.u.<...R........T.S.zd.j.+P-C......]*..S...1....s.]..}..p?.E.Z.......6.x.;..l..i^ajB.........<.Dvx.|....t.nB.._.......+Rs...>.A.T<.....%"%%T.Y....J.Bd.!..{..w...,...ie....cM.I..k...P..A.K...tg{.5.......K.....<.mU?v...*Sa.4 .Q..\qT....9m.........O.G.#9gy.7.Y...({.D...X...P.B..]..-.|.>{,6 .F.q... Z..~..o..97...Gl|.../....bJMp...E....@......F%.....E...]..|.....b..^.q..fW:.A..D=3........\..C/u.^..........4.4.q#R........4....*.C....(.QF....8..0R..3=WPh....L0.....%..V...<.U.X..f..~4|X...^....!.b.eZ....I...6....g.9..WX.J.....KG..?.P....*..@.=6.B..n."..vG.X..n....X.c1.9...HE.C.........>...I..}....I.s..D.pG5>.......(.Oq..X..I$2j..t./....-.........@.}..+F.{y.$bvZ......r8@.n..'..#k..o..]...&..t...A..-o =f.h@.|.......;...W.%Y\."m.....(n.:.".E.4q....t.\...H.M..%..i....|.....*Y.n..UpB..g....l.X3"..=.W*K..>.i.(@..f...4.5`.7...7....|W.......l,.S..%?3..V.*A;...v+I'.&e..../c...1..(.(.5..>.(.J.#..O8..E.ch..Z...s.....-.e.*...Q...,.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):16456
                                                      Entropy (8bit):7.9885795613335295
                                                      Encrypted:false
                                                      SSDEEP:384:uenuod9MZyydQyvg5mizr1r97bXdrS5L4s/IkQbx2DIkL5Y:u8d9MZyyLvg5milpprW4MIz2DIktY
                                                      MD5:16324D197C3853A782BFBF8BC6A561D1
                                                      SHA1:6E627043419FAB6EFA79277DCB3311DB3A08F774
                                                      SHA-256:EDC31342A7A0B37AB4BEE76A01AEEBF8B5F59C27E0258AFFD951AC44CF0A5A15
                                                      SHA-512:CC77555DCEBF80331AE98C64D3B8D96FB94F31A162BE1A5BA196603C5C9C5AAABE457C46F4EAA35B93DBD02B1B57EBFEC0C92D25A8D23E29ADED22B2B1A055B5
                                                      Malicious:false
                                                      Preview:WANACRY!....1.X..FZ.......V...4..b|..L.....5..zK...R...[...=......Z."......i..i9.O......+....+.O.a'z.Q`.."6|../.... .@.c....c).....v......d..s.._.u~.qF:.1....L.{.D:.......J.....nH...+e.V.u......M$SV..$.|.i'..Qa.......q..z.....3.)M.m....H...^...h.m.z.(?.&.......$?......c.~.z,. .......to1z........N*D9.......K...~....\..@..@..W<3.4w...gM^.>T.}O..Dg.Y:%../..M..`f"...1....u.....J.b..".....&...jXB..l.@.a..i@.[.l.q.K9.@..~......VE..f=.c......FF-....*.W..........A....J..iz.bH......~.+.R.y.O.w..S......ji...t....B...'a..h..G@~....#.t.........;..a...L.3|..0./.....N....j.~.4Q...p0..!..1...$X.R<.vK.l.gI"..Bq.K...3aMT......j.....$..Nu....M.VD.#-[....K..N.X.K...S.l...J...:.z.....R.L.G...%7+..z...n.MY....2o.".i....q........._W.%.1.y...1.=..V.FLf.]>.F....K.P..](.sV...3....Ne.f,.=..m...._.H./o...EI.@8YZh..=..B....To.J.avn...2i....U..m.T....oB..h&p.......,X..u}...\.....#.l;.Rf.D&N$...y$^.ZS....n9.]b....Tj.......J.n...l...0..r.E..l'..TE.-Q..g...6A.U..3pm*.A.....2
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):2088
                                                      Entropy (8bit):7.902420675380799
                                                      Encrypted:false
                                                      SSDEEP:48:bkdQSeiKnIAktsTuIkgjmnhObSN/iTBaxEMH4A622U7J7Z3+c:odIiKDJkugk2CTUVQc
                                                      MD5:0EF024E55897E0DB3169345255C461B8
                                                      SHA1:8209CFF2A89D159915312F3D5E833EF72808E22D
                                                      SHA-256:85BB35D20CE6B03D22D9E9EA97FA985791FDDB7BACD447CCED88F98FE9BACE00
                                                      SHA-512:4AEBBC5E37A09DDD5CC09D754A6B0292501462BDAC9A3FC8B746A2DD3752C70D6F99D521990659A9C61B9FAF828CC5BA31C87F21708E14E8C6FD856541166DE5
                                                      Malicious:false
                                                      Preview:WANACRY!....K.:]..E.?6..\.....au.p...hb..V.....=.p..b..=.{...E..qm....n...).3...52.|.....W.h....G#j......].U4$..NJ...........]..jO.._).?;.j..J3.5.@.(.z....\(=...Nh..9.D..>.-.I....T..%..q*..J".[....-....:...k....^6..L8...D.vb.....R...}.3..).2....#......vW.i...............B..)...m....,...TJ.C.#h.".&...zs...l..T8....t.qD..6{a...5......3f.....HJ.6.6c..9.e..!.Z2..._....M..%./.Y.+F2..$...C*.C;I0.......o.....,..<......t.0...Rw.[?.......:...C.)...Mw.i....x...(.3.....[O..V......#.$.....}...)F....!.p+...Rj.V7...ao..D....E.aM...\....a%Tf......5mm.A.V........O.Z.9m.}.Z.....d6..V.9OT...1........B....^..>...O(....6a..>q.G..l.V.....>|.6?j.Ni..nPU.:<..B+.1..K.....1....<..1.=%.J.......&M.^.$4.#......~4~.;....=..T.....D.'.{....b.qJb.....7...8q..dw..d0.w.G.....T..~.....U.d..2}\...8].#...F5.tY.!./...nH........H......`..t ....M=e.k..ku...8...|n[.z.M}x..DX...;.......b.1..Z1.6.nVG.. G."2..A..J$.oA.@.2..u..o................[.....k?.V...l..X..h..-....N..Uax....B...
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1394952
                                                      Entropy (8bit):7.99985774892823
                                                      Encrypted:true
                                                      SSDEEP:24576:8IXLx6Pt8Fkx/Y8f21qPIZKuTApccpb01k1ix54Y8t223rKt5agHgfxEpBtx2tSf:b9it8I/jsqP6KMWBEkgra3maITBtAtSf
                                                      MD5:957F93CB8C537DBEE489ECF2F29203B9
                                                      SHA1:1C9FA76EEFD95FB61D6E5BA524533545C83D3993
                                                      SHA-256:F7013D121668F7D5A82AFB8D71E287D68BB568903468BEDB2E325ED711A27DBE
                                                      SHA-512:BFD1BA13A56533CB2A04A0003EDD96301978009715D1C02C15C88601A248AF21D6E2E902F9D44E926E267C96420CE1B476510BB8C44A589B610EFB93ED4D12EC
                                                      Malicious:true
                                                      Preview:WANACRY!....!t...v.........0.....g.WX]."..$.....tr....H.....:......&.P....U:..gC....fN..qBc.zS..%...>k.-^.....e...Q.u.c..w..]. :&u8..*...M<.+s.......Uy.}Z...B.D.....c..$ z..a......3.J[....bn./...>.....O.".4......)Q#...Q.,.j+......d..=j*.........f....S.....Z.....G.......u.|.B..Q...O|...../8?....!Uu..!......K.....?>.z#B..gh........,.&..7Y..e@.V.....K..BO...P[.*...b..O...8ai.xi.....A..*?.|@..n..of.a.%...<.+(.X..8?.fh..:.Xp..l.....f.c..{4.\3@....-b~..u5t`.....L.68.}.M.Z.X..t..6c..o..g.. <.LYR...8.c$.Cw.h..I.)h...?.LJ.8..e..G.ZH;..!.....G..@.T.'..;.@..LDz-.(X3_..o.>...0...k.?......m.$"(.OP....~..iJ.."..?.'.(Ey".......Y...?`.....H.a.B...f,.wj..kC./.....T!......t.P7..3.a........&........T...L.......;.J.]...q..Ap.\..f.{\......&....b./;...4.J.....1.M.z....Rkk....Gf..k_x.j3Rg....lp.....=..pO..dv w.](.E....`..k|.G......OB..?a.8\9....^y..x..>$]?.#a../.g.T..>Rx.&.G[.$L.1..s..........%...r...2w...@Nu].q......}.......i.hN..S...I7.S.Q.<. ...S....4.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):2040
                                                      Entropy (8bit):7.913909627977196
                                                      Encrypted:false
                                                      SSDEEP:48:bkgadONL8UCotfdd+aZ1zchpyDAgOi1UG9wedoFmUbt:ogadOd8DoUMzchkD0wVVoFm2
                                                      MD5:4A238CD03838DB8A2B00EBCB06E7781D
                                                      SHA1:ABAC9151144E47F409E989F7259A4C577E12DB20
                                                      SHA-256:34DFB05826150BE84085320900445BF363CCB7E3D07B74E895B3CC86165178F7
                                                      SHA-512:9BF390A85E17C7E062B1711F164EE91DB8109A4C771D7B449A5B602D4DAADD79B8793EFC9D17977806D303770AC74C140A795307980C44A37C5CFFA93715D8D6
                                                      Malicious:false
                                                      Preview:WANACRY!.... ..^...Y}......).>75.v..g....s...;>#.....J-..#@zA....zZ.T.7<.7G....u.Y.d..m..~9.'.u..%.Y.%...>UD.`......Eo.P.....D.&*.....e.=w.f..}...3m+.zF..G.F......Izm.&.I.......*.s...X....$......3.(.........f*.Y..Q..mb..H.m.....R.k.....%..+......sa..O..............!.|_....6.KF.......JB=....].z_.X...;..0...7.\......R....0V......./..O".KM@...f.....1...Q...y..R)..q........LG.zJ../T.^....Z..%...#.am~./.>...%?qN...%H.......g.TQ..Q.jQ.]..)..8PW....".....F.9..DC.l.....I..B......]...."......!.?....rG..;W!..'..Nq...x..--F.F2.....uci..2_.dN~.V;.Z;1...m.2"V...C..aq.s.......^M...|......[..R.{......b~z.........(.KV.........:....)..LN,.n.=.-j.t.J2...Xv...*,g..;#.39!.vg.1..5..]zc.....z.. P.l......_.4..B..,...d...P7.~..L..F..W.G~1.O?...n.)..u.A.."......."....pl......k.\LEb'......c..;....G.......6....R.,..Z6m...O..b.t.p(X.V..l .q.-.".F{.....pi..k.J1.Uy..._.9..v...~N....o....K.B.j3H.............:.M......j...H.w..=5.'.'s.l\.Y..}...v..|..;..6..)%....|
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):843176
                                                      Entropy (8bit):7.999766648722183
                                                      Encrypted:true
                                                      SSDEEP:24576:J7rnijmufu6F8yU00CLKiDMLuMzIlcaquJjH+Vk0:J7DicnCjBMDaqieV3
                                                      MD5:7587EBD84306303F2FD489B4CE4DE669
                                                      SHA1:EBD0A5D84B13951E4BE38A4BF4D0304B7196E03A
                                                      SHA-256:A13BE10499D4BFA2F248C325F2EB94BD58FA4C7D12DF3950B2BE10471B22701C
                                                      SHA-512:AADF9DB87A171249CFEE9A2361EA71D98B6DD4A9C28C75BBBC5E897B843CE2B79F1E186E59C3E99A9E2D9BBA2B400524DDBC9A8644F4DB7931867B8F19CA6144
                                                      Malicious:true
                                                      Preview:WANACRY!......H....w....6....v.%........i==&.^1..g.\j-.Bu&.g$W.o...XUd.....vIO...#..7...<.{.a.7+...csmmPc.p.B%.8B.Z...r..?cdIhE.n..}.ev\.%M.......l..+_/.....)....5..&\..[M-..b.!..!D]..9....P..8P......v...I.H;\..:.<v.....,...............'................Nl.x...............DVj..........&^u..?]?.5.C....8.U....H.X..H......O.....?..(*..^V.!.../.m;.18..0..L...U...:.<.R.vD............v......'...bF"I?p"". ..U.:.."........gMq...]...s......... .c...9B.z....e..B..Km.CK.......f.ga........C.]9O.&.a.L.5&..79.5.8...}.tA.?.Y..S.....n.. ..F..]..~QY..@...y.........b2.T......6u.....T..CN......1...t.........D...a..C-.z.W..l..W8.2..)g..B.....e...xF...*;.w.{?T}.M.9%.....v..\.L|...........DB.:.*.....o..=..r..h.......:'1........(k.3.7....2n..z-,%d...{.Nw...\...x....T.+...B..TPD...X3.....)F.C.w.<Y.......UA....k.j..x..x...j.M.*S)G..t.l.K.....l5...c......E\b,.....p/.Z..WF).4Go.J\.?.'.p.........q.....I...a{...L(.j..P........)....~..lX....^...K.....N68Q.D.nf..
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):11832
                                                      Entropy (8bit):7.98607772092642
                                                      Encrypted:false
                                                      SSDEEP:192:B7+x/zg0rn6iwN17kBH1T+rHgSzNfs77L5J+fLnezDGhMHyflxeazN8dWANc:B7+xXr6lNSH9+cSts7x0fLjgyflxeaz5
                                                      MD5:1833C59F552753B51371CD2A0365AECC
                                                      SHA1:277B11D27401955EFF7D8E31FE2C21989D07CC93
                                                      SHA-256:4AD7C526F30E43AE8F8CA2A1D3D38E7564AFCAF8FEB486FBA1721DAE3D6377BF
                                                      SHA-512:9E40DBA309AE45E7EE882E512B9C5AF80664B13028CACF0740F8422B772F97101753F67D76A4BA8D5E5762336FC5F404EB7A0753B67D1BE35B83D8E206C51814
                                                      Malicious:false
                                                      Preview:WANACRY!......xp..J.C-b+..`.n.....w2.....4+....C>...:....+s..7..C..m.D.s..-.b.a.........%d........x..[a'Yd....`.....(,"i..a.+!....i..$.....7..).....J...O_#..=dOI.l...*..N...=Pj.Kk.\(z...s.cE?(.n.Lx...bf4.h0m...o............gaq.F.[.I[WS..^.qH}.>.3+.z....N~/.....-.......0S.;.w...]Ww%..t.$..BE}2p.0./.....Y..7V..=.- .L.....c.V..%.8.....p.s.G....q....L....v.X.. >K9!....# .i^{-|r..{....t=.fX.5.<wL.M...^.~.,...i..L.2.....N.I...j.nwZx.[)....<~.....E..........t....P... .;{......qNYoFlok..J..J...}.]...;y...fN.F/.*..g9..=...`.4_1.z1..}6..E.5...L9....*..^..q.".wqb......"9...e)..^bN...B.5.*5.8....LA....F..D.#.Jz.Z.V..`.x.....!.i..........;..*.....q..>....M.5.....s,...FY<.W...(..!/jor/.qI.9..l.Fp...3.Q.."...e..+y....-3........X2a..-E.)..pN..e.8.&@...!...u81.....g..m.n.Z?....Nz..#..T..D....k1R..A+.W.PN>.,f.....D...;Ri{.R..o_.=.....ZS.5;..D.g.2.#r...7.^.[...../L.....*(.,....XTv.).d....<'.6.bs;....%]...:..=].....mi...RQ.{8........D4.'.zy.fW...1^m........|....z.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):14632
                                                      Entropy (8bit):7.988742141359834
                                                      Encrypted:false
                                                      SSDEEP:384:YQoAFeTaekHpkwrVCSq3EKsomw/QB1R94kBLiCLaGpHbMI2Rt6ref:HFeOekHZrVxq3Ebomw/QD4kLLaAHhMb
                                                      MD5:913C13D11DE9AF6AF60F0AD9A10B7CCE
                                                      SHA1:613665796E317B42D4433A1BC4522B900F3FD205
                                                      SHA-256:BD4ED422D6F36C0695DBE6CAE84F249968220857078F1557007728C801A8D192
                                                      SHA-512:03CD1B77B93541B8E17B2CF60134ECBCB86DE3EFF0ADDACF9E9637869711C33A5ADEA63B387BDF8D837471363477CA9A86A7D05266F2FC6A674296EF2D2C4257
                                                      Malicious:false
                                                      Preview:WANACRY!....ZZ...h...(.y.eV.:..[.!.?.1...&Cl7..7ew...A..Pd....;0g0.vT..u....f.]....j.[.h.0`.....}H. ;..e..M..Ev.ROc? .D... m.D...Y..1.(.,...F$..1....K./._..q..Q.c....]"./.`..A..N.q..|..:<....W88.[..o[....Ja..j...L....G.....t...G../_...YN..=..p........U..!......8......Xo......xN.Ku......c.OtwN...p^...f............Pm.....}a.3-....cp.......F..?u.g..h..........p..../........X.A..y....f.4.k.HV,....h...A..v.....4.Dl.Be.&....I........{.WOF....Pi6....6.nO`.4...7..x,?...h@.m.......5.'*.........,....(.T}.r..l......]../`P..(....q..]....%.....r-..6S.....H..<...5..ng;r..nJoq..e*.]3...<...QP_.)....d.....y.KBV...+..S=.g$.vT.p.... .6.^..#.z.........?.....r.3.W.S...El...o?....{x". .U...i(Z..........m6.*.s.d#........[.#!@..`....XKU.....^....T...t..e.......~...M.......X...>G...l%Y....#.Kw..).G..]..W.m<..w.w..{kIP....r.xr..l$.NFT.....=.>.F...j...(.....wC..@.....At....."]b".G.....`V.BM..DE.X.....7OA...2EL......C....X.x..P...;.S...]: ...J..M........>..?e.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1946312
                                                      Entropy (8bit):7.999907285537823
                                                      Encrypted:true
                                                      SSDEEP:49152:zkfTxG8Hn3H2GM8FVzmxNVOBjwwhkQ5Bb0s8/:zy32P8vSxNVO5lBos8/
                                                      MD5:9ABEF8B7685995C9135C3CCA87E986C5
                                                      SHA1:E97445F6D7522EEB706C6A4B001BD625429121D3
                                                      SHA-256:7269212ABA9778F1218724E712E47A505085A10C54F291DE3D6C9F76E3B9F88B
                                                      SHA-512:A6B0A7CD3419D9E54CA11F6D243E186B84A53E2B40414CD4668ECD5B38B26CA473995075B940CDA530FC6B72E9480BE0C39D99F54ABBA37ECD45D618D6361667
                                                      Malicious:true
                                                      Preview:WANACRY!.......N.hM7.......l. m..\Gs..".R.u.....C.. .....AO\.`../?z.XO......0.b....:7......4.p4#...'....t@..B...._....i.t]6.SV_.....L.E_.b...*.r.DF1.!.@...;....f||.....#R....k_{....!..o......F.pQ..'.*p..Bx.3E.g.1.*.i..]r."..G.u<.38.c.. .I..O{2..H... &=...............i..hCX.w...T5.[.)...`;.Tz..OT....l.*../.W............c....3.I..P..F..W4L.I.m....t..jP.......Q..]..J.....d...(..%ZW<vvC......5...6..%Y...;Q(.y.fV."...A..._...].,.j.U..]Xq.{a.s:...b....bN...M.....jpQ..".Ll\AsD..Ohx.D.3x.DUd..Pz...(.~........r...O-.7J....7.V...h.u...-........i..+..H...d...}...-.]......O...[.....6....*...n+..3o{..pVZ.G##f.s\..('`C...o.+.v..._E...8P....gCA..P........mp......J.h.j...c]9@.bv.J)....Eu.e..T>....l#....c)..L...a.K...O)Hs.#Y=.$..E........c..>}.<R....f...r...m.8o......{.P9>.....b.jQ.:..e..]":yD...z....o.......OU..D..a...Y.v.......~%.~g...q...Lv............dn..n../R..^+.(....]+.A....C..!..x..L.E..G...... .=.C.^..h.A:b.....kTf[$.6..3..*.g?.n.l.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1624
                                                      Entropy (8bit):7.8756101492420205
                                                      Encrypted:false
                                                      SSDEEP:48:bknUp+9rNiRmMuD080l1WHJ8Exz3cJX1Zr:onUE9r8VuD0Pl1YKE13cz1
                                                      MD5:1A266085B8E4545069CB521680D201B5
                                                      SHA1:06A86943422C06CB0E1A59631423372C58164C43
                                                      SHA-256:4F2CD1F3FDFE77345EE2E243B016CA1FB423D8954C4A66D9D1B8AFE1AFC6AB22
                                                      SHA-512:2B755D3A1309426935F9884D5DC4FE056F31A40F7ABF0ED86108CFBEA9AC10F3A5536938F35CF5F7C6ACAEF30C5470A257BD3E94C3B24D88F815B3AD8E03FD34
                                                      Malicious:false
                                                      Preview:WANACRY!....*W.f...0cbm....YN../.X..n:..e..@....X.._.....4....Hd.....4|+U.q...(.{..i...K.B@..z.y..?.~..........nE...w...8Y.g..-\6.2....^...$..g..[..38.H.8...)?..........OV...V....L%..3..&..<ZJ.s?..m...@.U...4@.T....T..(]...Q.]8D..z..0.%.B..)d.+5%:.P..k7I..X....4.........a..\.4........4.uT(R.....[*._.+..?.q.T..3k..R......~..0.G........<F...O..[v.rq..!..S..H..o..zGa.....S.6..B..@8.*|3-.,.X.U..T&..........a..7.0~V.P......o...5.#....-.^ ..*.h..>..KA?...>,...YI.t$..m}.^b.Ia+Vns.[.....}..1,..&..AYk.Ox4....&~%R.$Z.(<O..{i.-$.OXr.@.....52].`r...86..)s....k.#.5....X.+R.F.2...%.E......T.Q<...H#...y.2+...........Q..y.B..tq.i.&.S.......`....Wp=W1...`...`.hi.rQ.Y.]..........6NF9S~)..'.!q._B...W.c.`..)).5...[.j...;8..G.L...A...wm0I......n.'^.!(s...t[3..;p.....HV.!.s.]...{...#.m..wX....+..v.P.\(>.~....?u,.~,k.<.q.D(/Y...p%"h.d}..$../...2...O),>R..42....z0..]W.....V....EHk.U...GW...g.s-. {8H.$d......~..;j...s.%...FI.....,..D.o...2..J..\...$..A...3....n.W....Q
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):2424
                                                      Entropy (8bit):7.929709509345389
                                                      Encrypted:false
                                                      SSDEEP:48:bkyXZ0pugj8ttWnBJlM/l9yQZsDxMWQGOjwXMlDGtyteGktUknHcnXjfxSR5C:o+0ogjyyJa9YDxNOMXoGtyt6PnHcXjfp
                                                      MD5:F1963D2EBB17E6C2AF56EB0423AA4554
                                                      SHA1:5629EC102B9EB1998CC3EC4EAE646629BC5BDF70
                                                      SHA-256:7B5169ABF3A5A2840C07D3A64D8F7849ACC09B84AFF6AC93A6EFBADA348CDBA1
                                                      SHA-512:BEEEDB94C8EC199296D1EB26D29221E43FB0B8ED57B029ABBC4EB724929B7C2BCE4F8C855935C56E3FA72D2AFDA319FC5E952120C042FFB27110834307D8281E
                                                      Malicious:false
                                                      Preview:WANACRY!....<. r-...p.@.t..f....H...$.F.9K...W.@......}...t.m#.i.T.4.0.z..W.0..@8..Vn@...u....g....... a.IU.qp.....4.$.C...r.S...]q........[l...Q_..v..?k_8...\.=.9...Na..j~.*P..R..cI.L.....*..wvte=.;..uI...S..%....]P.i....0L}..|._.4.Q.NC./L..]+Z1...L......b.-....^..........#-...Y......@.8.y.3...!.xd(E....+z.Ib..0,It.awU.....g".>.)....*G....X...].....E.....=B..\.k....a...v.Ug....[.un_b.G.x........}L0}...>..)`..*............M..z.Vf_p...Q.QL=\...pv2i`..<(<wvIE...u.T.q..6...).Q{f..G..T.Y.{....6.g....!.....Y....SO._.pS..?a.R.....Ml..j...FX.u...$.r..y..{X.....l...E.....\_..W.B.7....,...'..~.....-{.....LV!:.3......>...."C.Fl. .,B..##.|0......,.y?w.........j]r...Gd....UP...._..g..f..D&...dh...>....lq.\g..bt..j..T....3~..(^.:OW.~R....%.^.}.7iu..O..&.~.b............./.o&.5.......G.IG...Jj.FZ.RcM.g.@P..9..gO.X..Cq[.cQ.H....(.l%..}.W2..(..U.O...t.blR .A..@...Ds..E.]...C.a.^....u......G..1.{....e.=k"./N.H..l...(Y_|.....+q.s."5#3-.u............q,..
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):28904
                                                      Entropy (8bit):7.993240645846593
                                                      Encrypted:true
                                                      SSDEEP:384:OcK6dLjK5Cuzeskn/eEq2SnsGB6Bj7rygpJATwQjkDStyvMo+OoWsb6yn:5Djsjkn/vSzgBnegpJ2wQjk9x3oWsfn
                                                      MD5:83E3C4883A8A30821C679F6B1501F62C
                                                      SHA1:3A187555B124D99B1EB77634DE6DCDB385FBA71A
                                                      SHA-256:AB198E868CE30D48436749AB0E6671303EC727820CC48303EA63D8C24EBEBB31
                                                      SHA-512:A4F215EC892A0EDC7810CE4F943FA4A877640329750A3614FBEE6375070E08DC6646CED960B5653B8B9E983C54E41FD7A3CF3D1509ACE281632B635252FF56E3
                                                      Malicious:true
                                                      Preview:WANACRY!....d..C.,d....{.V.K...N.a%..*...Nu._...w..5D|...<.....}.4u...##.#..7..2....nb.i...7V.s....*.u .m....m.4..,?...f.w....X..."q%.....aw.S/...8.To0'.4.....x.z..;<<-n...5y...M.".Fh.b..F.....k._......../Z_...Iv}.).{9.....-b.T7.I..y#.}..E.Q.%g_..z.U..5.Xl?HK......o..........j,.w..r...q!.....A%..^.w...[s...v....z.. ..1.5..=...Am.Y..L."...L.K...,.J#r.1o.\..k...W.....~ .w...].[.J...F...\..)..Y.SU.z.=r....Z...g.}...2F.{...-;.....K.z...).......'6+i..`Q.:.XU......w7.i.~.t^8W.x55Et(..c\)......DMn.J."...p...,......KS..T....TN.]t..}s.._.9..'..l%...+.u-..T..x......q.V....j)9.:i.".L.-._.Q.`T...;..>.|..C..|^.=@.........9.C{Y._U%/X...C.0.M.......f.....=D.YPA...5[..,...hj....8JWt.:RPI.8n.S.......q....'.F>...$....Y2...16.......&|.d..,.[.;.&.K.vF..m....u2.M. ..mY...)^i......F|7...{.."`_...E.....M|.t...dr..K.b^..f..t.E.t"..s..:..U.>0..".V2.Q...Aw{3.j8.vI...W...`......p.rZ.....o.A%..L..5.....\3$.........{(.H]N....[....2...u?........k.a.hG.t....co($..`.....%!.aw
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):2920
                                                      Entropy (8bit):7.928838614480651
                                                      Encrypted:false
                                                      SSDEEP:48:bkiBLCQtpe8vUBjCIo9TaoxRLlPWlxW9eMN0BAwdzpEYYpzqwl/4OLbdkO86NxV/:obgpe6UBahaoxRlWX2e+CAwxSYizGydT
                                                      MD5:EA4B6FCC849B547EAFC6E15092C3A84B
                                                      SHA1:035D2D2B31DEA458556432E1EF9251EF2348EEF9
                                                      SHA-256:F1326069BD4A4186DC0CAB3BB2E32EC6F9188E5058834F6C8ADA275E68D99AFB
                                                      SHA-512:E0B18C53E3FCAC4F9550EF971D2FAE6040E1916EAEECDF7ABE1AD9B67AD9E0EE39F7ADD1CF9A9CA88AA759A94EA48B7809BF8C13A2E4F98C549A9C43D3C728C9
                                                      Malicious:false
                                                      Preview:WANACRY!....,!....K.x.A....i.a............C..E....j.h!.g.L.DF....=\.M..%..'.B...Z.t.\...m.x+...$.n.....e.....&.ME.z.ejHAh<M]`5..bVm.m.i..{7....VU...|......4.0Y...&.u....Q..q.5Q...G;..jqD..qC...R..j[..........."..Y,.Q....:..Rt.sY.W.i.....$..*.Z,`i..Hp*.T..........F.......D.`.:..XdL-....Z.....,..|x..EoN......8`G.."|.E.M.1.....p1..J.sJ...j.s.%".R.1b..Q.....i..&..2n%. o.J...-.....u.l...D...9...n.e...../-."..e.5)./.....F...!y|..l~....*.....1.........ZU...x...=!.=#.&nK..S.=...........u..J..j.......&..S.f.Al.}...Y..Q.}r..(.W.,."........]'....GF.hH...x..M.D.......*n.`.c.B.l.'...-M....z......k.../d).m35......m.h._......Y....S.c....dVo.*.C?..*u....!h$.B.=.sCS...R..J....r#e.:.I...l.RH.u}.Y2....Mtt.Kpx.r././W.......u...zNHW&.Q.....m.E.A...0..}......a..z.....7.../{Q..B.x.S.C>r.V...Y.j..i...s...M.V..~... .2...M~..M.wpn....%n6.y..CA .!....f..R.uv..q.k.'Q......;.R.L9nk..YU.....v...X.........@R.pb.m.vf......L....,...-..c*.......t.A..g..Xf.S
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1441224
                                                      Entropy (8bit):7.9998598405031025
                                                      Encrypted:true
                                                      SSDEEP:24576:RLn5Zj9kSVZyd/GVYI7GzqCy3/uMTJl3qjpQtcFcljc9zfR7ppjm7MyCTgYhH8:rtnZiEYIizqCyvdTJBqlQt+moNRvdgO8
                                                      MD5:CA3B98DDA8CA2CBAB726AF42CBC887B3
                                                      SHA1:3F437484FAA7C5C10EA6ECB576096FE22A4C2395
                                                      SHA-256:D739BA3BB5ACCC5165E98DA348A040625E3200D13B8066BF710EB6673B7FD668
                                                      SHA-512:2827F73514BB3A80CF8FA50856EB9FDC838C64A3F5F7AACDFFBC0386BEEBCD84EDEF922AA5569C093B7D5B5D7D1073DB7951D50351E4165783B17E2C58DD09AE
                                                      Malicious:true
                                                      Preview:WANACRY!....q.S.]H....2[..m.....{.H..._.C...D..`7...I.j..s_.\.........yDP..)A#z.w..j.x.W.....K....d.=.J{.<.....W..~:.x0..n..|.l...r4....O{#......R....F..a..I........B..x... ..j....(.~..'yrr..u.|....:8..\@Bz\R**.......A...o.vZ.......h..8.s."....T.i.<..<............e....z<...C.b..S!].N...}H..t4.yW....,.~qm:-=._*W)...SdM~....}..V.........vL..z.nS..l.Z!.@P.\<..P.@.o........|........x.Z^...O1...........^.N..."..}J..l4.g.x].*@u.........g.2.4..L...5......^(..u. ...,........"t..m6^w..&"F..M...Wx.~asj.._.....Z.....j>.l.@..:....s.kV..pa<.. 2`.}....n.w....%....T..X.s.u2...;.7dM...2c.5. Q.W..V...Gu..y....N...8.M.....;H.g....\....&I..'i....R5k......~.h.E:O.0r.`..2./.E...j.O.r......IT....HA`...dE....a`:.'bP^f'...V/u{r.)....2D>q....`.....L8...y.J..Z.!T...vX.".0l.....E...d....L.....<!QS.X.gnD........|..x.p0/9..WjJd.X...,.R.R%meA...[X.;Y....?...*..t.d.&.C..9..G.+..W...#m$!.NKv.$.39fp.)ti..0j..5........s...0w..g.w......}....!..w.t...J.......$.7
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):2008
                                                      Entropy (8bit):7.888313109313707
                                                      Encrypted:false
                                                      SSDEEP:48:bkFkjeDe/UgVckSDJcZVOULZbxtoYAZtHxU63bh5T62p0EGk3aMJEOhAF:oFkj2SnV4DJcaU9fpGU63bhJ6SGyanaQ
                                                      MD5:1B8531993B4F411321D763BB2D1F7131
                                                      SHA1:4C5600C492C412B1BD48977A2797A7CD33FEF3D5
                                                      SHA-256:D4395BD8328A937CAC5C2478157375F248446BE347D6F4F104EAF9C6B65FE642
                                                      SHA-512:DB04870BA3EE06F441633D4F13C9836B8FB2B7405428654E3377752A1F8F96B9CE203B2F40F02F2BE4799044240EF06B98A50932AAF2F2E40EAE4A9EABB46D3D
                                                      Malicious:false
                                                      Preview:WANACRY!....X.....(....y..lz....#.....j......\...;.~. '..lB]..J..rB..g5.x....K..)YO.F.E.G|.,.=2..d8z-.8....s...l....J......Y...w......A./.r.H.x..o.X.N...E..?R...a...@..(..9..Y.].."x$.).P.=....5.O.......^*:Y.O/e]..a.....a........1.v[.$N....!.'..H4+.y..7'_..............St$pa..3V.*f..H.JC'y.p...p.J..{.h.%.Y.h{..S.......A...D.E..........1CT...O...;..4....lq...0....3C..........E.. s....H..B!.Q..|..4.V.lpQ\f.....).[.1.1t.,....1PI".h{.......sS..h.......Z...J"KG.Xmd.?.m~G......D#..m.i...=...:....R..|0x<..T......?.$.T.+."..o..N.c23..U..........=....MpWUAU.=k.FO.....R O.. .L.)....C......^.y..q)......wo<......3K.2..a)0.. ....ms....jIX+.....-...z.%.81.ke4..e..e.?=-.......\..&.B.R0.B......qo..z.q..<1........+.}d...%.`..dB.....|.?1>......M........(a.M.Q....9M3x...C...5\.xt....j..1..%.3.(+[t<.A...Q]m..N.R.. ..j.....E.r....}/f}......4y..ug5..Q....Q...L..s60....Z.[r.U9..I..4..o1.>.V..l..Bko0...7.....C.b..I..2R .....?n..........a.......Q.D
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):2937064
                                                      Entropy (8bit):7.999935787713962
                                                      Encrypted:true
                                                      SSDEEP:49152:BwlQvZc5/FgtqTKoGhG02KYzdvEeg1HbMkEzg6F7fNGatMtWvu8lQ8ubpIgt370i:UQZC/itIKoTpKYzyvFJZatMOP3ubCgtp
                                                      MD5:0678307855114A47BFCC312DE1625025
                                                      SHA1:8884283961358C53821081E0E85F79810B6FA268
                                                      SHA-256:B5D14C714BFE8B9E61C9EC77A59553AB6583D0FC78FE69206575AC4980FA5F50
                                                      SHA-512:4D22B9C27EC07A979A9A3507BFAE085A5F0FAB3D8232842A9F43DD10C371B33010E6E2AA793EB5102FCAC367BACAF41FEA45014BF0C26544DA5370C0FB9C7AAB
                                                      Malicious:true
                                                      Preview:WANACRY!.....B..B.c.8.3D,.H.]...s.[.L..l_......d....f!k...P....s..xC....xH.t...Ax\......./.........J&s?.`..s..x..I.g..XL.m....i;."......`Mw..An...i.c.k...7.....A...U..f......W..Q....;.H.W.4..6<m../qP.Q....R/...S&...vdt[+.O{....:.eE.\.W..V.E..?..t...|..w........,.....O........6 ...3;X.....cZ.4j.M...h......P..#.r.t.:..4.15X.. .x!Z..T..T.%6..C..}.g...i!..W.F.Hh.<dxcw.=.W.~.^...;]..-<..a.E.!.....)U...^..K...Tu....v...'....G".bl.....x;J %4....V.. ......H-...p..........K...^.V......D..f.,zq.E.....U...._+.K7G/D.....t|..w_l...l._..{.R...Q......,..$..h..Q.........9.V%"3.....&J.i<9@%..m.6..u..6F..4.....x.....c.o|@p|\...TTp...x\.i.5...]....?._&.....il....l.4.98..X..v*...w...x.<5&.s=.G)..7.`;.:5.A.E,......4Z/-.=..".`...}Fq.N.}.8..y...R.nW.(`.mD..Pq.Y....._X.g..:.g.V...p.;.W.....wA...3]dUs..N"V....Zh....K.'..8....iA..u.T.5..l..e.*}B#.M..u}-C...;.......a;E/]..LO_.W..|..._..........4.c)...)...*p...iG{3.\.K.qd...wh...o1.....{4......O.(z..f.G.....
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):2600
                                                      Entropy (8bit):7.930915593157378
                                                      Encrypted:false
                                                      SSDEEP:48:bkq3tqfEfJ/P6ZRJajm/bL2Fvm/GFbsgI5iYtgKlrU47fsuiNN8eTuB4n:o8KWWbH/+gGFbbY2K1+yeT+4n
                                                      MD5:3557DE84F7EDD4D76DBA147FEAA8B340
                                                      SHA1:89F1619607A8406C2CEFE3DDC1049514D47B9B54
                                                      SHA-256:70AA5283587AAB71C885C9F625F922B9B320DFE0C54EF9368C3116F04DAA4720
                                                      SHA-512:D1D8DA2E9195E1BC94315599D3529ABC10717A58031378F9A9354C0C926AF498EF5B34EA0720DD54EBC2C07CD0F7972EAB2B40B02E8A1E4098C6ECE69701950F
                                                      Malicious:false
                                                      Preview:WANACRY!....R.*.|e...J..7.@L.i.;.2..k.c.,...X'A........]`......u..@.....Q..N...W.%.....d7.7..J..3k..(6../.^./.....mD.G.r.....J...z.r..r.ra........yt.{....<..F..RSG..!.b.M...#..{.N.C.]|.$.^...B.`F4..~..>..R......K...=.d.A+;..I.?q.G$..\k/.4.DH^J.N..C..............:..p./.w.V'|...2,{.Hof}.}.&../\..]..).x...X.%.b.&Hl.~..Z........u.}A..n..O......9...1&...>...-H..R.1..)..0;........h....J...S.......C..;_B......r^.5x.$..=H..@...P...}.2v..c..R.]....}.....&#)..^....5r..U..~Tq.`...WSQ'...#.m,.<?.....ga.Y...iZ...X.p.......`3.O.'.:.^.......q.CV T.-...."./yM....=.....m.....B9E...|R.-{.S....Df.g.}.Q.4!.D..F._P...q...9..C0..5$.h....#..M.{...d>.dEm$H.H-K..\.I.yGB..)...$.S.4....44...[.q.Z.2...~J........y.|...fG.*..P...D...?.RJ...G...F.2.I.1.-..J...Z.....d.>X".3....n...b-Z..X(!-.....B...l....X..#L?g;.5.t.Ap.........&..a.n>.{rdAv.....kh...w..m.3Ck..."J.._.R....;...tD.l...N.3...X......c&.G.k..j.sq.,.....0`E...#..OF.....!dEZ.b..,.l.jk....,.....Ya'......1.S.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):6856
                                                      Entropy (8bit):7.974237685729908
                                                      Encrypted:false
                                                      SSDEEP:192:69+0GdWfLRSAEHdJ6FeWQsZjMHV645Sxi:gi+Lkh9JieWhmV6AF
                                                      MD5:03953EF6A109F3EC998377B193AA61C8
                                                      SHA1:442EDB9982F879B12423B4665713752EA9E5DD34
                                                      SHA-256:9F515AE9270C341B9FB52BDB1750D7D9194E6090EA36A773AB08C03573EF8C53
                                                      SHA-512:565E46ED05766147ED0BF1B82D0E6C35870117059C7B940B3B4DBE0B9919783BF50A957BDCAF9D0205B2A822292DAAAC3FA4708B1654EE96FDFB9A37B757F970
                                                      Malicious:false
                                                      Preview:WANACRY!.....].... .7T.ce..j%.ba..u.4..Y....z~B.`.@.......23...r..QY.t.Z'.nN.>J.Q...Vq!...`?.Dkj P..Z...M....Z<p.._u..r(..{.3..$.Wo.R..8x^...+..L.)....>k5.Q RP...S...E.d.............p...Z.......5...d....'.......(&.N..yI-S.<...r;5DL`jU...I.........&...vC8..............5..)QR.....P>...\\.:..PM.S.n.K.x....FyJ...$..$Y}t....*.cs...,k2,'m.M.....l.....A.hb>.?.H.....i...w.5..^F.....z5b.3.....b.k..g,...i........1.......^AM.8.....>l.S..EXOL..r3.?..nQqj.2......;.i5..F$.>.D........G34G".F..r..0.....q.M....`..X.i..PF.ijGJ:.h..,.\.x.h.e....z....'........G..1_.I84.0.3..!),..&.x..&...?........Yb..N?.......l.`Y?&..~...V...B4..U.....Da...P.7L....s..!HAEiu.)e............).].4e9n.....).!..K...L.'#.v..L !....P...o.. ......J...s..c0..b.E..#.S.t.......#......ql.."....D.nQ.S+...xn..i=.....T.w..p.9....os..B..4V.4..p(W.O!.")......mp..j.s~.U...=Nd.. a.....3.A#........mc...4z..n.of..m..s9.+yw.....5....,.d(f....._bq.......9o6.J_.s..t0a]....B.../!...5]n}S..?....Bj..h
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):14408
                                                      Entropy (8bit):7.987817624657625
                                                      Encrypted:false
                                                      SSDEEP:384:zJkVjcDQ+7NZZWF/x4/5pjcMcZ4ETaPjp1Q9bah:Oli7NLWT4zAMcO+Ojp2ah
                                                      MD5:8CCA9BAFFDBA1BB75DA8CB69CDEF59BF
                                                      SHA1:43B5603045DADE8124C50E65367F0933613FECDB
                                                      SHA-256:A2DF7A9D7668327FE89F0BAEAA574D42484153A2E0F6E0D1427FBB023017A414
                                                      SHA-512:D17F62958CCC3EE37DFCCB0F689D6C4DB60D71EE4FD8DFACB59D01CFC4A448E8A4BB5FF8AA9D958107C43FC0D526DAD7F346D68BE6EC57CB6FCE69F2DB169930
                                                      Malicious:false
                                                      Preview:WANACRY!....vT.I..&..M...}.h..\.7eM....W..>..a.x]99.-.N..e.NtT..h.+Fcs].R..&.|..g.N.4...\...........qz...h...'IU..flw.,....<..dpb!U..7...t&..\..i..mI..J|Q.rg.>Mh.h.0...e...i..7..Gt..M_....L"F}..NN&.D..UL......Uy...fU...L.)~....\..F..:z......t...%.......`.G.....+7.......RQaJ..E>b.Zj......ux.7.,.%.r.Mt.1..:w&..Z).C...7..0u..v%[......%`.P.5...v5X..&...|-{D..*6%..u............P..[.(.h\..U$.T.4..?z.m...uQ^..........P.....f.3.i....%._....U.eeo.Ak....>I....>..J....g.e].b..D."&A.i..<yu...........N.(..v.8.%8....g]...rk.....m.....\..6..Z....).;...[u<.t.5v.#PO..<.I.e..jbH..r..2w.z.....w.\..6.m*+fk...9\d.@.o.n.\,+>...............~..@..b..HIc.F....R...F. .B.`..P....*.2h.0...c......X.."..`.....oi.....vW|$_.%........A..G....S..6.i....I.1.........B.?...B#...h9g9~.NeU..oT.u...`(....:@..,.....4.K|h...4.....]J.&.[...?D....4..Cc'2..(U..G.....0p.`W..f.fx....&.~....!..'/.V.[o-..m...E.......9p.X..wm:.N..by...q.%...b...e....s.VB...*.I;.'<S.X.]@PD..V....b.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):5240
                                                      Entropy (8bit):7.963648505403015
                                                      Encrypted:false
                                                      SSDEEP:96:owFbjq97EGHNpNsZPjWgOA6h4ADwlDKDruY5Azm4I41bfX3k:rFbjo7XNXsB3zy33Afnfnk
                                                      MD5:35E8E3930B8D97773978856BF9A02B41
                                                      SHA1:B6BF304F63A45B29C6BA2C20FD6C76F53039656D
                                                      SHA-256:4232D8974B2DD6AAA04A316220D9ACF17E4F42E80ADF14543AB0F251F0904247
                                                      SHA-512:3B210D623AB6209692509871B0978F58EFD93ED94DCA89D680BA6C5D4D0BBF3DAD8FB364B18871B3512D288CA00E4E5D16CD9FD66A010B13A3CE57FA9C2BF87F
                                                      Malicious:false
                                                      Preview:WANACRY!....[........q.2......f....~..{.[!.O]..%ZU.R.!.c..#-........@}n\......C.{j.C.}...t.<..Bl.weT......(..Eg.....5-..k.'.=.~F.7kE......=.u....b.?.f.js.J.....!c..V....K.d.tLM..,.6#.^....R..uA...=0M.S..8.-.A"....t.cS:.4Z.?..\.\...Kt,6..K..k.y3..hW.].>......@v...._.......}....1L...\..~|u<.7....:..0W%..d..[..t3Y..0[:.^{..l........'...}J`..`....W\.....{?7."1w..w..O..B.]..d..I.yh....)C.{...'....^.5..;...lI"..9.....#.........(.....2[..;q....z...$~....X=..T8.t..1J..W.....!./..G...]...........w.@>....}..i...A.^.K...w..}c.r*]........>.Yr}~C..).[.Uj.;r..).u..T...j........K/>..Q.2...[8n.^G.1.N........k..._....J'.../....y......S.P........j.^.....q.....S..*.r...<.\.l...J...i....F..@.....t.....x.b...c1w..w\.M#p.@.a..d..-.>.N..X..!...?.`.Z"....f3iO..2.;.1|>O..Q.fc....W~o.[.C..0.]..pR%."..f..)....v^.....'..............oM|........P.a...2.Bx...z..O.|......+m..^..?.K.(9..S....._.e}@...2=...w...A....#PP.W.......'.....A.h..=..1...r...,...Ya..&.y..p..F.PcM..Q...o.Nh...
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):8840
                                                      Entropy (8bit):7.979331443465087
                                                      Encrypted:false
                                                      SSDEEP:192:OpRI4G5/dSA2BuIA2TiTpy2TuY/5Fy6RcMj+GwR2TqYVdsu:OpNcN2BuITiTkSuYhFyYcMjw8XVGu
                                                      MD5:F5275B6CBFA277C722D82BB3F11145DE
                                                      SHA1:C7BA879215F86B0DEB5B3157784B0F9A46068B04
                                                      SHA-256:41198BB0E558D32405757C026C84BEF69BE65B0911EB68FFE292C583C46B05B1
                                                      SHA-512:A361E19FAC70DE340A3B7457BFEED32F385FD3938159D33897C0AE4CE509CEBD167C422D0A8C653EDCD692A8957FAF7FB9CF94E1F8253167D31493759E6E6316
                                                      Malicious:false
                                                      Preview:WANACRY!.....f....M....@f.j....ZF.8Qa(q .2....!l...G.. .j...u...:......v....2.ix4N...Im.. iY.F.xk....Q....>u..fe.E...m...y..\+{j..w.DL..I...f...>h!.lg{..~"......].o9.....W...^{5.....a..M......E...q.f......@..P..Ch..A.*...o\.|2`..!.cP..+0.f..c..Un.i.......i!........-q.m........,@F...+......:..-...|...5........!.4..g:.S.|...&+.u.$.{....t........~..[..!}w..q.1=V:.Gv.....)26on.O.............<.z....O3$[.4;.g.d..U1!.....4.!.@\>.2i../.pV+........T..t...D.3MQ@...V.V..........s.&.. ..#hM>.\..}8@..../.<..'n|.n.!}..M...A..aK?..Z..B...,....0.1gi..\..p...7.U.q"..8R}b$X.......t..hl.^....5.L_...~.F-..Z.@.%y`w.. \........H.C..'.y..z......`...<..S1.I>..w..(.r....ALR.k..,....>)?.K...'..NH.7...odu.4...[.>.B...)..$.NNQC.c.@9..EV>....~............c..Zh&...M..W.......2....P....D....-.<.....|6..^(`N...n@:.f.V.x.y..h..h..\....?I...Pn.1...r..[....Z0..&..&+..).Z....l1.D..].G%.nT..(...`.=A[q`.vA.^iH.b...........X..{c.......JI....o.".*......K..
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):9032
                                                      Entropy (8bit):7.980849484644189
                                                      Encrypted:false
                                                      SSDEEP:192:5nhYIMzM+4KZAqllWpgOqRaBck8q+miyaDdNjkmto8Cq4:kI8MPKqqll+LnBckp+mi15+mtoBP
                                                      MD5:F1F45D228ED7D2B53CD136DE4CC4AEA2
                                                      SHA1:757D983648DC3B80F3BB6AAC6C6131FD18779EF4
                                                      SHA-256:FBF3F769B96D288906A2B5B498CD2D8792F42C69A8CFF2749A6001498ADCCC58
                                                      SHA-512:360532B63EB40E70EBCC6FA5E73C09E23A3994D96C3F2B5F572EEF2882AFA85D256BDC3D88AC7926FF051A7D815CE8E1C56F52837BACFA7F064125C1A3E1DCF4
                                                      Malicious:false
                                                      Preview:WANACRY!....!T..gffhou....q`'...U0....).qxru"78....fj-'..F......s.Haq.q.?Vu.IB..F}1.{..o...|..7&....7....>.N......pEb.M...]{..Q.-.Aj$l*.X....P"f.....%...@.........#.....].F7~.......h.O(n.ta...-..-..Z& . !...K.?...&@ora...LKko...*"wC Z.......f7.....r..M;.....*"............g......oR....`..F*..NI.d.Hv..5/3.w8..5.#$....!E.HV.....'.......(F.V..(.6....nwy.Q.b/...**14....9....Q...t... .Z.Q....E......S.Q......q...<.Q2........[].J_^..#8.Bm.T......].|.b...5...`..5..7....u.n.{....rJ...#.{J..._C.]....^.%Z..`6....2gP.....`..Kq.}.o.J...O.~.Am.. ..J.u..........x.....XOx.#bA..I...M&..c..A[..,W.p..V......D6..G.e.?...q..,-.o....-.Wz...%.../.=[..)...g...'..&....:4.....5.... ...C..`....(....{D...g0...oT,.,.u7.k2..Wz..jn.A..J.Z..k.s(.j.K.....\.......a...Z.|...+..R.-.:.;.~.N%.w..a..C.1j......v,Nt*..0GP........h..o.&k.^[:8....M..6.cZmO..n.f#..$.....Z..U...F.=..j#..~q...L>.}4.......Y..l.............I..K..o..@..u......1..w.*..X.~."_.Tk.w...i......34..{.K
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):7944
                                                      Entropy (8bit):7.980834947889064
                                                      Encrypted:false
                                                      SSDEEP:96:oSiFkAcovdaYFzUy7SwESpksl4kIWP3UWIJlq42Sb+mRH6x78ZpLIqgkEbRBC0UQ:gkYydSpNJ3UDq4HRah8sqKkLgnv
                                                      MD5:2B1CFCD43678D4A7F51EF4D0C17DD90C
                                                      SHA1:5219525B46E6A3F26470E96C5509073D98EC0E82
                                                      SHA-256:6D78D679DDE68318CC69D67A7F8DAFACA507021D6D1B2161EBE2DF05563139FE
                                                      SHA-512:FDDC7EE3646860861BB8F253E4DB5474A783B57D411345F94642D67389F40D4A34DBD32F5C023F1B2D99D9D0C14647923EE9005216E5EB1D873FAB3723753A44
                                                      Malicious:false
                                                      Preview:WANACRY!.......a..>..N....X..on...x..L....O..N...Lh.H...rGX.K......$8..p...s..v+.!...:d..>...)..=L?.1.t.qeU.....]....R..X.B.M..[A:7..1E.....S..Bi..W.Z}D.u....e5?.p..>'..yu....U.0..J q.bS......d.....]Fg...yp..Pe.V.?.....Q.._H...*.d.@.t.Y...bp.^~..............Me.%:.Z.........R..g...#<FETh;.....N.Ml.....w.c..s..DR......D.d.....U.}>...:.3.q....hn'.ZO._...C.0.#..s..V........z...W...3..Qt.;0....7&..%..f0.}Sz...VpM..>Sq.......3..MG$..gP..rSF9....^..{.....1..S.....n...j.`...i.J.,s.x.......;...........Qg....[S..i..$Ly2.B..o.eR..~l..[tPPJ..a-1.....&..VR^.>...x.......W..p>..G..#.5.....(BpD...<..8...(..Ea.d..MRa.q...|.h..uz.G&.>....3OJ8IN).%^...8.L..Y@....9.5.....-u//..as.`.......k../.l...v,<%.kD.+. .es.O.......y.......z-<..T..&..N..Y...WU.=......G..>..."u..K...'.j.P`.x|.<...U.. ..4.b...k.....cM...g....b....W}p.0.n.u..dZy.=...[Q.yD.....m...y....P...m...d..\.'..4.G....X......k.2..V...<..."...T5o.........&5{3e..j.....`jO.,..t.'......fK...5.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):8984
                                                      Entropy (8bit):7.978837207111001
                                                      Encrypted:false
                                                      SSDEEP:192:9BrvxMvXeNMy2Pa20KTSP+la77cGS5VqLi52Q+TYDOxPZbX:ZMfeC0KuP+chqR52QLOPz
                                                      MD5:C6257024D3ADFD31CB5CAD070CB5F985
                                                      SHA1:82E8D5B9724209565692703CBB2FF70286AD6A43
                                                      SHA-256:53A89AD636B2C9C558F1E2FF82DD72F0FF22A7E7A8A8776B3AB0620708B462BE
                                                      SHA-512:7C104C3018A829A37B1C3C508B55A64AEF86D7C3FBF7369BB51009DDE03843B84B7BAE3737E5C343E4154A2CF55892E8486C04520063F32030ECE2510E2DD168
                                                      Malicious:false
                                                      Preview:WANACRY!.......n..].*T.37.g*.%.5.........$.....F...S....%..7.]l................._TW8..s..,..u.j.a.m......g.....@[A8..G..4.#Pmr.8....F.h.p...C.....}.>q......Aj..@.F....l.]'..n.d.Bz"..I...1Qg.z....Bx.g.i.\..z..i./....d\......[..Ad,..,G./`._.5..`.w...........!......."....q.n.x.e...:......1>b.#..x........Wwb...c....dx.N...B8.I3.....H.....j.l...Z..._n.Gi.."..".7`.B...zB....YQ..W.........s.dp(~.~3z..$.t..>.....Bh!.[._D.....+*.U8.;.)...%......JZ.....c..d\...81..i0.q.IR.{9h......;........4..x.~.aw.........o...<#.!...w~f..J.;.!....Y/.rBx....N.|...\..F....h..^{Xe.2*.....+..."!TH..Hc1N..h.x.V2.......j?......] ....db|......5..3..........'f.q...H`.XU..y.F.yj..X....D...\.Eq...f.P./.O..(...,.-h>.2U..N.....Bl..~..RJ.i.2:v.!..%.o=od~-....}.C...n"....2`..1c."..b.H(..C..a..2.....B.~)m~"j9`..!....;.%4../..0.A........N..f......Bd.$s.[w.t..?.7.G......U..>V>...P...Tu.r...O;.>P.(...............X..,..sz..j.....W...}....-..-.....6.T&z..`..U...mN...
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):7032
                                                      Entropy (8bit):7.972488635849811
                                                      Encrypted:false
                                                      SSDEEP:192:AS4ldtrZShdRdY2js0JB79rHy3rvBKnVC4rADyFQO:vY7r0hPWqzzckrsyn
                                                      MD5:1FEAEF8C832D8E10BFA22E7A06E9FC83
                                                      SHA1:E24EB225F1D99431D8CD41B85846BBCC172499F7
                                                      SHA-256:0BC34CB8B8C8AAAC5445E521B6DA386A1560D74700174FB0426C84EBB38BB82F
                                                      SHA-512:603A9E93124B2270657CB0D55E59BD5A7E842D614A09F2E7FF3F351C4912502868C0592A80F2995C419E80D09447A616C95D7C17B8A7F1E299F82D6E97D432B5
                                                      Malicious:false
                                                      Preview:WANACRY!........IE...G.v.@....Aw...a......_....X..L.M....pL....H.p.u......H.R....l..m../...no...U.......^...-e...........K I....I.Q..#.*....%8..j=..,.4.^.?B....`...'...G.B.....5x@\M.g..........j&~.....^..&G.'r.A....#.......2ovTZ..6u..@.eW...y.Bd..ux......T........f.....)*F..`8[R7.HU.,...;..p.=..ZvK.....t.8.&.uK...x.....1.7f.h<*...}....m.yI.h..+.F.M..Y~XdR.{.f.\%C.|...cwP.Q..G......<6NE.I...[&1M....scd.....P.0w........k)o6e...2l..H...EJT.l.....-..9}.8,>...;P...NV...4>..(...&f....'.4..s.1..@....*..).KB.3n.....E.?Uz0....g........J8.`.)PF...M.P..Q.Z......Z.....6.Nq..azr|c..T..d.p.s<....m<.M.mE...7l...V: ;l<9..>.k.U...X...0...?.)!@....M..ir@.....&Z{.#.O..^..~.......l.M.3.c."...vsi........'1.....0So.....|.......q:...*.b,.....,....E.+...X.~....j]...W.y..*...BU.....].A.Zp.Z..s.C5..F.)E..n.K..o.L.|....g9...'.Y.}|8............59.+.=v>.2*.A.....q)=.JB....i.H6.\.b/m.F|.a$o.;....M...:..Q.....C..k.....$|.f:.X@.oRaC.Oz&...@.A..I.Z).......sa..y....q.eS
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):7384
                                                      Entropy (8bit):7.975968225239877
                                                      Encrypted:false
                                                      SSDEEP:192:7C6me2zU16DFQqss1wk6b5/W1m4wItOne5o:Ope2gpJkp1m4wIz5o
                                                      MD5:FCF94EB32ADD1652C3B9FE49427044D4
                                                      SHA1:150C8238775BEEC8C2E041B511456D5CE5C7EEA4
                                                      SHA-256:077F56EA5663D3B3F1889CB9DE44B54D78B6667DC866B610DD91A6B83448A3FE
                                                      SHA-512:A56D41BDE351F708D6F647D02548EB4B5A1E594EEDC714BC9ADDC6F3E329493FB292F1BBF914CD3DA5ED63B9F1D99257E77DE1A4C97CF80792A52AF479EB22D9
                                                      Malicious:false
                                                      Preview:WANACRY!....u................9.{.b.(...l....1..+".46..6....._.q*.=3...k1./3&..idLs.L-......*....4.*....b8B.....`..X.j....r...Z..$..dMl...%s.{X'C...q.....|T....0J.U.EL.\..u...AXd.........d.....z..Z......\2....8.43.:.. =quV..t....F....xQ.SN....Z,.Z.ec...BJ.$............@..-...hm.d-.KC>..J^%@...c.d.....=.....F.....\..&~?Vn.k..8.t.H.....E.s.......`.Up}.?...pRE.H........?xyP{.'][..C...h.^..S..'.k ....k.9.v...;<t..........PJ.....&^.]..~.....X.....;w...^a...jd......S....L.X..7+p.<..2(.q.T......^..T....:K....E.W.....X...F.-W.....eNX.k....np...`.r.3..H....!.\P.K.=...0..;X.*(....f.Zw./.F.DK....C-kC]...X.@....x_W.......]P)..{..yD.H....47...#'%........sh.x.(.<1.....~+..Fe@.Y...z.{Dz....*....+..U...&e.$.M........U.iu......R.f...l..K.B.K....e._..Y..[.d~-.zb7..8u.QZ.... .C.T.6n.g.......s..#..|\$.#.w\X..p.*.a.aE...GI..NyX.J4...h.$....r..4...Q...d1.w.m!........J..Y.~b_l...K....Z.k.~l.y|ZL:=.\.w86..S:on!.(..;..n/..yA....,.o...._..X.1.y...el.....S..'.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):24856
                                                      Entropy (8bit):7.992357986757597
                                                      Encrypted:true
                                                      SSDEEP:384:C8TAttvxvsCoabcLksLhwkiMsJFO3P8nfQ6458CnvMgi4vhMwRL4+6lWS:xc/psf4lkiXju44hvM/4JMwRmlWS
                                                      MD5:E7A351456F81A6292B4117227092F996
                                                      SHA1:0F92B55C924BCA866A218E120EBBEA5B9859149D
                                                      SHA-256:794E193CF6533D51685AA74CFBECD798EC55B945A16775DEB6930489084DC0A1
                                                      SHA-512:D4EC5EE936F2D5C612ED73CD8BBBC824CEB80817A9C545BA57E5BD0B768670975418088E68C45498ECDD10367993B9595B610DA96F2B655BFE64DD6D68E4EA0E
                                                      Malicious:true
                                                      Preview:WANACRY!..........j.H.:..B-$....I..13.em%qY....O..Z......M..8.._..f2.#.x...^..R......'T.p...H8\...v...=.E..4].D.......A.g.....R.v.]......2..O.Z....;....Q....'X..=.K..MH<..N..Q...&&..@...M..<...F.2.2.<..)}.h...7.....S7.#...".."..i.`.]*..+\......U...o..`.\.^..u.....`.......a.9...[IjO..&>..W.b.>B4KV...".....[..l.w.vV.....c.}._.j...wzKD....8.aj.....4*.......U..>.0r..P..0.]....$..q.8eWid..t.....fo....BH#.v..L..aH.._.PZ..C;gz..-Q.n2.6...y..|..z~71.....8..?.{.z..\.y.a.m..U{7BT........:l#..k7....S..u.U.(.,V...."... @....FT..Xd.#6.<H.d.l..C6..TY.V>.t...6...]...x..'......h].L.:.K0.47" ...fp+.J.-@..!"Yn..C..N.cn.q!..8/q......M..M.9%,.M..I...I..}.>L..A...h.B....b..1.._.p..O...]QR,e..^..z......T.^..C.=a-..8.~`>.rU..It..).{(.H...f....y.A....K...L....EI..~..'O-o.....H.....1\..sf`p..o..'0].?j?........,y.T.l.*&.wQ....fe.'k.ak......r6.Cw..m..AuTs.........+2&..2q..'...*..5....f.-S.CG}._......[G..<...!z:......L"..Z...e]....4.........i..[.oz.}...#d...r_<dH.5.8..S.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):24856
                                                      Entropy (8bit):7.99272444413269
                                                      Encrypted:true
                                                      SSDEEP:768:XsY6mBV1VK5FNsfVJCyCPp7QVASJkkkJskah4W:awzK5FNsfHXCPK/6vxW
                                                      MD5:41349500129730B894A11DE757B6F30E
                                                      SHA1:EEBB375DC57F4F74DA48FCFF6BF3C71C4E3C536B
                                                      SHA-256:4BAB750382A7FFAD568D02F760322503786A679BAA497AC800D50028D8ACD5F9
                                                      SHA-512:956B6E143AC66C3C612255ED771FAA9E6E8A98A11F00F15966427B4F4A15D975069D4310F849FFAD85EEF65A849010F8B4A0FDFB093DE9E707FD5D7304ECB11C
                                                      Malicious:true
                                                      Preview:WANACRY!............j.b...,.......W\...'..>.!p..D.8..S..!O~.o......E..l.$@...G.V.*-.u....|...(.x.?5...P......*;Ge.(.....@w..o+...k..u.N......~I......c....]%......,..O./M..c.n...G.....M/...|.~G...!..T./.61!].....R.4.uU..........Q.,~j..:(....c......5..R......`......(.}wH..:Od?.`...-..C.Ua..#...o*..{F. ....{mB....J...........}..:{..;..*...._..H.B0kh.&..i.1Z'.EJ....T2.#.....f".v...cQ.).eL...JtJ.8o..GJ..gp.....T..C.e......9hbD"hm=6.,.h..Z.Cc.6..........,.>G.N..............<._.#..Z_....Yu.~.....Q.6...l.0.y#....8t:2...Q..{{.'S..O....#...&....v..+.z.....@.=7..,.....K.z.}...(. ..N.c....r.\..>OV..J....'L.r...>.C$.........X*.D.|. ...z....W..2......I..UFQ$...aL;.....).c..M.n..~+.{..]}......U..h....wt......!...F.9......Dn7.......]u...u(..=.....R..|=j.I$..........(.D..... f.|z*.-..".v.....%4`...e.W.9.,.NK.....^..3....f.r.[H^../.....v.3...8=.W.gq./.?F,q.AW(.:....D[.... ~.I.Q`ZiF0.....q....>Z.....{..'W..k..B.4!A..5.TV.....!..f-;u....2..O(Yn.B.o.....
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):24856
                                                      Entropy (8bit):7.9926329475012325
                                                      Encrypted:true
                                                      SSDEEP:384:okIsH5eKEC6SEnlyDeTbQZ1O1iY/YJszV38xF7iLdjyOtq+18WnRWARKkXQPuEfN:DHQTLnlJn2IibyV3uIMOtf8WRWAiwoh
                                                      MD5:4C804710B2FB807C4C8AC0718B4948A5
                                                      SHA1:72CAA14EB485727757747AE8872A902A79C9E3F7
                                                      SHA-256:18D8D74146D954093BF2342892DFCD94FE69E3FCF192DA42FA2DF865E871970D
                                                      SHA-512:30DCFF09DE5758C25E95F49267D6818148D494BA90C58C4F9D11AA06CB7369E5F8B21DA64CF9B89683AB05B61469A03A9CBEAD094B42E22BB7BC0AA9974BCFBB
                                                      Malicious:true
                                                      Preview:WANACRY!....`mO..........&........;.....7...<m.>...O..x.-....../..j.o..L.-S....@.J.EL...r..&eoH.?..E..M........m....1'%@.1.*.".9O...'...#>e+..4.jq..Z.Y~<3....L..5..Y...,.P.....JI....C `.`=?~.eK.9....+..,7.s[QB.F....k.r..)....=oH..9..,....2(.z..#N.''m......`......#...Hv..R|...F......}...1.N...E.....|....[..[(.f.6..4.s.>!....2.x.^T.E.N.......2.z..'! ..E................Np.,.).%.....I.pj.{Yo"........._+.)....=..\u.7S....v..v.).h.F.`xL..a..v..g......)..{..S.`...".n.k.C..'.....O....W..P....3.q$.,F.H.....qo.i..v.Y..%Ha...Y.G.^P\}i.......{@..T.*...N....Hy~...]..`.J..F=..#.H@!4A..nn.w....s(..lF..._2QR.WJ.g...o.B.o.."......xU.......S.5e...)O.^../........\..M.N'.)5.)!..X1........4T.V.W.o..Uv..z<.&.oe=....8c....D..H...^e...........v..@+..~t...o..W.B.O.u.D....C k..>.o.W8.!.,...,ej*..q.".*..T.B.....iDQ}......,._..WSh..6s:....Z.i.....4k..5ui.+..:..|'.Kx.Zv:..!M.....t.......D.(...d..V..vDi...<.#.......G+..\.e.<Z........JN.MG....o...
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):24856
                                                      Entropy (8bit):7.993627001488084
                                                      Encrypted:true
                                                      SSDEEP:768:Rzj18d7UTOXeTadFblgMNj346ltJhiJb0SqN0uyv:Rzj1Y7Utwbq6TiJBq6v
                                                      MD5:83B0966831C38D3A7CE4C72F1E861526
                                                      SHA1:4D12AFFC7D2C06698DBFFF6BB280BC1CB5E3C724
                                                      SHA-256:570EB9C8E8D9C6657336B82BE7A913ED051FD6ABBE4AEECED5940F0C95B2595A
                                                      SHA-512:D06DA610FE5DF28C569EE336AAFBC66F3C4DB8AA00964587328979758376D95BEC8BCFC003A7374BA2033A4C52F0F0F871ADA2B4BFA18D413103B427DB70A8AD
                                                      Malicious:true
                                                      Preview:WANACRY!....z.....z....e...0..v.8....4........t.....T....<.UU..,$.3..?.-.z.".oVlZ......<@...v..>n.bb.q....6..S.....H.b..A.5.O.f....dN2....0...\.K.C...^.O&.c...8...$.y.NV....I....?.e..)...*....U.Q...y....+.F.s..a.....2.<4..m...0.w##.....Wv~.iQ2zf...N!.....`........"q.g..Nv.bg0?...JZ....."Z..%...../...L.......6*.D_.tx.2.Y...`...3Q.....7..B...S..!(..,."#..&l..0..R....B0......4F.$.&../.,.!..r.....)..{X9.f<..N.zY..8.d.....,.Uc.q.T.../....J...e.....'.o....v..UO..x..PZ......':..,.6N....%.%..7.T......<....yq.>#B....G.c.W|.J.*...~a..{..........Q....n.jB.9....tp....r........l......Sh.0..2.x[h.. UV..._8k...|o.-...%.,.....\..].!.+.......9.n3..(q.B.~j^..(..y....|I&=8.:]z.P...t...._...0.f.L..!..>...&.8.`.......t..{\.......b......%X..C.!.P........w..P......H....P....}.:...Z./?.va..`5/.f_.}.............7.v..@*.]..%..t....z.a..R.'h....U.....$.....,...j.BQZ9.Cs.5....?..*...L&....[...ck.LL.y\....)..[lZ[."..%.#.8C.6...#..v"8..3...../z_...` ....Bx..3.'..Fo&.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):16664
                                                      Entropy (8bit):7.989325880188682
                                                      Encrypted:false
                                                      SSDEEP:384:5YSkV6LYq/VpSR3/gCj02skbFAZDFReFl/crPs:hk4LYq/VYR330rrDFRi/+Ps
                                                      MD5:D5CFD27207194F77DA3806D3B8B0C6EE
                                                      SHA1:350620204384FF5ED6A908C763EF53EAA7DC62DD
                                                      SHA-256:BC6E03E95AE210DA755456E360BE7AE5A406D46C58F711758FBFA751ECC39C4D
                                                      SHA-512:064CB16DD96F0EDAB945D403E31AD4266FA65852AC5F0C64E80FA829650AA5E6963C235B85F69FEA56C91CCD4AC0D5B1160E3471C8D04F1C85BBF9213AD26F41
                                                      Malicious:false
                                                      Preview:WANACRY!....e....D.u.t.>)L..8....@WQ3W.v..`F;f.[. 1.5?.$..7..Q.R1_V..x.h7C.2.....w:.Q.W...J..+f=.XOk.\.....m..KJ."....Q.\..(...p..M..}...YG..'.j.@..1U....]..C.._1'...2......_./Z...R.[.[w...w&r.....q...iB.F((..P.....\.s...-...q..8..X9...XDb.O6..?.......\P..._.Hd.....@.......4[].<..-.^f?)H6n...... ..l....O(.......9...E s.R.w.........z.}...J.0..D..:."..Ed:...:..3.....u\N^..A]......9iV|..-P^cc.{.^..(...(!W..1.#.....)....;Z.=..a...w..!Q......Sl...N....g.y.Ix.._.-.2..nj....N.BdC'.p@...h.......AV:C.....<.>..m..z..E..w.t."I1........|.#I.R.../....|..iMm..NA......%.!.S...OwS.u..=.%....$\T....|....h.?E.9Z........<a./t....)h.c#..y...1.Z....Yq3Cz!&X.[.gQ.e&.....65.p....F<(....z!.B'I:.....V.[...+..hU4.....(.Y+^N.`.a'.........R;......z.)....w....yK........X;$uSt..;........x.....q.,...p.Y......9..m......l.y&..DQ~....B.....O`.$([...W...../.....|.......6.h..e.?.g..K......`.Q......-...=.7.i...O..g.....Z.U..Th..[..e....m....b)X.....C!..]..^.LDl..f...DGr&...[P<6e0.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):16664
                                                      Entropy (8bit):7.990062053736231
                                                      Encrypted:true
                                                      SSDEEP:384:4tlSymCltO8u9qgSmIYXAxE/nQmiZ6uhQ8h6dqOpcdZMv9:uFmCltO8u9qgBXAxE/n1boh6gJq9
                                                      MD5:619F1BF935394A26D8D11CDF7F6C498D
                                                      SHA1:AC40DDF765E1D756F99056AD2CC526B436043399
                                                      SHA-256:B82D87BD9E9D40048E36F48DBB385128BC4D1200269F4E819EF6EC62A805F380
                                                      SHA-512:40D8CD0D0F69454BAF69B7ECAA7EF40B66F6A20C47618F3F760B4CA1277B471C63C41C09BA33C89EB8A25C9ADBC5D89EE6D0258B52E9743E391AB69BDC27CC13
                                                      Malicious:true
                                                      Preview:WANACRY!........+...TR....c..g.M.c$..v_.. M..........k...R.q.?..~ .q.W..l......d.5.9.O..@.m...oaf.'F....i#.QL.z*;53$.g..zu..p/........!.I...].....X...x`..w...`&4!k.5.*k...[..\...*..&A.M}9....P+.(..(..o...k....r'/....../.F.N..../.Zp......P..q........v*.&0......@......M.@..M..#h..W.eE..x..3.<RG..6.+V<..B.)}&....]........ ..uB>y.....|...@....R5.*'.y.....O..g._........U..p.2..!..D....^..3..S.-f..^.d..6.}9.W-jmG.?O9@...k..a..R..D..../8.E.+..K.9..s....5.C..x*..BE..r.mO.*Eg...d.t....)...{^`..P~.CQ4~..B...C.H...K......r..W.....$....R.2......v#..2..q.......s.....Ba..T.....t....0.G...r.b....~G..f.....Z....}4.I?..........J..#..'=..U..`.bQ...Q......{.!"...SM..U8...M..G.v...?.B..W........N..=.\....{...k.,.....D`..7...W.64.. .r..2....`.......,.! ..`. ..bt./?.lF.eo....z....Q..AV..........Xj.3...Y{...L.4.h.(9.Wh....<..r.->.nA.......".....qN4T...X'dR....w......|...eXKUVR..E"..p<........h.D........KE...}3j.C"..i...c...KP.....|...;....:<.Tpr
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):424136
                                                      Entropy (8bit):7.999565940864991
                                                      Encrypted:true
                                                      SSDEEP:12288:68hTdQiPjNuO3HRVCGxYbUSM2MI/0cw/a:fpQejgOXBYbMcP
                                                      MD5:5B2D8CF32907341DF6C12661B7026AC7
                                                      SHA1:84CE1B4610795ABC6BE12C7DB23BC2CBFFE57212
                                                      SHA-256:4E85C657E9280E137C4F84ECD83E96EC8EEF65F1E6E443A76B53E7BE8B823991
                                                      SHA-512:47BBA6CA31486862359F9CDCFBB9869B3CDCEFF9E5E19EAA3AA1044000F05063C7C4500F363081FBB46ADE92AA6BC1BECEA79D1CAD47B07BD8F2862C83ABDCBA
                                                      Malicious:true
                                                      Preview:WANACRY!....ZK<l.....D.p[.j?.*..}p.Jx...}9...C.g.$..&^=...~...]C.{M}<..S^.nz..P.z..;.D....iC.a.O..."..\.-...k$......w....r&.E.7...kq/.zPn6l.._.[..."L..l....A.>.....o.v.M..$.D.e...#.1.....v.*....?3g..#.O...}..#....5..2..?.|.\..... Ls.w}|.Q.._{7....c.._m%.....w......o..^;"....G..3..t4.z`...@:..._.+.....C.......K.~t.m..9....Z.U....._+.m|...V"].....JI$..d.#.mH...m..N..L.i..............,[.............4~o[0....+7%..o.Q`N.fGn_.*.,).:.].{f[d...........&.....`1T>.,.W.Y7..O.....y.AC...xe^..4...]HR.$...k&..-...Zr...!n0... ..b..0.a..-.....)h......C......I....O...8S0'V.....t....6.\RIKJ.#H...Lj.'..kF....x2....5....'....../.V..:.Q..u.."......VI.....V.....M_.`F../<t.Q.2...\.K[....Q.`&|y"*..v.......)!.._......Q.#.h<5..A.C....!_h.]..:..,....F..5}.)..4.h...O....jc.K.\...g(I.j .../..lX'.....s....Y8R.C<........f..J..)#.-... .=......7...g...U.+..f..v.3B...X.~.J^.....T.B..}.CJ..im..Q.o.A..R.....,.*.._.S...*.<....}...Pf....'m."Q..Y>...........Y-..=.4..!f.H
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):71576
                                                      Entropy (8bit):7.997208757597996
                                                      Encrypted:true
                                                      SSDEEP:1536:RRMyqpgOC3xAZ7+G2VfaqVY2XHl5yAJIOCx+8qAFqJATi3Yr4hLl:YtpBB2VtVY2XLykIOCRqAFal3Yk7
                                                      MD5:B8267F04CFDD0EFB0B8DC1B6CD3B306C
                                                      SHA1:3A15B20E281E8429536807CA8BD29C47FFA5540D
                                                      SHA-256:DA1A35BBC8E9D357A47A05CFAE9B57C370CEF958ECFB41655F323DC18F4834FD
                                                      SHA-512:554DC070261C8DE279F392D827F0DEF8D0F07DD5E35E36838A0B28579FBDE13EC368C08E345990756756B15387332C51ECE78F10F64913358DF1B396B567F3EC
                                                      Malicious:true
                                                      Preview:WANACRY!............9..$....`)....s|.2.&:..H..N7o.J.j..)~.8;.%./..-.aC.D..../EV...8.b..Wna.k..L....&...T.5...x...8......2|...b..3P./.v.[`..........i....!..4*.Xx...=...+.....w;...=.5.g...5...ab....c&..Q..)t.......u.A.(.V.x..~/q.lT..DK.....Zg.LD...O.z..W...._.............H.Q..~V.B.=....A{.....N...&...`.3]..'^.......Q#......K..n.?HPB.~.......9\nr..`.Aw<...K....wM....Z...W0=>."#...'.U.3.nO#..3K'!.k..B.......\%..c...-|....Kl).A.#4.Y...j.....j.,f{~..t.F...~:.o2o..).Z....]1...K=.U.+..;..H[8.OdnP.J..SF.hr._@W.>..p..Y=..[.L....h..1.4.vz..41@...l.%...}.6K......"...M%........o.]B7..S<..#.K....2.'..o...d....\..u....r^wq........]n$e; t...).. .X.Q....%7wV.....#.)..v.a.....k...b...Z.%....v.O..rmDJ..Z.~.....s;.H..3..>?..s.f...H5-.O.yf(...zp.M...a..5....[XSL.. .n......t.E`<Yg[....o.....LX.._h...OP.P.B.>O.q......(...Z......../.+o.r.*...!-.+.......=x.k.4...B...7..Eg.'.@.oz*.bP.."...BA.3.g...<mn&....j.v%..1YL.N}\..;af..j.^H..............7L.+v.......%.e#gT.8
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):103960
                                                      Entropy (8bit):7.998217584413761
                                                      Encrypted:true
                                                      SSDEEP:3072:e8SjUQ/DMa1Jk95cqNnAWcyuVIXt07ih9bJ6:eCQbJwHNnJcyuVIXt0ms
                                                      MD5:8916F806A972586EFCFC02B7203ADC86
                                                      SHA1:DC6E0A28064D3C0C86B1B80CCA20969648C803E5
                                                      SHA-256:4FFCBE1E0A67CDA900F5EC57BFDA7E5C1A9F503504BB7E299419B49F4C8D8CF4
                                                      SHA-512:EDB51D556CE7F5EE4A52EFB0762C119C7F24C2F51FD713CE4BE3C3A7825BEAF2119EEFE1BF390722D85908F3EA1BFE04C82BCE361EDB0F7ADC111AA31569C76E
                                                      Malicious:true
                                                      Preview:WANACRY!.......@]q~....!..f..t..RH.2...g....J..F....(-....X.E......5....$...Lo`.i_b...F7A.....r.Zs.\`F2..[p......aN..G...d..b.....@c.Jz...L...N...lC.YF..N+b/oB.."]...m......<..D.&....{..^W.O|......1e#.Ine....e...@..4K.......{..f...u.*..h....l..f....I.........................l..;.....`y|....cyj...M....xBA.i.s......ff........I5c.."33M6.......PY*..07.........3B..,..J.....8nd..<.-.*..lO.q..w/#.u.)WA4.9?.....x.s..\..)>......|.z..<sK.!.?..y...2mi..w...f....$.{.s.."......&.dh..........Y+.MW.>.>. ...d. ...DQ+d)}..q.J...*q*.../..;...i..x....e..,...c.ZDd..Q..}..6....)s..F0.k.l..d.K@Y\%.GiD..;.cd.B.ELu....tM#X......P...q.D...M@.j. >5.,...0....f...S..9.#o..e._.cho..^.D....N.Cb..$e#....=.....P.......oj.e.+|..... t...2.S....}..5.......D.(...3./.Q.w......k_..zy.l`.)u..D.j).'..8........G.H...&<.0.f..,..C..w5,.;.`P.@.T{..........@"}Z@.}.ss.I......A...n...W...6.k..h.&..a.R0"..;...s.Cr....P.D.#0..9;,.....:.c.N.g.q..... d...P.3.}....q.h/.~..).s~.o%.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1048856
                                                      Entropy (8bit):7.999848716294727
                                                      Encrypted:true
                                                      SSDEEP:24576:ayhgXyg/TluOB+MoNDLXhgnHUeVNb/V26U/oYZqcCfciQX:aDX7/oYoVLXhMhVdYAFfgX
                                                      MD5:BC3B763E8D88CF075E15130156AB9199
                                                      SHA1:738ADAC5ED379FEE7C5212B0B3B83A87EF5637EB
                                                      SHA-256:AB01DF67EE277546F58795294BCF9577A1EB9B419107D6D4A03EF798D7A27127
                                                      SHA-512:2619DA551DCF6745B5465AED5872B56248A50838A10BA4D1D15079A157F521B677694555AC99989040D1058C60FE0F72AFA4FC7797A121E150C6E7B01076E32D
                                                      Malicious:true
                                                      Preview:WANACRY!........>.k..PX.:..p.^.MH^..../.<...A..T68I.8s..kPxWa.....k.."$Bj......../...Y<..... ..t.*f..S!.t..Y..#t.F.}b..gD.s..'....].%....9..%.\.+..l.R.3...10.^:.m.........."..&V@...St.3. ...#8..#{......|..I..<...".L..=..2.)....m!..,..S..>......<.....s:.K..............^..~.?o.......?._u.XHQE....F.M....H%l...j.....6.{.......(.q..d.?........J5..&..i.q.."....<..eP4Td...Q..*.-q..T.......Oy..]....._.....%G..dF.t .\'1.7~......d.a.C.k9g..u...]g......-....+.Q.Y....2..S<.8g.............4J..Pg....$f.U......!...i:R.F.i.P..!lA/=......U.L..a..7'F...Kn....[5...vT.X..".h...hw.el.....?'.. .....j..i.......l1..y.y.....h.....y>....~..]....V.....'.(g.W...<....y.V.d.>...U.P..5.)\?e.mY.f.8gEy.m.e]..3.e.U.....&f.m.g..I.0..U..G3c..D...(........k,.p....R.....4l..|DbG....;...p.K*..6T.."h.7..(`Q..[..68T}"}.p.6.m..K.MCz.t=.v....D3..vUT..k.8.=.IL...y.... ..(....Z....i.+0.F.d6::.].R..xT.<...gG...rF.z.>.m..&..Z..w..h..."%..gh...!tm;....D.......92..W>L......
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):3146008
                                                      Entropy (8bit):7.999943821547186
                                                      Encrypted:true
                                                      SSDEEP:98304:7A7VDPKsZyeG7QvqInKqhOsmNml1FGLWUw:7A7VDySBG7QvqgPSmrRR
                                                      MD5:4798B8814BA2B4767263F2B3153118B9
                                                      SHA1:5C8A21F94DEBE6F653D00C23C0B7255902E85681
                                                      SHA-256:4B6FCBA982A50EA10ABFC5EA6FB63FD70D24DD7E20DBF2153A5215660D11D24E
                                                      SHA-512:3D0081D5BC18CDD3EEDB9AFB59219196C57F213A02D6AF8B9D47C32DB50BF3A7AF306F9CCC23E2DF457B37F23D5BA90B1AD3F96BD2DA223AE97B604ECD81F9B9
                                                      Malicious:true
                                                      Preview:WANACRY!........3yWTY..S..B.O{n..W..I%...h0....a.8^.*5>%.K....i.B...L..........f.'.f.$.l. , ..Z....K....E.&....8.4..R6.1....^B...39i..b......0.....C.....]...9.r..A.L.|.e.z!....|.Y.Dr.7{.*.P..!...B....|..`I............%+.$...-/h.}....E...6-C:.7.Bb....[..5......0.......F.....>....H.z.<..;..}.^d..C.;_.T:<..v.u$.s.k.xP...7.\.S.3.u....M.....bI.O..&.Y..z=1.f.5U8&.'.G...J...}..}^..........g.|u.*-e".fv......d.\............bZ.3P.\. .|..S..:%.j.j......@...y...u....q...j.2a...+.D..;...f...........0..EJ.2.{9....... ......c.8-.D..B.4E.@Dyeh6.\.b}C.....8.F.m.b.l..^6J....g...4.....*t.Z..8.".u.{.v`Ev............~.!.....q....W.Q.h#7..?.............4...{...BUr..6.[mF........@3...wy.{!;..g...V8...V...U.o...P...Pb..!I..4W .oHc.{.l..L..0.u../..w.C..D..~..=.^}..Vs.2..&R.'.#<...s?XT..:.....Vo..).T.^R=z.>....../QX.h..(.G.Rz.2I.4..M.....m...q-...Ko....k[.6.......n...l...qP$B..>.%.G[0.@v1.\..Jy=......E.6.8.a..1%"....j.\E..y.9.B.].?Q0.+.)..J+....3....c<....t..B
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):2097432
                                                      Entropy (8bit):7.999899046746898
                                                      Encrypted:true
                                                      SSDEEP:49152:MbrXCXMi2huOLsf6XBTyZ5IEw/wqyXIcnur7HFIa6VTN9:Mf6cuO8aSZwRyohuZ9
                                                      MD5:0249D9EBBB628F0C0D577EF9F093AB84
                                                      SHA1:AD65644DDDDA7D2CA4191AA234707BE983DE3B96
                                                      SHA-256:1B4391018A3E1463427EE9B44513EC1950153418199F5C2BD7EE15463BA25C1A
                                                      SHA-512:7D1EB7790BABE50683D6CB4F5FD131EA89F827AC58C1A52BA1FE8FEDE69C8A20F353597F301A4D374643716FC3A3BA624A03EFBC2D576ADEA292B21C428E5857
                                                      Malicious:true
                                                      Preview:WANACRY!.....B6..-.J,.....T. ..W.@..4.-r....b.V...+e....$H.../.Pw....h1....R.l..\?.0.2..`.T..M...z!..^.6..^-i.:.^.h......b`.g."...^O2...5K.6...h...fm.C.sH.....D2......H.....&..K[R.M6.j.#.dd..v.A1d.6...jcw...=...p...c6.lP..".b...'.m.J...J.}..o....e8..(.&.U..Q...... .......w....,.f^..#&z..X.x2..q..6eA!.. ...sj^f...].....i.<.e.L}.I.._;..o?....F0.).J+...e.G.A.#....;...8. X.s.LO..Y/.....:.....=......Oz...!c....f..&.A+.q-0I...v.x...o...mu..{Y...:.\EL.....l..\Gro....I...z1...#ZQ..2Ui.........x...X..\d.).......$..=Aw..z..,....X.,^.....z....e..s#J kHmc...:..-;...)..h.%....f......TJN..MS|.5R&..W...D..9.B]P.@..2>R\,...^>..j.V..B.FJ.@.t..s..E.L.....:.1..8........8...j....AR...7..0N..E......;.....-.~Pm%v.#m$..E%i,.M}.[`r...X1.>..P...D>-......Td..S..?*EvT...."hsz......:.._.H.....}..-i~dT.\|p....o.w.w...1=W.]..n.N9~...d_._..t.g.j...E..\."jl.!k.......1@c..m..'...'......*x..0.......).Z..S...,...!.; .....~.!...vI..........g%...=......cP.. ....g.....U.V.'.n..K.k
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1048856
                                                      Entropy (8bit):7.999829095228962
                                                      Encrypted:true
                                                      SSDEEP:24576:HCJrN24CkQKuBLAxxjCPSnJZOc32fVf0C5LzNwp:HkrA4CFdakYJ8cYCC5LzNw
                                                      MD5:E0ECFEDCF193439AFCF0DF054DAFB98E
                                                      SHA1:9227BC0141F27975A8C736DBC031F0F4DB47522F
                                                      SHA-256:805BF4D5C4A5DAD3EF7099423384AE9D5EC0198829C697467B130A9ED7A11300
                                                      SHA-512:CEB4C46A61F6EA2BCDC8DEAF752724F9A73AB960E373E65F7B107131F1ADECDC93D53D0658752AEE0025977E838AC3412FF39D402E5E13033B0362E8C7BD3891
                                                      Malicious:true
                                                      Preview:WANACRY!....5P..5.#.K.`i....a....f.8....$It...p;..].SP..&.Oy.......V...dgG...g..g.Z.S.Oj.3..h.PRq..z..(..+...D...Z.g..{Y....%q.r..&M.<h..}E<..}.L.....-...7.n..\$u....P.&.']..........:.F...^..a-......+0.m...!...F>Q..[..W.0..J.....PT.7.....c.;...............5.b]....6.'....J.6d;..AG8.?..`x....'.~.....:.v.;s....W...!....B9..I..=.V.Z..'.T.p...}h..I..F...%....!8^.M....4k.....l............._..j.....Jdd..o..V...u.9G..v.k.u...6.....h.3e.5+.b.............a..Hb.......f....u :.*E.k.w.j#.l..,'..'.b.t.3Ps..F...h..B..]..5.XM..S..1.''....o6S.B....x'..p.^...<.o6..\.F.,8.X..Y.P..v..z\.N7d."....s....Y.NF...h.q.7.|.p1...<..%!....*c.]..AE..m.....(.Mw[.=.o.n.z|......oc..Ldm.....\........gb.;...'....,".....6.p.-..|.=$...$.H.J4.E...U....IMBN.F.....zIt.]r..W....bZmo..w].v.4.@./.......!..h"..Xc.LA-.?L.*.q......h...S..e..P......}f$..HSQ..d.3....G.....`...g..0.....<.I.P.-5....h.......g.W.>6..f6.g..._EK!_.....Z.. ..u.i_.)$..}........Y....pT....,l^:.8..*Q.....8.2C=
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):58600
                                                      Entropy (8bit):7.996887800555099
                                                      Encrypted:true
                                                      SSDEEP:1536:VerRQnNZwagcF9dildaEM+Gj6YCAUmc9cDOGEvySgtL:sr8NZwa79dQaEvGj6YCAzc2Dky7L
                                                      MD5:7D56F7BEB764ABEF48F5330F746C3D1F
                                                      SHA1:FCF417306E8F582C09CCDA3835CA8A4ACC107640
                                                      SHA-256:5A4D10EDB53B4A3C781E999D62C24EB227879E20E630F0B19A2E689DC031E00A
                                                      SHA-512:2694CE16C54FADE6D48F8768B0CEAD534A33067877E777F1BAFA23E73357786E34DA26D52F7C9C0D73F2128675E9AD358B54F43699C92BDC7CB72AAC78C26772
                                                      Malicious:true
                                                      Preview:WANACRY!....q.....iii".._.AB>#.... kY...75rk$~g..9.j'TFSx..e.L...rB#......`L2.Y. ..GO..y....q_.V...J.IG..DL..~..4..~&(.{S8&Wf......V=.:....s.`J..-...V...........?T..V.C!.U......m..(}.,0.u.~.....D...../.nu.:@.....(i.(k...ypb.c ....FmM...K..G.n.n3.c._K.7B.>69................P...VJ.z.....t.~~..oj.D....7.#B.."I.Fb\r...S.).#.a..:I...P.....0h.K.k...F:.{ e..`..xf.W.(.o....y.N<.,./;,.....q....$.6AR...-Q..6C.h(.=?..Z..-T.2...H..^!.....jC..Q..h..&...@.........d.!...E....X.0.O+].....x...\P........B9.R.W.f.E.a..%..7..8.2......a..pl%/t/.......3.a...I<..6.:....B?.....y5Y...C-...U.sx.F.t*.g..D.,."YC.%...P.l...Z..'..h....)|..u[b^.L.......#9..x..L.H.n.".t.J4..i...........e..~.1~.w.9.H......n...6,.......y....e.d..Y.(."[.....-.C.........E.a1(....W)4..%..g..x..M.&E3s..H.E.._....{U..#..tj.#=....>K.yk<.$.!......<X@......iq*.T....?a8.....4APd~..D...3..5...+....h.C...kH.3w..h74.../h)....@.ju.....jx.P...|..Q..".mP9.....4.oyk..g...j..z...(..p..>N}.....+...z7w.%./j..-..H.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1048856
                                                      Entropy (8bit):7.999833561975707
                                                      Encrypted:true
                                                      SSDEEP:24576:CzDNN7IG8TpbWGa8Lm3t/m8AgPQhKRLTPkX:C9N7IhiPtubinM
                                                      MD5:B6C25E5E316B643FCB359AAED86B8C6B
                                                      SHA1:DA2FD7F7CD5B752E6BA482B3F400E22E399EE6DD
                                                      SHA-256:A9D8DD24B114F46EE6BE283DA07E3F01C6530919DA90CE7167444B7FB27321BB
                                                      SHA-512:1D6535F1B2CC4C2086F145FD369C5B42D2F3D6D3071FD2B502875909E2D110470215D80EA0ACDEEBD621B3413CCF3388BF0B12F405B0B1A4588734F0BB96D26A
                                                      Malicious:true
                                                      Preview:WANACRY!....G.....d.L..........[..T.b..{.VX...y.&P.o....^.i...kl9uZ.kz.\._.^..^.....31I.z.J.{...>v.......w..:..".&./........^<,..89.a.....B.<.{..nv.....~. .L.....0Q\...`a..J......[....<]J..~.y.t.>..~?...3.C...4...j.mcY....v...{}...#.....O..;.K\.&.."@.z<se.............<o...h.W.P..]..c.@a..''t...,I<dy......FeC...."t.>Rv.|.....Fq.l..Q.q..*((+@...d?......|..V8.X[:.z~..d.8..2-...8.......uL....&3....?.|D-.tY]..A&I...{... .%..v2(....9J24N.B .....Z+.......=..eC_4.eV..c.....c>+...=~..E.wM.N.....j..{.I.D.N.J..F.....I.....a.Q..`'..S..G...]..h...I..k...,k./.F.Q..f...JE...k...\.P+..w..IETq..Y..L.K..W2...O}.&.-...k<... ..eqk........s.n.H.Dx._.,.s.x@...=.j...w.`G..jKW.d..5..*(.O.o...}..gP.t....nI?l.[..j\..3-.dIa3@H.c...X....0..#...!...[.".[6......W...U.`I.X......,O.....|.m D&.t4...i..a&..A..%....g..w5M..g...z.....".)...'..B.W.P....r8....Y)...X..N......Q.P.:D...+...%.Y?J.%..;...n..+......>o..P...?.q.m.-x}M6E|;%.Y]B....Ke ....F.G...qJJLdBn..%...K...t.omB
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1048856
                                                      Entropy (8bit):7.9997961001743825
                                                      Encrypted:true
                                                      SSDEEP:24576:ktO5LINfBjeorcg66EJmgPCWa6H1HuCJ8RRlYfBCFE0peIowUlI:9INoPlJmma6H1HuIKcvwf
                                                      MD5:276201B248D3C17440BD80982DF8DC29
                                                      SHA1:4857F324E496E41458EE988B2582B8B2F6EF222A
                                                      SHA-256:3241F08DBF93BC0717BA7006AD30DD78114B2EFCD2B4F3C5D5B3457479AE6A07
                                                      SHA-512:ADA3EBDF58A18F87EB92CD22F71C40ADC45669D57FE2E8DA7FA7DB550E8A842C7AA327680F642A5EB8F1089DF7115D7BDF92CFE54281EED85A882E30F9D735C4
                                                      Malicious:true
                                                      Preview:WANACRY!.........7.I.0....[.*.LpR....?g.5....u.x...c..E.ZJ..t.................y....M...2g.l...!.,.~.bxb!.]......<\Lf.3E.I..).....'..A........k..M.(...aQ....)S3....K..}.p.....$@X."..^.5.......q.W%..Qb..K..".............H..(.......H.)..k..,*.6.._.h......&z............V..2..h.n..B6..VJ....6s.....uK....B..k....n.X....Yv^.6g.."..H...qqF.Z......^....52......].Sx.}..<........+........0plD+M..........T^..~s......Z..?..sl..gZ..L....Wkd......N.z>..Ju.d.....VR...|'E)...uC.........a.x..'z..K.5.;...*a)\...8m+~!m~..G.N....H......T......V.6.2...]..R"aR.5Ac0 ..|..ozy..))q..e.3%b.....GO..n/...1.0....vXySH...z.=....T...G...P.q....Qx.@V...}..u/2.....f......8<Vz...*.>.#.....S.....s..+....d..a.|Q..".a$....t..;.T,.Fa..^..(i...mI.^............&.];...W ....-..'.a.......k]..3n..._....dO.%...x1..]..<._(U...H..0.}.;.....XH!z8C.izu...J...E.sw....g.8...<.i+...N.;1...{A..}e?..........f.k.!uk..lWF}.....v|.R)..1Vv....fv....]<....h.........>v-kv[...V./|-.**...S`
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1048856
                                                      Entropy (8bit):7.999840288442815
                                                      Encrypted:true
                                                      SSDEEP:24576:PPyB+ZQdFLM41A/YmzxldTAWLXwfPOHSw1PtoR:Pp0FBAwmtlCpXOHSw1PuR
                                                      MD5:AD1D34046032932101A46B310BBF91E3
                                                      SHA1:67194EDE6D9FA1A5CE9D13758D13F3A0F5BE8687
                                                      SHA-256:ABA444F7FBF0E55431BD1363A487D0300A001447D377737260516050C8F6829D
                                                      SHA-512:5C214FD36DBB543F3C34DD77FCEE31661C57F70CE4038EC108F17C272823FA39E6B5AB8625B47BB8156523B85FDAD987112D0343D8C3A81DB0902F17AAAA43F6
                                                      Malicious:true
                                                      Preview:WANACRY!....%J.......X..je..R...5)d..E...V?.......ZC...k.k&........|.....X'.`.f.R..1.c.b.X.e..U.R[...+...*..R..Z...I....`....Yc.<.^..E.cw.W...N|.8{.o..u.pG.Q..V.......7......F.vH/0\.h.`...A.1......j..o....K..(.e..*H.M.I.....x.....kN_.]y..XW.....8.q.8f..(.................%...&..D.2.b.v..._.3q`Y...a..=....0.a..w.[.5+'J... ...N`D8.xo..8J2.l..............02;b...V...F".%t.......y..^?..p6}.....n..>...%A...q._.r..W/O<.gN.{.w.7.fG.!....N./.}0..a..g..p.M.;Fj.c8eQQ|K.......*.?.. ..H.E....Ehj...w.......^.u.i.l.x.....5..9{...qT.PQ....B.Y.............._.VS.2P.(.v\...mvLo.I.*......;~p..|fC.Z..C?.....lxt...J.5.|,D.!..(.M.1o..G.g.s....}n$[.f....}h..%.*.Rh....v@...w...\..p.?I4.)...f.>..j...wE.>..e.%:..F.\....z..K5M....i..XW..[H.e(,.L).YLl.L..8......c3....".D.P`...?x....5*.......Hi_.^.Q.c...M..\..8.<..8|...i.lZ....I...T[l..t ..;.}..O. i/....B..|.m.y....Q.w2-#.F.SMrx,........)..@....nb..:5A.....].C..II.a.....N.........N....I.M.b...5j......FT...I2.x.k.[L
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1048856
                                                      Entropy (8bit):7.99982880447374
                                                      Encrypted:true
                                                      SSDEEP:24576:S4QRhpXh1sYc4oK7vN+OBGLuiV1k/5A9JN7w9i0u7tK/x:S42xsYc4XNFGV7k/5AQi0u7a
                                                      MD5:DC9C9CCF375F5822FEBA1C8A26F31657
                                                      SHA1:065B05E01F54E2BBBD7EF8B9E93242FC058F5127
                                                      SHA-256:361F839A1927E7BA5C5A0B4DDE055990F3A01D9F7011F38CCD15E6D80674263E
                                                      SHA-512:3C4E29376CCE687C0D6054B8BB6FF2114D3414824954AE4864AA7E61CFF816BD9614F1010B8D47B5DC8861E02AA36711516450F75B49D19811A655E4BF35DF05
                                                      Malicious:true
                                                      Preview:WANACRY!....u...X.!{.!g.TD'.k......-.t..=...........G.....9.EI.0ez...../.m...."..X.../G4.:.@g.m...u.>.-.0...M;.6P"...m.:Q..d...CBh.|\:....B......Y=.>n.U>.......WA.............P...eO.l. G:.;.M..p.....9..4`.cV~]J.n...%.u&..gO...Z....D...........WH....uN.K"..............I-0.Y........30...p{......4!.....-...;v..Z..m..>P...g.....7wo[R..H.D..qg.,.Fko.5)...?...C...\...Le8.E,.<...K.v%s6....>........k.....6.t1@.$..K...uv.>K..{L..C.#x..;.....TY.q._.@,`iF.S.......U.:0...ps..S..T..\.{.....r(...@...h34.K....7@...<....#.?.)....{...0.... .;..3..3(3..+.j.N`..9..oY,..%.).%..... ...m.&Wi5x.q.(...#..H...,..~4._..Y.....'.f..u....GY....'&...t.M.sU.......A.G.R.V.B...<....;wG...4..\..}..u..C..0..Y.\...j.Z....]'N...g....E.....*4!..;.1...Z.^.....Jh...3....T.9.5.Y.U%E.j......2.l...4.e.....7].N./k...Fv_J.4...C.9Q.H|...27..`.C.o.....Q..qB.[l";)+.33.0XG....gm...m.f.mr...L. T....I..8B#l.k 9...^.e.O.Z./.'x;.....7...Aq..kZ...i6.8.2G.....x.Xv..sB.:i.....:.=...(.@....`A........
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):4194584
                                                      Entropy (8bit):7.999959721238994
                                                      Encrypted:true
                                                      SSDEEP:98304:hP6O4sTB3RJiJsGuqNVsBuf75jKl/V3FqGQ:QqZmJ9NVsBmjKl/V1q3
                                                      MD5:C8D05E02CB9EECCA83B254E9D026DC5E
                                                      SHA1:42ECE4E29799A2F8484F51E034918F708E103076
                                                      SHA-256:EDEA5FB4EC64040882CEBD4ADA5E2576C7C1703A9199EEBE385F2384E7C10CA9
                                                      SHA-512:C8048514998B9145830BF031494491C02656341E33D7F067FC6C252BD96F75CEC730CE9F9776F1B38771E7A5456A57CD7A61995A97688950D65B49AEBFCB0EC3
                                                      Malicious:true
                                                      Preview:WANACRY!.....M.d.Z.........I .{.f...x/....m.+8 .....'F..+.Q...=.2....:.F.......~i.O.....&..4.J.V..`..k.4.&.E3....x...C...Y...DY....B...L,.q...!.c.J.....V.b...Xd.9N..........SRj..3.x..L.S...?./.,JG^..}C...g..%..$..I..f..E.x".4CEG.1|Z....h.._..>UgC.D...G......@......_z5..%.kH..F..}.,w..0......m.%{1....?C......Q...T.h..Yd}HK...{.W...f..zx\....K7Nh.{.Y%..O/....0.(G..6..8..N.`.S.....R.{..@...|j..-.>[?...w.g..h...._$..6E..r.G..j[,.Y].....*.hd.._..HXP..I...O....;.7......l.F.l......G.d(.....V.....&;.c.M.. ..}.x...r2B..7T.....n.....9...ye....#3..Q:(-..i...i.1."..Z%...;............?.....+.*.....U.o..#.lp.R.W..v.V.>....9.V.1(.)..zVX....u.I......%qk.".9.A.u..WU3P...?..aB1!..:..:.6..<..t..P.....f.V...k.^...H.]#-hp.'.7e.'b#...d&{|.......={E.z...X....^.....{R.~.(.(QN.....Q...FN......Tp^>.L.%h<g.&..x............4`.KJx.......}..GP...f............|x..$Z8..4B.....nY<...,..e-)V........kP.^.....B!.y8;UW.T%....V....A"0!s..a....r.(..E/..m...oe.G.[D...MH..w..,
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):58600
                                                      Entropy (8bit):7.9969500003368665
                                                      Encrypted:true
                                                      SSDEEP:1536:qdxh+qR2Jf3jirnrEx/XW0cpd0M7f8UvTDgD72fdnkZXA6N:ABR2fTWPsYvvvgDCdgwm
                                                      MD5:FAEA5FA193E2470C89FB5144862E146F
                                                      SHA1:4BB2520F1F17681BA20646BC99D7017CE88199B5
                                                      SHA-256:D696A6E3235175E44F138039F91612C07770D541C4C86DD93206CC393963CAEC
                                                      SHA-512:62AED30E55AEC4F1652FB5DF27557325E68B81EA67BCD4307ACB80CC60B40141C56EA01C8DAF87D364C3E137289CF3EDC40C94A6987330C869C049CAE19D6625
                                                      Malicious:true
                                                      Preview:WANACRY!....Z4d.s.:....l]$.A..z.XG.i..N....].t.*..%....@.M..<>.H.. .|..,..k..z..k>.k.....i.3..k.i_(B..#../....V>...l.A..X.....5,.V.....qe.}...p.<..].....].>....t.3....!.......\..p.}.OM1..F...m..o....;.ZQ)....7.SJ.j.g.U.[\l.6ur.....3t..U|.....g.xa.].M]y;............r......Uh..Y?..C.1.J...J.L.).G4 .w.h.?.....T..@.d.~t ..;.C......Q'.=9..:..P>A...$.A.jDVR..:*...l.C$2...........{........s........Z.I?..86$vG..Q.>...7S.1gy....sf...K..W./.\...............z.V0.B*\.(...A.r.ay.,#...E.Yy.~/....pIp.%].....zz6..Du.Y.....8.D.@0..z..xm....}..._@H"o,....~u]h:..UA..o...wH.9....3/...RU+...K!k..).[......l9.....@......*...aK.:..(.);y.B.1..W..r...C.\N`.MS.'.X#..9F1..A.."..*b[.'..Kmd./...d..E~.h.z.wtv'..!.:.}..u"..".....H.Lnia.Y.Y.PK.n......<RN|(..(,..b...hNY...u.|8...a.P..DL.k...!.=g8......>....B..#.$.W5?..c..{.@O.f........../...i..>.I..(..s..*.67"..4.....].._@.4.'...F.4.q.....W8(7.{8..A.#..OP.Nl...d..:~.6/:.&F"..../...AM2.*v~...v.@.!..|...d"H..(h..4...i...E-
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):190440
                                                      Entropy (8bit):7.9991296051030325
                                                      Encrypted:true
                                                      SSDEEP:3072:AMm/lPxdSAw+Y/VRhL06z5kY9liCMcSAlAwBtVyUCC2kDPIHtyPN/rmK5+4bIbUp:SPpK9L04uCMcSAlLkUCC2kzg0DZb8Nzs
                                                      MD5:2753D276A803890E9B3AA73CF9BB077D
                                                      SHA1:52C4EAC270D0B4C32530A78DE54A401B01BF7D5E
                                                      SHA-256:A3753981D6F9304E6DEF8906FB136EAE68FB5BE0F734AE37EEDB6A9AE99027BD
                                                      SHA-512:E0DEC730653D0B25503293EF6806A7DE6B7DE568A0ACF623BF33BF1F2BDA1D6F37178188B442DAE1BED692AA2AB1B3F7D6BC573AB37084176F0B6BC68E163808
                                                      Malicious:true
                                                      Preview:WANACRY!......,.dZ.j..z..9......<..\..eF....b4G...0LUU..`%<W..S.*.G..r...X.)cH...:.. M..z.y.E.U7>~.2.V.~..h=}...+4..Q.9...HHpL.ZLL.._.,...(..1.BsM8..V-...n....9.}N.).7...:V5..I#....m...TS...IR........p..8.z........c ....5..%..R..:*...P....a.c.0.......B.............bK.7.0.D.6...bA...9..I{..Z.k...}Xf.t.P..+...W.?.5_.rbc<..b..GLA..e.....!..?m.g...X...7q..$.!.P8% gh ..K..`>...MN<}.@.W...f<V4.cYd..... .S.Y.i.:.*..X.y...|..x;.)c....X}.@..^.g..4M.[.......vq...\..p.{..W...f`x`Z8'2........`.~T..."3.{.<.Q`...;1.....+..Z...I[.@.....T.,.....SI...i..-(.l..o`#.....7.'..E.~.L8.![;..<..Tm..!.=bWV.lH......'.....?%?.z.A....u4.....iJj....]..,$..#..=.F.<G.L*%6..BV....G....upxB.OI...0..9.y.2.l...v.....t...t.r .3.yB...|6...)6O......}1K....6.5....-.._.....{~....f.....1 ....F..:E....PKY...D..s-F.#..Z......H@...%..o.C4.$;....ns.....%.....C...q.RW...|t.....[n...a......o2.......I...~}..|.i...6.(..:..30.4>5..%3.V......;G....D.k....A..4..Uq..j8.K..f/eE31xk..
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):36888
                                                      Entropy (8bit):7.994815703276785
                                                      Encrypted:true
                                                      SSDEEP:768:JxhoeG3KITaWlWLhsJTe5wckk5MDIsdpnOVe2vmhwA2obTWzX:Ph+aclm5wckMMDIsrOh+PbG
                                                      MD5:353CD81784940357214A488F25020B94
                                                      SHA1:FBDA43F506F065E8FB4E064CC3528B74DD155898
                                                      SHA-256:BE41F07740B3218C36B8DF47AD7CF8A97520B736A928A0390F7DEAA7ABA96B7F
                                                      SHA-512:7608DA404A863382C1EACEA9A3AD539C8D8BCB910EC0B25C2984EA94B0B0648A01F41255867B9E1A4BA5D306EFF2869FA6A437292F2952DBE43A1E0D0A630BE3
                                                      Malicious:true
                                                      Preview:WANACRY!....aP._p....h..../1...p.....p.9..&.|.i'.j.......Y..T.....4y....<,h..{Y)..G\X...y>."...."s.!..M[.r..4.k,.L.+.\.xl..C..N<...&T..G...*..Muz.0..P....._d.]...le{.'.U....._..I...P.ML{...~u.}.;>.....G%....}..2.Z.....2.OiZ....x.i=.T.....E..L......,-M...".P................s.:....I._G..g3.&.....P.I=..,.<..H...._....J....,.Zm.../.i..........[...:..}ee"w.....1.&...C.s..,.9....p...g......wQ"...H$P...6....X...:.;.n<.u..7.Q....y..r-...WSo{ ?g.....`..}...0..^.|...}...4..3Ao..N.z....O..U.<1../U.}`G....V....R~..`y...y..I.X/.u..r>...9b.....e....N.6u.q...%.0.~.|.N...F....1...x.=.H.|.}..[+.w....D....UN....,Z.8..x.....yV...........1..,....12.D..........P..T*..i.>.......>..n.?L..+s=..ydi.h3z.G....3......%3Q...q,.t..D...$...jF`>.N...YO..68eH%w..........t..v.@.c-.*..ef.....m|o'..{...(;...q._.!./..[X.9.'1.x.....U....c.".......E-.%......H.....1@....q.J.....w.u.{<...0.a2...7\h92.>x8_o..G.Rk~2.D...Rv..~.s.......E37..}....T.{.u....Y.C.<e......^}..d@..V....0
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):7304
                                                      Entropy (8bit):7.974547670170085
                                                      Encrypted:false
                                                      SSDEEP:192:b+QtprESo5G7xD6Pf6S4NhHRMlYCenXCsTo8XT3aCn:iY50WxDCH4Nh6KLxXWC
                                                      MD5:4752AA77C2310C0CA32E5580F5502FA3
                                                      SHA1:6AB0D6F829D281C2A006606059399A753D4C5C77
                                                      SHA-256:C809CA69D633C1E695224E162BB4297732308DE03679BEAF651BAA427E4E7114
                                                      SHA-512:21E8D611346DD158CF12469DC60D4B4ADA32F2AF3D38C15D67355AB0F90A83F0037E2326366E2C976D7BC55252A4E36431172FBF108017CED99C27BA942D1F6D
                                                      Malicious:false
                                                      Preview:WANACRY!......\..$..i,.9...81.S....8..>3.............U/..*.=..r../!.|.....0/.Y.....U.S.m.......o...1R)...MW..(...f..c.aAW.`..@_7.l.+$.m|i..Fq2.P.V...4"....mP7.?..L%.|%...<..~.J..i@rV|V..6..G..+.c<u.Lp..7..B.....c.J.]..l..h......t...<G.Z-...S.d...n...6..j-......e........9./~V...TN.$t,~\.....|N.....\...{gR..I....}y.../.......e.....Q.v....W......qP.....Mi..]........E..r.....%.+.Pp..6N%.....r.."[..9x.c...J.0[...*...~.6!.. .K4f.&...1v.c.......#.....*....W.s...1.}....jWQ...$Lt...L2.~N.......Q...jv.%.bd...0....H5u$k^R..H.|.y.F...6.....g..X......R.v.#b..q_.....H.N....&ef.1...;.ixJPi.*T.z$V..$..R.R...AM..[Z..>...7XI.+v....<..1.:......[.V.............!.+.n.......!J'E....6"........R_..3..p2.P.NhU>.DQ...>~N...gw."..[..6h..rf..Z.)...Q..iXh.....4..|._...'>....n</f6g.,...]]Ya#.....b'3.PxI..i.N..pr..jH.aK..w?...j/.x.{rN.7.X.`....#.M3.yQs#.U..oq......=........Cotl2iU..|.. ..........`.&.....MS.@.......d .`~._g....R..oP......*V.0E...06.Z...S..~...#*.2.a7.r.b<D.f.j
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):416088
                                                      Entropy (8bit):7.999635522218772
                                                      Encrypted:true
                                                      SSDEEP:12288:+EX1p9QnZu56R4Af8B6lKDQHlTxEwaJt0d:pXn9QrSDQ9xE5Jt0d
                                                      MD5:2FD950BA8CFBC7D780C838AC03DD93B2
                                                      SHA1:B6C769DE332EBC361CC7ABE20CCE63C2567186D5
                                                      SHA-256:4B02E0B1F68E5CCC193284E116589E6FE84834B6F3FD764EC0D025C1D152F382
                                                      SHA-512:7B6F7DFA6333E595BD4BE1DA2749EF254CB45959D0C1D50AAE26D3D399E2FB3A6AB0535B9677C2C8E515807CF7FCD68EBBA8F89C7EB659959C91EEE434929C11
                                                      Malicious:true
                                                      Preview:WANACRY!.........@...\...z...?............3.K[ZS.~y..`vkO.DQ....1>..ZG..E.s.:..&.i.K.U.~..r...r..,...n|.il...G.-<.7. ./..sl..T.....Dj...:d;W...9!.J...0G.W.:0.Wr..$..$...............{..]..R.aS.z.%..vBdU..4.;t.!.n ....a..9m...[...XC]N.t.B...!h.?g.!........2X.........o*....`..../..Dw8i..?hK.s..%.......<7.....+.`j......|L.X./..v...-R...4V..#D.eR....E../.$t..Bi../.*..Mv.3.....%.v..S.w..BF..i....]u...h.L..w..3.....Fh.GZ..!P.q.../.5c......*M..x..5............W.o.....g.f.s`....YuA'y..|.).i..|x..=.c.u...b......".{.'.\6l.f....X)......{&...+w.P.vny..q......9....W.`^.EiG.UM.w{..IU..).!!.Y1. ...G.......|.+..)&a..Pa*..M.._.V.f.!..L..g.....V..<.\-J.r{op.4A.t....*........k!..].Q.5..3..j:..+.[.n.../.@K...$/..ya.+ax..HR.R.n..].q..l...*^...^.S`x..z....!./....lh..jY..6...Z..8....N......i.!....o_.?'....Z.O....n2AG...w..7.G.MI...h.....X.t.U.........M71.q.A.Y..3.....=....!.).........r...;R...~....t...v.k..Q.co;>.u....]iU...M.f.r.~,.8.r.X..1t.dfD....
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1048856
                                                      Entropy (8bit):7.9998625673667965
                                                      Encrypted:true
                                                      SSDEEP:24576:8hfyyZdosrwRQX2Otr07gjiAnY5f22oIvxMOvgHnz:8kydoewk1wciJ2kvxMOvCz
                                                      MD5:6D2BF43F3A7483624D2319CAF92915C0
                                                      SHA1:67C9BA32CA8300B48C977AC880346D056A76CD17
                                                      SHA-256:3FA1E3A2D9912CB1B428F0C95BBFBD9DC763C7A627824323485FC887D11DDDDB
                                                      SHA-512:7785A3362F2A0D96D2DD1661527B2D731B98364F762ED7074E4CE9365705C8AB5476F21D8152D2CAECBB908779844BE6A6BC86CE7E8FC6ECD5C53127EE626F9A
                                                      Malicious:true
                                                      Preview:WANACRY!.....r.!.r.J.Gr(.n...;.(...#q.V#..`....)q..Y..?z..Z).f]y...aq..d.,es.a_..`o..6.I....8P......l..I..i]..1.i.*.X..w...]..x..nM2J.....:.GT.C-....E.C..n....3p...$4&..eJ...O5..{wc...4?(oK<.'...AJ^r.c.oAT.SO^.}..cw$k.+.*.=...u.wZI..{{..9...-q..U..d.......Y..9.f............*.........A...J..........P...}..u....q.?^l.u-E+).e..X:"Q.Yg.b(......#....T...w..9.....|.oe.t.O.).'..Y....I...M*...!..J.}Jp+..?0/...i.q.....8k.v.|.SQ..\Q..3'..sY...h....-.PX).c\..vst...~..;.e....y....u.8.v.^.Pn..S..rP..O....?.\........... ...`....H.%..oX..f...............S.kW).mP.`.....]k"(..:C.,..5..N...No; .(+J...5/..{...]!:..n.bZ..(m6.".......C.(^M.V.Fc....5&...s..:(..LN......0A.o..].N}.@.D.......:n.]s"u.o.(Z`./u....K...E.<.T....B!^....m.f....1X.l....tE.o.)..!...P[..k ..$=%..s./...X.t...$.Ou}S.. r.R.>...W.J).P.=...F&.G..a...Sq...v!PG%...7..$...........n..... .u.p...?F.......y....$.t0-...............\g.`n.....?$.<.3x.....y....}.n..\4%n..<,....Dt...F.P.#..(.<....../c...^.p........
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):2680
                                                      Entropy (8bit):7.922022195511745
                                                      Encrypted:false
                                                      SSDEEP:48:bkigPiME7AGpWeAtQNqFUAL5US3FBK5OxWnK+03sfopxhvZ33ICLDiS1POaaq:oVEUGpW2qFDK8Fw5OxWA8fopxHnImiSH
                                                      MD5:4B86DD31B5BB0FB2FFF7DB65EF154199
                                                      SHA1:4C4B3E5B9DFF9275CA61EFB14C0A515886BB1FDC
                                                      SHA-256:437A9947E3B3687AADCACC1B56F4276EA646261FB4C913B00486C718A98EB063
                                                      SHA-512:3E0902F421744EED03AF10E1F69517C680A101E86934E3A4AAE7F0320F63A8E35309CB72AEA224FFF0C88CC953A0DD8369E29615434135AD3F5E86CBF97F7C7F
                                                      Malicious:false
                                                      Preview:WANACRY!......M(eXg..z.S..]...i1...{<d..7..u...9.O.....lp.T.3T2.....*ob...X...W!..;..ss..n.O.........U.....{.......r{......*.2..h081..q2.T.!g>hP..G..-ww#J..c.h.X..B-.j...?.M.vmx#;..//..Z......M.._-..j....T.-c..;e.At...s.-...zW.....D....#.P.U.L.4.9...j...........Y..........b..]..._...r .jd....*.^n/B...,..j...m#...$o.hwRinzk..`.... D...c.g..:.@.J...5.q...I.4..>.....:...A-a.M....Q...b..m.-.w.O..p.8..."..#.K.(.....L.... .....:e..e..E...w..hjH-.m... .w.S.Rp...fa.a.....N.v...{?........8.....|..Z>[S....C}g,7."Z....k[.j+.Jk....../.)......O>...I@hp&$.X..^#...?`.{...Y.:.....`..h..hv.?1t......_..~.......'ttvj...<.......l..a..JvR.......*..[s..........,..Q..8.,eS.~2.}%........y.l...{..>*.I.%|..v..R....Q...U...}....cu./..U.dgB.&..&..E..8xm......wM..d...]|.Kv1....D..;3.....c.(k.._..T.,..J.....H...+KE.1..R.{J..Go e..p..n....b.G..k...........M....$.......%...p.._.......[f..lb\..S2.......l............ *B..E...;...d.....c.....w..v:y..%HX4...KW&hn.z.:...a.g.K.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1912
                                                      Entropy (8bit):7.879012665310359
                                                      Encrypted:false
                                                      SSDEEP:48:bkyipZDRNlD02od/Qowzvj3yGfgCd4PSQZKsdy/1FL2G:o1vGwoAv74FbZQ/fN
                                                      MD5:6D825E96A1A47E9CE83C62ABF09A3CF7
                                                      SHA1:1A30D7AA5E76DA829D24ACD5B441BE5E0ADABEDF
                                                      SHA-256:78DFEE7860FE2DA5EC109234133014C5016EBD329FFBA2ACDB9AFB87826E45E0
                                                      SHA-512:9A3C21845FF94A26345DA810915F4031170E7CA7B46925A6A1E03D5F6C2FFD6ACF0D2F3520EA006451B62F96A12FCE0BAA9B07036A26FB44D0C9FD4763A2B2FD
                                                      Malicious:false
                                                      Preview:WANACRY!......_9J..SH./.X...b........./.....4.5.....?.....%....O... (..N.\/..s..z5.... 7.`.......[._@._....r&...QR.........q)=.tI.{1Q....zI..o...........N^".[.........O:.*..j]..o..).b...}..=..%?:.C...8.H6jF]7..(.....'.w..Y..2xC&f.FB+"......?f.S..<*.D%.....[.......H...>...b&<...9.5.....5'Il;..B.z.9..#VRk.I.....P...K.....U.../..=.~3OF..?......V..6....9..w|@Nr+L.zou.=.EE.:...'.q........X..D.OWF.....T..#....(.jD.*)..'..m.t.(&<..6.....L.?.z81.NY..>..2........j.....;..bPXK.b....*.t..Zv.3J...:.&...|....h....h.v...&..F./...7.2d....+..52./..J.&d.v.<.t.....7.St5.t....u<H.. ......\.=......:.6.d.... ..$xt.U.9Q..5;...........N.E.T?.n..u..I.....o_'%.......J\i..O..Lv...0.;.N.....^;.4.V........+.....(.?~x....I......Wkr.g....?....0H..eC.....{+h...Bwotv.rZ.y...?..G...ds.K.H..Q..1$....@>.iXE...+.B..]..Pe.V.<....Tq-/..F......~.J..+.scz.ID....R......}..L......h]:.3._..LuS...<.N.......a..p..:....O.!.SQ.............G..&..I...a...sY'X..c\~8k..F.I=.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):2696
                                                      Entropy (8bit):7.928782291598241
                                                      Encrypted:false
                                                      SSDEEP:48:bkAzyy1y4jkz8uThlwjXb/lTIqEwGo9TsNlGqEimlWZFykci4yrQxjn9MUdIgfU:oAzyauzfGX7ldEwjhsXXclyyUv+n9Mf1
                                                      MD5:0CC849067FE7FA0AC502E5B2D696ABE4
                                                      SHA1:36FE7CEDAD0B3FE2F801BA3361462FDBDAFCC0AB
                                                      SHA-256:AD9047D75890589B1C663EB8DB3BB6F876CD18ECC9F6973441EBA109A327A328
                                                      SHA-512:F09DA004832B6910687EA3E1B628C7008C36D430A9B5B935397DB09004DB8FCFE371410561D05422176FB462DEEDFC3F140562BD781383D80C9F1402CEF181B8
                                                      Malicious:false
                                                      Preview:WANACRY!......g.nuA.q...s......:Z.kp~..8w.=b.g...C......P...M.#..L....V(_.:l..VCn.*..`&...i...r.).F j"L.m.0...t..........}n2AXO.FXg)n|....Q@...-.k6t%........&. ~........^...n..7...@.6 FW...B8..w?.xG.CQ.....k.d..z.-d...T.=....C.....Lxzu.@...\.Y[.tT..Y,..Y.8U....a........1w.7.$...+X}#.B...l..,e.".....?~I.\'7.f.a..\.c.....I... ..+.P.-....9e_.Y.3M."..........).X.8.(....A..o.%.....8.n.........."........!..n.).%....R...X]..#.+.y.......[o}qt.C.....:p......)QK.h.E .0.C....+8.&.F`v0'4.i.T.."G..~.X.r.1.. j.V4.B..0.1......y..%sFx.A......5<..3i,..3t./..3?/.'.....u.fl.<....<.c.....J..T....r........(.8~...~."...!..........oN=i|1.....:...6%{..f6.E>0.m`H..n..hsiP....l..^..]...*s.....xwU.N..<.z......t..F=S..........P.....a,9..OM4..6!9.....Z....GF...3.Y.C.d.....w..t.......3"...-.Qk......C....16.ku...I.~..,.jAx>...&.-..S.}.*.S..^3..G...Y..E...0F9.1"Z..'.1..(#....mu.:.._.J.wZ..U.)x..!G..{............~..}..m...z.C.9$..V..V\..qs....?GL........ :).....t./`^.,fy..
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1864
                                                      Entropy (8bit):7.9010430115603
                                                      Encrypted:false
                                                      SSDEEP:48:bkcHliUPgvhxtcIPJrvtD4aPz4sCGluI4o9nWpp55j2foKO/oZS:ocHlHNIPhtDppSI4o9WB5j2f3OgZS
                                                      MD5:10D616F9B655D8A18860C09B5C32E3B4
                                                      SHA1:D4B80C4C53AD276AF349FEE3C05305A4BDF4356C
                                                      SHA-256:16864EDFDDFC9B0B59FDAB5909C2013F76CF8E4ABB7816A3A1A4FBE2B5506BD6
                                                      SHA-512:BA9EA20D5721BF945C0D8A4B53446311D5EED00C889BC08C995D00FCEFB440E781C9D54F349305167B2684D167D2CDD97D53BF84DA33A7FD8FDA22D1B041539B
                                                      Malicious:false
                                                      Preview:WANACRY!....-.....N.n.E.E.....C..:.\;...%?.+.o,...n.+....ptyV.^.y.5nL.....P..y....-Z..0.Z!K2x....I.........k.b.V.8F.G*..9...xn5.<....F.O..;r.......]7r.q....v.@$.."!..i...R....!...'..b....).Y..J.....~K.f.t?.\B-tc....Z..N.~.Y......zRZ..d.._f%Q2..P.LW'-...'....).......hi...#;..jZ....r4. .p^m=S...'....n{.|..F.PG..0...v........E.....r.9....7_.=.............,......]....>.a8\..C&/...%p>.....m.S6XsG...+w)n.V.b.d....6.n.E4..L.-9..:a.^hO:O.#.9..'........YR'..].....k ...q.......:....'.i.V....k.H..I]Xn.g..Q,..^..I*."..WR...v...s.@......UDY&.HSU0.6Q..5.w>..am-...E........*".D...R..y......... Ve...L.X$.dV.Xpf.y,..?......c&.k..1.<..S.5..%...J.kW....S~.......N...@A(....o.26X.f.[...o.l&.hf...jI..A...Oc..!.w?...8...m.@.A.'.|.?"...J..{Y...P.}..b....O.xl._.(.H.o._...p.N..-.....r...{L..Y.q/..r.l.;[!F.ZWkc.p.z...,D.Ay~....8.%..J..sV`._.X....s.,{34e...m..L...(..Q....0.V>1U.o..w5.....v.KE . ..V..t<........~?..}.<+u........~..?`Zi......`.X...P.]..F...HNM..m..G?.|....Dw
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1848
                                                      Entropy (8bit):7.889596343263989
                                                      Encrypted:false
                                                      SSDEEP:48:bkXDjfKNsAEO270n3rFap197qVceHwirclX:ozjCjENWrgR7qVEiS
                                                      MD5:CFE878700CEECFCC0B9EDFC9E3D8B41B
                                                      SHA1:F9A56CE8F94723E08A71A2AE5B5131292506FAB9
                                                      SHA-256:5184FAB2BE400C7B7C8ADC887162E1812C26FEE8F17E9A7F51BAF9FB8A720D81
                                                      SHA-512:381CDE092836CA9ECD81E8D03530D8B7485CCB2BAD5659A738D5756FA816BD0FB4C9C52EA9077C05E8B357EF4E710DE53FC2A26640BDC464BE62B922324B0568
                                                      Malicious:false
                                                      Preview:WANACRY!.....<u.T.TtI..}..P4..]w.....7.F..:...d".z.!R.h.g...%.t5...C..)...!.K...N.....;.Z;....#...'.X....w............^..|,...'.K=.!Z{....../.@'7..;........4t.<-x'g..&.-....e........4}.] .'...E...1.....6.o..Jz.."9........RNiZ.4A.....U....G..Q.................W.......4....a...k...=.UP..........O..X.J.q|Hr.N..~$.....8..i ...,>Vk...6....F.......D.....*R\C....L...p..+.D^....n4.v.....C........F...........y>...Z8.B.~8..I.SY1!F....J.[g......Mn.....-A.A7.Abh.$.50P....':...j0X..U........_...l.......DG%......S....H......oE68..[E"..a...NO.....~.5W./O...~...>j...gv;.:.J.W.%L{ 4.Eb.QFj..k...H...Vbop9....`]{6^M*.<.a..B.h...CZ.%...e..yW.C.;..+"..1!g.../.hE.H].;..o.}.9.....w.%....>.......bR.."..3.<.}..z$=I..!.....p..\@2NqCw.(L"..|c.y.~.`.fT..r..^.#}..}....yM.#Y...<.7A..Y...r^..?g.]?@.8....<s....k.j.i..Z....tw.?..{..t&d.;.APX.c.u^.g.-X.......8..\.<.....0.K.Q.M-..y.8..3X...S...P:.cM..8....~....Qi.u.o...U.h.bl..G...EC.J.."..Y..q\.......F.N.f.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1400
                                                      Entropy (8bit):7.8669651374466625
                                                      Encrypted:false
                                                      SSDEEP:24:bkYc0Gf0rp/br4fMJe9ruh38TErl0Vj1KvEx9+jlx25gK1x9r4H4PpG:bk3Zip/34f99Q3rmdKEx9+Pagy/r44Pg
                                                      MD5:56405AB9FE448B2FA240810A9AD06740
                                                      SHA1:84A40CDB11652D7252B195440D30CC2CE415C3E9
                                                      SHA-256:38485AEAA272431C5DBB14C24A30CBFB8EECE2E3CB5AB4930A61534EE137D392
                                                      SHA-512:AC3F4C8E11E709BA98F1CF27ED915ADA31181B8F6FCE4C85C8620A3AFD848076C99AC3C17DFF7CB3C3C4A87761539E1264BC5A52F79FFFB5A283F2E54AA27222
                                                      Malicious:false
                                                      Preview:WANACRY!........Tn.SQ..:A.-si{.1.3..&@...3..i$J.56R2.c.Jo..3;5.?.(....aX....r.'..~.b$.v.A..#M.7.(.^-...DX.I..CB....X..Vq.sO..oL:.b(A.j.....F.(.....A.b....Z..S.s..=y..W.t...a.$]a...n...E.;0......lp W..t...0.<..../E.n...c!.....g....>....=.,m....].^.W....Y..........@.].....!...@M.H.;.|..R..C.N....*4e..c.Vl.y.ln..;tI.....`.v..O..&ub,A...dU.......l..H..A..T...G..@dT)h.6%..=.....;F..[.d..T.....^. v.J...w..:....".....T.\...........Rl..D"..X./.p..z....A.m..jG&....7O....UO.1......*..ir.@...o.18*.5T>\....\P=..Q.....=./y..).U'.uq...8..*E.N......x..\}_..X.^=...../.mAJ.!aK.S.j.......Z.....L<}.B.W%.;.%.TOb...#.F+..1U..e...e@W&k.Li....KL...D</......p..?)-K.M.)Yu2....3C5.`+.P_|&.y.6=u...c..4....JZ.X&.&w..2....V..>.YFt.E...s<.....j.Z..........t...+&.t.?u....!.M.bz.}....KBy.B./....J.||..5...kG.p..<........#4\.....X."T..i.W..].9.;...m...!.=.p.x......4.Pg<H.j.....}..@...U.....Y.)..JT6..?n.b1Ct..sS...!..M..$..Fv..B2.?I;L-X.5..+.......e<....J...
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1736
                                                      Entropy (8bit):7.888304480656171
                                                      Encrypted:false
                                                      SSDEEP:48:bk99CeOEnL20l/fKHe8TkrvahJg1XCzlLGd01v:oDCeBS+Xrvazg1SzUd0R
                                                      MD5:D43E406F899398D3F39F4154AAD49FD6
                                                      SHA1:A38012C6D652A3DB95BCCABD440F4F0F2DACEFD7
                                                      SHA-256:731BFC890E1D20FAC62D0F392FA4A4008C83524901B84641DDD3392F3CFEA09B
                                                      SHA-512:188EA98418ED6E95DD9F097AFFC7A619EA27A1FA57C751D05ED27AEE0EBA26F116A9CA173D3EE4031620FF125676CF5FF82693BDC9CEB5BB54C01C5F59A1388B
                                                      Malicious:false
                                                      Preview:WANACRY!.....%..Y.......D8D]......P...y..Bx.g=.]..8..xN6.....)"...2...(..{.Ag...qCA.hOZ.h.`[>#.K....9"Z..To.A...7U6'.<.c.eT.x.....<...)X.a.^+..\!1G...,>..#..^..6n.........'!..KV.......=.!.e.!.;.n:....#..Y..SK."....D...c...$...8.C.d..........qh..,s.&3....\t............../..........lP'.....x=..zR..7.....2..6VNT.}..C6..Y.....V.tb.`e..ut..E|..d.pc....7.._..Ef..$.G......U../.Z.Q.4(..f~.......`...q.H75...At i.7.U~w).%.........%......]}GR....ma.....,....E.G8?-.........@.../*...O.k..._...BS.l..VZ....C.....l...._$"@. ..&w#.RQ..h....l_...r.(...Bj...z...A!U..,.,...j.\..wzQ...Z...s...#`s..(.,3..p)...F.j..m...B.;z..H.)m.....Rp..j...Z..".pK..a+..,9.|.....xf .r.."H...KJ...?.-N..Y...X.t.q..).f.gU....]..)m:....'....ks..f`?.?5-~....f.@.....H..b..aM......|'.....\..z.#....I.!..XNY..d.....sXVd..../Q...k.y.[....z`.E....h...R.%..JY...u.....K...em...5.,j.......F....|S...dh..@G-DU.!R.L~..o.~...A.?.J]..&......c.w.5'...nR.h...2...M..[....L./.eQ?.w.Y(....C._x......
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1352
                                                      Entropy (8bit):7.858251535829475
                                                      Encrypted:false
                                                      SSDEEP:24:bkklvwDUmscgxEz1denlIEGyWJMNa9H8sRgngVnhBMXxBs5U8lsT7Y:bkkkUmscgxGEld/WeNa9csmgphaXxBsp
                                                      MD5:21F5B475F8128B83A1965FA93A9DB46D
                                                      SHA1:3116873D13B37206F46292C8202FC53C96393D82
                                                      SHA-256:024AC718EECF45F667178399FF78947072E4A0371B60A6FD2A70F45B3BEA07DC
                                                      SHA-512:99C17B379E69FC4FD3EFC0FC52C7992EC170A625FE8CE2143843799B3E47952439D93203A6F5D4A4EF7B353BE4D4257E7E772C7ED092467EC82FBD1C3C00F35B
                                                      Malicious:false
                                                      Preview:WANACRY!.....|...G.c.T..ZIl.?P.l.\Wq.~.X?.....X.2.u."..t..)k`U......(pz...a.<...pC.|uNQq...N....+.l...S.r..1...=.2.G......yT4c.v!.L..1$.pVh.P.x.i{.Eg2`C...|{....f.mS....G...ys..Ur.....U...q..PC...vW...O...--.Pq..0.a..o..x.....!...y...[w,.mHXK.!...k^E2....U....$.......?.#K.#...A..(.^l.gk....y9...j..3.F.s.u....P....U..Tb.Q..-.....H.-..;...Zo.ZQYg............n.`.}P....B/..u....!.~B.F.g...!.qu.....tb5..x...Z...9q..7 V~...Bw...{.D..\.....l.2....:.l..~..MJ.J.....L.Y.W.z...b..E.b..7...........d."..)...1........5.....Ce.1.4,......&.....X.g.(?....`..9N..m...@..\(....k.@.{...@..&W.t.&po^..:.......^.&.+..[/\...v.-/x.H.ef...9..............ke/.rg.!p.M.3A.(L..E.E..9#...w.......Z..Wr...../=.!....)8...d.$...c9..r....3.[...!..J..v&...?Sg,u+!.........8*.[....E.H.R....|.-!..W......9..*&..b.h.q7 {IZJ.x..p/0&V.tV.....tE.c...i..|.....%M6.A .......2.e...cCz%..@.#...p]..dO_e..W<v-2.T.?....O....P.D.s.n.bh..4..-<.1Q.....q.Sa.o..%.......R...^.l4F....?..sN.bB....pirZ.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):20568
                                                      Entropy (8bit):7.991330875529921
                                                      Encrypted:true
                                                      SSDEEP:384:Y5oVJBuBmyVqlC4FkH2RiiGXNFRmOf/GTDbRlllh10BChvD8:Y5gBuBmyVkkH6PCNFIO3GTDbPIk8
                                                      MD5:2F8D1FD2E84B378A14E81B7292F0FBE7
                                                      SHA1:F072378D1ACC759F4AECACE06D52F5E8E9A2A17E
                                                      SHA-256:3CA7A7943347BC5B31FE21381BE67386F6A4156FB7B1069D3A84E2B9AF52CEBD
                                                      SHA-512:667F1DCF66EB8214DA38CF3BBCB079551A2FC74E6931F1E57E1FCE80E40D71933D9CC3F2727A82A5CFA545BC146C49F8A0A08612E6838E779133C5E468519D76
                                                      Malicious:true
                                                      Preview:WANACRY!....ei.....J.mk..H.).'..S.k..4...=X...4S..L7x.,......P."..#.0?IC|6..7.y.;.........H#.^.].V..M.....0f.@.O'.....Z.Jp......G.jc.b..............f..W..y.t.A?...[K.G,r.E..r...;...].......I^.D...P....b.+-3gA."...$=.cO.*e.u.{F(....]...I....p.-....}..f......4O.......8W.:I......=P.=?j.v".T~.e.L.#...Ve...ZQ...I......=...........?..j.4;.W<."r...m.PZo..{.o.L....(Hf.um..R...&.='...[`8.:vI.tz.\.k-&./....^?Ny...>..J...V....'..)zp.....m....fN._e....F..v..s..(.Q=3...h......Th!O.CP.wQfz..E73!..N...Qg....:....xr..7.bN}#P.F..k|.).)U..d\^..r.u2s.H..#h.....>e..'.....HY....T.&.d..[#.AK.6..W..<.z..ua.......Y.o.@..x...%..V..Tv.X.jy.....{..@..->......".'.....(.......=.S..CL.M....,.SA..............m....Y.b.>... k0c..l..A5....7b.I..A. V.9H.`q.#.D."nw.w 1u^.Y.z(.U.|1.....L.=Q....).x..+X.k...[E..^.q...v..o@`..Z....k.4S.......;.2.E...?..iv.V...C.h..T/|.G...o?..N=F..wU'5!`....I...Q....hyT...W.?....=.x~..T.P...$..oq.@..#...l.][H......oi.Q.9....MP..e.d,.._..{..4
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):13176
                                                      Entropy (8bit):7.98505502400349
                                                      Encrypted:false
                                                      SSDEEP:192:77ID1a4kGdGbY/jNoha6mAsiJNjONrlxmDHgWPLSSoYe93Abf8rMzfJ2I7:77pKR2gXN5uACbf8rKfJ2I7
                                                      MD5:CEED91B0F7635CC217061F1DADDB95A5
                                                      SHA1:5AF0D547BE3A5D1B96A7BC9781C3925BEE74C0D1
                                                      SHA-256:0E3DCA5BAF9403EAEEB7AD454585943B3026C5C4B45B44AF553028DAB38D6E64
                                                      SHA-512:0209F8AEAC9020A525F28B4762CB78B5753F090C20279E7CADD9D1DF7EB9FE97BE0E39E41C0792C79238FB447F0079924628C6E61086A95F3A75263B0B469B29
                                                      Malicious:false
                                                      Preview:WANACRY!.....R.......z.1...Z4.),._.]..]..z;(...xw..deL.[..Z9.....N./a....{mna..X.R6.:.1&.lb..)5......{..E.R(.Q...".C~..9.....0#...&.p...{...!r...Y......o............R...p4...............E.JqS.-..0}..L...1....*.3.t..j.....sae2............]f...".L..^........^2..........&..M..;..q$... Rw..\z..{A.".k..1.........GU]yS.....rz.p.............UG-r{l(= d8X.......,...Ydf..w..@.iy......3._3.V....FPu..Q=.&...K..e..U.J.n.>G.,X2.+.0..d..2..$...OS..../..u..&O'....Kq.....2..{d%L....Ss^')...J...........J..1>Z.3_W..T.Q.!.. .^../.X.._.<....W....Z..q..P.......L....r#......O..(..(c,.......aT..ql...,U./....].-......o].`|#.4.l..#.Vbr`.x..7e.hD9....d..@..8...vT8. ...5..Q.C...p.HL...yf.Ail..X.....}.d%....p.U.9s5..<..{...b.....%c.D.b2......7.:2.UJ.@*\...coe./...vE4...././y.........5.f|.h.f<.B.....<@..,.(..q..-...b.....}.Cp`k.0?\..\f.(.d.-...9....].vxl(..!.1......y.yd..q.. jv....:#..f....9..?..z....+..]nu..Fa...d...Le..(..z.}Z1.V.r...-...>...5..0.r`.n...=.M:...@
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):80360
                                                      Entropy (8bit):7.997079230702948
                                                      Encrypted:true
                                                      SSDEEP:1536:8ug74zYdpMbn1kAoO5jjan8YCrc9Ixhfb1ih1wWNMWJD3:bg74cDMDmxCjaJCY9Mhfb1i3LD3
                                                      MD5:9F07C5216FEA80A10948AD6C01ED4DC2
                                                      SHA1:6700C10960EBAA3CD6E7CB66DF328E009FBCB519
                                                      SHA-256:EDB597DAF2598041F599547EE2AD7B15B1A057F933BD5B0973745DD4C56D9EBB
                                                      SHA-512:1F553C076656243BA00FDB5A5A4F8E8C1F21B953DB70900126A9EEB296F7DD649272D4923BD69F063DDB980AD95659E3561046591736090FA4377A47CE253B67
                                                      Malicious:true
                                                      Preview:WANACRY!....u..G8{....~..e...7_&z...C.~...w.9+vD...jyl...2i.|%.t...d.]0f5./...O..%..:.5..$..,...e1ICb@...j..F3..u.B.,......eqi.8.............8'.e..oC..R......-.Fj.b....sY...:.E`.v.EK.6..zM...uFC.......-.".8......5.{.0..X..pi..!^h^...Q......+.o.M...........8......b..S..N....M......'..,w.A.`.G..+-.[..8.;.m.17..}...%r.H"..5..F."]..X/.4Dm.t...n....}.k.>`..H...{8,.%A....MI.*.B.4...=..j.z.h.2r..H......`.*....av..4.Ih.1.MTC..u.......6um)V...E.]M..^...`..X...........V5.M%Mvk&.>.T}....=.....F..mwb.....u..7../..D.X.$.|...9..Z5...r.;.....4...EJ..0..9nz......8.....</.y.v5...a..^#jSec@4..B.G...\H.J.G..2D......\.4..Z'<lcI...,DBE(....(.F.6.|...ep...].GE..m..i..2..:.`6.(X.?.6.... .&"...v..:.s.-.:.I....6....@N7.Jp`(s.tB.."=....Y...I...t.3.Uvq.(.?.......D......QG....^.Y..(/M...'.)&.]iKeG..(.....b.:.....m.Q...bji0....=.5..;..'.e(c\...F=P......T.l.*..`...|..2..0...+c:`].d.)7...y22.Z*.=.3.H.9...xGs.....\....R...,......~.2...<.E.N6.....S./.D,...........8
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):18856
                                                      Entropy (8bit):7.990492882655605
                                                      Encrypted:true
                                                      SSDEEP:384:aOk1nMXZbGJVkXBKxIQDLyktUSjEWfIzevUqHQ7W61hrOBAnlRlOo4:aOk1nigix+DLyk2WC4Uk6HOBqRsN
                                                      MD5:61200D347D2F7B9D6D0D75F89F59934D
                                                      SHA1:C3CB558B7FDBA8912033FFC36AFA42EA6393049F
                                                      SHA-256:0F1E8ED3951F219B371347D0BA00A6CAE69B87FC09D5F8B7AB217ECDC7862E7F
                                                      SHA-512:BDFD3305E3AE3444698209A1B7D37013597E27103E3DC5F7A4609A6CFF343BB4A156F4AA747C8AA8774528A4DB978D3FDE9C6CD159F619C150C01BEF3EA6F310
                                                      Malicious:true
                                                      Preview:WANACRY!.....uM...ab>R<.G5l..=E.U...0$'...][."..=..)...............~.~yd@..i\....{..=9.)j.,V....L..7...k..$.P.>G`s...#...5&.....+&.E...v</D......OG_@.D.*........3...Q..k...XtAz#..1.....G.f....VI...hKi..yk.#sfl..;.s..PEUgl!."i....r....|n.P5...!oJ.!..A......H......8....xT._.x....$..X...\...dba...{...geK.U....k....r.k.2.2../0nx..:..2.%....*...z3..7...fM...p.n.a$...;.?E.wa.9...1..2L.K.H?8W...oT......k.Q.../\.>..H..a.AC.>O5.....F..-.......@.I>v.v....^.....p..B?..G.j.v.0 .N7.f..o...._...X..3..DC...T.v......M.....N......m..2....4. 2...Zdo\..<..X...EAa.|...o\v.%.G.:.k!r.4.al.0.:A......N...o..;.l?..~.(q..pT......F!.....E.....LC_..".mE..v...1....g....A.(12.=\..4..2..0~..R../.3..3..+.)..V+.~..tX.....8.......O^54..]<vhh.Z..#).Rp4J....AgjirO...E......{..ck.k.......1......../....n.oRN&..m.d..&SQ.....)]...A.."'..2......W.9..5..!NC...(...S.px....{.Gb......._0.....m...F...y....K.V....ECqX..6y........0..7.o.c.....^.T.w..l|R&...VF......\wT.%=n..T.<...
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):7304
                                                      Entropy (8bit):7.972787393495236
                                                      Encrypted:false
                                                      SSDEEP:192:Z/ZkKE9eLXd1jUKhfxSIue1Uvgqx71TyM/TSYs:ZBkKUez3jUi0Ym73/Tm
                                                      MD5:150625FD2E8F9F6DC66F8A566072B499
                                                      SHA1:1950F0092C0BF0B111AD6F8F79036EA086F5FC3E
                                                      SHA-256:A728A564F5FA4F68F7650CC3C2F1F5EE269E1F649F62B72EEDAACBB3F742ECC8
                                                      SHA-512:E2C97A3E7CD3725A9CC1387146F1CC9D9035745B89B6D74D15CC4BEB5137B30A2A46E0EBD9245458864C04B7E9273ECC3EDDD9C19BBC6FB976FF4ED22A9B7494
                                                      Malicious:false
                                                      Preview:WANACRY!.......#.j^._./?..:.......;.R.. bg^..A.|..{..._.#..t..G..y5.(dj....G.\.V!.x..9...M.)..fY'....B..$.e.Q'..x.v #.6.QK...B.f.N{...........:+.v}M.~2.T...@'...]..Dc..!S./....2...._.........7..(!.z...u+..Z.X_.%x...M.1..'..Y...'....[D..&......r..Bu.p".....o........b=....k..|......K.<.....-S......t o........>..wo....\.:...$#.%m,...?b.8..T..._./ds..C..j..o. ..i..o.;~;..+.C.u.RS.$....]....B...=Z.c....d.J..9#.go...Y.k..V..).wy.S.8{.Ng..o/NI....b.ta..3.giM...z.B...ux..;..nI....e..a...\y.."I..B...&..5......1v...XGI..A.t...K..).h..p..k..^..P..a....1...:Z.>N..4e'.e..#3..Y..#..w.:X9.u.......p....&(..f@.y...!..7et..i....!.8.^...HBt.k.x[..b..J..LN...E..S|...-......{.aD..G.2..y..S.-.nftI.x...clf....r.U'...O.k...+;34E.......jbO..6...4....s.n..(....Sz..4.>..'+......gCPs..9.W...UY|O..R.+...,Gy."H..*m...=..M......,7..t}..J...L..$C.z..8.j.O........r..%..P.p......?.~...mTs\g..K....B...D.yjq(y..1..A.|..*j.p,).v...)..mGvd......a=...A@MR.....h;...l.p.....
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):98584
                                                      Entropy (8bit):7.998183698264744
                                                      Encrypted:true
                                                      SSDEEP:3072:YUi51fTHa+6iZPh8XL4trkWl/K6VmMqAj+Ht15:JMTHa+/ZpSL4trkU3VmMqASf5
                                                      MD5:5FD168BD4D54DDC1571B7EBF83454F8D
                                                      SHA1:8CFF65C0BEF58998A9184F4E7310F4ED5F20C631
                                                      SHA-256:55DEAC3823776E575F82AC1CE6012EC2A5D578C65E9BAF0AD0705F31118AEA5D
                                                      SHA-512:73D1F25024D06FB3D9860DF873E6D828748A7D1C325303ED6CA5860961AEA69962050456791C175A9FC1CAD2F778BA3BADD4CAF108B9058D4E836D97A65E06C0
                                                      Malicious:true
                                                      Preview:WANACRY!....S'....t.9..s`0$.......B/.,....PI...../....B.t.m...NQ..g:...m....rY..V..........K J2C;.O....;..G~..6.M..s.1...Z...h.n.).)~.dw.......j.SM.......(.a......?.a.C....#..;z. ....;..]...4..?3..u.|........h2..$cn...0B.[..n.)......FR....o2....{....t.M.o.....................>....sb6.^...z...3...}L&.v|.yT....T... k...!*;...y...)..........$...`.Y.U.......rO...Q.1.n..*.a.L...G0.m.co..!.z.......R.)...=.68t..O.5...J.2..+..$.m...V..t..k..%m.(.2.~2..$|.b...3.6....)~&.e...-{I..u2..*n|#m>..4R..EY...,..A....Q.uY...2.C..a..^.fR..X5f.N..[J. ...XY<..W.c..b..Df."A.....Y..:.".I.K...j....".I...c.u.....I.....<..y_...d..BR..Wz...P............r.`..."..$...`t..xR...$.@.d......3.{k..r.}...#.........u6]W.zU...o.F.lx......uzs.M.....N.$.....}.....a.70`.B...VL..V3....DkX^.@c........J.g..g..,..v...Wi.z..G....@...?Y\m..w5..h..N....0.8....n...^.......W..g?o.._.X..)?.Y.F\.X:.....Z....$....w.D8..?...1.D...3L...`y..`.@...H5...x.......).....*....L.p1.h6./..b.K.N..V...a...}.+.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):5096
                                                      Entropy (8bit):7.958503780492355
                                                      Encrypted:false
                                                      SSDEEP:96:ogLdOGr+eEqjj/g3M6c1T9B6wbgA2vPa+2IhbW1:4GMWDXL5uHc
                                                      MD5:A558B0962A4A14A4BAF83FEB9E0D9A42
                                                      SHA1:1D63815B4A08DCD1735D94FF5D904D4008150541
                                                      SHA-256:084CEAECC4DF314A68E49B3C2D0590869D1FA620AF526AD0CFA3AB1BF28E411B
                                                      SHA-512:466CB6C6E41270B12CA22A072A25076D515665D3EA036C509FAFACACD974E217DC2855B986BA17F6B56A2EE4E1E7984F91772284F24BCF18D1BCF0C59E50F463
                                                      Malicious:false
                                                      Preview:WANACRY!....g..4...a......P...j..;.2.D...X..{=.Q..{.e2..-..d2.d..YK|...Uw.........$..Iz..c.e.]"mW.~.....92(.u.._.....1.2.B.:Y#.i.i.I.&..W..n...{....$.............)..k..i....>..../..^..^.i=.9h...x.5^..N....o..:..L.....G.N...(.i.......L....cm.....W...].................s.......a.cR. ..ukd-.!......E^n..(b-w...`oz|9dh..m..!H...4.......*.@..B...[..`?.............f.9P.%@....W...4O.[..Dz.i..5...n........TO..Lur0.w.<...........>....s...X8...F.....S..9r.9:..o.<..B....v...76..x...*.o.#..,1:.g....E.b.]...a..=.#...@.$...t.i{....z.........87...z..E....:'*....@h.>h.;P.?.Fa/..1.Z.?.j.1..T..=..1..[h.P..."..p.....R..[.~.T.@....6...'"G!.`..]....@..$..)A.5...8.UZ.N.....l...\X.qA...6.GW.#.....:"....P.K........I..~..$M....RPg.|.E....v.5I.2X....".......+Ox.,..e.?...I..(..4...l+...a....G...y..A........y.K"H...k2`:rbH..v..d).|TK=&=....h.....<...w<.....f...L/.X.............=D\y...4?./....JU.L........0>.w4.f...1b.."...V.....IJ*.x...................X..e..
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):97816
                                                      Entropy (8bit):7.9980107725674445
                                                      Encrypted:true
                                                      SSDEEP:1536:7WPIwxxlOQYOl4fi7DEL+sz2iKYp+YBj3gHx+NPJ3kPE1uvgMwOFke95Dd9GHaD2:uZnoEEUDECK2iKtYBMR+tOE1uvgMlPDy
                                                      MD5:190E8D3FACA52C6D03E19A5111598FB9
                                                      SHA1:8F0C87E0DB5BED2E764ECCF8B9D098C5EB28CC78
                                                      SHA-256:711FD0FD7DAE4784DF0BA456509348AE8E5CC9D3F32663206F754BD15075EE7B
                                                      SHA-512:EA80F0B8106AE842AE52EDE1116EFB99525A67E49B86B125A6FE9C7A40BF85ACA07087C57B98EB053E7832E468568BCBC86AE71067070D9EBDBDCA7857478809
                                                      Malicious:true
                                                      Preview:WANACRY!......R.RdwHU.%.7o..i.*FoD..>W`L.Gu%..$(..h.l7....k../....\X8...%...y..il.l.....&._.._..;.H).o.f...(.jr..X....W<F.....`.A.4km.gp!....<(?.zJ..._8.QA....z_.6..4o.....(......5.>.T/c(.`w.....k.E.L=...:}...l..F.-..c'E4.\...2O......2-a...+.]^..7.$D.....|......|.R..W..>;SoN...b..{..........P3.*..x.@...Y.fz/..If...Y...G..V........S..7.R.!/..K._....t..t.........PJ.O.....T.XE.5o@..6...1.k......x..F..4.{.....i........f..&...V&.n..@B*Q..s[.,...H.M..[...J...N.....'Y./.}..U.#.....i.+e...a9O.$%z...{)...s.7Q..j9F.......X...Kp...|D..E.{..<c..|......g....T.].E....".t_OS......w?......+t..Bk...Nh..J.....^....y.m....h.:|gm.s....2\...nn.4.m..!....e..+.].oZ.'e..g.X-..s...?..c.:..u.g.[....1..(.7Oh.2I...........".C;p...-i.._..W........5.b.-..xa.:.(........0.E...2...........`..w..e....'[.+......u.ccP`..a...C..}.7b.~..t...evAA..c"J..EV..I.t ...2.....V.Pwn.k._.:>.0.D._..m.?....w)...{...)...k?..1.S...1..{.$?.w......w.v......{..HH9...U$.7.....7L.w.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):46296
                                                      Entropy (8bit):7.995827278573962
                                                      Encrypted:true
                                                      SSDEEP:768:ejw0nD3dUO9eSHAxAbewLtKKUaWW+wwunlZXl5JqtJQ2FZtN9gG+oSif:eM0n5j9e1xn5aWhvunjMXQ2FZr9g0f
                                                      MD5:AD96915F0445B5951374CD3DD6AE45DE
                                                      SHA1:E72A9456B2157C6387C13D431597B65A99DB8A73
                                                      SHA-256:268DCF50F11BA709D0388B936098C4FA15347DB3100A3B51F1A574BA43C6D5C6
                                                      SHA-512:D365CF5B11DDC775ED433FBDF3361FCB9309CD798975CE9FC27E2338857B0126C4D2A7A014717A4756FFF2EC98E45A2B9A63B8F0E4B67A1B324CF2779361B6BE
                                                      Malicious:true
                                                      Preview:WANACRY!....:..5...........s7......A.Y....Ok.....Z...t.;...=..b....2........0).S...._r-M ...A.\.u~.......IDg....N...t.!'WJ......#B.k.......KV3...j*.3M.i....C'.G.j...#/..A..LK..f=P....s.....>....p\<...NI....c?2...7n.J.x...e.'X{b(..r...Q-Z....F.h.m_....;.............N[....V0......G.f......0\.Pf..^+.J0Yt.K..S..>.,U..2.2....<..u.&.@.s...s.\:......Nw..7.6......dMT..i.E.,[."G.T.S*-..B|.f...^P.|..u..{.B.....&.Z.O..5.P.......M.X......tN.3..+.7..w..%..&.".#\..v....B....;....*n...P._X.......#...X,MA....T..UN......o#De;.l.21.......e K5...$.]..d.J_.....9.l..+cB....#y....h....l..]s..K...O.T...,. ....w..8.zp..l..P...lD..*,Z.3..p....H)....rm....w..#.Q.P..,[..\)z....1..&m.* y..|.z.`i.....:..b..X.O|u..w.z...;.q...A.`.*...e.Rq:....-d..0...F..tE3.A.d.M=....cAp.3?.i-.@.?.v{...{.H....#[;.&..}R..b.......KeO..*N*..sv..:z..U...2r...Q.4......... Q.Z.^..0..rq...c...k..A....-.)..6..8.%./".h.s5.I.3..)0..j..r.V.....[.6.).....f.9.....,...Y2Rg}d..8W.8.......l./
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):21048
                                                      Entropy (8bit):7.99289268442224
                                                      Encrypted:true
                                                      SSDEEP:384:cJ/AWsBQihGlC0p9dLVxWR9nggK2Vl7SwUvmK8jfgGGSi48p9:2IWsryzZxYDKRP1SDW9
                                                      MD5:62D8BFDEC158B1C6DDA3067EE3B82239
                                                      SHA1:43D184549B40CFF7C9EAA1125AC7AA2226AC2198
                                                      SHA-256:5426EC6EF8440C517270D3413E76D5EB64CCAA8868B2C097C030AF5B75269791
                                                      SHA-512:555F9DC884B2EDAC754BE18132D005FF6EFC0DEB783BFBD1A0E2ADBB07F7AA441ED2BA3C3C9852ED83F04AF751757C3E14D2C8871EA49632B0F52447FA9BB0E8
                                                      Malicious:true
                                                      Preview:WANACRY!....>.l.A........Q.........J...l...v3<.B`.{.(3.N>}7.,.~......c...w;r.8.9...3.Ha.y._..]...V>..c6L{.h._..&.+T...r.GJ.< ....R#{U.....{..U...y. ..9..]..........N.k.T..~..w..]....X.@.,6n...5..j.r.H....D.i .n.r7..'../a.c.;.R.E....9..../.A../..H.jf........Q......ab....+..4,L.I......q.[...n`.....3.r.mTV.{.V../9..............YS.)..:.._H.....?N..9p.uY..rT.Z`{e.h...Pzf."y..k.2s.{..^.+.C.|+....9t$.;..Z..{.T.....P...k...E...w........v.j...Gh.>..H..'.0......M...Y3HX.>t ...U....#4....*H;...P.z.v*)..A.G..h6p}_*.E..-.hQfI..T*.@8..m..}o..X..;.K...f.[.....)y.Q.Q\..A..+*zh..b.[I...rw.Z....h..~...G"Tq _.. (..!|..........n.y:../....._..8.Y.N..H`...ku..O..9..d.z......W..z(..}|u.%.i.Z.Oc...........mQ..Z......<7...H........z..pZ{.].u|5A...........1mc......d|.SW:..vS....m...:..z.(.n...y8. s_.0..~.......9...ae..\q'...Z8..f..B.Mj.0.X....|.n..X.%..5p.....=6..ET:KI..W..<N|[..z3OT}/.W..|..q.q...9\...N.....G..Y.....K......K......5...QF|..7.8...B..nW96.f.%./.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):11880
                                                      Entropy (8bit):7.9826852529750685
                                                      Encrypted:false
                                                      SSDEEP:192:glIusxXn5NaLYxVXfAYJmZRWNRmUaWgimFKDpk07xhAG+ibiZMk:vljAYJmfETnBzpk07vhb3k
                                                      MD5:A78F1888F4AB76F679513D1A450FF132
                                                      SHA1:5DDD385D1CF4E0D3521BE7EE683C5A96381591BB
                                                      SHA-256:BC96CA4C110C40BA7C7ADD21A5B01268B9D46392223A8D2AADC5310E749D84BA
                                                      SHA-512:A64F86CA405CB0A9AAB25F822918E83D1F6743CB89523C48DCC80792292C20C8CB1B3406139BA040C6AAC4A77FE8337C3D2E9F2D2398FE12E877C96ACF4BB46D
                                                      Malicious:false
                                                      Preview:WANACRY!.....`K...k.N|U.\..}.....E.x.[.........j.-5...U.+\.<y.5n9.9.i.......H+....3....~%..M../.w..>j.@{.......G.ma.....Q>z..x.4...P/.$....>.C.U<...(L!.....U.U.keQl.0...$(..]`.O.y%...B|.."BDc.`..|%.y/..r.".....G...[Z`......i.x>?....../...X....Z.....u...K.D.....O-......L....7/4..c..k,}.|.>....{..........9...KQ ..w.......)/.8.~r..l..(k.bm..HQ...>Y..Z|..5...&..0cGE..q..1).h(.....R..7SLT'.U...".#...!..O.]c1.|.7.0z.....N+Z{S....oV_......#uL..1~..x.89...~.D@.....Q..52.;....... 'f.:.b.~......:......bRe.,.%..H......m..n~,......s.[.N..X...0.Q5 ..L.>a..B&...d.a`....C!Nz....*...wjd..;.....,n..N.=9."..S.....P.j...."..zh^...V.4^.Q....<....Q.......q>>....X....[.a.z..F../|1..N.y..=E...d..1.#...Z...@.8.....iq5..R...... .-....y.......j.Z..nw..O..y..b_0.-."y.k............0.........u\....iBN5.....{.-?:.Mn.......m?..Y.f..W.#P~t.7...Av...f.f9[J}..""..Z.....]...p.+.}....@b..,.....Amm..j)...).....U_.H.q..X:...c.i(.(^.j....J@".."-....G1."...A....(+=..A<8Q...5...
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1212760
                                                      Entropy (8bit):7.9998595852575844
                                                      Encrypted:true
                                                      SSDEEP:24576:jAnCnEpdRJRd5whFMvSZHU9866BFNX8ERvgZs8FE/vZOSDEx27s8BI3+iMb:jACn8v5v6ZC8bFl8ERv12Ecr8Y8ah4
                                                      MD5:CD5AB3ABA7BC5F42B59107FDDFECAB4D
                                                      SHA1:CC4E21F1A7CAF8D10CD570E3041EA598A9768D28
                                                      SHA-256:9E7DCEC3B896B5FC2D3957EBD22849FA5C6A6A906F6199072FEA18E331E002E7
                                                      SHA-512:0BA349850DCA772F0CA8C59D894E9344975E8F2DC8CE01AAE99B429FA7AF8DB65B7EFCDC015649E59ADDDEB4E2AF053149FBA91FE363311F6536D606825493B6
                                                      Malicious:true
                                                      Preview:WANACRY!.....S.W..d....J.....]Q..Cf.....$.zi .....1..W........UD7o.)Fp3.....pen.F.S|.....p.....y.....Nc...[.-.....d.J.4Pc...v...gU...*h..f)o......)B?q...\.....$.KGp..T....w.+.V].o.Iv.`.......'l.F.hsg,.d)..@....}+..c~.cQe..@...g=.... &......sbl..9Y.6.j..h.........;........E.x.W.F..lp.p0l... ./.yy=...c...\7Q.Y....7e.............=B..#.L...F}Y..c~..eWIn.~.D_...S.Xiq..U..O...W_..0}..v..!....M.|.dm.Ym...B|.IM...Q .^p..>i....<..S...lI....2..|..........eWTs...t...H..9.....#>...@| ...3[.........a.K....3.*.@t.H.e....z...%>...JK......2G..RM4m...v3.g.H..f#r.g..m..#(..._....F4.C..?.$i..gj.F.b..JD.,..R........L..p6.V.q.....w..F.......2..z~.~...5T..2.9....d.HdbO....7-V)4B....L./...o.s...y.:s........[.}.ST/3...9..N.H0.o.6.!(0..Sa..D...[..I'..... ....;.........HT..i..cn./..cK..m.9........v..'.....[..X...k../:..|?.m...-]p..HY..7.y3..`q.W..6..JM/.....e(ug.>...`.%?m.kKS.i.Y.:d..m..O.v]......T.[......9T.Qjl...p9..........s.c..!5a.a.....O.....u....;.#..T
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):36264
                                                      Entropy (8bit):7.993909222036719
                                                      Encrypted:true
                                                      SSDEEP:768:pYQlY4037ZHa3UiBkCsu82S1bGBnyVrZWNUSbZ9MfJpStxdKssKXUHTV:px037ZH4U+su8B4yVIKdfUb7kHp
                                                      MD5:52EF30094A5063555A48D157BE126D84
                                                      SHA1:F329616900E0677FA3E38B5F2C8F419838743868
                                                      SHA-256:A6B285989825EDAF2AEDA7D3B98A589DDF7744C9623C5F2D09ACF9955D80055A
                                                      SHA-512:3D687FAD422F3D09E09C3F877EC058DEBB40DF030AE3A2E02539809F98D2BDC8FCC06F2B8BC412775B459A1B4E0EF9E302B2D43D79DC7A3C26683470136D043F
                                                      Malicious:true
                                                      Preview:WANACRY!....l.....{M....pi,...7A.P...f.,....).u.N...E.......se@..nIG\1.....q...i....Sn.$@7...RA....*.[..n;C..z...% ...O..9c.-..b.K@....4...b....*{..x...5q>.!g@.}..../.....;:..q.Vpf...h.=.~.&.u...uB..o..xv......L+....X.h}.....:.8....@.|.!.W}..$.ry.....................].X;..>.A.....5......X....>wQ..-..4i.2...B..t!..Y...\...nfj...W.UT...esZ'...n.Z......p...fY..).&.(.1.Uj..=.....!F=2.!.:.\-..{.i.b..BG.z_?..(....y..h....R.'_....W..^bs...e.hu..2w....m.....R~...,T+.....u....+.n......n.q...n..w..n.nO4......3.. Py..........q.>.i.&...A..'.....i....o_p....gW]....F....N.o'4..>...].$..T...N.5.X"=.............^.$...i.-......}.Q.*\o..r.c...... ].m..K.Tr....m0.Q4.W(.L.r.j.>.xN.T'..l.K..l....jiv....ZN.......H!*.74.iV...F`.._e.....Ouf|....'....e....$S .. ....J6...6.r.*.F...z.1Ag..D..5...k*.......*..K..!.T..l.E;.#....P0E)a...:^.;B.%.RU..^..\1u........u!.YX<.k......<....7._.@Y......&h..M..&.a..&.OJV.......<...o.....+.W..< beh1&4C?F.wr...#.U.I..C.Z..\]..@.D.....1.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):43880
                                                      Entropy (8bit):7.995732079298416
                                                      Encrypted:true
                                                      SSDEEP:768:thLj7XhDfftA4kVGfffIgIY32NZ5+fYD7mlx6hPzLFXiGYSURSyxI3z8/UnSMeN:thLXRDf25VGffkYW+ADaGhFXihpRSGsq
                                                      MD5:C5B97BDA2EF5C8A66E9DEDAB486CA06D
                                                      SHA1:E8ACAB5CD157935D1BD74389BEE3AA0A396C3072
                                                      SHA-256:D119E0F3C3098BA4E3D6D66CF748418EF89733EBAD3E7B1507E36A51B8128B18
                                                      SHA-512:A3D2427698E14512920CC50849781F85D468EC4FDE0A42FD95915993AFB34F9B60C31A405B34E0B4831CB242D1C1A45EA680EAF8E9350F1BCC505BE9DD08CD08
                                                      Malicious:true
                                                      Preview:WANACRY!.....f.OG..I+....Q.0G.U.=.N.C.j.P.;....%......C3...Ux....[.=.........;.G.':..s"....~..:._Z.GhD..>..........E..<..nk......I|.e`b..Vq..s......(L.-.*.!...s..~.5&...7..`...+..?I3.+.JL....ODLQo...n.E.......{.|...*G.p.'7o../..DQ?<N.+7.. .Xo..><[....H.......U*..L.t....(.K.Y!.............bz.+......Q...W=/C=..~-.3U|.>.<...s...aB..M...........V.@....(..!.u.........it......dw5.8uK._,..p.]x.....sg....l#Mm.......F.....)...o.W.r'........B".=....).....'k..C^..:.km.$.k....=>.N.....&...g.I}.dY:..*>.bk}.q.....0.........V..!qL....=t..?......u..k......z..!.@.?C.C.....V.Ap..V..j.....N..(.}O.X.P6.t.|y.m..K......|.m2..a.e...WbM.JAr..U..e.......A.....c._$F.b${.8/X....^...`..t.*0...P.F.......xZ...n...tp.r.xN.{... ..z.)....nMg.#.u... .@.=.?].t!...A....t......6z.]2:.{..l..2?..?B`.`...J,K.sH...........6.L0...MJ...4.2.....:>/2..p..4*Es@\..F....&....V.. ..)....L.u..{.[V../.m.h.x."...8..|............z...B..k.giU..G.EJ.........<.....I....mh_.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):702504
                                                      Entropy (8bit):7.9997414871936
                                                      Encrypted:true
                                                      SSDEEP:12288:MnXLxh06KCKgoNMFop/vFeTO/3EcQX7fBjzJhwB1CJuYltLQPZJWuRm:iv06KCpouw/vFey0cA71TwkuYXQPA
                                                      MD5:CBB29B09379975383F2F61D72650F432
                                                      SHA1:384019F23DCA24AD9396558F552A68FA1915DD8A
                                                      SHA-256:97538AA3A86871AF3E9C2A6A04C6CD5BE20F6CB86A2A1FC420CC4A87C160A683
                                                      SHA-512:EE19C819B89CFD69A88D598B3A2E8E98E3FBA4475F984DC02634935E37DA6DDC41793FFED656FF79D7A2B3B9B7791261F07384BA38C5E2F781CD4C68002BAFA7
                                                      Malicious:true
                                                      Preview:WANACRY!....?.k7\..A..6G,.B...bY..._.{ .-].../....>.3..Xj.w. ..KI..-.&....f......6.].%b...E={gV5.....p>V....U.../,F.F....\Zy7.{.."L(.....s..[...q..}..u..%.....DR.*...}J#...2./....V...l.9.2.I...=.-...N.B_..k.(..'v2o._..B`...o&..}r..MDp.PD.F..7... ..zW................|.fv.9..A.-......l...8..#b.=....$UB.).eX%<...K.q.t..(RW7E.5...7...v..K;......y.i!..F.....I...<...e..%))...z#.(.-.rp.......}..vUan..$n.I1U..y....2....4~}A).*......,#4.@.m.B.`7.|M..$}..=.h...._..p&K.3...>....l!...Z..3....f...z..o.`.0..*.Q.1;..A_g...#z.....;..w6IG...{.o..W`+h.1. b.`%..... i..!..F$.0....f}."^...7...#..F.jv.Y{a...0.!:A.K..a...M...H......h...(b.2.u.).L_.LaD...A...g._..!.'.p..3.V..)Cb..U....t.gY...[`.....}.zA4!........V..oQ2F$....=..inn...u.,BR.jb. &E..{..]Z.cq<..r..b`.}y:.$xu.Z....p@"......=..(\...@......-J....l.}.. D.h..Ie...z.............=@.13.Gd...z...w..z]....a.pP+F.U.j.r..?.\.).....T..i.f....pP......9V...+.?R.X&.......Y+....h..w..^.lb.6.:{D.@.Yj.....61....kK..*M.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):53480
                                                      Entropy (8bit):7.996404987751446
                                                      Encrypted:true
                                                      SSDEEP:1536:TY4FEM70nVUeqXrN09VGIOHZRxehugO4DX:E4tfx0fOHZRxeb
                                                      MD5:0C8AC3F4D853F78566B3EA8E550BB46F
                                                      SHA1:49454FD3A9288CC5961D72BE2E0DCD983D9A74B4
                                                      SHA-256:EADC5EEDCBE86BD5285BFFF76A1D66168E1A705EECB8AEA5BB1DE847B091A0E3
                                                      SHA-512:1724E653177C91C3886371B33AF2F06071C73319D560BA644813B3699A57EAA8E30FF26EB5CE5DC441910E6D2712C7DC11341D6172D730D59B2DB58244932BD0
                                                      Malicious:true
                                                      Preview:WANACRY!....Y...W..DG.R......*~D.a./w8./......h..^..A...2..q....*D..M...IN.r}.n..O.:Dyx.'t[....t.....Y...;.8.k.&V..s!.uZ....0..P.X4h...&.^....]toU..#...C.t..B..r.......f.n..M.b.K7....;zD.=.sy.#h...vJ...).....cU.Y......S......-.)*,...%{...=...._.....\.9...............!...l.\.e..h..#..U...z.e..Y..c(...%........v'B.U0...0p\.][.E_.I.z^.N..`..J..@..H.N.T.}.m.I;.3G...`.|.~.B..7(:.tH.2..HC..]l@s.j...n...fKk<...[..uq..%|z.........A...fIS..,..3.S.a.T.a...6,..D../.........|.a...1...'VX..%m..sp.Z`M.h8..[....V..+$...M....r....v..T.:.jz\_..`Q..I.....r.8. .yB$.....Z~2.^..A....,...m&...YRtTr......./..,/..\.c.JQ...#....zg.Q.....&...0..?.....'.4RU...X..+.FB.6..Wwc....kDz..NQ.s\[s.|..Ay...Y.Vc..Y...=...V..5..0..3^....'zy.b.... .<....9.....'.......k.V.u..G..-q..u.y&..v.q.:<W...a...T.S.o}.MT..i.....&.....M.....NIH... .||....j[......].zZ.h....@...}....]...R?..n_.I{O..hi..{.'.=mm,...+@J...I..l.Ms.J..~...>...@Q.....).Rc.Vm-...6..\6f2./T.....!.....R.$-.6...)
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1573144
                                                      Entropy (8bit):7.999885075166239
                                                      Encrypted:true
                                                      SSDEEP:49152:G98qqzlR8KHW84OkUef0dPV/P6/7MghZgUsXf:GuzIpiS/4ghZgdf
                                                      MD5:4271DEC206D707E83BEC6E226ECC6C80
                                                      SHA1:AC075AB00832F42CC4ADAC0C45EFC71089E44EEF
                                                      SHA-256:B65268C7BBA263D2A426E4F1757CE8658ADC44CA4EF9BF0071B71F39B3561F2A
                                                      SHA-512:AE6BF3F585F828A2C3C7DAF600F82B1CB4793AA3B393BEC991633B1468288F244D14D8806938D602ED9E9CA6C8C15E61108E9122F7CC0B00F319D5FD62E3F7CD
                                                      Malicious:true
                                                      Preview:WANACRY!.....;.].......2....W.(4Gv.s..fa.c....*..W......".. ..-l.........cR...7.`.z!.u....K..B.>|wF...K.D......[.2.@l...].Y.H,..[@.!.M0qI3.KbP6.....Kp..O6.EX])p..>.Pn...>}.].....:..d80....r..8.(..9.....1s.'{..#.3..F..E....G.......&..3...A'<......CHg..e$.............J.R1.T(..^*'.U.#..P.\y+.....g..T...V6s.u7.[m..s.&..&.......A..c..Mg..4.g&e.q.g].K$..M.-../..#.<.......b..]........U0.T$..sh@.b..9U/...x1'.....ls.\..AL..z...s..tV..[....1;4..?0.QH..u.!v.19]w.,)\ZUcFY.M.H....\5.*.uF/.......l.9h...\.Lu.;....m.%Zj...`yqq..'@[....M..V.t.....|...a.;.X.c.G...p..3:.....#........{....S9. ..g.'.1q.4..2x..^....|F>...' m....i.d.....$....s.....o.ZW.....#]+.. .......x.9.......w........;H.Q.....2.4o.YbT.A..i.....(>R.3....../.3..O^`v.+..4X.J+..b.{.[.}.......`..624.....|..:....!.,Y..[~....B...x.3.:...*...?M.nz..Ep.....b.h.86I.........t.c.s&.....L..N...W..........y.Ym......%&...J...@..4...}...lz.]...t.Sy0.....G..Q..JWH....!.....&a@.Ui.^..<.<.v....gS.MD....@J.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1573144
                                                      Entropy (8bit):7.999888170929809
                                                      Encrypted:true
                                                      SSDEEP:49152:yvgHlZOfTEGCDHCkE7HqDGrPbhU7NIWjQeYnILC/Zk:8mlZOfTMejLaGrjhYElnIGhk
                                                      MD5:121273B7BCECB98FF6F3903276EEFF05
                                                      SHA1:306BECBBD6DB7EA73B060D7C158F14E6580E31DE
                                                      SHA-256:D141E6F2E03FDF3D665BDED49AFA740C08B4C8315137CC771B97A7C7F8027C26
                                                      SHA-512:5E64B6AFFB9DF4B81A52CA8A0F1FD9136150FCE2BB5193527E89F084375EA51D0BF5CA913D8110E3C1337BB69E3802062E3CC4C987862CF91C87654FD76DE5BB
                                                      Malicious:true
                                                      Preview:WANACRY!....?$Ek\..U5k....|....-..U.q. ..N2...,..PP..:...;.m.F.[7...S3)...u.w{`.e.w/..V..]......iX..?...m...-.....\.D.g.\W....ZkJ7!9............t0..V.......%.j....Kl..!......].d...U#?.M..hP'.#....!...W.C..x&|...u......].<tg..j.f.h.?.$...a.8...OJ...TJK..............|@....=..@..:).......x....V.......K.,"j....w>u.../._7.P.....G..l...2.f.KA?'..k.....[..6./p...wG0.QR "...^...<8P..d..xzD..a..%....Nkb.....r.\.j..{.<..W$R.X....."..0.@...8.E..p......+.k...ti .{.../..u.l..!R..'..$..9...#....fiI..e,..5..P..N..f.......e..W<zs6..A.......i...{.s9gd...P..O.,....0.^@[i)...#.=.1..M..@....?}Y....W....l...'......u/....+ .T.!..G.rU...x....5..l".5T..6C.)...~.Ek%*...F..?d...E.4.\..94:.L........5.hEb...B....a.$e.......YZ.Q.L)7.q.w"..JU....Yh.........'r....@7..}GR..+O..\.7G.........../.'.W...8.Rx...)....T.h....J....6...V..<.....m.~8rPK...Z.&..>.d...,.Q....A.8E..1K....._a.*9QR5..L.2...Kq...y>',.w....r\j..M.g.!...?"...."..2..!r...@ax.3..A.t.e.P....X.Y.....!..
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):91752
                                                      Entropy (8bit):7.99797496820266
                                                      Encrypted:true
                                                      SSDEEP:1536:cC3+Njz5bBXmSYOf7MUPSAcJaC4Qo5lFR0bq0HbBasRu2gtZhesTwH26aSv6/P6p:cbjbZYOfgnvtGlLuq0HFmteWPSula
                                                      MD5:A6F69D10479AA1DB0004987AC1A45BC8
                                                      SHA1:3624B585203A8B1AC0D7536B00765902FC95CCDE
                                                      SHA-256:05842436FB48E31628F626C4A9BB284D096A0FC9F043D10263BCA997A4BCC941
                                                      SHA-512:4180788C1E35B1F89707F95046B375AF6891C3185FEDEF250498856F35B5751EF8F7E7BCA80C8F3073A5F61DB391E52230C35B71F8F20384AB224FCD81A7965E
                                                      Malicious:true
                                                      Preview:WANACRY!......m./.-C7k1J.3..*~..:.....L3.u..w..........7.g.>.F.-.?.3.#..vA8=...o...+d.@.....u.x.O.."..>y....e......_..;x..|]iv~<]..l..'....}..%..kD...d......\:;QrW>..G....<:q.C.....F..N.P.... _z\,.........("\B..........V9Pm........&4V..O.>......u.~ce......De......6.*.*JW.(\.F.P.;..%k...01i...X......",4.bc;z,.8<.o..\..y.+.M.;.h..g..9~(k%+..].<.$...5H...4S.U.o`...".0.w..9M.....@.R.3.]g.(v;...Z.....c.{M.q.....m..81o..+f....z.|...quZ ..W.8<.Y..`Z.O........Gt....l.%.Z.X.h..gT...k.K.$)_...&@.....[..t....S..xG......V...|.6..wh ..>.\......Y..)......U.aM...M.ZZ~..OQ.u.....X&....G......q..A{N.8.e.V.H..L...C...F..."..b.....).a..j.k.........X...CMH..o...LA%]Yx.,8.).`....&.u..x.7.Z`....5....D$.....z..k.q.....U..XX......h)..+(.6q...dj.}....T.s.....&....3.1..g'....6@.]..=D.h4...I.....I...&......Q..6V...%....mH......HwO...W-..sC`@dX.6.H..1J..@..t..+Y.z+...i....k.<.x....r^E.aSQ..K .O..,...*..5.....;.......(.*m.s.......DV>.R.F.TI....zf.6m.......+G..Z.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):15160
                                                      Entropy (8bit):7.98743123283889
                                                      Encrypted:false
                                                      SSDEEP:384:3SQ8Z6s5YNebksq38Rvf+TQlNyGB23L+kbqPf:3SQ8ZJPq3ICQlkGs2f
                                                      MD5:0A1755C012B02A3578980316DC8AA5B7
                                                      SHA1:3D62433A639502FB867CF5B114F3F76EBCFE84DC
                                                      SHA-256:4BC954AC2362DCDAA77782EDE70E9146188E53646B29CC354AE71EE3AFDEA22B
                                                      SHA-512:946B05549C800B861CB902280041178B76ECF0B53DA1900D571124905EBAAAAC3E134DEE72C666579810BF854707DD65E7AB9A87CC4A5013BF37842A50344C88
                                                      Malicious:false
                                                      Preview:WANACRY!....%/k..j s......I..J.>]......Gp?.jI'Ah..:2.V.5db....2$.%..c3I.zl4'\.n.e".n..I{ ,.Pp.Z.]j......).../..4..."9.i7.p....o..YF.?..n.(.GT.L.O.%..m....w.7..V......O..NM..B..I/.......E.........`.|...). .p^a..8,H...A"...9^./K....&.x..b.........L-x..S-<..w.~......:......mZZ..).....1)zsat.H..;...0..F.+...{...L1......S....*..95*.....?.^urb.A....s.v3/)Mr.3C.v..0.....z...{...._@$.A..s..+..jT.|...yx.......h..a.oL..R..EX...L....Kl.g.T..y4....1a...4 .@.../U5.D.......p.l.!..*0.M.$....wB. . .g.M..t.e.[.....D.S..)6...69...z..t.u...4.....U...~.$.."5..P.3....\#...HN..!.k"|.z}....m.lP.Z..>../.?...o^.N..vn...vz{..%...&..~+./.<.I.r....w.......o.x..$......g......r.Jq.q&....\gE...q.h`@..\..XC......7.}.j..].N...... (P9y....~.N.....a..#P....6..R.lo....).1.~.#E...{._K.W.8.....i.......g...0.5}....dc$8.e.r!..0...M1.?.w8...Eq0Bo.z4....&.D..d....((....l..B....{..9.,L... ...NRa.f...M.{.......(.tgT.*)...._.. D.9..~-.j....]T-......&.P...e}....b..n.(..]..'W..D....yR.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):45736
                                                      Entropy (8bit):7.996068445571653
                                                      Encrypted:true
                                                      SSDEEP:768:ut9dEiMCp6BzLMjSoyII2g4Fa5rposg2FfRdjZ7Zs6uQuESaK:u3XuzQEIIJFR7ZTuQusK
                                                      MD5:B149A8A82399C522F3D837C07FFC431F
                                                      SHA1:4AF7FBCAA8B200F8A7C5662DEC32EC71DDF8B845
                                                      SHA-256:C8700D0DC3C4F7E105338F34084EB8849802ADC68A70F319D7E4772522E93752
                                                      SHA-512:BBA9765F0ADFCF92E67D334B57F28E5B9E46B8F3511A82B7A956015B283FAE78F5A551B1526548F3F896C944574461A5B9FEC8356833D8275FAEDB49235DC38A
                                                      Malicious:true
                                                      Preview:WANACRY!.....;...Gu..z.b.%%......F..X.?....>..7.+.Hn..h-.v....E...........X.j...B..K..qi..E}QF........C+).U._...0`"..E:.......]..x.N.}......A..E....&...rO.2 P.Z...=.._.rb.7..%..|9.m..e.w..pVa.r.<Y..Y.A..^O.k..LX.....E.lu..}..UN...^..%shjr.{.Uk.p. E..dKa?f/..9..............=5./'.........^.r!s%..uE..6;uNn,..........XIK.X.r..%q=).H. N.r 0Z...=.kbA.Sh.Am..........&_ls..(...C......|4....a..;...]>..}.}.Y..?..\.Ml....k. &.4.FU.|e_.F.|...X..}.L..V.C~`V[...82..(exk..I5...........sf.{).[...\R..h.....=.....F* .1..x.0.....X....b=....].$...L....`\...B.'}.8...@2......P.....4..U9%.FZ..;=..6...d,tu....up.HD..@K.A...Z..4..:...t...k..c ...R....].0mK../{n....3k]...Y..d#.LC.q..Y.....M..p...@Y...3...e..ib..s..@=.. .RS4`.<.<..v....?i<.^...5$...H.....y.qwT..S.~.n.w......Us56+A.Z.G.b.7*...7.?.....mg.Y.'.R...aq;`.z?..;I.><%......>......%.J....1w..k<Q.4.,lAM..V...X...fJ..r.}.n9...mp...O...YU.%[.3..qB.+t.l2-..=..x....D"Ho....Q...h...}s.'.E.S.I/.J..s...8v....[/K..a...
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):349176
                                                      Entropy (8bit):7.999504569787919
                                                      Encrypted:true
                                                      SSDEEP:6144:r7YWs4pUM+FAFGVcsMUbh5tbMDQ9TYZE2dChMJBRfS9LU+FmcejICX:3YWLpcAFGVcsM0b/YWICsBRfSCQmtz
                                                      MD5:22EBA19DE16A7481F03F1A5146EF79E5
                                                      SHA1:9F15FFBB65EA02B7B926124B67A4DEDC08D1CE50
                                                      SHA-256:78832E45CD697D752496EAFCE859E6914540B185A9958E5599C792CAA1F1BABC
                                                      SHA-512:7FD1C7CB578BA77C2C1316482FE0E4AF7CBF5F5545240B62DAD89BFCA68535EE1A77E025B659D3B7C5B9F8CE40CCF300DB2C9CFE7BF32579743E86C189EDC597
                                                      Malicious:true
                                                      Preview:WANACRY!.....y.:.7..oV.Kv.P......@hp...8.=.b..Gk.*.......x.(<:..N*C.YO.D\}.....'.r...m..a........ ).bk...$]....H,......*]...#td.m.!...G..~U...M.....Y........I@.v..H.ie9i...<...}%.f..s.k|0.._..<..'....a..x9..:_...Q....sT..xL.....?...]|(.f.B.E.a..t...../.......R.......s...x.....^o~...H.k.......o.yA.....l.....d^..{d~......:`6T...|....%.0.....\%.(/V.m.S9s.02.;.Z.8(I8t7.R...i8I.zIEv......d.).~.S^U....ph.H.T.......n.=?...D...=..M.J6.(<j...0.u.&.......{8.D......... JM..R..Kup..L.p.....)j......<.3.....k..i.Z..YG...c.6...\....?.b..p.dS../...5.o...........?...V.R..*....L.....jX.=..Tb.0....'."..!hQ,...+.0D...Y.4......S.E...-.Q.M.u.W.....j...e..3.s ^.yy.u.I.[I...o#..."kZ..*..j..q*..qJ.9...W.0}......?........&..;T..R...;.~S....pa.6.R.....8..~l..7../..../..:..N....:..r.^..4Wq.>4.... .".?;......Q.wU.......u...\.yc..qU@..6...........b.5.V.:.h.......s&9..j..@=92-. +.{.,wTb......0...N..b..j8.......I...hZ..c.....M]u}6.{..1.4..>i......A....[.`.T...
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):127752
                                                      Entropy (8bit):7.998717080701173
                                                      Encrypted:true
                                                      SSDEEP:3072:4NRXtWkwTBkX6iyRPjkozIQ5vWVapHLVESAxLiTXuPGhbIa4bS11gI+E:ICBkZyd1n+0prxaeTXWKb5Z1gI+E
                                                      MD5:F1445A4A2A01578B53A5599B219B945E
                                                      SHA1:A2180FAC376F14D26A4818584660BFED9FBDD5BB
                                                      SHA-256:6EF94566B2DA156C32D2862F58672AD60D828C773A7C290AFA0C5D150DAFAF24
                                                      SHA-512:CD0EDD2991A9278AFB0E856540761B678385EB7A00C9F89E8A2753809B351299A6726DD167E58F108F543710F3B40A883436A3AAE4268C18811FF8962DF8C87F
                                                      Malicious:true
                                                      Preview:WANACRY!.... .K.."..H...t..'.,.jhHC.X*.. .....G.SJo..vK.k..B]:.\..........j</&.-..*.5..l.Rod..u.@......V.`.".hTO,M.....8.....B..|....P{.6.P.x.CpT/.......!.._T:.pCs.Y.e..i.Z.mdC.....yU#.F-F..2...*.2pu.77K..]..."...`.j....../.....S.........6!.#.....L&.....r.............()[h;?...n......`%0...q.4.....p!+..C.KVF.m9..%..;.%.`n.v...t&<. .E.ku...v$I2....&Mc.q.o.R..c].auqg0< ...........\.=..S].WV.Mg.qW.-_............Y..R....{.]..s..AF.?.?./....5Rlh...I{.yyh.p .........s0...$...yQ...t&.6#...#jD..4.6..i..1.%.\.......s.v....]...:=..o...!..,WG8.........86\.G..f.....`..f...q."..f..ZsZZ.$$/.R.%.=..\.Q........o..k+...X....I1X.q..av-.G^....|...R..i..tB........P.A..{.&.o.0..z.+..i..V.c....l(......)F.X....DX..\..l.....W.[@.A..k..u..i.bo..2m>....P.?.c..0...J..S.M@.+.L.[..(.-.I....&.W..jA/.I..B....8?.?.._K.].....,.....>.....0....+I..u...B..5............w.>1n... ..#.4:.v.(C@.=qAQ...7r.s..R...w:+..$.b..7r.X.3DM..E|..s.F[P.%..C...sz.#$....]. n@Zy.7.....Gy).;.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):234376
                                                      Entropy (8bit):7.999279838616703
                                                      Encrypted:true
                                                      SSDEEP:6144:MPFzYm+Nt6VzmFQlkApL+8fj9VhibbCAmg:EXdzyQSB2j9VhiCAmg
                                                      MD5:26E521BD2D5FF1C1EAB7036BEB7544D1
                                                      SHA1:CD4FC09B6C399F1E63B88B850B388E3B3C8A3D3F
                                                      SHA-256:7AD2962E09F05701A0636ACCF22B6D922FD2074785C057517D87C79C19C2E805
                                                      SHA-512:90C95C443EB9CCD1E88E85661FE27B3F952EECCDC9CD0B4DADAA70734DF7C1BA88084EE556C477583FBA7D9AC671F441BCA161FF9D5E18061F7DA4FDC4FD778C
                                                      Malicious:true
                                                      Preview:WANACRY!...._...(..i.. .?g#...w6c.|.....Q.......o..j(.wk..<0.!.....5..c..}...KN.?..3<.y[.&J...?R1.c....a=J.50.PE.p.e+.PY....Q...4]..K....h#..C.?...P....(f..nss..R...X..nqB........Z#.IF...>.....D..N.&V.`....LU_..#f..NT..!E....W..l.9...N...[..m.}...f....%.......c...........C.^....8}....b.......ax......&...V.[.O.....IDFk.g.z.f0s\*...(...u.>...D....w.H......m.....UW$.....Mc.EN10!..}....../.....2Q..x.H5.fU=W.&.Zh.O....n.....[B..6....Q.^P..7...... ...$.2..%.t........z.1.G.8g....SW8&.!.\.......]..>.t.M#...![.g..2.m.t..c..dF....}..f....jj}[.~..Z.....o|.M....4..h.T.)Ki..G.Bc.z\q..^<5G.....,...JI.0HR..x....g...o."....$....G!.....O...f....oA'.......d......iS.r&.BC......*..t..9Z7...../F(.3....G.^.....$T.....]..r.,7.(...'N^^.....s....m$^.6$N."...b.3.......q.....n....|L.y.i..L". ...h5.x%...D..C.......R. .\.. .eD.a.9G...s.W..`..,Sh.o.\.\..Su`_H-E..Y..Q.......A"..Bp...`$....H.M#.zS.<..uE~./[.G.I.L....'`.`C..4....U.....T.k..c2..r(....|4...7.3.E..".(.......
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):2392
                                                      Entropy (8bit):7.9192332612467755
                                                      Encrypted:false
                                                      SSDEEP:48:bkI7nHyHXM7o6hck07SILIK4XOTNkR926H0CRMljE9KDdkLXoD8fTTn2bBH:o0Hy8BqOILCQmUCmWLXc+n0
                                                      MD5:AA8CBF0432F5AB6E7610B7FE8C9EFF64
                                                      SHA1:1A42AB1E155E591ADADDA3BF2DA416043E711AEF
                                                      SHA-256:BD561A4B8F7B3B20FD9EF6CB450DD9D7714B7A1DBAA7FD490AE0BD3A958F2041
                                                      SHA-512:9D941184451EC4EC0F1FC7F12F629FCA12D1FC6B8FA36CE4BD42C286E1F287D2EC86DD5F53478BC06E4FA2802D508E31A420F8F61BFEF85B6FB50362A39221D1
                                                      Malicious:false
                                                      Preview:WANACRY!.........{2...X/..^e.R..x......m..!....G.3.j..a..`.MElX..`...Z{(...O...2. .z......%...%...2..6x4.!........Kd....!.E..y.._..^.l..6.s.Q..ZY.r.'.%...&.......Q..=XR..-.9..+.../..2...t.....*...q...J...&_O...U.y....S*..A.*..2...f.l.?.J..um:.0M..V.C........6.......Z..f..1B.....^.[..."..zt.....m.r91.fG...F..&.,.Gp.B....S.1..|..o...+.%i0.L3.;./.S~y.w.avM....N....Mh.....xC...W..7.. B.3.Mc. ...F.s.u.D.g.K(.F...o.....!.....rI.#...>.Q.Q..M.)....7#...).gHGCn..@....T.^2.G%.E..S...*.n.....{.%.s..p...;?....E...k|[6G.=........R,..8...1.x........}#.....l.e.Q3W^...G...#....!.NS.L.j...kP......&..5.(.?u.(.`.q....._6........G.....[c...[<._e..0Y).K.$.7.8...xU."~...).. "Z}A.h&..'GF.ws.7...w..} ....c...yg..O.O..:.[..)6..(OF.tH...3./...l..@D..*h.<.....Z...La.....M..i.!j.:..<.Jz....}MC...(.\.........$....V8V'w.i.$T..c.L....s..K.......]..a.3...az.S.u.P.o<+...&...:.B.cB..3.#.v.AW..;..Ix....}.+,..'.. .t...G.,...+.4..N.0o..c...U.|.e..eVv..w.1.k%m..~k.y.w..A..UK
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):2392
                                                      Entropy (8bit):7.908842316584206
                                                      Encrypted:false
                                                      SSDEEP:48:bkIu77NQAYIUhXvh9/DVGiY5wF3UmKFKDSjPPz9XXlneeuxJgD5Tin:ovpQkUhXvh9bV1KwF3UmKaSLPRteeu8Y
                                                      MD5:B0BEDF0B27FB6F41C2DDD5F8FD8A15CC
                                                      SHA1:B78D8063AACD2834A1F0041685E1907C00C1C156
                                                      SHA-256:7A19B357979960B3F516777AF0BDDD6C8404A2089A556F47C8BECE2329E19315
                                                      SHA-512:0B89FB0B33EA85D007273FD667DB20AB1C9F4EC36B91CD3B6BA25A871021239E08E3FE0FD96DCFCED239C29544BC516A1C97C3141D2985A86D025B4EE8846751
                                                      Malicious:false
                                                      Preview:WANACRY!....AI?.4M...X+....F.Mi..... ..A..!0..-...$.A.E.y...2"..f.n..l...)..rh....P.rN.Ma.2<.a..|O....mL...R..P.f..MF.J..p7 &......e..`E.D..w.5W..B...5..=....[.{..H..".L.0.....to.....+^h.U&Pc-E...z%.'.$.be......<...B...|..m.> v. .s.9.X).......I.9d2%N...8.i ....>........../k....Vi.\..2z.]....l.k.$..=.n..=C:k~....'Zr=.."|.y.b.0.lK..`@B.m.C.K!.|.I6.k...3yOW....|.$..t.....|g.Da.'.z..v...&.2.._...x.h.v....V.`....:..:.A?f..a.z-...JS.z....Q.H.....I.....l.~)(..z.".!.:6..=Z..[w...!.].J9......n..%.....q....r..t......1h..3..,CG.9...A.T.p..RL.D3......J.....,V....#..7|........lJ.y.L\..-.,..K._[...R...M3@...;D..>..5fL...:.:j2.L..;.-x1....Ob'....F.4.W.l.I.6.'...C~.F.<.i..-....K.....NU.....&..t...{.>.....9D..%<v.$CU..BA..#...e..".?m.ZQ.............Q.......%.......n.Yfl...7.4...=.2zhF...c.@...q.(..-...gO.w.....l...J;.q.=]<W...M.9s.f..|..R.Io..*W.f.[.{.]...X.....]O.4...&...U/B/%..-.b........,.?%w..N.}.u...i.Y..hW.k.&....i|f..k[.....2*.}.xa*.......I9.H.}...l@..F
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):192872
                                                      Entropy (8bit):7.999041831017939
                                                      Encrypted:true
                                                      SSDEEP:3072:DfSYco6iPn5zqBMk4KUbUPaFCjtCRMvA9ucRBx9wlI9FMunKDhEKW1ErT:JcMnABJaUSFYCRW+uWxSS9FMunC+KsCT
                                                      MD5:AD51F9C3EAFEBCC812FAC77DEF21CD8F
                                                      SHA1:AFF266011C7A3863B1121B6EE643B49005723612
                                                      SHA-256:0E8797F7CF42B19E8D564528C6F4170C1A145F0CC63FB9CE7CD0CE61C3B1512B
                                                      SHA-512:FA00787F523A6840FD5E617DF2AD338C68B2C88DBF1766BA22DEB1409182795FF0088DDF28EE8EF566DD4CF8A65BCB98DD54D347DA3E3ADC58B36CB41C2972C8
                                                      Malicious:true
                                                      Preview:WANACRY!......w1..j...u..!1/Pc.By9c:.k.a....9.v.."N..O.W.c....N..;.r.v..$K............fI.H;..6....O;A.Ro...;.=q..u.a...)S0........3.+....6KV.=..f......^{..i<n....y.....2..C...).e...L........@...q......3........u..H.p...t.E..7.]<.........@.........=......N.........q.N.-.}...k.t..Y..:..=R;.%;.9.oES.2J.<.|Dn..."|<.+...U*....s{.6.@.3..E..W...\O...Ox]..V...5..p.mA}..r..g.3..*..._...k:...h.*..........3...zg>B7k.z.&=:.....A..A.......f=.a..1WGt..G...K......z..U.~>.Y...i..Nqoy..s...O.Wp...kyi..J......\a.RV..#....4...6...j{.&.......mT..o09..d" .b.h..w.O.k....F.^..P*7.....L.f.......r=qU..p&..J}..).v_..f.V...;...s-NwY F.Fe.m..`SH...+.5P|....d.B.....V.+.[.wQ.+...%.....6d..Vl.......d...?..4.....]._'..g*.!....?..OK.N.>...bb.....:._'-...Kx.q..>..Sa.BpT"<E.'...{......m1..=.`g.>..{..EWz.g..'.......=5.VC..4.T..D..'...+.... !.......TMPaK.#0..Z#.....$...8...vOu..m,..f.<...2..Q.V]`a79v..NqG..q1A...........h^....E..>.j;.2......4q...gQ....!...9@.%..$U....GQ.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):131672
                                                      Entropy (8bit):7.998688430820642
                                                      Encrypted:true
                                                      SSDEEP:3072:JOW/IecY2Vc3qgMJFMUKn3oVhcY1d/KqXwKpRQtASoa2Uiy1+j+N2bm70p0D:Yr/YEc3vUOYVGDqX9AASo5B9+NVYp0D
                                                      MD5:AE89ED6B34A397FE1B42AD8FCCAF3E79
                                                      SHA1:CF5C7E6673FEAF4CE45A621176127F7F3F773669
                                                      SHA-256:5EEF27CC4157A40A4ADB8BF8C12F5C7D384DDD45F1C90D7BFCAA6C93F4ACA716
                                                      SHA-512:ECAF341D4CBFE2F682BCD16B0E0FEBF6987A5696CDD995C3AE4E8CD493A7FA6D7766EF16405B26878ADE9B5A5719373CA08C98045433FC4F0583BC75046ACA4B
                                                      Malicious:true
                                                      Preview:WANACRY!.......dJ].#v0.p.j..V.XrS.....O.H!.3r..$w<..E....N{.{.}j8..P..[}.r..Qs.8..".l3.7..x.B4.t...P..ao.qVp....s..+.......~/.-....I..ms.(O...-&@.jyyU^_..5....W.Fi.....F......g.cs.p.px*1.....UJ......x@N{...L....+!9r.....F...K@...%.[.gV.Rt.k..N.j.z . .u...}..".0....<........V.D.'.6q.Zt.......<.....i.._...2.G.I.6L.{.>?..fh..a$...w....p..d...H,...]F[....O........vw....)#c...jcs.].F....4..6<5.`B;/.E..aj......g(L(..%>....g..9....h...[...... tLL...(...u........v.@..iYm.@}...9.:.k.<n|.kKS.y8*..#.^:u?(6..0......{8....&.;.v.b"g...t.SK.y.0.............H.KA...%....Q.4.D.ul.$..$.p..>...fbP.[r5\..n.$h..+....u..l.Q.f...J.\..lis..!gs.....L........b....o8b...@.p.....X.>$}..E.F.g&M.j.d....2e..p......A...A..i..Dv....o.:..(k9*.V-4..M33..$..W.\..O7...p....%,....u...."...%,.4ySE....&...}.......~qV....v............I._.Z.k........&..x....t.kid...i`..x.3.:...#.|...G.3YC............~,...'.l...T.......`y.......<L6Xy...9C....Q.....F,@.44SU/..h.......%.N.+k.....Fv(
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):17784
                                                      Entropy (8bit):7.989725742337135
                                                      Encrypted:false
                                                      SSDEEP:384:oPNXRO6ArHAQ2zXVzhkdesGLjlKYlBQtvSgvk0IwlUMGAS8:o1X+HArz+desGLZKYHEhpIQbS8
                                                      MD5:F6D6FCBBDF2A48D65E1C18C23855ABC3
                                                      SHA1:95D329F4987A5746991402F1B28BA10E96EE552B
                                                      SHA-256:65C48C244FD21C231B33B0E2A4C46EE730F5F857CF4CE9A1292BAC17FC748F6B
                                                      SHA-512:0E7B5F0E0869191B736BCADCCB6C3BE3EA7B4927F563DA3E05FC675B1CC28824A3E5580C2D6FD54132F156F5B2ACDFD6F4DADF1350D59C76CA6129956F14411E
                                                      Malicious:false
                                                      Preview:WANACRY!........Ob^.7H.....@.l.t/.\w...}..vrk...B..$....L*.%?s.h..)..N.l.0.}...Vw..g^....L....A4.M.....6.a..>...T.).M.......R ...\42..up!.%...y.cs..;\.[....m..!...N?3e.f...Fb...S.D}m...6...:r..Y.....j......y.....X....:Ec^..........av.......Im.M..e..^!;.`......ZD......qp...jQ..Z+..a.*.2-..z.,....xX...r.m...#l..28...KDh....r.....^..O...wb..|k.8......(O.g...|.ID...Z.`qn..5......k.bk..a...v{u.M..V........B..v_S[N.t".>....b.Stp...7FYH.?...a.g.X...O2r..E.n$.{&/|....\D2w..6....1Q[T..L...<..;..=....yV4..f.c6*..L..7....^...h!.w..^.K...h...g1.]....H).K.(....q....C.OB*....5...rE.....A..-l.|..s....Z..Pd.K...i..5..lz..\.~.`..z"&...5.k..G.v.r..#.......u.Y/:%.}_7..!...Pf..Z...t.$..r.....%....\.p.]'.Q...q..rF....V....!./..BU:..E...~...d.J......+...i9>]-S1i.E....A.....D\....1..,2.....5....f....W.&.&p.........>.........a.x[..f.. i=..T.^..5.Qg......&.+x..`.....h#SK...>.7!1......NBeMf%`;..bkR(1.~...X*......./......~......6 .....9.-..J..>.t.........
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1749912
                                                      Entropy (8bit):7.999901923076321
                                                      Encrypted:true
                                                      SSDEEP:49152:iqr7D6dQ4z4cjPpd3jGHvKURFRwNQ1cuvgSGlG:3HP4zPPnmvKQFRxmPSGlG
                                                      MD5:FF486BB39F508C2DA8474211DB977013
                                                      SHA1:115A5A2CDA9748E669A708043540E9E5D461752E
                                                      SHA-256:114BD9B7E7D513856ED55DFA1D3EA4A07D17C473BEC465E0F324D0E6067188E2
                                                      SHA-512:0F040AEE293CD6BB4E3318E993AF55F23309661F05F57661AD11BCB9FF22B6DFDF90E94AD0C9EC341C48B22C9F9439AB30765BD1E7A79B1AA29FCC857F107DFA
                                                      Malicious:true
                                                      Preview:WANACRY!....5w..*....|pd.+]..K....!a].|.7.g...=....T|.T...........:..P.;.B...(.......`.6._..:.~.<.V..T...&D...j.ee.../.'.v.N;#7.puI......l...~...i..At.07.....4F..:.D.;.W..a.>.<\..h.T..k.n-'...+......j..KHk....B`Q.!....M#mv...c.ek..+p.;...^q...*bw'Ec...N......{.........Y...Q..c..#..]...PO.q.r....V.a...Y....l.#_Ml..........v].....D.%.a..0E..Y...z..{`....@sl.u.`=JX.R....E@0.%=.id7u...P.he.a...WBc!.q.GA....../{...r...lQ`.._.N.C}...{~l.a..jD.....Q.#..P..M..i+..U..3.Y...y"^...X ..0.".=.R2.9{.6!..|.G...e..`...W.MO..3g..Y{.x..vX.*.))?!.miasw...{..l.....TP.Bkz?..n..}T...X..g.B]...>...........c#...6.2..J^.Z.;0..".k.>..0Z..W....=..>#.Z.hEO....fp:D..J..z......4.{+.Yf...e.vl.48.....;#...l.-..Z....^yg.2.........f.E.[!^.<.......r........<.^.j.3...u..)..I....b.p..".M.Na/8q*....rF.b.......-Wx.}r.z.Y.....O...dje....z......W.kh..}M.......pg..I.`|Ja....Og.|..?....K.Y...O...5y.!..#.M.U;.&....s...[y...lv.(......S.I3.6b.s^...,.bd~r..M..&.d.T..>.bXF.......!...R...
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):467448
                                                      Entropy (8bit):7.999633590735558
                                                      Encrypted:true
                                                      SSDEEP:12288:3i/A9i7QT7CCjVy989Dn/rOcEOWIwb7arYsYpe0:3iYQ4uC5ycz7APeYs30
                                                      MD5:695D4E04420F71820E732A61A976F1C9
                                                      SHA1:0F25FC00BF421D9E94F31DB64B3EB694F502000C
                                                      SHA-256:9CBA4AA51BBA23DC2DA76DF183D6E7D7759DB0B358F9879730BD033A43BAC548
                                                      SHA-512:58E52FB268314A6DA5B15BAEC0100C6F8D2383447C6FB6075D92759FDAF72AA36C6E926647FBE17188383EF9F5940364E48B61FAEC4164A78B2EA987233F0E38
                                                      Malicious:true
                                                      Preview:WANACRY!....,^-......M......>=]e%.0O...U.Zx.\.b..`..c......R}.@...d..S..V..u..y.m5J.........,.^.>..t.....]).QM..a..V.:.....JZ..Z......,......Lt....D$...k6.v....=...d,...,..e."...............ku=.q......8.....Y....x.....v.../....L.u_.}.../....I.......[...6..... .......... ..)........w,.@....W..ZO..j.._~....C,A.G".z7..... s..m...V..../a..#(\....i..(...5..."..f..59l..+..X....K^....F../...M.....7e.Q.Bl...V7.6.8q6.q8S3I\hG6a..pA.?.^P..Wv.#\~........6...i..82...2.nT]..l....Y,...M..*9.....{.Z..S.*...........6D..}t.W...<:p)..?&F=R.<..].s..V*..2.r.._.[.....Z|.....@6..T+.&....`.....2X..,..|.(gxz............_.....NX.f.......~...|.E.....8..0.z................>._Z@>....m.....s..!.b.J.....!.fN..v....%d^%.........N.....\...N.W.....u...[...{..4..&....."O..^./..l..5.!.k........#}o!y/%.%].<.b^[.....ht.:5..r...W<.9.D[e]....w=.J...L<.)}...4*.........I....i.....*.y<.0.=......^...SE............^..."..$,.~...t....x.V.:p..%b.7....2..^k+b6].p...RoK...
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):9160
                                                      Entropy (8bit):7.979697355477676
                                                      Encrypted:false
                                                      SSDEEP:192:m9+6oeREJJm3SuBXnpKi/gG80Al0StMPJCJiBMt:m9+6tmJM3SipKtF0cWJCJi8
                                                      MD5:068ECADEB436F443EBA5D3F801DD83B6
                                                      SHA1:6AE2C5BB11A3DFE22BD21712CC4AA3392DDFD51A
                                                      SHA-256:ACD50E5DCCB29AE099DE3F8FD2169D94490D81372CC070C9A08199958B845B75
                                                      SHA-512:ADFF04BEAFB6707DE48952C7A32F2EB3DD56B6279B376BB1A52724F1CD4E7C1537545A985EBF23D4F2F383F6CDF721C20BFFB48B509D8D5C3BB4A8E08B0E8F66
                                                      Malicious:false
                                                      Preview:WANACRY!....=...H...w...,U%.s4...........7..ci..d.q.=.).Y@...kS..../.3..W`e-...I....b...*Z-.....[.O..;..r....GU. .J..J[......Z.&..jm.-.....\..8.:5...Dh@y.1.I5.1.....}.i.I[s..o..5.x.....Q9.;K...z3*/..._.......]}..&.T.C<Ed......p-..2/..Tm.......%....e."~......T......"......z.....*[P@.....q~.@y.7....bD.bq.x.s.'..O..I.h.(..w.....2..:.T..]%K.d....).zS...r.RH...s.X-.U.#;mCS4'..j..C...R..+...... ....8"M.1I....c+..{m\..o...'.fy..t0.E......2...8..0k....f......$...Y$.!.6.....X.P........2.f.dd.>.5..t.xZ.c.%.N).".z...O........\.D@....H|.(T.@.=.*....,1.. (....UI.`.1)......<.t...g.q....,T .0.0&...u]...p..X..N.).......#(.m.nd..`.........J$..f^....1Hz....NW...>.MT........H.p/..N....AYF...V%.t...Px..|...P.#..z..Y.6d...q..E.K.......'.R.m....(.../.{....(./u./[...c.my...q...A.O...M.........F..i..If.......`...o..Z..V..).FI..r(q.V=.\\..\..'..7.j..].JJ...YW!...O.EH.0.........Q.."...5..Os...#\[.....".........6...A.2&M..^.%.....l...0C.W......Y...zTa.....#2xTY.!.l0..}.D....
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):16056
                                                      Entropy (8bit):7.9887188147121275
                                                      Encrypted:false
                                                      SSDEEP:384:k5R0jVddGPNtQBIS4Z1ne/JqntVq0n+CgJZ7k0mr:kiVddGVtQBISW8RG+CgJZ7k0mr
                                                      MD5:A857B2495F010FD44A67FA2AA52E342E
                                                      SHA1:19E62DA9489B8072E5C15E086B9EC80B472ADFC8
                                                      SHA-256:B32E18022EBE70F0D4D46F20CD747F1EFCAFA3A761E3D4E3CEA510C54C9981B1
                                                      SHA-512:C921BE5C901B35064C239477DE977C5D057EEF5131F1086AB8BC649452ABDFCEC2CC4323A37C623C26FE6BC62DA779F62BC8AD26E5C66BC0E8C65BB5E8882BEC
                                                      Malicious:false
                                                      Preview:WANACRY!.......,.g...l......R.A.*k..&Kd<.....G.b..0bi..M.x...4..&.E.DUm.H.......4..6x.....|........B.......1....W.s..l.r.S/....'..K.r.b...#..Z..P..F<....!B...6F..eZ3?.*8}..F...X._FKL_...nx.Mv3B........"..>......q.... .15...(;."...P$.{...q....i.....Jq.......=.........(Y..{..e.F...lP...._jFL.}....`'.$..d..5wd<y5.njp.....}.*f!..d.@.6...I.".".c...e(68......h.$_.o.R.........T..Si.....qt.........X4.Exvf...bX.....9N..i..v....T.o....`.&i.0...o.J@*.........z.|B2..SZ.i.....=.W...z.!...j;v.X...9N.....[....&....G.[B..wE.$.@..eVb...'1B..I.~~(.J+..J....>.0.....@......q...H......!.......*[.....x#.9...K_..#..gwd..dA.g..`1...-(....4..g.@.[...;F..2..${s...\.!...2.....@....:16.uvO|G..G.g.|$8jE(.a5...../..2...B/r....=.`<,....]..?.._"..&..^......d....c.....q........X...&.....%...........q2........5{... -;....bb.P.g..#...}EV....v..D.........=...d.......a?...+.....B2.Y..g.nP.o..M...t...M@...a...}..>Ov.......z~G@.....^.5(B.....s...nUS...%[....E'..:.....
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):105400
                                                      Entropy (8bit):7.998335030014057
                                                      Encrypted:true
                                                      SSDEEP:1536:VVybC5AuqlhTAiyrPent0mUm0aqQzWuHVa8J0ir+LcaEP9KkuSiF+z9o:ryb2A7hMi0Pgtum0avxpKgP9Ru7FIo
                                                      MD5:DDDBD3843364CBCA2EC854788C6A2461
                                                      SHA1:EEEA581044DCFA1CAFC9439FD63B4FC0ECBCD78F
                                                      SHA-256:E5DA1E69E2E034BD50F35E52E6CC7400C75FE39F1703828A7BE5981919C0039A
                                                      SHA-512:649F83A93A4BCD37B6E9F437170118809D0B27EDEAC1740C7FF2CC446193D9F2A5B73CC612264D7FFF09571FC2013C3DF7248D833B9EAF0466AC10C0C1D260BD
                                                      Malicious:true
                                                      Preview:WANACRY!....j c....H..,@j.48\..&....._..\.sc..wS..Em.U..<.........:..2..N....5........|.D......h...62..}D:.......2x[......R....1.o3..&R!I./....b..i.. ............q....zF....0.......>=.._..J./....]X...]....@5.3. ....kwm~..6q..ZC4.+_.G.....u....v.....d..................|mB..M..:v*}[A...*..tj..(.X..M...K.....h....*]s,G...d...I+.>.#...r2......A....).)..|Rd{F...>.W.y.T.a.'.D.Jk..a|.LG.=.B1....'..F.}O?....t.C.U5...u^......j".)n,../.).s.(}.."M..z..W.`[..e.a.......f......+/...$#...<.5..-_Q....)....{.....(h.......XiYW..`i....^H4H.7......\Mj..D0../.}LQ..E...:.;.5?.3...<..H,R...-....k..K...g.W......0?:...Ev./eD..TSy..],v.j.......$-W.z..#..n..r..V.&..7.......D.2..........j(<..z...H.h.%..q%..3H.2....}N.....g.....|...]....Ltx._.....DX.....h.".+.Z.va1...1....Wb..W.c.../.<.&.\V..v.}.((1..aNG..,I.O.=<..&.....X.\.r.M.S.J.[2.o.Pw.WV...f...(..r......2...{K.._.6..OZ./YV|.....!.m.r:...8&....b...hM..-.l.^..?.....P...y...92H....^......C~..3C..qrP^.U.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):14456
                                                      Entropy (8bit):7.988541684124136
                                                      Encrypted:false
                                                      SSDEEP:384:D211iGAjuF5/19x9zLkxy52J9sVvrCNzDhZEgJfh15Kbe:D21kxuF591kWmsB+hDhdJr
                                                      MD5:CCFEAB1A6ED79B6810AAC32C0707D99F
                                                      SHA1:8CD92B7CA331642144693417C3721781D9DCF2CA
                                                      SHA-256:1CB6EBA371A390FA984A9645C51CAA39315D57374C0B784A7C135FB21A7B02BD
                                                      SHA-512:8D4D200EA7C859DBB1A39EAC5243DE9053D2894E3CAC8A2DF286FD3B417BA7A3327E2C63A06253024FCFFD49E19676A085A1945197139F1C858A7C77AFA168AB
                                                      Malicious:false
                                                      Preview:WANACRY!.......K....4...'Y...1Ft.N..T.J....b.o......,..s..c.@]{(..Og.0..<e.....Q:L.N%.^.....".2.mJ.,..UC..6...BJB=...;.sQ.$T....U`....%.].|.TIS...}.hN...6.....j..Aj.T'.6.0.ieB.4A......Kx.?.......B|..[R....1Q.9.AA...|..P..=@S..}..'.4,.N.p..J.R.....Jp.......W7...........9.X...bY..M_...|.$ .....O.a~....0..qp."..s.:.."vU.7V...Iv\Q...GZm....h..CK...|F......,/...CY.6.H...V.c'...u<.h y.......*..6.L..08..9.........0..A=.`..2s&#..Os....m.m..?.*~..s6u.E......J.....r.9.;...^..=,Y2/..r.F(Glp..vK]..Ak..oI.G;.m..S.W............%2..F.w.I.K.;=..WI.^.!.!...C..........D!....j@..+.>......`<.[..j:[.9...1[.oG...k..Q..|..=j......f.....9.f.....]....{.....N5...k.v{.. )k....j..h...-..qY..4i.?-..l..bcI.....4F._9..f.o..........L?....(.....Dl..o.W~3U..j.,.2...QP...f.SD..[C.=<.....oiL`.U\Fa..7.....T..9#.VL.j..E..N.i;.....H..8....B......UP\<xd.E..Vz.L..P.......-....6N^j<./`.Y.#>b1.*.Iyd.J5..Xb........EVy....\....C.I.>..?...1.p. .>J...-.,.j<..QM.....8.f.d.....r.z7
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):3160
                                                      Entropy (8bit):7.941835005542873
                                                      Encrypted:false
                                                      SSDEEP:96:oKjXS1ESZdX6jzqxyiKKeClZMC5XJ8IkbL:zjXS1Nf6jGtHZMuXq1bL
                                                      MD5:3B44D1100F502BB66D02859A65466E82
                                                      SHA1:0F5736CDA59D08A4E8713DB414E51DA0207EA447
                                                      SHA-256:B238A7EDA3D4140656A139BF5E2E02E6995E95E7A0E35540764AC6F66EF30A67
                                                      SHA-512:B23B3876D373499ECCB27F26B01EED66DCE8BEC5DDA8E932EFE11422B1FAE27236BDB114BBA1C09851C4CE3A19D32770CADB5181BEFBF87A901A3D0A753E2FB4
                                                      Malicious:false
                                                      Preview:WANACRY!......D....h.g...e...%Q.m.G.'....z..0..=.tk>2..`@...o.........>u...)%.nE...V... ..j.G....{...%s...I.V.....N.2^)].....r..t..*..Z....#....e.A.R......R..f.(Ir..i.].m^n...Dj.......8.].Q..Q..u..&+...~....Q..".0.!>....,...;n@w.o.....#.Dg..=4.........7.....3.......q...V.G.q..ll..P40..>.EI.mhC..q.Q..UR.q..8Hd..X...h|..Q..&4N...W...B.R.$.....L/`&m.J.h.o...(..-..H.)..@......B@jH.O.....XQC~..y!..9Kw..M....:].l...=.....;...5:....|...$F9.o._\C... Q+.\....o....*.4..<.0#.m......`a.~..-.xbd.......A ../t;........W.F_m.......O.]....8-UX.......1_..V.+.Bd...p.P.r/.I.i.....:..?8_......}{...k'.E..%...J....q... ......Nw.."km(..H.bO...K.<;#R@`=l..4.(V.,O..........%[d!...h......p...L,2.......X.....N3..{(.5....;..jc?.#I.<5..H...-w...|..`Y.....a.....2..J..1..h;.h.E.dK...y..VY...S...0...f(N.f.|a..@.g....H.-.9.G..eZ...y..W..oG3..x.|.WC..f..Q...b.#.....<.M.R...D.r....c..Z..{J..n..#..k..6..q......rk!..}..........'atKV..r(..\#.$.3.......E.&d..}.)2~...
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):11096
                                                      Entropy (8bit):7.984016668408386
                                                      Encrypted:false
                                                      SSDEEP:192:Vil9AmFUoFvcTizRu8qq9m60WrRIj3PlaDc4U67tYnT4KwjYcLRJgp1Z0FpQRfQm:ViTpmTiNu855vRWh4UoUEccLRJA1ZMpA
                                                      MD5:C77C34E228105E9FAEDB1AA578005C33
                                                      SHA1:5165ED5D9CA620CDAA8367F6235E1513F36E3D41
                                                      SHA-256:8834279A8D5F329A15BFCAB15B6949BECA8539BF9E5A020734823A70556C9C53
                                                      SHA-512:0DCEF4CDF2FC0A95FB0B58BA70ECDB37641D8EE0E3555042D01A5171A34351C1E88E81893362647FFF7DD8A5EB62E256E897B4B20941FEB9047B6E1515CF7A9F
                                                      Malicious:false
                                                      Preview:WANACRY!.....1....c$Mp'.+K".@b...P+.c.[..n?...4....~...r8.3.Q...H.......XTB|w\...A..}...2..GXWq....'Y.6CJ......8!.a}.+S.....r....rs.E.F.6 j...S.... 4H....uL6t..S.O%.......0......u..?.........,....Y.....v..v6........S...Km7..><..\..|.....D..LI...B...4...._H_....=*......o q../.a....A....<'....@................1..!m.lC~....&7..w\..)...?..g...`.]vp..DW,.cFI.b..+.5.EF.:,..P.;p.+..'.+.{X..5p.N..`...../V-....J....;.5\Apa...}..e:.v^<. ....+.......r2.o.Q..IA!{....Y.2...Z..=M...I..[l..R/}...4.o;........8`A.h..F...'...j7...[...eE.l...9.........m..l\...TEcj..;.h.f.H....f1e....d_/..!.....=.e5.`.KW.X.4.{f~t......%...[.._W..g....r.<..{U....=. \....e8g....8.....q.P.O....w=.Oq.C..&G.....1..f....._.w.n..C..........N..b.q.Cv.TS7....\.JL....n...y..e.8.......X.4.%..*.*wj$0...j4..b.M.5:...._..'(p0.'0.$....B...._...T.9.....~..o..,o.<z..Q..7Ik.td....Y.UG..3.U.@m-d.....(..Z0O...{...m.....Vd3.M.]...-...jeHaZ.....V...6...u6$.Pq.3.:1.rT..DBkc.5~.&,..1.kk!......&c.}l
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):545288
                                                      Entropy (8bit):7.999667309701323
                                                      Encrypted:true
                                                      SSDEEP:12288:dLgYXQcPpRCiLahFV8/7LkunqZo+F94zvog/50j2QnkUKNcuZZ:N/QcgiWhIk1vF2QcRZZ
                                                      MD5:D4AD595735DF2E5EE9E49BBBEC492A34
                                                      SHA1:38E8739E6637148B5B228EE92ECA872A698907CA
                                                      SHA-256:F9996EED36A1C51F3A874C9F88E6DF14513BF3D73B11824B2613FB6F8A340E8B
                                                      SHA-512:97AC642A063788C41A15E37D27FD736120A03886CCFAEDDF5E42432695A26CBBC35BE62BE4447137BD57923BE95845D2036FC1742B1DD64756E637BFE3C960B5
                                                      Malicious:true
                                                      Preview:WANACRY!......9....yI.l...>.`.w...Fl...a....b...V.w......4Za<...X..~...w......p..)./l......s....?..B..@.?c..!BO..TM.U...4.=.w....)o..Gw..nd...,>>fd~X;..^d:...m.]......+...P...x*p...X......U....7j>...b....r.Ux..;.\..Q4J.."..NTh.h..t.._)Q...&.\.Ah...bd..........P......j.Q....&(R.$)..'.d...b.?*.....+.Kjq....o.....p@..9D}.....2.c.._G.....:j1..S...x.v..!..Y|..(.....@$g.T.....5/.4...q&'.....Y.&H.@..:/...t@X......m6.i.HK.v...%.<..S4d...~1*H..0....W..f.H...vwqX...g.......m.kM..DOQ@..8.!.V.z.Z..-...b./..9..."%)...5*5'......\.u"....(...7..+/...Q....ly.SM..I7...Q.e.m..(1.DM.P.....gL..D:.*.;....!N..lFh...Cu......F~...N..b,K.s..;..K..h.....;{..c...F.....O=P`.....4J...F...$.n...d.....B....%....Z..........Id.e&.+..b.M ....0..\fX.Y...Z..Dc .PWi.y.wt.C`5....f.r.....V...`;.x..y.&K*.+...n.k.u..Z.;$j../..ka"...u..3.u..pa3H....)A<.......,W.v,^..^.(......n..\....i....qI.i4.A.biFc0....;........=R(9xb)..-..P.pI.7.m|A...<....h.x..~\..Y..&..s....v9C...r.T.m.S.`
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):59048
                                                      Entropy (8bit):7.996910129275227
                                                      Encrypted:true
                                                      SSDEEP:1536:jn67W/rZSW3b2CzEScBY9waL/yM6k+ZQpIHR9Vzf6unmqOi2Yu+fF6:uK/1SW2wEScBYB96k+jHR7f6uvO1Ylo
                                                      MD5:BE797AA424DF6F05CEC366B6A9739C38
                                                      SHA1:37F140504EC500B8313E8B7ED9E443BA389ACF1D
                                                      SHA-256:F90141C8B9D71097DC1A01570DC6553590B6FFA5ADA05A2549905F6F4CED56A0
                                                      SHA-512:1257542F307B902F8EC0E7DAA22DA9BF613D44A1E75E281B18F63398D4D1749637A03C3000EDB06B7BB6BF2CC27F35492A2DBCF7C95F90BF309E2577E16D2DE5
                                                      Malicious:true
                                                      Preview:WANACRY!.....O5${N.);....-'.5..#..8.....+.tB..*...\Q..<...~*[p"....i....G*^.........}..1.q...'J:T.b6/....:.....d'L.JRt.D.S...8......8.......Ih@mbM...I..A....l....#....c&U..d.nX.~..i..W.%.VZ..i.UQ0.EK..W...z.=.N ..x.e"@.o.\{.....~.9..w........N*.;..6...Q.=.............Z.....]8.......v..%..4.$......8...M.......A...N..8.U.5.......C...](..k..rr.D.e.i.#x...h.3T....-e0".>.{.....d.Z..@z.G',.."..O)l........>;8..;B.o.7..b. )1...~.M$q.g.F...OW.|W..|...>.....].2E........|.$"rLM...^H..Bz.U....K>..(..\..:.[..]....i.....IJ.e..=X.U....Yv..i.......g.7Q#.y5KE.....AO...."Q..&.Ut8..~{..tDB.j>....H......=.{.J~C...8.%k~...4.7.{..0.....X`.qaI2/..a].....M.K...`)/...%^..K7P.aY..3.H=.a...dtO.U.f........j..?.^....0....PZ7<.f...M......MFD....x.M</.D.3.K1.S..S...%.g.j.....z.c..B.4 E..... <d...m..o.h..W..6.=/H2.x7...M...=..A.-`K'....s.d,"&k..=j..T..g..c..[.N.6........o.I[*`..`.....:.{.n{.>U2...B.q5I..rp...K.3.y.C9.$I.k+..DEM7.....r.D... ...g..m..1p.a.H0...c.H@.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):121496
                                                      Entropy (8bit):7.998442949392999
                                                      Encrypted:true
                                                      SSDEEP:3072:cO/1Qc4Gb0ZQPezj5ZWyjCvUVJeK3+jcX+dulkXje:z/oGb0hzj5ZWylw7uKi
                                                      MD5:21E398693EBE23EF2F54874C91B6AC95
                                                      SHA1:03E4EE1873DDC625004061F8D91B81F7E318E433
                                                      SHA-256:49A18ADD6591ADB76525AE16DDA63AB08070BB1F37A74C964B8D15605DA2AEEA
                                                      SHA-512:473782217CDC30C16C5997707D1C70432646DE7356E1CC4F47EC0FF966A78DBEF20BD25EFCBD1E78CC6A1633A3AC78AF50A53A2D429B25B00ADF110F6A83D1F9
                                                      Malicious:true
                                                      Preview:WANACRY!........Z..2.5&cz1h.a..n..v.|Q.=.....y..l..Pn....l~O..6....s.....`..(b>/..j.'..P....C...*.D..w.4....QM4.E..........O....).cZD.....r..{..#.~....1...s....P....\....(.;|G../L. ./..>.....S.c.J.HP=..|*7.o(.Y.).oP..'PX.V..8.mV..d.[ I..*..P."...../.-.!..mZ....~.........gQoU..#G+.C..8..,.o!C1.6.^F@.5J_..S....r..z8..~...R...H.x@.6\G..J.s....!..... .Wx..A/.W.k...O.#...;*.h..;....E........X.\..nck.....^@h...~.*......#..^.@..6..a..~.c@..I-I.[.?..&........]..B...b?.kN....W.....<{.P..O.~mR...d....F..J.1*..r{4$&.>..V...P.X.J..pA....f.z=....... 8J9.k.|.|\..I&........u..... ....6..I..XF.....P>.v.c... .........i..q.....L../I.$.AU$..-@..$8RyC.3....!w.X.u..DdH+@.4.k...<7.X.d........tT.J.,.....d...@G......{.a..R.PrWu.v.E.......o.F5.ie....D]O...M..8H.............jLT.Q..j#...w.=.?.....p.}....s..D2.:b(......V.:2......s.D.G....D.D.%.FL>...{...|z.nr.?..5...h.^...L.}........O....u...1r....j.B.....m..z...HSo;...=.S.>...Z..:..F&.Z.$..J..2.nC.x.3O..sV.#s...E'"3..Ay.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):4024
                                                      Entropy (8bit):7.957767866291706
                                                      Encrypted:false
                                                      SSDEEP:96:oHO3TEJPBHAdBLMW/gBiAlWti/om4ihEv/Rh8rcpXprQyPjz:NErHAvL2lWti/oIhqRmOlPjz
                                                      MD5:6A685EE2B16CC63DDE0FD946F12DE97E
                                                      SHA1:D94AB7AA0B9D68B08733D2F8F335C8B77ADF0D8E
                                                      SHA-256:AE33E21C03EF652DB0C477A2C534CD482C3DED92425D740276770CC25446E39F
                                                      SHA-512:60A88540441A3386100EF1A7BE32DB88D88E92235120F2626EDF85861CC382C3021A51D29FBF5E79351B00D804B0474EE6950904276B1DDE5A8A149B68CF10AD
                                                      Malicious:false
                                                      Preview:WANACRY!.....F..YA..&eU...d.#..TaG..x.../..p.....X..H.H.v......-{.vb.X.2j.....G..cW.../>.^........<V..!.n|.X...+g..+.%kW.....e.g........e..K.l..V..|.) .7e..|...U.).3.Ix.5x~$.gR. 2......yrHP..B.|Cd.....9.......XWk.&e ..Z..:).u1.8......(..P....m.....@.P.j.f.............2..!..<Q.......Ie....R..g...c..r...].(K....^..p.Qw4.1.8.....!..<....8-.lw..........+.......($..Dx....p9b.U.4......_Is.9./G.U;.;..2...-...?..aUL1..z............O.d...-*G...Vp....V.:.~..9X....\......W....y..QP.....=.^......[.Q../E.e...r...U...cb..oB.......0.Da...blj\.g}...?.[..j. .|.s..-y.)..a.x,..;+........n....A..!.<...}/.af...{s.]...a...<k.mc..-.(Blr'..a7.dK.j..+...q7}|.....q.".......s ...L..(8?U..I./..gd....@.E..DM.e..".e.,.E.c....J..t.j.[....-...+..._.<..n#..|.)...Ec...&...L....F.../..Z.`......`]Z_P./#.j..|.....P..&.S,l8....]]..~rF./...$...|%..6.9..g.... {...FU..*....h....R9..h...|....>.qr..yN.m8.e.....U5j........'.u...z..{.w.d.....'-..H.e.{z..~.8{.....5)...K...#w...i,J..T....
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):2184
                                                      Entropy (8bit):7.906177957959955
                                                      Encrypted:false
                                                      SSDEEP:48:bk5kro1tSK2hGy15yjS1qyCD/YMLUynWNKuQdf3DzXixeNIY:o5Ao1ULGruqyCDhJuudvnXixeiY
                                                      MD5:6C0086BFF4251B0E0836CAA4C6E37FE9
                                                      SHA1:3B7461B61069C2A4870072C5FFFC39BD232747C1
                                                      SHA-256:376D21ACA2A18CACAF3E5BB412433178E49469156C8C228B721A512A14EA0E70
                                                      SHA-512:622FE1A5796B6F70897DEC7C89500984A3F324E9C9C19691B2CD5FE0A0A8BB806EE4F5BCA0784B32E700B69E25C810E2E5E7FD3978284F25911DCA52EA49E31E
                                                      Malicious:false
                                                      Preview:WANACRY!.......y#..2.UJ,7`...U..;..=.K.a3V..4."RW.w..<..i.9.$i.....U.!I.1jL.>.aE....)...ol... ..QP...GM..<.2+....x^.l..:&..@....r.H..U....I.{..p...P..+E..`s....|x...TF.D..T....{`..F....Q..U....j0...4/..VN31.f..7..,...15...wDb6.....4.f~E.\.;. _.../..*..>..+.7....b........U..L(l.cO{v.<.[."\}=g....P..M.....B.+Rx...c~....-..F}T..Vx..X.x.G..u......`....F..Tc...'.......z....|...]..x..Y.nj..Vh......*h.G...{".v1&._ 0...g....&{...Z......I...H...M....{".n..fJ.h%D.....%W.4,...3/............v..<7..%<.}l....j..2>.....2.@....4(.aV.....[..n^u+|.7...VMY.+.\.Z. .....k..=......%.........{.V..SR.b.#_mB.Q&`...>.G....`...E.7..xh....g~&.|..W..7../..x}.`.5fl|.&g.|Qz\...f....v........#.....'%.O.......d...j..!.T@._....<.^..$~a<n..y.f$.....dW.j...c...,}.t...-....-T..c..>M.....~]nnp..i;.xX...8..G.1...Y..Ej.......q.|+N..Xo9...4....H.Z....!'...l~0.g._ .kf.d-.{w..$.'..Q.{.........!/_.z.pm.~_B...(.I.Fca......xh...xt.4.......v........#....]f.yAo.\+.e.W#;.5.)...)..
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):172680
                                                      Entropy (8bit):7.998946515747633
                                                      Encrypted:true
                                                      SSDEEP:3072:87uCOkO/kzpMe+eEQpeWA00GHwqxVgJglKaI3LkC1FW/6U0Sgi8:8i0ukzpUkrpxVgKsDgCvWBgi8
                                                      MD5:BFC56EC4E8FFDCE1B4488D32EDEAE627
                                                      SHA1:E34D88263D2880C0A201DAB0CB9E8FF7068CDEBE
                                                      SHA-256:AE07BE3EE799753D426519638FACDED83369FD185E7DB800D0F72E17C3A50F67
                                                      SHA-512:56CB97B940475F386D207028D0287D5B7D7644D14F8D8CC10ADF8BAB0A92ECDA7C09F064F67A29E2A3510327D9314CAAE945D1EE1CBD0B7846F5B07BAA93D1D7
                                                      Malicious:true
                                                      Preview:WANACRY!......Y9..#...X.q..c.?..[..;z&.....{..ya...UPB...ok...%.#<.Bq...n |..M.@)mV...N..1....&..8.B.K.....f..."c...6.B'6+.-a...%..QC..&.:........G.c..xt..|A..N.Z..<.M....F.gj.i..r.....S...2.v.z*.N......{.'.I...^p.-.)1....N......f.G..G!..[......$H..h.......j.......NC5Z...$./r.s.W...xdI^i.....Tq.1.f....Z.k.{...Mg.z..k..Ytz....1..M.W.d..d..v......e.\..a...Y.......>/.'.L..QX.9.cJ.D../M.8d^A.6n@wY.d..C9......o;..2*..v.{....[-n#?7jRMs...<..=[.....$4...>.:.SZ....]..<..>../.:i h.6.-]j...S...p.....J).}j.....k%.z.......[..a%....YQm=s...-..U.......f4..P.^..F.@?P.8.b.JH-...g..h8W..b..M\.A.o...-..c1......Q..5...8.M..{..Q...../D."K.u... ...1...h....sc2...y.......#.]h-..7.n.H..X.n.....U}....v.*r..!I..."..ybw....#.=$..X.....w4s....?e..a.*.y.i...."..L.8.5..EO..!..+.5.}}.1{.a..b..F.....0...u...h(.....\...|.+..5jd...4|..[........']..?.^gX...x.Q.p.cP&..;....Q.re.....#Z_.?_...rG.Xvr......v.Vr....f=.M..D...j.a.Is."1kz_K..6^.]Ab r...@../N..w......s
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):14648
                                                      Entropy (8bit):7.9876876847952625
                                                      Encrypted:false
                                                      SSDEEP:384:iGl0/GP+onaLvXg11ftitZJfO3PC5UpBw:5CGGo0vIYZE/CSpK
                                                      MD5:306ADE82BFA4F59FB494C36CF7FE764A
                                                      SHA1:99F94DEED9037FF74B7FAC02565263AC0021058D
                                                      SHA-256:57EA72F6582127848655C4E5B2C51D59C97E26DC89F2FA2A90F158C6A4A6A984
                                                      SHA-512:33843E3083830EEE2285E62149F5B88A127BB62CE57C1BF21001AAB85F33F9F234F0C9607C03F82D340AD4FEEC82AE7BD55FD5E22845D826D23FC2333BD6B997
                                                      Malicious:false
                                                      Preview:WANACRY!....CA..$.*..........q.?y/9..N0V..N.........0.S...w.....W.iS.T..T.y.5....x7......'.......7..&t!..+...d>bg.Q...>f.O.#.+v..J..C. ..P.....N_<.g. m....&...G..`....X.H....5._..4...E.L.|.&.....y...r......e.^[..... bc.LEB...K/.J...wy...!....Q..09.J.....8......;2]5.4:|.d.Jbu.5.sA....+....j@L.$/...K..l9.)4...M#RR_@..s..qt..1....Ew.....dj..al..n|...JV.f..yF.&Y.i..@<.]2}6NRt.#.B."..d..[.1.....QqqC....op9..Z. .M.E#...=.!..t.x.g......><}#.ApJ..6.t.H:.....n.R..'.F.g.....Iko...@B..k...~S4{.)..J...U.V3..../..&0.Z.U...c....)b$...[T....=K..o.Q..{.^-W.n..y$X..a..............wb^..8....AR.KiK..n=..w..\.L..dy.{.......-k...5......O.......>.h.s...7.]G.@..o.,.z..G...Y7R......y....H....QS..........L#..;......e.N...^p.H..>..lm.Y.WVV.s...u.....&..P...'.2...&e..=.q.[.....7cY.u.f.K.,..o......q6.O......0..^..^-.k.&...../...Qo....o../.Y<...L..#^..I......@....:.m.k.e}Lo.r....LW%9w.Y.K%..!.+%......a...N....l.....v..C...0#...s...........d..R...9..q.>...v.+.`..c~
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1784
                                                      Entropy (8bit):7.908185103758062
                                                      Encrypted:false
                                                      SSDEEP:48:bkJ0lp2hqPMoP+aSmHMp0VDs8ToLOY7c55ZDilZKhYv8a3vPA:oJnCMu+aBDSaYg55ZDMKhB
                                                      MD5:5D460B6765A3897DBA0033AC0029D73C
                                                      SHA1:83750D05484C306B74B0C02D32D1C431AFF28577
                                                      SHA-256:B36E0D566C71CA932C1507FA49526E48D98C91819680FBCF9C94EFD4F084BAB8
                                                      SHA-512:73D35896C9678BCB919A49518C7B936E86FF667424D501BCC38F0604008468AF93A2C59853C4AFF6E97810ACAF8622DDF264C61ACD02AC92ACE25090E2DDDE63
                                                      Malicious:false
                                                      Preview:WANACRY!......u..1,.L.+..o...NW.....^..3.l..,.&...@....zd..a..........r......";C.?.....j`M.f-..nU....'7#...H&.....F$...b...P..ziw.B.P{$.....x...5^....g......pz..K+.C'.2..X...%.l..ovm..0......Z....t...U.z.~)7.......0".;A(n...#..C.C.C....../W@..F.eg..i...C..............YQ..AM.*oM...........,id..U.!...l<IYA:.i.!.[.c..K.X0X...ThP<U..~..v(U.p...w,....o..3...._.{.H!31..u.]..t1...._+.]>.vW.......~H... ..J.....L.Qo..&[d....C.Z.P.kV..*.B.G..Vz!...6u...Xv....S._./.X:.....QU.C..:?..&.=.Ru;...E.[*iy...:(..8...f..6.....l.c2~..3.....8............. ...(m!.h..s.>..=.(C..a.LJp4..0..y...........0..l6..9.1/.-.Hl\...K.Q.~...z....J....B.......n6.R0V<..(d7uNt.9.l$...p.W..@8.....GB!.~es.I.X x..6'..............=.W...J...l....`W..,..}.EtH.O..M...5l<.I..\..,l#/.?^F.cb.Yn..".c.@6_{at.PtL..&..2%.I.&.y..BC.......'.1.....u"... .BH......]=F..kc.-.S.N......c.s..YBI...m........l.'l..0.....@5p#:..e....9It.K..V....O..w.lG.B|...Z.t..`.j.........cB9W..QS......+..0#..V...{....
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):7752
                                                      Entropy (8bit):7.973433368367687
                                                      Encrypted:false
                                                      SSDEEP:192:0FJ1ecy3av0gfiBauRPzdWGZ2taNSFSzx:0L1e1qlq0uRPzdW8/9
                                                      MD5:BCDCD034AB5736BF17AC89C569F952A2
                                                      SHA1:7B05E6A074FD5AE904BA829714546AF2A657852F
                                                      SHA-256:6739DA4DF9A28776491C58DEA6ECF01C762F65E6D4E0E6D3BEB75FFA3C96B84D
                                                      SHA-512:A242F6368CAE14ED8CF2F8772CECF94FE65CF17B58729C02B00D6E332CEA3BD69DEEF9B20B8B083E99FB1FC2612EAC0CCAEDA7DB38C20354AD1C60522FD6DC74
                                                      Malicious:false
                                                      Preview:WANACRY!....[.s.0=>.xC.....>..I.#C..."J...*..K..$E....CZ..]tx%.o...4. ..H6.s>...y.xUn}.+...|.q.v.*...Y.p+.,.|>.....uL.NGbB([.-&b.N..{....o..<X.LZ.H~.@....X.....fp.b&.W.v...R...w...R._~.`4....,.1e.I....w.....l)7....n... ........B..Bd._.d.&k..`^...p...nr........$........g<....Z.......O..<...Vk..ws.:G.(.......Q...&.C.......a..N2...-d..Y....$D&........../....|......y..`...D.J.^.....@......Q.N*X[..:w.MbXi...6._.Mq./I.1F....$gp+...O5.Mf...9....%....M...J.5..'l...=...;..._...<.o...~]..L!.Ywx8S..3.1.nJ#.oW.........d.."...)t..n3....t....A. #.....x&..Y......D.....Q..OOH.......i:.....My.$.)V...A.;...j....r..;m.Q......@..H...w..,...y0y..~..42Z...q....[....C.......S`.b..S.....-.(J?qX.....'O.[sp\...(.<Em.U.9.#.&5.1'..b...1...}.*.."Q...4....|^ih.9.|......6..D....W....).d..>.6.d.&0."C@1...y.R_....Dx......m..G..>Iq.._..?.k...V.^>..nUE:.B...E....!X;..|q.."<...Ea.Ms,*....y.0.p...5(.|.%.@.e..h....U8.....P...h....~L..gE.5{.I[.!.$*p):.....6...W.>./...V.E.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):44632
                                                      Entropy (8bit):7.995406613844166
                                                      Encrypted:true
                                                      SSDEEP:768:J8A4ABKmgkDVsHSLWYbR+X4fjfMtjDmIwhAuKKCyXSax3seXabEYsmw5IqBe:SG1hVfqYt+XMjIjOAuKxyXXxcGYsmeIP
                                                      MD5:77E771DFA924C8B8EC8A7D44C337492E
                                                      SHA1:4B2BC3FB2C0AEC5E2118AFCB14B111B61F10509D
                                                      SHA-256:0F03260048C8065C649FB5337575F9074E64A47D53F0BD77FFA6144BB5035E20
                                                      SHA-512:E3998EF382C747B0A37F6EEE9FCB53E86B6FE5EB77C9B7F1F11FA250FDCB488AB95B383C8B6C19624E10EB55C605FE0AC506A1762AB5B5EE0AE247F412ADD263
                                                      Malicious:true
                                                      Preview:WANACRY!....n..y..E.b1...i..b....<.a...I.B..&)..%$@..R|....4.qx.5.!.\?...m...K..gvl#?8...D.0...c.;..@_.'n......4.l..-.....P.{V\..T.X^.}>.U...{...U|..o3c....'..+..WA.X....L;.....5)8...J.)&..t.$..;]6#.O......"."C)>.<:BU...{.'`2P.Y.s&.)l....{.......r.BK...........:..............1p.........].:.l.h.)..<.......,j..$.#<.X...3..,t.....$+../....3.&.Kn.>4.N.u.0..w.7....}$........,Z..n .P..?..O.2L2ee.....B....*...\o.F..q.h..b.wr.6.U.....Ds.Y.X.+G.l#..*.U.B.d.?`..`...?..h._.qx.E\..A..g&.X.W....*.B../.`..G....X..........MU...c.4....1..}#...kW.....V..d...K'..)l.a.'.U.._...?...(...6.+....H/....~9@..=F.,D..._.R..O.....a.P..ij......I?Sn.....dB...U0..qv.&.8ux.na....v.$.^.....G...:E*"..?.......s......P.._..^.o.<d.&8..0..*rG...X..L....1..p.Y.*v_..s.x.g\.~..,W...A....^....Z.....".i.i]..........E....Hx.(....K.".......B2.x....5.ty.:.....I.I...e.s.E*...o6...KzSF~....^..pF+.s<.g!.d.`.D/..4.L..$......`..Y*..Y...9+.LB...T..Vd.}....X...k .f8...S.,..|.I.(....._...BxEn.`..1...4....
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):40248
                                                      Entropy (8bit):7.995384949311801
                                                      Encrypted:true
                                                      SSDEEP:768:ZqYQhfWpk3NYkW2yZRtjdlgXj2trmUX0lvIUSlZebOsAUhjC+Ryfu+YaqJT8is5:Zq/WWNYX2yZRmXamO6wlUqsAUh4frqJQ
                                                      MD5:0BECF0E2AF222D0BBFBCE79057465FF4
                                                      SHA1:7D7FE950EC7C23B3EAEDC217B2473FE2532A9FBD
                                                      SHA-256:DA4B099F3D53459A6379F50D473BD58064F530BE3BA987666AD39778869C2EC7
                                                      SHA-512:29ACC41E368E2DCFC1315CF3CCC04CA6F4359462B8A2D417500B33F5724B5F8DB743B09E9277386ECCA6F93D61A78B1F9AFAABB8E549D06D5081DAD8398BDDD5
                                                      Malicious:true
                                                      Preview:WANACRY!.....liF?33/f.;0...$ix.."x.0..F. D...!{8l..<..y.....H.!.>.#..!W...........4..h...D....7#.i...D:.'F..*k..t. .{....R'.5./b..@.{..T.......i..x.....>f...?oed.ntm'.ss..d./.'..y.w4.6..E..<4....D....[..EG=.....h<....`...2.1...Nc.:;X...0..P.'...C.o.tk.^...............{*...U.I.j.~..P.....PY.*...0..".......R~........E.P.d..|....L..V.T.....%..."|.N.}1OfD.:./}.ah-.&~..h..........= ..@..$k..K.u...v+...T..f./.l$fQ.......<..........@b...J]..e...0..}.]b.4.'.$..!..<...Wg6..!%...55HE...Q1..G.f._^.-..L.|o..x..j..+e.....q@.*...R..OG.!>;=F.h.....&..$< C8..f-.0f..i].hz=.<).C..v...Ko...0......3JT........gl.R9Q...&.q).M...h.J.........ss8..U=.z*...Y=W....8x.p...-....x......Uc.7.m.Of..U....r...D..y..\..M~.|..(1t....*.?.......r:m%./.X...$...J._.1.....6=j.vJ.......\!..@..E.N_..Z..6..P.G....Z.p.....NcMT.v....{.}*...;.O.qVwY.2.9..l@4M5...;f..{. ..JL.(M.....y..D...v.Js..=b7W.b....[e.!..n...%U.,f..[M.T..r.s.Zwo.^:UiY.......y.KQ.....0,..N.....-....z.*..y.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):2152
                                                      Entropy (8bit):7.9122553315781605
                                                      Encrypted:false
                                                      SSDEEP:48:bkP64UgJqNWQzJhTnjpxF2ynJGTW6NuUcJAEhT+D5CZyJW:oPJFqDXxVUW6NST+WKW
                                                      MD5:BD0EEBC79DD09AAACCA47574E84965EF
                                                      SHA1:0EC362A929B39AEAE936650855B6F9BE7E37C44F
                                                      SHA-256:8137ACC51BF5D6FFCF155BC8218C084033121C58C16CCD3DA756AAB4CB04EAA4
                                                      SHA-512:B24E2F99AD0E7ECCC2646228805F1F3F13477DD8C1062B7148AE22B41ADD03D361D9411D8DF9EEEAB322DF15F8474ED7D7EECD9055FA92E3D32AD1315AF9D7E3
                                                      Malicious:false
                                                      Preview:WANACRY!....?.$....t.>......>.3)..C.i ..E...0.0.U~.*.....z.0?..3.]d......%\."z..@.......E.`.2...n.5....>7"..Ky....<pxd8h5.]0.PhH....%q.2.M.p.dd...#..B....sj!...V.M.Wz.z_?...O!.e.5E2L.|....)=].G@.......MU..+.d.3.q....G._...q......C...-.. !!>.mI.k....}.......C.........#..-.!.B.3`h!<B.....d&.t....0..(.....F.!(..z;e...<.....&tC./ ..W.3.K./'m...H]\.o.B.O\.=.I.K.Y./..Wz.k.a:..W./.....=.Y6.z:.Z@.k.9..oR.....\.Uq...J././g..e.<...^...a.c.1i.....d.h_3..y...(..o..#.,~.......,....8c:2.i...t..5.v\..H.W...D.....E.b...#..,.LX..8.."/w...Q........vl<fQ...UB*.tn.m.sz..y....k...NU.*J...6uR.a...A..A,.8.iV..X..|a1....M...'I7.......[2}[cb.F.R.,$..d.%..7+..B?s2..v.V.O...1.....Lc.Q87............1....Se.jN.$o.|.O[.dO..xwI.s ..C.F..?.....0.....L|.....J........U.>y....O|..s_..@}q...8.bY.6h...G!.......`....m1..y[....u...n..........6....8.4.J.W@.*&..Yi.vvT..{.D'.=F.....V.)..7..>...%M..C...Cf.-.V...CT.V]..[.../B".H.8..I..+t.}B-....z......r`.9......v..Y(......fC ...4
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):126392
                                                      Entropy (8bit):7.998435927486092
                                                      Encrypted:true
                                                      SSDEEP:3072:oX3HP//yUUzdqN3dkNTz/d+G7zrr77Yh6q1XT:8P//yUGwVON/d+G3Lzq1XT
                                                      MD5:095A1D572C461D6CD85FA4852781003A
                                                      SHA1:51663174ABF9104CA9A1EF20829177E4C3EE269E
                                                      SHA-256:0088EF0811E74977B8FC64F2B6297B28435E24A5C8FBB6742EF77DC03A3468DC
                                                      SHA-512:7BB5EAE4A79A641959460F0DB98F4B51C4B61DCB3774298BFD90092FC3DB2DBBA4EACD9929E85A8363E443124D93DA018F69AD0AA0A23742B119BF08B0307E23
                                                      Malicious:true
                                                      Preview:WANACRY!....t........4...-.)2j5..)..u.{.m&...I(!.Z.<.E.."1j.{x...9<.5.a..{*.d...xT.7....$.k.wf".....7=.......{hS...9..c..:.l.i....s.......FV.U.vw%5..#....X."...).%.X[.....(@...*g..N.2..f..-.$K.I..e..8I.e7.t.8..~dD&|........>....,.....`.[bR>.....x.KT>yr...;......................;..QFO_..&U.J.....d...K...n...Q4.(+..../.c.........#...&.0....B=@b2P$.[.w....H..<.........X^-.0.[......%XSS....?.y....>t&Bs._G.....%.2f..Q.4}.{...$5..>.eo.lU.M.jI...?..E.F.JG.....~ ...XMv.......H=...........1.B.............:NYt\... .{...Z$..w.x.,...^....T|..x'.h. ..:..,W.?..K..&,?`]..P.[...._...o...5.h~.......5.M.A...^d.....m......2...n(>.p}.X......b.R.%..I.8.....0...v..7.d}j%.:...M.mBUpZ.3.....Ky<...Qb..N.....r..Y.|.k.K<....8hBX..S|.c.Zl.<#.S7...4xj..7..]=X.z....*.s..m.{...E_....j...%:vyC.. ......A......W...fc..$R...}0..Oj.......1.C...kg....r7I;...8P...mp...t..'.S....<P..!.;._bW....{....Z.Fk..$...q.....'.M9......J...q.l..Hwt@.3Q./.3Y.zCkh.wS..9Fq..:...9RII.X.1...*:
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1896
                                                      Entropy (8bit):7.898328266426091
                                                      Encrypted:false
                                                      SSDEEP:48:bkYWjsUGnVBB7HHJ85D0S9S44j8MlJN/B/CmLpAiiDn6efn9:oYaqVBMS408MbN/BztkDnfn9
                                                      MD5:52786E29EF4678418D3A842E9B8430AD
                                                      SHA1:3E487C6EA09BA3778181BC79888EFEDF53D9F388
                                                      SHA-256:36DA25F04276173B3C39E95C50054BF854C77AE19A4DDE56AA040C5EFA7AC26C
                                                      SHA-512:14A26A7E6108ADD53D78AFB2928D4199FF07981F542B0548C9F17D4302821E588B009DFB80C59520F4057E8C8FB6D9587B10D491787EE6339FDA3A818F05D0CF
                                                      Malicious:false
                                                      Preview:WANACRY!....(<.[hTL...O.k.Rx.H^.y]..-{.#..597....*Y.r-.....?..}..%T.Y.\...-b...*.q.sr.u....\.J.=..?.h.4..o-.fe...ie.~.#dNl....1.p........N.C.t..N..Wa.j5.... .x/p...I.UO.E.v..d....#.Q...2.K..>.0;...?^......24D..D:.g..+..2D....8...c..b....l1..!L........*..........O..........\.\..9... 6.^Wp....0..E'%.vKH...0...fKo...H.&.L..aa... '9.....>|z...O.....W.Bu`..Y..@...z.dp.....6e..$_?..w....z.{.....@.O.../.".bOQ..@..zW...S..........!B..&.h.Z...G..]...D.C8...^n.W.<..Ra5.......N...ZN?.a......lh.8.q5.LD.N.......L.".....:....&.q.I{.&g..I..T..:e....hO.E./ .&z.{,'....{..Fc.,..<f.U~...a.49*D.m..}_...R.....$.V(....\l..r.D.-.?..?..$.}.;M2.....Z5j..}O.$l.N.I....}..{W.Fv.....[..I...8^2...B....t....b...K...j.e.1..n^.R.$z|.1=.K..V.....L1..1'.....A>.]..L.n....t=z..2l. `.gR[.........Gb.....A.(.{T.\tKa.T.C......2.<.Q.....h..._6..]..[i..I.Ad....._....Z.6;.VUz.....V..=.3FC.RK...U.-f.3....A.k....l.0.b.....QFu.l.oxn.'...{..h.a\.%8...%.D^2..D8....p .....b_.w.eV.2V...v.._
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):254712
                                                      Entropy (8bit):7.999332480510708
                                                      Encrypted:true
                                                      SSDEEP:6144:Li/Og3yvS3tRLICJ1g1sRmk/08F5XSXLep8xPMCW0JJ:LCOO53t5g1sj08F5O5Ztj
                                                      MD5:311FF79C1A16F9655A4644F9B19F5C55
                                                      SHA1:E1D888E7D9C655034A89F621FB7117F2DC0754D8
                                                      SHA-256:5D143D38324B0A88866007856E12B3917596B0B814B35A61034360C7118A721E
                                                      SHA-512:5BAB376F8421672DE7B77B4B4A6011F43BB8EC2E3D797943A4A346F11C4DA6D2DD5C67851DF31EAA23939740AD0AF9B9FE6C7044B044EB95DF7161D9AC66740D
                                                      Malicious:true
                                                      Preview:WANACRY!....b....l.nCc.@S...i.....2.DO.G5....pCia....:..9c..v.).....y.6.'.g."....N..]..........V. ......*.........A.....wy.f.......c.T.,.....y.l"l.{..2.".....W....a^..U.u...p.........~..0C.Z...=.C......y.&ss.3...HoY....@.-.B0ff..5.r.uQ...2..c...9S...'..8............u..MfMFG......\.TQ.Qe..86`.M.n.pL.......7[y.^.'X...S....t...E^XI..~..A.b.........y.D.FCQf}.xC...N([d`.V..O8..>..,~..$........)d...N.^P..vs.G.|R.g.^&.......*.qN....1..B..s..^$~...4;@........`6.'..0. 2.n..c.Q..t..o.A.;g.:LW....~O%...V.N.7...31....E\XK6.......HUu.f.e!t.s.A..k.(....RC.q.o0...*W.c$O.zk@H.1.1../.$.g.....AB1...l.-J.....g...74.p.I\..L.n_ .KE...N.5...-.'........g..N...p.`87...@K..nR[d......c{..OaQ...y..J~...{}..U)Wi..(...r..SL......YC .p..Mf.9s.cm...Z..}T..y.m....!#X...$.a..F.._i..{.22.q=...{w....;)p...W....#...t.+].A...h.D?..jE.0..q.....D....FJ.J9oz.....5...LQ...Ne}C...q2....S.D... fQ...`..[}.%a..H..y....G...y.R.. .k.<..........*!...G..N........JX..N.&...u..R...2.^...O...
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):58072
                                                      Entropy (8bit):7.99676836192225
                                                      Encrypted:true
                                                      SSDEEP:768:le30KexeU9BmLL+7w8kvZGDea2Cg1Ft409OYb6eezRY5cie7ZoApm5r3wiMHsLV2:I0KeELiwX8j2Lr209On9Sci7LxzLV2iO
                                                      MD5:BCC49D9B2015445C7ABCD9ECDBB9DD66
                                                      SHA1:EE7B963AEFB5CFB410B540B63BACDDBCBA2143E8
                                                      SHA-256:0A2B77643D9F680A29549E16C9856012295DEF4DB5CF41F0104994B9F58E4004
                                                      SHA-512:DB844924826AAB9B61E5AF4BADC29B45B1E0EAF2E33B9D3F33733B2254754D74B59BC78EE1301AA3D661CFAACE678C5C0CF206DC62E8A115B7D653AD0A12BC13
                                                      Malicious:true
                                                      Preview:WANACRY!....<....2.....S(&@R............<.|.....Gw.........t\`[W..^.._.*|?..i.y.!...]....u.M..X.. ..dO..C..^.N..O...2Y..mW(Db...M.[..*P.....i.9c.J.Z.r.&.8..c.A..1m,.....wU..w.zr?.H.s.........8.'...f.. .'0.O..z.j..I..^.M...J.B..X.h.&>g.n.)...{....Qk.e.y.5,...............E8..C...8.qp..$.......6'.I.!1a.....J.J......J!3...mz\;.......Q.M...."...".l&t.v.'..U...J.A.H......n.~..|0.<2...C.......C+.C.y.>.)....t..4...Q...8.E9.q.t62.g...+...-....E..=w.......t....5..l.D...e..O..U..p...+.X=...J.7......cs<}..U..(.....*...=..8.p].S.X.V....3.X..Rd. &R.g....Y...e.<.Y....-.RU>a..Q..."...c......vO...50....T.;..R.,T{.P..'S..A.......$..j..M.............u.........+?....J.8..8.:s5...Qy...p...u..K.3..).:...q1..._)a.z%o...........@..:B..>.Yl.#.:&...|....[s..*.9..{..}...L.y..P.`3...k ...Cn.F......`....z...E...h.F4r..xX..O.$.2iH.i.1.a..'....8Ho`......\.[mP.......(&~..JE...E.Z>........L......O....F8.o.R.uO..u. ..h..._.vL.[."7..V.+.|'..8...`}h.$.Eo..T0&_.A'.y.%n......
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):95672
                                                      Entropy (8bit):7.99792593801978
                                                      Encrypted:true
                                                      SSDEEP:1536:YNgwzvNd/1AjgtB22avqZZYt+bF60OOYKZspvtmVvyRFmgGjFs9QoIbFfgHI6u:YNgwzn/yNryZZVAKuUySnj2IbFfgHtu
                                                      MD5:C08AEE6458049484A7D3467016A27BC7
                                                      SHA1:FA616C321C7DDACB997EE5D9337377FF717423FB
                                                      SHA-256:A279A9E0872F7A6A71D642C546C5711040BF71EADB0B4EB43D6572A49138182B
                                                      SHA-512:CA2D510FB6A91730D1BB538B7F064BF1E1255AAD20D9E10B16BD022E4D152783FDE81A57DAA25B3C6BECA7FF97A1C31625BA3C453574C16F1C7652C3EB5B05AA
                                                      Malicious:true
                                                      Preview:WANACRY!...........Ox=.50.9.~3..9......7.S......_....&...d..xx.O.Y:.5..I...Ki...|....E..3.....d.....]...M.7..c9.J>c.......F.u.4}....7D.......<..g...o.>o..c..j..m.&h.s.F..,....<{...-GS.n..87.(...2\w.l6...dA..9.U....F.[.3 .Z....@.._x3..![b_6.d..V`2u..r.m.q.....t......8.dh.X.....t.#...a.\..A..u....XS.f....@.....&u..!k=..;.....3.1....-...h.*..y..'.....B..{.\..u.....;/.=,..\.PE..jS$.....?.....n F...Mt.B.VH.6....._3.~.>N.D.VIG>...n...Y.N.7.j....R..g..c.(...e..&..xUx~#..>.I......$..sA._...bh.....w..Q.~z0..}v|..L.W..;.a%7;%..{.TS.b..[......8gT.....MqO>..9BY0....X.>.....^.Y.v.dqq...U....72.2O..........B..\a].gx...Q.....'....[..l...Wi.DQ.2.=..Y...I..:,.b..0.i....Z..5.z...\....o.&......#..yK..m:...Iwh..|.DX....d.".I....Y..U$...].$..r..x.d..hkBF...<..E.Q...:T..,.I...3.....f.y#..O...u.0:.P.N..5....8..'SN...$@k...%..y.#4..|=.Z.q+X...#....9.xe.5.....v.Q.>.~.....v..Ho.k.{.);..;.......C._..U...PC...G2L...P.6. ..v..m..o...2k!..?..h.WOe..B..8.......G.:...&.......
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):70360
                                                      Entropy (8bit):7.997326119029228
                                                      Encrypted:true
                                                      SSDEEP:1536:3TmzRePkZ/PRwwPHvzwFZ/ZC4lYUfzgWfAucjsm:jmzRbd5PbwFZ/86zgWfAuo
                                                      MD5:E142B4E241DDBF31751D7EE922E59FFF
                                                      SHA1:DACA915A074E15571EA720000B90F4E1373023A4
                                                      SHA-256:0C832E89C2574BBB434436C4054F2BD8B83D19C0E13DC102D3521C8B426C4FF0
                                                      SHA-512:0C1AA84A4F30C60F0DF30EFC1E1CD6C3DEBFD347137E6CC146C32CF9089BC8DA7C6A763DA10F15803DCA372FA1DB5C34A10EC4D942535EF1C1882F47F015D1A3
                                                      Malicious:true
                                                      Preview:WANACRY!....1(.;'M......U..*......Ti.6.i..y]s.q.j$#aB.9..2+jv@.p.+...X...U....]A.j....*.v.tk........m2.....,g*.x .L.&....A9....3..S}>x|..h...$...]..Ti&.....Q..G:..PT6..3..T>?\N.Ga......J+?..#L..}.\..h\...Q......%.,...e.....z..} ......#C...B7.Y..Q..a...T.r..T............b-k....[t.x.E.vw....)....yo..l.Z....y...*8....,.At.....|.>.{=....H\R.W..`E...._K...?.RC.7...`.....go.;.......+E....-..a......rv.=4..g..#...~S1x...M,..8..w....,a..K..U1..., .u:...=.2<....h#...c.IK...H...`...@.O.'..L.`p<r.F.OG..f.p.*....a.G=..M.qz...E..&).ZL.%._..v..@....4..>:NXS.8oq..v.k.$...~....D>[.C.z..K....I[....._.*.9.....$./.?64.+..).Q../....A..=.oi:2..G..W... .So..q.)..o.m...'%......IH.W.z.<...m......T........w...H..O....;2....4..bcR7vW.{..9P.w..T.Z)...w..H.yv..j..jD";.L)s <#;.z.]r......m.a......#{.c......z..3!...s.F=A+*.@..y.Hv....s.D.K.y..!...P..lj2.I#.. k..i#)....4.9..9.R...TKe...P..t5.&.$.p.*..D..9.NX..:o.\.m...\...c8.....E...e.I.FV$s.\.j.}]..=..l.0.=CA).......67.8".....
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):18792
                                                      Entropy (8bit):7.988968839289142
                                                      Encrypted:false
                                                      SSDEEP:384:Uxn7hXIdmCHI87CBHcnFTqIETy98sMTEBzT3kNn9Nt+YLLMRYaCFWTXF+oG/H:OnVXmm25WMlAy9CEBf0XLHebCA7g/H
                                                      MD5:CF638C23413F758A04EE290E08CF2417
                                                      SHA1:BCFA7F232A0058C2DED54D7F8CB039147D70AA41
                                                      SHA-256:039AE11263A2437A440AEDA16055A0E0CAB37F0060EA1D74606C5F90D3FCA1AF
                                                      SHA-512:0119E1C381E8423FC3B6747A65A242E5B6B35F652EF1C994BD5E606E88EDCCAC26F21B515EBD2D301FE7CC1676CDE3A86D39C58CA8E6CEB3B745F57F5051CB7D
                                                      Malicious:false
                                                      Preview:WANACRY!.......U.3....K.}....x.jv...'".f#..V...pg......*W.S..t..n.|H?...?...A~........`.-....u...bq...A.#..j..5P|.S.98.aL.?.z..x....{"I1!..Q...w..uz.H..Y..3..6j.=...'m......J..........A...c%.Ma..S..hk..%t.....`Gs...Y{...=.R......6_E.v|A)..|..H...Y..^M)N1eB.....OH......Q.'..]..^.c.]..kP.f.X._.I.=gN..o57...S..E.:].7....F.)..p.0%.....k...k.yOA....... ........i..9.c..'.~...)1lP...z.E...H6gj,u-..G.....u.kg..NDK.Q..j(J...a. .... .?w.}..v.M....<v@.".b....6.q..Wah.2D....y.3....Q.....#.L.^..SU`lYf..<..U...G...=...y.o...L`[.S`.5.'3'-C...*.......t....8.j......%."...."7..@[.*X.[...X...0.4.......%8.!5t1E/..[..*r.!.. .w|.wt.w=.Ep..{hh...-~...L.y..(/......c...XyQ....2..=E......k@.Dx...:..3..l.. .....E^...';.X':.d.....W...Y....cd+.O..(Hk.9.4t..@~x.:..}...|.../.$.d..7....!...t...'.%.3n....d...\8.~..Sz..E.|m>(E.0.......;.&l&..Z..........@q.N....|.......h...P....H...l..R6....!.7...+:.^U1m..1.S..-...m..rC.....}..-.Z...4=.2bdXy...S@...d%.Y...cy.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):28728
                                                      Entropy (8bit):7.993500222404278
                                                      Encrypted:true
                                                      SSDEEP:768:ToxFiSF0AZrjNOpZmJR+E9/8YHcianNiN2hv:ToxFisVWmOEwAG
                                                      MD5:A59EA1DF437315C6B949DFC944F7CD2A
                                                      SHA1:F05E7CE7ABDE3F473B879348E6AC0FD29134CB12
                                                      SHA-256:AD369553A660259D652834AF37E71FFBA77D8D2F1D2FA44B25420BD83803209F
                                                      SHA-512:D4BC64AD535751DFB68AF2775D9E7827626FAD4479916680A0FA37930AABB3A01DA7CA8DBBA857DAD29864BCFC3BE01DD5A72B3D4A17CF0F94E3E1DD02616186
                                                      Malicious:true
                                                      Preview:WANACRY!.......W....5.n\.{...3.v.../..9...D..a._.....O.........F..dYtr..RF..F&...<.B.*.O.s...U..^,1...Jr..9[....2@/..'..a.,.Z.t.....2{..P.I...w'fI..".......@..?..0a.ZV......0+...vcT...:.^.Z=.?T....,9H.Z{........=......|..W.........:1x4.V.s... .a."..(......o......#x...G0.%..@.@..n.Q..?P.<..O..Q.`.Y.._..B.d42^..K.......w=..O..e..k.l..D<.6.....l..2...aS....e..k.f....N.c. y.c,>!!tqU5...G7].~~.B=...D.^....7...p.E....e;y.\.(..-....my......n.b.`.3&.s.w[.:....&,...*.K..o.C../....=].H...D.+.Y6l.).^.. &=f...suQs... ...P$\....[!..k.2 '...o.8b../.f...j........^)..Y.3.eb%j.yO.J..vH.5.S......,...=..._Q..[...#@b\".c...Q...X.,............w.sX.^..O.h....1...,....El.....i.i...b,Hv.7..\3.$....M, i ._=..-Sl.>.`8.r0.....}E.1z......j..t}...|3...._\...Q\._o,<.'.X....Qn{.3..q...qn..3.4......2.....'5...*K1R./j..!'R.iY..g.b.".$....c=.|DkP..zR.3.i...XF.~>q.D...C.z...-.$Uz........j`.j......8.<...@..Kb.aM....x..&7(..........:.x.U.6..@9.%.WL.c.%0.Q....z[.geV..8...!...8..
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):22136
                                                      Entropy (8bit):7.99127442197407
                                                      Encrypted:true
                                                      SSDEEP:384:GKl1Wtad0Zp/6FepcDLhbfSobBmjmpEpHrsXbscWYWXxXeOxxgiuzcPyWbZXKIIo:GWLd60eWDLR1kuEpLsLaNvoiBxZXw2/
                                                      MD5:90FC05E98263520E003A6379AE217C09
                                                      SHA1:3F0581637B7BFFB89E4EFC12BA476017789F1410
                                                      SHA-256:30BD858488AF9802DBCE3E6BE4E0CD17D70F771B74C4C7FC98035A6CB1DFEC6A
                                                      SHA-512:48678EE71A06DE00D1488D62609ABABED216E891742910A47EED44F74E00666170577692AE7AC0FFE246416EA624FD082E90E3AC00E8A6113CF4A3C0345F2041
                                                      Malicious:true
                                                      Preview:WANACRY!......j....[;.<%.......%?....Q.....S..=*S.....:.&.;........sEnN@jh..=5R.97.S....z.~.U...m.n.C..Q....f...Y.-.w..Q.P"....G8.w..TFY%.....]..]i..f..L9F..~.Cr....x.v.zDv0..0}..F.+f....t..].."...(.....ND.B....OoD......T...p.&..^../.}..e...frX..rb...J..Ev..*....YU.........x5.K....%p.Mv.C...l.g...........Hv..leYV..D.....y...7.:....E..^?l.(..2..2.....E]M..O.ja..:`.....?a.q.x...6..a[4...)!...P...f<....tQZx.c.3g......fu....n...\......D..,.][gW.VR.....%.....C.........W.L.....n.R...].z..1..5.l..}....2....../~q..iX)8I.V.Z....Sn[D:%..3.|:.....@..K.Pa.#IL.W~..'.k...&CC7.JQ|.j@.E...W.H..ga.(....c>09...m..".....&..Rb=.*..y..._...|.......n.h.|M....M..n.X............<IT.w....ER.../.`.%.z!oNd..d...-..!.m.Eh.......V.|.u%O25G..do._.!....<F... {T.......CV. +&...l...L...wv.O.L.Nk..... q.|.s.k~w.b.!G.dk...]..419.*5.".....jX..`.]8.P........%..."q. .3f..ZK...x.2X]!...ww.J8..2ia.....w.....d=...|........%.+....,.|G,.......K..:/.pmq..wW.!X...6..?..B6.h....K.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):18792
                                                      Entropy (8bit):7.991176504180272
                                                      Encrypted:true
                                                      SSDEEP:384:9YUxxg/EvifcXfaWESgTqarxxlHxdSgX68iS9:9zxgSifcXfabSYPx3/XBn9
                                                      MD5:A0CAC5AE8CCB561AC95CDE1D3E59509E
                                                      SHA1:E7D468B9C4159C0A9D91DB52096D86EE1E398EF9
                                                      SHA-256:E55A1711D857FDFB3CD1A91CEE71B7EFC2544BB4BCB9129D31795AC045EA5028
                                                      SHA-512:C792FBA1816D0AB1663D5FA38A1B9F8996B137D2DC68F3EA1FD3A4EBFE6546874BD7E5CBB040B41E2975304FD2A2722740C897B6649F7E29F6D24FF9BE26DAC2
                                                      Malicious:true
                                                      Preview:WANACRY!.......OK....h+.$Y....].....g..&....B........)....o.G....AZ....~.F..s8m%....U.F....L"l.w0 7.-.Q......../IE..h..e.s..vY].....Z"!.T.&=c......P.6..}.W\..W.'z.R.=..<$....u......J.&2...3..u...c[02M..(.[x.m..Qy..../.AxF..&.#....CY.+;.......4.ee'.{.'t. ....AH.......F...q..U.3.?..#...z..55..T.N{.w..I.D....r.n.M@.I...iJ..N.nG@3.>.......}.A..fp.....j....@T.},.......n.CK@." p..e..L.W..C._..A..3..#].R.,....W.X..gR)K...1?.}........4V.JSu.l...<....U..c.M_~[..O[.N....j..e...#k...Eig...j.Co.:......tA".-.......d.iN.;p&.....:+..DB8.nA..nq..E....S...A.....^..@..H..x.y.B.j..\..f.....L..C4.*.......>...4.a$......i...G..|...0h.:...k..8._ ..8z\=....T........y..|{.l.S..q!).j.:.|.......p...:.I...P..... d.4.*../.j >x;.r..YMW..@OYk+2Ic...#./Zc7...2`..-..f..p7q...vjp.3V.F.q.-.....C.`.3.qq.a......7...a.f,.H..f...W....r.k.....0g+$...AC................B.3......N./4.J....r...3U$.(}nr`j.<$]b.=&.U....^B.].2.`.....Z$*..l.....Z.. v..<.6......,cC}BL..t.[6g.*...IF.dU
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):20952
                                                      Entropy (8bit):7.990904854592217
                                                      Encrypted:true
                                                      SSDEEP:384:rDVl+eBAq1TjO3ydFDvvCKFvLogmHz8/Ld3UcY5SEpjSI5uww6NQ6EMThDaM:r/jCq1TyifL5ogmHY/LlUchMhC6NThGM
                                                      MD5:EDDEA6A4D523B7E1F3D46A6358B1D22A
                                                      SHA1:B2043D75337F9634FAA9113F97F32C4668B63BDA
                                                      SHA-256:DFA1A64BBAF0FFDE28E120CDA57DD2F546792EABD416A64EEDD049C3057DC21D
                                                      SHA-512:D707CD55888AC14D54892CBEDB78D5A3752ABECDF0F94ACF0D59C338F6A275BA3FAE65575AB64C073D614C955699F7F222EBB4F97FE757D81077E2122139B673
                                                      Malicious:true
                                                      Preview:WANACRY!.....B........9`.%.@....$B..}."K[`....0XHw.7l.9.U...[..*.Z.;..'...(..J.x.-.=.1SE...,..].ANq...@...a.6....4.+>) .iyg&.h..4k@.f............+6.......yd.g.4..Q..I...E...:3...|.... ck.@.L.N.R...1..d..i#..H.H?[>."B...@.j....K.m.-.I.MK.i.....6...IM...x.......P........FVP.f2c}.a...pM.l&q.*.T.....x.|.#c.P?&.........$..2C.U:..y<.....is....U.B\.Z....v.s6.e?...u..#.X...q.}..c;..T.?..=..{..[..m.3.wj.}.....Zxo.=d....TV.$Z:d...I.1.....n*.......vt..T.s../;`....Zo.....]........~`a..d.g',.......ZH..q4...9.W{..}J.E..v.....&/F.p.Q/.......a8.....y.\......`^r.$...... .....[.....L.h7..u.]g.'S......p.....W.E.mJwG.p...1a.s.z.,.7..c....p........W..W......*....."_..I~.X.5....%.....W0.6."..S7..w......c.U1zI..}.K...$./..=.I}...9....E......z.8i =....}...R..d.YD16.+..54O.v.<uh.S>qn.E...<@u..Z[...8..x.......1..E.3.. .x...U.`..../..s.^.C...9...#.....t...9X.i...U.....i..F.'...6.......Y.v.V.+D...D..~....A........g.(.>.@..h0!.oV.(...K..7...@. ../%}.1..g#.G5."UQ..?d.Z.i..
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):58104
                                                      Entropy (8bit):7.996526952000476
                                                      Encrypted:true
                                                      SSDEEP:768:geCayV8V8BmdjCL9pqluLWri4xuqqOhcBH8LETBErYExIdPEWePY50L+R:lCrCVYL/CgZ4sqqF98LEasEmdPE9qr
                                                      MD5:B5C626794A0CE27AC52C0D8496F936B3
                                                      SHA1:4AC98D28E28FB3DE9B9A7B68A05EFF436C429616
                                                      SHA-256:BC31A73922B036A8EADCE2698AC6BF9348E3CE75D2401DF5C01D8B98A13BFFE0
                                                      SHA-512:593486CC5AE91D0B44613B0AFC25535D5F6A929262C8A4ACD6728F06DBC9C5255C88FC0F91EB7F55A57380424095C323647C11E06EBD4557E63D97772D03E7C2
                                                      Malicious:true
                                                      Preview:WANACRY!......S.]!..pl...J..N..E..P.hm...?.....'!....T..q..J.f(.E.I.b|+...K.J{{*.64..J.v..X.r....=6.C...s3q6..[.....t.r.\s....Q.a...T..F..4......h....-tr..aI&.....p....7..l...?.][Vs\T. .)..Hk..|.......2..^R..(.*.Ky.5{..6[.T.f...(.D.\..K9.....bK?Q.."..../.;[>..............P...'.#....;.....%.U{*"..^%T$...F.D=F.a...W4[k..!..4_...1..h.w.....M....r....KR...S....[..D.......=.$.....nE.l&.,G..I4..LF<.D..Y.Y..S....IO..)..)..[O..(.[S.*zm....g...0.[..&...6..T.f;...;.1..........PSs...v..=.ur.m.C.E..?}..{..X..)F.D......)Mlp.LJ..A......a...v.47..$.1.....)B<...2$...rF...W.\.!..78r...ke..1.#*j.......}e&._.Iz.Em9[a.Q.o.n3..N./.)y.............tG..$h.........m.....D.\J...."D...we.[Sg1......W.^Q._.......!OB"h'.......d.h..1.......g'........D.M.H....$mQ.....+.....q`.2.5....Y{&%.....[...%....!F1........7.8.f.y2?.>U..6n..^.S..#....7..R.....vBs}J.0.!8U..^.....)a....k.";M..UH5..G....~..4-.-...<.brqW1C.C....R..#..."J......M3!.e.*'...0>.e.;.=Ah........,..."....k....F..h
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):20728
                                                      Entropy (8bit):7.990990218208001
                                                      Encrypted:true
                                                      SSDEEP:384:E/2q+ZqTelvXObUeW85jHPEtkH9xCM7WtwVBN9bNknIdc:EuAkReBNDXX7WcBN9by1
                                                      MD5:E20C63490BAC09AFC3E727857458A7C2
                                                      SHA1:358B43C07C71487487A5F6FB6D4A20B75C2D2344
                                                      SHA-256:C1D0CD4A959F59FE0A8782B67C81780737A4AE9F4B3D8A3E6898F3E42D7409A6
                                                      SHA-512:0A4EF21CFCCC5AFEAC7E94BCA48D5FE5666E3EDD6680D4B98BF827B16D19EA4426E96DF9516A89525FD9D1423DA80DFE2D48D3D313EA0081BFEC69FC71F18C11
                                                      Malicious:true
                                                      Preview:WANACRY!.......U.o.....Z..<i;|h.....{$..s..P....B...uG.....B...K.............a.U7.t....D.F.+..r..Akr.-:...R..A....F..7..e..6.<...n.;r:>?....H.._?...A. j.g.=`Z~A...I..k..D.v....V>..<:....../.....q.:s.f..{..._.../u{..}.p_....B.m."....#.5....\.7..y&..*......O........m|W..U..WU%.@..DK...F.c..x..in.X...B....a...C[.;x.7+.+...E.K.H........-^.s..C..U.._k.7......F{0.+N.r......tm.Y..y"E.td.|5.s....C...\O.|..<N.^.<..^w...N.';.._..a...T9..J.Z....B8..%R...S.E c...z.)<P..%...3...W./..:).1....$;...v...ei...d..z..`.?P...N.`2TU.$.L.wd ..reB.0.V)W....oW.8.D..s0....4O.j%..tU......k...2q0..P..}.\n9......~.Fw..}g.s...E,hu...m.........Q*mRj..i..XA.......)+.^~.(`..ZU..r.'.k......V.?.....O..&||.P..z...;{..|tl........U{..3@....|.....T...U.=?-.K...)....~{(cm.:7ZZ.. H.H..6...k,...%..N.j.F.5....;d.o..#.P.R'.p.........._..E..~*.."....^....'>."X.U.R.......V.^5....o..-I"=...E.T.}...W...".=...VZ.x%6K.L...J...1..0Y/.@..r.%S..Q..<1.6!TG...%.(y2PI+.....X.m.17.y.....[..
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1944
                                                      Entropy (8bit):7.891681674174759
                                                      Encrypted:false
                                                      SSDEEP:48:bk5wDDVCICv+/Y6szCI4a3q9N4bthVXemy1MHjwrsyrpk:oCDUv+/YQmb3VNDwHpk
                                                      MD5:CA52609247C19553EC4E63EE95B8AB4B
                                                      SHA1:9104641142C8ECBAB5260B09F46F74CB91705029
                                                      SHA-256:E2598A624605E26945A74D83AA018B09EDAE9BFBD501BBD1175C6D9D639A05F8
                                                      SHA-512:E2D2D8E5E9CB21F83D4511CCBF019630FBAF74E958B2EBFC635DB2246F9282B90B5F9E458751799A4F4F4ED05E43329B329AC8D67AC8AF8F14B459D7D2B0F388
                                                      Malicious:false
                                                      Preview:WANACRY!......B..._$......rt.Y.t.T..1}..........6'.5...sU(^._.2^.~.....g.........lA....ibCr}..;.......KI-..j.?D. .._.?.!..U.q.f..W..jb5...w0;.1..v.3.....t....Hm..".h...M`..b.....`..-..1...J.HR`....#.....-.r.,^.@.a.?..K.g.t.K.@..N....r.b.k@.E.h...0`.............v........Y.i._y.T.'..4.....%.;..9.......N9].S...Q....1....E....wW.gU...e.e../?...:k..S..n&os.E.F.H.y.Tr_..9.C.D]...|....Z.....A...`R....Cu).r,7....{?.x.>..T;8.mQ!.y4j]i.g+t-.l.o.... I1.{..yx. ..,.....#)...y.....U...''.Mg..@.".A..-<}V..`.......$.x.7G..+a......,.....t.cY..vVQh....w<....da3..._...X.(R.....zoM...Yee.....N.7...q..:0b...p...85..V. ....<...Z.RPL...\....1^...*......~U.G...)].....K"N........Icm...8]p..Q?.Q;,....)W...2.D;X...L..`.[. e ..B...FfEo..V...&l..-.3..<.3...mm.p....n...C........i.......B......T.*.\.....0J..1+}._b.Tl.t.o...}).....P..W.w.z.$S.'...n...X....."t...q o....v...W.)..bIQ.`.a.....g...,...v..P.W....EX.M.}..&.....xy6...9...`.A........+...h.uA....(...QOm.w
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):14776
                                                      Entropy (8bit):7.985563740112417
                                                      Encrypted:false
                                                      SSDEEP:384:tgzXldxV+DptaPBGUdSA0prQGVLyAWvZFCVthqX:t4V9+tIlSA0pLKFC7hk
                                                      MD5:C501AC2C67AC219D00ECE309D3031235
                                                      SHA1:DF0D3227238F707B810D0258BDF0DD59BC1699F6
                                                      SHA-256:223FC91C29EDC828321A1AEA9E44E8CA3ED3C5E397A19A3392D8A20C9C7AE531
                                                      SHA-512:359ED192290C0C3C09202000BE262524A9CF371D0E78582A6195134FAD07165F5D30F3CB37C18510C7E69128CEA7CE8D9DE0CFBA6E09B178ADB53752DB2BD56A
                                                      Malicious:false
                                                      Preview:WANACRY!....{.H@z..|A>.I.....0."z&.Ur....f.9..\.A....._S..Ar..M.7....9H.M0`.F....S...*X...TtV.Z..W..IU\...K..\p'.::.y.g.tj..<r....a.V._k#......V...T....'.u....3 <i9...zuI...f..1z:Z......!|}-Rh.JkTL....C..{..$.v...^...S*.p..x...5..k...- ...T.NO.l.&../........8........6[1....UuI....[c...... ...c*...a..6.c`...'..f.0I...>W.k........z0.."ap.......p.E.R.!...C&......qSD#.o.j.......;#....9...c..+Q.s%.rD...r..f....yt.....YF."`A.3..._..8....{).5)i..........1u......J..f*.#:..%9ZJ...<.C}/.!y'..s.....n.lO.....,.....8.x.._!K.SO.....3= .A.....^..iN.nb#..n......W.v...).sT.O...^&....9.8....%.(j.8"}./?.u.n.!j.6..'zn.s}.....dO...N...q>.S..&.......TP..#..Q.....7..T5.....$DO+;T.FF..PrN*R.....a.B.A.C..8../..,..X....C{a.t%j6p..R.W.T..yAqYi..=.........1F.r....B.....w.<.k.js..&.K.7..F.e...=bM=..y|....{.S.3......9.....j|.(W......,...C...6...gQ%.w......*..]...ki{.......Y.......i.T_....Y.yU.6:..l.A...].;aB..o. .4.B..{...>. p>.ct..;.M...j....=.rH....#..X...i....>
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):15896
                                                      Entropy (8bit):7.988606423783264
                                                      Encrypted:false
                                                      SSDEEP:384:0v9laS7jOlvL0HAR7BwCFvsfG4JfpF51ndS0dby:0vUv1BXcG+hFTh2
                                                      MD5:77F507334971460A142BE8A59D2FD6E6
                                                      SHA1:7B549D30922F212392D3217C9DFB575BCB15E431
                                                      SHA-256:FA795349769E2A90A9E636AA6992BD0C858933739ADB92B06A5FA3AB8DDF7392
                                                      SHA-512:B64713C86B5F15F867C921090BF3E2F5E5E6DEBB5145B15F53CA63CE0E7BD510DE45D7CF2BDC24A52DDA203F3253202CA9E84A8CCBDCA1CF80F3C49286BEB15F
                                                      Malicious:false
                                                      Preview:WANACRY!.........?...SR_w.....A.H%...Y&..d4..V...p.k.j..=.....\Sj...G.`fD.-b.=1%i........UcS.3oAh.V.;el.C.'j.0..iL.......<.m..}...&..+'..m.7.*y...^...w`\.....L&...Zo{@..k..P.)........uq.....5e.];^T..R.....J.%.e.5.=.q..K.>*.3...l.......}.Gm...[....AtZ...4.H........<.......t.H...[.Xzb..|q...s...TC.@p<.S.u.....RQ.sM.$!O............n.,.u...^;.a.L....'I.....<......@F.@......k.g..H..g.....7[...mc.Q.&w{Dz..I5r...ge...<..2.fa{..#..'.].....:.@j....9:.6.*u....c.vY|..."2!1%..(.<.&...."I.b&=O.q...<K.m.;u.x.....W...h..&Ma7'o...a^X.!$p..<.......+O\.=....E..&..@.X...d..e... .j..c...;...:<v... .....M........M[...K?./GPR....9...J....i.Q...."%....q......~_:.9s.{..,..._..<?.w...?..k..4...n..1.e1=>..*.....'.m.e..J.....b=..;R.2.7..A....|\..@G~>.P.dT...,?...]V.......q.......C...\.[?&54..H..I.../.Q.O.>....e.2..{.G.X.#...S.$.O...*....Z....B..n.a......`!!`...#..6y.t.iC-O..J..`.....)..2.....W..K.C.#.".|..YJP.|7)|..n.S'.m.......O6..b.I`K..Zp...Tx....|.v.d.h.j
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):20552
                                                      Entropy (8bit):7.991399068793826
                                                      Encrypted:true
                                                      SSDEEP:384:YCbaYHn5A5AFYAuNUEK5CGldFP4D1+YVRiEBtZMX:YCDA5AFYAuNUEMCGlfPY+4RiE3Zi
                                                      MD5:90712AA44C5A56B01C2141371BAEBBC2
                                                      SHA1:5D50D72C5BEE48A55D3B6ED722E2A33BE0A82CF4
                                                      SHA-256:A7957D5F4665D4E1F6E80D05934759F2C13C832E4F889DC78B31583FCB604B2B
                                                      SHA-512:0E5F964EE1A176D880C1C3F93583A5F336A0F1E31BD8E0E2217A8B7EB0CFEFF1CDAA335ABA7B525E66B920F910D08AF8250445C991887193F5C5A75F604D4C1D
                                                      Malicious:true
                                                      Preview:WANACRY!.....*,.k:..;T>..KL..Np.eg......b.Sd...h.g......N|V=....~Ad..?..k...\.p......4.?....rV.....D..`q#$o..mK..S]Cz....N...!.L]{.jE?(......c......U.|...K.z...%..s..S...#..p.....oz......_+.5.\2.......s.F.t.i-.&..`...@i.._vq*..]......Z.}....L.1..5.....$O......%../6J..TOm....@.K.*~. .rboD..M....<..L...H{.B..z.N..3..H...s..3.l.k./...1.....m7.m....(.j..X.tf..*..q.Hz.v.J+...&R=R.......k....._..^.VH..Z ..".....=F.G......-....F..r.../Z~...t..>....T.5MR.}...T.x..{.'R.....)>.Sl..b.?.O..R.!d..-`...5.C...{D.......n......> /a.,g.!.,y.........\g;..P.5Z...~:@.N..-+.4..,.$.{..Dm...>o..t.....6r..,{0G..UM..E.4.-0..-T.tR....1.....>.6[.`U(C..W..e.....<....\wQ.......Sa........p..L....6...6...)..{.`~.p....A.x2..i.v#O......E....m.Bw....aCkhm.S.&......|!.q0....E1.e....3U.x!?..u...<...^8..2....y.Q5..B~....R.>.9.e.....=.H..K$|c.?U.. y|......E...4:.zk|.....:t.......-{....[...wB.. ....s......JQhV.-.W&......0q..c..%.%...`... .....h.../..d..=.q..bH.i..
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):22456
                                                      Entropy (8bit):7.99245768797441
                                                      Encrypted:true
                                                      SSDEEP:384:Wx6ghooqWETS1uutEP6yuA42C43+fdSuBpcvQBvaQcIJkNguJTxzvw6wTCzQ:c6gho7k1uB1uUO1B+Qp1cguFx7w6K
                                                      MD5:3F74FA9088942EB142CEE924FA496486
                                                      SHA1:3A6FA96CC64B7A7C6CD31AB4AE49EBED9076716F
                                                      SHA-256:CE27EE0B4F28AF0AD585B9FE6A30D491795DE06111570EE8FF5F83576CA86A24
                                                      SHA-512:BBD3A2FC730B7FD5D6951DF2532BFAA37687CD3122E1A924AFB9C0E1FFE4795A3EB5BA12C1D24CD3F1749A10C4FF7721F6052275E68A96D86EA6F6EF557D8988
                                                      Malicious:true
                                                      Preview:WANACRY!.....<d.h.......S..q..9@D...VyT..z.H..."....y.b#.pG.R.t#.....:..iff+....u. ..y.$.O.. Q...N.g#..o:l..D....n...>{JVj.G..%.[..>^..i..5...<..E.B5..;.A..[.$H......:hn..4.tL...a.E...I........Q{{.@.`r@.....W.....f......u....xe;..P..~...mZE...`.|..U.`..?=.....V.......a..Q....$.C......F.....'C.....2.9..^..b<#...Q4..CP(.(.'..)...aZ.........c).......Z...0...V......R.`....KB.....G}..i./......E8.....P...U....J..~.-...q}s.CMS.vA.*..5....[..S....Z.~..).WO.......ci...Dw.@.rI."..7..E...........<.....;..V(..1l..>..o.c. .`....#t$.......&0..W.....9........t..;}...\.c.P ....2.N....!.\..:WK.S..:.G......s.$}/...T.H..s.0...b.d.y......gJ...%xP.I<........>77...]...j.>,r,.4[.N...K.HE...@*...8U........A....U....!.....?....2...rDL......Z.|.'.5..}=....x.........v....P...wl.GS.........lNd.M.F..z.....{f.K;Ta.[..........|Z&).@q...x.......*.Ct.5.H...}.,......L}.y.Y.C..../r.esJ.X...a.o3f.e.....7.{..r.(...hT.Z,.*.ufL.w..0....o)....vp.n...X.j.....C...
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):28760
                                                      Entropy (8bit):7.994155685273132
                                                      Encrypted:true
                                                      SSDEEP:384:rIWlBWbkyj6R9DYfTtMJTfFYpKw/Vvep75/RluwtBJPH1X9EIWWjZEhT8CzfZJTc:kOUwRmfSJTmoZAwtBZVX9PWZRJTaF
                                                      MD5:F4465CBBA8DD2C7B67949EE1CD90AD55
                                                      SHA1:3BDAF593C8235199254FBE013F026BD9AB0C903A
                                                      SHA-256:C2A10402495E74C07DA80853ECAC638A370033F34C5CDD8CEE3F3126B99104A8
                                                      SHA-512:D46C79D84D73548FE60A49DBAFEC8F6F2DC66A485578AC5528162F354A521B2D49881972B0C915FD8FE89021B6AF0EC9EEAD3C00E0DF66385377C30AF879E66D
                                                      Malicious:true
                                                      Preview:WANACRY!....t|u...,...!......^..I...g$M%.P.:+..a.'...XhC...L1....$..J.9.o .Ya..#.c.qL<tR..KjdW.......n.....'........!v.O.e.~ '.X.....zz..Q..... .u. ...0..S.@....+.=.fwXA..c~ $...8.9..-~G/.j.Y.`.H....9..p..F..yi.....f.4v.-.r....O.1........]..cgAg.K3......?o........./<0N..)%Wd.a.S.N...X..._@.. .=..Nbw.).6.Fh..$.....~.\.4...!zq9qG......T..'.......3o.^~F^5J.....ZZ?.=.....=m..b.cG..T......."...N>.%.........4'{.uk........]i]....~8.u.....s..<...#.w.'.*T.6.uo...=...v..f.r.#......>.O.....V2.#$2.l..<.4......&.......[..8.S..F&.Y[.pvz )/o?..P..}.....GU...$2D.J.X..E,.r9....`........cR..t.,Z.{0..`{f.7#......x.Gu.a[......p:[.+....e.~..O.6W...."(.7m.<.....XE...N..wq.MnX.f.i..m.-./....t../...t7=....U..}9.`i.n.q.#...z.. .E.N.o...T.k.c...W..EX...?.4...^....a.#.A..cL..h.(..x.{..b}.Hz.a.....?....@Gg.0.....K$1...@r..M[ol.k...1:..2t.e!..8.{............k...."..0O.]..Z(.Z72.."t.l^...w...Ni.g!...y.S.+..^..#.....Zd....^.......D.qE.yh..k]..:.;.7.S.....$...l.q
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):21816
                                                      Entropy (8bit):7.992173472715018
                                                      Encrypted:true
                                                      SSDEEP:384:PTjOvZrotjcu9fZjLjkznyFGt6LbR3UEZiJKOaI9O3tpjpt0PeKj21LndJtiwX0V:PeBlu9xjLjKWrRgaZaeKj21LnMBKSUvQ
                                                      MD5:8CEDB6B0E92D8EA68C35315FBFCBA44D
                                                      SHA1:38A4BF2405E9B7A99CD30DCB555FE9C42A38E4F5
                                                      SHA-256:412C5F901AB5FEC6B40891ECDE2003A62716A32E64B7AC04E0D7A0D78124459E
                                                      SHA-512:48EE03DF3CE405A6B043A51C175E504CECEF6312729C9A4B8AEFD36B1C868396C8FEEF79AE5FB5F69DDF9A4C89FEFD29FD9B075DB315133D030BA79BA32B5ACC
                                                      Malicious:true
                                                      Preview:WANACRY!.......i..V.o....:FG...=..wj."..a.2s..7.*#.5..}....!(.A^...n..M...>..\t?RQ..... .lJ.G..muO.E)w..\m4.Fb..<..@ +j$.]n.....}.j..'q|CQ)......<..x...x...)|YO./h|.......} .)&!.c.._[.j..m\.K.F.2..%y...U...^i\..,...........n..........i.C..#.S+O.....=..r..... T........_m/.+..Q...U..U..N....{..[W...C/._.. ..|...S..+(..^..6..r0.......z,Q.}.0._>.~..J~.i....}..x{........8....o..r.=....r...S.....6....R..=b..M/..<.2.$x X%..A.v1..a.]a._..@...._.J./.....A.......rtb.6..T&..D..,..:.U0......\.+.....J../...(...1.....K.EQ...."...d.h|.t..L.B...Uc...2..Ik":6V.#M2...d..av}..|.&.[`:.t......(`~s W...N%.e(.&!..W...en.'.P.s.7.!..A/...T......3O.5ZJ...;.H...cQ.o._W...].'..$W....6.p.....W..J..H..Z/.j....(.Xx.#m..IO..=.e...y.io.P..=..FC.b]..q5..:..iY.".>S......vQ.38..V3,4T.T....`.U.X..<0[.....\R.V..y..9r4-.......>.g!."T...u%.......[............D~/|...A.....:A5......W..ln....i...X1$N......3q.ii..].Z*FHY.......O.}#...c..X.k..>..@..D...P.r...Y.o6.X..*.B..C.)z..UDm..js<.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1573144
                                                      Entropy (8bit):7.999879616953345
                                                      Encrypted:true
                                                      SSDEEP:49152:WybRHvnR/IFFKnFWPfzTw7hLEdW5v7eP5N4g:WyxvF4FKnYX4Ld7erb
                                                      MD5:00DE312CE93E9B3AAF7ED26C3C14B585
                                                      SHA1:3BE67DA5BD2CEA58A5CA7C421F47ACAB45A86636
                                                      SHA-256:10B4AAB53823209DFCE6CE6F81E706F2063E365AB73265900906575E76BF6110
                                                      SHA-512:7C725B46D739BD682A745710EE608568BCB4D545E8B231363BDBA696D960AA27F1E910115804A9A4E025F02078E24CE584588DF15B1565D70782518DBA9F961B
                                                      Malicious:true
                                                      Preview:WANACRY!......X.\.Z...U.X..*..*...a.........W:.+.>....8.-...m.n*.hYcY..N ..}....g.......W.(...1._.....7h2.0ION.`...g....b..f..../I....)x.C...@G...f}#.Q..\o.O v.7.n.}.>..f].#R.ZRr8...iJ.mA".U8./^.W..../..h.\1........4..6*..F.....nU..............}............2.$.>I.qB.P......`p\1...h.(#..5;.3.SJ..k...T...Q.D.5..[....U..~..{...e.o~)...s...u...u.AY</..-..#.|kO.%s.B....9S{D...\....*...f..s..OAky).8.n.Z.h..f;.V6i8[.q..[.....;.^..(/.;.....@ 9...><[.;.a....B].)J&.m.e.6Ia..t1.....e.5=j.Z..c>....l,{[},......u....Nk..K........4.Y.q..u_..._1.9.0..OC..\6d..:...z.$.].*......1.+'.?.....9\.... e$.S.s......IP.s.W..Q......f...'B.80n..7.[B4.<.Di..I%.Z;n.z...."R..]K..1.vP.`.f..k9o....$..P"rY....U4.?...5. .].n+.[..c.......n.>.E....r..3.E.+....t.............W..6..D.`g,e...P..iA...E.H..?....9.....:.EC.../.]._Kv..C%.@)..A...J.|O...L<57...7jL:..L.Q7..}.4..........%.b.1^.M.Oe.......,V<.....2. ..~3..>l.e.*..S..Pc....*g.O..T..5...)....T...
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):2097432
                                                      Entropy (8bit):7.999917814944676
                                                      Encrypted:true
                                                      SSDEEP:49152:OqHJ5rfKFFvPsGUGQELE6Vf0wEK5NVzuysLuIIPEPb2L:DIFhPHUvEYsrAywVIYq
                                                      MD5:6CB1C4B014A793BFD0E6CD2651DD3194
                                                      SHA1:91EA64A8928CA132F6582362072729ED8EC516A0
                                                      SHA-256:43699A823F6D3B17E28365AE8699A0DF08B6CAE32D1D0FE66D47FA2266F699E2
                                                      SHA-512:8CE08CFECEC5CC84B2E508812B7D9CDAC4B12F39055D9E93920191EB28199AC4AB112BA65685988DB48461B8BAE4CCC2A61AF27D8226478A8E29E6BA9B3D8863
                                                      Malicious:true
                                                      Preview:WANACRY!.......#4=.B.^.b...x:......f...j."...u..'..DG>x!.f.+..L.3..\q....9.O;..m.8~C...A...;..._..q(.qb... h5.V...0r..>..A.=.........'}u...........n.Q..uIH..I.>Q;i..c..Yw5w..."..I..:..Q..K....1P.2jc.{..z#l...6]..).4,.a]....m.l.......E...WY....~.).^o...v.0......... ......t(..{.}...D...5x6e..$..j...0j<>.T7...VH..g....XQ....x...Vr.9X......_...P...9....7OLV0.4t.J#,=S...-;..g.E...N./........G..]0..@......=.E..va...=fP+...c.<...U^R.....Fq}.x6......3.{.I.a..>ez$/{..`...rv.J.y.........[..[.....o...o.[O....Iq.B...lA[?;.z.H{..,....;.h}d.....#...n3$#...m.....*..M.,...3JO.U..T.#..[i.H.a_.-.k.R...z.C..}..Bp..fU...1}..\.3^. 4...7.nD..t.`$.W..d..K.*w.FU.a...;M.sk.@....1..U.A.s$$.........&..F.E*..A.a..gy..z]...f.7.!..?2... ....K..l<y..<.a.....X.Y.lyE.7...0...)..y..7.....G)"....y$<.=+....h...,g.......r1Zi.r[.....c..LI...D..yYpx./..i..#I.O.r6..db...>..I.....~!8 ...........$T^-.r..{......l.4.W.w.=A..l.8...Z?M....a..@(.i?g...F....../..T...@B3..}o2...]....Yc\.A......W.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):37464
                                                      Entropy (8bit):7.994961345605732
                                                      Encrypted:true
                                                      SSDEEP:768:3PFt8kFEMng9qsEVDLbvRzGOaCUIRdyiolh2aKRFgdV+BIQi8XYx:39CMxVDsLISiolh2DFgdcIOg
                                                      MD5:06BC0C381BB5ADDB90C94698705DD177
                                                      SHA1:BF1BEC13BCAC46BB5E863F71F6DA5736E6F55F25
                                                      SHA-256:EBE2935B9827E80407888AA99C156B1731316F366EF3F9A734E158591FE47E8F
                                                      SHA-512:15E665599A27D614223AA0F2DA983F294E0BE4BC418E27865C753112C3AD16D255442B696DE3AE1019F3957AFF97052167821DEB33174DF6909C7D9438B7CF7B
                                                      Malicious:true
                                                      Preview:WANACRY!....E....../L..lE.-;wL..t Q....z...0h.........m.....I...F ...`.*r........G..qa.....j...f[i....4,B...tM......D+;..K^..4[.x....`N.O9.2B...z...}RPLp..N......y./[............0<?.../@..}>...9z.z......B.}.U..oV.......Q.#.n4.]?.......+L. .x.34[-..6C..n.AR........4........5...~..V9....|rD.H....Q..z..S.....I/.;.......zF'x....R.q`.>.MS%.&.QN........Z..c...........i..^RX.......h4@..a<..9v......#....g...e..G..'....?.pK.+..LB.G...L.1)X..0+..N.z.+{....o.v....1F.....Q!c...&.....h.Y!.m.../..dM..$.)!|N..z.1.7....t)..)._Db..9.cd........O|r....q.5nR....".5......s.5$9.THP..U,.3....`....@.6..#.../R.f.....T.fJ|Fh.............>..r.T....J.r...h%....UU\.......K.!@.=....n.8.FU.9.^8.R.(m....U.l+.!k....=...+.....-.P*.n#5..@....O...+E..Vm.m...J..W..9..rb|.z.B..."Dz..1w...Z...k.'...bV.?rq..=...K~.[Q.Ph\....4'.#..UE..b..g..R..'?[.WR).f....[........>$.......=.M..*C;...1.....G.O8O.M..&.....j.7...,..C.O....c8.e..sk..r..v..+......d.A...v..........,.Q.".X..O.P0.......
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):37464
                                                      Entropy (8bit):7.994488160774127
                                                      Encrypted:true
                                                      SSDEEP:768:S49MNUV95/fKw5Tw6pEII36WegCgjfg7zt:S4RV95/fguErnegCgcp
                                                      MD5:DEAB669EB6E634F5BED6A508477872F5
                                                      SHA1:941B371F9C5B4D9D0759DFBF65C3466627562A34
                                                      SHA-256:7792B02070FB475CE81656A0F7C724289664CCCC84D3118902132D2483FADD2A
                                                      SHA-512:D1531D43AFDAB895B04E1429BA5DF99BA4B89895873547EC1102A19C4B13BDFB28D78199E2A60FB4BA3D8F29F555A1F1AD7B6566EB3C525CB4AE845F708F1527
                                                      Malicious:true
                                                      Preview:WANACRY!.....|...&.E."..,..A.|.K-.#X.....Rf....$......^.h..!.....(qf...J.x..... |..P ..._.....E....iR}......L.VL..q?*+h....5.....&..J.......gB.......`.L..p.sqA..=.xN. *?.2$.<.A...O..<e6]...`.C.}.G$c..];.#g...c.|RY........]..z=.hvI...[U$q..2]..ux....h.$....4.......o........LL..7.@?gA8U..?5..*6.k..-.-(..o2.W..a.6........Q.K.z.N5.<....X.1H.....-jhZ.).b..Cl7b..W%......j..2fk.M.h3..`......Q....5... ..k.;...........S.2...tY.......6X.N...K.(b.....\. .....v.........x....L.^.g....9....7.....b /.Z'.UU........z\...E..G...D...D<.Z.,..|...lG....L....U.....m....c..1...:.L.D.H.j:)..i."e...@+..*M.....U..w....~...s..X93.Zf...#.....D......)....M..^.Z...."6o..n.-...b.........&y...+...`.. w.....;.....(.4qp)(f.f3'..[...cM.0...ID6....a.8$I...v.]...".p!^U.v...9..60f._+......=..6.1}......CC.1A...!....@V...a..(.M....Q.J=.......J...di.w...Tr...i-.De&..:..j.z(.Ll+..\.U...-.{/..47.|.....u.G.....xwC.....Z...H.E....7.....M6...\&..%.Ji....~{.S1+._.k......u.C
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):37464
                                                      Entropy (8bit):7.994830554682372
                                                      Encrypted:true
                                                      SSDEEP:768:8CieLA3vdFc29w4b5tUJ0vvwo4FSgcwBQX5zoGz7Cmqzalb2kwFcXBhx/PmbHuo:8CBLA3k29tb5WJRo4QgPMxw9oWh
                                                      MD5:39AC5890FD8CFE8E128A16FEEE9C7627
                                                      SHA1:E0B16E8A0ABAA83FA1E8FDA040E80DAF78159FBF
                                                      SHA-256:00AF58767AAF1F51CC71533882CC203EAADD2AE2751BAC7329DE9ADC8AAB6B53
                                                      SHA-512:B73D062C83089C191B94D16B85F683EFDD88CDD8F16D15FA745363496F9CB2A603E1077BE902A86DC449992C70B75E45206CCE2810A94D6689FA581D7A32E6ED
                                                      Malicious:true
                                                      Preview:WANACRY!....uQ...y.c4.F._:o.7G.R.~`..GtYo.k.\..m...U.......1..}..+{/ZsY..`S,..|M...S.^.u.Q.qn&p..7?Q.....~..b6.[kw#.....l.o7P.W.z.).....C.[.9.f~2@......}.$.....w..4...mx..E..=..i....... SBI.R._...?+....b...^~$L.r...."p_I.5;H.GFQg.A./.h..G..tg..;@......6..z........4.......y..X.l.K.->.....R..ZSF...A.qr.....k.G.j.H....<8...~3...+...,.P..'.m-.,..).J.$,....@.L...W.U.b?.....yA......9./.........H,.L..p...1(..~i...p..@.E....[.....D.r.[R.....R......N...|.'2.G...@..-.s.bc]e..,....L..jU;..m...`.~...fx......[.4F^.H.@.h...YG9.U....q..n:..D.4..k1p..\.^E.\0.N...@r?.6...cA......P......#.I..... ...iCo:.@.\4.&q.N_.z..>.n..<qF....._....2.g"F......i ^0.......0s]..@.'.8.....V.....6...j.fy+.'...%...M%.... c.I...c.e...C...(......`J")..|....?.."'4.M....}..*..........u..ES.|.x:.......X..%8.EP.....!..5.:.Z..!.{O?1...@....N...+_..+y..3.1$.#?..P.....=S......a,.pn.......K....o......l".3....N.@..$.,n[.l...@..t.....B....vI....._@k..Z.<}....6.1_...........Y....o0u?.h.X.....2g..r,
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):37464
                                                      Entropy (8bit):7.994920339931241
                                                      Encrypted:true
                                                      SSDEEP:768:Tb/djdVupqkUe0Ge4u8Bw1WE7g3JHBUVwbp/kuTVWTyBeGQL5P:TRfuwk1enBIB5SVkHw+BeGQL9
                                                      MD5:28F66AB691977E5E6B75BE028FB0E9FC
                                                      SHA1:4430CDEA8E4F39B69ACA7038E0538C9E2142ECCB
                                                      SHA-256:6C58E93405A42B916F6CFD3714768F2E6C98C5D58CC16CFE1795CD933B15CF4D
                                                      SHA-512:3CFFEDE390611068F8D8A8FCC5264B29043700B1D3F494D62ED1C71DBEA63EB7CD9CA7389E3839AED4815E24D5C87A36A118CF81FA47E2FE26D5BDDD0E441988
                                                      Malicious:true
                                                      Preview:WANACRY!........ .6.g=....H.[.........aC.......P....,7[-UH..=s.....W..s....~w{....'.=....z.K..~.xH.Wx..~...AM...S..!l...y.4.g..8.....@...>:.g.0....#e...A.'Y....jK..=.S$"..D..2r...,...K:..V."..oCW:^.Q.s-Y.P&Z...uiH....5FY..]...C.[a...g...<W..`A..9.....O0....4.......l.....X....J...{...........Y...........yP..p.v.2.. a....5..B..V;GU./.....J..rM.U..&..vZ...._r}..m. $.5....{....l.S..bl.....d.>.X5.....j.Q`....h..Z`.2$\2,.-.....i...K....G.......Kf..d.=F.8..y....Y.......E. 5.,......(....L...R}3I..$~*.4..hY].......h.<Q.,._m...0..l.1>.\.)._..S.r!..%>.....%5....b.8...K@!Bw.=..Wq0....o./X.....pgh?.,=u/.....:..k..N..4..-... u.Q.. ....YlJ]Y.Ac.A5.........@.3...\.`S....P[(.n....j.r.MQ&..pF....n..-...F~...SI....|..q.#vS.{.Etbc........ " .~>..;....r.d..$.r.d8].U}. ..p...m.WT..Da..l..........CTi...\Qkb\...[l...,P%...&w.0...iim..L. H1[KF..3 .kKm.X#..i....H.....)....j0..r:....uW...G...C..U.>.....K....n..jU.."..h5...C.:.GW.Ax.ayU!....+2.pQ......4...
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1426184
                                                      Entropy (8bit):7.999892376402034
                                                      Encrypted:true
                                                      SSDEEP:24576:o+vjBud5jTdP2zgjj40PDFiLyaWz2d3NcEsA7Xf03sJJhZ4RVOve+jqb8CoiU432:oyBuvjl2Ujj16Azs2R4Xf9JruSveV8Cm
                                                      MD5:E743F74965040346F5B556D6D227C5E8
                                                      SHA1:FBBB264E06074434308CFE7B8A91E3E027FE94E2
                                                      SHA-256:5309EA465CBD7216D00FBA8F237536A4317DD24CC2CE913D17C8357662D516B7
                                                      SHA-512:1B26548210172672281D395AA34BEEAEEE18BE839EF7D5402860EBE9F5412E02085CE6E0D16B63F9E8C778E6AF9498DD4E4A4C1B4EBC01ECEF3FC39519EA60E3
                                                      Malicious:true
                                                      Preview:WANACRY!.....:...s.[E....I.. Ei.r......N.Qx...X.D..2.....Y.r.._.q....>}.Q...tl.*..K.J........y..U..%..)....V..}...[......'.........*............q.. .A.'..U..$.....o.[.Q..DfQ.O...y.....J..3..`.N.C&.../....l.....n8."....T<.W.....lZ...Jd..k2..!.w...;.x+..Y.h{................Q4.O.cx.I'u74AH>.'.....Gd.. .bm..P..!x.I.?....y.I2P.<...tO....df?z.6h2... s..Tv.....b... ...;.6K.9.t.V...<..<../.w../...b...|.......+..Vp..W..)......3..v..........fl._..........g...>...6y.;.Hl!...q.~.o]z?..:p 4.*...q.n.....YT..H....h=v.l-.$o...M....}..!".E.j.f..R?..=16%..].5..T...........~{c~....X.....ft...........QD../D..Y.\.."....0...m.~...wf:.J.O... o&?...)...XU(.......U..{.O1.h.[..].>.O.f...+).@E.....z..f.z.......aU$@w"...A......2.n..=.1<...P.=.M.r3b.......`......IE..q@.<.,1.....~.....V.Y..wx.h...H....Z....f.Wv...g...0..q.....*....) ....f..[{. i...hQ.XX{....N.>.VY.*<mC.SG..&GX.f..w!.[.sa..Y...'.6..d8..B.ad.u..f.&^.....c. ....2..z..1.D.c.......B.9. X9o.Q..V...H..w..(}vr..lV\...H...
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):352008
                                                      Entropy (8bit):7.999419498427925
                                                      Encrypted:true
                                                      SSDEEP:6144:CrLfdKCkoKrbkDjdvvXXp3whUI/ZUzZUZNMgLXE/wgx3zXf6hiMm:IgClmbFUIxUzm7Mh/wgxDIo
                                                      MD5:4A1E4C0231A6830D2F10257739EACFD4
                                                      SHA1:B28FB3834AEE732B6DF06D9C3D84B959E6B683F5
                                                      SHA-256:3E40A764FDC2BAC82FE5181A29D5808D7335660A2E59FF99029C5C37CA3B5D41
                                                      SHA-512:F15F4AA12B6EB5C24CD3F810F68FB27F8A42EAEFFDD70A94C96D95C26E628CCD34447D6E3B5EF2FC5FF9EFD962D38BF4B5BFEF6E8FCE72E29D895B4C0A91877E
                                                      Malicious:true
                                                      Preview:WANACRY!....3.G.T..aI....o.]'.D.h+...M/.$..7.......2.jD.K..X..uuJ.`\/f..h..9.NC..I..E4.'H..!^....0f.H..OQ.N.6...Y.e..ptJ....D.F.....f<W..Y.7-..........L..v..|..RJ+.`.........M...m..........F..e3.D.}..F.&.v.x.W.......\.X.n..YZ{M....!24N.j..s.:..8!2.............]....... .h.......;.S...X.....Q...0...E..rW.}.......}8.....X~(..z.P..!C^..mu.NP=.Q.h.~.aZ.A.(...U.z.QSs.....jM8..gp).D.f.{.?..M"e>#....$8...c.P../2.x..r1'.........Rx..l.*...Fu..3....N..}F.C .h.T.X?..j.?f?..,.0S.{.N...A...a......!......&@.7p..~d.8.u.q8..}.&..1..-..z...&Y.H.w8.>:$...|.o.MH.4Y...................)....g..v.....A..-..45j.....3...........>.?....m..9..S....j..sDG....]..VOZ.6......86R.I..r.;.a.L....}..8L././d...^.Z.X...].V..p..Ff.;%....N.}.?..$.;!8O.ML}z.*.S$..........D3.......TD.Gt.za......ob..2.9H(...../..>.AMW.v.Y..w..#......-..ey.l+.O.6.ss.&Nj....1.e.7.."...c.:%P;..x.oP9.*.8.}......s@g.O...d..<.".oA.....9..fE.y........$...\...g.4..... s'.?..Y.....,,..j.&.yR.<.....qr.}.O..D...
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):243784
                                                      Entropy (8bit):7.99929259073878
                                                      Encrypted:true
                                                      SSDEEP:6144:oDlyZiGgIX7UEOf7EaFA1V9ggQcafQYrTVr+:YlyZiQUEpaFMbggQbZS
                                                      MD5:4504AFDEF179971D3ED631A019B84E4B
                                                      SHA1:C32D55756F77EE9352ECA4DC77DE436F34DF1F1D
                                                      SHA-256:ABA72E4CE71E0E48B54AF066F1254EC4AAF00E213B2B3ACDED932779788AD430
                                                      SHA-512:3DB1525EAF5F9CB1BD4C823FDACB1C54BDD852B95C3D91858FF458B33DFE876A29121A05B72F1F7E50DA6ED1BFBCD54961C2A9689DE853849B6B120796FE299C
                                                      Malicious:true
                                                      Preview:WANACRY!....|^.....g..0t..Y.Z.......k.-...;...<...N....2>.......a..Q..)_.2..|TdX..3^...E..^.2.2...-..<m/.A....!.q^.mA..!.X....x.{SR;.9...O"A.l.....C.8.s7P$.0.D..l.>.;....\d.5.=.q...3.!..S)..J.-V...b(.....!.W.9...]?2l.c.b.'.p.....E }9.:?.:b....|.`v.........&.......0E..R........cE.{..N.........+U..t..o....".....3Om.p...X...3R~..../.Yp...>r..........yl9V....3.....v.w.p...h.....N....U......9.k..p./o.E......o.\.@A.n.m3.3.O.........TMO...R.L;=)..3....MT.......y.Y..9|.uC.....w."9\!..Q....E..z;.V:...:(.g..a.`..nn{..v..^..Q.M..<.j.......<%tE.h......!p.NH.u.rh....&H.z.%v...`(...)/...........7..b./+......L.f}k.......V5)./..<..}.7.v.....a.R..Wg)t.5... .^.[~zJ.<..&..Hn..X.n.JC"...E.oY'......2K.3...s.l.d8"qN]..jp.y..1.- 0..8y..X...4...H.P{..ansnd...../0.+.@....V(.eLU..U..kj..D;._.n...<....Igt.*...o,...F.T............v.....[.m...(LE[.O..p.......^..........l.kD.u'...x......+.....R..8.....}.4..=<.......xo...(..XIX.+}o!..NSp_.r..J)..(E.P\.}....{.|Y.i...
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):533032
                                                      Entropy (8bit):7.999628872311894
                                                      Encrypted:true
                                                      SSDEEP:12288:2i3/urWQO8LIgQIrWU5ZURyQ0iMTyAElEAr0TcIal:L/AJO8ERSWU43MRArOal
                                                      MD5:55C3869E0D112976E9DA96AA7A3BC16C
                                                      SHA1:8AEA2F40F62098A91E2B2426C5CBD91438569481
                                                      SHA-256:2C82A9B34972120D539ADD84F4E27AACB28DDC1BC91B2CFB802DF7EA3DCC1EE7
                                                      SHA-512:23B5FFBD04EB9ED67F80D14A2BD9854E4DC6BBF7DDDA2482B968C169F8C9DEF45207C5E37264C40992CC111EA296D0856D963675E997BEE7ACDED40FFB27658D
                                                      Malicious:true
                                                      Preview:WANACRY!....~?G....0..4.....@j]/...S.....j...]6`........]35/?.C..s.8.0..u...%.U& ..>.N.r..J."F.E..R.Km....h....%,..|.w..q.!.J..%.n.K.(.f{{..Ry..;....o9..Q^l..fB..V.'....h..j..4P..$.g`.....V...a...1u.V.kM..e...-..~u.Q....b.B.p.=.H|..."..(.....,.'8.H....y........!.......j.`......."...|.K~.Y.9......-y...PR..e..F.r-...K.g.V.@.k..8l&.Q.Q..^....T...1..3.{.......@..x...@.g'..~L_.....8........2.-...[4..B..+...5....Y.,.*..V'b..W..m.....:../ M.FVn*...};kB..k.L..K......s...*.1k..@.&....Z.........|.w\.G#...y3......ZxO...D...Ic.t.._....TvT..}..........v?H[&soE...k.;..J(..o.m6._.I..b)vn.Q4.5.}..A..2..2N.B......../{..Fq.qZs..bh...k..Yw$q.A.K...=j..*;J..u....m.........-].V..9.gy..B...&...6...'D}...i.<.Z....(.. .WA.F|.w..cx\...h...w..3X".*....=A..1.H......=. z/Fp;A....!...t.q?r5..Iw9..K.<..U..Bf.=8...8.AP8....N.e....T.$.5....4..=..t..:...n_I...N...P.(..^dx+.,.l....O...&.e..<.....s...t.\z...C......@.:..Y.y....U....&.l .",...Y.) ...p.*X[F.,?.].4..wupwX.x$.r;
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):44792
                                                      Entropy (8bit):7.996180382502978
                                                      Encrypted:true
                                                      SSDEEP:768:GqEIdyw5pG1XUXMgZplopuakr2lz/g1RsFTNXbRehFyOlQNb6hKz22/HBtb3FlXZ:GJIdLGqXM0rc/aiFTNrRJNUhZmhtnQu
                                                      MD5:6B960B3F4F6DD7EF11F23D15178083E9
                                                      SHA1:5FA0E3703CDCE48CABC4CCF3AE513EA531877F4F
                                                      SHA-256:8CB0213F8078902EBB5557F9AEFB9E55E8EEC6DCD99F3E1C62327E7F66A44AA3
                                                      SHA-512:FAB1914D90B646CC947C161729F970018561E98B76926F0504FC8BCC11E1FD9E7A08EFFE5A931DE25B3C8752CED479A3EBF4D9A8A9BD7371B21DB63DE03845CD
                                                      Malicious:true
                                                      Preview:WANACRY!....!J.~..1.eli.X.... ..!.}...0.g.Shw...F..;h]x\......./+.$m.H........x./-s%!...}ua)R.oZ.tW..........-....1.:.....S.\<.#.?V<...Y+..$..O "..F.^).G:.t..;..U.Xe.k.....).4.k.8I px.....s.Z4.G|..S..~.z5u...\..SHQI..Q...V..R..x5.T.3#....}I..W........h............}.^T./.ia=l...:....W.FNO............4.z.kT9.%.b.cQc..{..w5.g,..a..j=v.. ....QC..G....I..J.q.N.E.<9.}J..u........0R.#=..KC.........K.A..fZ;ggA....J..........W....e..B.e.kBy..5.....:.P.s..[.._f|..F..H.v4...P.A.r..^.i._.=.....aR0..<.^.H^.lOY..q.4W.#...qO0.......I....V..F...U..=..Wl......9.o.t...#.C<V..8.)..R:\.U..ii,.hVA.D..!....m.lxS.B........p..N...$.K3.+.f.{..C.U-.....Z...AKbt..@..M2..y...;....I.@.$..t..-..C....,.iR.......n..T..u.d...u{HUn...<o..Y..].........r..3...f.O.E-.g...#T9Y-.)d.......)..=P{..........&q.HC'M.....b9...+.%p...@Z..1]Y...L..,...S...:......|..~...5.e......}[Q7.L`.B...3.......i&..N...(NN..k....a.4b1.*....c["s.Cn.nA^...Z.*O.v.uc..........U.R..i\.W.`,pF.p+:...
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):104008
                                                      Entropy (8bit):7.9984656977130175
                                                      Encrypted:true
                                                      SSDEEP:3072:P2fCSHpgPixiGjauzcAyLIE9eauOOGdWQUcwoGYNxaWLXZ+7:dSHm9cyUEETiWQ1ay07
                                                      MD5:09A01C55609135A3FBC291600E242630
                                                      SHA1:3E48B43C8B7A3363C44D09611A4CA4B2ED51A851
                                                      SHA-256:B9D5DDF0C7B4749E37EB4F6E0DB164B32FEA0F3FCE6051F6D1771793943FEF68
                                                      SHA-512:4718040FA5AF1606928AC6E58D85DF9BCFC8A17ACE0D4ADB66C96B400DED8E03310F91FA4449C766239B57E58945A8980DC13E96A1974A6E649AB28203107BBD
                                                      Malicious:true
                                                      Preview:WANACRY!.....Y3...%..k..X...4G..0k..0j2..@.V.e3.Z......c.. 7TKv....*e.X[..`.5.l.. t...r.....-..)JsR&..u..Le2..*.:.5.jC=...L..7#B.0,.5e....Z.....s........i....xx?_QuG.tf...u.yu.jl.....c..l. .....Q.&...&..M.K.J.y.L.......~.e..R.mm}.D..p..Et.r.f{R..ex.R,......%........1.z..6...P1...%T....a....g..i.\..0.9..v[8...O0K!...|.U.T..>.o........t...$..\0...SD.K^/Sk.n......o........(*2'.K....C.V........~..1K"...$..e.&.....f&K.?..&,...e..h....*iIh{........*4.....L...7R^...d.'r\},..C.x....Z{.s.:.P!'.=..W@h...l.89R..K....M!..*.C....5IN ...[.....b.....F+.8#.[.u.C..Z.t.m......*.U.~.-..).p.1..T.R...}(.D^.k.......{..H.W>DL]+-D...w.;p....Y....j..sw....~9...To........n....0[._..9;....j......UY..P-L"...{...J...O..].....f)........~.. T....&m.<.......{...V.t>........l.hI]..r.Y...j2w/M.....d.\>Gt...7.&y.p.....B....S.....l.....v..m`n5...Z..&..?\.T`G.D.D...!.I:j.C.4.^8..p.Z.....3.!.4g......W..T..\..).K..mb.@..k... .[..NB.U.I@.v...w......Y....%E..C\.f.y.Q`*.b{
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):217800
                                                      Entropy (8bit):7.99920940340715
                                                      Encrypted:true
                                                      SSDEEP:3072:6fyZKS4NARtOB2n4iuHH2RqgFuYE0ksK54DkOozCSjCBsY/CeYXaR3bjWumiHI4t:BZKJySB+9FlKYVSeBJ7YXaRLaumuXYw
                                                      MD5:33AB886284402A87048C2305571202D0
                                                      SHA1:937655FBB585388E4E9E64E822C00991AB4DD54D
                                                      SHA-256:36E38FEDEEDF786CC93E9222306D0121F73E856B728652E91A9572C6671479F9
                                                      SHA-512:F121035B14876BFAB109FFF4A61A887EAB8C2F095E10B956CFC6EDE9AD6CF79DFC9F9D6B33237B34EA7B76313A1BEB4D6A8F5B8719D36622C9DDA56528F7BF4D
                                                      Malicious:true
                                                      Preview:WANACRY!......]..|x....)&.. .u.....?..+...C;.,..../.,.$....V...E.?.$......3~.}..%..q..=e.r...|..`yI...j.n..G.....{.......Y.@.. ..x..G..1.6.....H(.{...zx#m.+.....^..7.KH@`.h.L#.~.e.....<....!p..`.....I....}..2.....w.'.*q.a..........m#..|...../.T...amO...Fp........Q......yj..c.W.2s..L.....,...t.K.-...P...p....W....E.Y.V:).@..3........mx~B.m.......z...Z..<.-..A..K`.D.Sk...$..g...HFWEl..(..v.7w..m..#....T./..rP..X"......:.U..U^..:'..`..m.\../N.l.....c.GNm.`.b.A...k{.t.V.`u...TX..ac(.FIL(..9....v.....A.kw..p4.5=I.w.......9N.q..`\....C...+.s...JE.U.....(.z.j...; .Y....O.M.E.P...........|=..O.H.`t#..b.[me..v.ie...h).:..6..Z.. ......B....Gj...........X.n.w.h.... .>........}R..ng...x..e...)!...E:0.....:...6..Jb.4ZO..T,....!E.0.p..C.2F..Ot\ ...2#..}6${..Q.8Y.I.{UD;....<^..n..ZU.sQ.......)N.p'.lc.dHM......*..p...&.8S.D1!.9.].e..Xm*.....)j....-.Z...q.*..J..v.5X....@.$..Q;9Yz. ..e..W..3..=.f.@....'..[.w.^..Oj.m#c.kD.8.........A..P..."I.............u
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):217800
                                                      Entropy (8bit):7.999161755535768
                                                      Encrypted:true
                                                      SSDEEP:6144:Ywb0qJxHrjZGp6UbJ2LefW6posOygAthXRheVGbyiqpH:ZRLji6AolaggWVMeh
                                                      MD5:4DF90683B08E76156D6C612B0E510311
                                                      SHA1:5B6D7E34A93CF846576ACE20D3DA9898C0D13402
                                                      SHA-256:E51BF35A800D1FE2B5C9F12C5CADB8BA4B5269490615FA3021E498D70F407CAA
                                                      SHA-512:3967603499927A64E3706C2A7AC3DCBE7B956078939A12A78F4165AF19719D097540850EEAB4A9512E46CAC50523C54539A474F094BA67F44C62A150B2B51856
                                                      Malicious:true
                                                      Preview:WANACRY!......b....S#..k.(h....N..Xh.?F..5....._.T...1.9..........A.....@].]......J.Y_./.XF..!."..7$.W1`..G.;,.\..4.F_....SZ.......G..}..~h+{.n?"..p.......S$.J.,..|..U...]4..(B.....T..y.qu....(1....?.,..xw.Q L.j,.Q..4.z...G.l...m.>q...>.....z.mTN........Q.........7s$....<e....D|.&.;.P..6..,....|.....7...!T.c.....9....f|..S\E$.w...j[.$...J.K.K.y......$...o.Z.O.[M.s...(f>.X.`l..w..Q.X*......v...~..L0ZL.5T....I`..|...(.........QV..94:%~2.e.,.j...A....(.J24"...V.G..6.4.I.E.f...A.In.. .x.%/T......m....0...1....n....R.y....X.,@.gC..........b.\..A%.r,...y.1.3.8.@.A.X6T..x....."...P@..1.y...c.8..T.Dq.w.f.......Ns...g.......WP.V;..h.....8..(=...* /F0.(h.o.?x...M..^:..">d.........m.yX.B....P...|....!3r.. m~..6.Rp.n...&....k.a..@......T...\6V..?s)8.......W.j;..L.&.../....'<..g=.=.Tqvv1..K...=.BH....a.Q.g...4....~.p<.:......c..&..5.............W....|k.|.Q.....G.e5.2.d......e.X.]0......'.."h0v..u*<=.W..>..z...u.kCE....h.|.....\z.}..H.d.........K.~l
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):101816
                                                      Entropy (8bit):7.998324523345451
                                                      Encrypted:true
                                                      SSDEEP:1536:RKllHmGwS0QN5QJzgPhCziDn6wyQHMluhVIrYrBaom5GD0V7XMd58AQhEqz0eAYB:elGsnsyyQ+yVIrYlaau8n8A8EPkj
                                                      MD5:FE197EE45E1FA24716B5126CE181F058
                                                      SHA1:AC1FB8E2BF8EBF5012D9E86B1BCA2A3D1BDCFB35
                                                      SHA-256:FCC8CD04AA585F32763B2BFE071D37583A7B61A92EA6DE209F6F252227CFE5BB
                                                      SHA-512:06310CBE5170D2DD23CC8C2F3BC42369879E7FE790F4CA6D559E3C79EB901DA61503E3B0FDD60D8508CD127AD94188065771A9762ADD7CB2E0271023262B82E0
                                                      Malicious:true
                                                      Preview:WANACRY!.....g..u...W....2..........P.>x..B#...n...P..Z 0.Z...%xU.kr ....*..^..Da.s...G%.`.llq.B^...<u.6.9....6!...0F]..Z..Q...w.|..'":...?%.Ug....&.D....I&..v.|<.<.w....F.4^.d.+5F*...E81.}?3.^....?k.B^N....-..Ap.L..c..B....@...p..H.>&......kAr=.M.o.A.7.Wu.q................!W...[_..W.R./..G......6....*.^...Z.9|............n...r....M.y......Z.I...O.6]..zF.x.'..f......... .....n........A.....\.}..F.H.........x.u@......L.m.qW.0.....4..>T]|.<7......h...WD........YxV.....a.7+....".I.mT.v..LD..)?.Dp..b.'].^.Z.G..F..n?..:.hY.+..`.'t.I.TL.......*1.......:.c..-0b.._.<...Z.....&.k.......%#+...f.'.E0.ch...p.....ij.)c.@...J ..C.XM...A.R....Q....?.}..tGJ..9KPe..m.A..%...\..w.\wm.TK..u.U.....|.U..6.....c.2.g...y.`s.a..|..........4...#H....q....Uk7.....1....G...7........k3APO{..K..[.|...1.Xk..1.f{v..\,(..Vv....?..?P.C..]..t NU.2&...v..._=N...S....6...h@U...........*Td.e~..Y.\|.#P...G{O...z.H..-...a?.V.H.E.....+.a.e....#K...aM...K ..8ef.C..*.d.n94..g..AV.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):102760
                                                      Entropy (8bit):7.998142093755336
                                                      Encrypted:true
                                                      SSDEEP:1536:7RBWO7DcLme2/3lO6uINZ5djnE2u7TWTiLJbBuq6evFTcDnDcqJwcHNdjb53tGgI:7eoDzMmZ5FE2OTWib0ST0wUNdZoglTy
                                                      MD5:0C361A9F6A432923D2006D270C0EC1CB
                                                      SHA1:16D1BDC3777C7E7AA1A0F40B4BA2536BC2C40AEA
                                                      SHA-256:3EA38FF2DCF1E622EA7666BB944E0EFD7AE04B538EEE942F762C24F98ACCE092
                                                      SHA-512:B1A439E35BD0AF460112BEEE73CA822E9A0E6A1AEE8DE519ACB5DA27A946DB48E1AA77737358A32949BCE4EFB638197F4C413AC47646EEA7C4090CE3132C54F5
                                                      Malicious:true
                                                      Preview:WANACRY!.....4.p.}.=O....W .....v.S.......na.w....,}.=T..q.,V.Z..3Un.....&.M#'..r.....LzK@...T..B|...G.....Rh`..8..C...e..6J,..../..R.r.&..:.J.....P.<&9OD.w..t#<..U..5...t...F}.B..q.Y..f.\U.......$...'$v...i .....y.1..lG.r.n..4...r../X...._0.'....C>..H]6.7x....P............F...\..+:....~p..Ow.....n.4..<x.......P.E.@.Fi......@.719Z.j.u..g..O..f\O\.A....... J..6..t......r............z{T.5j.yL:g.+..'A9#...g".Ay..M....|Q&.... ..rV.K.._....kv1.z..m.h.....S.[...1.....W.<.........]".VY_.:sk..".0.:..}....>}...A.j......2.mU9......]2vz<.C5N....8.YG.l2TvA.~....^.6.X..8,.}-..)G.AW.=$...5?M..O.l..XT....c8..y.[..6|. ..s.....A.D..M.B..Q...'x<.^8........vJ9G.xC...ty.+.t..$.....Xj.@O..7.|Z.8...k.L.q{IrU...l.:..m.-..WX...v)...RH.pa.s..J.p.I..}..d.y!...C..`.N;....5..ar0.....n\...-s..v.......Bd..c.c._..........A0.9..(....G...v.as.D......f.cB^...f..P(5..7..2_...)....s...K..-....<..#ZG....Rc.#K.._/....>].0.m....c...W.T...M=`...SD....{.57.1.!.dO.a.g....[.J....!..}.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):104072
                                                      Entropy (8bit):7.998377447581812
                                                      Encrypted:true
                                                      SSDEEP:3072:VxA8+mZsWD5EeLHuouynolFXdgpJqnjsVm0i8Yljo5QtGc:V02ssLHuouynox64YnBqjYeGc
                                                      MD5:16413ABB58E9C9119FF1B0CB17C1DD77
                                                      SHA1:53B5314C2830D9702575FF79C31FFA2C85FA0F04
                                                      SHA-256:23050F1B567D85DC317CD55D49AC762FDABCFA7106E5BAD485BC597E9877E480
                                                      SHA-512:7FA71BF1D7E7B2CC12E55F8A67609323128B23EC606819AB473FEEB324E957724E7C5211C937B980458658BE0544E3F8F04D8151C201797885B673E8825A852B
                                                      Malicious:true
                                                      Preview:WANACRY!....w......:.... ...m..wM..H.=.............c..q#l.....V.!G..f..d...lr@..g..M.q.].....*H_O.R..Z.(PV....a..Z...v.a.>A)G...#D...q.D..eK.....+..-G.>.H.D.P.j.....;>.3.d.}.....s.H.LwSD.Kw..'.0..TX..@Z.$.....P......MhM.w.....h bS.y.......(...X...%...#.I5....@<....h.......1n..H1.:..j...8.Aw................H..SG.......w&`,.x...[@.Sy...<....7.q....d..".5..n..Q...su7d.....(....=......i.,.)s.....]s.k.....u.\q%.......&k.H..5.E.~..@.r.48B..4Z......4.Eu.....B.n..b.0.l;...](..9....DZ.#.n...>[iJ.R4......71..#....I......cY....@aQ...dW............*L5.QQ....G..g...9j........h..NWAK.g..^.S...UG..^.n..kx*.....M...w..h...._Q.E..3.r.[`hK.......m..}l.T).c..`vK.J..T.j..Z...i.b..D.;kx./."q..Gi./..q....G%(9.0.....=.......Y.*...5n5/w1?...\..x....'&.0Kn..R.j.y.D......QR.tS..2....L......WL...p......6...9.U..]c....h.B.....$....z.;..i..G{,..^.G.ik..!R......\Y..s7H........%..r.u.%(|.%.....k.....-....G}5%.O..r/..*....2Ks$my...InwuTH .)..g......Yx.Ya!...!.Gw;...
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):104072
                                                      Entropy (8bit):7.9980732706473185
                                                      Encrypted:true
                                                      SSDEEP:3072:i024qaX+qf9tLZCogOKuzhPpRejXmEYZNlgIUI7073PRs:iv4jXdtLZCJIhPp4jXmEgNlgIb07G
                                                      MD5:457CA2E7E931BD97389E3EFE30A592F7
                                                      SHA1:BF25FBDF354A4795295617207966B7B0703E0F77
                                                      SHA-256:830E8E800B6745BB7D5186890342DEDA6B9F6321520B8B1F79213C07660A07D0
                                                      SHA-512:03C7493853AAB6A45ECBAE3EDDE8E299810D6F6A557DDC07B8B7CC6DFE59DC45D87FD79138AED0351531A3174E767C32A2821DB5524C0044DD17B45200011D71
                                                      Malicious:true
                                                      Preview:WANACRY!.......C.}x ./$.V(,.......J....F.HI.XK...8.`.}._...R.8....m.CaN....6M@...N\.,+V......z....T.H.....(.mZM..6..0........#$.u4.8........>........Sb#>tT i..t.....w....$...Qq'..+.t..bb.W"...KX....%...cJb.tKf..c._3.....+.=B...7<s9tR....t.._6.,e.c..F....&.........h........:d.;..g.Mga@....K......%...3+..>.6....}..A^...v;....6..h.........;.c..g.....5...(w.S...b...b.Q....u..l!.`"F*.S]...[=w..{.]/.0...)..G..R.6.2J-.!..a;...."KJ..tv.....q.....>>...6.!..=Z....iF..8.Ez.......J.B.hK.J...xq,..W.&@..[w>..E..O."[..#}Wd....H......,..+..s.=..u.x..F......m...OGo....t`A....9,+s...o.......-7.zk...4.l`h....s...../.?..+78.".t..H.......E...,2 .......x.<..._O.P*...l....Y......t{w...c..\....T.~&..O...nTj...=.......W@.YEt..>.F&.^.e..O(.XM.x}..eR5.P.g..667;@G..:..az...x..^...Srj.X.R..:.".c'..U.....4....X.!..[.p..3'9O.=.5...w..Y.#Ox[IN>.H.z/&q..x.[..u..p.P.~A4.3.J...X.....l4.........|..{m..?.|.:.x....Ff.>..So....z...[...cg.7.2....TF.s.V.!.....*:..i.....X...d..I...u(x....
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):104072
                                                      Entropy (8bit):7.99817706523581
                                                      Encrypted:true
                                                      SSDEEP:3072:ikPKObX4kPK0HC+fjjplOT35d83seefBA1HgQgEJ:ikPMmC6q5dNeefBA1R
                                                      MD5:9D2D0F8C2E38C387D3BF451BD8EBFAAA
                                                      SHA1:A3290AA91B74A06FEEF8A6C17EAAACB910DB382C
                                                      SHA-256:933D2A74389B1732F2619FE7AC921AB4307280ECC702C4B86412C1A386B75300
                                                      SHA-512:4F71F95F25FF7B4BC77C96880C498062C1A3474E82FF4C230404EBAEE10E935352D16206EA120CCCD8C341E3EB6A80289D96209EB3B96106BEDE2AD8C96AD252
                                                      Malicious:true
                                                      Preview:WANACRY!....m..d.....;..z.Y.5.....4ty.....k..kW..@H.{/.T..PeX.....j/..S'.j.0".c...@.W..y..e.q.....";..-......2.R..,..?~....B..y.I......z]...{.{...5X..y....?V...b(|..W...1.3....f..Mi...d..7...C.......r...h0G.Q.@.....?OdY..5......-.u.....~.~..~.S.8.\.~...@.."....h........c.3=........8....Cp.~.<T......`.T.4n... ..62.J.|.`y.J...8[(..]..j...v.J...b`}.~>.=Vz@....k..#q.a.;..`ND.....G..P.tVT..6...#.....b.. nz?.9...S....Ud.LP9vE..a.3Ji.. `2u.........p+..C5.>..`..[.....=%.Npy....mU.VI.#.IH.uDb...*..{X....8..q.....+..Q.|......m.+.RC}..w@$..R.;\...X9...@...1..fDZ.V.F..~.._..[X].aM.}#.:.+L@..!.;.DY`..ofe.\..._....O.2C.\......+~O.lXB...Q.,.!./jC..@......1.......Hm. .{5.r....Al.k}...._.)x.W..Z.,.1ei.[....c....)?.......,H.s......).D....wA.....i...s.O...."o..l...5.$.0C.h.A...k.r.EV....B.....'.r{.ile.K..=u.f..3.2..Q.#...u...F.c....&.........G.4&?5u....YpwF.s8}..... W.N....s....;#P.Ya.H..cP....3.`...v...R.....U,.......>H.D..$\.E..n............V..+R.....
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):105464
                                                      Entropy (8bit):7.998410986146707
                                                      Encrypted:true
                                                      SSDEEP:3072:ZL2IsjqV3oPmQsiapNQz9uI6mDwGBBg/N:QFZuis9CdBg/N
                                                      MD5:681521BA746BC5DB331043392819161E
                                                      SHA1:E015222F656E980531419B5E52EEDD8D67324752
                                                      SHA-256:73E8129987FF5A60C2AD4DA541D1B4175C89B8A9673B114B344FAEA400187F8E
                                                      SHA-512:6C36DF33B96CD968D3FBF61C04A7FA14159EB12448270A67757EFA82111740A3FCCBA90385CB8A8B51AA4D11C236E7C54850D6D34F71CAD53FF9279B76C87EA5
                                                      Malicious:true
                                                      Preview:WANACRY!.....S._...W........c.........Y<(...eE.3...x...$.y..?#.X.B....&.^B..K.D'.-..4s..........c-..tc.S0F..sWl9^{.....?.s....LhdB....T....U.GP..';.H+..Y....Q....H!...a..,.C...P^...<F.>...K...vX.-Ui..D...=X....H.3!.i*.['..S../|.An...nYJ.d..ts..._................*M}.+E...!q..h.^..5......(.=o....,Q.a..q.`@.N..f.O.Qzh..s!..F.t..A.....|..W.o...2Wb....A...E.`...(-.j_naa.V...q...L.|..{Tn.K..#Ui?....qW../nEq(:[.o..`..+......~.(L....0..ic..Ff\.B..@...(%..<f.S.o..k.D..W.)...I......T.bt.A.*..*..?....q..xoj...%.?...}-....k.3+c........s..n.OEj..a.^.4.........._..Q..y...SA.....AR..?.-x.r.=D.;?{P2.&.....F..w.9S.|.a.4..Y!H%z/.....]*q.&..q...UB.(...\......B_.I"z....4..d.....O.SdvJ8.//@..V..h.G.&.}.zD..][..I.`6h.....\i.}!5.i..g..!.D.r._..".......*..IF:.L..3.k...W!b...Y.._8...#O4.f..M.....&NiNg......C........7=..h...K..D.@RFG....,.J.n.......y...g.p.@G...o.Vxy1'.n.O.@...<n.*y....:...../UURHn.F?...B.^..)..9..H.@.i[.1....5l.e...F..HQ[.........q...a.O.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):105464
                                                      Entropy (8bit):7.998353792043287
                                                      Encrypted:true
                                                      SSDEEP:1536:G5FRMrlbQxVU9Ur5ieiyn/51r4No3+hdpvG9bezD4xoVOz6gMEPoSfSw8b8at4:GnRMrJyr5rxF4m+hdpWG7chMEPndat4
                                                      MD5:AE75E35807474A9564A74F8C0915D892
                                                      SHA1:D935343C4F1DF24EA6FD74818D71A35C1C1E8E33
                                                      SHA-256:AE121739BF1521740F9CD4ADD03913E9B2CF63D09F13E0F511814F1DB99CF5E2
                                                      SHA-512:7ABA134EE9695F229576C17ECBBAF9A9B28888488030CB3A41B1859888A2319D9563EFBC745903D0D8EFEDBAFABFC2AC1A9B568BCF77E294BDAE7F214008B6E3
                                                      Malicious:true
                                                      Preview:WANACRY!...........:o.h.....\.ZCb....Q.v.D...U.1F.*..E..2.l.t'.MS.Km....?." .d?.qR..:..N....K.)4.4.....x.E.P.A......%r.v.U......|gD.7|;,..*/|..B2..i.8..R..C[..Y..?B>iZ!=S....m.mU.Zh[9"..oq<=.......d..s..-..$......M.......?.P;+S>...... ..8W.W.t.m..S..^L..b7L.;..............=.A....lv...;..........j...%q..V..T.....=.sRs.\.=.......V..D....N5.y.t.,....[H.$.m..>v.T.........U.hp.].)..Ng..A...x...*c:/a.....M.i..o.a.x..E.............8.ov.t....tU....8..0.....C.......O_+....x...D.7.."..tB.)...U.w......Im....K..S..#..m...(J.O@..^Q.s-7....*...]..`;.j...].k...J.j$....h.|..J...=..w..B..|n9.5_.....g...7.P...CA.=.T..RZ..g."o.....Z>.,qRI&.S<L.J.........cp/......X........1..-.........DA.+T..Q...).9.bM=D*.5...!.J...2Y.&.>.|..'i.SsJ.x.{.p......w.wQp.._...$-..'...B. ....Y.....v...E...\czeR........9.Jf._.=..{......y'V.\.u.k...pc.c0..ud.......u...".....A...#.d.oE.M^.1L...z.,aA..[H&.2.[...._\.._E..R..#..s].S....zYP..lDG.g.-}|)...1..........r....[5.a.c.3../1y.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):105480
                                                      Entropy (8bit):7.998218219655311
                                                      Encrypted:true
                                                      SSDEEP:3072:drCcCtNuN8qn0jJIC495zA5RRNhhGJ9X82+7xQk:INbuN8q0xAZA5RrhhI9nyxR
                                                      MD5:1591F52743FDCC98CE58351E7E42AFBC
                                                      SHA1:3FB7BF6C9C7200E8210CDC30BA4A1FC417D28CC3
                                                      SHA-256:7CBA4BD7783B4BF934F68349784422C527FF90C14C05A8D943CA7C2E175903C1
                                                      SHA-512:CFB5299ADB67675DC873F466FF64C42F03057A1FC2E453D202DD8583CC162B3F7FF6903F5C161D6CA585FBED45B9EECF26D3E881DE4D30427A62B361F01468C7
                                                      Malicious:true
                                                      Preview:WANACRY!....O...-.A...^U..#U6.......(..#..ei7...:.....p.,?...M%.ax....lF.O4b.g/..&K.,..=..0......?f.v........`.q{..+...f..,..@.z.......8....nZ.;.....{g....#.rXegB.3...W....I3..{#.2...K.R..}x..Im..^{.#..Y.w..y...VYdMj.:.T6..B.;g"Bz...`..a.....{r")...-..s...R............dl.j$a...U...^].|.........4C9}h..K......Hn..7.*...2...E.....?m!..^.a.a..8.Uf*o...7..."..J..;..Q8...,a.xX....s......K.d...!..PByG.....%........b...B.......}...H5W....`yn..!....m.jr..;.S3}.W.|..xx....^z..s.3'Tzy..p....f~..jS_.Rt9..p.yim!X..ZR.V.)\..c1..2......U......@}....A...ya...5..<....d....d$.ql.T...5........6l....=.!....J..\CT.l$..1./NA)...{~j..+n.._'.\...Q.Q-u..!:*9.4...?..Nv.........(..Dg.....Lmf..o0>J.#...8_.k..8~o..:vr#....e.........&.:....c...^.a.K...`(G...P~.j}.Nx...)...u...G....9Z.....^..>.)m..cX...).$.d^`oar...._......J...}00,..o.....6....?U...u{;4.<...>.zGVU......c....UIJ...Xw.....^...}$.no..]._y..a.|..[-..3.......t.7.)u.t..%..\.)K:T.@.;+..1Hx.X..... J...y.M./....R.fKZ..
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):105496
                                                      Entropy (8bit):7.998051196764029
                                                      Encrypted:true
                                                      SSDEEP:3072:q5AW/i3KTg9zUPS0q4oqlpFgvv6aGQUq+SseiU:4K3IcUPS02qFcCaGQUxG
                                                      MD5:CA1113978E2D3F993928BFA6845D9444
                                                      SHA1:541E7768223D7DB09C26D81B5DE8F899B041082F
                                                      SHA-256:9471DC6ED30564CE37804DB5E9C38FCAF4C7FD2A71C3F56E6A065CE382091F0C
                                                      SHA-512:E73D72C390B4B38D671EFF98BA031D4FF66C7C699ED3E4C3C3862FF1B5899B1513047F9F2FAD86C3348B76F4BC2C073E462FED8C5FD9942810AC6A4C069A800A
                                                      Malicious:true
                                                      Preview:WANACRY!........+.H.Q.Sa.S_.p..'..hm...=....T.SG......kkM..E.B...8Bb,....R...i.....#F|h]}7o.......}.0.,X...0.e<.........@..^.s|..P..U.......@....._...=...j[..@J...,.S.....C.(.........1#..-6......dY.. ..[...V.b...M..z.&..?_?....&...\..|....{.... .CCRs..............Uc.aQ.f..l7..\..P...5..D...o.HG..j...k<.........Z.....u%Z-4.=L.)SSo.......[{..n.U..^b_,?.Ik.,f.p>.I...........GL.O...$.......O.F...Qa.#...y*D~..x_>........6Ez..x.Ob.....J.....)...t..I?;....k...73... .^8...4.....SY.....5M.s......M..a\....e..m.g....x>".jQ.3..Y.D[.p...`.b...C.[.vu.LF..5$.;.P.sF. ..%..B.._.....Aw(...^......l..I.H.....S.L...`.6......\...6..AJ7..0.}..ek.,......_...../.,nI.?.\.f]Su.x..R....m.h..o.Htu......l...6#....._.?z....8w..2....nr.y.......:E.{iGP.!!.;o...=.|..C<....J....>.5..<R....Z......3.J.X..zM..!2..._.m.K..'g........hY..M....r'.2...k.*....k...!.....TG../.. ....A....s..f..~.;c.......t.T.v.....d...1i.I.ud.&..P%.....c ...=8.ixx....C...![.c.CI.$..2:.,..B......y
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):118072
                                                      Entropy (8bit):7.998404398137297
                                                      Encrypted:true
                                                      SSDEEP:1536:DQTuxvhfYt2KIjWrKfl8vjvPXNjruOCJSyKHxNf79BJ1quJpBQrtg4dkYQSNxV7T:xvhfGSAFvfNuOcS9RNzexlNxVjz
                                                      MD5:33498FD3EA4C9F2AFA663B8B49CCDE7C
                                                      SHA1:0022CC0FFE2E50BD4AB8C3020A2ABE203ACBA31A
                                                      SHA-256:ABCE1E4AA7C733E58180E7A7F00CA442F967B44BB9D246F1741018D5D04A941F
                                                      SHA-512:A6AC1F7978537E29CBDAD72B65608AC674D9A85BE75D8AA4B81A5289964FC5515C16987F7BFA69B73B1739F2B0DE4F6BDFF67726C10CF3D848ED1E9F516EB096
                                                      Malicious:true
                                                      Preview:WANACRY!....DcK......)q...T......?.X.-Y.gd...h........t~..ah.n.+.e..8....*RB....f!~(gb._.-3.k=...d...U.N...|.|..z3G.:.y.f.Qg.......B@}(.h9............xt...i..CG8.My..,....d.QQ..Znr.0...6..u...,.v...J...Y/..@s..>6.....8..W.tn._G.$....2_C...".T'8=.gH.R...A..K..]................j!4.AU..8......Y........v.s..F...c....v-...x../S.;....f.q.GE..%wf....t...$zR....g.._..0.D9}%....[..H.+I.K&...D.J9...{JReK@........x).u$.~....T[.e.^F.a.e.;C.J....;.}....>^...O.hUE...V]....n....._K..ZtjA."c..p...I......oR...e.UF^^.v]..AW......s.....(.S.W....p..4.. X..M..*<....Ag...O...U..wLUN.Ko..!/...no...{./jU.$|...q...J.......L..C.......j.G../.R..v^.3...^.Y..%M...u`h&>'.+..\.z[...a..0..j.s...o4E?.N..`c.~.\.&ZlnL@...pi.......Xi...n.b.;.j.....~...$.Y...3Jb/C..]....U.....32...L0.O...7X{u.......S.|M...8.....&.il....Dn)..@..W0).v...a..l..p9.8,;....`.2....}.mrB..`...0sm............n....z...^....J..F..s M'...KZ../T...EG.,.7......A...!)n...#A......Q...g~...3~..e..^{.zw\...Uk.)..Ae...
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):118072
                                                      Entropy (8bit):7.998447234685394
                                                      Encrypted:true
                                                      SSDEEP:3072:nIASZEOI9kEb3oS8MFAM3BoZlgCEim3WaNddiR+tVAC:nJSZ4WyuvgtWaNuR+tV
                                                      MD5:BED00989A3DEA6981CA7B5C8C8015CE5
                                                      SHA1:5B50C66D040967FD4D0FA1656955439E003F6E33
                                                      SHA-256:374CDF79B51D11B33BF5BCA8E0763CB8C2A1DF9469B96D9B36E32792A0DFF491
                                                      SHA-512:5274DE3067C78AEACA27F9F957D6797B64284A83E8B841B559BE39E5DA6A77F3E6C0A3EB6D5264DFD9D9115B539A86E2F7B7B64A1E8320E5DB25D6F252B76499
                                                      Malicious:true
                                                      Preview:WANACRY!......Fh.z.)..O..G.......9c\.......b-..O....X..h...p.;.T..$.m[.3B6K._.....F...t....v.=.y.}.....R.qd.B....6.h........9.XE...js.Yhs..k7...x[/......0.f...;.BX..$73.y...4AAV...+..7.. i..bR..?Y..2.....,.|2$.y..g...m...RI.<...M0u\.....zV.....2.k...L..............h.....}O.FM.3.,.p..O...Q..lc..=."LMPAw.J^Q...]Y"|.zT.S^2lih'..j ..(4....-...:D0|)...?u.C......Y..1.5v...@f8.J........(.}Q...:...S..S.E(-._..^.#.(.c'....jdS....(0..J.V......E=s<....E.Gj..F.@.:sG*.u..b$..6.5.v.-R~..6.u...3..J.yRY-...L....S";.i...~N#K..=U.....[.br.....)..X....`..&.G/..$...+..%R.0...r...=uRsR.m..%...._...?.34..wu.kdM. .:.g..J.....b....a....;..;...}......SW.jD.....r..n.c...7.a...(5..;....j.6.]m}R.....%...}.1I9lbz3%.i.U.....:....g..c..3..c....e..L....c...u.......8J.i`..pl{..q.$:.n..i..?...>0.1..]...wPf..MY.4.....Ugp.%.Qht".}AS...w.&.E..phH....#3a...>7Q..i...N......D.d..Q........z.c.T....y....{.,(..@...._.8!...+...wk...l.8.37..1..r.J......^.Z./.B-......=
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):118072
                                                      Entropy (8bit):7.998600262997509
                                                      Encrypted:true
                                                      SSDEEP:3072:3h1gHepF0l/86e0tIEw8f3FlAAF/pWobORI:3hC+pFMv3KEwG7AAZQbG
                                                      MD5:09BFD0F3E90900F821D111972985B6A6
                                                      SHA1:5254DCE7F849DDB48867D0E19AD44F8B21D1CC67
                                                      SHA-256:7C22F017A37E4DFAACDD0AADF075FE0324AC9CDCAE011B7ECDEAB710A773620C
                                                      SHA-512:D98D998AFEF410F31C54BDDED4E0C96C31F444986EA5BC25511D5652B910FEB2143B8B528ED934A32F6C480AE82211E4A1B4D13D774F36E7145E35A943354A80
                                                      Malicious:true
                                                      Preview:WANACRY!......d.=....oX....Sb.a.6.k.. .AJ...4.K....R.5...e..0.s..Z.{8N.e....(r.R..K.L(..H...X..[.....E..-..Y.....O.b.n.qN...o|!..DI.....4A...Z..J.$..%......\.....T.U..A;..z....7...D.h.....:.>..%...!u:M.sab.ep1...+....jr...M@.i..O.....o../.Q.:&fB.@..s....... .......8._s...;..;...!v(T^..|l>.....=.l.3...a....5e..e..P.?.Gc?.?V..e_..vZ!-9..a+.d...s.....~.d......@..x.".P.f.#6w..}...M.x..1.....l. p....^-?.V..<-.e:.{.......J.!)rt.rB=S)..,.XB..?...u.....]..d;......A[..2i..!...e.7l^..2....b...pO.......h.).aV...Le.i......k...xZ....t..9.......X.?..C...|H.].|.U. Bi..OY.a>..Y..+.FD..`..].c......8n....c}....k.1.hbCa.T.fxq.%Y.:....z.6%.~...I."..<...z..=..`..AA.\..E..WO...j.T|.i.....~..S..Z......M..%....93.G.tv...HM....kR..0.....A.s....y...+..a. ....`.)..#.<.(.#f..Ej...../~...L6q....u.......t.'.2*x..?...}.G.Z../.m..+k...R0...u.VvIX.|u....=...t..]......C.ys.<,L.kp!@.U2*.~...'AAoOx_$.}G...}.].../o%)..SA..<U.<..U...iE8.z.o...1H..gz:i.u....l.#...7|.kO8)...Q.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):118104
                                                      Entropy (8bit):7.9985014717779785
                                                      Encrypted:true
                                                      SSDEEP:3072:yBLuzb0CSyzNAa44As/zqlIds6RDiI3q6/DZaCfprXp:yBsbSyzV44D/zqn6RDiI66/Vfpr5
                                                      MD5:194ECD56C575B6BE89CCEE2BB808BEC2
                                                      SHA1:D40AE8CEA9FEA1F73C0475667C5CBF9C221A0760
                                                      SHA-256:4B7A941CEB3A49C07EAC9E74D2C89EE0732B6F2B68382CB6D3D2F12920BF6CD0
                                                      SHA-512:DC79136566926387EF19688C2D5918A12682B186EA2FAFB7684934E4D9143F1A5A0DEB6B77207996E47D1A4DCE97BE67C104AAE3FFFE737BBC7E3507CAFED5F5
                                                      Malicious:true
                                                      Preview:WANACRY!....^H.5.M?.>.+/X...&..%.5m.*{.<...~....n.-TU0..<..\.......SU....4.....o....z..x..H|QJ...../..h..d.;H.n...2.....#...e......H[....m|..$........u\.p._z.Z..2....{x^\.NPq....Z7...t.....am.....I.~ox....].~T.2..9.."...6./.R..|.|?+........H..uO.Py.>....2..........4......-....2dW..[.96....W.cv..V...Z.W........@._.e.........Art...4..By.X...Q`%..X...oJ.C2..;I=K6..CD.n...&.&.P../~...A..J:.}...&F....s\.A....H1..09....#4......-....b;....;..t.TLM5j.....!.}&........;=.]h.mif....k.a..d{.Av..1..20v...Zr.O&(R.<....d..v..?7......#.|..... m.VrV.U..<.ha-b=l'.I..w...T..xz.!..F.D.(......$[=.Nzg.|Ci.=.............J\........U..B.D.Rqj.K...4?...}....R.>....[Z..0f.l....O......6...^.S.....z..[.Y..;l.._..CI.....J.j..-.,..}..9.:b..Yt&`..K...=........i.2ua.W..0....;p*....9....x....+.m........G.u?9E.o..|k./s..)|f..T.y%I...M..9.x.G.j.~U..7E.N.'d)r..Q1..O.m.....!.S..;~x......'..z....v.......'.w.._E.b..T]_..,..s...v..\F.uR.e...:.T........F'@...9...#...p...[..
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):117384
                                                      Entropy (8bit):7.998374895903503
                                                      Encrypted:true
                                                      SSDEEP:1536:LVjRUTUmQE/3d/QpSMX3KUtpVFBBH+FERoWq1VCnCH3ZxBxMwhSVAUxjmcp1mIX9:L7N7Eep9X3t9Rr8VbBxV8bpgIFlfQE
                                                      MD5:A83F6A88801CB13E8EFC8039CE40F134
                                                      SHA1:5BED1807B85EA0FF3493D79F93E8BE16849255E6
                                                      SHA-256:5BD7BC3CBAF4C7C3C86EAE2A0D037961D0E688C802C124C659879841EE5B11E2
                                                      SHA-512:5F0E6F1649EF47CCF23119B17E38D0F20C95D1B398687F11F60CA49AF8D0A22539B83C409D242BC032901A2BF99A9C28AD1B71D164FB6813ADDBD5ACA04EBAED
                                                      Malicious:true
                                                      Preview:WANACRY!....Jn..|A4.`..aO\...z.Z.<......W.._....Mk)..oOJl.+p..oP.u....A..xt.)..G(h...B|...&oX.H.Tv......~.wOo...|..z7...'...m.O..~.(,9..(._..5`.w....../..9;.I.....z........N..4...g...O.r.r.R.F..{.$uy....{..y.)g..G)..~X.S..d.T8!.....G.m.^c....q..u.....d..........G.V........<..j.;...A.sl"CGFcJ8o..r"Q.WJ....(..................b.yi....k.>.S..f>.'..I..T.........f..Ts#.q".,..}.=.:s...XVl......2....^..$.pD5...s..t....;..t.F0M.#..I}...|....EJ.8.......8.o.BC.h[.K.....2...A.....$.:.0<...<'.C..c:.Z.v..V1..A.n.$t9P.;.).yae.@...m..7a:..hUu......B.....q!..........3...a...g...m....."c.@.5..e......G...W..n.L....B"..<........t......=...0g.....(..T.....\....Tu..bx.XF.~h.-....q.....W..O........GR.g...g......D.FQ.h.t....)Z^H.....#m...I.._.8,!.......5....#.....A...|. _..e8...L.v....<...0.....'.#.....;d...Nr..)[..IE...v........kq..KB.p.`3......=.|T~pd....'..0...t....6f...n.h..K..f...........].G.'.l.n..?..U.../.'N5.h.Y..[9zY....hf.5..'.....,`./`
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):117384
                                                      Entropy (8bit):7.998337606138264
                                                      Encrypted:true
                                                      SSDEEP:1536:4SAr3KTUP/1pfPVEeiwpeOi2UjKPPTlWLSzYuXKeNjBOtZmXtvIizObp:j+KU3/PVEei0XffPBEuNJemqizC
                                                      MD5:5CE08E7BB4E554954C65789E40D7081E
                                                      SHA1:8C16341AC9C1BC9420D13AEA7964821D7DCD3905
                                                      SHA-256:326CD363EC98EB054FD7C4DA4C243CEED1E814B5D83038AA03A275A12EDC0F97
                                                      SHA-512:7F41A48F1E3A6E2910D6B6C7DB03BD067437E23E786537A6CA338966D98A035ED899A353EF64E2DBCF90F32F68AD9659EBD2102C3EC20FA5226A915F281C434A
                                                      Malicious:true
                                                      Preview:WANACRY!....%.+=..s.y%.97M....R..,...(...N.....(.0..o]x.=.5.......X..M..o.3.+......0.....5.b.(...{h..p..;.q.e.,.U(..Ba...8...".s.k.\.$...:.+j#c...[].}I7.".i.e....3....v{d.Mdb.Q|Z....5g...`{.Pn.m..e...`.....+mV4..d..B..q.+".....(...F......:.@!k.".9.......d.........m.B..u.......,....6I,..-...D`kW.rR.G#vB<n.&.T8.'.-.0....b......u...T@.}...4..@.......-z.j..{....\@..5=z.C].!..m....w..T....w.......O..@..m...O.g.\../<...Dz.!..j0_#0........\.z_...5.b.......~n.5.......0......v...<......i.....Mg$.xv]r..{...#"!.n.S...* .7.~l..m./].z...B.._Cvg....r..VC..!7..8..`~H{..*.(..r.)....L.....sc..........7...:+$`<....Q>B..~...S..X........<.D*R.[fT..P.KE......X..x.+..J...H.FH../.......m?..up...Y...>........Z._|....lU.J..=...U..t-.A=..51n...T...l.C.&.............>...G..s..n.b,Cs).........z...z.%..|.z...h=..xS.R....4..H....<=...f...Sg...-.......X.Q....W...+....Yi.`...g-...nw..........O,.J..k5.Q....\+..e.a.}h..q.....*.R...M|.^...b.f..\....Sl...>84....n..U#..%g..5.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):116952
                                                      Entropy (8bit):7.998410769863449
                                                      Encrypted:true
                                                      SSDEEP:3072:5OElbsnBQUGpvQg1J+ZAEqUUpDZ7twfyKA7DewTI:Bmn9Gyga6e6r7DeYI
                                                      MD5:B49CA61750788933FCEF6C11B0CEE82E
                                                      SHA1:49F7CF5CCF1C4C57377F7B1335756630477B1171
                                                      SHA-256:D0BC2A25345F15268531D3931024482C8635E2149BE7FF7379A732FBF1141D08
                                                      SHA-512:8DE297BB71C552CEA957EE86CB23E230D0919BCDDDAA93C97FDEDC9058F8D5B5DD63DECBB6C311FC8A00FD2CBFAFD2D7A5405BDBA7FD32E00DEC306729893562
                                                      Malicious:true
                                                      Preview:WANACRY!....U.....\v`.}D.O..S..]#..5..gk....n>.V..K..l.?....0.zc(........M..PF.,<..P.\.a/.!.CJQO..k....62..FP..R.PX-..7.:2P...#....L.o..)......L0.N..Z:.eWwr.p..._.`...m.......O....d....9_Ju...Y.I.....\....X...q.Hl0&.t.e=*.\..9..b..[.v....TzI....'..r.+S#....N............6.f..Wd.<..zAhC.n..@.....!..h........Q.;.Q..cfKr..#$..+....g;..x.A..*.3u..$.......O..`.[=..\$.U;..-MmRk..52..R.....}.y.5......H.V...@.~M...].CI.>/.9x...o..W.7.J.+vQ!.....s...m.....b.:.N......3&.r....a..$.;..<.~...:?Pg...vq...%. [.._qu.G-W.h.h..:.]5^.-..E3..?........YXfy.!J...'.=.).l...I+"@(.v.E...E.....z...3[..h.s..z..".nJ...]..S=.a|....L.$..>.uQ.v....v.!.x.V).....l..JY...5Q.Q..Z....}......b.0b.h...X..z..7j.....aE..W..?...r..%...|...Oh.lj../.px.\.........E.J.A.....P...b1....=....'..E........''.H..._....Q.8s...}.M....{.@..._`."'..7w....A.....^.....#...Mq^..<.1......ufT:...SP.H.9.al.u.....>..h......."M.t...k7...........i...[#w6..gf..Jxi%:....a.....[....)<U.Ae.....+A. a.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):116040
                                                      Entropy (8bit):7.9984658593487055
                                                      Encrypted:true
                                                      SSDEEP:3072:Ht9mCmhN/yGMXAvr2PK1nMuf/kF3Qwqf0aGR:N9MHqGUAj2PK1FnkMfNGR
                                                      MD5:4C445E50508115E3AD338C02BF24B8D6
                                                      SHA1:1C21826CD370D9B3512A4CBEC0CDB5485C10A67A
                                                      SHA-256:724523AAA4757BF5D38075F3BCCA8CB3F8D2A1F25C60CB0B90C9EC1C59972FC3
                                                      SHA-512:AAE8F8CC32664453096E33614D3ECA72C91400DD1E9FB2F1DE7454622E4BA685FD0FAB14529D693499ECD7EC60C7A1F15F43F7F917358C2D89286FE597B6E55A
                                                      Malicious:true
                                                      Preview:WANACRY!.........Yv.......G..g.4;:....J.........M.d&.X.E#".S.4....s?.2.o..#q.N&b\v.5.<.2.li.teF..o.4.....KsA,.....a.1.@\\V.....K..[b.....Ro;...}..6W.b.2o.xP...!.\.8.b...o...<...Q0.:.M...XA....&....(....a...r..e(..Z.}...5......F.*`^.4.U9i}.u,"O.....d..xn..=c...../............O..2...`w...u.[Eu.].o%..#......y.S...b....O.6...."N6e...9 Q...~.T.f.......7j..0..z..P.E..HA..IH....#....N',.eA.....}#(vH?.V0?.4.Z.jQ.Z'(...{0|/....1.....q..T..x|g......4^.M_...9?*.t)._...l.;z.xQ..[..A.7.oYWDu1....g.....p ]4n.c.A..~.`..H..w.....;...>y.qsW_.r..-...G.....C.......W.......5..v.e._OxF.-..}r/.[..&...Q......Re..n..".G.H}:.a.........;Svo.....Bc<..C...h.p..5.1..@..#...F..4.|;...9}.ZKS.c..o..*.....z....\.....V>./?..p..e#peh.)..3.._...r..Q.iWn...^.L...0....<.9.H.Zg.q.O.b05y.`.DC..RCn..-....T.nEf..N2...hl..Q.%JLN..h.M..L...G.c6..v..MO.-...6`L...k.3F.......=b...o.ha..:.#.%......J...?.{...Q.$.(.#5..."..Yy..C.Z...\..X.T.o.{..].o....Lxb.?/.wQ....a...v29F#.;...
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):115096
                                                      Entropy (8bit):7.998475688974396
                                                      Encrypted:true
                                                      SSDEEP:3072:AMVX2AOkEMU6daIn2+99kLLgEIvXvochgRQxNgVXFTMTRD6:AMVXjJPUIc+9yLMEcXwgaVTM9D6
                                                      MD5:FCFDF63B1E2468904F96AFDB8C35CD16
                                                      SHA1:46395EBCE09FA00D596BFAE0975AE358EC56A70E
                                                      SHA-256:4016D9A4BC03903CA1106D2791DF702902BA4D38BE79AB96846DECF0C8256B53
                                                      SHA-512:7416686252F4403C9C6A6D3513501634FAC469268628FF08B209E6D086FED2F488C9387E445629D942EAD19F20D1D475F9B2B542CC0A44DFB577F393CB009249
                                                      Malicious:true
                                                      Preview:WANACRY!.....W.....>1...#.~.C.g.:x#w.N&.....vn...(..@...v..\.Y.....c.,..4....m."..d..NV69y......Y...:S.....y....k......HL.......F..F7............loV\4A..l.....|....5..(.?...b.......2v..L.6..B"|...k4La...{.C..?.[......I.!c..B..B#<WA..0..+V...L..[..^<.../`.....~........b6...^..I.....y.|.. .8..Pi..26.H..%_..N}r..=..\.......#.I.....J,.....8V......P.C.:ag....R.......k...[.Zy..s..@.H.G_d&X....N.Q:.......?.]]...X.'.(.$X.*....o.,.....u..oV..5......)w. ...s...9Q_....T./$...'....{........"w;...'...}.w..9.4....#.+;...&V....&.>..k.*..R..v..?...../I.gI...d.-..=.......*F..~.LOG.....m.....@..'.L.<.4lL...t.=.......-Mk.(...qDCs...J?.(..%..........N'.J.|.Z.u.DC.L)B9rR.oO...s..:.3.}~..~D..i.):.X.....T9..@....2!.c...>G..fjs..Q........Y...5....Wm.Or..o..]..|....m.U.P..h...D.%...M..'.O....g....k....=...%...h..Ao...D..S.....z...v.0.T..v0r'..|.$...c.[....F..cwP...Eb.Sf....`.'....[.....5.....f.a.:.~.YJ....WZ_../,..]E..y.......=....Qy.42).....]../.*KJ....
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):115096
                                                      Entropy (8bit):7.998607677518114
                                                      Encrypted:true
                                                      SSDEEP:3072:GhIBmfBfxue2UUHapnUWD6I3Kw/YUJTXy1FkW+Mi:SjfGeMhWOIbJT+kXMi
                                                      MD5:95D354A21177379467EF0545FE8786B4
                                                      SHA1:BCEC649BF9C983EF918104B1AEC7129FCF691BFC
                                                      SHA-256:C74EE90686C881799A8F86777899FEEB4EB6F7486D22123F23FBE3EEA286F9C2
                                                      SHA-512:50CB05EBF87C09E16F14112EA967B24FBD13EC19B49ED283894C9092E35A57CDE6B5C15BC76FDA9956EEF0C647943853EACE827D256DBB6F0C13D74DC16C57A9
                                                      Malicious:true
                                                      Preview:WANACRY!....|.Gc.....Q......R|W..+.x8:P!..GC..6..1.{..#.PR..Xm.. $..Z.k...BO.w......h_.......9....%jr.vKd{..u...#.C'..H;..._*./...t......h",......_..d..h.......\G....J.._..X......q..2..r...W.... .vV.#..U.67W.e.5..<+..u}...'.0.........8<.....5<........;..e......~.........y{.Op..}P...q....!R...S(8|E."1..hX..J.Ko...C..IT.=.}...l;T./.g.....E..s.Da.....=.k.f.?m(g.k)...X......f..o:*..;.G.. o.RR.n...E.....b...j.r.V<I.t...vH.1.......!...WE....>..)g..#...G..'....d..u). S...f..P.l..j.p......3.{y..A.....CZ....V....9..$6$.$x..Y...k.z..V...8rZ.W..P..%.g.........c..v......\.G.;...?u....W....yC......7.Q.Y....@...../.B..Eb..x.... .y.N..2.*.Qj[20{.....]9.....Qr.B....$.g4.......m...Ot9.....M.].O.....=.~.e..tJgp.. .kt..cr............S...K...>^.*...<\kg....Ko2..t..B..J......y....l....o..)c.[.:.].AH.c..~y.......3.....^.}.tFR..R0.o....]v.6...0.a0X...%...PP,....r.....aE.. ..lV.-.~Q/.r.&..E........<m..a.....^.x.PU.............7.J...P..F\..,..jf.....*-[...G.!..
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):115096
                                                      Entropy (8bit):7.998431435823143
                                                      Encrypted:true
                                                      SSDEEP:1536:M0tVEm065SbBb4rhpuWOW2Id4mcJ2A6FqoA/4QHohOsZButrh9S0olgnC5M8:79SbxesIOJx2A/4QHf+BAGlM8
                                                      MD5:8A3299E92E3884D8D6662A769A5661D9
                                                      SHA1:F98BE7DEDC2E1113CD03C322F187D3B3DC5470F4
                                                      SHA-256:EE6DDD75ECC82BC3817D6D54C496F63E5C527A9E95816CC559357ECB53128653
                                                      SHA-512:5CF332025EB95A013E8C22591E737EE4F8F5FEBB5A3FCDE8D5CFDE20F48E25C07D2E41678B71C08171E3F0A73C266992413206778AF5B7977B0D3B9CC448630A
                                                      Malicious:true
                                                      Preview:WANACRY!....HV`YtM.O...W.|...r).....9...L\..c...8.+.8..%kB.S.M;..3+f.e-....FN..i.0K0...L G.I..,..A=i.?....|..B....>..dU.m......,.D.Z:........L.......M.0...y.S......C.J.....xhv.x.f..+........i..c...s.?.2'..d.R...:C.P.F.Z.F...tk.=.y2...:...kP...K."v.k.%.YT....~.......r!..R..?p...*..........cG....Y.m.oF>f6F.m..:.P..b.........RkZ_...P..g86qsu..:..4.^....E.5r....].$..;.M} ..k.<..b-...(-._QoAK:.h..:..U=$..*w..u.i....,n..5......h..nu.3{i...4LW>EM`..0G....S[....F...1..{e.... '"{...Z...?..........;.....F....%...<t.....{..V.........+_..:t(....}.O{y.{!..We...K..0.m.7......W.m.5&f]m.'..X....\E0....=.........(.x..G.....;.O+-.-P.K32.S.}.Y.Rg@...-...+.6..........ZC.w..Jro.;........z.y.eo:..!.w........E...;U:u[..71C.'..>A....'..8..;.|...;3...}X..1.5..:eO.O6+i.N.<.ja..+.w52....Z.t.f<_k..m...@V.|.>3........?d..dPG^.....P<0.w..!..oe[..x..[...{..8...wN.&.V..?..R.F.....?.#....9.L.,....6.....G...r...>.....g.F]z..*v..FQ.>x`.b.. ..9..^y.p?.%.. .r........3..G
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):114264
                                                      Entropy (8bit):7.998492771503279
                                                      Encrypted:true
                                                      SSDEEP:3072:uihEFr57Qg/k8g+egRV8zh8gqgqhm+rxF+1+:uPd7ZVUzmLrxw1+
                                                      MD5:D8EA699DE0BE7E974F049093549D2305
                                                      SHA1:FDBFFDF5D1BD3B67734BFD12306962A3FAFC7A2B
                                                      SHA-256:A47BCB33FC505B5628DF504604F818AC6A56838495602745ED1F10C951FF3864
                                                      SHA-512:E1C2FEA39ECEC5DC896DE88B583DE39FBAE67B4599E25D483910A1B4891C6037014FB3CA51D833CACC8ED44707416821F0BED15C12A723066C9A3FC11663B664
                                                      Malicious:true
                                                      Preview:WANACRY!......W$..?..2...n..f2..........TWl....'..-....X......[08.%.J..mb...D..9Z..*...........+..u.u.i!...........2.....!Q.Xrj.I.zn.,.....1M.<3.8.C)...w..q ..........2.6.Li.....9....!............7..pF.. .v..iy<..K..!z..~...g.r...=J.M..wf%.&..x...Y....6.........q...I.5....G4.B...m..}..4.+,.p.E.4..@...u..K...Y.2...Gu...$.Q..,/.=....o..Mf....[...$[G.n.0....{..h..p....-)....M...B...x..4.phmt.=...jc .9.|..Zs\.m.Z...3.../E+......4.....j..n......)5.e..#w...7*c........X..p.../..'8=.........&.>..8.1j.j....27}>#N.y.*9+.84R.c......e....>..54.d.....\... I...F-^..R......q.a....r..OF.:z.I.H.0\..g$.RR.8.3Y..._.....=lw.f.Q..0.`..#G...6....9T..hn....A.n.1..;..W..u..0.:E.a>..'\D..O$.K.I.X..Ob..HI....Z1.....?.D.H.7....R....oC..z..].sG.?.r....3.9....f..wQ..@.....^O....m!.B..s.?........m.i\..{..*..D..Uzg +.=~C.....Q....u..3......h.F%.e....h.Fg..G'..".is2UfW*.,....y*..m........U..H|..+.h..ED..a/...6......I....UKr}P.r..H.YzhT..Z.....t)^B..@.dzJ..2.D...s
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):114264
                                                      Entropy (8bit):7.998465315805634
                                                      Encrypted:true
                                                      SSDEEP:3072:mvmtb+kUjjG+MmPtASsIoe6gieb41AzuvW47j32u:mvUtIG+Zfoe6Ouvx2u
                                                      MD5:C91E3DE03D64408379374D101D309B73
                                                      SHA1:412DCC3A28360B5F5D90B0095854E1DC843128CD
                                                      SHA-256:159FBC60B68CC05091D361B6357B711741BED30B9EDE81D3E01B38E5D64B2A56
                                                      SHA-512:0ADC821F7C7E7C3AC59EB66BAADB25CB31DDADDB7277EDD2409C6E2FCA760EADEBC70286DB02190A9C593C30002A905B2BF029C9E2B0643BF20A5AA6CF3A93BF
                                                      Malicious:true
                                                      Preview:WANACRY!.......@l*./..6....^Memm.m.#$../"...G.....Z...J+n.^R.'..*...C..W-..p...;*.j.E+5$.......wT......OsG"m....oFN.G.',..ha..Q......p6.W.....@*...&qOe.W.\...k.......ef.b.7.a......sk....*......F..J.O......,.J..q.~.;D...y..5~..O"+...VU..5.b..a..N6..;..@3...-L.fd.....6..........i]..........>.q.\...M<..+4......\Qb.m7..M....l...8.DWz.r..O(...A.b...?......Il.c.]..j.H.X|...(..m8.:....JTV,...v{..e.K...ta..........rF.<...+...D.t..Gl....a;p.%........d..P2:...o..8#.....>...........w\_.....O^.....I.._kY.....5.....n.2.....d.b.q.Y.7..%.dPx3s...%.........%.....).Y+..#...(.;...........[p...D.rK..G.....J. ...U..n./....y.MQ....n..#.;Q.u[...C....YH."..p;....((...F.~Dc......~U.._@.g...m...g...N.<...w`H......j......O..:..4..PD...O..cG..*.T#....BL...$MA.K.i.`.ZQ.C....|..u:.*.Fu.....s..C..(...''.u%.q..T....B(._:l.2O.j/|.79}..Z..W...y....N...b........Z.L..6.8C..9m..Xw.i...^...y..&...(.Tr...@...!.5lg......:........._.3n.G.h.L+.}.I....3.2..J.....~.....f....4..f.E
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):114264
                                                      Entropy (8bit):7.99833490946137
                                                      Encrypted:true
                                                      SSDEEP:1536:flO+Gp1rS4Xo4h3KKw1xoyntuqmLMhPofiqRPFABXh+gQYhkPCLly66hEs2rsmkB:flzGXrd4BL1SCZmQoaRXhHjM66h/2Ylv
                                                      MD5:FEA39436B72CCED3FA06606D545FE899
                                                      SHA1:126C69B172CF12B9CF28CC2C1060832A948A31FB
                                                      SHA-256:4D3CB14DF2D4168038E4960DA924A0961ED96984383745F712BB8CE472840604
                                                      SHA-512:186BC3F240A2941D6116996CA009231F5C9FB6959EFDA5E2EBA76235CF7855B19A69D88999DF675CE3F6A322204A93A87B8C59A8D911382D5EBD1642665A6E55
                                                      Malicious:true
                                                      Preview:WANACRY!....].....t.......q6._.q...v*"...........^i.(..1.U.-.kH^>.A..S..f..X.....oJ%*q0..Bh..........$rj?w>..:L..B.9..J.e..Pr...&.l.|e...T.j....U..8.-.6../o#...T..5.D$}.......A...a..>.5.#.}.Q-..G.\..IL..(&.<.`.S4.tX./..s:..4..:...X."w..f.0-...I.3..........6........qG...M.....:..o.f...4...qU...ohBYkoFf.....l|.x..d...hk..y..8a.^...'.0W2...C..Td..7.....R.b.V.......*.d....jTY1.........up..2..,..........:....&k%.<.z{.q.p<.A...'...fP.....[.....B..G....y..)..`.F.C9...!.(........C...K.t..*Wfs.R..k..a.b....>....0@+..r..Xg...9...<3....h.....ocM......&........2..v...n.....H.{c.H..%.e..&..}.Q..(6.,..|..p.P./4...k../x..q..i..WPo,".f.b..,.2..s...)A.i....`.'....2.A..D..,b.)(.P.F.<;E.%.....X....}0{..I..|o....!..D..G*.6)..3I......u)O...>.v.._HZ..w......<V...4..1.4.R}.A.'W.$.R.p.w.....|Es.MZ..{.0./0....p...!....EK..~".......1.(.u......J..O.(1!0....%C..-bi.|..k.D6..v.....(5]./..0B...*?y.)...*.T`....^T.?.Y9K.;Y..$).$...s..l.1.....h.1.9lr.....v.A.. ..]48Ec`
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):114264
                                                      Entropy (8bit):7.998524200979648
                                                      Encrypted:true
                                                      SSDEEP:3072:11Pr8MD83Ep7nzihr1lKHZrp0n2HdxPaIbqzu:1t8eNObKFKoxiIbqK
                                                      MD5:527F22F1C3B296187F1FDA55D208FB31
                                                      SHA1:F6A8F3495B6896941D3447B68C89D2B21C0E0516
                                                      SHA-256:D8AB6251996091EFEFAC0C5CEAAE51EA3552384D96786658200F850BD8258D8F
                                                      SHA-512:25C25EFA116A4DA6E4516AFCB761303BD36657197767694E0B003303A920E9FE0DE1A162A90A6C5200F296CFFB838B34C032C94DC1208CE276970CF328AFD6F1
                                                      Malicious:true
                                                      Preview:WANACRY!....[..Y.a..5.IfT.{....!..e...@.d..`.f;ME.?a.(B... .j.K..bm...R...i...5l..9..rz!.q.|z_N].(..<.;./..j..'R....m#.~...u.Z..B.sA.BLk..cQ...F.sNY......z.A...7s.u..._..E.....l.....Zymx.. W..G...g3.C...fn7+...j..-.>I.....- ...o...|.cV....=.`......-VK...;_|.^).....6.......l.....h#.Kj...H...,._..Fs.C.R........!..73...!J...8...x.F.B..c}..hc..R.&..[...I..b.Sm...).l.*...XW..v'..,...1.h...Q._..PB.u..-5.......RB3....b.q.v.......8.NH.<..3...%.l..+G6en....][l....:.>.....!..`...GwDS.,.W......../........|.g`.O..B..|.....AX6....C...(V.....>..U.M..|.(........]q..;.\.-..~>L.....6...L.Z..O9a.........SXL..~.3...)U........cC7.k.w.>R.;r.C.mO......r....T.....=.Q.....z...t.\..G..=TY.)w......L...Z.$..Tqa.....4Y.&#...I.y..?.i)..!..@...".V..6.V.,..!7_..{-z..W4.3;.KM.M.N}...%j".-.N..[.........HW.. l.9(...p....P..}.... .B.^.....O\q|k*.E83`~.Z..).2..wc......A..}9>.k..HV.67=.3...6..7..]...U.n.{a.i.....Q(.x......K.8Ak..4z.O.a6n#..n...<...............$..>V{...$.Q.E....)}.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):696888
                                                      Entropy (8bit):7.999729823779383
                                                      Encrypted:true
                                                      SSDEEP:12288:a9RcfokJq7viyc/SJ3ych/IRZiNc4hb9jI0ayc35bMGev:a9R86sSJCWIRB4hV4yc5RE
                                                      MD5:A58E25410C2F76FC38A52B3912140223
                                                      SHA1:6F36BA8CDBD842CA1548B4646ED1055A13170446
                                                      SHA-256:0155D8702A821EF510FB11402223CB0002863555DC550D3E5222AC9863678CD6
                                                      SHA-512:AC2F3CEB2C0DB8636016F600FC48EAA6DDFFFEDEC59E68E0895ECF4234159D2B1367A86BDA0177AF3EE47BF90816ED68E9D5B4DCB99F45ABD391B63C35565604
                                                      Malicious:true
                                                      Preview:WANACRY!.......;`R._...~..|>.&.w{fYL./a.J.....K.:..WgJ4yHS.... ...^...t..o..&mYF+...k=u...D...".G9i..o..''......)N... .Hdy..6.2:.j.$.......m.*.o.pqrr..*.m....#.r...N..HV.`.{..... ..(?...2..'}>"2.N......iy*g..&R....l.V..A.B...NH.a.Cg...o...U...i...'J9bQO...*@.^.............G<..&....\`..\....W.W].\.'......UET\......C...{.y..N<......n...?;PZ.o.9C......n[..s2..Q,.........]...8.V.[J..\..8\..L...}...3.<..Yzb.$.......;..".:.....L.3..4W9[..*...9,....Rm.)..O....*N..A....e......tX8h...o\...#.....[...`../..A..V....rH{.....kl"..o...>.O.T.....H].....4I.RlJ.M..[yDu...|....S<.(f..U.%..H......(.).p..A.&.......^o62.OO2.E(N../.Qgc....?..+..~..o.............`.....d...1lK....Z.....--.i.I.......<.gA.nR..]w.&).,..r..HlYPu..?./.M"..+r.P.\J".....kS.....D.i..z6.zY....+..y.O..I.A$.o."....q...;.~.....K.F...&#....ped.{.....`B.R.....d{W.?.Z......7.N..UmA.....Ic.:=.....zJ.b....w...|.8..GQ.0.?{...............?Lt.pBk.d..E..J..<..........CO+.+..U..Z.F.w..#..#O.I...6..&(E..u..
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):28728
                                                      Entropy (8bit):7.994449577431811
                                                      Encrypted:true
                                                      SSDEEP:768:5mdX4SS9QPW4FvUyZHBXHGa2n0doXQzOahi:5mdw9QDZ9BkPypi
                                                      MD5:DBC8D365F3EDC08CD3D30D43ACDF90B5
                                                      SHA1:9021E83409C35C88746FD2BE3508A26C725F6DCF
                                                      SHA-256:5E0DF6D4E5D70557FAE33601B100F3B38430E29FD24901745A4EBEEBC1A31A10
                                                      SHA-512:3BDB1C417B78C64E81A02EA0CCF70EA545EB022FB229352B443D8364269A7119A94C2C05941630A2E71D46B3CC00CE660ECF3FD73FE2113F6F4C25786BB5C1A6
                                                      Malicious:true
                                                      Preview:WANACRY!....r8.V...........&^kr_|i.~.N!3.....NXOE96....C!j.....+......|.?....S..1..'v(O.9H....]....Q.._....f.5....c.-..g..."7.hp.|..JbC....D.%.....S....p.`*VJ}..\....9.....{.U../..U.6.o....dy...a...$..... Nf...j?..QG..y....J....y....{..?......P..y3-4..Z".m.........o...........1V&.".......%e.x..\..$...*I...R.Jv5mN.\B...~.>.....v3...}..1...-.......^.z.B..<.Y..X4Ki...t...?h?..._.0C._........>..ZA..........[.Y.......}.;fg.X...+.Ga.I}.hD^26.m..32(..>.5......;?..xdy_.....Z........q...u.,.q..K..UD..u.PI9.+xq..t.G......C...[.q..&.........A...T&+..w..x.......^..Fc..._{.E.q....Qh4G..p..UM.......d.z......e...r@..Z..Y_.q.$.g..S.!CV.TQ...>.......>C.C..0.]...t..<.(.Z...L.;.MVk.().W....a..e....s|...).^2b.r..../..;g.ye^......w]rxS...<^w..l.].]..3.f.ag...3R.H-.S..."...n0,`...:u......7............k~...].@y.3.2ROH...8`..Z...?.!.m$Fn.??.3...wBP.[...b..}FJh[.t........-..H.|?..|fT^.f$...^.#.....'.lD..[...+..!.G.g....O.%>.9=.....a.....5 .:.........+b.m.=..
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):28760
                                                      Entropy (8bit):7.993892338031974
                                                      Encrypted:true
                                                      SSDEEP:768:s3Zd1aRMA4mxZCdf3rMnqRpSbWRRh16TXbOl7Mo79QA+4yno5m:OERMA4OZCqnu8bCRh16Ol7BmATzQ
                                                      MD5:B22C7833D1CB80C624A948C8F46B4165
                                                      SHA1:CB9D28CCED067FE8911E7198E69DCFDFC36D21F2
                                                      SHA-256:06CAFBD1C8A57EE927A550F3CCCE58A430D6F912FBB6B1BC2A97FFF71C3CA83E
                                                      SHA-512:A3F1D6AF272D70D12738967C91CD4B29FEF9C923BC41451FDDFA68855B2E547376006B12A5FD941C7B1CF0CB7C128754567C8EF84736518926FEB437D3373F4D
                                                      Malicious:true
                                                      Preview:WANACRY!.....t^j..I..MI.0.<.0..|.8...E|....cj.....\....G....r\./.....'y./..../x..X.t...W.RPu..}.j.D........+.....I......aH.So../.L{.8.;yqI.1H.]:......._..m..I.......).?. .....}..5.*..5.r.o..P.m(..q..nvK.x.......$N.H..v........8s...X.f\.......u.%P..2........I....?o......a@!{..mE....;W.q........N.3$....4L.,.)S.*i..&..S....o_.xs.Y..e.....H..:.G..B....x.Ju..;D.T...r...i..j.fL92...^.m..^.f..1..U-..&.....6..>..OI.v....@.3.s<..9*...S.._7.t*XcCQ+.&N-...X..wg..f.IfMW..N...ZX..[.:...;.*.z............._EK.B........r.=...t.tJR....n..I..O.V.X.b...{R%.l.v<gdK9.@.:O.r..M)..9tfh...z.u:.NJ.#.+.....:V.....#.Vu.Ju.O.......4KJ...M...1.'.f.l.K1.j.a........!..V"...&m .......l8.K.$EI.t...M.a..\f;...?B..!.!x...5wq..Z.....#....#.....(P..+.....`....A.j.6/........,.V........m..>...>U.z!..P........TP.......a..h...Bl.l...Q..+'2.....-.6..G..;..mY...uB.+....h1W-.....$.....%7.....=5J../.#.ne.......*.`.BM/.tF...E@Z..Kn&[JNk.I..f...C{%..EP..vb$.+.....3.t..m..=..G...z
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.816534722076974
                                                      Encrypted:false
                                                      SSDEEP:24:9TYfxWx0QOIkgcpxq6osNKhVKuFTWdncN3qPocG/lxr7B2U:8xWGQOIBV6osEhV/wcN3qPoRN2U
                                                      MD5:47A5508E88EC5C593C55BF67657319ED
                                                      SHA1:8F12EE9B9CBF16BF045019C0F5DD7A1E24F33781
                                                      SHA-256:BDC985A32278CB9D0359A6439D80694571D79B1F9E20C846B1276FCF228C8A87
                                                      SHA-512:0D896E3A60E36F21BF549FDE680FF20F68E1BBA80F7E2BAAEC5F5F5D2A1A8A0F73DE79AA10BAAB209D95A05CCDB04B681B1DF1C598B73C015E50687237D813BF
                                                      Malicious:false
                                                      Preview:&..zI.b.>o...2..p..~.T......gg.. .......%\.{.Z*=......4.....!..._{.(.....q..{'...>l..34.a.........CX_...y.,\.~.Q.!......8.s..7Z..'.....Q.C...I..0.=..AK.Y9.m.i.>.@..f...!..u'.2...s.vm....\.N.8.Y..3.."..JHGF...t^...`0U....|.Co.L^.U.{....N..........G../.TM.d.e..../]..=......r...D.aE..Rh,.!4.....f>.....Fh(,.9.<r..!..O.T...TI.jDi.+.'.ENH...\......sY%.[.,.........)fY..X8..bQ..dG0G7%..........<6Jv...s.QgG..S.B...U8.&:..s].....5.`@.m.]u.b........Z.!..%.qk7.}..`iM.....Y....x0k..7....=.+(..,v.w,5..].q.3.....|..h:N%"...U........V.2&..%i..xj..~.... ...\..t......p.SgE.m%.....CZ..;H.1.Q@6*2.|.~.f.>Z.Qc.3..1...H-.'E.}..._4.(~p...V...K...........6.F.[>.5b..j...o.......M|.......aN.....J.p.Z.....Y.......W......I.....Q..."fq...D.g....HPyy....yq;........YE./.f"..e.O...7M..Wa-.& ..8.b..G.*N.qW..[..J.-a.|:}|P....N....O......{Y.{v../....].f...U...&tr..f...[.Fp.."!n.<&O.E.P.WK-gn...NG...+]..5.v_..w...)am...)0...j.w....._.9..-.....Y$u.+..-.Tu.....q....ja"B..h.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.819023204267254
                                                      Encrypted:false
                                                      SSDEEP:24:F+jRSnoY3OODOX4kqGq841GyZyj98bsfRocPlcM/gedsSc+P:FBnTeyOXd2xZyBysfRoujgGsSx
                                                      MD5:7B0169B46F572F366CEE198AC4B3E10F
                                                      SHA1:8D1881C7DB8C6D342625FCE3FE67C81AF339A640
                                                      SHA-256:DD380DCF0168DFAA64191707F5E03CFD7649C680B1E532CD42B307AD175973C0
                                                      SHA-512:38AC7C6447D8DADDB37D7248E74C439D711DB3FF5A2EE1D98AE3A1B89099C3713DBB1ADF88A57A5223F2E7A8B022960388059EF5DD2D138E8622C1939497DD4F
                                                      Malicious:false
                                                      Preview:. .JK......G.{...H2............;..a...T..@4t..g.....B.e.x..].7.i..w...N..l.b.f..P.C......`I..z.K'C.]..0...G)......wf...s.Zz.>..:..n.cP]p.M.Jex....g...8.t.7[.M*6*.p.K-......o.4:..*.d..'..J.9.D...D....he.$.I..m..s3.!....t.../s)gX.Q3...V!.@>.].+.....7.}9.U.....T'x..U..0.|..c..sm....S.\...R..N..q.P....u.;p.X.V..$Z..... .7.......[pt....'.].<....V..Z.CV.e)......tqO7.g\.....X?^..^S^Z.....E....G..`......W..+.8.T....z....S....s....t...@H.c4.)^aN.'.v.v0w8.Q......a....@.....[.;...9h....m..txQ..D......<..b..4)....D*............6.s).~uk*.[.f.F%....U.......d.:.B......g.,.T+.;...cw]5q.'z.....T. ....G.....X;....@...O.f...C.d..y.......u&w5...xQP...`A.......7.....X.R..-....~x...d..u"..Hf.b-..!..?....U......;'.....2r.e4?..;..*7*....(Z5..LB.....`$T..=....4Z"....N..l]K!R.d6......BP..T4.o..<.....~.a..v.......X/.......G{.l......l...vM.3.Y..]....O._/y.H.....y.f#..8..{p.VmW..Z?"Y....0ny......k....p.....r5...l.?..T..^.}@...G...8....CP..-....r0.,N."..
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.7763642577579
                                                      Encrypted:false
                                                      SSDEEP:24:BOFzJbFno77u0lSGG9w7+cA836dUeJbU4Vbsziak3F9:GzppfyVJHdKd1Xoiay9
                                                      MD5:8A2B12011399AB6DBA4EC2A3DB4A41B4
                                                      SHA1:E2A943FC4D0AAFADCF6217CC0B7205E3ED32C599
                                                      SHA-256:42CF77F4CB3F7C110CC6A11F7480EE3C5876689949CBC82915403302AC255CC1
                                                      SHA-512:A39689A2EB9653979E7369140F4249EB907CFACED4B664502E32CC7112344CB3CCB50A999617B88E41B6EB2C74162C3678F64E9FFA0223468B3B4B2E2827773D
                                                      Malicious:false
                                                      Preview:..=_.@....}..-8...RC...0.?..`..b......f612i..oc....GO...D..=+_...a...C.;.../.W.<.~...\...O.f.}.6.r....:.(....9sG.e....zH.......F.F................ji.P..XpJ.Z~C..u.K[.y-Z4..jrC....@3#)..t.f.WMw........a..}...P..w....A. .aN.]W.$.8..,...c.p.......U........_.W..+5..d.W}...a......R]+D...L).6...(1..ZV..|.F.@.u.....c..C,."(........<>i....}Y.....E.....:[..W.A..l...\*.1q|t..w.....r...o[.*.[...i|..F...9+.d..?...a..u.b.R. .K...6"V..a..p.....`c..4.|...J.%3......g...e.[j*#..Q.H].|h....s....D.-.t..t&.R....Z...C..7..j....n...(..u5.?h\..|.2...4:....*..+...u.T...........U..L..K..*.0iN.....S..Ow..3.U....@.B.......N...dz..).....5.4...u.D......GM.(E...z.a..^..........U....\}n.6.\-.aq.<j/....$Q|....O.K D[.:..d0..;...x\...u.z.......c.Eu..k*...~.X`..$.E....d..+.V73i..._k. ..f.^^.h[.,...l...o&....g.T......M.o.74.EC/6.?M|J:6..V...s$......w..y8/.......1G?..Wus....ur.T.X...6....I..F.F>...<.....n...`D.4..9........ '..W.C.4......N..*.C..;?.h.XM.^(J.f.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.8032710233789215
                                                      Encrypted:false
                                                      SSDEEP:24:lSYmHmCsWCht74WdMWwQLvJ9bA3NFuYsl4s:ll+mCg7FamtO9FElp
                                                      MD5:78896852F769BF2F15384F6BB544311F
                                                      SHA1:2A33FE484506B28D9B2EA4F119E127F0AADEA935
                                                      SHA-256:92090ABF9E45B4DFC323D84365E5ABBADA5C40BE142DA79220CDB4BD1D6417CA
                                                      SHA-512:0E97AAC91458304B0141543324C6EA30EA5FCE4044C54CC243F766ECC2B9C3ED9CD70D1EFEFCDA97615E8270D8C6CD60E1EF26A0A1F967C7B2A282F910440BBB
                                                      Malicious:false
                                                      Preview:.U.....5 (...m....c...m.rY...sG..:.=.0........g.>..,..n...>..R.Op.._.o!Y.9.n.d!...#..E..>....&.....V8}y..M...j...n.<'....1E....F.,.D7....<......-..4.....z\...pv(hr..v.eJ."..aog....ks...7.v<9..Y..nl...3...Hvm.....lm...'.|.?k.......V...].D.Z.k^.).2k...u.......I......E........{vh......%i)....on....z.F},.s..at.m.....k....h..|..\l.u..Ar..c.?.d.....5Gn.7F%.e....0......q......([.S..fJn....[:..2W.:S..(......A...I...X(.....}a.zX(.Yt..o%...2.XZ..E.....=-.0,4..j..E....Mq.r....@.?.......Ig.6..?r...........cN.KJ......bhu........v.y..R..z...d.r..+:..E..O.y........*:.....Z......G.X..TqF.....*....TCzML.%{3W.0....`.?...we.9[..3..0.=.=$a.+p.E..f.I.....?Z....|....Tru.Ox9w.......#..Tk.q..`......_..a,..*..$.X.z...e..D.....n....dc.-d.({h..m...*....$....N.[i:.@h.........n.kzf.:#[...{,#.s..i...1.,!.........*......X{9.u.!,....M.A.%\.@.f%....(..B..3..r.}...N..G...G*.....W}.....3l^.Q~.d")g..X4C .&..e..........8...>.QRV.E.c.......>..x.4H......%.|....S.......
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.798353287802944
                                                      Encrypted:false
                                                      SSDEEP:24:s4nCbVNINFKRxp9n3MmzaNzmkye0+E9UUQEc4aX6poMj5idO:XnSVyKHX3rrjUTsJidO
                                                      MD5:B15C81F42501DE98BE7FED436E8BFEFB
                                                      SHA1:94E088B65A8DBE07FC567F82AF775A2649EBCEA4
                                                      SHA-256:22535A9D9854293EE86CE4F5C441CF3888BE0E81CA6CD7E5C11C1213FAB95DF3
                                                      SHA-512:9E3517AD6B6561581896E39F8888594E14A1E12936A42908FD4477AD7FE421C9D985A2805637358620CF08BDCD143FB959183E1F18CD775C671D5C0D2CFC0867
                                                      Malicious:false
                                                      Preview:.8...>Q.....I....<...V.{Y...{R...M&r..?. .m.O.h).K-...F}$t.Y.v...A.T...c.6{.*c..hV.!u.C..f%P...y.Jm..z..A&j..P..~.EP&.4].*.'.............UX.6m.......01.?9.6VQ..:F..kC.\v9..m.:.ylY4....D....W..@R...e^.H..S&.Q.x.Y86.n.P.nN..A.......UC].1..g..42.o.&on@I..!LKd..g...x...."'......].....`.-....&ggk..4c..^.od!'...Z...&P|.0....s..1..\<...h..... ...~.l2.f.$.....`...t.U........I.^...T...@..t4.8#.L..\d.bA....7;r......]..$-du..g.u...$zp.'....8..j....A(#w...$RQr.R}!U..-......u.U. A........2...G>....Ai..GK....e..qu..3...V..........`... ...O9.2.Z.....e...#UB..........Q..r...".jQPYX..a,FK........o...0]p4...e.xE..H..c:........S.I.U.*......^B.0..R...;....r?..z...;|..2l.5.h....|~..*].vlFv..2[......?.G.c....Wy....C...MLU0|.+6{.Y.q..-..t..:......-...Q....!...s..g.v2.l.....).'..!......Ls.5.Wb.G....-.g.^~.j...]...l..(.....C~..^U....^..v=.X-..X...$...o....=$../.:^......)]O.X2.6.kuH.....<T....K..p..As.h.c(A.......$.D.....^'..4f..c.R..'.D...3D......h.m^..<GC...!...P....(V.d.k}....
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.810970812976166
                                                      Encrypted:false
                                                      SSDEEP:24:0p/iQ3NiAXUy87GFo5ofNZbCBDV8zPP3mWYxkrfMXzZMIsbys1KTB:4/igNi+qCLfeBBQPPWWYxkTjD1KF
                                                      MD5:FA71DCAD7AA34BDCEC4F93B6CF6F4F8A
                                                      SHA1:1E1DA5E5F1749FB1EA56B5DABF631AAA84D06867
                                                      SHA-256:9899FCEFA62F2B7D4458E03346D61F64D94280D21112F0B11E0002EB7BAB6DFB
                                                      SHA-512:2EDDD4770EFB022EA7430D5EF8EE6FCFCA5C47BA2FDDE26575A382649C3A0F5C814D91148D2352F9840D9829D4BD63021DD5F92F2AFD27A0BE05A4019F90044B
                                                      Malicious:false
                                                      Preview:]..X.m..1G..U.....h.,.W......g....?.>...:.1....Q[..{.j%...Qg.7...}x...."D..I..G64..y.w.P.7g...>~.:.1..?C..R ..k=.)..j..(...p.ov2`...U.lN.../...:.sp.....c.V..w.D..h ...e8.A^...0..1.d..]rsW..$tI...%...?l1 (..-{q..v.E6FLt.#37vj....>....0.yZ.......2.|.<W...A.....C..$.j.j.u.R....x.i5.....%1..>|.2.*.HH..#...T'r.{..4...."+p.*..2.........`.-XV..c....g.P...yb\.g..dR.........OZ;"....7.j..`U.(+%r.J......mKNG.Q?.a.9LZZr......s....t..Je...6.\U...!..)\.{j.D.r;.)...yB.....%.D..E^...k..;.K.v....M..I?1....rTC.....!7-=Z...Kk..<O........sE..S.L..:.D.nE.5=..kMP....h4....a...T.7:.j...w..CH....2..k8..S&G....-...$\.b3..v1@9..C...`+.[.xA..BY.*.H.U1.....8.....u.L..L.....^..W....Di.r..ig!8L.kk.Bd..<0...f}....P.O...X.X....3..&.:UY..%%...W.q..Pr`w..E6.N.&/.]......:>.R'....G..a.Z.L~stnL".6.A.|..<I...Od.n. ......q... Y-0....z....)...8.......".../...H...2F.=.L.^bY0:\....ol...J.....,.B....a./...6...B.C.4......P ..;./.j\..m..2.PBO..E%.}./.I.....|.x......q.X?..UTxR.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.806269438753434
                                                      Encrypted:false
                                                      SSDEEP:24:vZamzsuQXfwCEseAHkytwYWBxwdrS/y7t+n5/OsQGPU3F+w+VlECAUz2:MmzwPwHPo52yxAWsTaFv+Drxz2
                                                      MD5:BE55681C41C07066AAD709EB2544D06F
                                                      SHA1:15E0353BB7E56BE605EC2C152DF57C086AE00BF3
                                                      SHA-256:FFC79FE435C81BA014650D0B7D2B672244B8B90A9C9FCF060A67B96CADA9048B
                                                      SHA-512:E1D39AFBE1E341D34F280914017AD75CC4D4C4E03E5EBAB32C2403FD5F3376569A46487826DCD920D2EAC9D095D8EC43F591E0AA8F61919FF0D680ADBCF2A731
                                                      Malicious:false
                                                      Preview:..<Ei.;.0...}ZI..0.........1.hs..h...a.V.0w...Z._...}x.....*...A.....-.....h._........./..h..<.....@......?....(..\4}.|...?n.f../......7ko.F.9n#.3....{.,#...w.`R4.6.b.b._.a.v..Q.....u...J.v.t....U..U.]`z......O!V...a......=..G..b0L....E.6..*......C.T.&a...>.<.:.4.....u.M.U(....w%N..H....x>.j......}`>.k..B...g.b...x....U...\gY.......).`.e.'..J.....XmE.f..V.v1......-S.98..V....`:V`..(L...o).5..`X..p.d9..b5o..H..Q...K._`..p...&.....U..Po...SZ....R4@....")~.!?.Fvh..TYh3..$..M.D.Sz3<..$J..".....m..zD...F..k.?>.b...|ZT"..w.S....K...%...a..u.8...FK.f.M'dU..{......6.q.P.}. ..g.j...\z..cxu#.$....!.2.7Q{.b/WX....).8).......$..SL.>t.=S.....F...y.....p.."...1...M..?C.."..BK....).y..f...).7..X..0...$O.18.~.0K...r.}%t.]z.../L.......u]...x...1b........-.}..../#.C...rN(~W....e...S....E........1..c.F.Z..h)......y.Y.}...{.D':.M.r.N..Q..dG.>>....k.......M.XW.t...G....R......g1F.O-...I'..j.......&.(.$um7..k.Y.>...4fs...T.....?.b..Z.x6F..2'.:.~.B.\.2N.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.822916180185078
                                                      Encrypted:false
                                                      SSDEEP:24:xN1dQx58cLzJe71l/vPoWO1eWT9rMTKsmhtaAP3pp:kxHL1e7xmR9b/iAP5p
                                                      MD5:6A87BF8B16F88D21016E3471FFD469A7
                                                      SHA1:39EBFFBB797007071D9B5E6AA62DEF5716F501FE
                                                      SHA-256:BCF3E7800EAE7DE5800AE32287201A212B3291B346D93A220F9A1AB879D5333F
                                                      SHA-512:F3581FC487492157DCDFDCCEA7278692B7EC5A067F213EBF29A01F8B745C8B2020608F97CDC31BE9B9A655BCA332C173AED2D5083F53539006F87782E1138665
                                                      Malicious:false
                                                      Preview:I."3...a...UZ.> .Fb?.c.]aa.L...E..1.4..sb..l..;.4Si....?.+=..v.|...'.ae|.......F+....G.b...B|Cr,...,wYW...gw.@.L...0#..X`..ax.......]'..7..../ J.C....>U.lT".......0....6S...Z<...........j.I...nA..Z/s1r...%...r......c...D..;..dW..9.^@rP..{9%....z\5..0.....0<..0.&.......j.A..n...-RO(.....|.'..d.Fo..w.|#..;W..k .s./r....39....lVc..nd..A...4.....4..`f..... .I...o.J...3D....Q......%.....jy..._....9~....T.._i..%....._h.s...|iQ.....Q...X....U}..4|.........t..r98E..<.??.]m.U.2.....W.....[tX.....Y.......@.Q.Nb.D..Z}..K..Y.1.3..|....N..v..7....Fx\.s.d.S^w...........WW.B...4qw.k.......8B..)..!zn3......[J....A..;.U....Bs...J;.hF..w.\L$A...;..h...I.J.t.*..|..R..Zh.m1....o.dI..6$G./V..P..X4.}....{..KJ...:b..[;....%S..-.@..fe......!..8UM...O+M.. ..KH.."B+.c..b_....3..RP...y4..q...i...7.>\.`.....Gu.tj......~.GU..C......1.Z?..Dt....Q..t.0^.`.t.%...VJj>..n.....".....5..;....7.....r..v...if?9"hU..u.\b...3'x....b..ou.....z.%.....n...v.lg..+.._..+........
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.820270167079531
                                                      Encrypted:false
                                                      SSDEEP:24:UZI5HSiSHvpUi5kTNyz12VrH2UQsBXUHvTR:SuyfuQkTNggVrUUXUPTR
                                                      MD5:A80BD758E5B19F4F272BC49941F064EF
                                                      SHA1:588D894A68AEF130ECCD8E2AEEAC9C46623689C0
                                                      SHA-256:AF4B7F5CAB8048A8FC7AC287D97FA84B74F87E79E92E13E6A2F9E434824061B5
                                                      SHA-512:15731C1A71D07529527D68935FD264D5F8FC57FEFC5C5384DEC475D33D02AA051223CFB9DA62B57DA9154CB347DA5C6F4BBDF788D2A44A07CDEF1197A4C17E5A
                                                      Malicious:false
                                                      Preview:1v.s...4.j....Ri..~..l.o.wz......,.@.H..........Q>./._y...?...@...o.AV.w...M..of.4.w.......:.?..U..|.......3U%...B.A.J...=..L..;S.(k,.H..dZ.5..VT...V....%......SXz.W)...N...$.6>9.DS<.p.....)...(.,.D.8:...gj.Gs..)1B ...z.x....n(..e.mv.L.....-..X7Y.u..-..:.\w.Mk..%..O.Z..5...b.i6....f..jkFC....cZ'uS@,..f.g.&...zV#.Q|G_...nuoa.M........2...o.Bj.1~of..,.1j...Z.WK*.o.a.^......D...%Na..9....O.%.u...XT..>L?..Mv...._..^.N......+.F:`.)]...GR.rV1Q9.....I..N.__.(.....Xc./`.0.S?,..2R...,.D...5.U.v;{...6...x......y1...a...n#..........I.3U.kv.r\.i.....?[G.x..k...Ke.NoY.....b7\@..IU.NV.%....Q.T....o..@.......$...~.hkDF.....P.....6....:P%r..t..t.$...I.......?.......`nx...."....8...R3....x/H0+..; 8c.A..)....e5..-....H.8.[K`Nk ..g....1..e.#N..#.3......6\^#O.2.o....G.B.m...Cb..1.f~WE..b.q......_...-<..iUw..L..8...T....L...).U.c.UFM.+.%....].dv...G_..9s..".....\...d>.u.XI...Q..(.G+G0......?..%...}....s.1.eF?.[U.......p..<..l6.e...Rt....T..t.@.(..5.3.. G..{....
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.802296508734037
                                                      Encrypted:false
                                                      SSDEEP:24:vAlRaUpO9ra6f9r1IsVElLIlrN0xdvnqyFykRRRDb3MDjjI53:vAEBa6f9r1tCarNC9qoRRH8fjS
                                                      MD5:73B6D1CB9B4247DB175B4291C3E5F3B1
                                                      SHA1:16EDFC511D6AC884CDBA0064AD78D644083B39A6
                                                      SHA-256:8273D61C7D5269E331B5528B99C6D0DF05E3B2B942C92AC42CB341038DC47067
                                                      SHA-512:50414E45EE579226AA4B8715A4435DF97DA6FFEB1142CA08309AA303866933E83662FD09A9FF15FDF57083E4A2F478E60A8333CA5BD766B9CAB005D5DEDF5E46
                                                      Malicious:false
                                                      Preview:.`$.'.9m....?.u+.-.._.6....:.[.I.N%..g.mf..,...\0.iv~..1...&2q.;{!.w....B\r,.$].g..2..&.s..^.....b.....BR.'6h.."!..8pK?......9k(N6..:y.0.L.s.....hu.%Zq[\..S..bv...U...f.....qqP&.I.$z..(.f}...H]......yQ.x0..F..P.:IL...l...g...n.KI;Bc...-.)".%._....D.*.n.......Q+q..k.(.a....n.E....t......m..P..#DKO.y.UP={`M.).j........nM...`..f......n.A..Q.[t...1!..........i.)./!.&.PV.^r;.u.$/.+.+.)..0.......:y...M....7.$.L..Ne...cn{.......;...C.".......4Ba._.2=c..+..(.%.... %.1_O.p....R"...c..c._..b..kBC..^p....1....fF.P.2*..]1.D.O:y.......C@.4a7..[d...F.+Q...P..0.U.s.f%(.8a...l...s|.L.Z.|]..K..Y^.....t,.. A&d..u.#...4qdX../2..a.M..,....(.q x..W..y,..}.F.....{-.i..v1..!.,...7b...(z...[l..}...U.z.T.U-.....{@.+..,hJp.X4..oM..D,Oi..l...?...@.L.@s.ez{.}5.P.]l........}..m...^.........'k.WxM.......u2....m..w.+._{w...........v....u/U...\t..G<.5'5.q..[.fX....A....guB.kR[...t"e.^....gH...U..G|C&%.~.>."V.!.x[..{$...T6<6...w.[FX...(pb./.@..Z..n.*.. 6hd.....>.=..`....
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.821190381571588
                                                      Encrypted:false
                                                      SSDEEP:24:mXhacjqwzLKLFp0lMaqBiJKh/+3/7KaTr8jOs4+fka81gFUMo+:mMcmQL+T0R6iAh/+3/7Jn8Ks4+fka818
                                                      MD5:6191BA52516B0B420C2F8679DDEB57E6
                                                      SHA1:9FB0655477E3552212CAC32F7D0C4E31C919B22B
                                                      SHA-256:C7FF960DAC625D34D0183F240F6D3D169BD9B5D7D14B1D3269E56C6FCFD307DE
                                                      SHA-512:3B6AA091964A511920CB84526262EEC2F82C66DD6EFE7F7C3B037C18B71DD1754578A812D50147236840106A98A7A47721E9EE4921D917B602C694E6FD66334D
                                                      Malicious:false
                                                      Preview:.&.2.........g.Y...r;+MN.{.wC<....L.<mI.....H]...r......H...0....Q...K... .m~....... ......R..9......C...ui<.D.tvz...)TW'(..Q..h.....2...~.~@.@..?i.F,.>".Z).|.f..D....8-lE9..e[`...M........y@k..81..:3.Y...>a.hD...6X..>.c:..Z..G....."e..j..Un. ....Yhd..d...Uoa.0s..[.Y|M...ymj..$C...*cfi.k;.P.e......C..)...Q.....%.A.PH...1...IE4.....3S.H.B.h.;....U+...`...F...S....8=N.>(.9...Ad............ 2....)1...z.......Z@W.......*.:....t..1...`X.....N..%...;.^.D..O3P%..B..A-..m.....(..Q...\....0.o..g.Tg@.x+..TS.b...WG..s7.b.H...%..Nkn./.:..fq..wC.T..Q..;Vv...5T..... .I.du._...65q.9...r?.U)...@u.),..........2.S..9L.....0....A..g+3....V..N..D..N].v.....-"!.^.^...;...l....hc.....m....^d.....%...m..`...T,Mf..e%.uY....".X.5..B....j.N....+..m....x...[u...J.3.tx..8..!z...u?....M.....~p..^....3.~.'.\=.{....f....#.d...[...U<<.....m.6.c...s....j.nW.qz.{.SH.M..zz...(.$..*2.@..HR"..B._b<]D..=\vg.<TG...._Y.}.M .........DT~...."....j!.`T...Ys.Y..8......l.x....$.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):24856
                                                      Entropy (8bit):7.992054111734836
                                                      Encrypted:true
                                                      SSDEEP:384:NULDHkN4QClmohDHaZZBFZ2qbXfZ84YAEDnBzYTkc4YQyQ5mPrNCuwbXef:aXEAlLWSqbXfZ6PnS/c8DNCBbXy
                                                      MD5:C696800EC338DD6DABFFC841E5C836DE
                                                      SHA1:C7B40812ABBEC02858F4B20E15E0F728AF343AD8
                                                      SHA-256:7D6B64DFD7E9C67D65DA7F4241179F108AC2324EB6D82023F102823F6F59F0E7
                                                      SHA-512:C81561F0DA21DD57E26D5EB50E9B0624745ECE7DC246F4BD395D8AAA0761E12A43C7578B76549B38CA6B4EE920EEA130EBBB84E164F60452FE835BA1931A4171
                                                      Malicious:true
                                                      Preview:WANACRY!....5.r|&/...e..[*.............?d..E....4+/....E).|......i.i.QX..8..QD...3~m..E-.S..F.....J.b.N...........$8$. .i.J%....I.@..P........W@8.y.SPF.F.t9N.@......KG.\F2.A.."..p.w..i..`..2....A.p.......ij......1H...d.....ru?.:.?I.g..m.oL..No\T.3...|.z.....`..........W.}]..j.K.....4.E...4....q........+).LP..BL....+`.../o.t.QyMY..c..$.7pO.B.*:6...l.%7~.bYS,A.K.z/..g....._.T)R.WT.......m.?.,l....aQ.f.m......0.p...P.5.g.p..?y..0....6I.G.....R.q-...w......lC.r..~...h1.....K^..tX.5,..A<..8.*G[c.....)...y^.d......e.N......._..d?.P.7.k@T)kF..$.~V.k.JP....$g....q3....ZD.]..2...O,;.a...M._.%F...4......5.........]..a[5..x..]v.0xo.a.9E<5v....!...;....@.\.i..aK..m.8.n.1-k............v.q.<w5.#.....X..`Go.t..1r.5.|.......z...x..Yj.c...."(.W..u.4..k...'..c.......QM=...V.#<....~.h.M...MA.].....%..WXdl..f.6.F.q.....*..0.45.....P..#.ZV.*c..b.*...ee...A.U+n.e.......|"i...&...f.^|............T..0B.M..x...r.y..*..I.G..B}.e..Sz.......k......I......Y;..._.K
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.80318701195497
                                                      Encrypted:false
                                                      SSDEEP:24:9HQ7txyVhtKLMJyHS/V8VkzoZ5cjZoaJOsakpbzCAKEATJIe:VfjKLMR/E5Qo+akpbzCu6JIe
                                                      MD5:60E938F57D6566A6F60A6F11A69C5874
                                                      SHA1:376145D064DC5739CFD820E96C8127C8C5899202
                                                      SHA-256:8BCBF9CEB85A44E9D7BB88C4560B0D925004B5A5F970CAE5A8DF662A9E3BCD2A
                                                      SHA-512:B944829B58D40DCC616B4931E7605B1016DE03DEFDA1EBCB0375B567A0BF1246831DA9C3722BD51A7F0CA8DB10D506C0ACFF71EA8E8D0DB0F365C920197E5F6D
                                                      Malicious:false
                                                      Preview:..*m.-.6.v...._.9c.:b....5$A.%.%..q.@..k......8......V...U6#....X...T..6W..v..`......"...O...k[5A..1J..;L%.c?1"..."-..[.P#s...s....v[&.b.G..qq..8!.d.F.O..R'..>eu.t.dm.]..:1^.g..7...n...nL..Z.e.7...65.+.$-rm7..[o..\*..9.Z=..nF/.C...9..{s.3o*'P...8......\<s...lQ....."....O..B.x..j'....4.K.....st....bO".=N.......[....!1..&1..a....AM...."3f!{Y..........P......K.B.Ox../...o..ez1F^w(."N.7...J1.......z..pm:62.....r.d.~.:o}..2.4}5...m2...n.._;..; .q@W....+p.,.nt&r9....11XZ{%.._..p..R......@..$U.E.C..1]..J...r....[.3L.))u....c.(x.y....b....z...G...-.H!..Kf..h.o....}.N....NB..r.u.WS..*.=b.'..8.k7.,..b/.[..xr....`I..k...y."..D...E.}.#../H..KE.....`.y?E.u...P.-dX......W...0...~y......VxGM.K[..sk.!j...(\..@...E?.A<.'....f...$....t.h....>.)5..\TiF>..wVKKlR.aCC/.!xe|^.J.^.....p...._uv.1.c$.._h..\Y....).ej.~.......{5\.<....W>./.l.1.E..>f.`T......-;">....j.KG..k..(8.L).......D.`..SX3.5N..?Yb...m[...21..y....MeT...1.X\*.>....-x..ER.d.n.....q...Xs
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.794636815230596
                                                      Encrypted:false
                                                      SSDEEP:24:BncEFpIgtx2xDHuyG70yrMh6Ru+FTvCwSKdSoo6Px0J4hGJ3G4TyAOq0M:BncEFpRgxDOBjxhzuoo6PmJ4UyAR0M
                                                      MD5:C7E62A797C638FCEB85D0128F171219E
                                                      SHA1:BDD7EA6011DF94BABD766B7C0DFA79825AB4367D
                                                      SHA-256:26A6C59FD07C764F34D86D04BB81CE29CC8CC7BEF64CC66E13B29CE0E37C0E3D
                                                      SHA-512:D01FD8574EEF11043CBED20D3A1D9B715E28AC1191EA85C38170AB4117D6EB018ED117B043C07783F188620FCAA1076FE07D988D65AD257EBA7EF3BD4EAEEF04
                                                      Malicious:false
                                                      Preview:`p.....u.......;I...~Z....2`#Jp+..CC.._?x.nx&A@M..\.2..w.IG.Zb..U-...h.p5...N.P...!....q.6j....LT...H.......... .lR..h~?....b.8o.@..0)r..dC."._... TYAuzo.0..F.....w.l....D'H.X.w}...sp^I...5..i.....ep..?..j...$.9......0.].@.p...i.>jD...oC.@.........p(Q./.5W.: ..$KB..Y..?..9z....=.<.k*-..N}...D+..oY.C.6..........R..Q..L~n1.H.?....}..s...1...v.H"A.>...9....`.b_h .+u..tiC..*r.B.p._..Q..h.....<.N.<ka.T]....o.z?y...S..xZ....B..........o....|.....Mmw..g[.U.a'..%5..B.'L"cx.T"....Z....v.ln.+..pn.........!.}yI..`.uhwh..g..u...F..j.$.. .....#,..:8......-....yp..Y..Mg...~...$.An....j...0..X.;.6......j.S2U8...~..3j.`j.....0..;..}.OYar....vt >....}D...k.;.XD.0...S|...,J...D.I.?q.....C..._.u.|V#.....j{`.]...v.<.......T..qP.....F.".o......Ha.$}.^R....J'..P=...V..c...;..-.E...X.4;.J^....D[.l.BQ.h.......N).,\-....T....c)x...*......k.....@....&3...r....>#..a.m]X#..&1o...{.r2...F.8.n.E.Q."N.........=J..).J...0vH%........&4k....w...$$...-.fa.,...=0....*8V...N....|..
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.8217475581499025
                                                      Encrypted:false
                                                      SSDEEP:24:K6qh59jCEyh7LNJrThPJXtC15FqBxgQ9arL+1hnoJ7cB:K5Oh7vTJJXyFabf/6cB
                                                      MD5:F88D1170D751C5936B4E1055D57F2C11
                                                      SHA1:7725467C10B067EC4A9C4F092BE89A519FBE5648
                                                      SHA-256:0FEB44511F41977691B6A439393B2E9000D5FB9F4223078BC486761D0345A725
                                                      SHA-512:78DB7F7CCD1CD094DBEC2C10F17A78992EF57760062DA260D798A46A4C5C45980F346B8F16DE2B07747977399AC16C1DAC07E3B49B47BAFBCB0E192610F980E5
                                                      Malicious:false
                                                      Preview:..x...y.-.-w..b ....#.AK.1............H>...]7..pY.N.e4'...T..../......?..P..Q/..[.?.._....T4n.. ...dW...(.?..'...qC...w.rF.|g....4..?..."d.:?+G.....c..f.....J.o..k"..\.Io..h.?h.7.q..0.J1.R..[._..<X.V...K..w...D..!N....7.......S*7:...H{b..Pj...R.X..H..C.e.=.~...E.Y.e4.....I..U.Xc.[j.........J.....`...Q,N..}..\..:%..U..V..Uw4^..$.z...ak..q..R:xy.&%..l0./.+.....P..}..[.6dgF...X+\.\.....4t..1...#e.-..7^.@~Y.......>."X.HM.'$/i..y.b...z...r.`..(..+J........n..1].4........N.g.Z.S...(.x....u...<{D.$.:(...wa.*.'....;k.;.q'.l`h..c..5.....a.@.%...|.).e...........OB.}.|.n.....W......]7............PTk...................``Y..&...8E.Bm=B.."F..G...".V|vbA...Qw.&y.(...Jm.l.C..j.t... 1...8D.9....&.)......>j..U85u.<..x&-^..(.....Q....i."..49x>.j..].8."..>@.g..V0..W...X.l.rN]kRN._0 ...T-Rhw{DB....x.3.F...4......~..."......L;!..G. ....Q.Q...]..|.V......4_..v$`....e9.......v0x.......@..2.)..~...N.2..o7_|........v*...+)..J*....B...{/.3.7..S.\..<.J.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.824080178585958
                                                      Encrypted:false
                                                      SSDEEP:24:UGjFFuglAMoXOIq4hEe0NIjxzK3oI83UvJvmC5yGfLq7/Ssfzu:figlAMoXL5Ee/CoJ3UBvmNGfLI/hu
                                                      MD5:53C747503715861C8DB4AF6763BCFCAC
                                                      SHA1:7A2A87FFAB574C9AEA0C84C986052E77EDD6E963
                                                      SHA-256:FC04AD11FAB22397B2DD3556DC4F9AD1103A4531F7DBE9F79CC23AE791838BA3
                                                      SHA-512:99A4CF80AB4C59915FD99AB41D27655CEEF920E5D3ECC1CE554CD72F02E22C2ABD0209A9212902BDA8051962ACEDAD92377688BE33D5871CF5BBBE4061855B12
                                                      Malicious:false
                                                      Preview:....._.:p..........B..#`...).......(....w(..\.h.!....zI..+q.h..a.c...+P..8...7-.j.nL....@..O.r..n*."...^..tVI...."..$..Y...!.d...*sf|0]."..1.:Y..DH.T.e.....u#{.O.K...V!...O#...,..#...vq...9......d..\-...k.-;r.(}..{...#e.E....k#..e...@..........:.~....3Uk..c.Zn. ....3.7.8..r.k.+`.......Eg.....!\.d^.B....R./X.=w}F+.......`..V.j3....E....{..F?.Z.#4.b...k..g...>Y`I..m.X..=Hl.aGI..gj..=s|..b...$..D......:.......k.X.....MZ.....j..C.....W.d.S...V.T.:.>A....<.../r..a.X...u.7.q.......hi0..}.'.&..&.N..C.>...e..A.X....!.J).=@.KVZ ..^.>M'.....y:fwC...:..m.k..Oa@.c..r.#7+.S....C..Da\..>...r..#b..V]._.Q...#(EL.K..C..../.....r..!)..NS.H..t.....m.......Sd]..Z.k...h.N.e.............".TU.[(C]{.eF./.y.K..b.@. |.d .a.}...@.).......PU.J.......i)1A...O...............T...m(..A..2.hD.....e9..3.a\_..F.N&GYG....%.....(n..o..|\n?.....v....W#q..-.<J<4Jeh.......K....iX..W;e.^h..../....9.d...VJHQ..;.=%3....}1.4..xSv....j.H6......J...}...0.....2.u.k.OO)....m...V0.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.8242316070306765
                                                      Encrypted:false
                                                      SSDEEP:24:H8zRP5xjrpxYa1XwIbgsj21cJel3PQ802ekfFG9:H8zRht1acgIbgwP0Pe4k9
                                                      MD5:EBC575B3A6991CD6B742472ECE253897
                                                      SHA1:138C415DC79ADAB103AFF4519402614F855B3763
                                                      SHA-256:6F6CF4695E1ADFDE8492D2C80DC832595205727DC6598F1A23C6F711437413C7
                                                      SHA-512:10FDE4623B8AA7CEA8831C00248B78109A6E0A7EE942977CD0C27D64F6C297263977F25B34AD9D336DB98196FBF2330A8596E04407F3459A89E57AA53AA5FD29
                                                      Malicious:false
                                                      Preview:d$e.....8.-...a..._.|.5J.....1)..R...Z._..h..M!/.Y......5..Q;..h?...Si...Y.`...0.;..>.9{.~A....*.Cc.4.4R..v.....JZ%?..~...K..e/.S.O.QW)./l...P.....(.,..".8e.:Z;.Fr..|....^.[Q....H...60..sx6.'....f5..Q.i...aF.$.....@.qu.Y....b.C...K?.#.1.VO.U..>.. ...).q.@...D.....Q;.x`.....o...@2B..PE0.M.'..7 9.3..S....(kk_.E.a....h....B.L.8.`...9. Q...Da.......Y.T'.DW.kF.S..x....<}"..8...........f.U.e.....g.4..{".U.....Qa%..>.C..}.M.. .....hD.....p...A..>.^4.JW..!....Zu.....c..%.V....j........k....T...x.4.;.{..x.x....`.....>&..jS..2..T...sC......CK.]......9.H..W.._...\..>.J;....%J.X.6..2Oe..8v.cn(O...E....$..1n..I....Vx...\....R........d.?uc.i.eKD......l........'Ag>:....Tf<.....C.L.C.......2y..i.7kf....k.F...P:.J`\`..T..r.........>3%.<.....)....:1.@..&+....p;.-.^...c.v...n.b2.7.....Xp....,......m0...l.>F"rB..k9.s#.*.%-...}.m.N....U..k*.7.4B........F.......W..u.^.....c-E..'...W....s....>.H...g.v|..[Yf....]....r..g..-R.O.........j....F.*......
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.818923195073525
                                                      Encrypted:false
                                                      SSDEEP:24:ySe5p22oUpnja8SqOoA9+J3GKJgN6tc4VA4vSdR:yHulUpnjaNoAMFGKKND464vK
                                                      MD5:FD018F63563B9E432ADFF2ADB504CF3D
                                                      SHA1:5F62ECE00261D2D07EF92714B878DE96EF1B1FA8
                                                      SHA-256:6A60C0160EF1BDB64A8AC0DEB67DECD3C6DD2C94EABA4B3EA8CCD7F4E4297C83
                                                      SHA-512:492C6A633D53598FC847AE4A279D1BC52268106FDE2913BC2F5B81AD9F75CAFDFEAF3E5FBDD3E241369EA1C3AB876C0178C33676EDCDFC11DF2F338A0ECDCFE2
                                                      Malicious:false
                                                      Preview:).&...+...?.o<..w...7..s$....n^d.}........~.U-.F......@..,}Z6.b(...a.....pj......m4..i.bZ.9../...i.g...s...w.=e........#oX..6...[.. .......+...3...6#..m0..5...#d.C3...e..}.F. >Vz.E.C.B......#....x.A...K60Kz....2..0.7..H.on...b.b.*.P.'.m.;.._.... F'.......`^....,.(...^j......y.<...2N..G....Yf..SOwc.Zz..=..s..:....4.\\...+..........K1u...N&.....F..C.d&|(.q....L 7....|..........x........$.p.]....."...A.rn'l-g.G...?C...=..e...f...j.^... ....8"a...'.r!..?..q`.~E.M..V...=....W'y-.(%.....+2O....4...^Qij.B..}..@U....e.......H@...s..{.9vz.\..h.e..o.z5........9....v.....M..O..a.w..9&U..".........T..b...(0[.i..u..4......%..P..F...,.N:Z.8.Y[F.....+T%..v|v...C.z.D.y..m|mS.=...ij..l...|.O../......M.)1..h.U.=..o....^.LV.P.....!a..i..\.:M[..8_.}. 9.....m.@.J-../.e.5.'.x.,:..c+o.1BR...s.j..M.N.\...XQ h.P.....%.PJi.....=..O13..(..1....B..=..p.S\..!XnV}i+.Q..{R....-.....AX..._.v.v~Y3Y............F.Y(......&7<!...Wu._.]...d..7....D..s..X.(D^.).|/_...:..1~..X
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.810473385384848
                                                      Encrypted:false
                                                      SSDEEP:24:6TiosNgIhvRMDEMroSW+sTFKWeM4/7/kCMn8XnrOFUPGZZR4sXO99Pk:6Ty/6powyFMM4D1M8XnrOFwkDc9Pk
                                                      MD5:0A83D08056B9FC7E37761B885ADA2B7C
                                                      SHA1:BB0A48223A3243F588860B09DAEBEB1758534528
                                                      SHA-256:0FD4302789CA796F28F648D750A382738571EE54AE461B3B0807469D394921E1
                                                      SHA-512:E67262AFB213B5DF0A181E09FD35E0A846CC82437378CA5B2FC678E6362A40C1E6D34D7334C97E99A3B655B1191C20BC755C6B4146519158D727F35E4FAE7F83
                                                      Malicious:false
                                                      Preview:...u..<#-...........v..t....eI..3.....X5{....q.A.ys.FJ].e....){...D..I?.&..{...lJ...K.g.!....1x..RG..(m6.`.&.a.?.Q..E+.e+..|...8.S.)....Fjf8.de.EY..c.Gxcv....-.Jq......t.[....~.....QF........\....p.+.&......XfUQ .+e,/.5l...b.....:c....V;..i6;.`..h.h.d.i...k...8.M.......!.g.n..K.Y.....*.......X...b<J.v....,q.g^Kk.......f.1;..<..c...Se.....nNH....@?...F..*$.>S..Q...d..o.{...".8qv.j..#nk.c_.6..SyZI..I....6Wqh..'.Sb....OQ.I.;.JwRA....kb.Nw..*T...C..;...c.?{..r.1.aP.....g...+UJ=.e............:'@%-i...D.....Z.nU.#:........e...a....G.zzP..".C...$#z.&.2.".....~.8.n.....v..O*.;...I....0.Z#....O...f.......CXKm.n.J....Em...0.=...&..C..+.^.ku.".1......,.yd..3...5...7L./.V.T...i.Q......p..y....R.i.52.jk.Y.w.XT..(.D.....?..^...t<.B.s.O....i.x.($...B...{x..Vj3.F.W.. **i..PL....<.*lo6h.0..K...$G`...;C.....H .A^..Y.{....xY.D7B....f...3.....HeP...S.f.....TE2.9.u.nU.B.....?k\.1.U..-..Rd...X..5\.|...>.....D.,`..F_.Us.....Q....y.k..."u........IM.T....
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.813641977638775
                                                      Encrypted:false
                                                      SSDEEP:24:4amUgLyYURRw5gql58ZHr8tCKDgp7u9fyDhQ:4amUgLu6Di8t9NfQO
                                                      MD5:1F8F17E91FB04BA1B2DAB57036801E57
                                                      SHA1:F813E5FBC8F161DFAFE9CC529B209DE244798688
                                                      SHA-256:0BCE358EBDFE8D92181C0215479219BCF680463BED03F684734D72206C512480
                                                      SHA-512:69D2926AE7FDCACD91B0CF23DC3C93FFA293318F9EFA9CDC85CD9F632F70AE43B6880A33986A606895590FFC2F92168F350081CCEB6790368105F22639029D1F
                                                      Malicious:false
                                                      Preview:5"M.(..H.I..0...ki/...X..i...w.O.R...2.....a.c2...S.U.../..j(.CK..s}h..\..<...D;........#...v4.%pKUu...e.q.9.....5..8)......v.2....?.'a..2q>#...2..I;...>...Y.sV..........mt....Iu......8.z.G.A(..K*......L..pxOs..h.#...>.U.EI.4.."...n]I.\z.\..h.F........I......<..]a....D....?J..Ct....O?..|wD......DH.<. ...6:a.[..\o._'.*.Nt`..0..S..Z.3.$=X....l......p..<...E.v..c..a/.=.....2.n..N^uuV...0...,.HR>.s......>Q$..6.n.+,... .b....~..C..^&D..,..<..,,...2...30.]..)':.4.>.P.aR...FW..%..P.(....Ng......).`..o......[s.\'.....I..0..TQ..'..s..1:...6.....\.."....Fv...@s7.P|.vn..LI3}W.......w*a.N.M.....S...5...T..g....rI..P..6....H..K.....&q"P>=U.......=.#.2...q....H...c......<R...:..kD...o.J.=$Sa*.....?..^acZ/....k..-..%..\;k7.".......*.wvQmc2.."......K....Q....~..N2....}....5.;.T......T./....x.......d..!.og*]..B....Y_..?=[..X..3.p.[......{[\.?:..MW.O.C.....!.R....0......Vo..kb....t`g....y...D..<........`,$.......yH....FJ._.R..J....4....>........s.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.819532918322578
                                                      Encrypted:false
                                                      SSDEEP:24:7EWArNP6HlAw4ulSpxWYz1NyqbI1wfL3eHrTaUrIZ3Fp68KX/UVizp2:7nClGluxzaqE1Ag9UZ3368KvUIk
                                                      MD5:889970D20C38506CB632BC090C9C9BE2
                                                      SHA1:3188B2720EEA5B96D73328EB5875A66F876E76E0
                                                      SHA-256:655C27953F82AD5035F5FB5F0E79E768A6BABB64E66B6A8AD1B9E2D142BC3981
                                                      SHA-512:A2544EB1D249DB0A6534C15AC6EBCC92615CEC1CD2B2FD856C002BD29FF4133AC6E9F002670209AF5AF2441E4CCFFA49703E51285713B249B3341A58518BACA9
                                                      Malicious:false
                                                      Preview:*`..=W....b4I.......x...}...+3.<+.c.11...H.fgF...C.H.......BL.;>e........I-......kN..d.....3..%...b/1....Z..T.* %Q..<.!...c..Q..F.....6..<:..A.....Z.`,..?9...0.8T..A5.r4.p].):........bIG..;....t...%lh'....s.j[..\}!.u.s(.,T..%....9.s....$...m.yU .3..../.l..5....p...R.{.,/.}.gp.K..w..&.A.j....?O~....(.:..m.Xx..sB......Dp.d...y..,..K...t....D`^.A..TXg1.L..0.... ...N.').G.5...:....E...\f.7..'..V.*..`tj/.'....(.A.Y.3.;."."..(!v.C)...r...w^.~1H.....K.uU.(.....~....]......5[.N..`....9j..R.3.....,w^.....'.0..........n.f...f....Ke.!o.V..U.~.6..PM..6..p...Y.H...~.b..7....$...2......93...../....N..I.W.....W"?E.?...':L..'[...v....e4#5.j.y....m}m..1.Rx..t].2<d.c)....7F......J.K..a.R9..."c G.......)....&..7..e...i.($9..mMj..@...q+.'1...Rg..\. .......v.~m..2.z.{@.r...Po_......k..)3.,fh...VX.N..D...)......D....*.......2.yU)..G9RX#...%}2..$.2S1......`c.>mX..9.K]..'.v..O.J.@<`s...A.L..D.j.....2..-O.7.8.4.u.......w...*~...3c!.1......]p?.d..)..."._>o..|#..
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.831493138573924
                                                      Encrypted:false
                                                      SSDEEP:24:NFdWvqieqa5tNERYVMYwku3xCNXVQND/Y:F0/ogkMYNuYhmM
                                                      MD5:14A80476AA53BC513B7D5204B494E414
                                                      SHA1:021FFF9D1A98DB83B9F96894FD08E39E33B7C7C3
                                                      SHA-256:F50F24D19F4AE3B0E62A599752B183FCCA37A22994985C1213C5D9036C711F4A
                                                      SHA-512:02517B9722124D3AD22B9AF230229CECB033A694799B23F7544BAF31CA16147CBF8AE880671DD9D1512E56841495CA06C2C9CF20611C9B6378F0BAF030615944
                                                      Malicious:false
                                                      Preview:.?..d.(.Q...s.L...-!0.8?n.5...n......)..I....-....z.V,.%..y.....qLC.$.....St...6*...b.V..,W....j.#..sP.z.8.....D...NI...Q....}8...@5_....P..w....T.R ...].'8...<.jO..*.T.a...%5M.K .,...l..4......T.;.z...tr..#..<..^..a."z.&..&.../..@6..|..9.....}M...f.... "5NT]....=Bx..?Rx...Jk...LW.....LPa)....V.b..+....J.+.....$p3.....)..F.f7..P..4..#=...5s..8.......Z.k..e.I...Hg!.....1.. .&w.u...o?..].G.e".o.L.tb&...L`..........g..d'....X......n...R.;.m..-.[]....._.s......\......fV.io*a.}g..hh.........:5..d........NI.EH1.6..P....~..a...+.G...5.I.j..F,..h....Z7..I.c./.HB..:.._..C...kJ.. V@l.C.2@5.A.?...{.b...4..u.sQ....d..4.+.k.....z...u....^.....~......8M].5"U.6.......c.>.t..r&..vm.......4.....]}.....HDC....|..#V.1..0...xP...k....HV"..-;._..n.f.M...p|...F9......C.LpE..>bD..B......._wB.(q].P..!...k.V2.T .4...=..6....(....)....W.<B*.e.4}4#.H..=!.R6.!...z0.....A.8."....o..^.RU..V..T.Q....'.".^...Ynr].=2Bk=N.l...IcQ._#/.}..h.c..sh.......< ....B.-.)E.....
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.803761233315607
                                                      Encrypted:false
                                                      SSDEEP:24:XiVG/e2uWGr7Ou5qt+ppYuv55X3jByMlBvqiTvliJ/J3f0s:SVGx+HItE2AXjBpBSihiBJ35
                                                      MD5:E585FEE480C3D4E236808708E510A77F
                                                      SHA1:E564E25E14EF165DF7BC22E6BFDB28CAF9158D6C
                                                      SHA-256:6E1F4308BC744C90C1BAB87A788CB68BA076E246491F412D518A86D2A80F7982
                                                      SHA-512:8048F38AA0562B7FE08F87FB68310E83F19772DD99FF1C7714FCEDA881E42F1EAFE3D8059E92DFF65EA70838450E0C4747C39D43DAC6AEEB10940038632ECEA0
                                                      Malicious:false
                                                      Preview:.b.!..>bs........=.....u/......=N..].mX...PFJm....$n%rn.1.......*)..&.1...W@CF..%.T%O...$.p9..v1.*..=.+k......."...z.[.F.../....)........y.>C..D..W].@...d..@.j&..%......IU..*.".G.^1!;.....5.SJ.fs..R.].D.!.....n. ./.....q\.m..(.C..o...../".....O?q.==.wQ.....y...u!..i...c1)P.K.t...%...........}.S,....y83...e.......n....]..S?...........Eq...u.G.cY.H!.n..s@..bD.T...........B.1...\..|[n?...,a.0.....D!....a.....C....;.x..V....D$..S.)Q...,cm..7...m.o.2.8..^.......?vK2...y.'|.G1.....{h..M...51....:..l@>.K._...aT.v..d.........R.*..o..4..r<....V........?p........R...m...4|=r...g.(.Ik.X.S.kb....e......L...o...b.`.....&...v.V..".>i.$....T.....a...H@.<..x..$..}..R..d*......A......@.f....b.Z..a..O.+~..}.V.....,...b......dD..@6.s.........h.<2.md.v..;.Yq.+".C}..L$...QEL.uP...u..q......."!...m\i...Z.2.k*`.V.0..^.u.. D..sT*..K.y..5..>..W.....sD+2.v.z....51....R.........H..&8=.q):.6d..r.?.............r....%.m../...=*=*..z..D.jp.l.z.`......./......r\M..d)}.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.807642973819652
                                                      Encrypted:false
                                                      SSDEEP:24:Tf8PJcgli9kx2q32iHw4TYtO6KBTNW6LU/qWqSY:z+JLl7kQ20w4GKNNltgY
                                                      MD5:B273A2361F93D42B13768E5446DAF380
                                                      SHA1:34DA3D463C516F9FDB44F4E22CA184699D1800D0
                                                      SHA-256:9FFBDF2FF746905FE02945ED335B71B0ED16251276EBA6D78F81D241DD1FDFB9
                                                      SHA-512:FC1414E4A3BEB5374984E89E8AA904B9E25FABE77E9C20194BC074ED4018831685073D2FCC783283BD349707B7D391E7672DDCD99FDD6C8C51E1B5C9D622EB64
                                                      Malicious:false
                                                      Preview:|.Ju)h.ij......7!Q.V...l........<.....O9zd....$..9...$<.q*..Z.u.+...fY...ia....'R.........O#5...=v.$K.^]m3.O.O.r.2..JBH==.^...\..hV_...0..r`A....h..].....[...b.....z:?#Z.fn..`.....Et.r.6...+KFp..y/I1.al#....4..@G$.O.........~...c.e.om.W....H91.7..I.....>.X.AV0.....%q|...r,...u.....[A.%..d.=.1.j0\..q.|..u..>....3.R.....:^.. B..[.^2ar..}k.r....75 ....o.Z.p.R...~..y...A.b.Bb.>..s..:Q>.....L.7M.b.#.g..0.U`.L.;.r.6..GD......O8....bn.7:2...|..x(.\..N.e..&I..A....q\.5......... 1..x$.J..q9.~..k.I._..n...8.......s..5.o.......~!.+.......C.B..........og..a1..M....#.b...[ZVz.fU+TC.H@..S.<....%.M.....s.4..]:.E..L..H.d..a......l..AT}3_~..`.R.z._.....U.{.b.......t..3o.t..3.>X......;..B.%...Q1...s......r.7....qb..x.N..1.pAg..p...!.{D.Sl.....>...E.q/........."..WCs.X.........V..........P..I.....J`...Va..oL.... ^.y.+..;W..B2*z....C.c...C..,RF....>|..(..i.c.B5....3]..>;Y.I2$.q[.;...^...z.O.4...e....E%.<.l.1+.3hj....(A#..$p .n=.....>.K...e....../.&0..
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:OpenPGP Public Key
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.84706288034368
                                                      Encrypted:false
                                                      SSDEEP:24:gGexX7faE6HGRurlUlWL1hwUW+BIwiGbdTTG5fiEnj:gGIX7XiG4rlAWL1hwtCgGbdT8fiI
                                                      MD5:B33AE15AE6A1AEE098B7AF87254DA33F
                                                      SHA1:423F095BE28CE14607E7A8FFAEFB590D2D01D267
                                                      SHA-256:401F8A56464E3BA804080FAD23974B2D3D655B97A8862CBE6FB37A56AF9EC8AD
                                                      SHA-512:91A878B5D3B4B885F14B79C6E21AFC36CE5EDE0E4EA889CC50A12C671E496CB4304EBAD51D6A6BDC0F89C9CD74DCD13FCAB90E4B0E7B4889D1443E6B5B7B54BF
                                                      Malicious:false
                                                      Preview:.....lq.i...1D.;..4...o...@K.r.$hC|qn'...)U.l0...}....:K....#.X.....J#Q....3..=.....n.DnT..{>.?@P..99..]...0D....:7..E./r.l.O......u....f....B.`......u{8!..X.v.Z..3O...txO.%...%..?....../.m..(..q.V..N.3U;?.V ]0..T.fr 9..p..2...`..S.....$.U9w(.ME.tz{.=JL.......k#..P..M....'...Z..Yb>...<"E:.l.@w......a...jm....U.?...'.......;!.R_2.2......4..`........(!/"..y..\.Xs....'.d.+...5...n(.......J........C44.DI..u[f.~....h].`%..3....."BM.........O....%....N([.ER..l..|..8....8..i+.OZ.......(.7c=.....P.`D....7n.T....I.....ee.A....|.B.o..q.m.V.l.'~...[.........t.."V.....N.}.p...I....4.P.(.}.f4.-4......1v.......A...........w....1..(<<.....(Z;..qv.I..p".....Z.0......C...vE@\....w'.....z.......P..^...Rq">k..[..-.i%.*.;..J..Y...kJ...{.+.$...U../.~.T.....,....../[G.x........ah......'5\.....e^...c..$.....,..GB....V%h.g.>m.b0.1...gGg*>l.9HO.`&......&.......x^...d..z.AX.:6>._H.....*h...j`.M...r.i.B.m;].._ .~Z.zcD..$.x!...(.1.]4...A.].......*2V...5..*..W..&.D.F..
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.817670076743921
                                                      Encrypted:false
                                                      SSDEEP:24:nmGyTb8IKSCWZ3ZrL86sfxEStWlptzQkgNQi8Lw:mGyT9gEZvJwL0RUYi6w
                                                      MD5:5AAEA6C42EB343071EA5924FDD328873
                                                      SHA1:A2DDDBCD5861D7E4793A4FF3959F5DB2AD3CAADD
                                                      SHA-256:143183C7985BE188E81CAB35F092FD35B7977233F8473188774A28B3AF178738
                                                      SHA-512:36516566771E1A83DA67477BCC587E686E3E817EA7B094062F82828BA82F492F8BC46ED5035262F3503EDF7530471A394BBE20D76428D775FDF505E419CA4099
                                                      Malicious:false
                                                      Preview:..\...C......#.....-.f..R...L.e.?.C.@...Y.m.&../O/.....7..H..E..\.6......@.X.4.(.......E....,3.,.._.F..t+. 3.D....K.+...s.mB...F.8..l.Eu..7|9..f....#cA5l."..f5.S].F...x.<49b.*.n#.y..7c..B.z^.*..r.P.M..N./............).ot%P.Z+A9T.P.(.v.Z.h.iea6zK8.:..q..g..T..o..=....N.9...w.Y..(...:.x.....v.M..6..S.w/.<.o..."...P.0Q."...(....?.4./.b.S!...s..._.na.1.GxT/.|....u.......6.Yl.@.W->.U.......5.f*.y..L..#.Kj...uG .Tr...E....^E.%..U..~]..MC...7b...U....w...p.}....E.~Y....aEG...e9. $......Cl^y.#h...G{.3.C;b.42O50.#_.yI/...\`.v......<.+nN.l..oL..IK..... s.Km.%.'..'.P.......t..N....".....~........gL.<....o.6.$.*..#*\rhL.gYW..A......d..\.5k0;....b....X...tU..T...3.._.....f....M5.t..od.:..K..#....9......|.l..h...0.'..u..5.Q..b..(|...o$.aCQ....m.K.|.;.M...g.ZvC9.r.?.V...."@.......vZ....9,.........g4k.X.p.\@._.x..2.wz.kI......b.R..]...J.G:...!....{....P...kd7-$,H... h.(.7YJ5.@.j.+..,.4.Y.T...f.......80...;.n$............/..`...o%......t..'
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.803194756226117
                                                      Encrypted:false
                                                      SSDEEP:24:rHR71og+E2hbGZ1JJ+Cs5lEkTEbL/Kx+veAjxawLKbl9:rHHo/lbK9ClZEbLCx+veAj8wyl9
                                                      MD5:92C528EDEB454DC4EF6E30C2E9BF7824
                                                      SHA1:A4D547D6665FDFEA765F68B296FE180420CC22F7
                                                      SHA-256:C7782CE9022F261517EA5F48E8C98959BB8C3CD2F8C4BDEC878888700DA58E79
                                                      SHA-512:67320457BAEE70D81B277349437B4F8B337662084E9B5C60C5CE1C8737F804E5BE93A7081DC222B749C0B1FF7A10785079FCE3511082D4630C05B0523C780918
                                                      Malicious:false
                                                      Preview:....-Bfm......X.;xpi........ur....?..z..1.`.....=.........2.B...O.....6......r..I.]......u.X6..(m.%..w....;^..b...o1x*.~.(..p..15q..0.T..:..7$.*.eYO.?.....R....E.o..+.p`(..I<6_e.CX.......e.8...:..J...SyF....!a.........Xr.....h.b.8.7~....H.ZO'.es-...O-.D...u.5j..@....O[.j\.=..../...0...~.n.L.3.D.S.K.....E.....).ZC..._.fO.L..*.......j.Y9p...O...L7..o.x.E.V..........)..G{.....)......Y.0.|+]u..y)....(.e..t..u.#.\%]gWH....e..#...,^....e..L.^."._gW....F.`.X4L.3.gi.....#........8{.1o.n.u@...|....yO.....q.o.. .......C.#m..x_.q9O....!.C@.J.7*._.......F...0.vW..c..T%.7..R..J....f.u....'.bu&i.......[...7.).R....#O.*bw.O.S"9...BYE..0@......,..wSa..'..-|PW~...z.Y.@g3+...y.x8N...T.n......n|U..oZY....J.X.E7.p....J..D.wN0.=.$7.0R.5.9'`..-h....;.4-........."..O....dZ..s..$....)..}h.i;.naC.vcUw.o(.`..R.J+....7L...n...~*......C..+.B.+...-..t...o..?..e...xH.i*......0E..?....K.x...H.......k)ok..............I....l}&...aHl..>....:.718_.Fv..U..1.....\f.=%X/.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.816924222037612
                                                      Encrypted:false
                                                      SSDEEP:24:PhXIIbIK00hvc6S/enJ2de5x6Ll/+PBQfR7wE7CVEW:PhXII0K0smmJ2dsx6JsQyE7CVEW
                                                      MD5:5B67E7A06085AB1BE06C65678EEB03B5
                                                      SHA1:EA9C510DD1525209B57CFF5CEDB053C18A9E99C5
                                                      SHA-256:12484F57ED30C59154360398FDF79C02E6CFEC513AA5E97E5EAD9481BF883A67
                                                      SHA-512:014768E43AC18E05464E31ED84BD0527D1741AB45FC884FC542D82600E13B49398E82F5BC89A670E5072E1DE1AB7273B552D881C65375F0134AF2BBFC5A01452
                                                      Malicious:false
                                                      Preview:[f{...m.....s..Z.(.X...........\..^....{a.n.Vt...b$..<g.....:IV.,@....*...4...8..sS.......b.!.....jzh.O..2.DU:$.h...L....b.M.i.......w?H-..Kp^I.8..Je:w.....T...H-.mR...q.8Eb....3....>.k)...i..).....b.8...WD...X.W...}.5..{sKW...>..L.&.|E.yk....JUjy.}.i..5R..3.;.\~..M<?.q.%.It...bOI.._.<h$...B..@F.\..10...*q.......R..8?0.@n.......e.?6X(k...(.J.l\+...JbVh....24........D5.P.;...-...D.Q...o$.L.W.~-..F..;..".X...5...V#6|.^...S[...c[.s.....%'U.......^c6.A...p.n_..F..".oJD.R....Q.....'...<.8$.....3..d%....3..C>v.'v.5G.u2.].H.U.....+.C..;q...j..68g......)....1k..<...9.{r.."...|...T;...8F....{.....e....T..D.<..[.Mp.O....JIC.k...6...|..... 4.....y......|....f-........W.....%......K*,..G.......tzr.+!_.*.O.N."...Lu....Vo<...".....@.f$....]..WPD../C..P........!~.e..:7=xF.mh.p.I.}..LG...U8.....`....4"...IhN.=}.j..HDv..^.`.....h...W.E.3..-.....-}.;..?m..A.a-*.r.,...U}f>..<d.x.LcQ.H-.....V..............(-.5.......f...D..EH.w...T.....O..........0....V.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.8365131871839315
                                                      Encrypted:false
                                                      SSDEEP:24:8ckMXJjQpCCyKX7X1Ezr/KAOw6ifA2uWXG23NQX3VaHdq:hTwzu/KAoifAWZdcx
                                                      MD5:0C7CDFBE0B58755131CA56D87C01C639
                                                      SHA1:FE640726F4A1E0C2E38A816CCED39CF2D4D4C80D
                                                      SHA-256:C561F0FF0B0C0E66827A397345C8361AC1E85C29389E288CEB24BD56008050AF
                                                      SHA-512:8D0EE4E8734D7FFDFAED3E889B965DE6F8FA485FD4833D7E6840633CE7D2AC5D4FEA793478C0A34A1E0F65F7F367A2EE464CC931C6BE28EAFDEBD95F67CE43D2
                                                      Malicious:false
                                                      Preview:}O..'n.:...^.Z!...d.?.wG..a...=..f*u..'.a....N....suE...u)ReJ..+...]q........E$.s..0.B.....=..Y..5..U....P.=L.S..^&.~....._..(....+Ka<.k..(.J..bH:w...<J.6......./.X6.>..E02F.%...K.....E.`..z..+...K.........E.]...j...k.&.....J.1...v.m.N.a..o.N.f..IT..$o.$)..JD.%..%...W.........z..rK..T..z...'c...BC..G....H....Cz.^..]|..M.........O.`.0=9Y.-T..lo..........g-.:;$.;...h..y_..2.e;. .>...h....e;..P..o...E=...,%..tN......-.IiF....S.e..H..B.]..)m.o...b.7.!|...g.`.?...M.|.Q.o.].YI......f.,k.....k':....?..IN...}.)..#......K......s..nVy.....3.....d..q..G..ys.6....wj)...4..)..A.../..<......I...x.WW{..G:.I...........@J.A...&.).....C..b...C/.....2.t._...........W.`..Q.hNf....0.."......R.O]..WucN...>.}....0......@.rd.^......DR.(.t.t\'h...V..c..C.G.D{..#n..V..cl..R.V.2.7*[e..h..A....VP.D.B5.....B9~.....joN..C.D\...RX.L......M3^.%..\p.. ..m....1.V.}zp?L..R.*....Ie.8o.."O... &5...,.V..hH....&.oS....!VL.q.%..L`...^s.L.:s.....0h.o'...$.Q.9...9]R.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.8184428783675965
                                                      Encrypted:false
                                                      SSDEEP:24:ETKHOiNuyGzEalD9V0qHQ/3AB6c5iDkZOfJvZQBNs8frD50M66sF:ETKH9NpGYalRV0Qg3AN52kZkIs66MoF
                                                      MD5:FE3EBC24AE874EAA552BB5737417415C
                                                      SHA1:3ACF73107AA77A3291F0FE6FBE8004C5EEFE5FF0
                                                      SHA-256:3C6FF8F229487459ACEF7ED055F8E8CF33928EA74FF5CC792B38661A7D88599C
                                                      SHA-512:302530438017E5E5567EDAEAA84112302CE386B95AAC1326179E88BDD453AE1ECEFAEA52B5247E03CD8AF9C1AF6AFF0D9F686078ED9AA1BEB763E89235038303
                                                      Malicious:false
                                                      Preview:..x.,S...F..X.....O.a.AT...N8.,98!8.<....&L....J..U6hh..\#.v-..5.....NH.G...co....../.[.v..3.w.y.3._.e5.%........o......I.J.~b<...h)..J...L9^w."..o..z73.f?or...?..Z.W=.DO.l.sf..e[.<..r.C..b.u.m.h....2....!Rx.....`..zN....W...D..b..C.K..3..l#..%.]..gp&N./q3.I..*O......$.E.E.....b..E.u.n.L_.~.[{..R.B....+...s.S..%y..$.4.~."..#L.$.V...>..^...H.S.E1.>.=V..D...:.&c..n....}......=m..'..0..j..k<j..F..<K...........^......SSI..E.T..4....w...-<oPie.......\...a..Z_....}....2s.t..jJ_.\:...&.. S8fn2i...w........6f...K.y..T.A..v..9..i.a.h.;...3I..B.d}@..Pb..A...-S8.?B...y|.,.........S..../}..~.7..9.;5K..B..T......Gi2..#..=..A.smE...m..<..^&3.I.Y.pa...+.`+....%S.\...'I...B>.........6.......g...Re...E.......$o..........p(..c.p.l/),/.Xu......E./..n.2.pv.<..!.f......o....>3......n...#...Ha.E.8.%.\.kS.q....n. ..!.$..U+B..Sl..@.PjQ.....{'......>.{.\...gV.kW.kn..O.)pV......3.[.1.j.o...+._.V.pC;D4.Vp....N.m.......~RH.U...8v8Q}.dg.....(>.D.Qg...o.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.827603052995493
                                                      Encrypted:false
                                                      SSDEEP:24:FERADFVeSZ8aUVY6P8EetAk3F0xVMwFEQIprYLlwu95xYK5WIG1:G+Fqo6det5GGogEll3xbq
                                                      MD5:20DD8B101D62666CC239D8E7BB3FFC93
                                                      SHA1:557E904959739C72170140B5288C5C56969BB97F
                                                      SHA-256:6B157F03333DE874155A4CB17D724EE69827D8C0DA32B620CAFC69529E24A363
                                                      SHA-512:9F9CBFB6B25AF8E8EA75CBD0B1A487592E773107A2CB3F75C54471239CE87AE0C436E2C5D3F7F7819A21EBBD76F6434D3376E326F150FFCDB7D39114424DBB7D
                                                      Malicious:false
                                                      Preview:.@g~..|...x.h....1b<...Q.7...]^eM..D{.u.Q....0..7f......78....e}...l...A.r..........8"D..\..,..P....7'e..QA......~......1..TD.}..n_r...\L.Q..Kk..i.=.)....._.....J...I.X..@41..u...C=..h...Z....f..#P.K.b...7.~"..py..X.q.\...s.......i.8.&..Y..#..2......;G<...IL.K..5...A..*..m.m.7.C..v...}..<..f1...S..?...1g.sT..].|..s.;./..q..S..$5.W.._..\.n...,..X....5.D..<K.a.{.......A..;....-........k.zA.h@.F.&.$...kd..cM..Y>.+*..(....,.b+}R......:b@#.....BP....!..<S[T...Wm..F.......4..{............5.u=...<j83#...'..!1.....=4x\y9p....C..z.5Z.H&......F.@^:.TG..ED..].Q..=..%i2...'ww.w.V^).Izq.209$.b.&.-".!.gD5..g.l..G.C.......q..q........h..-..N.`..Pr7..F..E....#...6....|...g..g.L.Ls........+t.......$...J.7.9Ya..$....Q.g..d....?....W$....6&.!..4..H98...b.X.......2VR..M/i..P+.....%:.l>.4....i......c.......8...<...^..Nx..@.dFe..&n!.../o.^3O....c.*...k\.b.........P.|_.U..l..Y..Qr....{@..,.#Y....X.......G'Ty..C..Z.a............:.R.V..).XuH.v/ .3..K....
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.815149584842096
                                                      Encrypted:false
                                                      SSDEEP:24:I3EzXxiNEAbZDTA0OIQmByODxR1Ivm9CmUO:WEzsDZPpXQzOlR1+yUO
                                                      MD5:438CA24647DBC92FBBABD65F87189159
                                                      SHA1:0CC7E5EDA84D438945A42F31E906F81A00995479
                                                      SHA-256:370029DBDE15F2C283A01D345C575F0FAA1B486114C7EFCF047168463E082906
                                                      SHA-512:F549DC75734B73AAE0C02E1DAFEA1F1D6F3D6C446DF4894A812B7478B5CCC6431880E4D2E9DFE2EA19AE62CC950F9A02B9C00830045DA599B9A3FCCC7A99D48E
                                                      Malicious:false
                                                      Preview:;..+./.....V.H......... .f.;.J...jrV.....v.s`>..Bxch... .}N.......uk....h./..f..3Y..m...!.*.xr..Q.7...w......`4..HCmA.%....p..FpK..^=;....~^`....7.bbi8....3.vA.*..B..fN...9.~....?.P.h.1.-....L.TR]..y....w.@c....1.`.....?...j.;...u..........>...*a]iy]V.4.e......-.`...{cR....".M.%.*..../........\..;+......5.xT}...R........9.?T.=..Zl....../.53.....`.=@.@>....f,O...62iN.K.1 c..S.B;F..1.3..%<@... ...Ii%..)..H..R........r..b.f...C...&>.o..5m....1.V$..y..K...r.)..U#zb.....s.EUH....g:+X....6.........L;F..).ouU<v4)...-\#..6kl\...).v...Q.`.q1...h|"..K..5.^.0...V.Do...h...q!W..3...:.(le.`.........z.7[..i...;..L.$.1s E....L...I..n..c.6.Z.....Iu......eg.5bp...^M\&.W.E.m...k&,.(O.R....T....+.gp.~[.8\s.x...t.T..\.G.II...2..<.....}.[.7!..'_M..=G,..!'.V..*..Mf....z...=...K...x...z..,....j.4.1*?>v..|...ve.....k).VF.,..G].....)I^E.....K..0.w...=t`t. g.X...gCS....[..=...&.*b.A!'..yy.8j.b.B..D......#k...]=n..\l...yp.1\....v.O.:....l...Z....lW.8...Ly..
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.819259516901212
                                                      Encrypted:false
                                                      SSDEEP:24:LXUcV0GZsaduXCKaQBrxdape0VnANM5YA1QXDn2fq+:z10edaaQBrcCNM5Y3Tn2fq+
                                                      MD5:FB5F54653D99883293056126B73F6E19
                                                      SHA1:F60112B28A75BCD895EE1433875FE5AD603A75CA
                                                      SHA-256:205D8E477D0CAE9871D04E586A327A70316887E6656AA14B49D54719F303C295
                                                      SHA-512:FADEABEABC64BE1C0F7F00EDCCF625B9EE964C10D897265B83B2B16CADE36D280E6694203D23778A3A2608F1F9E84AFE2CECA5F0343574EBABE9423BB0942791
                                                      Malicious:false
                                                      Preview:.y>./"..dp..0..%.Q=..FE.dw.$..V..5.+.,.,f,...;^6...E.>.../.?i.@.+.z.K.............;X..S.P^.f.'.k..P<}J.&.D.I.....6. $..ko\....}FaB..!.4.O..).........1.m.....&...S.T.......iM...5..v..........c^7N..4..$Zi...K.-.6.t......s...C.B`.E"3....L.oa..:u.Y.&..ZF'.L..#....Jxf#.....4....@j..h.a.....?.j.S.........3MQ4...F?..Wt~..?7..bb#....6Y7VA...X.|l....Pp.]0N..y.....E7v..u...Q.m...5q..p:......;zN/..$.X.......t+T....>..qiq..I....T.S.-..H...l.....l.t.KW.4....v.6..97.....=i<..E.FG.8u...g5.F.Y..:[_..e..........j.=.>]b^...C....es....w~.-.0/...Z&.g....K.z.....).D......oo.T%.._B....h.j(6..@..:...+..W...R........X.@...6.Dl......<.<...&%.L...[.\Jg-Y3..Z.7b*F..PwQ.Qz...w...$.|.......[{.P?.......}iF..r.lr....[.F.vQ=.....M.....*.....5...H)^..`.....'.*[...{....Ci.m....%..X..t.].=.2.:.".../..?MU...9...pU...LP.l.p...8pNes....<...E$r.D.......O.G.;1.O1.3......X...>.(.....^QK..U..3w.....P.M.z..f!9..V{.-..x...0.9..m(H..f........|..B.|.]..c...%..j.3...5Eh+0A...i;$N0%o..z..K..
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:OpenPGP Secret Key
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.809077389543913
                                                      Encrypted:false
                                                      SSDEEP:24:1cIaTZec3K3KA9kkvXazR3gJ48gBV/+b3LFLEPVH5MZdc1Ncz2TyrZt:1cIaTZeciSkv8WNgBViLFLEPVZMZ8c2o
                                                      MD5:3D503886A300235637A62A5231D175B4
                                                      SHA1:F5162CAFDEFEB61A873E6DC79EC1E8C0701167F6
                                                      SHA-256:78715B87581048F1BFA11F0BD07DD88B8E671C2FE7BBB884E99D820F4A0DDB6D
                                                      SHA-512:C0BD93C82AE8BF97B46F8AD354F19FA63423B1615F4407FD0C936C2C0AAB4E0912C3F1C2D82172BC6C4730861D31E36B6DC691E0236C0817B49E8C7E41569984
                                                      Malicious:false
                                                      Preview:..8@=..[*...O5"9(.,B..*.!B".^(.Ukp3..22.o..q.xAD.I/_J....z.....<..D......\<.F..(.t.$L....3m.e..8.?/X.:...r.....$..,]%f9..h.N..A..&....cR.X.gg.gB.B..&.?oyj.~y(....F.pKE...F.....l........(.).xh."Ay...X.A..-+v..#q.7..g.C.[....<.eK.:,.... ..f4$.Y.Z...e&ki.xZ..KU.M.).P.....Sr6.V.#.A..........~{..o@....'.".&f.uo...Bo..\J7.../|.....%..v;.?.|_...\!....v|);*#%$..\....BU..l>.f..Hw.Y.="1*S...l........x.....E=(I....;.......!..y..`g..q.E....4../-Ed....fJ..'...V....a5.x.k|k.......5[...=...a,..$..cd.....DT.2s.mQ..<Okn.=.3...8 ...!..g|.|ai=....\.........W}r.m..LbV.;..<j.....{._$.p......@5..O..H.....F`<.. j.}.RTi..6="#H.! ...@{]....rV..[oq.Q.3n3.E".:\.x+....#.'.....-..!"[h..e7.S.,z..Q'...E....\.?./$..6....O........]b\78G..N.....E.#..M..J..(p=i.M.`...b.....%.hm .M.v.P..B1...S.....2.#...N..f..I...LDJ tB.d`y.Pt..l.i..O...Xx.GL..0..A...L|.W....M{A....P..T.9..WY....._nH..I...,.{.O.=.C.z.v.......k......B....F1i.....%.F..w..\...f.,...<...N\FH.t.<...\T....2...
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.830036907841302
                                                      Encrypted:false
                                                      SSDEEP:24:WzsdewmD7oz/BwCZt9dpodvQdBCHBt5tv9fjNz7tIwqenw2VLzWzGUZo:W2mD0DyCTEQdBCHVfhzhw/zGUe
                                                      MD5:768BBBC7360BBD80D0B1C20FAB42FE1F
                                                      SHA1:21BB10B9BDF754A3D184197988EB74F930A9DD49
                                                      SHA-256:D7C9D0E2250FA40FD745AE53A2EB3C1C7BC1A8CC39B0EFC5CF8E6DC1C903666B
                                                      SHA-512:82CD7A1476BD188C04A8D8E15806AC6C4F04D9B64EF63585695D5B84B3ADBC4BE25D2F793AC6CB39C3AB238FEDC8071F5BC01260CCE4FA6E3EB26D13ACDA1C95
                                                      Malicious:false
                                                      Preview:k. wAY4i\Z)./..U.g..k..._.i5;sw..mnXq.`....uG.z.A.%....b.W...d..}...7.g......]&..r.p&..4u....y..@..<.K].|..|.>.9:....$....DR...?.'.......R.S....D.....P...`.0..<.=......)>E......,.`V..Ql...f....z...t.Gjo.{...\.!..r=.e0R..."..V..}.?b%....m..g..A.7 .^.z.L.tD.....@.l.^..|.....6*.@~.yx...H.4D...AK.I.[.=.`X..E.`N~*f..CBS.0..^..@..Y.Rd..wF..@...m-.........Uj..CsG.%ZP.q+{R.4p.y........KL..G...S....N..:..'........:.K>.T1..........u..pr.A'v.V..K..hH.j"w.`W.).V...J.....<....AH~.1p2.....O.l.....4x.h.k.RE..A@.m.e]}.....~......w.Z.........:i._.E.g8aV....qq%%..i.;q=P#...jo.^.e..G.65`......X..-S...GB..iq.Rr.R....l....>@..[H..N.2.{....|..cd.`J....8]....>.......o.tk.Gf..n..,C.......e..`...)Y4...}. ..W.P.L......'.Q.c.].._.<..=...3y.]......]..u.S....r........."G.(7o...$-yA:9....|......NEi.{;..h.Z.[?.a..Z......Y.wc.....?..o.n.^...v;.6...@p...U.......H...v.[..$.n..>..(.x....O........* p8%l./.KRh.RS.........r0).......M...I<.v....up...E.c.4z.Q.9.[......
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:COM executable for DOS
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.813495794237703
                                                      Encrypted:false
                                                      SSDEEP:24:pGQwJA6hoZc+w1iKrKok+JdvVRLKPrYYc0Tkd6TBhSPaiDueq8fvn:pGQwJAeZZ1iKOokEdnMDc0+6thviDpqA
                                                      MD5:145418D1946FAE346D2CF97F052DC46B
                                                      SHA1:455187B0AE93E85E24056D1DA056D10F103D41D4
                                                      SHA-256:8D7FF0134CD9C658E4D8C006FBC6CEE094A75AFFCEBDA99DFFF29710AC19E42D
                                                      SHA-512:079984267114840EF372640ED90E70E2E8EB1124269480087A9A36DD7FE5E53B5E09B64044A566EB948EFA9622138214DB39270CA10540EF591B6F56E0728034
                                                      Malicious:true
                                                      Preview:.-=}..`aw\.....wfm'..{.:.5.....H.,..|...s...W. .t...c.?.L..i...../...`R.L.a\v,/..F..=...V....R...7..y.3......j.*......l`.....H.n.2..}..z0Q.Z..H.......p.....R.^.-.M..4k....].Q.k...W.8...M.Z..q......'....>J.#.....*3.A.I.*f...c.?Pa.B[m.t.O.wxU..v.E%.9P=B..<.. .m...1`..~.j...>......^...d...u.x%.H..x.*...b......Y.D..w...D.Fg@....3V..}.....l.%.?.A,..9..9*CG..#..8H..pk>......p.+.}..i.$bO.R..Uiyx.........`..h...{..Y..6....v.R..3...n..*y...W..@......1.<.$+v..M..]c.Q.B.&.z...kMd..x.......x....?`..H..0Er..M..<.7|....}w[.t.Syl...ba.1:.$..m.Q.....Op.s.Hc...4......-......N.2/.....N..U.\...Y3..7.h;.q.eC...Yk.X._.t........}..X.o.%~.....u..Q.i.) UV.R.........@Y..-M.j.....o.<...6%2..o0.>.N..4..qC.4.|..k....#..X..m......k..`.8t.b__.G.*.......iP....ii].}.....`}.8.^.#f.QB.5.xz...!..o..TW........xg..N.i.<j../.5.....)..g..].:C....k.{m..W.....z.=V.......U...j..|....=..; ;.Or......~N.....}..0.6...."`a...^l,......`.".E.Uq....v....@.r..?...Em... P..#@..a...Y
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.809289330857566
                                                      Encrypted:false
                                                      SSDEEP:24:rXgl3AYmrOO4ityVJIWnsbNC8munkib/NhXNTrOH:Elje3caYs0mHXNU
                                                      MD5:8E54FECF35FD5BFEAED951AC5D86C02B
                                                      SHA1:B22E4568687D004891FACA6692C134073ED419C7
                                                      SHA-256:F59FDF7276EC4F2CE4403F1542B8409898076BF9F27E7B2810B239E9CDD8B3B3
                                                      SHA-512:C7F8D29FF73775EBEB906AB6B1060ED6D9FCA6672C1D7344D2AF8F90A27BA31D06AC38AE319F86E05E2786D7B49977F1A6722F9DB6A56C8219C19EBCC455D0A7
                                                      Malicious:false
                                                      Preview:..bq...%a*......h......W...!A....:.]....,.J8.#.Z.. .h[...&..y...t.+`!xjj.......n.'<38.v-.5.`97c.S.^.`j@Z...<......-........]as.Eyi...L^RTYd*...0j.F7..0........O..}....s.=..+0.....?....E.*.b&..Xc......jy..^'.....Il..M....y..s.f;...!.....b.<.Ow.w.^!.........-rE......2%Z...7.....w.I..@..v...S..D..,.9....].[... .q./F...V.....U!.Z.pg"....+`c.V.o`.2X.lBV.a.u3.2j......y..x..9..U.j.I\Q.....#..Y?|..5..#/...\...'4.n4........g~.....~..>r..Tv....#.sM...G.....0p"]kkLT<....h..>..*..@Wj*.".@y..<....(C....I..j...D.....~.7.d.CeL..l.V..i........V..H./.*.B..s0..z...vrg*n..).j|....7....d..#..h 9N..f.........."..q@...i.....x.s.8..~.D.....rO..T....~....P..+^..(q.X#n..V..g^:....)$.$..wQ..n...{....C...k.0.R_.M...N.{UB...b...#S.MQ...*.5%.....l...58l?..}.L.....;.Vb;.j].$...|b..5!....4...h|.r.u..?R.....6......in..../p........r.Cp..y..09..p4.LRaDI...0.!.LB(....o...mibP....{n.o....S.(nJ.F.:......W...=P-.0a.....t.s..\.....B...{..h...N.UD.R..(...'T.....^h...y.<.ab.CB..
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.820603977558391
                                                      Encrypted:false
                                                      SSDEEP:24:gkDP7JYTfQylb/sOXVfmNAV9ph40vXVNEfjF:3D72cyVEEVuaphhXVNEfjF
                                                      MD5:0B17B5D7924795DEB73D3EF6F3E9CB70
                                                      SHA1:292B8347F4513C3E34185ABBBF441A4591F51DFC
                                                      SHA-256:F47FC1CF4219C5F933FB195CFE3950E25EC2DCE3008A554361E1988241DDAD43
                                                      SHA-512:25E079B66F81FACA3398AE5FE3AE18283DC61AB5495822A5F47333F58CD484E6FA3FD9F8E8BF9B153C4DF1218BE1FE28225490F470AB6EC85AD4A3D0C12BFDDF
                                                      Malicious:false
                                                      Preview:r.@`..7.r..[.$.f...i.^.vt.y..p*...}.vYO....G..8.....l...-D2..,*...Z....r....C......`.......v.=H..}.O.2..k.9...x.a.....1.......}Nv....?.._3/?...-B..2.<&..FK.&.m.q.m.j..o'K..Q...B`v..\:......b.....,R.v.N`....:...^.J..~..}....Y....) D.,./../.D.....^x.............!..e.z..$j;.....-.....q.^.,..%...-..q':.p.dzz~.3...`..*R.l....m.....+.U^....<G._.J).........o-d.... .%.2z...6. .g(.H..g......w:..........y.|.rX@.YxL..IB..2+.a.L7x..-....[.V\.e..U..j.......(..c..D\.p....s...Z.;....-...{?!!..G..."Y.j.8..RC.s%..m=/[K......*..z..8.B|:..>.........i&._.O..c..A........{...g..~........}..Wl.q.K.7.I..`...Ap@...B...R9.#=..I.Wg..._].N...1u..29.jjn..U.....X\`..(...X."...o..B...k....l,v..H&'n...E.b[....H.'A..$..-.....lt..5...".r+...q."8gT.Byh{"..mN..(.8%...[..o.....e;.B........S..Um...,.t.R5......._....!..h..5<g.k.89.W.&...}.8.3+....>....E.J...z..*.=..Y.$!..=..QS.}.....k.h\.37....f....K_f>BpR...............J...s...ZHm5.7NZg.v.\@._..........C../y.8$.r=...is7.|..y>.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.781069475573988
                                                      Encrypted:false
                                                      SSDEEP:24:1VS7YFmCfQ2E0hUYJKlFNalTQn8ktgsZViwh5SHLX0E9Nrx7jKLz0:nrmCNE0h/rTQn8ktgTwhOwE9z6/0
                                                      MD5:9C2683F84E85F0025B9975A94F1EBA81
                                                      SHA1:DA522A08C3C39CD25FC06BCA72E78CA9BF57D929
                                                      SHA-256:57A48D48FF3F1127C9D5A9EEEC8FEB996F0EC9DF541ED8A36BA1E80018C0A678
                                                      SHA-512:F272B21A95091DF267C0E2E4736789FF99A83E436701A563B675956E11BAD06FE01B00138D4CFE3AA9C6297350EF86A4A5F4C030A01C9FB50C1C99FF84B51747
                                                      Malicious:false
                                                      Preview:lC...).%]...........,D..d..3s..j<.5.}...~...e{B...6.:.."-./.g....U.rA..a.%S.2...........@r..b......-..8...n".)..`..8.0.^<...I.....y..H...._...|U..l..]..;........<...y{....@.q..B.`.gT.1.0".....o.*%F....m(.......sE...m_.+.D.q.....lq..+9.t......,.[.Fx.....t...........(.7}.f6.P6............k..u...0E.._wV.f......I..|.e..D'...TG.C....`.Z..bm|GfC......o.kX...n..a2.#....!...!9F]"a.[..r.'&......y...4.3.p.RU..mu....../e..+...%.......l.......l0X.o...e.."._....r[.6.`o.MT.q..<.}.......Q...i.}.+I.W.O.u...S!nDg.".....|.Z4F.:..j..]..L.w..X.Y.*...p.&.......T...DGIc..v5Q..d...w.|......a.....K.B..7....o..}..>.%_L...f.PX.d.w.\...}x..&4.N.9K...........p.5w.d...7.q^..7.....{.2...\.....X........Qs.,D:.7..r....,.Y..Y....e..KA.....z....O..".:.H..9......!.~..........L.\.......Fp1.}....I.s....c.X..w..f.e:.o.}..+...t.|\.]T.......)..L(.B..\....:?.....)L.j.....s.X....%.s..$......tS..ZKkP...W...wZ...k.....]..c...x,gP.....u....D..:..,..q.lB....qf........e.E......Mq.....
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.805430836436896
                                                      Encrypted:false
                                                      SSDEEP:12:E6CLkdEZZ8oSyZMZMukQcYFAf8Q8scSbrtJmZzVKURePH3nkaCQloihoQMLC/j+Z:VCLEUvvH1JmhV9RePXnk78ZMLUYfR9
                                                      MD5:091DF7A5876B7E9134657150FD5BBDF5
                                                      SHA1:3CFEC0C1D04934DD803383657075D7FAC53C70BA
                                                      SHA-256:379DFE8B016E4A17F7F213AE7D6769F746208A8387F921E8EE595BB9EBBFB4A5
                                                      SHA-512:AF69B41D1B362217CDE3CB792FD79B6B495F4456AF1B4F298BEF7988C3696997CD67B7991398BFD02F3155FB0BF06D08710EFE772D7924FF4C9B51C8C47A2F58
                                                      Malicious:false
                                                      Preview:0..$.90.S.,.c........".".......7;..HD.....4....-...}.L..Jo..p......Wi.0..H`..O.....L .v7.R.#I5a.j.....A....$ .......3..,`<$"...b..N..w2R.e..1B./O.....1.i..%}........G..t...!H......[........2...W...P..$..?........".J..A.....{.@.9./...v.A.....v De...8U.K.HzMW...WqR{O.;(.6.'... Q.....Mq....d.?....]S...L..YUx..}.5...|.......}zr.S.....u*.&=.s..s... ?DT...J./.....d..P.6...:+....F"..J.L....mHt&.x.\.....]..6..7.Y.>.qT.r)~.+..5...l._i.j..d... ...V0...@..........=........$.@.W.}N..h\..!9o.R..4...8.@...,..w.p..`G\...KR.........#].....n;.|....qD...x.U....%..4.?Y.?2.Q.r.....Vx.z...(.>s......Y..b.,qvC3..)zix....z...t.Q.8p.U)...[D.../ZI.9.xt.@.;!!A.....H.)...d...g...TFe*..+...o...6k.X.......@...................&3(....I;.%.}5Q.M.J.0.@..P.+...=....L.6...v..0...S...p .U..xT.."......_...#.....%1"[.G.9:.. .T.@...?...C.hb.D.....S=F2...Ks...f.).|.w...[..Y.<..De..^6y.........W..>s.......B.......Z......."I....U.....t...J@..s..#.f...!m.^...=..Y.+`....|\.f
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.8301503309188005
                                                      Encrypted:false
                                                      SSDEEP:24:LVmjuVF7lQBbQGmf4uE2dTy7adgfAG7x3N7bohROXvtPju:p2w7yGHf9g7MG7xJV/4
                                                      MD5:CABF6A2E6DD01B70492DEA124807BF32
                                                      SHA1:BC45569021CCBDC4C1E2FDE98838A7B1F6573C49
                                                      SHA-256:37C156C4CDE40AFA248C4911CAF4E73340013EC85DC54623D6D6FAF4F822EDCF
                                                      SHA-512:DF328B4CFBA1D5F4EA2D3D5901AA96CB9C7F7A599E059C3D8652955FF6664093CA20125E45CE95BF39246FAD8A0A4E3BE6DE9FF8C19857045749E0F9FB03166C
                                                      Malicious:false
                                                      Preview:..J.......~.....N.*3d.6....y.....:R.-.F..w~7.2..f....Y...t.5.H.SS...e..m..U.......VA..1s.^.<V..Cc...s...$wgL.v.k.b.2...E.z......A.....Tw...B......Lymj.......gel=)i.^nj.....|6..G.h......fr...~.......?...Qr\.........Z..".........N..u..8..Yo...z..7.H....y...A.T.?..H..R.......w.E/.d.w.w?.h.3..N..z.!H. a!rM.I..H.X.t.>.R"..;.cMT &.>8....>..h*..p....o..o..T):./.:..M.pN.S...}.^........P..=6D...9Oz...RI....?$.x.}[o...R.8...w...4u..........%e...."'i..".../........Bg..F.yO...8s.5.Qse..z..F.n...1........{.......@.M.?._.F.R|}..D..o.cs.......C+...p..:......u..g97E........^,!.02.-[..~/.....^.T.C.....@....7....GY9.....r.+..p.-K..m7y..5.":Xf].V./..p....|`.4U.G.Zr.........Sp#..w.M.Z...'.,o.p^.F.8.$u5..*.....N..W.xx....S...1}..|=.]s.....=...".IEs..Z9.|..O9J4..Ifh.mp..m..g1fiA......g5.%.]....@...N.K.4...gd.5J>....s...T.4!...).M....}?\.....t.N.W..T.....ag..h..t.......^.....j.........EJ..........%..0N.v.'..W..W..&...........p...........[...jF.g.\......o.{..~
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.800000933156506
                                                      Encrypted:false
                                                      SSDEEP:24:eyxoq/9DlLnjJ13p3WRSqpyZr51ZBit4nx7zVh562VdyO0kyh:eyxoq1JLnN131W9pyZrNoOxVho2ykyh
                                                      MD5:417BF690964938D1E7EEEE84846DB8D4
                                                      SHA1:1D8FA52DA29569E99B1E37179B09A94088CF542D
                                                      SHA-256:F615B3FABA1FB8C3D7A9D56F33A67E59E428A8C901E499CC6D19D162818EE219
                                                      SHA-512:56F847E73EB3895AAE49AFAF9DA62D6FE2C37AEDA442C4A630C34EE2597432ACE9B2341268FD89D416B3ABD88BEEE48E60D8D8E3B6961BE9B610383228BE4AF3
                                                      Malicious:false
                                                      Preview:`>Zv..\-D.2..S.3'{.U...'......u.>......$...k....GY.;...b_..Wzi...x`.%....I...*.f'......S..!...MO..,r}..........?:..]....8....H...h.5R..h<.>x.......KS.7.&....<...)J.9\,.wo..]."Q.G..5._|..pq.3......^.lWK){...I.(...|.}.'()|tK`B.C..?..._......[..|..%.t..6..GR..].BU..2....}..xq......i.P....^...,,.....N..=&@....P_au\...48.V..D..o....4....TG....QN].H......b.m.......DKo.[{).........l..|.C.n.D..*...h..g.....#Bm^.`,....[........bH......N.6.x{.g...c..3..2.3.........M"..x...~fM...c.#.v...l=.6......G .Q..FQ.......2<....T..9Bv.....X..z..G%*....*..b......*....x..?"S......:#..;.Ky..o...`..... ..].'..A.....s.{-..+Z.@..P....'v.bK...}..l1..%!]W.g.'.c...\9o.U^(v!.cM.....5...<S..5yr.m9..._.{...Xf.{.b.yA z.I...i.......?....4+.zs.B.s:....G.;,...X.y.|'.......B..~.9.?.5CH.....Db...e.i......k.^m#......?.Q.[.c.cx^........>...2D..F.@.(v3...m...u..2...1.........vU....s=....%.4'..#%.=..b.>.bH^.>Wa...U;.C..../.}eF.>......."..0...P`..%........HV).g....E
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.779474588765354
                                                      Encrypted:false
                                                      SSDEEP:24:8Gg+iO31DC85H2pOeNm1o27rvso+OWR1nJLVl+oZVzlovXYv+:IO31W85huo9rvWOWRxht2fN
                                                      MD5:07BFCECD85606088049049CD0DDFFEBE
                                                      SHA1:0FCE5990C1B409B6E691AE620DAC51184A4B3328
                                                      SHA-256:EEF31FACC957E53CDBB4E2363F956B4715CDFD7803DD7EEB9DCBC77C1B050567
                                                      SHA-512:25F4A34477D377FCBDBD0AFAEE2C5CACFCD19A20FB1E2653F44212A49ABE911960F14BF11D273FF01665089C2ECD6F3001153769BF2F9B52FFA1DEBD1F631520
                                                      Malicious:false
                                                      Preview:.n|f..a.l.;.).I.Q.^.Q. 9..l"..I.,.......?..nd.b..\u#cr|4..'.[Zo.q u.Lw....i..Z..6...V.Y......C....g.^.Q.Yt....+-.[J.....t..?..H....>.\8C;W...8......YQn.b...V....q.:*..%.V&0...9..p(...xd.9..'3.Z.i..7@.~Q!..f....../&1......."..U......2.l3.G..A.~..A..AXO..}/"..}M?...8.9CAu.....77..or.O...c...7x.G.......e.3.n..Oc..Z..Ax*.........s..\!;......BRt.o....Qf..~.....L..;.....5#.Jhp.+..u.Y..'....3sv.7.7tc..E.)........5v......,...@..wG4.U{?e...{Xe..[.....l.......4.~..C".'.S.?.....i.s.z`"....v7.+...-l.S.-..O\..$.W..J...xf.i..- /.r...3.g...e.....85._X.....O.6g..(...~v.Zk.?.A.{.j..D.AR,-.I.o....u...09.j".#.1..k.Rb..a.I.k..m?.../..O[}...w..z.0..Hi.._......)d.......7%~01.a..n.,y..3.gQ...l.1.P...lX...u.o.#6.....VU..y.o....)i`..wu.#.;....4.9C0stF...f......mc..].}........y....V.]IBh..kR..c^.7.Y@..q.D...F\...f.W..|j.E0..e.S.N.....&X7......9...UJ.r.q..z}..I.............,!1".f.].....D.D.:.e.#.c.|.e....=......mu.k.,.....Dn.k.9...XD..r.V.K...~..6.7......f..(..d..$..1
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.771863276547537
                                                      Encrypted:false
                                                      SSDEEP:24:8ZN5Fr9rUsqlua7hbo1nGq5rIZRImKwvd4VJU5vrq8rI:8ZNRgsg97jIdJz
                                                      MD5:CAF1A9B6624D2F1893737194E135615C
                                                      SHA1:8FB9916D59D1B0367805DF26BE46D1C7B74E9AB2
                                                      SHA-256:99CE521468797CE477A21DAF990AC63B6F86CA8B83948BA249DD18967B1C566C
                                                      SHA-512:582E348C317040BBF9F053BC0039CE5B0080FD63C7D757868A1307EC14EBBCF280A83C446252030FB46197A1F1817CB4593AE298B1BC252A1065904D6C3128D1
                                                      Malicious:false
                                                      Preview:R[.cB..v..p...y..p8..S..E>|t].\.6.....gV@.px~...g_q.3. ....Tl..mk.kF.\I.md..\.8Q2..Y..S{.~..*b....._...,..o.b...~M..T.P...*....v.=..8..ofD.3i=..H.6..M.f...)f.8..o..Z...e../BmS.......Z..bT.M...~f.F.ZL.tF.]....v.Z.l..t.<q....,p.r.@.[.d.5g.!(...Pt!(....%.?.itP..#x.?p....T..,.2..l.F.....S.._.g..b.B75m..@.<.E.,~d..|.>..+....s(..n4P.T....]X...cr.....9f....~.....W...5.n*.....*r?..0..&.|..XS}..q.]...L....d...v.b^c.a..7.......G....!G*0.b<..Z..z5..0&PQ.Zb.!...(P..T......n.-[.9[..%.p.2......3..6_.px...l.O.4<..g..,..m.j....L.`b5.4..<>..E..4.`F>t...~....t....fD..Y8D..gH.~.Qsx.S.gIj.,.1..!.....174;.. ..~.P..Qo..U..........d...h..RU~...W.'S5.....p...-..P.f....5.....5..B....wu.w.&z.F.G.)x...?...d...0...^....U..Q?I...S..<(...;...o.x..@=..1.z.l..Ba.....:B...d..B......0....!.-.j.n..m1n....j....Z........".j.[..j...=.........s...G......TH.i.I...Ly.X.i[.Y...Q.e.....8..(..M...].t.w....3...30..@{.,...2I..C..zL.(...Q...T]..P...(.......Y..9a}.M=....Of.H.>.....
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:OpenPGP Public Key
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.8148078581091145
                                                      Encrypted:false
                                                      SSDEEP:24:7iP00xcG2l0FyeNTv734QKr9U27Tua1D7b:7m00xw2FxNTTojUEPd7b
                                                      MD5:D162F1229732AD1E0755B88211BAC96B
                                                      SHA1:3590D453BC5E933E23F65F61045A098D06A1FAF1
                                                      SHA-256:9F2820C4D9B97EC64B973B01B69D319D0412D3BAE14F4FC8A308EB05C264AF1A
                                                      SHA-512:7A2C9D5CF15D635E52DFB2EF37F3B6AF3F80C24FD574B42464DC268DA49AFCD419A18E07484C282A300F5783CC876B937D18168E28230E2749E4FFF9422DE176
                                                      Malicious:false
                                                      Preview:.. .......Y.....I`Q0..(.E..)C..R.Q...I.Kwr...V.V..~....].!6.....j.gQd..g.Y.......:......u;.E.O.....svn.....Z.......&.s...t:.D.`p..3.S..G.......PpZ..7c.'.&...9{...j.-z.<.H3..z.5{....v...@..U.....#.IX...4......9.#}.,(."E..t.^.*E7.R.r..3s..f.kH-.].a&.s.]...xV!..i.}.....+W.yd3......r..1..>B....\.).}...\h.. .:.......[k..W#.D....1...`E.....V2...TV.!b$.?...`...*RYv`.].........8.......-.....".I...l....]z*.*....u2.]......."....gR....C.....y.@.a.Z.........*4.R.?Cz.\.2../J......R).io..+~SRyP....u..T...[8.Aa{i.M...6......Z.M.......f.} .J.0G.i..gX~....7......rwt>..$..z..K7..,...O..bF&.j.8./-V.....(8.....;.R....hZ.C..3..s..O.>....6...|....n....E...G.W..L ...7a".k....^..T............Ee..<F...1...&< N....pxx..It.b.......?8....)t."..0..6.......#."|.*...m?.|W.&....J.4.....^.9a.y.F......c[)...g..H...<.{.&......'.._..Q...J. .....5...s.B\.b..@.5..6.E:.B...<{.'.%...O.l........GJ.V.U....{..9.=..>Oh_c..........X...(..5..J.....G...gn.B..*f..Pb.\.Y.z@z....$
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.806088560946787
                                                      Encrypted:false
                                                      SSDEEP:24:qi7EPEDRLeZPAcHmWW2gMfuPXq424EkCOLZun:icYZo8EgfuPXdBYn
                                                      MD5:E8835B5D8BDE058DC20C2D19886CC3D7
                                                      SHA1:F3A8A62C8DAE9382CABD42F3C94593BBDE04155B
                                                      SHA-256:F28816A9FCF5236909F775ABBCA8CC33621BFEC8C1A3FB71E06C71F3F43DC1E4
                                                      SHA-512:7964333E91FA6A8349E77F472A65320CFBC946EFF9FE47A692E0A0BDC041A5576812624D887C8732FEB0FB2267BFB59DB41335E29121402E430EED7D778E3A80
                                                      Malicious:false
                                                      Preview:A..,.?7l.. EBy.....uL.J......z.B.f..f.]...=p...]...FY......U......?. 3.P...).>Q"h.FQ.!.3..].s.3E.-.`<.4...w.@...._.\.\.{...<.......].(..\.In.-G...%..QR..1.2.X..(F..,......GO*../.Y....<....#....$FN.?9|.X..sa..../uv......C#..&.1...[..c;....c.E.e.W.....h=.......@....d.#!a...:.ql.H..}.c.........y+Xh....c. s.4......X..d.K....N.C.e.J~m.....!...a"PJr......{.-a$.w.....>RAF.6..\r...N#......Z..j...8.@a.@t..r..}.....+..5....X^.l.^F.:mfu..@`..1D.(.-:@LU..m..........|m...~.)...D.1..a.I...r.,C..g<.c@4.2..*..5"_.v.@:@...'>.....Z..G!Q.0....c.z.7...V.6..A$9...7`...v.j..$1I?.=.......,F.C....S.yX..W..m..z.G5.3...4;...N...:....!....@.k...[T.+T...8k}.4......jU...l).DM....F...J..Nk.<-..Z...O<.&...b.5.X.V5......!....'..D.I`;<..I..U.%.......).<..56.O..K\......i\g'..\....Un...W.....w*.O.^T.D.]....FI,....|6l..Z.F.Zb..%....D4llc.".3..`.;...-..K...../...@r.K......64..B.kd...YO...7p.1.8....@6..5`Q...._..$..S..;..?,U4....y.{v.V..(.C..^.4.g...r.....h.]......{{...<8dw.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.8002889857989794
                                                      Encrypted:false
                                                      SSDEEP:24:qkdlRfykA9h520ErePOMeUlgRXefdCPUvy:qkdakAh5REKP8UlOefc8vy
                                                      MD5:5B8A8DFCB165E00EFF766DEF331B6576
                                                      SHA1:A20EBE27C1F29C247605B7B78BFACD500210B991
                                                      SHA-256:694AE8ED0AD7AABEB70AE9F8F0A0B0EAA84742D7931391AB49236409561FA5FC
                                                      SHA-512:FFC956EED8F8790810E5EAAAB5997D17CC89EF95622287CF2E306BCE2CF2D2F6CEACC558F21DB2C23881F6C4E7EF3B5124FA43C985B8DA6FA0B5A7D9C4BD4C6D
                                                      Malicious:false
                                                      Preview:....)9.~.>..W....K...r..T.S.Gv|I.L.ST@...H3..8J..?.t.!.?..Z/.....*+U"....a.D,.".i....j..2...@<..kdpH.Re..".d.....|)....9z.uZ...S.4e...A.+.0.v.1|.E_."...a..b.7Yz...0y.|YE..d`..Wj.5..d......C9..A.g.7Q..........5..)"Q..,.A....&H...Y..V#.....x&7......Ow4.g7.<..Lm......K..V~...7>....x....x..........56$....]CPC....x....?11..{N.E.....2..T..^..ZR........pl..:...S. ..zqg.,.m0.*..,...(w.F..h.i........Ia...e.b.7....yP..g..P._.q6"....`\.....w.^...1........v(..1.......+..'.........E@.vv....z.....J...Q9...Z....l......A..$.{....j..'J....... SU..iw.v.X..............*..4.z>..HP...qs.1..2.5hS@4.P.O.r.m....y.hW.D[$.......)@.~..j.c/..S..d.#/.... .).J. ........m"..Z!...@.7..=.,.?.Q1;..K...aV....../..e..@.....I.(m.....9+bH$..4.........G67:....6..U..G....y..g...D.7..f.0.`. ..d?....?[..w.K.D.<l....8.~...pzk=..?V+M....3..}....D........*..bo.E...$(K.huC...7#...0....$:. s."..n.OF&..0.@mNU.....u~cPUZN..oQx.%e......@..+..ek....w.:......L_i.P..u...}...[....J..."m
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.806030623674904
                                                      Encrypted:false
                                                      SSDEEP:12:dH8OG6JI92scesF00TxNekVVZbW0AuXWd7IkkXZJNKIWzvDC3U0GXsmPZuOuWNnB:dcp8I9E7x4QVwoXsIkhCKtumgK5qbIb
                                                      MD5:2745BF2B85F8A7285CC39335F54AB7DC
                                                      SHA1:F144F9D2E1E8C060EA7F2CB62FBA33AC3BE8D4C9
                                                      SHA-256:0A8793640AF3FFB56DC051F6B4CB8FEB4ABCF4173B50753041D47B1A27DDF363
                                                      SHA-512:6E73C38CC0CD2D6AAAFBB205C61AD132E93CEC8CBD65FBC8D569055BAE62CD5B3B70195078BD6D3314284D8D7689481416BFFEEAF89C5E185CCDE6FE1E0605EC
                                                      Malicious:false
                                                      Preview:.....V.A..."$O.. I.N.TO....D?'..)S.I.&..k.cXO....M..+.*!......#/r.... .......L..2?v..g.^...)..,...v&l.;m..l.G_..2)E.....s.vC..L'E.B..n.....:.=.`.2X....G>."..njq...~uE.... ......BH.O.D.D.......d..9/.....S-.MH.G...U=....$.....g.x....O.K...-...!`..?.d"....a_....@/...."Y+.84M_L..\Jzj......ho.J$K.i.#..8.e..h..d.2-.t..#...$...$Y.m....8.q>..wd......;.t`cu2...5/.W3..a.V.g..[X..7C........5$.Z$.Z.{L..._.a.....h..O...1..%"^.?....^R.0.C.;.`<..c......y@....,1.h9....A....,..V....&..h...sO.J...3.t.....eK...Mg.|......+..e.a.Q.....o.AB6...>LQ.LH.$y..5.dQ..Bd.>....J.*....b....tTG...s...~kY._'......=fPXH%.}..r.}Le]N.. ..*...+.5....-/I.;..t.86....I.\..~.A8./......S...E.j.oT....h.,..j8W....X....'-...1..|..Q..{....y.....\.:....Y.i.p.V....".V.Q....V....b...i.q.:.......YH.B.....T..z.E.G.&4:&...N.^....o%...l.....9E...nLp..!.WUHn....4C.......K...........?......".^{..Y._m..9.B....i-...|..g.H...3.$u..9.,0.Pb..m..\.|g(Po....Uqks.L......R........\...0..Su.HXY'x).s.pQ( .x.....(J
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.790806389131858
                                                      Encrypted:false
                                                      SSDEEP:24:oQ1k4Ea/rwBY3VXWhlAfAtN1bwx0cfABg9I1Q2q9O:oQGa/1pAbwx0NVqE
                                                      MD5:1B46E2B25DA0DF6DA69D1E5736A41B4B
                                                      SHA1:68911B273917A1D836A9FEE84968230C2E42E1A0
                                                      SHA-256:E2732C0A7367C65FF16128DBFACFF32731FDB61133753F2FE2EE2A5235E78D33
                                                      SHA-512:6A10D82D07CC1B00AC358553B6DD5AB7823F8D6F0D7C4DA1ACFEEAAACE3DE9F43A4C20315127EC7706E207D0BBC5833C79E325990252F84BB363EB29141BF71C
                                                      Malicious:false
                                                      Preview:...8E+...R.....".....t....v...).....6..=...v...4...{.K^.^N.....M..W{....../..Fj...a.3....g..P........E.7.?.v..YK..n.K.vC.r.... .TF-..tT..&........n.....C.Fy..1.2.../...a l YD@.u..2,..D.j:dbL&|;+:.>.x.../.1..N.T_.aj.~qK>..5.X...v..<..y9.v..y.*.8.E_, '.r..C.OU....f.=...j..i..M......l1...>.....$i.X.../..R.~..d@...8.5.RJ.+.0s`$...G/..Jh...p...A..C...9......o..h...*..is.?.4.z...._8..{L%.\..Z..*_...W;..k......&k.i.:&.$\......e#...y..y.x..l...NDWm...@K3.KE.S.ntLh.......b.Oh..\....^u.E..(....Kf].f.lc..L..!.]o.$.....].kJ.E.|e.-.g-.Or..Q..%g.^......yF...W...T.*.+h...-.'..Wjx.h...=.........UZ../.:)....%.|.h....Pi.A...(s...|.Y..'.p.....A..R6p>..W=..<D.w1......*Vc.h..%.8.+....^...:. .g.-.Y.,SV.2...<..A.K`.......{;.x./..Q.....U@J.R..j..0.~W."M:D../.A....Xh.+.J.8d..g-..y)=b.:=.,.!.......%2.b..C...Z$8....+%..#..8.T.O...:..&...}-..N1.......XGj..d..{|....),.?...j..=.........1=.j.Wv..i....c`..h.7..5.uc .C.Nr...&.A....1.`f.M...1.dA;5.RL....`.d...#E...uG.c.U
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.817268395164956
                                                      Encrypted:false
                                                      SSDEEP:24:XEGRpTDZvj46OFhLOW0fUTJL86btG1Eicj+0YS4B+KRKBSKbF4TS:XvRrj46OFhoT620c+WKR5
                                                      MD5:A8AF2CA4DD1BC7B1A2CE72250120D63E
                                                      SHA1:0E600F6EF7F2CDB8597F58087E976A80514FC261
                                                      SHA-256:F6F52D5F5271301371B82B6936F7EF7659916E2EB31C08D7659EFBFD8C1C51D8
                                                      SHA-512:6C03FB24C99E0B28518C4F5223F61004DBF86CC1ED87942F219D1822590E7BFB54C294B875261C44E40EF0C9673CDBF9044029C2D4302548E7658371A263B47C
                                                      Malicious:false
                                                      Preview:K.THH:.\.y............1...y......q...$.s.S4..W.}%.........\.y..1..].5....d..Yl.Z.^.+I.U./...x.._o.......y..I..h.".1..O...M..r.>qcy\b.?Q...L.f....=...X..etJ....6.....DB...,Zu..{......@..X.!H.VN.w~..sO.....[Q..Q$ .P.l.F..w.h......L..`...k..e..$.....,..tlp............1@<..:..-..F...*+..R_.]#.5q..w......H.|...{*.jX.h8.b....f.DOq..u..s.....]^...&..S..*.Q.g...G.X;.er.3...e<.UAx.......z.|.|.v...#jI...n'H[..2.D..+...D.[$....;.A...;..j...#............o.~....J......M.+.........{"..i..5......X..9...uox.b...Cp...t.V/......Y8yK..l.F[...].W./\.*.H..'...q(...E{....t...h.,...._..6N.../<.tr.....>..p.$>;...Qf.u.e....Y.]...}J...{$*......N.^...9.\g..;..`8.>c.f..+.C..J#.....P..z...Zo.N."|..9.Q?.Is.:...zvy.hU... .t..u.v.g.u-........4..S|x\.1Iv...i.I<..|l<...-....X....@,.k.~...k.=.A&...B;....K.j.-.....?.[...w.d..n...!.Z......N..u....[.i..S{6..w...."cRK.....b.+.>....&...J."Q....G.}.m|.OT.....R.48!...u~..Pj..>.el.YhD........C.J$`.O.....|.f.S..>..Nl.6..t/8
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.80533100902087
                                                      Encrypted:false
                                                      SSDEEP:24:IFwXxyh4g31mfzTYdjHGKF8+UKWuQaHXuPByA0jdVZr33:IFwjnYVmv+Upe+pj0Vr33
                                                      MD5:0447E394E51D66683E83D8510B9B4468
                                                      SHA1:A2FA2676EBC9CAC4E1996D34EA587D6290F1DFE2
                                                      SHA-256:2C086B103E5AA8464756EF3B5E426C96DB762BE7A7822798B1B0A9EE8FBF6475
                                                      SHA-512:49303845832CCC87FF1D3035E48790E1B5EA0385BF04D96141828E968FBD247B41868DE2732A3A280AEA82485C3B2D0D78E97A5B1E6295292BE48735EDD4F377
                                                      Malicious:false
                                                      Preview:......y.F....f......c..R..?.tA...`.w..YgA.]!.I...* .{6.H....2.........s...L~`..F......*~.dL..W...K6Vwi........-].7..."..Hu.."..p...~.s......q.i.....\$5Y8.S..Md..p..g......V.h."...}.f....h.p<.J..r....M.e..._x5e."A.....y.=....6+;7(t.,.<.64.o...*.....:..5..B.v.<...<..G.:.A...z..+.!.+...J.T...,..G...k..g..H...d.R..)bl.....UFta((.9@s'..zvq......bG......M.-....f>(..".../U...n9...8.2.t-.2tL.r..!.o.....U...."-8w|.G...G.~.~.S.[r).K..Hlx..%.A.Kg...X7.#..".......s...d...{C."._.,..AC ..{.~j"..Q...*....lClF.i..d.g...:cj.6.m........./[..:.v.Q....5....w..}...7..C7..UW....!..&.L..\C>p.Z1}...........j...#.._.$..Tl.k.G..:..J E.....v..._Q.L..*...+..t......s.j....^k........=.:........|m.^..M..=......Q......._.QGD.......\..w..G...y.y....a..h.@M.J.>.T&...~.4..4..c. ....#.&n..J.]~..f.,{-..+...;.5\1%V...T#...$...".o..I.dI-?...=bW.4...)./..!w\.Q.9|....>...;..c!..jtc......R.....Ls."..l.....p_.)/.QCG\.Ex.V|up.x...Q".:K..o#].so..*2.......MP...r..j....a..".(c......l
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.813825101052696
                                                      Encrypted:false
                                                      SSDEEP:24:wDCrJprPIeqfWFlLakD7Dp8VwcivExPXI3l/SR3dZiKsn0:DJBAHfIhakaVvYe33d4X0
                                                      MD5:18B40D2FE8E5F6EF602863A3DC5DAACB
                                                      SHA1:A189DCAC821A52D3F0DA6F32CAA07AAE4D550AB6
                                                      SHA-256:44CCD51A69F1AA5E99F9FD5FA366D41A176EC9F64E210C1EEC8A78962E85D5A6
                                                      SHA-512:D4DDAD791A2B80C510DB1B0C1A7DE2E9F0F43343D7FFDBD507EDE3F282B4DFCB88079452D051CE87242B18C84822C361E65BAFB20ABD9AD8C08DC1C1C1BFD431
                                                      Malicious:false
                                                      Preview:..S...X..SQ.V:j.l._..,..A.&s...Zx.#U{...M.b.b0.../|....!'.>...Z>...s.....opI.i+K.H.+".;..-..F.Dsl+....U..i.1.S %..^.3L07.k....)r.1...hB..U..>.m...>..6z....R.. ..'..W..="...r|d.0.`..Q.Ij.Q2.b...Z<.@l..u.3....f.9bh.^..*/.....G..`.k.n.i}U.8....d.......6_..4Q..p...Xs.(...#..=Y.twA=.F.VL...y~..t...S..J.r.y-5....c...+.\...v.W$....b..W.m.A'5B...P'.....C.|...O3J<.o....m.`r.U..\...G0.s.....-.`..]>..}.GC....."G..(^VI3.rB8e.c...5..`.9.4;.g..3A....m..V.q*..6.....*...%nw@;..........>......~../|^./J...#.Yi...`...s....E._u..>......:.G.Z)?.,.yDX..=...A......Dv........g...a..8X%...Z.T.........h.b.oID.....T....}..: ..\..^q..d..i.0..*.....G....gat./....:.&..,...t..nr.HU.Q.b.;3"...&..Y.i..%6.io.._.<+....!_M..N.E.V..:7.....UtT.@....[@...h.k: 9.c.w.e.7......Z.?...I"..9.,.....4.....VW.....p.....I}@y..0..&Y.<.^.S..Bg.s.Z...H.C.:.p....L3e.%....L....?.I.........-_..m...>.a.?..f.........T....\...*...`x,.....^:....ME....Hj...@.Hz.JjC5...kM.Z.C6[@4 .mYb.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.809466313058323
                                                      Encrypted:false
                                                      SSDEEP:24:dw8rMr9EyiXeihVWSUegYUy9HJyKKyDdAHx3g+z+03:dhgCyY/hVVdzrJgyDdARw+q03
                                                      MD5:DF1E5D381F726692D57994EEB9C80815
                                                      SHA1:E15B43D30789F4071B211BCD3E1B82CB1964371C
                                                      SHA-256:A47CD508D39E9A1348BE9CC445FAE39950AE37118285266B59DBB098F03329D7
                                                      SHA-512:196F65C9239D8F13825311EA7E30DFFC7B15231898855794CD9649BF204AD4BE529828238C40D4631404E36B2999AD05BEEE51757D45BEFD7CCE9F5BEA77B6B7
                                                      Malicious:false
                                                      Preview:..j.23.N.q..@.E.h .p`...=t.g.F4z..2..G)7+.....].H....V\.8._Nt2n.B.^.#......+.d.?............C..(......<.'..=..Q8Mj*.S..S.xBUB..!.|(..r.|....S...Yk.5....%E.w=..|.x..$pR..<q.-R.e....stC....N....<..?9...y..[.......Mc.S.e.@...W..]t.q...M^$.._..;..B...?N.d.D9+.O..ke.I...<S.WA=6s>....1E.tfNa.8...U.o.U-...4&V.....y...5RL......w%.........%.#.....5X.Kr:.d.....s..............;.Bv.W=[C......F.....?...a....mz.........i.m.)...5.m........a9m..<..Pd.!.;..8............w...2.M)..s.2/.{Wg....H.jI>.h.a..M.^. ......K....84X.u.xF..Ahy.Av.~..*x...Pc.P.......\..9K)..O.......*L.p.9~...w.=1.:y..M.5C..y#.K..JSg1&.&TLh!.Z4m....%......h..17..0)..I.....H=_.}......L....a.%.P.}.7t.&XuoC... ..B...0|..t~....M..8*.-.c-.".UD@.lK........4.^.A.5lr..'n....v[Z....o.<.....@...s.~......Q.. ... $.......V.....ve.9>R.b..2.M...$GfU..+..aU.A.h.7TV....T...7..L..n...j...=..1(.J...#Wb...XQn.3...'.5-.i.j.d.g.._....+8.Y5.h.V..f...m..T..=.t..eZ...i.m`..;......R.7C=.D.M....H7...4.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.829709307895732
                                                      Encrypted:false
                                                      SSDEEP:24:zLQyMhZnIXAD/BRH3MEiOrCPR2Dhq/o181l7hy:YyMhBIXAjrH3MEDPDhEo2Jy
                                                      MD5:02F127E61A05EE629049225BB9250652
                                                      SHA1:62913336AC3683FC1A6B5F751630BF4B8A3DB342
                                                      SHA-256:E8CC00847B8560E8F2A76079054E253F6BD0B1469B6F49C91C78901BE4E50E42
                                                      SHA-512:40D7E2E6812C1F5E3088A7468092505E554FE6CFF35D2DB3C2FAA0EDA5276C98CAF031B5783B77E8E0B8E483683CC35418EF906F26D6A4A75B211C0609BB299C
                                                      Malicious:false
                                                      Preview:.-....<D.N2.r.N;...*..8.|...l....pBn.4g."}....q...>v../.ir3..@..&\2..0_..?jf8.1n....V....K...H.q.h-&,lc]...C^.../.x.OnwW-a.g(."...8...e.....c9...<.S13.^X}CB........{.M...R.........Z5..x#5&..=..m.&..1......RE...ma..Z...U.W...".z~XC..)m..j.oD.......)b...l.`.+.pF...F.7..(*...%.J.?..l..K..'..#57X.....mN.H..%...._.#...&M..-+w..........4...AhfS.JS^5Y}.E.+@t...r...p...*@?.....N.<.H.#.?V..r...G..Y.|...~{05}!J.|.}z.b......p.".6_!7..`c..]../'.>6;hS....0..cds*.X#Y|....K.x....L.b....o...B.m..y.......a.CZ.p......._'y;.R.E.5..T./.a.[v.+#T7iR.2.k /..t.K....<R'G.....~1.....a...<u..v..x..\A3.FC...~ ..?@GG.`0Z%...Hm....}'oQ......\.Q..Q....5./)u.M..{.E..R.Y..&......]`..W?........)t...;.P.DF.W.pk...8..f.:..q.J.}...Oq...~....u.wZ..lut..@.?....H.7...,...........Y.QKsoZ|..%.b..^..@\..H..........w..`...`.....d....I..\.I&..w.~.F....3.~.(.U.#... ....k.><...X R.;......CF...H..8.#...Jm.?....:.Z..RW.D....L...'..a....+.qrz.e........)e.QZ.PxW0......{........^...
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.8118812370146715
                                                      Encrypted:false
                                                      SSDEEP:24:0OSVXnL3FrryLwgmFVwl46ZgEqhdaKafE:0O23l7wLunkKa8
                                                      MD5:9D5BA5741C91BBFB64542DCD564E0873
                                                      SHA1:189EA626305FD0DEECCA0984316E07A24E48D79F
                                                      SHA-256:62499AE7A7B85E7B73990D28617548218D5604A943AF83484953A87671099422
                                                      SHA-512:AA18F53ACCB0A505049932F0C11857927A4357EF4F061B0CE3C5353043453FC7FA8392D87F98A7F4743E48603C33BA0E4E41A2364FA4770072AC86FFE4425572
                                                      Malicious:false
                                                      Preview:;...{......v...P.}.C.s..].K...c....G..?|.7_.A.|..qh.9..T.Y...0......V.A8../8.[.i$....C......~...i...Z......-.......$..7........m....;...8..o.......-.Hl...!|......sC..%..).....x..)...riU.wx..E.U%k..5......ya....;{...v..v/i.2b....&..=KH..+(.0Rh..`(..>..R...mT..$...&../..d.W.?....D..S.N.....a.4kEbr..a.-j.'..a.E..0.1.KL.f..h..3.Y.p...T$.?...FE.3.e..GmS..u>.0'/.x...)i........hG.@[.=.......B.o:.3..n....Y?M..P#.(+...o........R-c.......]1.A...*.a......Uy.+o..'..r.....a.Qw...".$.V..6v.d.4$.Q........w......\.....'?.#Q..@D...m..6.|Dn.q.Y-...|H6.....m..J..s.2..d...;./........fH.l.dv.E;..3.E..*.sr....~-A.....#...%Q$)Y..s...b.VWnq...T.5.8>l....z....R`....6.;.>..,U.:.g..D.$.Z..-..<......"#..P...\}w.d..ZL.}.}.....pB([.....l,...."l...y.e..r1#I....0.......V<......1.l.W...A.r.....Wt.....=.....M..k. ...>X.C...........@..s...f..{..W^K^n_.>K$<~...R...R......Ab.*t.//.!..p...o!ec..Zh...#...#~.....T...Mg}!.k.:u.m.G.z.#.S....{n=6s..}..0.R...D:.l..9...l.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.814571612612444
                                                      Encrypted:false
                                                      SSDEEP:24:paljvivDvRk6+fvG1/OaNQQed/YGUVYBY9bP1L0yzd:pa1vQDvqMJOWI4YBYx9L0yd
                                                      MD5:ADB016F6D9F01FD83B27A5B5BA617FE9
                                                      SHA1:46257B9085DAFFFA493B7D6EA9A6200859016B5E
                                                      SHA-256:A8FD8CD83CD3CBE306C72318973202365CA1A385941A7E360A6AA7D7EC877B7D
                                                      SHA-512:95879D98959F45132DC0A9B6D12B6120E8572E7A45445477301BE12CE02822529BAF4B855A646A23D37AA89443CDEB744AD5FA732D478EFC7EC72416F525062B
                                                      Malicious:false
                                                      Preview:}...@..2....t....WDt..1....S......n~..a..<._./.3...)U..D.*.c."*4.{...W....Eg....K....[|.H..i..s.......{.E...-l.......q..t.Z.."..=.R.k.\..Z........o....*...C..L.[K..>.K..Z.m.K..1..~Dx....^Z8....r/..w$)&K....l..kB.....R..63.&x......k...C..N.t...C..d8..........f.......>.bT6)G*Y/../kA..x.>.H.Q.6....0:....$.E.4..k.I.Y0.$.\..{.y=.i..c...N.S.-E..P.3.0..RI.{c..d>.../..5..t...b...../....bJN. .75..T... *.P.c....B....9.`..p.5..[L].......".)...0...1.j..oT......e.|.{..M;..t........t?U.K..f...*.8.5.......s.....=........c..;..+{...oV..Oz..B...*...S.y./.....O.9........3..@.}..<..G..b...=.'h+...*......m.F!...T.....{........3.33.R.%..N....q.U.#."..8.4.u......k{I~m.Dm.Bm..v.i.o....!..t.G..@..dvd,x.$........?r.u..ia....oW.q...."5..=@..EY.d.~=..I..5..H.b.Scsy..jST...].62.3..O#j.x.....$.hI..a.....s...mG......"'..BxV....&..hI.l.....T.F...%...N..Q/.{g.B..(...`Lz.[.c...=G3....).<.9..-.FcI`.p..{...W[.....+...$.'.r!Q.C...7..R.I/_.T....p....^..t9.-.F..3.&...
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:OpenPGP Secret Key
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.796702126662983
                                                      Encrypted:false
                                                      SSDEEP:24:hxx6HGuw7v61FISEe/k026TsPhx7XmLyMYQmRmcm3DE5:hxsGD61FISEz0Y7WVYQaES
                                                      MD5:3E0C9DD3C3B9E1786A835BF5B8161A7D
                                                      SHA1:398822B7D9A4758B0913DB45C8103AB8DF9EE828
                                                      SHA-256:868586258A121CB8B790266D6B914E89BD0B28B6550D4738CF5A87ED94ED067B
                                                      SHA-512:9F6D32625989BD81B2B86FAFDE3929072CF82C2111497C52309B8190A19C0106D0783A357965C1C253EA7562DFD7A26CCA628DF5DDE5D19826B35E2AE9CF5204
                                                      Malicious:false
                                                      Preview:..P...J.l.mU9..8...Gf....t.~.*.].....C..}.*..O.:*.B..WL...,..X...F?.~J........H.m.:...x....U#.R.."k..n.=.g.V.......F.D..9..6v...g0.\D.$.4.>.9zU_k.2k.Y.vW.llT..%..N......3.....n....J..+@.q&*.=.nV.oPxK...)..#A..-d<..Fl.;{.6.....W...2J.R.T....8.........8....#...yK.c...r..M....@f`...g..[.Q?%.....4O..].V.e...}.....D.~=..x..w.T!.w.]..W.....?.... ...*z..KK.....V-.x.k..e.k]8..q..k..w...4...l.s....%...x.%..>.m.D....k>...5.}1+DR2.Ij.,....f..)..j.....-.d.8../...(...!..VI3.(.^...b...~.Y....~..B..Cg&?...K.^.....&...y{.....).....X..[.L?...Z.so.E..Z...=..Sv..b....>.E2.6uB=..d.o......{..W...F....h..ssT@`5...j.8G...6..Y.:t...8.A.I.r.].3*"..b .n....%q....|.V.*K.1.q...h......n...nx.#wv.D.n....>..HC.....}..K...V.........n.{..m..9..;i......BO...a._..".wE..u.UQmGg.A)P,.{..........V...f....B...H...-Yi6..F....L.ksJ.^..&0...p.....ld]..2...BU.?HE$....|.0...:......h...Z~.g......,...Hi.T..!.rO..j.R2.L.].....].3.#..w...s.......5..q8.xH.1)..\w..V...;.+..Y..L.l.X..c.X..;pb..9=
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.808791917570398
                                                      Encrypted:false
                                                      SSDEEP:24:c4aOeTiSb8nbueCGBIaYGl3ALGoTKChzhOVdmS:chDMuEIaYFLGJCegS
                                                      MD5:A5B1844D831C734D22CD1A89ECCBD66E
                                                      SHA1:2F952E85DD3262C5CFDC4D8292BCE7F8C0CFACF0
                                                      SHA-256:998A953443BB40BE585AAEA08F53AE2C38E57B00E702138FA1AD1B338E6F2AD7
                                                      SHA-512:59F575A5E9441F9C5BC7A64E46AB4D4F3E3A876F85907CE7C264799A84221A3C5FEF1B47D90964443CE528FC8EC2A9566A7AC7C07EAA257246CDA1BA53C554B9
                                                      Malicious:false
                                                      Preview:.....*....3.....><.jM..O..........._..H...2.^_ ..r=.%.*.ty..c......l.N......[.#.J.e#...,."N...T..O.N....{..@....b.....ip .D. q..E.\...m.....a-..y...i.QL.;..}.0.m....X.M.j....G..opa...c6.H...\K..4 .p.....(#....I..s6..o....5.....!..R...G...6c3..*....v#....2...$/.v.,QZx..>.|z.!...v..A$....E..=`.!+.X......}_6..S.3.9..fz...HUX..]...M..Z...D..Jc'.#.../&2#.a....]...L...Q.u....G.1.~.7..A.$...x0...Y...&6.<...Iz$...l.qJ$ mqi...!{f."&$%s[.o......1D*%x.....<.w7.b...\..E.N9u..I..P..D..,.8...u?.+c.@K...@#..Nd...O...%...N 1.+.s.....Oq.8..'..4...t..p}.L%,..m...p.b..}..4../BC.6s..bg.i@~...X..........+.....T...R..d..g........W....6...B!........X...z&9 ..aJ...q..K...D..9..B......@...1I..a...Jh.0.u!.c\4.D.....m`FZY.....qU.3...."...Y.:b...{.^..+...Q%,.>H.k.K...k\.)Z..DY.7E.w.....uW......<W..&.1.....].......k.......0.@>.|.....l..$..'.....O...i..2L....+.e.R.C)@;."[{....HD....k..H.,.>.5...tm..p..W.x..U....X.....^.......uE...K.^..pD>.O.<M..0.gB.'..:'..;..o
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.8123863151185535
                                                      Encrypted:false
                                                      SSDEEP:24:JnskQHv9/Asut/6Q4OFd3g7qgvvax2MmJBjpx6H4U4:qkq9/32ia3okx25U4
                                                      MD5:8E3A88313A9A5CB81115EAD38D5BA0C1
                                                      SHA1:4B6A9D212DAB4FF5FD37841E92A3803C2D7F06FD
                                                      SHA-256:91DA79363425B1E89417A6F26904A6EA97E632C8B631C26F2378AF688B87F73A
                                                      SHA-512:5EA91FF90FA03E6104196E410F23EADE5A49094433651FDD1B9FE1F834782E29BE51EFCAE756A91ED29CC0EBEDA21DF59F3BB46C9319AE3D7D72EA0EDF541152
                                                      Malicious:false
                                                      Preview:?....c...K.A.q;R<....Y.t..w..U......1..^qI.go,.*]N.5...(..h&.....A..SE..b..'..Ozq.kqS5.......o.@..3N...d.v.o.J..f.J.r..y.......`~...=!...YE.@........b....t....nGI1W..(......".....(1j....u..8..|....:.El..C.#..E.....c6../.....=.N....8.]g0.I...1^............7.e.'..N..x..k......b.U|.#kT.D.....7RK..|.2&.*.:..i....@...{@..1T.^....5(-...G./.^........19z.L....R.a.L&...._.@zJS.N...h7la4./.-.....:$q.C...............;.c6.....hi.hb~V..Q.Q.f....t<%_.,...]n....7VM..".9..b...<.u...)..W..>...I^.Q..,...p3.%j..+..Z.......okf.\.Aw.yA...9...z.m....;4..Vj.^........>..+6..H....~_.)c...+.C.l.0....]....;.....)g..-....T.0..*48.G.......=...*.^Es@.O..p.`.T.......O...$,I...C.g8Ka5.....W..(.f.el..L~.-....QA{....1.dU..U(.{s-.r..x%P.....VIL....!.......:...E.....&..&.!B..}./.....!iz`Cbi.:}.._.,....>M.}$J#. .....l...../%~v..Q.PIt?.T.....r.HcQ..SM...!qy....f....P...j.b.......Jk.iT.mvh....R...*]...n.. ......Q..O.<r..rr..~.S.>.$.d....%.....q..%...-...S.\k.L.$,i...S.%Z..n.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.80946241341476
                                                      Encrypted:false
                                                      SSDEEP:24:t3cHUODDZTL+VLzL/rrQMu+cp8lp/VZYGNU+AYGKaK:VgU8Z2VXLTrZu+cp8ldVZxFAY7j
                                                      MD5:B7532FA78E78C106B63559FD57E9F11C
                                                      SHA1:CF62F2D65F493BF32FD58FFF92DAA0396271F277
                                                      SHA-256:B902E5749BBA88497A98D327D93FFC23795648D6E9B42EEF13551385B5E3F855
                                                      SHA-512:37392494A4952AD915E7935199148AAB19591471BBE2FF168E1BC4EDA4E6882DA32E3CC95DBF109A86103EA6314D266D4E0D270E142B7320B9EE2DDB0B7FA371
                                                      Malicious:false
                                                      Preview:...wB..@I........X{X2K.N.....s$o%o....A..U.y..^[..{...Z&./..G;..e..,".D(F......6..".....-...d.:z.5}O......zw0..a.<9,....2..?;..t...H.P...g.WS..p.z^.A.w...$l0.3...g..|..bw....d....cz..9.<!....=[.xJ..'M.......@.D.0>.......F$\4..].c....[.:7hs.`.R...'.I.>...9\....!l.<..J.#......?..4.A-m..9>..f. .i.2..G./....y..... .tp...c......9N.j.....*:.)...D=b.P.....T.D...c....Sz6o.`.........#?@....n....f....{.g....-.-)6c.....D......v}.....;.~3&...h.*.......m.#...-x.H.H..._....9. ....h...F..v.E..93=e...O.W%@o.bMP.].2..Xo....Y^).w...I.D...u..W!L.`....G.Y.szv.T...9.o.j.W*..G......9.o..sc.z....J..e.&.E.GVN...1m.R..+..m&.M.W4aAA.pL......s^B>.qJ=..=./.`...(.............|._.2a.l.f..N..HJ.)...0v....Wc.*#..o...fW..z...P F._..G......i....K.._.Y....a_"..1.0.CsNY...F...&. ._0..F|.%.p,..G.|..z.I..ss.o..s.....MY.`...[..s..e......_..0.~.m.AK.E......0..C..6.5...~.T.....nt0...\)....:....../...4$.:.N.U-........Y=.C..S...>O=[.]...IAz..y........V. .f..... ....&L..AB.......
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.816021485185824
                                                      Encrypted:false
                                                      SSDEEP:24:QD3FxBGkUyt9YREACJUIm7xeLSI6kN7CkU5brTO2s0:YFxx9UEACJoINN7CkUtfO2s0
                                                      MD5:A985CDA5849DC00FD061FAB87B9F8FC5
                                                      SHA1:B4C5172210AC848B95B5FEB57DA6FDB01B417D63
                                                      SHA-256:808632F1764508DE3A25FCDCD1F92AE42FF872F1979AD3F853AADD2E069DA639
                                                      SHA-512:AADC1D39A1C3AAF79CED1C7F62806D57B923EE4B1F5C766229ED32D8ADD0BA3955D64EC118D37048329AECBB2F4CB03D95221FF19AB59F1334B09EEB04C0D9A8
                                                      Malicious:false
                                                      Preview:.........J..`.lD....Y,.7...%... R.Q.......r..6h..!...L.R....d.#......mU.k6q._....d...+..d...q..;$.|J..f...).......@b..n....."...J.......O.*.A...[...`..p.*.n...K..zl.8.y/;.-...HZ..%.}F........r..j...Jv..1.9@.....wi.RD.&..$.o.sH.zM...).. ..x=.....|.`].^...&.8M8O....O....{.|.6.^..v.'...a....S..2.:..j..>.z..Y.....<......l..r.V..9.v.m,+.6S.....G@..g.......f.l....Do..m.+.1.Qz...9..........2WO.8....V..&oMS:.....o ....7... .]....=.,.y......wYA...+"./....Y.n+K....c.b....O.......}om....@.O.w.A....."..#.../,c..R...S6...3....J..Wh...]b\5R..N.........9..z...z....D....l..'.%....k..../L.jOhR=.....ot.N.......gp..8.m....v.I......@..32.Wr..;-o....E.6EVC$z...3S....Q.6...F..m...b!..`g.O..Vy4b.$o...#.>h..Q,.E.......t`]......k...;...&....b..oDS@..]...iR.H.d. Oy\..b.@.]j....y......u.g.._..u[*.1..I.@..i2.2.&.){.......:.K.b[5.zd..gyh....iC.B..]..L.S..Q.A..d.......>.4.].*.....3.....N.XrS...vw\.<..S...x..%..b<2.nf.c6!.L..e0.@...'..}..Hw.5.B..$3.b.:..Knm...R3.'... 9P
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.802678844907424
                                                      Encrypted:false
                                                      SSDEEP:24:24fr/L0tu5W9dlPUIB6NyZ9rBx9bXHHciz/bsyu:rrY9bFLpBnciTwb
                                                      MD5:108C14E3EE4092E5AEFE496C7328577B
                                                      SHA1:215C50AEB212AB917F83F0CB4E49E5640630749E
                                                      SHA-256:07C8C7E8D6DED01417575833FDBED053D474B32C3855BE094EAF1855802C1372
                                                      SHA-512:2989F4504F503DD05ECF94478D1F7EFAB9FAE70EB10371CB64988EEE63FF32DC249622223D23B04D286ED900D871A5BEAAF66CBA6AF47C1FB1264B97B6A3C4ED
                                                      Malicious:false
                                                      Preview:...H..+.xfE.k.k.P.8.C......c....;L...Oh.Y.1.......sn.S.E..;5...F.c>/.M...~.....z..B9..u......@..u...O..^...$\.d..o.}0..r..>..>.V...E.Q.P...O.. }..<.k..8...{....7..o{.r..M|...)...FT......z.v..e>..z......}B&.+..Z.>..9.F.e.:.#.F.4G,.i. .5Y.!.E....a.......J.^...jD..Io.$...F..m.,D.(......%....k.|..X..{.c*x..]G.v.XGjh..5..).._l........x..{............>#.,ej.....h0/..Z.#.bb._.h.*c.........!@^....a..2#$..,.......=v.Nk.u/.1.k.8.....v.QF....r..~n.?6W.AR.+..5.{....3...>.......&..u... ._.De..b.... ....G....".y".j..v..l.z....-..j..><~=#<.....%....u...v.$....@<...J.N......'90V.{.."...Eg..3...|......b.\..s.R$[M...../.LO.!HOy:...6..L<4...iu.N...O...3i..a..mn..|...\.W.o?d..!R? .<i.....n..;*p(r*..."'k...j...D.K...xJ4.!a.F.`V.:.|`.5.x&G.o.KAN..........+.U`...~.{.....d.d.(.^\.0.......S:@8G..G...@(c.N..S..%...S.u....T.e..<.>..?)..o...........:&f;.o......R.~V..d.7A....A.].V&.M/.b[.2..&:U.:...3.{.:!..H.....H{.v.~.C.*q....O........r.#B.....=..L.2.Ne....C!1
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.811238166942946
                                                      Encrypted:false
                                                      SSDEEP:24:kP1KVKXgQmoEvVFsw0eDzdKh6aKmqM/S/dZ2Ya9r:kP2KXSXt906dBaKmFDYaV
                                                      MD5:1B5B89110998AA3BF5CAAE226F0B2799
                                                      SHA1:6D0C5574AEFBB1C1B827E935E8BFA6B2F7599C89
                                                      SHA-256:20533664547F65A94FD8938FF97D542E2E4B68150FEA3FA9919F522CB5C03D32
                                                      SHA-512:3B45F0F0D4080FE75B47DFE870F018F2FCAC77B64FC806943033CA23F97A1B73757C9DBBF307053040001DD5C4C881BD822F1EF90C31D13EFC4B7A7629436BA8
                                                      Malicious:false
                                                      Preview:~........7.j..I..u-..t..!Q.('.Zv......$...kZ.......m.o..4...6?...F....e.x.....75u..&]....K.4[.UV.3.}...E......#.;x#O5.....+%t.#v.4Q.b...n.l7.h..3R~.C...........d..t.3.f[{.l.......VqJ.......~q.M)...Q[I.\...v4R.4.q..-...).....*.S...).L...-.UQ..')..Gb..q.L>.........H.|..z`.w....u{p./.3,A.....T..P.....y.C....3]........(..[........b.R..;...fA.p..Q.N}.2..[%.d.......z.......|.bn......_.........,....L...Hfv.....@.-.^....[....J....p.<hLWi......A./a3.h1/.f.2.XQh...&;."......ZO.E.B,.gG..d.".&..Y...Lxn'|....d...ke..4..G.....2.=+A..k&p......<...w~..(`|+.....P..3.....V..i.*K.N^.7bS..V.[.-.bl.;.3.....D1hL..5@=.v... $.7..3t.....?.F./.-{Z....Q=..8f...^y...&Zk6.9..'3..N.m...\.Z..e..VKF.Kf.T0.d..}.7.v;..o...n.. ..vC.*.2.dA.3B..9".i... ...&"..^..w....,c.~f..M...S....).q......}.t)..B...[.Q.3.....3..h..#..&..........A....XS=.!.D..\)(.I.7@.....r"..N.3^.j..d.A...Z.a...........Z%7.4.. k..K.T]`0K...j.6...V._......Y..Y.O.,..u#..Ey...A.j......sEQ.w.S..."
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.804592566999216
                                                      Encrypted:false
                                                      SSDEEP:24:M6cPtT8KvPKHpdZHEIs5bg4gcW12rfMgrK/XDRmmu:IPtDaSRJg4gF2r0dRml
                                                      MD5:330770863C58092450446BE1B52BE8A2
                                                      SHA1:CBD9D676502D7E43BDBA0DCBBE69762ACB758DB4
                                                      SHA-256:38474F183933FD5872262762C5961B3ECE830E4DC88FC09D0CA62ED761C78E71
                                                      SHA-512:061CE603D2FC394C21281789BA97DCD0E5AA7BA172C8D8FA998FC2E2D752617B491728436358DE9B286FAB37B4BE64902CAC247E59B2369E0111F5319CA3E5F5
                                                      Malicious:false
                                                      Preview:. ..}..*.\q.0).o'....../......k.j.........6......%#.E[.....eHR..+....1 .Jf...N.m.^..UT..3.3s5..b..F......]..:5`.}.......BJi0......Z.-w..\.!/^...\T.].....^..@.u..;>..Ut..RY..Z...F.i.m..9.I.>....m..a1.p48u.D>v..]..w...6..L..)Cmx.).....,D#..'............+#..!.......9...!pRo7..^...E....\..d........N.(..AC....g..33..x...~...@`7......_...C....C.M.J(.%..-..W......C."z..{.O...:.r^y..-.[F...Bu..Ar|JhH8..... i.......+.9.....G...Z..Q....I..JMa....-...KZ^....t.{.N.96.6..Y7...`..q_?v....n8.W......t.8/88..CP`)8.k...Q........wpqw.B..].<.e../<(....Y.....H..w.t..{.)....~..%.q.w2D.....h.G.q!.h.m.ye.Pc.F.Y."...1..T..0D..R...`.....g.~..:U...=..q..e......@".x3.A..,T..NE.......v ).l..."y%C.?WwM.l.cM.9......0kM?..Kp|...@'.zJ.'.cP.n.c.....}.._......:d....?.....O....^:... l*W.c..\.fi).eSU...Fe..U..1..+.(..^.a..6.D..k. n..f4.C...Y..%..!....lS|.._y.A.....(...\w.G...=?.:...9:.6.1.....q....?s.`...(..O...}..^.6.7^..\<.h..-.E..5t..=~'.Ak..4.......E#DB..5$W.X-*..
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.748738507978382
                                                      Encrypted:false
                                                      SSDEEP:24:fxzy+IjN5RaajNDA5Nq32StedhA9VFAzJYwyu7obKavbp:JzEjN3Zog3ftMO962zKaDp
                                                      MD5:099A0790C94FACB3AFB8F9B72B8DE370
                                                      SHA1:B8D9A0E40EC91D8682F94CD48C334FE606CEB8A8
                                                      SHA-256:43DA8AC4F99E38C9470C9EBDD4CF14E03276B36993240538B591A5789CCD0650
                                                      SHA-512:80712F7F5A1392E582C8669DB850063776ECA7D54681185561EC72D2EB4C141A3D3C848C557E776F9D24BF89DF08480A6FCCCA0DE098A265B85B45FB7E00F1D8
                                                      Malicious:false
                                                      Preview:P...y!Ki..x..8E.g1..6....Mn. J..AqO........J....;.&..).'..?.M{......4.}...Z#.e.LhF=.Q...*.1.L.|./}.5.....rl..U.......Wt...?##...;.W...S........]*..s6......W...]....i.=.a.O..}..6o..+.I..'...P.4..[O..8J'.7[S.yt=.U.j..R.>......a...&J/Rqf.7.(.R.R.x(fL....h...w..oTq.q 2rq..1.;...^G._.....8.L...AQ.Y!...t.M.u0...........T..t.+*f.........J....qr........cH.FC..W.l].N<..W.7......]...ZW..t*vM_..q.....a...rr..6..C...^.8..3.vm.s...4h..D.qH.....&..kw2d.c.^-W...I..2f...=a.M46l...'^&.0..+...e...9wF.B.ys.d.(..jz..zB.v.D..4L....&X.q.|_...+|.......(.kx.\.B... .).T&......1..!..;.|.]&H...V.)o...I.4Q..........a...Bq...oJ..q.d....C>...q...0A.+...\.ZR......=..A.v^g..I....|...&1< ...`.'Pg..B....{...A.....+..(k....e......xdj..1..M.....:..^.'n.....{m.VO...;U...r.k..Kx-...F+.e.+L.k...;4r~.sq.g8.~..A..SM..1..q|K....-... ...$.7..A4=K...v9\.0..`......N.(.8z.J$`tH.ea.6.....|Q7........S...0#.n./{...........Jo.G~.8....8:.;GL..H......].^...*...Y..B.<.>.....40..J.y.....{B>..
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.807785096681283
                                                      Encrypted:false
                                                      SSDEEP:24:1Uo/HCX5bmi6qNksdh2cdPQXjVZkVBCv38uJe4RN2UuR:15CX5v6qNndhRdIXQCP8uJZRQxR
                                                      MD5:2108CE9C08C6F2C8ECA3EE6993E8B602
                                                      SHA1:5A35CAE7667E1BEA5FEFB1D1FFAA9AA6756AE580
                                                      SHA-256:313354023144C1CD6A1330DA5092AA958841446555112BA2B8C37AA346D7B87E
                                                      SHA-512:07601396F4CDF0A179EEE030F4F824F801ED7596B6B5AFCB709A917C61128543020D62B67B67E5BB62587C76F0D6D9599642AE50B5529103CB2B6AE8D712D30F
                                                      Malicious:false
                                                      Preview:.k.r.|.=....z..}...G..o.[.............U.+.H..k..<..r..~P.i..u^...^.....Ziw.t....P..N...O.......;...Cm....P&.JNH..><~!.&..a..=.h(.ai....ot2..Og/..N..........^:....r....b.Q&&~...*.=6.Y>RF...)%@.v5o......t.`G..`....^.u.....#.....{q..I.0.X.n. .2I.-H...\....g.R..9...y..:.5.....s...@_!,....pS.w1......~.7A..i.2t.z..=Q..vt.xH?*+../Zg..p...c}.K..[.Uy..6X\.6.<o.}{7...G.0$.@.......\...[.r[.....2....#.......p...&/@.?..).5.8..........].t-.....fXE...'t18.=...Y...j...'.....*.?..._9..@t...w..~...\7%.4w..o.X..c.....J.....g.......DX.%..qz.QG/r=p$3^....7:.Y...}..R.......X.E..Ol.....d.j......M.;..W..f...6.Q%..g....j.....Y".G.....A8..6.)....4.Ey.8.]........m1.K|.yu...M".:..Ba.N..............4@...[....H8..E].zA..<..>W.Yc6<.......n.t.f\.......m..Di.sa.sC}Pa.X.9(.bX....a.R...)c.H.?.A../.R1...=.Q.....P f`'.(.e..+D.L..&.{..1.".G.....]R......).rM&.&....*.,).7.[c ..H.%.........t Q)....:'v......k'.@...:...B.......7.f..6..H_...D,..K...!.76b....8m.Zn.e....@.P...1m.F.).iGN.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:COM executable for DOS
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.808023602089374
                                                      Encrypted:false
                                                      SSDEEP:12:u0se5W/y52wVqveNCEDtXDmpjDs1ol3/SEPeTrttPzK+hoEgg8QroE2dENWfc28F:X5WKVistXDR1ol3dsl1hoE58yBgfRvPO
                                                      MD5:8016E59B345679E4F9FED72B000DAF77
                                                      SHA1:E7CF11C1DBA3AD09FCAFBF6596B72733458BC94A
                                                      SHA-256:1DE6FCBA6C802E6C5D185EDB55F82C44761E18B315EBBDAD27729C46F126F4FB
                                                      SHA-512:39D0D0A1AF24D10F6F89958B911F9C31C20967763EB201E74F12019385FE24CE1C76838353B65952487B133E2EA2B40763FB70BA87AF27461BF07BCB128D2111
                                                      Malicious:true
                                                      Preview:.Yke...y_f#K6L.....R....>...5!<...j..?.K.^^....([....k"..B.{..I...1.........w..}..vlA..C....Hz.s..p...Y>..hp.\v.~0<..\iE.U......[..z|"*..$.S....G......gu....c.38...2..P"..3M.i..Od.._.......ol......A..RLz..+R>.....O..Z......]&..4D...8.2..tKen.3...Me3.....u.*m.KEKQ.I.6.../J.T..!=.........,.5.g+.n.r...._......5V.......~...:...:E.".....?......UU.leT;&|....(d....7..f..-;....=.i<p3.9....f:8.....(7..@a.4)~....M.F<.W.4...?.6.[2?.@..^....R_...`.~zR7.)L.6..%7.F.jh...Y.A..M.d.x~.5r.:...y..M...n.(..^..O.0..t:....K...|..DA.t.6.....P^.2.j.|..5.....8JZG.d..N&;...~......l._Zi....P[aLR....h.W..\u.5..E..s._...;t.-:..|.no.$.2.?........}O.?...v...wv.B...*.>..!....b...-J..S..A..>N.i.....(\..M....1M...U.".J#.-..;s.U..].S.p......B......b..8+T.......w....R.].Cz.?....)....)..&...l....N9@RB=.....o.G....<...).N..8...z..!:..+..b.x.5.0m...{..r3(....v0........3..~_.Y,.+]..a....O.v...c..:)...i..1.....@..y...43.'3..k..6....p..3I..|.A.X...H.8...p......|#}..I3<..
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.823908496444819
                                                      Encrypted:false
                                                      SSDEEP:24:5CIQmShcg262+hZUKpEFKyO5sr5O/GlaP8579RS8R:5bQ52/2lE8vy0/G08/S8R
                                                      MD5:3B97D951C920BBC9873E1D586622AEAE
                                                      SHA1:E28D9E983A8268BFE93450EEAA667449FA676DEA
                                                      SHA-256:1A5EA1D287D58D8D7952E89A2620104BFE61B6F3451EC8323818B8D9B1000B75
                                                      SHA-512:B16C32AD67D331174FF7D00666DFC02168876707E174E5D1CF6983FA335D7B02C9E9CDD072CAF72999FB4BE21AE49004DB86FB02344EA0F6F0C996966D6ECAE3
                                                      Malicious:false
                                                      Preview:.RSX......r..]..../_.d.....\..Cx/.K..'d..D..+S7..H....=.z.. ....(6zYO.8...$.".u.:...UN.l`....x.2.........+..!J..O|K..A..v..X.|.#...Y.....pY..E.X{T1Eg..l.q....k.B.$Vv0.yn......gU..U.?.....@1...e.].[.k.h..g`.LGC...*..p>.'...^..I.....).'G.S.M3.f...8OPF6.....p...).E...F..dq.^9...5s..3.d.p.M..I.U.9...>.f.?H..?..gF.....`3.{~...........?.n.p6....JpX.u...6.f`Wt...srh...F(V.{...N.QyY.(i.w..V...&.|.=.@> [.z8...b>....\."...R.7...k..j..0..2b...oP.1..z.~|.}..w.1.E...6.7..i.;e...Kb.>..e.&7I.g/.....V../k..}..?P!..x.....s.....[}.Lp..lP|.}..).>+Z..$?..y..,6.=...:x.\.;...U.......>B..P..Z.c..[s.M|...E.:...E........v...R.x.Q.).....M...< ..........%/O.........i.V......j.{m..Ai.#[.!.......S....^...!..,.*y...d;.2g.....a...D.....a.M..;>(..ZO.k....cIU2.........dH...W.c.>1....[..~..H.....G.pe.W_\.*qn8Ns4.5.=R*p.....Ec..O.e..4.+.....Ea...-U..az.l...@...B..!......_h..C1............2US....../DK.%K.,.....(..~.W..i.<.k^...i........v.....C.....$..q....{...Z.].i.E#.C.i
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.804431931801906
                                                      Encrypted:false
                                                      SSDEEP:24:L1FmtQRWoMcQO8TlSQEXERqUwzEsY0dCzi+DP5AvSl:h9jpqkQEXQqHzrGAk
                                                      MD5:8E2DC5BE6258C5EEED7269734259093B
                                                      SHA1:2418F12E3A15E1D36905443BD18CFAFAB20F0E7C
                                                      SHA-256:7DAC53012EB93490C682FD68A80D52FC7F2F0BD174EA2D0AE8A4DC07851BD00D
                                                      SHA-512:BD4A6DB8E3426570F74E852FFE198455061280B6DC49509F2982D4A25C1DC57AA1CBDF216DA039B19A655B29FE0C141CE5FB4F60B4B9036CDAA1FFDE9578BEC2
                                                      Malicious:false
                                                      Preview:cA..+........j.x......z$u.?.]<..........t.....&.w=..!3.B.L.RB..@.,..dE.`..........vM..}e.`Uo.D..S....Q...[*....J..oR..7.fc..YO...e..F.....$..(....`.GY..&...H..d..v.;5...b..u.fK....^.c.....8*J..TR7?.[.AW....%9.......<.(....8,....."....I...nqz....}3$.&"Q{.$b..^oy..y.5..Nv...a....o-$....t[O:?..|$.z4...I.fa........V.LQ...ga.......'lr>...k.h......E.M>..a>}..8.{U..`.....h...vX..._."..C6......W..<|..wm\..*c.GU...._b....=.FKk...A.RU....L....2..Tg.`y....~.B..EG..ffN.s..d.P@d8e.1&...~6.....|...T.].-K.B`..|.(..y...S.Q..)..^.........F....M......Q&..>....E...N...*5.M:C./....7[:.Ic...X......T..:.....e....|.......XO.x...}..L....XT...V.5..^...q.5..c.........k...Z.CA..........}...^...33Ge?}.7.\.w...a.)HN.R.|..{...+...}.m...3"...aD`.Qc.,.j....\k..wP-......{{...-..f1..o.....s..x}.&I.q`.......5T...u1l8*E....vP*.....^..Q^.:...=..R..E...r.7..,..C?..Z7.;-.mg..{...a..\\...:.){.....BP(.Y.m...$..So....B..g.6:l....N.hb..T/.E.2"..u..B.............
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.773889940063415
                                                      Encrypted:false
                                                      SSDEEP:24:AkwySdtV4XilcPCuDXQKZQkcgGnwBdFKF4Opo9Un:Akg2XqgCuEKn3fJOm9S
                                                      MD5:E27D28D5FCC457C16190A392EB92909D
                                                      SHA1:69AC66CC68790BE52027FB792F48C38BFFC487D2
                                                      SHA-256:CF7FBC0BDE5046CC56B157DDD8EC821121BF3059C521BA4B72F2C649132D27E3
                                                      SHA-512:E92C7ACB1C62C9714B628A445B94E689D9F0EE9D0140C8999E7AAA0EDE067CF3A1075A6A09EE5368444F0A97EA55E9B22CF36AC9615D83CDB8733FC83D57D409
                                                      Malicious:false
                                                      Preview:..r?..<b..k1._.....~Iw.._.m..T.f2\.. .....1./D6?...2.$...uW]d..<0..w)].p.1.....&.rvJq\.........F.^.!..>..+..?B....s......8.H5...=.3..^.../bk9...W@....@jo#..5]....I...4.#...-.....5...v.`.~......$..:..jDA...o.8.2>.93..R.j.....G..C....Y...[.z...p....`........).......x`(..qD*..5I...'.....l.j.9.......c....H..Z..c.0j....V.I.)...n...D5bh...M....1d.-6../.v.o..i/jd.a..t.&..\....c..s.f+u.....c.6^Z..L...R..k?..C.nx..`.e.<`..Djb....^...U.B...q..A..C.....mg.H.zZ....$_..`...x....v..{.U.?Gmk.........I..U.+.#.....d.ig...@./M..57..e..L.C... ..t...gO..{_.L.g...IY%.G.....%...B..|.9....2.&.@a.$.....(..Gl./.g$.P..ph.`g..a.n.."..E...|a7.HNv...6.Q!9.....!.....T{..D....4..)2..b......4..pn-<6.DyI.mj...^<D..Ti...I.s..Mxc..d.....G..2{#+.X_'..*.="..-px..<._.w.#8....:.fAj.C......_..>1.|^.W.4P&.....+L..9..p...;.k.Pg..O.J..VG......X^..cA..>.S.ZM(..lk......$....(...lH.P4...(.mvk...8.D...!...!y..a.s...zh^K..Ok=.~....8{.k...!.8...*.> .?-.k.....P0.>'..6..?G..3.t
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.804804334147068
                                                      Encrypted:false
                                                      SSDEEP:24:XbVPqjNGLB08oLuGX5LNHmV86IH5a2hm6sDv+VbSP0vqR:rojuSPuur16IIV6sDvmbjY
                                                      MD5:FAAB128DDC814C1C34649F9B442CA4A2
                                                      SHA1:E70399894F2ACB51AFAA9BCA5645843FC08BFAC2
                                                      SHA-256:4A759323AFEB3942A65D1D34C0683E7D15C9A5FB5270CA400373E4D7A61312F6
                                                      SHA-512:708E5C7D5576348250625CE0155124F6124C8D9A60DEB671864E94A6B38FBABAB8E9CCBE61AB2C59AABF80629C4608847C67674DD7BD19D231DD0F16A17FE1E5
                                                      Malicious:false
                                                      Preview:.!..c.N..Y....u..I.1.g3.~/>k...........Q..L|.w.+....tV...T.....p...j,.#>...g.....<.1.}zq.{...x..5..@.....3)o...../..~.,......<.id..v..!#..4.UgP+...0+...B2.e..r!.g.(.....-.6...m....;{..'..../....T^.WV..hEA.....b....HW.UQ..P=.&...P..Ahw...V..x^C....Dj..lm.....{E D.a........Yvb....h.;..N7..].......?4.I}.@...G...=..]...*."d....G.....b<I.?......?g.."iq.A../.i7i.'.....g.{&A* "<]...{.K.[..6.$l/...JU.:./.1..l+.X.Z.i.M.......|a.d...U..\.ved..CXT..M...d.....9..........~...(..a.-.t).@....v....Bw.}27.}2..i'...0..3....u.T.Rvc.....F.."=....'k..u@.,.da!l[....>W.D..........8.w...\Ym2..P..7'.n..f...~..!....`.i......=..+3.......n..P.5.2..e....N.3.8.R..vx.;.6..O0GmN..w.g..\..).;...2..9@.6.......9....hL.{[..Y.9..A......bg.)..{(@..?r7...2gn2._iZN.v.O..v.^....K."d*)..W...N.cH..xrU.t.-..Z....I.>...;....G......^...(.!..|C.^v..p...N..V..3..e.m.L>.H..I9...Ng.9.....y..F..u=f....k.Q.la../z4If.8.=.*.9..C1.z$.u....#..wO.R.&n...\.(...;tJ.F..3).m..S!......iI=...v1.).
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.829735494148207
                                                      Encrypted:false
                                                      SSDEEP:24:Xdh4IuQK25RjjO8+xfEA1c925MKEoq3zfiLHzdRzf5JEM9R:NhjRKexq8E96nKE13zKLHznfpz
                                                      MD5:D3514BAEDE510F010A3C3E77E00D6770
                                                      SHA1:49F785448B67E0D65D591A3745EFA4C0EEC95940
                                                      SHA-256:E393C5AAFA3012AEF99B8ED740BD003856BE71ACA67D117FDFAAC2CC34B1EF26
                                                      SHA-512:41233737BF8551D22238F7272DC36395E7FDA8A1E84364714721719611F925DC7E0CDF7169989050476CB6CDF5539472B3D8B10536FAE263F81ABB77E3EDFB97
                                                      Malicious:false
                                                      Preview:'........GQc..QLZ.S..,...9<.k.57.... ...Y....>...M..........92...h.l.......j.)..5$.]de]/49........C...\.M........7.U...x.p.......J..*HlKS....N.../......%+TP..4.....b......%.{..w...}4Lse...M8....O.~-5k..%..|81..L....?...T..J@.<..A..,P\.4.h4..)Q...Dc...}.......:#.?.b'%...q.....4.y..+#u SC4.y..=.......e....=..S..........z.....W.6..........*.t.....l(.6.i.|@G.8...|+2V....@G.T.c...5.s...q...."...B.*..K).....v..c....!~R2dG24...1.....!/.1?iy..pp.."..+.6a5A..F=g..l0..R.>^..S.._..RV..Ic)k..Tt.|.>.".t..*...D.\..N.:.u.u.1Kb..1+.&^c.m>..U..T!.Oo..6...q.g....@]"X. .:Y...}.........N.<.......x.7..rR.S..n.K8W..J_jI1.'FS.'.n..pm....n..ZI...G>.B.2mx.}.N.....$os..Z...sF}%.@K..@+?.m.P.ssz.:y...9m.....H..g..Ut.8..3.....mj...kJ..l.a......B.d....t......=....=;.G.'...c.......}&..._.*.0......r.G.R......^._.n..q.\..S.h.b.H!..W.d.P...j{.O..ER.Z61./=...{...)aO.!@/..%`.....4.7..8.F...f0.2 .8s.*%.K.;.H..My..1.?...cb..hGS.Q.HA..wq...gLj...%S]i....([x........
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.791038479038133
                                                      Encrypted:false
                                                      SSDEEP:12:IWjyyHjiwLUJRnKeLcMnRfloItOHca3FcLnmiBqWR1eWmeAl820w0Z2IOw5BYhex:XVWK874M1lozca3FYqWR1eheAn0SIBGs
                                                      MD5:5F8496912852B92F87B6D676B9D611A6
                                                      SHA1:488505E842035A45D2B2EBB6A55DDA73AE077302
                                                      SHA-256:5497094C2EAC07C6A6577EE4156C6EA2688B08D8C729A616A7397296914DC774
                                                      SHA-512:EB229DB25F9A024F4E3E8DAC9E955D8847392DC383D2BCC9637016A1BF61DA958384195D01A0459795AF7FDE0CE294C55BE1F2A7B1D3D51A0165C8236BFEDD53
                                                      Malicious:false
                                                      Preview:.l.<....a.&S..R....VJ'C...%.n./.R...I...J.j....R..H.]o.0B..@...lL#~.n..ycvz.*M..$.P...L>8U...!......a=-..j..C.@}.+.P...../..~../I......G...s...t<m.....VeN.t".f*.UP..].......I...!W.a'..\C..>...rB.3.o.....i.....(........*..)(.].......'..2..n<S.|.G..a.r#...D.f..m..3..c.R.K....?M..ru{.....$...S..[7...7x.n.K./.?+..X...m....\.k..}.}...[..>..3{2(...#~~..Hp..o.w.....o.]R.*.|..lA3-.!...\.qU.#.i.q....t....%<.a.z../._...#3...H...hj...qIT.%.m..H.gw.Q?[[o.zk...2w......|..;S...)|~k...[r.!r.>....F.o..Gg.....~.C...6._.`...|h......)7U19....5....XT..\.5..t.f..q..c.1s.5.t<../......(./s.b..J.J.M....k.w.i.y i..L..2..:......P.W.`.q...:...`.......$f ..m.V..#..=..P.w.S.<8,......a..w../..|(x.../c.N...@.D..9. .'.u<Isv`..q1U.5..c.....%V3.Y..D...w$.:X.....+i=....L&./+\/.S.9,xP.S?../.(..........8.3...*.1.@ZP.W_..b.W&......w...q.R.],\....-.t...QF..7.....>3.....k.. ...MaZ.7..P..\9.g.U.....b....D|...y.Zw[....h...!.....wzrm../3.r...Lz.a.W.r.74..f.d.^.....Oi.R.g.......B.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.786974988220282
                                                      Encrypted:false
                                                      SSDEEP:24:NTsiyP4Zjh01srvZLPY94lGtsh7GP8Ooyoxjh9oM:N2P4Q1sjlGGhy8bZoM
                                                      MD5:4B9AA02A802A3F1000B33F19C5B4DAD0
                                                      SHA1:9965B5A84019FB45B2229EF501C964B5BEB5581C
                                                      SHA-256:7AA1D065890377017494D71BC31E493CB7055EEE95DAE67E6D410F3F794E5710
                                                      SHA-512:656A68CDE95C6BF0938DC4123AD6FF76B3A9DEEEBFED1ABFE6DD072A543597A2ABD87B6C11CF966C5D2B044C021595A48ABCB5DD0DFCD33404DBC4EF3D283BA5
                                                      Malicious:false
                                                      Preview:.L.O..G.....Q[t.&..0....j.[......h.......)........v~....A#Zs~..Q.C#.P.NZG...?.3..".;3.....Z.qh..t..%.hf...\k.!..S-.F.r.r@c{'.P.&.=B......J2n.H.G..Y..5F]F.'..}...Ok%.Hv....2..so...........*.<.XG1....s..|.;{`..2...'...,=...-...'.H...S~..,)..B.......&.C..bm[.n.A...Y.....)....)...\..e....__.....(.H....7A.........z......h...$.7.P..U.....!....n.r..+..px?..I..\0..S.q..e.XI...*.y...M.Zx...r&.{~.n.}......T....72]}......aI.......%...?_A6.V ...x..v*.g.......I^r..{1.=.... U..Uu....b)..ha&.....|.f.i.u*0..r.rp..9.!l....J.._M.YO.4... .F2..\...^.......x.B`N(...5.......!...J......LA....}...?.....vo.5K......Q......P..d.^..Cc..x...>...7;.U..k..VI..%..U~vu.P.%dK@..6...B.<a2h.O.........S....S..K3.9......1....Y:.n..,.Ul.....w*.*...\4.i./...q...R*......;A..*n&...uj0/L..`....8I..$.*wr38..f..n.lJ...}... #p.=Iyt.iw.N...J!E.d....I$......7...D..=....A...x.j.....g0.V..$.y3..pj^.<.i/.o .{.`..5..Z..Z..X...c....A..... ..i.`.F..5...c.I.h...*..D....h.....Hw.3.P..s.#B..d..bP.U.g
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.80494261341535
                                                      Encrypted:false
                                                      SSDEEP:24:Dv8GLFhZIdb2Q2OAwJaGUkH8yCTjsm6ad6IW7WEFghuKBn:DvtDZG3bGNdvW77HKB
                                                      MD5:2C0AEE372A6FA1BB936B4A10FC6179A7
                                                      SHA1:3DCDC7BF262D90FC7E76AF7948B3B5028753B170
                                                      SHA-256:A988C8B843D7F39D6C8C2EE5261333C7F5D7F31C55A574E2C1BF13F88046D79C
                                                      SHA-512:1571A094092EC91E7C63B35093E1413DC785106AF49162866DB363E7BEAB6DDBB57CCB725C5121CE60CB9A5E79225A6F6CCF2273FC1CF1E18C28416112AA254B
                                                      Malicious:false
                                                      Preview:0..C..cm2SK....iO8!.H..x..4..*..1..@.w....F..f.....p.%..B.A..'b.j2c..T/.M..hH.\.W......E;....{.o..R.:)....1..5.>:.H.)l..o.{......kZ,f.(....F....=ov..`].....V.?.9^.e.1..D1.....Q.p=F..;.F[q....R;j.C6....;xQe......e..w.......4..K~..iyOo.$.T!....p.i^?...]....k.x77..,.O......L..4.l....%.....6)...'o.j.!...O..N.q$~.h.]...Y.......B.g..-..I.|)...t....wB,w3j.(.I...h..U].c(...4ovw:.=.r]...O..Qk. n..c........qW..|......1..$. YL..V..N........a.Q..).Y.>GL@|Hq.!2..1./.Y.?..O%].s.;J.D...p.v.R.......:.E..+..b..i....:.9.b.'.h...0%..tn.i...!.,..\Z<)...x..w;.....o.S...'{...'j..W.nY....G..&4.i.3.....>..Ny.&.@.to.L/..R....gr|v..B..@.m......p.2.3{A...j.?.$1..V...z~...3PoP....euP]H....d.-..y.5...........&...1E...F.z.t...3....M..{.i^Z..aP0.o.....e.C.1K.|.U...`.e...UP...E......GG..q..i.....%.!..};..;y._...u...;..?SA.r.<.Z..-&.....z...M^...{?w.A....U..o.3(..mtU.k.F.#.f.B......ASO.6..?5.......u...;....`...<..Q.}5>.S..2./~...`Q...B&9..#...Z.."b.>U...o.%.....>.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.808550909717734
                                                      Encrypted:false
                                                      SSDEEP:24:A8ieResCF3ZePC9nnuHrCFyQLQlPuGVBI9FhEeTdOH+m2/QSmmZze2K:H7CDe6NcmFX2NI9hoM3ep
                                                      MD5:014CE7AB6FAD2A089A6BFE79FB3CDA74
                                                      SHA1:FB10136270678781258E02816E34A95A1A3CBFD6
                                                      SHA-256:94E1E42E954947DC045D47538B3D2F0FC495DCDDB01F6B1EF9E58E4B7FBF294D
                                                      SHA-512:1ED3C7598575EBF5FBEF1253DFA8F01893857C3BEF928A42AD46058D3EDCC85BFF970F68D67BD3B289184CD0B06C7AEF85500F57BF6DE8A2DE8DC6BB519E21D8
                                                      Malicious:false
                                                      Preview:E.Y%.s.........._...\.rW&...@*.C....cR../.cHI........C.z~t...+5`36.{(.._..c....+..~I+8..].|.D.%.5..U.e|..'.$..Z4..{.N...fE..F;..n=......d..S2..?.l.&..j.8.|$..%..._.pN[k..Q...P|..Um.%%f|".s Z8.....x...D..Y.S...q+...#E....5p..&.~.\.qe..y.'vQ..).MS...l..u..;G.Uq......!..4.....)...U..$..M..d.=...~..H.I..#7.k....[.......~!.D.S^.M5.......(...5.B....<-[]2..._.,.A]3V..,o'2.`.^....5..Qc.z4....rk.&. .Ei./.v........b......*......).....M....x..H5.........q3.:.F.....F...r'.I..fx.$.@t..-_...H......U..?6.3.....N..k.Z.]9.........z|...Ln9H.t.^.u...oA..,.<.q33k.:....Y.o.k.U...7Ff............).|x.j....d..s....W......N+.kC....T2XFuPl'...}.N?....0IhE.T4..s.toM6e..aD.6...B.-T=c.a..i.p..QG3.v..u.I......{.......a..;d.)..s=g..8.......|........)).l.... .o...T..r.E*.#......6u.F....\.O....@.S...bW..KW...I_.K.....A........(9.7A.a.s...:....`...........n....>...Q..]$.8T.Y..s/...{...<...rc.A?...=..O.......h,;.....k..F....._.....g.v.....R..X..\wt..#M~.a{.h>..8.]?.Qr.....x.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.837818733034449
                                                      Encrypted:false
                                                      SSDEEP:24:uJlHuHEq8Dq/P5TAE80w6abDTeIWEDuPVQtQiN/DRMA4:uJ9M8wh0t6dIWmuN4v4
                                                      MD5:15CB1878593DCE1B2CBCFD3185015496
                                                      SHA1:F254332CA8630EE7CFD934BD985A8C3A2F5DEA9C
                                                      SHA-256:F8984CFB03A1BD246DC153685579FCFEAC15040AD15F1567F5534A23085589E8
                                                      SHA-512:D57FF49182F0A97F7C6982FFC3A6EED3A4F3B1FBF067932C2A55A2FDB39568714C7F5A3073BF0393E8CB42E32778B2FE9129803B372464150BCA956F5E680258
                                                      Malicious:false
                                                      Preview:.1.^....:Q.|U..z..(.c.*....."3.._.X....?.5&cVUOH.....$..Y...E....}[.@..uW..)..<mAm..........50..%&.2M............b. .....cpT.....+e?..7(4..c.5..t|r.l...??....TA..N.bK@......U..q>...f....uN'|.y4=....pq....6n..V.{y...HF@:.Y.....v^....IQ.....D.Y...l.G..)..4..~c..M.B...H5.{.k..*..Ef-".W>.(.r.d.Ht..P....FH...+.S.1#..p..9....#Vn_....l..p...j#..f...+.o.%Dup..3[...AhF.-.3\.Y....#..1..4..3....?.W...,.B..%H.wCW.......6"..-.CIM..T....{D\.....[~p.?.......N.^.....1&...x.q.tA.r...g.......".$.A..yzSE].`...Wr.R...~6B..OH.y..k.O......X.u.O.!.c.9..2X...a.....%..79+.a".....x.`f... ..' ..<${'9..i..(..[S..\.....mUAc.3L...?. ....|Q............_....:;,.}..u7)W..n..".._.6|....wK..,..Y....$....}..R9..,[[..n.:U@&.zgS[......I..(x.o...c...$........}.+.C.].@(=..!.5...mN....}_...'\9~...j..~%c...0.X_E.$,.....4.....HT.$+,)r.E.~G.+......i...2..m0......L.F.|....(..K...wu1R*Z.>Pb...Et0....,..e.`T...b...S.........D....-.E..O..C.......i.i.z\.x..W...v.A8.M..O.`....U.^.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.8324955628276856
                                                      Encrypted:false
                                                      SSDEEP:24:Q2h28MkWTQ1MjM6zTLTk1EU65bWfZ2/YWzEWrICeNcfQvnCJOqkPadJU:T1MkW4M5zTE+jFG2/3GNcuCY3CU
                                                      MD5:623411FE65ABF8AF9067AE289FA44F6A
                                                      SHA1:8F479CFAFDEE35324BF02756675C3CB71F9F6A5E
                                                      SHA-256:2DEFCB9F2835BC4FBB88B7C1D309C55EF14DB97389F2F1CF59A63E145B2769FC
                                                      SHA-512:F59A250FFD43177BB785EC422B74DB71AFAC2C3F6E6752AE890905AC298DDBA57B62219DC344CAAB1C8033D1477087B9CCE8C49E2318CF2A0399D0DC41550B9E
                                                      Malicious:false
                                                      Preview:3......Z..t0...'...ai..;.s..r6.8..O/.,.4...\..XU..............}.3&.C....U5.:oe7k.X6.. ..^ <..*..Av..E.".............Z_............R.Lx..<..B..dT...%.........!N..D'<.G....>.#...1...K.{.....O.`...h>.44.R... U._.v.[.N4.3...r.j..Nja,w.:]3..X*sN.....v.F......<.f.......J....u.......y..D.!M...?....hA.z...u.umE.o.H0.&..|..M.I..I.7...;..73...s.m.Q..../".P..'.)...+j..v..g.b.n..%~.6y..{"*>...4..B.=r.]".;Wb..u.M....W...k\...S..O.....gH......xK."p=%.2...xo....`.k.E.S!..W...(O..>..C.mJ..>.K5.Z'..w..yX..OR.....$1.^.I.'..v..s......5\....c.x3c.T.....l....D....d's......@+#..t8.y.HO|.z.......1.g..^..=.c..D.>]..x..?...O6}E.+....Td..r.Q...D.&....kM......}..O.,?D(.....-..>.B~....V...F..QT.(hn.g.z{.....|-&T...M......D..2xv......B../.G M..... .._c..)....#...Y]b..gZl...U ....#.WGI*@",.\.y6..^D].;>`-y.v...%.8.z0.F.|.(...".W..+.t.+...`....R\....B..&......|.G.......7d..`^#v.*.{8..LY9.X.c..\p...8.{.g.Emy.dH_X.al...VzO..Jx..@P'...E....vs..P..:...a.?T..Af..8..
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.830356495591331
                                                      Encrypted:false
                                                      SSDEEP:24:k1l8qhAjEwo+tccFCrqjMkC45yUt/oQZGWmsNQO1fCm:YdQG+tccFCr7kC4cUfZPmaNCm
                                                      MD5:C98BC314B3DC3E0C8B44B7589DF3E5A5
                                                      SHA1:46D166FED674344B5A9E02F36670045C452020C2
                                                      SHA-256:A0DD2B70CD69AA84FFC3DB10BC0CE8D5335D24F18C94DFF3D21780D694A7A012
                                                      SHA-512:87C52387A98D79AF003141EF62B52D714D346C774E8106F89E9858F723C9ABDB9CF6E7FF389B60CE5973AF5CFD683B5A9FBEB4383746629D6A09DB272EA3ACFB
                                                      Malicious:false
                                                      Preview:..&PGZD..^..C.@.\.G}M...M{V.:....{D...X...S..||..Mf.{(....fE...B../NqAl.?..`.h..1;~~d|.)..;L.+F<...9... .L..v...5g..D...=..<9b/.2]...mM..!l.=......,*.r.D./."...U...b'kd.....B+L@...O...v...~\......>`.M..%.Z..]....Nu......d.9..g....i..jTCR.[s....Y.........T{.?...!..t9....JUT.Jv.3eo1.`....d"L.!..)P.3`.g.:H....E#..*].28.3..:Wo...-M.....__.F;..sT.$...yu...m..(.*~...p[e..B..-....Q.RZ.Q..i...P.c7..Y.`.5\.....~........:.-.. c.(,.J.u...m w..dUP.......r../....L.o.:..M&.[..!O..gf..b-.@...Q......0.a~.=..L.W.%..I..S.YB.d....j...w.hk..4...&qr.O..I.0.<.!.9#:..bp..c.Mvkx.u..W..emP.B9.Jj...v.l.f..........W.e/"..)..w..`....Q.y...>.eR:.b.n.6...[..j.Z.X...Xc\v..2[.+~......DQ......I..a...4...0....6.B.}.O....9...o.jZ'..Tk8L2.n.Py..m..{.k.P...s..a....]3#pW.$Q..7}5...Q.......O....x9....MS.l..-h..3.va.^...n...N.Mjf3...#+......'6.\.F.....fGg7;..W.._.P.2.t]7.......Z*.u|.S.6....|...a0.u.a........ 2....E....W.D.I.;..d.....=jRf"&...."]....9....G2..8._.Kc..S..D
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.811734626976156
                                                      Encrypted:false
                                                      SSDEEP:24:oNKCIhdJgnweAXMIsr7VTQmwlTkDk5wwIyhr:zRrJgnweGMIslUT6KwwTr
                                                      MD5:052CE1C15EC2E0170596DBBEAC543535
                                                      SHA1:34089896DE94565C0A36D82EA286A882913EDCEB
                                                      SHA-256:54B0376043AAADCE4E484DE56E198F78289FE20E095117DA6726EC29BF635B4C
                                                      SHA-512:A9CFFAFB0B431BFF1D3D40A29533550223834646950CE7125B6ED3D2B6F579496DE1C7920660C2E2A775B546D8B201457A1791C13482A8A49FD54EDA4C1CE617
                                                      Malicious:false
                                                      Preview:iT.d.`U....s.U..N... ...I!.<. !..0.3Z.u..v...\i]...C.L.*Q........b7.....=..U..,...R..T..re. .4lfO...^?o..m7.qF......+..*r...j.....".<...s~.,..g.).!.4..C.F..U}...c?.7...U8....a.}.u.i!.........e7.....-.L...Oa6..g......V..0Y....@.7..ft^.......x....n..?p....4^f9.MD.?Q./..2..k...j.e...Z.x.D..]...t.%WH|.-.2..[...N...o.....p......!..W...f.1..w...+......HRl.{U....w......\5.}F.U..$Q....8].x!...<0...5.....{.7v~...H......"Ma-.....[S........I..\.U.w......Z...j...`..B.}..Ui>..........*..KF.O..@...:...(...&......_,j.Ti..p!.T...ex........CU...].<..2/.. .-.}#6Q.[w..^......P$.h... ..rV...jJA.......V9.....5q~Na.4x)1.u...'..dg.R.=.Ck.W..OGK..`....X.51.g..G7j,.l.A....h..^.(..r.^O.p.N....'..}.....v...."...+...T)..[H7|W.sZ........s..c..Pw'.@f..W$.z..%h.'.O0.!.......#.Q.3Xn).t..z..^{.O.:)..<.U...%.c=.OHx....U...,....E.sx..y*v>B..pX.4..uoD:.?%k7..J@gvEK... .._..s.. .8.....n.....:.V.b.z.WGs..-u^..au.j..D...A.....a..j...:1..lk..#....t.Qg..8..mY
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.800250178020821
                                                      Encrypted:false
                                                      SSDEEP:12:npoaw7kGZGA8Owe9rgqWvl18HZSO1h7LBKbFWyM65XQ45Y5JKGx0CoaFiNwRhhcF:npI7RZYqWDW7LBIcyMmgsYrKGxCwVclb
                                                      MD5:1BBED22FFA65AC4EE42D648160BC1FB0
                                                      SHA1:03609242768AE31BD93AE663FF2F2A36DD47F15E
                                                      SHA-256:A6DACBFF723EC8B226264346DC7A221F203E1133527E9DB94FB188B6B3EB11DE
                                                      SHA-512:49E83B6722CFD0C45902BDF1C0E4FCC217BC3B6342436D552DD01F0EB184F785D548FCCBB8E5B8B861D71F0FAE9339C237FD4193DB06E8C826347BA165CD3AE7
                                                      Malicious:false
                                                      Preview:.W..x.Z....X...&...h..(z...*E.^.cI.q...w.wMs.s.{./.h.$y..b.....".3=..[.0.0.{V.D.CMn.#..O........k...P].dRqmj...(.-.........".wY$..|.-.v4..#0.-.....c...js3..8...%.).@.o.AU.[A.2e..?......ev...>..\.QS.X.3...78.X.|.K..h.Q\..x..a. .Z._....l..G-...-Jk.,9."3y..b...FJ.(b.. .S.&Z.../U.W.,......J.;.....@.[.ed.1... .....9x...C;hX.4....@!.]^y.@.&.<...M;..JW....u.....6J.....^.J....@.O..n.p..=rX....:/...Ht....1..^z,.h0.;o..9...&....x.A..1 /$.o.hI<v..v..i........-fn=6&..._.%.M9U..B....Q.....+O.....~..e....d.........v....5."...,..S+..x..o.rfb..._.b.NI....\I......&.....{n!+...e.......D...J...........MwG..l.(..+.=.G?.H..5.J.............:>..EKXR.h.~..?..h.x.....G[}...K}<..|._.....w.>....x.;W).8...!W.".p..t....Q.1.'...@....7..$.nx...b.He..'...:M..F/.(.DQ.......S..1[.2......X...2D.....E..'h....[...I..8.e...H.j...a.B.W.:B|..nV.E=..fSO~.....C..+......2..s.\...&...p.Fy*..|%..w`{..UwG.......c\c..=S..cY.g.b....~qT!....|.K..7.r(........).`.....`..d../.....M..}|.=h.F
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.820552761983576
                                                      Encrypted:false
                                                      SSDEEP:24:/v8+SspC3bAulADIYWRWu36tCN6Pr+wMAK1lFQB4:/EQp9uyCEuK1Pr+wMA8B
                                                      MD5:30A5B9ECF381643007C35A2FB847454D
                                                      SHA1:38FB1108541F4978B6FD629BF2F331186B4A9F3A
                                                      SHA-256:E51608C34D139C62EAAFE79A6CABF5DAA0EFAE3DB0A38C8D074F66DF9AB37191
                                                      SHA-512:F6F12072763C453789947DB7DD6770DF38EAB3AA71AF9EA785B220FCB32942E48DF4296B93E38A3BCDD378AB42337521359497E2EE8015ECA54B63C1C2D2881C
                                                      Malicious:false
                                                      Preview:........jC*[.....X ...\K....U.Tx.>.g..... .sHN.k....C..xv.^.'b..B...%...!......Q....G.d.......e.....'.5..O.,... F......Z7m`.-.Z-X.$..Q`q&..y..}..y.r........HR...i........g.M.0..r.v9].F..9.L..h~.f...R._...G...X..Rb..A;S.N)p4..w.`.H .:1...X../}..,....E..a.6.p~..Hiq...q.D........aI.......Bevx6..>Q.)..NA..I.}.#:..d.E.*...s..H.U.i.....s.J..q\_.>..$KT...9..vQ.Zz%X.pU...uq9....A...lb...e<....~..-...a.._6W..%..z...S.R7...K.Z.m.#Br.r.#|...Q...\../0#...B..n....[..M...N......)p.$.].6".Z<.{y.......[.7.1..->H...P..k.N..@.8.o.@Oe..r+ogW...W.._..T.......`...t......J.Q..e..;{..V.Lx.......?.S..}>....v/..Ff.s...(.:.z........r.V.....kpB......99_.s...G....h7.q.i?i.l.I#..M....y9i.m|.>L..._.b.t..p....R.q.....qR..}.....$J..7.jm?.|.G..u.9...]IHw.n(.;..h.....a-7.gk..w.A..x,.?).8..%.e......~......2..T.../(2..&3K...!...JX...Z...L...biS... .s..)..0u.s.?...,..Z...S8.,$...y.Bb.P>......snd..<.ls..Nh.zL...f..z..m|Z..F..U)...Jj..{.*p....g.XY...+...C.f^...E...Ob...Or....
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.821499172780964
                                                      Encrypted:false
                                                      SSDEEP:24:9k8heLa6qQgC8MNYv4CQrukqdg5h4E8jeS9C6c9En:9VeLaKgC8MNYvrQrukqdI78jeS9t
                                                      MD5:A940A0F7E45C2936E4A91AEF17D639FC
                                                      SHA1:FB25FE8F010C073645AEABD155A5CC28F2E8825C
                                                      SHA-256:C13DEB4D7337E1BB89170C37B2EC691C62D7EA9B1B9E9FFD22A9455177435891
                                                      SHA-512:4495EB9409BB60DEB34E3B13A5984A5FB0D06FE7181788D1FA960187E40E57781EAB16A355A6DA14B0AAC433B82F440F40BE3FD52A90EFF438DF9592B3C92129
                                                      Malicious:false
                                                      Preview:.b....ZV $Z... ..,.:<r.^z!/.......]....R8U..Bd.....'.........{.zE......e.I..U/.cP.L.^.p.m.K.....[..V.g...4...en4e.+....w.I..=..,............HbE.o}L..F......k.OgN#H..z.T....2..Q...tf.^>V.Z........{..KK.gr.A$s&5...*O........f.....).B...)....8.1..C<.sS.Y.........B.O.Y.......[q(L..A..._.*.).YZ.~.B3..=.\+.d.y..J.:.....K.m.......D..1s....XrL~p...c...D..?.Q.Q..1..wD8o.......,...sh.h../.u..y.hO...a. bt..{...N.4..!.x..K.g..&......P.D....c..[.l1.a.k....ZH...%.8......J!.......{.....P!).yS.u..=LWN?...)....5V.G.;...4..!.*.8.21...u..../."6Q0.{>..j.Y..+.=...0MB.!1.e.wz~jp.*....9..[.b.KP*| ..e>S....f..+E....b...n_..;In0.',.Q...{...J.J.t.{H....o..e.T.E..o..4.?...zd..4g.[..c..]i..7......E.i..]..].\6...]...v.[.r-....?.P.....K..X.....f.......V..#..c...)/...$t2e.\b..HX`.2S...8#....0@w.Rl#.p.N.3.dB.;.k.U.=.......cm.k..Q?;....#H>;J...Ai...zSA(k...Bm. ....F..7..b......;....>.X2.CU.P.0/)Y|)..[-1Iy........#8hx..R......Bev.."..9...$nr....F.....8.mBX....~
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.832562061085807
                                                      Encrypted:false
                                                      SSDEEP:24:h7X9gVBHnZYuXv4pfX8yt4JNAmdR+2poeTiveBLOQpqej+NpM306bEaR+:h76VdnZVv4pf38dR+qTAsTqEACZNR+
                                                      MD5:1A507BBDCF4E034138CA488D5E981FB5
                                                      SHA1:7215F40F2F4EC2AB06B90D660F37FEC66057B014
                                                      SHA-256:2D3938AF3A824BD69B1854B3359E85BDF801E07746A0788DD71E7C2F61542510
                                                      SHA-512:4874C2B03229C3FAD8AAD26275D25775D45F78F7EEB355D868A08D36532D97D1721843A48A0F75BD1BE61406F74EC9A6E34024E805E3706E883BDEB25A473281
                                                      Malicious:false
                                                      Preview:.........4d..p.@o.6,.7.t.X.q...N*..*.\d.7x.k.tw5[..=..T.....D...7...41N..9y..b^....R..=.Y..E.L.P...H./..j.....g.#.c{.._..L...G.^.V......OL.2.n]0\}....Y)..4n/.57W.[.~?...gz...I.;1.{.w.>.V..I`.....\..l'.4....z....W.Hp\VL*(?....YY..N>..-...).+..9. .xu.O...D=?._..>.H..^.H6~Q6....|....D..i.>M.^.+Em...!...<...P.F.(.O1.D...eck......vu..|..N..H.%...2".....Rky...{c..].=.k..H.w.-K......u.C^.o..IB...l8f.Bz.o..dC.....n.K..>1&.4..F.........N.b...Fn.F+5Q.X.......?...1...v".s5;..;B.....~.).]y~sDr..2D.......k.._.T>z%........E......W..8.H.....P.5J..N.....R.e....T..T...#l>..B.lf%.z+.....d.>c'P.........%..n......2..B....Vc....H...&.........Ua.........8x.....P....B.:...z...~.<AT.7.,L.'.".|........(.E...<z...bjc.em0.[Z....'.)..kN.A.K...m#.t&Is.$.......yx... 8Me4...WC.<2...>S..<...E.=.;.......6.6..`..%R..P.<..(....M..f......^...dP.......{.j..`.|.lqqT...:o|....P..j.v......9....{!..D.P..&&L...rh...Di.I.....C...E..X&.,..-.>.\..Reu..'..Vv~o....g.,.4.J..6T...l..u.2nH.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.783786989643977
                                                      Encrypted:false
                                                      SSDEEP:24:cqDrmMrzFd0n/C/Mph4c2rukVlJikfkATIOPYgsgPAq6oid:cC5ld0n0M8Brli4ggPRWd
                                                      MD5:4BB5BA5FBC69B2F6C5E97AE9A1DFDFA7
                                                      SHA1:D0E93CBA72058A3AB420F8FBE5002353C8CD37CC
                                                      SHA-256:BC915666C81CBD4C712DFEA929F1E79E8422E6E1F0C2382A46B61B6C5D01EFEB
                                                      SHA-512:7BFCB63DE35BC0829E1006425985A6ED37CCEDED88067349B4F3FFCAB72A65790905150A1088BA275CACD1943B54B7B395B8485083F347F662AA3ECAFAE6B7F4
                                                      Malicious:false
                                                      Preview:.:Xp<....9T..Z=...n..../.%F$....n.0...&5..I3P15>$.....A...l..c..gKZ.4..%Qc.gQ....e..~xW.H.W.....3.q.o{0..#........S...=.p....".J..}...s...h.Q..........S8.(9..%....F.Q{.~~.T....k....9.gQ#.P...S.....+.baX..6R%.CQy..R#v.v%s<..z..B..../.!Q.^a...X:h.A.........A%?.9...?$g..2K.,..X.U..>...............c&.......ny.OP.l.QT....:1].2B.%.....3c.'W(gC$...%.~..6.......2..cK.,c..N.N.....s..x...n..-..=).M$FD....81..Z...R6.....h..7..@7q....m.8....WL.$....i..Qs.+.2N .R.8).~.!..f.N.....j.;......6...[.....C..:....Ph4D.....,i.nD....$...CD.5R.....g.)..,[......IC...\....y $.*' .......i.V...)/...r..Y.=..B...O%...[.v....`|./:.....?@.k...6..."j.fzwq..E....,<v....( ..-El.......).......Dai..w~_.v`;.@.b..P.Am......9.HW1...Ji~...bh.../...5....1.AHQ5...y..ZgM.......N....m../...R..r..".{..<...N..Px....^.B.............j...;.}A..?....:......6.E*.v...........S.&.f*.l......;z...O..E...R..pG^..../O.f.0#q~,.;.....u~R...{.I.....n..*.`.;vO]...... ...u..K!Q..;.8)
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.780425381893952
                                                      Encrypted:false
                                                      SSDEEP:24:HyOOlXJMNAFAgUl9ugc4ilAr4xddXG3nwSxd5lPTblRR:Hj0XJMN6A7uDA+dhWw4P3XR
                                                      MD5:079A3AA88A67BB148C32E5D6EB0E9103
                                                      SHA1:E0C597512EC46D23883BA5929044F686CAD939B0
                                                      SHA-256:B36F60F47C7301549E731972B332FA9094C7ED2CD36548E0E54180D3400213E0
                                                      SHA-512:73D63295F4D025F4D6233757392938C19AA7A04F1D3890C639455E4250DD498351D684FC3599BE370C004AD58C651BA5474690DE7CB1255C1486C6844B2CB25D
                                                      Malicious:false
                                                      Preview:`..f..]3sv|.>~...:.s.=.J...........%..d+...~t.%p.........]f$.......V....%.P.[..RO1T..W&..u..z(..u0.).P.....|-...s..78.z5..g.m. ..A...M.I...}....o......9\.....v.9........"z.......n&x.+L,...[....].w.6....@....[$...-.mL..`.....Cq.5.>"",A..I-....^..[..Kp..E......j..A.WPLA..]....U...<.P.ba.2./S.).Vu.S...I.@....H..jl......*.=...6.YjM...w...ca.C.].o.C..q..}3;..lM..}.]C....A...R.B^5M.G..ycq.....o.......7?].k.X....7p3......lL...,'.}. .7..[,..~.d..[[...i.bRTD.K|.1?:9../......x...3%..6....W`......wb.Y..$......%.Q.x.+............`....0.qzb..N....$.....]...Q..l.*.wvZP...y,b..)...tx.6.t.17.=..cH.q.]F........K...............H9.v/]jhG..Up.T^.5...E.%.ue..b.N-..V.l...........Xz..0L..Y..-....\......*.G.?.....C..V.&.B....G..$.6......F.....x./.)."|...}u.....8..-...(m.~....LJ$.`..:./......I{.:m........=..q.%...X.4.......4...51..$%.......6.&Y...Yh.Xx..-7.........9....6.O..=.e..}...D..#.{.RC.,.t.%.....0P.`s #.r{..7. 7.s....=ri)3..~...."s.$..0....
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.8066336537030265
                                                      Encrypted:false
                                                      SSDEEP:24:jYjN1Eacz8TJp8O3m1lr7deaOFlTcOJGqkbIw0T9mm:jTKFpfQx5OFATIlTEm
                                                      MD5:4A0FE191DA3B3B0E67194FB8DCEF9EA4
                                                      SHA1:0D2B882634428C246DD47FDE5616864E6187421A
                                                      SHA-256:CB2A6D22167DEA55C2B01448ED191EAFB20D4330B5E92DD125EC87989894E383
                                                      SHA-512:4871FCBE06D20A025E95849BD88DDEE0B6B7B83A88990A5E4EDB09EC2281B5C0ECEF334E7FD4AE9C364CE2265C0989A9D126D963A3C19DD500C87F2C88947E08
                                                      Malicious:false
                                                      Preview:.a..r..L.^....%..YS.E3,....(.4.W.@7....f2....5...<.6JOz.-.=....A.A..X.@bG...J.1Uj...jqt..3Y^....?+2....F....*'x..K.KC.+.%..X.Xm.......T.#JMJ.a..?.L.q..d>.....Q2.Kp.sf.....+....E..*00O.j....|....t..:j.fJJ........m}..E.F.!.*..x<$)..V....h)..BO....hx..Ux....$p......P.&uZ....i0.JN..X.@....M).....{W....=E.1...IU'..s.7...+._........5..C0...6..o\..3..K.....F.]..G....pG.g....D1u...xt..C......M.p......W.O...32.(..'.l..V...=..>....2...8m..k..j...0....R.oP....K..)ai.+..95..q.W.S..aGV5._..x .I.m..G....0.P....<.#XuHX.......|w...%...Z.....`..U.....2}..;\...0Jv.!,gb.%X q.....O....0.....^..."].`".-.e,`..Y($..,M..o.:cJ.!1;.3.b.(hIN.Xj;...U..o..'.....3.]....O. ....Ib7n.)d.9-$3..}...j....d:....t.>\.$@-..3RU....I.~.....b...r-.....,...:i|[6.F(.~...].u....Jf`.9i. ..n......Fn.8.J........3pc....."...I.6^..#...7...,C.......z..F0.Y..*zP....c.:.......K?...H$..F.......c.96..C..dG......%p..B.<..?...<..a_%.h.....L..G.x.Y.4.0k...B.d..\..[1y.+..v...*...F....L
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.8067757908688105
                                                      Encrypted:false
                                                      SSDEEP:24:djniQ3AObVooLFpg/rcq7gvIvORajcry/3+858eqC:pn4IG2pArcq7ggQeqC
                                                      MD5:4205891A278912244677197468271CD1
                                                      SHA1:DB0A30B0F0C056A57281BD8175FB226D43E2FAA9
                                                      SHA-256:DAFAE282E12E60431B16F0619EA1EA0937FA2BCC32E002A27A9E7C9C7997D78F
                                                      SHA-512:F72288C13E29A21C4C35FA87DD4F3D1D429A35F6C139CCD902CC7FC026D889C08502A122210CC2C026D5F4D91195333B752CDAD95D6D21C11607B59129DF214C
                                                      Malicious:false
                                                      Preview:#........M.]....f...j8.gb.<T.z.z..-.F....1.OL..@...H....*...co.Py..w..?=.X5M.E....9.v.4f..{....Q2G..*.`6....l_L5...4.%".;...m.....|.;/Q`.IO.U)...<F'..0o...dos.,.$..qv..e.+"..z...WM.;.|....-?....m.*!..zYq.......G...>5ym..s[3Zt.....c..".eG"..E.\.p..v.b...bQ.'}..^.F...+..@.X..$....<.Eiy........*/...m..X..m......7..#...Q.`..B#[.1.{..p...M..S.....m.y.pJ......W..$1.oj2!'.%.(...M.o...k...F.wruW..g..0..!....s.....ty..Y4K..M.C...N.N.sK.(.>...[JV....5.2....g...F.X......#.Ad..s...dF.nJ...G.'...-yG..._.*.G7l...,..\.....x.*...Rb.<..+..S;i.CW.e..2.@...9..o.l.B...0*..bdUlJf_M...9G...7a...S.N..H...\..V...c.5T. KzV.k.z......fE..).A5..5PJ].kp....xx.<....L..}_...,.;..p.h.Q..)....j{.....P.G| d=w2R?wLb2@..0p.i}...]..|D..y...B.:1....}ZW.............%........Wk...#a;UJNCA.U..7.d.7.r...kL...-%.pA..a%.S......2g+3...n`...j.g...-...[..n...".j3...n..g9.....Z...}.V...f...a.....+....{[...+.....Elx.T..ZYJ....O<([3./>..1.%.i.A...\....'.....0b.T.....<...T.e..=.v..
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.8385689700719645
                                                      Encrypted:false
                                                      SSDEEP:24:rqoihyoDdK7RnHgutx+ks/pbWCpQaSs6tFmWwH+PBpQ1xZsYx:enhyo6gE6BvEO6BK/sYx
                                                      MD5:4CDC180A8FB391F4EBF1220881B84195
                                                      SHA1:4CC2D45F2CD07FC5DDE5490D38D2F5C9502CD62B
                                                      SHA-256:2A0C53D7744479E32A18CB878DA0A02F768D19FC9C43E5A987B09C613C085303
                                                      SHA-512:5253B81D4CAD79F99B2B5367648D097E84AD62F4C5C71EA203E53D35DACADDB443C2D88DA7D3E1264706B20EAEC564CA893239069D359405D69A4C36E5A12251
                                                      Malicious:false
                                                      Preview:I<.l..1....q..w....p....5......Sc....d..(X....e..H.x..J.=....48\...`.=.....<...(..{..%.nrx...Q}&i.,...C..QCv....h.`....d}...........~...m..%.4.....u.n..........9.(.,...z..O3.A=.[...l..D.......2.|.......B...E&[(K....~..-C H,.....4.T_Q......Su.p...;O........*l..\..igB$.2.$.m_.....sz\.C.wj..7.Y...."V.M....doVv{.._..Nau=.;iL.....@.'p.&.......#!....L.;Z..K.........H..`4...>..[E.66...f.#......N...7.O..;..A..._......G./,...x^.8...+.F..a....n.....=...1.b.>.;.....1-.F.W..h}.+.d.#..8...?S).Z.o9.T.Gat+..:9.v.....y"?..i..w...}.f...H.Pnf9..s.7.w,:.I...a..2J..P...h.w.X,L.>HK..=..-[..|.../.O..H.d...M.XR... ,..2W.......Lc.@..C._U...f......m...g.....l....{).......+..u..?7M...XP.t6.R....!...>....Jw...Z...t..0....d.E48.<.i.C..1...o}..G.......W.U.&......4..1.>....),W.}...N..;...h. ..n.o...%..X.F...SB..}....-..k>....Iw#......Zl=...../pM...>...u..i....I.=./....b..;HY..F...:.......v".q....MW.Cm]...M)X.U.....~N/!../.i.~!y....R....y.:.=`o....F.^^
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.8116259069873895
                                                      Encrypted:false
                                                      SSDEEP:24:2aimZhdc9MgP6IsZHob7AUzx3efeBMZhag6tgGRArrBj7:QmZhdHgDyQhF3SeB+1ggiAfBH
                                                      MD5:5E18A9978D2FBEB68DECD59BB7B8F8A9
                                                      SHA1:BB491B29B6EE21E79B57577A1A78D77A4C34AB0C
                                                      SHA-256:C6B22E2FA1EFDFEE0CFA94D5A0E9D6871AB7257B823AED3FB48382DF3EC49B3C
                                                      SHA-512:E0EC1AD13E5D79492B19BF965ECC9C3B842C3DBD0370B50C1982F6B676DFFB7E2DA60819F46A9D56024F067EC4F38FACFB2995C21394691E310ABBA9E57CA0B5
                                                      Malicious:false
                                                      Preview:.P...2H....jW|..p........F.._X...._fx.rt.=8.?w.q.....7.e..}.\..O.s....-!b...C.7...y.j....6.Q...,.X.R.B...Qs.On(.yL.....;.OBF..2!..it..C.".O>.d...k..*....d..@....S --5..Y.E!.W...^....?Kf.....I..'..x........ng....a...rP.......>.LE........=d._..\...W2.![.e.I...|>.`.k.Z.<Wq;<..`[`.X.K^sa.+......ko...D,.-.KQ..y.:..%....>.X..........H...A.......q..m....j-....s.?..m.:|..w.....]...W.E.fCR.j..Hn.`e..g..a.=%W.<..n.6t"..lf...0..u.0:3....|!r.u.R./....[7..z\M..".........*.c}..:A:..[ ....Q.]....;c.dJ.6...l.u.hx....."...Lm.<]2/.........d..+ydv..k...=,..F,Q.........E.d.A.....!.....f.r(.5.T.Y.]Z...57............\.pn-.n.9..;>~..".R....'...x...'2A....\$Q)9.(...%.'K_.=.........w.C.Xu..Y.)...b....T.r..S.I....q.A..-...D.<.*}?#G.e.,8..B.Z..k.v_GfM\j..J.$I...i.r.-.Y6...*...L...8*.]DQf...T'....h+..!.....H\T...d..O(.ZJ.2a'...{P.."../.gO.......B.:....m...BL".]kz..b...U]./....y..L..<...Vq.?...o~. =...X..m.&.W:9L..W..]I..\8..!..m..GS.d.l"w\....)F..}H.C...........l?P
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.795152622737845
                                                      Encrypted:false
                                                      SSDEEP:24:Ycbn7VBSzoBoOfT16JYp2iTV50EkJAZ3CSyhKDx7f2MSBqS:Yc1BSzKoG66p2ivbZFzyhg7f2MSBqS
                                                      MD5:DF32E4646E27D23EAB44E67949682A54
                                                      SHA1:BAC69BAF44981B28B7E8128578D91EE3CD0EAFAB
                                                      SHA-256:03A3CC50E7D630593E1A9E086ADCBF21EA07014F9E6A995D7431CE5BEBD11950
                                                      SHA-512:9BEBDED76FA52B7BCE3EA7579738EFBF95E23A779299DCDEE5FA4412C2866C39F52033659B65CD5B0CAA941A05039785F379D506917430A6E868B62AE5DE46C7
                                                      Malicious:false
                                                      Preview:.&.fV...!.....6?Ck.{s..3..g}.6u...7.I.L?.......b......@G.^...T.F..K..'..."2..@D..pw.c....Z.gt.......d......`b.@..]w..aY".4.(....W.]!x..Q....5..Z...E.....m..%Q.Q.u...4....C........;..`./vF....Y..#...%MJ.....47.....K..g.S..6N...2....^..~..J.[d.a.:...%ay...>....8\Zn.|.c..X...r.........B.z'....`.SZ...8+...~..\b.9Fx .7.q..(.K...n...My.....#S&.D!f.,..S..(-.*z_W.O.\.S.r....c NZ....S....^....U....m.......`E...T..p..&.@|.;.#......[fI;........#5nx.........O...B ._m.7M.xA.+.}..N.a........Od`\/...r..'&....N.........4d.4./..L..(.2C...5=D1Cr...>.y|3j\.i.e.|CCnI.(.Z..../C(...n....w.q..$7l`..a.a-s.a.[.{N..4.<&.p..x....l......x...Fu.x....zk.-....?...b.....[.mE.q.'...:........O..g...4.Q....N;9..%.....F.......1J9U..E.7..'s...././...H.....K...O....t|...7.....+L.../jD2...+L..kU..]...Z..9P^K..a...X?.......v...z{..1:.OR\..).....2|Td.,..$...q......r'R7....c0.wta...t..~m..%..mr...f..l.[.qr. !.2U...`...@..LL..e..Qe.V.r.M.-,....=L|.y.....+..D.S.#..TpsF.......
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.8032177404002985
                                                      Encrypted:false
                                                      SSDEEP:24:AAnQ0NyiiTvsKulIIRL/BNdLKGFobTZJjXu/:q0NyiiTvMlIS/BNdLKGFelxu/
                                                      MD5:B57B4C7AEC295D2C851188BBB978970D
                                                      SHA1:A62EC3015E4CFF7E2621FEAC9E48B8FBFBC367F8
                                                      SHA-256:4000FDADA312B5926FA31CD53932C09DA888A0FF54DA4D0448A0E5E1113E1B85
                                                      SHA-512:56727179D5F966D1B0CB0E122E0906B1DE07C3A47262385455B4E89DFA13F3E4E3B7B8246C5D34458B5ADB6281CD87EFA349BC81E5C18A3E4A347B4A0C2C665E
                                                      Malicious:false
                                                      Preview:}.<...:....j....1..D.1..JN.........n....(:Ss#.L`.2....=..m..X..<3...sK*7.E.. G......W.9lUh..n|.x....w..._...s.]F6g.N..i....E.G.R}MK.WU....D.df+...s.p...T.....!e)..,.@.p#?......Z.Q...=KV.K?.C..Mv.#+.Alx..+.gY.........3=......%.y.+F.....<.".h.i...Z..............=....&..b......z.8...f\?&..........V...8......o.J."...s.J.i.5..A..._.-.q$..oz....-.$.L.K...WB.F.d....,(...0....b..T?..........y........&.s..v/u...6.*L.j.v......r3D.Q..n..7w...B.j*<T..}6....{$.8...7.ob.6.M...8...R.....@H"k..3:9.0=2...R!yhb...!."...3<.......T.>S....=E.....tc....}P..<.1...l.6.F.?...g....;ds#...p.2Q.!e......~.Z}d.D.U...RI.S....B.Ah.]qg.k.....{..G.5We.R6....D<..&.iraCq.x....]......n............".w....b.qRo.D..9Z....0.......Y.?...`..U..<~.9C....m..B..)y.*.PD%..... ..S2.0..s..".....!....Z..co..,..-..n..'.A..e..I..)&K..K. .........W....p.$.1Qc./.@...a.Ni.....'..%.)..9~b....yg{7.&Yej.@......_>&,o/uXJ.V......|L.g....muN..L6(..:..8..f..,.~.........R.o..a.p.=...D..4'(..
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.785246700432138
                                                      Encrypted:false
                                                      SSDEEP:24:jiDY/POPtsHkCvXixlsXjg9fRVXu9k8rIEbb1QUcmwEIm6F0p6kn:kIepCvGP6kIxbpchW
                                                      MD5:E71956F263F0BC91D7181CD9BECD305C
                                                      SHA1:9E2BB402305B2188196D1DEB6C37F417BEFD80E9
                                                      SHA-256:8264EF99BA1D5932600E0FE6CCCD56112FF85E9A090615402C0B90E4F2C915EA
                                                      SHA-512:E4B40ADACC10316CB4C99759AF33523C1C39AAA3AACDABC4023077E0030EBDA76E17C80A81F76C4AF90785D9028FEEFBF53E10C3C5F076ED229DF87BBBBE430F
                                                      Malicious:false
                                                      Preview:X.W....;.qt....K.....%t......%./....wRm.....[8..}rH....8....D.,.n?.U.9;..N..`..\.N.M.........:.H...A).....,.)>..<J..v...}%r..>.P@..\.....0.v...[E....LF.hi.!.0..FC..H.Ib.I.4nv%.&.A.W<K.%.d.K\.....[+...(.........Pi.v...MB...K^#.W......5....C..4..s.NN..bm........@...w5.zo[S.....j..6;;0.d...iR.....N.....P.o0....wB..:x...5g....nZ..X.%....W.[.kdD...A.... ...>q..'0.Ct.%..Gh..h.4...v....)....w.".n......I..zX...H..+.'<..\..EI..>....&?..~..}..(#.f..C}.[..|.(u...^......nQ.....q.b....@.d....B....c@.N.....O..[d/\yv.P....?#,..V&6.#..5.iA..=..5...5!.;$Ap...|...L}.Z{g..,.Zydlv...sh.J..G>.....z..,8.R%H.i.).R..b..{.'.w.+}.m....j.......R.*.6.w.z.b.2.l..,.dy.h...."2..@..d8...2.%.]v.Q...,b...9.+O..5.I.=+7.V...,#4i..X.W@l...5T....|../.%.R.[|..XM....I....].g.....;A.`...iP1f.R.b.M9.F..[.PR .(....Zz\.`....R..+.{l.["...../B..6...8.5.1..I#....0.OP.-...F)....^.|X..(].i.W.>.$.K.`..".u.$..sY.M....2ms.GLk............t.........HY...i.0.^..;S....I...........!x..m....^.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.818755517421615
                                                      Encrypted:false
                                                      SSDEEP:24:p09/45VczZPMN0Ifop3pL0qCohqwV7O8WTpAPNGVTbWs2rm:6+oqN0IWp03ovxUSP0Vn0S
                                                      MD5:DD5A8DB8DE88B285A647370F83B98077
                                                      SHA1:72698E84A70C8E2D3B459927C997C94DAC79819F
                                                      SHA-256:2221F17D9246716DD8916DC61E900F6BF28ECA989C064B743BA414994B88B574
                                                      SHA-512:B1924D71A73B34A2A073128097F09791D1D779BE88A08E33217D53BA890A5EBAC2F174F02A011B5C6AE9FC2B77DBE2AEBD4879EDB6BD7CDEB9769F3FADB6C983
                                                      Malicious:false
                                                      Preview:.....u#....R.).K.....1....&...i.KP..E....3.c..#F.B...*ht{....^Q.%...L.n. .....V-Y..-.A3....D...0.e5C.@+..K....Xsj...........N...L.5....#..JH@[......{.......i.X.z.)4t{l..z1ob...js.....XL:.L.T.'.!-(}....@G..;...|..&_.E%g......c.;...d..DAO.E.l...%...:..A.F.&..v....1..?..... .{...n.:.....M.O.a....L..z.d2..C.CS.'.#L.K!%#.../M@<.p.....yW..m.w.I.{...5..tQ7.6?|.g......c..[..(....h7.0k.=.:.....q.B)....2nz...uc...!`...G....;I..v...,.....[Ff........W.5....7.*.....h|^..Q.e6"..f....c0.$+.0..6P&..%.I.H.lh..P.>.R....G...M$..n..g...>5.0_}......&.A8z.{...U.3...@. .IZ.].B5..&Y..g....l.- .h...!...@..[.2.h....;........b....*.........e..*. ....+../8..U.......T.J..K.......9Jx.M..<.y.%.....k....C.hO8.Ru .aYZ.j.....d......M.w.26.C..l]A{..Jq.p......j....S.6...$.ILG........tI..p...y.I..z...ar....'?...H....th...&*..y.{.....v>.Y`....|..{..FVJ.3U&m{..fA...L{.{....=.Q..1....fv.$$..........q..S.J...Y......~-E...$..........B.....J..(y...G}...1.JL..._.`4.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.815144179936806
                                                      Encrypted:false
                                                      SSDEEP:24:7dTIR1mfv8R0DYQy8/JBmGQvzm/mn1up0MgUA1YGCh:5TWUv8R0Dpy67Azm/mngiU6YGCh
                                                      MD5:39D0BBD1F11C71E301B6D7D1E178D3EC
                                                      SHA1:E744DF7AA35524A1893DE057E5D4D6E023C805AE
                                                      SHA-256:5D6055937131681D31B9275B08AD3A80E591953FB2C25C8A4434DDC8E19E6E71
                                                      SHA-512:ECF5AC5338FD7C375115993C3FF4B5FE006AD3C13E3DF2F873ADCA6FCFCEE89B2A129BE81B431DA88040742722B37182125A24DAB32EBC8C9578CEC49EF333C8
                                                      Malicious:false
                                                      Preview:k'...!.,K.....Y2.U...n..\x../a...[..>y...C.B..{..#..AR.N)..._..t....6XGF.ZI..2L..=......Y\W..}.......g0y.L..^.@...6../.V...;..sc?.....&-....q..._0...E.|!...,`.R.......w..h..j/..;.9yq:..K...^C......0S....a........L.{+Z.E.O%[!...i.cK.*......U~4....U.m.K.....*6.mO..}.P.G.jH;..E.J=G.3...0.5Z...........Q.P7.@.C....0.d..'x......x.\@...yX.T...T....z.(=...."...oZ.x.r...YI..d7q....,.;zX.\.VM..+.G..+.v....7.7...N:..u.....B6..N.8p.9....t.Q..7..H.K.ay.i.2.....W....Jv..J:H...C3.....qk.:..H...qY*.Z...5.. -?..`.3..... 1..t.i.<."..l...<....mr............!~...Jt.C@w..B......\.<..ed...F....+.....)..[..&...@...W1`..(.R.'.....i..C...;p.!`..../..I.K.^.....=[..2B....!yx..R.n..7...k.....R.....Y..R.@)....H4.9.....Tfg.+L..|.5.6M...T".Zl...z.>?."..uj.i..v..!6a..y..ymC...d~..w.N..V....xs....R.{.8.....s@38`.&[b.+.;zg..[`x.Ox...4..../C.......j.....XS...E......s.......l.A...N....G6...H.....,..xL;..I....6.......d...h......}.?..(S.N.........X.<Z..U-...8a.6.X.....K.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.794197672984629
                                                      Encrypted:false
                                                      SSDEEP:24:M6Ff4rJxM16M3tTYx5Y7jWUF2xf5rG+pKD7qgRKM39O:ZsYIsTYxCjW82Z5rTpoW5
                                                      MD5:482036DE068C7672A63196B9289CABF0
                                                      SHA1:C97085E9B257979BB2E24A0BFD9BB35B66084FCA
                                                      SHA-256:76C2F7F1D47581D8B4DAC1E6BC160A40B4F5065684728AB6951C4E607591FA04
                                                      SHA-512:E2DFC97F946F0FD7EC8429951507714D85091706ED20BBC7C03D2388C046D7418EB135C2CDD30E3AE8945F98EA6DFF076CA673952EFD985A4AEE66BB233D65E6
                                                      Malicious:false
                                                      Preview:..S.:c.T.t`........d.B)6....5`$.C......PI..b....&.k.\q....B......}.=...mS..V..x,.b>.R...{j7S.t?.n.`.;Q...a.j.`/J.....+..s}..H.....1J..N.*...i5.e.B..............LV....s.....F}..r!.O.(N....<.A............(.M..].b..G.!...]D...b.'..:.(...zW^/j....bT....3f....OP..r.65.(..m!L...>.$t........{....>.O...Ws.....z.:.E.dpo.#.e._......m...A3..{5.a[........s.UUs.t...h.G.T.....0....Z.g...=P..}o...r.%M..a....@.~..*..cNx=.....F>Z;S.*..;..o....'X.......T.Y.4..l.......-a.......7..7=f...,As.7(....!...#....St..9e.0h.Y..Y.....~E/....P.VR..*0..%.,..5s..8..A.|vs.@..f.g..k..d3..y.Uc.....p.B......6@;X:.......t..>....sg!<I:...Wv3.-.f.2.Fr/..n.\.u. ..8..E.............+{;....e...Z>.....o..hg.|.y&ig..4..`......#.rj*%..jBs.Px....a....2.E...bRr..*.M...N9..MM....$..u.GRrU.Dn.<.3..bQ.....S..-..$......YT.GQ.9(^.b..%9...Z_..[.iO....*...h>F,.....l.U..M......1XNsB.'P.M.t.gy.\.T..Vt.....(.f!lk.U..-=7V..A..j.Q*...M%...Ik....0.8m.Z..cJ.......(c...w..U...5.B.H.....)p._.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.798456718819192
                                                      Encrypted:false
                                                      SSDEEP:24:MuogsEk8LziuZ68QVSidpIqN/4ciDcghUuO:MWsEtJZ5+4qh5igUU9
                                                      MD5:9463D178BC7250FA437943DFC081A9B1
                                                      SHA1:60DAB2E418FF8643C68C81F8B639FD36CAAB9432
                                                      SHA-256:0144DC7C58AC98978A77E47CE71C44A3EEE935ED77C229ABF3151C1014C34F05
                                                      SHA-512:A07490498FC04629F399B94A46E6A50621EC16ED5FD0857656D4CD001C13DFDE8EB2CBE9291E281254DB68458E1465A3762FFEF636B4A9D2EE778A9BFE3B46D6
                                                      Malicious:false
                                                      Preview:o...K+;.s.v........L...a.J...Y*K~-g.X.q..Hc.VPW.f....XD.Jz.N_.$..,^...vF..o..?X.G..D.....i%.I..nd..T..Ne5Z.O.%...b..q.~.....E..).P.....e)o.\S...*.9UGA..\...<...`X.?9.w.3..V.x.y......dw^.*..r..^.h..CR...1....t{..|.v;...r..0..1.-..AYAO.m.?.?r}...9......k..4..c..W..U|..2.o..@!.jyS=dz/.U..R..C`..7.&..|..<...v..Y\o.l...w.u.-i......d.r-.....fniv#.s...9.~...q6.D..].6...0X..C.?......S..=...N0..JK|.-./..=.T....~.N=W.C.?..n.=%R.As5.....cq.'..Y.P.....Wr-...N......SV......A(...q......O....]F..e.]Q.R..........L.H.[u.J."2h.c.....3s|.K.f..7.....N./.a.F.D.]?Bq..j=?..8......3......AKO0h....B.).n..$.N.E....g.A=<d.......9.x...z...I...M....h.....<........>a...l.U>..T.....SioMl...<.........aZ...&.-..i]...).'....<0...e.~wyO.q.S"....Lh.U?L........-FD.....B.....9...f..;...?..Jg.R".....eu{=...1.......-..T.......JYt[..V....F........+3.k2...c..|'......w...iW5.c=.Br.....@...]7e.v.?L9.pa^V.8.e.u..9tx8.x....)!....!.4L.n.D2...@....C.(....."...t."...I4.h.....-..xg(rV..Ro
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:ASCII text, with CRLF line terminators
                                                      Category:dropped
                                                      Size (bytes):933
                                                      Entropy (8bit):4.710902136409594
                                                      Encrypted:false
                                                      SSDEEP:24:ptrPzDVR5Gi3OzGm0EigS1xbnS4RQhbrW8PNAi0eEprY+Ai75wRZcet:DZD36W3ChvWmMo+S
                                                      MD5:7E6B6DA7C61FCB66F3F30166871DEF5B
                                                      SHA1:00F699CF9BBC0308F6E101283ECA15A7C566D4F9
                                                      SHA-256:4A25D98C121BB3BD5B54E0B6A5348F7B09966BFFEEC30776E5A731813F05D49E
                                                      SHA-512:E5A56137F325904E0C7DE1D0DF38745F733652214F0CDB6EF173FA0743A334F95BED274DF79469E270C9208E6BDC2E6251EF0CDD81AF20FA1897929663E2C7D3
                                                      Malicious:false
                                                      Preview:Q: What's wrong with my files?....A: Ooops, your important files are encrypted. It means you will not be able to access them anymore until they are decrypted... If you follow our instructions, we guarantee that you can decrypt all your files quickly and safely!.. Let's start decrypting!....Q: What do I do?....A: First, you need to pay service fees for the decryption... Please send $300 worth of bitcoin to this bitcoin address: 13AM4VW2dhxYgXeQepoHkHSQuy6NgaEb94.... Next, please find an application file named "@WanaDecryptor@.exe". It is the decrypt software... Run and follow the instructions! (You may need to disable your antivirus for a while.).. ..Q: How can I trust?....A: Don't worry about decryption... We will decrypt your files surely because nobody will trust us if we cheat users... ....* If you need our assistance, send a message by clicking <Contact Us> on the decryptor window....
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Archive, ctime=Thu Jul 25 21:01:45 2024, mtime=Thu Jul 25 21:01:45 2024, atime=Fri May 12 05:22:56 2017, length=245760, window=hide
                                                      Category:dropped
                                                      Size (bytes):575
                                                      Entropy (8bit):5.140446565826782
                                                      Encrypted:false
                                                      SSDEEP:6:4xtQl3y03CpzeVs+bTNAUHUtxXCzaMmM7/gtrUod6tMljAlpdmqLEoJ4D6Vod6Nd:8iypzYNbd0thHZOgZUobjArozhmV
                                                      MD5:CCD2610ADD4080C4DCC35A11217DA6A6
                                                      SHA1:001ABA92D58B546C8BD54E0BC4103661F68CF92A
                                                      SHA-256:0E272CF58CC66E7B0CC4F42094232A46B6EC11AE5ED695BA4156A1A28DA41E6D
                                                      SHA-512:36DC5CE3027E8A77639783E31AC69C9FA61C4761FBEB9A819C1EB49F4A32BF2001C0441FB28D35C4EC9DD1B713576E7894DE8FD13BF14CE62A436F9619093DEC
                                                      Malicious:false
                                                      Preview:L..................F.... ....b{=.....b{=.....`.1.................................P.O. .:i.....+00.:...:..,.LB.)...A&...&........DDj....%.=....(..=......t.2......J.2 .@WANAD~1.EXE..X.......X7..X7...............................@.W.a.n.a.D.e.c.r.y.p.t.o.r.@...e.x.e.......X...............-.......W.............,p.....C:\Users\user\Desktop\@WanaDecryptor@.exe......\.@.W.a.n.a.D.e.c.r.y.p.t.o.r.@...e.x.e.`.......X.......216041...........hT..CrF.f4... .u.E._c...,...E...hT..CrF.f4... .u.E._c...,...E..E.......9...1SPS..mD..pH.H@..=x.....h....H.....K...YM...?................
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):24168
                                                      Entropy (8bit):7.9927548528966375
                                                      Encrypted:true
                                                      SSDEEP:384:7Wc6mBfuEtJgg9YSUJXHBSOjki/38Ux/efIBw3Po2JIXCiTt7S1j2KOkEjL9Y/uH:i8BmEtJgaYSURgkh38UuIBIAyigkbku/
                                                      MD5:33BCFC016F8B49E76BD86AEEF76BA3FD
                                                      SHA1:341876625C70A25D2CE7357AF42BE68271D88AFC
                                                      SHA-256:A48657096E7CA7AB7928CE4F2A638144871385CB356A71921E745B6A58403CF6
                                                      SHA-512:7BB02FE92A16682D49BCD6E102AC2EFDCA5297D158E7E5B9EA5C9D1D71E50402E1B1453E530886F5046CB6DFE8BDCB94AEE699D2B9BB8BB2FF12C88A9F825885
                                                      Malicious:true
                                                      Preview:WANACRY!....-......5...D..i.^@n...I}UD....Q@p3.9<..(.@!.....Q..4`*.).......$:9..3..|.G..8.\...:P#.qw)..7..b...sh+...$...T.1.~.|..4....S......A.q:..d.EU.-.oJ.......3.I.F...Lp..+.......D...O.2.5Ze....0-..a...'..7..?..[.$Q..)Sb.........f8.Z...Mo..._r..a..,.7.8*l#.%.....D]........F.T>tt..9.7...NpgUJ...V...(.a...\84.pB..k.hmG+.6=..+.X^9O.~m..)..w*KX.Jq..9.EdK.......`V... .Sw...#@.)0....&............. .....v.[.4.||#..LAb_.n...o..........T...Y.+W......G....Y..T.......f.r.ds....8.u.........k...M/..h.....3?.s.GJEj.-`.2..[.J......e)&.^%K..2C...p..h.q^(...j..oV_G...o...e..w_.9.N.v.......C..v..2..V.Fwy..A....L.k.b.K...*S...5..N..5....Z..*_..u."..%y...)..:x......s1^Q......h~.,. %.H....L....`.V.HyS.x....z.T...K...'.U....>.@:...R1HT.d.`..p...!~.S.sP...Z...{Z........j....E....C.*w.^.|]8Y*5.fU......5....T..M.....W.A.Lm.@.2.....V*7..=.zu.....y...g"..u!...3a~c.-.e...['......p...}C:.s~..9..s"....&T.z.@.$7..h{..W.V.|8..X,y*...D.m...W,k.Y..G.6[4......J*..?p. b.`...K..7..;.....
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):602456
                                                      Entropy (8bit):7.999669063833384
                                                      Encrypted:true
                                                      SSDEEP:12288:8++lmY/+5by+gpDjZ9/QI7cSoRXK2oGdl/rv9nI46rT3cZy:vMmY/+5bypprQI7o449vtgrjcs
                                                      MD5:CF85EE4660106CF2BA33B0C3B5677689
                                                      SHA1:40C6A3F7A39D835BD73736FCDBB2AA6C169CA57A
                                                      SHA-256:6DC9E6C27056CF7EE32E61CDC94A89894A4673943C9EF059369D0674996EF11E
                                                      SHA-512:5F6BDEEC52E6CB292B11ED0172AE5E84274683B34D90ABB31457D1B45BA2D1B14AA12059B70BF7EB0D4EC82FA243C43838ACABCFD5CA0E8D23F4163206377311
                                                      Malicious:true
                                                      Preview:WANACRY!...."..a..b7.p^....G.&-3....F.,....?.]....e..=.K.!.="B.6.'.Q"...x:....]r......~'.y\c.#.q_{..v...H2....s.....2.5=...&..r....I....&x.w...Tya..9#T.y.Op.h.?...j....[..g.=..kq.E|k'w..23..6<..]#......*"!..^lM.N......#0..~....:..co..E.....6..BWk..8s...Sl.....80........h.....5p....{..%..%...#*.nR... .{~.\Z.P..."... ...?......o.=.A..K.tv.31...D..2...c.....<.D^69L*...u;..k..=......`.q....;.."O.....=V..2.S..m.$.s.F.-.A7y..x.E.xW..%.F..?...kS.....kO.&..A.Ni..<l......A#.r5.....J....}.......(.t....h=.u9..|....e..Q5.n.."....r(,..z.....BZ.z%c...[..Q.T......L*.....Qc.d.....TE.+.#.6...%.y....:.^.4.x.te..(P.s........;_.+...Wn.,.}..../t..._.K.....`....J....)..&9L.6..r3O..p..W*[l$.`0..T...6.E.........N.=..$.w....AX...\..=4......q...Q..I6....@..$N.!w;.m]t.....*$.l..]..... ;.Y:.vF..7..a..^(G..k..X..w....b..VJH.K..S.j.i..M.w..f..~...k.[....i.5L._7#......-......>..Ir..R..3.u.4...|.x}:5*.....]a.S9.3?..m..P.z...*~.... e.iCn.t..OS.>?..^.$L....Y8..._.."....ou
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):602456
                                                      Entropy (8bit):7.99973154956735
                                                      Encrypted:true
                                                      SSDEEP:12288:tC5MDcbAtFIZqBDihVkSBEmb+KMEfIhhfOYZRk/O:4CwcDWqB4kgHdQhWoN
                                                      MD5:E379EA46CDC4170798E8901EFF2AC0D5
                                                      SHA1:055843944B31CB2558182FD1365E0C15E42942CA
                                                      SHA-256:6E4BB345C56987DC8B589DDC9A870C3ADA371E87A9ABBCE439CB0BF79E71ABCF
                                                      SHA-512:A28778121BC4C2230BF774AFCF47122CEC4B2A0469433FF2DD4149AEE23F1AB9DD7C600F6544D444F64BAC63EE1787FDA5DE62FA5D189F8488B1A12AEAE7A18C
                                                      Malicious:true
                                                      Preview:WANACRY!....z.O..><..;Y[..^...+..w......t...HU...3.??..r...L.....UK..^.s.........C.r.3.......f^......lr..P..*.:..b.............Y...KT../.IF..d...(....s.......n=...\v..a..;.h=....E1J.?..X.0..U??..E0R..|.]..2L.yV.....v7#+.%."........F g#/.&.d.g..1.*..VW...0ps7`Q....80......F>n>..6.Y.>.vY...Jd.e..e......8.7....U.3L.C.ax..%....9%.U......{..ck.B{....Ag....q.R...E..z..@.._5.....I;.t..'.{.f.*..@..|..T.F;9.&...=u.&.;...x...L.sO.......j.!.^...+...bb..>...1..,T.....O.i...6:UH..e...+.mCoF...UR(L>....u.....CuH..D..$.3..{..H.:0..=...d.|s.y. o....2K.?.['.#.o.@.K..\........=...{..o[...O..r.$&.T72.....\.t.0.......j.H........P.j....AF...1.09.T......7..i...2....+.....U]6..`6,m.a.`..AE]X.?.9{..Dbi....?I..'./..j<.kncb/.`D./.{0..5w...6*.(Y6!..[.5.;..X...bYhw.i......\.d..b!.Vxf,..vy{Rn..`.Q.M...a1..}......RT..^...e.'...Z54.......Z.1Y.03.Z.pNU.........Q...^JX.6..m*s.H..K.._U...G...W_.\..D..|.........3.cTB*......0" .F.n#m$%..I....~...xO.*..u..'.z.l......E...=m....
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):6088
                                                      Entropy (8bit):7.969173478669774
                                                      Encrypted:false
                                                      SSDEEP:96:ocBOoMvBktkSfLS5dbXR4z6AnsGppx/BFk7f14Ifq4Y8W2Nd7Dm29ORnwxpFMtHa:+3BEjSDaz6ysGZ/c1C4pdDmaORnSPwC
                                                      MD5:E9255EAB9C86D030A17639CB51060ABE
                                                      SHA1:51CBBE3B7D8F684F4B31E70CC99B3739A38F0CA2
                                                      SHA-256:E536B0412E410FFF81DB50639D659B7BAE296990527A8880613A0889F25107E4
                                                      SHA-512:738C1DA2C77760C38AD62EB1DFAB917E56422B75A685A991D8257A155B9C360956F60615E0AD3DBC680715854E013A905A262F1A4FEE3A3A48FE689CF725ECEB
                                                      Malicious:false
                                                      Preview:WANACRY!......h...z....`.p.;S$'....X.....f.g.<.F|..z.[.[...._ .M.1. ..#(..t..0..w`J.N.q;aP......0.A,p.5.......TZ3_....+..".d..Qz./y..O2M.B....A....1.....n..[.0k.q.(..L.....R....7..j..h..`.^..w]....P..>..s....CL.g.WC...7F.,..H.....@EN.)y......LL.)7....oD..............6.p...b..EO@.....+'...b.m..I3sc...c..H~R......f(,.H..YB4...-.B:A.R..Y*K.....j...7....c{.c..y..:2.z..W~..H........d.i.E.<X..Q>..c..F......<.E.h....ez<v./p,FS.w.&?E.WX%U.%....?.l.....qWo..'..LZ.U.J6J.$.s.D.{....;loo....U........%..g.P6..uh..m0...U...F.3.......`.KA.......B&h..w.O"/X..W..O..!...>..A...8^.O.K&["(<..b..-x...k...P....0 .C.V..{=y....=A^A[.s...'t.b|Oq*7.........O."....O...._N......./[...A...3....F_...zxo.1....v....@.#D..E4.1........#.Z....<HT....X~.#..........u.YEo.Qd...:..n..\.@.&.\...............q)>....J........1F....+;.......o.'.i......uA._g..8..O.Pf{U.ofm".M`Y$....2l..#.U........].?.=..Z..sX.|/|...b.~.F&....l..o.....shS:w.E.DL.P..9o...Q.v.sF1.s..3O.Wt@6.......#f
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):6088
                                                      Entropy (8bit):7.968352565721933
                                                      Encrypted:false
                                                      SSDEEP:96:okia49g3bJuMtVNjA3VWkKhfBExNZNZ+DXiUNsLSqkyEYVtESnAFjeaYabNnOhlm:TiaeWuMtk3VWkKZuxXH+DyUNtXYVegAh
                                                      MD5:1AD7B96C99199DB7530E7EF37472EDE9
                                                      SHA1:729F8145C7C6D009F210F51FA6DEFDACE8DCE5B6
                                                      SHA-256:6743937FE8BCC13B3530A5F6905337D25ED63456F790EBD4DF2DDE02351C51EA
                                                      SHA-512:DB288ED9B314B61E58C1D4615CD8A32A216EDB50F4340D659ACF3508EABC48901F20235A1B0C978EEB9591806EBB710A4E059DF4329301BB4BB990345512A6F7
                                                      Malicious:false
                                                      Preview:WANACRY!....N....If.0.....8.D.Cg..U.q...$.....6f.......E_+).P..Ul....e.....B...S{7....8.d!~...5..J.26%T..*U#..U..@#.x.D..6...q..h.......o..U7.....$.Z...T9....:j.y...#^H....R...B.."...!..._y.j...rD4.9...-......x...AVdDl....J.]{..\..........S"...J.7..q....! }.................Z.........._'.."...h..pe.)..;F.cgP.{...T.,X.}L..<.46...6($..}...Y...p..{...@.K.Qo?.7....F]50e.......4..<.I.Y.bm..L1.0..gJ..e.wx@.>..4.....Os$Ex......E0D..Uh.SO<.....d=w8.....a....Lc...L.M.+......yD.2.9.}+5"1Y....Z.E...3xV...B..G.u..DY.iPI.K.U....a.Eq..D..F.b...J.c....1.......ex.KM<5[,j.\..-...l>...._.]5&..1')...1.}....).?d/Ml...SN....OS?&TY....6~.9k...K.......9...[.h=bf.....=...S 0..].3...".*..`.2.....Xn...?...@..........c..q._......h...=...Z.^."......7..Gq.@S.F.&Wx>s..etL.....1...........X.H.......CV....(RC.....B..MT"].....H..<@.?..-.,.e..h...8ZLc.(.....&..v..o.....%........7...."J..V...2....t.|..0..b..s.5.:.....z.p.cq{......|k.|u...~.....H 4.Gv.+}.....~......T.-.U
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.855300108460208
                                                      Encrypted:false
                                                      SSDEEP:24:bkK6U4m/HhGGRJJF2PTFVux/wF65mhryEkUx2HOZsCWsc7IyIGyQ:bkKQWHh11QbFYxYdELEW5khQ
                                                      MD5:A8324AB7B1E0A120910351E45A518C05
                                                      SHA1:D8F87792A6167153B9F914D5DE5E3EF177B5B804
                                                      SHA-256:824299355F8A55419AEFB5C8AB37F31A2ADAFE75F02B15759ABB5F004CDF9529
                                                      SHA-512:3B9C334C8D319D2EE92C8BA3D504D4A622722292908DE33466744EF15CF12825E2D3690ABBA59250BED98AA6E7C03BAFBED5E2122EC204E8B7A103DD0C54825D
                                                      Malicious:false
                                                      Preview:WANACRY!.......p.%..=)6Ir..P...B6.t..........N~.2M':.....`.$|.?...0..r.rw+..z.]t..T.A..y.R~....$..NkD....BC...W....).3..X/........[..@w....h.2...D'._..=#..$...o..~.v..MugJ.......N....O...H>.7..#y.J4Z...2@...j.HdR....X..b.XX[...*./.....o..._.`.......?|.................gO..{d>...7.R..L.</.....K....+.`..=4....\A%.;...Yvv"..BE...L....q;.W.J6...]..x:.D<.&~.9.5.(.......3.r7t.2...[iU.......6.(.ry....c..{..q+D......Lf.....{..S..W....K...J]6.-".........L^o.....P.^...b......H.......b...."P.:..:.y..:.3...6.:4_|.S.rI.....4.q.c...D.=Oy....o.[..|..L.<.........<.[..iO..T|...=K.F..k....2...6+.|.}.........9.i.....z ..<r.k.A..g..\..`.%.Q...Y.t6.iaCqgoOB...x......C.|q(Cz......K.;d.C..H..YhD.|}.5A.g..`...".G..Hk.l..XU..D%...W....M..}.k.R....3.m.V?'.$~YK.`.....qz.*.......B......q.pI.g....Ov..T....r.4Mbj.9#ne...*Lx.Y-]..M.uC.1...c.z.R=D. G./.....%>.......s.R.;Q......:.........6*.Z..q...}....pB'.....{..-w.Z.....".D.o;V.j.a.C..|.m..U...#|C.Q.D.Tr......}.m.d;..f..
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.84240682110715
                                                      Encrypted:false
                                                      SSDEEP:24:bkQjT5zJbvIT5R2g3CY63XjQwMJqSS6CSqgs8UBti9d8/2PA8YjQ+9sVV4cdE:bk0TxxvIT5R2g43XJn6CYdUDiz8ePA5n
                                                      MD5:DCC624CA3A952A541CFFB5010A05974C
                                                      SHA1:E39390FAFD50209A51A8C9842E8C0B3F1607E8E2
                                                      SHA-256:D2ED9829019219FB2F0304C30BF1C33F22F818E100686F6FA106EBA0216D1BEA
                                                      SHA-512:13839CE1484394D58D9E2DAAAD9F3725802557EA0649661473705BC913B2BAEAE49E72339389250241D06D8B03A2CC2EB8E429292F88B1212572860D12833B3A
                                                      Malicious:false
                                                      Preview:WANACRY!......$.7.,,.A.:q..'......N..........U"..).3...~X.U..nkjf..h..+.03V.a$3r|..].m.m....K...&...3...(.0.{..B.....<.e.....N..=E.KPK/....Xt.._..Z..~5..'.-X....J.,.+.......#G...<.%..3(i..:..6.L.q........h../z.)j..g.A.....K...%.@a.T.:.Fsb.f.8.X.../#*..sk.............A..F....-...G..t.~Pa..bOk..*W.%HM.......|.....m...H"VL.....b...L.wk.Z.5.!....\.:qH.\+O.v.).p.J..8.b...#t.a.....<=....H..%...........P.....#>'........9.....HE.&a.>..".?.N.k.j,.;!...V....>.7$.....cA......k.H..`3...%..[Uv...)..*{:S4D.....{U.f.s$..lB.3..\.4eL.\.s....+..w.....Q...M.z....j!b@>..%;..(.(.L.%#....te.-...L>V.F.#qJ.R.cnj.y...ob...2...(Y.r.X#.>...l.....HA.5.......{...p.}t....>6....Y.H..+OQpe.= EM1(8....@;..../....e$.J..z.h..FP.N...&....gw.l...F.n.\.....<.e.x.fZ..i.py.n.7........*n....'..S.R.,.e=r28.U'...eWk..N>.....a..p..f....30....=..,2........$..y].........o.V.t*.h....:wV....;.........1....d......."......w....Gs...UJ.QH......yz....4k._...6^.O^... ..Eb..QN$?n.M.e..p
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.835577477337923
                                                      Encrypted:false
                                                      SSDEEP:24:bkhT6Jtnzhd+SEi/a/VodemAYeWLjbgFvm0DZCP2kFpnEcAJZlHmARfcV3jtSXNE:bkh2fhEiSKvuFvm0kP2kjnnAJKCO3xSm
                                                      MD5:6B18E80A407E37A87C85F8227B0F69D4
                                                      SHA1:3B128573C8F169017ACF56CE52A3F5FACD130832
                                                      SHA-256:B078F05B81B9E84772B4871EB739412E8FDEED76E0A896F331EFBB8C93C1A551
                                                      SHA-512:849C6BFDDBAE88BFF0013C440A250E486707806E8811C2CCC1C408CFC66130073D0C0BC152872E12EBE12AC50B9A472103E6DC5D36997F5C10538F300EAAEB7E
                                                      Malicious:false
                                                      Preview:WANACRY!.....=.^....;..Y...h.;4.H........i.,.\.......%.{4l.a.iP..6YrKn...O5..q.P#...%a...C.D..6.9|...a:.W.....a?x.#.....N..g..`.G..>&@.........5J.&.....X....b......S..{u|Rh].~..y.....O7"R..D..3yl)[.+......r.h....AE....Hz.W....H......~.^..=p.$.f. .#K..............6AK..../...F.R..Bb.U.VVTV.O.....l..&)\U"i.Z..*.....5....t{.m......X....{u.<. ....Q..E....B...O.m..Dpka.....d>. ..I.?......}..q{.Q\....P$..+-....m.....|^......R6...)..32..........*N=.&.... ...L.==...+. ...Hw...J|.HuU...N.+..V\.eD*...`..a...Iz.w.Y..kM........y..!.XE.........z..$.V.E........e...KS...q.u+..k./..d{......&8;Fu:....V.<....1O8?$..B.........g.T....g.3P....<N]jW!.u).|]U..k:(o.....M.y...LsL.B%.r...i...qF...1...cTa.n_...L>....f.'..L..T.2<..u.O..|`p..7.V>CF....i..=..... .......3:.\.>iJ.Q......v...........uz..........<.X..?...tB......:...l...y{.<. K.i.-....k.:+*.j.<...L...<`r.gx...n].+.........P..xB.".....a....f...'.Q...%&..,.....k...<...%L......`.)D..V....Xn..h..:.-.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.83064212852944
                                                      Encrypted:false
                                                      SSDEEP:24:bkE8qM7ZPiaagXV5btUVuxjzFdRLNxloKHu8Byo/l62E4p3ywzWp9Byrj+:bkE8hXagX3WVehRxlBc2E4N1qyn+
                                                      MD5:C27ABC6C5C9EFAEE5253DC2E70DED925
                                                      SHA1:DF4C69E7EAB28EA727AF8634A2330DC52C47B047
                                                      SHA-256:8915E98193B24ACEB40F995AD38D97FB04FF4C6AD2F7714E6313999A81723931
                                                      SHA-512:11B1DF85A8C44EF48E813D282F43C0ADE3AA6F298412208E148EE154A1EF1ECB04DD95BD40114362A68F3996A6185AD83412BAD9D05478B5616F430FC29DA2F4
                                                      Malicious:false
                                                      Preview:WANACRY!....?#.!.&....S..}.D..JE.. .o..=)i..D..W.M....f.(...f...v...ZqQ.._..vsp..A...A>.?.9t2{..'......nVH.d..%....d^.......|.!...H.B.*.6.:..=.d.0j.j.p....t.Hy.4!dO.c<V.....1.....;'....>.P$c.$(....4W}&4t.;g..[3.!.G.w....VR....}X....I.Q.}.,z...m..DG4...H2.............Am.....[....:..m..ccv%.79.+..e.@..u...b:.&o.N..._].X..........9..........|_.1`.q.p:.....u.!.?....w...X.U./.p=.E......)S..92o.. xt..y(..WY.......+.{K...V.-.-.YB....N..c...#..@2..8_.9#~.Xi2....>z....._.........G,.s....j.g+.....V..M...3.s..CO.....[Hu...C......:..Zhd3....'.H&S.(...\3.%.._,!...x....d...._Y....!.uF..[Z.}..}...N$7d.p^N.9..r$.9......&]..U.j."Z@.0;..L...g....! ..G&.......b. ..Ik.....G..Ut;...i.4..<..kC......J^..h&....D....>...o..fD.....3..9H6.<.K..lt..b...{.W...I.b..#..(Xl.M....4.{.8.8.6-i...=..$......<..../...c..f..>..2.. ..(....k..4$..=`.E"SAn....u.=......PL.x...T+{?......_.9.".]..?..C..;.#.@]..4B.!..Dc.S#4...;....`5. Z..'..F.1..(Ux9Q.........T...%s.>.L.ez..,$.j....;v..1.....
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.841251890394978
                                                      Encrypted:false
                                                      SSDEEP:24:bk4g9/NH8Svg6sgH49FkzivvcKxzWvsjrTUC/UYswx9hSLgLsHzn4huyilo5OqZj:bkT9FfI6CF8+nV+sYC/BfhSLgYswy0Gb
                                                      MD5:6C1E37158DC4AC751A1C83204C534DE6
                                                      SHA1:EFBF472E239316A47294C936BDA3BE5A943DB011
                                                      SHA-256:219986793F09105D82EA190C5502F08CF19D34DBD3967D7A1E1EC5162BDAF68C
                                                      SHA-512:00BD300DE382704D720DAFA21EF7CEC94D90718D736C1DE4CF13548F045D1D493F0D6BE59870312BADD0F2AAF988ACD9DB1D78E8BE9ADC07FA08243D911BA9ED
                                                      Malicious:false
                                                      Preview:WANACRY!....r...Z!..Sb.6A.Dsl.0.........|...B..qlc. b.8$..sD}..J.:B.7...[O1..<..E>I....w.....]sH..)...N..3..S....dG+.6....n`Ky.>a(.'"w....O..}.&.+e.@.bb..../Nhbds.B.....DX.~.L....6.....I....._Q._........w..^..{B.s?{.21.U.K...[...V.7#....y.s.p..SYe..m.+\...XA............w....w9.^.....%u.C]...,pO..+e.G...7!y/..yD{?.}...H..@......n$.x~......&..p<..4.X5& .'!.*...Us."...B.c ...M.....N....F$.hbg.>6I....%.....I..X..R....T+.....1(~.1.or.x..P.a..R{l.........'.d...M>S.76.....1..*9..9.9.d..G$^.&..^.E.XK..@.rbr..>.......B.n.1..ix..).g...g.......xZ.F.}....p.S.T.?'.;.$ .]...G.4.-....G.*].P;.g..gn.5..]}..,z....o.V.8....s..b.=..[.....x....g.r..t.&....&...[.nh.B..{......./..!.".....h.j.&V....yC.]'....Z..............1.X..!....}...H.j...",hb.O.....I.X.szS.......\k. ....&KO...{.:bT.L.|j.,"t.ZwT..[.b.....o.[%.K..,...Q......+Ux..$.... g..<....>..v.B../^~.....^...-.g.....ak.4....t. +..7.4\1..<OY..vpwqG.....$....2.6mY..x*F1...(.S.v.C]x....;.H.YB6......%.eq`;[........
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.849099880792621
                                                      Encrypted:false
                                                      SSDEEP:24:bkZzY9tdNzpUp/0TWA8hgMzfdBGR8x74m+a2m4zP+U5vFhZpH4pOeJFlyn:bkZUrYMaAEgMrI8x7p4D+e4pJo
                                                      MD5:F64BAB5F427CD5EDE4B795CC2A44AECC
                                                      SHA1:2EE2E38FE13BB4B0746C6771C4BA1AA6A1A6C4F9
                                                      SHA-256:537CFCE9F1B1496AED03E0517605802E6BB5301D14B444FFA33C75C095302753
                                                      SHA-512:5D8062FC1AD439E37BDBC895927FA61A8227A8BF348AE46470FEB36CA2B9D379BE0221EE0EE32130C1BEA85760A6830595F43248209789D5B1F87D8879CABD5A
                                                      Malicious:false
                                                      Preview:WANACRY!.....O..D^...u.....fU.I..].....i..%..}<./@..Jq.....F..-...!..8..(.P...............A.'.../.(z....R..W...7(...Huh.B..._.z<&6K.....3>.j.|.C......\...i...7....F_..nuN... ..3x^.8.M*..(.v.....?...$(.U.AD.....Q...L...._/-......a....f...s....'vP..Ml.8.3.K...............*......Pm..7x~.j..dY..gw..$.W.@.......l.....!...,..cZs.$...t].|.P.EO.2...#. "\G_W_..3...o,.FyP> 4.b........n#@....bl.g.5..k.4?.....#...W...D.}...!.|d.0.`kT.....q...}:.~........Mh6.............t..U......r..'>2.l...T..,......=.5.|..[....K...r..cc...._.05\.....*..?T...?....... ...@|H..Z...Q.!..v":j=+x\.Ho...>....&....a*.....q.y..Y.Lf....y.....!.X=~:.....'.}G'$.$P....'f..;...o.5.....K1..s..,...M..m.q.<..A<6>.<i-I....19%.......B./l...._..T_;3...X.=;.JT.)...AF...M.B.8.ig..[............J%..U....3..U..{.(..5Y...Sa....}C.i......V..Q.4.\._........W.....En:.6.c..Y....w..>.V)"....%og_..W....;......4X..p..k..Va...3...C.X]..J...F.h.x1>.}.z+.X..`X.D.h...I...d..+."....4....<...17..
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.839949299386788
                                                      Encrypted:false
                                                      SSDEEP:24:bkNo+eYB1WrdzfNNdy91xhvn/DfXJd0S8BdRgj4IbEwoElfTa:bkNo+aZzl2fDPsLTRG4Fwoa2
                                                      MD5:419A37BA8BC8B8C9B3A9B8ECA6628404
                                                      SHA1:486AB737085565DEC79CD8C58F04C914D3F86D34
                                                      SHA-256:EB9172514C59E27662BD24BDEB3CF12A6BC6D2B8AD444E44DD302319DF4A9E02
                                                      SHA-512:F7F13AA24A087EE7D59B503525F11DDBB15B73E73465D5F3A115000721B38FFC501E17DF39DCE02C0FFECD775DB1337C0471C76FD01A6A4AD7E294A395CD88A9
                                                      Malicious:false
                                                      Preview:WANACRY!....i.........s.6...U.g./.3..x.z...jP.v.\f....rL...Bd.\.<Ib..uL......d.#eR|A...*.|..cW/W...N.*J..Xy.cL..=....^h6.$B.......mP%q.n....L.B...t]{..F.OG^q>.IWk.3t?.....9..R1.R..p....]R.<..jI.^e.'....{..B.?$..X1.q....*U....68..a...ILw.@!...8..v..i'P..F....................".c/b.+..&d.:.. .l.3...i.....>...W.@....A.\y....%k).x.17\..D.........+W...6..\....G............k...Q4ow*.UE."e...:..HG..[..:..v.X..|.1.T..&..Lb..L .6..KwC....L...St0.LjZ..7...W..;{.....p...f{z...d>...;..l.N.W..A..3..W........z.b....K|."..9..\C..#K~~a:`u.f.w=b.$msf....H......%M....p.R.v...k..#K:..R]....._..&.r.3O......h`O...@..1....+.Ti..l{......A..r.!...8.).Y....%_.......-RO..?.3....".... ..A....$>..K#....r.~V...ZM.2..p.....PZ.!(.H.w..Aa~... .;Y.(.fo..6...\.(..=.hi.&.\n....$_....{.&x.X.#O..../.....:..>U..^...4.Vb...y..N]..3..............ZPW.iq.4]..*<....}5!`z,%w...1.T#bG.fv.U<W.I...R...w.L....x...n.bX):.....$.0...*.kh..+.'.^5..9w.+'........a.HISB...oa.K.....wb......U.7f..%a0...
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.861003058549653
                                                      Encrypted:false
                                                      SSDEEP:24:bkmwkteNM64gbR5NqnHIHPGmJmQz112MFohQqpL1aEGVcNKV4G66T/SBzV9T:bkat1yMIvGmJ119GWqhJGVZunU/sDT
                                                      MD5:D96B3C3EA94A22D237ED4085A9226D0F
                                                      SHA1:2828F2B75BC8BF474EE8A7426189BEB6292374BD
                                                      SHA-256:E0FCC67C634DE0477C8075DA4C44D16CFCEADBECDFE2EE54BEFB6146F78B1FAF
                                                      SHA-512:C96FF189025D8D99B7C9F9534720148A6C5C9C1EFCD11A167B7909134C3D04AF9C72598A8627F44DE1C2D71128D38592A3C2F7B4F7B73B3397620B29F6315EF8
                                                      Malicious:false
                                                      Preview:WANACRY!.......Q,.j8...c....6.t......jz..41n..e...{.....a..n..'....z...<X0y.....[....,.U(3cx..g..:.....%x`..f.IS....Z0..?.U...'Li.e|oM,..&.A.4v;:=.Ur...q.y._Y~.... .......X,@z..o...V...t<...=..0k%".^A.N(P...Y.BK..3.;..R...y..Z......i6}..Q(l..`...n.H"..............2Nv......b6.+.7....cd'w.'l l..G...*.g..3.${.j]....w..g.8.5.+..f...!4..A.Z..;s.m 3.;<.)C.+..-,.....=C...7W.7=.N..'a....j.%......vpQ=.e.X....%.."..Ri.G.....c.J..U..O.:j...5..a.....G}..D.!...%p..!..^WLK.q........>..T._~.3%...(..T...&...bl5...I..H7&...|[._......xv.P.O.c..geuHh!....va.<..|R.0.5.%YNW......u..E..@....=7.s7@.../..N.....A...wp..Q...N%R%V..N .qi._.uD<pV.)FB.K.....2....2F....F..e.....s..2M..v..(...S.].MX}(..M;[_.5...V.K..2..31..2.0|...UZ8..|.+l..g"..\m...pn...+.Kc....3(^...KL...t........\..q(.M.....Kj.f....}...5.......T...b.c.M.&...._....Y......d.U..9>.=.<s.@..e.Q.X.m..>.Q..0XE.....LnFs.....!.$i._.2...*9X%...%d..]'...4..M....h..33=...Y...`...D......\.. }....-.m(..
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.834487318698788
                                                      Encrypted:false
                                                      SSDEEP:24:bki9eQY0JteJAu+SKA5ZIAAxxyXX3UsVR95x1cLEruwJHWmo:bkitPJti+xmX3J914Eqw9Wmo
                                                      MD5:DB2FAE91C95D044C4A78823896126532
                                                      SHA1:EA8BCF5C4E52D5AF36F3A547572B4DCFD1625DA3
                                                      SHA-256:16673153F3524A02B90349E5858EE0E86E4B5BC8B58CA44071093961545CF96D
                                                      SHA-512:416FAD7F36453479299FF24DBDE5DCA50E6072F734FFD06816AA60E0D29B0A909FDA25169A3B9D2595AF0FF88FCE24771EB2B8D707A46E13285B8D6BA02B1240
                                                      Malicious:false
                                                      Preview:WANACRY!.............Z.A.....(a...-.'....0-^c@.......DIR..xr.O.Hn.. R..\...6..."i.c.$...R.|..T.9....@.az.R.O.Cxk. =....^4.[.5.....i..i$!.[......T.x.Z2.ro....m}..aC[.]Ac...&..P.tE...2..D.......Q.i.[.x~O.x..4...n"..9....d.h.aV....K.a...7d......\.r..:............@....L.,..ZO/.. ..e..1.G..Q..W.cJ.M..PF..2..>5Nt.T).j.'...g.....(.!<.. .....|,..p.....U..Tc.C.^...g.@...7.7....M..r...R.S!.\{....I.i[t.+*...1d..;a.t...,H.T[~...K.._.Si.$8{.%..J[. .U;H|.'.v...'.xCCY..x.9..6.w:U.^.w.FO.lO.............u......?.....h[...f..~!.......l.<h]........y.V...<?....>y,.}4..z..]..;..U..:..x.....js"....Pr;..........j.K...f.sr...H..k....(.?..W.3."N].?.........0F&.. .mt.)..SR.Cj..P.s...p.....H..4,'.q..z.[...iSi.rq\mf9.be.=~-L.`..2.3.E.KG..yt.=.D{'MV..Q....h]....u$y....d...|'..7rv0...y...U.vm\}4`.V..+...K..>@.....y.;N.2.&.....P....C..F...r%5..[.h~.f3.I.%K..!.."d.....4..}.......].(...d.u..<k.[u..U.|e.nT....0h.....;..."#M.?.d'.@C..4..}>...f.0.....6..,....b.oZ.i..*
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.853852133615042
                                                      Encrypted:false
                                                      SSDEEP:24:bkpaHscx9mAYwCzbu9iZqlr2Eg8UfgdyojXC8zKo74Ob:bkp4x9mgCzS9iZGNUROBr
                                                      MD5:2F4D2F0593A82183B99A74F046FEA296
                                                      SHA1:8150CF37C6DF8F6E43356CB1F2D7FB4B1A3EA843
                                                      SHA-256:DDC42FDDE86037B4A86610802992573B49C4E256D2DD0E670E2D25D6248C55D6
                                                      SHA-512:67ECF55637FA6754D927F50657D2D821653D6A6161E1750BA8ABAC700CA8DB8C4BFA745721F666513120159898A6F67900E98D29DBA83725A686C00391A2BEA4
                                                      Malicious:false
                                                      Preview:WANACRY!..........uD...X.e.C.../....b*.Kc....n=..X.....D..U3Z......l..Y.'Q..D........p3g..3...z..{G.J..m.A. ^-..,..m.....#.^.&..@4S`u.h..%.....Dk%...^O{h............;2^..+h.*...{M...W........5./.k:..}}...B.H@[..............(|.......8..t......=..O............}.....&.T.G.(...-....A._....UPga.aQ.a].&....qH.I=........_>S..i.b'....#.?.8...l.-&.....{..L..|0........M..N..~...&z.[..ijH....*|:.c..:.._..W.v.H..;.X....n....T..d..f.........N......!.;...%.....Qp&r......A...2.d"..i["z.w.Z.^........<.b..g.zh.Sw.=5...+.@....g..r...&..M].k.g7..)&:...%..^.K0yi3...$95..4Yo|..<#..j....8../M|~6&......oQ*tv..%.Y:_.>.tl.}..paX...6Sq.WKZ........:.O..g.2w.....5.g.?\.LP?.......=....w..Y...x..TN...89....b.u....k..E.fH.u....L...vI.....8..yx..hq.".J..B..r.?~..oX@....D...Lc..."_9?.G\..Z2....%.i........W.............U...."...-...X.G..R.".sj>..2.%).g..... .QMK.I.....5....k.`.9........Y..hT..oW..A""..XE.MX..?.2<.....4...H^Cj...}...@-B.}s0A..3..c.h
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.84434407658169
                                                      Encrypted:false
                                                      SSDEEP:24:bk1rqs61JEFGYVplqyhJO7TqENEOQTeXMWhw/CAyN7oXgfHmPvCdvFH4rtOM7:bk1O7XEDVrqyhJO7Ttzr9oZP6dWOM7
                                                      MD5:B3165E5E52C9D76496AC4DDD9A35F1B4
                                                      SHA1:3EC5A694EE3C10007F2AD3E52A5510F7193E1506
                                                      SHA-256:8D4A486636D9BA696463A886FD70A0D8F798B9981DCC2DAC674E18E3C9C33DFB
                                                      SHA-512:578FFF9ADE0342071F25DC6103C6238D5E719A3149D7ED7D0F76AD987970AFFF2A82C6D9846ADD82572D6F21A6D9F6F5D51DDE74AA5354F4158B2B91E82B4D4D
                                                      Malicious:false
                                                      Preview:WANACRY!.....i...q@G.w}d....I.CJ.0$..q...;[...+...=Q].W.).......\a...x&F^[?......4.D....#$..Q.(-..G!a.F.........I....`....!...B@4..Z......pL.(2[....~W.....2`..O....:.+Q.PF.....]..DW?(<.....,.A...g%.}5Q.<*..y:...`....l.;.v<.x..6.....q..o..e.....L...D................_,u+.D.....>.....5#*.....Lb.S.Ew[H..x&_.......F.F.V.....D..l.O.....lfc.K.Ys...ESG.~..g.."...=..tH..rzh4...F.*/a.....w...8KR.O.N5.......a.2Y.f.9.I..n..m.<iy.7."..i..z./.".i.-...]'.._.0.......#.Rm3....*........8T..N`.].i..uCk...n....h.qlM.3.Z.....g.M.UX$>...H..H.i."ba.......k..FO..HE+....i.O..Q....]`..e.)....%...^.d..#L.v..X.>.......]R.......F;.@..!...}}D... x.G.Ip.'.h.......|K............,K.4.!..t.W@v..._._.M....x..Q.ef.......1p..q..$.oO..*{y.O.=.I-....k.I..+}UI.-....?3.m..s)...art..a..k........XZ....q.'.>h2.#Pw.r..$....)...ns.....).Cx@.T.@.JO)o=......H..G.8=......qg@I.O.c.R&...h..3..K.Gn3oS.g.F...H6O}s77../......O..[V9........:h..N....$!.9=@,...m.(....B>..Q.@.2.R.I.k.9.d..Z&.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.839804814220248
                                                      Encrypted:false
                                                      SSDEEP:24:bkq5Ov/gD7UPoclkb/FqCtGVCK3IjIwjPktI7FYSnRW1MYKQiZMUgPvNK4t6/:bkq+oMb+tNQKx4tI7aSVxJMRdU/
                                                      MD5:AA98119D5C61E408C39CB0BCD2CFEAEB
                                                      SHA1:F3E68FAFFE55DD16E97758229D2557EF0D393148
                                                      SHA-256:C527B45315ABE6EF4F75F34AA10F502D11C28D9C2FA1C0564ED4AC65D28DED1E
                                                      SHA-512:5B7C90347A8B1E22FFD153F2F8D10357B4D0336B9420FB3873A9D7858B79CE079A36794CB3838C37A24F87F6299D575CDA64B7CF872E9DC0DADE133D19FEBF3A
                                                      Malicious:false
                                                      Preview:WANACRY!....,..6.(..K..z..e$vzrF..X....d.,.../9 ...g5@......Q..d..@@.;lK....-.E.".SB...KA/3&i..O..V...v...y..)....\..3..h..8%B.Mhq......./....`.%.)..R[..xy..J5e......~.. l.~.m.q..o.?3........R...w.&..T...4?'Jz......=...S\..%"eJ.R~xg<.r...M.o.r.....E.}................./q...G.../ @b.HFbf.Y$.JG7S..37..K_...1.3suy....A....I.T]....9..cR....tz%.2..:W'.B..d..QwvH..(\.~9..IG....A.IN$....T./...{g..[@..T....<.o...k.`m...n.1.. ..N..C...( ....$.......+r0X#..U.d ..H..........|vo`p.w:g.....k....,.w..1.`x...;.1.....rJ.....\.S..H_MN..|.K.k.X|q.j^..c.A..2.A........k.....q......P.....g.....aT>@0..../-Z...fjR..K.y.1.%d.$..mQ.&.......p....x...%KV.b..l..i.VHC...k.O|...J..>EG;....7.X.8...G.Q...gQeM.Q...[....z...6..5".A....^......}........d..i4u1t;...E.&(sj......................k...{.?.&..y....~Wq..*.b.\.-..~...g2...d|....+.7.t..aF...<.]....F.st.......-L..)....@}.@...@...Y...-.Ad...v._G...............s.?.|.E.j..........f.S....`..J..X.Q..V/T:.U.~.."I.v.U...
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.859509933467673
                                                      Encrypted:false
                                                      SSDEEP:24:bkGqHPtbVEwj5NRGUYyDO5Oayq4xhDlpQQrCPw3lRON/su2IA8q:bkGqrhj7Rwgaopuw3lc/su2I9q
                                                      MD5:A4E9964068EF0DAFE18B3248CCE299D8
                                                      SHA1:991221ED6125C8CBD485737D1FB6B84435E23DC6
                                                      SHA-256:EC0CEDA645E8AD0D4EA5596D603187466B77B33E24ACD107526B41F71090C6C3
                                                      SHA-512:1B347DF2323F4B47710C2B502C6B2D8F7EDCF7B965E121E5AEA5817E625A4393DCE91BCC5A1CE23A6716B944E88A33B508AF86DFFACE6852272FDD0B95256B5C
                                                      Malicious:false
                                                      Preview:WANACRY!....^.Ri..^..wW.'u]k..2.L....j.W...A![.x.....5p...E1...'..~...p..I...H.....f...\p..Q$9%0>..F..m|...@.n..N..._..J.H..l...%L w.Z...pr......H-......A#.,*...}X<.{v+.^.V..xU^..'.{7..N.9.x...J..j[v.S..".B.....q.....-G7.I.U.8..!..^..$N8E.?.4..H.._........................$.(.....t..w.W.$.G>......MC.C..)c%.,;.J.-.%g....>...Z'G<I...p...d..E......B..r..G.b....(.+..[<..Y%..A.S...7\.G.$......@b........bw.\..n.VAU%..[8k....T_.<......[..\3n.h7?...`......].},`.00R.oh3\z.....M.K.......\.|T.X...?..2J..iC;......]pO#.%..b)...h.._.E..$..r./u.I*q..s.....\..]*..&...Q."n.O.n.0qb..W....x.N^._.hTU......jz.S.w...b.t......l..'.b:........f.3.,....'.+|..1...5M..5>.........Q....m/......Wp/........XNZ..!2.B.PnX..q..dQ..D.V.c..t-..zd..R5.c..6C.....i.....%.!.QW).$..Y.m,O...(.N"-+.....yh...M,tf.k6u!...d.#....1...]H.!W........UoKe...g..21..... 0.D.r...t....x.HTQFIyQ.K...].`0.w..Q....:..m.I.'B.&~.},........Z..#O..,......ay.'.....2f.ID.....p..DP".vW..N..<.@...P...K..Jj^m.......
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.848832529091301
                                                      Encrypted:false
                                                      SSDEEP:24:bk9tlLSeJgwdhsGUi9X14/3rI/+fNTqyQFwtZLuqMdFFxbQbgq7K8jf8oNg59:bkLlVJgoX0PrHTJGFb4P8i09
                                                      MD5:9FD722E3C1EA4DF7CFCE9E83AD38EC67
                                                      SHA1:DF7D96E5ADDF1AF29D703DCF4C7875D33ABBBB20
                                                      SHA-256:0FE5CB9E453D8819D5052DC83A3631D9A62152C3625792B70B6E363839E7CC47
                                                      SHA-512:BC41631CD6E1043BF685E7B013F036493EA371094FB7D4317F5A21C6BF541226726A06884763AFCAE77834BAE2029F2E918D4DCC6E24CCF47490A7544CB6D3B8
                                                      Malicious:false
                                                      Preview:WANACRY!.....I..Ra.....].....,.bE.~tx..Y~.q.-5.......Ya.3p. C.~ev*...hv.s...g..giCJ.([.........t'..O....i!.1..p........u 9N..`..f.2..}.....s*.~.......bZ....}8|)..dM.8.....v.. @2uO.q...."...iI".#.....w.6........t.sB6lh\ZRSX.t.{`..t.p....=....}..LA...=.@.Z,...............Q..j....?...1.}..y...fcg....)Rt.D.|b.9...`9..I....%o..T.....1.....e.A..b...@h..C!hyR..r....w.PV..R....X.@....U....b....X.r.o.=..K._hU.....lf<..y.......u>......I.(..f{....xi..~...3.[.Y...M._.FXC`7.~.W&...,.'...(.H...C.B5(.z...l...........>.~.S..)...JB..n._.o..;..........^.A.|es.N.\{V...a..*...#.%m7G.@...S...U..1...8..v...Q.y..T....4.4P.W...g..l......{.1.Nm<<a.2....|W?.Qi..a....m....u4.w"V.....sl..>..u.r.!wt.X..>SO,.....g-AH.P...5.rgF.,....>]..S.C...M.}Qg../..g.#..;?R+)7..s...=.[.G..9.+.?AV....$Y.L..Oa...-a...U.........+.|...`.I...*."...<n.Ve2..sf.JFs..x."......,.7/..[P.?.(...p.....]$I...d.[.#....!....9f;........F.O..T:q4,....WH.x..H....I...#N..I....V/..".@e.;l>..}g.2.....
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.823041060647548
                                                      Encrypted:false
                                                      SSDEEP:24:bkglVn53zS/F7zXS76Y7HeVj5PJrJZSWiiioh1yIv6Y4vEAAR95WHSobGnJsCRcz:bk62NjSjeVj5hrJ4Z3W1Pv6Y4vEA0958
                                                      MD5:8076EC14857E4C3EB63821BFF2291985
                                                      SHA1:C1FD66FBBE8F08D9F1ED641B2DC98BDA29562F06
                                                      SHA-256:41DEEDD35A557A86A10C704B5F60F6BB0AA8AFC5A9015D8A97B47BFAE57D1318
                                                      SHA-512:FCDC89A1EE81C08F0DD4A82AA8709F3E1D25737DC0F739569C658948C954C1A67C618ABB7D91436DA73627D22BC881B33703DEB153B35240011109D7DB16948C
                                                      Malicious:false
                                                      Preview:WANACRY!....z.t2r...~q..YX.....(....S#..].....P.u9;\.. .....K2....Y6..q.Nx...M.i]..`.}.....0FV..$.....z|y......#....7V7..N.C]r.;R........+...~..l)...6o...hiZC.........5.J..v.6.W.i...[...X...a.4.?M*b,....q....K..d..=.U.`..].N....Gv.....ng6A....e..2....A.............@>...V..T.....vR...5..K..\.6PQj..F6.Z...A.K...$..wn..% .;oi..0.Sz.L...d..t.'...%...j..+.............6...o!YFVX.6..607j.E...`.-.].{.j.n..-.|....K.Y.....?.5R./...\<]W0......8^..c...p8..LA6..0.....-.F..z.O..2QX..7.}Je&..k0:g.;.m...Q.Ce.L.....r<....+..;S.WoP...-...l..2../...rZ..9.."..&..U.T.......g.........G.......'T}3/...r.......Z.......p.F.q.g.....b....j.yF|..+e."..5..W.{Z....m.QA..x..l.+.....8..(H..kQ"..Qd..L..stJ.(V.. B..r....-&.kJVZNH?W}........#9.Ns.jFf....../.d..cC. .T(._......MG2...JW.Z^.$v.$..K=Ev.1*.<.e.R.N.1t...*d.g..*..W.cYw...Y5....%.>...Z.>..........<.,....,.hp.v.+3...!....'U.I.X.B....7(~...l....e.!8..j.z..f..ke..A..pW.h..:.../..F.,..6.aR.+~.1.T...B.@.:pZ..(T..B..g.j..E.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.841922678554366
                                                      Encrypted:false
                                                      SSDEEP:24:bkBHjepKpqWz6YsBh85mjZL2g6vQemEkaG29TrAYLFHSaIZFjz7SeLX:bkBkKgWWphWmjZqg67mEkadh8Yx7AZjX
                                                      MD5:CFF1CAD89C81409EA691C6FDD2FC308B
                                                      SHA1:733C1E88D95F7247D883C4511C6DF07E380DA50D
                                                      SHA-256:78BFC5DE43B6F94422F33C48F04A853F74EDBAD6EFFF11333458EE6A13C87C10
                                                      SHA-512:D08B54446E63FCC610F8CF0894FADCAAA18D48C7DB800E2B1E603ACE79C3369BE62933545EE01030AD93B3511401041246FDA27F942B3E87948616DFABA6566B
                                                      Malicious:false
                                                      Preview:WANACRY!....].[\....._..i.J..c`.;..gU....in.|..`.V..G..hKR.j.,A2|.......>.2..V)...=....!....F..o.w.dw.p...tyi..uDT.i...Q.8\p..,.=..m...p..)......z...$.1o.E..p.D.yk.....S.!.....Xf_8....M.../..Y..=.........,......rI6.X......",.pD..~...hy~..O..Z..../N.d$b............!..{.R..b.....V........c.....+....2....^.y.......8.?^...v>o...e..U..p.nh.S.p.0.w....PH!....Z.!Q.yI........r4q..[....z...+.b.....rZB..g!.s..T..5-.(.....+...x..y..'..E..].&/.~[..ZS|.@V.2.!.k+2.<..-. E.#.....q.|.i....v......R....c.bL.....=8....i.io.D....<.c..?.^Q.6g.n.p....m..O.%.2.E"%V.a<a.q.S.S..Lp...Hz3.a}0).E.;4.o..2B....,c./.....h.&.2..l.&~..?...F..6~vO%.j;T~.k....T...|S.{TE.6.]1b ;N..`MQ..t.q&w.C.Y4.....)..K..{.(.+..M<..l...c^$.3.VXz2....G..=o*.Zsv..`.!~_..TRw:M....'F^m..0y4u.D...)...2..q......TiH..U.To.@\...dV8....../.br&.PN....K.HB...XB...t(....x..@Jx..CH...a..9=........Zf..[......j..Tu.}..G..8......<.#...z..z.T.k..p...."....a$..v.u..o.I........1.^..\.......V.G5.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.8376703702260535
                                                      Encrypted:false
                                                      SSDEEP:24:bk5o37sEtozG5H7fBNjfIV0OKoYREngs+inNxFK46hKScP6MZWB4OLA:bkIczYbBtfe0OKoYREng8NxFK7KjyMZJ
                                                      MD5:404FB19F7B5DF66F26E22F80E261DF6A
                                                      SHA1:484284828E197779F3364D01815D5BF96896C003
                                                      SHA-256:633416E29EEE784955DFD1787FBFE5318FDDA8945CCFD46903CF515352A2EBEC
                                                      SHA-512:1A774B1A6BEC8169B77BA542F07CC30C593C99EE6FE3CF487F2F32E6E6963C7B936CCDDAA6609A755932B79D2C6800A34792EE221426A7D5BBD73FC11EF08750
                                                      Malicious:false
                                                      Preview:WANACRY!.....B.^.7....\.m<y.+....X...I..!G..2.&...q$.. n.l.. E._....*'!...).u.M.....9.d.~.l.....-..oh.w...n.....y{...j.U.Kg.u^G;.o...wZ.z....v...... x...Cp....Z....Q.64..T.S..GJ.A..V.?..Q..>.r#.Z.<Kf...y.b.. Q.2....(...nG....@8..{.}P...}aL.J.83..C.D....`U...............6..]..d.".....6._....B).a...WX.x....$.sjtM.G..\...C...d?]P5~.i`.. <.#.....T[W.l..Hd...':.....%....)...N!..gT....2...2..>..7X.r..R^0!.....M..-.Ky..&c..{...6......-..%.0R...........Hy2>.bF.U\..C?....\9...;a.j<.e.P..]....c..}S~........em..?....DS..U..`.:...U.T...x5N....wE...E....I..#.~k..`(R......._.e%.yZvK..o....^..6.F..X....AQy..:.3..=v.......3V,...TP...K..(......G.U|...5.\.0F.>.-.t.Jk.*aC....vh..!.k..R."P.sht..M...>'.8.......h.p{....g..y'.o..lQ.....R....W<............aL}...5Dn....8C{T.%...f..4WxWU.0...|....k8.B}C|.k...A......dO.2e...{..,...J...,..F...;J...#.D.C?..2...[....n.y.U.......?6e@...T".~....v.......S...c..].&..L.q.i97.d.0j..F.I.^.v..=..Y.9.G.........U8..>oG.7G.qUN.iY3....
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.830078248714749
                                                      Encrypted:false
                                                      SSDEEP:24:bkGAnURPlnAiEylX0kKdByz/dTXv5hH1SroxckvcOEQyUYFosJ8iIG6:bkGAniNnjcPyTdbvn1SroS+fIUYF2iIZ
                                                      MD5:2D1D0E9AC3B9A79098B35DE4421FD385
                                                      SHA1:B330E8C61572A0850899203F7BB6BBC9CBEE0605
                                                      SHA-256:1ABB01972410D2306B03D951D5E90F73AE1067490204AD0828D13AC11D41BF2C
                                                      SHA-512:3EE506A8805C6A93BCD8C532D815BA2A3B7459000506A6792A0268A543519CAF5BBF627A44F24CFB2805A48C870CC1BB9952A58813C98A615643B6BF01CA6A37
                                                      Malicious:false
                                                      Preview:WANACRY!.....p.[S..s.'..}..ei.....e...S..aF7./...q.^sH#.t.c;.p.'Gh$)a..`.[.h. ..&.&D".1-G{.O.3?u.".....%.3pc.V..O.....<=...C...Mp......a......J...i..l.....sT.4OR..N.~.~>........e.|.P...vg!S.\y..rxo..9f. 8...;...n..9.3U\.f..f..3.{N.Y..L..}..H:Xl.G..... ..H.............p..'f...H...lJP5.{>.RF9m.X..",......6...>..c.tS..{..!..|........N.2.1..W.{*b....H.(........0..(...Vw.hm.C.._k:P..o..'q.../...JkD.v...A....}.s..ep{....~'/)m..s{.._.R.}O.$..R..z..e..W.....F....}..6iW....Y...b..A.......m.L....7.0.....}AF8...!.3...x5.F....d...|.Z..V.........`.B..\..V../.^...|..z0. ....|.B_u......Wj..9x..2.X.0T.Efv...#..YX)h...../..r.....b4..D.......^(./.KS.Z@..Qn.Y..+....m.=)..H.F,.&.c......p..l.../.....j..6...T.].. ...|....n>^..pr'Y...z.....)O.Fk.Um..@...qw8..z...5....X.(...&..[.2../.w.$.2b1...7.!.l$.~mA.....?N.p.....l...zO....0.I.....w.s..r....5...........xw0..O.i../~}.......6}..H.~7.[.I.N.........l..6E..:R.......bk..1..e..`..V.F#....+..a..4/...E..vG."4..
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.833806556747599
                                                      Encrypted:false
                                                      SSDEEP:24:bkIWR504WB+UcYsjkppaL+VDxcZEa3KtmscPF1ES1Zu4OvqjEGDd+zdLal3eyqTm:bkDW1xNpaSi3em/9LTjEGDyy3eFNNS
                                                      MD5:00E6C673EF5E378FE09F6CAF197DC3DF
                                                      SHA1:A415FE4D3D86B5BF7BDEEF10B8F99405A1C1DBA2
                                                      SHA-256:401675DBCBF38AB8C170ECE4210F1F1F50D55C43AC6A987E505BEAA441A7BA49
                                                      SHA-512:DA07BD2CB2952EB1F500CD64D363C58CBD6AEB01F2398AC111F1BB2B45CAC64ED343C41177566F4D8E9E15338526D4D0E504EF4B95D3D9A5F0A2158DB82EA8BC
                                                      Malicious:false
                                                      Preview:WANACRY!....s..8H.."....!..A.....NC..y..^....h.~.Vg>......3..w..z$...Q..cV..:i..3 ....s.V.*._...;.W1....p3....3P.....}P.zO..[n..Oj...2....y..._.5...`,&^4......'y.!..%#..X.5.....8.J2Y.{C.X....[.4...3.`%.se..G5.8x.A._..j.6-.+[..^...H4.o..8X..@D.J]..n!>..................\....8..R.zM..;.....l.........&..L...5..i..z{.6..5.l...u.FZ<..r ..Xi-.:..ba...h....0.-!..c:..E....D.D.s.I:*dL..T.v.....(.5...cvRPn.'7..).Z.Ej..dv.Tq..f....#.s.*.<|XA.l.d....B7.....j/.w?1m..].(E.6.J.g....S.{...X..&z....7.j.Zh1../..K4...TX............<$.Ey......m..v&.ZHM.,.XF....tv...p..R.......F1jY..8...Z.2VF.d....+..=.....&h8.b..T.%.s}..%........3.*..J..r...M..8.Nf....9zO`u.N....k.B..V4...+.:....,'a.P.wC..W.l.a..9fC....jM.....2.6.....|}....`.N......i#t. g._...FS.v.Kv........d......$....?Svk.....l.j..&.4E..-NH...N.'.D..3Y....9k.......6......YZ.W...*"zt.J.=...'.'Z.=.R...S..P....K}......2....u..M....5...c..+..O....p.b..<^,.>mD.fdng..f.....4...z..KO.E ..n4E]...........].W.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.854319624811935
                                                      Encrypted:false
                                                      SSDEEP:24:bkQ/8WknFDSXbIDzpj8rpl4r06uk0EKCY1SbADXgSF/P6H7geULPrg:bkgrqzMlc06bptwLnI7JULP0
                                                      MD5:1A95C951B364D0A4D715387A123ACBA1
                                                      SHA1:D332BBD30E5E0F50C71A6C009630DE07E8AABEC6
                                                      SHA-256:DE2AFCA847EEE3912050A0987C1BC502972E4EAEE2F2721D346FDA9C6B3F7A53
                                                      SHA-512:A5CA53D2A2A992FB36E39AF09AC2F805AAD68CB1792D7C1F1352DBE5C1AA91E727D6D568A2A304A34063E0417E8C0EEB5B79770F71EEE0E26EE9CCDB4B01C07B
                                                      Malicious:false
                                                      Preview:WANACRY!....9.L....U...a....$!..0..3.r.!..})`]...T.{..S,.d*...Q!_.LM.2.r...... ..r9..N.iU..Z..K.#.Qdk;9`.>..c.....`eU\3Mx..6.7.C.A.k2C.k.......GA.c....4.Ji=..}.....;/SN@>'..s...0........[...G8..-..W...J....~....l..h.0Iz...'.#%..>...~.fN.b.t........l.d1..@..z......................%|...`1.%...K...//..6%AO...y..O.t.."G.o.e.K.........,....|...N"L[(..!L.6~.......`...'..Y..6..... .T..\R..O./.TC.....i.>.....CV:...;.T...1r..){,P. ._.....S..M.&.@{{..>.f..2.PJ.<..I.e..K\;...K.C...n.EDBps...nk.....24...]..8.?1....DY.T.xgH..D.<|..M.&......s.s.31..n..j..=.&............d...%-.iF=1.Z..5LmP)....L.I...E..h..|...E....o.....t.d.sb.u ....u.0..F~....LOm.p`.&|...`.c...Z..#....w9..z3.<.........Z&.Y...U${...J.=V=.V....o...'|..F........F..,C.%F..u8A.{..8...u.tc.&.`?...,...or.jE.....>{.. ....g.{....Vl..n.\7lA(..e.RPh...6pG.A*A....9>.Fl.g...E.<.=l..];..=.K.'.<.5.kU.5.x.y+....8.P....k..Iu......... j.i.......-.Z.}....1..j..R..._.=.......l.}..........e.........!#z.....n..rP .*.."..
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.845073724070644
                                                      Encrypted:false
                                                      SSDEEP:24:bklyyy1ru4M9gGthyvtl3rUwzvir2aKM84jyDq2+n8S/MpbwwCHkTNWH/:bklzzBtcvXTir2BM8bUn8S/MdrTN+
                                                      MD5:0465214736F89F05968EF43A44245032
                                                      SHA1:50B616D520AE4192C9EB1625A3E241709D83F268
                                                      SHA-256:6218A61C7F410A7505B55E0C3304BBD372532C2CEFC755D7DD339EB5D76A3C31
                                                      SHA-512:D263FA7D7D20BCE03C615F9A33F91C17B76B0578772B277FD90804F3673228013A16DB31F6513B16830D590E662566A40A3C8EF0144881EE7C40F857633B04E5
                                                      Malicious:false
                                                      Preview:WANACRY!....g..=A..v..-<....D.....{...,JS...,`..>..%....(&.<q.uU.=^./l.`|.6.\p..V...."+X..m'S.h...yK@r.....l.H....W..:..7..~B...1.h.Z.wD.rIQ.+.H. '..`..5....%r.5.:?.l...r....$...{.=..4.m.3....=F....V1...Uq%~.*t..R(.2c....L.%..../<fZ....S..<=....h..t[.. _y`<...............G.R\...pcZ.*..-1.<rLk....O.F....9J.....L%.I2#.U..{.!.&..V.r".!../.;..}..Ci..,.....{E.....|.k.j.h."d<.......'0......j.e...{y.8.......qr..?...a.."..^.j.........M..H.{%.....&p..q|7..^...8.v_..f.6..|..A.....|..~y......?.#^.V...I.KM..x..S..q.....M.p#..t.X/[0Clc.s.`.S..o..j..&.:$....G.`...3,.R..b.d........k.........V.F"i29.f]..S........hK:....z.../.....:.wa..Y.L....D...."..p...r...eu...C...I.v..o...b..) %0.f...ZcO..X.....d.F..!#..V...AT...8^c.....mA*c....{........g;I..E...3...h..4E....;S.D..*6?z..P.i.e..'D..0.#....;..Y.A..tM.xf.u...-..L.....'..M..<D...3i...{q.F.@...+D.....u8C.fS.'..p..$"........W......9...\.|...n.o.nd+....n....I...$/...x.$.*. d....=L..o........0.H.c.?....xx....P
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.846720563783398
                                                      Encrypted:false
                                                      SSDEEP:24:bkoLyXweRf2rApvXjyKe1P+3vNoQfGzJnSBXzew7CiqFO4BWp6IkRs5Qq:bkoyXNfUApbZe1P+3FoLFnawl84BI6ed
                                                      MD5:0A8CE0A2289D7B47DF0F842C801FA0AB
                                                      SHA1:078A94A21ACB6141BDF5B49E2B78A5F5EBADE03E
                                                      SHA-256:D984659E66C467BF2C17A1337BC9099332BEF4F566C5AE6710A35470BFF07CCE
                                                      SHA-512:1E1A327D89011AFFA7AA3F5BA0BFAB8A3D46D5DFBAF89F1328BAB3B066DC08E5900618E1EF0A381914E2C482944CBC98C493FBD2EA5FB18BED01306256036993
                                                      Malicious:false
                                                      Preview:WANACRY!.....A.=>.....P.S..../.K[5.hK^....C....QA.}.).u.s...jCm..b..P...;UKHs..uZ>.b.`.\....3t.....".q.$.Q...;.0Lc%.Q...HQI/..p.u...../....9...-jJ..8..Bm.c)..Q.#=..........e..E...r.....p.......!.[..........NLUqph.g..I.)m...`..n.0...G0Z.#.l.d..I..V.w..G.8..'..I(.............P.J(.GY.)0\.p.^..3......=...A1..A..~W:V..&...M..v...(+s..-..T.KO.~.@.....i.....~.SJH.iWE;.....7"..(......R....c..m...Fn..P...........ht.@7...&6.l.... .nK......-.N.k.....4../m8.....m.&$.V.>..w.<.XZ.W.C4...r...l._.....jm..tu....[.(:.....D.9.k{.%.!...#...'y.....vw...1.fO....cC.<I7=E..v...cst.........@O`.O...B...[...............g.L._`...>......G:.`~......K.O.Q..p/.]+......D...K......nNE....Q.....`\.fu8M..&p.X..9...<..e....[.C l....Kx.OB"..Q....L....~ =X..y..}c 7.7(.........?...*..#.....V..j]..G..M.i.v.u....|..%!x..YD.T.n.<....m.l.h<.q...b...6..E..e...[IYu?7)..Pt.g..l?...z.z.a.. .f.R...`.R...i|r..9.........p....i-RO[K.r_....:..!.W.>... .;.+...."..y..W1.....9x.............H.....X.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.855369680667037
                                                      Encrypted:false
                                                      SSDEEP:24:bkNpwV5p29a2/l5kaiAyX+XQXeMRLDp9Ya9pDA:bkNpN9BXkTJXZXeMnyCDA
                                                      MD5:3F7FAA4BB2C95068312514431D3CCBD1
                                                      SHA1:D37EF17E232F419124CD77C52E410682CD3090BB
                                                      SHA-256:5647784FBD6A1C3DAE848CFF5F3216A1F4CC0A460501AEEC6B26CB33176C82D3
                                                      SHA-512:58B029A27E99F76FE6B1B85CC04DF0A8AEA0163A03890C57FE3FD032B60AB5533B1968D29C44F3ABEC87FE9C8CF4C34AAAD8E5417F38F49AD7332E67E1962E6A
                                                      Malicious:false
                                                      Preview:WANACRY!....~...>.....u)...=#xZ_IB.......=...vl..0w.X.....B..]..B=..r.)5.0.j....G.Q.\_>.:..$i.....,F......V....l^.d....3.....m.,Wn..(..*?..';~....K..V...f/.!m=.b..t..d...R....~7..=.N.....7,,.`=.?i4h.}...D..^.@....GR..srT<...|.J..If..ap..........72..gV.S*................G....%.p#FsK.U...!..(r.q......^..si`+\.....'.h....0..UT.9G...].q..H.....R.0...x.B.S..8..h..}.....e#j._.....fP.-...T......:..|I...y.............s]...FE....!..E.....5=.q=d..G..".TB.....@..v..8y..D|.>....d).".. }..x..m...s+..`.....6.....Ji..?..K..Q...Th..5/....vV.C.d......;.@_..R+........(...........,AXJ..M.%=*.8%V....7e[..8..>.EL|...2.Q7S........... ....-. ..V....|{...sPJ.;|.........N?..gZ....Q#u..~.Ap.J.{.n...]FA.@..kt......n.....k..Z...>Y...Yn..id%....d..X.+......!..~!k.;KY"..1...F.z...4^U..?.....F...bP~)..4...@![.j.X.@...R....?.4...!z.!...).....+.nK.n.8L.7!...e..(/..1&[.[-.-...X..\.tgU.q.[.{....iH.@J.^...T....|.........6J.4..,mfkq.`.J...Ai.\*........]...CP.1.p6#.27..f...z
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.848926961787327
                                                      Encrypted:false
                                                      SSDEEP:24:bkJPt0DfF5NP9QSuZhY8MNXaZLB1CCoZNFIrLD6Jd/sPRvz3HmWYQlMn:bkBerdP9QLIdBaZWLZcLDodgZHD8n
                                                      MD5:41BE8B6D7D46E75D9C0DCEC78E0948A2
                                                      SHA1:DA4D11EF2F5D40A975F9C16B3756256FCF944259
                                                      SHA-256:64C77163BE65A6DE41010DBFBCBCD518890118562BD43798E14B3B1216FB960C
                                                      SHA-512:BF51CAF938E3BD2A98F9C8BF39641461D0A94FEAC9E3E27836D2FE63D87CBCDCC4F9A17E4E7FEDD6FB66CC755295C1B55A7CA9BBA2A84876E0BA5B269E10EBBD
                                                      Malicious:false
                                                      Preview:WANACRY!....d.L.&5iZ..l..qB.l3Thg.:Pls...#.Y....{.$..W..k...o@.w.H..K6qpM/0..W..(..'..y.-....A#....]...N..P..{.u..j\...i$.H~.;./.Ap,N.y.L.e$......lX..-0.<zw`..as.y_...\..0.!....O..M.aAL....KFh4..C...5.k.*|.??G.Q.sD.".....9..F.W}.8..3u%....&..4...f].W.z..+L.v..............ya.4..N......i.9/^...a......!.....p.\.l....d.......D.+n.a..o......:.f....UAR..-..F!..'4..XcL..%c...1..ul;j<.u...J%.G.(.j.;..~Aw....?.1...[4<ay&.@.cj.0f.K....3_..)1..V.9;...... ."..A........#.UT....Z....U*..x.;.8.I.|.}....3...'>...)...u.b..y...l]E.P...P..I.O.I.^.XD..Lv..*M...4.,tFlv.........K.~.h......?Q(m.\s.t.3s.h=..a.R..s....r5a2...mf..c..E.AC..JS[...r....QS'......d../.9..0.{.[.tt.....;.;..O...*......a.4...Y*}...I.... -dz..N./`.T. p0....1V....@.....$.= ..i.d...$h.U2yD./*.[.X#..]..D..p...M....3..g.;9..I1F......+..?|...-..5....O...(.k.}.........gZ..+r.W......X5...T..5Y..|..T.....S..{m4.+.....E..sI.F...........4.3._...._....[..EN.......4...GlW..k|rF.,...f,{..q....I?....d~...di..T%d
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.840858755238121
                                                      Encrypted:false
                                                      SSDEEP:24:bkihm7iZDZY6ChuyF1Q9nhJHqEMPMvLXOWXBMpWJMbVADD:bkVgCFF1WnrJMULXOlQJeQD
                                                      MD5:E90D50BE2E73ACF53F63BE1037473008
                                                      SHA1:220140488012D0729CA3EEE51A6D177858C4D642
                                                      SHA-256:67F0A0098FAD2275705C7FA0502EE8737252F8701152FF80F2B3CA24A23F4180
                                                      SHA-512:187D426845F1E429543131B939024701F10D74ADD25BEDB8C35370597D8A217D02EF384746B6FF109E29D82B0DB6540B00FCFD963EA7725440CC97B390DAA386
                                                      Malicious:false
                                                      Preview:WANACRY!....p>~..........Bw...o.Q$..q].f.Y..teU..,......h.....S.3.X.e.OMg..w6..}...........t.]...:...........".2..\.6.p..Px..\...*{.WF.7z..Ew.p.o.B.nM>...Vq.%.....P.Bm..g.N7r=e=`....Sr._.&.<..0eh.]..z......F..?].;....N3U&k0..l(..(BY.aVY.Ce9.3.H"..k .............8.F....f-Hn..2..z....\e.f..`XpF.!.j.N..8>.^/..g1...q.....c.9F....p......h.p......)..U.<.k...XL9{..t.)..I9^w#.+....-.p..wX..s..$K.../6M'..8..Ie.V..n.....9.O....c....O.0.c......K........sG...i...;...O.....b`.....$....W"...p.U..? ..+S...fK...D?....mC..brBwCD.....0~.lw@.2a.,..d..,..O.D.....g..B..hI^.......m.Pc6.w.j..7. .;".Y(m7.kO.[lT..D.......R...>.......[..m6s9w^...2!..8c... 0..(..*T.'.H....y]..........D4.....g...1E....q\A....'..pb'...IA..*..,Y..u......`.<h........k.A'....|...YoU.l..).m.s..ox}.2hpY.....1.pa...!..c...H..N/.R...4.P.Y.=......i3......em%.G....!...|........IX|.F.u/..^G+.......o.g.5.}H..........V.....2...z.}eR[.B..s...QP.|Q.|..)..>....?.>N.>N.]8..&...5WkQ.....VfP..#P..@
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.850505398526495
                                                      Encrypted:false
                                                      SSDEEP:24:bkUYEukah+f9CeT7ewpLfRw/BUGhVHTHJ+39pJO8NF0+:bkTEuFyT7ewxRw/mGTVEpJO8D9
                                                      MD5:44793C49CDDC8E09DB787CB2CEFD5A61
                                                      SHA1:D6AA1C4930796DF7F18C763A58727E9922033C85
                                                      SHA-256:E58F78A593A59C5C67DCD2BFA7171AC61F2FB01854A0F466BD0BE4CD5047CAE7
                                                      SHA-512:5BBE98FB889C58692A14B0A9FE6E47DEB8539482465E9063D91038023CC8D2EE97D5D52097E8B39568745F15DEA7A37FA32799A4CC23607EDEFBCD3E762A38AC
                                                      Malicious:false
                                                      Preview:WANACRY!......}+..v.T$...._...)]...K..7...J.C3B*....>.7.g..[....j....fM.w...&`g.....V...b0>.....(....Z.,%.*L....Mx./...[7.....m<.........m7.H......\:$.....x.L.B.....*..@....E..............S.....J...@I.v.}=w...8.......8k...#.M.f..U........7D..6A.1.5;...............h.}o.p...A?gKP[...z.._..MH~.,.(p\..C......;.Q..[Zm..[......F2........0..8<..bC...G}....'K{............c#..r.....&.z.p.JOM.E..|~@..?...:...S...../.@.d..=..h$7.%}..X.N.f...k.'"&.?.nd.m<.P."........@h9_.^V.3..S.^..z.i.-K.....}....F.:...............h./Ka..na..:..c.....b......8.1......#$.4...L.....[.#...$....i0.%....r...y....7..6.g..pU...Q..kr.!..E<....G...5....^3sV.c9!...dp=.......%...f...8.&..>.*..mf.9.........k@T....Tot...P..:....'.4.r7..D._..i.....DU?~....K...Sf9.5....:.&......rq....0.....8f....}...P.n>.t..k#..+b.yH...........=.+.Yf$d....2..]..."...H".~..?s.C..eAM.3.?.......U....=.]...-N.c.....gF..C{#m.LK....pu.C..)+..B..L....mV.hj......Z...;...[.o....%..z.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.831997077043649
                                                      Encrypted:false
                                                      SSDEEP:24:bke7iUk4dSg2VOCw+hTzCSNRHOagj3K0yXKWfnsUEa/ut5ypTQRaF:bke7iUlEVOCw+hnXRbgu00XPs2/utM6K
                                                      MD5:C6189BB12D06691A0558944173FB60C7
                                                      SHA1:5C4D7B1C7E09A6C963BBDF14DB265D736DC0CCBD
                                                      SHA-256:48C6B8A45CE25A7E123923E98E9C20BC4C9D2EE891C1A27A0B333ED80E52CB2D
                                                      SHA-512:4BD6DC2AE763B27BE0BAAFF386EF8BC7FF77C61949C7D4CDB7F6C37E3F9A28BECDE2257B193ACCA4ECE5BFA7C22ECBDCAB25D6932A5DA000DB5AB8EEEEDD7AD9
                                                      Malicious:false
                                                      Preview:WANACRY!.....w....x...I.....VZ.>u...]..t......H.r......t`../.S'$U......i<..R[....`...D;c.%.."No.Y.d.gDJ.*...[...N.}.+..).......KL..q.\.;"Z......_4...-..PKP...<..eB..<..O.....3.?)..~...O.....-.{B.........."..$Y.7....Y%..HS.t.sm.b\<<..#....y.....c....................n...~..P...o..E.3.}_JXg.......X\._J.gj3W...%3wj.......W.o2"..8..*g........*x;e.v.I....\D...p.!..R}...*...#.J.R/t._..e<.^...pm.$ ..r:.!*)..._.......-F..;%.^6...CjAH.).<..... .X.].XT..Xp-.q...m.....C.+Q.FE....d(....R..QE.=.y...T5.....d.....i.bGi.-YxQ.aNX...i.@~<..3}]h.... TO..+...8...m......N!.X.9....$e.E#S.df..].o......8.{HK..xv.#...j.MeL*......."...q2.F...Y.~...6.V.G.6............+.+ K...".V....P..!.....I...S.a...<.:..S..-c....C."D..1P.....=..H..n....L.._..D......a.f.N.p6G.1..G(4Y.n.o7...O..'...-.3......y..W.Ys...{.lD.TM..j..w.vM......^.._.L...)RAo..[...2.m,...*.........e.......:...?.......<K..*.=..'...B@sg.D..-..`&...Ma..j.,.)...QG..`S.)....3.A....H%}...u..uq..\Q.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.849141345932391
                                                      Encrypted:false
                                                      SSDEEP:24:bk1TdPKHIdI3JIFYMB6Guv1yBmhwqf46OazGW0jgPhGhzSraOCxtM+a3c9NwqDYU:bkjKoG3J0YMstv1KmDQ6tzJsSraOCxWK
                                                      MD5:28416C5819643D161ABBDD5C704932F3
                                                      SHA1:74725945A969437FC01210ADB5976E0BADDEF161
                                                      SHA-256:2970C17B7365C1C5940B384106207A4F67FC3BE4AD9F851D01C56D050DF584AD
                                                      SHA-512:6E7F45967D68CAFB4D3D47F241FBC3368B457CA4B3039FBAA4FC6F3361A9F8EBF064F914AFF3B0C5E601518B60F719933B776DD091C7CA0C98439323CA56AE5B
                                                      Malicious:false
                                                      Preview:WANACRY!.......+.y....N.0...c.,2.F..]q...t.........j6....(..j.Fk.b...U.t^A..0.+.C..........Wp..#...Z.d.....W#=.../v.15..1.Y.:...>W.o.....o.....<V.d...;..2~.SJ...T6fI5T...B..iv'.%0.2......Q4.....R...;...J.\..nWU.i.7.v....S8..kE.W..u..T. ..7#.$.4..+...................~.;2..PQW.%0y..V...."nEK.Q.Zws~x...2....$"?&h.9..3|.....J....S.s.W.YQ.....$....%!U....]5h.(.j.yK.....U_...-..9....^'.i.d.,....=..{..C....Hu....D.eLM.Vu1^..B...Jv...T...Um.+ .i..EB.<....+..+J.=~J.c...W}..v=...?.....q..=..y...{G...3.x..G...+R.(...~Q.5.Ze._.,K..<.uW....U..8.<..!V}.F!...ly.....l.oZ.....g=.}..)C..u..[D.xR...l..:.w...t....b..?}&K..=.3........{.Ie....g....A5..0.q.Y..........&.....O.D)n..._o..l*.../.C..].y@..Y.$.....BC;.....DS.hf.m.H*l...NA..3l.......v....8c>.(Q...z.].q....g....1..1o..k|l/0[Q.....,e.......%...dJ.....^..1.....).K.....OM........5-..jVf.ix...r.. .....9.^...H.enI.h..l>C/.r.#XP...).,......e......O7......|.l..Y........;.....R.o.....n......>....{...
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.849377744430831
                                                      Encrypted:false
                                                      SSDEEP:24:bkT33MqzBN/AKMF71J7BTwaq9QNmhuGkGgSosqOga:bkbDT/AKGvyamQZGkGgXsPga
                                                      MD5:85AAE536A8EFACD6DAEBB0B423D6E712
                                                      SHA1:F9686A6A4F35BD0025D75B7E6751175118704F6D
                                                      SHA-256:ED583B5F8BB93AC30263BA0A3BC8C17357DA246A37ED0B677D8F703A0D33199C
                                                      SHA-512:955B03E098A3F181C0905A8A8C8C5C037D308CC5BD96916F3E90652DDDB64AE4B04E97F7516A89DBE4679C6EC1472438D83EF5901696EB18CAF0B47F427DA729
                                                      Malicious:false
                                                      Preview:WANACRY!....w.I_.[.*.8..p3.......'F.>.`...H.!..>P.~vGh*..n#fgTi1N..]..Z.xxIOK.T.i......Z...qa...26#.....}.3c...-...,,.&.P<1...D#.....6...+..s&..r....S%.+.:7.....|...^...d.\..[..%".....P%.4.`.M...R..)...........j.........*..........F...2...{..`..G.._..............."..(4P..........[..Z8~.Q..)05....C.Q...k..F..*j.[.v0.}1..'...i.Q<...Z....Cp.s..4h:.3.).=Y...I.o..%w....Bi./.%.s.....j..m.M4.F-......(..o)R.n.....,|G..-Z|..\...d@.r.._...B...2.$.%.W.80...!....!..?Q.......V...x.J.t_hLZ.I..O.Q<.3q.s..._.....{....1...>.r.n.Ke...L....^Krg..P...s...P.k..Z.ZHxB.1..3m....[f.7 ...s....G`...Pz.=`...Wr...9*...EX.....p..X....x...}-$.......h.5.)Wf/.0v.aJwqF,.....A....U..|}...G..*..i.u...v...)t=.!}..W...e..w...I.X...y`..+........o.6..FdQ..W.......<.U.....l.Ur9./~{......].&.z.).\Z.n..`.g_J...k..2...\!ls....q.A.?..g.H.HZ<P.X._;...{......Z{a....T.....S.....H..Z.s.......@0..;=.1oI.i$...k|..... .;-...7.....A.3........F.....N..n.V...(o.[.ai0(P......B...};
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.84864930332257
                                                      Encrypted:false
                                                      SSDEEP:24:bkUDE7vUxS5Szdgfen5iuyjI0r3W6FNacAHCmU9z0+yaa9EF:bkaIU45Szdgfe5wI0r7FNar25zai
                                                      MD5:2B5B0FADFD44BBF7BCA6C9864F1A3062
                                                      SHA1:BE7457505CEEAB900E04133F8ADAC8B5092000EF
                                                      SHA-256:C43119C17CB1A983164CED5D76263E0314F5F626740964029BA0B5CEC6433BF7
                                                      SHA-512:EA21DE92645862383C755DD793C4A0C8B79CF0B974511C12DCEA2F196724826122F79A82031C17CB2B7ED223680DED77829E40D7F34B8CC155DB9F090B16141D
                                                      Malicious:false
                                                      Preview:WANACRY!..........)'z.....(...&....kt..(6....5..!Q../yf..R..{).u.v.2..c....$......{..4.[m..c..4...q.........Z, ..q'N.......&,...-..$8[.S.._BRk.P-.%%.c...N.^.1."...Q7..@......B.4..#...`/.<.Ys....L.....[7sc.`.Q.2?.r..I...v.9....u.rmM.9.<..A.WJo..*.^.....K............~Qu[N........l.wZ.,.|...j.I._.........N.&..../{....Q..p$^..(.{...U.?..o..N\.)...F...7...@>P.37..vM.]..?. ...L..Of{.k.c...Y:.v......_....eJj..O..tx.zm..wm]v...c.......B...3O"..2w...r.....i..{....()Y-m5..D......J.P..... .4...'v..\4...3......!.....R.D.v.]x.J..Of....@../[......YXi....+._".ps..F0.......W..8q.v._.O.........;..z...'...&..WH..n....?e.l...6.lf..G?p$!.}q..Kb...S.0~3"*....(o.I.d.....0..nf^~Q...xb..(....%\.Oe5..'@v.....i..*.a..[...j,..8w..)Q.G.f9?MLE:..>.Yoz.O.Hb..........w...z.. ..<-\.GbpX........f*...<.P.#..@.Q_.....If..UoyW..Y..u..OfM.h*....d..@b3eO....BN,X......(..#..[..d...3_..t.m[...f.|.......s!....u.%.e.....k..t........2h..........F....e<r~;.......'.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.861282866650529
                                                      Encrypted:false
                                                      SSDEEP:24:bke+RPnSKNJ/H1aD9bieHEUV2jeg7KWmIexJce4sjeou7Zc5XkUuZ6vA:bk9nSwNaJ/HEUcjekNYilsiz7ZiXoB
                                                      MD5:7BD245B040FFCE6D8534B538864FFCD0
                                                      SHA1:489C99E74E4FE3F5EB8472025ECD099A4AE36D0F
                                                      SHA-256:E356F5FCCB713B8BC3A24207F55D3E28FC1DF10CEC3B52D3ABD766CA3F6626E8
                                                      SHA-512:3B81683A9C507971A36892B81AE9F143027EA039F78B0660160D533AC19774A578EA6E7FFBD005534E96909D3032492B19B7BE8B3B024CD08C5663DBE8639BAE
                                                      Malicious:false
                                                      Preview:WANACRY!........b..<.K]..I.~-).;...`...H...I.......Ew.njE.M(5O>Y3.@...A.U-E....g.JOG.,.*.B.Z(..m...:..J.}p.......y./1.|.6.Qa-Z?i...5sC.=J....c.,,.oL`1R.mh.N.'...E...W.[x.a......E...3..;...[E.lO...0..._....".^.w.n...I.9Y.1^.9F.5d. .9b.!.9..@.pN&_.86n.\;............Nhv|e.1PO.._.M.5......'A..dh..7..+.V|j.!..A.k.IF.l....aPcL.2..h....h..|.-7.e.....M6g.Y.(JU9.o. .......t..V..".b^.1.Q.>Q....V(Wqi.m/..`.+...>..`.r&...l1...!y.[...yB*.e....u..CS....S...!....r..en...]....p.vc....T.E~.c......."..s....dJ..@c..w.kqf.....a.x.<T.zQP......f.>6......4.8.].C.FR.9...p.Y..i.JR.7CN..~.cC.\.XwG.r].$.....0s.o....x......_..l;.u..tB......CUO.1z7.SX...!.Y.^n..b-........]......d.......?G.\.E9.i..~.9...q..s..W..vXY..*.....6O........s...%./|$[Z.m.,...O.........pc..>.B..6|....e;....S.3..S.......O.=.M...3..a.g.xy.q~.....mz^.p.,-..9..K}..;..@.J.V.pd......2..O....j......m.V.m...).(.o...t..1..?H..z.M.0!........m........A_...j.P....~N..XdE..6.i..<....$m...Z....2.F......
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.84769815507449
                                                      Encrypted:false
                                                      SSDEEP:24:bk5NDJhfIsQz5epAZ6kFgRcmRgcJ7Uj9Td9lX7y6PluBRQG95qIdCe6xM2pyR8VO:bkZhfvQNepAZfFtmxOh59lXCSsm9E
                                                      MD5:E0707019654ACF1EA41F0A0804EA2508
                                                      SHA1:71447C229C0C670A66588855A589D618BCBEC07E
                                                      SHA-256:44DBC4BB10EB7E290AB964704E3979D7A1DC3C526FC4E9F8F746F777B2556923
                                                      SHA-512:48C22485C58084C32AE6665E8C5E3511B9500299EA85E4FE6A65118863B6CFE774661C97B8C3C68756BA32B62CCEFDF8A274675F888C7AA90A898AEEEC1FE16E
                                                      Malicious:false
                                                      Preview:WANACRY!.....V..;z..D...}.n...........1I.....X.b.....;j.O..K0.....e7.6P.....Kd..PzR-.i.f.2..A...C-...o........W..=t.n.$....f..`..~.#\l...S.#.>..G..3^j:./.F.......r.. .'...Y....$G.5...6..,.kd....U'......r.O......`}z....b.+Xf...Z..~......!.q.M.p@..<..:H............$._U........J.JH>...w..f.....=..F..D...p.)..n%..D.k..9....E.Z...J.?.C8....x;>....|a.r.].'......J....&..^.Ff.v...//..X.M6c!.$..."..b..9.7.~.6......5..P.-^.e.vu......uy.=.....M...c.<`cu=2.^.....{...A!.U..n.......\...+..1X...F...J...bkZ1.'.....KE......a3..+6.....S.....ZRm-g..n....U.X......^...*.Ypa.e.P.R;...4V.N....p..".3....>R....F..._....6...`a#.......M............P..5..d.M.0............9.$..9;X...(;-......Q..N.....E+..s....}:ck..9&s.}._k.S6..ORQ..{.G..).MB....Z...).#2W...Z....fd......G.d..d...x9._.|...........+.......>._,...~.....*.....Y..........=.1.$,..Z=.xv..Rg.t.'...H...P."...x.m.3h.P.1-L.v..R.(.|U...^.......W.27h..2.J..#.Sa.l.a.DK.... .K.m..0...`.Gj..$0.2U.F.R...%.$...
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.824926567987749
                                                      Encrypted:false
                                                      SSDEEP:24:bkvW3FFcInzGsBq3zzf2W5vx4pwwXEW6WgLM0rOBUyAwDo4UfrRuwsD:bkkFvnBq3zK6ypOW6WUM0r8kwMB92D
                                                      MD5:FC98BA3CC9997236EDACA5A0003F9BED
                                                      SHA1:1210C39BF273670A42C4186CA231AF144E707F2C
                                                      SHA-256:0D0BF1E010E6CFC5594ACB78FFDDFE75EFFF806E9BA756FEB3115EAC603B07DE
                                                      SHA-512:9A2206CEEC94EA59AE3CA36A0492CC58FB5FFFB0957F73026A7029EA05E3C9B677988F7F577F5FA4953DA73A5505455806B00F8A6A8EE913FFE82D488E81EA96
                                                      Malicious:false
                                                      Preview:WANACRY!....&.T...T%.\.[..z!,..Ou....o.v...8GH...?..D.V.~ly.N......XX....|.;...`.......h.V.}i.~r.2.Ob~.....(.I.d..X...(.....`....G.A..0..8.Gx.....T."..]l.......>|.Zx[...N..g.]/t'.db.?[.3.....^.=.3B.}J..v.5."..._c(C.?.........).0by.....VnjO...9..({..Uh...;W............Y.W...c..5........9...M.>.+'-..!X....n..w.<.HS.Q..]..-..1d%...#L.../...#.m..0th......Ot.......c.J..4..$..*.K..fL*...4...*.D.......4..b.i#.W..r.m.......C7...*P.-......2..s.u....O.b.r1$.C*.+...2......`.-e..z...J......:...u..........j..h..$wC.~.R.:.,.b^|N.....R..o&>....,.s.....QRc....`V..r.g../k....=..*\.z91..,Ek...... w-....L.....p/Z.../....=......,V.Bid...+.#t.........A..q...K..!:.G.S[.]BN..;@8....~...'.m..'..g!,...g&.d.%..\....7..R..#YD.....l.h.:~t.....q..<j....B...v.[......7..x.I ....C>2...|X..x.W.B.........w9z.</.~..L............9..T.L..M.}x...B..~V...Z.9wr....D..\e.B.H];.qo..Z...u..U.;,B _.(K...i..._.p!..Z.g...h..|KV......P....0.%...^.^J./..7d....-.......2..K..:..t....VJa.K
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.843868701065443
                                                      Encrypted:false
                                                      SSDEEP:24:bk96YsroqSjr33x3bi9sqXgsAmjRK8gyYE6zzjZbZroSEFGPm1Rud7OZififwQbE:bkkBCr3dROK+wHj9ZxtPm1Rud7MifDQY
                                                      MD5:05165F009B11707ABDADD16C4C06BF3E
                                                      SHA1:D5463B1A0D2F6E59A9627611A0A3E391DC103A2E
                                                      SHA-256:163308119E14AF72048E413BD7C73C551EC6033F9A28C0C65BDCB492EF85FB3D
                                                      SHA-512:A1CD02D746FFA1F6610691A724985BC9A8AECB03953F129D788FB11E29236F4013D637A050B12F58848C1FDEFB6AA856B3BBE1872C16C8A9F78184E83E961DC2
                                                      Malicious:false
                                                      Preview:WANACRY!.......y8..,o.Ln....!.3.JG..........yu....Iy$.vz.X..R...:;.%.t.......is.).Qs_."o...C....rxSY.!{/r......U..\..(.H..?.q.O3.7w..*.a.3PQa.6..Q n.%_.............p.(8.....Nu.=.8........{....9C...(6j..Y.V...e.L..V{.7...(h{....a......h.......!....h.j..*.V................p.K#............=.ZX.!.OI..b(E.SN.Li......@...&S...(..7?yA...1.zk9H.H`..D.c.Qd...^..ro.NQ.a../.../.....%..#..u..5yi.|..E..x...[.o.!B...-..ur.......tG......V2}q.qr......:.t...,J.....rQ....Le*;.^..)-.....1...-..|.-1.n..@.../.s.....3v.P.|.._".L.x.yB.|h..F..g.....X.*.."....:.3.:........e.. .(....N.d2...l.T.../...$..\.;.j......WB..n.3..f..c"..W;.................f...8.Y.f.\.|7.%..VP..n>..<...g.!..[...>.....H.........%....L..9r.........)Z...i..f^.\b.Y4?.n........ao.=..4..#..$..Y...F.'H...El..<.]....T>...@.<.....?.o.r..a.....#..QG.+....q..v...o.M.\X].....E./}.j..s.=W.x.^y......J6\\:6..N...V9...5v$n./Zl..ef...[.?..8..Ph..e....9.]*....j...\.i.....YhT..ta .F..JQn|2...3X..e..
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.861138583655845
                                                      Encrypted:false
                                                      SSDEEP:24:bkky91L12mpQd7SIOzODsiGaj9EjQ3LrX6zbBHJkS5Xnk2rJhdTpvXF7V2X4Z:bkk21L7zSGajGjQ3LkYQXkIFtvXF7VyU
                                                      MD5:081687627151BF9A38093DF2728B2094
                                                      SHA1:E40AF3A184D06CFE12A9D6F8A0383CBC09829C11
                                                      SHA-256:C00E3A7F3E686FC75672BE3DFA1C87FB96CF75FDC5B1F58B8B7EBFAF33CB4380
                                                      SHA-512:5F03AB13828F3BA8B8EB71AAED9B695578F34E41616F8D1889FDF2934AA6AF4EA3A8DAA154245C05F4FDDA61D74A11CF98C90A3F7A3D94CF52EB1B85B8E09732
                                                      Malicious:false
                                                      Preview:WANACRY!....=..../e.b.r.l..L..$oB.!y..S..1.9...D.s..W.......q.^1.........H.ksp..=....g.......e7.v;.{/.;+.=,.*...o.......dQ~.F..G........nb5,...X....t.O..D.]..&Cys ..%.R....\..."z.Nfk.:...h._f..}Wy....}UQV=0kl..[/H.A.......".I.d.o.,......Oa.\5b.....{5.....9..................*i..J....r-.\J.%g.y_..%...Y......7.Y..[..12..c..As..t..L/g.^..R-...k.7'yO.&......p]..0pl%........>...k...'f\=^......f[..U...;.M..`q.N...F.iT?...%.r..9la.+....[.*......`.L...Ia.r...A....F..3..h.L#..e8_vS..;QYh..o.7..../G....|..j...C..r..x.d....n..p.x...m...r%..O...#.E.%6......(..70.8.(s.m..).E=....r.0.o..F..I$}.'.[;....-...~.m..y.LK.".PZ..L.4..t.6....[.z....[i.c.9-.$Rv....%.|vq&.....<....e.w.t..Tz........2.tE..H../L?.?.<>...r.......hC|$..NH.\p+.l...3R.y.-...`..)...@..8.KQ.M..M.;.A[....?....d..-......2&..)Fc..76....f+k.A..k...~..r.......rLs..J.4t:4.r....I.......,.U.o X ...J4.....*6./.{...h.?.k=......vv..L..].....s!.gYL..$!JVG....t.....%Z..;j...`..<.%.z.1..V...".?.s4
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.828956671353872
                                                      Encrypted:false
                                                      SSDEEP:24:bke0bT8A60RPhy+hWJV6LOGb9ex/WZsjjEO5/N4B+zrZ4RW6C:bkeUTfHP7m6Bept5/2eigR
                                                      MD5:266270670827FE51224CAF05D4867D55
                                                      SHA1:D1876730D71806C4D7912874A13F6C50CA377847
                                                      SHA-256:393127C34667A103471C6FF41371EBD2E0250C62324E81AB0410EBB5CBC209D5
                                                      SHA-512:E3A379FC28EA8DA9D2197A1229B29638C2DD8991088C4307DC5E7748C520B93B7A43C69E0276CC135D285BDA3CBBDEB4E171318E6113535C3C7D84833B520391
                                                      Malicious:false
                                                      Preview:WANACRY!......*......$.S%..].*./..X......e..7.,.....C.hA.Z...u+....h......v.[|../..e.B..Y..|!..>...B.;...w..ZKt/T.>.....A.R.s.$.....)k.] ..ao\d.."...R)3'...t$......M88...+^.P.......i..-..[........IKr^.B.:..0....j.x..t_E.A.{OE?f.5....i.........MQ...~.s....o............h....z.....?,.0I..P(...sTj....b@:.+%,jYBI....A.Uj.. ....7[/.g&..m^~.:2..l.]..Q8.J.$tB...!.G..t...B.?.N........d...^.KZ3.o'.8..6M.2L.._.....K|.....f.-.h.X.3.....T.'d........9(..}7y......;.(.......kY....a^*..2...(7..!..l..W....}..........8w..t... .k...;../c....~.f....}u..*Trj.*.;.4.+E.....Jc.....z...3..&.r....^...sAX+A......{1'B+U%......,|,..(..(.m0.M.m.^.6Z.).R....M......r..v.=WB..9..Z.u7..w>...V.R..l,..>..=Uv..o4q#..7un/}i.l.O.\%m.X[..|pJ.........vRt...`.=o....5#......q...^..<Mj..-.I*..3.V...7.....BIw. ......ZHo_.t.....1 ..O.......HP...*:...x..&...in..S....w&|)..m.*.G..y.Y>r...t....q.T...m..O.5C=._4.*...|..9B......}...>X.8..Y....s6.j";..m...v...4....).."..S...'1&..o.Si..,.....#O..*
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.847464372862753
                                                      Encrypted:false
                                                      SSDEEP:24:bk+Gy3ExJy4Tl5e4htdEtjhAHeg/qmcjOe0vwooIJ2e2L40K:bk+3ErNTlqtdqeIqPOE02e2Ub
                                                      MD5:7E874316DAF84E3EF4BED5141271E93F
                                                      SHA1:0FDC436AA6B4B3EF296613E4E3B070F57C5A922E
                                                      SHA-256:E5602A463D74CA9B53B4862F05D6C14604790E01E282955DE7E8FCA0BF7E9E8A
                                                      SHA-512:3AA44990E0D3CAC677F43FB52CD2EE951E1A775A34AF07F091718526C5A6F224834C3C9F7E7AABE532BD65D8FEC6352D9B30675F4B329CD7402C39D81AD6518D
                                                      Malicious:false
                                                      Preview:WANACRY!....9D.w".....,&..E(BM.zB.3.=R.Yv...IxH..M.j........`(E.w$<.{?n.^.Y.i/.c.@.F;W5S.AR&.6\......S.....%..b...w.u....c\rn...B.....{.....e..Nx...P.pn!^..%.....C..kb.|N............E..r....N..l.,..m...x.).(0.D..3..-..x..../e....3...@n....~o.G.S..O...g?u............p..r2WC..A1_E(...L.....^.O.&..../.....c`f..q.#..p..ArV}K.!.{..].)|-......If8?.].N..A....+.......$.....)z.GfK....H7.^.e.k9.V>.j.Q7..v.....'.y..[<....K.`)..5.*...:..b!....'.F..x..9................TKj....8...u.`s.h...wC|`..Q:O-.....H.....`..Aw...i %...[......j4.........Wf.b.z...t*<..>..ecr.[...$.n<..O....a4+~:`cC.....q.Y.$...&.".H.x...Z...2.RN..#c..5...n$..aQUEQ..@.e:*.[..U<.=......[.i.|uJ8..*.<.......GO..}Y@]..i4.I=;W..Z"..?..M!.{.j..i........k.4....f..0..M...7&".P6Q../..#rcR@..b.RJ]Z.v=W...L}.K.........J.i!D..>.,.......J{p.s.....C.R.S.>......P..BM ..1..#..2...m...w....h...|......c0.....L..B....u.P.+..4n.]...46..d.L~}#...t...J.V.)#..b...S;.H.O..O.\$O...3.e..2...m.pC.l>.5}.Z... .......j|7.Y.l
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.852675393523559
                                                      Encrypted:false
                                                      SSDEEP:24:bkryVTYH3N6M5jBmzG8isMTFms9HZkybHGOGMJ15ajVMSD7iNmoIbRLx6Y:bkr3Nbz6isMTFms9xbHGIJHauSD78lI7
                                                      MD5:F206AB6925F4D73AF7A66403D6DED522
                                                      SHA1:8F33B28A3FC12411C14F5093B1C090CBFF8B86D9
                                                      SHA-256:3F9DD3AAF96D0B8503A512865D292D4077CB7AB7214F93D8C465084F24C80C63
                                                      SHA-512:B431065C3E96B76A5FDD57539E0E4CF2C56748B449BABB1058C567685FA14FB22124A5DCB12EEC6452C06304649F45A12460D01AEAE020A07A8714FE0A1EE855
                                                      Malicious:false
                                                      Preview:WANACRY!....U...@.'.3g..&..ks.uX.[.z.p.o[...E.k..3}_.|0.".y...4.q..4.c.TCk..9d.S..5.........".i{`..?F6......O.6....N...TwN|f.)=....V...k050..W..)L...G... O..2...2....3...S..HJ(F.a.....t...?..9.x./ Y......:...SN.wY.'...4.XZM...K.....%."3/.......6i..O^S.|.....!}.J(6............._8=.O..E.o.`3...{....l.iF..Q.l..h.v.\...a.q....~..I..8......Ca..k.\.%z..w.t6..j..W............Y..Zx@.^.6U...VS..,..<=.En..8.H0L_;.N.AhpSx...1.4....k.....b..J5rH..I.@jo..h./.A..........~..b..tz.....P9...n.+..0DDf.i.u....L...J'.n.r..oB.$..`e..k.....OL.2....PK_!u..l.....>..n..Rn.....NXl......uT...G.L......dh...^f...]3mm.F.B..^..u...=.4Mr1.|[..Ce.. ............&..Z......A.s..7.d.'"..b.u..o.G..../....S..7%.PZ.....9.i.W.h..........o......q(.i|..|}8.i..<......7..\....3.mz`..%P0......c./.}?*..P.xz.[^.....x...x.....D[<.H..].9...}......*.H...$....Q.:Qp..9...<..,[.....L.e.N..]..d...2@Y..$A%-..z.v..$$.....)..T........T....H....2...{6.&.....8H...C6.I\|. ..)......gJ.K.`.|.r./v).[-...U.pX...1..&
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.835976584090721
                                                      Encrypted:false
                                                      SSDEEP:24:bkalU/0PBbr69gKJIaFgiu6kMhTloeO8yttfW/S/VvbhoGjBOnhSSbTMVCTfzL:bkl/0PBZKryNkhzF4PhOhSSbQQTbL
                                                      MD5:1E258AF49748DE511A7274804BBD5963
                                                      SHA1:965C9EFA655D1C36DAA7387FC35EAFE9B250842D
                                                      SHA-256:7080B5D4BE24689C42BFF8671D0A6C5B3896FB4BBE593D706F8375AAEFCBF7E6
                                                      SHA-512:8588B10BFAF535A1B511C431E43F7CEFB1B7D8EFBB31F38D184DB539B9959926B888778CFFC375C269A06E177BD80AAEB89EC1ECB981F1B0419CCF4F9DDB567C
                                                      Malicious:false
                                                      Preview:WANACRY!......A....XZ~.._.L.A35.}^...>......i.[a..q5..]\2.>.=...1....W...<..c......=.q..U...(-...8j.+a.P..W.E..?.&'._S.Q{.U...4.R./._0.><.......q .OpS.......`....z...!.~y.WU.....pK..\\.]..n.}...`..6...Dt.{.W....gl...2*...j!'P.....yj.W;.....G...._6ix...............t.*@.y..y...'....i....29.$...).f0.oO.....]Z...jbW2<.a..ek....`....@...h..,.a. ..~..GF...:...s.R=..=lE./.0s.. ..W.....(.n..8....YP)....E]=.j{.}..... .X.....?.Fo.p*..n[..ST..v...v..D..l.....CmE4..Pr#... 2.}.9.D'.Tv.yOQ7..9.9.l......3..qsHRK..3D.+.[....*0.r'...d.t........3.}.O.%.d.l.0.<..U.. ....(.....M.-....w....v.MSv6BK.d.....o..k...e4.-.O.m@.a....p.......@..T...~E.@...(..Z...?.k.%.FA....:........&...x7..Mb.0...<B=.<..E......\..d.p.P..tLr.4.......u>.D.dIN[..Y...Y5.a\.....a.-.aP$(O..v.]....,...p..I....../;..S.,..&k.\......l.E..:M...2Ms........{:muE.....m~.g.!5\.N2.Z%)..1NB\$...k.h.......Ic..c..a..d...}.<?..N...{`w..l.T#.....F..d.=uK.h....s.....2.7.Q%67..b~........'5'*+.+Me..
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.84247644543347
                                                      Encrypted:false
                                                      SSDEEP:24:bko69t7O7dNQ/25+t8nqIBTDGGv8eO5F2CZ/Y2fQypeWkbxVUFF+3ANnWEzI0mO:bkoWQBm/25wQqIViS8nHdfPotvUFs3Al
                                                      MD5:31BC2F1188846F7BD62C193BB6E2CDDC
                                                      SHA1:25A26CBC01F4AADF7B53D2585DA3C7824E93AA5E
                                                      SHA-256:FC5461A1715E858C0E1E9446DA384BAB3CBD08BDF510D53ED4832CA2D47DD890
                                                      SHA-512:997888B1583C4F83DD2BE5E15AC090A0F81F5210E6A15B62D7D9564945858C7E048E5B02E5381B19B8518038F86D024B8A523ECEA08C09378C1E82E3B59D7617
                                                      Malicious:false
                                                      Preview:WANACRY!.....$.c..1L...=$......V.P.>....\.....R..a..7.E.%".V...........4...mj...G@.\..-c........T.c..OY..)..........|../..ru.|f.uU...2.A.72...a.4.&.......W.W.-.m..O......K.;.}..._.D....?.C|7-...{..t.m.$.n.&`.AOFO...22....U.x....|....D\|'A.g.W.L............v.+.(.....X4Z`...\....>..U.s.........2 ..lf|i.r.".FF}sy.v:.wJ..;R.0_n1w.x..4.*_....+.H.)...]+..S.....xX.$.!.Uy..u.4..X...o].6...._.....A>.c.*.H.A..6...o..Hw.z.yA.?Sy.@...K..w&....O...5;......Y.+k..H..,7..F.Z....^..=.7..u...v.4...1...q........H*f...;.d=...HF./;$._.......U..R..H..4.2'.e....$]D.....`..7...C.|?.......-....Sp....QKz$.j.8...2.['.J.*r9.~.f..../..Y..*......=:4c.P..X1.Y........|.......v....9@.R..n.....*...|....R.a..y..Y...3..'5.'.I.%.K/SH<~\......_.....Q$...T...Qf..\i..,T..Ya....+..z...FQDA..}...S..''.%.m.^.Z._x..2j.b..{;e....-QH..3d.].....=.....Yu.....s.eC.......l...@......+"&s)..kG..-...2.DD.f._.nQ.........T..).nH?jw.?.C....b.B=.......%.<....."1..\.W..f.......G2..UCd.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.845494258042585
                                                      Encrypted:false
                                                      SSDEEP:24:bk2nIpuLy1tLrxoIArb/G8A2vLxqVbEduvzwIZ31QsrYPahnOXvpRoT4LV:bkEI8+PrxVArbO8ZMa0MA1QT0OfwT4LV
                                                      MD5:DF0184895E8E17693833C29B6B8189FC
                                                      SHA1:3E6C4433838AAE3805D655E1CB7B56D5DFF49E58
                                                      SHA-256:F97D23DF168B8CDA16E7CED04B3D3E4126AB91F8BF94E5D2B42586D68FBFF485
                                                      SHA-512:6D60D80D790195497CE85CF4D16D9E9BFC5A3796A3932849931F0EA08A44BCFAF99C193E6BD228BA52366FB6105E86E88FC404E2C4B216C2FB3E84A1C8F85C07
                                                      Malicious:false
                                                      Preview:WANACRY!..................D.._W...>w.\.k|k..L=7S.......'Q..o..|.....o.VI"./....#.R..=..%D....Q.P7..K.U5n}~E.x.......J.C....s.>wG.@...yD.....A...Zi.9A .%..F...Q!n.^5p.n|..../.&T...V...G.....:_J.."%......2...T.T..|.h......L..2..y......u..<.t.U..s..N\>.............%..n...;;.F.&..I..G...'..N...J..AH.P....@.I.<.;.G.9.'....a~...'fJo..7..f..{6..4..Z6..Q.9.Q.#.&[h....e(i....:J....&...5X!..{.....k..C....C..d.wV.rA..k..u.../....Y..`...........I.j.....T..`' ....?.......CA.T.s.....y.......\..?(..kY..s1A..r.u...[j{../....6..6.........E{...w.8.4aV...Q..@.....`...S.U..n..n.xU...{.>..gX.........p.Wv.....^....`..a...<..zy.......Q@Y.3.5...8...W..?N@...G..h.~..72..=.-Q..U.Z.....F.c.3J.........u,............$.3\....(...;.u8Z..a...%/.....).^|..v.......\:;e....~.....3...OT..8A..r..V.k(f..\.+...PPQ.<$8T..G..3....X$.....iXI./..B..2<]....w..A........'...7!..iFN.?t.....y'....+..:.r.@.a.qf.>.#....kX....%O..aT-..y...A...jm.E?.........)-xk...D.ZWSF......
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.8516625081588485
                                                      Encrypted:false
                                                      SSDEEP:24:bkGXsUXcM73qeOMLJ1283o/tvqZXxdiQfREJdrjvSFhbgUep9kNfunRwn:bkGcDyqe5284/tvqZXxEoREJJvIbgj+T
                                                      MD5:428656FD792BD92CB0468FB0A975C8DB
                                                      SHA1:53F7EBE7977C08851F554AAB580FCFD7020AE270
                                                      SHA-256:1C8DB6CBD225C308A92F573905316F7C0000EF42DF65943D6FB685E6CE9A95D3
                                                      SHA-512:0029910A28F042CDF7126FBDDC41BA542FA9FF1052104E9FDD5A69614BC438A8D5FA6AE897DF0A52BD06369B8A9CCC2E692F99D59ADC9BB6A6BF72BD34D47F0F
                                                      Malicious:false
                                                      Preview:WANACRY!.....&......,q...+BR...Q.F...~....wn...~>nC.....4R.n..n....l.nF...k.......[...,.o1...A1.73....~+......2...[Sk.c........S9.66-....(..%.y....`.K..S...s;.vt|{..Y2l.f]?\+..?.I$....8.9p.x.T.n.....3.i.....7u.z..|.C:=.~.\..K.Is.a.......).2.1....a:..2.e.\.............b..wz../.`9#....7.7d.r!..C.....].......$..G...m...u..G.OFc..]....A.EKe.@......Yw.o.Q5..Pf.h.m..,.IG|.<.tR\...J...%.M...?...;s..b..a9.B|0.....n+.2..u..(.hG+O.M.i..M../6......'..0Rs...[.]...*...8....W..".o.}*.......{.q.n-;;6f...~..U.B:./..Y#.C..]cqt...<T.....T.(.W........r..{*x.L.k....h.. ..~sF;.....eix.Z...N%....#...d.xn.....v....A....q..I.r.P6..P.o..W7Y......SkZg....7...:..7~b9L.x......R.5?.fn..I.>a!..BO>.s.<..a.9.P.e.I2....T...N@.v...Z....Q..PV..A.c>..J.J.E.z....q....&.N.Md........pO.|ca..Q.R..f..K..M.f.'..[.Z..I]#.+v(^.......PvA:...~.Q.~.....+.1..'. . ....RX.r.j....BnOc.P9..}H.4=[y..._c:.l..[6....K.e.T-0.SX..........1._y.*x...z..4yr...U..v..Z0.?.....M..X....F._..t.{.!
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.837743321825747
                                                      Encrypted:false
                                                      SSDEEP:24:bkJnsjx1u/bAlt1Rmii3W1Gqpm0UGAvW+W7+lqxM3eaE1fIkB4GNZ:bkNsjX/3WoGs9UW7XxMQBbfNZ
                                                      MD5:4C40D30132E371AC124540F04B51DE42
                                                      SHA1:F801BA19A12CAF59B3C6E7A9149C0DFD3F458E89
                                                      SHA-256:3C8AE58A4B85D7A4E6ABDD680EA06801BCC0712BAEDF232B9BD8CA010BF1ECE4
                                                      SHA-512:9BD5C69BD2E0545BE60C670E13D2274A9ADCD6F640B4570B4C660A9CEBD3D9A23C831126CCF3BD5E4D204F18B5BFAEC414820B518ED7E0E18FAF0EE0BEB1EF79
                                                      Malicious:false
                                                      Preview:WANACRY!.....p.&p......-`).}..]....UI...7J.Q...n&9_.....u.W..<.R....gw.O.m.D..^.;wj.....\p.}.o....h.=......kUGVp..(.....D.M.r..8.Q.....2..p...}3.,..(A'{o...@...g..,...n2KU.0.<VY...V*R...d.8.G......C@....0.....=6.!.W.wUp..Sy.T..dM..xd.{..<.m.............................<t.$Ni....}...K?..vMb.e.$>....D.4...Lf6/....x.J.<..#@."....{F*.....J..B.....e.B.....n.v.r..Fc..ff*.-..b8...2..X.....Hu./.D..C.e..z........1.N@.U./+...G...$..h.^..`iM,.#RV.e...i.....m3..n[.....o..'@...m..q..'...q* Xa....h...TU.2..........J.J38.9..).%M.q....Z.ZO.!v.X..%-(..R..mV.o;.;...<{.t....9.@p%....d........Xg.r..g..a.^.....}c;.....a7....o..q.......hN.0w.......$M..H.].c.$A..;|...+..`..&`..* .H...V.J....O.$...=.Mf.(e2..._..r.^#..........l.&v../!...Q._i.4>o.^.....6.ag.:n'..Z....uK.j$|O i7 ....U ..t...[^4.;.6.z.` .7...x.4. ...Z.m..E.R..~2.#L=.IU..[d.........B.C|t.6..g....V.KfC:...(. $.p.:.ig....z..s.2o....i.6kA..w....]...3dx...S..xr[L~...U.....j.<...Q>..g~...|#.."G2<....Q9.(...F...
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.859781572915098
                                                      Encrypted:false
                                                      SSDEEP:24:bk/0U7NUebq67I75e1mq4B+LxU2IfiuOCXNTSuz/Dnr8MDXMDmL1:bk/R7NUeZ7IsQiL/CXNTbvn+DmL1
                                                      MD5:037B98DC1B193ABD3FDA02F4C0CEA79B
                                                      SHA1:EB56EE12BB5E43744EE305F0F09218D8C7BCC259
                                                      SHA-256:C104DC39D3B2E9D4D721833503ADDFA5974A1581E7125BE809DAD1B296822D0B
                                                      SHA-512:4180225A3CF0D4FAC383633CC8CC27FD8E3A1B34814A4837C39AA024942A289F0A5FFB825F284A40E45FF66085CE22622B6C069F7011F19C2E71EF6B640CEDFD
                                                      Malicious:false
                                                      Preview:WANACRY!............=5...E.....!i.,...tn9....'.}...}s/....b...?`R.....UU....4.U.p..U..m...7.....l?s.#.1KT.3E.....r.Cf.m%.h.....+....!h>...T.|..AG../|...k...y.3.H'Ms?..:o._.e.s....0.\8...v...`|..b%....hK.o_.L..h{6...m...].B..eJ...n..]=...8.;.`p.........d.0.P.............WG,...)w.......a..:...io.....'.....Qg.........1F....i.. 6........N._.5..X.C..\ ./.U.W.<..+#f....sL....@.u.....mD....Y.W...2..).....H......#@..L$....n.>M...*V.x....?....x.<.uK.Xl.|....o...E..r.....{5..Xb...IJj.S...l-.<`b.@.%p{5.Vq....e2...X..V ....;0.e..............1......E...1y.....`m...?..w..x. 4.]D.B M..:....n....UP....T.....k.>.\J..&.b.:.Gy./.O.e..[.~..2.;.X-n.C.&b.6..w.yo..Q....+.......v...'.../..>...p......1..M4.~.&*(..r.e...P..ziE....P..U..yt.k..W.j.!.@..!N-$...{..!8.P..?K.9\.............(..........0.U.{...~l.S....-.O.)+....M .^@_..v+...d.e...N...]......c......B.G..m...v.Pr..%iq..{.......Z..?g.@..........e0b..._.3w..5J.eDZCi..4.......a3.m/.7..!."4.7$P.....sId,.;bx.T..
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.859669258324317
                                                      Encrypted:false
                                                      SSDEEP:24:bkg3xe3Ja8GuINOj93U4L7hplPqTYsTf7t0I6T8/6gCTPc5RAiN5/LsyXBGzDNH:bkgm1IIB39L7hplQTl6Tw6hPcDPN5/WB
                                                      MD5:CE5AE74791EEB54C14C436E336EFEB83
                                                      SHA1:67C3D15C1E8B2559F3291B7838E54E0126FD48B8
                                                      SHA-256:A1B4B876091ACF873B93CBA86E9233D3E8716B6BE05C8B8D6C741DA0C4133280
                                                      SHA-512:728824991CB8E18F964D196967F292C756FFA70F2E30F11228EB61751F139ED684DBB8CB13C1ED142F017D862C7AE404DBB4F5071A280F5381A0D685020E7A26
                                                      Malicious:false
                                                      Preview:WANACRY!.....i^M<.+u1..o.@8....H......".h.kt...T.:.:.... ..N.Zi.......Z..EL0.,.F,...^.~Z;.P..u..)S..S..|g9j..C.+..B..8^.@G..E?<..(l.~..&...1.\.UAN.J........4.k".._cp.Q.j.r..r.._y.C.1~l..... .t)........b.J[|M..[Hy...x.E.L.X...dNBk%f.b.L!.F..%...,.Z#.?..................,[...~..G.dS.^".2n=.E.K.....=#r..k.[h......;@N+u..g..m .N........t0....7..[.?..e....%..........FH...S..j...>...I0.4.s'..L.>..)...2.l..{..2..9x..2.J.......q4I^b....,......T..t.f#.D. ..+K....Fal....\.(..D.LCt.)..f/x.gIV.*%.b....>;...7.i...H6j..x.._'.......*.....tX[...O...y..r..p.|q...d....\.-N...HRL..{.e...Qb)..u"S.....E.....(Z.G.bT.J..S.O.....)9.....T.s.RO...Yn.>......WH.....u,]........+.....[M<O^$.$..n..Q......>...e.].(...7."h...A].....C..j2..&Il.F.....IE>..y.-".^;. U...J.D...=...wm.r..~..pG...H.....\....o........#G...h....K.<..4.g..Sy.`g.=.Ht..e...EM.F.Ze.Y>1.'..KI....$..W...p..5..Z.."U..'[.....-...g"..2p.v..7J..........1b..C...4)kx.8...sx.t.4>p...2.T...L/X.n.#A.}B
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):67976
                                                      Entropy (8bit):7.997338989601223
                                                      Encrypted:true
                                                      SSDEEP:1536:6nwXHjfvErF6qz8FB/hePbfTZAdrpDbbcqOahqsk9c8V2mVsn:6wXHjXSFsFB8BgrpD3cqOiHk9V2P
                                                      MD5:116F5E47839FB8B471CE5C26A2DBDDA2
                                                      SHA1:BAA192AB64B64D14048AF0754ED902B270780166
                                                      SHA-256:54FBC46C20A86E8931F48B96DD201DE733278612417C6D930090D432C8CD16DF
                                                      SHA-512:F70144B896044AF431089E69D7D41F89C264618FBA8B93D6A2A157C406B8DBF9A3B2F3838D776CB11CF6D73D40302172FC29FF933FF6C83F9DDF4D96E04C7C05
                                                      Malicious:true
                                                      Preview:WANACRY!....82..e7[.....}...x.., [....-...\n.E:..z^..<......"^....%V.f.H.p2..Cq.A...+2C.+.R.........k.....e....W.,h.o..NH.2M....(.\p...f..WT$..J..)X..+.6...$)P9..........$$.w$.Kv.^0..!..m.1..s.......g.MW.=i.eno.ve.l..3..I....]..8'G...%...]..%u,.6N.a...n/.S....d.......1...N..wY.....G.d...p..Y.[c.=...?e1...).....0U...q.8..S.v.T....Gj!.l."...S.U..x.n.H..lY...&...X.n.:.>x..;.F..RTF.{P.C ....-..I.o.{k.{...?.T.[....).y.z....d.3..f.3...JN..<.:.@.<Z...e...45W3.r#.T.(....PZ.....1.S^.T-...*<G..."..8.2..M..."..H.....a{.N.d.G...%.v!R...R.^..........N..2..D.\b>.&.."Wx.K.,....8ETG...a.F.._c-..a....d.FEb.Q..i.q./...\..."6.....!s........n%...T.<.O..A..........3....C(z..y#.M....!..~`G.Z...\k......<.).Ly...s..+[B.h.#e.ks...Z....$sC..l...`,Fi..F.L"*o.%Rr.-.yC..E5..K...g#..._..G......0..C..d.s.i{..G.c...X.tW.Q....h...Bze1..."..B...........wz.....R$..ic.,......wZ.q..@....C..x6Mi...|.F.......awN....M..-..m...q+.....a|.F..d.l&.3mC....#.9....;..0...q.....e......P5
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:TTComp archive data, binary, 2K dictionary
                                                      Category:dropped
                                                      Size (bytes):1284
                                                      Entropy (8bit):7.848127650767157
                                                      Encrypted:false
                                                      SSDEEP:24:1hEpA3pzrM1Fn3O6KusfDBqsXNtbJYXdd8ZhLMTrsNWZJVAHmRKC:Uq5zYP3KF4OtbKAbMTrIWZJmH7C
                                                      MD5:ED5182CF1B004421C14E11E05B47E023
                                                      SHA1:F2CF487C6565596A78F62A61B24826B43CCD036F
                                                      SHA-256:CBF6C327538B78AEB5A579105D96A82018354D3A941683A63CE22A44C9391AAE
                                                      SHA-512:D3DC80DC604369E1DDA77A4FA90929EE0BACA18925BFB095EC7232B65C3EEB0A43D9AF9917BCE874C60176A8D687DF0127D7E7A0A6819D41090362E47655C4C4
                                                      Malicious:false
                                                      Preview:......(&...?n.d..J0*cd.{..j-.U.&......F.t...|._..5t....b`..G...fP..;.1..&c.-......W..l...IP.....k...Di!n..2d....f[LTF...1.Z.]ixx07V...3KN...E!.....Zf+..k.....8....dJ.s\2tA......T..x.....y......z.......|+7..Q.P...0v..^N.j.....]3...d.L.y=Pne........q...|..a.H...*.-_.. A./;...5.HRG)...0M.._..a.O8.u.j...@._..o....{'.......A..J.rvn......k.<5..0N.........][.......j..GR.X...Sp.+L.Mjc1..-.q. .g.Bj...v..e.A1................6.o3 .yT.l..H.u....f..pE.X.R... v....`D!..Ty..(.Y.......6k..../U.q0..v......x.C.MC..{......ez.rN.\.H...^.[R........>7(Q. ...7.VO..%.G2.Z.}.*V|C..^............*N/P..W....m.....v*WW.=.."...).....A...T..V.K.$.z....^3N...M9..*.,.R.t...ghj.-..Q..#...Q>%`..V.lX.<S....%.C.j........ST...-....*....<.uj..C.S.pH......R....AS.H..>.......}...Q.Q...R......ro.....W...T..)8I.p.#..."|.h...*..R.dw&v.>L.^....Q.f.F..J3.a.:...L$W.~.E.*6~ggJO+..._h..#}.P.x.eMr..hT.........Gp.Is..."...~O.J..1..*...g;..w2j).....*.-....S.#...,a...$.^..$9GYn.^..,....xK..K.......
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:b.out overlay separate standalone object file V2.3 Large Data
                                                      Category:dropped
                                                      Size (bytes):276
                                                      Entropy (8bit):7.197738006280103
                                                      Encrypted:false
                                                      SSDEEP:6:mtNbEiVlGGiX0BoxudtS5xgxjKvSl//8X2L8ZI/tBfb+/wkTn:YbZGlpxF5QIYv8S/zz+4kTn
                                                      MD5:810F28F91DF4B55C4C2A2D9C95B0C246
                                                      SHA1:3C38948B3A2E11270EF04F563E35DDF3949D5A9B
                                                      SHA-256:E8366379DAD8149F37C8BCDADF6401408249E6EFB3275B0843A744C3D1D78E43
                                                      SHA-512:69419CDC712C714E80DC1061EEF8461F9324ECA971F8693C1DB94BFF0906128FB6C240BA698C754178D1D5183EA19B6E2EB9E63322A4F7CC6EE0ECBA74EF8672
                                                      Malicious:false
                                                      Preview:........RSA1.........AYtdOm..+.v6........U.../..V.....M.M..C.3@...N@S .=l(............99...).I.,.O......]......l..LNe.w...K..x.x....g...!rR.a{r7.b}<p{^,.....cnB0.3.7....B;.@..|..s...{E.."b.18...*.6.$W............a..$.}`.....:s..{.....S...znk....>:.....U.].'n.k.B..z...
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:modified
                                                      Size (bytes):136
                                                      Entropy (8bit):1.2233025807003515
                                                      Encrypted:false
                                                      SSDEEP:3:2Z+rLt5llll/YlPllSl:2ZC55llleSl
                                                      MD5:1A51AE173A7C42BFEDE6ED4ED749CB7F
                                                      SHA1:073834E8AF6CD96F08AD7D764159D55EC62CFFCE
                                                      SHA-256:2C712DFD406DDA2EC71A42D2F3BB32D0DE31B0CBFD5155FEEF9ECD60D6FF72AC
                                                      SHA-512:7900A6B347B800ED26811DD07D3930EEEFB10787303D52028B33CE6E6EE0F5AB80E0EF38083AD586BD776C4CC52EBDA68A91ADD05C2756F0B1B9DA96B576A62E
                                                      Malicious:false
                                                      Preview:......A.........................................................................................g.f...................f........@.r.....
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:DOS batch file, ASCII text, with CRLF, CR line terminators
                                                      Category:dropped
                                                      Size (bytes):316
                                                      Entropy (8bit):5.069669182845472
                                                      Encrypted:false
                                                      SSDEEP:6:hqn4+B9TqLEoJgpPqLEoJ0F9a2T2ZLT2Ln:Q4+B98rT2r
                                                      MD5:840146282466542BAF10E2D129D064D9
                                                      SHA1:04DEB960A79BF9B55F2404EFED1FECDDFABEF016
                                                      SHA-256:C13C9DF7668B47295FA6B6AA035F3DA1EF6ECFB66EF4E2866592789525465E40
                                                      SHA-512:72F4FC03D7C142CA1CD0274378AFF927572DD7548727EE4247FB601EAA8047A0005E744D93A61336773E194FA272457E259C49A02CFCD7D25B3A5976DB2BA9A2
                                                      Malicious:false
                                                      Yara Hits:
                                                      • Rule: WannCry_BAT, Description: Detects WannaCry Ransomware BATCH File, Source: C:\Users\user\Desktop\70341721944935.bat, Author: Florian Roth
                                                      • Rule: WannCry_BAT, Description: Detects WannaCry Ransomware BATCH File, Source: C:\Users\user\Desktop\70341721944935.bat, Author: Florian Roth
                                                      • Rule: WannCry_BAT, Description: Detects WannaCry Ransomware BATCH File, Source: C:\Users\user\Desktop\70341721944935.bat, Author: Florian Roth
                                                      • Rule: WannCry_BAT, Description: Detects WannaCry Ransomware BATCH File, Source: C:\Users\user\Desktop\70341721944935.bat, Author: Florian Roth
                                                      • Rule: WannCry_BAT, Description: Detects WannaCry Ransomware BATCH File, Source: C:\Users\user\Desktop\70341721944935.bat, Author: Florian Roth
                                                      • Rule: WannCry_BAT, Description: Detects WannaCry Ransomware BATCH File, Source: C:\Users\user\Desktop\70341721944935.bat, Author: Florian Roth
                                                      • Rule: WannCry_BAT, Description: Detects WannaCry Ransomware BATCH File, Source: C:\Users\user\Desktop\70341721944935.bat, Author: Florian Roth
                                                      • Rule: WannCry_BAT, Description: Detects WannaCry Ransomware BATCH File, Source: C:\Users\user\Desktop\70341721944935.bat, Author: Florian Roth
                                                      • Rule: WannCry_BAT, Description: Detects WannaCry Ransomware BATCH File, Source: C:\Users\user\Desktop\70341721944935.bat, Author: Florian Roth
                                                      • Rule: WannCry_BAT, Description: Detects WannaCry Ransomware BATCH File, Source: C:\Users\user\Desktop\70341721944935.bat, Author: Florian Roth
                                                      • Rule: WannCry_BAT, Description: Detects WannaCry Ransomware BATCH File, Source: C:\Users\user\Desktop\70341721944935.bat, Author: Florian Roth
                                                      • Rule: WannCry_BAT, Description: Detects WannaCry Ransomware BATCH File, Source: C:\Users\user\Desktop\70341721944935.bat, Author: Florian Roth
                                                      • Rule: WannCry_BAT, Description: Detects WannaCry Ransomware BATCH File, Source: C:\Users\user\Desktop\70341721944935.bat, Author: Florian Roth
                                                      • Rule: WannCry_BAT, Description: Detects WannaCry Ransomware BATCH File, Source: C:\Users\user\Desktop\70341721944935.bat, Author: Florian Roth
                                                      • Rule: WannCry_BAT, Description: Detects WannaCry Ransomware BATCH File, Source: C:\Users\user\Desktop\70341721944935.bat, Author: Florian Roth
                                                      • Rule: WannCry_BAT, Description: Detects WannaCry Ransomware BATCH File, Source: C:\Users\user\Desktop\70341721944935.bat, Author: Florian Roth
                                                      • Rule: WannCry_BAT, Description: Detects WannaCry Ransomware BATCH File, Source: C:\Users\user\Desktop\70341721944935.bat, Author: Florian Roth
                                                      • Rule: WannCry_BAT, Description: Detects WannaCry Ransomware BATCH File, Source: C:\Users\user\Desktop\70341721944935.bat, Author: Florian Roth
                                                      Preview:@echo off...echo SET ow = WScript.CreateObject("WScript.Shell")> m.vbs...echo SET om = ow.CreateShortcut("C:\Users\user\Desktop\@WanaDecryptor@.exe.lnk")>> m.vbs...echo om.TargetPath = "C:\Users\user\Desktop\@WanaDecryptor@.exe">> m.vbs...echo om.Save>> m.vbs...cscript.exe //nologo m.vbs...del m.vbs.....del /a %0..
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:ASCII text, with CRLF line terminators
                                                      Category:dropped
                                                      Size (bytes):933
                                                      Entropy (8bit):4.710902136409594
                                                      Encrypted:false
                                                      SSDEEP:24:ptrPzDVR5Gi3OzGm0EigS1xbnS4RQhbrW8PNAi0eEprY+Ai75wRZcet:DZD36W3ChvWmMo+S
                                                      MD5:7E6B6DA7C61FCB66F3F30166871DEF5B
                                                      SHA1:00F699CF9BBC0308F6E101283ECA15A7C566D4F9
                                                      SHA-256:4A25D98C121BB3BD5B54E0B6A5348F7B09966BFFEEC30776E5A731813F05D49E
                                                      SHA-512:E5A56137F325904E0C7DE1D0DF38745F733652214F0CDB6EF173FA0743A334F95BED274DF79469E270C9208E6BDC2E6251EF0CDD81AF20FA1897929663E2C7D3
                                                      Malicious:false
                                                      Preview:Q: What's wrong with my files?....A: Ooops, your important files are encrypted. It means you will not be able to access them anymore until they are decrypted... If you follow our instructions, we guarantee that you can decrypt all your files quickly and safely!.. Let's start decrypting!....Q: What do I do?....A: First, you need to pay service fees for the decryption... Please send $300 worth of bitcoin to this bitcoin address: 13AM4VW2dhxYgXeQepoHkHSQuy6NgaEb94.... Next, please find an application file named "@WanaDecryptor@.exe". It is the decrypt software... Run and follow the instructions! (You may need to disable your antivirus for a while.).. ..Q: How can I trust?....A: Don't worry about decryption... We will decrypt your files surely because nobody will trust us if we cheat users... ....* If you need our assistance, send a message by clicking <Contact Us> on the decryptor window....
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:PE32 executable (GUI) Intel 80386, for MS Windows
                                                      Category:dropped
                                                      Size (bytes):245760
                                                      Entropy (8bit):6.278920408390635
                                                      Encrypted:false
                                                      SSDEEP:3072:Rmrhd5U1eigWcR+uiUg6p4FLlG4tlL8z+mmCeHFZjoHEo3m:REd5+IZiZhLlG4AimmCo
                                                      MD5:7BF2B57F2A205768755C07F238FB32CC
                                                      SHA1:45356A9DD616ED7161A3B9192E2F318D0AB5AD10
                                                      SHA-256:B9C5D4339809E0AD9A00D4D3DD26FDF44A32819A54ABF846BB9B560D81391C25
                                                      SHA-512:91A39E919296CB5C6ECCBA710B780519D90035175AA460EC6DBE631324E5E5753BD8D87F395B5481BCD7E1AD623B31A34382D81FAAE06BEF60EC28B49C3122A9
                                                      Malicious:true
                                                      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......%...a...a...a......b.......u.......`.....d.......j.......e...W...b...a.......W...s.......`...Richa...................PE..L.....[J.................@...p.......1.......P....@..................................................................................0..|............................................................................P...............................text....3.......@.................. ..`.rdata..h....P.......P..............@..@.data....2.......0..................@....rsrc...|....0....... ..............@..@........................................................................................................................................................................................................................................................................................................................................................
                                                      Process:C:\Windows\SysWOW64\cscript.exe
                                                      File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Archive, ctime=Thu Jul 25 21:01:45 2024, mtime=Thu Jul 25 21:01:45 2024, atime=Fri May 12 05:22:56 2017, length=245760, window=hide
                                                      Category:dropped
                                                      Size (bytes):575
                                                      Entropy (8bit):5.140446565826782
                                                      Encrypted:false
                                                      SSDEEP:6:4xtQl3y03CpzeVs+bTNAUHUtxXCzaMmM7/gtrUod6tMljAlpdmqLEoJ4D6Vod6Nd:8iypzYNbd0thHZOgZUobjArozhmV
                                                      MD5:CCD2610ADD4080C4DCC35A11217DA6A6
                                                      SHA1:001ABA92D58B546C8BD54E0BC4103661F68CF92A
                                                      SHA-256:0E272CF58CC66E7B0CC4F42094232A46B6EC11AE5ED695BA4156A1A28DA41E6D
                                                      SHA-512:36DC5CE3027E8A77639783E31AC69C9FA61C4761FBEB9A819C1EB49F4A32BF2001C0441FB28D35C4EC9DD1B713576E7894DE8FD13BF14CE62A436F9619093DEC
                                                      Malicious:false
                                                      Preview:L..................F.... ....b{=.....b{=.....`.1.................................P.O. .:i.....+00.:...:..,.LB.)...A&...&........DDj....%.=....(..=......t.2......J.2 .@WANAD~1.EXE..X.......X7..X7...............................@.W.a.n.a.D.e.c.r.y.p.t.o.r.@...e.x.e.......X...............-.......W.............,p.....C:\Users\user\Desktop\@WanaDecryptor@.exe......\.@.W.a.n.a.D.e.c.r.y.p.t.o.r.@...e.x.e.`.......X.......216041...........hT..CrF.f4... .u.E._c...,...E...hT..CrF.f4... .u.E._c...,...E..E.......9...1SPS..mD..pH.H@..=x.....h....H.....K...YM...?................
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.816924222037612
                                                      Encrypted:false
                                                      SSDEEP:24:PhXIIbIK00hvc6S/enJ2de5x6Ll/+PBQfR7wE7CVEW:PhXII0K0smmJ2dsx6JsQyE7CVEW
                                                      MD5:5B67E7A06085AB1BE06C65678EEB03B5
                                                      SHA1:EA9C510DD1525209B57CFF5CEDB053C18A9E99C5
                                                      SHA-256:12484F57ED30C59154360398FDF79C02E6CFEC513AA5E97E5EAD9481BF883A67
                                                      SHA-512:014768E43AC18E05464E31ED84BD0527D1741AB45FC884FC542D82600E13B49398E82F5BC89A670E5072E1DE1AB7273B552D881C65375F0134AF2BBFC5A01452
                                                      Malicious:false
                                                      Preview:[f{...m.....s..Z.(.X...........\..^....{a.n.Vt...b$..<g.....:IV.,@....*...4...8..sS.......b.!.....jzh.O..2.DU:$.h...L....b.M.i.......w?H-..Kp^I.8..Je:w.....T...H-.mR...q.8Eb....3....>.k)...i..).....b.8...WD...X.W...}.5..{sKW...>..L.&.|E.yk....JUjy.}.i..5R..3.;.\~..M<?.q.%.It...bOI.._.<h$...B..@F.\..10...*q.......R..8?0.@n.......e.?6X(k...(.J.l\+...JbVh....24........D5.P.;...-...D.Q...o$.L.W.~-..F..;..".X...5...V#6|.^...S[...c[.s.....%'U.......^c6.A...p.n_..F..".oJD.R....Q.....'...<.8$.....3..d%....3..C>v.'v.5G.u2.].H.U.....+.C..;q...j..68g......)....1k..<...9.{r.."...|...T;...8F....{.....e....T..D.<..[.Mp.O....JIC.k...6...|..... 4.....y......|....f-........W.....%......K*,..G.......tzr.+!_.*.O.N."...Lu....Vo<...".....@.f$....]..WPD../C..P........!~.e..:7=xF.mh.p.I.}..LG...U8.....`....4"...IhN.=}.j..HDv..^.`.....h...W.E.3..-.....-}.;..?m..A.a-*.r.,...U}f>..<d.x.LcQ.H-.....V..............(-.5.......f...D..EH.w...T.....O..........0....V.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.839612882701785
                                                      Encrypted:false
                                                      SSDEEP:24:bkagBQEQwqYs05HoZkZMlbSzfV4+uO49WQH/vR6E7XrkhkC8bIpZWhN:bkagKEzQIo2AbSjVKO/kC8bIp0hN
                                                      MD5:09864E6B1AE942B56F6CD293A22BF895
                                                      SHA1:0660A7B57B84FA7BAC36E80DED17208B8A6E2361
                                                      SHA-256:31DC1D0203AA80752348E59B8FC9AD849683D593E00C06CEC2AA07CD47904C18
                                                      SHA-512:D6A67F990FB799AF0D8A0AD1EFC79CF4B064B8BC471F9BF21E14EF157053399DF6F5EA1D9EA61EA1784156A8C6D80729D8BA0A9F8F1C1778B05A46AEBF728062
                                                      Malicious:false
                                                      Preview:WANACRY!.....<.Z:....D..f..>.z^w%a+'......a.C.Gk..B).6..$.`.KW.XB..x.....R....)....5OaI.v.{t...@..3hr.jh^.A.d..2%^.......#T)o.U|jE.4..~.._...bdB.pF......c....]..1P.I'.6..(.....|>k..3..u.-.u...e......4.....09..9W.....x^....}.......S.$.}=R}..-z.cG..w5..hU..rp9...............\>..5..........;.Uf.....O....a...k..T......d....N0...K_<..L....W.|...vkIc..#:..+.......Q.T.Eu..k{.....L..2A....~R.x.7.h..a....*}+.Z...k......8..r.y.._...@...J?...}g..y..Rq....:q.F%>l..,#....C..O. <>|..]....PBnIk@s.vIY..Rs+kf.,.<mn@.y....E......h...*1bk....f....]l..d.}.X....L...MF....+%.h.h.m.....0.....[..L6..uV...yR....?....;....z.u....:E.....C.....J..J.....F2.. ..F....!..<"W..M...Z....uUI.3=....R...&<=./O..#.........r.>#.i.. @5..`.w. G*.;..J.%[/.].{...Q`.@1..TkHO#Q.,....~8..lz....b..kBxF...s..>.t..E3..*!q.._....0..o.dt.&....@...Db'.?d.I8..b..v...?.m.....{../.KR...T..|`................"d........27..G7..f97...D.......2[]..K8..3u.....7........R.K.....?y....n.%.&1V..By..`.J..6..{S)L
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.839612882701785
                                                      Encrypted:false
                                                      SSDEEP:24:bkagBQEQwqYs05HoZkZMlbSzfV4+uO49WQH/vR6E7XrkhkC8bIpZWhN:bkagKEzQIo2AbSjVKO/kC8bIp0hN
                                                      MD5:09864E6B1AE942B56F6CD293A22BF895
                                                      SHA1:0660A7B57B84FA7BAC36E80DED17208B8A6E2361
                                                      SHA-256:31DC1D0203AA80752348E59B8FC9AD849683D593E00C06CEC2AA07CD47904C18
                                                      SHA-512:D6A67F990FB799AF0D8A0AD1EFC79CF4B064B8BC471F9BF21E14EF157053399DF6F5EA1D9EA61EA1784156A8C6D80729D8BA0A9F8F1C1778B05A46AEBF728062
                                                      Malicious:false
                                                      Preview:WANACRY!.....<.Z:....D..f..>.z^w%a+'......a.C.Gk..B).6..$.`.KW.XB..x.....R....)....5OaI.v.{t...@..3hr.jh^.A.d..2%^.......#T)o.U|jE.4..~.._...bdB.pF......c....]..1P.I'.6..(.....|>k..3..u.-.u...e......4.....09..9W.....x^....}.......S.$.}=R}..-z.cG..w5..hU..rp9...............\>..5..........;.Uf.....O....a...k..T......d....N0...K_<..L....W.|...vkIc..#:..+.......Q.T.Eu..k{.....L..2A....~R.x.7.h..a....*}+.Z...k......8..r.y.._...@...J?...}g..y..Rq....:q.F%>l..,#....C..O. <>|..]....PBnIk@s.vIY..Rs+kf.,.<mn@.y....E......h...*1bk....f....]l..d.}.X....L...MF....+%.h.h.m.....0.....[..L6..uV...yR....?....;....z.u....:E.....C.....J..J.....F2.. ..F....!..<"W..M...Z....uUI.3=....R...&<=./O..#.........r.>#.i.. @5..`.w. G*.;..J.%[/.].{...Q`.@1..TkHO#Q.,....~8..lz....b..kBxF...s..>.t..E3..*!q.._....0..o.dt.&....@...Db'.?d.I8..b..v...?.m.....{../.KR...T..|`................"d........27..G7..f97...D.......2[]..K8..3u.....7........R.K.....?y....n.%.&1V..By..`.J..6..{S)L
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.816534722076974
                                                      Encrypted:false
                                                      SSDEEP:24:9TYfxWx0QOIkgcpxq6osNKhVKuFTWdncN3qPocG/lxr7B2U:8xWGQOIBV6osEhV/wcN3qPoRN2U
                                                      MD5:47A5508E88EC5C593C55BF67657319ED
                                                      SHA1:8F12EE9B9CBF16BF045019C0F5DD7A1E24F33781
                                                      SHA-256:BDC985A32278CB9D0359A6439D80694571D79B1F9E20C846B1276FCF228C8A87
                                                      SHA-512:0D896E3A60E36F21BF549FDE680FF20F68E1BBA80F7E2BAAEC5F5F5D2A1A8A0F73DE79AA10BAAB209D95A05CCDB04B681B1DF1C598B73C015E50687237D813BF
                                                      Malicious:false
                                                      Preview:&..zI.b.>o...2..p..~.T......gg.. .......%\.{.Z*=......4.....!..._{.(.....q..{'...>l..34.a.........CX_...y.,\.~.Q.!......8.s..7Z..'.....Q.C...I..0.=..AK.Y9.m.i.>.@..f...!..u'.2...s.vm....\.N.8.Y..3.."..JHGF...t^...`0U....|.Co.L^.U.{....N..........G../.TM.d.e..../]..=......r...D.aE..Rh,.!4.....f>.....Fh(,.9.<r..!..O.T...TI.jDi.+.'.ENH...\......sY%.[.,.........)fY..X8..bQ..dG0G7%..........<6Jv...s.QgG..S.B...U8.&:..s].....5.`@.m.]u.b........Z.!..%.qk7.}..`iM.....Y....x0k..7....=.+(..,v.w,5..].q.3.....|..h:N%"...U........V.2&..%i..xj..~.... ...\..t......p.SgE.m%.....CZ..;H.1.Q@6*2.|.~.f.>Z.Qc.3..1...H-.'E.}..._4.(~p...V...K...........6.F.[>.5b..j...o.......M|.......aN.....J.p.Z.....Y.......W......I.....Q..."fq...D.g....HPyy....yq;........YE./.f"..e.O...7M..Wa-.& ..8.b..G.*N.qW..[..J.-a.|:}|P....N....O......{Y.{v../....].f...U...&tr..f...[.Fp.."!n.<&O.E.P.WK-gn...NG...+]..5.v_..w...)am...)0...j.w....._.9..-.....Y$u.+..-.Tu.....q....ja"B..h.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.847418409808785
                                                      Encrypted:false
                                                      SSDEEP:24:bkxHcIcJhdTkOhLJ/EK3DVDk+pDi/d9aPJU0C5CcApAa:bkVcjdTkOhLJ/EKgaRe5jApAa
                                                      MD5:FE9DD68B8BE811205DA24FDCEDDA5C5F
                                                      SHA1:AA1ABB3EADF1A519177AF0278FC41FE59B16D854
                                                      SHA-256:74A08173AC6527282830D04189E36089E68BAB79C72BCFD6B75954168784395F
                                                      SHA-512:5A9ACE0DE7DEAAC8DDAD396AC02A9E1D8E2874A94419F816C4C5F8DD477556A08D054552D4072CCDE5D27B849AFC3E89A972521B2E0DD1BFE31DC0F51FBBAE1F
                                                      Malicious:false
                                                      Preview:WANACRY!.....s..3....kq....N.....>5.qo.EVUb..+...B...DV..C...Fx..........5%.7.4o.{>.Y......;y.Z@]..V...$..r.;,.?......c...C.<.y.kS......70..H...#..H...xK.s....z...:..~z^.*r6.....xB...y....p.a.g.G ...-....X.\....9.K...... v......r..`x._.A~..y.....h.G1.:w..y...................yC.dy.A..C....V{<.........J,.+1..h...............(*....L_...qIC...`V..>.0.....n.PAc....Pe&...{1..O15...^.......Q>.}...$.!.<.6...{.e.d{..%........}.*.....n~.......0@..]..TdXipY...#vG...Xy2)I...t.L..B0...A.Y...M...)5..R..4.i,k......P.J.].....b>.i...........'..#..q.8..uJ...RGPu.........o..A....pVNN'L.F#...v=....M..B..2d.h.[......J.q..0.2....d..Zb."...__.K1xj..p.X.m....I.^..1..a....3*>....ggui.j.....N....\.c.i.S5.,.l...z8....UR....6~.L..=......I^.t.j.........n;.......x...A...6H_U..'.Y_..Oq..BB.8......F}.-...b.+a.9..).,.ad..gP.v..i..R./......f:..Dp..,A....f...{....^M..+\#5+I...>..sNo|../...q..r.F..f.......h(I.}..0U...7.B.f.c...9|.X.........S.M.........J....;t......./...x....,
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.847418409808785
                                                      Encrypted:false
                                                      SSDEEP:24:bkxHcIcJhdTkOhLJ/EK3DVDk+pDi/d9aPJU0C5CcApAa:bkVcjdTkOhLJ/EKgaRe5jApAa
                                                      MD5:FE9DD68B8BE811205DA24FDCEDDA5C5F
                                                      SHA1:AA1ABB3EADF1A519177AF0278FC41FE59B16D854
                                                      SHA-256:74A08173AC6527282830D04189E36089E68BAB79C72BCFD6B75954168784395F
                                                      SHA-512:5A9ACE0DE7DEAAC8DDAD396AC02A9E1D8E2874A94419F816C4C5F8DD477556A08D054552D4072CCDE5D27B849AFC3E89A972521B2E0DD1BFE31DC0F51FBBAE1F
                                                      Malicious:false
                                                      Preview:WANACRY!.....s..3....kq....N.....>5.qo.EVUb..+...B...DV..C...Fx..........5%.7.4o.{>.Y......;y.Z@]..V...$..r.;,.?......c...C.<.y.kS......70..H...#..H...xK.s....z...:..~z^.*r6.....xB...y....p.a.g.G ...-....X.\....9.K...... v......r..`x._.A~..y.....h.G1.:w..y...................yC.dy.A..C....V{<.........J,.+1..h...............(*....L_...qIC...`V..>.0.....n.PAc....Pe&...{1..O15...^.......Q>.}...$.!.<.6...{.e.d{..%........}.*.....n~.......0@..]..TdXipY...#vG...Xy2)I...t.L..B0...A.Y...M...)5..R..4.i,k......P.J.].....b>.i...........'..#..q.8..uJ...RGPu.........o..A....pVNN'L.F#...v=....M..B..2d.h.[......J.q..0.2....d..Zb."...__.K1xj..p.X.m....I.^..1..a....3*>....ggui.j.....N....\.c.i.S5.,.l...z8....UR....6~.L..=......I^.t.j.........n;.......x...A...6H_U..'.Y_..Oq..BB.8......F}.-...b.+a.9..).,.ad..gP.v..i..R./......f:..Dp..,A....f...{....^M..+\#5+I...>..sNo|../...q..r.F..f.......h(I.}..0U...7.B.f.c...9|.X.........S.M.........J....;t......./...x....,
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.8365131871839315
                                                      Encrypted:false
                                                      SSDEEP:24:8ckMXJjQpCCyKX7X1Ezr/KAOw6ifA2uWXG23NQX3VaHdq:hTwzu/KAoifAWZdcx
                                                      MD5:0C7CDFBE0B58755131CA56D87C01C639
                                                      SHA1:FE640726F4A1E0C2E38A816CCED39CF2D4D4C80D
                                                      SHA-256:C561F0FF0B0C0E66827A397345C8361AC1E85C29389E288CEB24BD56008050AF
                                                      SHA-512:8D0EE4E8734D7FFDFAED3E889B965DE6F8FA485FD4833D7E6840633CE7D2AC5D4FEA793478C0A34A1E0F65F7F367A2EE464CC931C6BE28EAFDEBD95F67CE43D2
                                                      Malicious:false
                                                      Preview:}O..'n.:...^.Z!...d.?.wG..a...=..f*u..'.a....N....suE...u)ReJ..+...]q........E$.s..0.B.....=..Y..5..U....P.=L.S..^&.~....._..(....+Ka<.k..(.J..bH:w...<J.6......./.X6.>..E02F.%...K.....E.`..z..+...K.........E.]...j...k.&.....J.1...v.m.N.a..o.N.f..IT..$o.$)..JD.%..%...W.........z..rK..T..z...'c...BC..G....H....Cz.^..]|..M.........O.`.0=9Y.-T..lo..........g-.:;$.;...h..y_..2.e;. .>...h....e;..P..o...E=...,%..tN......-.IiF....S.e..H..B.]..)m.o...b.7.!|...g.`.?...M.|.Q.o.].YI......f.,k.....k':....?..IN...}.)..#......K......s..nVy.....3.....d..q..G..ys.6....wj)...4..)..A.../..<......I...x.WW{..G:.I...........@J.A...&.).....C..b...C/.....2.t._...........W.`..Q.hNf....0.."......R.O]..WucN...>.}....0......@.rd.^......DR.(.t.t\'h...V..c..C.G.D{..#n..V..cl..R.V.2.7*[e..h..A....VP.D.B5.....B9~.....joN..C.D\...RX.L......M3^.%..\p.. ..m....1.V.}zp?L..R.*....Ie.8o.."O... &5...,.V..hH....&.oS....!VL.q.%..L`...^s.L.:s.....0h.o'...$.Q.9...9]R.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.837875768774002
                                                      Encrypted:false
                                                      SSDEEP:24:bkkAd5piVs8PBGk+dbgeR97SSmtbG0SxfILqYjfb+9XixjgPnF26+oJq:bkDTpi3Pokwcomb1SxfGb6WE/F26+x
                                                      MD5:9371F84750BC53DDF9A09886E0016AD5
                                                      SHA1:D0CD8492BF6F0F3E9932F96CB614C0C0727E708E
                                                      SHA-256:898B6E3442217A8EA0FB40E2CE0D3E124DD61ED9CF0B9647ED4885CFD62D7D82
                                                      SHA-512:3AB5BDA4C37323C1EB1631AAC71F16F1911B34F1C416450F667E5532DB54E0F6AB549EC45D8813373449CC67160BB828CFDC00E942A93D9AC4B85604111A49AB
                                                      Malicious:false
                                                      Preview:WANACRY!....5:..dgO.!....&.{6..a.h(........Z....2.@.Z..dZa...dd....)cr.q...>O......{..*9.<.&.....(whHO./es...tGpt@.+........M.OEM[..`].TSh$..-.{o.\...{../......'....$... :.i5S..,../i...P+&P.d..a}EF..;d..P...B/.]>.p.......u.)...M....)...6.@..N.'.`d2.H.9................>.....,j..W.}...i.}.r.-$..*96[..O9.......-8.cZ....GNy<....r...Io.v.@!)zT.g-2u$jrh. ....iG..{.......Q...^.)5G]H/K........x.c..XX`....h_...0>.S....Z\...{.....-..1...V.;..'2..k.oF3..)}''#...G..Ym.\.n..O..XC....{.2P}..0mgoW...m.......7...>Z....(.A+.c..d.. D6c......epXyK..X.2......'+.[.....X'G;......%..-.^.w.|........-Svu...N...Jx2....fL;..s.{..2j.!3.LBI.......1.... ........w..1..M.O..kT{..v..&..#.}0..'.?D.m6..-....>.|7.Dr@....M.,.....>..~.M..Gb.azR........Z...J.;...Lr...]..gX...6.X.]....}3..A.xP?...N..`Vx)...pn.Z..?..0....|Dg...kt..&..f47R.k[&a.....lV........E%....Wv.......1W.Y...CS..{6.....rCFT....;Y ..o...Z..-&.^.......Z......Dq..[..%I..OZd..._...U...6..G.w..6.#j......|...
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.837875768774002
                                                      Encrypted:false
                                                      SSDEEP:24:bkkAd5piVs8PBGk+dbgeR97SSmtbG0SxfILqYjfb+9XixjgPnF26+oJq:bkDTpi3Pokwcomb1SxfGb6WE/F26+x
                                                      MD5:9371F84750BC53DDF9A09886E0016AD5
                                                      SHA1:D0CD8492BF6F0F3E9932F96CB614C0C0727E708E
                                                      SHA-256:898B6E3442217A8EA0FB40E2CE0D3E124DD61ED9CF0B9647ED4885CFD62D7D82
                                                      SHA-512:3AB5BDA4C37323C1EB1631AAC71F16F1911B34F1C416450F667E5532DB54E0F6AB549EC45D8813373449CC67160BB828CFDC00E942A93D9AC4B85604111A49AB
                                                      Malicious:false
                                                      Preview:WANACRY!....5:..dgO.!....&.{6..a.h(........Z....2.@.Z..dZa...dd....)cr.q...>O......{..*9.<.&.....(whHO./es...tGpt@.+........M.OEM[..`].TSh$..-.{o.\...{../......'....$... :.i5S..,../i...P+&P.d..a}EF..;d..P...B/.]>.p.......u.)...M....)...6.@..N.'.`d2.H.9................>.....,j..W.}...i.}.r.-$..*96[..O9.......-8.cZ....GNy<....r...Io.v.@!)zT.g-2u$jrh. ....iG..{.......Q...^.)5G]H/K........x.c..XX`....h_...0>.S....Z\...{.....-..1...V.;..'2..k.oF3..)}''#...G..Ym.\.n..O..XC....{.2P}..0mgoW...m.......7...>Z....(.A+.c..d.. D6c......epXyK..X.2......'+.[.....X'G;......%..-.^.w.|........-Svu...N...Jx2....fL;..s.{..2j.!3.LBI.......1.... ........w..1..M.O..kT{..v..&..#.}0..'.?D.m6..-....>.|7.Dr@....M.,.....>..~.M..Gb.azR........Z...J.;...Lr...]..gX...6.X.]....}3..A.xP?...N..`Vx)...pn.Z..?..0....|Dg...kt..&..f47R.k[&a.....lV........E%....Wv.......1W.Y...CS..{6.....rCFT....;Y ..o...Z..-&.^.......Z......Dq..[..%I..OZd..._...U...6..G.w..6.#j......|...
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.819023204267254
                                                      Encrypted:false
                                                      SSDEEP:24:F+jRSnoY3OODOX4kqGq841GyZyj98bsfRocPlcM/gedsSc+P:FBnTeyOXd2xZyBysfRoujgGsSx
                                                      MD5:7B0169B46F572F366CEE198AC4B3E10F
                                                      SHA1:8D1881C7DB8C6D342625FCE3FE67C81AF339A640
                                                      SHA-256:DD380DCF0168DFAA64191707F5E03CFD7649C680B1E532CD42B307AD175973C0
                                                      SHA-512:38AC7C6447D8DADDB37D7248E74C439D711DB3FF5A2EE1D98AE3A1B89099C3713DBB1ADF88A57A5223F2E7A8B022960388059EF5DD2D138E8622C1939497DD4F
                                                      Malicious:false
                                                      Preview:. .JK......G.{...H2............;..a...T..@4t..g.....B.e.x..].7.i..w...N..l.b.f..P.C......`I..z.K'C.]..0...G)......wf...s.Zz.>..:..n.cP]p.M.Jex....g...8.t.7[.M*6*.p.K-......o.4:..*.d..'..J.9.D...D....he.$.I..m..s3.!....t.../s)gX.Q3...V!.@>.].+.....7.}9.U.....T'x..U..0.|..c..sm....S.\...R..N..q.P....u.;p.X.V..$Z..... .7.......[pt....'.].<....V..Z.CV.e)......tqO7.g\.....X?^..^S^Z.....E....G..`......W..+.8.T....z....S....s....t...@H.c4.)^aN.'.v.v0w8.Q......a....@.....[.;...9h....m..txQ..D......<..b..4)....D*............6.s).~uk*.[.f.F%....U.......d.:.B......g.,.T+.;...cw]5q.'z.....T. ....G.....X;....@...O.f...C.d..y.......u&w5...xQP...`A.......7.....X.R..-....~x...d..u"..Hf.b-..!..?....U......;'.....2r.e4?..;..*7*....(Z5..LB.....`$T..=....4Z"....N..l]K!R.d6......BP..T4.o..<.....~.a..v.......X/.......G{.l......l...vM.3.Y..]....O._/y.H.....y.f#..8..{p.VmW..Z?"Y....0ny......k....p.....r5...l.?..T..^.}@...G...8....CP..-....r0.,N."..
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.843194413288236
                                                      Encrypted:false
                                                      SSDEEP:24:bkRSHaWVy+xZqn5t2/+kkxaMNUSQTNrTu7QEIhvpasgGzQ1WxjJKubzodyl:bkRWHHqn5t2/+P/+NpBasg+CYjDMd2
                                                      MD5:CC274207DCBE3E34C5528FD01F1065E4
                                                      SHA1:712836C28A15A322C3869922CE71A9FBFD9AB4E0
                                                      SHA-256:B5CAE2CC9E8EDFC3487553AC155853F66E03FCEA4279B4A4F2624728EEA98B7E
                                                      SHA-512:D2C22F9EB2001D0953C9456CC13512812FA1C2FEE2349C5E8DA14A316A0668D79A20A5EF677DEA011435F742F02CAE22FBECE1637963E9EA40DCA84BB8429F32
                                                      Malicious:false
                                                      Preview:WANACRY!....l.:Y..b.*.X.......:.T.$k...L....]Z.Pw....#/...Qx...5......u...^hNE.%A2..h^......N2.r.|.S.y..fN......q..?v......'.l<....V.G...n.k.L..8].}.C...w.K.....C...G..{.*.v.Y\.._._W. .q.}].....\L2..&..V.e..{.Q..'.".\..>G..@..|#..>7.B+H*~S..Gp....ZZ>..............^...1......o+.H.uR..'...up6clF...p..m}..C....}..T_S...s....#[.5.k.x.6..0O........O. .....%.~.(....,.w..VZ..GW.M.J14JD.~.}..]771ukll.9.u..Z.k.^1.*.V.).U.&.P.Bpl....up..kt.a+a.-....A.|JfW.H.....c?.6.^(?j7.!...|2j..P.:J8d..0.$2d...{...=.P6.......T{...?8....B6.9..h..-~N.l{.7..N..k.+.....Ig......!.jH...:...|.B.g...=^..._.;.N.:..Z*(Yx.,...g..b..]I..s....:Q?s2.+..~..7 .x...../.C.U...2..{..OMm.4..[...a..1..,(n...IV.....b...W.=D&.V....f.+K@s:...;....J.......... ..:.....E........YP8}.F{.&.:{....|...&..9....^-c..p;..%.>..B.......bT..W...j. ..N.....g.....O....c..4u....ps.(P(X......y".-...u..~...?..5}...l.c.w..........c.Vy.I.O=t.Vc.....!.....M...<....4.2..zONi.J,q.o;....5...3..a.....
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.843194413288236
                                                      Encrypted:false
                                                      SSDEEP:24:bkRSHaWVy+xZqn5t2/+kkxaMNUSQTNrTu7QEIhvpasgGzQ1WxjJKubzodyl:bkRWHHqn5t2/+P/+NpBasg+CYjDMd2
                                                      MD5:CC274207DCBE3E34C5528FD01F1065E4
                                                      SHA1:712836C28A15A322C3869922CE71A9FBFD9AB4E0
                                                      SHA-256:B5CAE2CC9E8EDFC3487553AC155853F66E03FCEA4279B4A4F2624728EEA98B7E
                                                      SHA-512:D2C22F9EB2001D0953C9456CC13512812FA1C2FEE2349C5E8DA14A316A0668D79A20A5EF677DEA011435F742F02CAE22FBECE1637963E9EA40DCA84BB8429F32
                                                      Malicious:false
                                                      Preview:WANACRY!....l.:Y..b.*.X.......:.T.$k...L....]Z.Pw....#/...Qx...5......u...^hNE.%A2..h^......N2.r.|.S.y..fN......q..?v......'.l<....V.G...n.k.L..8].}.C...w.K.....C...G..{.*.v.Y\.._._W. .q.}].....\L2..&..V.e..{.Q..'.".\..>G..@..|#..>7.B+H*~S..Gp....ZZ>..............^...1......o+.H.uR..'...up6clF...p..m}..C....}..T_S...s....#[.5.k.x.6..0O........O. .....%.~.(....,.w..VZ..GW.M.J14JD.~.}..]771ukll.9.u..Z.k.^1.*.V.).U.&.P.Bpl....up..kt.a+a.-....A.|JfW.H.....c?.6.^(?j7.!...|2j..P.:J8d..0.$2d...{...=.P6.......T{...?8....B6.9..h..-~N.l{.7..N..k.+.....Ig......!.jH...:...|.B.g...=^..._.;.N.:..Z*(Yx.,...g..b..]I..s....:Q?s2.+..~..7 .x...../.C.U...2..{..OMm.4..[...a..1..,(n...IV.....b...W.=D&.V....f.+K@s:...;....J.......... ..:.....E........YP8}.F{.&.:{....|...&..9....^-c..p;..%.>..B.......bT..W...j. ..N.....g.....O....c..4u....ps.(P(X......y".-...u..~...?..5}...l.c.w..........c.Vy.I.O=t.Vc.....!.....M...<....4.2..zONi.J,q.o;....5...3..a.....
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:ASCII text, with CRLF line terminators
                                                      Category:dropped
                                                      Size (bytes):933
                                                      Entropy (8bit):4.710902136409594
                                                      Encrypted:false
                                                      SSDEEP:24:ptrPzDVR5Gi3OzGm0EigS1xbnS4RQhbrW8PNAi0eEprY+Ai75wRZcet:DZD36W3ChvWmMo+S
                                                      MD5:7E6B6DA7C61FCB66F3F30166871DEF5B
                                                      SHA1:00F699CF9BBC0308F6E101283ECA15A7C566D4F9
                                                      SHA-256:4A25D98C121BB3BD5B54E0B6A5348F7B09966BFFEEC30776E5A731813F05D49E
                                                      SHA-512:E5A56137F325904E0C7DE1D0DF38745F733652214F0CDB6EF173FA0743A334F95BED274DF79469E270C9208E6BDC2E6251EF0CDD81AF20FA1897929663E2C7D3
                                                      Malicious:false
                                                      Preview:Q: What's wrong with my files?....A: Ooops, your important files are encrypted. It means you will not be able to access them anymore until they are decrypted... If you follow our instructions, we guarantee that you can decrypt all your files quickly and safely!.. Let's start decrypting!....Q: What do I do?....A: First, you need to pay service fees for the decryption... Please send $300 worth of bitcoin to this bitcoin address: 13AM4VW2dhxYgXeQepoHkHSQuy6NgaEb94.... Next, please find an application file named "@WanaDecryptor@.exe". It is the decrypt software... Run and follow the instructions! (You may need to disable your antivirus for a while.).. ..Q: How can I trust?....A: Don't worry about decryption... We will decrypt your files surely because nobody will trust us if we cheat users... ....* If you need our assistance, send a message by clicking <Contact Us> on the decryptor window....
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.809289330857566
                                                      Encrypted:false
                                                      SSDEEP:24:rXgl3AYmrOO4ityVJIWnsbNC8munkib/NhXNTrOH:Elje3caYs0mHXNU
                                                      MD5:8E54FECF35FD5BFEAED951AC5D86C02B
                                                      SHA1:B22E4568687D004891FACA6692C134073ED419C7
                                                      SHA-256:F59FDF7276EC4F2CE4403F1542B8409898076BF9F27E7B2810B239E9CDD8B3B3
                                                      SHA-512:C7F8D29FF73775EBEB906AB6B1060ED6D9FCA6672C1D7344D2AF8F90A27BA31D06AC38AE319F86E05E2786D7B49977F1A6722F9DB6A56C8219C19EBCC455D0A7
                                                      Malicious:false
                                                      Preview:..bq...%a*......h......W...!A....:.]....,.J8.#.Z.. .h[...&..y...t.+`!xjj.......n.'<38.v-.5.`97c.S.^.`j@Z...<......-........]as.Eyi...L^RTYd*...0j.F7..0........O..}....s.=..+0.....?....E.*.b&..Xc......jy..^'.....Il..M....y..s.f;...!.....b.<.Ow.w.^!.........-rE......2%Z...7.....w.I..@..v...S..D..,.9....].[... .q./F...V.....U!.Z.pg"....+`c.V.o`.2X.lBV.a.u3.2j......y..x..9..U.j.I\Q.....#..Y?|..5..#/...\...'4.n4........g~.....~..>r..Tv....#.sM...G.....0p"]kkLT<....h..>..*..@Wj*.".@y..<....(C....I..j...D.....~.7.d.CeL..l.V..i........V..H./.*.B..s0..z...vrg*n..).j|....7....d..#..h 9N..f.........."..q@...i.....x.s.8..~.D.....rO..T....~....P..+^..(q.X#n..V..g^:....)$.$..wQ..n...{....C...k.0.R_.M...N.{UB...b...#S.MQ...*.5%.....l...58l?..}.L.....;.Vb;.j].$...|b..5!....4...h|.r.u..?R.....6......in..../p........r.Cp..y..09..p4.LRaDI...0.!.LB(....o...mibP....{n.o....S.(nJ.F.:......W...=P-.0a.....t.s..\.....B...{..h...N.UD.R..(...'T.....^h...y.<.ab.CB..
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.833496475334634
                                                      Encrypted:false
                                                      SSDEEP:24:bkRW5pwgLOqaPkbRVV3+EywhUgSw35pGWlWy81KbGY7baZkxgTWcEmXe+sX:bkRWLssbR73+ExhFpSWlc2CZkxgTWcub
                                                      MD5:C1D1028C93445296CC0F9D6877138CB3
                                                      SHA1:39629CCA6CD1F19068D96A43E06BB5714EA82E83
                                                      SHA-256:FEB2ED75D1B4178ADB55399D8982BCFCFF9B6B31255D5C281683C1B11A6550D1
                                                      SHA-512:3B4D597B1071D8F62FA61AF1021D89791717BFEFD372A49F5C4D0258627252B7EBA4F5EB13A584F2D7C7F6F10F870EBB3CCFEFE892FBA4B2CF496263430B6A4A
                                                      Malicious:false
                                                      Preview:WANACRY!..../..w[..Ud.uk&.(.Kn.....`....G....r..).?...\.sG>-..../"..39..#.jm....,.lu.....n.G...yY....e...`........bm...&9...i..+...{c..R....~q.|......kO.>.h.n1._laH.X....5.R;..NM..O..dR.I.zc.A?;..C...1.......k(.k.7.O......(........D.}..x....i.8?..[A....dT9b.............X".$P.:AT............Q.5..Z.5.SE?.x...d@C....G...*^998..~..d..8}"......)..sQ.3E.....,.!g..r=...Z.Lu.>x.T...f....g5.I-..M..h......].<....>.#.X..+..1aB..(....}.JKK5w....I..n\.G..$.N..=..M..j..0...4N,....N0.lu&....{.w.B.v......+....z..v>l&....._X.t.U`....|...[3.=..s..NS.<.'.|.-.....j%...%...;../.Vb.I.:o.:.?...w^9..+..b[.....5......)..^3o4ZO.Wco..{.K..Q.q.2.J9F.-?.......... ........b:].W......h.Q.%!m.\...;.U..\....._..y9....=n.U...<.|....7....H0`37*..5....r.b.u.....EJ|...+..@........ wW.....7.c..B...R.w4@m#..._...5...9cL.)'.NGT(4..|vTf..O.R.x|\.E..|.W.08..t.E5....H....-.....J..\.H.{...MPg...1.N1-..a=...;DG..M..,..~.:H..$E..bu...&...|..Z.G3T..4s..Q5y6..a.d&F...0.[;n.H5..wVkP.....)&...
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.833496475334634
                                                      Encrypted:false
                                                      SSDEEP:24:bkRW5pwgLOqaPkbRVV3+EywhUgSw35pGWlWy81KbGY7baZkxgTWcEmXe+sX:bkRWLssbR73+ExhFpSWlc2CZkxgTWcub
                                                      MD5:C1D1028C93445296CC0F9D6877138CB3
                                                      SHA1:39629CCA6CD1F19068D96A43E06BB5714EA82E83
                                                      SHA-256:FEB2ED75D1B4178ADB55399D8982BCFCFF9B6B31255D5C281683C1B11A6550D1
                                                      SHA-512:3B4D597B1071D8F62FA61AF1021D89791717BFEFD372A49F5C4D0258627252B7EBA4F5EB13A584F2D7C7F6F10F870EBB3CCFEFE892FBA4B2CF496263430B6A4A
                                                      Malicious:false
                                                      Preview:WANACRY!..../..w[..Ud.uk&.(.Kn.....`....G....r..).?...\.sG>-..../"..39..#.jm....,.lu.....n.G...yY....e...`........bm...&9...i..+...{c..R....~q.|......kO.>.h.n1._laH.X....5.R;..NM..O..dR.I.zc.A?;..C...1.......k(.k.7.O......(........D.}..x....i.8?..[A....dT9b.............X".$P.:AT............Q.5..Z.5.SE?.x...d@C....G...*^998..~..d..8}"......)..sQ.3E.....,.!g..r=...Z.Lu.>x.T...f....g5.I-..M..h......].<....>.#.X..+..1aB..(....}.JKK5w....I..n\.G..$.N..=..M..j..0...4N,....N0.lu&....{.w.B.v......+....z..v>l&....._X.t.U`....|...[3.=..s..NS.<.'.|.-.....j%...%...;../.Vb.I.:o.:.?...w^9..+..b[.....5......)..^3o4ZO.Wco..{.K..Q.q.2.J9F.-?.......... ........b:].W......h.Q.%!m.\...;.U..\....._..y9....=n.U...<.|....7....H0`37*..5....r.b.u.....EJ|...+..@........ wW.....7.c..B...R.w4@m#..._...5...9cL.)'.NGT(4..|vTf..O.R.x|\.E..|.W.08..t.E5....H....-.....J..\.H.{...MPg...1.N1-..a=...;DG..M..,..~.:H..$E..bu...&...|..Z.G3T..4s..Q5y6..a.d&F...0.[;n.H5..wVkP.....)&...
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.820270167079531
                                                      Encrypted:false
                                                      SSDEEP:24:UZI5HSiSHvpUi5kTNyz12VrH2UQsBXUHvTR:SuyfuQkTNggVrUUXUPTR
                                                      MD5:A80BD758E5B19F4F272BC49941F064EF
                                                      SHA1:588D894A68AEF130ECCD8E2AEEAC9C46623689C0
                                                      SHA-256:AF4B7F5CAB8048A8FC7AC287D97FA84B74F87E79E92E13E6A2F9E434824061B5
                                                      SHA-512:15731C1A71D07529527D68935FD264D5F8FC57FEFC5C5384DEC475D33D02AA051223CFB9DA62B57DA9154CB347DA5C6F4BBDF788D2A44A07CDEF1197A4C17E5A
                                                      Malicious:false
                                                      Preview:1v.s...4.j....Ri..~..l.o.wz......,.@.H..........Q>./._y...?...@...o.AV.w...M..of.4.w.......:.?..U..|.......3U%...B.A.J...=..L..;S.(k,.H..dZ.5..VT...V....%......SXz.W)...N...$.6>9.DS<.p.....)...(.,.D.8:...gj.Gs..)1B ...z.x....n(..e.mv.L.....-..X7Y.u..-..:.\w.Mk..%..O.Z..5...b.i6....f..jkFC....cZ'uS@,..f.g.&...zV#.Q|G_...nuoa.M........2...o.Bj.1~of..,.1j...Z.WK*.o.a.^......D...%Na..9....O.%.u...XT..>L?..Mv...._..^.N......+.F:`.)]...GR.rV1Q9.....I..N.__.(.....Xc./`.0.S?,..2R...,.D...5.U.v;{...6...x......y1...a...n#..........I.3U.kv.r\.i.....?[G.x..k...Ke.NoY.....b7\@..IU.NV.%....Q.T....o..@.......$...~.hkDF.....P.....6....:P%r..t..t.$...I.......?.......`nx...."....8...R3....x/H0+..; 8c.A..)....e5..-....H.8.[K`Nk ..g....1..e.#N..#.3......6\^#O.2.o....G.B.m...Cb..1.f~WE..b.q......_...-<..iUw..L..8...T....L...).U.c.UFM.+.%....].dv...G_..9s..".....\...d>.u.XI...Q..(.G+G0......?..%...}....s.1.eF?.[U.......p..<..l6.e...Rt....T..t.@.(..5.3.. G..{....
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.831386707891555
                                                      Encrypted:false
                                                      SSDEEP:24:bkhAvRMWCh1uSb2Lks0xx7o350x75jyCNODWorrTvatuUcpv9pUx4nQa:bkyvEDuSSks0xx7o3OXykODWoP7atHAh
                                                      MD5:60669840B37D5675EDD85A176B7FCBDB
                                                      SHA1:6E226C8BDF87FFBCE2190779415D2F97D500CD88
                                                      SHA-256:BFAA8C0A980BE0808AD5A96A398C6D1D806711C275F48C053B0DED0F10E7289E
                                                      SHA-512:BD6C651E227A3252C15CEA355B60D0EFCDD14C86EE6769A63218E1E10CD6D7EA1A8230F5E7C00D3B4711C41F589D68CB3FE578E03E73604F34E500F651C965DE
                                                      Malicious:false
                                                      Preview:WANACRY!.......(.,......'0~r....b..{D..-....#.9`:.*...........F..q..J....o....SyU.GJ&w..Z......Esk.f>...........F.=.I...N..k. ..`.1.^`.v.1....I'...Fz.U:}.\..O..z........ ..}..vU.a..*.K32.k.{...\lb. XD.r/....(.....w..<.;...a.U-.;.^.k.!.t~.?=......z...J....T..............#........@....9..........%}0..A.(...be.Z@....!..lv.1....C.m.k...*\...h.1......N...n.6...J.drG.e..Hj...nu ,.%._...h...X.Vj...5%...l...b.....1#.....p...B............t..T.DH..MDd."q.'.w.c...zT.].*.g(.B....3..N!.KS ....x...]........9...V...y...Q...d}...}...|o.1..(.%.".1./...5p..c..h.h]..a.&...xF..1~W..I ..+`.'p;.b...X...:R.[=...m.?.[.V.6Z..tf. _....?..k(v.$Bf'._.$F../l7..JtD<K..D^d..Md...T.......ZB..WC.g...;...kAfV...C....GS..S..z3...iOZ......:..]..].o..0.>....F......................(..m....)..|..aAV;t..d......|B...m.].5. .L.xq.B.t......hAm.....Q}]?.#.74..vT...XFK.....1}e;]E@......W.q=..T.7w..?.....rT..^.z....V....%"/...[..sud.FO.....G.....(.1805..G.*..`Y.q....C....,....~H..
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.831386707891555
                                                      Encrypted:false
                                                      SSDEEP:24:bkhAvRMWCh1uSb2Lks0xx7o350x75jyCNODWorrTvatuUcpv9pUx4nQa:bkyvEDuSSks0xx7o3OXykODWoP7atHAh
                                                      MD5:60669840B37D5675EDD85A176B7FCBDB
                                                      SHA1:6E226C8BDF87FFBCE2190779415D2F97D500CD88
                                                      SHA-256:BFAA8C0A980BE0808AD5A96A398C6D1D806711C275F48C053B0DED0F10E7289E
                                                      SHA-512:BD6C651E227A3252C15CEA355B60D0EFCDD14C86EE6769A63218E1E10CD6D7EA1A8230F5E7C00D3B4711C41F589D68CB3FE578E03E73604F34E500F651C965DE
                                                      Malicious:false
                                                      Preview:WANACRY!.......(.,......'0~r....b..{D..-....#.9`:.*...........F..q..J....o....SyU.GJ&w..Z......Esk.f>...........F.=.I...N..k. ..`.1.^`.v.1....I'...Fz.U:}.\..O..z........ ..}..vU.a..*.K32.k.{...\lb. XD.r/....(.....w..<.;...a.U-.;.^.k.!.t~.?=......z...J....T..............#........@....9..........%}0..A.(...be.Z@....!..lv.1....C.m.k...*\...h.1......N...n.6...J.drG.e..Hj...nu ,.%._...h...X.Vj...5%...l...b.....1#.....p...B............t..T.DH..MDd."q.'.w.c...zT.].*.g(.B....3..N!.KS ....x...]........9...V...y...Q...d}...}...|o.1..(.%.".1./...5p..c..h.h]..a.&...xF..1~W..I ..+`.'p;.b...X...:R.[=...m.?.[.V.6Z..tf. _....?..k(v.$Bf'._.$F../l7..JtD<K..D^d..Md...T.......ZB..WC.g...;...kAfV...C....GS..S..z3...iOZ......:..]..].o..0.>....F......................(..m....)..|..aAV;t..d......|B...m.].5. .L.xq.B.t......hAm.....Q}]?.#.74..vT...XFK.....1}e;]E@......W.q=..T.7w..?.....rT..^.z....V....%"/...[..sud.FO.....G.....(.1805..G.*..`Y.q....C....,....~H..
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.802296508734037
                                                      Encrypted:false
                                                      SSDEEP:24:vAlRaUpO9ra6f9r1IsVElLIlrN0xdvnqyFykRRRDb3MDjjI53:vAEBa6f9r1tCarNC9qoRRH8fjS
                                                      MD5:73B6D1CB9B4247DB175B4291C3E5F3B1
                                                      SHA1:16EDFC511D6AC884CDBA0064AD78D644083B39A6
                                                      SHA-256:8273D61C7D5269E331B5528B99C6D0DF05E3B2B942C92AC42CB341038DC47067
                                                      SHA-512:50414E45EE579226AA4B8715A4435DF97DA6FFEB1142CA08309AA303866933E83662FD09A9FF15FDF57083E4A2F478E60A8333CA5BD766B9CAB005D5DEDF5E46
                                                      Malicious:false
                                                      Preview:.`$.'.9m....?.u+.-.._.6....:.[.I.N%..g.mf..,...\0.iv~..1...&2q.;{!.w....B\r,.$].g..2..&.s..^.....b.....BR.'6h.."!..8pK?......9k(N6..:y.0.L.s.....hu.%Zq[\..S..bv...U...f.....qqP&.I.$z..(.f}...H]......yQ.x0..F..P.:IL...l...g...n.KI;Bc...-.)".%._....D.*.n.......Q+q..k.(.a....n.E....t......m..P..#DKO.y.UP={`M.).j........nM...`..f......n.A..Q.[t...1!..........i.)./!.&.PV.^r;.u.$/.+.+.)..0.......:y...M....7.$.L..Ne...cn{.......;...C.".......4Ba._.2=c..+..(.%.... %.1_O.p....R"...c..c._..b..kBC..^p....1....fF.P.2*..]1.D.O:y.......C@.4a7..[d...F.+Q...P..0.U.s.f%(.8a...l...s|.L.Z.|]..K..Y^.....t,.. A&d..u.#...4qdX../2..a.M..,....(.q x..W..y,..}.F.....{-.i..v1..!.,...7b...(z...[l..}...U.z.T.U-.....{@.+..,hJp.X4..oM..D,Oi..l...?...@.L.@s.ez{.}5.P.]l........}..m...^.........'k.WxM.......u2....m..w.+._{w...........v....u/U...\t..G<.5'5.q..[.fX....A....guB.kR[...t"e.^....gH...U..G|C&%.~.>."V.!.x[..{$...T6<6...w.[FX...(pb./.@..Z..n.*.. 6hd.....>.=..`....
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.8447514039954935
                                                      Encrypted:false
                                                      SSDEEP:24:bk9mjQoLEnIsTWX8+mTTVpgoPgh2kG8ait4Z+FrPbkVoQn46Neqy4bJZ62yc4nr:bk9mzL9T8v4sgMkAiierPb2o0/eqy4N0
                                                      MD5:3ABB8A8A18A54CBFEC76D3F455587CC4
                                                      SHA1:B96D61BE15801621AC52DB94C86614DAEB01634F
                                                      SHA-256:539A62F1431592DCC8F8CC96DF76BD9D0379AA4FB6556EC5C9DC7824828E2D5B
                                                      SHA-512:3A8EADEFC2317CDCD434C9C72DE5F42BCF4F5E45B0D4E039616E99CA1ECBCEABDCDC62AD65F3E57B4F30BC638AE83000F31F028DE34F07F37690711C5D93276F
                                                      Malicious:false
                                                      Preview:WANACRY!....F.;..]..z&.._#.1..g....y.e..(s.E.y5.S...h.;.'..*C.&x...i.g.M..X.~....0...S|....t..f-.....v.;.......a!............'-..f.(............B..A.g....,...l..0 m'l7...:=....8..P)'..........D.]....z.^.ZH...:."..:k)..b..Jw..n7.........A.^YKr*....9..k...B..............4..7...%z^...pG+.b...T.{e2?.wGI.x....8.h.m.]%u..|.X...i.jj..I.\U*m.w.....?.l......m./W.3...)w.\..&\V.&....gB..Q..W...0..fj..G.XD{=S.........Y.=.8Pn.T..]..).H....H...skU......o.H..?...\x...tO..It......'B.zB.P.....8C.k3.A3|.7P...E..1....Oj...#....2{..P....-.?...t..C"..4)`x.u.n.L..C6._....3......}.....6.N....k...1.. NL..J.n......>.?.B ......w.%....w..I../Y.. ....\...$Pa`NO.M.pe.m.Y.^..o.0.<..5@...F=.(.-3......f..!..:........-.-.y.-..)7.p...J....4.... .{..|h.E|b.b..py.&..L..H.b.|u...0......7..L..$1.X...A.S..h.VE.,x.:9^_M.7..~;.R#..........(~...H%.e0.Pt....*4.......O.&o../.h.sm.d..x.......d......u@.&.Fk.*......H..~.k....W..m...E.d.%...._...f..5HQ..`.,a[..;$.XoY.....9D..
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.8447514039954935
                                                      Encrypted:false
                                                      SSDEEP:24:bk9mjQoLEnIsTWX8+mTTVpgoPgh2kG8ait4Z+FrPbkVoQn46Neqy4bJZ62yc4nr:bk9mzL9T8v4sgMkAiierPb2o0/eqy4N0
                                                      MD5:3ABB8A8A18A54CBFEC76D3F455587CC4
                                                      SHA1:B96D61BE15801621AC52DB94C86614DAEB01634F
                                                      SHA-256:539A62F1431592DCC8F8CC96DF76BD9D0379AA4FB6556EC5C9DC7824828E2D5B
                                                      SHA-512:3A8EADEFC2317CDCD434C9C72DE5F42BCF4F5E45B0D4E039616E99CA1ECBCEABDCDC62AD65F3E57B4F30BC638AE83000F31F028DE34F07F37690711C5D93276F
                                                      Malicious:false
                                                      Preview:WANACRY!....F.;..]..z&.._#.1..g....y.e..(s.E.y5.S...h.;.'..*C.&x...i.g.M..X.~....0...S|....t..f-.....v.;.......a!............'-..f.(............B..A.g....,...l..0 m'l7...:=....8..P)'..........D.]....z.^.ZH...:."..:k)..b..Jw..n7.........A.^YKr*....9..k...B..............4..7...%z^...pG+.b...T.{e2?.wGI.x....8.h.m.]%u..|.X...i.jj..I.\U*m.w.....?.l......m./W.3...)w.\..&\V.&....gB..Q..W...0..fj..G.XD{=S.........Y.=.8Pn.T..]..).H....H...skU......o.H..?...\x...tO..It......'B.zB.P.....8C.k3.A3|.7P...E..1....Oj...#....2{..P....-.?...t..C"..4)`x.u.n.L..C6._....3......}.....6.N....k...1.. NL..J.n......>.?.B ......w.%....w..I../Y.. ....\...$Pa`NO.M.pe.m.Y.^..o.0.<..5@...F=.(.-3......f..!..:........-.-.y.-..)7.p...J....4.... .{..|h.E|b.b..py.&..L..H.b.|u...0......7..L..$1.X...A.S..h.VE.,x.:9^_M.7..~;.R#..........(~...H%.e0.Pt....*4.......O.&o../.h.sm.d..x.......d......u@.&.Fk.*......H..~.k....W..m...E.d.%...._...f..5HQ..`.,a[..;$.XoY.....9D..
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.821190381571588
                                                      Encrypted:false
                                                      SSDEEP:24:mXhacjqwzLKLFp0lMaqBiJKh/+3/7KaTr8jOs4+fka81gFUMo+:mMcmQL+T0R6iAh/+3/7Jn8Ks4+fka818
                                                      MD5:6191BA52516B0B420C2F8679DDEB57E6
                                                      SHA1:9FB0655477E3552212CAC32F7D0C4E31C919B22B
                                                      SHA-256:C7FF960DAC625D34D0183F240F6D3D169BD9B5D7D14B1D3269E56C6FCFD307DE
                                                      SHA-512:3B6AA091964A511920CB84526262EEC2F82C66DD6EFE7F7C3B037C18B71DD1754578A812D50147236840106A98A7A47721E9EE4921D917B602C694E6FD66334D
                                                      Malicious:false
                                                      Preview:.&.2.........g.Y...r;+MN.{.wC<....L.<mI.....H]...r......H...0....Q...K... .m~....... ......R..9......C...ui<.D.tvz...)TW'(..Q..h.....2...~.~@.@..?i.F,.>".Z).|.f..D....8-lE9..e[`...M........y@k..81..:3.Y...>a.hD...6X..>.c:..Z..G....."e..j..Un. ....Yhd..d...Uoa.0s..[.Y|M...ymj..$C...*cfi.k;.P.e......C..)...Q.....%.A.PH...1...IE4.....3S.H.B.h.;....U+...`...F...S....8=N.>(.9...Ad............ 2....)1...z.......Z@W.......*.:....t..1...`X.....N..%...;.^.D..O3P%..B..A-..m.....(..Q...\....0.o..g.Tg@.x+..TS.b...WG..s7.b.H...%..Nkn./.:..fq..wC.T..Q..;Vv...5T..... .I.du._...65q.9...r?.U)...@u.),..........2.S..9L.....0....A..g+3....V..N..D..N].v.....-"!.^.^...;...l....hc.....m....^d.....%...m..`...T,Mf..e%.uY....".X.5..B....j.N....+..m....x...[u...J.3.tx..8..!z...u?....M.....~p..^....3.~.'.\=.{....f....#.d...[...U<<.....m.6.c...s....j.nW.qz.{.SH.M..zz...(.$..*2.@..HR"..B._b<]D..=\vg.<TG...._Y.}.M .........DT~...."....j!.`T...Ys.Y..8......l.x....$.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.852194198012468
                                                      Encrypted:false
                                                      SSDEEP:24:bkEkllDDP4DbhIOcgXW6H7GiQDTSgfHghWAsSklWfnBasJc2288Mkx/AXW3:bkLla/nPgfHgh5vuiBaF2QD/WA
                                                      MD5:0E9317CAB77EB9E39F994572DB7E1363
                                                      SHA1:04AC46B21BE4155B5AFF4D701E13B1A89E4018BF
                                                      SHA-256:C8886A95A1D418E4CBEEBCDBC0C4A7DD7B082DFD1630F95415C35E986E6F28F7
                                                      SHA-512:0AAC432E2A1E127B66802E19F2C79958B99B61215F973B1A0CD7E99C41AAD7A8ACE1B9690810F30F46D14738565901B23CD1A8FB1061B9ECC9DBA689CE364BFD
                                                      Malicious:false
                                                      Preview:WANACRY!....t.!.6..w...x.r.C..4.C?..]g/<..W%Y......T.BT...M..0.E..?X..X.21c.YM.D@_.y.#....$..`[..G.E..F..rL....]..^..}$u'..toq(.....;d..z|Sb..;y;.$.G...<.N$M.=....H.{0e....?.J.....Z..H......._YrIZ...I..3...;.vBFL.Q... +.$n.(/q.=..I...s.B.:..w.o.*............r8A....i.x4W.fPP..:*>.....a:...v.Y..$....`$u.............Gw7...y .?..G....a9..c.....t.a...}..H...].}../.c..o.....1..?I.U...U.{..k.C]q....I.....j..D.Q.!.h..>..@c...l..}.....]"..8}..6G..2...td...<n7.......>a.....l".....z....$..<v...6Y....e......0...,xPk|t-.........G.3....s.<.R.......*.,3...U^-Ss..?.(...u.....2..y..0x.[o<....Z0.:'.mf.3...._..~.Q...D.........+.8"........sw..AaS..N5..UU.......S9.'m.k....;...+...2....[...b...K..q.tu.v.$L........KL.....H.D..`..KT...q!N...e...3.*$.i.J*.y!1.....X.E..Q.OL.Z..h.t.!./..R.....@.J....R%S.^i.:.c..kN..a..3O./.%F..|..K./..,.,.f.a..5.tJ..........A....C....^.|...`...;.U.\..`..-7..B.p..A.r.if^.....C.B..........3.v....b...?..].od..w....9..o>G.....
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.852194198012468
                                                      Encrypted:false
                                                      SSDEEP:24:bkEkllDDP4DbhIOcgXW6H7GiQDTSgfHghWAsSklWfnBasJc2288Mkx/AXW3:bkLla/nPgfHgh5vuiBaF2QD/WA
                                                      MD5:0E9317CAB77EB9E39F994572DB7E1363
                                                      SHA1:04AC46B21BE4155B5AFF4D701E13B1A89E4018BF
                                                      SHA-256:C8886A95A1D418E4CBEEBCDBC0C4A7DD7B082DFD1630F95415C35E986E6F28F7
                                                      SHA-512:0AAC432E2A1E127B66802E19F2C79958B99B61215F973B1A0CD7E99C41AAD7A8ACE1B9690810F30F46D14738565901B23CD1A8FB1061B9ECC9DBA689CE364BFD
                                                      Malicious:false
                                                      Preview:WANACRY!....t.!.6..w...x.r.C..4.C?..]g/<..W%Y......T.BT...M..0.E..?X..X.21c.YM.D@_.y.#....$..`[..G.E..F..rL....]..^..}$u'..toq(.....;d..z|Sb..;y;.$.G...<.N$M.=....H.{0e....?.J.....Z..H......._YrIZ...I..3...;.vBFL.Q... +.$n.(/q.=..I...s.B.:..w.o.*............r8A....i.x4W.fPP..:*>.....a:...v.Y..$....`$u.............Gw7...y .?..G....a9..c.....t.a...}..H...].}../.c..o.....1..?I.U...U.{..k.C]q....I.....j..D.Q.!.h..>..@c...l..}.....]"..8}..6G..2...td...<n7.......>a.....l".....z....$..<v...6Y....e......0...,xPk|t-.........G.3....s.<.R.......*.,3...U^-Ss..?.(...u.....2..y..0x.[o<....Z0.:'.mf.3...._..~.Q...D.........+.8"........sw..AaS..N5..UU.......S9.'m.k....;...+...2....[...b...K..q.tu.v.$L........KL.....H.D..`..KT...q!N...e...3.*$.i.J*.y!1.....X.E..Q.OL.Z..h.t.!./..R.....@.J....R%S.^i.:.c..kN..a..3O./.%F..|..K./..,.,.f.a..5.tJ..........A....C....^.|...`...;.U.\..`..-7..B.p..A.r.if^.....C.B..........3.v....b...?..].od..w....9..o>G.....
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.80318701195497
                                                      Encrypted:false
                                                      SSDEEP:24:9HQ7txyVhtKLMJyHS/V8VkzoZ5cjZoaJOsakpbzCAKEATJIe:VfjKLMR/E5Qo+akpbzCu6JIe
                                                      MD5:60E938F57D6566A6F60A6F11A69C5874
                                                      SHA1:376145D064DC5739CFD820E96C8127C8C5899202
                                                      SHA-256:8BCBF9CEB85A44E9D7BB88C4560B0D925004B5A5F970CAE5A8DF662A9E3BCD2A
                                                      SHA-512:B944829B58D40DCC616B4931E7605B1016DE03DEFDA1EBCB0375B567A0BF1246831DA9C3722BD51A7F0CA8DB10D506C0ACFF71EA8E8D0DB0F365C920197E5F6D
                                                      Malicious:false
                                                      Preview:..*m.-.6.v...._.9c.:b....5$A.%.%..q.@..k......8......V...U6#....X...T..6W..v..`......"...O...k[5A..1J..;L%.c?1"..."-..[.P#s...s....v[&.b.G..qq..8!.d.F.O..R'..>eu.t.dm.]..:1^.g..7...n...nL..Z.e.7...65.+.$-rm7..[o..\*..9.Z=..nF/.C...9..{s.3o*'P...8......\<s...lQ....."....O..B.x..j'....4.K.....st....bO".=N.......[....!1..&1..a....AM...."3f!{Y..........P......K.B.Ox../...o..ez1F^w(."N.7...J1.......z..pm:62.....r.d.~.:o}..2.4}5...m2...n.._;..; .q@W....+p.,.nt&r9....11XZ{%.._..p..R......@..$U.E.C..1]..J...r....[.3L.))u....c.(x.y....b....z...G...-.H!..Kf..h.o....}.N....NB..r.u.WS..*.=b.'..8.k7.,..b/.[..xr....`I..k...y."..D...E.}.#../H..KE.....`.y?E.u...P.-dX......W...0...~y......VxGM.K[..sk.!j...(\..@...E?.A<.'....f...$....t.h....>.)5..\TiF>..wVKKlR.aCC/.!xe|^.J.^.....p...._uv.1.c$.._h..\Y....).ej.~.......{5\.<....W>./.l.1.E..>f.`T......-;">....j.KG..k..(8.L).......D.`..SX3.5N..?Yb...m[...21..y....MeT...1.X\*.>....-x..ER.d.n.....q...Xs
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.8442401023693265
                                                      Encrypted:false
                                                      SSDEEP:24:bkusYgUBZsrlbeY7k98kyudsXyJBC126sfQKTv5fx9JpTq7o4o1iOIFdbDBe9S2U:bkvYg9rk98EW8CfTM57/qrgibFdb0cF
                                                      MD5:525007B261CF903DBF193032C12003E0
                                                      SHA1:2D6AC9EEBFCF32EC9C392BD641AF8CEBB6FF0507
                                                      SHA-256:8B1A6093C93F358A43BF108FF63DCB9034E608335ED8D84D1CB8F6049594290C
                                                      SHA-512:85349DD4CB86BD6558A2B4E5CFA98EF57979069DBC85FF71DE41013D014F41CCFF1809E366DA3A4F370CB0B7E355401388D89F3CBE92DD1B6EEF086C0966D61F
                                                      Malicious:false
                                                      Preview:WANACRY!........2.....@.RNG.%..G.&......Q...W...oqq.};S./...g..!#....fF%.@..6...TKo...u..p..:.G.&.I.t.E..yLc?.[.w8....v....X...'....Y...[..H..]..h.O3..=..i...+.y.....zWr......\...gJ..O..k@2..bM...h.V%D....j..8..T..'....z@.(.o..V.R[(..x.^.....k......k............t.#P..]..^...G....K.KRU.R.l...D.(..|.:).5.(.P.x'm^.\...|..o.....[U>Z1..`r...3Kg.eN.AUX.|....D..3F.\+...%..r;XArD.|C..]. .l....`.?m".f..0.#..fKM!.T......Ty.d4t..Z.C:.w...."k..2^..............=4..:.C...Q...5.....P?...\.r.G...n.!..M......m.y.....+)^q.....n...5....zC..dz- .......g.R:....B#..<...|.......k.:v....5LE.X.4V7......Cf....X.....R."'..oZ..]...;.{..lR..\.Y.....7...1....hZ...9 \..T..h...;..9..2.n..$...i....*.......P.k_...*!..a...{..7r...M"...[...P.x.f."..1m._.En.|...2...%.....R.0.q.bP.....*A.1!..zZ..J~........3.:.......^.3a....g..........,..K...<)<].>..%S...Z..].......)....a....."..[.........l......W.A!L...$.........J.X.M5..e....7o..*.3~9T..6.......uN.8)
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.8442401023693265
                                                      Encrypted:false
                                                      SSDEEP:24:bkusYgUBZsrlbeY7k98kyudsXyJBC126sfQKTv5fx9JpTq7o4o1iOIFdbDBe9S2U:bkvYg9rk98EW8CfTM57/qrgibFdb0cF
                                                      MD5:525007B261CF903DBF193032C12003E0
                                                      SHA1:2D6AC9EEBFCF32EC9C392BD641AF8CEBB6FF0507
                                                      SHA-256:8B1A6093C93F358A43BF108FF63DCB9034E608335ED8D84D1CB8F6049594290C
                                                      SHA-512:85349DD4CB86BD6558A2B4E5CFA98EF57979069DBC85FF71DE41013D014F41CCFF1809E366DA3A4F370CB0B7E355401388D89F3CBE92DD1B6EEF086C0966D61F
                                                      Malicious:false
                                                      Preview:WANACRY!........2.....@.RNG.%..G.&......Q...W...oqq.};S./...g..!#....fF%.@..6...TKo...u..p..:.G.&.I.t.E..yLc?.[.w8....v....X...'....Y...[..H..]..h.O3..=..i...+.y.....zWr......\...gJ..O..k@2..bM...h.V%D....j..8..T..'....z@.(.o..V.R[(..x.^.....k......k............t.#P..]..^...G....K.KRU.R.l...D.(..|.:).5.(.P.x'm^.\...|..o.....[U>Z1..`r...3Kg.eN.AUX.|....D..3F.\+...%..r;XArD.|C..]. .l....`.?m".f..0.#..fKM!.T......Ty.d4t..Z.C:.w...."k..2^..............=4..:.C...Q...5.....P?...\.r.G...n.!..M......m.y.....+)^q.....n...5....zC..dz- .......g.R:....B#..<...|.......k.:v....5LE.X.4V7......Cf....X.....R."'..oZ..]...;.{..lR..\.Y.....7...1....hZ...9 \..T..h...;..9..2.n..$...i....*.......P.k_...*!..a...{..7r...M"...[...P.x.f."..1m._.En.|...2...%.....R.0.q.bP.....*A.1!..zZ..J~........3.:.......^.3a....g..........,..K...<)<].>..%S...Z..].......)....a....."..[.........l......W.A!L...$.........J.X.M5..e....7o..*.3~9T..6.......uN.8)
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.820603977558391
                                                      Encrypted:false
                                                      SSDEEP:24:gkDP7JYTfQylb/sOXVfmNAV9ph40vXVNEfjF:3D72cyVEEVuaphhXVNEfjF
                                                      MD5:0B17B5D7924795DEB73D3EF6F3E9CB70
                                                      SHA1:292B8347F4513C3E34185ABBBF441A4591F51DFC
                                                      SHA-256:F47FC1CF4219C5F933FB195CFE3950E25EC2DCE3008A554361E1988241DDAD43
                                                      SHA-512:25E079B66F81FACA3398AE5FE3AE18283DC61AB5495822A5F47333F58CD484E6FA3FD9F8E8BF9B153C4DF1218BE1FE28225490F470AB6EC85AD4A3D0C12BFDDF
                                                      Malicious:false
                                                      Preview:r.@`..7.r..[.$.f...i.^.vt.y..p*...}.vYO....G..8.....l...-D2..,*...Z....r....C......`.......v.=H..}.O.2..k.9...x.a.....1.......}Nv....?.._3/?...-B..2.<&..FK.&.m.q.m.j..o'K..Q...B`v..\:......b.....,R.v.N`....:...^.J..~..}....Y....) D.,./../.D.....^x.............!..e.z..$j;.....-.....q.^.,..%...-..q':.p.dzz~.3...`..*R.l....m.....+.U^....<G._.J).........o-d.... .%.2z...6. .g(.H..g......w:..........y.|.rX@.YxL..IB..2+.a.L7x..-....[.V\.e..U..j.......(..c..D\.p....s...Z.;....-...{?!!..G..."Y.j.8..RC.s%..m=/[K......*..z..8.B|:..>.........i&._.O..c..A........{...g..~........}..Wl.q.K.7.I..`...Ap@...B...R9.#=..I.Wg..._].N...1u..29.jjn..U.....X\`..(...X."...o..B...k....l,v..H&'n...E.b[....H.'A..$..-.....lt..5...".r+...q."8gT.Byh{"..mN..(.8%...[..o.....e;.B........S..Um...,.t.R5......._....!..h..5<g.k.89.W.&...}.8.3+....>....E.J...z..*.=..Y.$!..=..QS.}.....k.h\.37....f....K_f>BpR...............J...s...ZHm5.7NZg.v.\@._..........C../y.8$.r=...is7.|..y>.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.84711444046916
                                                      Encrypted:false
                                                      SSDEEP:24:bkjpsONwn0N+ffUyvDAkWeBSmRZal3EqybRjtAdjgKPUFKtBDP2ZGjiGilSz3RdN:bkg0NYfUuN9B1e3yKjzJtBL2cjiGig7F
                                                      MD5:9125FF2F90569DBDCD4EDCF4C494103C
                                                      SHA1:9C2C976C4A70BEF7B1945507D891755ABDDDC718
                                                      SHA-256:F4CBD777E67743921683DED0A74460C1B186C27F23DCF2DB30586248DEDEF339
                                                      SHA-512:3061AC680721D0564C6A194C60C9FBD6D04DC6DA60C6487ADB1E74D114F6702FF1D4ED3C1E6AC1929AD4EB48A371B8DE7EFEAAE411CA953F67C5075BF41CE1E6
                                                      Malicious:false
                                                      Preview:WANACRY!.....K.....W.3.l?..1N..G.9...b.......s...;9.\.cM{.>iRB.>...!..."HkI...).{E=../X.......Y?..N.L.........>J..Y>6.p...mU?{.a.^.6j^.....G.:.r&.....zE.<N\..~....9..{D..se...<.16.....m.O.u ..KRF..q.?......~.1.Q.\.c.k..]bF.@....0O.......U...\W.e...j.............-;.. .z<1..qR..6E\pIX.O?.eHZZwq..*.2'..o>I]z..=E=.J..";...8L...W$Y]..O...@. &...../..D.3....4g.i.x}...q.F..py.`..\.g...YE.0$..e..#....q...u.m...[?..4..`.L.I...z...1f%...3.!..n.<Z.neX....v^./....e.F..ly..%`*;l;...J.Q.P"....:6H.T-..g:..FX..5..O*R..s....h1k.....?....."P.@..\w.....lE....bXU.Q.D...2C.X..h..m..l..?.f.......[....*y.......;T.b.....fm.P?.).|.....}.OY.Gb......F.0..W}.g.^.T.^...u.9...?.mR..]6.\@............(...j~O.,..[.p..JZ..()F5%.............[E..$.....rtin...N.{.f...0^.LG..B*.h.......F.2A...5.G.....(Bh.l...^X....&fX..:....i...._i.%......!..K.&.g.Wp+t...y`O..j@.+..a$...v9m.=..:./.2`...0..CF@..x.C.c...G9........A....\E.i...t...&..x.'r.&<.<.*..K.V....I.?.~.p.M...8f.O
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.84711444046916
                                                      Encrypted:false
                                                      SSDEEP:24:bkjpsONwn0N+ffUyvDAkWeBSmRZal3EqybRjtAdjgKPUFKtBDP2ZGjiGilSz3RdN:bkg0NYfUuN9B1e3yKjzJtBL2cjiGig7F
                                                      MD5:9125FF2F90569DBDCD4EDCF4C494103C
                                                      SHA1:9C2C976C4A70BEF7B1945507D891755ABDDDC718
                                                      SHA-256:F4CBD777E67743921683DED0A74460C1B186C27F23DCF2DB30586248DEDEF339
                                                      SHA-512:3061AC680721D0564C6A194C60C9FBD6D04DC6DA60C6487ADB1E74D114F6702FF1D4ED3C1E6AC1929AD4EB48A371B8DE7EFEAAE411CA953F67C5075BF41CE1E6
                                                      Malicious:false
                                                      Preview:WANACRY!.....K.....W.3.l?..1N..G.9...b.......s...;9.\.cM{.>iRB.>...!..."HkI...).{E=../X.......Y?..N.L.........>J..Y>6.p...mU?{.a.^.6j^.....G.:.r&.....zE.<N\..~....9..{D..se...<.16.....m.O.u ..KRF..q.?......~.1.Q.\.c.k..]bF.@....0O.......U...\W.e...j.............-;.. .z<1..qR..6E\pIX.O?.eHZZwq..*.2'..o>I]z..=E=.J..";...8L...W$Y]..O...@. &...../..D.3....4g.i.x}...q.F..py.`..\.g...YE.0$..e..#....q...u.m...[?..4..`.L.I...z...1f%...3.!..n.<Z.neX....v^./....e.F..ly..%`*;l;...J.Q.P"....:6H.T-..g:..FX..5..O*R..s....h1k.....?....."P.@..\w.....lE....bXU.Q.D...2C.X..h..m..l..?.f.......[....*y.......;T.b.....fm.P?.).|.....}.OY.Gb......F.0..W}.g.^.T.^...u.9...?.mR..]6.\@............(...j~O.,..[.p..JZ..()F5%.............[E..$.....rtin...N.{.f...0^.LG..B*.h.......F.2A...5.G.....(Bh.l...^X....&fX..:....i...._i.%......!..K.&.g.Wp+t...y`O..j@.+..a$...v9m.=..:./.2`...0..CF@..x.C.c...G9........A....\E.i...t...&..x.'r.&<.<.*..K.V....I.?.~.p.M...8f.O
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.794636815230596
                                                      Encrypted:false
                                                      SSDEEP:24:BncEFpIgtx2xDHuyG70yrMh6Ru+FTvCwSKdSoo6Px0J4hGJ3G4TyAOq0M:BncEFpRgxDOBjxhzuoo6PmJ4UyAR0M
                                                      MD5:C7E62A797C638FCEB85D0128F171219E
                                                      SHA1:BDD7EA6011DF94BABD766B7C0DFA79825AB4367D
                                                      SHA-256:26A6C59FD07C764F34D86D04BB81CE29CC8CC7BEF64CC66E13B29CE0E37C0E3D
                                                      SHA-512:D01FD8574EEF11043CBED20D3A1D9B715E28AC1191EA85C38170AB4117D6EB018ED117B043C07783F188620FCAA1076FE07D988D65AD257EBA7EF3BD4EAEEF04
                                                      Malicious:false
                                                      Preview:`p.....u.......;I...~Z....2`#Jp+..CC.._?x.nx&A@M..\.2..w.IG.Zb..U-...h.p5...N.P...!....q.6j....LT...H.......... .lR..h~?....b.8o.@..0)r..dC."._... TYAuzo.0..F.....w.l....D'H.X.w}...sp^I...5..i.....ep..?..j...$.9......0.].@.p...i.>jD...oC.@.........p(Q./.5W.: ..$KB..Y..?..9z....=.<.k*-..N}...D+..oY.C.6..........R..Q..L~n1.H.?....}..s...1...v.H"A.>...9....`.b_h .+u..tiC..*r.B.p._..Q..h.....<.N.<ka.T]....o.z?y...S..xZ....B..........o....|.....Mmw..g[.U.a'..%5..B.'L"cx.T"....Z....v.ln.+..pn.........!.}yI..`.uhwh..g..u...F..j.$.. .....#,..:8......-....yp..Y..Mg...~...$.An....j...0..X.;.6......j.S2U8...~..3j.`j.....0..;..}.OYar....vt >....}D...k.;.XD.0...S|...,J...D.I.?q.....C..._.u.|V#.....j{`.]...v.<.......T..qP.....F.".o......Ha.$}.^R....J'..P=...V..c...;..-.E...X.4;.J^....D[.l.BQ.h.......N).,\-....T....c)x...*......k.....@....&3...r....>#..a.m]X#..&1o...{.r2...F.8.n.E.Q."N.........=J..).J...0vH%........&4k....w...$$...-.fa.,...=0....*8V...N....|..
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.86199747067746
                                                      Encrypted:false
                                                      SSDEEP:24:bkR0LZymvmfdvn5rwErO654F1V83WsSnEMIza3wRilCHpTtic1nfSuXjB0Mg/r5I:bkR0l/+fdv5rrKixJQlCJ5i0fSKB0M+y
                                                      MD5:39A2C93A466A63B68A892C35A64202B0
                                                      SHA1:F5ACD6D87ADA4EE52DA6B6DEC512D3D98D497E60
                                                      SHA-256:62E8FE4C285F82328A85EC7CBC39E2D6AC30177991089EB95BE4614F7B68926F
                                                      SHA-512:69FFED37A3DE8843170E7DF8C7FFD9191274F7ADD9C1C04D85D332B0ED0B21508F5C7741C0CB54D9FAF7B2C1BEB3F3E636728AF68642B7B29D15ED30472C5BE7
                                                      Malicious:false
                                                      Preview:WANACRY!......_S.T>....Rl...!.y.=...`..H....$.*..x:..j}.....J/..y0n....!..v....R...N.:...R...xq...*...R$..&....K..e..80.J.P..o..].6......]mS..cD..R..Lw..n..m...t....4)....(K_...#Y..+.....QA.]....".ae?. d..n.H....i.....)->.f.D .0>c...=.r..=..U...g....K.6{%................>..D..B...{.uy.Y..7.>6..zR...&.e.....E.N.zW.m...@.....D..4.....r...|...3.Va.A^O#W..U..4.|.6R.E.:.a..8..f.gB.@..d/...m.M.1'D.M.}?..c.......]%(.C.U.a.1VV.x .....T....~......6$B.A.N..M)!....)S.._1W0...gU......y....+*...i.s....b..^....\....tV.x%.B.(......22Z.e.y.$....3..%0...RHA#D.....I.t....!...a}....uU. ....g...dm..)^.....ei.Ys..%....S.H..............Y..!....SW..^1A.l.08e.Ws.....i3.B....1+q.....2..?o......|.*>.4...~.V..r.AN....8.z.6y..?...}......../p.Hg....5....r.m.M.u...s.t.4...V.j.k:c?..i.(Q.$l}w....c.:e*?2=k.....Z..mS.].....@7......`("T. pw.*...C{../.I.+E...r.)E|...8..z.....m`..U^.HP1F..S..0.fe.........+mo.`.......kXx.2n.1....C....?Y.o.(n,?G-.YKf.e..[.BE9..x./?.....!.....'.Iw
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.86199747067746
                                                      Encrypted:false
                                                      SSDEEP:24:bkR0LZymvmfdvn5rwErO654F1V83WsSnEMIza3wRilCHpTtic1nfSuXjB0Mg/r5I:bkR0l/+fdv5rrKixJQlCJ5i0fSKB0M+y
                                                      MD5:39A2C93A466A63B68A892C35A64202B0
                                                      SHA1:F5ACD6D87ADA4EE52DA6B6DEC512D3D98D497E60
                                                      SHA-256:62E8FE4C285F82328A85EC7CBC39E2D6AC30177991089EB95BE4614F7B68926F
                                                      SHA-512:69FFED37A3DE8843170E7DF8C7FFD9191274F7ADD9C1C04D85D332B0ED0B21508F5C7741C0CB54D9FAF7B2C1BEB3F3E636728AF68642B7B29D15ED30472C5BE7
                                                      Malicious:false
                                                      Preview:WANACRY!......_S.T>....Rl...!.y.=...`..H....$.*..x:..j}.....J/..y0n....!..v....R...N.:...R...xq...*...R$..&....K..e..80.J.P..o..].6......]mS..cD..R..Lw..n..m...t....4)....(K_...#Y..+.....QA.]....".ae?. d..n.H....i.....)->.f.D .0>c...=.r..=..U...g....K.6{%................>..D..B...{.uy.Y..7.>6..zR...&.e.....E.N.zW.m...@.....D..4.....r...|...3.Va.A^O#W..U..4.|.6R.E.:.a..8..f.gB.@..d/...m.M.1'D.M.}?..c.......]%(.C.U.a.1VV.x .....T....~......6$B.A.N..M)!....)S.._1W0...gU......y....+*...i.s....b..^....\....tV.x%.B.(......22Z.e.y.$....3..%0...RHA#D.....I.t....!...a}....uU. ....g...dm..)^.....ei.Ys..%....S.H..............Y..!....SW..^1A.l.08e.Ws.....i3.B....1+q.....2..?o......|.*>.4...~.V..r.AN....8.z.6y..?...}......../p.Hg....5....r.m.M.u...s.t.4...V.j.k:c?..i.(Q.$l}w....c.:e*?2=k.....Z..mS.].....@7......`("T. pw.*...C{../.I.+E...r.)E|...8..z.....m`..U^.HP1F..S..0.fe.........+mo.`.......kXx.2n.1....C....?Y.o.(n,?G-.YKf.e..[.BE9..x./?.....!.....'.Iw
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.8184428783675965
                                                      Encrypted:false
                                                      SSDEEP:24:ETKHOiNuyGzEalD9V0qHQ/3AB6c5iDkZOfJvZQBNs8frD50M66sF:ETKH9NpGYalRV0Qg3AN52kZkIs66MoF
                                                      MD5:FE3EBC24AE874EAA552BB5737417415C
                                                      SHA1:3ACF73107AA77A3291F0FE6FBE8004C5EEFE5FF0
                                                      SHA-256:3C6FF8F229487459ACEF7ED055F8E8CF33928EA74FF5CC792B38661A7D88599C
                                                      SHA-512:302530438017E5E5567EDAEAA84112302CE386B95AAC1326179E88BDD453AE1ECEFAEA52B5247E03CD8AF9C1AF6AFF0D9F686078ED9AA1BEB763E89235038303
                                                      Malicious:false
                                                      Preview:..x.,S...F..X.....O.a.AT...N8.,98!8.<....&L....J..U6hh..\#.v-..5.....NH.G...co....../.[.v..3.w.y.3._.e5.%........o......I.J.~b<...h)..J...L9^w."..o..z73.f?or...?..Z.W=.DO.l.sf..e[.<..r.C..b.u.m.h....2....!Rx.....`..zN....W...D..b..C.K..3..l#..%.]..gp&N./q3.I..*O......$.E.E.....b..E.u.n.L_.~.[{..R.B....+...s.S..%y..$.4.~."..#L.$.V...>..^...H.S.E1.>.=V..D...:.&c..n....}......=m..'..0..j..k<j..F..<K...........^......SSI..E.T..4....w...-<oPie.......\...a..Z_....}....2s.t..jJ_.\:...&.. S8fn2i...w........6f...K.y..T.A..v..9..i.a.h.;...3I..B.d}@..Pb..A...-S8.?B...y|.,.........S..../}..~.7..9.;5K..B..T......Gi2..#..=..A.smE...m..<..^&3.I.Y.pa...+.`+....%S.\...'I...B>.........6.......g...Re...E.......$o..........p(..c.p.l/),/.Xu......E./..n.2.pv.<..!.f......o....>3......n...#...Ha.E.8.%.\.kS.q....n. ..!.$..U+B..Sl..@.PjQ.....{'......>.{.\...gV.kW.kn..O.)pV......3.[.1.j.o...+._.V.pC;D4.Vp....N.m.......~RH.U...8v8Q}.dg.....(>.D.Qg...o.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.835740428467474
                                                      Encrypted:false
                                                      SSDEEP:24:bkhltZTp6IUzsO2mAYQeYEkJV6EjmZFZp83ap+1UJLGibNhGtKg13gqnH:bkhFHUzMYQerkJfmZSiCihGH13xH
                                                      MD5:1D39F00EFFBB37E75371F61477436803
                                                      SHA1:49ED4E6CC7D16556AB319BB05210C0B5312A2322
                                                      SHA-256:05ABF824E0546C59AF1F615E12B2FC41009D0C65C943E304641CD5E73E693F0F
                                                      SHA-512:B3A3E2BF715E2BF0C7622E7625403A141E62D9038F10E0C85D9E6CB46C43889135686DA6B63007CF1042F021F6F49408708C10122E8AE9133FAE116E34697DAE
                                                      Malicious:false
                                                      Preview:WANACRY!.....XY..\.....uPj."....e........;.y*..WUEps..J...FF...0.Y....T.?.t)..Z.......".Dz...a..~.`.V..}.u]2.........l..&..|..}...c.w.{&...>{G?.Et.../...uXO.h.D.4<..+a.'...V.@e.V..2=-..@.....ia.#.......K.d..q.....V~.r.j...........%SH.dKa@Q0.<2....b+......<.............N.......#..Tq....7..c\.'..v..........F#..co.C........O83.P...g..h..f.2.....S.....$..>IR.../w..K....L...;*f....JF..[&P.\.5c++..L.X]F.<F.L..n.Px. ..]yJ$...9^....."W=..v........H..Wm........~iA.......^....f...eg.7.0G.W<.u.P...1.....e..c..~y....{._n.5.K7nK...}."%...TH.....! .......;.N..!.s.1T.v}......w..JPn..q........y..6mG...6;......q.T.~".Y.Qt...ns..m......4?".t.............e...........2Z.y.._...l.O..XX..QL...Si.q.l.MT.....3:...Z...=.!...1...`..W.x...<..6..HP.f.{...r....#.8O..JA>..u.......30.t..Ft.%..B?G.I_;.Q/$1...............=...W......c+S$.V..2.2.x.U.=.x.$r#.i...........n....R..C"J..k..R..V..=..l..?\Z...).O.L....;..S%..w...I....x[S..=nI......fWP..6+.%...{......s.S.!o.4.e..n.[Fa.2...
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.835740428467474
                                                      Encrypted:false
                                                      SSDEEP:24:bkhltZTp6IUzsO2mAYQeYEkJV6EjmZFZp83ap+1UJLGibNhGtKg13gqnH:bkhFHUzMYQerkJfmZSiCihGH13xH
                                                      MD5:1D39F00EFFBB37E75371F61477436803
                                                      SHA1:49ED4E6CC7D16556AB319BB05210C0B5312A2322
                                                      SHA-256:05ABF824E0546C59AF1F615E12B2FC41009D0C65C943E304641CD5E73E693F0F
                                                      SHA-512:B3A3E2BF715E2BF0C7622E7625403A141E62D9038F10E0C85D9E6CB46C43889135686DA6B63007CF1042F021F6F49408708C10122E8AE9133FAE116E34697DAE
                                                      Malicious:false
                                                      Preview:WANACRY!.....XY..\.....uPj."....e........;.y*..WUEps..J...FF...0.Y....T.?.t)..Z.......".Dz...a..~.`.V..}.u]2.........l..&..|..}...c.w.{&...>{G?.Et.../...uXO.h.D.4<..+a.'...V.@e.V..2=-..@.....ia.#.......K.d..q.....V~.r.j...........%SH.dKa@Q0.<2....b+......<.............N.......#..Tq....7..c\.'..v..........F#..co.C........O83.P...g..h..f.2.....S.....$..>IR.../w..K....L...;*f....JF..[&P.\.5c++..L.X]F.<F.L..n.Px. ..]yJ$...9^....."W=..v........H..Wm........~iA.......^....f...eg.7.0G.W<.u.P...1.....e..c..~y....{._n.5.K7nK...}."%...TH.....! .......;.N..!.s.1T.v}......w..JPn..q........y..6mG...6;......q.T.~".Y.Qt...ns..m......4?".t.............e...........2Z.y.._...l.O..XX..QL...Si.q.l.MT.....3:...Z...=.!...1...`..W.x...<..6..HP.f.{...r....#.8O..JA>..u.......30.t..Ft.%..B?G.I_;.Q/$1...............=...W......c+S$.V..2.2.x.U.=.x.$r#.i...........n....R..C"J..k..R..V..=..l..?\Z...).O.L....;..S%..w...I....x[S..=nI......fWP..6+.%...{......s.S.!o.4.e..n.[Fa.2...
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.827603052995493
                                                      Encrypted:false
                                                      SSDEEP:24:FERADFVeSZ8aUVY6P8EetAk3F0xVMwFEQIprYLlwu95xYK5WIG1:G+Fqo6det5GGogEll3xbq
                                                      MD5:20DD8B101D62666CC239D8E7BB3FFC93
                                                      SHA1:557E904959739C72170140B5288C5C56969BB97F
                                                      SHA-256:6B157F03333DE874155A4CB17D724EE69827D8C0DA32B620CAFC69529E24A363
                                                      SHA-512:9F9CBFB6B25AF8E8EA75CBD0B1A487592E773107A2CB3F75C54471239CE87AE0C436E2C5D3F7F7819A21EBBD76F6434D3376E326F150FFCDB7D39114424DBB7D
                                                      Malicious:false
                                                      Preview:.@g~..|...x.h....1b<...Q.7...]^eM..D{.u.Q....0..7f......78....e}...l...A.r..........8"D..\..,..P....7'e..QA......~......1..TD.}..n_r...\L.Q..Kk..i.=.)....._.....J...I.X..@41..u...C=..h...Z....f..#P.K.b...7.~"..py..X.q.\...s.......i.8.&..Y..#..2......;G<...IL.K..5...A..*..m.m.7.C..v...}..<..f1...S..?...1g.sT..].|..s.;./..q..S..$5.W.._..\.n...,..X....5.D..<K.a.{.......A..;....-........k.zA.h@.F.&.$...kd..cM..Y>.+*..(....,.b+}R......:b@#.....BP....!..<S[T...Wm..F.......4..{............5.u=...<j83#...'..!1.....=4x\y9p....C..z.5Z.H&......F.@^:.TG..ED..].Q..=..%i2...'ww.w.V^).Izq.209$.b.&.-".!.gD5..g.l..G.C.......q..q........h..-..N.`..Pr7..F..E....#...6....|...g..g.L.Ls........+t.......$...J.7.9Ya..$....Q.g..d....?....W$....6&.!..4..H98...b.X.......2VR..M/i..P+.....%:.l>.4....i......c.......8...<...^..Nx..@.dFe..&n!.../o.^3O....c.*...k\.b.........P.|_.U..l..Y..Qr....{@..,.#Y....X.......G'Ty..C..Z.a............:.R.V..).XuH.v/ .3..K....
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.847933069523614
                                                      Encrypted:false
                                                      SSDEEP:24:bkP8ZkAj0BCN8SO0f6wTc+nE/FF2cn2VVoFieGiXA0PY3FNdA1/uzBDUJGGmuRl:bkPakAj0gNXrRTc+nYuVCZw0P6zdA1/T
                                                      MD5:EF4AFD9DFC14297AA1C48D06BF616706
                                                      SHA1:A6D3DE4E38AFE682E104E219DEA4338030256E51
                                                      SHA-256:93BAB77444905F2CF1ED638AD42FA47453DF56DA413E312A1AC819500413D619
                                                      SHA-512:7BCCE76DFCC9F7FB9EB1663CE18BDE1A6D4260815C8CEAAA8CCEFAFE8CA4EE9A85059694BC82CC819AED49363D76763CCC64332D0563851129E0D9FF434D7EEC
                                                      Malicious:false
                                                      Preview:WANACRY!.....~...B4......!...f*.kh.F...%...iY..x..[...,.}:...}..0..P(gU.DAu.l....H.....f+s@..I..B"....6j....s{35.&YF$...q,D0...2.....p..`;...s.....%P.$ZMw....#G.kN....O...y.......i..{..\..F.K.9..2.../."...9......<.Vg.K[..Z..9k.C.W.o._YSq.h...9c9.[J....Cm.g..Rz.Z............P...UHsr...q@.\B`....Z..}u...F.S.A.En&i&.>....A.i..b.e...9....&{Z..K$8N...0.:M..,.:....}.fd_.E..;-.}.h9...J......Vc......'.....?Z.W....g.W..!..tr\jt.m."Y.'.V.v2.....dA...F).v.....p:.$....9.K..<.N..&.Q51..XI..^.2~i5[y.*.k.o..%.a.p8Y92...d..$.z^....2.....2.+..'....K..(^p.b.....S.A.6.\.[_^.B..9......mB%..P...B..B.b.....#..8......'wy..+#.>.r..h(l..,..~x.%...,.....2.+ ...<..D.....R.Z.yQx...4R............{.G..,.....(.].5.6-.o.9.~.z.T.{.D.Bf..m>*..0R..ZLFe8.'..eg.....)..t..b.mS0:N2.n.z].c....|....W....r#.,.V.i1d.O.T.t .M.....Yl..}...qXk.../..'.T..]....7...3..-....w..)....o..n*.......3.pg6..'(M...5=+..9!kZ....:.2.eP[..5...{.......2...'`....0...'y>..l./W..4.%..W...`.2...}Pg.......)g.*..
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.847933069523614
                                                      Encrypted:false
                                                      SSDEEP:24:bkP8ZkAj0BCN8SO0f6wTc+nE/FF2cn2VVoFieGiXA0PY3FNdA1/uzBDUJGGmuRl:bkPakAj0gNXrRTc+nYuVCZw0P6zdA1/T
                                                      MD5:EF4AFD9DFC14297AA1C48D06BF616706
                                                      SHA1:A6D3DE4E38AFE682E104E219DEA4338030256E51
                                                      SHA-256:93BAB77444905F2CF1ED638AD42FA47453DF56DA413E312A1AC819500413D619
                                                      SHA-512:7BCCE76DFCC9F7FB9EB1663CE18BDE1A6D4260815C8CEAAA8CCEFAFE8CA4EE9A85059694BC82CC819AED49363D76763CCC64332D0563851129E0D9FF434D7EEC
                                                      Malicious:false
                                                      Preview:WANACRY!.....~...B4......!...f*.kh.F...%...iY..x..[...,.}:...}..0..P(gU.DAu.l....H.....f+s@..I..B"....6j....s{35.&YF$...q,D0...2.....p..`;...s.....%P.$ZMw....#G.kN....O...y.......i..{..\..F.K.9..2.../."...9......<.Vg.K[..Z..9k.C.W.o._YSq.h...9c9.[J....Cm.g..Rz.Z............P...UHsr...q@.\B`....Z..}u...F.S.A.En&i&.>....A.i..b.e...9....&{Z..K$8N...0.:M..,.:....}.fd_.E..;-.}.h9...J......Vc......'.....?Z.W....g.W..!..tr\jt.m."Y.'.V.v2.....dA...F).v.....p:.$....9.K..<.N..&.Q51..XI..^.2~i5[y.*.k.o..%.a.p8Y92...d..$.z^....2.....2.+..'....K..(^p.b.....S.A.6.\.[_^.B..9......mB%..P...B..B.b.....#..8......'wy..+#.>.r..h(l..,..~x.%...,.....2.+ ...<..D.....R.Z.yQx...4R............{.G..,.....(.].5.6-.o.9.~.z.T.{.D.Bf..m>*..0R..ZLFe8.'..eg.....)..t..b.mS0:N2.n.z].c....|....W....r#.,.V.i1d.O.T.t .M.....Yl..}...qXk.../..'.T..]....7...3..-....w..)....o..n*.......3.pg6..'(M...5=+..9!kZ....:.2.eP[..5...{.......2...'`....0...'y>..l./W..4.%..W...`.2...}Pg.......)g.*..
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:OpenPGP Public Key
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.84706288034368
                                                      Encrypted:false
                                                      SSDEEP:24:gGexX7faE6HGRurlUlWL1hwUW+BIwiGbdTTG5fiEnj:gGIX7XiG4rlAWL1hwtCgGbdT8fiI
                                                      MD5:B33AE15AE6A1AEE098B7AF87254DA33F
                                                      SHA1:423F095BE28CE14607E7A8FFAEFB590D2D01D267
                                                      SHA-256:401F8A56464E3BA804080FAD23974B2D3D655B97A8862CBE6FB37A56AF9EC8AD
                                                      SHA-512:91A878B5D3B4B885F14B79C6E21AFC36CE5EDE0E4EA889CC50A12C671E496CB4304EBAD51D6A6BDC0F89C9CD74DCD13FCAB90E4B0E7B4889D1443E6B5B7B54BF
                                                      Malicious:false
                                                      Preview:.....lq.i...1D.;..4...o...@K.r.$hC|qn'...)U.l0...}....:K....#.X.....J#Q....3..=.....n.DnT..{>.?@P..99..]...0D....:7..E./r.l.O......u....f....B.`......u{8!..X.v.Z..3O...txO.%...%..?....../.m..(..q.V..N.3U;?.V ]0..T.fr 9..p..2...`..S.....$.U9w(.ME.tz{.=JL.......k#..P..M....'...Z..Yb>...<"E:.l.@w......a...jm....U.?...'.......;!.R_2.2......4..`........(!/"..y..\.Xs....'.d.+...5...n(.......J........C44.DI..u[f.~....h].`%..3....."BM.........O....%....N([.ER..l..|..8....8..i+.OZ.......(.7c=.....P.`D....7n.T....I.....ee.A....|.B.o..q.m.V.l.'~...[.........t.."V.....N.}.p...I....4.P.(.}.f4.-4......1v.......A...........w....1..(<<.....(Z;..qv.I..p".....Z.0......C...vE@\....w'.....z.......P..^...Rq">k..[..-.i%.*.;..J..Y...kJ...{.+.$...U../.~.T.....,....../[G.x........ah......'5\.....e^...c..$.....,..GB....V%h.g.>m.b0.1...gGg*>l.9HO.`&......&.......x^...d..z.AX.:6>._H.....*h...j`.M...r.i.B.m;].._ .~Z.zcD..$.x!...(.1.]4...A.].......*2V...5..*..W..&.D.F..
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.860349155383738
                                                      Encrypted:false
                                                      SSDEEP:24:bk4SoeA2kaeF85d6gJyBGXJFcr07/waMk4k7WEybxpS3lmOMJ28ep:bkIeA2wYdvJyeFco7/waMk4y11wa
                                                      MD5:859F73C9244E83532E52D3C002250B8A
                                                      SHA1:EB0223294485D868346F0B93208E5042B5C1FBE5
                                                      SHA-256:1A393E3D07BDF2DDF27546F8921F544769650DDB334F08DB51B00F9B37E94DE9
                                                      SHA-512:204253AA55F597FFE4FD62FE810CAA8958089DCB2E4934C023E31D7C85B65081144C1F54C241AEA892F782D19E0E19BE81712A4B855BE9A4707ED305CF236C6D
                                                      Malicious:false
                                                      Preview:WANACRY!.....|....~..[...S^..%xI0...&......UG...9).<..P..r1-.j...D.p.Y#..>.m........@.(..+u:.A.....d.|W........_...6|.).....n*.d]....G@..+.....2..O..#:g.du>...R.r..)#...0..Q..G (......N...X.=.)Fw......ZHt{.....)>.$..'..F...=....zzPG.x.[../.e.N....N&.$.............<...P..wx..*.F`*.......|....&...~Y.".n....(:....~...ih..+..j...y.K..........z.m..*...@o...".oXN..B....?...,.k.!9$......_~.}.uW.i..P..X...U{j".| ....78.Y.4.[T..l..F]...r............cS.2..?.>.0...... .0.k..R.$..!+.vj,w.-..DQ..x.....OWOqd.....]..g.\.=U.ag..T....pb..X.Lw...`p.b..w"....*.c......4.%>%y.}.F.[....[.zK.Z..$b.;...\..R......N?...@{...0G..yA............620.C.YE.....U..KHp.5g..~^J.1......XI.*|...TB.P..R`5:.xl.Xm....3v....0.EV ..:.F.V...F.d(Ju.P.....R.HS..aPw.P.Ok.8...t..)XT>....6.M:....S%B....PL..x7>.P18D..X..4...,..o.+M.SQ.......||L.t,....Lu.;f.YR.w...3~.....O..=~....X.6{..>x...{#7..../..j?.P....^.\G....q!.G@$.j.h.|....%.z.[.C..M....QJ....z....s....@......r{;$...Kw...
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.860349155383738
                                                      Encrypted:false
                                                      SSDEEP:24:bk4SoeA2kaeF85d6gJyBGXJFcr07/waMk4k7WEybxpS3lmOMJ28ep:bkIeA2wYdvJyeFco7/waMk4y11wa
                                                      MD5:859F73C9244E83532E52D3C002250B8A
                                                      SHA1:EB0223294485D868346F0B93208E5042B5C1FBE5
                                                      SHA-256:1A393E3D07BDF2DDF27546F8921F544769650DDB334F08DB51B00F9B37E94DE9
                                                      SHA-512:204253AA55F597FFE4FD62FE810CAA8958089DCB2E4934C023E31D7C85B65081144C1F54C241AEA892F782D19E0E19BE81712A4B855BE9A4707ED305CF236C6D
                                                      Malicious:false
                                                      Preview:WANACRY!.....|....~..[...S^..%xI0...&......UG...9).<..P..r1-.j...D.p.Y#..>.m........@.(..+u:.A.....d.|W........_...6|.).....n*.d]....G@..+.....2..O..#:g.du>...R.r..)#...0..Q..G (......N...X.=.)Fw......ZHt{.....)>.$..'..F...=....zzPG.x.[../.e.N....N&.$.............<...P..wx..*.F`*.......|....&...~Y.".n....(:....~...ih..+..j...y.K..........z.m..*...@o...".oXN..B....?...,.k.!9$......_~.}.uW.i..P..X...U{j".| ....78.Y.4.[T..l..F]...r............cS.2..?.>.0...... .0.k..R.$..!+.vj,w.-..DQ..x.....OWOqd.....]..g.\.=U.ag..T....pb..X.Lw...`p.b..w"....*.c......4.%>%y.}.F.[....[.zK.Z..$b.;...\..R......N?...@{...0G..yA............620.C.YE.....U..KHp.5g..~^J.1......XI.*|...TB.P..R`5:.xl.Xm....3v....0.EV ..:.F.V...F.d(Ju.P.....R.HS..aPw.P.Ok.8...t..)XT>....6.M:....S%B....PL..x7>.P18D..X..4...,..o.+M.SQ.......||L.t,....Lu.;f.YR.w...3~.....O..=~....X.6{..>x...{#7..../..j?.P....^.\G....q!.G@$.j.h.|....%.z.[.C..M....QJ....z....s....@......r{;$...Kw...
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:COM executable for DOS
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.813495794237703
                                                      Encrypted:false
                                                      SSDEEP:24:pGQwJA6hoZc+w1iKrKok+JdvVRLKPrYYc0Tkd6TBhSPaiDueq8fvn:pGQwJAeZZ1iKOokEdnMDc0+6thviDpqA
                                                      MD5:145418D1946FAE346D2CF97F052DC46B
                                                      SHA1:455187B0AE93E85E24056D1DA056D10F103D41D4
                                                      SHA-256:8D7FF0134CD9C658E4D8C006FBC6CEE094A75AFFCEBDA99DFFF29710AC19E42D
                                                      SHA-512:079984267114840EF372640ED90E70E2E8EB1124269480087A9A36DD7FE5E53B5E09B64044A566EB948EFA9622138214DB39270CA10540EF591B6F56E0728034
                                                      Malicious:true
                                                      Preview:.-=}..`aw\.....wfm'..{.:.5.....H.,..|...s...W. .t...c.?.L..i...../...`R.L.a\v,/..F..=...V....R...7..y.3......j.*......l`.....H.n.2..}..z0Q.Z..H.......p.....R.^.-.M..4k....].Q.k...W.8...M.Z..q......'....>J.#.....*3.A.I.*f...c.?Pa.B[m.t.O.wxU..v.E%.9P=B..<.. .m...1`..~.j...>......^...d...u.x%.H..x.*...b......Y.D..w...D.Fg@....3V..}.....l.%.?.A,..9..9*CG..#..8H..pk>......p.+.}..i.$bO.R..Uiyx.........`..h...{..Y..6....v.R..3...n..*y...W..@......1.<.$+v..M..]c.Q.B.&.z...kMd..x.......x....?`..H..0Er..M..<.7|....}w[.t.Syl...ba.1:.$..m.Q.....Op.s.Hc...4......-......N.2/.....N..U.\...Y3..7.h;.q.eC...Yk.X._.t........}..X.o.%~.....u..Q.i.) UV.R.........@Y..-M.j.....o.<...6%2..o0.>.N..4..qC.4.|..k....#..X..m......k..`.8t.b__.G.*.......iP....ii].}.....`}.8.^.#f.QB.5.xz...!..o..TW........xg..N.i.<j../.5.....)..g..].:C....k.{m..W.....z.=V.......U...j..|....=..; ;.Or......~N.....}..0.6...."`a...^l,......`.".E.Uq....v....@.r..?...Em... P..#@..a...Y
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.851325930538287
                                                      Encrypted:false
                                                      SSDEEP:24:bkfu+Cwk7aBTwSGxUR/wCrckYU1ClWwUEakpsJyfIN34aN7BYsIMPs4v1lly:bkG7wk7aBrSY3crUMl3UEgWIx1YsIYlQ
                                                      MD5:07DDC62C16DCB979FD67688F1061E65A
                                                      SHA1:F81F420555B798CDF01C1C1EEEE84A18D03B5EFA
                                                      SHA-256:840D1DD7C9BF76729BBFDAB24DDCBDF63D13A4061A6E24B3E55B4645D5CB99A2
                                                      SHA-512:7C0391321F3CD0430CE51299CA6C821296F483B80AADA6935E84773884CBDCF609E7412B9E1B4048D3D8AC5BBEF9AEA4A91A211BE5D18755CC4CE8C590BB3D95
                                                      Malicious:false
                                                      Preview:WANACRY!......bv?....(^.#8..K.RW.P>#P{./..T..dal].\.r.\..{o.V.#'3..M<!..a........ .A#:..H%..r..r.'j...Kk.._..+"K.20.Ss..q..B>L..P.....{L........Y.r.70....2...s..l....t.^....D......_?...<..P..Am..l6...:..i..*i.2K=..3.E^..:A+.."..t..R...U....F........VB7..cZ............r....lZ+..].F%.,..D2...|..P...D......w?.12..W..".......&.u,...E.n.D.}`9..n.......qz...E.@x.;l..d.U...b=..)5..h...G.fG..P,95...tf..0.+K.C....B..|...^..wL.....a.`\....e...w..S...J5......w.A..LX.1r'.[l..S...`..!.....j.h.)..x.M%..n@....Ji..A..7.p.z....g.j')O...#...E.h..`P.n.-.K..!....=3D.d)...[Z5.......};H......A...!.[.....ost.O.%.B...|*a.*|m:..G.(.(.....~..].....0p..<......@....u.7.78..}g9...d..7.....8.(...dq......I;\..%~..q.....f....p,...:....H.?/O]..v}..iS.K.H..D......i.....X.>]...=.....@......V.9.t..5..k".y..w..}..Q..~.n..5.8p...p....[.<..5d.-\.Fc?S...t.~w.<F..9. .@].Cs...5.If...w.....`k.......8.T.W....E...>w...^}...*3..P*#.%D..!m..$.....E....~@C..f.-b...B_.O...\[...<....)..T
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.851325930538287
                                                      Encrypted:false
                                                      SSDEEP:24:bkfu+Cwk7aBTwSGxUR/wCrckYU1ClWwUEakpsJyfIN34aN7BYsIMPs4v1lly:bkG7wk7aBrSY3crUMl3UEgWIx1YsIYlQ
                                                      MD5:07DDC62C16DCB979FD67688F1061E65A
                                                      SHA1:F81F420555B798CDF01C1C1EEEE84A18D03B5EFA
                                                      SHA-256:840D1DD7C9BF76729BBFDAB24DDCBDF63D13A4061A6E24B3E55B4645D5CB99A2
                                                      SHA-512:7C0391321F3CD0430CE51299CA6C821296F483B80AADA6935E84773884CBDCF609E7412B9E1B4048D3D8AC5BBEF9AEA4A91A211BE5D18755CC4CE8C590BB3D95
                                                      Malicious:false
                                                      Preview:WANACRY!......bv?....(^.#8..K.RW.P>#P{./..T..dal].\.r.\..{o.V.#'3..M<!..a........ .A#:..H%..r..r.'j...Kk.._..+"K.20.Ss..q..B>L..P.....{L........Y.r.70....2...s..l....t.^....D......_?...<..P..Am..l6...:..i..*i.2K=..3.E^..:A+.."..t..R...U....F........VB7..cZ............r....lZ+..].F%.,..D2...|..P...D......w?.12..W..".......&.u,...E.n.D.}`9..n.......qz...E.@x.;l..d.U...b=..)5..h...G.fG..P,95...tf..0.+K.C....B..|...^..wL.....a.`\....e...w..S...J5......w.A..LX.1r'.[l..S...`..!.....j.h.)..x.M%..n@....Ji..A..7.p.z....g.j')O...#...E.h..`P.n.-.K..!....=3D.d)...[Z5.......};H......A...!.[.....ost.O.%.B...|*a.*|m:..G.(.(.....~..].....0p..<......@....u.7.78..}g9...d..7.....8.(...dq......I;\..%~..q.....f....p,...:....H.?/O]..v}..iS.K.H..D......i.....X.>]...=.....@......V.9.t..5..k".y..w..}..Q..~.n..5.8p...p....[.<..5d.-\.Fc?S...t.~w.<F..9. .@].Cs...5.If...w.....`k.......8.T.W....E...>w...^}...*3..P*#.%D..!m..$.....E....~@C..f.-b...B_.O...\[...<....)..T
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.8002889857989794
                                                      Encrypted:false
                                                      SSDEEP:24:qkdlRfykA9h520ErePOMeUlgRXefdCPUvy:qkdakAh5REKP8UlOefc8vy
                                                      MD5:5B8A8DFCB165E00EFF766DEF331B6576
                                                      SHA1:A20EBE27C1F29C247605B7B78BFACD500210B991
                                                      SHA-256:694AE8ED0AD7AABEB70AE9F8F0A0B0EAA84742D7931391AB49236409561FA5FC
                                                      SHA-512:FFC956EED8F8790810E5EAAAB5997D17CC89EF95622287CF2E306BCE2CF2D2F6CEACC558F21DB2C23881F6C4E7EF3B5124FA43C985B8DA6FA0B5A7D9C4BD4C6D
                                                      Malicious:false
                                                      Preview:....)9.~.>..W....K...r..T.S.Gv|I.L.ST@...H3..8J..?.t.!.?..Z/.....*+U"....a.D,.".i....j..2...@<..kdpH.Re..".d.....|)....9z.uZ...S.4e...A.+.0.v.1|.E_."...a..b.7Yz...0y.|YE..d`..Wj.5..d......C9..A.g.7Q..........5..)"Q..,.A....&H...Y..V#.....x&7......Ow4.g7.<..Lm......K..V~...7>....x....x..........56$....]CPC....x....?11..{N.E.....2..T..^..ZR........pl..:...S. ..zqg.,.m0.*..,...(w.F..h.i........Ia...e.b.7....yP..g..P._.q6"....`\.....w.^...1........v(..1.......+..'.........E@.vv....z.....J...Q9...Z....l......A..$.{....j..'J....... SU..iw.v.X..............*..4.z>..HP...qs.1..2.5hS@4.P.O.r.m....y.hW.D[$.......)@.~..j.c/..S..d.#/.... .).J. ........m"..Z!...@.7..=.,.?.Q1;..K...aV....../..e..@.....I.(m.....9+bH$..4.........G67:....6..U..G....y..g...D.7..f.0.`. ..d?....?[..w.K.D.<l....8.~...pzk=..?V+M....3..}....D........*..bo.E...$(K.huC...7#...0....$:. s."..n.OF&..0.@mNU.....u~cPUZN..oQx.%e......@..+..ek....w.:......L_i.P..u...}...[....J..."m
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.837748366575144
                                                      Encrypted:false
                                                      SSDEEP:24:bke4AGxzindLyewVC5205L9ohl3xiOtpZDmJica0pk8ZTP7gcJRyw:bk5/xuo+5LShl3TfDmh9BDgcJR
                                                      MD5:E5769D6C76F4DD3CC671591632F02E2D
                                                      SHA1:5DF97A9E28A96FE03D9C14B4BD65AC48CBD68B09
                                                      SHA-256:DF1C1166ED2223E66AE685056EE0100AAC9B59BCA98BB494A0C06BE2ADAD3AA6
                                                      SHA-512:D10A898EFF424912E52FC927B91C505FDF82A56D4ECD0CD77B4EA4D557563AD7E2312C3AC343ECFD078888619E7EFF0B599EB855354F2247F63CFD753C311F6D
                                                      Malicious:false
                                                      Preview:WANACRY!....y|HX...D.#.fh........H..#...........a1E...{.....X....~0di.J.[..Y...5......A`.c.....@..2,?..-.n.H.2.M.1..P..Fp..u...;y.(.....{0.0L.."..(..W...q.(.Qz..A..R...-.X....u".x.......)yG...q...%..,...<....).F..L...((wu...=......B..~"|...).i..\.P..Xj.............,S5..A@...K6s-.q..?.h........q...U..../..H..ET.7[.......E...]...Oc..S..qB.\X...5....q.@<.^fN.j.....k...g.p..!(......6....%J...@.@.nc.74.q..cD+(..#)x.......H.<.....#I.q[_D..P..&..f...\...K...8.....Q..tguBt..2.._2I...7b....P........1.iY.Y........../%.q......W.3...Knhh...}2.y...x.......M..38...b..,.s..L.,.xK1.:^.aY...Ga.9.o.Se.....cQ......'Z..9.Z.<...r..s!r..7..v.).*P....%...9."..s...==#.|..&....O......x...0.....v...&.e.K.%....U .T.(.....-...*..BcrH.!..f..........n....9h.,.r..A...Q.......k...."A.*M.ub.!.i....f..~......ws.$..q.f.l(.o.`...|..u....&%dG....T.....i...r...;..DQ.....B..i1....w.K+.}.r.v.9)J...,.^....&p..x.+.g.....:..i._?p.g.7.,...n.R..e).d..\.....2.y.|..8%(..Z...d..
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.837748366575144
                                                      Encrypted:false
                                                      SSDEEP:24:bke4AGxzindLyewVC5205L9ohl3xiOtpZDmJica0pk8ZTP7gcJRyw:bk5/xuo+5LShl3TfDmh9BDgcJR
                                                      MD5:E5769D6C76F4DD3CC671591632F02E2D
                                                      SHA1:5DF97A9E28A96FE03D9C14B4BD65AC48CBD68B09
                                                      SHA-256:DF1C1166ED2223E66AE685056EE0100AAC9B59BCA98BB494A0C06BE2ADAD3AA6
                                                      SHA-512:D10A898EFF424912E52FC927B91C505FDF82A56D4ECD0CD77B4EA4D557563AD7E2312C3AC343ECFD078888619E7EFF0B599EB855354F2247F63CFD753C311F6D
                                                      Malicious:false
                                                      Preview:WANACRY!....y|HX...D.#.fh........H..#...........a1E...{.....X....~0di.J.[..Y...5......A`.c.....@..2,?..-.n.H.2.M.1..P..Fp..u...;y.(.....{0.0L.."..(..W...q.(.Qz..A..R...-.X....u".x.......)yG...q...%..,...<....).F..L...((wu...=......B..~"|...).i..\.P..Xj.............,S5..A@...K6s-.q..?.h........q...U..../..H..ET.7[.......E...]...Oc..S..qB.\X...5....q.@<.^fN.j.....k...g.p..!(......6....%J...@.@.nc.74.q..cD+(..#)x.......H.<.....#I.q[_D..P..&..f...\...K...8.....Q..tguBt..2.._2I...7b....P........1.iY.Y........../%.q......W.3...Knhh...}2.y...x.......M..38...b..,.s..L.,.xK1.:^.aY...Ga.9.o.Se.....cQ......'Z..9.Z.<...r..s!r..7..v.).*P....%...9."..s...==#.|..&....O......x...0.....v...&.e.K.%....U .T.(.....-...*..BcrH.!..f..........n....9h.,.r..A...Q.......k...."A.*M.ub.!.i....f..~......ws.$..q.f.l(.o.`...|..u....&%dG....T.....i...r...;..DQ.....B..i1....w.K+.}.r.v.9)J...,.^....&p..x.+.g.....:..i._?p.g.7.,...n.R..e).d..\.....2.y.|..8%(..Z...d..
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:ASCII text, with CRLF line terminators
                                                      Category:dropped
                                                      Size (bytes):933
                                                      Entropy (8bit):4.710902136409594
                                                      Encrypted:false
                                                      SSDEEP:24:ptrPzDVR5Gi3OzGm0EigS1xbnS4RQhbrW8PNAi0eEprY+Ai75wRZcet:DZD36W3ChvWmMo+S
                                                      MD5:7E6B6DA7C61FCB66F3F30166871DEF5B
                                                      SHA1:00F699CF9BBC0308F6E101283ECA15A7C566D4F9
                                                      SHA-256:4A25D98C121BB3BD5B54E0B6A5348F7B09966BFFEEC30776E5A731813F05D49E
                                                      SHA-512:E5A56137F325904E0C7DE1D0DF38745F733652214F0CDB6EF173FA0743A334F95BED274DF79469E270C9208E6BDC2E6251EF0CDD81AF20FA1897929663E2C7D3
                                                      Malicious:false
                                                      Preview:Q: What's wrong with my files?....A: Ooops, your important files are encrypted. It means you will not be able to access them anymore until they are decrypted... If you follow our instructions, we guarantee that you can decrypt all your files quickly and safely!.. Let's start decrypting!....Q: What do I do?....A: First, you need to pay service fees for the decryption... Please send $300 worth of bitcoin to this bitcoin address: 13AM4VW2dhxYgXeQepoHkHSQuy6NgaEb94.... Next, please find an application file named "@WanaDecryptor@.exe". It is the decrypt software... Run and follow the instructions! (You may need to disable your antivirus for a while.).. ..Q: How can I trust?....A: Don't worry about decryption... We will decrypt your files surely because nobody will trust us if we cheat users... ....* If you need our assistance, send a message by clicking <Contact Us> on the decryptor window....
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Archive, ctime=Thu Jul 25 21:01:45 2024, mtime=Thu Jul 25 21:01:45 2024, atime=Fri May 12 05:22:56 2017, length=245760, window=hide
                                                      Category:dropped
                                                      Size (bytes):575
                                                      Entropy (8bit):5.140446565826782
                                                      Encrypted:false
                                                      SSDEEP:6:4xtQl3y03CpzeVs+bTNAUHUtxXCzaMmM7/gtrUod6tMljAlpdmqLEoJ4D6Vod6Nd:8iypzYNbd0thHZOgZUobjArozhmV
                                                      MD5:CCD2610ADD4080C4DCC35A11217DA6A6
                                                      SHA1:001ABA92D58B546C8BD54E0BC4103661F68CF92A
                                                      SHA-256:0E272CF58CC66E7B0CC4F42094232A46B6EC11AE5ED695BA4156A1A28DA41E6D
                                                      SHA-512:36DC5CE3027E8A77639783E31AC69C9FA61C4761FBEB9A819C1EB49F4A32BF2001C0441FB28D35C4EC9DD1B713576E7894DE8FD13BF14CE62A436F9619093DEC
                                                      Malicious:false
                                                      Preview:L..................F.... ....b{=.....b{=.....`.1.................................P.O. .:i.....+00.:...:..,.LB.)...A&...&........DDj....%.=....(..=......t.2......J.2 .@WANAD~1.EXE..X.......X7..X7...............................@.W.a.n.a.D.e.c.r.y.p.t.o.r.@...e.x.e.......X...............-.......W.............,p.....C:\Users\user\Desktop\@WanaDecryptor@.exe......\.@.W.a.n.a.D.e.c.r.y.p.t.o.r.@...e.x.e.`.......X.......216041...........hT..CrF.f4... .u.E._c...,...E...hT..CrF.f4... .u.E._c...,...E..E.......9...1SPS..mD..pH.H@..=x.....h....H.....K...YM...?................
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.8217475581499025
                                                      Encrypted:false
                                                      SSDEEP:24:K6qh59jCEyh7LNJrThPJXtC15FqBxgQ9arL+1hnoJ7cB:K5Oh7vTJJXyFabf/6cB
                                                      MD5:F88D1170D751C5936B4E1055D57F2C11
                                                      SHA1:7725467C10B067EC4A9C4F092BE89A519FBE5648
                                                      SHA-256:0FEB44511F41977691B6A439393B2E9000D5FB9F4223078BC486761D0345A725
                                                      SHA-512:78DB7F7CCD1CD094DBEC2C10F17A78992EF57760062DA260D798A46A4C5C45980F346B8F16DE2B07747977399AC16C1DAC07E3B49B47BAFBCB0E192610F980E5
                                                      Malicious:false
                                                      Preview:..x...y.-.-w..b ....#.AK.1............H>...]7..pY.N.e4'...T..../......?..P..Q/..[.?.._....T4n.. ...dW...(.?..'...qC...w.rF.|g....4..?..."d.:?+G.....c..f.....J.o..k"..\.Io..h.?h.7.q..0.J1.R..[._..<X.V...K..w...D..!N....7.......S*7:...H{b..Pj...R.X..H..C.e.=.~...E.Y.e4.....I..U.Xc.[j.........J.....`...Q,N..}..\..:%..U..V..Uw4^..$.z...ak..q..R:xy.&%..l0./.+.....P..}..[.6dgF...X+\.\.....4t..1...#e.-..7^.@~Y.......>."X.HM.'$/i..y.b...z...r.`..(..+J........n..1].4........N.g.Z.S...(.x....u...<{D.$.:(...wa.*.'....;k.;.q'.l`h..c..5.....a.@.%...|.).e...........OB.}.|.n.....W......]7............PTk...................``Y..&...8E.Bm=B.."F..G...".V|vbA...Qw.&y.(...Jm.l.C..j.t... 1...8D.9....&.)......>j..U85u.<..x&-^..(.....Q....i."..49x>.j..].8."..>@.g..V0..W...X.l.rN]kRN._0 ...T-Rhw{DB....x.3.F...4......~..."......L;!..G. ....Q.Q...]..|.V......4_..v$`....e9.......v0x.......@..2.)..~...N.2..o7_|........v*...+)..J*....B...{/.3.7..S.\..<.J.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.85346543831183
                                                      Encrypted:false
                                                      SSDEEP:24:bkMd8/vvLdauMwtyANECfIv26vhx3NXhYafL9I0I1UCPoDdX0abu:bks+3R7gv2K9NXhYaz9rEUCQx0abu
                                                      MD5:07D9D0A6296D714CC8532821DF11760D
                                                      SHA1:659D063C030B523CA4D3DF80ABAA772CD8E06BC4
                                                      SHA-256:1D27E1043F6E33ECEAA7086F1DEC6CC9FB62365E8A8803C9FE8FD4D3ACAD5A8A
                                                      SHA-512:01444D1E5B3234A7CA19663B28CA02F53132EE8460FF92C06C8FBA71015D9AA1BE0DE16EC08CED6B9B6E3CD3DAAACEA44D723AEF6BBDEDC72726F70C420140AD
                                                      Malicious:false
                                                      Preview:WANACRY!.....x...@.F.....".*C|.....}..w].I.{Pn;..._.O'|....1.!...1.b.M..p....U[h.......6......b......-....Q.f.h....8......rt....../......1.@D..&.fw...W#.7........s4P............LER..UG..0....;.4.........6).)....,.....u.R.2...........x._..7.t*...S...W................`.p_.X..@..8KX^*V.n.o......G.f.Y.......i.{.j....Mas...r.$.J..#.G.92|.Z....@..a...&.:.u.#PI.z....wi./?_t"......$I.r....H.....2.Kup<0.c#-zc.j.q.....]...}.....E.;.a..@... .N_HV.V.|0..-.......*.V-v....B..?.P..BN....Y....B.X...nD..s..R .Cmh.4....5.;..LL.Jv....K.e2...;.7D...u..A..NFs...i]...%...I..z...Ic...]..R..!..w..5.py.iW.0{.N('^g}...Cn.Ia{ +U.X....%F.?..IWI.6..s.-.O..?4..m....T..UvI...C......T..IB..Jo-.V..+...z.h....x.r......).......;..)N...t.8`.T...`p...1@e.Is. ..lT.......V...TY.W....`h $..{>...`......R..V....!...jCM....3.QA..u...,...S...9g.|qC..*.d.....5Q0..oV.Z...n....\...Z.l.:..+.....%.V...&....Cp}.....E.t.\......!@..s{V.6..t.SJ....,....{.5.S....A...EjV....HT.C....U...
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.85346543831183
                                                      Encrypted:false
                                                      SSDEEP:24:bkMd8/vvLdauMwtyANECfIv26vhx3NXhYafL9I0I1UCPoDdX0abu:bks+3R7gv2K9NXhYaz9rEUCQx0abu
                                                      MD5:07D9D0A6296D714CC8532821DF11760D
                                                      SHA1:659D063C030B523CA4D3DF80ABAA772CD8E06BC4
                                                      SHA-256:1D27E1043F6E33ECEAA7086F1DEC6CC9FB62365E8A8803C9FE8FD4D3ACAD5A8A
                                                      SHA-512:01444D1E5B3234A7CA19663B28CA02F53132EE8460FF92C06C8FBA71015D9AA1BE0DE16EC08CED6B9B6E3CD3DAAACEA44D723AEF6BBDEDC72726F70C420140AD
                                                      Malicious:false
                                                      Preview:WANACRY!.....x...@.F.....".*C|.....}..w].I.{Pn;..._.O'|....1.!...1.b.M..p....U[h.......6......b......-....Q.f.h....8......rt....../......1.@D..&.fw...W#.7........s4P............LER..UG..0....;.4.........6).)....,.....u.R.2...........x._..7.t*...S...W................`.p_.X..@..8KX^*V.n.o......G.f.Y.......i.{.j....Mas...r.$.J..#.G.92|.Z....@..a...&.:.u.#PI.z....wi./?_t"......$I.r....H.....2.Kup<0.c#-zc.j.q.....]...}.....E.;.a..@... .N_HV.V.|0..-.......*.V-v....B..?.P..BN....Y....B.X...nD..s..R .Cmh.4....5.;..LL.Jv....K.e2...;.7D...u..A..NFs...i]...%...I..z...Ic...]..R..!..w..5.py.iW.0{.N('^g}...Cn.Ia{ +U.X....%F.?..IWI.6..s.-.O..?4..m....T..UvI...C......T..IB..Jo-.V..+...z.h....x.r......).......;..)N...t.8`.T...`p...1@e.Is. ..lT.......V...TY.W....`h $..{>...`......R..V....!...jCM....3.QA..u...,...S...9g.|qC..*.d.....5Q0..oV.Z...n....\...Z.l.:..+.....%.V...&....Cp}.....E.t.\......!@..s{V.6..t.SJ....,....{.5.S....A...EjV....HT.C....U...
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.824080178585958
                                                      Encrypted:false
                                                      SSDEEP:24:UGjFFuglAMoXOIq4hEe0NIjxzK3oI83UvJvmC5yGfLq7/Ssfzu:figlAMoXL5Ee/CoJ3UBvmNGfLI/hu
                                                      MD5:53C747503715861C8DB4AF6763BCFCAC
                                                      SHA1:7A2A87FFAB574C9AEA0C84C986052E77EDD6E963
                                                      SHA-256:FC04AD11FAB22397B2DD3556DC4F9AD1103A4531F7DBE9F79CC23AE791838BA3
                                                      SHA-512:99A4CF80AB4C59915FD99AB41D27655CEEF920E5D3ECC1CE554CD72F02E22C2ABD0209A9212902BDA8051962ACEDAD92377688BE33D5871CF5BBBE4061855B12
                                                      Malicious:false
                                                      Preview:....._.:p..........B..#`...).......(....w(..\.h.!....zI..+q.h..a.c...+P..8...7-.j.nL....@..O.r..n*."...^..tVI...."..$..Y...!.d...*sf|0]."..1.:Y..DH.T.e.....u#{.O.K...V!...O#...,..#...vq...9......d..\-...k.-;r.(}..{...#e.E....k#..e...@..........:.~....3Uk..c.Zn. ....3.7.8..r.k.+`.......Eg.....!\.d^.B....R./X.=w}F+.......`..V.j3....E....{..F?.Z.#4.b...k..g...>Y`I..m.X..=Hl.aGI..gj..=s|..b...$..D......:.......k.X.....MZ.....j..C.....W.d.S...V.T.:.>A....<.../r..a.X...u.7.q.......hi0..}.'.&..&.N..C.>...e..A.X....!.J).=@.KVZ ..^.>M'.....y:fwC...:..m.k..Oa@.c..r.#7+.S....C..Da\..>...r..#b..V]._.Q...#(EL.K..C..../.....r..!)..NS.H..t.....m.......Sd]..Z.k...h.N.e.............".TU.[(C]{.eF./.y.K..b.@. |.d .a.}...@.).......PU.J.......i)1A...O...............T...m(..A..2.hD.....e9..3.a\_..F.N&GYG....%.....(n..o..|\n?.....v....W#q..-.<J<4Jeh.......K....iX..W;e.^h..../....9.d...VJHQ..;.=%3....}1.4..xSv....j.H6......J...}...0.....2.u.k.OO)....m...V0.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.836483532839249
                                                      Encrypted:false
                                                      SSDEEP:24:bktj5dtmuBPq9UQ+MvNdDKZpbCR8Wklz16iTTDgYU88rkQVGf2L3:bklY6PqWoDDK/CR8BZvTISjf2j
                                                      MD5:A8675DC95C081644FD4D2962960ED964
                                                      SHA1:15C97EB67167400953C412F37835CC60347DAEAE
                                                      SHA-256:35758195443445E9C7926D95F5B003765674472665C2057EAA0E0E034556F764
                                                      SHA-512:5355CF8FF3CA24119298124777899DB3FCA7264E48A76F618F04A7EB436CC4F709E1BDE2E8D1CE289ECFA9D471C01E27134EEFD94F627D879A763DC937FD3A1F
                                                      Malicious:false
                                                      Preview:WANACRY!........U.2...-...n..y.t>....\......-.-...<4..#..kA 6.....KG.I.B.sw,C.2.FN...g.N..bp..$...].....{....M.)8IR..\Ez...2......#r..c.m.i.....K...U..%[.+5B.i.Qqh..C|T....L.*...;..X.R....8a..8Y.YX....-......9..g<..X..Nq.O....F.O..o...;!.....)].&/.%................).tn.$y.]....c.{.<ZM3.G..=.PWFmH.]...S.....8....^.:.Hrz.MH9.._.:K$n...JC...3...0t...-$....;]_B....SE.q=..U..,.F..g..eq...\?..Z9..p.>.8..X.L.D.......r..m.Un...+..7..B"d?........O.w..@.HH=XKv.....].B.Y..d..........EK..V...y..+?..."...@.Um....T.hw.P..o..r.P.hI........N....!k.1...O....o..I"P.x.^.xs-@..!.h.....V/j.b0.P.B......u7.s.F.h..J..aMpPD..#QG8.|}u...X$.._...<`.N.HO.W.........jt.q"(..L........2......&...@,L...s...n.R1f...AcU..r..O,s...'{..b.&.....O."....f.#M..;..J.hOF..9S2.'X..|.H.g..V.....CO..4...i.N.....g.....H~..t.X.'......|+.O..:>LU."Xo.;h.9^i..E..5.........=...3.1.k.VQ...y>....3ea.e..3{v.........i..c..y.J...v.E..#..L0s9J.n..O.g0.......A.<....).....R.....u...HbD.....)...
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.836483532839249
                                                      Encrypted:false
                                                      SSDEEP:24:bktj5dtmuBPq9UQ+MvNdDKZpbCR8Wklz16iTTDgYU88rkQVGf2L3:bklY6PqWoDDK/CR8BZvTISjf2j
                                                      MD5:A8675DC95C081644FD4D2962960ED964
                                                      SHA1:15C97EB67167400953C412F37835CC60347DAEAE
                                                      SHA-256:35758195443445E9C7926D95F5B003765674472665C2057EAA0E0E034556F764
                                                      SHA-512:5355CF8FF3CA24119298124777899DB3FCA7264E48A76F618F04A7EB436CC4F709E1BDE2E8D1CE289ECFA9D471C01E27134EEFD94F627D879A763DC937FD3A1F
                                                      Malicious:false
                                                      Preview:WANACRY!........U.2...-...n..y.t>....\......-.-...<4..#..kA 6.....KG.I.B.sw,C.2.FN...g.N..bp..$...].....{....M.)8IR..\Ez...2......#r..c.m.i.....K...U..%[.+5B.i.Qqh..C|T....L.*...;..X.R....8a..8Y.YX....-......9..g<..X..Nq.O....F.O..o...;!.....)].&/.%................).tn.$y.]....c.{.<ZM3.G..=.PWFmH.]...S.....8....^.:.Hrz.MH9.._.:K$n...JC...3...0t...-$....;]_B....SE.q=..U..,.F..g..eq...\?..Z9..p.>.8..X.L.D.......r..m.Un...+..7..B"d?........O.w..@.HH=XKv.....].B.Y..d..........EK..V...y..+?..."...@.Um....T.hw.P..o..r.P.hI........N....!k.1...O....o..I"P.x.^.xs-@..!.h.....V/j.b0.P.B......u7.s.F.h..J..aMpPD..#QG8.|}u...X$.._...<`.N.HO.W.........jt.q"(..L........2......&...@,L...s...n.R1f...AcU..r..O,s...'{..b.&.....O."....f.#M..;..J.hOF..9S2.'X..|.H.g..V.....CO..4...i.N.....g.....H~..t.X.'......|+.O..:>LU."Xo.;h.9^i..E..5.........=...3.1.k.VQ...y>....3ea.e..3{v.........i..c..y.J...v.E..#..L0s9J.n..O.g0.......A.<....).....R.....u...HbD.....)...
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.8242316070306765
                                                      Encrypted:false
                                                      SSDEEP:24:H8zRP5xjrpxYa1XwIbgsj21cJel3PQ802ekfFG9:H8zRht1acgIbgwP0Pe4k9
                                                      MD5:EBC575B3A6991CD6B742472ECE253897
                                                      SHA1:138C415DC79ADAB103AFF4519402614F855B3763
                                                      SHA-256:6F6CF4695E1ADFDE8492D2C80DC832595205727DC6598F1A23C6F711437413C7
                                                      SHA-512:10FDE4623B8AA7CEA8831C00248B78109A6E0A7EE942977CD0C27D64F6C297263977F25B34AD9D336DB98196FBF2330A8596E04407F3459A89E57AA53AA5FD29
                                                      Malicious:false
                                                      Preview:d$e.....8.-...a..._.|.5J.....1)..R...Z._..h..M!/.Y......5..Q;..h?...Si...Y.`...0.;..>.9{.~A....*.Cc.4.4R..v.....JZ%?..~...K..e/.S.O.QW)./l...P.....(.,..".8e.:Z;.Fr..|....^.[Q....H...60..sx6.'....f5..Q.i...aF.$.....@.qu.Y....b.C...K?.#.1.VO.U..>.. ...).q.@...D.....Q;.x`.....o...@2B..PE0.M.'..7 9.3..S....(kk_.E.a....h....B.L.8.`...9. Q...Da.......Y.T'.DW.kF.S..x....<}"..8...........f.U.e.....g.4..{".U.....Qa%..>.C..}.M.. .....hD.....p...A..>.^4.JW..!....Zu.....c..%.V....j........k....T...x.4.;.{..x.x....`.....>&..jS..2..T...sC......CK.]......9.H..W.._...\..>.J;....%J.X.6..2Oe..8v.cn(O...E....$..1n..I....Vx...\....R........d.?uc.i.eKD......l........'Ag>:....Tf<.....C.L.C.......2y..i.7kf....k.F...P:.J`\`..T..r.........>3%.<.....)....:1.@..&+....p;.-.^...c.v...n.b2.7.....Xp....,......m0...l.>F"rB..k9.s#.*.%-...}.m.N....U..k*.7.4B........F.......W..u.^.....c-E..'...W....s....>.H...g.v|..[Yf....]....r..g..-R.O.........j....F.*......
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.843950629598441
                                                      Encrypted:false
                                                      SSDEEP:24:bkYArbUnyixcCOG5EkkR4qY/siBa7QiCuuVK3otQFZIVO8XTYrwkrxE5jnGYIo/F:bkb0zL5EkkR4TnBKQD5ztQfoXTYrwkre
                                                      MD5:E667ED4A41372C722E424D1497B46333
                                                      SHA1:4CB4201CC1B9054FC2934425F9325909E57E4568
                                                      SHA-256:6B31904F9935D090AA85CED1A303A58DE20BBB90BBA1B087E8269CFE6D05A2CB
                                                      SHA-512:685F06E5A1AD1F8EC3F2D81FBEC02469EEF00D06888FB01D620BD51F6045762ED041E12F6CE794EA3B4135F12C3DBC7D50210BA42C9D7DEF42F249DFD6E2BCA1
                                                      Malicious:false
                                                      Preview:WANACRY!......cv..T..*...s.Y..A3..(tj.?Ko..Q}...........b.<.e...l=..t.........[.v.;...W.... ..b..9.....x.o-U.~1.u.:.cL.X.p.i1......"..G...{..*+=t.JD....h..b:Y[.3..p'Yq..y^G.Cmx-"...u...}..F/.n....[Q}MY.[.?..].....%.3g[Ep.&...*.o!...Lx?..F<.....d...-.qYb..............2.S*..z].b..:^.!..W..~......f..>..q...u.i.....A.........}E.:......K..?.3.5H Y....O..a.x'R.....S_FN.K.]y).u.7oo.........+.:M..v.....H.v)c...8.$_vA.......`..q,...3.O..: .."Z....&..|$\R.n.......*H.FW...#,..b.)~...+b_....0...s.......b....i..5 EX.].B_G......"......r+.M!f..z..........,=..F.#!...u.'.z..<..}.P.G.<k.."..n..P..$.C..gTw.+1.=.:.w..G..(ijQ.i.w....@....r. ....6..ms.B.I.bj.....fu!2V..J.4...........G.f....4x.j. #...=....0..`..f...39c.?.R.iV..d.u....`...m+.4D..o5lD.. ..._.K.UrR.p.K....zd.Q..9k.i:%..CF.}."..{..h.y.....L..D....W..'...|.I{T..j.]...t..x.=F..U..YIY.f.zTa."W.i..L.]?.O}....."..qx}...m.[..t..z.^u....-XE......d.....3...Y.&.}.... .6..........;X$Q...WU1fs....I..L
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.843950629598441
                                                      Encrypted:false
                                                      SSDEEP:24:bkYArbUnyixcCOG5EkkR4qY/siBa7QiCuuVK3otQFZIVO8XTYrwkrxE5jnGYIo/F:bkb0zL5EkkR4TnBKQD5ztQfoXTYrwkre
                                                      MD5:E667ED4A41372C722E424D1497B46333
                                                      SHA1:4CB4201CC1B9054FC2934425F9325909E57E4568
                                                      SHA-256:6B31904F9935D090AA85CED1A303A58DE20BBB90BBA1B087E8269CFE6D05A2CB
                                                      SHA-512:685F06E5A1AD1F8EC3F2D81FBEC02469EEF00D06888FB01D620BD51F6045762ED041E12F6CE794EA3B4135F12C3DBC7D50210BA42C9D7DEF42F249DFD6E2BCA1
                                                      Malicious:false
                                                      Preview:WANACRY!......cv..T..*...s.Y..A3..(tj.?Ko..Q}...........b.<.e...l=..t.........[.v.;...W.... ..b..9.....x.o-U.~1.u.:.cL.X.p.i1......"..G...{..*+=t.JD....h..b:Y[.3..p'Yq..y^G.Cmx-"...u...}..F/.n....[Q}MY.[.?..].....%.3g[Ep.&...*.o!...Lx?..F<.....d...-.qYb..............2.S*..z].b..:^.!..W..~......f..>..q...u.i.....A.........}E.:......K..?.3.5H Y....O..a.x'R.....S_FN.K.]y).u.7oo.........+.:M..v.....H.v)c...8.$_vA.......`..q,...3.O..: .."Z....&..|$\R.n.......*H.FW...#,..b.)~...+b_....0...s.......b....i..5 EX.].B_G......"......r+.M!f..z..........,=..F.#!...u.'.z..<..}.P.G.<k.."..n..P..$.C..gTw.+1.=.:.w..G..(ijQ.i.w....@....r. ....6..ms.B.I.bj.....fu!2V..J.4...........G.f....4x.j. #...=....0..`..f...39c.?.R.iV..d.u....`...m+.4D..o5lD.. ..._.K.UrR.p.K....zd.Q..9k.i:%..CF.}."..{..h.y.....L..D....W..'...|.I{T..j.]...t..x.=F..U..YIY.f.zTa."W.i..L.]?.O}....."..qx}...m.[..t..z.^u....-XE......d.....3...Y.&.}.... .6..........;X$Q...WU1fs....I..L
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.818923195073525
                                                      Encrypted:false
                                                      SSDEEP:24:ySe5p22oUpnja8SqOoA9+J3GKJgN6tc4VA4vSdR:yHulUpnjaNoAMFGKKND464vK
                                                      MD5:FD018F63563B9E432ADFF2ADB504CF3D
                                                      SHA1:5F62ECE00261D2D07EF92714B878DE96EF1B1FA8
                                                      SHA-256:6A60C0160EF1BDB64A8AC0DEB67DECD3C6DD2C94EABA4B3EA8CCD7F4E4297C83
                                                      SHA-512:492C6A633D53598FC847AE4A279D1BC52268106FDE2913BC2F5B81AD9F75CAFDFEAF3E5FBDD3E241369EA1C3AB876C0178C33676EDCDFC11DF2F338A0ECDCFE2
                                                      Malicious:false
                                                      Preview:).&...+...?.o<..w...7..s$....n^d.}........~.U-.F......@..,}Z6.b(...a.....pj......m4..i.bZ.9../...i.g...s...w.=e........#oX..6...[.. .......+...3...6#..m0..5...#d.C3...e..}.F. >Vz.E.C.B......#....x.A...K60Kz....2..0.7..H.on...b.b.*.P.'.m.;.._.... F'.......`^....,.(...^j......y.<...2N..G....Yf..SOwc.Zz..=..s..:....4.\\...+..........K1u...N&.....F..C.d&|(.q....L 7....|..........x........$.p.]....."...A.rn'l-g.G...?C...=..e...f...j.^... ....8"a...'.r!..?..q`.~E.M..V...=....W'y-.(%.....+2O....4...^Qij.B..}..@U....e.......H@...s..{.9vz.\..h.e..o.z5........9....v.....M..O..a.w..9&U..".........T..b...(0[.i..u..4......%..P..F...,.N:Z.8.Y[F.....+T%..v|v...C.z.D.y..m|mS.=...ij..l...|.O../......M.)1..h.U.=..o....^.LV.P.....!a..i..\.:M[..8_.}. 9.....m.@.J-../.e.5.'.x.,:..c+o.1BR...s.j..M.N.\...XQ h.P.....%.PJi.....=..O13..(..1....B..=..p.S\..!XnV}i+.Q..{R....-.....AX..._.v.v~Y3Y............F.Y(......&7<!...Wu._.]...d..7....D..s..X.(D^.).|/_...:..1~..X
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.847850213285894
                                                      Encrypted:false
                                                      SSDEEP:24:bkSrRvsPbD4ztqZg/WHzTbzghFz9yFr83tvMO28xyhcweGdda6uR1BQtPmo:bkQRvqbD4ztk2AzXaz9WKtvMAxHuaF14
                                                      MD5:D5863B9D764F610DD26F39B38217FF31
                                                      SHA1:EFF58D5E28F2F3B1F9A9F7D09889128C888770B9
                                                      SHA-256:04C8D87F91B98766AED782D2EFF0FFD371AFA81A67399387AA7F5F3599542C19
                                                      SHA-512:C739E42418ED4E95EDA55098869FE77D6B39A2192D44CB3EC144AA4847039D81D7D32F8FB36B05727686FE1DF66C796167E8F3FA4568FD59248F65D25A191D2C
                                                      Malicious:false
                                                      Preview:WANACRY!.........-.=.j...7.G@k}.<y.>q;.0.i..c.Q.!HN.5.*... #.....4.V.Y1.@E.=`A.U...s.w..E.g.!..e)...).....[.....Tt;..0.."...#H.v.C.+..v.:.. .*%.....H....E'...$U..Y<.W=...Il......2...~..(.!.~|...HA.c......=..O.6...f..jv..S.......o(..N.|....7.x.}.Z..'[..l..W..............?.6..W..]..S1'..........#J/7^.9..........M.....D...hNl.....N..[.Ey...~.#.-O..UtKT.@.EF..=..C....~.0...,.....A[.#g(.Fl:"k..d.$=...b0..o.t~e..)*rm|.....[..l|.".......~....B..4%.....y.9F.BKr..[g..Vt../N..PK.V.^S...^.u....65..P.Ed..W..5.....t..<...V..~.rz[.s......P....'.\nh..T...g.b..2..^.{....ux......iEO.....ji#/we:C..B.b$.Z5....3../...x.*M..|.]Q...I%.K....#>f.....>.HJ.....7...@|.h.......K.dwVUc9....%6...\.....5t..Yp*.../..^}.S......J...k....t/a4{.$g..6.fuO3ky........&.A.....M.aG.....=.:B..{f./.=D.....g=.....zp...v.60/..v..d.?.B.......s..s....|.2..6"Jz.w.v.&&f.92..d.....]..".........{.y..$..-;*l...[.&.]..WJ....!p.R.z[.mh...y+U5a.k....o.y....{..AP.......'b.x.......L.]x>.k.b..Y..
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.847850213285894
                                                      Encrypted:false
                                                      SSDEEP:24:bkSrRvsPbD4ztqZg/WHzTbzghFz9yFr83tvMO28xyhcweGdda6uR1BQtPmo:bkQRvqbD4ztk2AzXaz9WKtvMAxHuaF14
                                                      MD5:D5863B9D764F610DD26F39B38217FF31
                                                      SHA1:EFF58D5E28F2F3B1F9A9F7D09889128C888770B9
                                                      SHA-256:04C8D87F91B98766AED782D2EFF0FFD371AFA81A67399387AA7F5F3599542C19
                                                      SHA-512:C739E42418ED4E95EDA55098869FE77D6B39A2192D44CB3EC144AA4847039D81D7D32F8FB36B05727686FE1DF66C796167E8F3FA4568FD59248F65D25A191D2C
                                                      Malicious:false
                                                      Preview:WANACRY!.........-.=.j...7.G@k}.<y.>q;.0.i..c.Q.!HN.5.*... #.....4.V.Y1.@E.=`A.U...s.w..E.g.!..e)...).....[.....Tt;..0.."...#H.v.C.+..v.:.. .*%.....H....E'...$U..Y<.W=...Il......2...~..(.!.~|...HA.c......=..O.6...f..jv..S.......o(..N.|....7.x.}.Z..'[..l..W..............?.6..W..]..S1'..........#J/7^.9..........M.....D...hNl.....N..[.Ey...~.#.-O..UtKT.@.EF..=..C....~.0...,.....A[.#g(.Fl:"k..d.$=...b0..o.t~e..)*rm|.....[..l|.".......~....B..4%.....y.9F.BKr..[g..Vt../N..PK.V.^S...^.u....65..P.Ed..W..5.....t..<...V..~.rz[.s......P....'.\nh..T...g.b..2..^.{....ux......iEO.....ji#/we:C..B.b$.Z5....3../...x.*M..|.]Q...I%.K....#>f.....>.HJ.....7...@|.h.......K.dwVUc9....%6...\.....5t..Yp*.../..^}.S......J...k....t/a4{.$g..6.fuO3ky........&.A.....M.aG.....=.:B..{f./.=D.....g=.....zp...v.60/..v..d.?.B.......s..s....|.2..6"Jz.w.v.&&f.92..d.....]..".........{.y..$..-;*l...[.&.]..WJ....!p.R.z[.mh...y+U5a.k....o.y....{..AP.......'b.x.......L.]x>.k.b..Y..
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.781069475573988
                                                      Encrypted:false
                                                      SSDEEP:24:1VS7YFmCfQ2E0hUYJKlFNalTQn8ktgsZViwh5SHLX0E9Nrx7jKLz0:nrmCNE0h/rTQn8ktgTwhOwE9z6/0
                                                      MD5:9C2683F84E85F0025B9975A94F1EBA81
                                                      SHA1:DA522A08C3C39CD25FC06BCA72E78CA9BF57D929
                                                      SHA-256:57A48D48FF3F1127C9D5A9EEEC8FEB996F0EC9DF541ED8A36BA1E80018C0A678
                                                      SHA-512:F272B21A95091DF267C0E2E4736789FF99A83E436701A563B675956E11BAD06FE01B00138D4CFE3AA9C6297350EF86A4A5F4C030A01C9FB50C1C99FF84B51747
                                                      Malicious:false
                                                      Preview:lC...).%]...........,D..d..3s..j<.5.}...~...e{B...6.:.."-./.g....U.rA..a.%S.2...........@r..b......-..8...n".)..`..8.0.^<...I.....y..H...._...|U..l..]..;........<...y{....@.q..B.`.gT.1.0".....o.*%F....m(.......sE...m_.+.D.q.....lq..+9.t......,.[.Fx.....t...........(.7}.f6.P6............k..u...0E.._wV.f......I..|.e..D'...TG.C....`.Z..bm|GfC......o.kX...n..a2.#....!...!9F]"a.[..r.'&......y...4.3.p.RU..mu....../e..+...%.......l.......l0X.o...e.."._....r[.6.`o.MT.q..<.}.......Q...i.}.+I.W.O.u...S!nDg.".....|.Z4F.:..j..]..L.w..X.Y.*...p.&.......T...DGIc..v5Q..d...w.|......a.....K.B..7....o..}..>.%_L...f.PX.d.w.\...}x..&4.N.9K...........p.5w.d...7.q^..7.....{.2...\.....X........Qs.,D:.7..r....,.Y..Y....e..KA.....z....O..".:.H..9......!.~..........L.\.......Fp1.}....I.s....c.X..w..f.e:.o.}..+...t.|\.]T.......)..L(.B..\....:?.....)L.j.....s.X....%.s..$......tS..ZKkP...W...wZ...k.....]..c...x,gP.....u....D..:..,..q.lB....qf........e.E......Mq.....
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.845702227649035
                                                      Encrypted:false
                                                      SSDEEP:24:bkfb6mTFRJJA8fhzG1+zhySdtGfCC0i4XYd1lsQvAJ9KqMes+:bkzh/JhRoUGZqod1KAAjs+
                                                      MD5:6F11D51E40C1DA5A57F951ADEB7BDDC2
                                                      SHA1:C0947C09DDCA609ED3D78B80447C798D9720DFFB
                                                      SHA-256:C62275C0C13EBBB50D6BAD4527A5879C18462BCA3A5282FC61A971168DB9E537
                                                      SHA-512:4DF7D03CA19DA8C57718B554E5A7E999532C294EED1FDB487584BE4A2C031EE343AD4D6BFC3003A7C4EDE715F75FA9CF8E5F9840DB3D7FD563BCDD22D68B2BA7
                                                      Malicious:false
                                                      Preview:WANACRY!.....g=...c.9...7(.."$....U..1o{.%...xd...(wd.....*.B......h/.....,..:...r.|Q..s..Alc.;....v.F...l.pWP~.&.U....|.2.B..K.....U..Z..v.'.d.H)...x`jCx.g.s..U.C..^.'b.:Y..Gn.......u.S@.....J8.j...|/..9.[_....,#.....f..=..q.f..W..!j..;..vBA....D.:OJ..|.....&.............Y#...XJ...#.i..~....|.....q.d.C...<%.W.Cb....J=..F|8f:...... m........?.....N...V.3+.P.UF8A.....+9...N.|..-.l...#.J.._..x.@L............\...2.D8.._......5X...?..m8...Y.N6...b.>.&..`..,..].{.........+.aL....@.5...9n...:.{..:/hv.F...E{...Io4.._)`9..(..~.4d.....s+..jO. ...Bs`Z.....%.....,.......6_..e.I.W.2O...I..]v..<y/....^..Rk%O.Ip....*....NP......Q.Y../|... ...M.C.%.....q+..c..b`..v...........0..q.R.A>..Y(n.s2q...g..:I.x.7......P..r.d.z....9.*..G.._}..L..j".K..VxU...V8..9..O.\.nZ'.V.^..g+xo.....C...WP.Gt&<~q.0..r...*z@=..:..rA'|..nxI..zN.?....../....?.DjP....?..}:.U..Ey.....a.-4.jlm..Y...x..@..9..N.?.a=.h.....'.o..s..j)...3wb.#o..i...._.J2.].^..:*.....d'.....S..&e..;v..{.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.845702227649035
                                                      Encrypted:false
                                                      SSDEEP:24:bkfb6mTFRJJA8fhzG1+zhySdtGfCC0i4XYd1lsQvAJ9KqMes+:bkzh/JhRoUGZqod1KAAjs+
                                                      MD5:6F11D51E40C1DA5A57F951ADEB7BDDC2
                                                      SHA1:C0947C09DDCA609ED3D78B80447C798D9720DFFB
                                                      SHA-256:C62275C0C13EBBB50D6BAD4527A5879C18462BCA3A5282FC61A971168DB9E537
                                                      SHA-512:4DF7D03CA19DA8C57718B554E5A7E999532C294EED1FDB487584BE4A2C031EE343AD4D6BFC3003A7C4EDE715F75FA9CF8E5F9840DB3D7FD563BCDD22D68B2BA7
                                                      Malicious:false
                                                      Preview:WANACRY!.....g=...c.9...7(.."$....U..1o{.%...xd...(wd.....*.B......h/.....,..:...r.|Q..s..Alc.;....v.F...l.pWP~.&.U....|.2.B..K.....U..Z..v.'.d.H)...x`jCx.g.s..U.C..^.'b.:Y..Gn.......u.S@.....J8.j...|/..9.[_....,#.....f..=..q.f..W..!j..;..vBA....D.:OJ..|.....&.............Y#...XJ...#.i..~....|.....q.d.C...<%.W.Cb....J=..F|8f:...... m........?.....N...V.3+.P.UF8A.....+9...N.|..-.l...#.J.._..x.@L............\...2.D8.._......5X...?..m8...Y.N6...b.>.&..`..,..].{.........+.aL....@.5...9n...:.{..:/hv.F...E{...Io4.._)`9..(..~.4d.....s+..jO. ...Bs`Z.....%.....,.......6_..e.I.W.2O...I..]v..<y/....^..Rk%O.Ip....*....NP......Q.Y../|... ...M.C.%.....q+..c..b`..v...........0..q.R.A>..Y(n.s2q...g..:I.x.7......P..r.d.z....9.*..G.._}..L..j".K..VxU...V8..9..O.\.nZ'.V.^..g+xo.....C...WP.Gt&<~q.0..r...*z@=..:..rA'|..nxI..zN.?....../....?.DjP....?..}:.U..Ey.....a.-4.jlm..Y...x..@..9..N.?.a=.h.....'.o..s..j)...3wb.#o..i...._.J2.].^..:*.....d'.....S..&e..;v..{.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.805430836436896
                                                      Encrypted:false
                                                      SSDEEP:12:E6CLkdEZZ8oSyZMZMukQcYFAf8Q8scSbrtJmZzVKURePH3nkaCQloihoQMLC/j+Z:VCLEUvvH1JmhV9RePXnk78ZMLUYfR9
                                                      MD5:091DF7A5876B7E9134657150FD5BBDF5
                                                      SHA1:3CFEC0C1D04934DD803383657075D7FAC53C70BA
                                                      SHA-256:379DFE8B016E4A17F7F213AE7D6769F746208A8387F921E8EE595BB9EBBFB4A5
                                                      SHA-512:AF69B41D1B362217CDE3CB792FD79B6B495F4456AF1B4F298BEF7988C3696997CD67B7991398BFD02F3155FB0BF06D08710EFE772D7924FF4C9B51C8C47A2F58
                                                      Malicious:true
                                                      Preview:0..$.90.S.,.c........".".......7;..HD.....4....-...}.L..Jo..p......Wi.0..H`..O.....L .v7.R.#I5a.j.....A....$ .......3..,`<$"...b..N..w2R.e..1B./O.....1.i..%}........G..t...!H......[........2...W...P..$..?........".J..A.....{.@.9./...v.A.....v De...8U.K.HzMW...WqR{O.;(.6.'... Q.....Mq....d.?....]S...L..YUx..}.5...|.......}zr.S.....u*.&=.s..s... ?DT...J./.....d..P.6...:+....F"..J.L....mHt&.x.\.....]..6..7.Y.>.qT.r)~.+..5...l._i.j..d... ...V0...@..........=........$.@.W.}N..h\..!9o.R..4...8.@...,..w.p..`G\...KR.........#].....n;.|....qD...x.U....%..4.?Y.?2.Q.r.....Vx.z...(.>s......Y..b.,qvC3..)zix....z...t.Q.8p.U)...[D.../ZI.9.xt.@.;!!A.....H.)...d...g...TFe*..+...o...6k.X.......@...................&3(....I;.%.}5Q.M.J.0.@..P.+...=....L.6...v..0...S...p .U..xT.."......_...#.....%1"[.G.9:.. .T.@...?...C.hb.D.....S=F2...Ks...f.).|.w...[..Y.<..De..^6y.........W..>s.......B.......Z......."I....U.....t...J@..s..#.f...!m.^...=..Y.+`....|\.f
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.8502205370807365
                                                      Encrypted:false
                                                      SSDEEP:24:bkM7Eard8KMS4M8I5YIEimwyErcLPHK20rsnWkIEkdy9XhnllEDBorjpIWgTFF:bkkEa3MtIOQcLPHK2rWkIE2y91llE8IV
                                                      MD5:16DE6E7E921DA6D69C2552543B3A0884
                                                      SHA1:D5F4FEBC116D89855C1782ECCBF9553E4461332C
                                                      SHA-256:D79354B09753A430E94B9391065D16560A5BEA4C5473E3160593B89D71609146
                                                      SHA-512:38BC66D5CB1C1C6B0E16DBF054B8015D328EECC2E7725C32AFC184B831601C7DBA9F8507F7D81174205158771832EC096C3B505D651E1E1AA06DCC67FC4DBACE
                                                      Malicious:false
                                                      Preview:WANACRY!.............:....yy.....*.V4.t.BL3..8./..&.p[9.q...p.h..+Q..m.t..H.....n...W......mOE...-..+..J.-9k.$!`)N....U,.....j..DH..........3=qi%c..8.#....)...C.y.a..+b..D.:.....p..&...&.H.Pl(...01.z:[.+.kV.k.....2.l..1.N....^...F .....V?,,..r....E|S*I..............-.......q......-.a.R..._*....K.c..^.|NC.q...{.. ].P#]..#.)...#d..zY..=r..u...t..^........*..r_...Y..`....*...b...(.....B..S...X#%...k..'...TD...g4..VZi.v...Q....g._B..z._./55'..O..V...?.,..df8k.7..8.m...!.j..L..._.L....z..A....h.]...SEw.>>....<42..K.....Mf....F2.Ziq\'.L.7.:}#M1.a...".)j.u...K.o...J.....b.w_...[.hC.`......... .-..%8c...J&....E...1$....7`......Dic..a......Ky_....5r\.........|..3[f[.xAO?).#./U...'.D.g+..A.........Ti.FH?N....no..o..n..^$.o...~.q.`..H.Y..C".s...h.PF>...2f..tC.W... ..VV!.o...}....&.OP5.\.5..n.........>....:Irkp.1.g........1..T...s..Y..#.z^...;....6Z#8..._.....pl....8J.._..3.~..w(.q....D..L..P....8.j.13O..K.d3Y.<....lT.T.kg.b.}.p.2.a&..u.e.(40V
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.8502205370807365
                                                      Encrypted:false
                                                      SSDEEP:24:bkM7Eard8KMS4M8I5YIEimwyErcLPHK20rsnWkIEkdy9XhnllEDBorjpIWgTFF:bkkEa3MtIOQcLPHK2rWkIE2y91llE8IV
                                                      MD5:16DE6E7E921DA6D69C2552543B3A0884
                                                      SHA1:D5F4FEBC116D89855C1782ECCBF9553E4461332C
                                                      SHA-256:D79354B09753A430E94B9391065D16560A5BEA4C5473E3160593B89D71609146
                                                      SHA-512:38BC66D5CB1C1C6B0E16DBF054B8015D328EECC2E7725C32AFC184B831601C7DBA9F8507F7D81174205158771832EC096C3B505D651E1E1AA06DCC67FC4DBACE
                                                      Malicious:false
                                                      Preview:WANACRY!.............:....yy.....*.V4.t.BL3..8./..&.p[9.q...p.h..+Q..m.t..H.....n...W......mOE...-..+..J.-9k.$!`)N....U,.....j..DH..........3=qi%c..8.#....)...C.y.a..+b..D.:.....p..&...&.H.Pl(...01.z:[.+.kV.k.....2.l..1.N....^...F .....V?,,..r....E|S*I..............-.......q......-.a.R..._*....K.c..^.|NC.q...{.. ].P#]..#.)...#d..zY..=r..u...t..^........*..r_...Y..`....*...b...(.....B..S...X#%...k..'...TD...g4..VZi.v...Q....g._B..z._./55'..O..V...?.,..df8k.7..8.m...!.j..L..._.L....z..A....h.]...SEw.>>....<42..K.....Mf....F2.Ziq\'.L.7.:}#M1.a...".)j.u...K.o...J.....b.w_...[.hC.`......... .-..%8c...J&....E...1$....7`......Dic..a......Ky_....5r\.........|..3[f[.xAO?).#./U...'.D.g+..A.........Ti.FH?N....no..o..n..^$.o...~.q.`..H.Y..C".s...h.PF>...2f..tC.W... ..VV!.o...}....&.OP5.\.5..n.........>....:Irkp.1.g........1..T...s..Y..#.z^...;....6Z#8..._.....pl....8J.._..3.~..w(.q....D..L..P....8.j.13O..K.d3Y.<....lT.T.kg.b.}.p.2.a&..u.e.(40V
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.808791917570398
                                                      Encrypted:false
                                                      SSDEEP:24:c4aOeTiSb8nbueCGBIaYGl3ALGoTKChzhOVdmS:chDMuEIaYFLGJCegS
                                                      MD5:A5B1844D831C734D22CD1A89ECCBD66E
                                                      SHA1:2F952E85DD3262C5CFDC4D8292BCE7F8C0CFACF0
                                                      SHA-256:998A953443BB40BE585AAEA08F53AE2C38E57B00E702138FA1AD1B338E6F2AD7
                                                      SHA-512:59F575A5E9441F9C5BC7A64E46AB4D4F3E3A876F85907CE7C264799A84221A3C5FEF1B47D90964443CE528FC8EC2A9566A7AC7C07EAA257246CDA1BA53C554B9
                                                      Malicious:false
                                                      Preview:.....*....3.....><.jM..O..........._..H...2.^_ ..r=.%.*.ty..c......l.N......[.#.J.e#...,."N...T..O.N....{..@....b.....ip .D. q..E.\...m.....a-..y...i.QL.;..}.0.m....X.M.j....G..opa...c6.H...\K..4 .p.....(#....I..s6..o....5.....!..R...G...6c3..*....v#....2...$/.v.,QZx..>.|z.!...v..A$....E..=`.!+.X......}_6..S.3.9..fz...HUX..]...M..Z...D..Jc'.#.../&2#.a....]...L...Q.u....G.1.~.7..A.$...x0...Y...&6.<...Iz$...l.qJ$ mqi...!{f."&$%s[.o......1D*%x.....<.w7.b...\..E.N9u..I..P..D..,.8...u?.+c.@K...@#..Nd...O...%...N 1.+.s.....Oq.8..'..4...t..p}.L%,..m...p.b..}..4../BC.6s..bg.i@~...X..........+.....T...R..d..g........W....6...B!........X...z&9 ..aJ...q..K...D..9..B......@...1I..a...Jh.0.u!.c\4.D.....m`FZY.....qU.3...."...Y.:b...{.^..+...Q%,.>H.k.K...k\.)Z..DY.7E.w.....uW......<W..&.1.....].......k.......0.@>.|.....l..$..'.....O...i..2L....+.e.R.C)@;."[{....HD....k..H.,.>.5...tm..p..W.x..U....X.....^.......uE...K.^..pD>.O.<M..0.gB.'..:'..;..o
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.858037744234115
                                                      Encrypted:false
                                                      SSDEEP:24:bkqdnage4RUjSCSSGxfB0eE6k3LQcsO6UCsJcNgjlxJQfP9CRcp+Slq+pO:bkq0gnRvDJhEPrOtsJhjlxJgP9Hmx
                                                      MD5:6AB3E3016125703B6F380BDF343AA5FE
                                                      SHA1:1FE847D586DF7B1309980A70E43ABF15159A1127
                                                      SHA-256:B84E32CCF3BA3CCDE7D6FAF2F5B859A146F8F68B97FD1EBBD79AF411C413EB64
                                                      SHA-512:56B066E6BAE5C2F2E1723B1F72C4880DC08A7024B071FD8FCA1A733B53F9BAF6A066C50403C8AC6AFBBC46BCA5DD489DB4EC25F91CA854C83D500B55ACFB2D38
                                                      Malicious:false
                                                      Preview:WANACRY!....].^....*...,.;%k[P.9....c.G....;....<......D..4.k..2.a.n..8.q..p.|J..F|.jA.%..Zx..].<1..$.9,......._h........@.]Y!.o.VW.....w........K..%U.A....M..%r..Q.E.w.....{........UD{.q....6..|2%.9V....u..(HX.0_E.(.].22..VR..y..U.}..,..t.../.oe\$>./..............EO.l.!...@..e.7....U&.J....W.JA.`...8#..m..*.ab....|R!..W.[..e&..@.q\............%...'...2"...a .J.^...6....2..)..^.....,.;).c..Ta...p.m.1h2 .sm.....<..{.L...1.Y..5</...E.....Vi.6.+..?...t~...T..6a...q..1....=....}%gr..uIc..&..b...:......l....o{...C..0..R...7i....v....c.0A..v..8b..f........$..>....d7...u..../z...D.n..Z.6u).r....C..w<|...Z?.K.U....../.m...Q|$..Bm..5.xR#.)&><#..z3C...+..y........E...i.u..........,...Z.4V|....z...9.-[.o..P.L_>0.3..?..=E........j...;.6+^.@=l/...i.L3..hi..R.. i..g.^........0:.....0.......(......H.P..g.#.UEd.h...N?.Ku...J.a.0Z..~o....-..g....d....6...N...R6....nivu...L....)w..a..#...o....].m.[p..2uA.............,)W..c...z..QP.y..q...+
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.858037744234115
                                                      Encrypted:false
                                                      SSDEEP:24:bkqdnage4RUjSCSSGxfB0eE6k3LQcsO6UCsJcNgjlxJQfP9CRcp+Slq+pO:bkq0gnRvDJhEPrOtsJhjlxJgP9Hmx
                                                      MD5:6AB3E3016125703B6F380BDF343AA5FE
                                                      SHA1:1FE847D586DF7B1309980A70E43ABF15159A1127
                                                      SHA-256:B84E32CCF3BA3CCDE7D6FAF2F5B859A146F8F68B97FD1EBBD79AF411C413EB64
                                                      SHA-512:56B066E6BAE5C2F2E1723B1F72C4880DC08A7024B071FD8FCA1A733B53F9BAF6A066C50403C8AC6AFBBC46BCA5DD489DB4EC25F91CA854C83D500B55ACFB2D38
                                                      Malicious:false
                                                      Preview:WANACRY!....].^....*...,.;%k[P.9....c.G....;....<......D..4.k..2.a.n..8.q..p.|J..F|.jA.%..Zx..].<1..$.9,......._h........@.]Y!.o.VW.....w........K..%U.A....M..%r..Q.E.w.....{........UD{.q....6..|2%.9V....u..(HX.0_E.(.].22..VR..y..U.}..,..t.../.oe\$>./..............EO.l.!...@..e.7....U&.J....W.JA.`...8#..m..*.ab....|R!..W.[..e&..@.q\............%...'...2"...a .J.^...6....2..)..^.....,.;).c..Ta...p.m.1h2 .sm.....<..{.L...1.Y..5</...E.....Vi.6.+..?...t~...T..6a...q..1....=....}%gr..uIc..&..b...:......l....o{...C..0..R...7i....v....c.0A..v..8b..f........$..>....d7...u..../z...D.n..Z.6u).r....C..w<|...Z?.K.U....../.m...Q|$..Bm..5.xR#.)&><#..z3C...+..y........E...i.u..........,...Z.4V|....z...9.-[.o..P.L_>0.3..?..=E........j...;.6+^.@=l/...i.L3..hi..R.. i..g.^........0:.....0.......(......H.P..g.#.UEd.h...N?.Ku...J.a.0Z..~o....-..g....d....6...N...R6....nivu...L....)w..a..#...o....].m.[p..2uA.............,)W..c...z..QP.y..q...+
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.804431931801906
                                                      Encrypted:false
                                                      SSDEEP:24:L1FmtQRWoMcQO8TlSQEXERqUwzEsY0dCzi+DP5AvSl:h9jpqkQEXQqHzrGAk
                                                      MD5:8E2DC5BE6258C5EEED7269734259093B
                                                      SHA1:2418F12E3A15E1D36905443BD18CFAFAB20F0E7C
                                                      SHA-256:7DAC53012EB93490C682FD68A80D52FC7F2F0BD174EA2D0AE8A4DC07851BD00D
                                                      SHA-512:BD4A6DB8E3426570F74E852FFE198455061280B6DC49509F2982D4A25C1DC57AA1CBDF216DA039B19A655B29FE0C141CE5FB4F60B4B9036CDAA1FFDE9578BEC2
                                                      Malicious:false
                                                      Preview:cA..+........j.x......z$u.?.]<..........t.....&.w=..!3.B.L.RB..@.,..dE.`..........vM..}e.`Uo.D..S....Q...[*....J..oR..7.fc..YO...e..F.....$..(....`.GY..&...H..d..v.;5...b..u.fK....^.c.....8*J..TR7?.[.AW....%9.......<.(....8,....."....I...nqz....}3$.&"Q{.$b..^oy..y.5..Nv...a....o-$....t[O:?..|$.z4...I.fa........V.LQ...ga.......'lr>...k.h......E.M>..a>}..8.{U..`.....h...vX..._."..C6......W..<|..wm\..*c.GU...._b....=.FKk...A.RU....L....2..Tg.`y....~.B..EG..ffN.s..d.P@d8e.1&...~6.....|...T.].-K.B`..|.(..y...S.Q..)..^.........F....M......Q&..>....E...N...*5.M:C./....7[:.Ic...X......T..:.....e....|.......XO.x...}..L....XT...V.5..^...q.5..c.........k...Z.CA..........}...^...33Ge?}.7.\.w...a.)HN.R.|..{...+...}.m...3"...aD`.Qc.,.j....\k..wP-......{{...-..f1..o.....s..x}.&I.q`.......5T...u1l8*E....vP*.....^..Q^.:...=..R..E...r.7..,..C?..Z7.;-.mg..{...a..\\...:.){.....BP(.Y.m...$..So....B..g.6:l....N.hb..T/.E.2"..u..B.............
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.850747026087457
                                                      Encrypted:false
                                                      SSDEEP:24:bkEDKOGFLroUBsv9b5zDUQCD0Ulj4mPSQhFb6X/OJIAKEI4QO2f9F6rI7OH77stt:bkEDt0oUSv9VvHYUs42KTVO21FAIqH7K
                                                      MD5:1893491E8A1871320E77F2DB38B01919
                                                      SHA1:A4CA8EDAA744401CE3CBC31E030DAE666DC64367
                                                      SHA-256:4EC59753F512CF3EB6BB28D04E49D3A306217787B31C742C86CB30FBCCB75C9C
                                                      SHA-512:A574B3EF28F57F9B73B8812693B6732C29140A1339D7554973AC88AD685C9764EABE7A7C847CC978D46C462954E9D440B72BE1DF6F0C5B6F801677F88706BFA3
                                                      Malicious:false
                                                      Preview:WANACRY!....iv1.:....SH..5...Z.y .I.fI.>^.....a'>{...A..tY.E..........UE.d:-.Y.^.q.Q....tE.q3..X.*i.C.A.^Jxv....${.yDo..2./....*.4...v......b'{.u.....,.b..{....d$T:.a?..........h.....[..OA5...Sc......E..h..ju#.y.....n.Rd..y....@..5o...2U;'(4...F.x....[..f................_.`.I!m.....d...S.'$7.........Dh.>..O..g,...q...l...o.M...\Bg..5v.4e.....n..f*..4....._.+{.,3..0.......`..Z.l.{.....*..Xi.4.]U..cFs..OY..2.O._k.......<b./6$.L<...?.i.~.Yb......+j.)h.8.....#^..P.5...a..@x.01..<h.r$~.U=t.BW~>1I...._J...}.Q...H..n.{.f....Zx..K\EQ.....r..b..(....FdV.!I....{L..o.=A8B.....!F..H...V &.[...0y"e.>A{.&...2.aXDhZ.. .A=.|T..".3...z.....m.#.....l..T..C.;....uN.m...s`.3K..l....o....|D.;...3...Q[^f.gw..2..v.....c.WLQV.~b.nv..oUF.....4..Z..1.j.|.G.T.'............].-....Q.....xa..v...*q...my....W!%].6p...Q7.5^..L.....86...!.3.{R...jH}{....s[>.Y$.......1.....=+W]).~.......?......1.ab.p,..X.99CUG2.....k...P....N.....c....^.._m'I........`<8G.."#.v.N.....;....c...6.'..uE.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.850747026087457
                                                      Encrypted:false
                                                      SSDEEP:24:bkEDKOGFLroUBsv9b5zDUQCD0Ulj4mPSQhFb6X/OJIAKEI4QO2f9F6rI7OH77stt:bkEDt0oUSv9VvHYUs42KTVO21FAIqH7K
                                                      MD5:1893491E8A1871320E77F2DB38B01919
                                                      SHA1:A4CA8EDAA744401CE3CBC31E030DAE666DC64367
                                                      SHA-256:4EC59753F512CF3EB6BB28D04E49D3A306217787B31C742C86CB30FBCCB75C9C
                                                      SHA-512:A574B3EF28F57F9B73B8812693B6732C29140A1339D7554973AC88AD685C9764EABE7A7C847CC978D46C462954E9D440B72BE1DF6F0C5B6F801677F88706BFA3
                                                      Malicious:false
                                                      Preview:WANACRY!....iv1.:....SH..5...Z.y .I.fI.>^.....a'>{...A..tY.E..........UE.d:-.Y.^.q.Q....tE.q3..X.*i.C.A.^Jxv....${.yDo..2./....*.4...v......b'{.u.....,.b..{....d$T:.a?..........h.....[..OA5...Sc......E..h..ju#.y.....n.Rd..y....@..5o...2U;'(4...F.x....[..f................_.`.I!m.....d...S.'$7.........Dh.>..O..g,...q...l...o.M...\Bg..5v.4e.....n..f*..4....._.+{.,3..0.......`..Z.l.{.....*..Xi.4.]U..cFs..OY..2.O._k.......<b./6$.L<...?.i.~.Yb......+j.)h.8.....#^..P.5...a..@x.01..<h.r$~.U=t.BW~>1I...._J...}.Q...H..n.{.f....Zx..K\EQ.....r..b..(....FdV.!I....{L..o.=A8B.....!F..H...V &.[...0y"e.>A{.&...2.aXDhZ.. .A=.|T..".3...z.....m.#.....l..T..C.;....uN.m...s`.3K..l....o....|D.;...3...Q[^f.gw..2..v.....c.WLQV.~b.nv..oUF.....4..Z..1.j.|.G.T.'............].-....Q.....xa..v...*q...my....W!%].6p...Q7.5^..L.....86...!.3.{R...jH}{....s[>.Y$.......1.....=+W]).~.......?......1.ab.p,..X.99CUG2.....k...P....N.....c....^.._m'I........`<8G.."#.v.N.....;....c...6.'..uE.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.811734626976156
                                                      Encrypted:false
                                                      SSDEEP:24:oNKCIhdJgnweAXMIsr7VTQmwlTkDk5wwIyhr:zRrJgnweGMIslUT6KwwTr
                                                      MD5:052CE1C15EC2E0170596DBBEAC543535
                                                      SHA1:34089896DE94565C0A36D82EA286A882913EDCEB
                                                      SHA-256:54B0376043AAADCE4E484DE56E198F78289FE20E095117DA6726EC29BF635B4C
                                                      SHA-512:A9CFFAFB0B431BFF1D3D40A29533550223834646950CE7125B6ED3D2B6F579496DE1C7920660C2E2A775B546D8B201457A1791C13482A8A49FD54EDA4C1CE617
                                                      Malicious:false
                                                      Preview:iT.d.`U....s.U..N... ...I!.<. !..0.3Z.u..v...\i]...C.L.*Q........b7.....=..U..,...R..T..re. .4lfO...^?o..m7.qF......+..*r...j.....".<...s~.,..g.).!.4..C.F..U}...c?.7...U8....a.}.u.i!.........e7.....-.L...Oa6..g......V..0Y....@.7..ft^.......x....n..?p....4^f9.MD.?Q./..2..k...j.e...Z.x.D..]...t.%WH|.-.2..[...N...o.....p......!..W...f.1..w...+......HRl.{U....w......\5.}F.U..$Q....8].x!...<0...5.....{.7v~...H......"Ma-.....[S........I..\.U.w......Z...j...`..B.}..Ui>..........*..KF.O..@...:...(...&......_,j.Ti..p!.T...ex........CU...].<..2/.. .-.}#6Q.[w..^......P$.h... ..rV...jJA.......V9.....5q~Na.4x)1.u...'..dg.R.=.Ck.W..OGK..`....X.51.g..G7j,.l.A....h..^.(..r.^O.p.N....'..}.....v...."...+...T)..[H7|W.sZ........s..c..Pw'.@f..W$.z..%h.'.O0.!.......#.Q.3Xn).t..z..^{.O.:)..<.U...%.c=.OHx....U...,....E.sx..y*v>B..pX.4..uoD:.?%k7..J@gvEK... .._..s.. .8.....n.....:.V.b.z.WGs..-u^..au.j..D...A.....a..j...:1..lk..#....t.Qg..8..mY
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.834771580270793
                                                      Encrypted:false
                                                      SSDEEP:24:bk6lQBLL2tk00g4CD6zUu4mxqBweEqZIOs+gtB8fLKhwuZADVOgo:bk8Q9LKk0h4CGzUuPqtEqZ8+zBD0go
                                                      MD5:706655E357D3AF4CEA68771168AD2AC1
                                                      SHA1:540DF34F5F22742B93285EB47AC72A11AFFAAFBE
                                                      SHA-256:77B1853AE46598BEEAC58318B46BA9A459404F58A8548244A229B740AD23FAD7
                                                      SHA-512:C11FEF6E7F4213FCB928523EE8BC2CC95BCF997119A7918798CFC947B53F25D3DD7ACDAFC84C1488A5E9CDED48190CE7748AF20136E5C5DEFD7AA611D1C13585
                                                      Malicious:false
                                                      Preview:WANACRY!....<.*.+.p.'..i...e.F......t...B.Z...?......l?.....w.Ha.O58.=_Uv...C..I.;4..&....!....D.`.Y..+.Ul.1R.........H...k..h_..C=H#...2!$./.].....9...>.t<>.t.>,.aO..,y;.h.r..e...hmi..F../..;.#....(..L.....=..U.@...2<..*n?...,.@A...pM....x..{..<.U..............).|.k.~..{.U.7.X.".....u.u..;..b ...5...r..:..{.....I....2.........n#.p..i....m|....<...Kp.E..su..1.....v3.9p.Kj.q.8>0.%.nG8...S.d'2..A....qbj...r....".u....8...r..[........5.....#..Z.Wy..!..L.....X.....X.7J........1..X=.m2.hh`.1..DD.-O..7.F.......A."!....'..7d...F....t}.yL...g..>...y..D._..Ue........\...._..%.Z|...t..j...,...b.L..5.+y,a.Cv^gt(_.+JC.z....rv...i.V.|......M...]!.-......R.8.s.&..>9Q9!O.0...4j..2..R.y[GQvq8#....*.@y.bN]..7cCt3u...Y...ne..`{..s...)l.s.g.d....b;...3;$....'..z3.S..f...F.a..:......\.9.C.T.L9.....1H.:.......(..x+ST....0....ch..g....NBxB..W=!.....N...A.o.!v...5w.4i...:rM.@9...a....s.......a..1..#..{..5*&..i..........8j...N...;....8.k..q'.8.r..=.8t..I.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.834771580270793
                                                      Encrypted:false
                                                      SSDEEP:24:bk6lQBLL2tk00g4CD6zUu4mxqBweEqZIOs+gtB8fLKhwuZADVOgo:bk8Q9LKk0h4CGzUuPqtEqZ8+zBD0go
                                                      MD5:706655E357D3AF4CEA68771168AD2AC1
                                                      SHA1:540DF34F5F22742B93285EB47AC72A11AFFAAFBE
                                                      SHA-256:77B1853AE46598BEEAC58318B46BA9A459404F58A8548244A229B740AD23FAD7
                                                      SHA-512:C11FEF6E7F4213FCB928523EE8BC2CC95BCF997119A7918798CFC947B53F25D3DD7ACDAFC84C1488A5E9CDED48190CE7748AF20136E5C5DEFD7AA611D1C13585
                                                      Malicious:false
                                                      Preview:WANACRY!....<.*.+.p.'..i...e.F......t...B.Z...?......l?.....w.Ha.O58.=_Uv...C..I.;4..&....!....D.`.Y..+.Ul.1R.........H...k..h_..C=H#...2!$./.].....9...>.t<>.t.>,.aO..,y;.h.r..e...hmi..F../..;.#....(..L.....=..U.@...2<..*n?...,.@A...pM....x..{..<.U..............).|.k.~..{.U.7.X.".....u.u..;..b ...5...r..:..{.....I....2.........n#.p..i....m|....<...Kp.E..su..1.....v3.9p.Kj.q.8>0.%.nG8...S.d'2..A....qbj...r....".u....8...r..[........5.....#..Z.Wy..!..L.....X.....X.7J........1..X=.m2.hh`.1..DD.-O..7.F.......A."!....'..7d...F....t}.yL...g..>...y..D._..Ue........\...._..%.Z|...t..j...,...b.L..5.+y,a.Cv^gt(_.+JC.z....rv...i.V.|......M...]!.-......R.8.s.&..>9Q9!O.0...4j..2..R.y[GQvq8#....*.@y.bN]..7cCt3u...Y...ne..`{..s...)l.s.g.d....b;...3;$....'..z3.S..f...F.a..:......\.9.C.T.L9.....1H.:.......(..x+ST....0....ch..g....NBxB..W=!.....N...A.o.!v...5w.4i...:rM.@9...a....s.......a..1..#..{..5*&..i..........8j...N...;....8.k..q'.8.r..=.8t..I.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.815149584842096
                                                      Encrypted:false
                                                      SSDEEP:24:I3EzXxiNEAbZDTA0OIQmByODxR1Ivm9CmUO:WEzsDZPpXQzOlR1+yUO
                                                      MD5:438CA24647DBC92FBBABD65F87189159
                                                      SHA1:0CC7E5EDA84D438945A42F31E906F81A00995479
                                                      SHA-256:370029DBDE15F2C283A01D345C575F0FAA1B486114C7EFCF047168463E082906
                                                      SHA-512:F549DC75734B73AAE0C02E1DAFEA1F1D6F3D6C446DF4894A812B7478B5CCC6431880E4D2E9DFE2EA19AE62CC950F9A02B9C00830045DA599B9A3FCCC7A99D48E
                                                      Malicious:false
                                                      Preview:;..+./.....V.H......... .f.;.J...jrV.....v.s`>..Bxch... .}N.......uk....h./..f..3Y..m...!.*.xr..Q.7...w......`4..HCmA.%....p..FpK..^=;....~^`....7.bbi8....3.vA.*..B..fN...9.~....?.P.h.1.-....L.TR]..y....w.@c....1.`.....?...j.;...u..........>...*a]iy]V.4.e......-.`...{cR....".M.%.*..../........\..;+......5.xT}...R........9.?T.=..Zl....../.53.....`.=@.@>....f,O...62iN.K.1 c..S.B;F..1.3..%<@... ...Ii%..)..H..R........r..b.f...C...&>.o..5m....1.V$..y..K...r.)..U#zb.....s.EUH....g:+X....6.........L;F..).ouU<v4)...-\#..6kl\...).v...Q.`.q1...h|"..K..5.^.0...V.Do...h...q!W..3...:.(le.`.........z.7[..i...;..L.$.1s E....L...I..n..c.6.Z.....Iu......eg.5bp...^M\&.W.E.m...k&,.(O.R....T....+.gp.~[.8\s.x...t.T..\.G.II...2..<.....}.[.7!..'_M..=G,..!'.V..*..Mf....z...=...K...x...z..,....j.4.1*?>v..|...ve.....k).VF.,..G].....)I^E.....K..0.w...=t`t. g.X...gCS....[..=...&.*b.A!'..yy.8j.b.B..D......#k...]=n..\l...yp.1\....v.O.:....l...Z....lW.8...Ly..
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.853790754806177
                                                      Encrypted:false
                                                      SSDEEP:24:bkR2l1VpWmFzHjS4AXtXN/LVxg4e9kIYHeTz7ND:bkREVIo+L4dBweTzpD
                                                      MD5:D68A5FA1063FFF5FD9AB48DE28EFC556
                                                      SHA1:72B82B199648D981C255504284AD5282A07F8A80
                                                      SHA-256:BD3779ACECF7CBE3F500998766E6D021BCA1F337D44171EE7F958022E365F530
                                                      SHA-512:A47952110D2F3CC64027C02005ED3895448046CC470F86601276A43998BB00005204F134C3F80631ABBBC854EDEFD21EFF11E6B503315DC5FB8D718812D88F06
                                                      Malicious:false
                                                      Preview:WANACRY!........|.........LO....w...S3......[.Jw.;.N..1T.!...[....!.#.!..G.2.. ..6...)nU.s..O.*q.)r.v......-...&D....nE.D&..0a..)w..h..0.j..A}.T..7.y..J..S/......_.c....J..wwI[<..N.609j./...x..<.;#..B.(..Y.N....<.q.V.=..je}LS..i..lF..!..M..;..q.MV ...%..m............el.[.5..TU.W.......P..T..P._I.X.Sag..DJ.L.S.R....N.J....g2o.s.kv.`..U.AD....uj #m(O. .BP..V.LPM....'....2I...d....m.....!q..A....GC.uO&g....zB."m.|Dd..B..["e<P......w-U..a../m...=.:..p..$w-~.s..D..j<..z..U....<....... f...*!. .T..kGu....?.(.tI$+.%@0......=^..+v....S..../yJ.....?U...#|>.8._.s..,..I.......Ga-.......u.>...QC.W.V.....K...^...tQ..s..h.9..}@`T(....1co...R.w3Yh.d..y..o.a{..V..]..w'.SK..5%9..PS.[.tn...j}.F..*R.3........|.r.....XZ\.B..0.0.w.L..@..0|..QU...$.}..y.h.....B.....Z...2H+.....hI%....p>.....'.q.G.-....3G.*..6.k..L.:.MHI.Pp..N.....[yVh.A.+....4...;./.?@..........Wx7......k ..p..P2.vf...}*.&......&..c.j..@nx.M`;V....h..F..v...f.H.|.Z`..........G|n..x..
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.853790754806177
                                                      Encrypted:false
                                                      SSDEEP:24:bkR2l1VpWmFzHjS4AXtXN/LVxg4e9kIYHeTz7ND:bkREVIo+L4dBweTzpD
                                                      MD5:D68A5FA1063FFF5FD9AB48DE28EFC556
                                                      SHA1:72B82B199648D981C255504284AD5282A07F8A80
                                                      SHA-256:BD3779ACECF7CBE3F500998766E6D021BCA1F337D44171EE7F958022E365F530
                                                      SHA-512:A47952110D2F3CC64027C02005ED3895448046CC470F86601276A43998BB00005204F134C3F80631ABBBC854EDEFD21EFF11E6B503315DC5FB8D718812D88F06
                                                      Malicious:false
                                                      Preview:WANACRY!........|.........LO....w...S3......[.Jw.;.N..1T.!...[....!.#.!..G.2.. ..6...)nU.s..O.*q.)r.v......-...&D....nE.D&..0a..)w..h..0.j..A}.T..7.y..J..S/......_.c....J..wwI[<..N.609j./...x..<.;#..B.(..Y.N....<.q.V.=..je}LS..i..lF..!..M..;..q.MV ...%..m............el.[.5..TU.W.......P..T..P._I.X.Sag..DJ.L.S.R....N.J....g2o.s.kv.`..U.AD....uj #m(O. .BP..V.LPM....'....2I...d....m.....!q..A....GC.uO&g....zB."m.|Dd..B..["e<P......w-U..a../m...=.:..p..$w-~.s..D..j<..z..U....<....... f...*!. .T..kGu....?.(.tI$+.%@0......=^..+v....S..../yJ.....?U...#|>.8._.s..,..I.......Ga-.......u.>...QC.W.V.....K...^...tQ..s..h.9..}@`T(....1co...R.w3Yh.d..y..o.a{..V..]..w'.SK..5%9..PS.[.tn...j}.F..*R.3........|.r.....XZ\.B..0.0.w.L..@..0|..QU...$.}..y.h.....B.....Z...2H+.....hI%....p>.....'.q.G.-....3G.*..6.k..L.:.MHI.Pp..N.....[yVh.A.+....4...;./.?@..........Wx7......k ..p..P2.vf...}*.&......&..c.j..@nx.M`;V....h..F..v...f.H.|.Z`..........G|n..x..
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.795152622737845
                                                      Encrypted:false
                                                      SSDEEP:24:Ycbn7VBSzoBoOfT16JYp2iTV50EkJAZ3CSyhKDx7f2MSBqS:Yc1BSzKoG66p2ivbZFzyhg7f2MSBqS
                                                      MD5:DF32E4646E27D23EAB44E67949682A54
                                                      SHA1:BAC69BAF44981B28B7E8128578D91EE3CD0EAFAB
                                                      SHA-256:03A3CC50E7D630593E1A9E086ADCBF21EA07014F9E6A995D7431CE5BEBD11950
                                                      SHA-512:9BEBDED76FA52B7BCE3EA7579738EFBF95E23A779299DCDEE5FA4412C2866C39F52033659B65CD5B0CAA941A05039785F379D506917430A6E868B62AE5DE46C7
                                                      Malicious:false
                                                      Preview:.&.fV...!.....6?Ck.{s..3..g}.6u...7.I.L?.......b......@G.^...T.F..K..'..."2..@D..pw.c....Z.gt.......d......`b.@..]w..aY".4.(....W.]!x..Q....5..Z...E.....m..%Q.Q.u...4....C........;..`./vF....Y..#...%MJ.....47.....K..g.S..6N...2....^..~..J.[d.a.:...%ay...>....8\Zn.|.c..X...r.........B.z'....`.SZ...8+...~..\b.9Fx .7.q..(.K...n...My.....#S&.D!f.,..S..(-.*z_W.O.\.S.r....c NZ....S....^....U....m.......`E...T..p..&.@|.;.#......[fI;........#5nx.........O...B ._m.7M.xA.+.}..N.a........Od`\/...r..'&....N.........4d.4./..L..(.2C...5=D1Cr...>.y|3j\.i.e.|CCnI.(.Z..../C(...n....w.q..$7l`..a.a-s.a.[.{N..4.<&.p..x....l......x...Fu.x....zk.-....?...b.....[.mE.q.'...:........O..g...4.Q....N;9..%.....F.......1J9U..E.7..'s...././...H.....K...O....t|...7.....+L.../jD2...+L..kU..]...Z..9P^K..a...X?.......v...z{..1:.OR\..).....2|Td.,..$...q......r'R7....c0.wta...t..~m..%..mr...f..l.[.qr. !.2U...`...@..LL..e..Qe.V.r.M.-,....=L|.y.....+..D.S.#..TpsF.......
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.843599811419978
                                                      Encrypted:false
                                                      SSDEEP:24:bkaoiJINJRLIZ5I68KGTALRzJ1kHKGIUjLu7xIU9h3AS6Ku:bkaLJIT1I3I6wUqKGIUGGU9Fz8
                                                      MD5:BC988017DC1A61FD39D5F4C5444A54DA
                                                      SHA1:7DD4CA82E420ECCBB6D1C34FB89013DB2B3B57B6
                                                      SHA-256:8AD6C94BEA7311B6361080E16B43AA6A171C60C1A8941F210C1B983848D0C11E
                                                      SHA-512:B22A26945342390910EBC186642DBE386439A862319F5CB81524F707E1FB7D2E1E937688A5011E852C19C99D3CA9923EA75DC6766E8A06B005A26D2042EFF756
                                                      Malicious:false
                                                      Preview:WANACRY!......h......8(..8.......`....q.;..L..`.<jA..5..l.uQ0/......O*V.^\# ]........z9..o.k..J..5..........mb:.'....W.e"..Q...g......,...'d~L."..7 Wx...][...8<..k..T~[.D..`.R..>F.rE=.44v+Mz4..~.?........W>!.....2(Lj........y&."o"x.O9d.w^.0....b..-t_...............d.:.M9..JO..1S...U..q..8....un...[..kTg<.c.O3A.`..:..@.8..yLEjZ.......s...K....U...?..9#...-......&Rb..[.?......>P9..m.Q.E`..^.6...uy..UXW...Xz.GwHwNbf~?e..?.9...0@jJ.....'O....p..........$&^..P....CY...+d.G.,.ma...D....0..../oy<.h...{.......]L....K.......Y..k.}.yh!>}....m..v......P.-...7`..G.......&...$i....j}....,;......:AA.i...X....z..s5Yn.=.B......U..'s@h.^..bM..Q. .....f...z5......`X..# y.0...|..Y8V?"...&....f.`....P..f.)t..g.>....}...].j.....A~.s.a.../W.....4>^...b*h.eCY..........ZQs?*Q..k......Kw.{#...^.D.(...Q..{..2..#b.m7......[.B....7.Q.O....:v%.Qm0...w...`....&.-......T.W.....E....s.......e%i...).t....Vxe..E...!..~?.{fk..t.......U.R..L.."..=..h..R..3
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.843599811419978
                                                      Encrypted:false
                                                      SSDEEP:24:bkaoiJINJRLIZ5I68KGTALRzJ1kHKGIUjLu7xIU9h3AS6Ku:bkaLJIT1I3I6wUqKGIUGGU9Fz8
                                                      MD5:BC988017DC1A61FD39D5F4C5444A54DA
                                                      SHA1:7DD4CA82E420ECCBB6D1C34FB89013DB2B3B57B6
                                                      SHA-256:8AD6C94BEA7311B6361080E16B43AA6A171C60C1A8941F210C1B983848D0C11E
                                                      SHA-512:B22A26945342390910EBC186642DBE386439A862319F5CB81524F707E1FB7D2E1E937688A5011E852C19C99D3CA9923EA75DC6766E8A06B005A26D2042EFF756
                                                      Malicious:false
                                                      Preview:WANACRY!......h......8(..8.......`....q.;..L..`.<jA..5..l.uQ0/......O*V.^\# ]........z9..o.k..J..5..........mb:.'....W.e"..Q...g......,...'d~L."..7 Wx...][...8<..k..T~[.D..`.R..>F.rE=.44v+Mz4..~.?........W>!.....2(Lj........y&."o"x.O9d.w^.0....b..-t_...............d.:.M9..JO..1S...U..q..8....un...[..kTg<.c.O3A.`..:..@.8..yLEjZ.......s...K....U...?..9#...-......&Rb..[.?......>P9..m.Q.E`..^.6...uy..UXW...Xz.GwHwNbf~?e..?.9...0@jJ.....'O....p..........$&^..P....CY...+d.G.,.ma...D....0..../oy<.h...{.......]L....K.......Y..k.}.yh!>}....m..v......P.-...7`..G.......&...$i....j}....,;......:AA.i...X....z..s5Yn.=.B......U..'s@h.^..bM..Q. .....f...z5......`X..# y.0...|..Y8V?"...&....f.`....P..f.)t..g.>....}...].j.....A~.s.a.../W.....4>^...b*h.eCY..........ZQs?*Q..k......Kw.{#...^.D.(...Q..{..2..#b.m7......[.B....7.Q.O....:v%.Qm0...w...`....&.-......T.W.....E....s.......e%i...).t....Vxe..E...!..~?.{fk..t.......U.R..L.."..=..h..R..3
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.7763642577579
                                                      Encrypted:false
                                                      SSDEEP:24:BOFzJbFno77u0lSGG9w7+cA836dUeJbU4Vbsziak3F9:GzppfyVJHdKd1Xoiay9
                                                      MD5:8A2B12011399AB6DBA4EC2A3DB4A41B4
                                                      SHA1:E2A943FC4D0AAFADCF6217CC0B7205E3ED32C599
                                                      SHA-256:42CF77F4CB3F7C110CC6A11F7480EE3C5876689949CBC82915403302AC255CC1
                                                      SHA-512:A39689A2EB9653979E7369140F4249EB907CFACED4B664502E32CC7112344CB3CCB50A999617B88E41B6EB2C74162C3678F64E9FFA0223468B3B4B2E2827773D
                                                      Malicious:false
                                                      Preview:..=_.@....}..-8...RC...0.?..`..b......f612i..oc....GO...D..=+_...a...C.;.../.W.<.~...\...O.f.}.6.r....:.(....9sG.e....zH.......F.F................ji.P..XpJ.Z~C..u.K[.y-Z4..jrC....@3#)..t.f.WMw........a..}...P..w....A. .aN.]W.$.8..,...c.p.......U........_.W..+5..d.W}...a......R]+D...L).6...(1..ZV..|.F.@.u.....c..C,."(........<>i....}Y.....E.....:[..W.A..l...\*.1q|t..w.....r...o[.*.[...i|..F...9+.d..?...a..u.b.R. .K...6"V..a..p.....`c..4.|...J.%3......g...e.[j*#..Q.H].|h....s....D.-.t..t&.R....Z...C..7..j....n...(..u5.?h\..|.2...4:....*..+...u.T...........U..L..K..*.0iN.....S..Ow..3.U....@.B.......N...dz..).....5.4...u.D......GM.(E...z.a..^..........U....\}n.6.\-.aq.<j/....$Q|....O.K D[.:..d0..;...x\...u.z.......c.Eu..k*...~.X`..$.E....d..+.V73i..._k. ..f.^^.h[.,...l...o&....g.T......M.o.74.EC/6.?M|J:6..V...s$......w..y8/.......1G?..Wus....ur.T.X...6....I..F.F>...<.....n...`D.4..9........ '..W.C.4......N..*.C..;?.h.XM.^(J.f.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.849415428877812
                                                      Encrypted:false
                                                      SSDEEP:24:bkGpaij6yd2F2GtIQL4VUKtH1oPAKjzFXVfLjZtiI/c81e4d4m3uOUQt:bkGb6EbcmtVsRzzfLjZtm4Sm3uOFt
                                                      MD5:169EF530DC915C577D0B4FF0F80E72D6
                                                      SHA1:1FDBE683341C79DB826DB02E4A6FBB385B596A9F
                                                      SHA-256:2BDBFD92689CB9C3D05F09CBF1C2AC7BF9E32B4F977026AF945783031406C67C
                                                      SHA-512:9977E25768CA0625B3E13F63DF3C13E3F46F4EBEC1A8E8C0F1FBDDE162E7892F8B88F5C2A9ADA019786CD338D70FBC9D32AFA212D3924990C7EB5CB801B1CEC5
                                                      Malicious:false
                                                      Preview:WANACRY!.....d.b.o...#.r.;......m..2...V..*d.M}L.....gv.@..r.9.G.E;.... ...V"....vA.3...<sl..".....B#.YZL....A.|...l...UB]...M.#Z.H=..QP.MqeY...1...).6.}f.j.r....`.z2&`&..B:...{...!....5.....|.AX.F.0V9...9m..G?...q........ Rr!.S...0v7.....fq..."F...y!..............r.w.._.N.3z..ry/....f.B`.....(j...R`..<OTT..:i.y#..b..6X.J.[...%.......S.i..0#.<...6.f..?.).......lLV.q.;.......X$tb5Y...............>...}I..z.?._.*7..0.....2.x*[.gH....)..zz.|.?.+![)E...K.."....b..9.3"~1&M...P.....R.`I...%..tC.W.9..vf.....zOp.FM\....%.5..9.y....3.99....]?/...........fy...E..1V..D(..F.n.mi...7..-..*.G..]6V..}.N:*.]....k....9.ZZ.Ak.}.u.Eu...;%........Flt.S...Z.}~[8T.Z....I....X5%H...t.Q&.....K..K.&k....\..L}.P.KO.#.Z\U..g3 :..T Z...&.....4..`..."fA..a...%.263%>d.UJ.;....k...E.#Y...x.......f.....bk..6GO$n..5s.......,L..6..=.q.Z.y4jT.U..>q.cG......q~..{.......(.v_..teCk1.M...q=fJ .....T.v...Oa....].K.K..5G{d..3.....2/.<.q..Dtp..r...U.....W..+.=U.`.....>
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.849415428877812
                                                      Encrypted:false
                                                      SSDEEP:24:bkGpaij6yd2F2GtIQL4VUKtH1oPAKjzFXVfLjZtiI/c81e4d4m3uOUQt:bkGb6EbcmtVsRzzfLjZtm4Sm3uOFt
                                                      MD5:169EF530DC915C577D0B4FF0F80E72D6
                                                      SHA1:1FDBE683341C79DB826DB02E4A6FBB385B596A9F
                                                      SHA-256:2BDBFD92689CB9C3D05F09CBF1C2AC7BF9E32B4F977026AF945783031406C67C
                                                      SHA-512:9977E25768CA0625B3E13F63DF3C13E3F46F4EBEC1A8E8C0F1FBDDE162E7892F8B88F5C2A9ADA019786CD338D70FBC9D32AFA212D3924990C7EB5CB801B1CEC5
                                                      Malicious:false
                                                      Preview:WANACRY!.....d.b.o...#.r.;......m..2...V..*d.M}L.....gv.@..r.9.G.E;.... ...V"....vA.3...<sl..".....B#.YZL....A.|...l...UB]...M.#Z.H=..QP.MqeY...1...).6.}f.j.r....`.z2&`&..B:...{...!....5.....|.AX.F.0V9...9m..G?...q........ Rr!.S...0v7.....fq..."F...y!..............r.w.._.N.3z..ry/....f.B`.....(j...R`..<OTT..:i.y#..b..6X.J.[...%.......S.i..0#.<...6.f..?.).......lLV.q.;.......X$tb5Y...............>...}I..z.?._.*7..0.....2.x*[.gH....)..zz.|.?.+![)E...K.."....b..9.3"~1&M...P.....R.`I...%..tC.W.9..vf.....zOp.FM\....%.5..9.y....3.99....]?/...........fy...E..1V..D(..F.n.mi...7..-..*.G..]6V..}.N:*.]....k....9.ZZ.Ak.}.u.Eu...;%........Flt.S...Z.}~[8T.Z....I....X5%H...t.Q&.....K..K.&k....\..L}.P.KO.#.Z\U..g3 :..T Z...&.....4..`..."fA..a...%.263%>d.UJ.;....k...E.#Y...x.......f.....bk..6GO$n..5s.......,L..6..=.q.Z.y4jT.U..>q.cG......q~..{.......(.v_..teCk1.M...q=fJ .....T.v...Oa....].K.K..5G{d..3.....2/.<.q..Dtp..r...U.....W..+.=U.`.....>
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.8032710233789215
                                                      Encrypted:false
                                                      SSDEEP:24:lSYmHmCsWCht74WdMWwQLvJ9bA3NFuYsl4s:ll+mCg7FamtO9FElp
                                                      MD5:78896852F769BF2F15384F6BB544311F
                                                      SHA1:2A33FE484506B28D9B2EA4F119E127F0AADEA935
                                                      SHA-256:92090ABF9E45B4DFC323D84365E5ABBADA5C40BE142DA79220CDB4BD1D6417CA
                                                      SHA-512:0E97AAC91458304B0141543324C6EA30EA5FCE4044C54CC243F766ECC2B9C3ED9CD70D1EFEFCDA97615E8270D8C6CD60E1EF26A0A1F967C7B2A282F910440BBB
                                                      Malicious:false
                                                      Preview:.U.....5 (...m....c...m.rY...sG..:.=.0........g.>..,..n...>..R.Op.._.o!Y.9.n.d!...#..E..>....&.....V8}y..M...j...n.<'....1E....F.,.D7....<......-..4.....z\...pv(hr..v.eJ."..aog....ks...7.v<9..Y..nl...3...Hvm.....lm...'.|.?k.......V...].D.Z.k^.).2k...u.......I......E........{vh......%i)....on....z.F},.s..at.m.....k....h..|..\l.u..Ar..c.?.d.....5Gn.7F%.e....0......q......([.S..fJn....[:..2W.:S..(......A...I...X(.....}a.zX(.Yt..o%...2.XZ..E.....=-.0,4..j..E....Mq.r....@.?.......Ig.6..?r...........cN.KJ......bhu........v.y..R..z...d.r..+:..E..O.y........*:.....Z......G.X..TqF.....*....TCzML.%{3W.0....`.?...we.9[..3..0.=.=$a.+p.E..f.I.....?Z....|....Tru.Ox9w.......#..Tk.q..`......_..a,..*..$.X.z...e..D.....n....dc.-d.({h..m...*....$....N.[i:.@h.........n.kzf.:#[...{,#.s..i...1.,!.........*......X{9.u.!,....M.A.%\.@.f%....(..B..3..r.}...N..G...G*.....W}.....3l^.Q~.d")g..X4C .&..e..........8...>.QRV.E.c.......>..x.4H......%.|....S.......
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.832676603622014
                                                      Encrypted:false
                                                      SSDEEP:24:bkC0C3C233fI20jV0QflCI2lOIoJ3ihDLu+93jt61AvvS3L:bkCl3XnQFimCIFIowu+xjRvSL
                                                      MD5:917664C5DC71386F68026FC542616EA3
                                                      SHA1:F307FDCE0B53325F23CAFD10FAD5373F857E0B0F
                                                      SHA-256:A32C73E95ED267835D987626C4BB07D683F4CA170636F376BD283BE0ADE77C82
                                                      SHA-512:19126141F68B80D30404F265696C6BB048F291E903D503D53B7AE6970CDFB48E3EE93A78FC170CBAC59FB59A2AA5E5B363B88E682E95D0FBB00474F3EC210823
                                                      Malicious:false
                                                      Preview:WANACRY!........h...M..j...,..$.h..C{ ..s.c.F..bl0+F........%%]..5..F....5~.c..6N...."f........Fh..G...r.*e..]b7T......M..I...E.i,.Os9w.$.s5.0..A.d..U...@E.j.By.(....6r.0.S..y.g...?...eO.Qfv........./VW.x|..J..i....#46V....B_.L.L.....x...5sP...W...=.q..ob..n.............F...)..7*......|...+%~. ...L.R.U..7dA..<.q../l.U...r..E{u..?.C.....Z.9.6.Dt.8r.g.S..B....%gc.........v3`|....G.?..0.r,.Z..0yu..|.=_..D....;Z$.$2....Q?.'.{P ..+....Lz).t..zj.D.K.Q.T*q.m...Y.5"C[.5..vpF...,.#LU.....=.^F'.f#3BF...j..........q|.....I'..\M....Q...7/..o..L.7...0c...7x~`..A......#..W.A4.d.gD...b...u..f.Y.M...Uy.>./.{`he.nQ...6e..FC...e..L2.....(.....f.....B......O.+...I.........j.y..=..3....oa\C.5...-.NC.|...e.q..I.|.....;.A..br..0&6~.@.".5mp..w.lS.Par._E..X(.y...M..|$c.F.i..5.{.._y..o.de9.q.qi.j..".:.V.<C..kl=....."&.UB..N.F.........t..{....%..F....P..mQG.`.DO.%!..51.g{x..,....*.H.J..q.{P.Z.....K...`..!../2R....d......>.\qv#..h..'tY!....%ECk.y...q..Z.P.K.X...L..chj
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.832676603622014
                                                      Encrypted:false
                                                      SSDEEP:24:bkC0C3C233fI20jV0QflCI2lOIoJ3ihDLu+93jt61AvvS3L:bkCl3XnQFimCIFIowu+xjRvSL
                                                      MD5:917664C5DC71386F68026FC542616EA3
                                                      SHA1:F307FDCE0B53325F23CAFD10FAD5373F857E0B0F
                                                      SHA-256:A32C73E95ED267835D987626C4BB07D683F4CA170636F376BD283BE0ADE77C82
                                                      SHA-512:19126141F68B80D30404F265696C6BB048F291E903D503D53B7AE6970CDFB48E3EE93A78FC170CBAC59FB59A2AA5E5B363B88E682E95D0FBB00474F3EC210823
                                                      Malicious:false
                                                      Preview:WANACRY!........h...M..j...,..$.h..C{ ..s.c.F..bl0+F........%%]..5..F....5~.c..6N...."f........Fh..G...r.*e..]b7T......M..I...E.i,.Os9w.$.s5.0..A.d..U...@E.j.By.(....6r.0.S..y.g...?...eO.Qfv........./VW.x|..J..i....#46V....B_.L.L.....x...5sP...W...=.q..ob..n.............F...)..7*......|...+%~. ...L.R.U..7dA..<.q../l.U...r..E{u..?.C.....Z.9.6.Dt.8r.g.S..B....%gc.........v3`|....G.?..0.r,.Z..0yu..|.=_..D....;Z$.$2....Q?.'.{P ..+....Lz).t..zj.D.K.Q.T*q.m...Y.5"C[.5..vpF...,.#LU.....=.^F'.f#3BF...j..........q|.....I'..\M....Q...7/..o..L.7...0c...7x~`..A......#..W.A4.d.gD...b...u..f.Y.M...Uy.>./.{`he.nQ...6e..FC...e..L2.....(.....f.....B......O.+...I.........j.y..=..3....oa\C.5...-.NC.|...e.q..I.|.....;.A..br..0&6~.@.".5mp..w.lS.Par._E..X(.y...M..|$c.F.i..5.{.._y..o.de9.q.qi.j..".:.V.<C..kl=....."&.UB..N.F.........t..{....%..F....P..mQG.`.DO.%!..51.g{x..,....*.H.J..q.{P.Z.....K...`..!../2R....d......>.\qv#..h..'tY!....%ECk.y...q..Z.P.K.X...L..chj
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:ASCII text, with CRLF line terminators
                                                      Category:dropped
                                                      Size (bytes):933
                                                      Entropy (8bit):4.710902136409594
                                                      Encrypted:false
                                                      SSDEEP:24:ptrPzDVR5Gi3OzGm0EigS1xbnS4RQhbrW8PNAi0eEprY+Ai75wRZcet:DZD36W3ChvWmMo+S
                                                      MD5:7E6B6DA7C61FCB66F3F30166871DEF5B
                                                      SHA1:00F699CF9BBC0308F6E101283ECA15A7C566D4F9
                                                      SHA-256:4A25D98C121BB3BD5B54E0B6A5348F7B09966BFFEEC30776E5A731813F05D49E
                                                      SHA-512:E5A56137F325904E0C7DE1D0DF38745F733652214F0CDB6EF173FA0743A334F95BED274DF79469E270C9208E6BDC2E6251EF0CDD81AF20FA1897929663E2C7D3
                                                      Malicious:false
                                                      Preview:Q: What's wrong with my files?....A: Ooops, your important files are encrypted. It means you will not be able to access them anymore until they are decrypted... If you follow our instructions, we guarantee that you can decrypt all your files quickly and safely!.. Let's start decrypting!....Q: What do I do?....A: First, you need to pay service fees for the decryption... Please send $300 worth of bitcoin to this bitcoin address: 13AM4VW2dhxYgXeQepoHkHSQuy6NgaEb94.... Next, please find an application file named "@WanaDecryptor@.exe". It is the decrypt software... Run and follow the instructions! (You may need to disable your antivirus for a while.).. ..Q: How can I trust?....A: Don't worry about decryption... We will decrypt your files surely because nobody will trust us if we cheat users... ....* If you need our assistance, send a message by clicking <Contact Us> on the decryptor window....
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Archive, ctime=Thu Jul 25 21:01:45 2024, mtime=Thu Jul 25 21:01:45 2024, atime=Fri May 12 05:22:56 2017, length=245760, window=hide
                                                      Category:dropped
                                                      Size (bytes):575
                                                      Entropy (8bit):5.140446565826782
                                                      Encrypted:false
                                                      SSDEEP:6:4xtQl3y03CpzeVs+bTNAUHUtxXCzaMmM7/gtrUod6tMljAlpdmqLEoJ4D6Vod6Nd:8iypzYNbd0thHZOgZUobjArozhmV
                                                      MD5:CCD2610ADD4080C4DCC35A11217DA6A6
                                                      SHA1:001ABA92D58B546C8BD54E0BC4103661F68CF92A
                                                      SHA-256:0E272CF58CC66E7B0CC4F42094232A46B6EC11AE5ED695BA4156A1A28DA41E6D
                                                      SHA-512:36DC5CE3027E8A77639783E31AC69C9FA61C4761FBEB9A819C1EB49F4A32BF2001C0441FB28D35C4EC9DD1B713576E7894DE8FD13BF14CE62A436F9619093DEC
                                                      Malicious:false
                                                      Preview:L..................F.... ....b{=.....b{=.....`.1.................................P.O. .:i.....+00.:...:..,.LB.)...A&...&........DDj....%.=....(..=......t.2......J.2 .@WANAD~1.EXE..X.......X7..X7...............................@.W.a.n.a.D.e.c.r.y.p.t.o.r.@...e.x.e.......X...............-.......W.............,p.....C:\Users\user\Desktop\@WanaDecryptor@.exe......\.@.W.a.n.a.D.e.c.r.y.p.t.o.r.@...e.x.e.`.......X.......216041...........hT..CrF.f4... .u.E._c...,...E...hT..CrF.f4... .u.E._c...,...E..E.......9...1SPS..mD..pH.H@..=x.....h....H.....K...YM...?................
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.810473385384848
                                                      Encrypted:false
                                                      SSDEEP:24:6TiosNgIhvRMDEMroSW+sTFKWeM4/7/kCMn8XnrOFUPGZZR4sXO99Pk:6Ty/6powyFMM4D1M8XnrOFwkDc9Pk
                                                      MD5:0A83D08056B9FC7E37761B885ADA2B7C
                                                      SHA1:BB0A48223A3243F588860B09DAEBEB1758534528
                                                      SHA-256:0FD4302789CA796F28F648D750A382738571EE54AE461B3B0807469D394921E1
                                                      SHA-512:E67262AFB213B5DF0A181E09FD35E0A846CC82437378CA5B2FC678E6362A40C1E6D34D7334C97E99A3B655B1191C20BC755C6B4146519158D727F35E4FAE7F83
                                                      Malicious:false
                                                      Preview:...u..<#-...........v..t....eI..3.....X5{....q.A.ys.FJ].e....){...D..I?.&..{...lJ...K.g.!....1x..RG..(m6.`.&.a.?.Q..E+.e+..|...8.S.)....Fjf8.de.EY..c.Gxcv....-.Jq......t.[....~.....QF........\....p.+.&......XfUQ .+e,/.5l...b.....:c....V;..i6;.`..h.h.d.i...k...8.M.......!.g.n..K.Y.....*.......X...b<J.v....,q.g^Kk.......f.1;..<..c...Se.....nNH....@?...F..*$.>S..Q...d..o.{...".8qv.j..#nk.c_.6..SyZI..I....6Wqh..'.Sb....OQ.I.;.JwRA....kb.Nw..*T...C..;...c.?{..r.1.aP.....g...+UJ=.e............:'@%-i...D.....Z.nU.#:........e...a....G.zzP..".C...$#z.&.2.".....~.8.n.....v..O*.;...I....0.Z#....O...f.......CXKm.n.J....Em...0.=...&..C..+.^.ku.".1......,.yd..3...5...7L./.V.T...i.Q......p..y....R.i.52.jk.Y.w.XT..(.D.....?..^...t<.B.s.O....i.x.($...B...{x..Vj3.F.W.. **i..PL....<.*lo6h.0..K...$G`...;C.....H .A^..Y.{....xY.D7B....f...3.....HeP...S.f.....TE2.9.u.nU.B.....?k\.1.U..-..Rd...X..5\.|...>.....D.,`..F_.Us.....Q....y.k..."u........IM.T....
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.8560837323429515
                                                      Encrypted:false
                                                      SSDEEP:24:bk7QJFJLieGP9DjkwQxXFVZDnElXeFow02Kj0JUyLrvWy65dV4w:bk7QJWdNjkfJ/F+OJzJUyjpSx
                                                      MD5:BB11D8EB4D5443AAFCEF74D6CAAAC078
                                                      SHA1:8F3D1332ABB363790B8AE0C33EA635A21A09BE61
                                                      SHA-256:238C7BCD9612B387A860091461ECDA17F0941EF5B34E929729A4E95606ADE1FC
                                                      SHA-512:57290E9042DE5778E100221FB6D18665631E3BD2E6B9D65027630FD4B5248A47926ABB11041AD5B702729EB7DA2CF51012AABB078507E14A29B6AE30083C6C74
                                                      Malicious:false
                                                      Preview:WANACRY!.....#^Vf.t....J..=N.._....I.....;.r.M..y....YR.7..}.{.t.....%_Q5z.."....S..e.L.p<...c8...0..h...h[.....>..'.SG....#aL..".....H>...(....B..a.n...z.@......O.......F.hqo.R.L.k...u.h..u.D.O..2@...N.`q4RL..B..@..e.#.YXO....E.f..2.Z..e}..F.J..<m.I..............#.Z......b\..1.4,}xF...r.dB.....f_j|.C.j!.,....b....m..:.:.....uc..."....X...p.:?..~W.G..).....R.. ...]3J....A...K....~.......L6..4J>.@...M...i....``.).F.GBh!zQcbj_..'.x.+PY.a...m.....f-A.O .Cl..S...k3.-...5..x...$@.z}.:h...H.uNC..Hp-......1....I>.I......sS....%9.b.yw..w.o.....&D)...=.S(.8......y.E.......R(...-..S..iVF6....(......~.3...._...<.3K.4.OA../.6Jn.".@...r....].....>.dy...].V]OT..F.l..yY.<.....9Jf..lA.C.P.'..G..qr$..6...Q.t:.&..|..]`..h1..dG.k.#.h...b...TA..4s+..;..c..o.K...3.`b.i....:+z.......n........u...~....(+.{...G`...La?...b..\.swW.i....O..x.1....Q4.."....hR..o\p..$Q.tE...!........F..U<..V.}...G.1.>...`V.(.+C...v..`i.P\..Hs%{...A.>`bA!..yg".<.%Y..,:%L.`...t.;..
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.8560837323429515
                                                      Encrypted:false
                                                      SSDEEP:24:bk7QJFJLieGP9DjkwQxXFVZDnElXeFow02Kj0JUyLrvWy65dV4w:bk7QJWdNjkfJ/F+OJzJUyjpSx
                                                      MD5:BB11D8EB4D5443AAFCEF74D6CAAAC078
                                                      SHA1:8F3D1332ABB363790B8AE0C33EA635A21A09BE61
                                                      SHA-256:238C7BCD9612B387A860091461ECDA17F0941EF5B34E929729A4E95606ADE1FC
                                                      SHA-512:57290E9042DE5778E100221FB6D18665631E3BD2E6B9D65027630FD4B5248A47926ABB11041AD5B702729EB7DA2CF51012AABB078507E14A29B6AE30083C6C74
                                                      Malicious:false
                                                      Preview:WANACRY!.....#^Vf.t....J..=N.._....I.....;.r.M..y....YR.7..}.{.t.....%_Q5z.."....S..e.L.p<...c8...0..h...h[.....>..'.SG....#aL..".....H>...(....B..a.n...z.@......O.......F.hqo.R.L.k...u.h..u.D.O..2@...N.`q4RL..B..@..e.#.YXO....E.f..2.Z..e}..F.J..<m.I..............#.Z......b\..1.4,}xF...r.dB.....f_j|.C.j!.,....b....m..:.:.....uc..."....X...p.:?..~W.G..).....R.. ...]3J....A...K....~.......L6..4J>.@...M...i....``.).F.GBh!zQcbj_..'.x.+PY.a...m.....f-A.O .Cl..S...k3.-...5..x...$@.z}.:h...H.uNC..Hp-......1....I>.I......sS....%9.b.yw..w.o.....&D)...=.S(.8......y.E.......R(...-..S..iVF6....(......~.3...._...<.3K.4.OA../.6Jn.".@...r....].....>.dy...].V]OT..F.l..yY.<.....9Jf..lA.C.P.'..G..qr$..6...Q.t:.&..|..]`..h1..dG.k.#.h...b...TA..4s+..;..c..o.K...3.`b.i....:+z.......n........u...~....(+.{...G`...La?...b..\.swW.i....O..x.1....Q4.."....hR..o\p..$Q.tE...!........F..U<..V.}...G.1.>...`V.(.+C...v..`i.P\..Hs%{...A.>`bA!..yg".<.%Y..,:%L.`...t.;..
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.8301503309188005
                                                      Encrypted:false
                                                      SSDEEP:24:LVmjuVF7lQBbQGmf4uE2dTy7adgfAG7x3N7bohROXvtPju:p2w7yGHf9g7MG7xJV/4
                                                      MD5:CABF6A2E6DD01B70492DEA124807BF32
                                                      SHA1:BC45569021CCBDC4C1E2FDE98838A7B1F6573C49
                                                      SHA-256:37C156C4CDE40AFA248C4911CAF4E73340013EC85DC54623D6D6FAF4F822EDCF
                                                      SHA-512:DF328B4CFBA1D5F4EA2D3D5901AA96CB9C7F7A599E059C3D8652955FF6664093CA20125E45CE95BF39246FAD8A0A4E3BE6DE9FF8C19857045749E0F9FB03166C
                                                      Malicious:false
                                                      Preview:..J.......~.....N.*3d.6....y.....:R.-.F..w~7.2..f....Y...t.5.H.SS...e..m..U.......VA..1s.^.<V..Cc...s...$wgL.v.k.b.2...E.z......A.....Tw...B......Lymj.......gel=)i.^nj.....|6..G.h......fr...~.......?...Qr\.........Z..".........N..u..8..Yo...z..7.H....y...A.T.?..H..R.......w.E/.d.w.w?.h.3..N..z.!H. a!rM.I..H.X.t.>.R"..;.cMT &.>8....>..h*..p....o..o..T):./.:..M.pN.S...}.^........P..=6D...9Oz...RI....?$.x.}[o...R.8...w...4u..........%e...."'i..".../........Bg..F.yO...8s.5.Qse..z..F.n...1........{.......@.M.?._.F.R|}..D..o.cs.......C+...p..:......u..g97E........^,!.02.-[..~/.....^.T.C.....@....7....GY9.....r.+..p.-K..m7y..5.":Xf].V./..p....|`.4U.G.Zr.........Sp#..w.M.Z...'.,o.p^.F.8.$u5..*.....N..W.xx....S...1}..|=.]s.....=...".IEs..Z9.|..O9J4..Ifh.mp..m..g1fiA......g5.%.]....@...N.K.4...gd.5J>....s...T.4!...).M....}?\.....t.N.W..T.....ag..h..t.......^.....j.........EJ..........%..0N.v.'..W..W..&...........p...........[...jF.g.\......o.{..~
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.846879563143553
                                                      Encrypted:false
                                                      SSDEEP:24:bkl1KtfBbuzaTHUnGR36ub9jQV4kMsZC0qiuhZkLDxoocHOws/Pnb4V:bkbouegGRqQPX2C0fcmhws/PK
                                                      MD5:0B90C89F09E92D8A2485E332968AC404
                                                      SHA1:A914C944C077109619F13D8386C68BD4B09FD660
                                                      SHA-256:B625969BFA437394CA17C1202431165B9A6D85B31A6E43022E97CB566F528BC7
                                                      SHA-512:6623C09E80F847B913A3D29232D81AAD9EB4C7792E4847FF514A3539698E8DC257041BF137F22460F17C52B02E4CA5B1835104624CC4DEC93901AFAE66C9E15E
                                                      Malicious:false
                                                      Preview:WANACRY!.....'.6."l...d~...Q ...l...=.M...7.O.*\...tD.TEd..&J.E:._...[b.>.....E......x....S&..K.0...I.......h.d....a.2.....~....]v..C...#.....'..l...G..&i.}....DIz....Q.?...Q.$..:o.ge;.y..k..Mg.....O....(.?.t..6@.V.. dFXYwZG.XS^.b...C.0B.H.m.J..!......O.9.............X3v..Y+.e.8y{.C@=e$.....l....QUPh..3..K!8./fM.t...!c..A..=(..j..q.q....ey.C.bV.7.j'.[Y.3$0#....|...b...|(/_.@>I.e....:M.I..o.p.E..-(....-O..q....r`..n....ddx.....o(U...m.D. D....m.b{.3JjJF..<naG!jT.z..%...`v.J..5.....a..Tjx.....B..u....<.-....#S....w...Q..Q.S...l$.~.;:{.u~.....f...........Z...U.r.S..6...... .*lA}.@t...q.<.$O......8.l4.....Y/ ..."d?..jI..w..1.;.....+v.4.V.y......5{.nIl..}.`..t3..u...G.^..9....h.PZy.jXk..8T.\].vYz.......dm#\.#j..~....YQ.0.OJ...NO..=.(...Y,.......$.p...4?.@.fi......\..iWM._\.(gZr..{i.G...b.A....Z..].@..~..C..v.ey.o..1.C.d....'..%...u.rF.s...gX8..F.[qw.B..Lc;9.....P...m..8....._.j.BO...}..d(.q.k..6.7b.....!B70...HP%S....c.X....t..myC.B.A
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.846879563143553
                                                      Encrypted:false
                                                      SSDEEP:24:bkl1KtfBbuzaTHUnGR36ub9jQV4kMsZC0qiuhZkLDxoocHOws/Pnb4V:bkbouegGRqQPX2C0fcmhws/PK
                                                      MD5:0B90C89F09E92D8A2485E332968AC404
                                                      SHA1:A914C944C077109619F13D8386C68BD4B09FD660
                                                      SHA-256:B625969BFA437394CA17C1202431165B9A6D85B31A6E43022E97CB566F528BC7
                                                      SHA-512:6623C09E80F847B913A3D29232D81AAD9EB4C7792E4847FF514A3539698E8DC257041BF137F22460F17C52B02E4CA5B1835104624CC4DEC93901AFAE66C9E15E
                                                      Malicious:false
                                                      Preview:WANACRY!.....'.6."l...d~...Q ...l...=.M...7.O.*\...tD.TEd..&J.E:._...[b.>.....E......x....S&..K.0...I.......h.d....a.2.....~....]v..C...#.....'..l...G..&i.}....DIz....Q.?...Q.$..:o.ge;.y..k..Mg.....O....(.?.t..6@.V.. dFXYwZG.XS^.b...C.0B.H.m.J..!......O.9.............X3v..Y+.e.8y{.C@=e$.....l....QUPh..3..K!8./fM.t...!c..A..=(..j..q.q....ey.C.bV.7.j'.[Y.3$0#....|...b...|(/_.@>I.e....:M.I..o.p.E..-(....-O..q....r`..n....ddx.....o(U...m.D. D....m.b{.3JjJF..<naG!jT.z..%...`v.J..5.....a..Tjx.....B..u....<.-....#S....w...Q..Q.S...l$.~.;:{.u~.....f...........Z...U.r.S..6...... .*lA}.@t...q.<.$O......8.l4.....Y/ ..."d?..jI..w..1.;.....+v.4.V.y......5{.nIl..}.`..t3..u...G.^..9....h.PZy.jXk..8T.\].vYz.......dm#\.#j..~....YQ.0.OJ...NO..=.(...Y,.......$.p...4?.@.fi......\..iWM._\.(gZr..{i.G...b.A....Z..].@..~..C..v.ey.o..1.C.d....'..%...u.rF.s...gX8..F.[qw.B..Lc;9.....P...m..8....._.j.BO...}..d(.q.k..6.7b.....!B70...HP%S....c.X....t..myC.B.A
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.800000933156506
                                                      Encrypted:false
                                                      SSDEEP:24:eyxoq/9DlLnjJ13p3WRSqpyZr51ZBit4nx7zVh562VdyO0kyh:eyxoq1JLnN131W9pyZrNoOxVho2ykyh
                                                      MD5:417BF690964938D1E7EEEE84846DB8D4
                                                      SHA1:1D8FA52DA29569E99B1E37179B09A94088CF542D
                                                      SHA-256:F615B3FABA1FB8C3D7A9D56F33A67E59E428A8C901E499CC6D19D162818EE219
                                                      SHA-512:56F847E73EB3895AAE49AFAF9DA62D6FE2C37AEDA442C4A630C34EE2597432ACE9B2341268FD89D416B3ABD88BEEE48E60D8D8E3B6961BE9B610383228BE4AF3
                                                      Malicious:false
                                                      Preview:`>Zv..\-D.2..S.3'{.U...'......u.>......$...k....GY.;...b_..Wzi...x`.%....I...*.f'......S..!...MO..,r}..........?:..]....8....H...h.5R..h<.>x.......KS.7.&....<...)J.9\,.wo..]."Q.G..5._|..pq.3......^.lWK){...I.(...|.}.'()|tK`B.C..?..._......[..|..%.t..6..GR..].BU..2....}..xq......i.P....^...,,.....N..=&@....P_au\...48.V..D..o....4....TG....QN].H......b.m.......DKo.[{).........l..|.C.n.D..*...h..g.....#Bm^.`,....[........bH......N.6.x{.g...c..3..2.3.........M"..x...~fM...c.#.v...l=.6......G .Q..FQ.......2<....T..9Bv.....X..z..G%*....*..b......*....x..?"S......:#..;.Ky..o...`..... ..].'..A.....s.{-..+Z.@..P....'v.bK...}..l1..%!]W.g.'.c...\9o.U^(v!.cM.....5...<S..5yr.m9..._.{...Xf.{.b.yA z.I...i.......?....4+.zs.B.s:....G.;,...X.y.|'.......B..~.9.?.5CH.....Db...e.i......k.^m#......?.Q.[.c.cx^........>...2D..F.@.(v3...m...u..2...1.........vU....s=....%.4'..#%.=..b.>.bH^.>Wa...U;.C..../.}eF.>......."..0...P`..%........HV).g....E
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.839303808068335
                                                      Encrypted:false
                                                      SSDEEP:24:bkCBssqU8ybxFOH3Aw5KrGKQ5oNZBPBsozYN00FdNIbl1O8PMNDHKk57:bkxsL8+7e3Aw5LULk0gWbyJNWkt
                                                      MD5:0099ACAD88534D485A58EEA8389E7319
                                                      SHA1:3694622BBBE9DD5879F00F8F2F2B98B80B81C5B0
                                                      SHA-256:AD0D439A651899606CD374204AFD699993F0DB4BDE897D75036A85E1E7E8E9DA
                                                      SHA-512:E379AC45683977B05863562849CDE1336247DAA3D03F014A2914F083AEA1D5F59EDBC4D6A33E1F97D81DC2272ECBBB70A04A6C1CE9B4FD4498F7034727F5F63C
                                                      Malicious:false
                                                      Preview:WANACRY!.....'...~d.5.3.dF...X.^.C...;%Mz.V.......9p.:....._.6S..=..}6.B..d=dG.N..@..e.k...P..F#...|..{.....vn.H..t..O.j._...,....HK.G.Cf.*...6.v...........mA.Bj...3Q....=...u..$.`.UZ^j#...uC...H....."a.7.p.~$...2.Px.:P..b.......7.`.hE>r.2C.;V"..?......[..5.>R..............}..UW...O.`=..O..V.........w#......,E~.,i.F...$8.......I.N.... ..{..E..|A^.Jw.".T...2...[....#I.l..].!......B)..a.=..E.#Ej.8.a.r..cc<....dYv.=..E..'.h..H.q.~hlVu1..6w.......>.`.........=......[.H.M...'C...%.?Q...D..^.i;..>.i..WR......Kd.N.p...i....%\.(7.s...\;V9X...R.l...KHC...N4GT.\$...b....~.+t...x..."S.ev.....2..2..<.T.[.1z..~Q.....L...\...E5..R.t.......#.e...`..Y........ ...n.wS..'.$.g.r..6......hX....R.bz.t.$86.:..*....=t.J.L..o.W......g.@..(.y..^:.u.b...9....".........W......~j......V.L.E"..jh..-.@X.a..:.\.Xh................&. .9...].K..Qmq.V......D,....A\.RR.M..5.4.P...5oy..Kr..fDV...Q...Ke..x.C......`%.u,N...4(l..H..>.h.E7....?......d....w.?.EX8..Cl.Cq.......a...
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.839303808068335
                                                      Encrypted:false
                                                      SSDEEP:24:bkCBssqU8ybxFOH3Aw5KrGKQ5oNZBPBsozYN00FdNIbl1O8PMNDHKk57:bkxsL8+7e3Aw5LULk0gWbyJNWkt
                                                      MD5:0099ACAD88534D485A58EEA8389E7319
                                                      SHA1:3694622BBBE9DD5879F00F8F2F2B98B80B81C5B0
                                                      SHA-256:AD0D439A651899606CD374204AFD699993F0DB4BDE897D75036A85E1E7E8E9DA
                                                      SHA-512:E379AC45683977B05863562849CDE1336247DAA3D03F014A2914F083AEA1D5F59EDBC4D6A33E1F97D81DC2272ECBBB70A04A6C1CE9B4FD4498F7034727F5F63C
                                                      Malicious:false
                                                      Preview:WANACRY!.....'...~d.5.3.dF...X.^.C...;%Mz.V.......9p.:....._.6S..=..}6.B..d=dG.N..@..e.k...P..F#...|..{.....vn.H..t..O.j._...,....HK.G.Cf.*...6.v...........mA.Bj...3Q....=...u..$.`.UZ^j#...uC...H....."a.7.p.~$...2.Px.:P..b.......7.`.hE>r.2C.;V"..?......[..5.>R..............}..UW...O.`=..O..V.........w#......,E~.,i.F...$8.......I.N.... ..{..E..|A^.Jw.".T...2...[....#I.l..].!......B)..a.=..E.#Ej.8.a.r..cc<....dYv.=..E..'.h..H.q.~hlVu1..6w.......>.`.........=......[.H.M...'C...%.?Q...D..^.i;..>.i..WR......Kd.N.p...i....%\.(7.s...\;V9X...R.l...KHC...N4GT.\$...b....~.+t...x..."S.ev.....2..2..<.T.[.1z..~Q.....L...\...E5..R.t.......#.e...`..Y........ ...n.wS..'.$.g.r..6......hX....R.bz.t.$86.:..*....=t.J.L..o.W......g.@..(.y..^:.u.b...9....".........W......~j......V.L.E"..jh..-.@X.a..:.\.Xh................&. .9...].K..Qmq.V......D,....A\.RR.M..5.4.P...5oy..Kr..fDV...Q...Ke..x.C......`%.u,N...4(l..H..>.h.E7....?......d....w.?.EX8..Cl.Cq.......a...
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.813641977638775
                                                      Encrypted:false
                                                      SSDEEP:24:4amUgLyYURRw5gql58ZHr8tCKDgp7u9fyDhQ:4amUgLu6Di8t9NfQO
                                                      MD5:1F8F17E91FB04BA1B2DAB57036801E57
                                                      SHA1:F813E5FBC8F161DFAFE9CC529B209DE244798688
                                                      SHA-256:0BCE358EBDFE8D92181C0215479219BCF680463BED03F684734D72206C512480
                                                      SHA-512:69D2926AE7FDCACD91B0CF23DC3C93FFA293318F9EFA9CDC85CD9F632F70AE43B6880A33986A606895590FFC2F92168F350081CCEB6790368105F22639029D1F
                                                      Malicious:false
                                                      Preview:5"M.(..H.I..0...ki/...X..i...w.O.R...2.....a.c2...S.U.../..j(.CK..s}h..\..<...D;........#...v4.%pKUu...e.q.9.....5..8)......v.2....?.'a..2q>#...2..I;...>...Y.sV..........mt....Iu......8.z.G.A(..K*......L..pxOs..h.#...>.U.EI.4.."...n]I.\z.\..h.F........I......<..]a....D....?J..Ct....O?..|wD......DH.<. ...6:a.[..\o._'.*.Nt`..0..S..Z.3.$=X....l......p..<...E.v..c..a/.=.....2.n..N^uuV...0...,.HR>.s......>Q$..6.n.+,... .b....~..C..^&D..,..<..,,...2...30.]..)':.4.>.P.aR...FW..%..P.(....Ng......).`..o......[s.\'.....I..0..TQ..'..s..1:...6.....\.."....Fv...@s7.P|.vn..LI3}W.......w*a.N.M.....S...5...T..g....rI..P..6....H..K.....&q"P>=U.......=.#.2...q....H...c......<R...:..kD...o.J.=$Sa*.....?..^acZ/....k..-..%..\;k7.".......*.wvQmc2.."......K....Q....~..N2....}....5.;.T......T./....x.......d..!.og*]..B....Y_..?=[..X..3.p.[......{[\.?:..MW.O.C.....!.R....0......Vo..kb....t`g....y...D..<........`,$.......yH....FJ._.R..J....4....>........s.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.843012106480015
                                                      Encrypted:false
                                                      SSDEEP:24:bkXjpMW10auKrIcLPODvuV/iI8FtB2rf3bwPi6SiekGtGqxUTl7P:bkCWHUcL2QOtB2rPbwakGtFIR
                                                      MD5:7A28663F82E606BA95146412DFF05AE2
                                                      SHA1:7072FC2523E9DBF4227F8D9CF216D7A00E67F6CD
                                                      SHA-256:3DDD0E884963A86A5A283EA78917AE9BB90FDB9A70EB0AADA84D1D247DA8F107
                                                      SHA-512:2E3D2EB4E0BFBC13038994E7119833683D58927FEDEE053C6D78EAE6FCFCE15F72FC8AA3D5B9FF83E349EEC4BA88088714588508FA8E119A4223A0913599FC14
                                                      Malicious:false
                                                      Preview:WANACRY!.......k.*..`.5..NO.7..z..&3.0.C.!..;|....K.i...k.0.%n-.O......5yu.{....N=.a!.0&...:.-.V..a..s...3........W.}...>(..?.Z.....J.&.l.i.,wN.....n.<8cC...s..@(.:.Ibc..dI2F.x....N..]%..?S......4(*D~.....".G<s..z93...6C.......f..7.Z...O.X.C.......\..;+?............+4/....>Z...f.;...J&.P....?._..`..:....[U...\.... ..p .j...I......d.-a......;_...'......G..s...5Ys.S.$...0)n)........G...j.h=.l.K&~(NV.t...0...MD..'.%.8.*..!.y..40I.J..{.EY..s....Z%.}.-..-..u.............#bO.....u.@.S.g..m.>o.-.....n........n.......a.dp.F.=....Y......1.IQ......Sq...R....=.E3.p9...j...P>..J.;...?..q.....8J.p........mv.Gd.k+.b..h.{...Kx..WL.....XX..,de.).Q.*y.......>e...o..a..;.)./.Sw..m.Wm..a.f.|.;..2.j..w....R/..j.&.?..@{...w].Iz...L_.|...t.n...C....v:#|m`e.s.y.`BDd.)6.!...5....i$.bn..=..._cP..V..u..z.Q..j... .i..:.U..F.1Rwy..N..PP......}"v;P...`.3i9.!.......v.D.g.`]cW@....E..?.eu...........|.ZW.9.,.xY..Y5.....2..`......$(K......b.G......'.. .\.A..6..`..1&...
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.843012106480015
                                                      Encrypted:false
                                                      SSDEEP:24:bkXjpMW10auKrIcLPODvuV/iI8FtB2rf3bwPi6SiekGtGqxUTl7P:bkCWHUcL2QOtB2rPbwakGtFIR
                                                      MD5:7A28663F82E606BA95146412DFF05AE2
                                                      SHA1:7072FC2523E9DBF4227F8D9CF216D7A00E67F6CD
                                                      SHA-256:3DDD0E884963A86A5A283EA78917AE9BB90FDB9A70EB0AADA84D1D247DA8F107
                                                      SHA-512:2E3D2EB4E0BFBC13038994E7119833683D58927FEDEE053C6D78EAE6FCFCE15F72FC8AA3D5B9FF83E349EEC4BA88088714588508FA8E119A4223A0913599FC14
                                                      Malicious:false
                                                      Preview:WANACRY!.......k.*..`.5..NO.7..z..&3.0.C.!..;|....K.i...k.0.%n-.O......5yu.{....N=.a!.0&...:.-.V..a..s...3........W.}...>(..?.Z.....J.&.l.i.,wN.....n.<8cC...s..@(.:.Ibc..dI2F.x....N..]%..?S......4(*D~.....".G<s..z93...6C.......f..7.Z...O.X.C.......\..;+?............+4/....>Z...f.;...J&.P....?._..`..:....[U...\.... ..p .j...I......d.-a......;_...'......G..s...5Ys.S.$...0)n)........G...j.h=.l.K&~(NV.t...0...MD..'.%.8.*..!.y..40I.J..{.EY..s....Z%.}.-..-..u.............#bO.....u.@.S.g..m.>o.-.....n........n.......a.dp.F.=....Y......1.IQ......Sq...R....=.E3.p9...j...P>..J.;...?..q.....8J.p........mv.Gd.k+.b..h.{...Kx..WL.....XX..,de.).Q.*y.......>e...o..a..;.)./.Sw..m.Wm..a.f.|.;..2.j..w....R/..j.&.?..@{...w].Iz...L_.|...t.n...C....v:#|m`e.s.y.`BDd.)6.!...5....i$.bn..=..._cP..V..u..z.Q..j... .i..:.U..F.1Rwy..N..PP......}"v;P...`.3i9.!.......v.D.g.`]cW@....E..?.eu...........|.ZW.9.,.xY..Y5.....2..`......$(K......b.G......'.. .\.A..6..`..1&...
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.819532918322578
                                                      Encrypted:false
                                                      SSDEEP:24:7EWArNP6HlAw4ulSpxWYz1NyqbI1wfL3eHrTaUrIZ3Fp68KX/UVizp2:7nClGluxzaqE1Ag9UZ3368KvUIk
                                                      MD5:889970D20C38506CB632BC090C9C9BE2
                                                      SHA1:3188B2720EEA5B96D73328EB5875A66F876E76E0
                                                      SHA-256:655C27953F82AD5035F5FB5F0E79E768A6BABB64E66B6A8AD1B9E2D142BC3981
                                                      SHA-512:A2544EB1D249DB0A6534C15AC6EBCC92615CEC1CD2B2FD856C002BD29FF4133AC6E9F002670209AF5AF2441E4CCFFA49703E51285713B249B3341A58518BACA9
                                                      Malicious:false
                                                      Preview:*`..=W....b4I.......x...}...+3.<+.c.11...H.fgF...C.H.......BL.;>e........I-......kN..d.....3..%...b/1....Z..T.* %Q..<.!...c..Q..F.....6..<:..A.....Z.`,..?9...0.8T..A5.r4.p].):........bIG..;....t...%lh'....s.j[..\}!.u.s(.,T..%....9.s....$...m.yU .3..../.l..5....p...R.{.,/.}.gp.K..w..&.A.j....?O~....(.:..m.Xx..sB......Dp.d...y..,..K...t....D`^.A..TXg1.L..0.... ...N.').G.5...:....E...\f.7..'..V.*..`tj/.'....(.A.Y.3.;."."..(!v.C)...r...w^.~1H.....K.uU.(.....~....]......5[.N..`....9j..R.3.....,w^.....'.0..........n.f...f....Ke.!o.V..U.~.6..PM..6..p...Y.H...~.b..7....$...2......93...../....N..I.W.....W"?E.?...':L..'[...v....e4#5.j.y....m}m..1.Rx..t].2<d.c)....7F......J.K..a.R9..."c G.......)....&..7..e...i.($9..mMj..@...q+.'1...Rg..\. .......v.~m..2.z.{@.r...Po_......k..)3.,fh...VX.N..D...)......D....*.......2.yU)..G9RX#...%}2..$.2S1......`c.>mX..9.K]..'.v..O.J.@<`s...A.L..D.j.....2..-O.7.8.4.u.......w...*~...3c!.1......]p?.d..)..."._>o..|#..
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.846351623228352
                                                      Encrypted:false
                                                      SSDEEP:24:bkuRfS5THyD74xcnlbRpQQ+OYX2SuGOiuxfcWBTTU62V6FN:bkukTHc7Pn/pQQ+Ol0OiMBTTV2sFN
                                                      MD5:AF84C1C8C5D0BF63DD25B28B655AF85C
                                                      SHA1:9B48F6C0E23513A68CDE5EB5D4CD0F7DA5123A0D
                                                      SHA-256:97292BA9CF03E76C0C38C58FA98542EA2304387C1CE8FB0CE66AAB1DCB942804
                                                      SHA-512:D966BFCB9D063E65CA6573AF765FB33B71DCF905D7A2E8D530AF9DC50F999AE97CFE23D1788EF1C9F852732157D23F9704B8FB82497F48CB0259100B24C78E03
                                                      Malicious:false
                                                      Preview:WANACRY!......a.&.P]..H..R.>:...uR........^.....{.2e._.QW.B...I.:O{....0.....$zj.\...g...T.....m..6..x..e...X.V.)..9.I..#.T.H.b..t.[l{....Q.a...zH..Ix..(HP.-..Z.M62x.:0z.G.Oa.e.W[.C..r..2[A!F...6.1Q....>....P.s...h........F.E.}.y..............'..~LM............W.6^..>...0...Z.A\b-Y..|....Us.....I"k..2nd.3..n..6.\..A.4....S.....z..{.1.(...> A.2]..R.S._.J.`5?...q....UO8.....)X[.E..{'..t0.m...b."F{.. ..*Fqbj...z..e.Ia"..5...E..s:.|......,55/[fPU.S..<70....J......s....+xR. ...M;...'..d.F(..W.4%..:..........F.h.8.K.4..P.j.R..#;R.....I..J.H5.2...@....K...SN....+.j(..I@.~sh.....Bj..j.......-....aQ.(.s..m.......j.:`.P;......Hj.4.L$.#.V...E& .#.{.d...y..e....7_.`P.^b....c..."g..?.q.......V............?'.. ?'...L....[4.].R.....s... x#~.oh..lx.~.t+q...o(..X.`>.j.}..IW.....#Jg%......PM...}....e0..@.z-...=.L._^...p..2..Rx...Kd.W..[.s.._...UC$A.o.(k.E...).7d.X..2...L.3o...Y...[."..I{....5...gfR...|A.v..>.lW*~8*/..&.g....q6...{.vF..C.....hXd...@
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.846351623228352
                                                      Encrypted:false
                                                      SSDEEP:24:bkuRfS5THyD74xcnlbRpQQ+OYX2SuGOiuxfcWBTTU62V6FN:bkukTHc7Pn/pQQ+Ol0OiMBTTV2sFN
                                                      MD5:AF84C1C8C5D0BF63DD25B28B655AF85C
                                                      SHA1:9B48F6C0E23513A68CDE5EB5D4CD0F7DA5123A0D
                                                      SHA-256:97292BA9CF03E76C0C38C58FA98542EA2304387C1CE8FB0CE66AAB1DCB942804
                                                      SHA-512:D966BFCB9D063E65CA6573AF765FB33B71DCF905D7A2E8D530AF9DC50F999AE97CFE23D1788EF1C9F852732157D23F9704B8FB82497F48CB0259100B24C78E03
                                                      Malicious:false
                                                      Preview:WANACRY!......a.&.P]..H..R.>:...uR........^.....{.2e._.QW.B...I.:O{....0.....$zj.\...g...T.....m..6..x..e...X.V.)..9.I..#.T.H.b..t.[l{....Q.a...zH..Ix..(HP.-..Z.M62x.:0z.G.Oa.e.W[.C..r..2[A!F...6.1Q....>....P.s...h........F.E.}.y..............'..~LM............W.6^..>...0...Z.A\b-Y..|....Us.....I"k..2nd.3..n..6.\..A.4....S.....z..{.1.(...> A.2]..R.S._.J.`5?...q....UO8.....)X[.E..{'..t0.m...b."F{.. ..*Fqbj...z..e.Ia"..5...E..s:.|......,55/[fPU.S..<70....J......s....+xR. ...M;...'..d.F(..W.4%..:..........F.h.8.K.4..P.j.R..#;R.....I..J.H5.2...@....K...SN....+.j(..I@.~sh.....Bj..j.......-....aQ.(.s..m.......j.:`.P;......Hj.4.L$.#.V...E& .#.{.d...y..e....7_.`P.^b....c..."g..?.q.......V............?'.. ?'...L....[4.].R.....s... x#~.oh..lx.~.t+q...o(..X.`>.j.}..IW.....#Jg%......PM...}....e0..@.z-...=.L._^...p..2..Rx...Kd.W..[.s.._...UC$A.o.(k.E...).7d.X..2...L.3o...Y...[."..I{....5...gfR...|A.v..>.lW*~8*/..&.g....q6...{.vF..C.....hXd...@
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.831493138573924
                                                      Encrypted:false
                                                      SSDEEP:24:NFdWvqieqa5tNERYVMYwku3xCNXVQND/Y:F0/ogkMYNuYhmM
                                                      MD5:14A80476AA53BC513B7D5204B494E414
                                                      SHA1:021FFF9D1A98DB83B9F96894FD08E39E33B7C7C3
                                                      SHA-256:F50F24D19F4AE3B0E62A599752B183FCCA37A22994985C1213C5D9036C711F4A
                                                      SHA-512:02517B9722124D3AD22B9AF230229CECB033A694799B23F7544BAF31CA16147CBF8AE880671DD9D1512E56841495CA06C2C9CF20611C9B6378F0BAF030615944
                                                      Malicious:false
                                                      Preview:.?..d.(.Q...s.L...-!0.8?n.5...n......)..I....-....z.V,.%..y.....qLC.$.....St...6*...b.V..,W....j.#..sP.z.8.....D...NI...Q....}8...@5_....P..w....T.R ...].'8...<.jO..*.T.a...%5M.K .,...l..4......T.;.z...tr..#..<..^..a."z.&..&.../..@6..|..9.....}M...f.... "5NT]....=Bx..?Rx...Jk...LW.....LPa)....V.b..+....J.+.....$p3.....)..F.f7..P..4..#=...5s..8.......Z.k..e.I...Hg!.....1.. .&w.u...o?..].G.e".o.L.tb&...L`..........g..d'....X......n...R.;.m..-.[]....._.s......\......fV.io*a.}g..hh.........:5..d........NI.EH1.6..P....~..a...+.G...5.I.j..F,..h....Z7..I.c./.HB..:.._..C...kJ.. V@l.C.2@5.A.?...{.b...4..u.sQ....d..4.+.k.....z...u....^.....~......8M].5"U.6.......c.>.t..r&..vm.......4.....]}.....HDC....|..#V.1..0...xP...k....HV"..-;._..n.f.M...p|...F9......C.LpE..>bD..B......._wB.(q].P..!...k.V2.T .4...=..6....(....)....W.<B*.e.4}4#.H..=!.R6.!...z0.....A.8."....o..^.RU..V..T.Q....'.".^...Ynr].=2Bk=N.l...IcQ._#/.}..h.c..sh.......< ....B.-.)E.....
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.857335923348337
                                                      Encrypted:false
                                                      SSDEEP:24:bkAN+y9EUDIjz1Wj2YjHFSGWBAXe+RTLZ7fMpWxVgdzAvQ2rJ7Wgju:bkI+ylSO2VzN+RHZLMpOgN87Wgju
                                                      MD5:075AB6F8968579E6013A92C508DD67C8
                                                      SHA1:C8A4C414D88527F5472C2D3009BCB94550642E89
                                                      SHA-256:0604EF7204805073845AF1505ECE954CA735BBEBDEB58095263E843698458DA4
                                                      SHA-512:9DD7930773258E09316D50FC262B0AF4BB4FE995849B9D01EF1D609BBAE4196CF98E786BA2F57B21BB914599DA24F8A85403FBC0728386292A96F443659CFC1E
                                                      Malicious:false
                                                      Preview:WANACRY!....u.`_.......RR...)CO..vN5..%q.5..5.I...n....+~d.-..F..6R.Ha..f..p...\....0..?.c..IH.st#....Fu\..@....Wz5/....z.|V,.....D.........Q/>...2.R.......P.....6.(;.Q.. ...#..0y66...ho.P...g......mf..1n#:.d.v.m..6b.o%c.f.....F.p.V.....(.2...o.................?.|(....\.....Wk]..V...c......U.a...!......)I.>EF. ...R...Q...Zg.t.3...q.7.+..x..D.kPj<.~0.M.O..|.P....{.<....4...#M.i).y...a.hk.7....{_...M...h..G..PIm.{.b....2.>QDD.~....s..IP#..#..)}o..p.h..E1..>+_h........T.i.r.9 ....K..`@.S..2".%....c.:.......`ND..M..e..Z;..3...a..+..v..!.w......8.T...3.^9..o...<-..x...O0........g.7....(..E+....]l3.g..l....q...r.2..Nc..!.....:.i.<1..,.<l.....{...0.5.........z...u....2c.%U...A........L..W.2..VV.n.p@.......&....-..iD.(.J..J.=7./.w.4.]k.2..Y...O.^..3..SVQ..O..s...V.(...|.+...\g.5;....?>o..........w..=~...B...`..vU..2Kx. 8..5"...<....O.p...q...........@=..S..'..P....#....<..+....I..t...'...........jz,...&K.......b......7b.U2d..a.0B..@(.x...[.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.857335923348337
                                                      Encrypted:false
                                                      SSDEEP:24:bkAN+y9EUDIjz1Wj2YjHFSGWBAXe+RTLZ7fMpWxVgdzAvQ2rJ7Wgju:bkI+ylSO2VzN+RHZLMpOgN87Wgju
                                                      MD5:075AB6F8968579E6013A92C508DD67C8
                                                      SHA1:C8A4C414D88527F5472C2D3009BCB94550642E89
                                                      SHA-256:0604EF7204805073845AF1505ECE954CA735BBEBDEB58095263E843698458DA4
                                                      SHA-512:9DD7930773258E09316D50FC262B0AF4BB4FE995849B9D01EF1D609BBAE4196CF98E786BA2F57B21BB914599DA24F8A85403FBC0728386292A96F443659CFC1E
                                                      Malicious:false
                                                      Preview:WANACRY!....u.`_.......RR...)CO..vN5..%q.5..5.I...n....+~d.-..F..6R.Ha..f..p...\....0..?.c..IH.st#....Fu\..@....Wz5/....z.|V,.....D.........Q/>...2.R.......P.....6.(;.Q.. ...#..0y66...ho.P...g......mf..1n#:.d.v.m..6b.o%c.f.....F.p.V.....(.2...o.................?.|(....\.....Wk]..V...c......U.a...!......)I.>EF. ...R...Q...Zg.t.3...q.7.+..x..D.kPj<.~0.M.O..|.P....{.<....4...#M.i).y...a.hk.7....{_...M...h..G..PIm.{.b....2.>QDD.~....s..IP#..#..)}o..p.h..E1..>+_h........T.i.r.9 ....K..`@.S..2".%....c.:.......`ND..M..e..Z;..3...a..+..v..!.w......8.T...3.^9..o...<-..x...O0........g.7....(..E+....]l3.g..l....q...r.2..Nc..!.....:.i.<1..,.<l.....{...0.5.........z...u....2c.%U...A........L..W.2..VV.n.p@.......&....-..iD.(.J..J.=7./.w.4.]k.2..Y...O.^..3..SVQ..O..s...V.(...|.+...\g.5;....?>o..........w..=~...B...`..vU..2Kx. 8..5"...<....O.p...q...........@=..S..'..P....#....<..+....I..t...'...........jz,...&K.......b......7b.U2d..a.0B..@(.x...[.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.798353287802944
                                                      Encrypted:false
                                                      SSDEEP:24:s4nCbVNINFKRxp9n3MmzaNzmkye0+E9UUQEc4aX6poMj5idO:XnSVyKHX3rrjUTsJidO
                                                      MD5:B15C81F42501DE98BE7FED436E8BFEFB
                                                      SHA1:94E088B65A8DBE07FC567F82AF775A2649EBCEA4
                                                      SHA-256:22535A9D9854293EE86CE4F5C441CF3888BE0E81CA6CD7E5C11C1213FAB95DF3
                                                      SHA-512:9E3517AD6B6561581896E39F8888594E14A1E12936A42908FD4477AD7FE421C9D985A2805637358620CF08BDCD143FB959183E1F18CD775C671D5C0D2CFC0867
                                                      Malicious:false
                                                      Preview:.8...>Q.....I....<...V.{Y...{R...M&r..?. .m.O.h).K-...F}$t.Y.v...A.T...c.6{.*c..hV.!u.C..f%P...y.Jm..z..A&j..P..~.EP&.4].*.'.............UX.6m.......01.?9.6VQ..:F..kC.\v9..m.:.ylY4....D....W..@R...e^.H..S&.Q.x.Y86.n.P.nN..A.......UC].1..g..42.o.&on@I..!LKd..g...x...."'......].....`.-....&ggk..4c..^.od!'...Z...&P|.0....s..1..\<...h..... ...~.l2.f.$.....`...t.U........I.^...T...@..t4.8#.L..\d.bA....7;r......]..$-du..g.u...$zp.'....8..j....A(#w...$RQr.R}!U..-......u.U. A........2...G>....Ai..GK....e..qu..3...V..........`... ...O9.2.Z.....e...#UB..........Q..r...".jQPYX..a,FK........o...0]p4...e.xE..H..c:........S.I.U.*......^B.0..R...;....r?..z...;|..2l.5.h....|~..*].vlFv..2[......?.G.c....Wy....C...MLU0|.+6{.Y.q..-..t..:......-...Q....!...s..g.v2.l.....).'..!......Ls.5.Wb.G....-.g.^~.j...]...l..(.....C~..^U....^..v=.X-..X...$...o....=$../.:^......)]O.X2.6.kuH.....<T....K..p..As.h.c(A.......$.D.....^'..4f..c.R..'.D...3D......h.m^..<GC...!...P....(V.d.k}....
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.8293868356679495
                                                      Encrypted:false
                                                      SSDEEP:24:bkYhhEVPOFEe0aO9UpWZ8FzRWHumU1LxOJ5USO8w80JFSrJ14v7IwAE25aHmMn57:bkYAAcUsZ8nbmUloXrO20/Sr4vkwD25Q
                                                      MD5:ABD6AE01FE498F6859D4DB93EE99D906
                                                      SHA1:42542CF8CD3C0DD82F906FFE57D198531413120E
                                                      SHA-256:AA96AA039B5056AAFD72A489284C97A7DF366CC63364E4BA4FCA71F1BEA5BD17
                                                      SHA-512:93CC7ABCE0D02BB5D3741757D17A341E50D27E0F486A7ECD0D2BDE7100300EDC3C02A1816D080A81823E6DAA5172D7600B225568F26F8BA48BFCE3C6139896B9
                                                      Malicious:false
                                                      Preview:WANACRY!.....($.c.~...5E.c:.I..t.c..Jq..'?.......9..WO.....U..8..BT...._.h.5.|.>.....G..=4..{....#..I..gr.lsd(..............2...l..*_4..5S.j..iC....%|F3a.prk.\.Y...[R%.$.Y...*.....vK....].>..!'.H.....2FuS^....Y../.|..v......}.,..v..E..c....}...as.d.5.............._.x!?.9.M.\..PT..!....\....N..Z..$.R.%....AK`......yl.2;X.k...b....X...wP.....T...t....JU].6.H...3...IY.!...hD.k...`...sx..e..BT{.co..7..^...........l(Y.........'.Pg_._..^...v ?.....Two..*...lv/..!./9.Be...z....Ez.X..#.w^..g1....=.........E.<{.-.....5t.....J....n..@T..a.Q.}....I....;.0,os..+...F/...w...Ah....[.wp.!.=......v.:.......~.N...?..>...1vs. ,_.9f..C.....@.....nD....]...E#6...B..0.TgkfR.U 6.8........3X./.x..w..A..!.......z.J.9.~8...0....b....K..Eo...ic...G.z[o.u.....^a9A..9.}?A.o2....e...i.W...GTs.....8.[..U`T.*P..G..s)-.4..;.T.c.r.[...gK......s.c..7.$......$3(.<Jo....S&H_.e6...I..P].s7.} .0.....w..7.I....|Q._p~.....V.t6...".m.zz..xX&..%*)......... .:98/X....W..TI
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.8293868356679495
                                                      Encrypted:false
                                                      SSDEEP:24:bkYhhEVPOFEe0aO9UpWZ8FzRWHumU1LxOJ5USO8w80JFSrJ14v7IwAE25aHmMn57:bkYAAcUsZ8nbmUloXrO20/Sr4vkwD25Q
                                                      MD5:ABD6AE01FE498F6859D4DB93EE99D906
                                                      SHA1:42542CF8CD3C0DD82F906FFE57D198531413120E
                                                      SHA-256:AA96AA039B5056AAFD72A489284C97A7DF366CC63364E4BA4FCA71F1BEA5BD17
                                                      SHA-512:93CC7ABCE0D02BB5D3741757D17A341E50D27E0F486A7ECD0D2BDE7100300EDC3C02A1816D080A81823E6DAA5172D7600B225568F26F8BA48BFCE3C6139896B9
                                                      Malicious:false
                                                      Preview:WANACRY!.....($.c.~...5E.c:.I..t.c..Jq..'?.......9..WO.....U..8..BT...._.h.5.|.>.....G..=4..{....#..I..gr.lsd(..............2...l..*_4..5S.j..iC....%|F3a.prk.\.Y...[R%.$.Y...*.....vK....].>..!'.H.....2FuS^....Y../.|..v......}.,..v..E..c....}...as.d.5.............._.x!?.9.M.\..PT..!....\....N..Z..$.R.%....AK`......yl.2;X.k...b....X...wP.....T...t....JU].6.H...3...IY.!...hD.k...`...sx..e..BT{.co..7..^...........l(Y.........'.Pg_._..^...v ?.....Two..*...lv/..!./9.Be...z....Ez.X..#.w^..g1....=.........E.<{.-.....5t.....J....n..@T..a.Q.}....I....;.0,os..+...F/...w...Ah....[.wp.!.=......v.:.......~.N...?..>...1vs. ,_.9f..C.....@.....nD....]...E#6...B..0.TgkfR.U 6.8........3X./.x..w..A..!.......z.J.9.~8...0....b....K..Eo...ic...G.z[o.u.....^a9A..9.}?A.o2....e...i.W...GTs.....8.[..U`T.*P..G..s)-.4..;.T.c.r.[...gK......s.c..7.$......$3(.<Jo....S&H_.e6...I..P].s7.} .0.....w..7.I....|Q._p~.....V.t6...".m.zz..xX&..%*)......... .:98/X....W..TI
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.810970812976166
                                                      Encrypted:false
                                                      SSDEEP:24:0p/iQ3NiAXUy87GFo5ofNZbCBDV8zPP3mWYxkrfMXzZMIsbys1KTB:4/igNi+qCLfeBBQPPWWYxkTjD1KF
                                                      MD5:FA71DCAD7AA34BDCEC4F93B6CF6F4F8A
                                                      SHA1:1E1DA5E5F1749FB1EA56B5DABF631AAA84D06867
                                                      SHA-256:9899FCEFA62F2B7D4458E03346D61F64D94280D21112F0B11E0002EB7BAB6DFB
                                                      SHA-512:2EDDD4770EFB022EA7430D5EF8EE6FCFCA5C47BA2FDDE26575A382649C3A0F5C814D91148D2352F9840D9829D4BD63021DD5F92F2AFD27A0BE05A4019F90044B
                                                      Malicious:false
                                                      Preview:]..X.m..1G..U.....h.,.W......g....?.>...:.1....Q[..{.j%...Qg.7...}x...."D..I..G64..y.w.P.7g...>~.:.1..?C..R ..k=.)..j..(...p.ov2`...U.lN.../...:.sp.....c.V..w.D..h ...e8.A^...0..1.d..]rsW..$tI...%...?l1 (..-{q..v.E6FLt.#37vj....>....0.yZ.......2.|.<W...A.....C..$.j.j.u.R....x.i5.....%1..>|.2.*.HH..#...T'r.{..4...."+p.*..2.........`.-XV..c....g.P...yb\.g..dR.........OZ;"....7.j..`U.(+%r.J......mKNG.Q?.a.9LZZr......s....t..Je...6.\U...!..)\.{j.D.r;.)...yB.....%.D..E^...k..;.K.v....M..I?1....rTC.....!7-=Z...Kk..<O........sE..S.L..:.D.nE.5=..kMP....h4....a...T.7:.j...w..CH....2..k8..S&G....-...$\.b3..v1@9..C...`+.[.xA..BY.*.H.U1.....8.....u.L..L.....^..W....Di.r..ig!8L.kk.Bd..<0...f}....P.O...X.X....3..&.:UY..%%...W.q..Pr`w..E6.N.&/.]......:>.R'....G..a.Z.L~stnL".6.A.|..<I...Od.n. ......q... Y-0....z....)...8.......".../...H...2F.=.L.^bY0:\....ol...J.....,.B....a./...6...B.C.4......P ..;./.j\..m..2.PBO..E%.}./.I.....|.x......q.X?..UTxR.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.841596506979317
                                                      Encrypted:false
                                                      SSDEEP:24:bkyCGZ2R/VpRepeucrzGCyU0/9/Icq1V0B+DravLfyi0vesUt2Zc38m8y:bkyCGqVzeJcrzGy0VlYJDryOvesYJ8mL
                                                      MD5:87B9FDB1E5CE04F9279A5E504330F16A
                                                      SHA1:B4555AE66AF9372C516F96A97376CBBE49CEC77D
                                                      SHA-256:41AB89D1B3A4068F62DBB8B55E0E02F745F9F329579DCD6196FCEBC2416620E8
                                                      SHA-512:6EEB7F503B9B56E9593B3E1A3395CFAF09BF3A3200A8982508E5A8BA5BC46008AD3DF84133E8C07929282A54F075350A0E010FC833321000C5AC2C979CF730D5
                                                      Malicious:false
                                                      Preview:WANACRY!....u...R.".-E5..O..z.?..t......N^...D".A...oT..P.:....\.lq.*...MWY[.....B..._...mr=...^U.....wqF...2z......wO...e...m. ...'....].-.{.[!~..Y...7......a.....7........B....RCI.GJ...l.L.?t.................t.>x.c.r......i.S&......l..r........a...".Q...............Ai....6.gK.}d._..b.Q8r.b..O...,d......-L....9..2d...Q..H.(._.|!.h.XXf..T]p..-...C8...r.uKo......A.n.2.gr........\........Y.."z&...OM..4{...].!/..@.3.....J.VX.[.a.51....:!.R.a).Omj-)_....W..a..]..&....s.I[4~.Av...zR\...m....s....H.H.t.`..p.cx...M...%..*N.[K...W3b..pF...50q...o.<U.V6.. ....p.e..c=..;n.X}K..R.-e.._.......x...t.c..#....}.3}GA.........JN.....xc..,$..*...T.......A.G 3,o.E.........Q..J#N....r.5.9........9.....a..P.......h...{.g|.nV. .a.$...v(.>*..}.z...a.g+F.T....S..q....@.....LO..Fc..R%.p..!.../....-....!V..f/....D.Q...k.<!...b.Vh..JY......Ee0....`%....S.*g...'.;..wo%.0_...S1..mP.0.....eho.....j.C..TJK7.(..H..I>c.9...]m.}2.f..(.!I..n+.......&...E<.V6..=...P.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.841596506979317
                                                      Encrypted:false
                                                      SSDEEP:24:bkyCGZ2R/VpRepeucrzGCyU0/9/Icq1V0B+DravLfyi0vesUt2Zc38m8y:bkyCGqVzeJcrzGy0VlYJDryOvesYJ8mL
                                                      MD5:87B9FDB1E5CE04F9279A5E504330F16A
                                                      SHA1:B4555AE66AF9372C516F96A97376CBBE49CEC77D
                                                      SHA-256:41AB89D1B3A4068F62DBB8B55E0E02F745F9F329579DCD6196FCEBC2416620E8
                                                      SHA-512:6EEB7F503B9B56E9593B3E1A3395CFAF09BF3A3200A8982508E5A8BA5BC46008AD3DF84133E8C07929282A54F075350A0E010FC833321000C5AC2C979CF730D5
                                                      Malicious:false
                                                      Preview:WANACRY!....u...R.".-E5..O..z.?..t......N^...D".A...oT..P.:....\.lq.*...MWY[.....B..._...mr=...^U.....wqF...2z......wO...e...m. ...'....].-.{.[!~..Y...7......a.....7........B....RCI.GJ...l.L.?t.................t.>x.c.r......i.S&......l..r........a...".Q...............Ai....6.gK.}d._..b.Q8r.b..O...,d......-L....9..2d...Q..H.(._.|!.h.XXf..T]p..-...C8...r.uKo......A.n.2.gr........\........Y.."z&...OM..4{...].!/..@.3.....J.VX.[.a.51....:!.R.a).Omj-)_....W..a..]..&....s.I[4~.Av...zR\...m....s....H.H.t.`..p.cx...M...%..*N.[K...W3b..pF...50q...o.<U.V6.. ....p.e..c=..;n.X}K..R.-e.._.......x...t.c..#....}.3}GA.........JN.....xc..,$..*...T.......A.G 3,o.E.........Q..J#N....r.5.9........9.....a..P.......h...{.g|.nV. .a.$...v(.>*..}.z...a.g+F.T....S..q....@.....LO..Fc..R%.p..!.../....-....!V..f/....D.Q...k.<!...b.Vh..JY......Ee0....`%....S.*g...'.;..wo%.0_...S1..mP.0.....eho.....j.C..TJK7.(..H..I>c.9...]m.}2.f..(.!I..n+.......&...E<.V6..=...P.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:ASCII text, with CRLF line terminators
                                                      Category:dropped
                                                      Size (bytes):933
                                                      Entropy (8bit):4.710902136409594
                                                      Encrypted:false
                                                      SSDEEP:24:ptrPzDVR5Gi3OzGm0EigS1xbnS4RQhbrW8PNAi0eEprY+Ai75wRZcet:DZD36W3ChvWmMo+S
                                                      MD5:7E6B6DA7C61FCB66F3F30166871DEF5B
                                                      SHA1:00F699CF9BBC0308F6E101283ECA15A7C566D4F9
                                                      SHA-256:4A25D98C121BB3BD5B54E0B6A5348F7B09966BFFEEC30776E5A731813F05D49E
                                                      SHA-512:E5A56137F325904E0C7DE1D0DF38745F733652214F0CDB6EF173FA0743A334F95BED274DF79469E270C9208E6BDC2E6251EF0CDD81AF20FA1897929663E2C7D3
                                                      Malicious:false
                                                      Preview:Q: What's wrong with my files?....A: Ooops, your important files are encrypted. It means you will not be able to access them anymore until they are decrypted... If you follow our instructions, we guarantee that you can decrypt all your files quickly and safely!.. Let's start decrypting!....Q: What do I do?....A: First, you need to pay service fees for the decryption... Please send $300 worth of bitcoin to this bitcoin address: 13AM4VW2dhxYgXeQepoHkHSQuy6NgaEb94.... Next, please find an application file named "@WanaDecryptor@.exe". It is the decrypt software... Run and follow the instructions! (You may need to disable your antivirus for a while.).. ..Q: How can I trust?....A: Don't worry about decryption... We will decrypt your files surely because nobody will trust us if we cheat users... ....* If you need our assistance, send a message by clicking <Contact Us> on the decryptor window....
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Archive, ctime=Thu Jul 25 21:01:45 2024, mtime=Thu Jul 25 21:01:45 2024, atime=Fri May 12 05:22:56 2017, length=245760, window=hide
                                                      Category:dropped
                                                      Size (bytes):575
                                                      Entropy (8bit):5.140446565826782
                                                      Encrypted:false
                                                      SSDEEP:6:4xtQl3y03CpzeVs+bTNAUHUtxXCzaMmM7/gtrUod6tMljAlpdmqLEoJ4D6Vod6Nd:8iypzYNbd0thHZOgZUobjArozhmV
                                                      MD5:CCD2610ADD4080C4DCC35A11217DA6A6
                                                      SHA1:001ABA92D58B546C8BD54E0BC4103661F68CF92A
                                                      SHA-256:0E272CF58CC66E7B0CC4F42094232A46B6EC11AE5ED695BA4156A1A28DA41E6D
                                                      SHA-512:36DC5CE3027E8A77639783E31AC69C9FA61C4761FBEB9A819C1EB49F4A32BF2001C0441FB28D35C4EC9DD1B713576E7894DE8FD13BF14CE62A436F9619093DEC
                                                      Malicious:false
                                                      Preview:L..................F.... ....b{=.....b{=.....`.1.................................P.O. .:i.....+00.:...:..,.LB.)...A&...&........DDj....%.=....(..=......t.2......J.2 .@WANAD~1.EXE..X.......X7..X7...............................@.W.a.n.a.D.e.c.r.y.p.t.o.r.@...e.x.e.......X...............-.......W.............,p.....C:\Users\user\Desktop\@WanaDecryptor@.exe......\.@.W.a.n.a.D.e.c.r.y.p.t.o.r.@...e.x.e.`.......X.......216041...........hT..CrF.f4... .u.E._c...,...E...hT..CrF.f4... .u.E._c...,...E..E.......9...1SPS..mD..pH.H@..=x.....h....H.....K...YM...?................
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.779474588765354
                                                      Encrypted:false
                                                      SSDEEP:24:8Gg+iO31DC85H2pOeNm1o27rvso+OWR1nJLVl+oZVzlovXYv+:IO31W85huo9rvWOWRxht2fN
                                                      MD5:07BFCECD85606088049049CD0DDFFEBE
                                                      SHA1:0FCE5990C1B409B6E691AE620DAC51184A4B3328
                                                      SHA-256:EEF31FACC957E53CDBB4E2363F956B4715CDFD7803DD7EEB9DCBC77C1B050567
                                                      SHA-512:25F4A34477D377FCBDBD0AFAEE2C5CACFCD19A20FB1E2653F44212A49ABE911960F14BF11D273FF01665089C2ECD6F3001153769BF2F9B52FFA1DEBD1F631520
                                                      Malicious:false
                                                      Preview:.n|f..a.l.;.).I.Q.^.Q. 9..l"..I.,.......?..nd.b..\u#cr|4..'.[Zo.q u.Lw....i..Z..6...V.Y......C....g.^.Q.Yt....+-.[J.....t..?..H....>.\8C;W...8......YQn.b...V....q.:*..%.V&0...9..p(...xd.9..'3.Z.i..7@.~Q!..f....../&1......."..U......2.l3.G..A.~..A..AXO..}/"..}M?...8.9CAu.....77..or.O...c...7x.G.......e.3.n..Oc..Z..Ax*.........s..\!;......BRt.o....Qf..~.....L..;.....5#.Jhp.+..u.Y..'....3sv.7.7tc..E.)........5v......,...@..wG4.U{?e...{Xe..[.....l.......4.~..C".'.S.?.....i.s.z`"....v7.+...-l.S.-..O\..$.W..J...xf.i..- /.r...3.g...e.....85._X.....O.6g..(...~v.Zk.?.A.{.j..D.AR,-.I.o....u...09.j".#.1..k.Rb..a.I.k..m?.../..O[}...w..z.0..Hi.._......)d.......7%~01.a..n.,y..3.gQ...l.1.P...lX...u.o.#6.....VU..y.o....)i`..wu.#.;....4.9C0stF...f......mc..].}........y....V.]IBh..kR..c^.7.Y@..q.D...F\...f.W..|j.E0..e.S.N.....&X7......9...UJ.r.q..z}..I.............,!1".f.].....D.D.:.e.#.c.|.e....=......mu.k.,.....Dn.k.9...XD..r.V.K...~..6.7......f..(..d..$..1
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.838938555493282
                                                      Encrypted:false
                                                      SSDEEP:24:bkpnsOQjkr1Gb4UhQ8qxB0tYqGGh/JUAUvM9Qmdfb5uDEWREw+8txpegy7cmkKMN:bk1sOQjkpZUceN/vUvMzKVUejegkc0DS
                                                      MD5:8FA1CD921F8B9DCB452AB5192CBE566B
                                                      SHA1:1AF05427C2AAA8B62879CBED39F78A1DAA3696D1
                                                      SHA-256:71C7A4029327E542709DDA73B850F37D0A53BFB31971BBC8F604E48A3C27DC97
                                                      SHA-512:E1DFE3ECB313EC14CF204C4EC8922D993FF3284D090DB344B3662144DFA67BC41D396693CE69E2821C05761685E54BA2DFA37A6205D0C42D4A2585D90DE52E74
                                                      Malicious:false
                                                      Preview:WANACRY!.....)..{.....4..XF.A.....&F...9...y........M.....fk.......ptJ$....c.f.K.....w5a..c.b1>..n...-c..C.>..m..<.3.....R~c.R.f.m........d0..G.0..0a...+.P.h...o.n[M,#...-....]F..a.fY....4...S)..6..$.{ni..*....>K\y...W.%.a...c<M...~.%.........4.....?.................,.>.!aL.......Z.\.zIk|.BO..C"..y..^[2zxA./. T..m.v....pg..9......(w.$...e...d..xX...}.)M.0%.m.&._...C..?.N%..s...N..f.2.G ......N.(9h../..K....j).:.FV.H5.~..\Ox..z.19O....}.....{C....u.....h..\h.c..dBzt.D[...s.j...:}...).8..W.9..c...n..t.....~Y.].....z.z.y..P..s.6 ...r...<.D..$..`p.... ...4....hu=..1N.um....(.S..p2....c...-..*.{.8,+a..Z.U...v.(.....l...}.^..<..CQ{...X29BF$jl.C......]Cam..)..U....{j.<R..`wr...-............U.[..~[....`.v.g.1..?..).xHH...2.u..,,.m....@...UI....D.+>&.W}.\\hah..T.<.x.i...o......+M..#.. ...x...\^....i:....#....[...VM..`.I.p.sK(...u.3v.j.@..8{;T.).vE..a.*u....\fW...F...u.E.0.......|7L.....rq.b^.t ^....l.].}NK...W~&..#.${l"v...T...(.....DC..]..]=,...brO...M.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.838938555493282
                                                      Encrypted:false
                                                      SSDEEP:24:bkpnsOQjkr1Gb4UhQ8qxB0tYqGGh/JUAUvM9Qmdfb5uDEWREw+8txpegy7cmkKMN:bk1sOQjkpZUceN/vUvMzKVUejegkc0DS
                                                      MD5:8FA1CD921F8B9DCB452AB5192CBE566B
                                                      SHA1:1AF05427C2AAA8B62879CBED39F78A1DAA3696D1
                                                      SHA-256:71C7A4029327E542709DDA73B850F37D0A53BFB31971BBC8F604E48A3C27DC97
                                                      SHA-512:E1DFE3ECB313EC14CF204C4EC8922D993FF3284D090DB344B3662144DFA67BC41D396693CE69E2821C05761685E54BA2DFA37A6205D0C42D4A2585D90DE52E74
                                                      Malicious:false
                                                      Preview:WANACRY!.....)..{.....4..XF.A.....&F...9...y........M.....fk.......ptJ$....c.f.K.....w5a..c.b1>..n...-c..C.>..m..<.3.....R~c.R.f.m........d0..G.0..0a...+.P.h...o.n[M,#...-....]F..a.fY....4...S)..6..$.{ni..*....>K\y...W.%.a...c<M...~.%.........4.....?.................,.>.!aL.......Z.\.zIk|.BO..C"..y..^[2zxA./. T..m.v....pg..9......(w.$...e...d..xX...}.)M.0%.m.&._...C..?.N%..s...N..f.2.G ......N.(9h../..K....j).:.FV.H5.~..\Ox..z.19O....}.....{C....u.....h..\h.c..dBzt.D[...s.j...:}...).8..W.9..c...n..t.....~Y.].....z.z.y..P..s.6 ...r...<.D..$..`p.... ...4....hu=..1N.um....(.S..p2....c...-..*.{.8,+a..Z.U...v.(.....l...}.^..<..CQ{...X29BF$jl.C......]Cam..)..U....{j.<R..`wr...-............U.[..~[....`.v.g.1..?..).xHH...2.u..,,.m....@...UI....D.+>&.W}.\\hah..T.<.x.i...o......+M..#.. ...x...\^....i:....#....[...VM..`.I.p.sK(...u.3v.j.@..8{;T.).vE..a.*u....\fW...F...u.E.0.......|7L.....rq.b^.t ^....l.].}NK...W~&..#.${l"v...T...(.....DC..]..]=,...brO...M.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.803761233315607
                                                      Encrypted:false
                                                      SSDEEP:24:XiVG/e2uWGr7Ou5qt+ppYuv55X3jByMlBvqiTvliJ/J3f0s:SVGx+HItE2AXjBpBSihiBJ35
                                                      MD5:E585FEE480C3D4E236808708E510A77F
                                                      SHA1:E564E25E14EF165DF7BC22E6BFDB28CAF9158D6C
                                                      SHA-256:6E1F4308BC744C90C1BAB87A788CB68BA076E246491F412D518A86D2A80F7982
                                                      SHA-512:8048F38AA0562B7FE08F87FB68310E83F19772DD99FF1C7714FCEDA881E42F1EAFE3D8059E92DFF65EA70838450E0C4747C39D43DAC6AEEB10940038632ECEA0
                                                      Malicious:false
                                                      Preview:.b.!..>bs........=.....u/......=N..].mX...PFJm....$n%rn.1.......*)..&.1...W@CF..%.T%O...$.p9..v1.*..=.+k......."...z.[.F.../....)........y.>C..D..W].@...d..@.j&..%......IU..*.".G.^1!;.....5.SJ.fs..R.].D.!.....n. ./.....q\.m..(.C..o...../".....O?q.==.wQ.....y...u!..i...c1)P.K.t...%...........}.S,....y83...e.......n....]..S?...........Eq...u.G.cY.H!.n..s@..bD.T...........B.1...\..|[n?...,a.0.....D!....a.....C....;.x..V....D$..S.)Q...,cm..7...m.o.2.8..^.......?vK2...y.'|.G1.....{h..M...51....:..l@>.K._...aT.v..d.........R.*..o..4..r<....V........?p........R...m...4|=r...g.(.Ik.X.S.kb....e......L...o...b.`.....&...v.V..".>i.$....T.....a...H@.<..x..$..}..R..d*......A......@.f....b.Z..a..O.+~..}.V.....,...b......dD..@6.s.........h.<2.md.v..;.Yq.+".C}..L$...QEL.uP...u..q......."!...m\i...Z.2.k*`.V.0..^.u.. D..sT*..K.y..5..>..W.....sD+2.v.z....51....R.........H..&8=.q):.6d..r.?.............r....%.m../...=*=*..z..D.jp.l.z.`......./......r\M..d)}.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.8284337077189114
                                                      Encrypted:false
                                                      SSDEEP:24:bkxoCnM3/kbTB6cp6s7ihrsYQEBoZsOiQ3boBMpoN6B75Y84BCTQ/5pX11ZWHeyU:bkqCM3c4cYs7WrsluomYsBMpvBdZEiI9
                                                      MD5:E11B9480012ABEBA03A53D347EF9242A
                                                      SHA1:85CD980EF2CF4E1F76395241250F061F65FAC253
                                                      SHA-256:0ADD62120D9167605F134D6E8BC74C7CD72F48C7D890676A784D38453AD8C63F
                                                      SHA-512:B9220FB88947AD0CD213B2AE2E57220E14B702D78B1AF3E2A36FDBE949F7A7D3B0B84126665EE9168417A46AA17229A14A4DF5583C40D7C898D89E60C91760B4
                                                      Malicious:false
                                                      Preview:WANACRY!....,..q....{Y.&.AG.Wa..N3v..w?..N..JZ .t.`jc.....4.u$...a`..!.]}..S.....).X. ."..@r..V...W.H.I.:.I...&x...R...M..d}N...Q..o.........}.....O..a.%..........{..v.t........@......O...E7...j...p?.<.(.:.}K...<s.7.-.."]7O.Aq!..}?W.5o..tW.gB...'..kO"..............k...E0.#k7\..4..jt..h.yA../....H.,...Z^..e+3^b......zc.W.A.T...]`3.c.p.......2.....zg.....9q!...Et...eH..w...i:.6St.l....>..7.r.K$.I.eE.t.=a..x.... ..._...H7-/)....n6.[...M.=@.cz...m..b.hQ.dN.b..U..S...y....0q.C9.!]....@....fa7(..Y3{.....w.AO.....eB-p...(?.>.X.....*;....HZ...e..1..C..p...59..z*..k..........N.>..."........W.G.E....{.......|....UUC.xl.`.....e1....E^.O.Z.b........v.r...t.NQ..F...A..j...G..i.0..3......h..7....B.w.5..}..y..57..o..5.oS.s*u.C.......HC.|...v.NL.L.WOH............q#(2eN...O..l.)......^.Y...1.Zi.....q...iM...]..p....&.G_......M.<VC....A...cLZ...!....9E.. .P..y*.<O.`...|.S.@..V.V....,...i..Gc..,0.....+...~.]k"...+..ia=...~.V......o6:..`.d....T...#|..gv.\.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.8284337077189114
                                                      Encrypted:false
                                                      SSDEEP:24:bkxoCnM3/kbTB6cp6s7ihrsYQEBoZsOiQ3boBMpoN6B75Y84BCTQ/5pX11ZWHeyU:bkqCM3c4cYs7WrsluomYsBMpvBdZEiI9
                                                      MD5:E11B9480012ABEBA03A53D347EF9242A
                                                      SHA1:85CD980EF2CF4E1F76395241250F061F65FAC253
                                                      SHA-256:0ADD62120D9167605F134D6E8BC74C7CD72F48C7D890676A784D38453AD8C63F
                                                      SHA-512:B9220FB88947AD0CD213B2AE2E57220E14B702D78B1AF3E2A36FDBE949F7A7D3B0B84126665EE9168417A46AA17229A14A4DF5583C40D7C898D89E60C91760B4
                                                      Malicious:false
                                                      Preview:WANACRY!....,..q....{Y.&.AG.Wa..N3v..w?..N..JZ .t.`jc.....4.u$...a`..!.]}..S.....).X. ."..@r..V...W.H.I.:.I...&x...R...M..d}N...Q..o.........}.....O..a.%..........{..v.t........@......O...E7...j...p?.<.(.:.}K...<s.7.-.."]7O.Aq!..}?W.5o..tW.gB...'..kO"..............k...E0.#k7\..4..jt..h.yA../....H.,...Z^..e+3^b......zc.W.A.T...]`3.c.p.......2.....zg.....9q!...Et...eH..w...i:.6St.l....>..7.r.K$.I.eE.t.=a..x.... ..._...H7-/)....n6.[...M.=@.cz...m..b.hQ.dN.b..U..S...y....0q.C9.!]....@....fa7(..Y3{.....w.AO.....eB-p...(?.>.X.....*;....HZ...e..1..C..p...59..z*..k..........N.>..."........W.G.E....{.......|....UUC.xl.`.....e1....E^.O.Z.b........v.r...t.NQ..F...A..j...G..i.0..3......h..7....B.w.5..}..y..57..o..5.oS.s*u.C.......HC.|...v.NL.L.WOH............q#(2eN...O..l.)......^.Y...1.Zi.....q...iM...]..p....&.G_......M.<VC....A...cLZ...!....9E.. .P..y*.<O.`...|.S.@..V.V....,...i..Gc..,0.....+...~.]k"...+..ia=...~.V......o6:..`.d....T...#|..gv.\.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.807642973819652
                                                      Encrypted:false
                                                      SSDEEP:24:Tf8PJcgli9kx2q32iHw4TYtO6KBTNW6LU/qWqSY:z+JLl7kQ20w4GKNNltgY
                                                      MD5:B273A2361F93D42B13768E5446DAF380
                                                      SHA1:34DA3D463C516F9FDB44F4E22CA184699D1800D0
                                                      SHA-256:9FFBDF2FF746905FE02945ED335B71B0ED16251276EBA6D78F81D241DD1FDFB9
                                                      SHA-512:FC1414E4A3BEB5374984E89E8AA904B9E25FABE77E9C20194BC074ED4018831685073D2FCC783283BD349707B7D391E7672DDCD99FDD6C8C51E1B5C9D622EB64
                                                      Malicious:true
                                                      Preview:|.Ju)h.ij......7!Q.V...l........<.....O9zd....$..9...$<.q*..Z.u.+...fY...ia....'R.........O#5...=v.$K.^]m3.O.O.r.2..JBH==.^...\..hV_...0..r`A....h..].....[...b.....z:?#Z.fn..`.....Et.r.6...+KFp..y/I1.al#....4..@G$.O.........~...c.e.om.W....H91.7..I.....>.X.AV0.....%q|...r,...u.....[A.%..d.=.1.j0\..q.|..u..>....3.R.....:^.. B..[.^2ar..}k.r....75 ....o.Z.p.R...~..y...A.b.Bb.>..s..:Q>.....L.7M.b.#.g..0.U`.L.;.r.6..GD......O8....bn.7:2...|..x(.\..N.e..&I..A....q\.5......... 1..x$.J..q9.~..k.I._..n...8.......s..5.o.......~!.+.......C.B..........og..a1..M....#.b...[ZVz.fU+TC.H@..S.<....%.M.....s.4..]:.E..L..H.d..a......l..AT}3_~..`.R.z._.....U.{.b.......t..3o.t..3.>X......;..B.%...Q1...s......r.7....qb..x.N..1.pAg..p...!.{D.Sl.....>...E.q/........."..WCs.X.........V..........P..I.....J`...Va..oL.... ^.y.+..;W..B2*z....C.c...C..,RF....>|..(..i.c.B5....3]..>;Y.I2$.q[.;...^...z.O.4...e....E%.<.l.1+.3hj....(A#..$p .n=.....>.K...e....../.&0..
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.8478721423228075
                                                      Encrypted:false
                                                      SSDEEP:24:bkhmE+ArNiI7PibMldU6HV+QrSSI7O1aCBNZi8yssc1cgh2Ak:bkx+Ac6RldfEQeV7VCjKe1h2Ak
                                                      MD5:182A229B92F48F25951B4771345784BA
                                                      SHA1:E015AC08057B1CC9CBC977A67350DFD0BBD48229
                                                      SHA-256:D4910D47FD710C719C969EB84F640DD2339F8E4BD566D26A60028D0D4D0451E0
                                                      SHA-512:ECC451DD1817EC4304B3FE1501D1B55F0ADFAFE23C15D2C3ECC132FB7981726EDA634929177327B5E2E068AE83C1920146C7A9803518FD413FB9F551F4E39872
                                                      Malicious:false
                                                      Preview:WANACRY!......+.5..&..K.8g-..y..3T.u...bJ.!.P9u...._..Y........ ..+8.c..c%........U#.bH........S.dj...-..P/..$G..O.u...._...|..lN..<r ....c0.....<-q.j......u..Y{...a...9[....g..igM+.[.....GZ.nA...x..#A...Y../....|..`..` (d...S..;....Lq.,B..>.g....@...!....$..=]............W...wE.._..W.3s.xK!"n...[.!..B.b.Y%.b........S....Q..}.k@.g. .K.4d.....D.ab.6m../.....3. ..<.;..<..>..~.4~.s.2.[..24..v..f...>..}..#. .G.yQ.].V.Rv.u.8..fKl.L....iW.EW.).sI.q.....l.(.d(..a....=g..3.9.@.y.%..l.R....K..a.S...B...u.n..{.<(q7.D4..(.a.G.u]}..................i..v.u.q.^|....+.....%s1.7O..3.MG....U.....y ..U....B......C.lZ.#.MM.....g].......#..P....fC..[\..cR...KQ.@..o".tM,.J+...cqf..z...K..\3..h...+....M...x..M...P./.{I...2..OU..A..l...T.l......y*@.91.m,..-FX...$..q...=zA....l..lu......dc.....P\....EKh.V\R~...;...v....N...j.l...}!..K4...........w....i..,h..fF...t..~H#.R].`..|Q...:@..,.Nv*X.....5%..y..hY [.......<.....U.....(....!0u........;._p.e.....
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.8478721423228075
                                                      Encrypted:false
                                                      SSDEEP:24:bkhmE+ArNiI7PibMldU6HV+QrSSI7O1aCBNZi8yssc1cgh2Ak:bkx+Ac6RldfEQeV7VCjKe1h2Ak
                                                      MD5:182A229B92F48F25951B4771345784BA
                                                      SHA1:E015AC08057B1CC9CBC977A67350DFD0BBD48229
                                                      SHA-256:D4910D47FD710C719C969EB84F640DD2339F8E4BD566D26A60028D0D4D0451E0
                                                      SHA-512:ECC451DD1817EC4304B3FE1501D1B55F0ADFAFE23C15D2C3ECC132FB7981726EDA634929177327B5E2E068AE83C1920146C7A9803518FD413FB9F551F4E39872
                                                      Malicious:false
                                                      Preview:WANACRY!......+.5..&..K.8g-..y..3T.u...bJ.!.P9u...._..Y........ ..+8.c..c%........U#.bH........S.dj...-..P/..$G..O.u...._...|..lN..<r ....c0.....<-q.j......u..Y{...a...9[....g..igM+.[.....GZ.nA...x..#A...Y../....|..`..` (d...S..;....Lq.,B..>.g....@...!....$..=]............W...wE.._..W.3s.xK!"n...[.!..B.b.Y%.b........S....Q..}.k@.g. .K.4d.....D.ab.6m../.....3. ..<.;..<..>..~.4~.s.2.[..24..v..f...>..}..#. .G.yQ.].V.Rv.u.8..fKl.L....iW.EW.).sI.q.....l.(.d(..a....=g..3.9.@.y.%..l.R....K..a.S...B...u.n..{.<(q7.D4..(.a.G.u]}..................i..v.u.q.^|....+.....%s1.7O..3.MG....U.....y ..U....B......C.lZ.#.MM.....g].......#..P....fC..[\..cR...KQ.@..o".tM,.J+...cqf..z...K..\3..h...+....M...x..M...P./.{I...2..OU..A..l...T.l......y*@.91.m,..-FX...$..q...=zA....l..lu......dc.....P\....EKh.V\R~...;...v....N...j.l...}!..K4...........w....i..,h..fF...t..~H#.R].`..|Q...:@..,.Nv*X.....5%..y..hY [.......<.....U.....(....!0u........;._p.e.....
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.771863276547537
                                                      Encrypted:false
                                                      SSDEEP:24:8ZN5Fr9rUsqlua7hbo1nGq5rIZRImKwvd4VJU5vrq8rI:8ZNRgsg97jIdJz
                                                      MD5:CAF1A9B6624D2F1893737194E135615C
                                                      SHA1:8FB9916D59D1B0367805DF26BE46D1C7B74E9AB2
                                                      SHA-256:99CE521468797CE477A21DAF990AC63B6F86CA8B83948BA249DD18967B1C566C
                                                      SHA-512:582E348C317040BBF9F053BC0039CE5B0080FD63C7D757868A1307EC14EBBCF280A83C446252030FB46197A1F1817CB4593AE298B1BC252A1065904D6C3128D1
                                                      Malicious:false
                                                      Preview:R[.cB..v..p...y..p8..S..E>|t].\.6.....gV@.px~...g_q.3. ....Tl..mk.kF.\I.md..\.8Q2..Y..S{.~..*b....._...,..o.b...~M..T.P...*....v.=..8..ofD.3i=..H.6..M.f...)f.8..o..Z...e../BmS.......Z..bT.M...~f.F.ZL.tF.]....v.Z.l..t.<q....,p.r.@.[.d.5g.!(...Pt!(....%.?.itP..#x.?p....T..,.2..l.F.....S.._.g..b.B75m..@.<.E.,~d..|.>..+....s(..n4P.T....]X...cr.....9f....~.....W...5.n*.....*r?..0..&.|..XS}..q.]...L....d...v.b^c.a..7.......G....!G*0.b<..Z..z5..0&PQ.Zb.!...(P..T......n.-[.9[..%.p.2......3..6_.px...l.O.4<..g..,..m.j....L.`b5.4..<>..E..4.`F>t...~....t....fD..Y8D..gH.~.Qsx.S.gIj.,.1..!.....174;.. ..~.P..Qo..U..........d...h..RU~...W.'S5.....p...-..P.f....5.....5..B....wu.w.&z.F.G.)x...?...d...0...^....U..Q?I...S..<(...;...o.x..@=..1.z.l..Ba.....:B...d..B......0....!.-.j.n..m1n....j....Z........".j.[..j...=.........s...G......TH.i.I...Ly.X.i[.Y...Q.e.....8..(..M...].t.w....3...30..@{.,...2I..C..zL.(...Q...T]..P...(.......Y..9a}.M=....Of.H.>.....
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.819404848756348
                                                      Encrypted:false
                                                      SSDEEP:24:bk7HW43NgRrh8aM/2adnzmJ3fzdTBINAUNE7ozXnHgBuLn78YLYzCVIZDfKOyQur:bkq49gQSu60NAWE7ojnAanF8eVIxfKE0
                                                      MD5:453923DA11CFF355DCE04B75CE268C79
                                                      SHA1:0BFF4E7B02A8D7F3E2B87622DC3DB32BE4F9A113
                                                      SHA-256:35E1A273FF2A42F9604B455B67E27FAA69B197CF5B9BC50106D841EEF3B74083
                                                      SHA-512:6E4587D85C609B990AC02FEACA9AF11CB4399A47A365B7EABF7A0E0F68A23A6A63B53251B47A037144EE0FD16A393F48927B449B93F6841279D3C646EEC88639
                                                      Malicious:false
                                                      Preview:WANACRY!....J.q.x.a...V7....1......Y.......g.c....e......+cxg...QR.U.e!....2V.n..nY...&...G....^...{Q..IxI...F=P.a...4....R^.o.3. u...F]....NN.f.....>:....O..`.......-.A....e....gB..!....<jK.(P%8....q.....Z..p.S.._..4..m.[B...S.t..."...;..8.lLc.g.......>...............UrR]...........t....x...<....?j.%..........3.F3.+{.-p.J.xr...!Z...*H;='Ad... j...I.......Q......_^.l....2K...K......Q6..NH...m]..-V\.V..g.m....a..g...0<.^v<n...6NsC...._pC...y..1.|,.^..N....7.....2...V..7^.{...AH~..|n......Oqx.*Sh.;...lE.@IA...O4.........d.....@x8..vN:&.9....o.g..N..........}g^ ..;=.7e.X.e...w.;...QUy..8&.uH.k.....Nm.....^..$......h.HR..J.m4..&....D..\!.gu.>K..s/.....r5...[.Y*.l...]....F.(..^+.....d...&.9....rq.B......,..Z$|...'.5...h..n...%...f.^..v.....Y.f.q.#...7...Q...x.Q?...B.[..>........f- ..(?>....V....e|m...X....\.i.....`C.................zx..t..]o.a....4Q%9.F.~....n...Q.v".r.........{...#-0Y^....A...q>a..7......{C.....8T..a.T.\.\5'.......
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.819404848756348
                                                      Encrypted:false
                                                      SSDEEP:24:bk7HW43NgRrh8aM/2adnzmJ3fzdTBINAUNE7ozXnHgBuLn78YLYzCVIZDfKOyQur:bkq49gQSu60NAWE7ojnAanF8eVIxfKE0
                                                      MD5:453923DA11CFF355DCE04B75CE268C79
                                                      SHA1:0BFF4E7B02A8D7F3E2B87622DC3DB32BE4F9A113
                                                      SHA-256:35E1A273FF2A42F9604B455B67E27FAA69B197CF5B9BC50106D841EEF3B74083
                                                      SHA-512:6E4587D85C609B990AC02FEACA9AF11CB4399A47A365B7EABF7A0E0F68A23A6A63B53251B47A037144EE0FD16A393F48927B449B93F6841279D3C646EEC88639
                                                      Malicious:false
                                                      Preview:WANACRY!....J.q.x.a...V7....1......Y.......g.c....e......+cxg...QR.U.e!....2V.n..nY...&...G....^...{Q..IxI...F=P.a...4....R^.o.3. u...F]....NN.f.....>:....O..`.......-.A....e....gB..!....<jK.(P%8....q.....Z..p.S.._..4..m.[B...S.t..."...;..8.lLc.g.......>...............UrR]...........t....x...<....?j.%..........3.F3.+{.-p.J.xr...!Z...*H;='Ad... j...I.......Q......_^.l....2K...K......Q6..NH...m]..-V\.V..g.m....a..g...0<.^v<n...6NsC...._pC...y..1.|,.^..N....7.....2...V..7^.{...AH~..|n......Oqx.*Sh.;...lE.@IA...O4.........d.....@x8..vN:&.9....o.g..N..........}g^ ..;=.7e.X.e...w.;...QUy..8&.uH.k.....Nm.....^..$......h.HR..J.m4..&....D..\!.gu.>K..s/.....r5...[.Y*.l...]....F.(..^+.....d...&.9....rq.B......,..Z$|...'.5...h..n...%...f.^..v.....Y.f.q.#...7...Q...x.Q?...B.[..>........f- ..(?>....V....e|m...X....\.i.....`C.................zx..t..]o.a....4Q%9.F.~....n...Q.v".r.........{...#-0Y^....A...q>a..7......{C.....8T..a.T.\.\5'.......
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.817670076743921
                                                      Encrypted:false
                                                      SSDEEP:24:nmGyTb8IKSCWZ3ZrL86sfxEStWlptzQkgNQi8Lw:mGyT9gEZvJwL0RUYi6w
                                                      MD5:5AAEA6C42EB343071EA5924FDD328873
                                                      SHA1:A2DDDBCD5861D7E4793A4FF3959F5DB2AD3CAADD
                                                      SHA-256:143183C7985BE188E81CAB35F092FD35B7977233F8473188774A28B3AF178738
                                                      SHA-512:36516566771E1A83DA67477BCC587E686E3E817EA7B094062F82828BA82F492F8BC46ED5035262F3503EDF7530471A394BBE20D76428D775FDF505E419CA4099
                                                      Malicious:false
                                                      Preview:..\...C......#.....-.f..R...L.e.?.C.@...Y.m.&../O/.....7..H..E..\.6......@.X.4.(.......E....,3.,.._.F..t+. 3.D....K.+...s.mB...F.8..l.Eu..7|9..f....#cA5l."..f5.S].F...x.<49b.*.n#.y..7c..B.z^.*..r.P.M..N./............).ot%P.Z+A9T.P.(.v.Z.h.iea6zK8.:..q..g..T..o..=....N.9...w.Y..(...:.x.....v.M..6..S.w/.<.o..."...P.0Q."...(....?.4./.b.S!...s..._.na.1.GxT/.|....u.......6.Yl.@.W->.U.......5.f*.y..L..#.Kj...uG .Tr...E....^E.%..U..~]..MC...7b...U....w...p.}....E.~Y....aEG...e9. $......Cl^y.#h...G{.3.C;b.42O50.#_.yI/...\`.v......<.+nN.l..oL..IK..... s.Km.%.'..'.P.......t..N....".....~........gL.<....o.6.$.*..#*\rhL.gYW..A......d..\.5k0;....b....X...tU..T...3.._.....f....M5.t..od.:..K..#....9......|.l..h...0.'..u..5.Q..b..(|...o$.aCQ....m.K.|.;.M...g.ZvC9.r.?.V...."@.......vZ....9,.........g4k.X.p.\@._.x..2.wz.kI......b.R..]...J.G:...!....{....P...kd7-$,H... h.(.7YJ5.@.j.+..,.4.Y.T...f.......80...;.n$............/..`...o%......t..'
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.840369736263654
                                                      Encrypted:false
                                                      SSDEEP:24:bkzOXAPbncMyNPJ34hTQDS4QSGD0B4ypWvhtguGxKjiA2s+qHElPnNicKN16bAza:bkfPbn7yNGcSXO4yoh6bKGA2R4rqrYCb
                                                      MD5:8FAF4036B736197B7321447AB9DE8370
                                                      SHA1:9812EAA1D92EE3F7385B2F1F536F0D3F61A8344F
                                                      SHA-256:5FBEA8F7190EE05A8ECD780895BE6987A8577293282F11139499DB86A32947E3
                                                      SHA-512:589EA113917C1FFF6AA0313EAF5EF7B5513C31201D6D8D7593A54CD475BEB3E3EE3D706FCE9BFC4D7A3E8622B2D03C837F6082053FCD4C04C17BC45C262302DC
                                                      Malicious:false
                                                      Preview:WANACRY!.......y.....<....&...?~.C.c.x...T.f......>..1.........%z%.S".....J.Yaw.^.+..6.W...jF.^Yk.7G,....V.^j1....f.6DY..U7.]c)..D.rZ.)...~.{.5..C......".E.h.1B......Q....I.....P...Gm..4F......l.4.#.h.../..[....*P]..c..9......m....ew.J..P...?7D.......L................)....x.1..56........cf.... J....&.u..G....o9.... ....Qyz{M~.,...t.&@....I.... ..}....k..t.~..^.^yu.s(..[.........[.4.B..Y-;a...FS..H.#6)....)Hw...%x..4>.Q.,.[.?4....1...:-...r.c*....h.,C.</(..&.~f.I.}....gro.N.V.{.M....._-..T.0...,.4..7m.t......!..yb.....N....Z [.....{.;.rc..........5,.......>...8..r...\}...{..f.....\...i:T.l...5..b..{.e^a?...oB....7.{..]....S(....l....)3SI....0..I......Tu... d.3.. .?Q..}pQR....L.....>!.9.X.........AK....m.......R..`..#Gf.......k.m.S...b-.\_.V.......>...t..(#U%.}-.._....n..O.6..vm.....@A.fH.Sq..u`k8w.1.TU.).}.1st.7B.Y.'..k...4..M..5q\...}..G.E.As+..-'....7.b.g>.~g....E..+..........*..K...R.L.P..Q....(..w).....q..../S(.......#R..M...`.....
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.840369736263654
                                                      Encrypted:false
                                                      SSDEEP:24:bkzOXAPbncMyNPJ34hTQDS4QSGD0B4ypWvhtguGxKjiA2s+qHElPnNicKN16bAza:bkfPbn7yNGcSXO4yoh6bKGA2R4rqrYCb
                                                      MD5:8FAF4036B736197B7321447AB9DE8370
                                                      SHA1:9812EAA1D92EE3F7385B2F1F536F0D3F61A8344F
                                                      SHA-256:5FBEA8F7190EE05A8ECD780895BE6987A8577293282F11139499DB86A32947E3
                                                      SHA-512:589EA113917C1FFF6AA0313EAF5EF7B5513C31201D6D8D7593A54CD475BEB3E3EE3D706FCE9BFC4D7A3E8622B2D03C837F6082053FCD4C04C17BC45C262302DC
                                                      Malicious:false
                                                      Preview:WANACRY!.......y.....<....&...?~.C.c.x...T.f......>..1.........%z%.S".....J.Yaw.^.+..6.W...jF.^Yk.7G,....V.^j1....f.6DY..U7.]c)..D.rZ.)...~.{.5..C......".E.h.1B......Q....I.....P...Gm..4F......l.4.#.h.../..[....*P]..c..9......m....ew.J..P...?7D.......L................)....x.1..56........cf.... J....&.u..G....o9.... ....Qyz{M~.,...t.&@....I.... ..}....k..t.~..^.^yu.s(..[.........[.4.B..Y-;a...FS..H.#6)....)Hw...%x..4>.Q.,.[.?4....1...:-...r.c*....h.,C.</(..&.~f.I.}....gro.N.V.{.M....._-..T.0...,.4..7m.t......!..yb.....N....Z [.....{.;.rc..........5,.......>...8..r...\}...{..f.....\...i:T.l...5..b..{.e^a?...oB....7.{..]....S(....l....)3SI....0..I......Tu... d.3.. .?Q..}pQR....L.....>!.9.X.........AK....m.......R..`..#Gf.......k.m.S...b-.\_.V.......>...t..(#U%.}-.._....n..O.6..vm.....@A.fH.Sq..u`k8w.1.TU.).}.1st.7B.Y.'..k...4..M..5q\...}..G.E.As+..-'....7.b.g>.~g....E..+..........*..K...R.L.P..Q....(..w).....q..../S(.......#R..M...`.....
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.803194756226117
                                                      Encrypted:false
                                                      SSDEEP:24:rHR71og+E2hbGZ1JJ+Cs5lEkTEbL/Kx+veAjxawLKbl9:rHHo/lbK9ClZEbLCx+veAj8wyl9
                                                      MD5:92C528EDEB454DC4EF6E30C2E9BF7824
                                                      SHA1:A4D547D6665FDFEA765F68B296FE180420CC22F7
                                                      SHA-256:C7782CE9022F261517EA5F48E8C98959BB8C3CD2F8C4BDEC878888700DA58E79
                                                      SHA-512:67320457BAEE70D81B277349437B4F8B337662084E9B5C60C5CE1C8737F804E5BE93A7081DC222B749C0B1FF7A10785079FCE3511082D4630C05B0523C780918
                                                      Malicious:false
                                                      Preview:....-Bfm......X.;xpi........ur....?..z..1.`.....=.........2.B...O.....6......r..I.]......u.X6..(m.%..w....;^..b...o1x*.~.(..p..15q..0.T..:..7$.*.eYO.?.....R....E.o..+.p`(..I<6_e.CX.......e.8...:..J...SyF....!a.........Xr.....h.b.8.7~....H.ZO'.es-...O-.D...u.5j..@....O[.j\.=..../...0...~.n.L.3.D.S.K.....E.....).ZC..._.fO.L..*.......j.Y9p...O...L7..o.x.E.V..........)..G{.....)......Y.0.|+]u..y)....(.e..t..u.#.\%]gWH....e..#...,^....e..L.^."._gW....F.`.X4L.3.gi.....#........8{.1o.n.u@...|....yO.....q.o.. .......C.#m..x_.q9O....!.C@.J.7*._.......F...0.vW..c..T%.7..R..J....f.u....'.bu&i.......[...7.).R....#O.*bw.O.S"9...BYE..0@......,..wSa..'..-|PW~...z.Y.@g3+...y.x8N...T.n......n|U..oZY....J.X.E7.p....J..D.wN0.=.$7.0R.5.9'`..-h....;.4-........."..O....dZ..s..$....)..}h.i;.naC.vcUw.o(.`..R.J+....7L...n...~*......C..+.B.+...-..t...o..?..e...xH.i*......0E..?....K.x...H.......k)ok..............I....l}&...aHl..>....:.718_.Fv..U..1.....\f.=%X/.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.85494522228678
                                                      Encrypted:false
                                                      SSDEEP:24:bkDi/ual24ZZSo0plI6BPBXbibaPZAHmywlBc3m9O67eSMcCVtkSOakKn4ReYnuK:bkDi2eZSDlIkXbMcamy4dO67eSgg5yhO
                                                      MD5:A06DA1BEB456FB490174BC6225943A79
                                                      SHA1:80B4B8A8BA6B872956084FDF1307450C8FAB230C
                                                      SHA-256:EC483620EE9ECCA17B3D2CBAA37C1B7066BB05C7B15990F8485A636C5B1212FC
                                                      SHA-512:2AA0193A873D1D2A9574960E9810415660BC7FAC5E93A986770778CD566FE9CABC3799ED796F738D87F20416FC6CDC25EDB614816C4436A6C76021FEA0FBAE75
                                                      Malicious:false
                                                      Preview:WANACRY!.....=...zFa.`..d....O.|..e.W..WF.....s..Ik.2.u...............om......m.J...E/.........<N...q...GbX..#.c.e....k;tBJ^.`.wRA9d..E......a..G....)............(...YT(..B(....VC.....QD..I..L'.%.U.qo..b_H=...Q...._...5.....(<....1k....@\sk81...K...BEj.....3...............y..@_uYP.s3.<8%..7...c.`.9p....oL+..n~&...i..Tu..m...d..e......4.?.V-s..2x.^.:...5!.(.|.r...0....G..D......"Y.n.T.B....[..o.F.;-..~.w..<.....v...0)..X.9......7....f.2X.....Y.&..#H.9...s.k.bF1.......}.9......!0........Z.|..8..)....W.u.1x.nN...\..,.,..y.k.R\.........h.0...N.o.]..q..'?...<.n.....p.U.V.Y.....Y.......^....j\..GF:"a.<.Q...g.N59......2.....p.,.].;.....gd`...........=l ...l..v.."\,Xt....C.@......jC3..;....dU0.F3....yT._#3.D>..B..YGI'N../v7....}..am..j...4......G....#VPj.eS.....:%...n....G.YE..d...`.H.J........V...mp..ar:..:B.. ..|..l>..O..(<.Jc...?..M8..B.. B....h...[......h..Q.&..i.....\.:S..9:c....9.........B|dm.w%.0. .K...B..v=w^..._v.X.x..Nbc.N.`....>*hi2{...I
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.85494522228678
                                                      Encrypted:false
                                                      SSDEEP:24:bkDi/ual24ZZSo0plI6BPBXbibaPZAHmywlBc3m9O67eSMcCVtkSOakKn4ReYnuK:bkDi2eZSDlIkXbMcamy4dO67eSgg5yhO
                                                      MD5:A06DA1BEB456FB490174BC6225943A79
                                                      SHA1:80B4B8A8BA6B872956084FDF1307450C8FAB230C
                                                      SHA-256:EC483620EE9ECCA17B3D2CBAA37C1B7066BB05C7B15990F8485A636C5B1212FC
                                                      SHA-512:2AA0193A873D1D2A9574960E9810415660BC7FAC5E93A986770778CD566FE9CABC3799ED796F738D87F20416FC6CDC25EDB614816C4436A6C76021FEA0FBAE75
                                                      Malicious:false
                                                      Preview:WANACRY!.....=...zFa.`..d....O.|..e.W..WF.....s..Ik.2.u...............om......m.J...E/.........<N...q...GbX..#.c.e....k;tBJ^.`.wRA9d..E......a..G....)............(...YT(..B(....VC.....QD..I..L'.%.U.qo..b_H=...Q...._...5.....(<....1k....@\sk81...K...BEj.....3...............y..@_uYP.s3.<8%..7...c.`.9p....oL+..n~&...i..Tu..m...d..e......4.?.V-s..2x.^.:...5!.(.|.r...0....G..D......"Y.n.T.B....[..o.F.;-..~.w..<.....v...0)..X.9......7....f.2X.....Y.&..#H.9...s.k.bF1.......}.9......!0........Z.|..8..)....W.u.1x.nN...\..,.,..y.k.R\.........h.0...N.o.]..q..'?...<.n.....p.U.V.Y.....Y.......^....j\..GF:"a.<.Q...g.N59......2.....p.,.].;.....gd`...........=l ...l..v.."\,Xt....C.@......jC3..;....dU0.F3....yT._#3.D>..B..YGI'N../v7....}..am..j...4......G....#VPj.eS.....:%...n....G.YE..d...`.H.J........V...mp..ar:..:B.. ..|..l>..O..(<.Jc...?..M8..B.. B....h...[......h..Q.&..i.....\.:S..9:c....9.........B|dm.w%.0. .K...B..v=w^..._v.X.x..Nbc.N.`....>*hi2{...I
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.819259516901212
                                                      Encrypted:false
                                                      SSDEEP:24:LXUcV0GZsaduXCKaQBrxdape0VnANM5YA1QXDn2fq+:z10edaaQBrcCNM5Y3Tn2fq+
                                                      MD5:FB5F54653D99883293056126B73F6E19
                                                      SHA1:F60112B28A75BCD895EE1433875FE5AD603A75CA
                                                      SHA-256:205D8E477D0CAE9871D04E586A327A70316887E6656AA14B49D54719F303C295
                                                      SHA-512:FADEABEABC64BE1C0F7F00EDCCF625B9EE964C10D897265B83B2B16CADE36D280E6694203D23778A3A2608F1F9E84AFE2CECA5F0343574EBABE9423BB0942791
                                                      Malicious:false
                                                      Preview:.y>./"..dp..0..%.Q=..FE.dw.$..V..5.+.,.,f,...;^6...E.>.../.?i.@.+.z.K.............;X..S.P^.f.'.k..P<}J.&.D.I.....6. $..ko\....}FaB..!.4.O..).........1.m.....&...S.T.......iM...5..v..........c^7N..4..$Zi...K.-.6.t......s...C.B`.E"3....L.oa..:u.Y.&..ZF'.L..#....Jxf#.....4....@j..h.a.....?.j.S.........3MQ4...F?..Wt~..?7..bb#....6Y7VA...X.|l....Pp.]0N..y.....E7v..u...Q.m...5q..p:......;zN/..$.X.......t+T....>..qiq..I....T.S.-..H...l.....l.t.KW.4....v.6..97.....=i<..E.FG.8u...g5.F.Y..:[_..e..........j.=.>]b^...C....es....w~.-.0/...Z&.g....K.z.....).D......oo.T%.._B....h.j(6..@..:...+..W...R........X.@...6.Dl......<.<...&%.L...[.\Jg-Y3..Z.7b*F..PwQ.Qz...w...$.|.......[{.P?.......}iF..r.lr....[.F.vQ=.....M.....*.....5...H)^..`.....'.*[...{....Ci.m....%..X..t.].=.2.:.".../..?MU...9...pU...LP.l.p...8pNes....<...E$r.D.......O.G.;1.O1.3......X...>.(.....^QK..U..3w.....P.M.z..f!9..V{.-..x...0.9..m(H..f........|..B.|.]..c...%..j.3...5Eh+0A...i;$N0%o..z..K..
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.859045613694536
                                                      Encrypted:false
                                                      SSDEEP:24:bkPeqL80z5cNj+vhXKMHI5U7ht3+tYa9i1paAAHRMWFf6+Tr:bkGqL8e5cMhaMHIC7htOtYaGvAmoRTr
                                                      MD5:798310D3BF13BF6AB0BE266F9FC20F24
                                                      SHA1:80CAD9E8E41E4C10E6DBA289500AE8E0DBC41A11
                                                      SHA-256:3DDDD7418D949579C009F7E48A73254A416AF64467BBDCE8553AA0E8C23D33B3
                                                      SHA-512:32C39B992DDCEA5329638BA5FE239863DF49892DB40C857D3B12FEA892B4C2566F3B65CA786009556CE7A408A8BE4456F4B37D0BE8BA9A02A7A459AAED75D379
                                                      Malicious:false
                                                      Preview:WANACRY!....../US.N..O.e.I.PY.,.'........0..."y2...,..^..}...+b..~..y.. "..@.R.PN.}.....uN...):.....s.5...c..#'.+f......z...q.......>zX.!zm.....V...J..8..=^..k....m..r.Y...Z.(.l.^...g.nf22Y..$...-..c}....s...m.zL..?.............a.gQ..4+.I]....3...J................o....p..5.lhU.bn='.ze..@..&Q.Z~u%Q5...<..2..U...*pN.[k5l><jq.....r._,+..../..t.3.-{.9....P.............l..E..D+.V.;....C.E...x..9..YT..<<4YH/..9[...d......|.@...c\.t..4G.s..:.f5d.$..\..._>Q..J..E.>.".DI.Z9..H.......'.r.q.v...y..7...:.q............x.q.^1.Kf.v...6df.D.o!.~.........I.5....._N....S..6CT......3.w...)... ......|p...V..<......VI...Y...?o7\WE.h<.p...ct.*.r.1z.+..&)|..Ue..m...../.G./e.2..I.J. Z..]/.....Z.{.f..Z...f\#]BK|....\Z.....b.DA..s..W..-..=.l...5......8.].4i....(.a....!E....b....tm-e.?.m......~.....i:C?8p...^f.r;U..2~.RB...6..p|..R.7.&...O.....>...6..X...n...4.U( ..|.>.....{..]...w#Q..hj.G..b...+M..y.ir.-......P.?).J.<......V.. ..\;z[..<.....j.s.%.R.P".o....
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.859045613694536
                                                      Encrypted:false
                                                      SSDEEP:24:bkPeqL80z5cNj+vhXKMHI5U7ht3+tYa9i1paAAHRMWFf6+Tr:bkGqL8e5cMhaMHIC7htOtYaGvAmoRTr
                                                      MD5:798310D3BF13BF6AB0BE266F9FC20F24
                                                      SHA1:80CAD9E8E41E4C10E6DBA289500AE8E0DBC41A11
                                                      SHA-256:3DDDD7418D949579C009F7E48A73254A416AF64467BBDCE8553AA0E8C23D33B3
                                                      SHA-512:32C39B992DDCEA5329638BA5FE239863DF49892DB40C857D3B12FEA892B4C2566F3B65CA786009556CE7A408A8BE4456F4B37D0BE8BA9A02A7A459AAED75D379
                                                      Malicious:false
                                                      Preview:WANACRY!....../US.N..O.e.I.PY.,.'........0..."y2...,..^..}...+b..~..y.. "..@.R.PN.}.....uN...):.....s.5...c..#'.+f......z...q.......>zX.!zm.....V...J..8..=^..k....m..r.Y...Z.(.l.^...g.nf22Y..$...-..c}....s...m.zL..?.............a.gQ..4+.I]....3...J................o....p..5.lhU.bn='.ze..@..&Q.Z~u%Q5...<..2..U...*pN.[k5l><jq.....r._,+..../..t.3.-{.9....P.............l..E..D+.V.;....C.E...x..9..YT..<<4YH/..9[...d......|.@...c\.t..4G.s..:.f5d.$..\..._>Q..J..E.>.".DI.Z9..H.......'.r.q.v...y..7...:.q............x.q.^1.Kf.v...6df.D.o!.~.........I.5....._N....S..6CT......3.w...)... ......|p...V..<......VI...Y...?o7\WE.h<.p...ct.*.r.1z.+..&)|..Ue..m...../.G./e.2..I.J. Z..]/.....Z.{.f..Z...f\#]BK|....\Z.....b.DA..s..W..-..=.l...5......8.].4i....(.a....!E....b....tm-e.?.m......~.....i:C?8p...^f.r;U..2~.RB...6..p|..R.7.&...O.....>...6..X...n...4.U( ..|.>.....{..]...w#Q..hj.G..b...+M..y.ir.-......P.?).J.<......V.. ..\;z[..<.....j.s.%.R.P".o....
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.806269438753434
                                                      Encrypted:false
                                                      SSDEEP:24:vZamzsuQXfwCEseAHkytwYWBxwdrS/y7t+n5/OsQGPU3F+w+VlECAUz2:MmzwPwHPo52yxAWsTaFv+Drxz2
                                                      MD5:BE55681C41C07066AAD709EB2544D06F
                                                      SHA1:15E0353BB7E56BE605EC2C152DF57C086AE00BF3
                                                      SHA-256:FFC79FE435C81BA014650D0B7D2B672244B8B90A9C9FCF060A67B96CADA9048B
                                                      SHA-512:E1D39AFBE1E341D34F280914017AD75CC4D4C4E03E5EBAB32C2403FD5F3376569A46487826DCD920D2EAC9D095D8EC43F591E0AA8F61919FF0D680ADBCF2A731
                                                      Malicious:false
                                                      Preview:..<Ei.;.0...}ZI..0.........1.hs..h...a.V.0w...Z._...}x.....*...A.....-.....h._........./..h..<.....@......?....(..\4}.|...?n.f../......7ko.F.9n#.3....{.,#...w.`R4.6.b.b._.a.v..Q.....u...J.v.t....U..U.]`z......O!V...a......=..G..b0L....E.6..*......C.T.&a...>.<.:.4.....u.M.U(....w%N..H....x>.j......}`>.k..B...g.b...x....U...\gY.......).`.e.'..J.....XmE.f..V.v1......-S.98..V....`:V`..(L...o).5..`X..p.d9..b5o..H..Q...K._`..p...&.....U..Po...SZ....R4@....")~.!?.Fvh..TYh3..$..M.D.Sz3<..$J..".....m..zD...F..k.?>.b...|ZT"..w.S....K...%...a..u.8...FK.f.M'dU..{......6.q.P.}. ..g.j...\z..cxu#.$....!.2.7Q{.b/WX....).8).......$..SL.>t.=S.....F...y.....p.."...1...M..?C.."..BK....).y..f...).7..X..0...$O.18.~.0K...r.}%t.]z.../L.......u]...x...1b........-.}..../#.C...rN(~W....e...S....E........1..c.F.Z..h)......y.Y.}...{.D':.M.r.N..Q..dG.>>....k.......M.XW.t...G....R......g1F.O-...I'..j.......&.(.$um7..k.Y.>...4fs...T.....?.b..Z.x6F..2'.:.~.B.\.2N.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.8511542114794235
                                                      Encrypted:false
                                                      SSDEEP:24:bkfxJJr8E7SUsJBSZLV5jwhSRcv8q2IEVAxjsaBYaX4YkzcNVBtRIEQQG4:bkJJJwgKBQLV5jsUWlVh8WRIEJ
                                                      MD5:5449837F9024EC0286935ABDC0E7919B
                                                      SHA1:3BDF06CA99CD9DA3E4E5AA1D30CAC00CB30B797A
                                                      SHA-256:E78C3E658DD198D1D80FACC0BE731C72804D251CF82FB191E99E0B3F9B8DC4EE
                                                      SHA-512:584CF6E4E76840555D165D466AFA14FB6E29AC8B44EF5B6137F5D981E6F5457392E0DB21D11BC1D856263A3E022A1071172C38BB072B9CB97F84E1F733D7F67E
                                                      Malicious:false
                                                      Preview:WANACRY!......3A..R...u..?....{.t.K.M_`8C.@.......z?.|\..ze..G...W.ng....P..s.8x...JG.T.#1..("....G>.n.H..:.....d.g.ex.....;..@..jE....0.)u..=..H.....EY.n.}.5T`..i?GJ....O..e='..O)......y{.ZW..?}.k...e..B.......[eI......{....g.u.QoR.s@.6.)0A,...n.......6...............Q. ..E.;}t...3.....{z.....2ba.....8.,....F.../.-9hp....!^.r....j.2...6Km......-$A.......ULMs.vR..%...]...,.p...P.Rd..VDa.........Ci...m...P...}.D.p.....C.+.?... .b...h.q.e.O..o.}P.9u.5..uf(..C.A...o......:...1._.......D.8.NID.gx.K|....nI.IU.s..F(.\@.u8ce\$.*.......F..^...H...5.?$.zA..D....#...<O......N^_...-P.G*#...[.+..g...q.P..m*r.b..g...!A.x.....F.VHGE@.'.-f.......c.g.dcM...Y)..EnA....6.<`Q...%{.V?.<4E.C...')_^.d...3..q..A..v.'......v.$_...Zo.....&.R..[...b...X...'C...rL..>...P.......4.P......7.10..i.4+..%....o.....Za`.":...i..%..0.<.$;W..>...Zy..=.HM........>...kP.!...z...L..n.[]..\.........S...D"./...vV..Y..1.\.ghQ.3..c.M$.!...F"y..A.<.3.|....}#......|.n.....l...\.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.8511542114794235
                                                      Encrypted:false
                                                      SSDEEP:24:bkfxJJr8E7SUsJBSZLV5jwhSRcv8q2IEVAxjsaBYaX4YkzcNVBtRIEQQG4:bkJJJwgKBQLV5jsUWlVh8WRIEJ
                                                      MD5:5449837F9024EC0286935ABDC0E7919B
                                                      SHA1:3BDF06CA99CD9DA3E4E5AA1D30CAC00CB30B797A
                                                      SHA-256:E78C3E658DD198D1D80FACC0BE731C72804D251CF82FB191E99E0B3F9B8DC4EE
                                                      SHA-512:584CF6E4E76840555D165D466AFA14FB6E29AC8B44EF5B6137F5D981E6F5457392E0DB21D11BC1D856263A3E022A1071172C38BB072B9CB97F84E1F733D7F67E
                                                      Malicious:false
                                                      Preview:WANACRY!......3A..R...u..?....{.t.K.M_`8C.@.......z?.|\..ze..G...W.ng....P..s.8x...JG.T.#1..("....G>.n.H..:.....d.g.ex.....;..@..jE....0.)u..=..H.....EY.n.}.5T`..i?GJ....O..e='..O)......y{.ZW..?}.k...e..B.......[eI......{....g.u.QoR.s@.6.)0A,...n.......6...............Q. ..E.;}t...3.....{z.....2ba.....8.,....F.../.-9hp....!^.r....j.2...6Km......-$A.......ULMs.vR..%...]...,.p...P.Rd..VDa.........Ci...m...P...}.D.p.....C.+.?... .b...h.q.e.O..o.}P.9u.5..uf(..C.A...o......:...1._.......D.8.NID.gx.K|....nI.IU.s..F(.\@.u8ce\$.*.......F..^...H...5.?$.zA..D....#...<O......N^_...-P.G*#...[.+..g...q.P..m*r.b..g...!A.x.....F.VHGE@.'.-f.......c.g.dcM...Y)..EnA....6.<`Q...%{.V?.<4E.C...')_^.d...3..q..A..v.'......v.$_...Zo.....&.R..[...b...X...'C...rL..>...P.......4.P......7.10..i.4+..%....o.....Za`.":...i..%..0.<.$;W..>...Zy..=.HM........>...kP.!...z...L..n.[]..\.........S...D"./...vV..Y..1.\.ghQ.3..c.M$.!...F"y..A.<.3.|....}#......|.n.....l...\.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.822916180185078
                                                      Encrypted:false
                                                      SSDEEP:24:xN1dQx58cLzJe71l/vPoWO1eWT9rMTKsmhtaAP3pp:kxHL1e7xmR9b/iAP5p
                                                      MD5:6A87BF8B16F88D21016E3471FFD469A7
                                                      SHA1:39EBFFBB797007071D9B5E6AA62DEF5716F501FE
                                                      SHA-256:BCF3E7800EAE7DE5800AE32287201A212B3291B346D93A220F9A1AB879D5333F
                                                      SHA-512:F3581FC487492157DCDFDCCEA7278692B7EC5A067F213EBF29A01F8B745C8B2020608F97CDC31BE9B9A655BCA332C173AED2D5083F53539006F87782E1138665
                                                      Malicious:false
                                                      Preview:I."3...a...UZ.> .Fb?.c.]aa.L...E..1.4..sb..l..;.4Si....?.+=..v.|...'.ae|.......F+....G.b...B|Cr,...,wYW...gw.@.L...0#..X`..ax.......]'..7..../ J.C....>U.lT".......0....6S...Z<...........j.I...nA..Z/s1r...%...r......c...D..;..dW..9.^@rP..{9%....z\5..0.....0<..0.&.......j.A..n...-RO(.....|.'..d.Fo..w.|#..;W..k .s./r....39....lVc..nd..A...4.....4..`f..... .I...o.J...3D....Q......%.....jy..._....9~....T.._i..%....._h.s...|iQ.....Q...X....U}..4|.........t..r98E..<.??.]m.U.2.....W.....[tX.....Y.......@.Q.Nb.D..Z}..K..Y.1.3..|....N..v..7....Fx\.s.d.S^w...........WW.B...4qw.k.......8B..)..!zn3......[J....A..;.U....Bs...J;.hF..w.\L$A...;..h...I.J.t.*..|..R..Zh.m1....o.dI..6$G./V..P..X4.}....{..KJ...:b..[;....%S..-.@..fe......!..8UM...O+M.. ..KH.."B+.c..b_....3..RP...y4..q...i...7.>\.`.....Gu.tj......~.GU..C......1.Z?..Dt....Q..t.0^.`.t.%...VJj>..n.....".....5..;....7.....r..v...if?9"hU..u.\b...3'x....b..ou.....z.%.....n...v.lg..+.._..+........
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.829785338293005
                                                      Encrypted:false
                                                      SSDEEP:24:bk1yk+aLpf9KUbPbH5iVIO9HruCC/VnQlf0Q6WP+fTlua2ISJ/l6kC86hPlBAtO2:bkrhpfIUzbaIOBr6VQaQvP+bluaAJ/l3
                                                      MD5:61DF798DE579DF80D5B7AC6A91829693
                                                      SHA1:BB28AFB83DB609CF857C67B5A0621C8F4A4D369A
                                                      SHA-256:EE49385288188920D64D402529DA71EECBA2B58ACBBAEC67C3D69422784014DF
                                                      SHA-512:CB863EEF6977B36F725AD7747FE51B562EA81B689B55CD4FCE142E112AD06E3165766B5B7B3F11A13675A07B3CEE106AA5D4FB474004921DF450C5BC585AB27A
                                                      Malicious:false
                                                      Preview:WANACRY!....I......._.Xe^b.c0b...^.....A..aD.<....I.,.%2..}{2&.g..%4W.E.sc(l..UY..{..J&f..8..."#F....}.G>.......z.....O.E......H.....T...A%.......7.le.Dg."a.....R......N..P...`.D.....7......}......Zy.X[..-.D.k....7}:..D..]..%..7...]..1V..C.;.V......`.................+.*..BJ.0uXx..r....I.M t..".A.g...5..L1.'..c...p2..'t.h.?..jZ%.N.q...1.sB......N....[..!.`.?.-....l.'.M.re..D.v.......".Z..7....`6..r....[.DS.J.B9..H....L..x.w[..>Z*1.U....L.......d7..y.A.KL..W...xn..j....%.!u.;:.0..N%.......z...-...!..&R.v..V..F&e.!1uFh...B..u..m/Fg.lkB"4.Z.1.v.m.....h......r......$.......#.A.=5fTL.,....7_......`.......m..`...XAL..@/Mk..*..V...Rz..8..`...b.....j...".a..f...p.mk`..,g..ZbF,.:T.OH..z..MRP?DC^..C...u*....vg..(...p/......y@..Jt..qL...=.o?.;...U..=?..%4..A......4l.,.2..z'..>1i....%.9.t..R._;.%.FBuU....~.....F...:.....T...[!..j..........U.../...h.i.."...._*'....$........^1..b`j..`&@F......j...:j..s....p-......1........y.1....kt~wfY].j......U./^..H:H..
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.829785338293005
                                                      Encrypted:false
                                                      SSDEEP:24:bk1yk+aLpf9KUbPbH5iVIO9HruCC/VnQlf0Q6WP+fTlua2ISJ/l6kC86hPlBAtO2:bkrhpfIUzbaIOBr6VQaQvP+bluaAJ/l3
                                                      MD5:61DF798DE579DF80D5B7AC6A91829693
                                                      SHA1:BB28AFB83DB609CF857C67B5A0621C8F4A4D369A
                                                      SHA-256:EE49385288188920D64D402529DA71EECBA2B58ACBBAEC67C3D69422784014DF
                                                      SHA-512:CB863EEF6977B36F725AD7747FE51B562EA81B689B55CD4FCE142E112AD06E3165766B5B7B3F11A13675A07B3CEE106AA5D4FB474004921DF450C5BC585AB27A
                                                      Malicious:false
                                                      Preview:WANACRY!....I......._.Xe^b.c0b...^.....A..aD.<....I.,.%2..}{2&.g..%4W.E.sc(l..UY..{..J&f..8..."#F....}.G>.......z.....O.E......H.....T...A%.......7.le.Dg."a.....R......N..P...`.D.....7......}......Zy.X[..-.D.k....7}:..D..]..%..7...]..1V..C.;.V......`.................+.*..BJ.0uXx..r....I.M t..".A.g...5..L1.'..c...p2..'t.h.?..jZ%.N.q...1.sB......N....[..!.`.?.-....l.'.M.re..D.v.......".Z..7....`6..r....[.DS.J.B9..H....L..x.w[..>Z*1.U....L.......d7..y.A.KL..W...xn..j....%.!u.;:.0..N%.......z...-...!..&R.v..V..F&e.!1uFh...B..u..m/Fg.lkB"4.Z.1.v.m.....h......r......$.......#.A.=5fTL.,....7_......`.......m..`...XAL..@/Mk..*..V...Rz..8..`...b.....j...".a..f...p.mk`..,g..ZbF,.:T.OH..z..MRP?DC^..C...u*....vg..(...p/......y@..Jt..qL...=.o?.;...U..=?..%4..A......4l.,.2..z'..>1i....%.9.t..R._;.%.FBuU....~.....F...:.....T...[!..j..........U.../...h.i.."...._*'....$........^1..b`j..`&@F......j...:j..s....p-......1........y.1....kt~wfY].j......U./^..H:H..
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:OpenPGP Secret Key
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.809077389543913
                                                      Encrypted:false
                                                      SSDEEP:24:1cIaTZec3K3KA9kkvXazR3gJ48gBV/+b3LFLEPVH5MZdc1Ncz2TyrZt:1cIaTZeciSkv8WNgBViLFLEPVZMZ8c2o
                                                      MD5:3D503886A300235637A62A5231D175B4
                                                      SHA1:F5162CAFDEFEB61A873E6DC79EC1E8C0701167F6
                                                      SHA-256:78715B87581048F1BFA11F0BD07DD88B8E671C2FE7BBB884E99D820F4A0DDB6D
                                                      SHA-512:C0BD93C82AE8BF97B46F8AD354F19FA63423B1615F4407FD0C936C2C0AAB4E0912C3F1C2D82172BC6C4730861D31E36B6DC691E0236C0817B49E8C7E41569984
                                                      Malicious:false
                                                      Preview:..8@=..[*...O5"9(.,B..*.!B".^(.Ukp3..22.o..q.xAD.I/_J....z.....<..D......\<.F..(.t.$L....3m.e..8.?/X.:...r.....$..,]%f9..h.N..A..&....cR.X.gg.gB.B..&.?oyj.~y(....F.pKE...F.....l........(.).xh."Ay...X.A..-+v..#q.7..g.C.[....<.eK.:,.... ..f4$.Y.Z...e&ki.xZ..KU.M.).P.....Sr6.V.#.A..........~{..o@....'.".&f.uo...Bo..\J7.../|.....%..v;.?.|_...\!....v|);*#%$..\....BU..l>.f..Hw.Y.="1*S...l........x.....E=(I....;.......!..y..`g..q.E....4../-Ed....fJ..'...V....a5.x.k|k.......5[...=...a,..$..cd.....DT.2s.mQ..<Okn.=.3...8 ...!..g|.|ai=....\.........W}r.m..LbV.;..<j.....{._$.p......@5..O..H.....F`<.. j.}.RTi..6="#H.! ...@{]....rV..[oq.Q.3n3.E".:\.x+....#.'.....-..!"[h..e7.S.,z..Q'...E....\.?./$..6....O........]b\78G..N.....E.#..M..J..(p=i.M.`...b.....%.hm .M.v.P..B1...S.....2.#...N..f..I...LDJ tB.d`y.Pt..l.i..O...Xx.GL..0..A...L|.W....M{A....P..T.9..WY....._nH..I...,.{.O.=.C.z.v.......k......B....F1i.....%.F..w..\...f.,...<...N\FH.t.<...\T....2...
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.834419598427319
                                                      Encrypted:false
                                                      SSDEEP:24:bkRDsiL1QpnwNMvEv2TUfdax2U+MATkZShpWkf/9LlsQWo/mv/DNabfQ:bkRDslp8Mvx+k6ftlfWPv/DNUQ
                                                      MD5:A99ACD980EE3AB25E957BBF7A0D457A6
                                                      SHA1:37086D0324A33947E5BA94C9EAF1E3A055BC3F96
                                                      SHA-256:6E11F3CBAFA700B6B93704280944750F67992A3C7FD6CE7DF11AF7FBBBDB0FA9
                                                      SHA-512:1571438BD54A0D46BA8B5C1DD4BED7C8454D2E813EBA6A7051D765B41D3A13614BB98E13566728D40AC31430189263406BAF72A478441FA6C0D45219A7C3DD93
                                                      Malicious:false
                                                      Preview:WANACRY!.....*....%...;n...4J.a.................0...3...l.......4bWb.....0.....,<......`...vdU.Y.*..K.o.......Y....U.pmF....f.v.../...0R.9.q..Mw........S.PN........AC"5@..-...5:@..o..'N......6....j..4.m8.-..A.b....~..EK....E.>k+.hf..Z..T...:.....1!K.bS...............CR-WY.!|f$..?&...G.]G..............H.9r.x..^)g.D.............m4...4.....+.@W\.p.8..xU..._.K..Y.Q.6.;^.i.....G.... ....E.X...SJ.......Q.F0...|..?}U....*.Y....-...6.=.,o.....&"./~.'..@..q.a.}.<.s./gG0..7.e?.>"...........".&.....U.a..w..~.v..I..j..:..b..\.t...Uy..a.a.18nz..k....Q../.L..'..`..n<.......:{H..a.*$.8...t.+.t..a....X..E..7...T..R}#.i....h.+..A...+=n.x....^K.RD......x...Pz.._k..=.=.....o.....$..i.+~.M.....3Q..;....&.X..|..@.......k.....O3.Pe......L..fJX...*.b..Y...S.x..%J(v...u.4.@.?...e......l...M.....{1.2..?x.~.....k-(..U....dJ8g.".)..me.}Y.]vC....V{.^.x.L.l.p....j..RH.e...uP.c..F.......@..s..i........rv.&..ml.Rg.J..?.B}..4.H.Hr4..7........y8.qsp..Kc.....Y.H.(Y..DA
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.834419598427319
                                                      Encrypted:false
                                                      SSDEEP:24:bkRDsiL1QpnwNMvEv2TUfdax2U+MATkZShpWkf/9LlsQWo/mv/DNabfQ:bkRDslp8Mvx+k6ftlfWPv/DNUQ
                                                      MD5:A99ACD980EE3AB25E957BBF7A0D457A6
                                                      SHA1:37086D0324A33947E5BA94C9EAF1E3A055BC3F96
                                                      SHA-256:6E11F3CBAFA700B6B93704280944750F67992A3C7FD6CE7DF11AF7FBBBDB0FA9
                                                      SHA-512:1571438BD54A0D46BA8B5C1DD4BED7C8454D2E813EBA6A7051D765B41D3A13614BB98E13566728D40AC31430189263406BAF72A478441FA6C0D45219A7C3DD93
                                                      Malicious:false
                                                      Preview:WANACRY!.....*....%...;n...4J.a.................0...3...l.......4bWb.....0.....,<......`...vdU.Y.*..K.o.......Y....U.pmF....f.v.../...0R.9.q..Mw........S.PN........AC"5@..-...5:@..o..'N......6....j..4.m8.-..A.b....~..EK....E.>k+.hf..Z..T...:.....1!K.bS...............CR-WY.!|f$..?&...G.]G..............H.9r.x..^)g.D.............m4...4.....+.@W\.p.8..xU..._.K..Y.Q.6.;^.i.....G.... ....E.X...SJ.......Q.F0...|..?}U....*.Y....-...6.=.,o.....&"./~.'..@..q.a.}.<.s./gG0..7.e?.>"...........".&.....U.a..w..~.v..I..j..:..b..\.t...Uy..a.a.18nz..k....Q../.L..'..`..n<.......:{H..a.*$.8...t.+.t..a....X..E..7...T..R}#.i....h.+..A...+=n.x....^K.RD......x...Pz.._k..=.=.....o.....$..i.+~.M.....3Q..;....&.X..|..@.......k.....O3.Pe......L..fJX...*.b..Y...S.x..%J(v...u.4.@.?...e......l...M.....{1.2..?x.~.....k-(..U....dJ8g.".)..me.}Y.]vC....V{.^.x.L.l.p....j..RH.e...uP.c..F.......@..s..i........rv.&..ml.Rg.J..?.B}..4.H.Hr4..7........y8.qsp..Kc.....Y.H.(Y..DA
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.830036907841302
                                                      Encrypted:false
                                                      SSDEEP:24:WzsdewmD7oz/BwCZt9dpodvQdBCHBt5tv9fjNz7tIwqenw2VLzWzGUZo:W2mD0DyCTEQdBCHVfhzhw/zGUe
                                                      MD5:768BBBC7360BBD80D0B1C20FAB42FE1F
                                                      SHA1:21BB10B9BDF754A3D184197988EB74F930A9DD49
                                                      SHA-256:D7C9D0E2250FA40FD745AE53A2EB3C1C7BC1A8CC39B0EFC5CF8E6DC1C903666B
                                                      SHA-512:82CD7A1476BD188C04A8D8E15806AC6C4F04D9B64EF63585695D5B84B3ADBC4BE25D2F793AC6CB39C3AB238FEDC8071F5BC01260CCE4FA6E3EB26D13ACDA1C95
                                                      Malicious:false
                                                      Preview:k. wAY4i\Z)./..U.g..k..._.i5;sw..mnXq.`....uG.z.A.%....b.W...d..}...7.g......]&..r.p&..4u....y..@..<.K].|..|.>.9:....$....DR...?.'.......R.S....D.....P...`.0..<.=......)>E......,.`V..Ql...f....z...t.Gjo.{...\.!..r=.e0R..."..V..}.?b%....m..g..A.7 .^.z.L.tD.....@.l.^..|.....6*.@~.yx...H.4D...AK.I.[.=.`X..E.`N~*f..CBS.0..^..@..Y.Rd..wF..@...m-.........Uj..CsG.%ZP.q+{R.4p.y........KL..G...S....N..:..'........:.K>.T1..........u..pr.A'v.V..K..hH.j"w.`W.).V...J.....<....AH~.1p2.....O.l.....4x.h.k.RE..A@.m.e]}.....~......w.Z.........:i._.E.g8aV....qq%%..i.;q=P#...jo.^.e..G.65`......X..-S...GB..iq.Rr.R....l....>@..[H..N.2.{....|..cd.`J....8]....>.......o.tk.Gf..n..,C.......e..`...)Y4...}. ..W.P.L......'.Q.c.].._.<..=...3y.]......]..u.S....r........."G.(7o...$-yA:9....|......NEi.{;..h.Z.[?.a..Z......Y.wc.....?..o.n.^...v;.6...@p...U.......H...v.[..$.n..>..(.x....O........* p8%l./.KRh.RS.........r0).......M...I<.v....up...E.c.4z.Q.9.[......
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.823087274235232
                                                      Encrypted:false
                                                      SSDEEP:24:bkjlhd6d/kOsVpWk+85Qqd3AegkH/eajcOXgLmU/yQFAgbJ0T2:bkjlhBff78kfNAOut/BFPbKy
                                                      MD5:292EF1B6FE101F9F205D5C214BAD8ADD
                                                      SHA1:06A8E32BCD2F4C19B578333BFAAEBECE576B2B23
                                                      SHA-256:900E7A15F47A33F93D391DD874D717CE977E9343A65E8890E2E60109D66A7CE9
                                                      SHA-512:43311680688B0A54056EC4D47EEF5021E822569126285420B53D4D1DB18651C466BF40CD3C18EBF78EDCEBB34071E22AB1C4DF2F7E728FFE9885B2C055589173
                                                      Malicious:false
                                                      Preview:WANACRY!.....!7..xW.!..b.F..xvcn......E.i.~....../..-..Z .]..Q.X.q...&r...g.(.....3.#-w...(..1..;...57...E..... .>..q."+*.G.z.f@..s.............a....?..9..Xhy.7-di.E...g.....N.i...!.KS&..~N.....7_K....e./`._.s.\..1....X.:.. .r.z^.!...x..-).wf@..]<8.g.......................<.4...se..p.d.7i9.A3.....?f.,cS..B..1....b.Z.......$.v=WI....8..b..]..i`..a.g.d`........-....%NIu....BLQY.>.&.OZ..g...6...b..b>+.[..#...r.I..X.P.@.J..._.-..:".m..0&c(..W..../.m.8..q......h.F.{.lL.2...^p5/..@....X.Y-ImRS..R..B.^..0.1..P..?Z7.uU..V...U..,.4k....J......8...B.7..j.N"Q..WO..F...x,g.Wy....-?@...lK.<.)....p.:>....3]..R.{.py...E.......WUiNk.;...K..[.Vh..g.$-.w._5.`".K9}...n.._.../..$...)..<,8.-...nc...k..nA.Lr.e\..L.W.]P=.)~B8Cl~.)I...W.0&.ks..VMh......M.f.....8m......a.h..\...J.v.......0.*}4....JK...4`.....L.j>w.*-.d.GQ0k]}.$...]........5..hF..BO|".u.....N..^.:bZ~.h#..._]...pu..!..f...*.fs..B..\..f`.q..y.y.8....J.C.k.......u..TB`.|OF.....KC..P..}..a,.1..c..S...k'
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.823087274235232
                                                      Encrypted:false
                                                      SSDEEP:24:bkjlhd6d/kOsVpWk+85Qqd3AegkH/eajcOXgLmU/yQFAgbJ0T2:bkjlhBff78kfNAOut/BFPbKy
                                                      MD5:292EF1B6FE101F9F205D5C214BAD8ADD
                                                      SHA1:06A8E32BCD2F4C19B578333BFAAEBECE576B2B23
                                                      SHA-256:900E7A15F47A33F93D391DD874D717CE977E9343A65E8890E2E60109D66A7CE9
                                                      SHA-512:43311680688B0A54056EC4D47EEF5021E822569126285420B53D4D1DB18651C466BF40CD3C18EBF78EDCEBB34071E22AB1C4DF2F7E728FFE9885B2C055589173
                                                      Malicious:false
                                                      Preview:WANACRY!.....!7..xW.!..b.F..xvcn......E.i.~....../..-..Z .]..Q.X.q...&r...g.(.....3.#-w...(..1..;...57...E..... .>..q."+*.G.z.f@..s.............a....?..9..Xhy.7-di.E...g.....N.i...!.KS&..~N.....7_K....e./`._.s.\..1....X.:.. .r.z^.!...x..-).wf@..]<8.g.......................<.4...se..p.d.7i9.A3.....?f.,cS..B..1....b.Z.......$.v=WI....8..b..]..i`..a.g.d`........-....%NIu....BLQY.>.&.OZ..g...6...b..b>+.[..#...r.I..X.P.@.J..._.-..:".m..0&c(..W..../.m.8..q......h.F.{.lL.2...^p5/..@....X.Y-ImRS..R..B.^..0.1..P..?Z7.uU..V...U..,.4k....J......8...B.7..j.N"Q..WO..F...x,g.Wy....-?@...lK.<.)....p.:>....3]..R.{.py...E.......WUiNk.;...K..[.Vh..g.$-.w._5.`".K9}...n.._.../..$...)..<,8.-...nc...k..nA.Lr.e\..L.W.]P=.)~B8Cl~.)I...W.0&.ks..VMh......M.f.....8m......a.h..\...J.v.......0.*}4....JK...4`.....L.j>w.*-.d.GQ0k]}.$...]........5..hF..BO|".u.....N..^.:bZ~.h#..._]...pu..!..f...*.fs..B..\..f`.q..y.y.8....J.C.k.......u..TB`.|OF.....KC..P..}..a,.1..c..S...k'
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:PC bitmap, Windows 3.x format, 800 x 600 x 24, image size 1440000, resolution 3779 x 3779 px/m, cbSize 1440054, bits offset 54
                                                      Category:dropped
                                                      Size (bytes):1440054
                                                      Entropy (8bit):0.3363393123555661
                                                      Encrypted:false
                                                      SSDEEP:384:zYzuP4tiuOub2WuzvqOFgjexqO5XgYWTIWv/+:sbL+
                                                      MD5:C17170262312F3BE7027BC2CA825BF0C
                                                      SHA1:F19ECEDA82973239A1FDC5826BCE7691E5DCB4FB
                                                      SHA-256:D5E0E8694DDC0548D8E6B87C83D50F4AB85C1DEBADB106D6A6A794C3E746F4FA
                                                      SHA-512:C6160FD03AD659C8DD9CF2A83F9FDCD34F2DB4F8F27F33C5AFD52ACED49DFA9CE4909211C221A0479DBBB6E6C985385557C495FC04D3400FF21A0FBBAE42EE7C
                                                      Malicious:false
                                                      Preview:BM6.......6...(... ...X.................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):780
                                                      Entropy (8bit):2.3626374636337375
                                                      Encrypted:false
                                                      SSDEEP:6:cL+T2xglKaHqHgVcKKfF9mHRMMPRGS37LlN/sUQqGUSGeTsdEC:cw2laRVcKKfm2MYS3sUQqGLGeTEV
                                                      MD5:93F33B83F1F263E2419006D6026E7BC1
                                                      SHA1:1A4B36C56430A56AF2E0ECABD754BF00067CE488
                                                      SHA-256:EF0ED0B717D1B956EB6C42BA1F4FD2283CF7C8416BED0AFD1E8805EE0502F2B4
                                                      SHA-512:45BDD1A9A3118EE4D3469EE65A7A8FDB0F9315CA417821DB058028FFB0ED145209F975232A9E64ABA1C02B9664C854232221EB041D09231C330AE510F638AFAC
                                                      Malicious:false
                                                      Preview:...........................................................................................................................C......................................................13AM4VW2dhxYgXeQepoHkHSQuy6NgaEb94................gx7ekbenv2riucmf.onion;57g7spgrzlojinas.onion;xxlvbrloxvriy2c5.onion;76jdd2ir2embyv47.onion;cwwnhwhlz52maqm7.onion;.......................................................................................................................................https://dist.torproject.org/torbrowser/6.5.1/tor-win32-0.2.9.10.zip...........................................................................................................................................................................................................................................
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:ASCII text, with CRLF line terminators
                                                      Category:dropped
                                                      Size (bytes):1484
                                                      Entropy (8bit):5.039265095699928
                                                      Encrypted:false
                                                      SSDEEP:24:oAwwuV7kwwuVLqGVwuVwuVwuVwuVwuVwhLGOaMHwZwVwuVwuVwuVwuVwuVwhb+R0:oAwwuSwwuBqCwawawawawawhLsYwZgw/
                                                      MD5:93EF22DF0684F987733B1C219D6A7DBF
                                                      SHA1:38F1639C93A5D8161B43D873D2993B3388A2167B
                                                      SHA-256:F7818337CBF1FD8EA708D44EF062725000AEE50AB18244F18115233DF59C49AD
                                                      SHA-512:7F0855DBC7BFCAC2889ED0DAC18D18BA6D74EAA11DF8CED09988060917667D771A2423835A6600FF87EA551C6A926FE558A13C4B6AC203845F48BD7018EBE4BD
                                                      Malicious:false
                                                      Preview:C:\Users\user\Documents\TQDGENUHWP.pdf.WNCRY..C:\Documents and Settings\user\AppData\Roaming\Microsoft\Windows\Recent\LTKMYBSEYZ.xlsx.WNCRY..C:\Documents and Settings\user\AppData\Roaming\Microsoft\Windows\Recent\RAYHIWGKDI.docx.WNCRY..C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\background.png.WNCRY..C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Edge\User Data\Edge Shopping\2.0.5975.0\edge_tracking_page_validator.js.WNCRY..C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Edge\User Data\Default\Extensions\jmjflgjpcpepeafmmgdpfkogkghcpiha\1.2.0_0\content_new.js.WNCRY..C:\Document
                                                      Process:C:\Windows\SysWOW64\cmd.exe
                                                      File Type:ASCII text, with CRLF line terminators
                                                      Category:dropped
                                                      Size (bytes):195
                                                      Entropy (8bit):4.972539864099582
                                                      Encrypted:false
                                                      SSDEEP:3:gponhvDCKFcsDqLElynJ96JS2x9rbPqLElynJSK2Fvn:e+hvbqLEoJgJSoPqLEoJSK2Fv
                                                      MD5:876907408D9FC41B5AFDD67A1B8FEE14
                                                      SHA1:910D6A11B2A0F0A1166D7289ADD5DE4FF27A89F3
                                                      SHA-256:F3C6117602E3F85F6D46110C2DB5A8719AECD7EF5ECE10F1A1F5931C1B27BAC8
                                                      SHA-512:E50446C9765D1C2FDB4CC8452F08C82B1245FDCBA99C1A17C28C947108121F5D92E6DFB70002FD81E7CE7A79DBF2B25594FE312A9677E5C76FE6A4A8FB627DAC
                                                      Malicious:true
                                                      Preview:SET ow = WScript.CreateObject("WScript.Shell")..SET om = ow.CreateShortcut("C:\Users\user\Desktop\@WanaDecryptor@.exe.lnk")..om.TargetPath = "C:\Users\user\Desktop\@WanaDecryptor@.exe"..om.Save..
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:Rich Text Format data, version 1, ANSI, code page 1252, default middle east language ID 1025
                                                      Category:dropped
                                                      Size (bytes):47879
                                                      Entropy (8bit):4.950611667526586
                                                      Encrypted:false
                                                      SSDEEP:768:Shef3jHdCG28Eb1tyci8crbEw6/5+3xFkbP0vyzbZrS14e:SheU5De
                                                      MD5:95673B0F968C0F55B32204361940D184
                                                      SHA1:81E427D15A1A826B93E91C3D2FA65221C8CA9CFF
                                                      SHA-256:40B37E7B80CF678D7DD302AAF41B88135ADE6DDF44D89BDBA19CF171564444BD
                                                      SHA-512:7601F1883EDBB4150A9DC17084012323B3BFA66F6D19D3D0355CF82B6A1C9DCE475D758DA18B6D17A8B321BF6FCA20915224DBAEDCB3F4D16ABFAF7A5FC21B92
                                                      Malicious:false
                                                      Preview:{\rtf1\adeflang1025\ansi\ansicpg1252\uc2\adeff31507\deff0\stshfdbch31505\stshfloch31506\stshfhich31506\stshfbi0\deflang1033\deflangfe1042\themelang1033\themelangfe1042\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f2\fbidi \fmodern\fcharset0\fprq1{\*\panose 02070309020205020404}Courier New;}..{\f34\fbidi \froman\fcharset0\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f36\fbidi \fmodern\fcharset129\fprq2{\*\panose 020b0503020000020004}\'b8\'bc\'c0\'ba \'b0\'ed\'b5\'f1;}..{\f37\fbidi \froman\fcharset0\fprq2{\*\panose 02040503050406030204}Cambria;}{\f40\fbidi \fmodern\fcharset129\fprq2{\*\panose 020b0503020000020004}@\'b8\'bc\'c0\'ba \'b0\'ed\'b5\'f1;}..{\f41\fbidi \fmodern\fcharset0\fprq1{\*\panose 020b0609020204030204}Consolas;}{\flomajor\f31500\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbmajor\f31501\fbidi \fmodern\fcharset129\fprq2{\*\panose 020b0503020000020004}\'b8\'bc\'c0\'ba
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:Rich Text Format data, version 1, ANSI, code page 1252, default middle east language ID 1025
                                                      Category:dropped
                                                      Size (bytes):54359
                                                      Entropy (8bit):5.015093444540877
                                                      Encrypted:false
                                                      SSDEEP:768:SWjkSFwwlUdcUG2HAmDTzpXtgmDNQ8qD7DHDqMtgDdLDMaDoKMGzD0DWJQ8/QoZ4:SWcwiqDB
                                                      MD5:0252D45CA21C8E43C9742285C48E91AD
                                                      SHA1:5C14551D2736EEF3A1C1970CC492206E531703C1
                                                      SHA-256:845D0E178AEEBD6C7E2A2E9697B2BF6CF02028C50C288B3BA88FE2918EA2834A
                                                      SHA-512:1BFCF6C0E7C977D777F12BD20AC347630999C4D99BD706B40DE7FF8F2F52E02560D68093142CC93722095657807A1480CE3FB6A2E000C488550548C497998755
                                                      Malicious:false
                                                      Preview:{\rtf1\adeflang1025\ansi\ansicpg1252\uc2\adeff31507\deff0\stshfdbch31505\stshfloch31506\stshfhich31506\stshfbi0\deflang1033\deflangfe1042\themelang1033\themelangfe1042\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset0\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f12\fbidi \froman\fcharset129\fprq2{\*\panose 02030600000101010101}\'b9\'d9\'c5\'c1{\*\falt Batang};}{\f18\fbidi \fmodern\fcharset136\fprq1{\*\panose 02020509000000000000}MingLiU{\*\falt 2OcuAe};}..{\f34\fbidi \froman\fcharset0\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f41\fbidi \fmodern\fcharset0\fprq1{\*\panose 020b0609020204030204}Consolas;}{\f44\fbidi \froman\fcharset129\fprq2{\*\panose 02030600000101010101}@\'b9\'d9\'c5\'c1;}..{\f45\fbidi \fmodern\fcharset136\fprq1{\*\panose 02020509000000000000}@MingLiU;}{\f53\fbidi \fmodern\fcharset129\fprq1{\*\panose 020b0609000101010101}\'b1\'bc\'b8\'b2\'c3\'bc;}..{\f54\fbidi \fmodern\fchar
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:Rich Text Format data, version 1, ANSI, code page 1252, default middle east language ID 1025
                                                      Category:dropped
                                                      Size (bytes):79346
                                                      Entropy (8bit):4.901891087442577
                                                      Encrypted:false
                                                      SSDEEP:768:SDwtkzjHdLG2xN1fyvnywUKB5lylYlzlJpsbuEWeM/yDRu9uCuwyInIwDOHEhm/v:SDnz5Rt4D4
                                                      MD5:2EFC3690D67CD073A9406A25005F7CEA
                                                      SHA1:52C07F98870EABACE6EC370B7EB562751E8067E9
                                                      SHA-256:5C7F6AD1EC4BC2C8E2C9C126633215DABA7DE731AC8B12BE10CA157417C97F3A
                                                      SHA-512:0766C58E64D9CDA5328E00B86F8482316E944AA2C26523A3C37289E22C34BE4B70937033BEBDB217F675E40DB9FECDCE0A0D516F9065A170E28286C2D218487C
                                                      Malicious:false
                                                      Preview:{\rtf1\adeflang1025\ansi\ansicpg1252\uc2\adeff31507\deff0\stshfdbch31505\stshfloch31506\stshfhich31506\stshfbi0\deflang1033\deflangfe1042\themelang1033\themelangfe1042\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset0\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f11\fbidi \fmodern\fcharset128\fprq1{\*\panose 02020609040205080304}MS Mincho{\*\falt ?l?r ??\'81\'66c};}{\f12\fbidi \froman\fcharset129\fprq2{\*\panose 02030600000101010101}\'b9\'d9\'c5\'c1{\*\falt Batang};}..{\f18\fbidi \fmodern\fcharset136\fprq1{\*\panose 02020509000000000000}MingLiU{\*\falt 2OcuAe};}{\f34\fbidi \froman\fcharset0\fprq2{\*\panose 02040503050406030204}Cambria Math;}..{\f36\fbidi \fmodern\fcharset129\fprq2{\*\panose 020b0503020000020004}\'b8\'bc\'c0\'ba \'b0\'ed\'b5\'f1;}{\f40\fbidi \fmodern\fcharset129\fprq2{\*\panose 020b0503020000020004}@\'b8\'bc\'c0\'ba \'b0\'ed\'b5\'f1;}..{\f41\fbidi \fmodern\fcharset0\fprq1{\*\panose 020
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:Rich Text Format data, version 1, ANSI, code page 1252, default middle east language ID 1025
                                                      Category:dropped
                                                      Size (bytes):39070
                                                      Entropy (8bit):5.03796878472628
                                                      Encrypted:false
                                                      SSDEEP:384:SheftipUENLFsPzy3EFHjHdb2YG2+d18Scgn8c8/868H1F8E8/8Z3m8VdAm86a8n:Shef3jHd3G2n+p/mZrS14A
                                                      MD5:17194003FA70CE477326CE2F6DEEB270
                                                      SHA1:E325988F68D327743926EA317ABB9882F347FA73
                                                      SHA-256:3F33734B2D34CCE83936CE99C3494CD845F1D2C02D7F6DA31D42DFC1CA15A171
                                                      SHA-512:DCF4CCF0B352A8B271827B3B8E181F7D6502CA0F8C9DDA3DC6E53441BB4AE6E77B49C9C947CC3EDE0BF323F09140A0C068A907F3C23EA2A8495D1AD96820051C
                                                      Malicious:false
                                                      Preview:{\rtf1\adeflang1025\ansi\ansicpg1252\uc2\adeff31507\deff0\stshfdbch31505\stshfloch31506\stshfhich31506\stshfbi0\deflang1033\deflangfe1042\themelang1033\themelangfe1042\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f2\fbidi \fmodern\fcharset0\fprq1{\*\panose 02070309020205020404}Courier New;}..{\f34\fbidi \froman\fcharset0\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f36\fbidi \fmodern\fcharset129\fprq2{\*\panose 020b0503020000020004}\'b8\'bc\'c0\'ba \'b0\'ed\'b5\'f1;}..{\f37\fbidi \froman\fcharset0\fprq2{\*\panose 02040503050406030204}Cambria;}{\f40\fbidi \fmodern\fcharset129\fprq2{\*\panose 020b0503020000020004}@\'b8\'bc\'c0\'ba \'b0\'ed\'b5\'f1;}..{\f41\fbidi \fmodern\fcharset0\fprq1{\*\panose 020b0609020204030204}Consolas;}{\flomajor\f31500\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbmajor\f31501\fbidi \fmodern\fcharset129\fprq2{\*\panose 020b0503020000020004}\'b8\'bc\'c0\'ba
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:Rich Text Format data, version 1, ANSI, code page 1252, default middle east language ID 1025
                                                      Category:dropped
                                                      Size (bytes):40512
                                                      Entropy (8bit):5.035949134693175
                                                      Encrypted:false
                                                      SSDEEP:384:SheftipUENLFsPzy3EFHjHdg2yG2gv8n8+8zfB8k8F8i8k1Z8M8I818E838C8A8s:Shef3jHd2G26nyMZrS14g
                                                      MD5:537EFEECDFA94CC421E58FD82A58BA9E
                                                      SHA1:3609456E16BC16BA447979F3AA69221290EC17D0
                                                      SHA-256:5AFA4753AFA048C6D6C39327CE674F27F5F6E5D3F2A060B7A8AED61725481150
                                                      SHA-512:E007786FFA09CCD5A24E5C6504C8DE444929A2FAAAFAD3712367C05615B7E1B0FBF7FBFFF7028ED3F832CE226957390D8BF54308870E9ED597948A838DA1137B
                                                      Malicious:false
                                                      Preview:{\rtf1\adeflang1025\ansi\ansicpg1252\uc2\adeff31507\deff0\stshfdbch31505\stshfloch31506\stshfhich31506\stshfbi0\deflang1033\deflangfe1042\themelang1033\themelangfe1042\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f2\fbidi \fmodern\fcharset0\fprq1{\*\panose 02070309020205020404}Courier New;}..{\f34\fbidi \froman\fcharset0\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f36\fbidi \fmodern\fcharset129\fprq2{\*\panose 020b0503020000020004}\'b8\'bc\'c0\'ba \'b0\'ed\'b5\'f1;}..{\f37\fbidi \froman\fcharset0\fprq2{\*\panose 02040503050406030204}Cambria;}{\f40\fbidi \fmodern\fcharset129\fprq2{\*\panose 020b0503020000020004}@\'b8\'bc\'c0\'ba \'b0\'ed\'b5\'f1;}..{\f41\fbidi \fmodern\fcharset0\fprq1{\*\panose 020b0609020204030204}Consolas;}{\flomajor\f31500\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbmajor\f31501\fbidi \fmodern\fcharset129\fprq2{\*\panose 020b0503020000020004}\'b8\'bc\'c0\'ba
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:Rich Text Format data, version 1, ANSI, code page 1252, default middle east language ID 1025
                                                      Category:dropped
                                                      Size (bytes):37045
                                                      Entropy (8bit):5.028683023706024
                                                      Encrypted:false
                                                      SSDEEP:384:SheftipUENLFsPzy3EFHjHd02wG2roqni2Jeo75Y3kmA31dv61QyU:Shef3jHd4G2M5bZrS14Q
                                                      MD5:2C5A3B81D5C4715B7BEA01033367FCB5
                                                      SHA1:B548B45DA8463E17199DAAFD34C23591F94E82CD
                                                      SHA-256:A75BB44284B9DB8D702692F84909A7E23F21141866ADF3DB888042E9109A1CB6
                                                      SHA-512:490C5A892FAC801B853C348477B1140755D4C53CA05726AC19D3649AF4285C93523393A3667E209C71C80AC06FFD809F62DD69AE65012DCB00445D032F1277B3
                                                      Malicious:false
                                                      Preview:{\rtf1\adeflang1025\ansi\ansicpg1252\uc2\adeff31507\deff0\stshfdbch31505\stshfloch31506\stshfhich31506\stshfbi0\deflang1033\deflangfe1042\themelang1033\themelangfe1042\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f2\fbidi \fmodern\fcharset0\fprq1{\*\panose 02070309020205020404}Courier New;}..{\f34\fbidi \froman\fcharset0\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f36\fbidi \fmodern\fcharset129\fprq2{\*\panose 020b0503020000020004}\'b8\'bc\'c0\'ba \'b0\'ed\'b5\'f1;}..{\f37\fbidi \froman\fcharset0\fprq2{\*\panose 02040503050406030204}Cambria;}{\f40\fbidi \fmodern\fcharset129\fprq2{\*\panose 020b0503020000020004}@\'b8\'bc\'c0\'ba \'b0\'ed\'b5\'f1;}..{\f41\fbidi \fmodern\fcharset0\fprq1{\*\panose 020b0609020204030204}Consolas;}{\flomajor\f31500\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbmajor\f31501\fbidi \fmodern\fcharset129\fprq2{\*\panose 020b0503020000020004}\'b8\'bc\'c0\'ba
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:Rich Text Format data, version 1, ANSI, code page 1252, default middle east language ID 1025
                                                      Category:dropped
                                                      Size (bytes):36987
                                                      Entropy (8bit):5.036160205965849
                                                      Encrypted:false
                                                      SSDEEP:384:Sw3BHSj2cLeT+sPzy3EFHjHdp2oG2/CzhReo75Y3kmA31dv61Qyz:Sw3BHSWjHdBG2/UhsZrS14f
                                                      MD5:7A8D499407C6A647C03C4471A67EAAD7
                                                      SHA1:D573B6AC8E7E04A05CBBD6B7F6A9842F371D343B
                                                      SHA-256:2C95BEF914DA6C50D7BDEDEC601E589FBB4FDA24C4863A7260F4F72BD025799C
                                                      SHA-512:608EF3FF0A517FE1E70FF41AEB277821565C5A9BEE5103AA5E45C68D4763FCE507C2A34D810F4CD242D163181F8341D9A69E93FE32ADED6FBC7F544C55743F12
                                                      Malicious:false
                                                      Preview:{\rtf1\adeflang1025\ansi\ansicpg1252\uc2\adeff31507\deff0\stshfdbch31505\stshfloch31506\stshfhich31506\stshfbi0\deflang1033\deflangfe1042\themelang1033\themelangfe1042\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\f34\fbidi \froman\fcharset0\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \froman\fcharset0\fprq2{\*\panose 02040503050406030204}Cambria;}{\f41\fbidi \fmodern\fcharset0\fprq1{\*\panose 020b0609020204030204}Consolas;}..{\f53\fbidi \fmodern\fcharset129\fprq1{\*\panose 020b0609000101010101}\'b1\'bc\'b8\'b2\'c3\'bc;}{\f54\fbidi \fmodern\fcharset129\fprq1{\*\panose 020b0609000101010101}@\'b1\'bc\'b8\'b2\'c3\'bc;}..{\flomajor\f31500\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \fmodern\fcharset129\fprq2{\*\panose 020b0503020000020004}\'b8\'bc\'c0\'ba \'b0\'ed\'b5\'f1;}..{\fhimajor\f31502\fbidi \froman\fcharset0\fprq2{\*\panose 02040503050406030204}
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:Rich Text Format data, version 1, ANSI, code page 1252, default middle east language ID 1025
                                                      Category:dropped
                                                      Size (bytes):36973
                                                      Entropy (8bit):5.040611616416892
                                                      Encrypted:false
                                                      SSDEEP:384:S93BHSj2cguALeT+sPzy3EFHjHdM2EG2YLC7O3eo75Y3kmA31dv61QyW:S93BHSTjHd0G2YLCZrS14y
                                                      MD5:FE68C2DC0D2419B38F44D83F2FCF232E
                                                      SHA1:6C6E49949957215AA2F3DFB72207D249ADF36283
                                                      SHA-256:26FD072FDA6E12F8C2D3292086EF0390785EFA2C556E2A88BD4673102AF703E5
                                                      SHA-512:941FA0A1F6A5756ED54260994DB6158A7EBEB9E18B5C8CA2F6530C579BC4455918DF0B38C609F501CA466B3CC067B40E4B861AD6513373B483B36338AE20A810
                                                      Malicious:false
                                                      Preview:{\rtf1\adeflang1025\ansi\ansicpg1252\uc2\adeff31507\deff0\stshfdbch31505\stshfloch31506\stshfhich31506\stshfbi0\deflang1033\deflangfe1042\themelang1033\themelangfe1042\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset0\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f34\fbidi \froman\fcharset0\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \froman\fcharset0\fprq2{\*\panose 02040503050406030204}Cambria;}{\f41\fbidi \fmodern\fcharset0\fprq1{\*\panose 020b0609020204030204}Consolas;}..{\f53\fbidi \fmodern\fcharset129\fprq1{\*\panose 020b0609000101010101}\'b1\'bc\'b8\'b2\'c3\'bc;}{\f54\fbidi \fmodern\fcharset129\fprq1{\*\panose 020b0609000101010101}@\'b1\'bc\'b8\'b2\'c3\'bc;}..{\flomajor\f31500\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \fmodern\fcharset129\fprq2{\*\panose 020b0503020000020004}\'b8\'bc\'c0\'ba \'b0\'ed\'b5\'f1;}..{\fhim
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:Rich Text Format data, version 1, ANSI, code page 1252, default middle east language ID 1025
                                                      Category:dropped
                                                      Size (bytes):37580
                                                      Entropy (8bit):5.0458193216786
                                                      Encrypted:false
                                                      SSDEEP:384:Sw3BHSj2cLeT+sPzy3EFHjHdi2MG2AGsi6p07i/eo75Y3kmA31dv61QyR:Sw3BHSWjHdGG2Axa7iGZrS14N
                                                      MD5:08B9E69B57E4C9B966664F8E1C27AB09
                                                      SHA1:2DA1025BBBFB3CD308070765FC0893A48E5A85FA
                                                      SHA-256:D8489F8C16318E524B45DE8B35D7E2C3CD8ED4821C136F12F5EF3C9FC3321324
                                                      SHA-512:966B5ED68BE6B5CCD46E0DE1FA868CFE5432D9BF82E1E2F6EB99B2AEF3C92F88D96F4F4EEC5E16381B9C6DB80A68071E7124CA1474D664BDD77E1817EC600CB4
                                                      Malicious:false
                                                      Preview:{\rtf1\adeflang1025\ansi\ansicpg1252\uc2\adeff31507\deff0\stshfdbch31505\stshfloch31506\stshfhich31506\stshfbi0\deflang1033\deflangfe1042\themelang1033\themelangfe1042\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\f34\fbidi \froman\fcharset0\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \froman\fcharset0\fprq2{\*\panose 02040503050406030204}Cambria;}{\f41\fbidi \fmodern\fcharset0\fprq1{\*\panose 020b0609020204030204}Consolas;}..{\f53\fbidi \fmodern\fcharset129\fprq1{\*\panose 020b0609000101010101}\'b1\'bc\'b8\'b2\'c3\'bc;}{\f54\fbidi \fmodern\fcharset129\fprq1{\*\panose 020b0609000101010101}@\'b1\'bc\'b8\'b2\'c3\'bc;}..{\flomajor\f31500\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \fmodern\fcharset129\fprq2{\*\panose 020b0503020000020004}\'b8\'bc\'c0\'ba \'b0\'ed\'b5\'f1;}..{\fhimajor\f31502\fbidi \froman\fcharset0\fprq2{\*\panose 02040503050406030204}
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:Rich Text Format data, version 1, ANSI, code page 1252, default middle east language ID 1025
                                                      Category:dropped
                                                      Size (bytes):38377
                                                      Entropy (8bit):5.030938473355282
                                                      Encrypted:false
                                                      SSDEEP:384:SheftipUENLFsPzy3EFHjHdg2oG2l1glOmeo75Y3kmA31dv61QyB:Shef3jHdMG2l1AO3ZrS14l
                                                      MD5:35C2F97EEA8819B1CAEBD23FEE732D8F
                                                      SHA1:E354D1CC43D6A39D9732ADEA5D3B0F57284255D2
                                                      SHA-256:1ADFEE058B98206CB4FBE1A46D3ED62A11E1DEE2C7FF521C1EEF7C706E6A700E
                                                      SHA-512:908149A6F5238FCCCD86F7C374986D486590A0991EF5243F0CD9E63CC8E208158A9A812665233B09C3A478233D30F21E3D355B94F36B83644795556F147345BF
                                                      Malicious:false
                                                      Preview:{\rtf1\adeflang1025\ansi\ansicpg1252\uc2\adeff31507\deff0\stshfdbch31505\stshfloch31506\stshfhich31506\stshfbi0\deflang1033\deflangfe1042\themelang1033\themelangfe1042\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f2\fbidi \fmodern\fcharset0\fprq1{\*\panose 02070309020205020404}Courier New;}..{\f34\fbidi \froman\fcharset0\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f36\fbidi \fmodern\fcharset129\fprq2{\*\panose 020b0503020000020004}\'b8\'bc\'c0\'ba \'b0\'ed\'b5\'f1;}..{\f37\fbidi \froman\fcharset0\fprq2{\*\panose 02040503050406030204}Cambria;}{\f40\fbidi \fmodern\fcharset129\fprq2{\*\panose 020b0503020000020004}@\'b8\'bc\'c0\'ba \'b0\'ed\'b5\'f1;}..{\f41\fbidi \fmodern\fcharset0\fprq1{\*\panose 020b0609020204030204}Consolas;}{\flomajor\f31500\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbmajor\f31501\fbidi \fmodern\fcharset129\fprq2{\*\panose 020b0503020000020004}\'b8\'bc\'c0\'ba
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:Rich Text Format data, version 1, ANSI, code page 1252, default middle east language ID 1025
                                                      Category:dropped
                                                      Size (bytes):38437
                                                      Entropy (8bit):5.031126676607223
                                                      Encrypted:false
                                                      SSDEEP:384:SheftipUENLFsPzy3EFHjHdtW2IG2sjqMeo75Y3kmA31dv61Qyg:Shef3jHd0G2smJZrS14M
                                                      MD5:4E57113A6BF6B88FDD32782A4A381274
                                                      SHA1:0FCCBC91F0F94453D91670C6794F71348711061D
                                                      SHA-256:9BD38110E6523547AED50617DDC77D0920D408FAEED2B7A21AB163FDA22177BC
                                                      SHA-512:4F1918A12269C654D44E9D394BC209EF0BC32242BE8833A2FBA437B879125177E149F56F2FB0C302330DEC328139B34982C04B3FEFB045612B6CC9F83EC85AA9
                                                      Malicious:false
                                                      Preview:{\rtf1\adeflang1025\ansi\ansicpg1252\uc2\adeff31507\deff0\stshfdbch31505\stshfloch31506\stshfhich31506\stshfbi0\deflang1033\deflangfe1042\themelang1033\themelangfe1042\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f2\fbidi \fmodern\fcharset0\fprq1{\*\panose 02070309020205020404}Courier New;}..{\f34\fbidi \froman\fcharset0\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f36\fbidi \fmodern\fcharset129\fprq2{\*\panose 020b0503020000020004}\'b8\'bc\'c0\'ba \'b0\'ed\'b5\'f1;}..{\f37\fbidi \froman\fcharset0\fprq2{\*\panose 02040503050406030204}Cambria;}{\f40\fbidi \fmodern\fcharset129\fprq2{\*\panose 020b0503020000020004}@\'b8\'bc\'c0\'ba \'b0\'ed\'b5\'f1;}..{\f41\fbidi \fmodern\fcharset0\fprq1{\*\panose 020b0609020204030204}Consolas;}{\flomajor\f31500\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbmajor\f31501\fbidi \fmodern\fcharset129\fprq2{\*\panose 020b0503020000020004}\'b8\'bc\'c0\'ba
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:Rich Text Format data, version 1, ANSI, code page 1252, default middle east language ID 1025
                                                      Category:dropped
                                                      Size (bytes):37181
                                                      Entropy (8bit):5.039739267952546
                                                      Encrypted:false
                                                      SSDEEP:384:SheftipUENLFsPzy3EFHjHdN26G2VSA1Ieo75Y3kmA31dv61QyU:Shef3jHdfG2oe1ZrS14w
                                                      MD5:3D59BBB5553FE03A89F817819540F469
                                                      SHA1:26781D4B06FF704800B463D0F1FCA3AFD923A9FE
                                                      SHA-256:2ADC900FAFA9938D85CE53CB793271F37AF40CF499BCC454F44975DB533F0B61
                                                      SHA-512:95719AE80589F71209BB3CB953276538040E7111B994D757B0A24283AEFE27AADBBE9EEF3F1F823CE4CABC1090946D4A2A558607AC6CAC6FACA5971529B34DAC
                                                      Malicious:false
                                                      Preview:{\rtf1\adeflang1025\ansi\ansicpg1252\uc2\adeff31507\deff0\stshfdbch31505\stshfloch31506\stshfhich31506\stshfbi0\deflang1033\deflangfe1042\themelang1033\themelangfe1042\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f2\fbidi \fmodern\fcharset0\fprq1{\*\panose 02070309020205020404}Courier New;}..{\f34\fbidi \froman\fcharset0\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f36\fbidi \fmodern\fcharset129\fprq2{\*\panose 020b0503020000020004}\'b8\'bc\'c0\'ba \'b0\'ed\'b5\'f1;}..{\f37\fbidi \froman\fcharset0\fprq2{\*\panose 02040503050406030204}Cambria;}{\f40\fbidi \fmodern\fcharset129\fprq2{\*\panose 020b0503020000020004}@\'b8\'bc\'c0\'ba \'b0\'ed\'b5\'f1;}..{\f41\fbidi \fmodern\fcharset0\fprq1{\*\panose 020b0609020204030204}Consolas;}{\flomajor\f31500\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbmajor\f31501\fbidi \fmodern\fcharset129\fprq2{\*\panose 020b0503020000020004}\'b8\'bc\'c0\'ba
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:Rich Text Format data, version 1, ANSI, code page 1252, default middle east language ID 1025
                                                      Category:dropped
                                                      Size (bytes):49044
                                                      Entropy (8bit):4.910095634621579
                                                      Encrypted:false
                                                      SSDEEP:384:SheftipUENLFsPzy3EFHjHdc2oG2WWDFFG5BwKeo75Y3kmA31dv61QyM:Shef3jHdoG2NHG5BwLZrS14Q
                                                      MD5:FB4E8718FEA95BB7479727FDE80CB424
                                                      SHA1:1088C7653CBA385FE994E9AE34A6595898F20AEB
                                                      SHA-256:E13CC9B13AA5074DC45D50379ECEB17EE39A0C2531AB617D93800FE236758CA9
                                                      SHA-512:24DB377AF1569E4E2B2EBCCEC42564CEA95A30F1FF43BCAF25A692F99567E027BCEF4AACEF008EC5F64EA2EEF0C04BE88D2B30BCADABB3919B5F45A6633940CB
                                                      Malicious:false
                                                      Preview:{\rtf1\adeflang1025\ansi\ansicpg1252\uc2\adeff31507\deff0\stshfdbch31505\stshfloch31506\stshfhich31506\stshfbi0\deflang1033\deflangfe1042\themelang1033\themelangfe1042\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f2\fbidi \fmodern\fcharset0\fprq1{\*\panose 02070309020205020404}Courier New;}..{\f34\fbidi \froman\fcharset0\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f36\fbidi \fmodern\fcharset129\fprq2{\*\panose 020b0503020000020004}\'b8\'bc\'c0\'ba \'b0\'ed\'b5\'f1;}..{\f37\fbidi \froman\fcharset0\fprq2{\*\panose 02040503050406030204}Cambria;}{\f40\fbidi \fmodern\fcharset129\fprq2{\*\panose 020b0503020000020004}@\'b8\'bc\'c0\'ba \'b0\'ed\'b5\'f1;}..{\f41\fbidi \fmodern\fcharset0\fprq1{\*\panose 020b0609020204030204}Consolas;}{\flomajor\f31500\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbmajor\f31501\fbidi \fmodern\fcharset129\fprq2{\*\panose 020b0503020000020004}\'b8\'bc\'c0\'ba
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:Rich Text Format data, version 1, ANSI, code page 1252, default middle east language ID 1025
                                                      Category:dropped
                                                      Size (bytes):37196
                                                      Entropy (8bit):5.039268541932758
                                                      Encrypted:false
                                                      SSDEEP:384:Sw3BHSj2cLeT+sPzy3EFHjHdY2oG2pq32eo75Y3kmA31dv61Qys:Sw3BHSWjHdUG2pq3nZrS14I
                                                      MD5:3788F91C694DFC48E12417CE93356B0F
                                                      SHA1:EB3B87F7F654B604DAF3484DA9E02CA6C4EA98B7
                                                      SHA-256:23E5E738AAD10FB8EF89AA0285269AFF728070080158FD3E7792FE9ED47C51F4
                                                      SHA-512:B7DD9E6DC7C2D023FF958CAF132F0544C76FAE3B2D8E49753257676CC541735807B4BEFDF483BCAE94C2DCDE3C878C783B4A89DCA0FECBC78F5BBF7C356F35CD
                                                      Malicious:false
                                                      Preview:{\rtf1\adeflang1025\ansi\ansicpg1252\uc2\adeff31507\deff0\stshfdbch31505\stshfloch31506\stshfhich31506\stshfbi0\deflang1033\deflangfe1042\themelang1033\themelangfe1042\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\f34\fbidi \froman\fcharset0\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \froman\fcharset0\fprq2{\*\panose 02040503050406030204}Cambria;}{\f41\fbidi \fmodern\fcharset0\fprq1{\*\panose 020b0609020204030204}Consolas;}..{\f53\fbidi \fmodern\fcharset129\fprq1{\*\panose 020b0609000101010101}\'b1\'bc\'b8\'b2\'c3\'bc;}{\f54\fbidi \fmodern\fcharset129\fprq1{\*\panose 020b0609000101010101}@\'b1\'bc\'b8\'b2\'c3\'bc;}..{\flomajor\f31500\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \fmodern\fcharset129\fprq2{\*\panose 020b0503020000020004}\'b8\'bc\'c0\'ba \'b0\'ed\'b5\'f1;}..{\fhimajor\f31502\fbidi \froman\fcharset0\fprq2{\*\panose 02040503050406030204}
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:Rich Text Format data, version 1, ANSI, code page 1252, default middle east language ID 1025
                                                      Category:dropped
                                                      Size (bytes):36883
                                                      Entropy (8bit):5.028048191734335
                                                      Encrypted:false
                                                      SSDEEP:384:SheftipUENLFsPzy3EFHjHdR2AG2c/EnByeo75Y3kmA31dv61Qy9:Shef3jHdJG2cQZrS14R
                                                      MD5:30A200F78498990095B36F574B6E8690
                                                      SHA1:C4B1B3C087BD12B063E98BCA464CD05F3F7B7882
                                                      SHA-256:49F2C739E7D9745C0834DC817A71BF6676CCC24A4C28DCDDF8844093AAB3DF07
                                                      SHA-512:C0DA2AAE82C397F6943A0A7B838F60EEEF8F57192C5F498F2ECF05DB824CFEB6D6CA830BF3715DA7EE400AA8362BD64DC835298F3F0085AE7A744E6E6C690511
                                                      Malicious:false
                                                      Preview:{\rtf1\adeflang1025\ansi\ansicpg1252\uc2\adeff31507\deff0\stshfdbch31505\stshfloch31506\stshfhich31506\stshfbi0\deflang1033\deflangfe1042\themelang1033\themelangfe1042\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f2\fbidi \fmodern\fcharset0\fprq1{\*\panose 02070309020205020404}Courier New;}..{\f34\fbidi \froman\fcharset0\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f36\fbidi \fmodern\fcharset129\fprq2{\*\panose 020b0503020000020004}\'b8\'bc\'c0\'ba \'b0\'ed\'b5\'f1;}..{\f37\fbidi \froman\fcharset0\fprq2{\*\panose 02040503050406030204}Cambria;}{\f40\fbidi \fmodern\fcharset129\fprq2{\*\panose 020b0503020000020004}@\'b8\'bc\'c0\'ba \'b0\'ed\'b5\'f1;}..{\f41\fbidi \fmodern\fcharset0\fprq1{\*\panose 020b0609020204030204}Consolas;}{\flomajor\f31500\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbmajor\f31501\fbidi \fmodern\fcharset129\fprq2{\*\panose 020b0503020000020004}\'b8\'bc\'c0\'ba
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:Rich Text Format data, version 1, ANSI, code page 1252, default middle east language ID 1025
                                                      Category:dropped
                                                      Size (bytes):81844
                                                      Entropy (8bit):4.85025787009624
                                                      Encrypted:false
                                                      SSDEEP:384:SXZ0j2cKKwd1lksPzy3EFHjHdI2MG275rQeo75Y3kmA31dv61Qyr:SXZ0qbjHd4G2RNZrS14P
                                                      MD5:B77E1221F7ECD0B5D696CB66CDA1609E
                                                      SHA1:51EB7A254A33D05EDF188DED653005DC82DE8A46
                                                      SHA-256:7E491E7B48D6E34F916624C1CDA9F024E86FCBEC56ACDA35E27FA99D530D017E
                                                      SHA-512:F435FD67954787E6B87460DB026759410FBD25B2F6EA758118749C113A50192446861A114358443A129BE817020B50F21D27B1EBD3D22C7BE62082E8B45223FC
                                                      Malicious:false
                                                      Preview:{\rtf1\adeflang1025\ansi\ansicpg1252\uc2\adeff31507\deff0\stshfdbch31505\stshfloch31506\stshfhich31506\stshfbi0\deflang1033\deflangfe1042\themelang1033\themelangfe1042\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f2\fbidi \fmodern\fcharset0\fprq1{\*\panose 02070309020205020404}Courier New;}..{\f11\fbidi \fmodern\fcharset128\fprq1{\*\panose 02020609040205080304}MS Mincho{\*\falt ?l?r ??\'81\'66c};}{\f12\fbidi \froman\fcharset129\fprq2{\*\panose 02030600000101010101}\'b9\'d9\'c5\'c1{\*\falt Batang};}..{\f34\fbidi \froman\fcharset0\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f36\fbidi \fmodern\fcharset129\fprq2{\*\panose 020b0503020000020004}\'b8\'bc\'c0\'ba \'b0\'ed\'b5\'f1;}..{\f40\fbidi \fmodern\fcharset129\fprq2{\*\panose 020b0503020000020004}@\'b8\'bc\'c0\'ba \'b0\'ed\'b5\'f1;}{\f41\fbidi \fmodern\fcharset0\fprq1{\*\panose 020b0609020204030204}Consolas;}..{\f44\fbidi \froman\fcharset129\fprq2{\*\panose 020306000001
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:Rich Text Format data, version 1, ANSI, code page 1252, default middle east language ID 1025
                                                      Category:dropped
                                                      Size (bytes):91501
                                                      Entropy (8bit):4.841830504507431
                                                      Encrypted:false
                                                      SSDEEP:768:Shef3jHdUG2NQcbxfSVZiG9jvi3//ZVrMQr7pEKCHSI2DsY78piTDtTa6BxzBwdY:SheiaDq
                                                      MD5:6735CB43FE44832B061EEB3F5956B099
                                                      SHA1:D636DAF64D524F81367EA92FDAFA3726C909BEE1
                                                      SHA-256:552AA0F82F37C9601114974228D4FC54F7434FE3AE7A276EF1AE98A0F608F1D0
                                                      SHA-512:60272801909DBBA21578B22C49F6B0BA8CD0070F116476FF35B3AC8347B987790E4CC0334724244C4B13415A246E77A577230029E4561AE6F04A598C3F536C7E
                                                      Malicious:false
                                                      Preview:{\rtf1\adeflang1025\ansi\ansicpg1252\uc2\adeff31507\deff0\stshfdbch31505\stshfloch31506\stshfhich31506\stshfbi0\deflang1033\deflangfe1042\themelang1033\themelangfe1042\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f2\fbidi \fmodern\fcharset0\fprq1{\*\panose 02070309020205020404}Courier New;}..{\f34\fbidi \froman\fcharset0\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f36\fbidi \fmodern\fcharset129\fprq2{\*\panose 020b0503020000020004}\'b8\'bc\'c0\'ba \'b0\'ed\'b5\'f1;}..{\f37\fbidi \froman\fcharset0\fprq2{\*\panose 02040503050406030204}Cambria;}{\f40\fbidi \fmodern\fcharset129\fprq2{\*\panose 020b0503020000020004}@\'b8\'bc\'c0\'ba \'b0\'ed\'b5\'f1;}..{\f41\fbidi \fmodern\fcharset0\fprq1{\*\panose 020b0609020204030204}Consolas;}{\flomajor\f31500\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbmajor\f31501\fbidi \fmodern\fcharset129\fprq2{\*\panose 020b0503020000020004}\'b8\'bc\'c0\'ba
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:Rich Text Format data, version 1, ANSI, code page 1252, default middle east language ID 1025
                                                      Category:dropped
                                                      Size (bytes):41169
                                                      Entropy (8bit):5.030695296195755
                                                      Encrypted:false
                                                      SSDEEP:384:SheftipUENLFsPzy3EFHjHdcqH24G2ZN1EDCv3Apb0WD5gYV/S4L3rnzdeo75Y3f:Shef3jHdcMG2NpZrS14F
                                                      MD5:C33AFB4ECC04EE1BCC6975BEA49ABE40
                                                      SHA1:FBEA4F170507CDE02B839527EF50B7EC74B4821F
                                                      SHA-256:A0356696877F2D94D645AE2DF6CE6B370BD5C0D6DB3D36DEF44E714525DE0536
                                                      SHA-512:0D435F0836F61A5FF55B78C02FA47B191E5807A79D8A6E991F3115743DF2141B3DB42BA8BDAD9AD259E12F5800828E9E72D7C94A6A5259312A447D669B03EC44
                                                      Malicious:false
                                                      Preview:{\rtf1\adeflang1025\ansi\ansicpg1252\uc2\adeff31507\deff0\stshfdbch31505\stshfloch31506\stshfhich31506\stshfbi0\deflang1033\deflangfe1042\themelang1033\themelangfe1042\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f2\fbidi \fmodern\fcharset0\fprq1{\*\panose 02070309020205020404}Courier New;}..{\f34\fbidi \froman\fcharset0\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f36\fbidi \fmodern\fcharset129\fprq2{\*\panose 020b0503020000020004}\'b8\'bc\'c0\'ba \'b0\'ed\'b5\'f1;}..{\f37\fbidi \froman\fcharset0\fprq2{\*\panose 02040503050406030204}Cambria;}{\f40\fbidi \fmodern\fcharset129\fprq2{\*\panose 020b0503020000020004}@\'b8\'bc\'c0\'ba \'b0\'ed\'b5\'f1;}..{\f41\fbidi \fmodern\fcharset0\fprq1{\*\panose 020b0609020204030204}Consolas;}{\flomajor\f31500\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbmajor\f31501\fbidi \fmodern\fcharset129\fprq2{\*\panose 020b0503020000020004}\'b8\'bc\'c0\'ba
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:Rich Text Format data, version 1, ANSI, code page 1252, default middle east language ID 1025
                                                      Category:dropped
                                                      Size (bytes):37577
                                                      Entropy (8bit):5.025836823617116
                                                      Encrypted:false
                                                      SSDEEP:384:SheftipUENLFsPzy3EFHjHdy2MG2D7mgwroXeo75Y3kmA31dv61Qy5:Shef3jHdGG23KrDZrS14N
                                                      MD5:FF70CC7C00951084175D12128CE02399
                                                      SHA1:75AD3B1AD4FB14813882D88E952208C648F1FD18
                                                      SHA-256:CB5DA96B3DFCF4394713623DBF3831B2A0B8BE63987F563E1C32EDEB74CB6C3A
                                                      SHA-512:F01DF3256D49325E5EC49FD265AA3F176020C8FFEC60EB1D828C75A3FA18FF8634E1DE824D77DFDD833768ACFF1F547303104620C70066A2708654A07EF22E19
                                                      Malicious:false
                                                      Preview:{\rtf1\adeflang1025\ansi\ansicpg1252\uc2\adeff31507\deff0\stshfdbch31505\stshfloch31506\stshfhich31506\stshfbi0\deflang1033\deflangfe1042\themelang1033\themelangfe1042\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f2\fbidi \fmodern\fcharset0\fprq1{\*\panose 02070309020205020404}Courier New;}..{\f34\fbidi \froman\fcharset0\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f36\fbidi \fmodern\fcharset129\fprq2{\*\panose 020b0503020000020004}\'b8\'bc\'c0\'ba \'b0\'ed\'b5\'f1;}..{\f37\fbidi \froman\fcharset0\fprq2{\*\panose 02040503050406030204}Cambria;}{\f40\fbidi \fmodern\fcharset129\fprq2{\*\panose 020b0503020000020004}@\'b8\'bc\'c0\'ba \'b0\'ed\'b5\'f1;}..{\f41\fbidi \fmodern\fcharset0\fprq1{\*\panose 020b0609020204030204}Consolas;}{\flomajor\f31500\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbmajor\f31501\fbidi \fmodern\fcharset129\fprq2{\*\panose 020b0503020000020004}\'b8\'bc\'c0\'ba
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:Rich Text Format data, version 1, ANSI, code page 1252, default middle east language ID 1025
                                                      Category:dropped
                                                      Size (bytes):39896
                                                      Entropy (8bit):5.048541002474746
                                                      Encrypted:false
                                                      SSDEEP:384:SheftipUENLFsPzy3EFHjHdD2SG2gA8w8OJ6868jy8/8w8m8T848f8y858l8j8yv:Shef3jHdxG2KhuZrS14G
                                                      MD5:E79D7F2833A9C2E2553C7FE04A1B63F4
                                                      SHA1:3D9F56D2381B8FE16042AA7C4FEB1B33F2BAEBFF
                                                      SHA-256:519AD66009A6C127400C6C09E079903223BD82ECC18AD71B8E5CD79F5F9C053E
                                                      SHA-512:E0159C753491CAC7606A7250F332E87BC6B14876BC7A1CF5625FA56AB4F09C485F7B231DD52E4FF0F5F3C29862AFB1124C0EFD0741613EB97A83CBE2668AF5DE
                                                      Malicious:false
                                                      Preview:{\rtf1\adeflang1025\ansi\ansicpg1252\uc2\adeff31507\deff0\stshfdbch31505\stshfloch31506\stshfhich31506\stshfbi0\deflang1033\deflangfe1042\themelang1033\themelangfe1042\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f2\fbidi \fmodern\fcharset0\fprq1{\*\panose 02070309020205020404}Courier New;}..{\f34\fbidi \froman\fcharset0\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f36\fbidi \fmodern\fcharset129\fprq2{\*\panose 020b0503020000020004}\'b8\'bc\'c0\'ba \'b0\'ed\'b5\'f1;}..{\f37\fbidi \froman\fcharset0\fprq2{\*\panose 02040503050406030204}Cambria;}{\f40\fbidi \fmodern\fcharset129\fprq2{\*\panose 020b0503020000020004}@\'b8\'bc\'c0\'ba \'b0\'ed\'b5\'f1;}..{\f41\fbidi \fmodern\fcharset0\fprq1{\*\panose 020b0609020204030204}Consolas;}{\flomajor\f31500\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbmajor\f31501\fbidi \fmodern\fcharset129\fprq2{\*\panose 020b0503020000020004}\'b8\'bc\'c0\'ba
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:Rich Text Format data, version 1, ANSI, code page 1252, default middle east language ID 1025
                                                      Category:dropped
                                                      Size (bytes):37917
                                                      Entropy (8bit):5.027872281764284
                                                      Encrypted:false
                                                      SSDEEP:384:SheftipUENLFsPzy3EFHjHdy2QG2xgk5eo75Y3kmA31dv61QyV:Shef3jHdCG2EZrS14p
                                                      MD5:FA948F7D8DFB21CEDDD6794F2D56B44F
                                                      SHA1:CA915FBE020CAA88DD776D89632D7866F660FC7A
                                                      SHA-256:BD9F4B3AEDF4F81F37EC0A028AABCB0E9A900E6B4DE04E9271C8DB81432E2A66
                                                      SHA-512:0D211BFB0AE953081DCA00CD07F8C908C174FD6C47A8001FADC614203F0E55D9FBB7FA9B87C735D57101341AB36AF443918EE00737ED4C19ACE0A2B85497F41A
                                                      Malicious:false
                                                      Preview:{\rtf1\adeflang1025\ansi\ansicpg1252\uc2\adeff31507\deff0\stshfdbch31505\stshfloch31506\stshfhich31506\stshfbi0\deflang1033\deflangfe1042\themelang1033\themelangfe1042\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f2\fbidi \fmodern\fcharset0\fprq1{\*\panose 02070309020205020404}Courier New;}..{\f34\fbidi \froman\fcharset0\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f36\fbidi \fmodern\fcharset129\fprq2{\*\panose 020b0503020000020004}\'b8\'bc\'c0\'ba \'b0\'ed\'b5\'f1;}..{\f37\fbidi \froman\fcharset0\fprq2{\*\panose 02040503050406030204}Cambria;}{\f40\fbidi \fmodern\fcharset129\fprq2{\*\panose 020b0503020000020004}@\'b8\'bc\'c0\'ba \'b0\'ed\'b5\'f1;}..{\f41\fbidi \fmodern\fcharset0\fprq1{\*\panose 020b0609020204030204}Consolas;}{\flomajor\f31500\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbmajor\f31501\fbidi \fmodern\fcharset129\fprq2{\*\panose 020b0503020000020004}\'b8\'bc\'c0\'ba
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:Rich Text Format data, version 1, ANSI, code page 1252, default middle east language ID 1025
                                                      Category:dropped
                                                      Size (bytes):52161
                                                      Entropy (8bit):4.964306949910696
                                                      Encrypted:false
                                                      SSDEEP:768:Shef3jHdXG2Cz2/vBAOZsQO0cLfnF/Zhcz7sDsYZBB/0gBjL+IU/hbhMVDtsR49P:ShehlrGR1m4dx9mjVyAvg7ouDT
                                                      MD5:313E0ECECD24F4FA1504118A11BC7986
                                                      SHA1:E1B9AE804C7FB1D27F39DB18DC0647BB04E75E9D
                                                      SHA-256:70C0F32ED379AE899E5AC975E20BBBACD295CF7CD50C36174D2602420C770AC1
                                                      SHA-512:C7500363C61BAF8B77FCE796D750F8F5E6886FF0A10F81C3240EA3AD4E5F101B597490DEA8AB6BD9193457D35D8FD579FCE1B88A1C8D85EBE96C66D909630730
                                                      Malicious:false
                                                      Preview:{\rtf1\adeflang1025\ansi\ansicpg1252\uc2\adeff31507\deff0\stshfdbch31505\stshfloch31506\stshfhich31506\stshfbi0\deflang1033\deflangfe1042\themelang1033\themelangfe1042\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f2\fbidi \fmodern\fcharset0\fprq1{\*\panose 02070309020205020404}Courier New;}..{\f34\fbidi \froman\fcharset0\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f36\fbidi \fmodern\fcharset129\fprq2{\*\panose 020b0503020000020004}\'b8\'bc\'c0\'ba \'b0\'ed\'b5\'f1;}..{\f37\fbidi \froman\fcharset0\fprq2{\*\panose 02040503050406030204}Cambria;}{\f40\fbidi \fmodern\fcharset129\fprq2{\*\panose 020b0503020000020004}@\'b8\'bc\'c0\'ba \'b0\'ed\'b5\'f1;}..{\f41\fbidi \fmodern\fcharset0\fprq1{\*\panose 020b0609020204030204}Consolas;}{\flomajor\f31500\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbmajor\f31501\fbidi \fmodern\fcharset129\fprq2{\*\panose 020b0503020000020004}\'b8\'bc\'c0\'ba
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:Rich Text Format data, version 1, ANSI, code page 1252, default middle east language ID 1025
                                                      Category:dropped
                                                      Size (bytes):47108
                                                      Entropy (8bit):4.952777691675008
                                                      Encrypted:false
                                                      SSDEEP:384:SheftipUENLFsPzy3EFHjHdg2qG2aUGs0K6lyZqmfGGHRblldORZeo75Y3kmA31L:Shef3jHdeG2lGsDOcZxbP7ZrS14K
                                                      MD5:452615DB2336D60AF7E2057481E4CAB5
                                                      SHA1:442E31F6556B3D7DE6EB85FBAC3D2957B7F5EAC6
                                                      SHA-256:02932052FAFE97E6ACAAF9F391738A3A826F5434B1A013ABBFA7A6C1ADE1E078
                                                      SHA-512:7613DC329ABE7A3F32164C9A6B660F209A84B774AB9C008BF6503C76255B30EA9A743A6DC49A8DE8DF0BCB9AEA5A33F7408BA27848D9562583FF51991910911F
                                                      Malicious:false
                                                      Preview:{\rtf1\adeflang1025\ansi\ansicpg1252\uc2\adeff31507\deff0\stshfdbch31505\stshfloch31506\stshfhich31506\stshfbi0\deflang1033\deflangfe1042\themelang1033\themelangfe1042\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f2\fbidi \fmodern\fcharset0\fprq1{\*\panose 02070309020205020404}Courier New;}..{\f34\fbidi \froman\fcharset0\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f36\fbidi \fmodern\fcharset129\fprq2{\*\panose 020b0503020000020004}\'b8\'bc\'c0\'ba \'b0\'ed\'b5\'f1;}..{\f37\fbidi \froman\fcharset0\fprq2{\*\panose 02040503050406030204}Cambria;}{\f40\fbidi \fmodern\fcharset129\fprq2{\*\panose 020b0503020000020004}@\'b8\'bc\'c0\'ba \'b0\'ed\'b5\'f1;}..{\f41\fbidi \fmodern\fcharset0\fprq1{\*\panose 020b0609020204030204}Consolas;}{\flomajor\f31500\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbmajor\f31501\fbidi \fmodern\fcharset129\fprq2{\*\panose 020b0503020000020004}\'b8\'bc\'c0\'ba
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:Rich Text Format data, version 1, ANSI, code page 1252, default middle east language ID 1025
                                                      Category:dropped
                                                      Size (bytes):41391
                                                      Entropy (8bit):5.027730966276624
                                                      Encrypted:false
                                                      SSDEEP:384:SheftipUENLFsPzy3EFHjHd4Yb2YG2gNZ8a8zV/8j8U8l8x838Z8Q808m8d8T8hw:Shef3jHdZvG23AZrS14f
                                                      MD5:C911ABA4AB1DA6C28CF86338AB2AB6CC
                                                      SHA1:FEE0FD58B8EFE76077620D8ABC7500DBFEF7C5B0
                                                      SHA-256:E64178E339C8E10EAC17A236A67B892D0447EB67B1DCD149763DAD6FD9F72729
                                                      SHA-512:3491ED285A091A123A1A6D61AAFBB8D5621CCC9E045A237A2F9C2CF6049E7420EB96EF30FDCEA856B50454436E2EC468770F8D585752D73FAFD676C4EF5E800A
                                                      Malicious:false
                                                      Preview:{\rtf1\adeflang1025\ansi\ansicpg1252\uc2\adeff31507\deff0\stshfdbch31505\stshfloch31506\stshfhich31506\stshfbi0\deflang1033\deflangfe1042\themelang1033\themelangfe1042\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f2\fbidi \fmodern\fcharset0\fprq1{\*\panose 02070309020205020404}Courier New;}..{\f34\fbidi \froman\fcharset0\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f36\fbidi \fmodern\fcharset129\fprq2{\*\panose 020b0503020000020004}\'b8\'bc\'c0\'ba \'b0\'ed\'b5\'f1;}..{\f37\fbidi \froman\fcharset0\fprq2{\*\panose 02040503050406030204}Cambria;}{\f40\fbidi \fmodern\fcharset129\fprq2{\*\panose 020b0503020000020004}@\'b8\'bc\'c0\'ba \'b0\'ed\'b5\'f1;}..{\f41\fbidi \fmodern\fcharset0\fprq1{\*\panose 020b0609020204030204}Consolas;}{\flomajor\f31500\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbmajor\f31501\fbidi \fmodern\fcharset129\fprq2{\*\panose 020b0503020000020004}\'b8\'bc\'c0\'ba
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:Rich Text Format data, version 1, ANSI, code page 1252, default middle east language ID 1025
                                                      Category:dropped
                                                      Size (bytes):37381
                                                      Entropy (8bit):5.02443306661187
                                                      Encrypted:false
                                                      SSDEEP:384:SheftipUENLFsPzy3EFHjHdf24G2/ezV6YQUdZYlujeMQ9RXmhRweo75Y3kmA31S:Shef3jHdrG2fuhZrS14T
                                                      MD5:8D61648D34CBA8AE9D1E2A219019ADD1
                                                      SHA1:2091E42FC17A0CC2F235650F7AAD87ABF8BA22C2
                                                      SHA-256:72F20024B2F69B45A1391F0A6474E9F6349625CE329F5444AEC7401FE31F8DE1
                                                      SHA-512:68489C33BA89EDFE2E3AEBAACF8EF848D2EA88DCBEF9609C258662605E02D12CFA4FFDC1D266FC5878488E296D2848B2CB0BBD45F1E86EF959BAB6162D284079
                                                      Malicious:false
                                                      Preview:{\rtf1\adeflang1025\ansi\ansicpg1252\uc2\adeff31507\deff0\stshfdbch31505\stshfloch31506\stshfhich31506\stshfbi0\deflang1033\deflangfe1042\themelang1033\themelangfe1042\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f2\fbidi \fmodern\fcharset0\fprq1{\*\panose 02070309020205020404}Courier New;}..{\f34\fbidi \froman\fcharset0\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f36\fbidi \fmodern\fcharset129\fprq2{\*\panose 020b0503020000020004}\'b8\'bc\'c0\'ba \'b0\'ed\'b5\'f1;}..{\f37\fbidi \froman\fcharset0\fprq2{\*\panose 02040503050406030204}Cambria;}{\f40\fbidi \fmodern\fcharset129\fprq2{\*\panose 020b0503020000020004}@\'b8\'bc\'c0\'ba \'b0\'ed\'b5\'f1;}..{\f41\fbidi \fmodern\fcharset0\fprq1{\*\panose 020b0609020204030204}Consolas;}{\flomajor\f31500\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbmajor\f31501\fbidi \fmodern\fcharset129\fprq2{\*\panose 020b0503020000020004}\'b8\'bc\'c0\'ba
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:Rich Text Format data, version 1, ANSI, code page 1252, default middle east language ID 1025
                                                      Category:dropped
                                                      Size (bytes):38483
                                                      Entropy (8bit):5.022972736625151
                                                      Encrypted:false
                                                      SSDEEP:384:SheftipUENLFsPzy3EFHjHdb24G2ZKLVdDeo75Y3kmA31dv61QyE:Shef3jHd/G2w6ZrS14w
                                                      MD5:C7A19984EB9F37198652EAF2FD1EE25C
                                                      SHA1:06EAFED025CF8C4D76966BF382AB0C5E1BD6A0AE
                                                      SHA-256:146F61DB72297C9C0FACFFD560487F8D6A2846ECEC92ECC7DB19C8D618DBC3A4
                                                      SHA-512:43DD159F9C2EAC147CBFF1DDA83F6A83DD0C59D2D7ACAC35BA8B407A04EC9A1110A6A8737535D060D100EDE1CB75078CF742C383948C9D4037EF459D150F6020
                                                      Malicious:false
                                                      Preview:{\rtf1\adeflang1025\ansi\ansicpg1252\uc2\adeff31507\deff0\stshfdbch31505\stshfloch31506\stshfhich31506\stshfbi0\deflang1033\deflangfe1042\themelang1033\themelangfe1042\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f2\fbidi \fmodern\fcharset0\fprq1{\*\panose 02070309020205020404}Courier New;}..{\f34\fbidi \froman\fcharset0\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f36\fbidi \fmodern\fcharset129\fprq2{\*\panose 020b0503020000020004}\'b8\'bc\'c0\'ba \'b0\'ed\'b5\'f1;}..{\f37\fbidi \froman\fcharset0\fprq2{\*\panose 02040503050406030204}Cambria;}{\f40\fbidi \fmodern\fcharset129\fprq2{\*\panose 020b0503020000020004}@\'b8\'bc\'c0\'ba \'b0\'ed\'b5\'f1;}..{\f41\fbidi \fmodern\fcharset0\fprq1{\*\panose 020b0609020204030204}Consolas;}{\flomajor\f31500\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbmajor\f31501\fbidi \fmodern\fcharset129\fprq2{\*\panose 020b0503020000020004}\'b8\'bc\'c0\'ba
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:Rich Text Format data, version 1, ANSI, code page 1252, default middle east language ID 1025
                                                      Category:dropped
                                                      Size (bytes):42582
                                                      Entropy (8bit):5.010722377068833
                                                      Encrypted:false
                                                      SSDEEP:384:SheftipUENLFsPzy3EFHjHds42WG2mzGu/eo75Y3kmA31dv61QyZ:Shef3jHdsiG2moZrS149
                                                      MD5:531BA6B1A5460FC9446946F91CC8C94B
                                                      SHA1:CC56978681BD546FD82D87926B5D9905C92A5803
                                                      SHA-256:6DB650836D64350BBDE2AB324407B8E474FC041098C41ECAC6FD77D632A36415
                                                      SHA-512:EF25C3CF4343DF85954114F59933C7CC8107266C8BCAC3B5EA7718EB74DBEE8CA8A02DA39057E6EF26B64F1DFCCD720DD3BF473F5AE340BA56941E87D6B796C9
                                                      Malicious:false
                                                      Preview:{\rtf1\adeflang1025\ansi\ansicpg1252\uc2\adeff31507\deff0\stshfdbch31505\stshfloch31506\stshfhich31506\stshfbi0\deflang1033\deflangfe1042\themelang1033\themelangfe1042\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f2\fbidi \fmodern\fcharset0\fprq1{\*\panose 02070309020205020404}Courier New;}..{\f34\fbidi \froman\fcharset0\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f36\fbidi \fmodern\fcharset129\fprq2{\*\panose 020b0503020000020004}\'b8\'bc\'c0\'ba \'b0\'ed\'b5\'f1;}..{\f37\fbidi \froman\fcharset0\fprq2{\*\panose 02040503050406030204}Cambria;}{\f40\fbidi \fmodern\fcharset129\fprq2{\*\panose 020b0503020000020004}@\'b8\'bc\'c0\'ba \'b0\'ed\'b5\'f1;}..{\f41\fbidi \fmodern\fcharset0\fprq1{\*\panose 020b0609020204030204}Consolas;}{\flomajor\f31500\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbmajor\f31501\fbidi \fmodern\fcharset129\fprq2{\*\panose 020b0503020000020004}\'b8\'bc\'c0\'ba
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:Rich Text Format data, version 1, ANSI, code page 1252, default middle east language ID 1025
                                                      Category:dropped
                                                      Size (bytes):93778
                                                      Entropy (8bit):4.76206134900188
                                                      Encrypted:false
                                                      SSDEEP:384:SheftipUENLFsPzy3EFHjHdW2YG22cViQj3KiG8dpcH8iEriG8E8O83Jz52sxG8h:Shef3jHdWG2+oPZrS14i
                                                      MD5:8419BE28A0DCEC3F55823620922B00FA
                                                      SHA1:2E4791F9CDFCA8ABF345D606F313D22B36C46B92
                                                      SHA-256:1F21838B244C80F8BED6F6977AA8A557B419CF22BA35B1FD4BF0F98989C5BDF8
                                                      SHA-512:8FCA77E54480AEA3C0C7A705263ED8FB83C58974F5F0F62F12CC97C8E0506BA2CDB59B70E59E9A6C44DD7CDE6ADEEEC35B494D31A6A146FF5BA7006136AB9386
                                                      Malicious:false
                                                      Preview:{\rtf1\adeflang1025\ansi\ansicpg1252\uc2\adeff31507\deff0\stshfdbch31505\stshfloch31506\stshfhich31506\stshfbi0\deflang1033\deflangfe1042\themelang1033\themelangfe1042\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f2\fbidi \fmodern\fcharset0\fprq1{\*\panose 02070309020205020404}Courier New;}..{\f34\fbidi \froman\fcharset0\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f36\fbidi \fmodern\fcharset129\fprq2{\*\panose 020b0503020000020004}\'b8\'bc\'c0\'ba \'b0\'ed\'b5\'f1;}..{\f37\fbidi \froman\fcharset0\fprq2{\*\panose 02040503050406030204}Cambria;}{\f40\fbidi \fmodern\fcharset129\fprq2{\*\panose 020b0503020000020004}@\'b8\'bc\'c0\'ba \'b0\'ed\'b5\'f1;}..{\f41\fbidi \fmodern\fcharset0\fprq1{\*\panose 020b0609020204030204}Consolas;}{\flomajor\f31500\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbmajor\f31501\fbidi \fmodern\fcharset129\fprq2{\*\panose 020b0503020000020004}\'b8\'bc\'c0\'ba
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:ASCII text, with CRLF line terminators
                                                      Category:dropped
                                                      Size (bytes):864
                                                      Entropy (8bit):4.5335184780121995
                                                      Encrypted:false
                                                      SSDEEP:24:ptrPzDVR5Gi3OzGm0Ei5bnBR7brW8PNAi0eEprY+Ai75wRZce/:DZD36W5/vWmMo+m
                                                      MD5:3E0020FC529B1C2A061016DD2469BA96
                                                      SHA1:C3A91C22B63F6FE709E7C29CAFB29A2EE83E6ADE
                                                      SHA-256:402751FA49E0CB68FE052CB3DB87B05E71C1D950984D339940CF6B29409F2A7C
                                                      SHA-512:5CA3C134201ED39D96D72911C0498BAE6F98701513FD7F1DC8512819B673F0EA580510FA94ED9413CCC73DA18B39903772A7CBFA3478176181CEE68C896E14CF
                                                      Malicious:false
                                                      Yara Hits:
                                                      • Rule: WannaCry_RansomNote, Description: Detects WannaCry Ransomware Note, Source: C:\Users\user\Desktop\r.wnry, Author: Florian Roth
                                                      • Rule: WannaCry_RansomNote, Description: Detects WannaCry Ransomware Note, Source: C:\Users\user\Desktop\r.wnry, Author: Florian Roth
                                                      • Rule: WannaCry_RansomNote, Description: Detects WannaCry Ransomware Note, Source: C:\Users\user\Desktop\r.wnry, Author: Florian Roth
                                                      • Rule: WannaCry_RansomNote, Description: Detects WannaCry Ransomware Note, Source: C:\Users\user\Desktop\r.wnry, Author: Florian Roth
                                                      • Rule: WannaCry_RansomNote, Description: Detects WannaCry Ransomware Note, Source: C:\Users\user\Desktop\r.wnry, Author: Florian Roth
                                                      • Rule: WannaCry_RansomNote, Description: Detects WannaCry Ransomware Note, Source: C:\Users\user\Desktop\r.wnry, Author: Florian Roth
                                                      • Rule: WannaCry_RansomNote, Description: Detects WannaCry Ransomware Note, Source: C:\Users\user\Desktop\r.wnry, Author: Florian Roth
                                                      Preview:Q: What's wrong with my files?....A: Ooops, your important files are encrypted. It means you will not be able to access them anymore until they are decrypted... If you follow our instructions, we guarantee that you can decrypt all your files quickly and safely!.. Let's start decrypting!....Q: What do I do?....A: First, you need to pay service fees for the decryption... Please send %s to this bitcoin address: %s.... Next, please find an application file named "%s". It is the decrypt software... Run and follow the instructions! (You may need to disable your antivirus for a while.).. ..Q: How can I trust?....A: Don't worry about decryption... We will decrypt your files surely because nobody will trust us if we cheat users... ....* If you need our assistance, send a message by clicking <Contact Us> on the decryptor window...
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:Zip archive data, at least v1.0 to extract, compression method=store
                                                      Category:dropped
                                                      Size (bytes):3038286
                                                      Entropy (8bit):7.998263053003918
                                                      Encrypted:true
                                                      SSDEEP:49152:zUx4db9A1iRdHAHZXaTnCshuTnSQYUB/UZfCg2clOQin2h37l2Jh9iiRKpbXUSH:z/b96AdHA5XaTJvQYUBBgRlJi+rlliRy
                                                      MD5:AD4C9DE7C8C40813F200BA1C2FA33083
                                                      SHA1:D1AF27518D455D432B62D73C6A1497D032F6120E
                                                      SHA-256:E18FDD912DFE5B45776E68D578C3AF3547886CF1353D7086C8BEE037436DFF4B
                                                      SHA-512:115733D08E5F1A514808A20B070DB7FF453FD149865F49C04365A8C6502FA1E5C3A31DA3E21F688AB040F583CF1224A544AEA9708FFAB21405DDE1C57F98E617
                                                      Malicious:true
                                                      Preview:PK..........!(................Data/PK........M..J................Data/Tor/PK..........!(................Tor/PK..........!(..t.......0.....Tor/libeay32.dll.:.t.e....6m.....Me.Vjil....!..E..T..e...*..e....,.c..o=..t.u..,....J..k-.x.V..:1u....v..7.L~..?{..rN23.w......o..N2....WU..G..G.......Ed..7..q.o.5.]w.{...wl\y..m..w...?]......n......Z]UX./h4.....]...71....e.\^1..I..MH5...k.o+..s...c|s....-#d,!..............eW...?a.......R..I..R......w.....m..#od.*q.&..g.;.C(..t.V...j.Jq%...d_.Js...Hk.j#...DH.....,8_.O...]U....t .......ks:..T...18.C.%ASZJ3.U.nl..J.@)...$...N.s.O........m.0..*e..4.....m...lI..Z..7.f-.?....;...?.SO....}..7#.L8...5.z.~.........E.S..1....7.*.0...pf.....jz.)..Y..8..^....B........p.W..r..B.....p..?......../`*Wl..D.xAi..$..d.......&..p. ..bOtE.\.......(..&A...6v..S..Q...L...3 .:.6.m7.'.......)......iH.NZ_t.;./.a..n.g...A`.T.k.........."...<.rt..3....0.{N..yy...p.z.=..#.u.u...d......mQ..*.H..2.N.BRSN...XC....).".@.._.18.&...n
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):65816
                                                      Entropy (8bit):7.997276137881339
                                                      Encrypted:true
                                                      SSDEEP:1536:am+vLII5ygV8/tuH+P9zxqDKvARpmKiRMkTERU:a9LAg4tXPTEKvADmFgRU
                                                      MD5:5DCAAC857E695A65F5C3EF1441A73A8F
                                                      SHA1:7B10AAEEE05E7A1EFB43D9F837E9356AD55C07DD
                                                      SHA-256:97EBCE49B14C46BEBC9EC2448D00E1E397123B256E2BE9EBA5140688E7BC0AE6
                                                      SHA-512:06EB5E49D19B71A99770D1B11A5BB64A54BF3352F36E39A153469E54205075C203B08128DC2317259DB206AB5323BDD93AAA252A066F57FB5C52FF28DEEDB5E2
                                                      Malicious:true
                                                      Preview:WANACRY!.....8"'....].~>(...*PdIf.'.m>...2.0.`p...^...#I|..<.W.B.=....M..zxFp....0e...P...."....nhB)>....B..}.[d$......,...8.....k$.....S.w+.....N.....p/...Y.LC......9L.\!u...?hH".<d..dS%A.......Iu...nEi7I.....8.V..:F....-...,........\....}..`1?..m..5g.I'..................q.\..9`..t.....a......(|.8.L....67.gjrS.|.e...f.Fi......\...r.k.!d......8.'g1y+..'.i1t.L.>.u..:......<.fN.:Tf{..M.....W....._......_:...rR(.M..A?:...H.W.....=l......r..f..JX...:.z.rC.....f.X Qx.4....2....&w+..&kDqFU..u.............Sg..4k..<5.Zd$F.ED...1.S.d.. .eW.i....p.2..&.~S.l.R8$&q.L3.<.2....x ..by.zO.w. .hs.q.....I.1..D.F...J).&.....SD..v..m...V.....G...B`.u>K@.\_N......#.|..w.....Z.).X..[..o.(.'.~.nq.hq1.....:!.Q.P...c.KA,.3..m...j>.X.;..<.*."AU..R....Y....d]....U....).@...Q....|K.=.d.cI.x.....O...\(.%}.j..YG}...i.....R..j.`..9...5.....o..U...xu>+.$y...z... ...5......s..e...G...W.".T.'..iH..B.Sl...h..7B..E.8.....K.bRm...FE..W'_Q1...... ...A.5.}..%.../^VL.;.".w
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:PE32 executable (GUI) Intel 80386, for MS Windows
                                                      Category:dropped
                                                      Size (bytes):20480
                                                      Entropy (8bit):3.1664845408760636
                                                      Encrypted:false
                                                      SSDEEP:96:Udocv5e0e1wWtaLYjJN0yDGgI2u9+w5eOIMviS0jPtboyn15EWBwwWwT:6oL0edtJN7qvAZM6S0jP1oynkWBwwWg
                                                      MD5:4FEF5E34143E646DBF9907C4374276F5
                                                      SHA1:47A9AD4125B6BD7C55E4E7DA251E23F089407B8F
                                                      SHA-256:4A468603FDCB7A2EB5770705898CF9EF37AADE532A7964642ECD705A74794B79
                                                      SHA-512:4550DD1787DEB353EBD28363DD2CDCCCA861F6A5D9358120FA6AA23BAA478B2A9EB43CEF5E3F6426F708A0753491710AC05483FAC4A046C26BEC4234122434D5
                                                      Malicious:true
                                                      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......=..y..y..y......x......r......x......}.....z..y..Q..O..x..Richy..........PE..L...W.[J.....................0............... ....@..........................P...............................................!..P....@............................................................................... ...............................text............................... ..`.rdata..z.... ....... ..............@..@.data........0.......0..............@....rsrc........@.......@..............@..@........................................................................................................................................................................................................................................................................................................................................................................................
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:PE32 executable (GUI) Intel 80386, for MS Windows
                                                      Category:dropped
                                                      Size (bytes):20480
                                                      Entropy (8bit):2.5252509618107535
                                                      Encrypted:false
                                                      SSDEEP:96:UjpvOHheaCDCNIOgTegoddPtboyX7cvp0EWy1HlWwr:UjVWEam7ofP1oyX7olWUHlW0
                                                      MD5:8495400F199AC77853C53B5A3F278F3E
                                                      SHA1:BE5D6279874DA315E3080B06083757AAD9B32C23
                                                      SHA-256:2CA2D550E603D74DEDDA03156023135B38DA3630CB014E3D00B1263358C5F00D
                                                      SHA-512:0669C524A295A049FA4629B26F89788B2A74E1840BCDC50E093A0BD40830DD1279C9597937301C0072DB6ECE70ADEE4ACE67C3C8A4FB2DB6DEAFD8F1E887ABE4
                                                      Malicious:true
                                                      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......#O..g.v.g.v.g.v..2x.f.v..1|.l.v..1r.e.v.!+.d.v.g.w...v.Q.}.f.v.Richg.v.........PE..L.....[J.....................0......L........ ....@..........................P..............................................| ..<....@............................................................................... ..`............................text............................... ..`.rdata....... ....... ..............@..@.data........0.......0..............@....rsrc........@.......@..............@..@................................................................................................................................................................................................................................................................................................................................................................................................
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:PE32 executable (GUI) Intel 80386, for MS Windows
                                                      Category:dropped
                                                      Size (bytes):245760
                                                      Entropy (8bit):6.278920408390635
                                                      Encrypted:false
                                                      SSDEEP:3072:Rmrhd5U1eigWcR+uiUg6p4FLlG4tlL8z+mmCeHFZjoHEo3m:REd5+IZiZhLlG4AimmCo
                                                      MD5:7BF2B57F2A205768755C07F238FB32CC
                                                      SHA1:45356A9DD616ED7161A3B9192E2F318D0AB5AD10
                                                      SHA-256:B9C5D4339809E0AD9A00D4D3DD26FDF44A32819A54ABF846BB9B560D81391C25
                                                      SHA-512:91A39E919296CB5C6ECCBA710B780519D90035175AA460EC6DBE631324E5E5753BD8D87F395B5481BCD7E1AD623B31A34382D81FAAE06BEF60EC28B49C3122A9
                                                      Malicious:true
                                                      Yara Hits:
                                                      • Rule: JoeSecurity_Wannacry, Description: Yara detected Wannacry ransomware, Source: C:\Users\user\Desktop\u.wnry, Author: Joe Security
                                                      • Rule: Win32_Ransomware_WannaCry, Description: unknown, Source: C:\Users\user\Desktop\u.wnry, Author: ReversingLabs
                                                      • Rule: Win32_Ransomware_WannaCry, Description: unknown, Source: C:\Users\user\Desktop\u.wnry, Author: ReversingLabs
                                                      • Rule: Win32_Ransomware_WannaCry, Description: unknown, Source: C:\Users\user\Desktop\u.wnry, Author: ReversingLabs
                                                      • Rule: Win32_Ransomware_WannaCry, Description: unknown, Source: C:\Users\user\Desktop\u.wnry, Author: ReversingLabs
                                                      • Rule: Win32_Ransomware_WannaCry, Description: unknown, Source: C:\Users\user\Desktop\u.wnry, Author: ReversingLabs
                                                      • Rule: Win32_Ransomware_WannaCry, Description: unknown, Source: C:\Users\user\Desktop\u.wnry, Author: ReversingLabs
                                                      • Rule: Win32_Ransomware_WannaCry, Description: unknown, Source: C:\Users\user\Desktop\u.wnry, Author: ReversingLabs
                                                      • Rule: Win32_Ransomware_WannaCry, Description: unknown, Source: C:\Users\user\Desktop\u.wnry, Author: ReversingLabs
                                                      • Rule: Win32_Ransomware_WannaCry, Description: unknown, Source: C:\Users\user\Desktop\u.wnry, Author: ReversingLabs
                                                      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......%...a...a...a......b.......u.......`.....d.......j.......e...W...b...a.......W...s.......`...Richa...................PE..L.....[J.................@...p.......1.......P....@..................................................................................0..|............................................................................P...............................text....3.......@.................. ..`.rdata..h....P.......P..............@..@.data....2.......0..................@....rsrc...|....0....... ..............@..@........................................................................................................................................................................................................................................................................................................................................................
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:ASCII text, with CRLF line terminators
                                                      Category:dropped
                                                      Size (bytes):933
                                                      Entropy (8bit):4.710902136409594
                                                      Encrypted:false
                                                      SSDEEP:24:ptrPzDVR5Gi3OzGm0EigS1xbnS4RQhbrW8PNAi0eEprY+Ai75wRZcet:DZD36W3ChvWmMo+S
                                                      MD5:7E6B6DA7C61FCB66F3F30166871DEF5B
                                                      SHA1:00F699CF9BBC0308F6E101283ECA15A7C566D4F9
                                                      SHA-256:4A25D98C121BB3BD5B54E0B6A5348F7B09966BFFEEC30776E5A731813F05D49E
                                                      SHA-512:E5A56137F325904E0C7DE1D0DF38745F733652214F0CDB6EF173FA0743A334F95BED274DF79469E270C9208E6BDC2E6251EF0CDD81AF20FA1897929663E2C7D3
                                                      Malicious:false
                                                      Preview:Q: What's wrong with my files?....A: Ooops, your important files are encrypted. It means you will not be able to access them anymore until they are decrypted... If you follow our instructions, we guarantee that you can decrypt all your files quickly and safely!.. Let's start decrypting!....Q: What do I do?....A: First, you need to pay service fees for the decryption... Please send $300 worth of bitcoin to this bitcoin address: 13AM4VW2dhxYgXeQepoHkHSQuy6NgaEb94.... Next, please find an application file named "@WanaDecryptor@.exe". It is the decrypt software... Run and follow the instructions! (You may need to disable your antivirus for a while.).. ..Q: How can I trust?....A: Don't worry about decryption... We will decrypt your files surely because nobody will trust us if we cheat users... ....* If you need our assistance, send a message by clicking <Contact Us> on the decryptor window....
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:PE32 executable (GUI) Intel 80386, for MS Windows
                                                      Category:dropped
                                                      Size (bytes):245760
                                                      Entropy (8bit):6.278920408390635
                                                      Encrypted:false
                                                      SSDEEP:3072:Rmrhd5U1eigWcR+uiUg6p4FLlG4tlL8z+mmCeHFZjoHEo3m:REd5+IZiZhLlG4AimmCo
                                                      MD5:7BF2B57F2A205768755C07F238FB32CC
                                                      SHA1:45356A9DD616ED7161A3B9192E2F318D0AB5AD10
                                                      SHA-256:B9C5D4339809E0AD9A00D4D3DD26FDF44A32819A54ABF846BB9B560D81391C25
                                                      SHA-512:91A39E919296CB5C6ECCBA710B780519D90035175AA460EC6DBE631324E5E5753BD8D87F395B5481BCD7E1AD623B31A34382D81FAAE06BEF60EC28B49C3122A9
                                                      Malicious:true
                                                      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......%...a...a...a......b.......u.......`.....d.......j.......e...W...b...a.......W...s.......`...Richa...................PE..L.....[J.................@...p.......1.......P....@..................................................................................0..|............................................................................P...............................text....3.......@.................. ..`.rdata..h....P.......P..............@..@.data....2.......0..................@....rsrc...|....0....... ..............@..@........................................................................................................................................................................................................................................................................................................................................................
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.800250178020821
                                                      Encrypted:false
                                                      SSDEEP:12:npoaw7kGZGA8Owe9rgqWvl18HZSO1h7LBKbFWyM65XQ45Y5JKGx0CoaFiNwRhhcF:npI7RZYqWDW7LBIcyMmgsYrKGxCwVclb
                                                      MD5:1BBED22FFA65AC4EE42D648160BC1FB0
                                                      SHA1:03609242768AE31BD93AE663FF2F2A36DD47F15E
                                                      SHA-256:A6DACBFF723EC8B226264346DC7A221F203E1133527E9DB94FB188B6B3EB11DE
                                                      SHA-512:49E83B6722CFD0C45902BDF1C0E4FCC217BC3B6342436D552DD01F0EB184F785D548FCCBB8E5B8B861D71F0FAE9339C237FD4193DB06E8C826347BA165CD3AE7
                                                      Malicious:false
                                                      Preview:.W..x.Z....X...&...h..(z...*E.^.cI.q...w.wMs.s.{./.h.$y..b.....".3=..[.0.0.{V.D.CMn.#..O........k...P].dRqmj...(.-.........".wY$..|.-.v4..#0.-.....c...js3..8...%.).@.o.AU.[A.2e..?......ev...>..\.QS.X.3...78.X.|.K..h.Q\..x..a. .Z._....l..G-...-Jk.,9."3y..b...FJ.(b.. .S.&Z.../U.W.,......J.;.....@.[.ed.1... .....9x...C;hX.4....@!.]^y.@.&.<...M;..JW....u.....6J.....^.J....@.O..n.p..=rX....:/...Ht....1..^z,.h0.;o..9...&....x.A..1 /$.o.hI<v..v..i........-fn=6&..._.%.M9U..B....Q.....+O.....~..e....d.........v....5."...,..S+..x..o.rfb..._.b.NI....\I......&.....{n!+...e.......D...J...........MwG..l.(..+.=.G?.H..5.J.............:>..EKXR.h.~..?..h.x.....G[}...K}<..|._.....w.>....x.;W).8...!W.".p..t....Q.1.'...@....7..$.nx...b.He..'...:M..F/.(.DQ.......S..1[.2......X...2D.....E..'h....[...I..8.e...H.j...a.B.W.:B|..nV.E=..fSO~.....C..+......2..s.\...&...p.Fy*..|%..w`{..UwG.......c\c..=S..cY.g.b....~qT!....|.K..7.r(........).`.....`..d../.....M..}|.=h.F
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.845805357534609
                                                      Encrypted:false
                                                      SSDEEP:24:bkUTrFZPyG5goglchY4kb2j6lUZjrveTb5ss2obdPdkbtB:bkUTrfyGUYY4kbYwe45subNdw
                                                      MD5:99721F4AAE2AB7A5FD69A3D2E727E987
                                                      SHA1:B3F7E7D7CE324D0019E1518F80C11E3D60A572C8
                                                      SHA-256:C442DAF3C9CB6C7A541DE7974E58D282C4A38157DFEE9EF87804F0DB4FA8AAFD
                                                      SHA-512:DCCA05DE1E9D4AE40CC9DAD6FCBAC5E427155909586BF781C72150A33F2EA5407090D1CD2108F4959169E9279CF53886086DE8079A31A83BBA4AC1FB678F53D8
                                                      Malicious:false
                                                      Preview:WANACRY!....{....5..............wy....Wi<.....v4".v...X...HT.SK...,.-..R.T.9....u2.(..~.....;....v...^...;...'.b.8.G|....W....iF.1.0...-..vc......C......{w...R..."&.{.%..?.s&...I..z.........8..!;G=..9xz.4..#...O...zH..>D....L...T.NU...#m5.`.r.P"....._...................x2.A^Z....w..5u.~..V.t..f...WOA*.Y.o#..T.....E...............w.!+d.b.....>]F......L...tM...'.-w...f.!`5.n..^..?U....K..7A....lY....[ZS.P..9...........}a.......4^...U.Ua.q.I.@."8.4.!...= ...s-c04)...d......9....I'.........f3.(jX.M...>.kz.If.k....+...y...}DObR.....V...z0k..`iqq.}..Ur...K.R........h..."m+.3..I.X.v.....I.....8.O...>.z.>.D4:..8..1....("..i...l...*....t.mp.............js..gKk.4 ....C.......E....T....d....w..n.P{.D....{y.9..0@B4./....P.......Hp.R.X~.F..3.1..........&(kv%...y...y...U...<..h..+........a.....N....W..-.a..dE...(/X.....e.....=.H.`.S....q.3._,....Or_t.T3... ..-....Q.Pj.#@...^r7v.*.....y...^...z.....{..)..g...5....=.*..>...M.....S....[..7..!..
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.845805357534609
                                                      Encrypted:false
                                                      SSDEEP:24:bkUTrFZPyG5goglchY4kb2j6lUZjrveTb5ss2obdPdkbtB:bkUTrfyGUYY4kbYwe45subNdw
                                                      MD5:99721F4AAE2AB7A5FD69A3D2E727E987
                                                      SHA1:B3F7E7D7CE324D0019E1518F80C11E3D60A572C8
                                                      SHA-256:C442DAF3C9CB6C7A541DE7974E58D282C4A38157DFEE9EF87804F0DB4FA8AAFD
                                                      SHA-512:DCCA05DE1E9D4AE40CC9DAD6FCBAC5E427155909586BF781C72150A33F2EA5407090D1CD2108F4959169E9279CF53886086DE8079A31A83BBA4AC1FB678F53D8
                                                      Malicious:false
                                                      Preview:WANACRY!....{....5..............wy....Wi<.....v4".v...X...HT.SK...,.-..R.T.9....u2.(..~.....;....v...^...;...'.b.8.G|....W....iF.1.0...-..vc......C......{w...R..."&.{.%..?.s&...I..z.........8..!;G=..9xz.4..#...O...zH..>D....L...T.NU...#m5.`.r.P"....._...................x2.A^Z....w..5u.~..V.t..f...WOA*.Y.o#..T.....E...............w.!+d.b.....>]F......L...tM...'.-w...f.!`5.n..^..?U....K..7A....lY....[ZS.P..9...........}a.......4^...U.Ua.q.I.@."8.4.!...= ...s-c04)...d......9....I'.........f3.(jX.M...>.kz.If.k....+...y...}DObR.....V...z0k..`iqq.}..Ur...K.R........h..."m+.3..I.X.v.....I.....8.O...>.z.>.D4:..8..1....("..i...l...*....t.mp.............js..gKk.4 ....C.......E....T....d....w..n.P{.D....{y.9..0@B4./....P.......Hp.R.X~.F..3.1..........&(kv%...y...y...U...<..h..+........a.....N....W..-.a..dE...(/X.....e.....=.H.`.S....q.3._,....Or_t.T3... ..-....Q.Pj.#@...^r7v.*.....y...^...z.....{..)..g...5....=.*..>...M.....S....[..7..!..
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:OpenPGP Public Key
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.8148078581091145
                                                      Encrypted:false
                                                      SSDEEP:24:7iP00xcG2l0FyeNTv734QKr9U27Tua1D7b:7m00xw2FxNTTojUEPd7b
                                                      MD5:D162F1229732AD1E0755B88211BAC96B
                                                      SHA1:3590D453BC5E933E23F65F61045A098D06A1FAF1
                                                      SHA-256:9F2820C4D9B97EC64B973B01B69D319D0412D3BAE14F4FC8A308EB05C264AF1A
                                                      SHA-512:7A2C9D5CF15D635E52DFB2EF37F3B6AF3F80C24FD574B42464DC268DA49AFCD419A18E07484C282A300F5783CC876B937D18168E28230E2749E4FFF9422DE176
                                                      Malicious:false
                                                      Preview:.. .......Y.....I`Q0..(.E..)C..R.Q...I.Kwr...V.V..~....].!6.....j.gQd..g.Y.......:......u;.E.O.....svn.....Z.......&.s...t:.D.`p..3.S..G.......PpZ..7c.'.&...9{...j.-z.<.H3..z.5{....v...@..U.....#.IX...4......9.#}.,(."E..t.^.*E7.R.r..3s..f.kH-.].a&.s.]...xV!..i.}.....+W.yd3......r..1..>B....\.).}...\h.. .:.......[k..W#.D....1...`E.....V2...TV.!b$.?...`...*RYv`.].........8.......-.....".I...l....]z*.*....u2.]......."....gR....C.....y.@.a.Z.........*4.R.?Cz.\.2../J......R).io..+~SRyP....u..T...[8.Aa{i.M...6......Z.M.......f.} .J.0G.i..gX~....7......rwt>..$..z..K7..,...O..bF&.j.8./-V.....(8.....;.R....hZ.C..3..s..O.>....6...|....n....E...G.W..L ...7a".k....^..T............Ee..<F...1...&< N....pxx..It.b.......?8....)t."..0..6.......#."|.*...m?.|W.&....J.4.....^.9a.y.F......c[)...g..H...<.{.&......'.._..Q...J. .....5...s.B\.b..@.5..6.E:.B...<{.'.%...O.l........GJ.V.U....{..9.=..>Oh_c..........X...(..5..J.....G...gn.B..*f..Pb.\.Y.z@z....$
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.842576124153883
                                                      Encrypted:false
                                                      SSDEEP:24:bkVfASbKmHJYQu8PsfG5UKzNB10OQvAwakOn7qpQ2KNQ3bn7CTA7S6cYZtiSYv:bkV3bRi80y1PJXqC2KUb7CTAe1YZw
                                                      MD5:4CEB754A0A6455E1D498CC3F3A3DC89E
                                                      SHA1:C0F82DBCE9B3594FBCFAA55795E640A6EFD0F689
                                                      SHA-256:D162BC8F9DECCA4C7B5D0D5F16DD89251581A1348BCD4EF2D146D0FCFC7C66B8
                                                      SHA-512:B1158CEA237B3404328196E1E77EB1573E5A639E1CD0B984C5B7C3A5E00277A0A8B68BD6D8E1D527F6AD27C1F6B522CCE901B4AB59B478783B681DA80E9F9160
                                                      Malicious:false
                                                      Preview:WANACRY!......PA<.5...../:C.......*....3..JT.)...J..Z..!S)..Vw..`~..?..A;....U......Z...{."k.Q6....!.r.sZ...2....7+k.9.6&.l..(].g[.l.I..0.`...!...3.'..u...`.............e...qv..Ae.m..x.YN........JL......$O;Np....}4.L.J.....P..U..J[..a..:._'....t...E...&:..Mw.............(H......?..u...T..........0..lc.u...A...l.!T...a0.........S.j..6\...)"..:M.L\D...,a...3.n9E...L...UE."m..uVJo..".v.%h..W...'F..0.....\X..!.y..8.X.L..bR....AD.c........17.d...2..:p.2..;.w..R.Mg.....q.._.F6.....-.....*T.]Ch..%....wC.>6.g..6..Mn..3|X..1?..I............2.#<=j.b.2m...`..{..PRm%..V/.Fl...f.!..r..M..R.S...Lk.SDX.......(7.*.@...JY|.o.>.G.X2S.F..$:..I.....\.`x...ss..%%C".Ny6<?.d%2......D2...4..p|.6b|.....k...IDm..V.L....[.qr{.L%A.4.w...)O@...I.T..LM.&p......7=....Q.&.0...#...a.4......JaHI../....;.n.\....]-.G.U...u......m...]..J.).;.b...M.b..Q..C..~K?".j.^.rEK....>.z.+..|..OGE.A......[.n..p......#W.......X.=.] ....).2.....p....x...../.....a=&.....(Y.p..j+..eG{!B.....
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.842576124153883
                                                      Encrypted:false
                                                      SSDEEP:24:bkVfASbKmHJYQu8PsfG5UKzNB10OQvAwakOn7qpQ2KNQ3bn7CTA7S6cYZtiSYv:bkV3bRi80y1PJXqC2KUb7CTAe1YZw
                                                      MD5:4CEB754A0A6455E1D498CC3F3A3DC89E
                                                      SHA1:C0F82DBCE9B3594FBCFAA55795E640A6EFD0F689
                                                      SHA-256:D162BC8F9DECCA4C7B5D0D5F16DD89251581A1348BCD4EF2D146D0FCFC7C66B8
                                                      SHA-512:B1158CEA237B3404328196E1E77EB1573E5A639E1CD0B984C5B7C3A5E00277A0A8B68BD6D8E1D527F6AD27C1F6B522CCE901B4AB59B478783B681DA80E9F9160
                                                      Malicious:false
                                                      Preview:WANACRY!......PA<.5...../:C.......*....3..JT.)...J..Z..!S)..Vw..`~..?..A;....U......Z...{."k.Q6....!.r.sZ...2....7+k.9.6&.l..(].g[.l.I..0.`...!...3.'..u...`.............e...qv..Ae.m..x.YN........JL......$O;Np....}4.L.J.....P..U..J[..a..:._'....t...E...&:..Mw.............(H......?..u...T..........0..lc.u...A...l.!T...a0.........S.j..6\...)"..:M.L\D...,a...3.n9E...L...UE."m..uVJo..".v.%h..W...'F..0.....\X..!.y..8.X.L..bR....AD.c........17.d...2..:p.2..;.w..R.Mg.....q.._.F6.....-.....*T.]Ch..%....wC.>6.g..6..Mn..3|X..1?..I............2.#<=j.b.2m...`..{..PRm%..V/.Fl...f.!..r..M..R.S...Lk.SDX.......(7.*.@...JY|.o.>.G.X2S.F..$:..I.....\.`x...ss..%%C".Ny6<?.d%2......D2...4..p|.6b|.....k...IDm..V.L....[.qr{.L%A.4.w...)O@...I.T..LM.&p......7=....Q.&.0...#...a.4......JaHI../....;.n.\....]-.G.U...u......m...]..J.).;.b...M.b..Q..C..~K?".j.^.rEK....>.z.+..|..OGE.A......[.n..p......#W.......X.=.] ....).2.....p....x...../.....a=&.....(Y.p..j+..eG{!B.....
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.820552761983576
                                                      Encrypted:false
                                                      SSDEEP:24:/v8+SspC3bAulADIYWRWu36tCN6Pr+wMAK1lFQB4:/EQp9uyCEuK1Pr+wMA8B
                                                      MD5:30A5B9ECF381643007C35A2FB847454D
                                                      SHA1:38FB1108541F4978B6FD629BF2F331186B4A9F3A
                                                      SHA-256:E51608C34D139C62EAAFE79A6CABF5DAA0EFAE3DB0A38C8D074F66DF9AB37191
                                                      SHA-512:F6F12072763C453789947DB7DD6770DF38EAB3AA71AF9EA785B220FCB32942E48DF4296B93E38A3BCDD378AB42337521359497E2EE8015ECA54B63C1C2D2881C
                                                      Malicious:false
                                                      Preview:........jC*[.....X ...\K....U.Tx.>.g..... .sHN.k....C..xv.^.'b..B...%...!......Q....G.d.......e.....'.5..O.,... F......Z7m`.-.Z-X.$..Q`q&..y..}..y.r........HR...i........g.M.0..r.v9].F..9.L..h~.f...R._...G...X..Rb..A;S.N)p4..w.`.H .:1...X../}..,....E..a.6.p~..Hiq...q.D........aI.......Bevx6..>Q.)..NA..I.}.#:..d.E.*...s..H.U.i.....s.J..q\_.>..$KT...9..vQ.Zz%X.pU...uq9....A...lb...e<....~..-...a.._6W..%..z...S.R7...K.Z.m.#Br.r.#|...Q...\../0#...B..n....[..M...N......)p.$.].6".Z<.{y.......[.7.1..->H...P..k.N..@.8.o.@Oe..r+ogW...W.._..T.......`...t......J.Q..e..;{..V.Lx.......?.S..}>....v/..Ff.s...(.:.z........r.V.....kpB......99_.s...G....h7.q.i?i.l.I#..M....y9i.m|.>L..._.b.t..p....R.q.....qR..}.....$J..7.jm?.|.G..u.9...]IHw.n(.;..h.....a-7.gk..w.A..x,.?).8..%.e......~......2..T.../(2..&3K...!...JX...Z...L...biS... .s..)..0u.s.?...,..Z...S8.,$...y.Bb.P>......snd..<.ls..Nh.zL...f..z..m|Z..F..U)...Jj..{.*p....g.XY...+...C.f^...E...Ob...Or....
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.856324879399911
                                                      Encrypted:false
                                                      SSDEEP:24:bkRtAWVwHAnZr7i4s0pMjTyZmkc/sJ8PDwEsuhwRollBaOXC:bkRm0HpwKpBJ8L5n60MOS
                                                      MD5:A0CBD72AA35E3F541BBABD2A94A359BD
                                                      SHA1:EA73F1977F1EEDFA15334F237DC6354022B0B3BA
                                                      SHA-256:E86E051E6DB96B816C709EE3464984EED782A380F6993B9621FE829A530AB9B2
                                                      SHA-512:6EA62E558EA76B30E54B5DD2E985799BECA13BABBBDDA1EF5BA5BAB6292011116DF4102939997604099B4559D027E866598015C6506510D7DC063961C6344F1D
                                                      Malicious:false
                                                      Preview:WANACRY!....8...._.."Z..._....3.S../.6..+&Bb...J..R..IT./U....,*.fza....Y..Wa..,..".+...].....^q..y......T.....`......;...|........xF&.ZQt5....w.D..sB......N.C..x.f..}..r....o..9......Tc?.{ 3..A.......l.gx.>e"."....5..O........-..A|.l.0....2....<.........................#...$....X.....a..v...Dj.5..kjQT.W..0...A*....Q...>s...t.I4..P.K..Nh!...C.Q..,M...I.....j......Se.....K.B...m...[Le;...v..D...v l..:.Q..:6....4p89.q..2........BKL.a.4(.../.8:..5$...x+...?.[ib.......Y.....d.4.N.s=..[*N.....0.....F..|..f..>Ft$.S...zT.............3p9............~..H.q.s......wg@....'|,U.S..i..+.>e....=.......Y..../...._..\...1.U...^.H({.Y.....X..}j1..{ ..O.........&&..C...8.Ex..Tt.09.7.vx^ke.+......WG....x~.g....` .ne6.9.ob...BvO..3.7..Q.8.L..3wA[...?:U...e....3u.e..`....;9B..{...|.[........~H...3K....3*.@...g}.....4.3mt...5c....-.|...P..(.(F.....K.\p..p..E........K&.....U$v.%...#....a....*.9.3Q.A...F.........#.kp].7 D.F7.s.0.<......{.+-..t........V..h
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.856324879399911
                                                      Encrypted:false
                                                      SSDEEP:24:bkRtAWVwHAnZr7i4s0pMjTyZmkc/sJ8PDwEsuhwRollBaOXC:bkRm0HpwKpBJ8L5n60MOS
                                                      MD5:A0CBD72AA35E3F541BBABD2A94A359BD
                                                      SHA1:EA73F1977F1EEDFA15334F237DC6354022B0B3BA
                                                      SHA-256:E86E051E6DB96B816C709EE3464984EED782A380F6993B9621FE829A530AB9B2
                                                      SHA-512:6EA62E558EA76B30E54B5DD2E985799BECA13BABBBDDA1EF5BA5BAB6292011116DF4102939997604099B4559D027E866598015C6506510D7DC063961C6344F1D
                                                      Malicious:false
                                                      Preview:WANACRY!....8...._.."Z..._....3.S../.6..+&Bb...J..R..IT./U....,*.fza....Y..Wa..,..".+...].....^q..y......T.....`......;...|........xF&.ZQt5....w.D..sB......N.C..x.f..}..r....o..9......Tc?.{ 3..A.......l.gx.>e"."....5..O........-..A|.l.0....2....<.........................#...$....X.....a..v...Dj.5..kjQT.W..0...A*....Q...>s...t.I4..P.K..Nh!...C.Q..,M...I.....j......Se.....K.B...m...[Le;...v..D...v l..:.Q..:6....4p89.q..2........BKL.a.4(.../.8:..5$...x+...?.[ib.......Y.....d.4.N.s=..[*N.....0.....F..|..f..>Ft$.S...zT.............3p9............~..H.q.s......wg@....'|,U.S..i..+.>e....=.......Y..../...._..\...1.U...^.H({.Y.....X..}j1..{ ..O.........&&..C...8.Ex..Tt.09.7.vx^ke.+......WG....x~.g....` .ne6.9.ob...BvO..3.7..Q.8.L..3wA[...?:U...e....3u.e..`....;9B..{...|.[........~H...3K....3*.@...g}.....4.3mt...5c....-.|...P..(.(F.....K.\p..p..E........K&.....U$v.%...#....a....*.9.3Q.A...F.........#.kp].7 D.F7.s.0.<......{.+-..t........V..h
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.806088560946787
                                                      Encrypted:false
                                                      SSDEEP:24:qi7EPEDRLeZPAcHmWW2gMfuPXq424EkCOLZun:icYZo8EgfuPXdBYn
                                                      MD5:E8835B5D8BDE058DC20C2D19886CC3D7
                                                      SHA1:F3A8A62C8DAE9382CABD42F3C94593BBDE04155B
                                                      SHA-256:F28816A9FCF5236909F775ABBCA8CC33621BFEC8C1A3FB71E06C71F3F43DC1E4
                                                      SHA-512:7964333E91FA6A8349E77F472A65320CFBC946EFF9FE47A692E0A0BDC041A5576812624D887C8732FEB0FB2267BFB59DB41335E29121402E430EED7D778E3A80
                                                      Malicious:false
                                                      Preview:A..,.?7l.. EBy.....uL.J......z.B.f..f.]...=p...]...FY......U......?. 3.P...).>Q"h.FQ.!.3..].s.3E.-.`<.4...w.@...._.\.\.{...<.......].(..\.In.-G...%..QR..1.2.X..(F..,......GO*../.Y....<....#....$FN.?9|.X..sa..../uv......C#..&.1...[..c;....c.E.e.W.....h=.......@....d.#!a...:.ql.H..}.c.........y+Xh....c. s.4......X..d.K....N.C.e.J~m.....!...a"PJr......{.-a$.w.....>RAF.6..\r...N#......Z..j...8.@a.@t..r..}.....+..5....X^.l.^F.:mfu..@`..1D.(.-:@LU..m..........|m...~.)...D.1..a.I...r.,C..g<.c@4.2..*..5"_.v.@:@...'>.....Z..G!Q.0....c.z.7...V.6..A$9...7`...v.j..$1I?.=.......,F.C....S.yX..W..m..z.G5.3...4;...N...:....!....@.k...[T.+T...8k}.4......jU...l).DM....F...J..Nk.<-..Z...O<.&...b.5.X.V5......!....'..D.I`;<..I..U.%.......).<..56.O..K\......i\g'..\....Un...W.....w*.O.^T.D.]....FI,....|6l..Z.F.Zb..%....D4llc.".3..`.;...-..K...../...@r.K......64..B.kd...YO...7p.1.8....@6..5`Q...._..$..S..;..?,U4....y.{v.V..(.C..^.4.g...r.....h.]......{{...<8dw.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.8557992512788335
                                                      Encrypted:false
                                                      SSDEEP:24:bk89bPc9PgOZr8RQO7vnZrnA+00VWJLcIS1hoYyzvFeG6uvWl08LX:bk8BEKo8PvnZ7JbIdSoYKQ7lB
                                                      MD5:99B2FBCF8ED08E54A40694F01B861E15
                                                      SHA1:65202786D9AFB5202227B01A426B89D826EC6908
                                                      SHA-256:5376F21A3F955ABE275742BF19FC6622C7ACEAA9A7AC312C90CA3E9A7C2E268B
                                                      SHA-512:3D171E13CB574C3A7E7C2881181244736BE5BB76BB2A8BCA148B2D53AC4F17D6220A32AD3298208E35BCC053B65DCF5108E44F302DEA85AD77F85922670A204D
                                                      Malicious:false
                                                      Preview:WANACRY!..........0.......CS....mw.,.]i.....e.@..[.}...y^.....|..m..#.".....{/K`...h.....%...r..$.......81."....X..!...[e..>.>m`..V;.b\..s./x.X...7.s....Aj...../.hbw..<.op.N$.Fz.y&>G...u.Zb..Kw\..~.....(a.%...uvW^.....XP=..{.....D.Z.\[u_.3.C...`..>.................b......y.A...u..Y.oC.l..T...\G......x.Q=.b6.l..7v....w.........l...,1..<|.M+.E....#...il..Nn+.........A.u.n.Y.....-..[I.;V.B.x.D.[:...9..aTq-A..o.7...*.s......m4...x..j.~x..,~r0..|.V.d.y.m..._.........[...c.:..@.7D.....k.d...y./..'.....:.....i...=(....$QWQ5}.).Z.....]....:;uS.Pr?h.=..y/....#..ezZx$............i.\.@4...R..n@~..e."./D5...5..s..ij\Uh..W...f.x...zh..Q.l.4....I.....p.*.C.=*.(.n2...S.}s"?R.$...a.l/.4pv.V+....ifF.y.Mms..0.D..>.j.R.8z.q5....F.4G...]W...mMV.I]..=..?(...Yf...t.7.o.........W.B.r..&.fn0..~C.v.s.x.....B...?rB....h..V..J.;.K...H..7...@S...4d...z...#.~../..s.5(.l....XV.t..>*.O....U.5{/......w6[IE.L.8y]..*q6...E]..I...`...E.(..A.n..p.<3.=E.f..2.m.z.Nq
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.8557992512788335
                                                      Encrypted:false
                                                      SSDEEP:24:bk89bPc9PgOZr8RQO7vnZrnA+00VWJLcIS1hoYyzvFeG6uvWl08LX:bk8BEKo8PvnZ7JbIdSoYKQ7lB
                                                      MD5:99B2FBCF8ED08E54A40694F01B861E15
                                                      SHA1:65202786D9AFB5202227B01A426B89D826EC6908
                                                      SHA-256:5376F21A3F955ABE275742BF19FC6622C7ACEAA9A7AC312C90CA3E9A7C2E268B
                                                      SHA-512:3D171E13CB574C3A7E7C2881181244736BE5BB76BB2A8BCA148B2D53AC4F17D6220A32AD3298208E35BCC053B65DCF5108E44F302DEA85AD77F85922670A204D
                                                      Malicious:false
                                                      Preview:WANACRY!..........0.......CS....mw.,.]i.....e.@..[.}...y^.....|..m..#.".....{/K`...h.....%...r..$.......81."....X..!...[e..>.>m`..V;.b\..s./x.X...7.s....Aj...../.hbw..<.op.N$.Fz.y&>G...u.Zb..Kw\..~.....(a.%...uvW^.....XP=..{.....D.Z.\[u_.3.C...`..>.................b......y.A...u..Y.oC.l..T...\G......x.Q=.b6.l..7v....w.........l...,1..<|.M+.E....#...il..Nn+.........A.u.n.Y.....-..[I.;V.B.x.D.[:...9..aTq-A..o.7...*.s......m4...x..j.~x..,~r0..|.V.d.y.m..._.........[...c.:..@.7D.....k.d...y./..'.....:.....i...=(....$QWQ5}.).Z.....]....:;uS.Pr?h.=..y/....#..ezZx$............i.\.@4...R..n@~..e."./D5...5..s..ij\Uh..W...f.x...zh..Q.l.4....I.....p.*.C.=*.(.n2...S.}s"?R.$...a.l/.4pv.V+....ifF.y.Mms..0.D..>.j.R.8z.q5....F.4G...]W...mMV.I]..=..?(...Yf...t.7.o.........W.B.r..&.fn0..~C.v.s.x.....B...?rB....h..V..J.;.K...H..7...@S...4d...z...#.~../..s.5(.l....XV.t..>*.O....U.5{/......w6[IE.L.8y]..*q6...E]..I...`...E.(..A.n..p.<3.=E.f..2.m.z.Nq
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:ASCII text, with CRLF line terminators
                                                      Category:dropped
                                                      Size (bytes):933
                                                      Entropy (8bit):4.710902136409594
                                                      Encrypted:false
                                                      SSDEEP:24:ptrPzDVR5Gi3OzGm0EigS1xbnS4RQhbrW8PNAi0eEprY+Ai75wRZcet:DZD36W3ChvWmMo+S
                                                      MD5:7E6B6DA7C61FCB66F3F30166871DEF5B
                                                      SHA1:00F699CF9BBC0308F6E101283ECA15A7C566D4F9
                                                      SHA-256:4A25D98C121BB3BD5B54E0B6A5348F7B09966BFFEEC30776E5A731813F05D49E
                                                      SHA-512:E5A56137F325904E0C7DE1D0DF38745F733652214F0CDB6EF173FA0743A334F95BED274DF79469E270C9208E6BDC2E6251EF0CDD81AF20FA1897929663E2C7D3
                                                      Malicious:false
                                                      Preview:Q: What's wrong with my files?....A: Ooops, your important files are encrypted. It means you will not be able to access them anymore until they are decrypted... If you follow our instructions, we guarantee that you can decrypt all your files quickly and safely!.. Let's start decrypting!....Q: What do I do?....A: First, you need to pay service fees for the decryption... Please send $300 worth of bitcoin to this bitcoin address: 13AM4VW2dhxYgXeQepoHkHSQuy6NgaEb94.... Next, please find an application file named "@WanaDecryptor@.exe". It is the decrypt software... Run and follow the instructions! (You may need to disable your antivirus for a while.).. ..Q: How can I trust?....A: Don't worry about decryption... We will decrypt your files surely because nobody will trust us if we cheat users... ....* If you need our assistance, send a message by clicking <Contact Us> on the decryptor window....
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Archive, ctime=Thu Jul 25 21:01:45 2024, mtime=Thu Jul 25 21:01:45 2024, atime=Fri May 12 05:22:56 2017, length=245760, window=hide
                                                      Category:dropped
                                                      Size (bytes):575
                                                      Entropy (8bit):5.140446565826782
                                                      Encrypted:false
                                                      SSDEEP:6:4xtQl3y03CpzeVs+bTNAUHUtxXCzaMmM7/gtrUod6tMljAlpdmqLEoJ4D6Vod6Nd:8iypzYNbd0thHZOgZUobjArozhmV
                                                      MD5:CCD2610ADD4080C4DCC35A11217DA6A6
                                                      SHA1:001ABA92D58B546C8BD54E0BC4103661F68CF92A
                                                      SHA-256:0E272CF58CC66E7B0CC4F42094232A46B6EC11AE5ED695BA4156A1A28DA41E6D
                                                      SHA-512:36DC5CE3027E8A77639783E31AC69C9FA61C4761FBEB9A819C1EB49F4A32BF2001C0441FB28D35C4EC9DD1B713576E7894DE8FD13BF14CE62A436F9619093DEC
                                                      Malicious:false
                                                      Preview:L..................F.... ....b{=.....b{=.....`.1.................................P.O. .:i.....+00.:...:..,.LB.)...A&...&........DDj....%.=....(..=......t.2......J.2 .@WANAD~1.EXE..X.......X7..X7...............................@.W.a.n.a.D.e.c.r.y.p.t.o.r.@...e.x.e.......X...............-.......W.............,p.....C:\Users\user\Desktop\@WanaDecryptor@.exe......\.@.W.a.n.a.D.e.c.r.y.p.t.o.r.@...e.x.e.`.......X.......216041...........hT..CrF.f4... .u.E._c...,...E...hT..CrF.f4... .u.E._c...,...E..E.......9...1SPS..mD..pH.H@..=x.....h....H.....K...YM...?................
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.8385689700719645
                                                      Encrypted:false
                                                      SSDEEP:24:rqoihyoDdK7RnHgutx+ks/pbWCpQaSs6tFmWwH+PBpQ1xZsYx:enhyo6gE6BvEO6BK/sYx
                                                      MD5:4CDC180A8FB391F4EBF1220881B84195
                                                      SHA1:4CC2D45F2CD07FC5DDE5490D38D2F5C9502CD62B
                                                      SHA-256:2A0C53D7744479E32A18CB878DA0A02F768D19FC9C43E5A987B09C613C085303
                                                      SHA-512:5253B81D4CAD79F99B2B5367648D097E84AD62F4C5C71EA203E53D35DACADDB443C2D88DA7D3E1264706B20EAEC564CA893239069D359405D69A4C36E5A12251
                                                      Malicious:false
                                                      Preview:I<.l..1....q..w....p....5......Sc....d..(X....e..H.x..J.=....48\...`.=.....<...(..{..%.nrx...Q}&i.,...C..QCv....h.`....d}...........~...m..%.4.....u.n..........9.(.,...z..O3.A=.[...l..D.......2.|.......B...E&[(K....~..-C H,.....4.T_Q......Su.p...;O........*l..\..igB$.2.$.m_.....sz\.C.wj..7.Y...."V.M....doVv{.._..Nau=.;iL.....@.'p.&.......#!....L.;Z..K.........H..`4...>..[E.66...f.#......N...7.O..;..A..._......G./,...x^.8...+.F..a....n.....=...1.b.>.;.....1-.F.W..h}.+.d.#..8...?S).Z.o9.T.Gat+..:9.v.....y"?..i..w...}.f...H.Pnf9..s.7.w,:.I...a..2J..P...h.w.X,L.>HK..=..-[..|.../.O..H.d...M.XR... ,..2W.......Lc.@..C._U...f......m...g.....l....{).......+..u..?7M...XP.t6.R....!...>....Jw...Z...t..0....d.E48.<.i.C..1...o}..G.......W.U.&......4..1.>....),W.}...N..;...h. ..n.o...%..X.F...SB..}....-..k>....Iw#......Zl=...../pM...>...u..i....I.=./....b..;HY..F...:.......v".q....MW.Cm]...M)X.U.....~N/!../.i.~!y....R....y.:.=`o....F.^^
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.856947645583206
                                                      Encrypted:false
                                                      SSDEEP:24:bkcUCudo474uTyYqwVZ8+U5P1a4Hu0ElEttnJ2bMK1+zmxMs5UH2Od8:bkc07WRwn8S4O0lttsMK1qmxcH98
                                                      MD5:89CF7633B7143978F920389303D968CC
                                                      SHA1:D39C2F27FADE74E05DF13D66B990720ADC087D80
                                                      SHA-256:BEFA16B2B0216B1AE70FC60C5452F360346877DB0616AE61A513E052B3B3BC35
                                                      SHA-512:08EA47A9994AD8E64FB2068B6FFF465225943760A10FFB7C440816149129D5F3669B1C98CD2CAC099440D474A5E2E5C901BEC52D58582168EA02E70E91D6CD9F
                                                      Malicious:false
                                                      Preview:WANACRY!......SG.X4.e.s|..:n.....<.!....R....+...._..-...(.1m.@1..,...[..x.i.... ..J.y..3.(y...).&...%9...r..`AS..CN...Kf.vq.8.i..&V..B+..)...j..5.jPC-/...|C).P/.....6.&....."b..t..g"..=p.Y^.g.-...B....`...y.b.+Bm.1..E}.>....c#......^.R...t..O.3..@.......................~(...M..R.#bR._...j..H..-..........^..L.....Y.Q....Q....W(......j.....u...2.,....hS..0.:0..:....uZ..M..6......6.).j..KMh.4..l.....zub.X....Ww.e5((..%...No[..t.s..u..........C.......C.>.rpn.9..s.0..(*P.<.P.G...9.......G...?.]/mM.5.i.AAH.x5......N...!...`.uh..m;...[.....u.....H^..p.O....u.v9..^yz....,`.os.}...%nmL....b.BU.q.b..A.q..*A....Y....D....e.......JxG...<...?6.......P.....t.}...b.I=[...:n..)..O.dd....u....<..3..x.D...nO..o..7..5#...*.}........y...i..@.......-.W.....]8..K..*..@.c.D...}.....7..J.A..=.U.P..-...\.y.G..t....J...k.....J.A.7.C......N....<G.V.. Ip....D...Eq.cb...(N........98q...}n......\@..=...j..U..tVZ.Z.8No.?...f'...T}....k .s..D.....0..r{A..X...#....
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.856947645583206
                                                      Encrypted:false
                                                      SSDEEP:24:bkcUCudo474uTyYqwVZ8+U5P1a4Hu0ElEttnJ2bMK1+zmxMs5UH2Od8:bkc07WRwn8S4O0lttsMK1qmxcH98
                                                      MD5:89CF7633B7143978F920389303D968CC
                                                      SHA1:D39C2F27FADE74E05DF13D66B990720ADC087D80
                                                      SHA-256:BEFA16B2B0216B1AE70FC60C5452F360346877DB0616AE61A513E052B3B3BC35
                                                      SHA-512:08EA47A9994AD8E64FB2068B6FFF465225943760A10FFB7C440816149129D5F3669B1C98CD2CAC099440D474A5E2E5C901BEC52D58582168EA02E70E91D6CD9F
                                                      Malicious:false
                                                      Preview:WANACRY!......SG.X4.e.s|..:n.....<.!....R....+...._..-...(.1m.@1..,...[..x.i.... ..J.y..3.(y...).&...%9...r..`AS..CN...Kf.vq.8.i..&V..B+..)...j..5.jPC-/...|C).P/.....6.&....."b..t..g"..=p.Y^.g.-...B....`...y.b.+Bm.1..E}.>....c#......^.R...t..O.3..@.......................~(...M..R.#bR._...j..H..-..........^..L.....Y.Q....Q....W(......j.....u...2.,....hS..0.:0..:....uZ..M..6......6.).j..KMh.4..l.....zub.X....Ww.e5((..%...No[..t.s..u..........C.......C.>.rpn.9..s.0..(*P.<.P.G...9.......G...?.]/mM.5.i.AAH.x5......N...!...`.uh..m;...[.....u.....H^..p.O....u.v9..^yz....,`.os.}...%nmL....b.BU.q.b..A.q..*A....Y....D....e.......JxG...<...?6.......P.....t.}...b.I=[...:n..)..O.dd....u....<..3..x.D...nO..o..7..5#...*.}........y...i..@.......-.W.....]8..K..*..@.c.D...}.....7..J.A..=.U.P..-...\.y.G..t....J...k.....J.A.7.C......N....<G.V.. Ip....D...Eq.cb...(N........98q...}n......\@..=...j..U..tVZ.Z.8No.?...f'...T}....k .s..D.....0..r{A..X...#....
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.811238166942946
                                                      Encrypted:false
                                                      SSDEEP:24:kP1KVKXgQmoEvVFsw0eDzdKh6aKmqM/S/dZ2Ya9r:kP2KXSXt906dBaKmFDYaV
                                                      MD5:1B5B89110998AA3BF5CAAE226F0B2799
                                                      SHA1:6D0C5574AEFBB1C1B827E935E8BFA6B2F7599C89
                                                      SHA-256:20533664547F65A94FD8938FF97D542E2E4B68150FEA3FA9919F522CB5C03D32
                                                      SHA-512:3B45F0F0D4080FE75B47DFE870F018F2FCAC77B64FC806943033CA23F97A1B73757C9DBBF307053040001DD5C4C881BD822F1EF90C31D13EFC4B7A7629436BA8
                                                      Malicious:false
                                                      Preview:~........7.j..I..u-..t..!Q.('.Zv......$...kZ.......m.o..4...6?...F....e.x.....75u..&]....K.4[.UV.3.}...E......#.;x#O5.....+%t.#v.4Q.b...n.l7.h..3R~.C...........d..t.3.f[{.l.......VqJ.......~q.M)...Q[I.\...v4R.4.q..-...).....*.S...).L...-.UQ..')..Gb..q.L>.........H.|..z`.w....u{p./.3,A.....T..P.....y.C....3]........(..[........b.R..;...fA.p..Q.N}.2..[%.d.......z.......|.bn......_.........,....L...Hfv.....@.-.^....[....J....p.<hLWi......A./a3.h1/.f.2.XQh...&;."......ZO.E.B,.gG..d.".&..Y...Lxn'|....d...ke..4..G.....2.=+A..k&p......<...w~..(`|+.....P..3.....V..i.*K.N^.7bS..V.[.-.bl.;.3.....D1hL..5@=.v... $.7..3t.....?.F./.-{Z....Q=..8f...^y...&Zk6.9..'3..N.m...\.Z..e..VKF.Kf.T0.d..}.7.v;..o...n.. ..vC.*.2.dA.3B..9".i... ...&"..^..w....,c.~f..M...S....).q......}.t)..B...[.Q.3.....3..h..#..&..........A....XS=.!.D..\)(.I.7@.....r"..N.3^.j..d.A...Z.a...........Z%7.4.. k..K.T]`0K...j.6...V._......Y..Y.O.,..u#..Ey...A.j......sEQ.w.S..."
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.846548952285175
                                                      Encrypted:false
                                                      SSDEEP:24:bk6rFSrGc40yKLR/lNmZ4etQFInPryhH9n7gLf7eIoBrC9yrSDc8DCNmIWncIvlh:bk6rFEGcsKplYZ4FIAUj7/ocjw8DCUIo
                                                      MD5:445EE8F84F541AC5928543E7864498AD
                                                      SHA1:4170DE161BB59F9134D8A3476F4BA73674725A5A
                                                      SHA-256:13DAFFF314417D56D041C8354E15F36248FDEA6DB4AD83B5D0448FA20992DFE9
                                                      SHA-512:9315B6B2AEFC0B6053DDCDB7198E610CB954D154CD5FE69C6C78A1C58CA848A41DDAA51AB30E121406FC19E8AB04B6A40FD5E04D23E2DFAA92E92218A8798FB0
                                                      Malicious:false
                                                      Preview:WANACRY!.....^x..q.w7f.....:k.r..^.S.,$...j.L..'.....p...2d.......k6C.e.[5Iq..i_h..c._.Y..5.B.....p.U|.....L"x.p..i'k.{M....j.J.f1.0.l`<.A%B>..cl....`...%N..|.u..$.......R.,....'d.x...Ln?7^....{.5b....&..\..a. ....Mv./..Qx.......yi....e...w.\e.&...C.p....................,..T~..s_Ts.......d...C.w.s.e>.....2..$&.:T...?.J. F.n.^....dU.hx+M$.7BQk7zO"9.HI..i..t.*..0;..v.a.U...I..V.:..!..3...O./jo..t.Qa.V.-.2............09..(.D.X.ad..gT.`..DE.0..H.N.T....*$....-...!.y......F...9.7....J.....T.9R..e.3p...PXhx.E.........vVB.:...--.7......H.6..#.^`ya..O.!.......i..p.9..]....i@..q."....A....'.....|.'W....s.,\..D.e.Uq.S.W.~$a=zj...tXUl............R,J:.^....3.....U.X..g..2p ...|.qt..d......}Iu#.].....H.Q..8C.....{5..O......@<.*....M..AN..E...v.....%f&.?.t8Jp.=..;.".z..n..q....Z..._..62....}bf..M.).=w.b] f.a=...),O.......y.a.....'...@...R.(..Jth.-.B.].p.mZ.X..Rh......L.-..~k..dq....BS.D&....gWV..B.w...X..."......._r.z.......x$.6......&n........1@..S..B
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.846548952285175
                                                      Encrypted:false
                                                      SSDEEP:24:bk6rFSrGc40yKLR/lNmZ4etQFInPryhH9n7gLf7eIoBrC9yrSDc8DCNmIWncIvlh:bk6rFEGcsKplYZ4FIAUj7/ocjw8DCUIo
                                                      MD5:445EE8F84F541AC5928543E7864498AD
                                                      SHA1:4170DE161BB59F9134D8A3476F4BA73674725A5A
                                                      SHA-256:13DAFFF314417D56D041C8354E15F36248FDEA6DB4AD83B5D0448FA20992DFE9
                                                      SHA-512:9315B6B2AEFC0B6053DDCDB7198E610CB954D154CD5FE69C6C78A1C58CA848A41DDAA51AB30E121406FC19E8AB04B6A40FD5E04D23E2DFAA92E92218A8798FB0
                                                      Malicious:false
                                                      Preview:WANACRY!.....^x..q.w7f.....:k.r..^.S.,$...j.L..'.....p...2d.......k6C.e.[5Iq..i_h..c._.Y..5.B.....p.U|.....L"x.p..i'k.{M....j.J.f1.0.l`<.A%B>..cl....`...%N..|.u..$.......R.,....'d.x...Ln?7^....{.5b....&..\..a. ....Mv./..Qx.......yi....e...w.\e.&...C.p....................,..T~..s_Ts.......d...C.w.s.e>.....2..$&.:T...?.J. F.n.^....dU.hx+M$.7BQk7zO"9.HI..i..t.*..0;..v.a.U...I..V.:..!..3...O./jo..t.Qa.V.-.2............09..(.D.X.ad..gT.`..DE.0..H.N.T....*$....-...!.y......F...9.7....J.....T.9R..e.3p...PXhx.E.........vVB.:...--.7......H.6..#.^`ya..O.!.......i..p.9..]....i@..q."....A....'.....|.'W....s.,\..D.e.Uq.S.W.~$a=zj...tXUl............R,J:.^....3.....U.X..g..2p ...|.qt..d......}Iu#.].....H.Q..8C.....{5..O......@<.*....M..AN..E...v.....%f&.?.t8Jp.=..;.".z..n..q....Z..._..62....}bf..M.).=w.b] f.a=...),O.......y.a.....'...@...R.(..Jth.-.B.].p.mZ.X..Rh......L.-..~k..dq....BS.D&....gWV..B.w...X..."......._r.z.......x$.6......&n........1@..S..B
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.804592566999216
                                                      Encrypted:false
                                                      SSDEEP:24:M6cPtT8KvPKHpdZHEIs5bg4gcW12rfMgrK/XDRmmu:IPtDaSRJg4gF2r0dRml
                                                      MD5:330770863C58092450446BE1B52BE8A2
                                                      SHA1:CBD9D676502D7E43BDBA0DCBBE69762ACB758DB4
                                                      SHA-256:38474F183933FD5872262762C5961B3ECE830E4DC88FC09D0CA62ED761C78E71
                                                      SHA-512:061CE603D2FC394C21281789BA97DCD0E5AA7BA172C8D8FA998FC2E2D752617B491728436358DE9B286FAB37B4BE64902CAC247E59B2369E0111F5319CA3E5F5
                                                      Malicious:false
                                                      Preview:. ..}..*.\q.0).o'....../......k.j.........6......%#.E[.....eHR..+....1 .Jf...N.m.^..UT..3.3s5..b..F......]..:5`.}.......BJi0......Z.-w..\.!/^...\T.].....^..@.u..;>..Ut..RY..Z...F.i.m..9.I.>....m..a1.p48u.D>v..]..w...6..L..)Cmx.).....,D#..'............+#..!.......9...!pRo7..^...E....\..d........N.(..AC....g..33..x...~...@`7......_...C....C.M.J(.%..-..W......C."z..{.O...:.r^y..-.[F...Bu..Ar|JhH8..... i.......+.9.....G...Z..Q....I..JMa....-...KZ^....t.{.N.96.6..Y7...`..q_?v....n8.W......t.8/88..CP`)8.k...Q........wpqw.B..].<.e../<(....Y.....H..w.t..{.)....~..%.q.w2D.....h.G.q!.h.m.ye.Pc.F.Y."...1..T..0D..R...`.....g.~..:U...=..q..e......@".x3.A..,T..NE.......v ).l..."y%C.?WwM.l.cM.9......0kM?..Kp|...@'.zJ.'.cP.n.c.....}.._......:d....?.....O....^:... l*W.c..\.fi).eSU...Fe..U..1..+.(..^.a..6.D..k. n..f4.C...Y..%..!....lS|.._y.A.....(...\w.G...=?.:...9:.6.1.....q....?s.`...(..O...}..^.6.7^..\<.h..-.E..5t..=~'.Ak..4.......E#DB..5$W.X-*..
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.861181169698679
                                                      Encrypted:false
                                                      SSDEEP:24:bkPkJH31jJno8k+//MjNNPcXzQQkD/YMNgfrKnpwQrkiZrelEuPMnQ+50SDh2vAs:bkPaFB3sNZcXkQkD/mr2p7rVZrelEu0G
                                                      MD5:B57F393918D2F20963F03CB7C75CB9BE
                                                      SHA1:EFAFF41F04B21A5D000F370D07665640DF8CFD05
                                                      SHA-256:63A2571063735EE4B128707654E63C236A79410F68CD2F9DC9B1D72A9F064F22
                                                      SHA-512:D7A7E902C8CFA8EDE71361F467F344A36437F63A26CFCF1B9E130E04BE81B07F8F89A9F43DDAADD76284DAB125E53FC0807AA7BE94610BB2F8E1472F72217F2F
                                                      Malicious:false
                                                      Preview:WANACRY!.....2.*..<.j..Z....O.>s..H.R9pu....k..3...e....i1qk..\eT.8..f.M.........sPM.@....R......;1.K?MR.Z.-..#...~M......q.r.^......z.D.@.....xA.s......_...R......$B...+f..Kj..=.."..67Y.@.Z...`_J....."....i..v,.s...=b.:..p.<...I...R.......w.w..EF.M.............)>).5O*..|.m/w.n...*f.H.....dZK^.9.o.7(.xn.G...B..g.0.......X_.a.uh?(..U'k..m.xDL..0:.c. M.N}....M..\bc^.]Y..|..w/._+...d..[N.'1.Q.....G...H/|..".....k^...h........*!E....ed...A%.:)i..i...W......B....#...#.b....#.;5Q.}.[.y=....C.4.Q.8....J..m.....PX...7D.9......:8..A.b-.G.M...X...h....F.>.D.]..Q.....}.Ej......W8[..67.].odf...Rd..5Z`..=..W....Fjh^;...J........bu9LT.]...F.4.]3...........0....\.Z...b.u*!..H..)....u:..f..\......3...5.".......p......-.h...u.b.m..H.s..%.7.,..'..S....J.Q. n.s......r.dm.#.{.[...0..i./..n..)rv..9.......l#...OL%t.0..B..C.2 .s.].co.2.>]lhl.......w.......r.#<%.C3.2..p...x...u{^=]..U.1..?.....{....C<.er..5....JS......\.2|....d..A...E..."qb..oz..E..Gt..
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.861181169698679
                                                      Encrypted:false
                                                      SSDEEP:24:bkPkJH31jJno8k+//MjNNPcXzQQkD/YMNgfrKnpwQrkiZrelEuPMnQ+50SDh2vAs:bkPaFB3sNZcXkQkD/mr2p7rVZrelEu0G
                                                      MD5:B57F393918D2F20963F03CB7C75CB9BE
                                                      SHA1:EFAFF41F04B21A5D000F370D07665640DF8CFD05
                                                      SHA-256:63A2571063735EE4B128707654E63C236A79410F68CD2F9DC9B1D72A9F064F22
                                                      SHA-512:D7A7E902C8CFA8EDE71361F467F344A36437F63A26CFCF1B9E130E04BE81B07F8F89A9F43DDAADD76284DAB125E53FC0807AA7BE94610BB2F8E1472F72217F2F
                                                      Malicious:false
                                                      Preview:WANACRY!.....2.*..<.j..Z....O.>s..H.R9pu....k..3...e....i1qk..\eT.8..f.M.........sPM.@....R......;1.K?MR.Z.-..#...~M......q.r.^......z.D.@.....xA.s......_...R......$B...+f..Kj..=.."..67Y.@.Z...`_J....."....i..v,.s...=b.:..p.<...I...R.......w.w..EF.M.............)>).5O*..|.m/w.n...*f.H.....dZK^.9.o.7(.xn.G...B..g.0.......X_.a.uh?(..U'k..m.xDL..0:.c. M.N}....M..\bc^.]Y..|..w/._+...d..[N.'1.Q.....G...H/|..".....k^...h........*!E....ed...A%.:)i..i...W......B....#...#.b....#.;5Q.}.[.y=....C.4.Q.8....J..m.....PX...7D.9......:8..A.b-.G.M...X...h....F.>.D.]..Q.....}.Ej......W8[..67.].odf...Rd..5Z`..=..W....Fjh^;...J........bu9LT.]...F.4.]3...........0....\.Z...b.u*!..H..)....u:..f..\......3...5.".......p......-.h...u.b.m..H.s..%.7.,..'..S....J.Q. n.s......r.dm.#.{.[...0..i./..n..)rv..9.......l#...OL%t.0..B..C.2 .s.].co.2.>]lhl.......w.......r.#<%.C3.2..p...x...u{^=]..U.1..?.....{....C<.er..5....JS......\.2|....d..A...E..."qb..oz..E..Gt..
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.748738507978382
                                                      Encrypted:false
                                                      SSDEEP:24:fxzy+IjN5RaajNDA5Nq32StedhA9VFAzJYwyu7obKavbp:JzEjN3Zog3ftMO962zKaDp
                                                      MD5:099A0790C94FACB3AFB8F9B72B8DE370
                                                      SHA1:B8D9A0E40EC91D8682F94CD48C334FE606CEB8A8
                                                      SHA-256:43DA8AC4F99E38C9470C9EBDD4CF14E03276B36993240538B591A5789CCD0650
                                                      SHA-512:80712F7F5A1392E582C8669DB850063776ECA7D54681185561EC72D2EB4C141A3D3C848C557E776F9D24BF89DF08480A6FCCCA0DE098A265B85B45FB7E00F1D8
                                                      Malicious:false
                                                      Preview:P...y!Ki..x..8E.g1..6....Mn. J..AqO........J....;.&..).'..?.M{......4.}...Z#.e.LhF=.Q...*.1.L.|./}.5.....rl..U.......Wt...?##...;.W...S........]*..s6......W...]....i.=.a.O..}..6o..+.I..'...P.4..[O..8J'.7[S.yt=.U.j..R.>......a...&J/Rqf.7.(.R.R.x(fL....h...w..oTq.q 2rq..1.;...^G._.....8.L...AQ.Y!...t.M.u0...........T..t.+*f.........J....qr........cH.FC..W.l].N<..W.7......]...ZW..t*vM_..q.....a...rr..6..C...^.8..3.vm.s...4h..D.qH.....&..kw2d.c.^-W...I..2f...=a.M46l...'^&.0..+...e...9wF.B.ys.d.(..jz..zB.v.D..4L....&X.q.|_...+|.......(.kx.\.B... .).T&......1..!..;.|.]&H...V.)o...I.4Q..........a...Bq...oJ..q.d....C>...q...0A.+...\.ZR......=..A.v^g..I....|...&1< ...`.'Pg..B....{...A.....+..(k....e......xdj..1..M.....:..^.'n.....{m.VO...;U...r.k..Kx-...F+.e.+L.k...;4r~.sq.g8.~..A..SM..1..q|K....-... ...$.7..A4=K...v9\.0..`......N.(.8z.J$`tH.ea.6.....|Q7........S...0#.n./{...........Jo.G~.8....8:.;GL..H......].^...*...Y..B.<.>.....40..J.y.....{B>..
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.855883407688054
                                                      Encrypted:false
                                                      SSDEEP:24:bkgAa62LxnHhGLs1dhIlhJXVWuOYe/zQWneZiqyu/CMTnugmkMyi8wH6Avn:bkqFHhGLWy1lWu72zQWneZiqyu/CMrUp
                                                      MD5:AF2315408E484EF723E60CB88B498F6A
                                                      SHA1:7A2D25B2454231F3FE6D5B2374320EB1DC2071ED
                                                      SHA-256:757DFF9F4FA7F6642818B2AED0CD968364B095FEDA2EF3289FF151D0FBA9019C
                                                      SHA-512:D7891BEABB37ED30F305AE62E2FABF2C0D8F694A45D8FDF8DF9B04EB8C635C677F70281F83B3EBD9A9D160D8772C1C75CB4430F15F1584409C8708ED5E6E6CF4
                                                      Malicious:false
                                                      Preview:WANACRY!......z. %......l.;......+$.a.........O..Vy+W......$J.U.w.E..H..=. .s]`..*.1Z..4.....g.M.......)."vN...+..X.y.##h...W..G.c.:..P...vp....*@.!.11.3.Z....%.).........w| b.NbL.?2fs#rX............8.....o.H.I?..,.a...#..........e..j6.......].Z....a@...H..............Bqkj.....7B......1.-;.C....'.;.k.\..bZZC..W...2.z....Esu....f......)?....|i....f.v....j..d.9.=o....j...<o..1.....kx.{z..Z3..r$.j.e*.d.lv....m....gK,`.:.-...f".1P.%.Q^...FU...p3....2.mv..../..1V..Z.`~.`.[.c...cN..J.h......{....|..Rr....PO.7D.8..:l..C.4..^.`0=..Y..E-:.......?..#..1+..[R. H1.......ZmEk....6....0.vr.qxC........!_.t.1..p..V..V....Q....#..\.8...........\...A.Y..u........4.uAO.}..x\...P.d.,J.E]..8..U.6V].8D.%.&.[o.~A..U.x@-.7..*.C..$.l....S.@H&..x........m...Z...~.m...H. ..2..> .wEB.....}T.%.2..t.......s.3as.G..YGP.....F%s2X.`.G.=.f>z..?.....Fl.1M$.hf...na...!h..)M.}F...g...`...!.U.;...i.....m.nCk.H...Vd...cQOz.5..bd....>J...6.+...N..0.L.hC.hU........K...S..P.%..
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.855883407688054
                                                      Encrypted:false
                                                      SSDEEP:24:bkgAa62LxnHhGLs1dhIlhJXVWuOYe/zQWneZiqyu/CMTnugmkMyi8wH6Avn:bkqFHhGLWy1lWu72zQWneZiqyu/CMrUp
                                                      MD5:AF2315408E484EF723E60CB88B498F6A
                                                      SHA1:7A2D25B2454231F3FE6D5B2374320EB1DC2071ED
                                                      SHA-256:757DFF9F4FA7F6642818B2AED0CD968364B095FEDA2EF3289FF151D0FBA9019C
                                                      SHA-512:D7891BEABB37ED30F305AE62E2FABF2C0D8F694A45D8FDF8DF9B04EB8C635C677F70281F83B3EBD9A9D160D8772C1C75CB4430F15F1584409C8708ED5E6E6CF4
                                                      Malicious:false
                                                      Preview:WANACRY!......z. %......l.;......+$.a.........O..Vy+W......$J.U.w.E..H..=. .s]`..*.1Z..4.....g.M.......)."vN...+..X.y.##h...W..G.c.:..P...vp....*@.!.11.3.Z....%.).........w| b.NbL.?2fs#rX............8.....o.H.I?..,.a...#..........e..j6.......].Z....a@...H..............Bqkj.....7B......1.-;.C....'.;.k.\..bZZC..W...2.z....Esu....f......)?....|i....f.v....j..d.9.=o....j...<o..1.....kx.{z..Z3..r$.j.e*.d.lv....m....gK,`.:.-...f".1P.%.Q^...FU...p3....2.mv..../..1V..Z.`~.`.[.c...cN..J.h......{....|..Rr....PO.7D.8..:l..C.4..^.`0=..Y..E-:.......?..#..1+..[R. H1.......ZmEk....6....0.vr.qxC........!_.t.1..p..V..V....Q....#..\.8...........\...A.Y..u........4.uAO.}..x\...P.d.,J.E]..8..U.6V].8D.%.&.[o.~A..U.x@-.7..*.C..$.l....S.@H&..x........m...Z...~.m...H. ..2..> .wEB.....}T.%.2..t.......s.3as.G..YGP.....F%s2X.`.G.=.f>z..?.....Fl.1M$.hf...na...!h..)M.}F...g...`...!.U.;...i.....m.nCk.H...Vd...cQOz.5..bd....>J...6.+...N..0.L.hC.hU........K...S..P.%..
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.807785096681283
                                                      Encrypted:false
                                                      SSDEEP:24:1Uo/HCX5bmi6qNksdh2cdPQXjVZkVBCv38uJe4RN2UuR:15CX5v6qNndhRdIXQCP8uJZRQxR
                                                      MD5:2108CE9C08C6F2C8ECA3EE6993E8B602
                                                      SHA1:5A35CAE7667E1BEA5FEFB1D1FFAA9AA6756AE580
                                                      SHA-256:313354023144C1CD6A1330DA5092AA958841446555112BA2B8C37AA346D7B87E
                                                      SHA-512:07601396F4CDF0A179EEE030F4F824F801ED7596B6B5AFCB709A917C61128543020D62B67B67E5BB62587C76F0D6D9599642AE50B5529103CB2B6AE8D712D30F
                                                      Malicious:false
                                                      Preview:.k.r.|.=....z..}...G..o.[.............U.+.H..k..<..r..~P.i..u^...^.....Ziw.t....P..N...O.......;...Cm....P&.JNH..><~!.&..a..=.h(.ai....ot2..Og/..N..........^:....r....b.Q&&~...*.=6.Y>RF...)%@.v5o......t.`G..`....^.u.....#.....{q..I.0.X.n. .2I.-H...\....g.R..9...y..:.5.....s...@_!,....pS.w1......~.7A..i.2t.z..=Q..vt.xH?*+../Zg..p...c}.K..[.Uy..6X\.6.<o.}{7...G.0$.@.......\...[.r[.....2....#.......p...&/@.?..).5.8..........].t-.....fXE...'t18.=...Y...j...'.....*.?..._9..@t...w..~...\7%.4w..o.X..c.....J.....g.......DX.%..qz.QG/r=p$3^....7:.Y...}..R.......X.E..Ol.....d.j......M.;..W..f...6.Q%..g....j.....Y".G.....A8..6.)....4.Ey.8.]........m1.K|.yu...M".:..Ba.N..............4@...[....H8..E].zA..<..>W.Yc6<.......n.t.f\.......m..Di.sa.sC}Pa.X.9(.bX....a.R...)c.H.?.A../.R1...=.Q.....P f`'.(.e..+D.L..&.{..1.".G.....]R......).rM&.&....*.,).7.[c ..H.%.........t Q)....:'v......k'.@...:...B.......7.f..6..H_...D,..K...!.76b....8m.Zn.e....@.P...1m.F.).iGN.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.861197951166291
                                                      Encrypted:false
                                                      SSDEEP:24:bkhrJrq93pX0LXxKs7J6EERwXjQl8ETR/cnBv/VvSeYXNbT/nr/MWbBnOQHhKXu:bkhJrq93pX0LXlsEEReETRq/RSeYRvrL
                                                      MD5:F6D1BB15195F75EDDADFCA940AF47C48
                                                      SHA1:408DF50053B6E7E7BB8743CE41FF9C80F3D75836
                                                      SHA-256:FFF1BF0071FE44597204407DE63B99BC50B27E06432706283D668926FDA63CA1
                                                      SHA-512:274B293D4BA587EE80CE08126DBD0D3864663A58F8680C28A6B8C3CE3F548E3AEA4BBDAD12BB0D3B6EF0161C6C0B6B0DF325D3C19C0E14280C2AF901C9B817F8
                                                      Malicious:false
                                                      Preview:WANACRY!........5.!..,R...}.Z....`.....r(...d...@7..>*.V#40..T..E.aU3..Bp.2.OxB.z9...w..v4.....OM.........m&..ov..u7.m...!.......N.B...m.{b..)..Q..rv._ek......P......!.X...-.EC..i...m?..w".!.....Ll9..........Z>..6'.]@........<.}.....=.<..........q_p................9......2n.jDj..c.4I.J.r.u...HNJ..f...g._..y..U..J. .Q+)x=...@....4..A\?dMp..-c.f....0.../.r..t..w.a.........\.K1.WAX/....XQ7k..BO.U.:.........$.|..L.....0(.9.J...=N..m..|..R.h`.+..6.l...F.(.....a.Ut!h..*..}.`..9,.N".o..N..Aj.j..u.{.p{.......(M_....*..<@.I?.._....~....p.E{..}?.7.../5vL...).H./8.O5...W..#....8V......Ph..2.Ex....j.T.f.IIa.........il......tzH.1H.p@;....rW.E...Z.O.yOf..{.8....4.j..9- ....Q.T.(..G...o<T......."....5B....&.#2..S...q..g...R.];E..6.<..c7.$..v.K.......{.^.}.m.e..*b......!>.(A..A....7n%\j...h./..N...EEP.<....GO..c.)..'r...G..I.._...d..^...R..jc...4...s ..6d.C].._is..b....D..B.....T.......V.!..R..#...q<....y.#...x..1a.&q..*.|y[..{W....ce>..._Gb..o
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.861197951166291
                                                      Encrypted:false
                                                      SSDEEP:24:bkhrJrq93pX0LXxKs7J6EERwXjQl8ETR/cnBv/VvSeYXNbT/nr/MWbBnOQHhKXu:bkhJrq93pX0LXlsEEReETRq/RSeYRvrL
                                                      MD5:F6D1BB15195F75EDDADFCA940AF47C48
                                                      SHA1:408DF50053B6E7E7BB8743CE41FF9C80F3D75836
                                                      SHA-256:FFF1BF0071FE44597204407DE63B99BC50B27E06432706283D668926FDA63CA1
                                                      SHA-512:274B293D4BA587EE80CE08126DBD0D3864663A58F8680C28A6B8C3CE3F548E3AEA4BBDAD12BB0D3B6EF0161C6C0B6B0DF325D3C19C0E14280C2AF901C9B817F8
                                                      Malicious:false
                                                      Preview:WANACRY!........5.!..,R...}.Z....`.....r(...d...@7..>*.V#40..T..E.aU3..Bp.2.OxB.z9...w..v4.....OM.........m&..ov..u7.m...!.......N.B...m.{b..)..Q..rv._ek......P......!.X...-.EC..i...m?..w".!.....Ll9..........Z>..6'.]@........<.}.....=.<..........q_p................9......2n.jDj..c.4I.J.r.u...HNJ..f...g._..y..U..J. .Q+)x=...@....4..A\?dMp..-c.f....0.../.r..t..w.a.........\.K1.WAX/....XQ7k..BO.U.:.........$.|..L.....0(.9.J...=N..m..|..R.h`.+..6.l...F.(.....a.Ut!h..*..}.`..9,.N".o..N..Aj.j..u.{.p{.......(M_....*..<@.I?.._....~....p.E{..}?.7.../5vL...).H./8.O5...W..#....8V......Ph..2.Ex....j.T.f.IIa.........il......tzH.1H.p@;....rW.E...Z.O.yOf..{.8....4.j..9- ....Q.T.(..G...o<T......."....5B....&.#2..S...q..g...R.];E..6.<..c7.$..v.K.......{.^.}.m.e..*b......!>.(A..A....7n%\j...h./..N...EEP.<....GO..c.)..'r...G..I.._...d..^...R..jc...4...s ..6d.C].._is..b....D..B.....T.......V.!..R..#...q<....y.#...x..1a.&q..*.|y[..{W....ce>..._Gb..o
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.8116259069873895
                                                      Encrypted:false
                                                      SSDEEP:24:2aimZhdc9MgP6IsZHob7AUzx3efeBMZhag6tgGRArrBj7:QmZhdHgDyQhF3SeB+1ggiAfBH
                                                      MD5:5E18A9978D2FBEB68DECD59BB7B8F8A9
                                                      SHA1:BB491B29B6EE21E79B57577A1A78D77A4C34AB0C
                                                      SHA-256:C6B22E2FA1EFDFEE0CFA94D5A0E9D6871AB7257B823AED3FB48382DF3EC49B3C
                                                      SHA-512:E0EC1AD13E5D79492B19BF965ECC9C3B842C3DBD0370B50C1982F6B676DFFB7E2DA60819F46A9D56024F067EC4F38FACFB2995C21394691E310ABBA9E57CA0B5
                                                      Malicious:false
                                                      Preview:.P...2H....jW|..p........F.._X...._fx.rt.=8.?w.q.....7.e..}.\..O.s....-!b...C.7...y.j....6.Q...,.X.R.B...Qs.On(.yL.....;.OBF..2!..it..C.".O>.d...k..*....d..@....S --5..Y.E!.W...^....?Kf.....I..'..x........ng....a...rP.......>.LE........=d._..\...W2.![.e.I...|>.`.k.Z.<Wq;<..`[`.X.K^sa.+......ko...D,.-.KQ..y.:..%....>.X..........H...A.......q..m....j-....s.?..m.:|..w.....]...W.E.fCR.j..Hn.`e..g..a.=%W.<..n.6t"..lf...0..u.0:3....|!r.u.R./....[7..z\M..".........*.c}..:A:..[ ....Q.]....;c.dJ.6...l.u.hx....."...Lm.<]2/.........d..+ydv..k...=,..F,Q.........E.d.A.....!.....f.r(.5.T.Y.]Z...57............\.pn-.n.9..;>~..".R....'...x...'2A....\$Q)9.(...%.'K_.=.........w.C.Xu..Y.)...b....T.r..S.I....q.A..-...D.<.*}?#G.e.,8..B.Z..k.v_GfM\j..J.$I...i.r.-.Y6...*...L...8*.]DQf...T'....h+..!.....H\T...d..O(.ZJ.2a'...{P.."../.gO.......B.:....m...BL".]kz..b...U]./....y..L..<...Vq.?...o~. =...X..m.&.W:9L..W..]I..\8..!..m..GS.d.l"w\....)F..}H.C...........l?P
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.8281508378529105
                                                      Encrypted:false
                                                      SSDEEP:24:bkyBLIgV5jV5Lgj7f8tynTwFizqvOd5fw31o67eBhVCM228g8fv:bk4jD03f8tynTGWd5O1jKhCzY8H
                                                      MD5:4EB4B905C5098B9118B4A71D1B48F621
                                                      SHA1:387FCBD42D3C57152E5557AA5DAFE6B0611AB144
                                                      SHA-256:EE2DC293B38CBEE7FBB2BE1F236632A4E97CE1A20559AABE0F4D32D17268972E
                                                      SHA-512:9B2016655B08C04AA1D608FD602081B5156BD47DE6204AC456F7ECDA551925C4C63DF9AD28374E47B8621EE38A23C09C40441A48DB18B608BBA0CAD0F80DEC8D
                                                      Malicious:false
                                                      Preview:WANACRY!.....o.0..I&...._.I@.O...bHU.p...mG.*...C..q...o...3.~..#T...lqk..j..;...Y.b...}....0o?.{f..o.u..\R...oG......A....=n.M......X.<.h...je.M..Z."]<.+...L.....P ...,.9'..r~#D.<........D.9....L.@..F<....N..,$.{..A'.!R[..2.0....^...>0..D.!....m13...W............ ?.........[=P.[*#.M.V.g.6. ....<l}.i.92...%U&{.......8...xj.....\.: w`}..n..].}2s....%.~..=T...5.Cb{LnD..}...{.u....<|<,{..6z.........8iO.7................v...C...!.....>...UCw.M*f.t....z.0........px.y6%..N.}.3.V.....x..8..|.QV...]JXV....f.......z...c)!.y.... 8....2....HWI$0...%..N..-..Yl.o.....N.@~.iR.[.....af.?:~.c.ab...:.CRP..i.{.......A.n....IPH9....ru.....0e...V...s.L.l.T.CP.|../w.4.2..T....\...d ..#..I.Q.V!..,.F.......gE..dZo.@...v.}.?h.~Q.C.2.&...Eg.S..I.H...\...i.9V.GG6.go5`6...@ke..)..>K..wls.<.....Op..2..+3....T....*.V....i..1!br....{.B^.&..?P.{../r2..c....?.....;....:g...0#q..S..z~."kj.n.kk'.-d2h..n|..TS....V#4`.e.R.\..g.(.S.7e.. ...O.y..\....,..Xje..N/]sE.7O..Owq
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.8281508378529105
                                                      Encrypted:false
                                                      SSDEEP:24:bkyBLIgV5jV5Lgj7f8tynTwFizqvOd5fw31o67eBhVCM228g8fv:bk4jD03f8tynTGWd5O1jKhCzY8H
                                                      MD5:4EB4B905C5098B9118B4A71D1B48F621
                                                      SHA1:387FCBD42D3C57152E5557AA5DAFE6B0611AB144
                                                      SHA-256:EE2DC293B38CBEE7FBB2BE1F236632A4E97CE1A20559AABE0F4D32D17268972E
                                                      SHA-512:9B2016655B08C04AA1D608FD602081B5156BD47DE6204AC456F7ECDA551925C4C63DF9AD28374E47B8621EE38A23C09C40441A48DB18B608BBA0CAD0F80DEC8D
                                                      Malicious:false
                                                      Preview:WANACRY!.....o.0..I&...._.I@.O...bHU.p...mG.*...C..q...o...3.~..#T...lqk..j..;...Y.b...}....0o?.{f..o.u..\R...oG......A....=n.M......X.<.h...je.M..Z."]<.+...L.....P ...,.9'..r~#D.<........D.9....L.@..F<....N..,$.{..A'.!R[..2.0....^...>0..D.!....m13...W............ ?.........[=P.[*#.M.V.g.6. ....<l}.i.92...%U&{.......8...xj.....\.: w`}..n..].}2s....%.~..=T...5.Cb{LnD..}...{.u....<|<,{..6z.........8iO.7................v...C...!.....>...UCw.M*f.t....z.0........px.y6%..N.}.3.V.....x..8..|.QV...]JXV....f.......z...c)!.y.... 8....2....HWI$0...%..N..-..Yl.o.....N.@~.iR.[.....af.?:~.c.ab...:.CRP..i.{.......A.n....IPH9....ru.....0e...V...s.L.l.T.CP.|../w.4.2..T....\...d ..#..I.Q.V!..,.F.......gE..dZo.@...v.}.?h.~Q.C.2.&...Eg.S..I.H...\...i.9V.GG6.go5`6...@ke..)..>K..wls.<.....Op..2..+3....T....*.V....i..1!br....{.B^.&..?P.{../r2..c....?.....;....:g...0#q..S..z~."kj.n.kk'.-d2h..n|..TS....V#4`.e.R.\..g.(.S.7e.. ...O.y..\....,..Xje..N/]sE.7O..Owq
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.806030623674904
                                                      Encrypted:false
                                                      SSDEEP:12:dH8OG6JI92scesF00TxNekVVZbW0AuXWd7IkkXZJNKIWzvDC3U0GXsmPZuOuWNnB:dcp8I9E7x4QVwoXsIkhCKtumgK5qbIb
                                                      MD5:2745BF2B85F8A7285CC39335F54AB7DC
                                                      SHA1:F144F9D2E1E8C060EA7F2CB62FBA33AC3BE8D4C9
                                                      SHA-256:0A8793640AF3FFB56DC051F6B4CB8FEB4ABCF4173B50753041D47B1A27DDF363
                                                      SHA-512:6E73C38CC0CD2D6AAAFBB205C61AD132E93CEC8CBD65FBC8D569055BAE62CD5B3B70195078BD6D3314284D8D7689481416BFFEEAF89C5E185CCDE6FE1E0605EC
                                                      Malicious:false
                                                      Preview:.....V.A..."$O.. I.N.TO....D?'..)S.I.&..k.cXO....M..+.*!......#/r.... .......L..2?v..g.^...)..,...v&l.;m..l.G_..2)E.....s.vC..L'E.B..n.....:.=.`.2X....G>."..njq...~uE.... ......BH.O.D.D.......d..9/.....S-.MH.G...U=....$.....g.x....O.K...-...!`..?.d"....a_....@/...."Y+.84M_L..\Jzj......ho.J$K.i.#..8.e..h..d.2-.t..#...$...$Y.m....8.q>..wd......;.t`cu2...5/.W3..a.V.g..[X..7C........5$.Z$.Z.{L..._.a.....h..O...1..%"^.?....^R.0.C.;.`<..c......y@....,1.h9....A....,..V....&..h...sO.J...3.t.....eK...Mg.|......+..e.a.Q.....o.AB6...>LQ.LH.$y..5.dQ..Bd.>....J.*....b....tTG...s...~kY._'......=fPXH%.}..r.}Le]N.. ..*...+.5....-/I.;..t.86....I.\..~.A8./......S...E.j.oT....h.,..j8W....X....'-...1..|..Q..{....y.....\.:....Y.i.p.V....".V.Q....V....b...i.q.:.......YH.B.....T..z.E.G.&4:&...N.^....o%...l.....9E...nLp..!.WUHn....4C.......K...........?......".^{..Y._m..9.B....i-...|..g.H...3.$u..9.,0.Pb..m..\.|g(Po....Uqks.L......R........\...0..Su.HXY'x).s.pQ( .x.....(J
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.827469427370593
                                                      Encrypted:false
                                                      SSDEEP:24:bkDosjwWcKAebJHLiBTAL4jFWrSHNY/6ztEpxNzfQdqvVhIHiJkCXhARYvmYrkd+:bkDxLPRc+tiSpHzfQ3CJkAWRYvp2JMB
                                                      MD5:6FE0E9F1E1C8DFE6BF18ECAA67473C16
                                                      SHA1:D978F348BD1E35C35A66B18000BFA5E23E234D82
                                                      SHA-256:82BC7F16FCCDD22425F41A76ADB015E94C6CC8B2198CF64973A0D4B56E258F30
                                                      SHA-512:ABE1919D9D2A8E730672EF73BE0B842586077BD80D6B4B5971F2EA594D126B202FCEB2B6E336EBA3719786E028B8D3BCA91D2F370A6216090803623866841C5D
                                                      Malicious:false
                                                      Preview:WANACRY!......n....{C.....@.b<6..T.........*.?p...J....#g.2..H.f....j...mim..O.}.(<#&.g......j9S..h...+.....>.K.I.R2..P .......#Alh..!.*....T.B...;LL.I.9.mxB.....5..h.....1.......I^..mz.j.b..{$n..8f..-.3#.s.....eXS.0w.....y../<3...k.&.l......Q...k..o>..K.Z]..............3.JA......M......V'...A...N@...D.O.H...wL.W..4Tf(...#.7^N..(.K...-...f3...Z..+l....Ax..,zp..........;c.?......6..A...O.O.C5{.R.-...G.%~.k._..W..co......C&..7.BV..+.p..-...h.92.j.|.J.N...b....2..V...>(k...e.<.D5.....g.........XN<.7...].W5....O..<....S=m..f.>.}B]Ul.d%(....F7...Z...c..!...Q...4..R.'.V............g..H\.6h.b^..ZQ..A/..J...9..P.7/...>...*@..t.y..l........12...n...b...[0,...}Q.Z.||......5.(."..yPG.....C....".[z.WY.. 6s...b..P`..d1....c.....Z.2..;.t..%6...,.IN.Y........P.m...8.&...T.=k..._.{9..@....H5f%J...t...4.....,....(...|....#.x.-8...,/,.|...Id.G....=.."..K....Fk.....8^Yh~*.....%y..IG.Q...W}........k..j.4.aW.6o...EN..:.$.&}9.j.J............Aq.....$].2.\.5.)=..R.c
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.827469427370593
                                                      Encrypted:false
                                                      SSDEEP:24:bkDosjwWcKAebJHLiBTAL4jFWrSHNY/6ztEpxNzfQdqvVhIHiJkCXhARYvmYrkd+:bkDxLPRc+tiSpHzfQ3CJkAWRYvp2JMB
                                                      MD5:6FE0E9F1E1C8DFE6BF18ECAA67473C16
                                                      SHA1:D978F348BD1E35C35A66B18000BFA5E23E234D82
                                                      SHA-256:82BC7F16FCCDD22425F41A76ADB015E94C6CC8B2198CF64973A0D4B56E258F30
                                                      SHA-512:ABE1919D9D2A8E730672EF73BE0B842586077BD80D6B4B5971F2EA594D126B202FCEB2B6E336EBA3719786E028B8D3BCA91D2F370A6216090803623866841C5D
                                                      Malicious:false
                                                      Preview:WANACRY!......n....{C.....@.b<6..T.........*.?p...J....#g.2..H.f....j...mim..O.}.(<#&.g......j9S..h...+.....>.K.I.R2..P .......#Alh..!.*....T.B...;LL.I.9.mxB.....5..h.....1.......I^..mz.j.b..{$n..8f..-.3#.s.....eXS.0w.....y../<3...k.&.l......Q...k..o>..K.Z]..............3.JA......M......V'...A...N@...D.O.H...wL.W..4Tf(...#.7^N..(.K...-...f3...Z..+l....Ax..,zp..........;c.?......6..A...O.O.C5{.R.-...G.%~.k._..W..co......C&..7.BV..+.p..-...h.92.j.|.J.N...b....2..V...>(k...e.<.D5.....g.........XN<.7...].W5....O..<....S=m..f.>.}B]Ul.d%(....F7...Z...c..!...Q...4..R.'.V............g..H\.6h.b^..ZQ..A/..J...9..P.7/...>...*@..t.y..l........12...n...b...[0,...}Q.Z.||......5.(."..yPG.....C....".[z.WY.. 6s...b..P`..d1....c.....Z.2..;.t..%6...,.IN.Y........P.m...8.&...T.=k..._.{9..@....H5f%J...t...4.....,....(...|....#.x.-8...,/,.|...Id.G....=.."..K....Fk.....8^Yh~*.....%y..IG.Q...W}........k..j.4.aW.6o...EN..:.$.&}9.j.J............Aq.....$].2.\.5.)=..R.c
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.821499172780964
                                                      Encrypted:false
                                                      SSDEEP:24:9k8heLa6qQgC8MNYv4CQrukqdg5h4E8jeS9C6c9En:9VeLaKgC8MNYvrQrukqdI78jeS9t
                                                      MD5:A940A0F7E45C2936E4A91AEF17D639FC
                                                      SHA1:FB25FE8F010C073645AEABD155A5CC28F2E8825C
                                                      SHA-256:C13DEB4D7337E1BB89170C37B2EC691C62D7EA9B1B9E9FFD22A9455177435891
                                                      SHA-512:4495EB9409BB60DEB34E3B13A5984A5FB0D06FE7181788D1FA960187E40E57781EAB16A355A6DA14B0AAC433B82F440F40BE3FD52A90EFF438DF9592B3C92129
                                                      Malicious:false
                                                      Preview:.b....ZV $Z... ..,.:<r.^z!/.......]....R8U..Bd.....'.........{.zE......e.I..U/.cP.L.^.p.m.K.....[..V.g...4...en4e.+....w.I..=..,............HbE.o}L..F......k.OgN#H..z.T....2..Q...tf.^>V.Z........{..KK.gr.A$s&5...*O........f.....).B...)....8.1..C<.sS.Y.........B.O.Y.......[q(L..A..._.*.).YZ.~.B3..=.\+.d.y..J.:.....K.m.......D..1s....XrL~p...c...D..?.Q.Q..1..wD8o.......,...sh.h../.u..y.hO...a. bt..{...N.4..!.x..K.g..&......P.D....c..[.l1.a.k....ZH...%.8......J!.......{.....P!).yS.u..=LWN?...)....5V.G.;...4..!.*.8.21...u..../."6Q0.{>..j.Y..+.=...0MB.!1.e.wz~jp.*....9..[.b.KP*| ..e>S....f..+E....b...n_..;In0.',.Q...{...J.J.t.{H....o..e.T.E..o..4.?...zd..4g.[..c..]i..7......E.i..]..].\6...]...v.[.r-....?.P.....K..X.....f.......V..#..c...)/...$t2e.\b..HX`.2S...8#....0@w.Rl#.p.N.3.dB.;.k.U.=.......cm.k..Q?;....#H>;J...Ai...zSA(k...Bm. ....F..7..b......;....>.X2.CU.P.0/)Y|)..[-1Iy........#8hx..R......Bev.."..9...$nr....F.....8.mBX....~
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.82113101304843
                                                      Encrypted:false
                                                      SSDEEP:24:bk/3eV+XDIykm9pznC11V3m/MSDKJj1wRh1AqgghwcdwBY/el+gPJvIBr6ku:bk/OV2hkWpjC11V3m/MSGJZkfB3ZPgxb
                                                      MD5:77A41A4BCCCFC20AA8F95BE97966C690
                                                      SHA1:CE03F0858D8DD2A3110EADFBBCE8337426613975
                                                      SHA-256:81BB172028BAFFA51EBD5A23C1DFF56AAC66AF5DF4CE621862AF9E8F63A201BF
                                                      SHA-512:1DA9055B8898725FF86010982B33253944C54502CCEC705D30C60E23158DEE6CC0F9D965580931643EB1CC6D7447DEA557462F882C6011103FC9F187DA2A8184
                                                      Malicious:false
                                                      Preview:WANACRY!.....6.iq..B.V.zuYS|...9.%.R....+^.s.`p..p~\..y...f2Q(%.g..Ck.v....-....l.I.rU'a.;7.*u...y8.D..>..i?..>.[.a.w.)/....)J4mz~...0V..{.."Hb{.5....kH_......l..).aj..>~.7..L'...y.M.0.~..1.3..f(..>.......-....e.bFy.,o.-:..2.?P(....f.......K.|......;b...................>.M....v.W..hT..@p&R.............'.4...5..A.4........&)SpB...K.......f.gxOP.w...Q9<...d.Wv.._L............f.....4.@.../$...Dx..S+#y1.r.A.E..BK.B...A.....1".0J...t3.g.N.....W.."...kFBgl(..,..H(...,....+4H..s.,......Q.v.A.o!>$P.#..SF.)....f.. ...!..%...b......"GO./K.F.+z..@.e..8R..jl.r..W.43Vy.s.q6.C..j.......].. .[..f.........L.....-x.>.R1...Dy.L..>.D)8..%.....z73....E.b...|:.....!...Ats...J....j'N.Fkwb.......,w]3..%tD.41e...,-.W..a..;..U ;.&..B...eO...n...v..-.._xL .H..'K..8\...k0.O.7..3G\)yf.......h...l..f}M...r.s.}d....K.6../;w&.&.0-...T\&$.f&.pF..8*....q9%..o.i.=|....."J(..s-...N.. .....N...Q5...v,.)@....m.......M.1...!(...u..sb)oL\.<.JaP(.Eg.4...)...0._,.I.<|Pk.S...|'.c.o..
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.82113101304843
                                                      Encrypted:false
                                                      SSDEEP:24:bk/3eV+XDIykm9pznC11V3m/MSDKJj1wRh1AqgghwcdwBY/el+gPJvIBr6ku:bk/OV2hkWpjC11V3m/MSGJZkfB3ZPgxb
                                                      MD5:77A41A4BCCCFC20AA8F95BE97966C690
                                                      SHA1:CE03F0858D8DD2A3110EADFBBCE8337426613975
                                                      SHA-256:81BB172028BAFFA51EBD5A23C1DFF56AAC66AF5DF4CE621862AF9E8F63A201BF
                                                      SHA-512:1DA9055B8898725FF86010982B33253944C54502CCEC705D30C60E23158DEE6CC0F9D965580931643EB1CC6D7447DEA557462F882C6011103FC9F187DA2A8184
                                                      Malicious:false
                                                      Preview:WANACRY!.....6.iq..B.V.zuYS|...9.%.R....+^.s.`p..p~\..y...f2Q(%.g..Ck.v....-....l.I.rU'a.;7.*u...y8.D..>..i?..>.[.a.w.)/....)J4mz~...0V..{.."Hb{.5....kH_......l..).aj..>~.7..L'...y.M.0.~..1.3..f(..>.......-....e.bFy.,o.-:..2.?P(....f.......K.|......;b...................>.M....v.W..hT..@p&R.............'.4...5..A.4........&)SpB...K.......f.gxOP.w...Q9<...d.Wv.._L............f.....4.@.../$...Dx..S+#y1.r.A.E..BK.B...A.....1".0J...t3.g.N.....W.."...kFBgl(..,..H(...,....+4H..s.,......Q.v.A.o!>$P.#..SF.)....f.. ...!..%...b......"GO./K.F.+z..@.e..8R..jl.r..W.43Vy.s.q6.C..j.......].. .[..f.........L.....-x.>.R1...Dy.L..>.D)8..%.....z73....E.b...|:.....!...Ats...J....j'N.Fkwb.......,w]3..%tD.41e...,-.W..a..;..U ;.&..B...eO...n...v..-.._xL .H..'K..8\...k0.O.7..3G\)yf.......h...l..f}M...r.s.}d....K.6../;w&.&.0-...T\&$.f&.pF..8*....q9%..o.i.=|....."J(..s-...N.. .....N...Q5...v,.)@....m.......M.1...!(...u..sb)oL\.<.JaP(.Eg.4...)...0._,.I.<|Pk.S...|'.c.o..
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.832562061085807
                                                      Encrypted:false
                                                      SSDEEP:24:h7X9gVBHnZYuXv4pfX8yt4JNAmdR+2poeTiveBLOQpqej+NpM306bEaR+:h76VdnZVv4pf38dR+qTAsTqEACZNR+
                                                      MD5:1A507BBDCF4E034138CA488D5E981FB5
                                                      SHA1:7215F40F2F4EC2AB06B90D660F37FEC66057B014
                                                      SHA-256:2D3938AF3A824BD69B1854B3359E85BDF801E07746A0788DD71E7C2F61542510
                                                      SHA-512:4874C2B03229C3FAD8AAD26275D25775D45F78F7EEB355D868A08D36532D97D1721843A48A0F75BD1BE61406F74EC9A6E34024E805E3706E883BDEB25A473281
                                                      Malicious:false
                                                      Preview:.........4d..p.@o.6,.7.t.X.q...N*..*.\d.7x.k.tw5[..=..T.....D...7...41N..9y..b^....R..=.Y..E.L.P...H./..j.....g.#.c{.._..L...G.^.V......OL.2.n]0\}....Y)..4n/.57W.[.~?...gz...I.;1.{.w.>.V..I`.....\..l'.4....z....W.Hp\VL*(?....YY..N>..-...).+..9. .xu.O...D=?._..>.H..^.H6~Q6....|....D..i.>M.^.+Em...!...<...P.F.(.O1.D...eck......vu..|..N..H.%...2".....Rky...{c..].=.k..H.w.-K......u.C^.o..IB...l8f.Bz.o..dC.....n.K..>1&.4..F.........N.b...Fn.F+5Q.X.......?...1...v".s5;..;B.....~.).]y~sDr..2D.......k.._.T>z%........E......W..8.H.....P.5J..N.....R.e....T..T...#l>..B.lf%.z+.....d.>c'P.........%..n......2..B....Vc....H...&.........Ua.........8x.....P....B.:...z...~.<AT.7.,L.'.".|........(.E...<z...bjc.em0.[Z....'.)..kN.A.K...m#.t&Is.$.......yx... 8Me4...WC.<2...>S..<...E.=.;.......6.6..`..%R..P.<..(....M..f......^...dP.......{.j..`.|.lqqT...:o|....P..j.v......9....{!..D.P..&&L...rh...Di.I.....C...E..X&.,..-.>.\..Reu..'..Vv~o....g.,.4.J..6T...l..u.2nH.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.848610085391327
                                                      Encrypted:false
                                                      SSDEEP:24:bkEcYdw+fdUZm0lvXcMtCTVsSMoAhq7DuYx/hEgZgrtJdpuW79vKxC4E:bkEzlfuY0lvXcMtQWPoAurhESKlKJE
                                                      MD5:BB183F7DEA487A49DFB0AFED2589351C
                                                      SHA1:25086369788CFFD0E5ACAC6D3C503E778E8A81A8
                                                      SHA-256:14ABCFFB14DE1043219BFEEF14701DF5317D1FA2994FBE17D777869F6E31A772
                                                      SHA-512:DA98DCF4184462FF6119A1DC747D1F1B9F00651227B093432F33A1E949AB5371FDDAB8CCE9063BEC2C3E412030FA9F6305D9E72B830F02E6EF7087F6DD5C4A8F
                                                      Malicious:false
                                                      Preview:WANACRY!....,.H.(..>....5g..@......%cD..G.*.$.Bsh}A.W.....8d...N./`......iL.vU.P......;..Q&...'.x2..%...P..U..V.\..a.. .~....#..... J-MA...[r ~<...B....]....&Z.%<9o..X,...G.Q.....>..._...L?..to....eJ...rb5`Q.{bG..u.....G.!.>2&.....w..P.....J......#...............:..^`..G.`!..@$p./.N.+.z/0..G%.......vF-..).w..$.d....[n.X...o`.%u.!....d..o..r=z.....R~+..N..,..9T.$..../.......8....v)1E....X..U.gR.9.....g.g..;...<.MM....m.v]....@o38P.....]...Q..@!)...b..J......NP..W. ...RR.g...E.'..a..DlL{.u+...?7..zK]J.$s.G...7u...h3L98.'...j.(y.QU.uF...djP4.O ....G....CX.0'.9.RZ|..?f...2.u...>........^.U.H..zB9......n.9......fZ..?0.->}......y..)Io3...j/Gh...C.....j./......E.G7..D...1..........7H-?..E<.'...>a.S..&o.y.......f.V..0..VbPo.`.5.....f.K..(.......N......;..T..Y&n....<.).f%..^..p.....h.)7(Y2.q.g$...L.`..5...l23;...%uA...*...Yb.".*....&..G' Y>..@Q>..r.......[.x.7.os.E....~:.X.~.......S....I...}......F.i0).. .N.."...j.T.*..z..G...dX@..'.#...t.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.848610085391327
                                                      Encrypted:false
                                                      SSDEEP:24:bkEcYdw+fdUZm0lvXcMtCTVsSMoAhq7DuYx/hEgZgrtJdpuW79vKxC4E:bkEzlfuY0lvXcMtQWPoAurhESKlKJE
                                                      MD5:BB183F7DEA487A49DFB0AFED2589351C
                                                      SHA1:25086369788CFFD0E5ACAC6D3C503E778E8A81A8
                                                      SHA-256:14ABCFFB14DE1043219BFEEF14701DF5317D1FA2994FBE17D777869F6E31A772
                                                      SHA-512:DA98DCF4184462FF6119A1DC747D1F1B9F00651227B093432F33A1E949AB5371FDDAB8CCE9063BEC2C3E412030FA9F6305D9E72B830F02E6EF7087F6DD5C4A8F
                                                      Malicious:false
                                                      Preview:WANACRY!....,.H.(..>....5g..@......%cD..G.*.$.Bsh}A.W.....8d...N./`......iL.vU.P......;..Q&...'.x2..%...P..U..V.\..a.. .~....#..... J-MA...[r ~<...B....]....&Z.%<9o..X,...G.Q.....>..._...L?..to....eJ...rb5`Q.{bG..u.....G.!.>2&.....w..P.....J......#...............:..^`..G.`!..@$p./.N.+.z/0..G%.......vF-..).w..$.d....[n.X...o`.%u.!....d..o..r=z.....R~+..N..,..9T.$..../.......8....v)1E....X..U.gR.9.....g.g..;...<.MM....m.v]....@o38P.....]...Q..@!)...b..J......NP..W. ...RR.g...E.'..a..DlL{.u+...?7..zK]J.$s.G...7u...h3L98.'...j.(y.QU.uF...djP4.O ....G....CX.0'.9.RZ|..?f...2.u...>........^.U.H..zB9......n.9......fZ..?0.->}......y..)Io3...j/Gh...C.....j./......E.G7..D...1..........7H-?..E<.'...>a.S..&o.y.......f.V..0..VbPo.`.5.....f.K..(.......N......;..T..Y&n....<.).f%..^..p.....h.)7(Y2.q.g$...L.`..5...l23;...%uA...*...Yb.".*....&..G' Y>..@Q>..r.......[.x.7.os.E....~:.X.~.......S....I...}......F.i0).. .N.."...j.T.*..z..G...dX@..'.#...t.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.790806389131858
                                                      Encrypted:false
                                                      SSDEEP:24:oQ1k4Ea/rwBY3VXWhlAfAtN1bwx0cfABg9I1Q2q9O:oQGa/1pAbwx0NVqE
                                                      MD5:1B46E2B25DA0DF6DA69D1E5736A41B4B
                                                      SHA1:68911B273917A1D836A9FEE84968230C2E42E1A0
                                                      SHA-256:E2732C0A7367C65FF16128DBFACFF32731FDB61133753F2FE2EE2A5235E78D33
                                                      SHA-512:6A10D82D07CC1B00AC358553B6DD5AB7823F8D6F0D7C4DA1ACFEEAAACE3DE9F43A4C20315127EC7706E207D0BBC5833C79E325990252F84BB363EB29141BF71C
                                                      Malicious:false
                                                      Preview:...8E+...R.....".....t....v...).....6..=...v...4...{.K^.^N.....M..W{....../..Fj...a.3....g..P........E.7.?.v..YK..n.K.vC.r.... .TF-..tT..&........n.....C.Fy..1.2.../...a l YD@.u..2,..D.j:dbL&|;+:.>.x.../.1..N.T_.aj.~qK>..5.X...v..<..y9.v..y.*.8.E_, '.r..C.OU....f.=...j..i..M......l1...>.....$i.X.../..R.~..d@...8.5.RJ.+.0s`$...G/..Jh...p...A..C...9......o..h...*..is.?.4.z...._8..{L%.\..Z..*_...W;..k......&k.i.:&.$\......e#...y..y.x..l...NDWm...@K3.KE.S.ntLh.......b.Oh..\....^u.E..(....Kf].f.lc..L..!.]o.$.....].kJ.E.|e.-.g-.Or..Q..%g.^......yF...W...T.*.+h...-.'..Wjx.h...=.........UZ../.:)....%.|.h....Pi.A...(s...|.Y..'.p.....A..R6p>..W=..<D.w1......*Vc.h..%.8.+....^...:. .g.-.Y.,SV.2...<..A.K`.......{;.x./..Q.....U@J.R..j..0.~W."M:D../.A....Xh.+.J.8d..g-..y)=b.:=.,.!.......%2.b..C...Z$8....+%..#..8.T.O...:..&...}-..N1.......XGj..d..{|....),.?...j..=.........1=.j.Wv..i....c`..h.7..5.uc .C.Nr...&.A....1.`f.M...1.dA;5.RL....`.d...#E...uG.c.U
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.866099501508106
                                                      Encrypted:false
                                                      SSDEEP:24:bk3wcj6+XrSCy+k6VV2VkTe0pq0sOgefj3l5aFjT7+KbrQwQbUSPHG9jZ:bk3wcW+XG+bnU6+OJfj3naNTdpMHc
                                                      MD5:24621442F8BAACB8A8825301AA86869F
                                                      SHA1:480CFDE5D8E689211B5C41CA3F359651021AE5B7
                                                      SHA-256:57D5908147A72E720956EE37FEFACEAA2520F51A74BB2472B63CBBF9B5B8A195
                                                      SHA-512:A627871D30B456FAAE49601F205B707260CC70B7A7863B8A42FF6425BC8C23840C8AEAB7CF9C123768DAAC1CD3BFEC923CF772B72FAA3999D4D2198244495501
                                                      Malicious:false
                                                      Preview:WANACRY!......i..7..\k......D...X.%..2......|..!.^A.7...9.....zJo..1j.............M....ik2'.....O.,..+....7...JG...7s..^......T5...jYcN"p..I....qM).......E>.F...t....\.?...e.{.0\Y..T..........OT...?.....'.O.b...Go...go*..f.r+.5.X.'(.a..!L.2hf.....................&.?......gL.,W...L..%s...Q9.....}...p../Tt... ..I..W]...^xx....D....}W.d.....+.`.rEU..6F..........$..\d...4....YjZ....G&h.E...OD,`..T.t+oX=..'`V.&.J.....HBt............,{..cV]..y..X. q.e.eIQ.qK........W..E.Ri5O.........Q......Q%....g.}.0.U..<Oh.Ul....~.t...w..8..!...9..b.c...5.....6c..&.@FG..sK.v...2bI.s..4@=rT.M...&.(.(>....!......f.c...x...=.B.................M.....Iw.*.~.fC.........b./.$.~.....yduj=...d3..k..<T#..Zn.z^=.....B...*.y./..L...;%He4......B$......cv0e.........k@a.Yg....r. .......GfFL.]...d.W...+.?...J......!..v.T.ro...x.2.`..a...\............>.......g=R!..h..``?..l.,.6.2W.0z..2XD.<..`.......{.)..5.H.$...s>.._.O]i.C..|.B_....Q*."...5...G.2.H..g..<..#.P[.V.vM.@
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.866099501508106
                                                      Encrypted:false
                                                      SSDEEP:24:bk3wcj6+XrSCy+k6VV2VkTe0pq0sOgefj3l5aFjT7+KbrQwQbUSPHG9jZ:bk3wcW+XG+bnU6+OJfj3naNTdpMHc
                                                      MD5:24621442F8BAACB8A8825301AA86869F
                                                      SHA1:480CFDE5D8E689211B5C41CA3F359651021AE5B7
                                                      SHA-256:57D5908147A72E720956EE37FEFACEAA2520F51A74BB2472B63CBBF9B5B8A195
                                                      SHA-512:A627871D30B456FAAE49601F205B707260CC70B7A7863B8A42FF6425BC8C23840C8AEAB7CF9C123768DAAC1CD3BFEC923CF772B72FAA3999D4D2198244495501
                                                      Malicious:false
                                                      Preview:WANACRY!......i..7..\k......D...X.%..2......|..!.^A.7...9.....zJo..1j.............M....ik2'.....O.,..+....7...JG...7s..^......T5...jYcN"p..I....qM).......E>.F...t....\.?...e.{.0\Y..T..........OT...?.....'.O.b...Go...go*..f.r+.5.X.'(.a..!L.2hf.....................&.?......gL.,W...L..%s...Q9.....}...p../Tt... ..I..W]...^xx....D....}W.d.....+.`.rEU..6F..........$..\d...4....YjZ....G&h.E...OD,`..T.t+oX=..'`V.&.J.....HBt............,{..cV]..y..X. q.e.eIQ.qK........W..E.Ri5O.........Q......Q%....g.}.0.U..<Oh.Ul....~.t...w..8..!...9..b.c...5.....6c..&.@FG..sK.v...2bI.s..4@=rT.M...&.(.(>....!......f.c...x...=.B.................M.....Iw.*.~.fC.........b./.$.~.....yduj=...d3..k..<T#..Zn.z^=.....B...*.y./..L...;%He4......B$......cv0e.........k@a.Yg....r. .......GfFL.]...d.W...+.?...J......!..v.T.ro...x.2.`..a...\............>.......g=R!..h..``?..l.,.6.2W.0z..2XD.<..`.......{.)..5.H.$...s>.._.O]i.C..|.B_....Q*."...5...G.2.H..g..<..#.P[.V.vM.@
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.817268395164956
                                                      Encrypted:false
                                                      SSDEEP:24:XEGRpTDZvj46OFhLOW0fUTJL86btG1Eicj+0YS4B+KRKBSKbF4TS:XvRrj46OFhoT620c+WKR5
                                                      MD5:A8AF2CA4DD1BC7B1A2CE72250120D63E
                                                      SHA1:0E600F6EF7F2CDB8597F58087E976A80514FC261
                                                      SHA-256:F6F52D5F5271301371B82B6936F7EF7659916E2EB31C08D7659EFBFD8C1C51D8
                                                      SHA-512:6C03FB24C99E0B28518C4F5223F61004DBF86CC1ED87942F219D1822590E7BFB54C294B875261C44E40EF0C9673CDBF9044029C2D4302548E7658371A263B47C
                                                      Malicious:false
                                                      Preview:K.THH:.\.y............1...y......q...$.s.S4..W.}%.........\.y..1..].5....d..Yl.Z.^.+I.U./...x.._o.......y..I..h.".1..O...M..r.>qcy\b.?Q...L.f....=...X..etJ....6.....DB...,Zu..{......@..X.!H.VN.w~..sO.....[Q..Q$ .P.l.F..w.h......L..`...k..e..$.....,..tlp............1@<..:..-..F...*+..R_.]#.5q..w......H.|...{*.jX.h8.b....f.DOq..u..s.....]^...&..S..*.Q.g...G.X;.er.3...e<.UAx.......z.|.|.v...#jI...n'H[..2.D..+...D.[$....;.A...;..j...#............o.~....J......M.+.........{"..i..5......X..9...uox.b...Cp...t.V/......Y8yK..l.F[...].W./\.*.H..'...q(...E{....t...h.,...._..6N.../<.tr.....>..p.$>;...Qf.u.e....Y.]...}J...{$*......N.^...9.\g..;..`8.>c.f..+.C..J#.....P..z...Zo.N."|..9.Q?.Is.:...zvy.hU... .t..u.v.g.u-........4..S|x\.1Iv...i.I<..|l<...-....X....@,.k.~...k.=.A&...B;....K.j.-.....?.[...w.d..n...!.Z......N..u....[.i..S{6..w...."cRK.....b.+.>....&...J."Q....G.}.m|.OT.....R.48!...u~..Pj..>.el.YhD........C.J$`.O.....|.f.S..>..Nl.6..t/8
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.845889644944892
                                                      Encrypted:false
                                                      SSDEEP:24:bk49fJnXey0/Pp9atJ7pvZc8ynstwlQbzfMs1CAh3k9TlHmdZw8:bk49luXuj7p6bnwwI+Ah3kzmdZ1
                                                      MD5:C1F9C162E22DBECEADE1337E53F58772
                                                      SHA1:522C663277C6285F79CBD17A7D6F054B108EF4E2
                                                      SHA-256:86611F4B359B265A6EE3B94C1DFFA9832B58BE21BC7C6D9FD69EA667CB9F817D
                                                      SHA-512:1D1404468108363177983437B8E6E78564567EB90DC8D1B3444D8A2B069D60A04774058A217A6B47BCF479F8DB8B36F064AD57B3605DB0F2BC477D910367652C
                                                      Malicious:false
                                                      Preview:WANACRY!....Y7.{QONO.k.N......e......G...~.].{..k`...=.8.G]..H.g~H.e.....g.........m.;2..D>.1.Q?*....1.!.._...?..#.s".\....z.@tT\ RE.5..3..x....v..D".w....Z...0.....:.9/".u.."...........j..#........+FgF..$2..P.uJo......|..94m...F......0&.=.pX....v.....................=5C.........bdo...J..$..9G.h7..S....|.f.lv.Cg<..Ca;.`;..q..~....C....#..3H{...@`..(.8Wi'W...k..h.U.9...O...".Y...be{/|bu.Y...x....N...A]...Y...a...8G.T...k...d........*....G.h.].t..Jd..iI...A9I........G^..<.q.].0...y..=`...1.....T.IQ;.34.$.0.`jRw..*....4.w..qp. _J....~.....o.rZ..xV...,..$..Q.Cg.c.N.\XD...TD.if.N[...w.).D.l..A.A)&.|.<+^t^i1...^...xH..._..U..G......P....-..\.W.w.b...%.!........y...M[q.5......>%.x...Y...R....ms ..dD=Z*8..[...~.w6j4..Z....[....,Zyf`..5..e....-.:...*}..........%.....J..sL>....x(^..$p....g|g.)..I...03....W."...W...v_.&.T.........r...".wTv..E..U..?..O....;.........b.?...3....o./"N`s_.~..@d....T..?]h..\..l.&..e......{.....oE...!...DSs.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.845889644944892
                                                      Encrypted:false
                                                      SSDEEP:24:bk49fJnXey0/Pp9atJ7pvZc8ynstwlQbzfMs1CAh3k9TlHmdZw8:bk49luXuj7p6bnwwI+Ah3kzmdZ1
                                                      MD5:C1F9C162E22DBECEADE1337E53F58772
                                                      SHA1:522C663277C6285F79CBD17A7D6F054B108EF4E2
                                                      SHA-256:86611F4B359B265A6EE3B94C1DFFA9832B58BE21BC7C6D9FD69EA667CB9F817D
                                                      SHA-512:1D1404468108363177983437B8E6E78564567EB90DC8D1B3444D8A2B069D60A04774058A217A6B47BCF479F8DB8B36F064AD57B3605DB0F2BC477D910367652C
                                                      Malicious:false
                                                      Preview:WANACRY!....Y7.{QONO.k.N......e......G...~.].{..k`...=.8.G]..H.g~H.e.....g.........m.;2..D>.1.Q?*....1.!.._...?..#.s".\....z.@tT\ RE.5..3..x....v..D".w....Z...0.....:.9/".u.."...........j..#........+FgF..$2..P.uJo......|..94m...F......0&.=.pX....v.....................=5C.........bdo...J..$..9G.h7..S....|.f.lv.Cg<..Ca;.`;..q..~....C....#..3H{...@`..(.8Wi'W...k..h.U.9...O...".Y...be{/|bu.Y...x....N...A]...Y...a...8G.T...k...d........*....G.h.].t..Jd..iI...A9I........G^..<.q.].0...y..=`...1.....T.IQ;.34.$.0.`jRw..*....4.w..qp. _J....~.....o.rZ..xV...,..$..Q.Cg.c.N.\XD...TD.if.N[...w.).D.l..A.A)&.|.<+^t^i1...^...xH..._..U..G......P....-..\.W.w.b...%.!........y...M[q.5......>%.x...Y...R....ms ..dD=Z*8..[...~.w6j4..Z....[....,Zyf`..5..e....-.:...*}..........%.....J..sL>....x(^..$p....g|g.)..I...03....W."...W...v_.&.T.........r...".wTv..E..U..?..O....;.........b.?...3....o./"N`s_.~..@d....T..?]h..\..l.&..e......{.....oE...!...DSs.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.80533100902087
                                                      Encrypted:false
                                                      SSDEEP:24:IFwXxyh4g31mfzTYdjHGKF8+UKWuQaHXuPByA0jdVZr33:IFwjnYVmv+Upe+pj0Vr33
                                                      MD5:0447E394E51D66683E83D8510B9B4468
                                                      SHA1:A2FA2676EBC9CAC4E1996D34EA587D6290F1DFE2
                                                      SHA-256:2C086B103E5AA8464756EF3B5E426C96DB762BE7A7822798B1B0A9EE8FBF6475
                                                      SHA-512:49303845832CCC87FF1D3035E48790E1B5EA0385BF04D96141828E968FBD247B41868DE2732A3A280AEA82485C3B2D0D78E97A5B1E6295292BE48735EDD4F377
                                                      Malicious:false
                                                      Preview:......y.F....f......c..R..?.tA...`.w..YgA.]!.I...* .{6.H....2.........s...L~`..F......*~.dL..W...K6Vwi........-].7..."..Hu.."..p...~.s......q.i.....\$5Y8.S..Md..p..g......V.h."...}.f....h.p<.J..r....M.e..._x5e."A.....y.=....6+;7(t.,.<.64.o...*.....:..5..B.v.<...<..G.:.A...z..+.!.+...J.T...,..G...k..g..H...d.R..)bl.....UFta((.9@s'..zvq......bG......M.-....f>(..".../U...n9...8.2.t-.2tL.r..!.o.....U...."-8w|.G...G.~.~.S.[r).K..Hlx..%.A.Kg...X7.#..".......s...d...{C."._.,..AC ..{.~j"..Q...*....lClF.i..d.g...:cj.6.m........./[..:.v.Q....5....w..}...7..C7..UW....!..&.L..\C>p.Z1}...........j...#.._.$..Tl.k.G..:..J E.....v..._Q.L..*...+..t......s.j....^k........=.:........|m.^..M..=......Q......._.QGD.......\..w..G...y.y....a..h.@M.J.>.T&...~.4..4..c. ....#.&n..J.]~..f.,{-..+...;.5\1%V...T#...$...".o..I.dI-?...=bW.4...)./..!w\.Q.9|....>...;..c!..jtc......R.....Ls."..l.....p_.)/.QCG\.Ex.V|up.x...Q".:K..o#].so..*2.......MP...r..j....a..".(c......l
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.8394145264125585
                                                      Encrypted:false
                                                      SSDEEP:24:bkmIFBjCvIPA3+lg9wAH8CoK9InjE7SBlkjQerQfpq/AIWXPCW:bkFFBjCweewHdoK9X7S0jQFXPT
                                                      MD5:3CBC67F7C18ED8E08943AA67856FAA4A
                                                      SHA1:31C6BF15A20FC4D3903FBF72C8C76DB78DC8908B
                                                      SHA-256:B19D5FC3197D0E582B53E44A378B4AE4C90F6F3BB5F8CBFF8056C8DD95472BFD
                                                      SHA-512:435D69B39782747722A65190809EA717C623B70459DBAABDEAA6B769BD568909EB87C4C7EFF615A9179B764DEB97285069D9F8A1AC47221FDE4C50160E87143F
                                                      Malicious:false
                                                      Preview:WANACRY!....~}..p.K.Q}.....**..D[W....w[...]d.......~b.5...#......Qx...&.)I..}...U..T.7..{%a..H...#.#=......$.Z..e<...Gj..[....#..P..7.#....:..$."..}W....x...\.Q....-8g..*I..+...]..I....H.=8.y...a..._-..q=rOn.{....D..7?..s.Q..Y..JTS...0...+..l#...ap.............XY.i+P.cC".k..H.........@I.d.x"\A.$..$bc.y#..6..2...w.1@.P;.4.....fPH..=..MN)G0..d..i......r.^.m#l..8..8Hf.y...*.R(..D.L#7... ...O..:B..+......?.>....?..j..n...6.l..v.....,.rM.r...h..54.YY...y.Ql..:....5..d.Qd..q...g.......K]R...)..vq...ML.BF.:\.a.o.....+.b3.e3..b..c.X....@.N.~L".mq~k8h.......~M.V.......*...].<p.2.c.%<n..e\..n..+...H.?(j.Gw...... 3..g"qw.@y0./9.$...h.....~...r2nj...W..........RdN.P.Hz...l...u...]}..3.......".eK.Sj~...Kf.ak....F.m.l...+i..&.O:.@Q....V.~.....I...M...8R..d..w.}.*.w..`...rJ.....&X.].YU.Ba.-9.2....!..F..%.yLx...F..l!.".*.8X]#I.q0f.....]RR.....7~W;-v.=.......W...B....N..)>.U...7.+....;..S@XK)..7..>..Eg.....@..;.o B..B....;.....&....Oo|......4....r...
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.8394145264125585
                                                      Encrypted:false
                                                      SSDEEP:24:bkmIFBjCvIPA3+lg9wAH8CoK9InjE7SBlkjQerQfpq/AIWXPCW:bkFFBjCweewHdoK9X7S0jQFXPT
                                                      MD5:3CBC67F7C18ED8E08943AA67856FAA4A
                                                      SHA1:31C6BF15A20FC4D3903FBF72C8C76DB78DC8908B
                                                      SHA-256:B19D5FC3197D0E582B53E44A378B4AE4C90F6F3BB5F8CBFF8056C8DD95472BFD
                                                      SHA-512:435D69B39782747722A65190809EA717C623B70459DBAABDEAA6B769BD568909EB87C4C7EFF615A9179B764DEB97285069D9F8A1AC47221FDE4C50160E87143F
                                                      Malicious:false
                                                      Preview:WANACRY!....~}..p.K.Q}.....**..D[W....w[...]d.......~b.5...#......Qx...&.)I..}...U..T.7..{%a..H...#.#=......$.Z..e<...Gj..[....#..P..7.#....:..$."..}W....x...\.Q....-8g..*I..+...]..I....H.=8.y...a..._-..q=rOn.{....D..7?..s.Q..Y..JTS...0...+..l#...ap.............XY.i+P.cC".k..H.........@I.d.x"\A.$..$bc.y#..6..2...w.1@.P;.4.....fPH..=..MN)G0..d..i......r.^.m#l..8..8Hf.y...*.R(..D.L#7... ...O..:B..+......?.>....?..j..n...6.l..v.....,.rM.r...h..54.YY...y.Ql..:....5..d.Qd..q...g.......K]R...)..vq...ML.BF.:\.a.o.....+.b3.e3..b..c.X....@.N.~L".mq~k8h.......~M.V.......*...].<p.2.c.%<n..e\..n..+...H.?(j.Gw...... 3..g"qw.@y0./9.$...h.....~...r2nj...W..........RdN.P.Hz...l...u...]}..3.......".eK.Sj~...Kf.ak....F.m.l...+i..&.O:.@Q....V.~.....I...M...8R..d..w.}.*.w..`...rJ.....&X.].YU.Ba.-9.2....!..F..%.yLx...F..l!.".*.8X]#I.q0f.....]RR.....7~W;-v.=.......W...B....N..)>.U...7.+....;..S@XK)..7..>..Eg.....@..;.o B..B....;.....&....Oo|......4....r...
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:ASCII text, with CRLF line terminators
                                                      Category:dropped
                                                      Size (bytes):933
                                                      Entropy (8bit):4.710902136409594
                                                      Encrypted:false
                                                      SSDEEP:24:ptrPzDVR5Gi3OzGm0EigS1xbnS4RQhbrW8PNAi0eEprY+Ai75wRZcet:DZD36W3ChvWmMo+S
                                                      MD5:7E6B6DA7C61FCB66F3F30166871DEF5B
                                                      SHA1:00F699CF9BBC0308F6E101283ECA15A7C566D4F9
                                                      SHA-256:4A25D98C121BB3BD5B54E0B6A5348F7B09966BFFEEC30776E5A731813F05D49E
                                                      SHA-512:E5A56137F325904E0C7DE1D0DF38745F733652214F0CDB6EF173FA0743A334F95BED274DF79469E270C9208E6BDC2E6251EF0CDD81AF20FA1897929663E2C7D3
                                                      Malicious:false
                                                      Preview:Q: What's wrong with my files?....A: Ooops, your important files are encrypted. It means you will not be able to access them anymore until they are decrypted... If you follow our instructions, we guarantee that you can decrypt all your files quickly and safely!.. Let's start decrypting!....Q: What do I do?....A: First, you need to pay service fees for the decryption... Please send $300 worth of bitcoin to this bitcoin address: 13AM4VW2dhxYgXeQepoHkHSQuy6NgaEb94.... Next, please find an application file named "@WanaDecryptor@.exe". It is the decrypt software... Run and follow the instructions! (You may need to disable your antivirus for a while.).. ..Q: How can I trust?....A: Don't worry about decryption... We will decrypt your files surely because nobody will trust us if we cheat users... ....* If you need our assistance, send a message by clicking <Contact Us> on the decryptor window....
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Archive, ctime=Thu Jul 25 21:01:45 2024, mtime=Thu Jul 25 21:01:45 2024, atime=Fri May 12 05:22:56 2017, length=245760, window=hide
                                                      Category:dropped
                                                      Size (bytes):575
                                                      Entropy (8bit):5.140446565826782
                                                      Encrypted:false
                                                      SSDEEP:6:4xtQl3y03CpzeVs+bTNAUHUtxXCzaMmM7/gtrUod6tMljAlpdmqLEoJ4D6Vod6Nd:8iypzYNbd0thHZOgZUobjArozhmV
                                                      MD5:CCD2610ADD4080C4DCC35A11217DA6A6
                                                      SHA1:001ABA92D58B546C8BD54E0BC4103661F68CF92A
                                                      SHA-256:0E272CF58CC66E7B0CC4F42094232A46B6EC11AE5ED695BA4156A1A28DA41E6D
                                                      SHA-512:36DC5CE3027E8A77639783E31AC69C9FA61C4761FBEB9A819C1EB49F4A32BF2001C0441FB28D35C4EC9DD1B713576E7894DE8FD13BF14CE62A436F9619093DEC
                                                      Malicious:false
                                                      Preview:L..................F.... ....b{=.....b{=.....`.1.................................P.O. .:i.....+00.:...:..,.LB.)...A&...&........DDj....%.=....(..=......t.2......J.2 .@WANAD~1.EXE..X.......X7..X7...............................@.W.a.n.a.D.e.c.r.y.p.t.o.r.@...e.x.e.......X...............-.......W.............,p.....C:\Users\user\Desktop\@WanaDecryptor@.exe......\.@.W.a.n.a.D.e.c.r.y.p.t.o.r.@...e.x.e.`.......X.......216041...........hT..CrF.f4... .u.E._c...,...E...hT..CrF.f4... .u.E._c...,...E..E.......9...1SPS..mD..pH.H@..=x.....h....H.....K...YM...?................
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:COM executable for DOS
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.808023602089374
                                                      Encrypted:false
                                                      SSDEEP:12:u0se5W/y52wVqveNCEDtXDmpjDs1ol3/SEPeTrttPzK+hoEgg8QroE2dENWfc28F:X5WKVistXDR1ol3dsl1hoE58yBgfRvPO
                                                      MD5:8016E59B345679E4F9FED72B000DAF77
                                                      SHA1:E7CF11C1DBA3AD09FCAFBF6596B72733458BC94A
                                                      SHA-256:1DE6FCBA6C802E6C5D185EDB55F82C44761E18B315EBBDAD27729C46F126F4FB
                                                      SHA-512:39D0D0A1AF24D10F6F89958B911F9C31C20967763EB201E74F12019385FE24CE1C76838353B65952487B133E2EA2B40763FB70BA87AF27461BF07BCB128D2111
                                                      Malicious:true
                                                      Preview:.Yke...y_f#K6L.....R....>...5!<...j..?.K.^^....([....k"..B.{..I...1.........w..}..vlA..C....Hz.s..p...Y>..hp.\v.~0<..\iE.U......[..z|"*..$.S....G......gu....c.38...2..P"..3M.i..Od.._.......ol......A..RLz..+R>.....O..Z......]&..4D...8.2..tKen.3...Me3.....u.*m.KEKQ.I.6.../J.T..!=.........,.5.g+.n.r...._......5V.......~...:...:E.".....?......UU.leT;&|....(d....7..f..-;....=.i<p3.9....f:8.....(7..@a.4)~....M.F<.W.4...?.6.[2?.@..^....R_...`.~zR7.)L.6..%7.F.jh...Y.A..M.d.x~.5r.:...y..M...n.(..^..O.0..t:....K...|..DA.t.6.....P^.2.j.|..5.....8JZG.d..N&;...~......l._Zi....P[aLR....h.W..\u.5..E..s._...;t.-:..|.no.$.2.?........}O.?...v...wv.B...*.>..!....b...-J..S..A..>N.i.....(\..M....1M...U.".J#.-..;s.U..].S.p......B......b..8+T.......w....R.].Cz.?....)....)..&...l....N9@RB=.....o.G....<...).N..8...z..!:..+..b.x.5.0m...{..r3(....v0........3..~_.Y,.+]..a....O.v...c..:)...i..1.....@..y...43.'3..k..6....p..3I..|.A.X...H.8...p......|#}..I3<..
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.8126559645312605
                                                      Encrypted:false
                                                      SSDEEP:24:bk0rX0DAUqQ4P+gWKAvkXLJlxwpKvEZV3R6jyTV/0TC9IIzzFVbi3l2A:bk0rEcUhDKAfpKvEvE2TV/MCDpJe1
                                                      MD5:EE8EC472B52C9386F5453D4154D48BE2
                                                      SHA1:41D09453960DBCC2B8FACCDDCB97C168C3939D5D
                                                      SHA-256:96BB9E5C7F1B101ADC310B19C17E656F2780E93E90EFAD2A1E5E57F9AC2B1007
                                                      SHA-512:4326526867A50076C5C3F96DB69EA1B1470E4695338184F36B5C5E03A2EAC2743899994515855B894B66F9B630D8EEC0DB23812850C834611835DBA272043710
                                                      Malicious:false
                                                      Preview:WANACRY!.......d.FRh...@..:.8.}Q.2...Y..fJZ..x.Qd.g...S.@...v..Hh......Q..(r.f..k.....U6@....L.I.a......+yX.......YB`..g....w:[.7...L.O..=.f.G.QA(..{..Mo.p;El.)v...k...,..v...(...#..A...}...o.X.@..L.Lt.c.F.%g......MB...`.BO.k.....(..QB.d.w.....>e.s.v.................[....i.......T.......5......9E...F..J...l..lk..q........U.`...Q$...B..W(..e0...3...H.}21.....6.W..`V...o..1..slvA.l..> VHcH.......}..T"}"..z}G..%V....v..j..IkH.<..>.$..l..s.&.!.O..HX....Ra..qv(R.v..OX..&..y..........d.N..U...^].....iO.d....~......6.o@..d...%../t......F}..\..q..g.jl.....dPY~.f3S.....A.A>...Nv.:-..T.m.H.....M......K.X*....,..r.:.p.....;.wB.....a.O ..{pp..X6+.<"...%@X....,#u~]zq.k@....4.......L....Y(.P......rr..u...6.."...W...b.e...p$....i..TvXHE.7.......m;I.....9..~.Os.X....,.m.3v>O...:q..].?..e.WA.#0..k=....X<3.s..7EOo.....c3..4q>.....|em.N.0...l....h...pS.;Xb...YU6......t.4).H.pyZ.^..Kr.c..|.B..s..0....B.?.....8.N..`J...U=6.z.s.V.[.rWC...n...}..p...t+h.....7...h..-r.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.8126559645312605
                                                      Encrypted:false
                                                      SSDEEP:24:bk0rX0DAUqQ4P+gWKAvkXLJlxwpKvEZV3R6jyTV/0TC9IIzzFVbi3l2A:bk0rEcUhDKAfpKvEvE2TV/MCDpJe1
                                                      MD5:EE8EC472B52C9386F5453D4154D48BE2
                                                      SHA1:41D09453960DBCC2B8FACCDDCB97C168C3939D5D
                                                      SHA-256:96BB9E5C7F1B101ADC310B19C17E656F2780E93E90EFAD2A1E5E57F9AC2B1007
                                                      SHA-512:4326526867A50076C5C3F96DB69EA1B1470E4695338184F36B5C5E03A2EAC2743899994515855B894B66F9B630D8EEC0DB23812850C834611835DBA272043710
                                                      Malicious:false
                                                      Preview:WANACRY!.......d.FRh...@..:.8.}Q.2...Y..fJZ..x.Qd.g...S.@...v..Hh......Q..(r.f..k.....U6@....L.I.a......+yX.......YB`..g....w:[.7...L.O..=.f.G.QA(..{..Mo.p;El.)v...k...,..v...(...#..A...}...o.X.@..L.Lt.c.F.%g......MB...`.BO.k.....(..QB.d.w.....>e.s.v.................[....i.......T.......5......9E...F..J...l..lk..q........U.`...Q$...B..W(..e0...3...H.}21.....6.W..`V...o..1..slvA.l..> VHcH.......}..T"}"..z}G..%V....v..j..IkH.<..>.$..l..s.&.!.O..HX....Ra..qv(R.v..OX..&..y..........d.N..U...^].....iO.d....~......6.o@..d...%../t......F}..\..q..g.jl.....dPY~.f3S.....A.A>...Nv.:-..T.m.H.....M......K.X*....,..r.:.p.....;.wB.....a.O ..{pp..X6+.<"...%@X....,#u~]zq.k@....4.......L....Y(.P......rr..u...6.."...W...b.e...p$....i..TvXHE.7.......m;I.....9..~.Os.X....,.m.3v>O...:q..].?..e.WA.#0..k=....X<3.s..7EOo.....c3..4q>.....|em.N.0...l....h...pS.;Xb...YU6......t.4).H.pyZ.^..Kr.c..|.B..s..0....B.?.....8.N..`J...U=6.z.s.V.[.rWC...n...}..p...t+h.....7...h..-r.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.823908496444819
                                                      Encrypted:false
                                                      SSDEEP:24:5CIQmShcg262+hZUKpEFKyO5sr5O/GlaP8579RS8R:5bQ52/2lE8vy0/G08/S8R
                                                      MD5:3B97D951C920BBC9873E1D586622AEAE
                                                      SHA1:E28D9E983A8268BFE93450EEAA667449FA676DEA
                                                      SHA-256:1A5EA1D287D58D8D7952E89A2620104BFE61B6F3451EC8323818B8D9B1000B75
                                                      SHA-512:B16C32AD67D331174FF7D00666DFC02168876707E174E5D1CF6983FA335D7B02C9E9CDD072CAF72999FB4BE21AE49004DB86FB02344EA0F6F0C996966D6ECAE3
                                                      Malicious:false
                                                      Preview:.RSX......r..]..../_.d.....\..Cx/.K..'d..D..+S7..H....=.z.. ....(6zYO.8...$.".u.:...UN.l`....x.2.........+..!J..O|K..A..v..X.|.#...Y.....pY..E.X{T1Eg..l.q....k.B.$Vv0.yn......gU..U.?.....@1...e.].[.k.h..g`.LGC...*..p>.'...^..I.....).'G.S.M3.f...8OPF6.....p...).E...F..dq.^9...5s..3.d.p.M..I.U.9...>.f.?H..?..gF.....`3.{~...........?.n.p6....JpX.u...6.f`Wt...srh...F(V.{...N.QyY.(i.w..V...&.|.=.@> [.z8...b>....\."...R.7...k..j..0..2b...oP.1..z.~|.}..w.1.E...6.7..i.;e...Kb.>..e.&7I.g/.....V../k..}..?P!..x.....s.....[}.Lp..lP|.}..).>+Z..$?..y..,6.=...:x.\.;...U.......>B..P..Z.c..[s.M|...E.:...E........v...R.x.Q.).....M...< ..........%/O.........i.V......j.{m..Ai.#[.!.......S....^...!..,.*y...d;.2g.....a...D.....a.M..;>(..ZO.k....cIU2.........dH...W.c.>1....[..~..H.....G.pe.W_\.*qn8Ns4.5.=R*p.....Ec..O.e..4.+.....Ea...-U..az.l...@...B..!......_h..C1............2US....../DK.%K.,.....(..~.W..i.<.k^...i........v.....C.....$..q....{...Z.].i.E#.C.i
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.8354680951183235
                                                      Encrypted:false
                                                      SSDEEP:24:bkZzI5UOnTHmL8SBJvNvg0vDxZ3H8ugAW5TKW2+4sI2A5hVR//gUWT5I9rw8bU57:bkZzsUqLmQmvm0vTHgZTasGvhQ2c8bUJ
                                                      MD5:A0B105DA95AA28934E8ADA24E35EC79C
                                                      SHA1:64A6F0A4AA8F7903EC8B2B0DA9578E0E39C9A032
                                                      SHA-256:72B288800CB69FC02E50005477A78A1A0899D89067BA819ECFE106C8076007BF
                                                      SHA-512:AE3D1E8B3A36FC6E2DCE20D22DD3FA8CEEA55BEBF4A3424808A8C59B60DB8F4ACB4C7ECB3A5AF5AF3E0ED6358E9DC2E45ED3DE98D1FC0F6E014A00A71C242318
                                                      Malicious:false
                                                      Preview:WANACRY!....K..uZ.$o.A.B.a...'...3..c.~..(.(5D..f..7zh..m..r..D< ..,o.X...P.WB.../...w.-..=..+....EY.u........wY2Q......9....1.1.....Ptkn0.m9urQ..e.(.....9......q..'M.8.W'.A\sB..#......\.......2...i.........W...':....TI.3-A".o.fW6.L5t..y.....KhK.N'6.i....p...............^E..`|...(Y..."......y.4=..P....Y.....D.A%.......{.b.rH...hI9<E[.&c..=`.O.F(|.M.@-*MyZ...,.E....I7...Wgr.:..,.R.T..o.}[...g@7.4..s..M.o.b...d.<..Pp...<rc,...aa...3.F.&*8gRR.c.....W*...SA..1..q$....tF{!Z$k....rQ.R..8t7r..s&...@/...y.g..z....y-Y3Xiuu.B._.v..3.......[..64..E.g..oS..oJ.5!..e..M]8b\..l....6....!j0Y.dJ..i...E....& jL.W?.k..:7B.a..`..?B.4..-..tl..+.|.._.....S.......4]x..6!1%.Mm.J,..5.b........m..OQ........-...s1........@v...r...kc..^..#0..R.s.4.B..04w6.Gk.......x..,..Rx#Y.aW=P.(.c\r..m............0.,...-...u..*<..U..h.@tD..t...[..d...M.)ge.....8..d....W...[...h..;.Dub.-.....~..WVM......0Q..^..X...HC.....%.......|Ra.e8....WB.6.R....RF.......s..3E.....K^'.m...
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.8354680951183235
                                                      Encrypted:false
                                                      SSDEEP:24:bkZzI5UOnTHmL8SBJvNvg0vDxZ3H8ugAW5TKW2+4sI2A5hVR//gUWT5I9rw8bU57:bkZzsUqLmQmvm0vTHgZTasGvhQ2c8bUJ
                                                      MD5:A0B105DA95AA28934E8ADA24E35EC79C
                                                      SHA1:64A6F0A4AA8F7903EC8B2B0DA9578E0E39C9A032
                                                      SHA-256:72B288800CB69FC02E50005477A78A1A0899D89067BA819ECFE106C8076007BF
                                                      SHA-512:AE3D1E8B3A36FC6E2DCE20D22DD3FA8CEEA55BEBF4A3424808A8C59B60DB8F4ACB4C7ECB3A5AF5AF3E0ED6358E9DC2E45ED3DE98D1FC0F6E014A00A71C242318
                                                      Malicious:false
                                                      Preview:WANACRY!....K..uZ.$o.A.B.a...'...3..c.~..(.(5D..f..7zh..m..r..D< ..,o.X...P.WB.../...w.-..=..+....EY.u........wY2Q......9....1.1.....Ptkn0.m9urQ..e.(.....9......q..'M.8.W'.A\sB..#......\.......2...i.........W...':....TI.3-A".o.fW6.L5t..y.....KhK.N'6.i....p...............^E..`|...(Y..."......y.4=..P....Y.....D.A%.......{.b.rH...hI9<E[.&c..=`.O.F(|.M.@-*MyZ...,.E....I7...Wgr.:..,.R.T..o.}[...g@7.4..s..M.o.b...d.<..Pp...<rc,...aa...3.F.&*8gRR.c.....W*...SA..1..q$....tF{!Z$k....rQ.R..8t7r..s&...@/...y.g..z....y-Y3Xiuu.B._.v..3.......[..64..E.g..oS..oJ.5!..e..M]8b\..l....6....!j0Y.dJ..i...E....& jL.W?.k..:7B.a..`..?B.4..-..tl..+.|.._.....S.......4]x..6!1%.Mm.J,..5.b........m..OQ........-...s1........@v...r...kc..^..#0..R.s.4.B..04w6.Gk.......x..,..Rx#Y.aW=P.(.c\r..m............0.,...-...u..*<..U..h.@tD..t...[..d...M.)ge.....8..d....W...[...h..;.Dub.-.....~..WVM......0Q..^..X...HC.....%.......|Ra.e8....WB.6.R....RF.......s..3E.....K^'.m...
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.773889940063415
                                                      Encrypted:false
                                                      SSDEEP:24:AkwySdtV4XilcPCuDXQKZQkcgGnwBdFKF4Opo9Un:Akg2XqgCuEKn3fJOm9S
                                                      MD5:E27D28D5FCC457C16190A392EB92909D
                                                      SHA1:69AC66CC68790BE52027FB792F48C38BFFC487D2
                                                      SHA-256:CF7FBC0BDE5046CC56B157DDD8EC821121BF3059C521BA4B72F2C649132D27E3
                                                      SHA-512:E92C7ACB1C62C9714B628A445B94E689D9F0EE9D0140C8999E7AAA0EDE067CF3A1075A6A09EE5368444F0A97EA55E9B22CF36AC9615D83CDB8733FC83D57D409
                                                      Malicious:false
                                                      Preview:..r?..<b..k1._.....~Iw.._.m..T.f2\.. .....1./D6?...2.$...uW]d..<0..w)].p.1.....&.rvJq\.........F.^.!..>..+..?B....s......8.H5...=.3..^.../bk9...W@....@jo#..5]....I...4.#...-.....5...v.`.~......$..:..jDA...o.8.2>.93..R.j.....G..C....Y...[.z...p....`........).......x`(..qD*..5I...'.....l.j.9.......c....H..Z..c.0j....V.I.)...n...D5bh...M....1d.-6../.v.o..i/jd.a..t.&..\....c..s.f+u.....c.6^Z..L...R..k?..C.nx..`.e.<`..Djb....^...U.B...q..A..C.....mg.H.zZ....$_..`...x....v..{.U.?Gmk.........I..U.+.#.....d.ig...@./M..57..e..L.C... ..t...gO..{_.L.g...IY%.G.....%...B..|.9....2.&.@a.$.....(..Gl./.g$.P..ph.`g..a.n.."..E...|a7.HNv...6.Q!9.....!.....T{..D....4..)2..b......4..pn-<6.DyI.mj...^<D..Ti...I.s..Mxc..d.....G..2{#+.X_'..*.="..-px..<._.w.#8....:.fAj.C......_..>1.|^.W.4P&.....+L..9..p...;.k.Pg..O.J..VG......X^..cA..>.S.ZM(..lk......$....(...lH.P4...(.mvk...8.D...!...!y..a.s...zh^K..Ok=.~....8{.k...!.8...*.> .?-.k.....P0.>'..6..?G..3.t
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.839329689716738
                                                      Encrypted:false
                                                      SSDEEP:24:bkUh2wNP3HCDO3JXlYDjPgAOpINDIZv4n0uWdxvd2wTHkiqqmGwze0GwSdn:bkU3N/uOZXlKoAO8IdAspFTHkWmGwSPL
                                                      MD5:6B10FEDF63C0E2EC4A75228724443040
                                                      SHA1:396A6EA59A573F0C4AD6D0CBA0A17121E6E6E8BB
                                                      SHA-256:5BCFA00DBD1E51F157B9B499B6A38504CAC9EC7028E192512FF16410C8A6BE4F
                                                      SHA-512:9CDB59D23223B11A91A37881FBDAA463822AC77C5EF97C597FC33958E7577DE9E748288104546E8343BF16C6BAEF2570ADE8240CB5105928EE7E100C11AC4882
                                                      Malicious:false
                                                      Preview:WANACRY!....i4.. f;R...*Jg&Z..8F.R&. <...1.k...a.?.yq...........5O.k./.*uas.".U...*.$.Y3.Jj}A.".y..1/P.....IV..]...6.....,.9?V..U;...s.Wp .d@...{..t.......4%..O.3Li.rk.....-...'?9K/..Bw.1.......OZ...^C...u..#u..C.I]..<.@...H.V.s.g..T.&e..eH......g.i.Q.M'....................X....P'.t!K..^P...n.cJf .........r..=.;..A...-....;.....'.x...=..F.0.u_.a.K=....s..y..n).g!....(.?..=..9..\.R:./... ......qC.7s&..'. ........w.r......)..OJS .......N...h.J.O...k.X......`(h...n...R.9..4..TG...N.....4......Df.Q.axv{#. ..8........@(..v1......s.Wk.-.Qt.m....<...#H.-...0XC..*...F.5..........y.......:3...2....3'..S.g........Cn..%..3....Q..v.].K8%{.......x..9..H.....m.5.K.aGe.......dZ.@#..."....^.=_t.*L..b..QC.....)....Lm..j.:..B..TI.=x..z..).]....8...B..v.....7-4..gL.}.(...E$......Ii..>..aO..k..|....c..Q.t./..b..C...iEP.w.Km......$..B.|D.\.... ?.....J.>.<k^.a!<1)..,........`...._T.~..Kg....e..h.%Y.;.0..yc...|.?C..%.-l.N.x..`.....0.........}.P..OV!F.0M..a..N.pm.g...
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.839329689716738
                                                      Encrypted:false
                                                      SSDEEP:24:bkUh2wNP3HCDO3JXlYDjPgAOpINDIZv4n0uWdxvd2wTHkiqqmGwze0GwSdn:bkU3N/uOZXlKoAO8IdAspFTHkWmGwSPL
                                                      MD5:6B10FEDF63C0E2EC4A75228724443040
                                                      SHA1:396A6EA59A573F0C4AD6D0CBA0A17121E6E6E8BB
                                                      SHA-256:5BCFA00DBD1E51F157B9B499B6A38504CAC9EC7028E192512FF16410C8A6BE4F
                                                      SHA-512:9CDB59D23223B11A91A37881FBDAA463822AC77C5EF97C597FC33958E7577DE9E748288104546E8343BF16C6BAEF2570ADE8240CB5105928EE7E100C11AC4882
                                                      Malicious:false
                                                      Preview:WANACRY!....i4.. f;R...*Jg&Z..8F.R&. <...1.k...a.?.yq...........5O.k./.*uas.".U...*.$.Y3.Jj}A.".y..1/P.....IV..]...6.....,.9?V..U;...s.Wp .d@...{..t.......4%..O.3Li.rk.....-...'?9K/..Bw.1.......OZ...^C...u..#u..C.I]..<.@...H.V.s.g..T.&e..eH......g.i.Q.M'....................X....P'.t!K..^P...n.cJf .........r..=.;..A...-....;.....'.x...=..F.0.u_.a.K=....s..y..n).g!....(.?..=..9..\.R:./... ......qC.7s&..'. ........w.r......)..OJS .......N...h.J.O...k.X......`(h...n...R.9..4..TG...N.....4......Df.Q.axv{#. ..8........@(..v1......s.Wk.-.Qt.m....<...#H.-...0XC..*...F.5..........y.......:3...2....3'..S.g........Cn..%..3....Q..v.].K8%{.......x..9..H.....m.5.K.aGe.......dZ.@#..."....^.=_t.*L..b..QC.....)....Lm..j.:..B..TI.=x..z..).]....8...B..v.....7-4..gL.}.(...E$......Ii..>..aO..k..|....c..Q.t./..b..C...iEP.w.Km......$..B.|D.\.... ?.....J.>.<k^.a!<1)..,........`...._T.~..Kg....e..h.%Y.;.0..yc...|.?C..%.-l.N.x..`.....0.........}.P..OV!F.0M..a..N.pm.g...
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.804804334147068
                                                      Encrypted:false
                                                      SSDEEP:24:XbVPqjNGLB08oLuGX5LNHmV86IH5a2hm6sDv+VbSP0vqR:rojuSPuur16IIV6sDvmbjY
                                                      MD5:FAAB128DDC814C1C34649F9B442CA4A2
                                                      SHA1:E70399894F2ACB51AFAA9BCA5645843FC08BFAC2
                                                      SHA-256:4A759323AFEB3942A65D1D34C0683E7D15C9A5FB5270CA400373E4D7A61312F6
                                                      SHA-512:708E5C7D5576348250625CE0155124F6124C8D9A60DEB671864E94A6B38FBABAB8E9CCBE61AB2C59AABF80629C4608847C67674DD7BD19D231DD0F16A17FE1E5
                                                      Malicious:false
                                                      Preview:.!..c.N..Y....u..I.1.g3.~/>k...........Q..L|.w.+....tV...T.....p...j,.#>...g.....<.1.}zq.{...x..5..@.....3)o...../..~.,......<.id..v..!#..4.UgP+...0+...B2.e..r!.g.(.....-.6...m....;{..'..../....T^.WV..hEA.....b....HW.UQ..P=.&...P..Ahw...V..x^C....Dj..lm.....{E D.a........Yvb....h.;..N7..].......?4.I}.@...G...=..]...*."d....G.....b<I.?......?g.."iq.A../.i7i.'.....g.{&A* "<]...{.K.[..6.$l/...JU.:./.1..l+.X.Z.i.M.......|a.d...U..\.ved..CXT..M...d.....9..........~...(..a.-.t).@....v....Bw.}27.}2..i'...0..3....u.T.Rvc.....F.."=....'k..u@.,.da!l[....>W.D..........8.w...\Ym2..P..7'.n..f...~..!....`.i......=..+3.......n..P.5.2..e....N.3.8.R..vx.;.6..O0GmN..w.g..\..).;...2..9@.6.......9....hL.{[..Y.9..A......bg.)..{(@..?r7...2gn2._iZN.v.O..v.^....K."d*)..W...N.cH..xrU.t.-..Z....I.>...;....G......^...(.!..|C.^v..p...N..V..3..e.m.L>.H..I9...Ng.9.....y..F..u=f....k.Q.la../z4If.8.=.*.9..C1.z$.u....#..wO.R.&n...\.(...;tJ.F..3).m..S!......iI=...v1.).
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.8539860966450465
                                                      Encrypted:false
                                                      SSDEEP:24:bk0GOcbYeTeCPkvxXd+GGIlv4T1PmQm4DeOaZzH9j2yXFdmmP4q5yi0Wf:bk753pG1llwfm4QzdiyXFMmP4q5CWf
                                                      MD5:513E25999A5D52AA8C4B529E8331CE80
                                                      SHA1:7EDE640E753D14894BEF3EE2654A9F13355D18E2
                                                      SHA-256:2F2D01AA27A29A637E142EEDC77060100114F5A57570AAE522CA2DC01414BC0F
                                                      SHA-512:5CE5E6279063496CCDFF37E9BF3DEEF76CBADD23FBDEC9C9DAE95C03C6A77562689A459C3F83151F3A03700478F5D4AB4B01A26ECF449ECD0BB8D3A545079772
                                                      Malicious:false
                                                      Preview:WANACRY!....T.u......4.v...V...7..u.'..s.gD..]..D*......Z.h..2....s..#L..Mq....a..d..P...h...qt...p.@.!..k.,..y...z..g.....%eD(l.(#Y.a...'..I..X....*.`/$.u...G.....,...o....@.~.9.>L....m....Z^...0.......3..Ek....v .KL.GZ+.q.o.....;91dlp......v.Oy...O................N.k..>Q...u...c.`.i....1.>..2>.k.Q..3-ux........%.8|jq<....Y.g.tb.fKE.rh...).yKB....&...t.M..p..*B.c.P.HO...Z..~...c..5dj......e........S.y.w..hcp.n.;...wO...L....Hu.?.B.....y<K6.m.G..p>..{?iy........t..o5oH....v....;&..H....N.+..F.p..j...A........{8..M&zwUs.K....!`3.'.M..f.za.....Vj.!.9.>..>tj.n....hIk.....m.=\..w.<.....O#..5Uz@.g.>e.n[..d.pF....3Qd.....@..!....\.$Xx..DB..).|..*t..../.....O..:....e..9..............@...usP.......?w+.p.ZIc[.x.v..}.&..L...G.i`....";..2.a..>..H.5......_....a...E.`....qA..g......M.|....a....*L...a1Fe=+G/.v.Z..[...l-...B....S.....)Q.........M.y..$.)....k...2..E.^..M.........4...4K.B.....3......Ie.1.E.@.a.8..C.;I..xvG.\.......~.Galr).[....+$.l..bd.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.8539860966450465
                                                      Encrypted:false
                                                      SSDEEP:24:bk0GOcbYeTeCPkvxXd+GGIlv4T1PmQm4DeOaZzH9j2yXFdmmP4q5yi0Wf:bk753pG1llwfm4QzdiyXFMmP4q5CWf
                                                      MD5:513E25999A5D52AA8C4B529E8331CE80
                                                      SHA1:7EDE640E753D14894BEF3EE2654A9F13355D18E2
                                                      SHA-256:2F2D01AA27A29A637E142EEDC77060100114F5A57570AAE522CA2DC01414BC0F
                                                      SHA-512:5CE5E6279063496CCDFF37E9BF3DEEF76CBADD23FBDEC9C9DAE95C03C6A77562689A459C3F83151F3A03700478F5D4AB4B01A26ECF449ECD0BB8D3A545079772
                                                      Malicious:false
                                                      Preview:WANACRY!....T.u......4.v...V...7..u.'..s.gD..]..D*......Z.h..2....s..#L..Mq....a..d..P...h...qt...p.@.!..k.,..y...z..g.....%eD(l.(#Y.a...'..I..X....*.`/$.u...G.....,...o....@.~.9.>L....m....Z^...0.......3..Ek....v .KL.GZ+.q.o.....;91dlp......v.Oy...O................N.k..>Q...u...c.`.i....1.>..2>.k.Q..3-ux........%.8|jq<....Y.g.tb.fKE.rh...).yKB....&...t.M..p..*B.c.P.HO...Z..~...c..5dj......e........S.y.w..hcp.n.;...wO...L....Hu.?.B.....y<K6.m.G..p>..{?iy........t..o5oH....v....;&..H....N.+..F.p..j...A........{8..M&zwUs.K....!`3.'.M..f.za.....Vj.!.9.>..>tj.n....hIk.....m.=\..w.<.....O#..5Uz@.g.>e.n[..d.pF....3Qd.....@..!....\.$Xx..DB..).|..*t..../.....O..:....e..9..............@...usP.......?w+.p.ZIc[.x.v..}.&..L...G.i`....";..2.a..>..H.5......_....a...E.`....qA..g......M.|....a....*L...a1Fe=+G/.v.Z..[...l-...B....S.....)Q.........M.y..$.)....k...2..E.^..M.........4...4K.B.....3......Ie.1.E.@.a.8..C.;I..xvG.\.......~.Galr).[....+$.l..bd.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.8032177404002985
                                                      Encrypted:false
                                                      SSDEEP:24:AAnQ0NyiiTvsKulIIRL/BNdLKGFobTZJjXu/:q0NyiiTvMlIS/BNdLKGFelxu/
                                                      MD5:B57B4C7AEC295D2C851188BBB978970D
                                                      SHA1:A62EC3015E4CFF7E2621FEAC9E48B8FBFBC367F8
                                                      SHA-256:4000FDADA312B5926FA31CD53932C09DA888A0FF54DA4D0448A0E5E1113E1B85
                                                      SHA-512:56727179D5F966D1B0CB0E122E0906B1DE07C3A47262385455B4E89DFA13F3E4E3B7B8246C5D34458B5ADB6281CD87EFA349BC81E5C18A3E4A347B4A0C2C665E
                                                      Malicious:false
                                                      Preview:}.<...:....j....1..D.1..JN.........n....(:Ss#.L`.2....=..m..X..<3...sK*7.E.. G......W.9lUh..n|.x....w..._...s.]F6g.N..i....E.G.R}MK.WU....D.df+...s.p...T.....!e)..,.@.p#?......Z.Q...=KV.K?.C..Mv.#+.Alx..+.gY.........3=......%.y.+F.....<.".h.i...Z..............=....&..b......z.8...f\?&..........V...8......o.J."...s.J.i.5..A..._.-.q$..oz....-.$.L.K...WB.F.d....,(...0....b..T?..........y........&.s..v/u...6.*L.j.v......r3D.Q..n..7w...B.j*<T..}6....{$.8...7.ob.6.M...8...R.....@H"k..3:9.0=2...R!yhb...!."...3<.......T.>S....=E.....tc....}P..<.1...l.6.F.?...g....;ds#...p.2Q.!e......~.Z}d.D.U...RI.S....B.Ah.]qg.k.....{..G.5We.R6....D<..&.iraCq.x....]......n............".w....b.qRo.D..9Z....0.......Y.?...`..U..<~.9C....m..B..)y.*.PD%..... ..S2.0..s..".....!....Z..co..,..-..n..'.A..e..I..)&K..K. .........W....p.$.1Qc./.@...a.Ni.....'..%.)..9~b....yg{7.&Yej.@......_>&,o/uXJ.V......|L.g....muN..L6(..:..8..f..,.~.........R.o..a.p.=...D..4'(..
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.849887362174416
                                                      Encrypted:false
                                                      SSDEEP:24:bk3jJoCDDnVKex0nV0PTvBehOtalTqgFM3AKA5zB3eMnj9ckEDe:bk3bDrwe2nirBehMaZTM3AK9uj96De
                                                      MD5:7B8C4D5F292F54695B6F71AF444B8D61
                                                      SHA1:040F53F5F7809F593A7978452552D6FD4958B737
                                                      SHA-256:E836E9C2849A3A20A47EF41691A304B877C88A4B6CD1ADC8DA39BC52B1EF934E
                                                      SHA-512:16A4962E7FC906D98463E53A35CF4DE9525F33535BEC037727DA4D76E4A2371DE6D211F7FD8F0F3159C2C843893BE9D72B6E26F0F92EBFFAD046417087E69D3D
                                                      Malicious:false
                                                      Preview:WANACRY!.....}...k......`..JU.......8X.jW..+..,)..d."..\|....8....:.6..$._77....s.e...}..g......Tw?D......9z^n#.s?................7K..Z....E.4....k.M}t..f..zS.K.H..iw..2. ...=....C"V .........V(.J.8..e.[:..G>n........['n9.".....'*..$?.D..x.G6.o.<{.2..:E................`...... =....T..B.ru>.V4...o....l>y.A.........\..#4....:C#...@e...0A...s%.X.%.I.{...P.NF..?..#a.4.Z..}s..o.PY.w@(.#..x....5.|..Z.._.`p...b...!.!>i.m,./{3M6..4.0HA....L2BC`6.......C..4c>G...:.l.b...%T..>....mg2gH8.@j..X.G.5k...".4/.m..y..?....5.(..!s&ef..0..m.....t./Ky..S51.."8.7...w..,....#..c....)ec2O.;K..g.......-.b....&!.....Q. .TV:.}F......3|b...AZ.....)Rd]J....AF.C...'.D.U.r..}. .E...j.2..[..k.....e.J..T...u.|.!9..T#a..-.x...4e.5..QE]..q(....{.3.u..eU...g.v....$.I......-..:...........lD..=.....=}u.^.~.l....-*...pcT...63....A.>....2..*.fh.ro._.q),W,.HX.?.....W.sI)XP........vN.. }...Ewq__..g...`I.B?.x.!N......$...H..G`,...^.<..z.wm..t..i..6..L^59S...6'...+..NN..r."HO`Q.~..{ u
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.849887362174416
                                                      Encrypted:false
                                                      SSDEEP:24:bk3jJoCDDnVKex0nV0PTvBehOtalTqgFM3AKA5zB3eMnj9ckEDe:bk3bDrwe2nirBehMaZTM3AK9uj96De
                                                      MD5:7B8C4D5F292F54695B6F71AF444B8D61
                                                      SHA1:040F53F5F7809F593A7978452552D6FD4958B737
                                                      SHA-256:E836E9C2849A3A20A47EF41691A304B877C88A4B6CD1ADC8DA39BC52B1EF934E
                                                      SHA-512:16A4962E7FC906D98463E53A35CF4DE9525F33535BEC037727DA4D76E4A2371DE6D211F7FD8F0F3159C2C843893BE9D72B6E26F0F92EBFFAD046417087E69D3D
                                                      Malicious:false
                                                      Preview:WANACRY!.....}...k......`..JU.......8X.jW..+..,)..d."..\|....8....:.6..$._77....s.e...}..g......Tw?D......9z^n#.s?................7K..Z....E.4....k.M}t..f..zS.K.H..iw..2. ...=....C"V .........V(.J.8..e.[:..G>n........['n9.".....'*..$?.D..x.G6.o.<{.2..:E................`...... =....T..B.ru>.V4...o....l>y.A.........\..#4....:C#...@e...0A...s%.X.%.I.{...P.NF..?..#a.4.Z..}s..o.PY.w@(.#..x....5.|..Z.._.`p...b...!.!>i.m,./{3M6..4.0HA....L2BC`6.......C..4c>G...:.l.b...%T..>....mg2gH8.@j..X.G.5k...".4/.m..y..?....5.(..!s&ef..0..m.....t./Ky..S51.."8.7...w..,....#..c....)ec2O.;K..g.......-.b....&!.....Q. .TV:.}F......3|b...AZ.....)Rd]J....AF.C...'.D.U.r..}. .E...j.2..[..k.....e.J..T...u.|.!9..T#a..-.x...4e.5..QE]..q(....{.3.u..eU...g.v....$.I......-..:...........lD..=.....=}u.^.~.l....-*...pcT...63....A.>....2..*.fh.ro._.q),W,.HX.?.....W.sI)XP........vN.. }...Ewq__..g...`I.B?.x.!N......$...H..G`,...^.<..z.wm..t..i..6..L^59S...6'...+..NN..r."HO`Q.~..{ u
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.785246700432138
                                                      Encrypted:false
                                                      SSDEEP:24:jiDY/POPtsHkCvXixlsXjg9fRVXu9k8rIEbb1QUcmwEIm6F0p6kn:kIepCvGP6kIxbpchW
                                                      MD5:E71956F263F0BC91D7181CD9BECD305C
                                                      SHA1:9E2BB402305B2188196D1DEB6C37F417BEFD80E9
                                                      SHA-256:8264EF99BA1D5932600E0FE6CCCD56112FF85E9A090615402C0B90E4F2C915EA
                                                      SHA-512:E4B40ADACC10316CB4C99759AF33523C1C39AAA3AACDABC4023077E0030EBDA76E17C80A81F76C4AF90785D9028FEEFBF53E10C3C5F076ED229DF87BBBBE430F
                                                      Malicious:false
                                                      Preview:X.W....;.qt....K.....%t......%./....wRm.....[8..}rH....8....D.,.n?.U.9;..N..`..\.N.M.........:.H...A).....,.)>..<J..v...}%r..>.P@..\.....0.v...[E....LF.hi.!.0..FC..H.Ib.I.4nv%.&.A.W<K.%.d.K\.....[+...(.........Pi.v...MB...K^#.W......5....C..4..s.NN..bm........@...w5.zo[S.....j..6;;0.d...iR.....N.....P.o0....wB..:x...5g....nZ..X.%....W.[.kdD...A.... ...>q..'0.Ct.%..Gh..h.4...v....)....w.".n......I..zX...H..+.'<..\..EI..>....&?..~..}..(#.f..C}.[..|.(u...^......nQ.....q.b....@.d....B....c@.N.....O..[d/\yv.P....?#,..V&6.#..5.iA..=..5...5!.;$Ap...|...L}.Z{g..,.Zydlv...sh.J..G>.....z..,8.R%H.i.).R..b..{.'.w.+}.m....j.......R.*.6.w.z.b.2.l..,.dy.h...."2..@..d8...2.%.]v.Q...,b...9.+O..5.I.=+7.V...,#4i..X.W@l...5T....|../.%.R.[|..XM....I....].g.....;A.`...iP1f.R.b.M9.F..[.PR .(....Zz\.`....R..+.{l.["...../B..6...8.5.1..I#....0.OP.-...F)....^.|X..(].i.W.>.$.K.`..".u.$..sY.M....2ms.GLk............t.........HY...i.0.^..;S....I...........!x..m....^.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.839065787848235
                                                      Encrypted:false
                                                      SSDEEP:24:bkZy8S75TwGeVqQoR6FLrm1x4QtAlHfVd8vNkvSbDv2Sa3+TYl8S8cHCWo7w1g:bkZy8S7jeVV46RMx4QytVd82vSbXRTso
                                                      MD5:CDB43B9C12F8B2893314AA03F35A61F7
                                                      SHA1:4874C9EE51CC7FD26E23858575CA4A5191C2CF92
                                                      SHA-256:8A10C061AD56529A904E97CECEA15795228C1454DCEC1851F4E7EFE4B3AB166E
                                                      SHA-512:F77968B3F363FD4C291062A2C4DDF8108750BE23856013D38B7F14930E9658B14E0920E3CA6D49B2EE2F347B45BA446CD5CD7C150807C802E780136056D2ECB2
                                                      Malicious:false
                                                      Preview:WANACRY!............Y...u.rs_...TuI.6.m..u..'.Co]w...."...H._.9...&>D..X..V.[...!...-..gA..._....f..S.(>..0RM..4hu..(h.Q..G.(U7].Q.{$..*.....fBk........\}.Eg...]....!..^..=..>...\......ltA.....`..om.x...9I.A.......*..i..9.Gd|q.X.....&k].).vk.Sf...B.F|.............'.<...h....N8v..%...*..G..Nq.7.N........&.~..o.].#...ge?.......E.R./.yt^.v...2....1......6-..,.C..e.:...HQ]n.L.....~....ecU9MqX....f~.G-........e..q...h..%.`..$&?.^.H.+G..V>..........Q,..@A..|..-\...y.ab...dq.!|y..|e...4........s.}..w.{.2.*.~...P7..P..u...M.<..%a)ysy.u.\.LT..#.Hv..2(/..x.AGJ..`x.....*.ku..T.j 2.U.b)Z......C....G.q....l.@.=.o'8..x/l8.s..-..E...x.....2v.O..O....3z1\...a..F_.<..*...OM.d....R-f..'.X..J._.F..j.^.....t<..L;..q.H........tiKI.~3.aKH..$mO,q..`".4....Z....7.........@.=Td........b.7...0'.{.ihm"...[K.3...8.u...3V..Wm. i...|....ow..(k.vS'[...cb...9....."I.....oE........~G..U!%......2..*}.5..O..]..A..N.+jIy..Wgq]@co.A..b..&..=.w.k.`0v$..~..Q.KRo...j.{.m*
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.839065787848235
                                                      Encrypted:false
                                                      SSDEEP:24:bkZy8S75TwGeVqQoR6FLrm1x4QtAlHfVd8vNkvSbDv2Sa3+TYl8S8cHCWo7w1g:bkZy8S7jeVV46RMx4QytVd82vSbXRTso
                                                      MD5:CDB43B9C12F8B2893314AA03F35A61F7
                                                      SHA1:4874C9EE51CC7FD26E23858575CA4A5191C2CF92
                                                      SHA-256:8A10C061AD56529A904E97CECEA15795228C1454DCEC1851F4E7EFE4B3AB166E
                                                      SHA-512:F77968B3F363FD4C291062A2C4DDF8108750BE23856013D38B7F14930E9658B14E0920E3CA6D49B2EE2F347B45BA446CD5CD7C150807C802E780136056D2ECB2
                                                      Malicious:false
                                                      Preview:WANACRY!............Y...u.rs_...TuI.6.m..u..'.Co]w...."...H._.9...&>D..X..V.[...!...-..gA..._....f..S.(>..0RM..4hu..(h.Q..G.(U7].Q.{$..*.....fBk........\}.Eg...]....!..^..=..>...\......ltA.....`..om.x...9I.A.......*..i..9.Gd|q.X.....&k].).vk.Sf...B.F|.............'.<...h....N8v..%...*..G..Nq.7.N........&.~..o.].#...ge?.......E.R./.yt^.v...2....1......6-..,.C..e.:...HQ]n.L.....~....ecU9MqX....f~.G-........e..q...h..%.`..$&?.^.H.+G..V>..........Q,..@A..|..-\...y.ab...dq.!|y..|e...4........s.}..w.{.2.*.~...P7..P..u...M.<..%a)ysy.u.\.LT..#.Hv..2(/..x.AGJ..`x.....*.ku..T.j 2.U.b)Z......C....G.q....l.@.=.o'8..x/l8.s..-..E...x.....2v.O..O....3z1\...a..F_.<..*...OM.d....R-f..'.X..J._.F..j.^.....t<..L;..q.H........tiKI.~3.aKH..$mO,q..`".4....Z....7.........@.=Td........b.7...0'.{.ihm"...[K.3...8.u...3V..Wm. i...|....ow..(k.vS'[...cb...9....."I.....oE........~G..U!%......2..*}.5..O..]..A..N.+jIy..Wgq]@co.A..b..&..=.w.k.`0v$..~..Q.KRo...j.{.m*
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.813825101052696
                                                      Encrypted:false
                                                      SSDEEP:24:wDCrJprPIeqfWFlLakD7Dp8VwcivExPXI3l/SR3dZiKsn0:DJBAHfIhakaVvYe33d4X0
                                                      MD5:18B40D2FE8E5F6EF602863A3DC5DAACB
                                                      SHA1:A189DCAC821A52D3F0DA6F32CAA07AAE4D550AB6
                                                      SHA-256:44CCD51A69F1AA5E99F9FD5FA366D41A176EC9F64E210C1EEC8A78962E85D5A6
                                                      SHA-512:D4DDAD791A2B80C510DB1B0C1A7DE2E9F0F43343D7FFDBD507EDE3F282B4DFCB88079452D051CE87242B18C84822C361E65BAFB20ABD9AD8C08DC1C1C1BFD431
                                                      Malicious:false
                                                      Preview:..S...X..SQ.V:j.l._..,..A.&s...Zx.#U{...M.b.b0.../|....!'.>...Z>...s.....opI.i+K.H.+".;..-..F.Dsl+....U..i.1.S %..^.3L07.k....)r.1...hB..U..>.m...>..6z....R.. ..'..W..="...r|d.0.`..Q.Ij.Q2.b...Z<.@l..u.3....f.9bh.^..*/.....G..`.k.n.i}U.8....d.......6_..4Q..p...Xs.(...#..=Y.twA=.F.VL...y~..t...S..J.r.y-5....c...+.\...v.W$....b..W.m.A'5B...P'.....C.|...O3J<.o....m.`r.U..\...G0.s.....-.`..]>..}.GC....."G..(^VI3.rB8e.c...5..`.9.4;.g..3A....m..V.q*..6.....*...%nw@;..........>......~../|^./J...#.Yi...`...s....E._u..>......:.G.Z)?.,.yDX..=...A......Dv........g...a..8X%...Z.T.........h.b.oID.....T....}..: ..\..^q..d..i.0..*.....G....gat./....:.&..,...t..nr.HU.Q.b.;3"...&..Y.i..%6.io.._.<+....!_M..N.E.V..:7.....UtT.@....[@...h.k: 9.c.w.e.7......Z.?...I"..9.,.....4.....VW.....p.....I}@y..0..&Y.<.^.S..Bg.s.Z...H.C.:.p....L3e.%....L....?.I.........-_..m...>.a.?..f.........T....\...*...`x,.....^:....ME....Hj...@.Hz.JjC5...kM.Z.C6[@4 .mYb.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.848523285523644
                                                      Encrypted:false
                                                      SSDEEP:24:bkqFjQ3l2jm4xZr9siHxG6vV60Z0ikxr/d/2/t0HooAy:bkqFjtS4N7I0iiKjIt0HooR
                                                      MD5:3FDFD74BF55949952EC70F57888845CE
                                                      SHA1:5BDB43B60BF6F9DB2E5175AF86EBB05BE7DA4790
                                                      SHA-256:B93E1B3B86CC975FA70BB479991D8B271A42E3889BB410B3BD3D761ADE4B1C72
                                                      SHA-512:814DAC091EC2B8247C6C96CA30C3C08CAD8A06E5224CB70C1D370E829E06EF329E73AD9975B6AE869F7BC847E626C4F8FF8E2B31A3E65B1CBBE58299D2F5C696
                                                      Malicious:false
                                                      Preview:WANACRY!....U.P.b.F.+QYI.N>IO..v....u],D...[..h..Al......A.H.X........ {.#..)...X'.......~.Ve..0..WA...:..].?.QB..2...e...;.-#....s..h...S.=..dm.z...F(..+;X.W.^X...0MU.:`......0..-#.@?:.$M.O.`.].\#...8!.tY.|....8.o.(..!..x...L.\.O...l...`....;.os4.t.............x+...."...m.P....M2.4m...Gne.(.S&.uZ.^.....h....@..<S.=.KU9R!...|.......$.~r..F..."r{..DU.c0+...x...m....\.n....X..<.".B..j.G`........y.x.qB..D....gRQ........"[..+.9..j....y......k.R..S.'..!=S..{....$W......r;;k....zqw......J@...2:..r.LH....Vq..}..4.....i..!.._f....)a/..I.~.....dj.d...9.XE.R....Pa.&....xF..-F.c.P.$.'....._.C..i..S...|..O...Fa.c.K.`|U....C8..k.2g...T.F.}'..bu...Ij.e......Y.l.@..,...za......s.9:.B..;.h...o........Lc..2.kQ.]......@?\...$...fRn.$......8.HY.....$..X....~w0....j..M*.<1Ok......mz!./.}.dP.f...M...E.t|4..!T...U.C....<...G..[...N..-3.1....),..,...iu.S.*...Rj.P....2...t.g.......^..$.F.3..sx....Zjd'......F.W.....q5...V.\1...C..kG.y.~9....}E."`O...2..N%..v.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.848523285523644
                                                      Encrypted:false
                                                      SSDEEP:24:bkqFjQ3l2jm4xZr9siHxG6vV60Z0ikxr/d/2/t0HooAy:bkqFjtS4N7I0iiKjIt0HooR
                                                      MD5:3FDFD74BF55949952EC70F57888845CE
                                                      SHA1:5BDB43B60BF6F9DB2E5175AF86EBB05BE7DA4790
                                                      SHA-256:B93E1B3B86CC975FA70BB479991D8B271A42E3889BB410B3BD3D761ADE4B1C72
                                                      SHA-512:814DAC091EC2B8247C6C96CA30C3C08CAD8A06E5224CB70C1D370E829E06EF329E73AD9975B6AE869F7BC847E626C4F8FF8E2B31A3E65B1CBBE58299D2F5C696
                                                      Malicious:false
                                                      Preview:WANACRY!....U.P.b.F.+QYI.N>IO..v....u],D...[..h..Al......A.H.X........ {.#..)...X'.......~.Ve..0..WA...:..].?.QB..2...e...;.-#....s..h...S.=..dm.z...F(..+;X.W.^X...0MU.:`......0..-#.@?:.$M.O.`.].\#...8!.tY.|....8.o.(..!..x...L.\.O...l...`....;.os4.t.............x+...."...m.P....M2.4m...Gne.(.S&.uZ.^.....h....@..<S.=.KU9R!...|.......$.~r..F..."r{..DU.c0+...x...m....\.n....X..<.".B..j.G`........y.x.qB..D....gRQ........"[..+.9..j....y......k.R..S.'..!=S..{....$W......r;;k....zqw......J@...2:..r.LH....Vq..}..4.....i..!.._f....)a/..I.~.....dj.d...9.XE.R....Pa.&....xF..-F.c.P.$.'....._.C..i..S...|..O...Fa.c.K.`|U....C8..k.2g...T.F.}'..bu...Ij.e......Y.l.@..,...za......s.9:.B..;.h...o........Lc..2.kQ.]......@?\...$...fRn.$......8.HY.....$..X....~w0....j..M*.<1Ok......mz!./.}.dP.f...M...E.t|4..!T...U.C....<...G..[...N..-3.1....),..,...iu.S.*...Rj.P....2...t.g.......^..$.F.3..sx....Zjd'......F.W.....q5...V.\1...C..kG.y.~9....}E."`O...2..N%..v.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.809466313058323
                                                      Encrypted:false
                                                      SSDEEP:24:dw8rMr9EyiXeihVWSUegYUy9HJyKKyDdAHx3g+z+03:dhgCyY/hVVdzrJgyDdARw+q03
                                                      MD5:DF1E5D381F726692D57994EEB9C80815
                                                      SHA1:E15B43D30789F4071B211BCD3E1B82CB1964371C
                                                      SHA-256:A47CD508D39E9A1348BE9CC445FAE39950AE37118285266B59DBB098F03329D7
                                                      SHA-512:196F65C9239D8F13825311EA7E30DFFC7B15231898855794CD9649BF204AD4BE529828238C40D4631404E36B2999AD05BEEE51757D45BEFD7CCE9F5BEA77B6B7
                                                      Malicious:false
                                                      Preview:..j.23.N.q..@.E.h .p`...=t.g.F4z..2..G)7+.....].H....V\.8._Nt2n.B.^.#......+.d.?............C..(......<.'..=..Q8Mj*.S..S.xBUB..!.|(..r.|....S...Yk.5....%E.w=..|.x..$pR..<q.-R.e....stC....N....<..?9...y..[.......Mc.S.e.@...W..]t.q...M^$.._..;..B...?N.d.D9+.O..ke.I...<S.WA=6s>....1E.tfNa.8...U.o.U-...4&V.....y...5RL......w%.........%.#.....5X.Kr:.d.....s..............;.Bv.W=[C......F.....?...a....mz.........i.m.)...5.m........a9m..<..Pd.!.;..8............w...2.M)..s.2/.{Wg....H.jI>.h.a..M.^. ......K....84X.u.xF..Ahy.Av.~..*x...Pc.P.......\..9K)..O.......*L.p.9~...w.=1.:y..M.5C..y#.K..JSg1&.&TLh!.Z4m....%......h..17..0)..I.....H=_.}......L....a.%.P.}.7t.&XuoC... ..B...0|..t~....M..8*.-.c-.".UD@.lK........4.^.A.5lr..'n....v[Z....o.<.....@...s.~......Q.. ... $.......V.....ve.9>R.b..2.M...$GfU..+..aU.A.h.7TV....T...7..L..n...j...=..1(.J...#Wb...XQn.3...'.5-.i.j.d.g.._....+8.Y5.h.V..f...m..T..=.t..eZ...i.m`..;......R.7C=.D.M....H7...4.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.853050977181506
                                                      Encrypted:false
                                                      SSDEEP:24:bkqM9pAheuEUJr3+Bl76IdBIgMFOxNh02lNjvSbGbuPrJqMlCipdWYp1S:bkrpAheuPBUxdBZMFUNHNjxbuYMlbpdE
                                                      MD5:476000D29D538C03DEC2757D7A05F9CD
                                                      SHA1:6E56B27D7BAE0225828EDBFF9118CF11A5B35215
                                                      SHA-256:9534C13D3354244DC876FF17855E813A978544150E548C634EF0A530CF054C5F
                                                      SHA-512:A192DB1262353F605E4FC12E3FB26FA9B63CFD6E66150979A12FF76BDDEFD34EFD3F7D1CD47126B51FC6BE642273664227501C01E5C16A43DB237B26A54AF1A5
                                                      Malicious:false
                                                      Preview:WANACRY!.....|...." .Ec....j....q.<G...`.U.D.R...............f..8....2...8._H.........E.|.x.sf.e..'l.9.....Z..[Z.;....@....."...}..`.to.'gU\.Q..._k%.?....m...Y.d....%...-.*.g.75.f...$....MZ7.....W.)...0.>.A.CWH...cb...x.Za.L..,,.....u_.H.....4.i.w&..............+.8.;.B_.....v..........B..B....u...d.#..@..@..|}1...X......@J........r...].8./^...(o].=l.r>.8..x........SE'd.;...h...d.[._......3+...ZJi.k..Jq0`j.O...K...z....ti..5.t...wR.(6....f.I...'.?l....t... .m....I.Nw..6$H ...X+).Sz..Yf.@.xQ>.d.|.....H.%n...Y.....I.E.{>.@...4.*q.H~..w.I.}.Oek.l.......W..Wc....0t.Lh.|C}.0......b.|O<.....Z..UU.E*.<.....k..|.Nx...v]...Y96.......m...>y.D.....c.".nL...P|0..J.B.5X...m....]..@T..P~..a.J.C.D...n&.x1M.....<.^..#.4........8.HA<'...U.2.:.I..3..'.-...E."...3...{....~S......{.WB..F.....Qt.N....L.wf[......[.)....^s....y.0.......-.D|..f...*.Y..4[.7.W..ov.-L...!E.9$....w.P.Y*..'x.?...@.]....5G....-.l4.i..D.K..'.....2.y.....T...x....X.217E..R....k..
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.853050977181506
                                                      Encrypted:false
                                                      SSDEEP:24:bkqM9pAheuEUJr3+Bl76IdBIgMFOxNh02lNjvSbGbuPrJqMlCipdWYp1S:bkrpAheuPBUxdBZMFUNHNjxbuYMlbpdE
                                                      MD5:476000D29D538C03DEC2757D7A05F9CD
                                                      SHA1:6E56B27D7BAE0225828EDBFF9118CF11A5B35215
                                                      SHA-256:9534C13D3354244DC876FF17855E813A978544150E548C634EF0A530CF054C5F
                                                      SHA-512:A192DB1262353F605E4FC12E3FB26FA9B63CFD6E66150979A12FF76BDDEFD34EFD3F7D1CD47126B51FC6BE642273664227501C01E5C16A43DB237B26A54AF1A5
                                                      Malicious:false
                                                      Preview:WANACRY!.....|...." .Ec....j....q.<G...`.U.D.R...............f..8....2...8._H.........E.|.x.sf.e..'l.9.....Z..[Z.;....@....."...}..`.to.'gU\.Q..._k%.?....m...Y.d....%...-.*.g.75.f...$....MZ7.....W.)...0.>.A.CWH...cb...x.Za.L..,,.....u_.H.....4.i.w&..............+.8.;.B_.....v..........B..B....u...d.#..@..@..|}1...X......@J........r...].8./^...(o].=l.r>.8..x........SE'd.;...h...d.[._......3+...ZJi.k..Jq0`j.O...K...z....ti..5.t...wR.(6....f.I...'.?l....t... .m....I.Nw..6$H ...X+).Sz..Yf.@.xQ>.d.|.....H.%n...Y.....I.E.{>.@...4.*q.H~..w.I.}.Oek.l.......W..Wc....0t.Lh.|C}.0......b.|O<.....Z..UU.E*.<.....k..|.Nx...v]...Y96.......m...>y.D.....c.".nL...P|0..J.B.5X...m....]..@T..P~..a.J.C.D...n&.x1M.....<.^..#.4........8.HA<'...U.2.:.I..3..'.-...E."...3...{....~S......{.WB..F.....Qt.N....L.wf[......[.)....^s....y.0.......-.D|..f...*.Y..4[.7.W..ov.-L...!E.9$....w.P.Y*..'x.?...@.]....5G....-.l4.i..D.K..'.....2.y.....T...x....X.217E..R....k..
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.829709307895732
                                                      Encrypted:false
                                                      SSDEEP:24:zLQyMhZnIXAD/BRH3MEiOrCPR2Dhq/o181l7hy:YyMhBIXAjrH3MEDPDhEo2Jy
                                                      MD5:02F127E61A05EE629049225BB9250652
                                                      SHA1:62913336AC3683FC1A6B5F751630BF4B8A3DB342
                                                      SHA-256:E8CC00847B8560E8F2A76079054E253F6BD0B1469B6F49C91C78901BE4E50E42
                                                      SHA-512:40D7E2E6812C1F5E3088A7468092505E554FE6CFF35D2DB3C2FAA0EDA5276C98CAF031B5783B77E8E0B8E483683CC35418EF906F26D6A4A75B211C0609BB299C
                                                      Malicious:false
                                                      Preview:.-....<D.N2.r.N;...*..8.|...l....pBn.4g."}....q...>v../.ir3..@..&\2..0_..?jf8.1n....V....K...H.q.h-&,lc]...C^.../.x.OnwW-a.g(."...8...e.....c9...<.S13.^X}CB........{.M...R.........Z5..x#5&..=..m.&..1......RE...ma..Z...U.W...".z~XC..)m..j.oD.......)b...l.`.+.pF...F.7..(*...%.J.?..l..K..'..#57X.....mN.H..%...._.#...&M..-+w..........4...AhfS.JS^5Y}.E.+@t...r...p...*@?.....N.<.H.#.?V..r...G..Y.|...~{05}!J.|.}z.b......p.".6_!7..`c..]../'.>6;hS....0..cds*.X#Y|....K.x....L.b....o...B.m..y.......a.CZ.p......._'y;.R.E.5..T./.a.[v.+#T7iR.2.k /..t.K....<R'G.....~1.....a...<u..v..x..\A3.FC...~ ..?@GG.`0Z%...Hm....}'oQ......\.Q..Q....5./)u.M..{.E..R.Y..&......]`..W?........)t...;.P.DF.W.pk...8..f.:..q.J.}...Oq...~....u.wZ..lut..@.?....H.7...,...........Y.QKsoZ|..%.b..^..@\..H..........w..`...`.....d....I..\.I&..w.~.F....3.~.(.U.#... ....k.><...X R.;......CF...H..8.#...Jm.?....:.Z..RW.D....L...'..a....+.qrz.e........)e.QZ.PxW0......{........^...
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.844805951840964
                                                      Encrypted:false
                                                      SSDEEP:24:bkQ1W2JnFIHZLttP1gucV2bdzuF+DqtRe7s7C9adpJBBuAyJfwOmvNe4Lp6mZQ/x:bkQ0fLX9gu5dePRTGOO4p6mYyI
                                                      MD5:4588D326BDF96AEA73D92B2D9BB14DFE
                                                      SHA1:02407BAF867DA553720ABCF6D6DACF7A102CCEE4
                                                      SHA-256:0083828C705F989BC28DDC6D2683FF6F9A70139845DB8B65A90EFF20A0306D10
                                                      SHA-512:7EEFDFF107D3865C1D4568A5ACF15D81307255E52D3B4D49D76108719CED2E013022771CAFA90C691E161A83380922D45FE2AF501074895F98D933F1C4E6389B
                                                      Malicious:false
                                                      Preview:WANACRY!........i/...6...3...!U..lGb.J..hC..2n...Pt.3...qp$.p,.h^5.#F4..0.eJ......m..*@..?E....q..i..5...?..LC...V-..".......Sp..u.%..h .6;U..K....s..2w...OS..O.MT...yE4......w.!..a...%w.....M.....0...A..G/.,^t,p.k..]..{.....V\#vY.t.P4"X.#...=.!....,..Cd...............3\|.hr.....3.{.M.GX.x}...^.n....M..R..Ww{.`I>.){>@g.*~, ..,.K.>..+>...?.g....>.|3v9..GC....l\x.nN^.......%u.Lm..H.)@..h.....*... .jz.1$.^.o.b..Q.(....1.O..^;.M..F.T...p. ....7.j.[.7.D.........G..S.y.!.u9......[@.(..)....}...\|o.....NP...~.{.P......-k\Vk.....,.g.POgb.s.*..r(=.L.!...@5i=E.\N$...}.."...s..7O../..@.;..M...s.6..f..h..04,N..^..fKiV....`.O.. -]9.k'.\Y}z|...^.\..O....m#.j.^g.=.-2....7...~t.g.).+r(.d.*..A#.r.q1\J.26...?......B.:z.Ck...,.G....$$..b..Z."5.;.{zc.>.......`.&....=..zmO.....:.Y.."8Q.....no.%@t....wDm...0......Yy...o.1....>m{.n...H./...!*>f....(..E.......~Z...%iy.5.o...|K."b-.........4....!..z.g.w..F.-Q...qO.O.....5.......p_...By.......7..Q].l.*....Y.?......
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.844805951840964
                                                      Encrypted:false
                                                      SSDEEP:24:bkQ1W2JnFIHZLttP1gucV2bdzuF+DqtRe7s7C9adpJBBuAyJfwOmvNe4Lp6mZQ/x:bkQ0fLX9gu5dePRTGOO4p6mYyI
                                                      MD5:4588D326BDF96AEA73D92B2D9BB14DFE
                                                      SHA1:02407BAF867DA553720ABCF6D6DACF7A102CCEE4
                                                      SHA-256:0083828C705F989BC28DDC6D2683FF6F9A70139845DB8B65A90EFF20A0306D10
                                                      SHA-512:7EEFDFF107D3865C1D4568A5ACF15D81307255E52D3B4D49D76108719CED2E013022771CAFA90C691E161A83380922D45FE2AF501074895F98D933F1C4E6389B
                                                      Malicious:false
                                                      Preview:WANACRY!........i/...6...3...!U..lGb.J..hC..2n...Pt.3...qp$.p,.h^5.#F4..0.eJ......m..*@..?E....q..i..5...?..LC...V-..".......Sp..u.%..h .6;U..K....s..2w...OS..O.MT...yE4......w.!..a...%w.....M.....0...A..G/.,^t,p.k..]..{.....V\#vY.t.P4"X.#...=.!....,..Cd...............3\|.hr.....3.{.M.GX.x}...^.n....M..R..Ww{.`I>.){>@g.*~, ..,.K.>..+>...?.g....>.|3v9..GC....l\x.nN^.......%u.Lm..H.)@..h.....*... .jz.1$.^.o.b..Q.(....1.O..^;.M..F.T...p. ....7.j.[.7.D.........G..S.y.!.u9......[@.(..)....}...\|o.....NP...~.{.P......-k\Vk.....,.g.POgb.s.*..r(=.L.!...@5i=E.\N$...}.."...s..7O../..@.;..M...s.6..f..h..04,N..^..fKiV....`.O.. -]9.k'.\Y}z|...^.\..O....m#.j.^g.=.-2....7...~t.g.).+r(.d.*..A#.r.q1\J.26...?......B.:z.Ck...,.G....$$..b..Z."5.;.{zc.>.......`.&....=..zmO.....:.Y.."8Q.....no.%@t....wDm...0......Yy...o.1....>m{.n...H./...!*>f....(..E.......~Z...%iy.5.o...|K."b-.........4....!..z.g.w..F.-Q...qO.O.....5.......p_...By.......7..Q].l.*....Y.?......
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.783786989643977
                                                      Encrypted:false
                                                      SSDEEP:24:cqDrmMrzFd0n/C/Mph4c2rukVlJikfkATIOPYgsgPAq6oid:cC5ld0n0M8Brli4ggPRWd
                                                      MD5:4BB5BA5FBC69B2F6C5E97AE9A1DFDFA7
                                                      SHA1:D0E93CBA72058A3AB420F8FBE5002353C8CD37CC
                                                      SHA-256:BC915666C81CBD4C712DFEA929F1E79E8422E6E1F0C2382A46B61B6C5D01EFEB
                                                      SHA-512:7BFCB63DE35BC0829E1006425985A6ED37CCEDED88067349B4F3FFCAB72A65790905150A1088BA275CACD1943B54B7B395B8485083F347F662AA3ECAFAE6B7F4
                                                      Malicious:false
                                                      Preview:.:Xp<....9T..Z=...n..../.%F$....n.0...&5..I3P15>$.....A...l..c..gKZ.4..%Qc.gQ....e..~xW.H.W.....3.q.o{0..#........S...=.p....".J..}...s...h.Q..........S8.(9..%....F.Q{.~~.T....k....9.gQ#.P...S.....+.baX..6R%.CQy..R#v.v%s<..z..B..../.!Q.^a...X:h.A.........A%?.9...?$g..2K.,..X.U..>...............c&.......ny.OP.l.QT....:1].2B.%.....3c.'W(gC$...%.~..6.......2..cK.,c..N.N.....s..x...n..-..=).M$FD....81..Z...R6.....h..7..@7q....m.8....WL.$....i..Qs.+.2N .R.8).~.!..f.N.....j.;......6...[.....C..:....Ph4D.....,i.nD....$...CD.5R.....g.)..,[......IC...\....y $.*' .......i.V...)/...r..Y.=..B...O%...[.v....`|./:.....?@.k...6..."j.fzwq..E....,<v....( ..-El.......).......Dai..w~_.v`;.@.b..P.Am......9.HW1...Ji~...bh.../...5....1.AHQ5...y..ZgM.......N....m../...R..r..".{..<...N..Px....^.B.............j...;.}A..?....:......6.E*.v...........S.&.f*.l......;z...O..E...R..pG^..../O.f.0#q~,.;.....u~R...{.I.....n..*.`.;vO]...... ...u..K!Q..;.8)
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.819780597736166
                                                      Encrypted:false
                                                      SSDEEP:24:bkYrhfyOPX/KBfejxhrNK3DiMDeezDdAYqPuarSE2dAoZSCBJ+rfqd6VX:bku7X/Tj/Y3DimpzDdAWarSgoZS8UfAU
                                                      MD5:4C9C49FEB4BEDDBF7EDFB419E92C510E
                                                      SHA1:ADE763F837B8D63B418188F1ED646EBF1D425797
                                                      SHA-256:7966CD3EBEBEA21C1D7FD884BCDD3E7E2259CAB4F4D39695CE5356C8CDB19BF7
                                                      SHA-512:357FB276633BF102FFE0F5A9AEB24E1695E228F38FADACFD76C43CACBF493EA545A2061E8CEFF6B762E656E10E834D18E93B212B44969CF9AC91061A60A506D5
                                                      Malicious:false
                                                      Preview:WANACRY!..........&.F...V..rw...N.f4.pR.{.F.......U.!..T,.FZG>....#..#d..a.45.G...Q<.T..)..L$S.....Ae.\....H.l.. c.2w(W.......v+.q?R...9"~.,tWv>.f.K.....8.A.M..O~.ke3..hz.#v.\?!^|r.Y.e..et...{..,..7aCf!......2N*.Q.5.....a..n...w4.A.Ej.W.g.....L.M............KI.mL...na1Y?.yI...LY^.f....aNG...vj.M..f.....*k, 'RV<..S.t....v........c."f..p...76.J....O.<.m....Q......\.E.ZRq......a.`.Yl....zw..<Zi......x.....3A.a....$.....%..}.W..d...C...W...s...(..1kl.....v.._.%..".l..)O.V.../...3......rx..H..p.lY...z.k......98)cX...1... ,.2.96k.n.kt.D."..{.c.F..U......-...z.:qu.....K.z..t4...-..&....g...Y...........1.....%....o~MG...\.:`..y....~.......f..:s[.d...cb.C.3...7..[...`..Lk.+.])..S.._.p..nE.....U.......BL...{.&..........8...'ez........X..\....E)..h.+Q..r*..#LG#D..2..t.. ].P.rb...v.0=..r..S..b..@...........bL...9.>..Y.& .R......o4.DT...S. ....$..._z.>.Mm....R...K....Z...G.<...w^Q.L.......".8...A......a`.Go....z..w..H.U0#G..z."..!.M
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.819780597736166
                                                      Encrypted:false
                                                      SSDEEP:24:bkYrhfyOPX/KBfejxhrNK3DiMDeezDdAYqPuarSE2dAoZSCBJ+rfqd6VX:bku7X/Tj/Y3DimpzDdAWarSgoZS8UfAU
                                                      MD5:4C9C49FEB4BEDDBF7EDFB419E92C510E
                                                      SHA1:ADE763F837B8D63B418188F1ED646EBF1D425797
                                                      SHA-256:7966CD3EBEBEA21C1D7FD884BCDD3E7E2259CAB4F4D39695CE5356C8CDB19BF7
                                                      SHA-512:357FB276633BF102FFE0F5A9AEB24E1695E228F38FADACFD76C43CACBF493EA545A2061E8CEFF6B762E656E10E834D18E93B212B44969CF9AC91061A60A506D5
                                                      Malicious:false
                                                      Preview:WANACRY!..........&.F...V..rw...N.f4.pR.{.F.......U.!..T,.FZG>....#..#d..a.45.G...Q<.T..)..L$S.....Ae.\....H.l.. c.2w(W.......v+.q?R...9"~.,tWv>.f.K.....8.A.M..O~.ke3..hz.#v.\?!^|r.Y.e..et...{..,..7aCf!......2N*.Q.5.....a..n...w4.A.Ej.W.g.....L.M............KI.mL...na1Y?.yI...LY^.f....aNG...vj.M..f.....*k, 'RV<..S.t....v........c."f..p...76.J....O.<.m....Q......\.E.ZRq......a.`.Yl....zw..<Zi......x.....3A.a....$.....%..}.W..d...C...W...s...(..1kl.....v.._.%..".l..)O.V.../...3......rx..H..p.lY...z.k......98)cX...1... ,.2.96k.n.kt.D."..{.c.F..U......-...z.:qu.....K.z..t4...-..&....g...Y...........1.....%....o~MG...\.:`..y....~.......f..:s[.d...cb.C.3...7..[...`..Lk.+.])..S.._.p..nE.....U.......BL...{.&..........8...'ez........X..\....E)..h.+Q..r*..#LG#D..2..t.. ].P.rb...v.0=..r..S..b..@...........bL...9.>..Y.& .R......o4.DT...S. ....$..._z.>.Mm....R...K....Z...G.<...w^Q.L.......".8...A......a`.Go....z..w..H.U0#G..z."..!.M
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.8118812370146715
                                                      Encrypted:false
                                                      SSDEEP:24:0OSVXnL3FrryLwgmFVwl46ZgEqhdaKafE:0O23l7wLunkKa8
                                                      MD5:9D5BA5741C91BBFB64542DCD564E0873
                                                      SHA1:189EA626305FD0DEECCA0984316E07A24E48D79F
                                                      SHA-256:62499AE7A7B85E7B73990D28617548218D5604A943AF83484953A87671099422
                                                      SHA-512:AA18F53ACCB0A505049932F0C11857927A4357EF4F061B0CE3C5353043453FC7FA8392D87F98A7F4743E48603C33BA0E4E41A2364FA4770072AC86FFE4425572
                                                      Malicious:false
                                                      Preview:;...{......v...P.}.C.s..].K...c....G..?|.7_.A.|..qh.9..T.Y...0......V.A8../8.[.i$....C......~...i...Z......-.......$..7........m....;...8..o.......-.Hl...!|......sC..%..).....x..)...riU.wx..E.U%k..5......ya....;{...v..v/i.2b....&..=KH..+(.0Rh..`(..>..R...mT..$...&../..d.W.?....D..S.N.....a.4kEbr..a.-j.'..a.E..0.1.KL.f..h..3.Y.p...T$.?...FE.3.e..GmS..u>.0'/.x...)i........hG.@[.=.......B.o:.3..n....Y?M..P#.(+...o........R-c.......]1.A...*.a......Uy.+o..'..r.....a.Qw...".$.V..6v.d.4$.Q........w......\.....'?.#Q..@D...m..6.|Dn.q.Y-...|H6.....m..J..s.2..d...;./........fH.l.dv.E;..3.E..*.sr....~-A.....#...%Q$)Y..s...b.VWnq...T.5.8>l....z....R`....6.;.>..,U.:.g..D.$.Z..-..<......"#..P...\}w.d..ZL.}.}.....pB([.....l,...."l...y.e..r1#I....0.......V<......1.l.W...A.r.....Wt.....=.....M..k. ...>X.C...........@..s...f..{..W^K^n_.>K$<~...R...R......Ab.*t.//.!..p...o!ec..Zh...#...#~.....T...Mg}!.k.:u.m.G.z.#.S....{n=6s..}..0.R...D:.l..9...l.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.862162739568338
                                                      Encrypted:false
                                                      SSDEEP:24:bkY6DJ9Fqb4/zcpsbs2HKdbzJ9SB55wavBaQ6WKDyhIb0KE0W2:bkb9spMRHKZbmD92
                                                      MD5:28C063B4BF93899A97B276B681F3B5FE
                                                      SHA1:16A08E7AC3E0973C62D50D55500F68A063E01B36
                                                      SHA-256:B8E0C3AA02A93338E9043BED65F4464D7B125C70AA6DC3C57E769A74DAE36ACA
                                                      SHA-512:19593E14CF7C81D7CD5DC5F0F1CC96FF2A7D82A9060279073B893810F40FFA96FD3C20462E95EF206657C2BFD1CB659AEEDA965F08B880F47698B07A9D041B44
                                                      Malicious:false
                                                      Preview:WANACRY!.....1...f.G;.....$.K,.jvgZf ig?...}-m.......j?.@9....:....=..........$h.C.....=....Z...:.1.Th2.kf..`..p$.....Ii~b....(...O'..uqy%bK.M..L......\.!....O.O*y..........X.....T1.a.+O.....wO|S...^...L...._W...*sCD...I6..\dc..;..,....4Pa..i......................_.#......bt.E2......2..c#."..6..?....."n.P..2.{.I..eS8.[m...r.....b....<....Y.oG9..q*&..1.+.......{`.....1..rR...#.r~....W..B/.D..em.....}..+..~s.....?....>S..y...2Q..2.l..2.X.....4b...E......vO..X9..*c.D.z..E..|...2<2...$X..YF........V.g..b.H......(^<kz.=..F..H,..~...^..r.8..D..Y..]......#./..NLI..[.."id....F9..1e.ZD......O...M..L...........9.(-O.q.@..;.c...b......2j..qAn[..x.w,.u..._...K.6.j..l.'.a.F..........).P@...i&.e.z..Q...Q..l..S......e.f..T.........+.....).X0x&.j.......kQ...;... .......#.QT...?....'h.p.I.bt9#Mfy...I.B..v.9.c........{..u.....qhM.....B.8!...K.Bo;...Zg..f...=.i.s."p.3.F...\I..kGg*.4.&{....=....X.~.+,H.K*..:....gx.6..l(.J.`@..Y..]...p.._F.....
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.862162739568338
                                                      Encrypted:false
                                                      SSDEEP:24:bkY6DJ9Fqb4/zcpsbs2HKdbzJ9SB55wavBaQ6WKDyhIb0KE0W2:bkb9spMRHKZbmD92
                                                      MD5:28C063B4BF93899A97B276B681F3B5FE
                                                      SHA1:16A08E7AC3E0973C62D50D55500F68A063E01B36
                                                      SHA-256:B8E0C3AA02A93338E9043BED65F4464D7B125C70AA6DC3C57E769A74DAE36ACA
                                                      SHA-512:19593E14CF7C81D7CD5DC5F0F1CC96FF2A7D82A9060279073B893810F40FFA96FD3C20462E95EF206657C2BFD1CB659AEEDA965F08B880F47698B07A9D041B44
                                                      Malicious:false
                                                      Preview:WANACRY!.....1...f.G;.....$.K,.jvgZf ig?...}-m.......j?.@9....:....=..........$h.C.....=....Z...:.1.Th2.kf..`..p$.....Ii~b....(...O'..uqy%bK.M..L......\.!....O.O*y..........X.....T1.a.+O.....wO|S...^...L...._W...*sCD...I6..\dc..;..,....4Pa..i......................_.#......bt.E2......2..c#."..6..?....."n.P..2.{.I..eS8.[m...r.....b....<....Y.oG9..q*&..1.+.......{`.....1..rR...#.r~....W..B/.D..em.....}..+..~s.....?....>S..y...2Q..2.l..2.X.....4b...E......vO..X9..*c.D.z..E..|...2<2...$X..YF........V.g..b.H......(^<kz.=..F..H,..~...^..r.8..D..Y..]......#./..NLI..[.."id....F9..1e.ZD......O...M..L...........9.(-O.q.@..;.c...b......2j..qAn[..x.w,.u..._...K.6.j..l.'.a.F..........).P@...i&.e.z..Q...Q..l..S......e.f..T.........+.....).X0x&.j.......kQ...;... .......#.QT...?....'h.p.I.bt9#Mfy...I.B..v.9.c........{..u.....qhM.....B.8!...K.Bo;...Zg..f...=.i.s."p.3.F...\I..kGg*.4.&{....=....X.~.+,H.K*..:....gx.6..l(.J.`@..Y..]...p.._F.....
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.814571612612444
                                                      Encrypted:false
                                                      SSDEEP:24:paljvivDvRk6+fvG1/OaNQQed/YGUVYBY9bP1L0yzd:pa1vQDvqMJOWI4YBYx9L0yd
                                                      MD5:ADB016F6D9F01FD83B27A5B5BA617FE9
                                                      SHA1:46257B9085DAFFFA493B7D6EA9A6200859016B5E
                                                      SHA-256:A8FD8CD83CD3CBE306C72318973202365CA1A385941A7E360A6AA7D7EC877B7D
                                                      SHA-512:95879D98959F45132DC0A9B6D12B6120E8572E7A45445477301BE12CE02822529BAF4B855A646A23D37AA89443CDEB744AD5FA732D478EFC7EC72416F525062B
                                                      Malicious:false
                                                      Preview:}...@..2....t....WDt..1....S......n~..a..<._./.3...)U..D.*.c."*4.{...W....Eg....K....[|.H..i..s.......{.E...-l.......q..t.Z.."..=.R.k.\..Z........o....*...C..L.[K..>.K..Z.m.K..1..~Dx....^Z8....r/..w$)&K....l..kB.....R..63.&x......k...C..N.t...C..d8..........f.......>.bT6)G*Y/../kA..x.>.H.Q.6....0:....$.E.4..k.I.Y0.$.\..{.y=.i..c...N.S.-E..P.3.0..RI.{c..d>.../..5..t...b...../....bJN. .75..T... *.P.c....B....9.`..p.5..[L].......".)...0...1.j..oT......e.|.{..M;..t........t?U.K..f...*.8.5.......s.....=........c..;..+{...oV..Oz..B...*...S.y./.....O.9........3..@.}..<..G..b...=.'h+...*......m.F!...T.....{........3.33.R.%..N....q.U.#."..8.4.u......k{I~m.Dm.Bm..v.i.o....!..t.G..@..dvd,x.$........?r.u..ia....oW.q...."5..=@..EY.d.~=..I..5..H.b.Scsy..jST...].62.3..O#j.x.....$.hI..a.....s...mG......"'..BxV....&..hI.l.....T.F...%...N..Q/.{g.B..(...`Lz.[.c...=G3....).<.9..-.FcI`.p..{...W[.....+...$.'.r!Q.C...7..R.I/_.T....p....^..t9.-.F..3.&...
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.856516847258542
                                                      Encrypted:false
                                                      SSDEEP:24:bk89tOk0qG5zrKImVP22Dwydn0cV57jl3kOqWbW1uJOHh/0v7U7kHttnUymUdz:bk8fO56I+PR1WcH7jqOqWbW1QUh/0v7H
                                                      MD5:7E80F3B1E71A3C1F022E06170C2EE237
                                                      SHA1:51EA65AAC9D7F68CADDE4DEDAC9655A1B0435AA9
                                                      SHA-256:C0CE875CDD2B7065CB5D9341A6DD061CA9438A4CDD5A7040A34E272E6688E264
                                                      SHA-512:85C12B57A4E6243759D8BB7DB54CC5F3C02559EFBB14D2530F82B80CD7A4D34E7254469718B0230A5FDB624E68112B88C5D0E2A209410637CB7BA659482BA52A
                                                      Malicious:false
                                                      Preview:WANACRY!....?.........R.6Pt.Y.5....c.m....Nt..<.6....U....EE.....M.o.8j.cP|......]....u...-....f~f*.#o.B[1.r.K.S.m^#.=.8$[;...$.D.MQ.b.........`.Fw\E.>.`....t..1...b.n....i.Cq.P.3.|6xwt....E..s..8X..#.s.....gF..(pGyN5.>..Y.a&l]&)..e._y^.....!b......2{.... .............D...@...W!z...Y|...cY.f.r...:`c.....$.m...[....t....ld.7..t..|.....`..........*.....MZjB...T.b.d..a..m.....Y.....1e..%m..D.\..E...4X6&...R2.......z..H...X6].wJ...k.pR..8.t`.o....z..Dj...s...E..xB{X...~...]..;.q.K4......W..7I......gb...RF.x.;.....n.R6|.ZK[.....JG.q.2gK.K.....V+9\....Mg..5#<......._..Yw..m..SsYT!e...=.3.sp....4.x7'td ..Q.i....._.%..I...3.f]..1.<:C65..T=BSm.[*...A|...->.+Q.K....(.'I.m..jhi.L).>.0..b|.D.X.'...&.!.....eg+>!..N..`.c.5.=...x..##...)0..`#.W.K..z.|..BHhn....~[U&.M.^O.....MCU..?c.=..(..;X.^vE\..@.=...4.......v2^W'.~.6.x.z..!U.4&......"...Cr!.,..l.T.U.sn#d...H.a.LY.]d.....V..'%..l...EL..UL....XX.[..../d3.H..eM.{..^..:...n.b.{_...W.......d.i......,
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.856516847258542
                                                      Encrypted:false
                                                      SSDEEP:24:bk89tOk0qG5zrKImVP22Dwydn0cV57jl3kOqWbW1uJOHh/0v7U7kHttnUymUdz:bk8fO56I+PR1WcH7jqOqWbW1QUh/0v7H
                                                      MD5:7E80F3B1E71A3C1F022E06170C2EE237
                                                      SHA1:51EA65AAC9D7F68CADDE4DEDAC9655A1B0435AA9
                                                      SHA-256:C0CE875CDD2B7065CB5D9341A6DD061CA9438A4CDD5A7040A34E272E6688E264
                                                      SHA-512:85C12B57A4E6243759D8BB7DB54CC5F3C02559EFBB14D2530F82B80CD7A4D34E7254469718B0230A5FDB624E68112B88C5D0E2A209410637CB7BA659482BA52A
                                                      Malicious:false
                                                      Preview:WANACRY!....?.........R.6Pt.Y.5....c.m....Nt..<.6....U....EE.....M.o.8j.cP|......]....u...-....f~f*.#o.B[1.r.K.S.m^#.=.8$[;...$.D.MQ.b.........`.Fw\E.>.`....t..1...b.n....i.Cq.P.3.|6xwt....E..s..8X..#.s.....gF..(pGyN5.>..Y.a&l]&)..e._y^.....!b......2{.... .............D...@...W!z...Y|...cY.f.r...:`c.....$.m...[....t....ld.7..t..|.....`..........*.....MZjB...T.b.d..a..m.....Y.....1e..%m..D.\..E...4X6&...R2.......z..H...X6].wJ...k.pR..8.t`.o....z..Dj...s...E..xB{X...~...]..;.q.K4......W..7I......gb...RF.x.;.....n.R6|.ZK[.....JG.q.2gK.K.....V+9\....Mg..5#<......._..Yw..m..SsYT!e...=.3.sp....4.x7'td ..Q.i....._.%..I...3.f]..1.<:C65..T=BSm.[*...A|...->.+Q.K....(.'I.m..jhi.L).>.0..b|.D.X.'...&.!.....eg+>!..N..`.c.5.=...x..##...)0..`#.W.K..z.|..BHhn....~[U&.M.^O.....MCU..?c.=..(..;X.^vE\..@.=...4.......v2^W'.~.6.x.z..!U.4&......"...Cr!.,..l.T.U.sn#d...H.a.LY.]d.....V..'%..l...EL..UL....XX.[..../d3.H..eM.{..^..:...n.b.{_...W.......d.i......,
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:OpenPGP Secret Key
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.796702126662983
                                                      Encrypted:false
                                                      SSDEEP:24:hxx6HGuw7v61FISEe/k026TsPhx7XmLyMYQmRmcm3DE5:hxsGD61FISEz0Y7WVYQaES
                                                      MD5:3E0C9DD3C3B9E1786A835BF5B8161A7D
                                                      SHA1:398822B7D9A4758B0913DB45C8103AB8DF9EE828
                                                      SHA-256:868586258A121CB8B790266D6B914E89BD0B28B6550D4738CF5A87ED94ED067B
                                                      SHA-512:9F6D32625989BD81B2B86FAFDE3929072CF82C2111497C52309B8190A19C0106D0783A357965C1C253EA7562DFD7A26CCA628DF5DDE5D19826B35E2AE9CF5204
                                                      Malicious:false
                                                      Preview:..P...J.l.mU9..8...Gf....t.~.*.].....C..}.*..O.:*.B..WL...,..X...F?.~J........H.m.:...x....U#.R.."k..n.=.g.V.......F.D..9..6v...g0.\D.$.4.>.9zU_k.2k.Y.vW.llT..%..N......3.....n....J..+@.q&*.=.nV.oPxK...)..#A..-d<..Fl.;{.6.....W...2J.R.T....8.........8....#...yK.c...r..M....@f`...g..[.Q?%.....4O..].V.e...}.....D.~=..x..w.T!.w.]..W.....?.... ...*z..KK.....V-.x.k..e.k]8..q..k..w...4...l.s....%...x.%..>.m.D....k>...5.}1+DR2.Ij.,....f..)..j.....-.d.8../...(...!..VI3.(.^...b...~.Y....~..B..Cg&?...K.^.....&...y{.....).....X..[.L?...Z.so.E..Z...=..Sv..b....>.E2.6uB=..d.o......{..W...F....h..ssT@`5...j.8G...6..Y.:t...8.A.I.r.].3*"..b .n....%q....|.V.*K.1.q...h......n...nx.#wv.D.n....>..HC.....}..K...V.........n.{..m..9..;i......BO...a._..".wE..u.UQmGg.A)P,.{..........V...f....B...H...-Yi6..F....L.ksJ.^..&0...p.....ld]..2...BU.?HE$....|.0...:......h...Z~.g......,...Hi.T..!.rO..j.R2.L.].....].3.#..w...s.......5..q8.xH.1)..\w..V...;.+..Y..L.l.X..c.X..;pb..9=
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.852403562110979
                                                      Encrypted:false
                                                      SSDEEP:24:bkGI8LxTeD/FT+YZlPZS/sIbTcBAxM3VJfUStb6Wf9b9oQQjcYNu/LS:bkGIUTezFvZRrI8BCM34Spvf9buQQjHd
                                                      MD5:BBAC4019F09815B15F89E369EC5ACE73
                                                      SHA1:8ED4A853FA2C51E0C2A9FA8DE1E2B00FD7AD54E3
                                                      SHA-256:6BCCE23C4636AC655C3433D6E039577A9FF801913E624541D224A033ABA6DC75
                                                      SHA-512:7E88579972253D1FA9B6B57A6851ED5FCDF067031311E345EF38F0535C1F98ABFB10234905CF054264C1EE857CD73F9BCF3B08E6D0E551FA885EA0F0DF1DA605
                                                      Malicious:false
                                                      Preview:WANACRY!.....M.^...OY.X..@.V......[..(.I.'Kj%.@+_............9.?.....s...wg.X)C.G....|eF=NQ....!.. .Cci.xn8..*.d.........Pp.K......!..FC...@.....@..7^.4m.....J[....$.N..".......]..og..#......@d.m......`V..((...7....++..l.<V.)G!..dp..!..}....\w....i....9[.............E.LSG..}...^.3.%<9.8..d.._..3.p..**.f..G...^..-(..Us....<.........etf..]z.2l..].9#....*...c......J..[S.'B8...H..A...a..._.GV+...w26.....y.d]...'w.[G.....6.....8.E.OCA.....6t..&.|v.Xb.I.......sz'4...<........`CM!.h...G.....CB.h.+....p.8E..Iyf ..=.64l....l\..Z\..q..L..7.5.t.{.`...-..:}.Q_N...%f..#3b!RsI.....o.Q.v....s...KQ{|.(..g...L..M....U:.....ba{.!.;.....%..a.c...m.....f..]...a.E...j.D.v:9.A17..O..)k...a>."...#.s....V..A.N8O.....j.<...........^.4.......qBz.Z.PO.........$.V.4.....%..Z.1..7*"..d......ok...NhCX..I..J......_.h.0.R..c./..Qo!.m7..w..Se...M<..I.Q..;n..b?...'!.,`....].eV.L...$."^g.....+.1......<.^.....[...r")-.t.r....C%[..2.....b./..'..S;..)...e..#DMI..;t....
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.852403562110979
                                                      Encrypted:false
                                                      SSDEEP:24:bkGI8LxTeD/FT+YZlPZS/sIbTcBAxM3VJfUStb6Wf9b9oQQjcYNu/LS:bkGIUTezFvZRrI8BCM34Spvf9buQQjHd
                                                      MD5:BBAC4019F09815B15F89E369EC5ACE73
                                                      SHA1:8ED4A853FA2C51E0C2A9FA8DE1E2B00FD7AD54E3
                                                      SHA-256:6BCCE23C4636AC655C3433D6E039577A9FF801913E624541D224A033ABA6DC75
                                                      SHA-512:7E88579972253D1FA9B6B57A6851ED5FCDF067031311E345EF38F0535C1F98ABFB10234905CF054264C1EE857CD73F9BCF3B08E6D0E551FA885EA0F0DF1DA605
                                                      Malicious:false
                                                      Preview:WANACRY!.....M.^...OY.X..@.V......[..(.I.'Kj%.@+_............9.?.....s...wg.X)C.G....|eF=NQ....!.. .Cci.xn8..*.d.........Pp.K......!..FC...@.....@..7^.4m.....J[....$.N..".......]..og..#......@d.m......`V..((...7....++..l.<V.)G!..dp..!..}....\w....i....9[.............E.LSG..}...^.3.%<9.8..d.._..3.p..**.f..G...^..-(..Us....<.........etf..]z.2l..].9#....*...c......J..[S.'B8...H..A...a..._.GV+...w26.....y.d]...'w.[G.....6.....8.E.OCA.....6t..&.|v.Xb.I.......sz'4...<........`CM!.h...G.....CB.h.+....p.8E..Iyf ..=.64l....l\..Z\..q..L..7.5.t.{.`...-..:}.Q_N...%f..#3b!RsI.....o.Q.v....s...KQ{|.(..g...L..M....U:.....ba{.!.;.....%..a.c...m.....f..]...a.E...j.D.v:9.A17..O..)k...a>."...#.s....V..A.N8O.....j.<...........^.4.......qBz.Z.PO.........$.V.4.....%..Z.1..7*"..d......ok...NhCX..I..J......_.h.0.R..c./..Qo!.m7..w..Se...M<..I.Q..;n..b?...'!.,`....].eV.L...$."^g.....+.1......<.^.....[...r")-.t.r....C%[..2.....b./..'..S;..)...e..#DMI..;t....
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:ASCII text, with CRLF line terminators
                                                      Category:dropped
                                                      Size (bytes):933
                                                      Entropy (8bit):4.710902136409594
                                                      Encrypted:false
                                                      SSDEEP:24:ptrPzDVR5Gi3OzGm0EigS1xbnS4RQhbrW8PNAi0eEprY+Ai75wRZcet:DZD36W3ChvWmMo+S
                                                      MD5:7E6B6DA7C61FCB66F3F30166871DEF5B
                                                      SHA1:00F699CF9BBC0308F6E101283ECA15A7C566D4F9
                                                      SHA-256:4A25D98C121BB3BD5B54E0B6A5348F7B09966BFFEEC30776E5A731813F05D49E
                                                      SHA-512:E5A56137F325904E0C7DE1D0DF38745F733652214F0CDB6EF173FA0743A334F95BED274DF79469E270C9208E6BDC2E6251EF0CDD81AF20FA1897929663E2C7D3
                                                      Malicious:false
                                                      Preview:Q: What's wrong with my files?....A: Ooops, your important files are encrypted. It means you will not be able to access them anymore until they are decrypted... If you follow our instructions, we guarantee that you can decrypt all your files quickly and safely!.. Let's start decrypting!....Q: What do I do?....A: First, you need to pay service fees for the decryption... Please send $300 worth of bitcoin to this bitcoin address: 13AM4VW2dhxYgXeQepoHkHSQuy6NgaEb94.... Next, please find an application file named "@WanaDecryptor@.exe". It is the decrypt software... Run and follow the instructions! (You may need to disable your antivirus for a while.).. ..Q: How can I trust?....A: Don't worry about decryption... We will decrypt your files surely because nobody will trust us if we cheat users... ....* If you need our assistance, send a message by clicking <Contact Us> on the decryptor window....
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Archive, ctime=Thu Jul 25 21:01:45 2024, mtime=Thu Jul 25 21:01:45 2024, atime=Fri May 12 05:22:56 2017, length=245760, window=hide
                                                      Category:dropped
                                                      Size (bytes):575
                                                      Entropy (8bit):5.140446565826782
                                                      Encrypted:false
                                                      SSDEEP:6:4xtQl3y03CpzeVs+bTNAUHUtxXCzaMmM7/gtrUod6tMljAlpdmqLEoJ4D6Vod6Nd:8iypzYNbd0thHZOgZUobjArozhmV
                                                      MD5:CCD2610ADD4080C4DCC35A11217DA6A6
                                                      SHA1:001ABA92D58B546C8BD54E0BC4103661F68CF92A
                                                      SHA-256:0E272CF58CC66E7B0CC4F42094232A46B6EC11AE5ED695BA4156A1A28DA41E6D
                                                      SHA-512:36DC5CE3027E8A77639783E31AC69C9FA61C4761FBEB9A819C1EB49F4A32BF2001C0441FB28D35C4EC9DD1B713576E7894DE8FD13BF14CE62A436F9619093DEC
                                                      Malicious:false
                                                      Preview:L..................F.... ....b{=.....b{=.....`.1.................................P.O. .:i.....+00.:...:..,.LB.)...A&...&........DDj....%.=....(..=......t.2......J.2 .@WANAD~1.EXE..X.......X7..X7...............................@.W.a.n.a.D.e.c.r.y.p.t.o.r.@...e.x.e.......X...............-.......W.............,p.....C:\Users\user\Desktop\@WanaDecryptor@.exe......\.@.W.a.n.a.D.e.c.r.y.p.t.o.r.@...e.x.e.`.......X.......216041...........hT..CrF.f4... .u.E._c...,...E...hT..CrF.f4... .u.E._c...,...E..E.......9...1SPS..mD..pH.H@..=x.....h....H.....K...YM...?................
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.829735494148207
                                                      Encrypted:false
                                                      SSDEEP:24:Xdh4IuQK25RjjO8+xfEA1c925MKEoq3zfiLHzdRzf5JEM9R:NhjRKexq8E96nKE13zKLHznfpz
                                                      MD5:D3514BAEDE510F010A3C3E77E00D6770
                                                      SHA1:49F785448B67E0D65D591A3745EFA4C0EEC95940
                                                      SHA-256:E393C5AAFA3012AEF99B8ED740BD003856BE71ACA67D117FDFAAC2CC34B1EF26
                                                      SHA-512:41233737BF8551D22238F7272DC36395E7FDA8A1E84364714721719611F925DC7E0CDF7169989050476CB6CDF5539472B3D8B10536FAE263F81ABB77E3EDFB97
                                                      Malicious:false
                                                      Preview:'........GQc..QLZ.S..,...9<.k.57.... ...Y....>...M..........92...h.l.......j.)..5$.]de]/49........C...\.M........7.U...x.p.......J..*HlKS....N.../......%+TP..4.....b......%.{..w...}4Lse...M8....O.~-5k..%..|81..L....?...T..J@.<..A..,P\.4.h4..)Q...Dc...}.......:#.?.b'%...q.....4.y..+#u SC4.y..=.......e....=..S..........z.....W.6..........*.t.....l(.6.i.|@G.8...|+2V....@G.T.c...5.s...q...."...B.*..K).....v..c....!~R2dG24...1.....!/.1?iy..pp.."..+.6a5A..F=g..l0..R.>^..S.._..RV..Ic)k..Tt.|.>.".t..*...D.\..N.:.u.u.1Kb..1+.&^c.m>..U..T!.Oo..6...q.g....@]"X. .:Y...}.........N.<.......x.7..rR.S..n.K8W..J_jI1.'FS.'.n..pm....n..ZI...G>.B.2mx.}.N.....$os..Z...sF}%.@K..@+?.m.P.ssz.:y...9m.....H..g..Ut.8..3.....mj...kJ..l.a......B.d....t......=....=;.G.'...c.......}&..._.*.0......r.G.R......^._.n..q.\..S.h.b.H!..W.d.P...j{.O..ER.Z61./=...{...)aO.!@/..%`.....4.7..8.F...f0.2 .8s.*%.K.;.H..My..1.?...cb..hGS.Q.HA..wq...gLj...%S]i....([x........
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.840863206443557
                                                      Encrypted:false
                                                      SSDEEP:24:bkt+dSSghdIeTVP/bNOGeWn/vUcNDgQbg6QfK0y4ybLgJWYHTE6S1OWH/Wh:bkQwSgrIeTVPzBeWnn/sQbX70xy3qWY9
                                                      MD5:5084EA91E6CEBD4F441CA947DDD5C649
                                                      SHA1:90D893AE0900BC0BEFF4E8E25584DEB27D4835E5
                                                      SHA-256:FA0436BB3B5309364F7B36B1E6B3FBD06B0F9351FDDDF5E4F32E433B4A0DBD3A
                                                      SHA-512:FA13BDB6735A2AF749FAC5FBAB8001D00A68833725D7826FA180965BE9E5F132471BCD1BDB3D6D5EE9AC065FB1A2DE8CBE8613591A8FE7C06CBC6F4211FD8593
                                                      Malicious:false
                                                      Preview:WANACRY!.....U7.G.&_.Q.........w{l>.}....If..+...A`...W..=...n..@.....F..A...V..+...rM.n..0..L....X. .G..........2..uw.FM]...)...md%..Q....IGI.?.....Z....g..g.......c....h..m...Q.z..<..is.pa........U....A0.z!.........1...-..O.+.....Cp2..O!..+...e...|.d.s...............-...>.d.E.\.h.m...h(+..!.<...k.b..P....x.^.T.G&.c\y...=..3C..N.$...[.d.........\F..Uxk..x8...'.S#.o...<...j..4.../-urvn."r.|...AX......W...r..Y....)&.....OH...Aw.3.!K....*f.2.$.H28E.)...F=.b....D.9zs..YZ.C.c.h"gm6n`7..+..4.....LjU......8...N..]'.|.*.vy.M..2?....j*X.(..6...%..-..3....9,I.u.G.;....+.6.*.y&r9.Y.b......J.>....H..#..6 ..U......W..n.S..FR...........x..l .\.2%&...'.h........G.....4.....K<].y.v....k.#..tQK6..jG.|....V..`..e.w.r....1..B......[]..o......g.....0.W|......b|Q...cq!e.'... q...-....Q..\Qd.1{'N.W...v.r..`bW7....Y..!.6..O.....c..1......{......2..l_N.N...89.s.M89J...*...)....9.w....'.G_...-.z.rq.p..?..._5....Yma...G]........*.Fz."G..E..D.Y.>..0.@].L.J.=..
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.840863206443557
                                                      Encrypted:false
                                                      SSDEEP:24:bkt+dSSghdIeTVP/bNOGeWn/vUcNDgQbg6QfK0y4ybLgJWYHTE6S1OWH/Wh:bkQwSgrIeTVPzBeWnn/sQbX70xy3qWY9
                                                      MD5:5084EA91E6CEBD4F441CA947DDD5C649
                                                      SHA1:90D893AE0900BC0BEFF4E8E25584DEB27D4835E5
                                                      SHA-256:FA0436BB3B5309364F7B36B1E6B3FBD06B0F9351FDDDF5E4F32E433B4A0DBD3A
                                                      SHA-512:FA13BDB6735A2AF749FAC5FBAB8001D00A68833725D7826FA180965BE9E5F132471BCD1BDB3D6D5EE9AC065FB1A2DE8CBE8613591A8FE7C06CBC6F4211FD8593
                                                      Malicious:false
                                                      Preview:WANACRY!.....U7.G.&_.Q.........w{l>.}....If..+...A`...W..=...n..@.....F..A...V..+...rM.n..0..L....X. .G..........2..uw.FM]...)...md%..Q....IGI.?.....Z....g..g.......c....h..m...Q.z..<..is.pa........U....A0.z!.........1...-..O.+.....Cp2..O!..+...e...|.d.s...............-...>.d.E.\.h.m...h(+..!.<...k.b..P....x.^.T.G&.c\y...=..3C..N.$...[.d.........\F..Uxk..x8...'.S#.o...<...j..4.../-urvn."r.|...AX......W...r..Y....)&.....OH...Aw.3.!K....*f.2.$.H28E.)...F=.b....D.9zs..YZ.C.c.h"gm6n`7..+..4.....LjU......8...N..]'.|.*.vy.M..2?....j*X.(..6...%..-..3....9,I.u.G.;....+.6.*.y&r9.Y.b......J.>....H..#..6 ..U......W..n.S..FR...........x..l .\.2%&...'.h........G.....4.....K<].y.v....k.#..tQK6..jG.|....V..`..e.w.r....1..B......[]..o......g.....0.W|......b|Q...cq!e.'... q...-....Q..\Qd.1{'N.W...v.r..`bW7....Y..!.6..O.....c..1......{......2..l_N.N...89.s.M89J...*...)....9.w....'.G_...-.z.rq.p..?..._5....Yma...G]........*.Fz."G..E..D.Y.>..0.@].L.J.=..
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.818755517421615
                                                      Encrypted:false
                                                      SSDEEP:24:p09/45VczZPMN0Ifop3pL0qCohqwV7O8WTpAPNGVTbWs2rm:6+oqN0IWp03ovxUSP0Vn0S
                                                      MD5:DD5A8DB8DE88B285A647370F83B98077
                                                      SHA1:72698E84A70C8E2D3B459927C997C94DAC79819F
                                                      SHA-256:2221F17D9246716DD8916DC61E900F6BF28ECA989C064B743BA414994B88B574
                                                      SHA-512:B1924D71A73B34A2A073128097F09791D1D779BE88A08E33217D53BA890A5EBAC2F174F02A011B5C6AE9FC2B77DBE2AEBD4879EDB6BD7CDEB9769F3FADB6C983
                                                      Malicious:false
                                                      Preview:.....u#....R.).K.....1....&...i.KP..E....3.c..#F.B...*ht{....^Q.%...L.n. .....V-Y..-.A3....D...0.e5C.@+..K....Xsj...........N...L.5....#..JH@[......{.......i.X.z.)4t{l..z1ob...js.....XL:.L.T.'.!-(}....@G..;...|..&_.E%g......c.;...d..DAO.E.l...%...:..A.F.&..v....1..?..... .{...n.:.....M.O.a....L..z.d2..C.CS.'.#L.K!%#.../M@<.p.....yW..m.w.I.{...5..tQ7.6?|.g......c..[..(....h7.0k.=.:.....q.B)....2nz...uc...!`...G....;I..v...,.....[Ff........W.5....7.*.....h|^..Q.e6"..f....c0.$+.0..6P&..%.I.H.lh..P.>.R....G...M$..n..g...>5.0_}......&.A8z.{...U.3...@. .IZ.].B5..&Y..g....l.- .h...!...@..[.2.h....;........b....*.........e..*. ....+../8..U.......T.J..K.......9Jx.M..<.y.%.....k....C.hO8.Ru .aYZ.j.....d......M.w.26.C..l]A{..Jq.p......j....S.6...$.ILG........tI..p...y.I..z...ar....'?...H....th...&*..y.{.....v>.Y`....|..{..FVJ.3U&m{..fA...L{.{....=.Q..1....fv.$$..........q..S.J...Y......~-E...$..........B.....J..(y...G}...1.JL..._.`4.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.866790806990171
                                                      Encrypted:false
                                                      SSDEEP:24:bkwI6xg3hFhGbfiGSJdc0q+ohmzhwHwurTHp1lcPlI5X6X:bkIxsF5G09ThwHtDp8O5qX
                                                      MD5:776D1559926BD489C073F9BB5F77BC48
                                                      SHA1:4B60206799906B7E219EBDBB31380CF270EA7051
                                                      SHA-256:636D65275550E71E109FF9CFD28175E9659837D7678E4C7870C5206D124E3F24
                                                      SHA-512:BA23FC46A6DBCD471E409E779E998D048933D9295DFF1D07E75E7A289FE842C6DF7EACCBE3E3DD35432FC75E3268CEDFF71D6096E8E929F004326539C5590044
                                                      Malicious:false
                                                      Preview:WANACRY!.....aa.` q9..z.G..A........UrJ.....Y7I.?.*4.%....(..3{..\D..V...D..J]&.n._h......f...'.Eg.e.....j...-..o\...tiI...rgX..~...G....4..y.D..`c~]...q..i.VR=..^X..0Z..;.oK....>....)...Y..k....d...`..yf.?.@c.j..TR...|..V......#g.....;./3.Dv........J%...................Z.....&..Oe..;9$..]... .......(..*d.lVq.y.{KVt....:..J....rQ.C.a..c`-....+x... &.J.X.m*V...|+4G..*..H..?~.k...F...Y.H..T9).Mp#.S....%O@.....`...3.:.|..o.,...c...$.....[...$.la&x....Sy[O...~.E..|.\....T.B.q.,&xK...woP7:..%Q.5Nuw.....Z;.O.......^..NfKt...a......h..o.q......E..s?G.[....6....x>x+R.X{.?.^.z.U9.."..|.&@....*.I.9.:.-;..;.......z.t....LH....?...a..@.A]r~k?..J...L.<KX6...U...1...........3.N).>Z.Cl...-...R[.k.^.ED.^4..\...ll...~v2(....#.......Nca..6..U..3.w.^...3.6..t."{..m.!.Y.QX-.)?..1....h^_\x9...}.%.@...A.}Ka[.XB%g].x}HZ..x7....V....J....i.....i.>...Od..E...O......eU.I....'..h...sw..G....s...d*....C}q..2.Wb..E..l+`....Ye.jh...@."GhIB...z...%.Aw.7...t.u
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.866790806990171
                                                      Encrypted:false
                                                      SSDEEP:24:bkwI6xg3hFhGbfiGSJdc0q+ohmzhwHwurTHp1lcPlI5X6X:bkIxsF5G09ThwHtDp8O5qX
                                                      MD5:776D1559926BD489C073F9BB5F77BC48
                                                      SHA1:4B60206799906B7E219EBDBB31380CF270EA7051
                                                      SHA-256:636D65275550E71E109FF9CFD28175E9659837D7678E4C7870C5206D124E3F24
                                                      SHA-512:BA23FC46A6DBCD471E409E779E998D048933D9295DFF1D07E75E7A289FE842C6DF7EACCBE3E3DD35432FC75E3268CEDFF71D6096E8E929F004326539C5590044
                                                      Malicious:false
                                                      Preview:WANACRY!.....aa.` q9..z.G..A........UrJ.....Y7I.?.*4.%....(..3{..\D..V...D..J]&.n._h......f...'.Eg.e.....j...-..o\...tiI...rgX..~...G....4..y.D..`c~]...q..i.VR=..^X..0Z..;.oK....>....)...Y..k....d...`..yf.?.@c.j..TR...|..V......#g.....;./3.Dv........J%...................Z.....&..Oe..;9$..]... .......(..*d.lVq.y.{KVt....:..J....rQ.C.a..c`-....+x... &.J.X.m*V...|+4G..*..H..?~.k...F...Y.H..T9).Mp#.S....%O@.....`...3.:.|..o.,...c...$.....[...$.la&x....Sy[O...~.E..|.\....T.B.q.,&xK...woP7:..%Q.5Nuw.....Z;.O.......^..NfKt...a......h..o.q......E..s?G.[....6....x>x+R.X{.?.^.z.U9.."..|.&@....*.I.9.:.-;..;.......z.t....LH....?...a..@.A]r~k?..J...L.<KX6...U...1...........3.N).>Z.Cl...-...R[.k.^.ED.^4..\...ll...~v2(....#.......Nca..6..U..3.w.^...3.6..t."{..m.!.Y.QX-.)?..1....h^_\x9...}.%.@...A.}Ka[.XB%g].x}HZ..x7....V....J....i.....i.>...Od..E...O......eU.I....'..h...sw..G....s...d*....C}q..2.Wb..E..l+`....Ye.jh...@."GhIB...z...%.Aw.7...t.u
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.815144179936806
                                                      Encrypted:false
                                                      SSDEEP:24:7dTIR1mfv8R0DYQy8/JBmGQvzm/mn1up0MgUA1YGCh:5TWUv8R0Dpy67Azm/mngiU6YGCh
                                                      MD5:39D0BBD1F11C71E301B6D7D1E178D3EC
                                                      SHA1:E744DF7AA35524A1893DE057E5D4D6E023C805AE
                                                      SHA-256:5D6055937131681D31B9275B08AD3A80E591953FB2C25C8A4434DDC8E19E6E71
                                                      SHA-512:ECF5AC5338FD7C375115993C3FF4B5FE006AD3C13E3DF2F873ADCA6FCFCEE89B2A129BE81B431DA88040742722B37182125A24DAB32EBC8C9578CEC49EF333C8
                                                      Malicious:false
                                                      Preview:k'...!.,K.....Y2.U...n..\x../a...[..>y...C.B..{..#..AR.N)..._..t....6XGF.ZI..2L..=......Y\W..}.......g0y.L..^.@...6../.V...;..sc?.....&-....q..._0...E.|!...,`.R.......w..h..j/..;.9yq:..K...^C......0S....a........L.{+Z.E.O%[!...i.cK.*......U~4....U.m.K.....*6.mO..}.P.G.jH;..E.J=G.3...0.5Z...........Q.P7.@.C....0.d..'x......x.\@...yX.T...T....z.(=...."...oZ.x.r...YI..d7q....,.;zX.\.VM..+.G..+.v....7.7...N:..u.....B6..N.8p.9....t.Q..7..H.K.ay.i.2.....W....Jv..J:H...C3.....qk.:..H...qY*.Z...5.. -?..`.3..... 1..t.i.<."..l...<....mr............!~...Jt.C@w..B......\.<..ed...F....+.....)..[..&...@...W1`..(.R.'.....i..C...;p.!`..../..I.K.^.....=[..2B....!yx..R.n..7...k.....R.....Y..R.@)....H4.9.....Tfg.+L..|.5.6M...T".Zl...z.>?."..uj.i..v..!6a..y..ymC...d~..w.N..V....xs....R.{.8.....s@38`.&[b.+.;zg..[`x.Ox...4..../C.......j.....XS...E......s.......l.A...N....G6...H.....,..xL;..I....6.......d...h......}.?..(S.N.........X.<Z..U-...8a.6.X.....K.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.837955680203175
                                                      Encrypted:false
                                                      SSDEEP:24:bkxqiDpPmDSrMTRHlE57qZZp1kL706aMZKICf7fXPsJxLlz/IK9hu:bkzxkSrMNmqh1o7itf7fXP0F1Zvu
                                                      MD5:DBA377F377409A84DB81AB2958B542B4
                                                      SHA1:553AF9AC9D5C145D02CF414CF35FC096938967FB
                                                      SHA-256:0F4F33A92E96E33607C9C75A2468E1B5DD4B3111C39A6F02C4BA69C867659850
                                                      SHA-512:0C4E227637AB9E66BB4CD02C90EB2C294B27BAA5A361360D346AEBB76EEBD11E04F20D83CB97D99F8DD8B929AD0017728AE1C2372C7322584FECCE9883A8232B
                                                      Malicious:false
                                                      Preview:WANACRY!....<..N..V>X.[.XJ.Q..wcCj.....L.r;k..E.b...'f..Ys..G`.^.\pa...>WV...g.Q..._v.j!G..bC......CSw.3..<....j.l5.......|r...7...>'..OE.uh....1C.p0......-.?7...T...6eG....[7P..[(*....E.xL..Y..\.O...R.p.#L*d.k...E..{.4.xz;.<.u....#.=.:k.mXtu.b...j.:e..._................zI.;S.r.|.#&..sa[...c..1.V`..U.z.&.S.U..Pp.........!.......p..9BJ1.-.hA..$.....,.Y..M....%..7h..d..$6...iA...*.n.\V.....~=.lE.c.Ry#.-....*...n..=..n.N.0 .J2.....~I;=.p.g%.F.L.Z.3...1+.n....0Y.4...i .p...ty.....D.W.!.~=?..?.....Z.YC.i.C$KEl]..m.p.$....:..z>;3..:.F_.9...k.Aj.(C.....V....j.6#.z....E*..:30..H~........Eu#.....7...y..M..|..F...BAb...e^....N...*5.:r.......5.x.x......s....X..Z...=......a.K.L,]..m....;v9|[w.&..NW.9|Lm.;...f...Ta.u.$...;.o.Pb.`@o..Z.@AgH.0^.......t.z....].3...4..C;-Q...z..s.o...|.p..=..h....QX.......'....v.+...(..'A.H..j.i.|T.~.N.pq...|.Md..?K..y....,.. .n.'8..X....:....6....V..t.K........R:.s-..<..a....W>CL.....u......e.$4.....>?...T.Z..;.....#.e
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.837955680203175
                                                      Encrypted:false
                                                      SSDEEP:24:bkxqiDpPmDSrMTRHlE57qZZp1kL706aMZKICf7fXPsJxLlz/IK9hu:bkzxkSrMNmqh1o7itf7fXP0F1Zvu
                                                      MD5:DBA377F377409A84DB81AB2958B542B4
                                                      SHA1:553AF9AC9D5C145D02CF414CF35FC096938967FB
                                                      SHA-256:0F4F33A92E96E33607C9C75A2468E1B5DD4B3111C39A6F02C4BA69C867659850
                                                      SHA-512:0C4E227637AB9E66BB4CD02C90EB2C294B27BAA5A361360D346AEBB76EEBD11E04F20D83CB97D99F8DD8B929AD0017728AE1C2372C7322584FECCE9883A8232B
                                                      Malicious:false
                                                      Preview:WANACRY!....<..N..V>X.[.XJ.Q..wcCj.....L.r;k..E.b...'f..Ys..G`.^.\pa...>WV...g.Q..._v.j!G..bC......CSw.3..<....j.l5.......|r...7...>'..OE.uh....1C.p0......-.?7...T...6eG....[7P..[(*....E.xL..Y..\.O...R.p.#L*d.k...E..{.4.xz;.<.u....#.=.:k.mXtu.b...j.:e..._................zI.;S.r.|.#&..sa[...c..1.V`..U.z.&.S.U..Pp.........!.......p..9BJ1.-.hA..$.....,.Y..M....%..7h..d..$6...iA...*.n.\V.....~=.lE.c.Ry#.-....*...n..=..n.N.0 .J2.....~I;=.p.g%.F.L.Z.3...1+.n....0Y.4...i .p...ty.....D.W.!.~=?..?.....Z.YC.i.C$KEl]..m.p.$....:..z>;3..:.F_.9...k.Aj.(C.....V....j.6#.z....E*..:30..H~........Eu#.....7...y..M..|..F...BAb...e^....N...*5.:r.......5.x.x......s....X..Z...=......a.K.L,]..m....;v9|[w.&..NW.9|Lm.;...f...Ta.u.$...;.o.Pb.`@o..Z.@AgH.0^.......t.z....].3...4..C;-Q...z..s.o...|.p..=..h....QX.......'....v.+...(..'A.H..j.i.|T.~.N.pq...|.Md..?K..y....,.. .n.'8..X....:....6....V..t.K........R:.s-..<..a....W>CL.....u......e.$4.....>?...T.Z..;.....#.e
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.791038479038133
                                                      Encrypted:false
                                                      SSDEEP:12:IWjyyHjiwLUJRnKeLcMnRfloItOHca3FcLnmiBqWR1eWmeAl820w0Z2IOw5BYhex:XVWK874M1lozca3FYqWR1eheAn0SIBGs
                                                      MD5:5F8496912852B92F87B6D676B9D611A6
                                                      SHA1:488505E842035A45D2B2EBB6A55DDA73AE077302
                                                      SHA-256:5497094C2EAC07C6A6577EE4156C6EA2688B08D8C729A616A7397296914DC774
                                                      SHA-512:EB229DB25F9A024F4E3E8DAC9E955D8847392DC383D2BCC9637016A1BF61DA958384195D01A0459795AF7FDE0CE294C55BE1F2A7B1D3D51A0165C8236BFEDD53
                                                      Malicious:false
                                                      Preview:.l.<....a.&S..R....VJ'C...%.n./.R...I...J.j....R..H.]o.0B..@...lL#~.n..ycvz.*M..$.P...L>8U...!......a=-..j..C.@}.+.P...../..~../I......G...s...t<m.....VeN.t".f*.UP..].......I...!W.a'..\C..>...rB.3.o.....i.....(........*..)(.].......'..2..n<S.|.G..a.r#...D.f..m..3..c.R.K....?M..ru{.....$...S..[7...7x.n.K./.?+..X...m....\.k..}.}...[..>..3{2(...#~~..Hp..o.w.....o.]R.*.|..lA3-.!...\.qU.#.i.q....t....%<.a.z../._...#3...H...hj...qIT.%.m..H.gw.Q?[[o.zk...2w......|..;S...)|~k...[r.!r.>....F.o..Gg.....~.C...6._.`...|h......)7U19....5....XT..\.5..t.f..q..c.1s.5.t<../......(./s.b..J.J.M....k.w.i.y i..L..2..:......P.W.`.q...:...`.......$f ..m.V..#..=..P.w.S.<8,......a..w../..|(x.../c.N...@.D..9. .'.u<Isv`..q1U.5..c.....%V3.Y..D...w$.:X.....+i=....L&./+\/.S.9,xP.S?../.(..........8.3...*.1.@ZP.W_..b.W&......w...q.R.],\....-.t...QF..7.....>3.....k.. ...MaZ.7..P..\9.g.U.....b....D|...y.Zw[....h...!.....wzrm../3.r...Lz.a.W.r.74..f.d.^.....Oi.R.g.......B.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.843061265467005
                                                      Encrypted:false
                                                      SSDEEP:24:bk+BqBG2oCARZbghDURakhWd5EiFJNX6W7F0SDuRKwY/6nExzO3:bkXBGRRZhELxXt7F0SiRKwYCnEY
                                                      MD5:1E107F0FEBDE4631ABF32555C2B280F5
                                                      SHA1:7BBB8EF4EE4E1582EE3F35ED5871F13F465F88CF
                                                      SHA-256:BFB416EB192E73D23D44C11FC76D1AEF10481A014E6179FF63AECCE95D6C0A81
                                                      SHA-512:3DD39417D543D14023CA16A024B73B2D8D2CB5CFFC23483656618C9DEC3C3450A4AFDBD4977D46B1FE3B29ADAB696A58B495EEA543C4D999ECD0C33924A10E43
                                                      Malicious:false
                                                      Preview:WANACRY!..../^/.N.,...0.G.M.......z......O<..?..,.tp..."...^.x>....4O.+q.K....P..*f\.H..V.x&....V..s5g .....H..P..T.".j.KZ.....w....^.K.q...J..%....c...GLs..t..~"c(.<<..........O.V...|9.6Q...mS.@..... n.pN.Z..7........E...B..C.i.m....R.\8.d..?.,|c......@.g:=]..............>...~...YP.......9._b.^...L{.7F..6..a...Y....,.....[hp....Y.a^..Y...x.KO...v4..A0........P...~...+/ZE}b........MA.........A3^9...S.....qs\..a..bf(..#......p......R...D,...-...N..R.O..~.b..e.!...~...5..u.K..1......%fxC. Z).T=...n...........eg..P.p.i.=....(.....!.g..."@/._....^.z.&.A2.{&ot.#\Gw?&;....x..Zm....]..q......f.g.Jd.nx...O.^.:...%.E..XkYj.*. T.k...1... ..a..1C.w......S..>....-.[.V..n2.g....9.........4.........~..Vq.)T....(....ZMvuB@:...W..~.:.7.xOkY ....S^....t......"Cq>.c...pV./.x...~.!....Ecs.E..,...w(.K.............Q...s:....w..l..?_..?....WC.X...0%IP.d.lR...... ....D...\FU.:.._G-...._...1...PX..Wg..F...m.F$..*. 4........9...Y....,..|..c..3B;..../.r-..p...:.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.843061265467005
                                                      Encrypted:false
                                                      SSDEEP:24:bk+BqBG2oCARZbghDURakhWd5EiFJNX6W7F0SDuRKwY/6nExzO3:bkXBGRRZhELxXt7F0SiRKwYCnEY
                                                      MD5:1E107F0FEBDE4631ABF32555C2B280F5
                                                      SHA1:7BBB8EF4EE4E1582EE3F35ED5871F13F465F88CF
                                                      SHA-256:BFB416EB192E73D23D44C11FC76D1AEF10481A014E6179FF63AECCE95D6C0A81
                                                      SHA-512:3DD39417D543D14023CA16A024B73B2D8D2CB5CFFC23483656618C9DEC3C3450A4AFDBD4977D46B1FE3B29ADAB696A58B495EEA543C4D999ECD0C33924A10E43
                                                      Malicious:false
                                                      Preview:WANACRY!..../^/.N.,...0.G.M.......z......O<..?..,.tp..."...^.x>....4O.+q.K....P..*f\.H..V.x&....V..s5g .....H..P..T.".j.KZ.....w....^.K.q...J..%....c...GLs..t..~"c(.<<..........O.V...|9.6Q...mS.@..... n.pN.Z..7........E...B..C.i.m....R.\8.d..?.,|c......@.g:=]..............>...~...YP.......9._b.^...L{.7F..6..a...Y....,.....[hp....Y.a^..Y...x.KO...v4..A0........P...~...+/ZE}b........MA.........A3^9...S.....qs\..a..bf(..#......p......R...D,...-...N..R.O..~.b..e.!...~...5..u.K..1......%fxC. Z).T=...n...........eg..P.p.i.=....(.....!.g..."@/._....^.z.&.A2.{&ot.#\Gw?&;....x..Zm....]..q......f.g.Jd.nx...O.^.:...%.E..XkYj.*. T.k...1... ..a..1C.w......S..>....-.[.V..n2.g....9.........4.........~..Vq.)T....(....ZMvuB@:...W..~.:.7.xOkY ....S^....t......"Cq>.c...pV./.x...~.!....Ecs.E..,...w(.K.............Q...s:....w..l..?_..?....WC.X...0%IP.d.lR...... ....D...\FU.:.._G-...._...1...PX..Wg..F...m.F$..*. 4........9...Y....,..|..c..3B;..../.r-..p...:.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.786974988220282
                                                      Encrypted:false
                                                      SSDEEP:24:NTsiyP4Zjh01srvZLPY94lGtsh7GP8Ooyoxjh9oM:N2P4Q1sjlGGhy8bZoM
                                                      MD5:4B9AA02A802A3F1000B33F19C5B4DAD0
                                                      SHA1:9965B5A84019FB45B2229EF501C964B5BEB5581C
                                                      SHA-256:7AA1D065890377017494D71BC31E493CB7055EEE95DAE67E6D410F3F794E5710
                                                      SHA-512:656A68CDE95C6BF0938DC4123AD6FF76B3A9DEEEBFED1ABFE6DD072A543597A2ABD87B6C11CF966C5D2B044C021595A48ABCB5DD0DFCD33404DBC4EF3D283BA5
                                                      Malicious:false
                                                      Preview:.L.O..G.....Q[t.&..0....j.[......h.......)........v~....A#Zs~..Q.C#.P.NZG...?.3..".;3.....Z.qh..t..%.hf...\k.!..S-.F.r.r@c{'.P.&.=B......J2n.H.G..Y..5F]F.'..}...Ok%.Hv....2..so...........*.<.XG1....s..|.;{`..2...'...,=...-...'.H...S~..,)..B.......&.C..bm[.n.A...Y.....)....)...\..e....__.....(.H....7A.........z......h...$.7.P..U.....!....n.r..+..px?..I..\0..S.q..e.XI...*.y...M.Zx...r&.{~.n.}......T....72]}......aI.......%...?_A6.V ...x..v*.g.......I^r..{1.=.... U..Uu....b)..ha&.....|.f.i.u*0..r.rp..9.!l....J.._M.YO.4... .F2..\...^.......x.B`N(...5.......!...J......LA....}...?.....vo.5K......Q......P..d.^..Cc..x...>...7;.U..k..VI..%..U~vu.P.%dK@..6...B.<a2h.O.........S....S..K3.9......1....Y:.n..,.Ul.....w*.*...\4.i./...q...R*......;A..*n&...uj0/L..`....8I..$.*wr38..f..n.lJ...}... #p.=Iyt.iw.N...J!E.d....I$......7...D..=....A...x.j.....g0.V..$.y3..pj^.<.i/.o .{.`..5..Z..Z..X...c....A..... ..i.`.F..5...c.I.h...*..D....h.....Hw.3.P..s.#B..d..bP.U.g
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.847780784168077
                                                      Encrypted:false
                                                      SSDEEP:24:bkoDQ+rZ0riUSdkKx7aVet7lON9HGknPIrrsTDzGYvkqxjUvxOd8:bkoRkO78et7EfH/BkqxjmP
                                                      MD5:EBCD09761E7910F4F98FA0E660FD6005
                                                      SHA1:D1ACB41EC2537F28962EFD46F1A1FAC09617A180
                                                      SHA-256:53EAD7F9D5F215F755016E2402D549C68D4B4E4D1D3711466C4FF5BD1AC9116C
                                                      SHA-512:CE2F3A863252948393514A039FB3532E5B8DD2DB56B8032AE0B7BB884EDA491CF39C0478210949B6B715580A825ACEE7F8C051320C4FFA64A31E7F4479F6A207
                                                      Malicious:false
                                                      Preview:WANACRY!......=7..............ED...x...U]...L"..*..M]E....Y*.S@M...E...i.#........f..ag9........PB.Vj..e....(.|...+..}i.J..?..R.....Q=./..X..S..v:.h....S@.Qrq.{...)..*.G....E._.5.....},..8.f......9..|}..|7.D..+G4...r{}.."..Gl.."._9.Lj.K...N...d..p.!..u................#..Yq)....pv.%+x....~.]KolH.(.(Z.!...`&.....'.Y..gJ..p......\....S`...E..?...\.[.e.b&...9!../.....h...l..X(.~......H....v ....zy(.....d....\h..p......3z.(.}.....=.c?.5.N$c..`.......;}.wtB...o7.Z...*....O..6.b..b/d...3..h...6K+...y.........s7.E.a..f.=..@.....Z@..}..Pn.`?[].?..i._.1T....@.i#...Ty....<..w.'. ...dd.y~.|.)........5.G.CM.$/...6e...w...gi...G...^.....vRM...............W..)....zz.>=eQi.d..l.$UJ..o.......:..\..u.d`wyy.a....7..Ly.&:...e.%....R...*....]J5{.. .-X..7..`......g?....w0uR...`q..."..|6.,.47rL#..>..1...]'.:...S9..-..7..ZRA4.o.......;=....N.u...<Fh...$..S=..a'.R..............YB.o....c..U...k.V.7.......*@.....%(Y......g....J......l...{..*...d=...s..wwc....A.......0.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.847780784168077
                                                      Encrypted:false
                                                      SSDEEP:24:bkoDQ+rZ0riUSdkKx7aVet7lON9HGknPIrrsTDzGYvkqxjUvxOd8:bkoRkO78et7EfH/BkqxjmP
                                                      MD5:EBCD09761E7910F4F98FA0E660FD6005
                                                      SHA1:D1ACB41EC2537F28962EFD46F1A1FAC09617A180
                                                      SHA-256:53EAD7F9D5F215F755016E2402D549C68D4B4E4D1D3711466C4FF5BD1AC9116C
                                                      SHA-512:CE2F3A863252948393514A039FB3532E5B8DD2DB56B8032AE0B7BB884EDA491CF39C0478210949B6B715580A825ACEE7F8C051320C4FFA64A31E7F4479F6A207
                                                      Malicious:false
                                                      Preview:WANACRY!......=7..............ED...x...U]...L"..*..M]E....Y*.S@M...E...i.#........f..ag9........PB.Vj..e....(.|...+..}i.J..?..R.....Q=./..X..S..v:.h....S@.Qrq.{...)..*.G....E._.5.....},..8.f......9..|}..|7.D..+G4...r{}.."..Gl.."._9.Lj.K...N...d..p.!..u................#..Yq)....pv.%+x....~.]KolH.(.(Z.!...`&.....'.Y..gJ..p......\....S`...E..?...\.[.e.b&...9!../.....h...l..X(.~......H....v ....zy(.....d....\h..p......3z.(.}.....=.c?.5.N$c..`.......;}.wtB...o7.Z...*....O..6.b..b/d...3..h...6K+...y.........s7.E.a..f.=..@.....Z@..}..Pn.`?[].?..i._.1T....@.i#...Ty....<..w.'. ...dd.y~.|.)........5.G.CM.$/...6e...w...gi...G...^.....vRM...............W..)....zz.>=eQi.d..l.$UJ..o.......:..\..u.d`wyy.a....7..Ly.&:...e.%....R...*....]J5{.. .-X..7..`......g?....w0uR...`q..."..|6.,.47rL#..>..1...]'.:...S9..-..7..ZRA4.o.......;=....N.u...<Fh...$..S=..a'.R..............YB.o....c..U...k.V.7.......*@.....%(Y......g....J......l...{..*...d=...s..wwc....A.......0.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.80494261341535
                                                      Encrypted:false
                                                      SSDEEP:24:Dv8GLFhZIdb2Q2OAwJaGUkH8yCTjsm6ad6IW7WEFghuKBn:DvtDZG3bGNdvW77HKB
                                                      MD5:2C0AEE372A6FA1BB936B4A10FC6179A7
                                                      SHA1:3DCDC7BF262D90FC7E76AF7948B3B5028753B170
                                                      SHA-256:A988C8B843D7F39D6C8C2EE5261333C7F5D7F31C55A574E2C1BF13F88046D79C
                                                      SHA-512:1571A094092EC91E7C63B35093E1413DC785106AF49162866DB363E7BEAB6DDBB57CCB725C5121CE60CB9A5E79225A6F6CCF2273FC1CF1E18C28416112AA254B
                                                      Malicious:false
                                                      Preview:0..C..cm2SK....iO8!.H..x..4..*..1..@.w....F..f.....p.%..B.A..'b.j2c..T/.M..hH.\.W......E;....{.o..R.:)....1..5.>:.H.)l..o.{......kZ,f.(....F....=ov..`].....V.?.9^.e.1..D1.....Q.p=F..;.F[q....R;j.C6....;xQe......e..w.......4..K~..iyOo.$.T!....p.i^?...]....k.x77..,.O......L..4.l....%.....6)...'o.j.!...O..N.q$~.h.]...Y.......B.g..-..I.|)...t....wB,w3j.(.I...h..U].c(...4ovw:.=.r]...O..Qk. n..c........qW..|......1..$. YL..V..N........a.Q..).Y.>GL@|Hq.!2..1./.Y.?..O%].s.;J.D...p.v.R.......:.E..+..b..i....:.9.b.'.h...0%..tn.i...!.,..\Z<)...x..w;.....o.S...'{...'j..W.nY....G..&4.i.3.....>..Ny.&.@.to.L/..R....gr|v..B..@.m......p.2.3{A...j.?.$1..V...z~...3PoP....euP]H....d.-..y.5...........&...1E...F.z.t...3....M..{.i^Z..aP0.o.....e.C.1K.|.U...`.e...UP...E......GG..q..i.....%.!..};..;y._...u...;..?SA.r.<.Z..-&.....z...M^...{?w.A....U..o.3(..mtU.k.F.#.f.B......ASO.6..?5.......u...;....`...<..Q.}5>.S..2./~...`Q...B&9..#...Z.."b.>U...o.%.....>.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.833967001289037
                                                      Encrypted:false
                                                      SSDEEP:24:bkJsnHJAOYSjeofi962AcE2kvf/VDZVWZS+tUMeq2cM2kD8O5M2fcl/iGn:bkGnHJjB6962AcEdvf/VtQZS+ac51kDS
                                                      MD5:9A2B218404E3257BD114DB98F3677304
                                                      SHA1:6B2DAF31A90349874493EE3D806B09A4A0126285
                                                      SHA-256:721CC9866F5297D4D31FD0045EA24B5F175C178CB75158DD6AAB130D59CF07FD
                                                      SHA-512:6F907563DA8037EE91922442DD20237A9E31B6617FA558FE122837706C3584AB5AAB855250B0317B39EB055F468C3232A79534AC3A1F42C9648A68BC80693511
                                                      Malicious:false
                                                      Preview:WANACRY!.....[.v....".!.. .....t..O.....=t....)T...N.........W.w.bGg...D#..ba..."6..Q).g....pAQ9.*..W'+_.#g...A4..X....b+...YgJ.P.^.....RF..UN..3..x..q.O........R..>t..`.|.k5........r.>.@..,..,.z..|y..(}.rh.J.V.h.3..W.l..[.s.Q.=.!7d...~#.Q':......7%T...e...................k.#.].q`.....1.Ap.....^X..zKuv...j}.a../..."..\6.8*.z".......x.......Z".y..;k.....t;..}D.../Ev....(PYk.,o""...C^T&..qnt..A...7...K.@..O.^..[.{.......>..G..~,....d...w.......i...a....Z.)..iq)............N.......\K.T...?...P..5....p..x..oS...u..,..L.:...U..4...jl...E...IGLK..L..-.D..v._.....n....sP..HD.|x_....h..mf.K..3.(..-.._...'M... ..l_f.....w%..{...q...,...{....)R...h.d.Yu..MB.l...N.ps..;..U...0..3..Fk.0nMB.^1....|.~........W.....Z........t......D.P..J....7.0.5.....j)o"..V..I..4..^...p............1.O1.[..o+.[.+....|....s.U=.@..Kw&u.-L..H..1...=|c+...O..v.I..1..hr.g._t91...8>..q...B;...-..y-..F..o.......R.\.m4E..6.>.L9_[.`..x.O...*..{MK...0FLN\ yi/..@)...zD...
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.833967001289037
                                                      Encrypted:false
                                                      SSDEEP:24:bkJsnHJAOYSjeofi962AcE2kvf/VDZVWZS+tUMeq2cM2kD8O5M2fcl/iGn:bkGnHJjB6962AcEdvf/VtQZS+ac51kDS
                                                      MD5:9A2B218404E3257BD114DB98F3677304
                                                      SHA1:6B2DAF31A90349874493EE3D806B09A4A0126285
                                                      SHA-256:721CC9866F5297D4D31FD0045EA24B5F175C178CB75158DD6AAB130D59CF07FD
                                                      SHA-512:6F907563DA8037EE91922442DD20237A9E31B6617FA558FE122837706C3584AB5AAB855250B0317B39EB055F468C3232A79534AC3A1F42C9648A68BC80693511
                                                      Malicious:false
                                                      Preview:WANACRY!.....[.v....".!.. .....t..O.....=t....)T...N.........W.w.bGg...D#..ba..."6..Q).g....pAQ9.*..W'+_.#g...A4..X....b+...YgJ.P.^.....RF..UN..3..x..q.O........R..>t..`.|.k5........r.>.@..,..,.z..|y..(}.rh.J.V.h.3..W.l..[.s.Q.=.!7d...~#.Q':......7%T...e...................k.#.].q`.....1.Ap.....^X..zKuv...j}.a../..."..\6.8*.z".......x.......Z".y..;k.....t;..}D.../Ev....(PYk.,o""...C^T&..qnt..A...7...K.@..O.^..[.{.......>..G..~,....d...w.......i...a....Z.)..iq)............N.......\K.T...?...P..5....p..x..oS...u..,..L.:...U..4...jl...E...IGLK..L..-.D..v._.....n....sP..HD.|x_....h..mf.K..3.(..-.._...'M... ..l_f.....w%..{...q...,...{....)R...h.d.Yu..MB.l...N.ps..;..U...0..3..Fk.0nMB.^1....|.~........W.....Z........t......D.P..J....7.0.5.....j)o"..V..I..4..^...p............1.O1.[..o+.[.+....|....s.U=.@..Kw&u.-L..H..1...=|c+...O..v.I..1..hr.g._t91...8>..q...B;...-..y-..F..o.......R.\.m4E..6.>.L9_[.`..x.O...*..{MK...0FLN\ yi/..@)...zD...
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.8123863151185535
                                                      Encrypted:false
                                                      SSDEEP:24:JnskQHv9/Asut/6Q4OFd3g7qgvvax2MmJBjpx6H4U4:qkq9/32ia3okx25U4
                                                      MD5:8E3A88313A9A5CB81115EAD38D5BA0C1
                                                      SHA1:4B6A9D212DAB4FF5FD37841E92A3803C2D7F06FD
                                                      SHA-256:91DA79363425B1E89417A6F26904A6EA97E632C8B631C26F2378AF688B87F73A
                                                      SHA-512:5EA91FF90FA03E6104196E410F23EADE5A49094433651FDD1B9FE1F834782E29BE51EFCAE756A91ED29CC0EBEDA21DF59F3BB46C9319AE3D7D72EA0EDF541152
                                                      Malicious:false
                                                      Preview:?....c...K.A.q;R<....Y.t..w..U......1..^qI.go,.*]N.5...(..h&.....A..SE..b..'..Ozq.kqS5.......o.@..3N...d.v.o.J..f.J.r..y.......`~...=!...YE.@........b....t....nGI1W..(......".....(1j....u..8..|....:.El..C.#..E.....c6../.....=.N....8.]g0.I...1^............7.e.'..N..x..k......b.U|.#kT.D.....7RK..|.2&.*.:..i....@...{@..1T.^....5(-...G./.^........19z.L....R.a.L&...._.@zJS.N...h7la4./.-.....:$q.C...............;.c6.....hi.hb~V..Q.Q.f....t<%_.,...]n....7VM..".9..b...<.u...)..W..>...I^.Q..,...p3.%j..+..Z.......okf.\.Aw.yA...9...z.m....;4..Vj.^........>..+6..H....~_.)c...+.C.l.0....]....;.....)g..-....T.0..*48.G.......=...*.^Es@.O..p.`.T.......O...$,I...C.g8Ka5.....W..(.f.el..L~.-....QA{....1.dU..U(.{s-.r..x%P.....VIL....!.......:...E.....&..&.!B..}./.....!iz`Cbi.:}.._.,....>M.}$J#. .....l...../%~v..Q.PIt?.T.....r.HcQ..SM...!qy....f....P...j.b.......Jk.iT.mvh....R...*]...n.. ......Q..O.<r..rr..~.S.>.$.d....%.....q..%...-...S.\k.L.$,i...S.%Z..n.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.850731611750834
                                                      Encrypted:false
                                                      SSDEEP:24:bkRolLLgpn9Pzz+HCEa+bnxWL8bFvyKO8iMwf6zKTSF3ztZje:bk+JspZzyj3nPTO8iMZgSJe
                                                      MD5:63851713F5E5A4230C3C01878CF9EAD0
                                                      SHA1:F21B9B0E6E17AEAE3A4C622448E477C7B59EE571
                                                      SHA-256:294B3FB0A5106846824ABAED7086CD6B946B3470C4A82B7737168C95C17C9FEF
                                                      SHA-512:78B8B0F62C823AAD60D7B14BF2DC20D804586408689B96DB1DA21C56C6DBA1FAACBDCFBA07033FC6DFFFB117571128433A8700EB26D80D0049DCFBD638E165D1
                                                      Malicious:false
                                                      Preview:WANACRY!.............i.j<..K}.....&........!.n.8}6...!.t...@X..>....qS.a.#...`..SiF;..a.zh.....5..g..*.3Jj.S..[8..Wn...=.s.......o.'$Au...e.}.#".r.".[[..[...ZN/),o......B..9.Cc{Gg..45.d.7.h...J7.j3.z0..X.X?.3.)rE..R...h.{.I3.z.Hw...(...Y~3..`.2.#.......#R..a...............D.N]Si).km..D.I.a.)^.F.....i.....t..l*:..t...$#O...o.Pj...$/.>.........w._.b#(....b.\..Fu.OkU&e....-.#.k.]X .p.)v.i.4.....<....5IE...4..5..G..#T....f...]......T....L.B.Y...O...(.e...{..D.......{._..'rv...........;R.6c..ki ...E..$..!..V..8.\......{...[.81q..-........=./k|.W].]=p.E.)..."x:.G{.2h...K..M.]..|........58Q..m.;,.@9..}.6..0U>Tq..._.T.^.+W.F....!.._.D......pW..^..,P....*n@r..e.X^..;.....].$.D!.QK-.NL....Y.(.L....(5!.*.+6..$].e.+Y......v.%.,..A..Dk7...4V..7.k.K..4..N...Ww.d.2.....:...n.![.HY.N.F?;e..#..I..6Rd.v?....%f.=..|C0.KL..k.v....r..M......Qr.#i..@.<..T..q....N).......N.y(%......~.p|n....E.i.ka......0.]...Y..O .S.W..6.Z.I.J..L..Q..L..(..~\K.R....H.....[..2_
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.850731611750834
                                                      Encrypted:false
                                                      SSDEEP:24:bkRolLLgpn9Pzz+HCEa+bnxWL8bFvyKO8iMwf6zKTSF3ztZje:bk+JspZzyj3nPTO8iMZgSJe
                                                      MD5:63851713F5E5A4230C3C01878CF9EAD0
                                                      SHA1:F21B9B0E6E17AEAE3A4C622448E477C7B59EE571
                                                      SHA-256:294B3FB0A5106846824ABAED7086CD6B946B3470C4A82B7737168C95C17C9FEF
                                                      SHA-512:78B8B0F62C823AAD60D7B14BF2DC20D804586408689B96DB1DA21C56C6DBA1FAACBDCFBA07033FC6DFFFB117571128433A8700EB26D80D0049DCFBD638E165D1
                                                      Malicious:false
                                                      Preview:WANACRY!.............i.j<..K}.....&........!.n.8}6...!.t...@X..>....qS.a.#...`..SiF;..a.zh.....5..g..*.3Jj.S..[8..Wn...=.s.......o.'$Au...e.}.#".r.".[[..[...ZN/),o......B..9.Cc{Gg..45.d.7.h...J7.j3.z0..X.X?.3.)rE..R...h.{.I3.z.Hw...(...Y~3..`.2.#.......#R..a...............D.N]Si).km..D.I.a.)^.F.....i.....t..l*:..t...$#O...o.Pj...$/.>.........w._.b#(....b.\..Fu.OkU&e....-.#.k.]X .p.)v.i.4.....<....5IE...4..5..G..#T....f...]......T....L.B.Y...O...(.e...{..D.......{._..'rv...........;R.6c..ki ...E..$..!..V..8.\......{...[.81q..-........=./k|.W].]=p.E.)..."x:.G{.2h...K..M.]..|........58Q..m.;,.@9..}.6..0U>Tq..._.T.^.+W.F....!.._.D......pW..^..,P....*n@r..e.X^..;.....].$.D!.QK-.NL....Y.(.L....(5!.*.+6..$].e.+Y......v.%.,..A..Dk7...4V..7.k.K..4..N...Ww.d.2.....:...n.![.HY.N.F?;e..#..I..6Rd.v?....%f.=..|C0.KL..k.v....r..M......Qr.#i..@.<..T..q....N).......N.y(%......~.p|n....E.i.ka......0.]...Y..O .S.W..6.Z.I.J..L..Q..L..(..~\K.R....H.....[..2_
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.80946241341476
                                                      Encrypted:false
                                                      SSDEEP:24:t3cHUODDZTL+VLzL/rrQMu+cp8lp/VZYGNU+AYGKaK:VgU8Z2VXLTrZu+cp8ldVZxFAY7j
                                                      MD5:B7532FA78E78C106B63559FD57E9F11C
                                                      SHA1:CF62F2D65F493BF32FD58FFF92DAA0396271F277
                                                      SHA-256:B902E5749BBA88497A98D327D93FFC23795648D6E9B42EEF13551385B5E3F855
                                                      SHA-512:37392494A4952AD915E7935199148AAB19591471BBE2FF168E1BC4EDA4E6882DA32E3CC95DBF109A86103EA6314D266D4E0D270E142B7320B9EE2DDB0B7FA371
                                                      Malicious:false
                                                      Preview:...wB..@I........X{X2K.N.....s$o%o....A..U.y..^[..{...Z&./..G;..e..,".D(F......6..".....-...d.:z.5}O......zw0..a.<9,....2..?;..t...H.P...g.WS..p.z^.A.w...$l0.3...g..|..bw....d....cz..9.<!....=[.xJ..'M.......@.D.0>.......F$\4..].c....[.:7hs.`.R...'.I.>...9\....!l.<..J.#......?..4.A-m..9>..f. .i.2..G./....y..... .tp...c......9N.j.....*:.)...D=b.P.....T.D...c....Sz6o.`.........#?@....n....f....{.g....-.-)6c.....D......v}.....;.~3&...h.*.......m.#...-x.H.H..._....9. ....h...F..v.E..93=e...O.W%@o.bMP.].2..Xo....Y^).w...I.D...u..W!L.`....G.Y.szv.T...9.o.j.W*..G......9.o..sc.z....J..e.&.E.GVN...1m.R..+..m&.M.W4aAA.pL......s^B>.qJ=..=./.`...(.............|._.2a.l.f..N..HJ.)...0v....Wc.*#..o...fW..z...P F._..G......i....K.._.Y....a_"..1.0.CsNY...F...&. ._0..F|.%.p,..G.|..z.I..ss.o..s.....MY.`...[..s..e......_..0.~.m.AK.E......0..C..6.5...~.T.....nt0...\)....:....../...4$.:.N.U-........Y=.C..S...>O=[.]...IAz..y........V. .f..... ....&L..AB.......
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.852880707222743
                                                      Encrypted:false
                                                      SSDEEP:24:bkT/F32U7FTsbh9+BpUuHHQ+H4UiBqBcBzP60vXS7wxQN0YiX:bkzh9c9MuuHHn1BcpPtYO
                                                      MD5:B81BC4B808378A17D14F6DC6BC67CF33
                                                      SHA1:F28EA5CCAF7CF8D657E63046A15CA0D359552221
                                                      SHA-256:0832CDC5A5375FF29D22395EBCA464662C6E9B9462443822AA9477F17848ECB5
                                                      SHA-512:3A926B54E95CD11E45F2CA2313221D24CA8F9CA594211E2DEBC5B08A1183873C392CD3E8F2FF10A082F6CA2516AD4ADA2D33BCB8444282EE5A98D8428260C8C7
                                                      Malicious:false
                                                      Preview:WANACRY!.....9p>{...^...tO...7..y..(..9X..k}2..*.....C*.+..U<.9.A....D.u...y9l..z.1).2.D.....=..\.0...7....NA..HZ%....#..=~....r......S........Jk..c...LkX......e5Y..j.;......#.., ...X..$.t.............m.~c...Js.#B......+...$...G......d...(..M...b.`Yz%.R....................2=&..m&.0...........\......ot.u...6#....N.=..TO.y..$io...M.zI........../.....e..RV..:=..Vu....zG....,.z..=8....I..2...w......T.>..u|...k...eL..t.]z.cs....Y...I....q...6z..C.zp...V..eit.....t...."SR.Q.KG(Ge.w..>..Y.....P(..y...x..H.....?...>7.P......7.q$.n5..L4.....@".z.0+Bq.Y.....4.k.............5..r;.B.9<..O.!.....K,....+......Dd.........j....S.....w`.=z.....kX....w.NV.q+....O..u.:.../<w..\..8N...~....W_.1.s..FM/..23.^....Hi.....;.r.2....7U..$g..T..).1..}.v}..8.9.1.N..&..2J..!.....C.#k...(G...5...C........X.@`....aC!\e..<.....\.0..>a...3O....d.?I%V.g\..[.W..vq..<.....Z..m.7...hR.}1..?....l........b\u.. )...9..i.H...x.t..2-....E~,.U...D...m.-U'.G~j..]bW..i.v..5u
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.852880707222743
                                                      Encrypted:false
                                                      SSDEEP:24:bkT/F32U7FTsbh9+BpUuHHQ+H4UiBqBcBzP60vXS7wxQN0YiX:bkzh9c9MuuHHn1BcpPtYO
                                                      MD5:B81BC4B808378A17D14F6DC6BC67CF33
                                                      SHA1:F28EA5CCAF7CF8D657E63046A15CA0D359552221
                                                      SHA-256:0832CDC5A5375FF29D22395EBCA464662C6E9B9462443822AA9477F17848ECB5
                                                      SHA-512:3A926B54E95CD11E45F2CA2313221D24CA8F9CA594211E2DEBC5B08A1183873C392CD3E8F2FF10A082F6CA2516AD4ADA2D33BCB8444282EE5A98D8428260C8C7
                                                      Malicious:false
                                                      Preview:WANACRY!.....9p>{...^...tO...7..y..(..9X..k}2..*.....C*.+..U<.9.A....D.u...y9l..z.1).2.D.....=..\.0...7....NA..HZ%....#..=~....r......S........Jk..c...LkX......e5Y..j.;......#.., ...X..$.t.............m.~c...Js.#B......+...$...G......d...(..M...b.`Yz%.R....................2=&..m&.0...........\......ot.u...6#....N.=..TO.y..$io...M.zI........../.....e..RV..:=..Vu....zG....,.z..=8....I..2...w......T.>..u|...k...eL..t.]z.cs....Y...I....q...6z..C.zp...V..eit.....t...."SR.Q.KG(Ge.w..>..Y.....P(..y...x..H.....?...>7.P......7.q$.n5..L4.....@".z.0+Bq.Y.....4.k.............5..r;.B.9<..O.!.....K,....+......Dd.........j....S.....w`.=z.....kX....w.NV.q+....O..u.:.../<w..\..8N...~....W_.1.s..FM/..23.^....Hi.....;.r.2....7U..$g..T..).1..}.v}..8.9.1.N..&..2J..!.....C.#k...(G...5...C........X.@`....aC!\e..<.....\.0..>a...3O....d.?I%V.g\..[.W..vq..<.....Z..m.7...hR.}1..?....l........b\u.. )...9..i.H...x.t..2-....E~,.U...D...m.-U'.G~j..]bW..i.v..5u
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:ASCII text, with CRLF line terminators
                                                      Category:dropped
                                                      Size (bytes):933
                                                      Entropy (8bit):4.710902136409594
                                                      Encrypted:false
                                                      SSDEEP:24:ptrPzDVR5Gi3OzGm0EigS1xbnS4RQhbrW8PNAi0eEprY+Ai75wRZcet:DZD36W3ChvWmMo+S
                                                      MD5:7E6B6DA7C61FCB66F3F30166871DEF5B
                                                      SHA1:00F699CF9BBC0308F6E101283ECA15A7C566D4F9
                                                      SHA-256:4A25D98C121BB3BD5B54E0B6A5348F7B09966BFFEEC30776E5A731813F05D49E
                                                      SHA-512:E5A56137F325904E0C7DE1D0DF38745F733652214F0CDB6EF173FA0743A334F95BED274DF79469E270C9208E6BDC2E6251EF0CDD81AF20FA1897929663E2C7D3
                                                      Malicious:false
                                                      Preview:Q: What's wrong with my files?....A: Ooops, your important files are encrypted. It means you will not be able to access them anymore until they are decrypted... If you follow our instructions, we guarantee that you can decrypt all your files quickly and safely!.. Let's start decrypting!....Q: What do I do?....A: First, you need to pay service fees for the decryption... Please send $300 worth of bitcoin to this bitcoin address: 13AM4VW2dhxYgXeQepoHkHSQuy6NgaEb94.... Next, please find an application file named "@WanaDecryptor@.exe". It is the decrypt software... Run and follow the instructions! (You may need to disable your antivirus for a while.).. ..Q: How can I trust?....A: Don't worry about decryption... We will decrypt your files surely because nobody will trust us if we cheat users... ....* If you need our assistance, send a message by clicking <Contact Us> on the decryptor window....
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Archive, ctime=Thu Jul 25 21:01:45 2024, mtime=Thu Jul 25 21:01:45 2024, atime=Fri May 12 05:22:56 2017, length=245760, window=hide
                                                      Category:dropped
                                                      Size (bytes):575
                                                      Entropy (8bit):5.140446565826782
                                                      Encrypted:false
                                                      SSDEEP:6:4xtQl3y03CpzeVs+bTNAUHUtxXCzaMmM7/gtrUod6tMljAlpdmqLEoJ4D6Vod6Nd:8iypzYNbd0thHZOgZUobjArozhmV
                                                      MD5:CCD2610ADD4080C4DCC35A11217DA6A6
                                                      SHA1:001ABA92D58B546C8BD54E0BC4103661F68CF92A
                                                      SHA-256:0E272CF58CC66E7B0CC4F42094232A46B6EC11AE5ED695BA4156A1A28DA41E6D
                                                      SHA-512:36DC5CE3027E8A77639783E31AC69C9FA61C4761FBEB9A819C1EB49F4A32BF2001C0441FB28D35C4EC9DD1B713576E7894DE8FD13BF14CE62A436F9619093DEC
                                                      Malicious:false
                                                      Preview:L..................F.... ....b{=.....b{=.....`.1.................................P.O. .:i.....+00.:...:..,.LB.)...A&...&........DDj....%.=....(..=......t.2......J.2 .@WANAD~1.EXE..X.......X7..X7...............................@.W.a.n.a.D.e.c.r.y.p.t.o.r.@...e.x.e.......X...............-.......W.............,p.....C:\Users\user\Desktop\@WanaDecryptor@.exe......\.@.W.a.n.a.D.e.c.r.y.p.t.o.r.@...e.x.e.`.......X.......216041...........hT..CrF.f4... .u.E._c...,...E...hT..CrF.f4... .u.E._c...,...E..E.......9...1SPS..mD..pH.H@..=x.....h....H.....K...YM...?................
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.794197672984629
                                                      Encrypted:false
                                                      SSDEEP:24:M6Ff4rJxM16M3tTYx5Y7jWUF2xf5rG+pKD7qgRKM39O:ZsYIsTYxCjW82Z5rTpoW5
                                                      MD5:482036DE068C7672A63196B9289CABF0
                                                      SHA1:C97085E9B257979BB2E24A0BFD9BB35B66084FCA
                                                      SHA-256:76C2F7F1D47581D8B4DAC1E6BC160A40B4F5065684728AB6951C4E607591FA04
                                                      SHA-512:E2DFC97F946F0FD7EC8429951507714D85091706ED20BBC7C03D2388C046D7418EB135C2CDD30E3AE8945F98EA6DFF076CA673952EFD985A4AEE66BB233D65E6
                                                      Malicious:false
                                                      Preview:..S.:c.T.t`........d.B)6....5`$.C......PI..b....&.k.\q....B......}.=...mS..V..x,.b>.R...{j7S.t?.n.`.;Q...a.j.`/J.....+..s}..H.....1J..N.*...i5.e.B..............LV....s.....F}..r!.O.(N....<.A............(.M..].b..G.!...]D...b.'..:.(...zW^/j....bT....3f....OP..r.65.(..m!L...>.$t........{....>.O...Ws.....z.:.E.dpo.#.e._......m...A3..{5.a[........s.UUs.t...h.G.T.....0....Z.g...=P..}o...r.%M..a....@.~..*..cNx=.....F>Z;S.*..;..o....'X.......T.Y.4..l.......-a.......7..7=f...,As.7(....!...#....St..9e.0h.Y..Y.....~E/....P.VR..*0..%.,..5s..8..A.|vs.@..f.g..k..d3..y.Uc.....p.B......6@;X:.......t..>....sg!<I:...Wv3.-.f.2.Fr/..n.\.u. ..8..E.............+{;....e...Z>.....o..hg.|.y&ig..4..`......#.rj*%..jBs.Px....a....2.E...bRr..*.M...N9..MM....$..u.GRrU.Dn.<.3..bQ.....S..-..$......YT.GQ.9(^.b..%9...Z_..[.iO....*...h>F,.....l.U..M......1XNsB.'P.M.t.gy.\.T..Vt.....(.f!lk.U..-=7V..A..j.Q*...M%...Ik....0.8m.Z..cJ.......(c...w..U...5.B.H.....)p._.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.819752830789333
                                                      Encrypted:false
                                                      SSDEEP:24:bkQFyg2DHDfA96Fv05tpVVwTerWS33ThkBOPdIcBUZ24a/8xVlE4Lzv3A:bkQD2jrA96v0DpV6MWSS8lSZ2TYEAzY
                                                      MD5:5E95A9B02A9A7C8B1E3BF577903A9DFF
                                                      SHA1:096F111AFEDF25D6E180A31CAE4B52F53DEBAEC7
                                                      SHA-256:B46AC3FA7BB3B232492E470D2A4D4390B1596E5681AEF7FEB597EEE9388915C3
                                                      SHA-512:1E7D1B504F9A81C4FAE6DFE87367197013816B487087EEDBC3BDFD2A3BA2CC87703348946FE25C604C11C5F58475699184E401DB4337C03A771CF99A984CB7D2
                                                      Malicious:false
                                                      Preview:WANACRY!........ .....qc.j.=N...6....N.k..7+..q.../G...u5]......x....k...}.S..1.H..k...9.-...mj.....&.......E...0.>........O`.|\Y.?..$ ....s..)...._P....F.f.....MMk.~ZW.6[.....K...,-A.a..bv.....PS...>$...~ 6..I.~].~.^.Y..S.C...Q| ..yO.?.1.q._...V..6bUw.A............#..HyU.../.p../.2cyD$E........ym=..^.-...iH`kK.m....J!.VR..(*"@..FS=.......E....>6.txl.V%..v..-.".....|."P*p.*y.y4$..#.Hh.{c!..y}i`.h...{...l...|<........N.U....'.K$.S...e....^.B.i.....(...5_?sM..V2[S....HU3......?'.p.......Hm......Y}.......Ea...{..1.....~.[.b~...!...I.K-.k.KxS..s...Ju?m....V....+..L......M%.....G.5?..:..o..P...D..*vF..6N...... .......~i.?u...?....J....7...E.....E.'2%A..I...D...... o..1*.8.<`H..Y#....#.7..R.`"....g..,.zm{}........&.).]9..G-...0.R...;.P...9..$..5&V.o......p.#.....4G.SY.]6...f*;d.Kmm..s.b60C.UH[a.d.H......x.n.".'W...[.[2...y.....+-.(i.....M...E.D.T...^.zd{...%c._rg.2..G40....z.....*...*&....7....}.i.a.N..Sa..O&.b5,mP1.t"..l.....Y.j;.^.#.|yU...
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.819752830789333
                                                      Encrypted:false
                                                      SSDEEP:24:bkQFyg2DHDfA96Fv05tpVVwTerWS33ThkBOPdIcBUZ24a/8xVlE4Lzv3A:bkQD2jrA96v0DpV6MWSS8lSZ2TYEAzY
                                                      MD5:5E95A9B02A9A7C8B1E3BF577903A9DFF
                                                      SHA1:096F111AFEDF25D6E180A31CAE4B52F53DEBAEC7
                                                      SHA-256:B46AC3FA7BB3B232492E470D2A4D4390B1596E5681AEF7FEB597EEE9388915C3
                                                      SHA-512:1E7D1B504F9A81C4FAE6DFE87367197013816B487087EEDBC3BDFD2A3BA2CC87703348946FE25C604C11C5F58475699184E401DB4337C03A771CF99A984CB7D2
                                                      Malicious:false
                                                      Preview:WANACRY!........ .....qc.j.=N...6....N.k..7+..q.../G...u5]......x....k...}.S..1.H..k...9.-...mj.....&.......E...0.>........O`.|\Y.?..$ ....s..)...._P....F.f.....MMk.~ZW.6[.....K...,-A.a..bv.....PS...>$...~ 6..I.~].~.^.Y..S.C...Q| ..yO.?.1.q._...V..6bUw.A............#..HyU.../.p../.2cyD$E........ym=..^.-...iH`kK.m....J!.VR..(*"@..FS=.......E....>6.txl.V%..v..-.".....|."P*p.*y.y4$..#.Hh.{c!..y}i`.h...{...l...|<........N.U....'.K$.S...e....^.B.i.....(...5_?sM..V2[S....HU3......?'.p.......Hm......Y}.......Ea...{..1.....~.[.b~...!...I.K-.k.KxS..s...Ju?m....V....+..L......M%.....G.5?..:..o..P...D..*vF..6N...... .......~i.?u...?....J....7...E.....E.'2%A..I...D...... o..1*.8.<`H..Y#....#.7..R.`"....g..,.zm{}........&.).]9..G-...0.R...;.P...9..$..5&V.o......p.#.....4G.SY.]6...f*;d.Kmm..s.b60C.UH[a.d.H......x.n.".'W...[.[2...y.....+-.(i.....M...E.D.T...^.zd{...%c._rg.2..G40....z.....*...*&....7....}.i.a.N..Sa..O&.b5,mP1.t"..l.....Y.j;.^.#.|yU...
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.808550909717734
                                                      Encrypted:false
                                                      SSDEEP:24:A8ieResCF3ZePC9nnuHrCFyQLQlPuGVBI9FhEeTdOH+m2/QSmmZze2K:H7CDe6NcmFX2NI9hoM3ep
                                                      MD5:014CE7AB6FAD2A089A6BFE79FB3CDA74
                                                      SHA1:FB10136270678781258E02816E34A95A1A3CBFD6
                                                      SHA-256:94E1E42E954947DC045D47538B3D2F0FC495DCDDB01F6B1EF9E58E4B7FBF294D
                                                      SHA-512:1ED3C7598575EBF5FBEF1253DFA8F01893857C3BEF928A42AD46058D3EDCC85BFF970F68D67BD3B289184CD0B06C7AEF85500F57BF6DE8A2DE8DC6BB519E21D8
                                                      Malicious:false
                                                      Preview:E.Y%.s.........._...\.rW&...@*.C....cR../.cHI........C.z~t...+5`36.{(.._..c....+..~I+8..].|.D.%.5..U.e|..'.$..Z4..{.N...fE..F;..n=......d..S2..?.l.&..j.8.|$..%..._.pN[k..Q...P|..Um.%%f|".s Z8.....x...D..Y.S...q+...#E....5p..&.~.\.qe..y.'vQ..).MS...l..u..;G.Uq......!..4.....)...U..$..M..d.=...~..H.I..#7.k....[.......~!.D.S^.M5.......(...5.B....<-[]2..._.,.A]3V..,o'2.`.^....5..Qc.z4....rk.&. .Ei./.v........b......*......).....M....x..H5.........q3.:.F.....F...r'.I..fx.$.@t..-_...H......U..?6.3.....N..k.Z.]9.........z|...Ln9H.t.^.u...oA..,.<.q33k.:....Y.o.k.U...7Ff............).|x.j....d..s....W......N+.kC....T2XFuPl'...}.N?....0IhE.T4..s.toM6e..aD.6...B.-T=c.a..i.p..QG3.v..u.I......{.......a..;d.)..s=g..8.......|........)).l.... .o...T..r.E*.#......6u.F....\.O....@.S...bW..KW...I_.K.....A........(9.7A.a.s...:....`...........n....>...Q..]$.8T.Y..s/...{...<...rc.A?...=..O.......h,;.....k..F....._.....g.v.....R..X..\wt..#M~.a{.h>..8.]?.Qr.....x.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.823891919874285
                                                      Encrypted:false
                                                      SSDEEP:24:bk4XqzGMvYeQFBXLLQ7pk8/8tH3bWbW9vOC5Sa1BosXIDgyquY:bkaqCMvYeEopk8O3DvRlhyqX
                                                      MD5:09880B81D70408EE5FC0123BF570EAF7
                                                      SHA1:EFEE2AE688366ED0C9C828B0E542BCB06EBAA277
                                                      SHA-256:431C7DF34A06BAA7A9415184969D8B2336EAA6EF9009F544E07FF811FE82A43A
                                                      SHA-512:6003B6CBD904973C5F5E33D0E593CAD8F5F029209D6503A46909AA6D58F129E7E4B3213FEADA0973EAB638B76F68ED8A668427D5C6A7FA6976CBDF7AEB9AACB4
                                                      Malicious:false
                                                      Preview:WANACRY!....F{..k..`...G]q..JVj.p.....+....E..t..".J~/6..o...#..djP.RB0>..w.x+......W......=....V.f...{..\.{...O....g.B?.......;W..O....:..^.P.w..I.......h,o...H..Z....`.L?.^Q<'S...X.X...V).J...A..`.......X.....@.....S...];H.q.v.-.u?.....)$.;.....o..\............r...F).D.R...K.\.+.T...... F0LuB.^..6Q..R.<iLn.}.|.|.T...."Q_n..........u.^o.........o....S.L.x.B..}...W....c.0...)..=.w.U...y..V:&..@i..V......:C..2.P.U....?.k[.`.?o....2...b.a..`....\.>d.....5BO.J.k.Uo..W.L`..Y......:y3.hT.-u..$-M..K.Tk .I"..g..M.<[.$5;.c......aF.(7.....~O..Fb.....w.. ..#....Lkw.>.i.+.@.$...<.F .?...D...0...N(.A..W.^c5.1].z./../....py....||..$.^%..+.FU.A).UBn...$q..&..SU{.3%;..}..K/...w7b...v.X.y... .....\..p.&.c.B'.]3.D..D.X._.`.?.T..n.:b..}.|KW2N...@. _T..O..'z./..."..Q0|Q...:.>g..O.[g....._.W..@.B-X.X.H.+......d>...R.Z+Q...-..j....%.dI.B6...z.N}!.K..U.......K.K..x.F.d|..|.aS.*.._n.f'vA..h..L./&...B..b.o.f....e..oa.a(7.......*..Ot...[........L.=.:r:.`..]A...F..
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.823891919874285
                                                      Encrypted:false
                                                      SSDEEP:24:bk4XqzGMvYeQFBXLLQ7pk8/8tH3bWbW9vOC5Sa1BosXIDgyquY:bkaqCMvYeEopk8O3DvRlhyqX
                                                      MD5:09880B81D70408EE5FC0123BF570EAF7
                                                      SHA1:EFEE2AE688366ED0C9C828B0E542BCB06EBAA277
                                                      SHA-256:431C7DF34A06BAA7A9415184969D8B2336EAA6EF9009F544E07FF811FE82A43A
                                                      SHA-512:6003B6CBD904973C5F5E33D0E593CAD8F5F029209D6503A46909AA6D58F129E7E4B3213FEADA0973EAB638B76F68ED8A668427D5C6A7FA6976CBDF7AEB9AACB4
                                                      Malicious:false
                                                      Preview:WANACRY!....F{..k..`...G]q..JVj.p.....+....E..t..".J~/6..o...#..djP.RB0>..w.x+......W......=....V.f...{..\.{...O....g.B?.......;W..O....:..^.P.w..I.......h,o...H..Z....`.L?.^Q<'S...X.X...V).J...A..`.......X.....@.....S...];H.q.v.-.u?.....)$.;.....o..\............r...F).D.R...K.\.+.T...... F0LuB.^..6Q..R.<iLn.}.|.|.T...."Q_n..........u.^o.........o....S.L.x.B..}...W....c.0...)..=.w.U...y..V:&..@i..V......:C..2.P.U....?.k[.`.?o....2...b.a..`....\.>d.....5BO.J.k.Uo..W.L`..Y......:y3.hT.-u..$-M..K.Tk .I"..g..M.<[.$5;.c......aF.(7.....~O..Fb.....w.. ..#....Lkw.>.i.+.@.$...<.F .?...D...0...N(.A..W.^c5.1].z./../....py....||..$.^%..+.FU.A).UBn...$q..&..SU{.3%;..}..K/...w7b...v.X.y... .....\..p.&.c.B'.]3.D..D.X._.`.?.T..n.:b..}.|KW2N...@. _T..O..'z./..."..Q0|Q...:.>g..O.[g....._.W..@.B-X.X.H.+......d>...R.Z+Q...-..j....%.dI.B6...z.N}!.K..U.......K.K..x.F.d|..|.aS.*.._n.f'vA..h..L./&...B..b.o.f....e..oa.a(7.......*..Ot...[........L.=.:r:.`..]A...F..
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.837818733034449
                                                      Encrypted:false
                                                      SSDEEP:24:uJlHuHEq8Dq/P5TAE80w6abDTeIWEDuPVQtQiN/DRMA4:uJ9M8wh0t6dIWmuN4v4
                                                      MD5:15CB1878593DCE1B2CBCFD3185015496
                                                      SHA1:F254332CA8630EE7CFD934BD985A8C3A2F5DEA9C
                                                      SHA-256:F8984CFB03A1BD246DC153685579FCFEAC15040AD15F1567F5534A23085589E8
                                                      SHA-512:D57FF49182F0A97F7C6982FFC3A6EED3A4F3B1FBF067932C2A55A2FDB39568714C7F5A3073BF0393E8CB42E32778B2FE9129803B372464150BCA956F5E680258
                                                      Malicious:false
                                                      Preview:.1.^....:Q.|U..z..(.c.*....."3.._.X....?.5&cVUOH.....$..Y...E....}[.@..uW..)..<mAm..........50..%&.2M............b. .....cpT.....+e?..7(4..c.5..t|r.l...??....TA..N.bK@......U..q>...f....uN'|.y4=....pq....6n..V.{y...HF@:.Y.....v^....IQ.....D.Y...l.G..)..4..~c..M.B...H5.{.k..*..Ef-".W>.(.r.d.Ht..P....FH...+.S.1#..p..9....#Vn_....l..p...j#..f...+.o.%Dup..3[...AhF.-.3\.Y....#..1..4..3....?.W...,.B..%H.wCW.......6"..-.CIM..T....{D\.....[~p.?.......N.^.....1&...x.q.tA.r...g.......".$.A..yzSE].`...Wr.R...~6B..OH.y..k.O......X.u.O.!.c.9..2X...a.....%..79+.a".....x.`f... ..' ..<${'9..i..(..[S..\.....mUAc.3L...?. ....|Q............_....:;,.}..u7)W..n..".._.6|....wK..,..Y....$....}..R9..,[[..n.:U@&.zgS[......I..(x.o...c...$........}.+.C.].@(=..!.5...mN....}_...'\9~...j..~%c...0.X_E.$,.....4.....HT.$+,)r.E.~G.+......i...2..m0......L.F.|....(..K...wu1R*Z.>Pb...Et0....,..e.`T...b...S.........D....-.E..O..C.......i.i.z\.x..W...v.A8.M..O.`....U.^.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.873608984731805
                                                      Encrypted:false
                                                      SSDEEP:24:bk5ymDYfubaTBBJEDqIV1GlDDTNhHpH9tBzy0vDrLCoiI60hmXT+1sxGAbSFwGjE:bkXYUCbEgHhJH9FvDrW9q1nAehLuH
                                                      MD5:E282473D734C0D3A42B10EC252D29C66
                                                      SHA1:2681ADB529031940E1A44D1F9DC51313AADEEA85
                                                      SHA-256:40B774E220F131BAFF62A03C3238D6A4A9E6405AF21BE841215995202CD6C422
                                                      SHA-512:0FAB800E33C2DB62C0BCD323332C053828017C245F45EFEDBBB90E322DA6118D6AD41474326BE10537FF2343D60998F8D20BBEC07C1B30F9C2961813B1929712
                                                      Malicious:false
                                                      Preview:WANACRY!....Aw....>.=.D2.m.?.6./~......(....ML.m........a...U....t.7$O.pT&.kLE._.F.......1....K...9..%.:..b~..^.Ep....Piny.......<...J......J+4....OpZc..ql.2UH.n;......G..3.......R@s..+.. ..?..uY....w..l.@....J.^...R.I)......Q0.A*..(7....p/.4.V..|N..................u...g.v.J.......... ..B..L......j..Xf....6.Y...m....oCe..#......p$H.J...~..3/I..m.8..Q...Ln.vT..6..kY.w.j....*.OEH..hv...q..Q.t.K<E."....*.k....w_.w.7....9vw.^.."U...FE}.!&..aMj.X.3.4..-.{..J!..AQ....o{...$.Su....~..`..|s...:..(x\4.;`..5...lv..." ..[O:...}..*.yXR. .~./..].~?./L...khx.d.TB} ...{(..E"....2.^...#e..z.....G..V...>{.$......Uo&"..pkK.A..\~...0zf..7....M.t.p_.....R?.9.0...0x....D.....g..M..B.s.,...x.mo.!..V...F..*.b'.g.B1..w.r.Y{s..q%E.:./....F.GC4.a...3.|...C.1..W2.l...$.JR....{.I.J..z...'3gy.:X.#..O....*M.Z..6.V....C.ki..9.......ON>..m.R.G..i<..D.d.l.)3.......3..f.B....u(...o.[._...........+`.*+..'aB.T.3.).. c..i.......0=.._~Bo;.....t.....g4.7N.y....<.....I.m._g
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.873608984731805
                                                      Encrypted:false
                                                      SSDEEP:24:bk5ymDYfubaTBBJEDqIV1GlDDTNhHpH9tBzy0vDrLCoiI60hmXT+1sxGAbSFwGjE:bkXYUCbEgHhJH9FvDrW9q1nAehLuH
                                                      MD5:E282473D734C0D3A42B10EC252D29C66
                                                      SHA1:2681ADB529031940E1A44D1F9DC51313AADEEA85
                                                      SHA-256:40B774E220F131BAFF62A03C3238D6A4A9E6405AF21BE841215995202CD6C422
                                                      SHA-512:0FAB800E33C2DB62C0BCD323332C053828017C245F45EFEDBBB90E322DA6118D6AD41474326BE10537FF2343D60998F8D20BBEC07C1B30F9C2961813B1929712
                                                      Malicious:false
                                                      Preview:WANACRY!....Aw....>.=.D2.m.?.6./~......(....ML.m........a...U....t.7$O.pT&.kLE._.F.......1....K...9..%.:..b~..^.Ep....Piny.......<...J......J+4....OpZc..ql.2UH.n;......G..3.......R@s..+.. ..?..uY....w..l.@....J.^...R.I)......Q0.A*..(7....p/.4.V..|N..................u...g.v.J.......... ..B..L......j..Xf....6.Y...m....oCe..#......p$H.J...~..3/I..m.8..Q...Ln.vT..6..kY.w.j....*.OEH..hv...q..Q.t.K<E."....*.k....w_.w.7....9vw.^.."U...FE}.!&..aMj.X.3.4..-.{..J!..AQ....o{...$.Su....~..`..|s...:..(x\4.;`..5...lv..." ..[O:...}..*.yXR. .~./..].~?./L...khx.d.TB} ...{(..E"....2.^...#e..z.....G..V...>{.$......Uo&"..pkK.A..\~...0zf..7....M.t.p_.....R?.9.0...0x....D.....g..M..B.s.,...x.mo.!..V...F..*.b'.g.B1..w.r.Y{s..q%E.:./....F.GC4.a...3.|...C.1..W2.l...$.JR....{.I.J..z...'3gy.:X.#..O....*M.Z..6.V....C.ki..9.......ON>..m.R.G..i<..D.d.l.)3.......3..f.B....u(...o.[._...........+`.*+..'aB.T.3.).. c..i.......0=.._~Bo;.....t.....g4.7N.y....<.....I.m._g
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.798456718819192
                                                      Encrypted:false
                                                      SSDEEP:24:MuogsEk8LziuZ68QVSidpIqN/4ciDcghUuO:MWsEtJZ5+4qh5igUU9
                                                      MD5:9463D178BC7250FA437943DFC081A9B1
                                                      SHA1:60DAB2E418FF8643C68C81F8B639FD36CAAB9432
                                                      SHA-256:0144DC7C58AC98978A77E47CE71C44A3EEE935ED77C229ABF3151C1014C34F05
                                                      SHA-512:A07490498FC04629F399B94A46E6A50621EC16ED5FD0857656D4CD001C13DFDE8EB2CBE9291E281254DB68458E1465A3762FFEF636B4A9D2EE778A9BFE3B46D6
                                                      Malicious:false
                                                      Preview:o...K+;.s.v........L...a.J...Y*K~-g.X.q..Hc.VPW.f....XD.Jz.N_.$..,^...vF..o..?X.G..D.....i%.I..nd..T..Ne5Z.O.%...b..q.~.....E..).P.....e)o.\S...*.9UGA..\...<...`X.?9.w.3..V.x.y......dw^.*..r..^.h..CR...1....t{..|.v;...r..0..1.-..AYAO.m.?.?r}...9......k..4..c..W..U|..2.o..@!.jyS=dz/.U..R..C`..7.&..|..<...v..Y\o.l...w.u.-i......d.r-.....fniv#.s...9.~...q6.D..].6...0X..C.?......S..=...N0..JK|.-./..=.T....~.N=W.C.?..n.=%R.As5.....cq.'..Y.P.....Wr-...N......SV......A(...q......O....]F..e.]Q.R..........L.H.[u.J."2h.c.....3s|.K.f..7.....N./.a.F.D.]?Bq..j=?..8......3......AKO0h....B.).n..$.N.E....g.A=<d.......9.x...z...I...M....h.....<........>a...l.U>..T.....SioMl...<.........aZ...&.-..i]...).'....<0...e.~wyO.q.S"....Lh.U?L........-FD.....B.....9...f..;...?..Jg.R".....eu{=...1.......-..T.......JYt[..V....F........+3.k2...c..|'......w...iW5.c=.Br.....@...]7e.v.?L9.pa^V.8.e.u..9tx8.x....)!....!.4L.n.D2...@....C.(....."...t."...I4.h.....-..xg(rV..Ro
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.8652992265853285
                                                      Encrypted:false
                                                      SSDEEP:24:bkZg4y1o+yF6UVmwzioeZI6vdzPZ5Xms8wpRQelnKYp57IPBJRJ8pzKHm:bkZtKLlfXFt54w8UKwl0b8EG
                                                      MD5:F15EB15D56D2017FABFF75DD9C3D3959
                                                      SHA1:525F217EB49ADCB2E7075FE17999A4A0FDDC787A
                                                      SHA-256:78DFDB044095105869C88D1100A5621F8C4EB744770DBE09D3241142ED375576
                                                      SHA-512:1062DBCF1730799B28115A54885A01FBA64CAEDA2045FED9FD99C36013443BB61C1A27268A798D9D949ED09A84BBCFC466B08EEDC2BFBB9F1CF78848755028FB
                                                      Malicious:false
                                                      Preview:WANACRY!....._..:.#....Q.]r.Z.W..u.q._.hLC.~3^..,0P...H.(...w.!.%K.....u.8e....[.s6..{L_.n..6......O..=.4^.....I...6.c..00.....3., .\.]8?2.!.tt....t..8..?cu..~~c{..D..8t..A.ix_.+.M."{]j..!:2...Y.k.7=..u4Cc...X..V..>.w........-..a.....`x.b=.+.......................1;..+.3.).w..L..1..Vdl.Y....C#=..m..O.>.a.......k5.Q<.(.....@.L._....h`..........e..V..E....>.V.:R$yZ.......1_...SR%..N.y...,..........g.;...G.n.^.f.F..P.X>.N%r5r.sy#z.88.T..E.2E....._Rh.q9.......2....`.`f.]9....T\U..9]..,f...y...8..EA.d.J.GUS.).t.<CDT....P6=.-.dZ.....,.P.;.t.....y.F....(4.N..-S..X....k./.O.M.{...=w...l4.t..3ui.....F...^....o.h..9u...P.8...*.yxi.Xf.F\..C.._%..w..\.y..S.ZTc....ds.z0.......%U[......h d.......>.1+..x.."(e~..u.....(.c..xI4.x.d....17$.$x.H...lY.4.k ..6Q..g..&.x#w.g7-/..t.n........._y.}W.2...;.7..@...8.jwjolr.p........d..Y.."[KW..3.$....Q..k2....-.v...q(>.....:.1..0......:J....E5L>>~.k".6L.f.G.n..=.b..b.....'y.Y..b.......m1........9.a.G.G..)....<.`\3
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.8652992265853285
                                                      Encrypted:false
                                                      SSDEEP:24:bkZg4y1o+yF6UVmwzioeZI6vdzPZ5Xms8wpRQelnKYp57IPBJRJ8pzKHm:bkZtKLlfXFt54w8UKwl0b8EG
                                                      MD5:F15EB15D56D2017FABFF75DD9C3D3959
                                                      SHA1:525F217EB49ADCB2E7075FE17999A4A0FDDC787A
                                                      SHA-256:78DFDB044095105869C88D1100A5621F8C4EB744770DBE09D3241142ED375576
                                                      SHA-512:1062DBCF1730799B28115A54885A01FBA64CAEDA2045FED9FD99C36013443BB61C1A27268A798D9D949ED09A84BBCFC466B08EEDC2BFBB9F1CF78848755028FB
                                                      Malicious:false
                                                      Preview:WANACRY!....._..:.#....Q.]r.Z.W..u.q._.hLC.~3^..,0P...H.(...w.!.%K.....u.8e....[.s6..{L_.n..6......O..=.4^.....I...6.c..00.....3., .\.]8?2.!.tt....t..8..?cu..~~c{..D..8t..A.ix_.+.M."{]j..!:2...Y.k.7=..u4Cc...X..V..>.w........-..a.....`x.b=.+.......................1;..+.3.).w..L..1..Vdl.Y....C#=..m..O.>.a.......k5.Q<.(.....@.L._....h`..........e..V..E....>.V.:R$yZ.......1_...SR%..N.y...,..........g.;...G.n.^.f.F..P.X>.N%r5r.sy#z.88.T..E.2E....._Rh.q9.......2....`.`f.]9....T\U..9]..,f...y...8..EA.d.J.GUS.).t.<CDT....P6=.-.dZ.....,.P.;.t.....y.F....(4.N..-S..X....k./.O.M.{...=w...l4.t..3ui.....F...^....o.h..9u...P.8...*.yxi.Xf.F\..C.._%..w..\.y..S.ZTc....ds.z0.......%U[......h d.......>.1+..x.."(e~..u.....(.c..xI4.x.d....17$.$x.H...lY.4.k ..6Q..g..&.x#w.g7-/..t.n........._y.}W.2...;.7..@...8.jwjolr.p........d..Y.."[KW..3.$....Q..k2....-.v...q(>.....:.1..0......:J....E5L>>~.k".6L.f.G.n..=.b..b.....'y.Y..b.......m1........9.a.G.G..)....<.`\3
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.8324955628276856
                                                      Encrypted:false
                                                      SSDEEP:24:Q2h28MkWTQ1MjM6zTLTk1EU65bWfZ2/YWzEWrICeNcfQvnCJOqkPadJU:T1MkW4M5zTE+jFG2/3GNcuCY3CU
                                                      MD5:623411FE65ABF8AF9067AE289FA44F6A
                                                      SHA1:8F479CFAFDEE35324BF02756675C3CB71F9F6A5E
                                                      SHA-256:2DEFCB9F2835BC4FBB88B7C1D309C55EF14DB97389F2F1CF59A63E145B2769FC
                                                      SHA-512:F59A250FFD43177BB785EC422B74DB71AFAC2C3F6E6752AE890905AC298DDBA57B62219DC344CAAB1C8033D1477087B9CCE8C49E2318CF2A0399D0DC41550B9E
                                                      Malicious:false
                                                      Preview:3......Z..t0...'...ai..;.s..r6.8..O/.,.4...\..XU..............}.3&.C....U5.:oe7k.X6.. ..^ <..*..Av..E.".............Z_............R.Lx..<..B..dT...%.........!N..D'<.G....>.#...1...K.{.....O.`...h>.44.R... U._.v.[.N4.3...r.j..Nja,w.:]3..X*sN.....v.F......<.f.......J....u.......y..D.!M...?....hA.z...u.umE.o.H0.&..|..M.I..I.7...;..73...s.m.Q..../".P..'.)...+j..v..g.b.n..%~.6y..{"*>...4..B.=r.]".;Wb..u.M....W...k\...S..O.....gH......xK."p=%.2...xo....`.k.E.S!..W...(O..>..C.mJ..>.K5.Z'..w..yX..OR.....$1.^.I.'..v..s......5\....c.x3c.T.....l....D....d's......@+#..t8.y.HO|.z.......1.g..^..=.c..D.>]..x..?...O6}E.+....Td..r.Q...D.&....kM......}..O.,?D(.....-..>.B~....V...F..QT.(hn.g.z{.....|-&T...M......D..2xv......B../.G M..... .._c..)....#...Y]b..gZl...U ....#.WGI*@",.\.y6..^D].;>`-y.v...%.8.z0.F.|.(...".W..+.t.+...`....R\....B..&......|.G.......7d..`^#v.*.{8..LY9.X.c..\p...8.{.g.Emy.dH_X.al...VzO..Jx..@P'...E....vs..P..:...a.?T..Af..8..
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.8486048312891725
                                                      Encrypted:false
                                                      SSDEEP:24:bkEbf4NZEKAorMwaQa3h0BMpMxASF4AGab3ddh4JJZN5r82/BrBFTgn2wDO:bk24NZEVjw14fppwPbzqJJZNB82/BrBJ
                                                      MD5:C141AFE4D00BB0C394E91BFF80B4A0FB
                                                      SHA1:F95DF9B28DE54D09DED07157DBCE1EF25092361A
                                                      SHA-256:112CA4C21CF3FC3B3AFE9279B78AA7096DB7B61AE7D8EAEA464EC3D48DF18D12
                                                      SHA-512:0ACF794E3A197B718FF84F547ED791304AF392FED4914799B87F8CAA10772748EF7337628CBCCC34F34EA39E98A9975E08E7A6207F376E8E403F9DE7C7AE7BD7
                                                      Malicious:false
                                                      Preview:WANACRY!....o.N<a.XP.........B...*.#..e..w....i3.}Y3..{)..4.#..#w.....z.aZ.....6./L%......m...v...!.-....h...*..&...$..._7.n........_..o.j.....:.c$...h..4.....|..r..+...Qh......L....N..6{tg<..S../N\.t.j....d?..x.I.5\z.........>\.S..*<8....".f,#...k+..H...}..............|.&.,..eb...X...>../....Rq.&.......IF..N.6H...L......M=.-.[.*..f.:...L.;.tX.b..t....rN......%n..........:........)....&:..N.o....v.|..Cm....Z.'lbU(Y.+#..p...^..j.....T!..0R.3.$.}...b.p.. .'..k......?.=.h.K..'..6.eN@.{..W...6.l&..Yr..&...g.....).4]..>.f.......<..]w........~qi.X[.v?.{(......s.i!a~..J.n..'Mm.~p....Fu..Y..X[Oz....+....."...%Dy!..Q>4n9.`.S\nE..f......g'.N.k.X..39.&g`...<.Sa.......M...TJQ5..9.....}.Y.\.8).}z:Q.......}.....L.-..6...v......Vl...iE&.....Gc...cc.=....f.U.i..^..}.u.J..i.1..i..&.].Y... .....0.h_...5i./.......'.....4.........ZR.0..*X......A..iL..@d....4....G...-..+.l].r.H.#.<Yl.|.Y.....yC._.=..{k........>.....T.9.!......O.v.[.....x..!...-iK...=.5...K
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.8486048312891725
                                                      Encrypted:false
                                                      SSDEEP:24:bkEbf4NZEKAorMwaQa3h0BMpMxASF4AGab3ddh4JJZN5r82/BrBFTgn2wDO:bk24NZEVjw14fppwPbzqJJZNB82/BrBJ
                                                      MD5:C141AFE4D00BB0C394E91BFF80B4A0FB
                                                      SHA1:F95DF9B28DE54D09DED07157DBCE1EF25092361A
                                                      SHA-256:112CA4C21CF3FC3B3AFE9279B78AA7096DB7B61AE7D8EAEA464EC3D48DF18D12
                                                      SHA-512:0ACF794E3A197B718FF84F547ED791304AF392FED4914799B87F8CAA10772748EF7337628CBCCC34F34EA39E98A9975E08E7A6207F376E8E403F9DE7C7AE7BD7
                                                      Malicious:false
                                                      Preview:WANACRY!....o.N<a.XP.........B...*.#..e..w....i3.}Y3..{)..4.#..#w.....z.aZ.....6./L%......m...v...!.-....h...*..&...$..._7.n........_..o.j.....:.c$...h..4.....|..r..+...Qh......L....N..6{tg<..S../N\.t.j....d?..x.I.5\z.........>\.S..*<8....".f,#...k+..H...}..............|.&.,..eb...X...>../....Rq.&.......IF..N.6H...L......M=.-.[.*..f.:...L.;.tX.b..t....rN......%n..........:........)....&:..N.o....v.|..Cm....Z.'lbU(Y.+#..p...^..j.....T!..0R.3.$.}...b.p.. .'..k......?.=.h.K..'..6.eN@.{..W...6.l&..Yr..&...g.....).4]..>.f.......<..]w........~qi.X[.v?.{(......s.i!a~..J.n..'Mm.~p....Fu..Y..X[Oz....+....."...%Dy!..Q>4n9.`.S\nE..f......g'.N.k.X..39.&g`...<.Sa.......M...TJQ5..9.....}.Y.\.8).}z:Q.......}.....L.-..6...v......Vl...iE&.....Gc...cc.=....f.U.i..^..}.u.J..i.1..i..&.].Y... .....0.h_...5i./.......'.....4.........ZR.0..*X......A..iL..@d....4....G...-..+.l].r.H.#.<Yl.|.Y.....yC._.=..{k........>.....T.9.!......O.v.[.....x..!...-iK...=.5...K
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.830356495591331
                                                      Encrypted:false
                                                      SSDEEP:24:k1l8qhAjEwo+tccFCrqjMkC45yUt/oQZGWmsNQO1fCm:YdQG+tccFCr7kC4cUfZPmaNCm
                                                      MD5:C98BC314B3DC3E0C8B44B7589DF3E5A5
                                                      SHA1:46D166FED674344B5A9E02F36670045C452020C2
                                                      SHA-256:A0DD2B70CD69AA84FFC3DB10BC0CE8D5335D24F18C94DFF3D21780D694A7A012
                                                      SHA-512:87C52387A98D79AF003141EF62B52D714D346C774E8106F89E9858F723C9ABDB9CF6E7FF389B60CE5973AF5CFD683B5A9FBEB4383746629D6A09DB272EA3ACFB
                                                      Malicious:false
                                                      Preview:..&PGZD..^..C.@.\.G}M...M{V.:....{D...X...S..||..Mf.{(....fE...B../NqAl.?..`.h..1;~~d|.)..;L.+F<...9... .L..v...5g..D...=..<9b/.2]...mM..!l.=......,*.r.D./."...U...b'kd.....B+L@...O...v...~\......>`.M..%.Z..]....Nu......d.9..g....i..jTCR.[s....Y.........T{.?...!..t9....JUT.Jv.3eo1.`....d"L.!..)P.3`.g.:H....E#..*].28.3..:Wo...-M.....__.F;..sT.$...yu...m..(.*~...p[e..B..-....Q.RZ.Q..i...P.c7..Y.`.5\.....~........:.-.. c.(,.J.u...m w..dUP.......r../....L.o.:..M&.[..!O..gf..b-.@...Q......0.a~.=..L.W.%..I..S.YB.d....j...w.hk..4...&qr.O..I.0.<.!.9#:..bp..c.Mvkx.u..W..emP.B9.Jj...v.l.f..........W.e/"..)..w..`....Q.y...>.eR:.b.n.6...[..j.Z.X...Xc\v..2[.+~......DQ......I..a...4...0....6.B.}.O....9...o.jZ'..Tk8L2.n.Py..m..{.k.P...s..a....]3#pW.$Q..7}5...Q.......O....x9....MS.l..-h..3.va.^...n...N.Mjf3...#+......'6.\.F.....fGg7;..W.._.P.2.t]7.......Z*.u|.S.6....|...a0.u.a........ 2....E....W.D.I.;..d.....=jRf"&...."]....9....G2..8._.Kc..S..D
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.851081029983097
                                                      Encrypted:false
                                                      SSDEEP:24:bkRiuJGGxJaJtqKxvGlIvu7HUIy9WCWUtZjwRNBNYFpfMSS4a/6oFoaDPQXeE+Q:bkElGxJa/9dGlIW7UIyjHmBNKMznlyaW
                                                      MD5:39BC28F646636727F021A59120CA9405
                                                      SHA1:7FF954B4A45F0477D2067CF0F5635D45ACA6A4ED
                                                      SHA-256:2DC6FFDFE2ABF5D39F2B7F8E4F09249A9466C3D1502A7A4C49D57E4D02F2CE82
                                                      SHA-512:F121E94D65FF0E0D0AF967EE886971521A1C64577683D12243A353809BF4AFE8CEE8168C5365A83BEF902BB577059E4678E634F758E99180E09DE0E8AF8E7A2C
                                                      Malicious:false
                                                      Preview:WANACRY!....~.@..=tY..1...i..?...q.u.$...z._......~.c~.VG..s..p...{....o@...OH.k....&*}....].&...w...t.B.F....9.MP....z...&.*.%..l..K([...H-n..!....Z...9..Tp....v.B...3.e,.m... 5.c*..l1...AA...0...:.9a?&...3{.........S(.by+I..4x..k.Zq.`.bY5!6... ................g._..........p........9.".]'....\..~........D6...,...U......:,.M......Q.!.Ys..i.M. .....w.)..0..P......-.Kc....!:f....z...=b2.Y.....7...'U.R.h:..&.=....c..HB..V..3..'!.{..P..K...Kn.p!..(+R.(......X.....j..P.....x&.. .....?"P.;..m.R,ED..*..].3.5S..$w.....u...).I....i.'<..[..7.....n2uSo!....4....!...., e|ciy..y.......'..R..kV.. \.@..*.p.. .Kx.".6.o..+....-.....2....J[....M@UG6.~0.m.l..Szt....V.8.o...4....Gs...fJW=.Z..O.qL1 ..>tCn.GY.G.#.bId....V..b..].BT3....`.a.&...a..[.z....|...t`$....>.......g...>Q-...B..I.]C...4...v./l"cH^....kaV..N....U.8K...w.[......>p.k."2.....0...G..({'...A.aq.iE_60.......`!|DW.-..7-....p....*.NV...........Q....-x...>..k......w...:.s.&...d..S
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.851081029983097
                                                      Encrypted:false
                                                      SSDEEP:24:bkRiuJGGxJaJtqKxvGlIvu7HUIy9WCWUtZjwRNBNYFpfMSS4a/6oFoaDPQXeE+Q:bkElGxJa/9dGlIW7UIyjHmBNKMznlyaW
                                                      MD5:39BC28F646636727F021A59120CA9405
                                                      SHA1:7FF954B4A45F0477D2067CF0F5635D45ACA6A4ED
                                                      SHA-256:2DC6FFDFE2ABF5D39F2B7F8E4F09249A9466C3D1502A7A4C49D57E4D02F2CE82
                                                      SHA-512:F121E94D65FF0E0D0AF967EE886971521A1C64577683D12243A353809BF4AFE8CEE8168C5365A83BEF902BB577059E4678E634F758E99180E09DE0E8AF8E7A2C
                                                      Malicious:false
                                                      Preview:WANACRY!....~.@..=tY..1...i..?...q.u.$...z._......~.c~.VG..s..p...{....o@...OH.k....&*}....].&...w...t.B.F....9.MP....z...&.*.%..l..K([...H-n..!....Z...9..Tp....v.B...3.e,.m... 5.c*..l1...AA...0...:.9a?&...3{.........S(.by+I..4x..k.Zq.`.bY5!6... ................g._..........p........9.".]'....\..~........D6...,...U......:,.M......Q.!.Ys..i.M. .....w.)..0..P......-.Kc....!:f....z...=b2.Y.....7...'U.R.h:..&.=....c..HB..V..3..'!.{..P..K...Kn.p!..(+R.(......X.....j..P.....x&.. .....?"P.;..m.R,ED..*..].3.5S..$w.....u...).I....i.'<..[..7.....n2uSo!....4....!...., e|ciy..y.......'..R..kV.. \.@..*.p.. .Kx.".6.o..+....-.....2....J[....M@UG6.~0.m.l..Szt....V.8.o...4....Gs...fJW=.Z..O.qL1 ..>tCn.GY.G.#.bId....V..b..].BT3....`.a.&...a..[.z....|...t`$....>.......g...>Q-...B..I.]C...4...v./l"cH^....kaV..N....U.8K...w.[......>p.k."2.....0...G..({'...A.aq.iE_60.......`!|DW.-..7-....p....*.NV...........Q....-x...>..k......w...:.s.&...d..S
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.780425381893952
                                                      Encrypted:false
                                                      SSDEEP:24:HyOOlXJMNAFAgUl9ugc4ilAr4xddXG3nwSxd5lPTblRR:Hj0XJMN6A7uDA+dhWw4P3XR
                                                      MD5:079A3AA88A67BB148C32E5D6EB0E9103
                                                      SHA1:E0C597512EC46D23883BA5929044F686CAD939B0
                                                      SHA-256:B36F60F47C7301549E731972B332FA9094C7ED2CD36548E0E54180D3400213E0
                                                      SHA-512:73D63295F4D025F4D6233757392938C19AA7A04F1D3890C639455E4250DD498351D684FC3599BE370C004AD58C651BA5474690DE7CB1255C1486C6844B2CB25D
                                                      Malicious:false
                                                      Preview:`..f..]3sv|.>~...:.s.=.J...........%..d+...~t.%p.........]f$.......V....%.P.[..RO1T..W&..u..z(..u0.).P.....|-...s..78.z5..g.m. ..A...M.I...}....o......9\.....v.9........"z.......n&x.+L,...[....].w.6....@....[$...-.mL..`.....Cq.5.>"",A..I-....^..[..Kp..E......j..A.WPLA..]....U...<.P.ba.2./S.).Vu.S...I.@....H..jl......*.=...6.YjM...w...ca.C.].o.C..q..}3;..lM..}.]C....A...R.B^5M.G..ycq.....o.......7?].k.X....7p3......lL...,'.}. .7..[,..~.d..[[...i.bRTD.K|.1?:9../......x...3%..6....W`......wb.Y..$......%.Q.x.+............`....0.qzb..N....$.....]...Q..l.*.wvZP...y,b..)...tx.6.t.17.=..cH.q.]F........K...............H9.v/]jhG..Up.T^.5...E.%.ue..b.N-..V.l...........Xz..0L..Y..-....\......*.G.?.....C..V.&.B....G..$.6......F.....x./.)."|...}u.....8..-...(m.~....LJ$.`..:./......I{.:m........=..q.%...X.4.......4...51..$%.......6.&Y...Yh.Xx..-7.........9....6.O..=.e..}...D..#.{.RC.,.t.%.....0P.`s #.r{..7. 7.s....=ri)3..~...."s.$..0....
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.8578715007797895
                                                      Encrypted:false
                                                      SSDEEP:24:bkqjkDOe4LH1sASk9bCHyJoHzT+xMffyERf7mO/VpRBuLr9MTjE2z5XYYokn:bkqjkCxsCCSSzyxMffyKfbDRcLraE2zr
                                                      MD5:3E94E9C31DBADDB5218F536DAFCEB07D
                                                      SHA1:9F8F11F85E547DF3658E2D0E23C462C5594DDA58
                                                      SHA-256:6BA9FBAB099479ED0770F9C6F090871DCF426281CBBE9FF5110342C62E7BF6E6
                                                      SHA-512:3A8439BC4B2ACA376FED7B5D02F6AE44A7D540387D08604E1CD59074515F02C796BC65E2FAB1BF5637FE0DE4A5B7A076351E2BD351FA5CD14DC67AC309EE0659
                                                      Malicious:false
                                                      Preview:WANACRY!....M..nz.y.u..$sW.:....v.C4to..../.......<U.F..".g...V.A....uU.............L_..xn.4S...g.t..'X..}Z....xN."...fB..@.]...}.6j........-|NC(..+.Gh......g.S.Y.$..D.n=..rv|...]..X.~......S_......+....V.g......t.9.&1bx.....7v.......e.#`.-.@....`.m`.............#.._..Uu.u...ws#@.bO.?U...W oK`N$r..'.=s@....J(_.g....._..-....:B....K(.v.=...1[..f*.Z...nML.?o.....<.._.VJ.P8.&.\r...c{...kj.8.'.J..]9....7....".U...L..../U.......L....K....E..... ...)..Gl|.o.X.s!0.;n.M...5..z.L..$.@...l..a26../..6.|g.^.O.F..qA..+.HL/.2.on+K.....U...x...'Cib.v...I.%...qo<........]d.87J....TNkt..$..."..wN....m..L....>.O-2.C.t.o...KI.......J#.~..?w..r.v.....$Y.A.I+....,q.l.H..T.^!A...B?..T...;..K..KT......i...1.....I4........?........o....q..%+......oki.QZFi4..4.yFj......... .....~.0..8.k...].,..1..37...y....m...z....-.,pN...]......k........J..*_.........d.!......VQ.)B`.J.b..K....cD!...,i.<MZ...SK...n)F....v.Q..9y.d.^~....'....A...p..X.#....f...E.b.J.C\..Z...S.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.8578715007797895
                                                      Encrypted:false
                                                      SSDEEP:24:bkqjkDOe4LH1sASk9bCHyJoHzT+xMffyERf7mO/VpRBuLr9MTjE2z5XYYokn:bkqjkCxsCCSSzyxMffyKfbDRcLraE2zr
                                                      MD5:3E94E9C31DBADDB5218F536DAFCEB07D
                                                      SHA1:9F8F11F85E547DF3658E2D0E23C462C5594DDA58
                                                      SHA-256:6BA9FBAB099479ED0770F9C6F090871DCF426281CBBE9FF5110342C62E7BF6E6
                                                      SHA-512:3A8439BC4B2ACA376FED7B5D02F6AE44A7D540387D08604E1CD59074515F02C796BC65E2FAB1BF5637FE0DE4A5B7A076351E2BD351FA5CD14DC67AC309EE0659
                                                      Malicious:false
                                                      Preview:WANACRY!....M..nz.y.u..$sW.:....v.C4to..../.......<U.F..".g...V.A....uU.............L_..xn.4S...g.t..'X..}Z....xN."...fB..@.]...}.6j........-|NC(..+.Gh......g.S.Y.$..D.n=..rv|...]..X.~......S_......+....V.g......t.9.&1bx.....7v.......e.#`.-.@....`.m`.............#.._..Uu.u...ws#@.bO.?U...W oK`N$r..'.=s@....J(_.g....._..-....:B....K(.v.=...1[..f*.Z...nML.?o.....<.._.VJ.P8.&.\r...c{...kj.8.'.J..]9....7....".U...L..../U.......L....K....E..... ...)..Gl|.o.X.s!0.;n.M...5..z.L..$.@...l..a26../..6.|g.^.O.F..qA..+.HL/.2.on+K.....U...x...'Cib.v...I.%...qo<........]d.87J....TNkt..$..."..wN....m..L....>.O-2.C.t.o...KI.......J#.~..?w..r.v.....$Y.A.I+....,q.l.H..T.^!A...B?..T...;..K..KT......i...1.....I4........?........o....q..%+......oki.QZFi4..4.yFj......... .....~.0..8.k...].,..1..37...y....m...z....-.,pN...]......k........J..*_.........d.!......VQ.)B`.J.b..K....cD!...,i.<MZ...SK...n)F....v.Q..9y.d.^~....'....A...p..X.#....f...E.b.J.C\..Z...S.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.816021485185824
                                                      Encrypted:false
                                                      SSDEEP:24:QD3FxBGkUyt9YREACJUIm7xeLSI6kN7CkU5brTO2s0:YFxx9UEACJoINN7CkUtfO2s0
                                                      MD5:A985CDA5849DC00FD061FAB87B9F8FC5
                                                      SHA1:B4C5172210AC848B95B5FEB57DA6FDB01B417D63
                                                      SHA-256:808632F1764508DE3A25FCDCD1F92AE42FF872F1979AD3F853AADD2E069DA639
                                                      SHA-512:AADC1D39A1C3AAF79CED1C7F62806D57B923EE4B1F5C766229ED32D8ADD0BA3955D64EC118D37048329AECBB2F4CB03D95221FF19AB59F1334B09EEB04C0D9A8
                                                      Malicious:false
                                                      Preview:.........J..`.lD....Y,.7...%... R.Q.......r..6h..!...L.R....d.#......mU.k6q._....d...+..d...q..;$.|J..f...).......@b..n....."...J.......O.*.A...[...`..p.*.n...K..zl.8.y/;.-...HZ..%.}F........r..j...Jv..1.9@.....wi.RD.&..$.o.sH.zM...).. ..x=.....|.`].^...&.8M8O....O....{.|.6.^..v.'...a....S..2.:..j..>.z..Y.....<......l..r.V..9.v.m,+.6S.....G@..g.......f.l....Do..m.+.1.Qz...9..........2WO.8....V..&oMS:.....o ....7... .]....=.,.y......wYA...+"./....Y.n+K....c.b....O.......}om....@.O.w.A....."..#.../,c..R...S6...3....J..Wh...]b\5R..N.........9..z...z....D....l..'.%....k..../L.jOhR=.....ot.N.......gp..8.m....v.I......@..32.Wr..;-o....E.6EVC$z...3S....Q.6...F..m...b!..`g.O..Vy4b.$o...#.>h..Q,.E.......t`]......k...;...&....b..oDS@..]...iR.H.d. Oy\..b.@.]j....y......u.g.._..u[*.1..I.@..i2.2.&.){.......:.K.b[5.zd..gyh....iC.B..]..L.S..Q.A..d.......>.4.].*.....3.....N.XrS...vw\.<..S...x..%..b<2.nf.c6!.L..e0.@...'..}..Hw.5.B..$3.b.:..Knm...R3.'... 9P
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.859101855005952
                                                      Encrypted:false
                                                      SSDEEP:24:bkD2IV+Azx/uERt/loEewfJxSt3J+A29Vu69tXV8tT1h/GX3gzkiSjYKnRTyeI/g:bkdzVuO/loEeCJx2+A29869twTGgMUKZ
                                                      MD5:A63F5FE3C0E97767C4CCB5D0A147AC1C
                                                      SHA1:21BB21CF9DA8FBF8BAE835AB90A7F4E9D4CB6DBB
                                                      SHA-256:EC1216565522D48244139F494388CD9903D5203717BD92843C11A480FD4072FE
                                                      SHA-512:709D767D79C7401EC396744BB91E9275BEF968ED132708437338D371A9603ED7B6091004D188E37A6366AB68B0CB21C19947129CBD4316C5D89D616201F501CC
                                                      Malicious:false
                                                      Preview:WANACRY!....>.(...d.'...WD........ v.g...-.,-?..5.*..}..T.[...._..J.xG9^.qO.....uL.........3.s.foG.J....1\`..{.a.I....5.D..I.....+.....A#.....&.04t.E......3W%.%..[.U.......bu...Nv..R<n/6g..*.p`..3.P..='. ..5.X.f.#UZ.W.*....(.>..NjPdfnKPwa..r"..Pkt.R....x.a.............Om.3.\...../......G}.K..1R....F..1..[.U8".. .a.*S_<.)....k.B.V.....Jw.....Zp....8.A#[f.....i4..G:...x.x.r.....%.,...,.+R..i~E|.%m.._~\.r.cfMz...uc......:,)r...a.=.E2...sgH>..C.v+.8..0 ..P&.=<C.VQ..K.....f.....b..~..4..aPd.....=u.~}&Y)._..r`.E.....I.#X.q..N...f...R.;..6..w...o...R=M....?)...v.>...S..E.A3.....YO.=...b..+..8.M^l..j.Q.......9...j.8t<#...{8.....G.i...h..|.V.....K..Z.P.........B..0.R..L.f.?..V._..On.P....[3...D<..y..+.=.....~m.].1...\M..........c..a.%..g.&...C.{..\..G...-4.E..!..@.Ro!/.cxy.#..D.}...g.8.8...r2H.}ZF..[Vs....i..S.ch1..:RK....^...._...\.@,...lcC"T../".......1'.q..h......8..f..l.>..X?N..q...Ss.>3.I.^.o.aC...B8..Y..ufQ...6........&..".....6*|v,iv...30c..{..
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.859101855005952
                                                      Encrypted:false
                                                      SSDEEP:24:bkD2IV+Azx/uERt/loEewfJxSt3J+A29Vu69tXV8tT1h/GX3gzkiSjYKnRTyeI/g:bkdzVuO/loEeCJx2+A29869twTGgMUKZ
                                                      MD5:A63F5FE3C0E97767C4CCB5D0A147AC1C
                                                      SHA1:21BB21CF9DA8FBF8BAE835AB90A7F4E9D4CB6DBB
                                                      SHA-256:EC1216565522D48244139F494388CD9903D5203717BD92843C11A480FD4072FE
                                                      SHA-512:709D767D79C7401EC396744BB91E9275BEF968ED132708437338D371A9603ED7B6091004D188E37A6366AB68B0CB21C19947129CBD4316C5D89D616201F501CC
                                                      Malicious:false
                                                      Preview:WANACRY!....>.(...d.'...WD........ v.g...-.,-?..5.*..}..T.[...._..J.xG9^.qO.....uL.........3.s.foG.J....1\`..{.a.I....5.D..I.....+.....A#.....&.04t.E......3W%.%..[.U.......bu...Nv..R<n/6g..*.p`..3.P..='. ..5.X.f.#UZ.W.*....(.>..NjPdfnKPwa..r"..Pkt.R....x.a.............Om.3.\...../......G}.K..1R....F..1..[.U8".. .a.*S_<.)....k.B.V.....Jw.....Zp....8.A#[f.....i4..G:...x.x.r.....%.,...,.+R..i~E|.%m.._~\.r.cfMz...uc......:,)r...a.=.E2...sgH>..C.v+.8..0 ..P&.=<C.VQ..K.....f.....b..~..4..aPd.....=u.~}&Y)._..r`.E.....I.#X.q..N...f...R.;..6..w...o...R=M....?)...v.>...S..E.A3.....YO.=...b..+..8.M^l..j.Q.......9...j.8t<#...{8.....G.i...h..|.V.....K..Z.P.........B..0.R..L.f.?..V._..On.P....[3...D<..y..+.=.....~m.].1...\M..........c..a.%..g.&...C.{..\..G...-4.E..!..@.Ro!/.cxy.#..D.}...g.8.8...r2H.}ZF..[Vs....i..S.ch1..:RK....^...._...\.@,...lcC"T../".......1'.q..h......8..f..l.>..X?N..q...Ss.>3.I.^.o.aC...B8..Y..ufQ...6........&..".....6*|v,iv...30c..{..
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.802678844907424
                                                      Encrypted:false
                                                      SSDEEP:24:24fr/L0tu5W9dlPUIB6NyZ9rBx9bXHHciz/bsyu:rrY9bFLpBnciTwb
                                                      MD5:108C14E3EE4092E5AEFE496C7328577B
                                                      SHA1:215C50AEB212AB917F83F0CB4E49E5640630749E
                                                      SHA-256:07C8C7E8D6DED01417575833FDBED053D474B32C3855BE094EAF1855802C1372
                                                      SHA-512:2989F4504F503DD05ECF94478D1F7EFAB9FAE70EB10371CB64988EEE63FF32DC249622223D23B04D286ED900D871A5BEAAF66CBA6AF47C1FB1264B97B6A3C4ED
                                                      Malicious:false
                                                      Preview:...H..+.xfE.k.k.P.8.C......c....;L...Oh.Y.1.......sn.S.E..;5...F.c>/.M...~.....z..B9..u......@..u...O..^...$\.d..o.}0..r..>..>.V...E.Q.P...O.. }..<.k..8...{....7..o{.r..M|...)...FT......z.v..e>..z......}B&.+..Z.>..9.F.e.:.#.F.4G,.i. .5Y.!.E....a.......J.^...jD..Io.$...F..m.,D.(......%....k.|..X..{.c*x..]G.v.XGjh..5..).._l........x..{............>#.,ej.....h0/..Z.#.bb._.h.*c.........!@^....a..2#$..,.......=v.Nk.u/.1.k.8.....v.QF....r..~n.?6W.AR.+..5.{....3...>.......&..u... ._.De..b.... ....G....".y".j..v..l.z....-..j..><~=#<.....%....u...v.$....@<...J.N......'90V.{.."...Eg..3...|......b.\..s.R$[M...../.LO.!HOy:...6..L<4...iu.N...O...3i..a..mn..|...\.W.o?d..!R? .<i.....n..;*p(r*..."'k...j...D.K...xJ4.!a.F.`V.:.|`.5.x&G.o.KAN..........+.U`...~.{.....d.d.(.^\.0.......S:@8G..G...@(c.N..S..%...S.u....T.e..<.>..?)..o...........:&f;.o......R.~V..d.7A....A.].V&.M/.b[.2..&:U.:...3.{.:!..H.....H{.v.~.C.*q....O........r.#B.....=..L.2.Ne....C!1
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.85437605831841
                                                      Encrypted:false
                                                      SSDEEP:24:bk+q9HtQB8ftek/8YA9JdgcRBke0rUN1FMQcZPPJCrCb3ogd5ds84hXFM8oAK6dw:bklHtQB8fhADdgcRB6rqcZ3br280FMvf
                                                      MD5:6C8C38F0FACFE64731225DFFC2967BE9
                                                      SHA1:33A4DDEB46586362A3A7FE3FB2319D2D26739D4A
                                                      SHA-256:30A91916E85DF5203A8317CB3EA7DC67E8D4DA43490D9249650591F4FD413D79
                                                      SHA-512:481C78830D975468B36E720EFF6DAD90CB2BD49FB83B5701F77A8165944B52DA1C9DF94C6D3D57031D40C893FA286255F5B9DFDB1B288F08AE6D05460E8FE8D6
                                                      Malicious:false
                                                      Preview:WANACRY!....?E..|..XZAJ.X..C.}.c...K..1.....B..R.Z..x-4.I.U5..>w...+.....-l:.`...&#.};..@.B....$.A....%.6"h.A9....]..|.F:.....ne..c.X{..$......K..;\.......z6U..0.`.C.........z.E)."....`......J.e...j..(..s.. ....&G{AF......Eb.......i...O.+sw>...Cv;x.............'.-....v..1Z..CUx.cA.....G-.X........8..._..T.I>b..0d.l...=....2X....g.`.!"..[.s......~Va. #.T`..t%G5}d'.{....../.Z.....d0...e.@KJ...:....1*t.t......A...<.q.....l^..ME5o....Zl..R"..V..P....)......p.........y.T(.Q.,s..Yo....t......~h3e.....&......Dq.MO..G..%c..4.#..56.....L.Q..c.8 ....{.....X^k...P.......@....X..#..h.ZG..r........[.F.-.d.#hT...-E0s5....:.....r.7.z.x=.x...3.f..dbw..Z..U../)|.........-...9.B........b..+.m..\.........y~.0$....f>....,./.v.....1......;.vv5..D...HO.....1'H...C...d....X+..'J.m#.qo.....'.6T..}.W..;..".`91...V..N..#uwv;..t.....!...i....x...462......3k.....p..hr..j.'..u^w..9P....Y=.zQ...n.....+..4....N..-...,......S...Q..+.z.../...8.@..d..cd.V.R{tLf6.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.85437605831841
                                                      Encrypted:false
                                                      SSDEEP:24:bk+q9HtQB8ftek/8YA9JdgcRBke0rUN1FMQcZPPJCrCb3ogd5ds84hXFM8oAK6dw:bklHtQB8fhADdgcRB6rqcZ3br280FMvf
                                                      MD5:6C8C38F0FACFE64731225DFFC2967BE9
                                                      SHA1:33A4DDEB46586362A3A7FE3FB2319D2D26739D4A
                                                      SHA-256:30A91916E85DF5203A8317CB3EA7DC67E8D4DA43490D9249650591F4FD413D79
                                                      SHA-512:481C78830D975468B36E720EFF6DAD90CB2BD49FB83B5701F77A8165944B52DA1C9DF94C6D3D57031D40C893FA286255F5B9DFDB1B288F08AE6D05460E8FE8D6
                                                      Malicious:false
                                                      Preview:WANACRY!....?E..|..XZAJ.X..C.}.c...K..1.....B..R.Z..x-4.I.U5..>w...+.....-l:.`...&#.};..@.B....$.A....%.6"h.A9....]..|.F:.....ne..c.X{..$......K..;\.......z6U..0.`.C.........z.E)."....`......J.e...j..(..s.. ....&G{AF......Eb.......i...O.+sw>...Cv;x.............'.-....v..1Z..CUx.cA.....G-.X........8..._..T.I>b..0d.l...=....2X....g.`.!"..[.s......~Va. #.T`..t%G5}d'.{....../.Z.....d0...e.@KJ...:....1*t.t......A...<.q.....l^..ME5o....Zl..R"..V..P....)......p.........y.T(.Q.,s..Yo....t......~h3e.....&......Dq.MO..G..%c..4.#..56.....L.Q..c.8 ....{.....X^k...P.......@....X..#..h.ZG..r........[.F.-.d.#hT...-E0s5....:.....r.7.z.x=.x...3.f..dbw..Z..U../)|.........-...9.B........b..+.m..\.........y~.0$....f>....,./.v.....1......;.vv5..D...HO.....1'H...C...d....X+..'J.m#.qo.....'.6T..}.W..;..".`91...V..N..#uwv;..t.....!...i....x...462......3k.....p..hr..j.'..u^w..9P....Y=.zQ...n.....+..4....N..-...,......S...Q..+.z.../...8.@..d..cd.V.R{tLf6.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.8066336537030265
                                                      Encrypted:false
                                                      SSDEEP:24:jYjN1Eacz8TJp8O3m1lr7deaOFlTcOJGqkbIw0T9mm:jTKFpfQx5OFATIlTEm
                                                      MD5:4A0FE191DA3B3B0E67194FB8DCEF9EA4
                                                      SHA1:0D2B882634428C246DD47FDE5616864E6187421A
                                                      SHA-256:CB2A6D22167DEA55C2B01448ED191EAFB20D4330B5E92DD125EC87989894E383
                                                      SHA-512:4871FCBE06D20A025E95849BD88DDEE0B6B7B83A88990A5E4EDB09EC2281B5C0ECEF334E7FD4AE9C364CE2265C0989A9D126D963A3C19DD500C87F2C88947E08
                                                      Malicious:false
                                                      Preview:.a..r..L.^....%..YS.E3,....(.4.W.@7....f2....5...<.6JOz.-.=....A.A..X.@bG...J.1Uj...jqt..3Y^....?+2....F....*'x..K.KC.+.%..X.Xm.......T.#JMJ.a..?.L.q..d>.....Q2.Kp.sf.....+....E..*00O.j....|....t..:j.fJJ........m}..E.F.!.*..x<$)..V....h)..BO....hx..Ux....$p......P.&uZ....i0.JN..X.@....M).....{W....=E.1...IU'..s.7...+._........5..C0...6..o\..3..K.....F.]..G....pG.g....D1u...xt..C......M.p......W.O...32.(..'.l..V...=..>....2...8m..k..j...0....R.oP....K..)ai.+..95..q.W.S..aGV5._..x .I.m..G....0.P....<.#XuHX.......|w...%...Z.....`..U.....2}..;\...0Jv.!,gb.%X q.....O....0.....^..."].`".-.e,`..Y($..,M..o.:cJ.!1;.3.b.(hIN.Xj;...U..o..'.....3.]....O. ....Ib7n.)d.9-$3..}...j....d:....t.>\.$@-..3RU....I.~.....b...r-.....,...:i|[6.F(.~...].u....Jf`.9i. ..n......Fn.8.J........3pc....."...I.6^..#...7...,C.......z..F0.Y..*zP....c.:.......K?...H$..F.......c.96..C..dG......%p..B.<..?...<..a_%.h.....L..G.x.Y.4.0k...B.d..\..[1y.+..v...*...F....L
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.860635352838957
                                                      Encrypted:false
                                                      SSDEEP:24:bkgDvIONS8ms2mFjQKyCjPUjYztfTVJzZS8GdcOlHmL1U6C3FTTZqfe2T:bkoxYoJjPUmT/ZItaUP31ZaT
                                                      MD5:A38FCA2B96075A63220357A9B3DC45F5
                                                      SHA1:AABD21C2BEE5894B35BCB87E6D7562B4AF88619F
                                                      SHA-256:081ECF75446CA3D722ACAE951FF4EBC602593E71F16F3D2A16E30880D02BE227
                                                      SHA-512:BA078447FD37D698427F50D048451DC134BE06740D2A068C1A8F2063690EE51B9B5AE29D0EAB3CB1B439D638CFC35C1462FA22E40E6955FE5A4983C759FFBA10
                                                      Malicious:false
                                                      Preview:WANACRY!.......T.y.........g.(cSA.ZX<@.t.....i.[JH..Bmp......`...G..m$......"..\*$%I.$=.._.@'&..YH.1R......T.Ewv........(.8..op.m.,)g...u...]]..p%t.....1....Xc........E..:V.M..z..<..v.R..D.1.t.....40.q.e1$.....:.k....5.T$..,I4.[8un...R.......A.Ld.._K_.8Mi...u.............E..q*.2I...}.Rz....Q....R..j/.....:.3.........I..'....z..6Y..Xr....8:HD~.../*H.:...`.F....g.d..G...&$.Y..R..Y;.h....T.....O.h.Dt...c<.(.s......41R.6........w.vj.~'.......g>?.x...QO;x..7.3'. .J..C#.r......5.ele..=3.*.>.1.+.~.;j.D-&.QN.sv.....u.f!RX. .(r...W5....%mh.C.KC...@..x...U]it=.....>.$`h....$.....1...G._...v(.....iIs.:..6....w.T(........o6.._...}..F....C|.!...k..2.q4..jQ93.*b<V...A.N ...v.7.n..).-...D./..D7..mI.3."$.J4..D}....k'Nw....u..S....^.~..,;..uh....d..G.'....kmQ..].......No.k.7b..6+]J..-o.{.!...h......@.....4...,..n$.;bx.1o2O....cb.G<+Uvm.....y.!..vee...{.-e"9q>..L@..@p...\..[.9.c...m.Ys+...q.5.=|.u..7.7.v.]4.3..8.<..O.........S.Wf..y.Wj....`.a>E..!Nt;.C
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.860635352838957
                                                      Encrypted:false
                                                      SSDEEP:24:bkgDvIONS8ms2mFjQKyCjPUjYztfTVJzZS8GdcOlHmL1U6C3FTTZqfe2T:bkoxYoJjPUmT/ZItaUP31ZaT
                                                      MD5:A38FCA2B96075A63220357A9B3DC45F5
                                                      SHA1:AABD21C2BEE5894B35BCB87E6D7562B4AF88619F
                                                      SHA-256:081ECF75446CA3D722ACAE951FF4EBC602593E71F16F3D2A16E30880D02BE227
                                                      SHA-512:BA078447FD37D698427F50D048451DC134BE06740D2A068C1A8F2063690EE51B9B5AE29D0EAB3CB1B439D638CFC35C1462FA22E40E6955FE5A4983C759FFBA10
                                                      Malicious:false
                                                      Preview:WANACRY!.......T.y.........g.(cSA.ZX<@.t.....i.[JH..Bmp......`...G..m$......"..\*$%I.$=.._.@'&..YH.1R......T.Ewv........(.8..op.m.,)g...u...]]..p%t.....1....Xc........E..:V.M..z..<..v.R..D.1.t.....40.q.e1$.....:.k....5.T$..,I4.[8un...R.......A.Ld.._K_.8Mi...u.............E..q*.2I...}.Rz....Q....R..j/.....:.3.........I..'....z..6Y..Xr....8:HD~.../*H.:...`.F....g.d..G...&$.Y..R..Y;.h....T.....O.h.Dt...c<.(.s......41R.6........w.vj.~'.......g>?.x...QO;x..7.3'. .J..C#.r......5.ele..=3.*.>.1.+.~.;j.D-&.QN.sv.....u.f!RX. .(r...W5....%mh.C.KC...@..x...U]it=.....>.$`h....$.....1...G._...v(.....iIs.:..6....w.T(........o6.._...}..F....C|.!...k..2.q4..jQ93.*b<V...A.N ...v.7.n..).-...D./..D7..mI.3."$.J4..D}....k'Nw....u..S....^.~..,;..uh....d..G.'....kmQ..].......No.k.7b..6+]J..-o.{.!...h......@.....4...,..n$.;bx.1o2O....cb.G<+Uvm.....y.!..vee...{.-e"9q>..L@..@p...\..[.9.c...m.Ys+...q.5.=|.u..7.7.v.]4.3..8.<..O.........S.Wf..y.Wj....`.a>E..!Nt;.C
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1026
                                                      Entropy (8bit):7.8067757908688105
                                                      Encrypted:false
                                                      SSDEEP:24:djniQ3AObVooLFpg/rcq7gvIvORajcry/3+858eqC:pn4IG2pArcq7ggQeqC
                                                      MD5:4205891A278912244677197468271CD1
                                                      SHA1:DB0A30B0F0C056A57281BD8175FB226D43E2FAA9
                                                      SHA-256:DAFAE282E12E60431B16F0619EA1EA0937FA2BCC32E002A27A9E7C9C7997D78F
                                                      SHA-512:F72288C13E29A21C4C35FA87DD4F3D1D429A35F6C139CCD902CC7FC026D889C08502A122210CC2C026D5F4D91195333B752CDAD95D6D21C11607B59129DF214C
                                                      Malicious:false
                                                      Preview:#........M.]....f...j8.gb.<T.z.z..-.F....1.OL..@...H....*...co.Py..w..?=.X5M.E....9.v.4f..{....Q2G..*.`6....l_L5...4.%".;...m.....|.;/Q`.IO.U)...<F'..0o...dos.,.$..qv..e.+"..z...WM.;.|....-?....m.*!..zYq.......G...>5ym..s[3Zt.....c..".eG"..E.\.p..v.b...bQ.'}..^.F...+..@.X..$....<.Eiy........*/...m..X..m......7..#...Q.`..B#[.1.{..p...M..S.....m.y.pJ......W..$1.oj2!'.%.(...M.o...k...F.wruW..g..0..!....s.....ty..Y4K..M.C...N.N.sK.(.>...[JV....5.2....g...F.X......#.Ad..s...dF.nJ...G.'...-yG..._.*.G7l...,..\.....x.*...Rb.<..+..S;i.CW.e..2.@...9..o.l.B...0*..bdUlJf_M...9G...7a...S.N..H...\..V...c.5T. KzV.k.z......fE..).A5..5PJ].kp....xx.<....L..}_...,.;..p.h.Q..)....j{.....P.G| d=w2R?wLb2@..0p.i}...]..|D..y...B.:1....}ZW.............%........Wk...#a;UJNCA.U..7.d.7.r...kL...-%.pA..a%.S......2g+3...n`...j.g...-...[..n...".j3...n..g9.....Z...}.V...f...a.....+....{[...+.....Elx.T..ZYJ....O<([3./>..1.%.i.A...\....'.....0b.T.....<...T.e..=.v..
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.881987213912167
                                                      Encrypted:false
                                                      SSDEEP:24:bkwNp/a2tY3RV29u6b4uiQJu0m4yH7YHToayhyVkQbCz8wobHIMbk3PDajO:bkwH/8h+h4uiQUR4ybc/yhyCiCIdU8eX
                                                      MD5:3D4B5B911512788C6C17DDA174499D9D
                                                      SHA1:05E1F2C75A2ED2CD58008D67CBB4F13239407A03
                                                      SHA-256:8EA114B820C643E784B44E182B7FE9BAA5D48E7D00063C578A5406930701C56F
                                                      SHA-512:4BA936C421DAB80459881D93D044282324C6FD88B555F380275EE5CF9FAE7899B1726B95FB6663280D511559BD8F8D86C649DF4C5E14D8C223B92A9F4B552D94
                                                      Malicious:false
                                                      Preview:WANACRY!..........q..+...A....-....I.Q!...n.[..5*a.Q.m=|.~....y......U.4..<mbL."]..S0..,..!.)$.0..|.:....H..g.....uf.YJ@......V9hS......U..Z...J,...z...A9W..t."....u.LJ..om....a.zx.!.._...:.{.......2...>...n.....4..>;...^p.p.KBV.m...G./...:.s5U....;y..w.................W..*..t..b...".~...I...A...d...<.O....O..X-8}.t#...../m...}....y..(\.e..B...n:.M.....9k.#S!..K....K..}...x.[.....}...I...$.......tx3H...L&m.._....s..."d.1.~xF&y.H.K.i7..J..].-....M...Sy..L..../.._...ZW4..Gi#L9A..<b....+.v.zi...@.y.!.y.Fm....e.?#...M..jr4_.........fp^].}om....%.&.a............y[p..z...xH...~..E..0..". ..Z.QK.Q....'{..(8..7dGN..d...lw....(...h..%.P...p..H|.*..O..M.AY(!F....DujF..i..o.$n.....X...s.sO..]...6`..2...6 ..yM*B..).s...+......h..^..f..Db5n...w..........(..../g).R..,..{.hA.$.......M.L.>...N+.V..x.2.....m.......]r.Q.E.`.#b.S..M.K.?\........!....v.......o...L[..<.V.....k.#?..VMg..&..1...8dS..(.@~:*..x.R.*|@.=$,.......w..o)c.p.6..QQ.......fcl...
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.881987213912167
                                                      Encrypted:false
                                                      SSDEEP:24:bkwNp/a2tY3RV29u6b4uiQJu0m4yH7YHToayhyVkQbCz8wobHIMbk3PDajO:bkwH/8h+h4uiQUR4ybc/yhyCiCIdU8eX
                                                      MD5:3D4B5B911512788C6C17DDA174499D9D
                                                      SHA1:05E1F2C75A2ED2CD58008D67CBB4F13239407A03
                                                      SHA-256:8EA114B820C643E784B44E182B7FE9BAA5D48E7D00063C578A5406930701C56F
                                                      SHA-512:4BA936C421DAB80459881D93D044282324C6FD88B555F380275EE5CF9FAE7899B1726B95FB6663280D511559BD8F8D86C649DF4C5E14D8C223B92A9F4B552D94
                                                      Malicious:false
                                                      Preview:WANACRY!..........q..+...A....-....I.Q!...n.[..5*a.Q.m=|.~....y......U.4..<mbL."]..S0..,..!.)$.0..|.:....H..g.....uf.YJ@......V9hS......U..Z...J,...z...A9W..t."....u.LJ..om....a.zx.!.._...:.{.......2...>...n.....4..>;...^p.p.KBV.m...G./...:.s5U....;y..w.................W..*..t..b...".~...I...A...d...<.O....O..X-8}.t#...../m...}....y..(\.e..B...n:.M.....9k.#S!..K....K..}...x.[.....}...I...$.......tx3H...L&m.._....s..."d.1.~xF&y.H.K.i7..J..].-....M...Sy..L..../.._...ZW4..Gi#L9A..<b....+.v.zi...@.y.!.y.Fm....e.?#...M..jr4_.........fp^].}om....%.&.a............y[p..z...xH...~..E..0..". ..Z.QK.Q....'{..(8..7dGN..d...lw....(...h..%.P...p..H|.*..O..M.AY(!F....DujF..i..o.$n.....X...s.sO..]...6`..2...6 ..yM*B..).s...+......h..^..f..Db5n...w..........(..../g).R..,..{.hA.$.......M.L.>...N+.V..x.2.....m.......]r.Q.E.`.#b.S..M.K.?\........!....v.......o...L[..<.V.....k.#?..VMg..&..1...8dS..(.@~:*..x.R.*|@.=$,.......w..o)c.p.6..QQ.......fcl...
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:ASCII text, with CRLF line terminators
                                                      Category:dropped
                                                      Size (bytes):933
                                                      Entropy (8bit):4.710902136409594
                                                      Encrypted:false
                                                      SSDEEP:24:ptrPzDVR5Gi3OzGm0EigS1xbnS4RQhbrW8PNAi0eEprY+Ai75wRZcet:DZD36W3ChvWmMo+S
                                                      MD5:7E6B6DA7C61FCB66F3F30166871DEF5B
                                                      SHA1:00F699CF9BBC0308F6E101283ECA15A7C566D4F9
                                                      SHA-256:4A25D98C121BB3BD5B54E0B6A5348F7B09966BFFEEC30776E5A731813F05D49E
                                                      SHA-512:E5A56137F325904E0C7DE1D0DF38745F733652214F0CDB6EF173FA0743A334F95BED274DF79469E270C9208E6BDC2E6251EF0CDD81AF20FA1897929663E2C7D3
                                                      Malicious:false
                                                      Preview:Q: What's wrong with my files?....A: Ooops, your important files are encrypted. It means you will not be able to access them anymore until they are decrypted... If you follow our instructions, we guarantee that you can decrypt all your files quickly and safely!.. Let's start decrypting!....Q: What do I do?....A: First, you need to pay service fees for the decryption... Please send $300 worth of bitcoin to this bitcoin address: 13AM4VW2dhxYgXeQepoHkHSQuy6NgaEb94.... Next, please find an application file named "@WanaDecryptor@.exe". It is the decrypt software... Run and follow the instructions! (You may need to disable your antivirus for a while.).. ..Q: How can I trust?....A: Don't worry about decryption... We will decrypt your files surely because nobody will trust us if we cheat users... ....* If you need our assistance, send a message by clicking <Contact Us> on the decryptor window....
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:PE32 executable (GUI) Intel 80386, for MS Windows
                                                      Category:dropped
                                                      Size (bytes):245760
                                                      Entropy (8bit):6.278920408390635
                                                      Encrypted:false
                                                      SSDEEP:3072:Rmrhd5U1eigWcR+uiUg6p4FLlG4tlL8z+mmCeHFZjoHEo3m:REd5+IZiZhLlG4AimmCo
                                                      MD5:7BF2B57F2A205768755C07F238FB32CC
                                                      SHA1:45356A9DD616ED7161A3B9192E2F318D0AB5AD10
                                                      SHA-256:B9C5D4339809E0AD9A00D4D3DD26FDF44A32819A54ABF846BB9B560D81391C25
                                                      SHA-512:91A39E919296CB5C6ECCBA710B780519D90035175AA460EC6DBE631324E5E5753BD8D87F395B5481BCD7E1AD623B31A34382D81FAAE06BEF60EC28B49C3122A9
                                                      Malicious:true
                                                      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......%...a...a...a......b.......u.......`.....d.......j.......e...W...b...a.......W...s.......`...Richa...................PE..L.....[J.................@...p.......1.......P....@..................................................................................0..|............................................................................P...............................text....3.......@.................. ..`.rdata..h....P.......P..............@..@.data....2.......0..................@....rsrc...|....0....... ..............@..@........................................................................................................................................................................................................................................................................................................................................................
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.857398962888969
                                                      Encrypted:false
                                                      SSDEEP:24:bkLQc3m4Bf1pWkERmIy2HiDyJtCQnlZfdDeuv8OEJHsFeDFh3:bkMsmw9pbERmIcyjbFLvX0sFe9
                                                      MD5:C8DD0E7B841DFB1CE71D8F517E480DD6
                                                      SHA1:D44C294AB095C2FAE41FA8DF443EA4520EB1717F
                                                      SHA-256:5E846A84881866FFC2E59A7376CA2B1AE37AFD21F407032104F674ECD66114E1
                                                      SHA-512:5AABFB26897039813FFBAF89033603E368B5D844E73113C987F60C3FF87B840EE8FB79E98C97768E2A0D16BE717E95D5D587AB8F6FD11EBF1103C4A8C0B652F4
                                                      Malicious:false
                                                      Preview:WANACRY!....E.... .......w.<...r.....F..:..}.......C9....;..m...Jq.)...].]....W.]ar.....mp....p.GP.Z.[..4h.D.*^.Q.G%....g.,..[US&.X.Q=nj..h.]S.%...<.b.W....g...K.6...O%.#.NE=...{..y.9L..l@..f...j+...;,^.&...H.z.gMn...........j~17np.!..Zd...q...5<.dEj....D..W.............Q....9.... .DH...c.D..\.....\....Lu.s..PJ...4.^.n....6.5n.Y...<'..y8W...~`...7,.^(...u..V.&.:.,.u....8.7..tFW.._.]...V.,.U.SV.....89j......'..q.'.o.x...OD.l..V...T.T....tr.6..I....|.PGZ{..~.Z..~.nm...0.n@.Ei....Q.W.......~.+5..p.W.v/....m.ix..C(9...y.....P\b.r.o....B....aN.31.L.F.g}..M.^..(1YYX...^DU..vK....w{.!D...R...E.=b...:f.ItH.8E.`............NR........Ns..Q.2.i.Zh....a`m...'.5.D.b7.K.Qi.Rp...|.W....B.".......2.OJb,...:.WI.3.+.<*.E.Kb.Q..>.CV..|..N.g.'~5X..7F.$....\.yIn.?..Npn.|...=.q...3....@dXYv..r.....G...v.Mp........&.........,G.~..o.nI.Z..-ll|...c.k..W.S....tV.......x|...,.z..C..R@.nJ...lZ.&.z.G..N....d.....m........M$.Z/..r.R...c.g....+..#.u*.g..`....O.d;7d(s
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.836754166639898
                                                      Encrypted:false
                                                      SSDEEP:24:bkcgOQkpfSxA8tQSTyvgAXvmosKgYYi4viV1wTyTNnpgMAC15td3JqgGc/iruxW5:bkcgGwx3QSTz5YYiH1SyT/ZBvtkgf/iz
                                                      MD5:AFDD6E15B8B30DAFD4DA2D3633ED78A9
                                                      SHA1:02A115EDDC823A6EA3AA4FEBBC040E4802E7B18B
                                                      SHA-256:A3EF798CEF0BAE8F6A3C41290E277342040ED1BBA6A6DD14390165B9AEF6E2D9
                                                      SHA-512:EEB68B62083494ECDBCFFE8BEE09D7BF19C9263118E500C78A36CBB42BEBB4A3DCDBDD6B122D0D801F0E852DBFDFEEC93BE16684D42CBE648591DFCCA1097805
                                                      Malicious:false
                                                      Preview:WANACRY!..........h....../JK.E...W.V|.....K.[.......Y.W.|.;..=Y.$....a.~Re`....-}.. |.M...'.!.Q.m........b.....k......V..\T......6.:Y.k...9>V...Y.._..5.{q..zkQe.L....R.w.}..k....G.dr.....X.'.O..tR..H.T.I..Ys.R.+5.....b8..v...c....@..s.39..]ef..f..<...(...............M[.F.tO..{H|.......W.wg."......".........w..(u.m.....R.e..c ....WCO% ...T.[......g.2.:8.&.......v..=...}H.Zo....5.Y8......^L..K.W....(wk.eK.WVc$..K......j..?.K...E..a.6....!.Qs}.X.a...":....../..x...=..mQ..?.....,Q.B.S...~.....p..f.....\}I\..r.,.1swm6>U..?..k{....F....b..._...;;..L.X...[.>2Z...../T..x........|K.p.a....sr....,...7Lp'..Y...H......O.?j.s.[.......f...e....d..q....%..#....G`..I8.r...($...yrm.rQ,-.6..<m.\.)...K.Li6M....S..!..P....}.O..'.....I..r.+.C.?..C..I..."...>|....(.....F......!...}.F...;(H.RO .e....Q.).e.z...s.l.......I>...$.....Jur.>~]...%p....#...Z@ze.....\.N.y..H.J...R..K.. ...g..K..gf.......E}.Kf.>.(.^..$LZ.=.h.u......9...6.R...8.........!.V...";
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.861741741335247
                                                      Encrypted:false
                                                      SSDEEP:24:bkcUTY1FSjJVPzYIbi+PlQtGgik7xzgxOAahmHeGxVINEFTVkn0qZNfL:bkc71FSjA1f8giYZgg/hm+GzINOoV
                                                      MD5:7171798F0FE80BC38068BDAC9000BA20
                                                      SHA1:1F60C15FF8E231D6BDF3DCDFED14F622A3F84376
                                                      SHA-256:41672B21427A452F92FF05B275F7549BEF28E1449D6F648C9224BC34F997331A
                                                      SHA-512:1A55CB1EDA4E7947E8401457FDBED6BDF3F5F24CF8DFCBC3B3ED0C2354BAB992604D9833A55EDE0A4C5D4603D5EE7DE3DD276531022D9F518719A14DF6E5489A
                                                      Malicious:false
                                                      Preview:WANACRY!......,...is.x.|.....}AM.x6...\..e...j[.....2>.......B...xQ...`.S....a..T[.E.%a....=.-..<w.??..Dv..o..>.].gv..............i.I_l........{g.+y.#......8..0.</...*.t..8..G..j`1U.&...M../.M...._.l..G]9.N....l..|}....6.%6i.?.a4=.1.K......@.X)V..G....T.O..............50@..G.].......:...@.....D.E.."-.j.x.....C.t....N.q....a..ob...p....].......v.>W.....)H..c.*...(n....QfI..L....X....W.8M....\#j3.. 4...]........c...*..SB.1.....?.cb?.b.p....>.W....~...%.q......../.....#.E....'. ...:...T....:.z.c....#I...i<.j.`...S..@......[..O7...8..*!......x+U..u.Y..-A'..T',.I.<\....P.Zh(P.6/.g..F...!.@..[...d.nxK..I...'...$}=._..C..6#.....a.....{.y.H...C.;VF.*...._Q../l.3.m....t.^.>y.i.P..t.3..Y..M..f F......7....I..g..}M._..-...{.....F...d...zN1.S.Hik...=.....4..x..y.tL.PbS....>...xs^....fi.......]6.r..w.&.@*\.p."..\.7B..n.......\9.:M.D..^c_n..@r....!...e........_.1...3.t5.*"..".....dg.!..v...?d.<.UV?..4..n.....a....V._3.f.U.[..c/.2..x..u..6..VG..g.`r8C (..
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.854860036280164
                                                      Encrypted:false
                                                      SSDEEP:24:bkp8Cz+slOx1yoL+g2PtgvBqHRXG4G7CjwnMFthNmehCfuZbJvCzFa0GfxdxGWFt:bkiAt4bctyYRWssithIehCfuZ9vbBrx7
                                                      MD5:C2E4CA2ED9E077C96B01C415D45A2DEA
                                                      SHA1:C915D75041769A1364B740C4124CDE7D01D0D1E7
                                                      SHA-256:41B78E114537D43A730DDF4E0D55FF5DAE9C45F792093D7DDEFA11C4CB55180C
                                                      SHA-512:8EFACDC5CCEA4B7FA32A30271D4A1B1A6EEDA03235C88B768A98D45E1C1B8BBBA40F9D550254D7528D3CB8613D65A9D3E24849AFA3F3C4FC75366B5F4AC32F3E
                                                      Malicious:false
                                                      Preview:WANACRY!.....{P.&.7.y).4a<^.m.@^c....;D..0..y7...S._.:..%m4.U.L...Z......d+..P.^A.LfQ....^.....7YK,..4t.h.K.....].P.^.^V....^.<.U.F*..'..S.:o..d.G...4?.N........yK.^.,.09.L....A.M..7@....nC..l'..MN...[T....L.^.U3n..b...6u..1j'3.3.....D....|.7L$.o...'...Nar.............8..c]...<....z.H.h...z...D ........i.+.-.s0..Y..3.........Kc....Yk...M......[Y.v.5._....wg.:..VM..>N.i.`@.....%..?Pcvg.[..<..kSz...q.._;....6"0kg.g.r.Tt...s4...^m......j(...`...k..k....$G*az....*Q.L..o......N.:^..........A..(....w.:..LI.8.WM.l.p3.m-.;.0..).Jd..8....F.AUwQy..<f..mI..jW1.../A S}._:.......W.a.;.s.m..W.t]..l...V:..7.]......a..1.4..'P$"..1..X.G.T...@_....g...=.*.....Y.....&.Q..&%.....=.-.*.......a..Ry.........!..].6.7......<.$b,.g...........c=...1.}....O.N.2/.<.J...T..i..=..]...fb...Wp^..-..n..?......0.+T..2...[...=....H=..*M.....88p....E...$Yx.....`..R.dQ..8(8.......}...F.........I.....d....F...........p7.=..E.}.Iz.z.....6.d..'..z..b.U..W...9.E.C.%@/px...L..D
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.860696110571382
                                                      Encrypted:false
                                                      SSDEEP:24:bkAQ3sEEUr5OX/OalYwmGXtFg6f4PRaRLEzYUP8pxk9e9goedq/RFvaI9wnksT:bkAcsEZ5OX5lYwm+HttEzw89Ete+jyIC
                                                      MD5:C781613BC0F03A3518FB257145E52DFC
                                                      SHA1:673E6FD6FED0FE9F3F220363FBBAFC4B75CC9541
                                                      SHA-256:47B7D2EA23142CBD1E1C8B5A879710D21A010B398543B68987A2C7528753C251
                                                      SHA-512:679596D43F74B0E21411432156A14302EE9EC9A3716A497C5EF4AAC7507D496ABC0A4DD9ECE2701E016A020FA1E5AB5D66CE37C0F3C4D20CC5F92EE296B41093
                                                      Malicious:false
                                                      Preview:WANACRY!..........1.._.PS.._.D.U.wu.i.:UH.FJ.....3FGl...Q...iO.%@O.A..........=gH.vG@...>[.(..%].C&.B.fTFs"O.a....w....H....T.....{...=-.*....p`...W`Y.... .5_.V...,......q..o-~S..3.<..7...........-..U...+$..t[xX...g...BE...O..(..N..d.P.4X.....$.|.w93[........C............._..S...!E\A.4."..q~....IA".f5...b..8_o.yt.5...*........p.6@x...)..<.....>....}.:....;.J....!..U.....]...A}..N0S%EXp....+3........}.l.....M..G...p.qs....;uB.7....Q...h,......8`....r.z.....E.$).r:.......^^|....3".-.$.*$..~...A....i).Jb.j.M..J.~.].+..<.$.D..UJm..S..7. .pAj...`{. .}......z...:f..Mk@..XN..I./]K..0?...<...>.0S.R......^-..Q...y.[(.2..;....o L.ubk...=O....#E.+V.j]..Q..2C.......*1{~.C4......;.....h.]....]....^|... .eX.CF/.q.T.`...cG....e.RV....L.hN.\..+&.......9.y.......r.o]......AT.`.\.....aL..l..*.....^...M`w...ul..~.W.....a.y.&...g4..A3%Q....&a.bt>qts8=..C..>.;:.^..g.......H.+r ...W-w..n5.+...y...6....B..{n.:.......!/3..9.[.1..v....1.CE...9..f....>I4.S.V.D.z
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.845998088932148
                                                      Encrypted:false
                                                      SSDEEP:24:bkn28U3VoX3R0LoaadXWH5UJUbKKbUZtElLUv7wusLLKUBwgtNb4C2Maw4s5x3:bkn2pV+W/alOaJUbKKbUgpUs6vgrUCtP
                                                      MD5:3259D385B50358141AC0B65EE301CFA7
                                                      SHA1:DCFB0F7EFF83138DC8429CCEABCF47C7E8BB888A
                                                      SHA-256:3C10395BB40A364C660C7D2DF04D6AD0BC9A55ABC72D0698FE869CD096FD7422
                                                      SHA-512:1B4622C8C988BBC17C11617BAB84B5D9FF6696523E0A9D3E7880688EAB346E7A9386BB3D0C0B8A2415CC8F7CF409FD42DDB52552918AAEF052458F4E4324C700
                                                      Malicious:false
                                                      Preview:WANACRY!.....2...K..A..f......D7=Sy0...<_........4.g...z..m.d..@.._.M....RZ_3.......u..<.......@..M.T.to.<........F.o...!$..t.P.Z...t4.p...=..P.v....a.s..25!.6e...=......w./.|g..D9.L..P..S.U...5w.._.O..%_.....T.nV...<.,..{".R.;IM...=v2.......?b.9|..4..dNZ..............O.....F...Z.r........{B...m.+V....w.N..F..T...p.5...m^"....)#.A........q......?.K:z..Ixli. #.Lh.:H...}.Ac...R>....m............O..gA..G. h.....qxU...;.T..v2...K.._...j.......W.....$.9+.v....,bf;.1..)... ..4.m..A*...$...N.-.)..g..n....2.O..Z).3>.}.....m....g1....MR(=../...rN.P>.ti...\...!1.o..@..k...)...k+b..x.f..b.=..\....q..a<..PN..|.C..;...zb......7-.j.6....0..{..`....J.....a.c}.za.BI....s.....5...*.D.B..lIz.V.c....wb..?.K.....6k.....`.g.3..~0..A.....B. ...q=.n..y.69.\...PUxJ\ .G"...t^...-..'....BZ=....U ..V......c.K....-.V..`.yU}..r.,.4...]._.$.dT.>.....+g#(q...UJ..f...u.U...|.....,;W...A._....I.I...'._..:..F......]]....g.Y..d.7:A.. ~.......%....b.$...K$
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.835803576620504
                                                      Encrypted:false
                                                      SSDEEP:24:bkGCYfxTvJZBAjjpZpMIFFqgrwFPm5426MMpmMNOQAc4iUIVUazDBjKg:bkGBxTvJ34pfFNy94MEPNisaHF/
                                                      MD5:EDC89AA619DCAA3B528EFE975BE2D7FF
                                                      SHA1:F12075DA01C9DCD4D20440960E1AB154D53CEC46
                                                      SHA-256:C26DCA0C1A09E4912891A2C1E7EF8C3745E0D628767A297BB67E3EF7818C6A57
                                                      SHA-512:DF7B1D9BD2A016DB538D9CD27A85558C45E59E069CEB3E777BAC591C432097EADD993351E1F2E1D5D11757F539710A401F78CE38DE51E211D9183A21F4EEFC46
                                                      Malicious:false
                                                      Preview:WANACRY!......{.h..)p.......%..m..;..^.<5;.@...9...Wa...<.. ..h.!.O..&Q...ac.Ug.........<...S.z%...-.6{..{#..6...%......[....>kS....W.d..E..T4...&.I....>SR....4p..9)Z.|"z....gk...i......G.*....[I9h....]....2..G&.)....R....?.5.......w.l......i.....w.]Yv..:...............)..Mo.O.Q..)..5../..C......5......=...D.~.z<..uoA..[....^..../..... .{.1....&..dV{5CE.............+k.s.B4.....X.=T.....Jm<.(.].82....!.N.-..;.o....L.5..-..y.Dt..|x.Vx...._D.J.q|eGR..S.c.%...&....A...O|3I...G..(....IH\y.69.!...<@.{....=[.V".\....|.gB...2..k....;.p/..r...>}...y:.7....C...Vd....A....@.z....02;QR$....M...]..[..8....yv....f...cp_5=hk.|.......Sx......_.....L..;..*C.D.d...H.R.C.....R.&d.3..T)p..as..........|.%i..?..z.t!.3}{....s.m..hG......d.6&w.....qoXC..=A&kd.Yj..5.......l..x]...p}...l.J..1.\.......6.u.... ....J..F]S..'..WS#._./. .0. ..Ww ..)...-.{.?(..z....I..uT2...B...m.....S.L.P.8@.E.!.R.E.....V.QW.?w!A.=......=..-F..P..1D.W.o..L!.I...e.:...iQ.".Y...F.N......2.WD..
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.869132879191293
                                                      Encrypted:false
                                                      SSDEEP:24:bkAAtGUhnRUoZ0aQd1MMiiTWjDdRvH41rt57FrxYsGLsJsaTutA585o2zKPGyn:bk9tjD6aQXQDdZ435P9Gbaew8EPGyn
                                                      MD5:EBFAA3FD4646B07614571F12DDCF7154
                                                      SHA1:0DCCA911A02D3DC928A656AB6CC947A3AF7B30F9
                                                      SHA-256:EDA1FFD7559CFDBFCF830168A499A064B56AF33442DBCCB8CE2F100F46ADEC66
                                                      SHA-512:A6E8DFB5C07E5482BE19597BA5910F66AEDA48008BC8B828B103C69F3012E466AE342CFFCBBC235C59565F57991C1A9DB6F8C0E2D7ABBD7251B3190FBF9837C4
                                                      Malicious:false
                                                      Preview:WANACRY!......Wmk..E...u...%.(W..kL....G.....>..e.......G..i..m."..)...w..n.....v...e.Z.oF..q.<.mu....%h@.l.!.".M.m.....!4(.B.g...fD.x....Kz.E.DQ]H..Y......;3........&K.X<...5H4.`...e.wl.9....nmi~..<z.....(D..../.b..8...sW.......0........P..W..0z...8cO.......................J.{jS:...cYa.......p....ys.z.6T....p>}.%....X&...............m..?..i^k...n.O.K..@r.....L9P..a.h.5..=...OQ./y....e00...*.X.p1..C..IE...w.mOG.]..X:..\.=.......?/..1.A..w...=...1...@...o....j..T....4..@.._B.~l#$w....oMAF.A1..s...Y2.w.s.U..n5?...3.4.......!...B(....).....0...M.N]#....g......3a]".. .?...S.(.&...T...}3..n.%..V..K..O.~.i...7j....I.VOc.f.qSZ..;J.%n...+.u.E:gp!^.gEG..ZqD*....1.!.o....]q. .l..w.b....0...-..<.gx ...sok.|.....w................{.../R.....:..../.Jy.&L|..j.......h0t.=.^..?..^.....V..i.....v..S9......w~d...FQ.A...s....!U)0a[..,..Cf.Fyv....JFiu...A.7..].j{C.C..!I.....\ P..,(......k....mV.g....e.{S%.X.Q@......z6...T.C..r...q...6..L..f...C...'Z._.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.840296169725666
                                                      Encrypted:false
                                                      SSDEEP:24:bkTMeEBn1vZdZOVnw/us6tGE3PTzKf+6gl0Ed8aoyIrLWF3ck3MxP8T:bkTMTXZdESus6tGG/KtNyIrLQ93MM
                                                      MD5:0243B1DD2CE4D8A95ECB18D0404B8934
                                                      SHA1:78F1A3F3B2396F29834D848EB23AD103C34B0962
                                                      SHA-256:2C047466491B436FA8D0497182B6AD605CBF0D29A1C846221745B8C8F0280FBF
                                                      SHA-512:6A19A890A0671A2E8E3A8A4E1526717A6C0B0BE71CC88593D291525B83138ED2D63D03F5EEEF8152FAC2D120F14CE2A97175F29F762BFAE8D3B4DC29D4FC8311
                                                      Malicious:false
                                                      Preview:WANACRY!......*Xe......:`..?..`..<........l0......O...|O.-.q..D.|@..'!..z..hx/....:!..S....)......@.q..Gy...,'mB.;.......hC....B4C.W....=Ie.GRL..[Li.t[>0_!......A.....N.S.....*....V.u.;..e....u.D .OvB.6G.yy...Q.E`.j...%.D...,R..${+z......-..k{..8.w...................RE+...i...@...x.9.....0:.7.*l.3.A.YC5..B...I...D..>S......g.3..}.4m.;.) ...(.i..#..2.=]....F......]..L.#>..x;..a....%..=.M.....9...c...5... ..0..,...u.....R..~?.>.+..]...nUg....J.Jr.K..W.W....{. . .. ..!A...e.....}.....1...L..Q*..? 4]....u..l..F.....VN.O....Hb..i.....C.{A{...jnK.E...-.|FvQ.......`.E.yy....q......7D.-..HN...SllnY.m.. .$...^..?.Z..iE.....`x...4.K......Tr.7.-?...b[.+.A...+.KW.ZQZ..c.3....I...xl~.'Aw.c.E..`...._..(.....V.m..JB...J....HQ...i..t..M...............4..."Z"..E.>.Q.H\...5..p.g.R.Q ....B.*.;..}i/0...u..C^:.%.e..s@>..."9Bz..#.3.]x8..K..b.~...2..D...d.@...4=..U.......2.&r>e..-...L.^.....2..d,*H.sC....I...0.lt...>.k...Vp....jr#...-...e;.n./.$B%LA..4.nQ.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.840781609888517
                                                      Encrypted:false
                                                      SSDEEP:24:bkIbSwCaYhckq88beIaB8iNGIjQZslqil94xq74WPb:bkIbSu4VqafNGIMsldl9CeD
                                                      MD5:A5CD3675800A5D024DF22BD3D73B7F28
                                                      SHA1:7DE4B247B2AAD727DFB59BF34C251CCAD6779A1F
                                                      SHA-256:0F20843E9269EDC52CFC4AE43EC3A6CD98A80223B0C37987B7DCCD2C4944158B
                                                      SHA-512:73278462BB952F5B44DC061A2B675A919DBFFF584E576AEB6724848F931741DFFB374E826D9E413E5A9C7DD5F0865ED40415873033664022D7E5D8049779D7D9
                                                      Malicious:false
                                                      Preview:WANACRY!.....o.......33....0.?.6..}.....'O...i..]*.\-^...eA.L.#..N..W.9....1_..U.L..G$Jlqwf.b.$!....D...{.'..0.=...D...3......;.Y..XC.).^..B.V1...,....P.D..a.rP.(..E.......B.b}......$C|.'.Bf.d.oT8.*.u...6`<p....y..< D...D..$?H.5.P....]s6%xEI..-....?....*...6.............`.-`.U.*...=..*...[F.......s4_w.ID.m.j...<.Z.d.E.d3g<j.61..y.I,l............>.....&.......%.".k..I.<rA6...;o.Y.|..4.t9..._...iFkL..2.Uc:..jtx.'.O1./SZ...ME.wc.%.......L.f.v..b..1.=.]~.."-c......c.R.Q...w-y+O.M....".:J.....F..a....4.F.D..e..n....'.pM.<nq...J.b.r[.......D.}<.)P{.k./..O.e......9.9TlyZ=..T.."..%....$n[?x"..6J)....N<!|J.!bI.....=,.-",.)R......:?........{^.gT..-.....e.;...&..]<.!....Q.=tc.6.{.J.f...o'{p\M....j..#KN.....f[m.....v.:g1...>.=M...L5.R.\...sW.....'H.^..[/......+.......S..o......;.l..O1.^..m..L k...Yc..a..8h.3.d.+O..z...y.x.\...4...~v...Q{.m..|.v.~.)......4..._:L..;+...5]...H..OU"..J........[.Y....C..%.(.8..F..9...|.`..B...;...Yl.9.N`. ...^.J~.7Y..s...
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.830863680690429
                                                      Encrypted:false
                                                      SSDEEP:24:bkgK3JKlV1CshbINmjS9XSUe6nDY+QeP2xkgrZv0xsW/jRaaXuVLly6PHcT:bkgK3aV1Cs7OCUe6nk1aWv0xpdaaXkRQ
                                                      MD5:9ECA795BF91F340CC15ACD5D3ACD6A0E
                                                      SHA1:B9CB8E5512E6D038999F38614801A5EDE76026EF
                                                      SHA-256:43F9C09ABBE9A2A592299C455C120E4F0BC68042DEC4F5821644E64B67CBD764
                                                      SHA-512:C54BDD438BBEEE445627E557085900C9DD382A1B95EE6FCE90F2B7A9280A3582C7E7DB7EADC26B5A778A686F8C89137FE52254498CF14C61CADB75F36ADB765D
                                                      Malicious:false
                                                      Preview:WANACRY!....O.L.5.p.e.....}D...#G.S.C..(d...M..a.I=+\5.JJ..'-.. ..Z.........])k...... .&..X[.u.E..*...P.....d.{.&#\.....6....(.Q..."M.._U*.0.$.xM..C....i..x....Xq_...gU..&...|.+......3........M.R.........b9Z%....@..w..."7n408..%..E&..k..h.......?d................rz....b.w....h.6..-....-.Yxn....^....`..O.n..5k<....g.2.=.K...~..../}..i...dK)...+..S..s..n..<..Z.."...?.....].~i$.......@.........|;....0........S._...4g.*FOm.0+5].E....W.&.......<...T.r.+.U.l=....0#......T...1a...v....4rD)K.-..7..9[....b.W....E.{.cq(.T.L.g.Z.?!....0G.{5.....i*.)...a.....[...~&Pa.....k....:......W..*PeIy)..`.......f.......M#`.HX.5..E....~.v....I...opW..,A..+.T>....&^.*P.Y.g~?....*(.[.k.d..f../7dB......b..G:.hWX....\AU.........cV.Ws..'...~...didRO.r..9\.... ...._.A.....Cx@pzW..]#..Z.gjLn.&.[..(.4.z.H?.6.{....zc.......Y..t.5dj..2Dq.+....~..r...'..nm..X..Agi.8.#..[...D.)r!%....TT$-Yi.. D.R...O..O..%-..U{....1\.i..V.rcEX0..:.r...O..%._q|(...L.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.830167876025704
                                                      Encrypted:false
                                                      SSDEEP:24:bkKwog4kjOnzAuV+wvxWK+XsuBn7TrzJHJbyWwbr6ZX24ZOLiWEa+H0GGqyQdmWI:bkK32OG0g1zzZJbXuryPc7EvUGnyIt5K
                                                      MD5:B15233316B73FF3B2B09DA00A5818BD5
                                                      SHA1:95A45032B465E1F592D9C63DCAB8BBE419491465
                                                      SHA-256:E0C21CFA2B86DD6E2D9AC92AC36EDE00D72B79BEFD5470D84084DAD3A8CAD2F4
                                                      SHA-512:C555F623C2421382D8138F681CAF8935C20C4C70C5814857A75B58A92C886CC16BA0ADFB22B178BE92A69E0436C87BDECDD4D299A4D1C11F3B356716FF924413
                                                      Malicious:false
                                                      Preview:WANACRY!.....jj....g....9.4G..B$.P{aM.%ge.>>.....F.>0.p...VN.\S.....(......}x....W.......%5.Ssd..dY.........Q.{X:u.BN...&.A..R..W...%..iS..[.e......T].....s.X..-k.a7Q..I.S.......\#../.P...>.J.....Mv.l..%.p..u...^.S...M/7...N. ......'....:%Zio*.8.s.d..E[z*]B.'............J0&?.x.xN.!.j.@e....uX..P..*..@.q......a.2.-.........D[...w_.....^t.j....[...."R...:....=..0.$a.<E.i.Gp/...t..1..Y4.`@-.l..&.vXQ..........&"r0ix=.-.....w.$.H5.to1......V..Z?.3..q...L.uY..C.7..c..y....9.......L..y.j..&.W.}ED.....R.....O.=<...~.3.....A..,..d.F.>.z.{z.........CK.U.JM...7.=?......I.....mz...*.!..RR...(g....u.z..y..&....5.L...\..j.NM..L.4x..K.Q8o.u........1..X....A.x.v..'.J.\......p.. bu...[.^..s..=wRx.5.p..u!..d....... /;......._..F.V.....Xu.<C...anM|...G.Tj...%B(-8..+..-W{....O^[6LL:e..l-.y.hF`.M.%...6f.{.6..M........8.\*.2......#.w.[....J.E..Z.D.3..D....> ...B....P.ZX._D4.B.....~.pe.k.......u...|)..b..r..X...'"........ZL.P..:Q+../...s..o5....t..*.]q.7.Q..UMJ...
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.847562504908324
                                                      Encrypted:false
                                                      SSDEEP:24:bknfYzD8jnN1lhVqrcOl9QWFV+Uf6vVHeNnIGY/ETxjyhdQBdtbwdN:bknKYLNxOl7UTvUZI5EkhSBdd6
                                                      MD5:B677E79DDD7DC51B99B53D1F57B59F68
                                                      SHA1:7DAFBA6A24E0BDA7D0CD189AF2964A9BCF00A786
                                                      SHA-256:EC2363A33D5CC072BBEFFC28D97EC57CF053D94F8D6AFC9C59A97D0C67A0EF56
                                                      SHA-512:2F441C1D2FBFAACA4A99A63E01A6463A1832B2A960CCEC0925C720180FFF63634A895FEFD568BA537F08E3F7BACA950D0E0AF8BF5D5DA2916C7BBA05A802385E
                                                      Malicious:false
                                                      Preview:WANACRY!....T6:.F.IGh<..E;..'.~..O(.....*N4...:.....i.(Z/I..(./..f..=..2z.3.....6...H......27..,....`.R.W.D.T..q`.....B...m;...V..O.....B!...u..q......p.b.m..."}..%4?..].............v.Pb...p........+I.r....aIR.0..~.].m=.$..R.7.........].......O\4S.3...J...^.S............&.m....E&...$-..X..|...T....PSd..r..n.C........'...|nz.K092rVf..C..Q..8a3"..dp..G.~8.D7....p.....~~.0....k...&).....e&.].....v:.F..qO@..!.}.7).......|...w......D..1-.... .......:;{.....h..}.O?.....b....=...w5[.<...)........a..h.1....a.......3,.-.[\.].c."$3....Ps.....)..h.C.9.m.,A........G..'........x.U......is[....]..@......>...xs.........v<..H....9d..#..]..K=....KdP..._.j...........(O.w`.._w.PwE..%.J3.^h. ....n..]...v./o.>.n..!..__...IX.w..)xG...Y..c....#j..l..~`Q'...e.'5........3u.sa.m...r..C..i=l...by...;.aX.V.L.Cd...Bb.H|....w,CF9.;M.f.m.K.y.|.{.<I...2<./......&...../.....t.Kr..........sw]z..c...S.n.....e.2..z.f.W..Do....uy..h.......:..........k.f"VJ..y.\.\....&J.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.85360645605731
                                                      Encrypted:false
                                                      SSDEEP:24:bkMEy3shjQgcmUepyHVx0igapT0/lNPgdZhwq8qWAfsK0m9Uvkg3:bkby3u7Hs12alOlNEZWoETmE53
                                                      MD5:085004A79BF03E8969A894D9CA1CC5E2
                                                      SHA1:13ECADB53D4B13C38B0361BDBC6562F1F0F24AB9
                                                      SHA-256:3F8FD80803925A7581E27C5FF6E93BD8BD9B5F8E7DFA9A80C7A6344A82E85BA4
                                                      SHA-512:DB7BB1E640D232F0D5DD8059B55DC619D58F1CE5FBA78C7210276EC60998E8DB9D6A356FD76A3D9675F065D7569643128BA01006BD6328CC1E56EE6B4256797D
                                                      Malicious:false
                                                      Preview:WANACRY!.....@^...%..h.h3@YV.&_......'.#...a_.5..V*.L..0s...gt...L..de.z.H.......s..T.B...*Nw....:.k...A..L...R..}^..#.....O3..t..$j.{j&..x....H.x...<....7.d..^*P ...eUN....x..T......<D... .......f...3.M......_.WV.k/..&.[P.....f..?.d"%...D...'t......e.n.".............}.p..]..M.D.T4..[..VAvl./M4.)wMZ$.....4._s.o..".lW.;.Q.B.j.e].yFX..~G..k...$1L.*.PW...a#,.#.:C..Eo...{.j....H. .pg..Sb.lw.......J.#...8$.3.(.*..[+.5|....ly..s....h.H...f.{...c.<...I....U..DtM..._...%..y.6...........8..p..0.xp.j.........]..:1....v...i.y.#......9g.6.R..[.o...e.-..=.....>F'.3*.....x.t"........[.vz...4..Y.a..y1.x..Zc.....W....9.c.....p.>....t....(.....J.#.Q...x.>..v.....N...&.U..O...H-..Nzc=.8;$...... ....O...s./.r..{P|t.9W=.s..5.B.'...t..c_..u&.....7.Kk.H..t.]...k.Mc'j<.\.K.y...Jn.+..y.W%}...V+...Y.......9.....*5..E......\=...yI.LrC.....w.2u.%@E....W..17.[6..,q,...Ak..H................O.<......@...G....6v....9NW..nZ..>f8OU......k.{.Y.....qj..../....z..y.p.?.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.844856836691295
                                                      Encrypted:false
                                                      SSDEEP:24:bk9PVymgvYfT+GfnudTVvTP5eZDfcSVQmwmqphOQwg/+pRDwAYKd97m2ioGs0:bk9PjA0+IwhvD5eZDfdVnZqp9o1TXf6f
                                                      MD5:F4CAEA23107B4DA5756E22B485AB9311
                                                      SHA1:FBE235D87B3D33F53CA7E708BABF2A886EBE9F8E
                                                      SHA-256:787433E7D5DC44FECA43B493C40EE4FDD4D84BFD6AF8407BDEA15E134E3582AC
                                                      SHA-512:447F448C2238101115FA1CFCAD85C2513CBF7D45B38703BA0212612D390F0F7F87FE74B152356732166B9B0BF828E7AF99203E87DEA9D5813AC1F53A90BC04E3
                                                      Malicious:false
                                                      Preview:WANACRY!......#...X<.\q.<..#.J|........4o..<.]4..+..6..FE.d..u.6*...D...Y%y&-.v.YHB`Tk...|.Qi..@>..j....?.P.2...NLB....u0.f.M......!h..Uh[.A..0......&L..&..'Y.....r;F.5^.Y..).a....*..fY.z..0.. ...F].).c.+.8.\.:.M4r..m..6.k..0u}.2.......v...f.$./.KXt..<\{.............y_v..eP..+.E...8...pG.......... !....$.*6B........l..bk..I<P..f%s..[...%.....~+./>D>S...=a+...]p.M...J.=);ap....=.C.ud..)/tJ.P\q......V...a..'..=.....F.a)A.....D.?%).V.J..b....~...z5..p..VJ3......$^.\w'.<..."./.<.'.^.........N.^..#.M.t..TC.....jt.......'..(...m].,..$,I,Q.$r...+.4..&.}.......2.@...!.J..{.....JL..7.N4..x......`W.......N..4 &d....bW..g.g....\R.2...kQ.!......,......s.N......n...1..:..y.....?..Ya3..,U..=.....y.....//.....YX8C.u.I..3j..df}t.6........f.V..t..-..X...`)...T.....7..?M..9...y.jlb!g`....Yhn.&Z2.U.....O...$._...T...a\g..x*.....f9/..7......&`.C..7......R...G.....z0a.X..})]oM.2....K..:.$.....9jt.f./...<.7\....g#.*.].j..D..6B...'#......F....}l.7zQ...V..1.K..).
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):1320
                                                      Entropy (8bit):7.849112094612508
                                                      Encrypted:false
                                                      SSDEEP:24:bkr4J2x5ZKhdwLDOl22ZAZt6L88PNKmiV88WzbPrDFzSbod2:bkr4J2x5ZywDOl22ZAZcymd8GPdS3
                                                      MD5:99E1456C8564F00017C5BE9F37E6018F
                                                      SHA1:0BACD5ECEC2D4259C0D1873CCF3B8FEBCF421054
                                                      SHA-256:387C03BE007542AC114E0B24173D8FBC1F0D5AFD91431A32E38A3766B7E6AE40
                                                      SHA-512:AF3B1279CEC56E359A20157B23ED80EFA4ABA66FB8E24B4A97620D567A5F62FDEC5ED84D3A16B15C18BDE7E7FA96961F5560792232C635B9BD792B378DD70DD8
                                                      Malicious:false
                                                      Preview:WANACRY!.........~..{.y...Jt.Wv.F.l0..S<...l....o+...b...}.....2.,....z...U...*....w.........j(....I.)...3.i.*e..Cg..+&!.Y...O#q...L$.#E|..I..V.q.....\@..........&.:/n..f76.PH.7..z.7g.@/..L.f....0Q.V.I.`...z1.QM..jG}.*w.i...z..Eb..../<....Y..............F................$o....Prz.*`.......t{s.j.y7|.VY..Ut.\s....}`n.j.s..#@..@..?..L[<|....B....E.O...a.5..o.T...Z.hsw:zw;Y.Z.|......X.s...I@..|2b,.v..B..X.....9..F..u...nO..*..Z....`QC.}t..}O....z....}..a....(...EA.l@..D}pa...3...z.h..C..`x.._>.0..I.9.S1......#ths.....A...}.-.....Oi...H..........b7..a..'.c&.}....T.K....qS.K`I.;.=.a]^T...C:. i;=>+.Ekb......r>.a...>....%r4...E.G......g...N........`7..+.".X..X.OI.......m-..._5.-g..B.|...P...}..'...~{.......5>...1..F.G.....=0...,fE%y.G(.3...........Jq..g.\..N..KB,R..[.B[..~..#.. .z~.=..C..Gel...M.{.4......d...8...U...Ut.......y..a.r......X..x|X....oLU.G.m...?/4~dC..,_.......18.....~..#..........^.....[?t..o V.......J..2..;F....V&.....Z.. .../!A.
                                                      Process:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):114264
                                                      Entropy (8bit):7.998524200979648
                                                      Encrypted:true
                                                      SSDEEP:3072:11Pr8MD83Ep7nzihr1lKHZrp0n2HdxPaIbqzu:1t8eNObKFKoxiIbqK
                                                      MD5:527F22F1C3B296187F1FDA55D208FB31
                                                      SHA1:F6A8F3495B6896941D3447B68C89D2B21C0E0516
                                                      SHA-256:D8AB6251996091EFEFAC0C5CEAAE51EA3552384D96786658200F850BD8258D8F
                                                      SHA-512:25C25EFA116A4DA6E4516AFCB761303BD36657197767694E0B003303A920E9FE0DE1A162A90A6C5200F296CFFB838B34C032C94DC1208CE276970CF328AFD6F1
                                                      Malicious:true
                                                      Preview:WANACRY!....[..Y.a..5.IfT.{....!..e...@.d..`.f;ME.?a.(B... .j.K..bm...R...i...5l..9..rz!.q.|z_N].(..<.;./..j..'R....m#.~...u.Z..B.sA.BLk..cQ...F.sNY......z.A...7s.u..._..E.....l.....Zymx.. W..G...g3.C...fn7+...j..-.>I.....- ...o...|.cV....=.`......-VK...;_|.^).....6.......l.....h#.Kj...H...,._..Fs.C.R........!..73...!J...8...x.F.B..c}..hc..R.&..[...I..b.Sm...).l.*...XW..v'..,...1.h...Q._..PB.u..-5.......RB3....b.q.v.......8.NH.<..3...%.l..+G6en....][l....:.>.....!..`...GwDS.,.W......../........|.g`.O..B..|.....AX6....C...(V.....>..U.M..|.(........]q..;.\.-..~>L.....6...L.Z..O9a.........SXL..~.3...)U........cC7.k.w.>R.;r.C.mO......r....T.....=.Q.....z...t.\..G..=TY.)w......L...Z.$..Tqa.....4Y.&#...I.y..?.i)..!..@...".V..6.V.,..!7_..{-z..W4.3;.KM.M.N}...%j".-.N..[.........HW.. l.9(...p....P..}.... .B.^.....O\q|k*.E83`~.Z..).2..wc......A..}9>.k..HV.67=.3...6..7..]...U.n.{a.i.....Q(.x......K.8Ak..4z.O.a6n#..n...<...............$..>V{...$.Q.E....)}.
                                                      File type:PE32 executable (GUI) Intel 80386, for MS Windows
                                                      Entropy (8bit):7.995467986215682
                                                      TrID:
                                                      • Win32 Executable (generic) a (10002005/4) 99.96%
                                                      • Generic Win/DOS Executable (2004/3) 0.02%
                                                      • DOS Executable Generic (2002/1) 0.02%
                                                      • Autodesk FLIC Image File (extensions: flc, fli, cel) (7/3) 0.00%
                                                      File name:LisectAVT_2403002A_126.EXE.exe
                                                      File size:3'514'376 bytes
                                                      MD5:c98e7230adb1ba8d2f2082ca885068bb
                                                      SHA1:523a6fdf84bc1b0eec54d9532b3dbe564f29af38
                                                      SHA256:6cf41e72620cafb1577415d626dbb66c8c796d7167164ca091a27c4273378a20
                                                      SHA512:fd20a85e28ca7e4db3015299ce2b047c7868978ca98e170f3251b831b70214f6b4466b2e324edd9e5df33672d918be68929c975838dde8e877c94ea60d57c641
                                                      SSDEEP:98304:QqPoBhz1aRxcSUDk36SAEdhvxWa9P593R8yAVp2g3:QqPe1Cxcxk3ZAEUadzR8yc4g
                                                      TLSH:F4F533F4E221B7ACF2550EF64855C59B6A9724B2EBEF1E26DA8001A70D44F7F8FC0491
                                                      File Content Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........:...T...T...T...X...T..._...T.'.Z...T...^...T...P...T.g.....T...U...T..._...T.c.R...T.Rich..T.........................PE..L..
                                                      Icon Hash:00928e8e8686b000
                                                      Entrypoint:0x4077ba
                                                      Entrypoint Section:.text
                                                      Digitally signed:false
                                                      Imagebase:0x400000
                                                      Subsystem:windows gui
                                                      Image File Characteristics:RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, 32BIT_MACHINE
                                                      DLL Characteristics:
                                                      Time Stamp:0x4CE78F41 [Sat Nov 20 09:05:05 2010 UTC]
                                                      TLS Callbacks:
                                                      CLR (.Net) Version:
                                                      OS Version Major:4
                                                      OS Version Minor:0
                                                      File Version Major:4
                                                      File Version Minor:0
                                                      Subsystem Version Major:4
                                                      Subsystem Version Minor:0
                                                      Import Hash:68f013d7437aa653a8a98a05807afeb1
                                                      Instruction
                                                      push ebp
                                                      mov ebp, esp
                                                      push FFFFFFFFh
                                                      push 0040D488h
                                                      push 004076F4h
                                                      mov eax, dword ptr fs:[00000000h]
                                                      push eax
                                                      mov dword ptr fs:[00000000h], esp
                                                      sub esp, 68h
                                                      push ebx
                                                      push esi
                                                      push edi
                                                      mov dword ptr [ebp-18h], esp
                                                      xor ebx, ebx
                                                      mov dword ptr [ebp-04h], ebx
                                                      push 00000002h
                                                      call dword ptr [004081C4h]
                                                      pop ecx
                                                      or dword ptr [0040F94Ch], FFFFFFFFh
                                                      or dword ptr [0040F950h], FFFFFFFFh
                                                      call dword ptr [004081C0h]
                                                      mov ecx, dword ptr [0040F948h]
                                                      mov dword ptr [eax], ecx
                                                      call dword ptr [004081BCh]
                                                      mov ecx, dword ptr [0040F944h]
                                                      mov dword ptr [eax], ecx
                                                      mov eax, dword ptr [004081B8h]
                                                      mov eax, dword ptr [eax]
                                                      mov dword ptr [0040F954h], eax
                                                      call 00007F9298DD971Bh
                                                      cmp dword ptr [0040F870h], ebx
                                                      jne 00007F9298DD960Eh
                                                      push 0040793Ch
                                                      call dword ptr [004081B4h]
                                                      pop ecx
                                                      call 00007F9298DD96EDh
                                                      push 0040E00Ch
                                                      push 0040E008h
                                                      call 00007F9298DD96D8h
                                                      mov eax, dword ptr [0040F940h]
                                                      mov dword ptr [ebp-6Ch], eax
                                                      lea eax, dword ptr [ebp-6Ch]
                                                      push eax
                                                      push dword ptr [0040F93Ch]
                                                      lea eax, dword ptr [ebp-64h]
                                                      push eax
                                                      lea eax, dword ptr [ebp-70h]
                                                      push eax
                                                      lea eax, dword ptr [ebp-60h]
                                                      push eax
                                                      call dword ptr [004081ACh]
                                                      push 0040E004h
                                                      push 0040E000h
                                                      call 00007F9298DD96A5h
                                                      Programming Language:
                                                      • [C++] VS98 (6.0) SP6 build 8804
                                                      • [EXP] VC++ 6.0 SP5 build 8804
                                                      NameVirtual AddressVirtual Size Is in Section
                                                      IMAGE_DIRECTORY_ENTRY_EXPORT0x00x0
                                                      IMAGE_DIRECTORY_ENTRY_IMPORT0xd5a80x64.rdata
                                                      IMAGE_DIRECTORY_ENTRY_RESOURCE0x100000x349fa0.rsrc
                                                      IMAGE_DIRECTORY_ENTRY_EXCEPTION0x00x0
                                                      IMAGE_DIRECTORY_ENTRY_SECURITY0x00x0
                                                      IMAGE_DIRECTORY_ENTRY_BASERELOC0x00x0
                                                      IMAGE_DIRECTORY_ENTRY_DEBUG0x00x0
                                                      IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
                                                      IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
                                                      IMAGE_DIRECTORY_ENTRY_TLS0x00x0
                                                      IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x00x0
                                                      IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
                                                      IMAGE_DIRECTORY_ENTRY_IAT0x80000x1d8.rdata
                                                      IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x00x0
                                                      IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x00x0
                                                      IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0
                                                      NameVirtual AddressVirtual SizeRaw SizeMD5Xored PEZLIB ComplexityFile TypeEntropyCharacteristics
                                                      .text0x10000x69b00x7000920e964050a1a5dd60dd00083fd541a2False0.5747419084821429data6.404235106100747IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
                                                      .rdata0x80000x5f700x60002c42611802d585e6eed68595876d1a15False0.5781656901041666data6.66357096840794IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                                                      .data0xe0000x19580x200083506e37bd8b50cacabd480f8eb3849bFalse0.394287109375Matlab v4 mat-file (little endian) ry, numeric, rows 0, columns 04.4557495078691405IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                                                      .rsrc0x100000x349fa00x34a000f99ce7dc94308f0a149a19e022e4c316unknownunknownunknownunknownIMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                                                      NameRVASizeTypeLanguageCountryZLIB Complexity
                                                      XIA0x100f00x349635Zip archive data, at least v2.0 to extract, compression method=deflateEnglishUnited States1.0002689361572266
                                                      RT_VERSION0x3597280x388dataEnglishUnited States0.46349557522123896
                                                      RT_MANIFEST0x359ab00x4efexported SGML document, ASCII text, with CRLF line terminatorsEnglishUnited States0.42913697545526525
                                                      DLLImport
                                                      KERNEL32.dllGetFileAttributesW, GetFileSizeEx, CreateFileA, InitializeCriticalSection, DeleteCriticalSection, ReadFile, GetFileSize, WriteFile, LeaveCriticalSection, EnterCriticalSection, SetFileAttributesW, SetCurrentDirectoryW, CreateDirectoryW, GetTempPathW, GetWindowsDirectoryW, GetFileAttributesA, SizeofResource, LockResource, LoadResource, MultiByteToWideChar, Sleep, OpenMutexA, GetFullPathNameA, CopyFileA, GetModuleFileNameA, VirtualAlloc, VirtualFree, FreeLibrary, HeapAlloc, GetProcessHeap, GetModuleHandleA, SetLastError, VirtualProtect, IsBadReadPtr, HeapFree, SystemTimeToFileTime, LocalFileTimeToFileTime, CreateDirectoryA, GetStartupInfoA, SetFilePointer, SetFileTime, GetComputerNameW, GetCurrentDirectoryA, SetCurrentDirectoryA, GlobalAlloc, LoadLibraryA, GetProcAddress, GlobalFree, CreateProcessA, CloseHandle, WaitForSingleObject, TerminateProcess, GetExitCodeProcess, FindResourceA
                                                      USER32.dllwsprintfA
                                                      ADVAPI32.dllCreateServiceA, OpenServiceA, StartServiceA, CloseServiceHandle, CryptReleaseContext, RegCreateKeyW, RegSetValueExA, RegQueryValueExA, RegCloseKey, OpenSCManagerA
                                                      MSVCRT.dllrealloc, fclose, fwrite, fread, fopen, sprintf, rand, srand, strcpy, memset, strlen, wcscat, wcslen, __CxxFrameHandler, ??3@YAXPAX@Z, memcmp, _except_handler3, _local_unwind2, wcsrchr, swprintf, ??2@YAPAXI@Z, memcpy, strcmp, strrchr, __p___argv, __p___argc, _stricmp, free, malloc, ??0exception@@QAE@ABV0@@Z, ??1exception@@UAE@XZ, ??0exception@@QAE@ABQBD@Z, _CxxThrowException, calloc, strcat, _mbsstr, ??1type_info@@UAE@XZ, _exit, _XcptFilter, exit, _acmdln, __getmainargs, _initterm, __setusermatherr, _adjust_fdiv, __p__commode, __p__fmode, __set_app_type, _controlfp
                                                      Language of compilation systemCountry where language is spokenMap
                                                      EnglishUnited States
                                                      No network behavior found

                                                      Click to jump to process

                                                      Click to jump to process

                                                      Click to dive into process behavior distribution

                                                      Click to jump to process

                                                      Target ID:0
                                                      Start time:18:01:42
                                                      Start date:25/07/2024
                                                      Path:C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe
                                                      Wow64 process (32bit):true
                                                      Commandline:"C:\Users\user\Desktop\LisectAVT_2403002A_126.EXE.exe"
                                                      Imagebase:0x400000
                                                      File size:3'514'376 bytes
                                                      MD5 hash:C98E7230ADB1BA8D2F2082CA885068BB
                                                      Has elevated privileges:true
                                                      Has administrator privileges:true
                                                      Programmed in:C, C++ or other language
                                                      Yara matches:
                                                      • Rule: JoeSecurity_Wannacry, Description: Yara detected Wannacry ransomware, Source: 00000000.00000003.1788283067.0000000000AFE000.00000004.00000020.00020000.00000000.sdmp, Author: Joe Security
                                                      • Rule: wanna_cry_ransomware_generic, Description: detects wannacry ransomware on disk and in virtual page, Source: 00000000.00000000.1324912594.000000000040E000.00000008.00000001.01000000.00000003.sdmp, Author: us-cert code analysis team
                                                      • Rule: JoeSecurity_Wannacry, Description: Yara detected Wannacry ransomware, Source: 00000000.00000003.1374099272.0000000000ABF000.00000004.00000020.00020000.00000000.sdmp, Author: Joe Security
                                                      • Rule: JoeSecurity_Wannacry, Description: Yara detected Wannacry ransomware, Source: 00000000.00000003.1788065356.0000000000AFE000.00000004.00000020.00020000.00000000.sdmp, Author: Joe Security
                                                      Reputation:low
                                                      Has exited:false

                                                      Target ID:2
                                                      Start time:18:01:43
                                                      Start date:25/07/2024
                                                      Path:C:\Windows\SysWOW64\attrib.exe
                                                      Wow64 process (32bit):true
                                                      Commandline:attrib +h .
                                                      Imagebase:0xfa0000
                                                      File size:19'456 bytes
                                                      MD5 hash:0E938DD280E83B1596EC6AA48729C2B0
                                                      Has elevated privileges:true
                                                      Has administrator privileges:true
                                                      Programmed in:C, C++ or other language
                                                      Reputation:moderate
                                                      Has exited:true

                                                      Target ID:3
                                                      Start time:18:01:43
                                                      Start date:25/07/2024
                                                      Path:C:\Windows\SysWOW64\icacls.exe
                                                      Wow64 process (32bit):true
                                                      Commandline:icacls . /grant Everyone:F /T /C /Q
                                                      Imagebase:0xe60000
                                                      File size:29'696 bytes
                                                      MD5 hash:2E49585E4E08565F52090B144062F97E
                                                      Has elevated privileges:true
                                                      Has administrator privileges:true
                                                      Programmed in:C, C++ or other language
                                                      Reputation:high
                                                      Has exited:true

                                                      Target ID:4
                                                      Start time:18:01:43
                                                      Start date:25/07/2024
                                                      Path:C:\Windows\System32\conhost.exe
                                                      Wow64 process (32bit):false
                                                      Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                                      Imagebase:0x7ff70f010000
                                                      File size:862'208 bytes
                                                      MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                                                      Has elevated privileges:true
                                                      Has administrator privileges:true
                                                      Programmed in:C, C++ or other language
                                                      Reputation:high
                                                      Has exited:true

                                                      Target ID:5
                                                      Start time:18:01:43
                                                      Start date:25/07/2024
                                                      Path:C:\Windows\System32\conhost.exe
                                                      Wow64 process (32bit):false
                                                      Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                                      Imagebase:0x7ff70f010000
                                                      File size:862'208 bytes
                                                      MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                                                      Has elevated privileges:true
                                                      Has administrator privileges:true
                                                      Programmed in:C, C++ or other language
                                                      Reputation:high
                                                      Has exited:true

                                                      Target ID:6
                                                      Start time:18:01:45
                                                      Start date:25/07/2024
                                                      Path:C:\Users\user\Desktop\taskdl.exe
                                                      Wow64 process (32bit):true
                                                      Commandline:taskdl.exe
                                                      Imagebase:0x400000
                                                      File size:20'480 bytes
                                                      MD5 hash:4FEF5E34143E646DBF9907C4374276F5
                                                      Has elevated privileges:true
                                                      Has administrator privileges:true
                                                      Programmed in:C, C++ or other language
                                                      Reputation:moderate
                                                      Has exited:true

                                                      Target ID:7
                                                      Start time:18:01:45
                                                      Start date:25/07/2024
                                                      Path:C:\Windows\SysWOW64\cmd.exe
                                                      Wow64 process (32bit):true
                                                      Commandline:C:\Windows\system32\cmd.exe /c 70341721944935.bat
                                                      Imagebase:0xc50000
                                                      File size:236'544 bytes
                                                      MD5 hash:D0FCE3AFA6AA1D58CE9FA336CC2B675B
                                                      Has elevated privileges:true
                                                      Has administrator privileges:true
                                                      Programmed in:C, C++ or other language
                                                      Reputation:high
                                                      Has exited:true

                                                      Target ID:8
                                                      Start time:18:01:45
                                                      Start date:25/07/2024
                                                      Path:C:\Windows\System32\conhost.exe
                                                      Wow64 process (32bit):false
                                                      Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                                      Imagebase:0x7ff70f010000
                                                      File size:862'208 bytes
                                                      MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                                                      Has elevated privileges:true
                                                      Has administrator privileges:true
                                                      Programmed in:C, C++ or other language
                                                      Reputation:high
                                                      Has exited:true

                                                      Target ID:9
                                                      Start time:18:01:45
                                                      Start date:25/07/2024
                                                      Path:C:\Users\user\Desktop\taskdl.exe
                                                      Wow64 process (32bit):true
                                                      Commandline:taskdl.exe
                                                      Imagebase:0x400000
                                                      File size:20'480 bytes
                                                      MD5 hash:4FEF5E34143E646DBF9907C4374276F5
                                                      Has elevated privileges:true
                                                      Has administrator privileges:true
                                                      Programmed in:C, C++ or other language
                                                      Reputation:moderate
                                                      Has exited:true

                                                      Target ID:10
                                                      Start time:18:01:45
                                                      Start date:25/07/2024
                                                      Path:C:\Windows\SysWOW64\cscript.exe
                                                      Wow64 process (32bit):true
                                                      Commandline:cscript.exe //nologo m.vbs
                                                      Imagebase:0x180000
                                                      File size:144'896 bytes
                                                      MD5 hash:CB601B41D4C8074BE8A84AED564A94DC
                                                      Has elevated privileges:true
                                                      Has administrator privileges:true
                                                      Programmed in:C, C++ or other language
                                                      Reputation:moderate
                                                      Has exited:true

                                                      Target ID:11
                                                      Start time:18:01:45
                                                      Start date:25/07/2024
                                                      Path:C:\Users\user\Desktop\taskdl.exe
                                                      Wow64 process (32bit):true
                                                      Commandline:taskdl.exe
                                                      Imagebase:0x400000
                                                      File size:20'480 bytes
                                                      MD5 hash:4FEF5E34143E646DBF9907C4374276F5
                                                      Has elevated privileges:true
                                                      Has administrator privileges:true
                                                      Programmed in:C, C++ or other language
                                                      Reputation:moderate
                                                      Has exited:true

                                                      Target ID:12
                                                      Start time:18:01:46
                                                      Start date:25/07/2024
                                                      Path:C:\Users\user\Desktop\taskdl.exe
                                                      Wow64 process (32bit):true
                                                      Commandline:taskdl.exe
                                                      Imagebase:0x400000
                                                      File size:20'480 bytes
                                                      MD5 hash:4FEF5E34143E646DBF9907C4374276F5
                                                      Has elevated privileges:true
                                                      Has administrator privileges:true
                                                      Programmed in:C, C++ or other language
                                                      Reputation:moderate
                                                      Has exited:true

                                                      Target ID:13
                                                      Start time:18:01:46
                                                      Start date:25/07/2024
                                                      Path:C:\Users\user\Desktop\taskdl.exe
                                                      Wow64 process (32bit):true
                                                      Commandline:taskdl.exe
                                                      Imagebase:0x400000
                                                      File size:20'480 bytes
                                                      MD5 hash:4FEF5E34143E646DBF9907C4374276F5
                                                      Has elevated privileges:true
                                                      Has administrator privileges:true
                                                      Programmed in:C, C++ or other language
                                                      Has exited:true

                                                      Target ID:14
                                                      Start time:18:01:46
                                                      Start date:25/07/2024
                                                      Path:C:\Users\user\Desktop\taskdl.exe
                                                      Wow64 process (32bit):true
                                                      Commandline:taskdl.exe
                                                      Imagebase:0x400000
                                                      File size:20'480 bytes
                                                      MD5 hash:4FEF5E34143E646DBF9907C4374276F5
                                                      Has elevated privileges:true
                                                      Has administrator privileges:true
                                                      Programmed in:C, C++ or other language
                                                      Has exited:true

                                                      Target ID:15
                                                      Start time:18:01:46
                                                      Start date:25/07/2024
                                                      Path:C:\Users\user\Desktop\taskdl.exe
                                                      Wow64 process (32bit):true
                                                      Commandline:taskdl.exe
                                                      Imagebase:0x400000
                                                      File size:20'480 bytes
                                                      MD5 hash:4FEF5E34143E646DBF9907C4374276F5
                                                      Has elevated privileges:true
                                                      Has administrator privileges:true
                                                      Programmed in:C, C++ or other language
                                                      Has exited:true

                                                      Target ID:16
                                                      Start time:18:01:47
                                                      Start date:25/07/2024
                                                      Path:C:\Users\user\Desktop\taskdl.exe
                                                      Wow64 process (32bit):true
                                                      Commandline:taskdl.exe
                                                      Imagebase:0x400000
                                                      File size:20'480 bytes
                                                      MD5 hash:4FEF5E34143E646DBF9907C4374276F5
                                                      Has elevated privileges:true
                                                      Has administrator privileges:true
                                                      Programmed in:C, C++ or other language
                                                      Has exited:true

                                                      Target ID:17
                                                      Start time:18:01:47
                                                      Start date:25/07/2024
                                                      Path:C:\Users\user\Desktop\taskdl.exe
                                                      Wow64 process (32bit):true
                                                      Commandline:taskdl.exe
                                                      Imagebase:0x400000
                                                      File size:20'480 bytes
                                                      MD5 hash:4FEF5E34143E646DBF9907C4374276F5
                                                      Has elevated privileges:true
                                                      Has administrator privileges:true
                                                      Programmed in:C, C++ or other language
                                                      Has exited:true

                                                      Target ID:18
                                                      Start time:18:01:48
                                                      Start date:25/07/2024
                                                      Path:C:\Users\user\Desktop\taskdl.exe
                                                      Wow64 process (32bit):true
                                                      Commandline:taskdl.exe
                                                      Imagebase:0x400000
                                                      File size:20'480 bytes
                                                      MD5 hash:4FEF5E34143E646DBF9907C4374276F5
                                                      Has elevated privileges:true
                                                      Has administrator privileges:true
                                                      Programmed in:C, C++ or other language
                                                      Has exited:true

                                                      Target ID:19
                                                      Start time:18:01:48
                                                      Start date:25/07/2024
                                                      Path:C:\Users\user\Desktop\taskdl.exe
                                                      Wow64 process (32bit):true
                                                      Commandline:taskdl.exe
                                                      Imagebase:0x400000
                                                      File size:20'480 bytes
                                                      MD5 hash:4FEF5E34143E646DBF9907C4374276F5
                                                      Has elevated privileges:true
                                                      Has administrator privileges:true
                                                      Programmed in:C, C++ or other language
                                                      Has exited:true

                                                      Target ID:20
                                                      Start time:18:01:48
                                                      Start date:25/07/2024
                                                      Path:C:\Users\user\Desktop\taskdl.exe
                                                      Wow64 process (32bit):true
                                                      Commandline:taskdl.exe
                                                      Imagebase:0x400000
                                                      File size:20'480 bytes
                                                      MD5 hash:4FEF5E34143E646DBF9907C4374276F5
                                                      Has elevated privileges:true
                                                      Has administrator privileges:true
                                                      Programmed in:C, C++ or other language
                                                      Has exited:true

                                                      Target ID:21
                                                      Start time:18:01:48
                                                      Start date:25/07/2024
                                                      Path:C:\Users\user\Desktop\taskdl.exe
                                                      Wow64 process (32bit):true
                                                      Commandline:taskdl.exe
                                                      Imagebase:0x400000
                                                      File size:20'480 bytes
                                                      MD5 hash:4FEF5E34143E646DBF9907C4374276F5
                                                      Has elevated privileges:true
                                                      Has administrator privileges:true
                                                      Programmed in:C, C++ or other language
                                                      Has exited:true

                                                      Target ID:22
                                                      Start time:18:01:49
                                                      Start date:25/07/2024
                                                      Path:C:\Users\user\Desktop\taskdl.exe
                                                      Wow64 process (32bit):true
                                                      Commandline:taskdl.exe
                                                      Imagebase:0x400000
                                                      File size:20'480 bytes
                                                      MD5 hash:4FEF5E34143E646DBF9907C4374276F5
                                                      Has elevated privileges:true
                                                      Has administrator privileges:true
                                                      Programmed in:C, C++ or other language
                                                      Has exited:true

                                                      Target ID:23
                                                      Start time:18:01:49
                                                      Start date:25/07/2024
                                                      Path:C:\Users\user\Desktop\taskdl.exe
                                                      Wow64 process (32bit):true
                                                      Commandline:taskdl.exe
                                                      Imagebase:0x400000
                                                      File size:20'480 bytes
                                                      MD5 hash:4FEF5E34143E646DBF9907C4374276F5
                                                      Has elevated privileges:true
                                                      Has administrator privileges:true
                                                      Programmed in:C, C++ or other language
                                                      Has exited:true

                                                      Target ID:24
                                                      Start time:18:01:50
                                                      Start date:25/07/2024
                                                      Path:C:\Users\user\Desktop\taskdl.exe
                                                      Wow64 process (32bit):true
                                                      Commandline:taskdl.exe
                                                      Imagebase:0x400000
                                                      File size:20'480 bytes
                                                      MD5 hash:4FEF5E34143E646DBF9907C4374276F5
                                                      Has elevated privileges:true
                                                      Has administrator privileges:true
                                                      Programmed in:C, C++ or other language
                                                      Has exited:true

                                                      Target ID:25
                                                      Start time:18:01:51
                                                      Start date:25/07/2024
                                                      Path:C:\Users\user\Desktop\taskdl.exe
                                                      Wow64 process (32bit):true
                                                      Commandline:taskdl.exe
                                                      Imagebase:0x400000
                                                      File size:20'480 bytes
                                                      MD5 hash:4FEF5E34143E646DBF9907C4374276F5
                                                      Has elevated privileges:true
                                                      Has administrator privileges:true
                                                      Programmed in:C, C++ or other language
                                                      Has exited:true

                                                      Target ID:26
                                                      Start time:18:01:51
                                                      Start date:25/07/2024
                                                      Path:C:\Users\user\Desktop\taskdl.exe
                                                      Wow64 process (32bit):true
                                                      Commandline:taskdl.exe
                                                      Imagebase:0x400000
                                                      File size:20'480 bytes
                                                      MD5 hash:4FEF5E34143E646DBF9907C4374276F5
                                                      Has elevated privileges:true
                                                      Has administrator privileges:true
                                                      Programmed in:C, C++ or other language
                                                      Has exited:true

                                                      Target ID:27
                                                      Start time:18:01:51
                                                      Start date:25/07/2024
                                                      Path:C:\Users\user\Desktop\taskdl.exe
                                                      Wow64 process (32bit):true
                                                      Commandline:taskdl.exe
                                                      Imagebase:0x400000
                                                      File size:20'480 bytes
                                                      MD5 hash:4FEF5E34143E646DBF9907C4374276F5
                                                      Has elevated privileges:true
                                                      Has administrator privileges:true
                                                      Programmed in:C, C++ or other language
                                                      Has exited:true

                                                      Target ID:28
                                                      Start time:18:01:51
                                                      Start date:25/07/2024
                                                      Path:C:\Users\user\Desktop\taskdl.exe
                                                      Wow64 process (32bit):true
                                                      Commandline:taskdl.exe
                                                      Imagebase:0x400000
                                                      File size:20'480 bytes
                                                      MD5 hash:4FEF5E34143E646DBF9907C4374276F5
                                                      Has elevated privileges:true
                                                      Has administrator privileges:true
                                                      Programmed in:C, C++ or other language
                                                      Has exited:true

                                                      Target ID:29
                                                      Start time:18:01:52
                                                      Start date:25/07/2024
                                                      Path:C:\Users\user\Desktop\taskdl.exe
                                                      Wow64 process (32bit):true
                                                      Commandline:taskdl.exe
                                                      Imagebase:0x400000
                                                      File size:20'480 bytes
                                                      MD5 hash:4FEF5E34143E646DBF9907C4374276F5
                                                      Has elevated privileges:true
                                                      Has administrator privileges:true
                                                      Programmed in:C, C++ or other language
                                                      Has exited:true

                                                      Target ID:30
                                                      Start time:18:01:52
                                                      Start date:25/07/2024
                                                      Path:C:\Users\user\Desktop\taskdl.exe
                                                      Wow64 process (32bit):true
                                                      Commandline:taskdl.exe
                                                      Imagebase:0x400000
                                                      File size:20'480 bytes
                                                      MD5 hash:4FEF5E34143E646DBF9907C4374276F5
                                                      Has elevated privileges:true
                                                      Has administrator privileges:true
                                                      Programmed in:C, C++ or other language
                                                      Has exited:true

                                                      Target ID:31
                                                      Start time:18:01:52
                                                      Start date:25/07/2024
                                                      Path:C:\Users\user\Desktop\taskdl.exe
                                                      Wow64 process (32bit):true
                                                      Commandline:taskdl.exe
                                                      Imagebase:0x400000
                                                      File size:20'480 bytes
                                                      MD5 hash:4FEF5E34143E646DBF9907C4374276F5
                                                      Has elevated privileges:true
                                                      Has administrator privileges:true
                                                      Programmed in:C, C++ or other language
                                                      Has exited:true

                                                      Target ID:32
                                                      Start time:18:01:53
                                                      Start date:25/07/2024
                                                      Path:C:\Users\user\Desktop\taskdl.exe
                                                      Wow64 process (32bit):true
                                                      Commandline:taskdl.exe
                                                      Imagebase:0x400000
                                                      File size:20'480 bytes
                                                      MD5 hash:4FEF5E34143E646DBF9907C4374276F5
                                                      Has elevated privileges:true
                                                      Has administrator privileges:true
                                                      Programmed in:C, C++ or other language
                                                      Has exited:true

                                                      Target ID:33
                                                      Start time:18:01:54
                                                      Start date:25/07/2024
                                                      Path:C:\Users\user\Desktop\taskdl.exe
                                                      Wow64 process (32bit):true
                                                      Commandline:taskdl.exe
                                                      Imagebase:0x400000
                                                      File size:20'480 bytes
                                                      MD5 hash:4FEF5E34143E646DBF9907C4374276F5
                                                      Has elevated privileges:true
                                                      Has administrator privileges:true
                                                      Programmed in:C, C++ or other language
                                                      Has exited:true

                                                      Target ID:34
                                                      Start time:18:01:54
                                                      Start date:25/07/2024
                                                      Path:C:\Users\user\Desktop\taskdl.exe
                                                      Wow64 process (32bit):true
                                                      Commandline:taskdl.exe
                                                      Imagebase:0x400000
                                                      File size:20'480 bytes
                                                      MD5 hash:4FEF5E34143E646DBF9907C4374276F5
                                                      Has elevated privileges:true
                                                      Has administrator privileges:true
                                                      Programmed in:C, C++ or other language
                                                      Has exited:true

                                                      Target ID:35
                                                      Start time:18:01:55
                                                      Start date:25/07/2024
                                                      Path:C:\Users\user\Desktop\taskdl.exe
                                                      Wow64 process (32bit):true
                                                      Commandline:taskdl.exe
                                                      Imagebase:0x400000
                                                      File size:20'480 bytes
                                                      MD5 hash:4FEF5E34143E646DBF9907C4374276F5
                                                      Has elevated privileges:true
                                                      Has administrator privileges:true
                                                      Programmed in:C, C++ or other language
                                                      Has exited:true

                                                      Target ID:36
                                                      Start time:18:01:55
                                                      Start date:25/07/2024
                                                      Path:C:\Users\user\Desktop\taskdl.exe
                                                      Wow64 process (32bit):true
                                                      Commandline:taskdl.exe
                                                      Imagebase:0x400000
                                                      File size:20'480 bytes
                                                      MD5 hash:4FEF5E34143E646DBF9907C4374276F5
                                                      Has elevated privileges:true
                                                      Has administrator privileges:true
                                                      Programmed in:C, C++ or other language
                                                      Has exited:true

                                                      Target ID:37
                                                      Start time:18:01:56
                                                      Start date:25/07/2024
                                                      Path:C:\Users\user\Desktop\taskdl.exe
                                                      Wow64 process (32bit):true
                                                      Commandline:taskdl.exe
                                                      Imagebase:0x400000
                                                      File size:20'480 bytes
                                                      MD5 hash:4FEF5E34143E646DBF9907C4374276F5
                                                      Has elevated privileges:true
                                                      Has administrator privileges:true
                                                      Programmed in:C, C++ or other language
                                                      Has exited:true

                                                      Target ID:38
                                                      Start time:18:01:57
                                                      Start date:25/07/2024
                                                      Path:C:\Users\user\Desktop\taskdl.exe
                                                      Wow64 process (32bit):true
                                                      Commandline:taskdl.exe
                                                      Imagebase:0x400000
                                                      File size:20'480 bytes
                                                      MD5 hash:4FEF5E34143E646DBF9907C4374276F5
                                                      Has elevated privileges:true
                                                      Has administrator privileges:true
                                                      Programmed in:C, C++ or other language
                                                      Has exited:true

                                                      Target ID:39
                                                      Start time:18:01:57
                                                      Start date:25/07/2024
                                                      Path:C:\Users\user\Desktop\taskdl.exe
                                                      Wow64 process (32bit):true
                                                      Commandline:taskdl.exe
                                                      Imagebase:0x400000
                                                      File size:20'480 bytes
                                                      MD5 hash:4FEF5E34143E646DBF9907C4374276F5
                                                      Has elevated privileges:true
                                                      Has administrator privileges:true
                                                      Programmed in:C, C++ or other language
                                                      Has exited:true

                                                      Target ID:40
                                                      Start time:18:01:58
                                                      Start date:25/07/2024
                                                      Path:C:\Users\user\Desktop\taskdl.exe
                                                      Wow64 process (32bit):true
                                                      Commandline:taskdl.exe
                                                      Imagebase:0x400000
                                                      File size:20'480 bytes
                                                      MD5 hash:4FEF5E34143E646DBF9907C4374276F5
                                                      Has elevated privileges:true
                                                      Has administrator privileges:true
                                                      Programmed in:C, C++ or other language
                                                      Has exited:true

                                                      Target ID:41
                                                      Start time:18:01:58
                                                      Start date:25/07/2024
                                                      Path:C:\Users\user\Desktop\taskdl.exe
                                                      Wow64 process (32bit):true
                                                      Commandline:taskdl.exe
                                                      Imagebase:0x400000
                                                      File size:20'480 bytes
                                                      MD5 hash:4FEF5E34143E646DBF9907C4374276F5
                                                      Has elevated privileges:true
                                                      Has administrator privileges:true
                                                      Programmed in:C, C++ or other language
                                                      Has exited:true

                                                      Target ID:43
                                                      Start time:18:01:59
                                                      Start date:25/07/2024
                                                      Path:C:\Users\user\Desktop\taskdl.exe
                                                      Wow64 process (32bit):true
                                                      Commandline:taskdl.exe
                                                      Imagebase:0x400000
                                                      File size:20'480 bytes
                                                      MD5 hash:4FEF5E34143E646DBF9907C4374276F5
                                                      Has elevated privileges:true
                                                      Has administrator privileges:true
                                                      Programmed in:C, C++ or other language
                                                      Has exited:true

                                                      Reset < >

                                                        Execution Graph

                                                        Execution Coverage:24.8%
                                                        Dynamic/Decrypted Code Coverage:0%
                                                        Signature Coverage:20.2%
                                                        Total number of Nodes:94
                                                        Total number of Limit Nodes:1
                                                        execution_graph 315 401360 316 4013a7 315->316 320 401372 315->320 322 4018d0 free 316->322 318 4013b0 320->316 321 4018d0 free 320->321 321->320 322->318 212 4018f6 __set_app_type __p__fmode __p__commode 213 401965 212->213 214 401979 213->214 215 40196d __setusermatherr 213->215 224 401a66 _controlfp 214->224 215->214 217 40197e _initterm __getmainargs _initterm 218 4019d2 GetStartupInfoA 217->218 220 401a06 GetModuleHandleA 218->220 225 4012c0 GetLogicalDrives 220->225 224->217 226 4012e0 225->226 227 401305 GetDriveTypeW 226->227 228 401324 exit _XcptFilter 226->228 231 401080 226->231 227->226 255 401000 GetWindowsDirectoryW 231->255 233 4010d5 swprintf FindFirstFileW 234 40114a 233->234 241 401114 233->241 235 40114e swprintf ?_Tidy@?$basic_string@GU?$char_traits@G@std@@V?$allocator@G@2@@std@@AAEX_N wcslen ?_Grow@?$basic_string@GU?$char_traits@G@std@@V?$allocator@G@2@@std@@AAE_NI_N 234->235 237 40119e 235->237 242 4011ae ?_Eos@?$basic_string@GU?$char_traits@G@std@@V?$allocator@G@2@@std@@AAEXI 237->242 268 4013d0 237->268 239 401140 Sleep 239->226 244 401136 241->244 261 401870 241->261 242->237 243 4011d9 ?_Tidy@?$basic_string@GU?$char_traits@G@std@@V?$allocator@G@2@@std@@AAEX_N FindNextFileW 243->235 245 401204 FindClose 243->245 267 4018d0 free 244->267 251 401215 245->251 246 40124a 247 401254 ?_Tidy@?$basic_string@GU?$char_traits@G@std@@V?$allocator@G@2@@std@@AAEX_N 246->247 248 401265 246->248 247->247 247->248 249 40128f 248->249 250 40127e ?_Tidy@?$basic_string@GU?$char_traits@G@std@@V?$allocator@G@2@@std@@AAEX_N 248->250 297 4018d0 free 249->297 250->249 250->250 251->246 252 401239 DeleteFileW 251->252 252->251 254 401299 254->239 256 401022 GetTempPathW wcslen 255->256 257 40105e swprintf 255->257 258 401073 256->258 259 40103e wcslen 256->259 257->258 258->233 259->258 260 40104c wcslen 259->260 260->233 262 401885 261->262 263 40187a 261->263 264 4018bb 262->264 299 4018d0 free 262->299 263->262 298 4018d0 free 263->298 264->241 267->239 269 40152b 268->269 273 4013f2 ??2@YAPAXI 268->273 282 4015e7 269->282 283 40153e 269->283 270 401677 270->243 271 401574 274 40159e 271->274 280 401690 7 API calls 271->280 272 401616 278 401629 ?assign@?$basic_string@GU?$char_traits@G@std@@V?$allocator@G@2@@std@@QAEAAV12@ABV12@II 272->278 279 401647 272->279 285 401440 273->285 286 401458 273->286 274->270 275 4015b3 ?assign@?$basic_string@GU?$char_traits@G@std@@V?$allocator@G@2@@std@@QAEAAV12@ABV12@II 274->275 275->275 281 4015cd 275->281 276 401690 7 API calls 276->282 277 401690 7 API calls 277->283 278->278 278->279 279->270 287 40165c ?assign@?$basic_string@GU?$char_traits@G@std@@V?$allocator@G@2@@std@@QAEAAV12@ABV12@II 279->287 280->271 281->243 282->270 282->272 282->276 283->271 283->277 285->286 300 401690 285->300 290 401690 7 API calls 286->290 295 40147e 286->295 287->270 287->287 289 4014b5 291 4014d0 289->291 292 4014bf ?_Tidy@?$basic_string@GU?$char_traits@G@std@@V?$allocator@G@2@@std@@AAEX_N 289->292 290->286 314 4018d0 free 291->314 292->291 292->292 294 401690 7 API calls 294->295 295->289 295->294 296 4014d9 296->243 297->254 298->262 299->264 301 4016c0 300->301 307 4017c4 300->307 302 4016e8 301->302 306 40175b 301->306 303 4016f4 ?_Split@?$basic_string@GU?$char_traits@G@std@@V?$allocator@G@2@@std@ 302->303 304 4016ee ?_Xran@std@ 302->304 309 401705 303->309 304->303 305 4017b5 ?_Grow@?$basic_string@GU?$char_traits@G@std@@V?$allocator@G@2@@std@@AAE_NI_N 305->307 306->305 310 401775 ?_Tidy@?$basic_string@GU?$char_traits@G@std@@V?$allocator@G@2@@std@@AAEX_N 306->310 307->285 308 401740 ?_Split@?$basic_string@GU?$char_traits@G@std@@V?$allocator@G@2@@std@ 308->285 309->308 312 401721 ?_Grow@?$basic_string@GU?$char_traits@G@std@@V?$allocator@G@2@@std@@AAE_NI_N 309->312 311 401786 310->311 311->285 312->308 313 401737 ?_Eos@?$basic_string@GU?$char_traits@G@std@@V?$allocator@G@2@@std@@AAEXI 312->313 313->308 314->296 323 401a48 _exit 324 401a9b ??1?$basic_string@GU?$char_traits@G@std@@V?$allocator@G@2@@std@@QAE

                                                        Callgraph

                                                        Control-flow Graph

                                                        APIs
                                                          • Part of subcall function 00401000: GetWindowsDirectoryW.KERNEL32(00000019,00000104,76F90F00,00000019,004010D5,?,?,76F90F00,00000019,76F93300,00000000), ref: 0040100C
                                                          • Part of subcall function 00401000: GetTempPathW.KERNEL32(00000104,00000019), ref: 00401028
                                                          • Part of subcall function 00401000: wcslen.MSVCRT ref: 00401035
                                                          • Part of subcall function 00401000: wcslen.MSVCRT ref: 0040103F
                                                          • Part of subcall function 00401000: wcslen.MSVCRT ref: 0040104D
                                                        • swprintf.MSVCRT(?,00403040,?,00403050,76F93300,00000000), ref: 004010F5
                                                        • FindFirstFileW.KERNELBASE(?,?), ref: 00401107
                                                        • swprintf.MSVCRT(?,00403034,?,?), ref: 00401168
                                                        • ?_Tidy@?$basic_string@GU?$char_traits@G@std@@V?$allocator@G@2@@std@@AAEX_N@Z.MSVCP60(00000000), ref: 00401177
                                                        • wcslen.MSVCRT ref: 00401182
                                                        • ?_Grow@?$basic_string@GU?$char_traits@G@std@@V?$allocator@G@2@@std@@AAE_NI_N@Z.MSVCP60(00000000,00000001), ref: 00401194
                                                        • ?_Eos@?$basic_string@GU?$char_traits@G@std@@V?$allocator@G@2@@std@@AAEXI@Z.MSVCP60(00000000), ref: 004011B6
                                                        • ?_Tidy@?$basic_string@GU?$char_traits@G@std@@V?$allocator@G@2@@std@@AAEX_N@Z.MSVCP60(00000001), ref: 004011E7
                                                        • FindNextFileW.KERNEL32(00000000,?), ref: 004011F6
                                                        • FindClose.KERNEL32(00000000), ref: 00401205
                                                        • DeleteFileW.KERNEL32(?), ref: 0040123A
                                                        • ?_Tidy@?$basic_string@GU?$char_traits@G@std@@V?$allocator@G@2@@std@@AAEX_N@Z.MSVCP60(00000001), ref: 00401258
                                                        • ?_Tidy@?$basic_string@GU?$char_traits@G@std@@V?$allocator@G@2@@std@@AAEX_N@Z.MSVCP60(00000001), ref: 00401282
                                                        Memory Dump Source
                                                        • Source File: 00000006.00000002.1353477950.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                                                        • Associated: 00000006.00000002.1353460697.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                                                        • Associated: 00000006.00000002.1353493054.0000000000402000.00000002.00000001.01000000.00000004.sdmpDownload File
                                                        • Associated: 00000006.00000002.1353509883.0000000000404000.00000002.00000001.01000000.00000004.sdmpDownload File
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_6_2_400000_taskdl.jbxd
                                                        Similarity
                                                        • API ID: G@2@@std@@G@std@@U?$char_traits@V?$allocator@$Tidy@?$basic_string@wcslen$FileFind$swprintf$CloseDeleteDirectoryEos@?$basic_string@FirstGrow@?$basic_string@NextPathTempWindows
                                                        • String ID:
                                                        • API String ID: 2889739147-0
                                                        • Opcode ID: d094fdb74faa2036a2288d1d3d1a61125983eed402f55e78df214a8260d1f803
                                                        • Instruction ID: c02e7cbfb6260119d7520a8cc5a4b78e5b9d8733a8a6b2d1cbf059c3021fc26b
                                                        • Opcode Fuzzy Hash: d094fdb74faa2036a2288d1d3d1a61125983eed402f55e78df214a8260d1f803
                                                        • Instruction Fuzzy Hash: E551C3716043419FD720DF64C884B9BB7E9FBC8348F044A2EF589B32D1D6789945CB5A

                                                        Control-flow Graph

                                                        APIs
                                                        Memory Dump Source
                                                        • Source File: 00000006.00000002.1353477950.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                                                        • Associated: 00000006.00000002.1353460697.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                                                        • Associated: 00000006.00000002.1353493054.0000000000402000.00000002.00000001.01000000.00000004.sdmpDownload File
                                                        • Associated: 00000006.00000002.1353509883.0000000000404000.00000002.00000001.01000000.00000004.sdmpDownload File
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_6_2_400000_taskdl.jbxd
                                                        Similarity
                                                        • API ID: _initterm$FilterHandleInfoModuleStartupXcpt__getmainargs__p__commode__p__fmode__set_app_type__setusermatherrexit
                                                        • String ID:
                                                        • API String ID: 801014965-0
                                                        • Opcode ID: 4015c31cfa7eab49e8c51e62fd741af3e0d2f81cb378811d4cbcafae977c22e0
                                                        • Instruction ID: 68ab6ae738ded19f39d0610043d4fcd1ea5deb11ceedb7bb579f538117b6dbca
                                                        • Opcode Fuzzy Hash: 4015c31cfa7eab49e8c51e62fd741af3e0d2f81cb378811d4cbcafae977c22e0
                                                        • Instruction Fuzzy Hash: 42417EB5901344EFDB209FA4DA49A6ABFB8EB09715F20023FF581B72E1D6784940CF58

                                                        Control-flow Graph

                                                        • Executed
                                                        • Not Executed
                                                        control_flow_graph 58 4012c0-4012db GetLogicalDrives 59 4012e0-401303 58->59 60 401305-40130f GetDriveTypeW 59->60 61 40131e-401322 59->61 60->61 62 401311-40131c call 401080 Sleep 60->62 61->59 63 401324-40132d 61->63 62->61
                                                        APIs
                                                        • GetLogicalDrives.KERNELBASE ref: 004012C7
                                                        • GetDriveTypeW.KERNELBASE(?,?,?,?,00000000,?,0000000A), ref: 0040130A
                                                          • Part of subcall function 00401080: swprintf.MSVCRT(?,00403040,?,00403050,76F93300,00000000), ref: 004010F5
                                                          • Part of subcall function 00401080: FindFirstFileW.KERNELBASE(?,?), ref: 00401107
                                                        • Sleep.KERNELBASE(0000000A,00000000,?,0000000A), ref: 0040131C
                                                        Memory Dump Source
                                                        • Source File: 00000006.00000002.1353477950.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                                                        • Associated: 00000006.00000002.1353460697.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                                                        • Associated: 00000006.00000002.1353493054.0000000000402000.00000002.00000001.01000000.00000004.sdmpDownload File
                                                        • Associated: 00000006.00000002.1353509883.0000000000404000.00000002.00000001.01000000.00000004.sdmpDownload File
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_6_2_400000_taskdl.jbxd
                                                        Similarity
                                                        • API ID: DriveDrivesFileFindFirstLogicalSleepTypeswprintf
                                                        • String ID:
                                                        • API String ID: 570308627-0
                                                        • Opcode ID: fac8c12e3c7440fa081a6b1de2581f42964eb1eb3cef597a2f435b430f1423df
                                                        • Instruction ID: 4c7b1852939095ad3804a53ba97627e403d947e7219eb0394d6b0875d80bfcc1
                                                        • Opcode Fuzzy Hash: fac8c12e3c7440fa081a6b1de2581f42964eb1eb3cef597a2f435b430f1423df
                                                        • Instruction Fuzzy Hash: D9F0C8756043044BD310DF18ED4065B77A5EB99354F00053EED45B3390D776990DC6AA

                                                        Control-flow Graph

                                                        APIs
                                                        • ?_Xran@std@@YAXXZ.MSVCP60(?,?,?,?,?,?,00401AD1,000000FF,00401609,?,?,76E95320,00000000,00000000,?,?), ref: 004016EE
                                                        • ?_Split@?$basic_string@GU?$char_traits@G@std@@V?$allocator@G@2@@std@@AAEXXZ.MSVCP60(?,?,?,?,?,?,00401AD1,000000FF,00401609,?,?,76E95320,00000000,00000000,?,?), ref: 004016F6
                                                        • ?_Grow@?$basic_string@GU?$char_traits@G@std@@V?$allocator@G@2@@std@@AAE_NI_N@Z.MSVCP60(?,00000000), ref: 0040172D
                                                        • ?_Eos@?$basic_string@GU?$char_traits@G@std@@V?$allocator@G@2@@std@@AAEXI@Z.MSVCP60(?), ref: 0040173A
                                                        • ?_Split@?$basic_string@GU?$char_traits@G@std@@V?$allocator@G@2@@std@@AAEXXZ.MSVCP60 ref: 00401742
                                                        • ?_Tidy@?$basic_string@GU?$char_traits@G@std@@V?$allocator@G@2@@std@@AAEX_N@Z.MSVCP60(00000001,?,?,?,?,?,?,00401AD1,000000FF,00401609,?,?,76E95320,00000000,00000000,?), ref: 00401779
                                                        • ?_Grow@?$basic_string@GU?$char_traits@G@std@@V?$allocator@G@2@@std@@AAE_NI_N@Z.MSVCP60(?,00000001,?,?,?,?,?,?,00401AD1,000000FF,00401609,?,?,76E95320,00000000,00000000), ref: 004017BA
                                                        Memory Dump Source
                                                        • Source File: 00000006.00000002.1353477950.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                                                        • Associated: 00000006.00000002.1353460697.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                                                        • Associated: 00000006.00000002.1353493054.0000000000402000.00000002.00000001.01000000.00000004.sdmpDownload File
                                                        • Associated: 00000006.00000002.1353509883.0000000000404000.00000002.00000001.01000000.00000004.sdmpDownload File
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_6_2_400000_taskdl.jbxd
                                                        Similarity
                                                        • API ID: G@2@@std@@G@std@@U?$char_traits@V?$allocator@$Grow@?$basic_string@Split@?$basic_string@$Eos@?$basic_string@Tidy@?$basic_string@Xran@std@@
                                                        • String ID:
                                                        • API String ID: 2613176527-0
                                                        • Opcode ID: d8cc844e41db627e1c4436b7b7a073ec45db5ac64ec8fc819127fe6e53c62420
                                                        • Instruction ID: b735bfb2d4c14645f341b606901ad4f9af47e45cc28c7d2ea722b83d512bfbf9
                                                        • Opcode Fuzzy Hash: d8cc844e41db627e1c4436b7b7a073ec45db5ac64ec8fc819127fe6e53c62420
                                                        • Instruction Fuzzy Hash: 81410275300B008FC720DF19DAC4A6AB7E6FB89710B14897EE5569B7A0CB79AC01CB48

                                                        Control-flow Graph

                                                        • Executed
                                                        • Not Executed
                                                        control_flow_graph 96 401000-401020 GetWindowsDirectoryW 97 401022-40103c GetTempPathW wcslen 96->97 98 40105e-401070 swprintf 96->98 99 401073-401077 97->99 100 40103e-40104a wcslen 97->100 98->99 100->99 101 40104c-40105d wcslen 100->101
                                                        APIs
                                                        • GetWindowsDirectoryW.KERNEL32(00000019,00000104,76F90F00,00000019,004010D5,?,?,76F90F00,00000019,76F93300,00000000), ref: 0040100C
                                                        • GetTempPathW.KERNEL32(00000104,00000019), ref: 00401028
                                                        • wcslen.MSVCRT ref: 00401035
                                                        • wcslen.MSVCRT ref: 0040103F
                                                        • wcslen.MSVCRT ref: 0040104D
                                                        • swprintf.MSVCRT(00000019,00403010,?,00403020), ref: 0040106A
                                                        Memory Dump Source
                                                        • Source File: 00000006.00000002.1353477950.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                                                        • Associated: 00000006.00000002.1353460697.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                                                        • Associated: 00000006.00000002.1353493054.0000000000402000.00000002.00000001.01000000.00000004.sdmpDownload File
                                                        • Associated: 00000006.00000002.1353509883.0000000000404000.00000002.00000001.01000000.00000004.sdmpDownload File
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_6_2_400000_taskdl.jbxd
                                                        Similarity
                                                        • API ID: wcslen$DirectoryPathTempWindowsswprintf
                                                        • String ID:
                                                        • API String ID: 30654359-0
                                                        • Opcode ID: 4e66369f8c42ca16cc11ceda3156b996b8b268552c228e5f165bda1afb4dc665
                                                        • Instruction ID: 00ede0775e497762771a1e7050bb3ecf99d0a0070f097ddb1d391ed7ba2ca3cf
                                                        • Opcode Fuzzy Hash: 4e66369f8c42ca16cc11ceda3156b996b8b268552c228e5f165bda1afb4dc665
                                                        • Instruction Fuzzy Hash: ADF0C87170122067E7206B2CBD0AE9F77A8EF85315B01403AF786B62D0D2B55A5586EE

                                                        Control-flow Graph

                                                        • Executed
                                                        • Not Executed
                                                        control_flow_graph 102 4013d0-4013ec 103 4013f2-4013f7 102->103 104 40152b-401538 102->104 107 401404 103->107 108 4013f9-401402 103->108 105 4015e7-4015e9 104->105 106 40153e-40154e 104->106 109 401682-401689 105->109 110 4015ef-401600 105->110 111 401550 106->111 112 40157c-40158c 106->112 113 401406-401408 107->113 108->107 108->113 114 401602-401614 call 401690 110->114 115 40161e-401627 110->115 116 401554-401572 call 401690 111->116 119 4015a6-4015ad 112->119 120 40158e-40159c call 401690 112->120 117 40140a-40140c 113->117 118 40140e-401410 113->118 140 401616-40161a 114->140 125 401629-401645 ?assign@?$basic_string@GU?$char_traits@G@std@@V?$allocator@G@2@@std@@QAEAAV12@ABV12@II@Z 115->125 126 40164f-401656 115->126 141 401574-401578 116->141 127 401413-40141b 117->127 118->127 121 4015b3-4015cb ?assign@?$basic_string@GU?$char_traits@G@std@@V?$allocator@G@2@@std@@QAEAAV12@ABV12@II@Z 119->121 122 40167f 119->122 137 40159e-4015a2 120->137 121->121 129 4015cd-4015e4 121->129 122->109 125->125 132 401647-40164b 125->132 126->122 133 401658 126->133 134 40141d 127->134 135 40141f-40143e ??2@YAPAXI@Z 127->135 132->126 142 40165c-401675 ?assign@?$basic_string@GU?$char_traits@G@std@@V?$allocator@G@2@@std@@QAEAAV12@ABV12@II@Z 133->142 134->135 138 401440-401456 call 401690 135->138 139 401458-40145c 135->139 137->119 138->139 145 40147e-40148f 139->145 146 40145e 139->146 140->115 141->112 142->142 143 401677-40167b 142->143 143->122 149 401491 145->149 150 4014b5-4014bd 145->150 148 401462-40147c call 401690 146->148 148->145 152 401495-4014b3 call 401690 149->152 153 4014d0-4014f1 call 4018d0 150->153 154 4014bf-4014ce ?_Tidy@?$basic_string@GU?$char_traits@G@std@@V?$allocator@G@2@@std@@AAEX_N@Z 150->154 152->150 160 4014f3-401509 153->160 161 40150c-401528 153->161 154->153 154->154
                                                        APIs
                                                        • ??2@YAPAXI@Z.MSVCRT ref: 00401423
                                                        • ?_Tidy@?$basic_string@GU?$char_traits@G@std@@V?$allocator@G@2@@std@@AAEX_N@Z.MSVCP60(00000001,?,?,00000001,?), ref: 004014C3
                                                        • ?assign@?$basic_string@GU?$char_traits@G@std@@V?$allocator@G@2@@std@@QAEAAV12@ABV12@II@Z.MSVCP60(?,00000000,?,76E95320,00000000,00000000,?,?,00000001,?), ref: 004015C0
                                                        • ?assign@?$basic_string@GU?$char_traits@G@std@@V?$allocator@G@2@@std@@QAEAAV12@ABV12@II@Z.MSVCP60(?,00000000,?,76E95320,00000000,00000000,?,?,00000001,?), ref: 0040163D
                                                        • ?assign@?$basic_string@GU?$char_traits@G@std@@V?$allocator@G@2@@std@@QAEAAV12@ABV12@II@Z.MSVCP60(?,00000000,?,76E95320,00000000,00000000,?,?,00000001,?), ref: 0040166A
                                                          • Part of subcall function 00401690: ?_Xran@std@@YAXXZ.MSVCP60(?,?,?,?,?,?,00401AD1,000000FF,00401609,?,?,76E95320,00000000,00000000,?,?), ref: 004016EE
                                                          • Part of subcall function 00401690: ?_Split@?$basic_string@GU?$char_traits@G@std@@V?$allocator@G@2@@std@@AAEXXZ.MSVCP60(?,?,?,?,?,?,00401AD1,000000FF,00401609,?,?,76E95320,00000000,00000000,?,?), ref: 004016F6
                                                          • Part of subcall function 00401690: ?_Grow@?$basic_string@GU?$char_traits@G@std@@V?$allocator@G@2@@std@@AAE_NI_N@Z.MSVCP60(?,00000000), ref: 0040172D
                                                          • Part of subcall function 00401690: ?_Eos@?$basic_string@GU?$char_traits@G@std@@V?$allocator@G@2@@std@@AAEXI@Z.MSVCP60(?), ref: 0040173A
                                                          • Part of subcall function 00401690: ?_Split@?$basic_string@GU?$char_traits@G@std@@V?$allocator@G@2@@std@@AAEXXZ.MSVCP60 ref: 00401742
                                                        Memory Dump Source
                                                        • Source File: 00000006.00000002.1353477950.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                                                        • Associated: 00000006.00000002.1353460697.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                                                        • Associated: 00000006.00000002.1353493054.0000000000402000.00000002.00000001.01000000.00000004.sdmpDownload File
                                                        • Associated: 00000006.00000002.1353509883.0000000000404000.00000002.00000001.01000000.00000004.sdmpDownload File
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_6_2_400000_taskdl.jbxd
                                                        Similarity
                                                        • API ID: G@2@@std@@G@std@@U?$char_traits@V?$allocator@$V12@$?assign@?$basic_string@$Split@?$basic_string@$??2@Eos@?$basic_string@Grow@?$basic_string@Tidy@?$basic_string@Xran@std@@
                                                        • String ID:
                                                        • API String ID: 3154500504-0
                                                        • Opcode ID: 6636b44b641b77d4c97a97785cbcd8c41d41e59366c3e557b6000251a80c17ff
                                                        • Instruction ID: 1a94831c173c9211e28d46cdbba668eac71917d736910117d3345b582314b656
                                                        • Opcode Fuzzy Hash: 6636b44b641b77d4c97a97785cbcd8c41d41e59366c3e557b6000251a80c17ff
                                                        • Instruction Fuzzy Hash: FA81B472A003109BD710DE18CC8492AB7E5FBC8358F094A3EED49BB391D636EE05CB95